Community discussions

MikroTik App

Search found 9440 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 32
by mkx
Sat Mar 25, 2023 4:45 pm
Forum: General
Topic: Run a script with external device (but without another platform)
Replies: 3
Views: 78

Re: Run a script with external device (but without another platform)

Container, hosted by router itself. You can do almost anything inside a container. IMO it's a bit "heavy iron" just to present users with a big friendly red "activate" button though.
by mkx
Sat Mar 25, 2023 4:43 pm
Forum: General
Topic: How do we request for an account deletion?
Replies: 17
Views: 662

Re: How do we request for an account deletion?

And you too anav.
by mkx
Sat Mar 25, 2023 4:39 pm
Forum: Beginner Basics
Topic: Firewall rules for VLANs using their interface name
Replies: 13
Views: 294

Re: Firewall rules for VLANs using their interface name

Bridge ... has ports as members. Ports are ether2 or ether3. When it comes to bridge, VLANs are simply frame headers but beyond that bridge has no notion of vlan interfaces. Then there are interfaces. Those are entities where router actively communicates with rest of networks. Bridge happens to come...
by mkx
Sat Mar 25, 2023 1:12 pm
Forum: RouterBOARD hardware
Topic: Trying to unbrick my RG750GL.
Replies: 10
Views: 573

Re: Trying to unbrick my RG750GL.

As an aide to debugging ... it is possible to run wireshark on same interface. It then shows pretty clearly if/when RB starts with etherbooting procedure (it starts emitting bootp requests whuch are initially pretty similar to DHCP client requests). Another suggestion: connect dumbest switch you can...
by mkx
Sat Mar 25, 2023 1:00 pm
Forum: Wireless Networking
Topic: support for 802.11r
Replies: 19
Views: 727

Re: support for 802.11r

Are you sure your ax3 is being managed by capsman? My understanding is that local radios aren't supported. Probably it's not managed by CAPsMAN. But: docs say "APs need to be managed by the same instance of RouterOS" ... which is true if CAPsMAN (managing remote wifiwave2 radios) runs on ...
by mkx
Sat Mar 25, 2023 12:42 pm
Forum: Beginner Basics
Topic: inter VLAN Routing on RB951ui [SOLVED]
Replies: 2
Views: 98

Re: inter VLAN Routing on RB951ui [SOLVED]

CPU-switch interconnect has to be member of appropriate VLANs: /interface ethernet switch vlan add ports= switch1-cpu, ether2 switch=switch1 vlan-id=10 add ports= switch1-cpu, ether3 switch=switch1 vlan-id=20 Keep in mind that, from switch chip point of view, the CPU-switch interconnect (switchX-cpu...
by mkx
Fri Mar 24, 2023 10:06 pm
Forum: General
Topic: Link Aggregation Only Speeds up in One Direction
Replies: 2
Views: 120

Re: Link Aggregation Only Speeds up in One Direction

Link aggregation is not a simple "times N" business. There are many different types (or modes) which behave differently. And many types can be configured differently. And often both link partners (e.g. switch and NAS) can use different types but aggregated link still works. And most import...
by mkx
Thu Mar 23, 2023 7:40 pm
Forum: General
Topic: Range extender using MAC authentication config on Internet router ?
Replies: 3
Views: 146

Re: Range extender using MAC authentication config on Internet router ?

If you configure hAP ac3 as station, then you can set MAC address of wireless interface to something ISP's wireless router recognizes and allows. If you otherwise keep default config of device, then there are only a few changes necessary: remove correct wireless interface from list of bridge ports c...
by mkx
Thu Mar 23, 2023 11:49 am
Forum: Beginner Basics
Topic: couldn't use lets encrypt feature on mikrotik
Replies: 1
Views: 92

Re: couldn't use lets encrypt feature on mikrotik

LetsEncrypt has a global limit of how many certificate requests are granted per top level domain. Since DynDNS service, provided by Miktrotik, uses "mynetname.net" as TLD, there are large number of users trying to get LetsEncrypt certificate for their xxxxx.sn.mynetname.net device. This ge...
by mkx
Thu Mar 23, 2023 11:44 am
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 76
Views: 14457

Re: NTP stuck on Waiting....

Debug message is saying that Windows NTP server is not accurate enough to take it as time source. The most likely reason is that Windows machines traditionally keep time with low precision and are thus unfit for distribution of precise time (i.e. NTP). The less likely reason (in your case) is that N...
by mkx
Wed Mar 22, 2023 11:20 pm
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 23
Views: 2509

Re: House wifi6 network with Mikrotik AX or Audience

MU-MIMO, OFDMA, Beamforming, Target Wake Time, BSS, 1024QAM. MU-MIMO doesn't work well with only 2 chains/antennae on AP OFDMA helps where there are many concurrent users (not likely in SOHO environment) Beamforming doesn't work well with only 2 antennae ... unlike hAP ax2 Audience actually does ha...
by mkx
Wed Mar 22, 2023 10:46 pm
Forum: General
Topic: Changes to NTP in RouterOS 7
Replies: 3
Views: 306

Re: Changes to NTP in RouterOS 7

I never set up users using a script, so I can't help you with that ....
by mkx
Wed Mar 22, 2023 8:47 am
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 23
Views: 2509

Re: House wifi6 network with Mikrotik AX or Audience

AX2 has good performace over all it is better buy than Audience . I'm not sure that highlited part is true yet. This forum has plenty of threads about issues with hAP ax2 ... and none about issues with Audience. My own Audience works flawless ever since I purchased it. It came with factory software...
by mkx
Wed Mar 22, 2023 8:41 am
Forum: General
Topic: Hap Ax Lite WIFI Broken on 7.8 and downgrade [SOLVED]
Replies: 6
Views: 283

Re: Hap Ax Lite WIFI Broken on 7.8 and downgrade [SOLVED]

idk what happen if you mismatch packages.. If version of any of extra packages doesn't match version of base package, it won't be installed. BTW, no need to install all of the extra packages, only those which provide functionality you need. For ax devices one definitely needs wifiwave2 package, the...
by mkx
Wed Mar 22, 2023 8:37 am
Forum: General
Topic: Range extender using MAC authentication config on Internet router ?
Replies: 3
Views: 146

Re: Range extender using MAC authentication config on Internet router ?

Range extending, a.k.a. wireless bridge, comes with huge bag of problems. It's due to lack of standardization, so it's not really vendor specific, but it means that problems are likely when using equipment from different vendors. You can read more about problems in wireless station modes manual page...
by mkx
Wed Mar 22, 2023 8:30 am
Forum: General
Topic: CRS112-8P-4S with Packet Sniffer
Replies: 1
Views: 101

Re: CRS112-8P-4S with Packet Sniffer

Until somebody else with first-hand experience chimes in, here's my 5 cents: you probably have to configure port mirroring between target port and cpu-switch port, it's in switch menu . After that packet sniffer should be able to pick something ... Again: I don't have CRS1xx, so the above is only (w...
by mkx
Tue Mar 21, 2023 8:11 pm
Forum: Beginner Basics
Topic: NTP Server issues
Replies: 7
Views: 252

Re: NTP Server issues

Dont be afraid I am cleared up to PG 50+

You may be, but there are innocent young souls around here ....
by mkx
Tue Mar 21, 2023 5:31 pm
Forum: Beginner Basics
Topic: NTP Server issues
Replies: 7
Views: 252

Re: NTP Server issues

did you report that as a bug or do you get a spanking?? I was gonna comment your statement, but the comnent would probably be rated as PG18 :wink: Plus I only found this out the other day. Days of v6 in my home network are counted, so why should I bother to report ... And it's not a security proble...
by mkx
Tue Mar 21, 2023 5:20 pm
Forum: Beginner Basics
Topic: NTP Server issues
Replies: 7
Views: 252

Re: NTP Server issues

Additionally: NTP server on ROS v6 seems to be slightly non-standard ... ROS v7 clients don't want to sync with it although ntpq (linux command line tool) output seems fine.
by mkx
Tue Mar 21, 2023 3:18 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 527

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

Okay but only for RB4011 correct.

Well, OP's ap.rsc mentions it's from RB4011 ... hence my post is highly relevant in this thread.
by mkx
Tue Mar 21, 2023 3:14 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 527

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

It's been explained that when they first implemented L2 HW offload, they implemented it so that CPU-switch interconnect will only pass VLANs of which bridge interface is member (either tagged or untagged). And it worked perfectly because those devices were wired-only devices with single switch chip ...
by mkx
Tue Mar 21, 2023 3:07 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 527

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

One bug on devices that can offload VLANs to swtich chips (and RB4011 is one of them) on one and and have more than one switch chip (RB4011 is one of them) on the other hand: if VLANs span anything but single switch chip, then bridge port has to be tagged member of that VLAN even if device does not ...
by mkx
Tue Mar 21, 2023 3:01 pm
Forum: SwOS
Topic: SwitchOS not forwaring IPV6 packets from one CCR to another
Replies: 5
Views: 270

Re: SwitchOS not forwaring IPV6 packets from one CCR to another

TL;DR ... if you have IGMP snooping enabled on switches, disable it and see if it works then. I don't have first-hand experience with SwOS, but AFAIK IGMP snooping on both SwOS and ROS is broken and breaks IPv6. At least that was the case in ROS v6 and I haven't checked it with recent ROS versions. ...
by mkx
Mon Mar 20, 2023 10:59 am
Forum: General
Topic: IPIP over WG performance
Replies: 8
Views: 350

Re: IPIP over WG performance

It's MTU+fragmentation on top of additional overhead (both computational as well as data volume).

I wonder what IPIP functionality is missing from WG which makes you run IPIP on top of WG?
by mkx
Mon Mar 20, 2023 10:50 am
Forum: General
Topic: ARP List Auto-Populate
Replies: 1
Views: 86

Re: ARP List Auto-Populate

That's how IP devices are supposed to work unless there's a very good reason not to. So what is it you're trying to achieve?
by mkx
Mon Mar 20, 2023 10:48 am
Forum: General
Topic: WiFI VlAN Tag with upstream switch
Replies: 3
Views: 168

Re: WiFI VlAN Tag with upstream switch

You need to do this on the pfsense router and cisco switch so wrong forum.
@anav, I thought you'd come up with correct answer on this one ... which is: replace Cisco with a CRS3xx switch :wink:
by mkx
Sun Mar 19, 2023 9:11 pm
Forum: RouterBOARD hardware
Topic: AX2 Port issues with fixed speed
Replies: 4
Views: 205

Re: AX2 Port issues with fixed speed

Auto-negotiation includes (brief) link quality check. If negotiation ends up with speeds lower than expected, this indicates a problem with link. Most often it's marginal UTP cables, cable termination or connectors. And yes, some devices can be more susceptible to those problems than other devices. ...
by mkx
Sun Mar 19, 2023 3:51 pm
Forum: RouterBOARD hardware
Topic: AX2 Port issues with fixed speed
Replies: 4
Views: 205

Re: AX2 Port issues with fixed speed

Is there any particular reason why you want to fix the link speed?
by mkx
Sun Mar 19, 2023 2:13 pm
Forum: General
Topic: ip addresses outside of pool being served
Replies: 14
Views: 382

Re: ip addresses outside of pool being served

Could be some other device on same network that acts as DHCP server. You should be able to verify on client, which receives wrong IP address to see which DHCP server offered the wrong IP address. no new device that serves ip addresses has been added in the last 2 years. it receives the ip via ether...
by mkx
Sun Mar 19, 2023 12:31 pm
Forum: General
Topic: hap ax2 US, routerOS 7.8, UNII-4 not working [SOLVED]
Replies: 21
Views: 712

Re: hap ax2 US, routerOS 7.8, UNII-4 not working [SOLVED]

The "high band" radio lists channels up to 5825MHz (U-NNI-3) on my Audience. I'm not going to use those as U-NNI-3 channels are limited to 14dBm (25mW) in ETSI countries.
by mkx
Sun Mar 19, 2023 12:26 pm
Forum: RouterBOARD hardware
Topic: CRS312 1gbit combine 10gbit LAN
Replies: 1
Views: 190

Re: CRS312 1gbit combine 10gbit LAN

Yes, you can connect a secondary CRS312 switch as an uplink to add more ports. This is called "stacking" and is supported by the CRS312. It could be that different equipment vendors use same word but with different meanings. However, all vendors that I'm familiar with, use "stacking&...
by mkx
Sun Mar 19, 2023 11:57 am
Forum: General
Topic: hap ax2 US, routerOS 7.8, UNII-4 not working [SOLVED]
Replies: 21
Views: 712

Re: hap ax2 US, routerOS 7.8, UNII-4 not working [SOLVED]

I'm aware of that and obviously when device runs in AP / hotspot, it has to work according to country regulations. And in that case device has to find out (this way or another) which region it currently is to adapt to local regulatory limits. This is why I wrote "I don't understand why WiFi sta...
by mkx
Sun Mar 19, 2023 11:41 am
Forum: General
Topic: hap ax2 US, routerOS 7.8, UNII-4 not working [SOLVED]
Replies: 21
Views: 712

Re: hap ax2 US, routerOS 7.8, UNII-4 not working [SOLVED]

I was able to make the Pixel 6a see the network by installing grapheneOS. Strange, I don't know why factory Android couldn't see it. I expect that every modern device/OS has to have country limitations built in, just like ROS does. And it seems that FCC insists on clearing individual device types f...
by mkx
Sun Mar 19, 2023 11:25 am
Forum: General
Topic: Slow PPOE Authentication using RB4011
Replies: 1
Views: 106

Re: Slow PPOE Authentication using RB4011

Start by upgrading ROS to latest stable (which is 7.8 at time of writing this post).
by mkx
Sun Mar 19, 2023 11:23 am
Forum: General
Topic: ip addresses outside of pool being served
Replies: 14
Views: 382

Re: ip addresses outside of pool being served

Could be some other device on same network that acts as DHCP server. You should be able to verify on client, which receives wrong IP address to see which DHCP server offered the wrong IP address.
by mkx
Fri Mar 17, 2023 9:03 pm
Forum: General
Topic: 7.8 (stable) RB1100AHx4 CPU flaps between 533 MHz - 1400 Mhz
Replies: 2
Views: 153

Re: 7.8 (stable) RB1100AHx4 CPU flaps between 533 MHz - 1400 Mhz

Check CPU frequency setting (/system/routerboard/settings), if it's set to auto (default since v7) then it's automatically changed according to CPU load. If it's set to some particular value and yet you see it changing, then you may want to open support ticket.
by mkx
Fri Mar 17, 2023 8:56 pm
Forum: General
Topic: Changes to NTP in RouterOS 7
Replies: 3
Views: 306

Re: Changes to NTP in RouterOS 7

Yes, NTP setup changed. It's pretty easy to find out the new syntax if you try it manually. /system/clock/set time-zone-name=America/MyCity time-zone-autodetect=no /system/ntp/client/set servers=10.200.7.34 enabled=yes There's only one property (servers), but takes a coma-separated list of servers (...
by mkx
Fri Mar 17, 2023 7:39 pm
Forum: General
Topic: RB5009 Bonding Active Backup SFP+ with 1G
Replies: 2
Views: 418

Re: RB5009 Bonding Active Backup SFP+ with 1G

This document mentions that only 802.3ad bonding and balance-xor are offloaded to hardware. CRS326 is in the device class explicitly mentioned, I would expect RB5009 to fall in this category as well as it has a pretty advanced switch chip. Bond type active-backup is not HW offloaded on any of devic...
by mkx
Fri Mar 17, 2023 7:27 pm
Forum: Beginner Basics
Topic: VLAN ISP configuration
Replies: 1
Views: 153

Re: VLAN ISP configuration

I can imagine two possibilities: ISP will perform netmap between public IP address given to you and your communication address. In this case you have to setup a pretty straight-forward src-nat rule (similar to rule below, but without the dst-address part and to-addresses set to interface IP address)...
by mkx
Fri Mar 17, 2023 9:11 am
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 23
Views: 2509

Re: House wifi6 network with Mikrotik AX or Audience

https://rts-bg.com/bg/ethernet-routers/610-mikrotik-rb3011uias-rm.html - 189$ RB3011 is pretty outdated now. It was a truly amazing device back when it first came out, but it's outdated never the less. It'll barely route at 1Gbps. There are a much more powerful devices available now, such as RB4011...
by mkx
Fri Mar 17, 2023 9:01 am
Forum: General
Topic: IPSec IKE VPN: response packets are managed automatically? [SOLVED]
Replies: 1
Views: 106

Re: IPSec IKE VPN: response packets are managed automatically? [SOLVED]

NAT is a L3 (IP) function and when firewall does it, it doesn't matter how a particular local IP is connected to router regarding L2. So if a packet arrives via IPSec to router and that packet has to leave router via interface that has SRC-NAT active, then connection tracking machinery makes note of...
by mkx
Fri Mar 17, 2023 8:49 am
Forum: General
Topic: Fasttrack not working on RB5009
Replies: 13
Views: 618

Re: Fasttrack not working on RB5009

One question tough: what is your expectation when or if any time IPv6 FastTrack will be implemented in ROS v7, will the FastTrack handler also supports source and destination NAT, so special exceptions for NATed connections are not required. apply to snpt and dnpt actions (NPTv6) too as it seems le...
by mkx
Thu Mar 16, 2023 11:13 pm
Forum: General
Topic: Fasttrack not working on RB5009
Replies: 13
Views: 618

Re: Fasttrack not working on RB5009

Mangle and fasttrack are not compatible. Even in the case of the NPTv6 pair of rules that @Sob has provided ? AFAIK fasttrack is not yet supported in IPv6. But when it will be supported in IPv6, rules by @sob won't be compatible ... without properly configuring firewall filter rules (either fasttra...
by mkx
Thu Mar 16, 2023 7:57 pm
Forum: General
Topic: Fasttrack not working on RB5009
Replies: 13
Views: 618

Re: Fasttrack not working on RB5009

Mangle and fasttrack are not compatible. Hence it's good to avoid mangle rules if it's possible. If you have to use them anyway (meaning you have to take care what to fasttrack and what not), then I don't think there's much of a difference (if any).
by mkx
Thu Mar 16, 2023 7:42 pm
Forum: Beginner Basics
Topic: behind NAT
Replies: 5
Views: 287

Re: behind NAT

Both WAN IP addresses are in 10.0.0.0/8 and thus in private "non-routable" IP address space. ISP definitely performs NAT on your traffic.
by mkx
Thu Mar 16, 2023 10:51 am
Forum: General
Topic: HAPAX3 Low wifi signal strength & other issues [SOLVED]
Replies: 5
Views: 297

Re: HAPAX3 Low wifi signal strength & other issues [SOLVED]

Some of signal strength difference comes also from the fact that cAP ac uses 20MHz channel while hAP ax3 uses 40MHz channel. The difference due to this reason should only be 3dB though.
by mkx
Thu Mar 16, 2023 8:43 am
Forum: General
Topic: Fasttrack not working on RB5009
Replies: 13
Views: 618

Re: Fasttrack not working on RB5009

Fast track rule from published export is this: add action=fasttrack-connection chain=forward comment="Fasttrack not IPSEC" \ connection-mark=!ipsec connection-state=established,related dst-limit=\ 1,5,dst-address/1m40s hw-offload=yes limit=1,5:packet psd=21,3s,3,1 time=\ 0s-1d,sun,mon,tue,...
by mkx
Thu Mar 16, 2023 8:37 am
Forum: Beginner Basics
Topic: Auto Negotiation
Replies: 2
Views: 189

Re: Auto Negotiation

The RB5009, configured as switch, indicates that link partner is advertising speeds 10Mbps and 100Mbps. There are 3 possibilities (I'm listing them in order of probability, but you may want to check them starting from the simplest check towards the complex ones): The cable connectors are iffy ... if...
by mkx
Thu Mar 16, 2023 8:20 am
Forum: Beginner Basics
Topic: behind NAT
Replies: 5
Views: 287

Re: behind NAT

Compare WAN IP addresses on your Mikrotik to IP address shown by some internet-based service (e.g. https://www.whatismyip.com/ ) ... obviously you'll have to do some tricks get results for both WAN links. If IP addresses are the same, then ISP doesn't do additional NAT (but may still run firewall so...
by mkx
Wed Mar 15, 2023 9:40 pm
Forum: General
Topic: Upgrade and restore, now cant access Router
Replies: 7
Views: 251

Re: Upgrade and restore, now cant access Router

If the backup was made while device was running fine, then restoring config from backup file should be fine. If backup is from same device that is.
by mkx
Wed Mar 15, 2023 9:37 pm
Forum: General
Topic: How to free up space so I can upgrade to v7?
Replies: 6
Views: 241

Re: How to free up space so I can upgrade to v7?

Export config to text file. It doesn't contain absolutely everything (it lacks users, passwords, certificates, ssh keys, etc.), but it's pretty safe to trsnsfer to another device model. Plus you can see what it contaibs so you can adapt config if necessary.
by mkx
Wed Mar 15, 2023 9:32 pm
Forum: General
Topic: Upgrade and restore, now cant access Router
Replies: 7
Views: 251

Re: Upgrade and restore, now cant access Router

Restoring wrong backup file can completely mess configuration. But it's very unlikely that it would cause permanent damage to device.
by mkx
Wed Mar 15, 2023 9:15 pm
Forum: General
Topic: Fasttrack not working on RB5009
Replies: 13
Views: 618

Re: Fasttrack not working on RB5009

It's clear why you excluded ipsec traffic. But what about those packet rates etc.?
by mkx
Wed Mar 15, 2023 4:22 pm
Forum: General
Topic: Routers Coming with Default Passwords
Replies: 20
Views: 612

Re: Routers Coming with Default Passwords

You don't harden the router by default. You let the person installing it harden it. Indeed. But not on consumer market. If devices are sold on consumer market, they should come hardened from factory. Recently we've had an user who never changed any configuration because his RB worked as he wanted s...
by mkx
Wed Mar 15, 2023 4:01 pm
Forum: General
Topic: Fasttrack not working on RB5009
Replies: 13
Views: 618

Re: Fasttrack not working on RB5009

(2) bond (much like bridge) at the same time entity which distributes traffic between two or more physical links and is interface for higher layers. So yes, it's bond interface that has to be bridge port, not slave interfaces (used as links). @OP: what the hell is the fasttrack construct supposed to...
by mkx
Wed Mar 15, 2023 3:56 pm
Forum: General
Topic: Mikrotik as NTP server, reachable but does not sync
Replies: 8
Views: 494

Re: Mikrotik as NTP server, reachable but does not sync

@spyghost: when client status says "freq-drift: 0 PPM", then either device has a perfect oscillator (highly unlikely) or NTP client didn't do the synchronization properly yet ... it takes hours if not days for NTP client to settle to usable accuracy after it's configured from scratch (freq...
by mkx
Wed Mar 15, 2023 3:40 pm
Forum: Beginner Basics
Topic: RB750GL - RouterOS 7.6, Bridge or switch?
Replies: 8
Views: 342

Re: RB750GL - RouterOS 7.6, Bridge or switch?

The DHCP-client bit was so the RB750GL gets an IP address from the RB4011, so I can route return traffic from my main network more easily. it's not entirely clear here who does routing between VLAN50 and the rest of network. Since ether1 is either trunk or hybrid port (if untagged is allowed over w...
by mkx
Wed Mar 15, 2023 3:34 pm
Forum: Beginner Basics
Topic: RB750GL - RouterOS 7.6, Bridge or switch?
Replies: 8
Views: 342

Re: RB750GL - RouterOS 7.6, Bridge or switch?

I have a couple of RB951Gs, which feature a bit faster CPU but same switch chip. And I can tell that when configured via switch chip menus (including VLANs), this thing can do wirespeed without CPU even noticing. If done via bridge menus, it'll be able to go to 1Gbps between a pair of ports, but wit...
by mkx
Wed Mar 15, 2023 3:26 pm
Forum: Beginner Basics
Topic: Speed and CPU usage on crs310
Replies: 3
Views: 179

Re: Speed and CPU usage on crs310

Which interface is your WAN? If it's ether1, then it won't offload routing to HW, for that all involved interfaces have to be members of same bridge. Separation between LAN and WAN is then achieved using VLANs. However, some MT switches (dunno if CRS310 is one of them) experience quite some issues w...
by mkx
Wed Mar 15, 2023 8:27 am
Forum: Beginner Basics
Topic: RB750GL - RouterOS 7.6, Bridge or switch?
Replies: 8
Views: 342

Re: RB750GL - RouterOS 7.6, Bridge or switch?

Changing over to switch setup would definitely make your RB750GL a much faster switch. Conversion between the two configuration styles is not trivial, but not hard either. Basically you have to replace /interface bridge port and /interface bridge vlan sections with corresponding config under /interf...
by mkx
Tue Mar 14, 2023 6:29 pm
Forum: General
Topic: SSH-Session to Cisco not possible (ROS v7.8) - no matching key algorithm
Replies: 5
Views: 358

Re: SSH-Session to Cisco not possible (ROS v7.8) - no matching key algorithm

Yes ... using a full-blown ssh client which in fact still implements outdated algorithms but doesn't have them enabled by default. What I really wanted to know - is there a possibility to get connected to the cisco switch using a MikroTik router ? Is there a full-blown ssh client for MikroTik Route...
by mkx
Mon Mar 13, 2023 8:30 pm
Forum: SwOS
Topic: No https support in SwOS web interface?
Replies: 7
Views: 857

Re: No https support in SwOS web interface?

Post by @FramiJhames looks very much like something ChatGPT might come up with.
by mkx
Mon Mar 13, 2023 8:22 pm
Forum: General
Topic: Some flame around v6.48.6 (split from the "v6.48.6 [long-term] is released!" topic)
Replies: 26
Views: 412

Re: v6.48.6 [long-term] is released!

Such data as: SSID, MAC address, IP, VLAN name, VPN's name, ports, interface name, password, login, users, etc. Half of mentioned things are not sensitive at all. And further quarter is not exported (even with show-sensitive). IMO this is indicative why you'll have hard time to get any advice here....
by mkx
Mon Mar 13, 2023 8:15 pm
Forum: Beginner Basics
Topic: Mikrotik Hex RB750 DHCP Client Stuck on Searching [SOLVED]
Replies: 8
Views: 397

Re: Mikrotik Hex RB750 DHCP Client Stuck on Searching [SOLVED]

This device won't do anything because ... it's not configured.

Reset it to factory defaults and it should get you going.
by mkx
Mon Mar 13, 2023 7:22 pm
Forum: General
Topic: ROS v7 on an ARM board
Replies: 5
Views: 310

Re: ROS v7 on an ARM board

... it is different than ROS v7 installed on a hAP AC Router. Disclaimer: I don't own neither hAP ax2 nor hAP ac. However I do have a few other mikrotik devices (different architectures even) running v7 and they all seem alike. With one difference: wireless config comes in two varieties, one is leg...
by mkx
Mon Mar 13, 2023 2:34 pm
Forum: General
Topic: SSH-Session to Cisco not possible (ROS v7.8) - no matching key algorithm
Replies: 5
Views: 358

Re: SSH-Session to Cisco not possible (ROS v7.8) - no matching key algorithm

Is there a possibility to get connected?

Yes ... using a full-blown ssh client which in fact still implements outdated algorithms but doesn't have them enabled by default.
by mkx
Mon Mar 13, 2023 9:00 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

Thanks, that didn't seem to do anything for me, still stuck at 500Mbps with capsman enabled compared to 7-800Mbps without. Do you have local-forwarding set to no in CAPsMAN datapath configuration (it's default so this property might not be shown in export)? This setting is known to reduce throughpu...
by mkx
Mon Mar 13, 2023 8:55 am
Forum: General
Topic: login failure messages for various users attempting to access my Mikrotik devices
Replies: 2
Views: 291

Re: login failure messages for various users attempting to access my Mikrotik devices

Did you verify also the "trusted" applications? AWG antivirus is known to have a "feature" to detect vulnerable devices on LAN so that it can alert user about them. The feature is a recent addition and user is not prompted to enable it.
by mkx
Sun Mar 12, 2023 9:20 pm
Forum: General
Topic: Kid-control vs. Firewall
Replies: 4
Views: 283

Re: Kid-control vs. Firewall

If I understand the firewall implementation right if the first rule makes a jump to the kid-control chain for EVERY connection which started in the forward chain and no firewall condition in kid-control chain (which is added to the bottom) is met then it just ends its "journey" thru the f...
by mkx
Sun Mar 12, 2023 4:36 pm
Forum: RouterBOARD hardware
Topic: RB5009 power supply efficiency at 48V vs 24V
Replies: 1
Views: 312

Re: RB5009 power supply efficiency at 48V vs 24V

Efficiency of typical step-down converters is worse with higher difference between input and output voltage (there are numerous articles about it on internet). So I believe that numbers you're seeing are at least indicative if not scientifically accurate. Where higher voltages shine is power loss on...
by mkx
Sun Mar 12, 2023 4:07 pm
Forum: General
Topic: Mikrotik as NTP server, reachable but does not sync
Replies: 8
Views: 494

Re: Mikrotik as NTP server, reachable but does not sync

For NTP server on ROS to do whst it's supposed to do also NTP client on same device has to be up&running. So is NTP client state "synchronized"?
/system ntp client print

If client is not synchronized, then server will not return meaningfull sync data.
by mkx
Sun Mar 12, 2023 3:41 pm
Forum: Beginner Basics
Topic: interface list in /interface/bridge/vlan
Replies: 2
Views: 178

Re: interface list in /interface/bridge/vlan

Interface lists work where property is called <something> interface -list but not if property is called simply <something> interface or something which implies enumerating interfaces (like in your case with tagged ). IIRC interface lists are only widely used in firewall (which is L3 function) ... yo...
by mkx
Sat Mar 11, 2023 9:00 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 18
Views: 790

Re: Slow Hex file transfer speed

I'm sorry, but somebody else will have to explain it to you in Hebrew, I'm not fluent in it.

Perhaps it would help you if you revisited explanation of bridge mysteries by @sindy?
by mkx
Sat Mar 11, 2023 8:24 pm
Forum: Wireless Networking
Topic: How to create ap groups in CapsMan?
Replies: 13
Views: 958

Re: How to create ap groups in CapsMan?

Did you see this thread? viewtopic.php?t=175667
by mkx
Sat Mar 11, 2023 6:38 pm
Forum: Beginner Basics
Topic: logging in without actual login
Replies: 11
Views: 443

Re: logging in without actual login

so if i run a sniffer, what interface will be the target and if i opened using wireshark what i have to look in the sniffer file to identify the problem..?
Obviously it'll be WAN interface (if your winbox access is open). And the sniffer contents? Let me google that for you ...
by mkx
Sat Mar 11, 2023 6:29 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 18
Views: 790

Re: Slow Hex file transfer speed

My question yet unanswered to any satisfaction is what about the ingress filtering checkbox on the bridge a. should that be checked. b. what does it do c. how is it related to ingress filtering on each /interface bridge port line. It's about bridge port - the one that allows CPU/ROS to interact (vi...
by mkx
Sat Mar 11, 2023 6:15 pm
Forum: Wireless Networking
Topic: WIFI + BRIDGE + VLANS (access,trunk,hybrid)
Replies: 6
Views: 386

Re: WIFI + BRIDGE + VLANS (access,trunk,hybrid)

I want to better understand Case1, in case their is a scenario where it may make sense to use it. However I cannot wrap my head around Case 1, if you do assign vlan-id=5, vlan-mode=use tag! More specifically what do you then do on the /interface bridge port settings and /interface bridge vlan setti...
by mkx
Sat Mar 11, 2023 2:36 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 18
Views: 790

Re: Slow Hex file transfer speed

so bridge interface should be PVID=1 (as by default) untagged? And VLANs section of brigde shows VLAN1 as dynamic? It's not "should". But it's IMO a very good practice to have bridge interface (which is a "gateway" between CPU and the rest of LANs) configured as trunk port and h...
by mkx
Sat Mar 11, 2023 1:23 pm
Forum: RouterBOARD hardware
Topic: Product Request: Coax SFP
Replies: 13
Views: 5859

Re: Product Request: Coax SFP

Are they molded into the concrete? Yes, there are cases like this. E.g. my parents' house, I had to use MoCa adapters to deliver IPTV to the right spot. Works great as long as one removes any legacy crap (like splitters or outlets which feature RF filters) because those were made to pass frequencie...
by mkx
Sat Mar 11, 2023 12:23 pm
Forum: Beginner Basics
Topic: logging in without actual login
Replies: 11
Views: 443

Re: logging in without actual login

First off: it's a bad idea to allow winbox access from WAN. In past there were a few exploits of winbox access. Second: winbox saying "logging in" and nothing more very probably means some device is (silently) dropping packets and winbox is re-trying to establish connection. As you can log...
by mkx
Fri Mar 10, 2023 11:01 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 18
Views: 790

Re: Slow Hex file transfer speed

However unless I missed it (cause I don't know where to look), you are not hardware offloading the bridge. Config looks fine to me. I don't have any idea why it doesn't perform wirespeed. The fact that it's possible to get around 0.5Gbps of throughput without any noticeable CPU load tells that very...
by mkx
Fri Mar 10, 2023 8:53 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

Hi, your tests make no sence..how you can get on AC 945Mb/s? The old hAP ac (not the new ac2 variant) has 3 chains on 5GHz radio and has thus up to 1300Mbps interface rate. hAP ax3, OTOH, has only 2 chains and thus supports up to 866Mbps interface rate (if running in ac compatibility)or 1200Mbps in...
by mkx
Fri Mar 10, 2023 7:27 am
Forum: Beginner Basics
Topic: VLAN ax3
Replies: 20
Views: 2231

Re: VLAN ax3

( there is no CHAIN called drop LOL)
Really strange that you can create something that its not even an option :)

Creating custom chain (e.g. one named drop) is fine and sometimes very handy. However you have to configure firewall to jump into that chain (in certain conditions).
by mkx
Thu Mar 09, 2023 9:08 pm
Forum: SwOS
Topic: CRS309-1G-8S+IN - From Routeros to Swos
Replies: 13
Views: 678

Re: CRS309-1G-8S+IN - From Routeros to Swos

ROS defaults for bridge ports are PVID=1, frame-types=admit-all and ingress-filtering=no ... bridge interface has PVID set to 1 by default as well ... so if one simply enables vlan-filtering (default is disabled), device will still act as dumb switch between all nember ports, but this time only for ...
by mkx
Thu Mar 09, 2023 8:47 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

What does /interface/wifiwave2/monitor 0 (and 1) say about used Tx power? It should be somewhere above 20[dBm] ...

I don't think you have to set chains ... it'll just use all chains available in hardware.
by mkx
Thu Mar 09, 2023 3:57 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

That is when it did not match (even just once) the reject rule in your list. Right. I adjusted the rules that did not include signal-range to have one. Will test and report back. Edit: Here's report: I had to roll back the ACL changes. My daughter has a Nokia 7.1 android phone which seemingly doesn...
by mkx
Thu Mar 09, 2023 1:22 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

I dropped tx-power on the 2GHz radio to 12 so that clients prefer the 5GHz radio. You could try to "push" clients to 5GHz using access-list rules. I constructed a set of rules on my Audience (ac device running wifiwave2 in ROS v7.8): add action=reject allow-signal-out-of-range=10s comment...
by mkx
Thu Mar 09, 2023 12:03 pm
Forum: General
Topic: Firewall logs to files - naming convention
Replies: 4
Views: 260

Re: Firewall logs to files - naming convention

I agree that dateext is very useful option (if it's handled properly by logrotate implementation). I just strongly disagree to deviate in ROS from the way index numbering works in general linux.
by mkx
Thu Mar 09, 2023 11:57 am
Forum: Beginner Basics
Topic: CAPsMAN Wave2 802.11r fast roaming info [SOLVED]
Replies: 3
Views: 509

Re: Wave2 802.11r fast roaming info [SOLVED]

AFAIK (I hope I'm already wrong) currently CAPsMAN v2 doesn't support FT yet. So FT only works when wifiwave2 device (e.g. Audience or hAP ax3) is configured in stand-alone AP mode and FT works then between interfaces of same device (i.e. between 2.4GHz and 5GHz radio). The way it has to be set is t...
by mkx
Thu Mar 09, 2023 10:51 am
Forum: General
Topic: Terribly bad ingress shaping on CRS 317 and CRS326
Replies: 2
Views: 234

Re: Terribly bad ingress shaping on CRS 317 and CRS326

Out of curiosity: how did you test the performance of shaper? iperf UDP test or something different?
by mkx
Thu Mar 09, 2023 10:39 am
Forum: SwOS
Topic: CRS309-1G-8S+IN - From Routeros to Swos
Replies: 13
Views: 678

Re: CRS309-1G-8S+IN - From Routeros to Swos

Yes, this configuration will be offloaded to hardware, so traffic between a pair of SFP+ ports will not go via CPU. So it should match performance under SwOS. Yes, if you also add PVID setting to bridge ports, those will become hybrid ports. Obviously you have to change also frame-types setting to &...
by mkx
Thu Mar 09, 2023 10:23 am
Forum: General
Topic: Firewall logs to files - naming convention
Replies: 4
Views: 260

Re: Firewall logs to files - naming convention

This kind of naming is very common in linux when "logrotate" facility is used (the differentce is that in linux normally the file being actively written to has name without "index" (e.g. 0) in it). Plus it's pretty easy to trim excess files and keep the "index" in file ...
by mkx
Wed Mar 08, 2023 11:53 pm
Forum: SwOS
Topic: CRS309-1G-8S+IN - From Routeros to Swos
Replies: 13
Views: 678

Re: CRS309-1G-8S+IN - From Routeros to Swos

Just an example: /interface bridge add name=BR vlan-filtering=yes frame-types=admit-only-vlan-tagged ingress-filtering=yes #L2 setup ... all ports are trunk ports, tagged only /interface bridge port add bridge=BR interface=sfp-sfpplus1 frame-types=admit-only-vlan-tagged ingress-filtering=yes add bri...
by mkx
Wed Mar 08, 2023 3:49 pm
Forum: General
Topic: Ax2 in AP mode and bridge in client
Replies: 4
Views: 292

Re: Ax2 in AP mode and bridge in client

station-pseudobridge should work fine with a huge gotcha: DHCP server (sitting on the "master" side of such wireless bridge) has to allow multiple leases to same MAC address. If it doesn't (and many DHCP servers don't), then only first device on the "island side" successfully rec...
by mkx
Wed Mar 08, 2023 2:57 pm
Forum: General
Topic: Ax2 in AP mode and bridge in client
Replies: 4
Views: 292

Re: Ax2 in AP mode and bridge in client

To create transparent bridge between two wired "islands" of same LAN, the wireless leg has to support 4-address mode. WiFi standards don't specify such a mode, so vendors implemented them each their own way (so they are mostly mutually incompatible). This 4-address mode is enabled by setti...
by mkx
Wed Mar 08, 2023 2:33 pm
Forum: Beginner Basics
Topic: [RB450Gx4] kernel not found or data is corrupted
Replies: 10
Views: 788

Re: [RB450Gx4] kernel not found or data is corrupted

As I said, go for a pretty recent ROS package. I seem to remember that there were some problems with booting v7 kernel on devices with ancient routerboot ... so prerequisite for upgrading to v7 on those devices was to update routerboot to something fairly recent. And again, I've no Idea which fwf fi...
by mkx
Tue Mar 07, 2023 7:49 pm
Forum: General
Topic: How to force NATed machines to communicate with each other using their WAN ip addresses?
Replies: 6
Views: 376

Re: How to force NATed machines to communicate with each other using their WAN ip addresses?

dstnat: in:ether4 out:(unknown 0), src-mac, proto TCP (SYN), 192.168.10.10:51894->20.20.20.10:3389, len 52

I guess you see this in log ... is it verbose copy of whole log message? And what is now exact dst-nat rule?
by mkx
Tue Mar 07, 2023 6:19 pm
Forum: Beginner Basics
Topic: Port 2000/tcp open cisco-sccp?
Replies: 5
Views: 286

Re: Port 2000/tcp open cisco-sccp?

Document on IP/Services says that ROS uses TCP port 2000 for bandwidth testing service by default.
by mkx
Tue Mar 07, 2023 2:41 pm
Forum: Beginner Basics
Topic: [RB450Gx4] kernel not found or data is corrupted
Replies: 10
Views: 788

Re: [RB450Gx4] kernel not found or data is corrupted

I guess that "upgrade firmware over ..." refers to routerboot only and not entire ROS. So you can try to upgrade routerboot to at least 6.48.6 (latest long-term, I'm pretty confident it can boot ROS v7 kernel). Download main ROS package. Open it with 7-zip, go into etc folder (inside archi...
by mkx
Mon Mar 06, 2023 7:53 pm
Forum: RouterBOARD hardware
Topic: 4G LTE router recommendation
Replies: 4
Views: 337

Re: 4G LTE router recommendation

... the speed has been inconsistent. I got good speed in the early morning but the performance went down during the day. This is what usually hapoens if MNO's cell tower is in heavy use ... large number of subscribers competing for scarce resources (throughput). The only thing you can do to get bet...
by mkx
Mon Mar 06, 2023 3:04 pm
Forum: General
Topic: How to force NATed machines to communicate with each other using their WAN ip addresses?
Replies: 6
Views: 376

Re: How to force NATed machines to communicate with each other using their WAN ip addresses?

The dst-nat rules you already have, are almost fine. With exception: the "in-interface=ether2" stands in the way. So you can omit the "in-interface" property (but might cause some other problem, depends on the rest of NAT rules you have), or simply add similar pair of rules, but ...
by mkx
Mon Mar 06, 2023 9:09 am
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 17
Views: 3093

Re: 802.11r for hAP ac2?

802.11k is supported in wifiwave2.
the other one are coming too.

As the thread title says ... for hAP ac2? I'd love to see that ...
by mkx
Sun Mar 05, 2023 10:37 pm
Forum: General
Topic: Unable to access Mikrotik in bridge mode
Replies: 8
Views: 375

Re: Unable to access Mikrotik in bridge mode

/interface list member add comment=defconf disabled=yes interface=ether1 list=WAN add interface=ether2 list=LAN add interface=ether3 list=LAN add interface=ether4 list=LAN add interface=ether5 list=LAN add interface=wlan2 list=LAN add interface=wlan1 list=LAN The problem is that interface list is n...
by mkx
Sun Mar 05, 2023 1:40 pm
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 90
Views: 10584

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

With all the effort they put into antenna design, antenna radiation pattern is not spherical, it's torroidal (doughnut shaped). Which means that it does matter how device is mounted. If it's fit for ceiling mount it's not as fit for wall mount. Well, it can be done, but coverage won't be good in cer...
by mkx
Sun Mar 05, 2023 1:29 pm
Forum: Wireless Networking
Topic: AX2/7.8: Some 2Ghz devices unable to connect to wifiwave2 [SOLVED]
Replies: 4
Views: 411

Re: AX2/7.8: Some 2Ghz devices unable to connect to wifiwave2 [SOLVED]

A suggestion: try to set security parameters to WPA2 only ... authentication-types=wpa2-psk encryption=ccmp ... It could be that those IoT devices freak out due to seeing unknown security features offered by AP. Another possibility would be to downgrade the 2.4GHz radio to 802.11n (chanel.band=2ghz-...
by mkx
Sun Mar 05, 2023 1:18 pm
Forum: General
Topic: IPv6 Advertising two ranges on one interface [SOLVED]
Replies: 5
Views: 1638

Re: IPv6 Advertising two ranges on one interface [SOLVED]

It looks like Windows just strips off the vlan tags and then gets the RAs which are in VLAN tagged packets.
This is already a pretty well known fact around here ....
by mkx
Sun Mar 05, 2023 1:16 pm
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 23
Views: 2400

Re: Router Advertisement leakage across VLANs

IMO it's a gross misconfiguration (of network admin mostly) to set port as hybrid or trunk when machibe, connecting to that port is a Windows machine. Only when machine administrator adjusts adapter/network stack settings to deal with tagged frames properly, then it's time for network admin to allow...
by mkx
Sun Mar 05, 2023 1:05 pm
Forum: General
Topic: AP WLAN VLAN something wrong
Replies: 7
Views: 393

Re: AP WLAN VLAN something wrong

/ip dns is an array of properties with values. You can only change settings of existing (predefined) properties, you can't add/invent new ones. comment does not exist ... neither in 6.49.7 nor in 7.8. Sometimes I wonder if @anav has something to do with ChatGPT (who is known to invent things) :lol:
by mkx
Sat Mar 04, 2023 9:06 pm
Forum: Wireless Networking
Topic: RB532A in client mode
Replies: 3
Views: 248

Re: RB532A in client mode

Some DHCP servers can assign multiple IP addresses to single MAC address. I've no idea whether Huavei DHCP server is one of those. If MT device is configured as station-pseudobridge, then it'll use own MAC address for all packets going out through wifi interface. Which means that AP and all devices ...
by mkx
Sat Mar 04, 2023 8:44 pm
Forum: General
Topic: Possible Bug with DHCPv6 in RouterOS 7.8? [SOLVED]
Replies: 8
Views: 412

Re: Possible Bug with DHCPv6 in RouterOS 7.8? [SOLVED]

IPv6 setting forwarding defines whether device will act as IPv6 router or not. If you use device as AP or as switch (or as combination of both), then it's fine to set this setting to no. If device should forward traffic between different L3 interfaces, then this setting has to be set to yes.
by mkx
Sat Mar 04, 2023 5:30 pm
Forum: General
Topic: Possible Bug with DHCPv6 in RouterOS 7.8? [SOLVED]
Replies: 8
Views: 412

Re: Possible Bug with DHCPv6 in RouterOS 7.8? [SOLVED]

As @tdw hinted: Mikrotik default config is essentially not to accept RAs. You need them accepted, so configure your Mikrotik to do it:
/ipv6 settings set accept-router-advertisements=yes

Note that up to and including 7.7 routes, accepted by RAs, were not shown under /ipv6 route.
by mkx
Sat Mar 04, 2023 3:21 pm
Forum: RouterBOARD hardware
Topic: hAP ax² dual band Wi-Fi 6 (802.11ax)
Replies: 287
Views: 48585

Re: hAP ax² dual band Wi-Fi 6 (802.11ax)

I solved the problem by setting the frequency to 5745 UNII-3 is a fairly recent addition to allowed 5GHz band. Not every 5G WiFi device has hardware support for it, not every WiFi device had been updated with new country regulations. Support for UNII-4 channels is even less common. We'd have to kno...
by mkx
Sat Mar 04, 2023 3:07 pm
Forum: Beginner Basics
Topic: Dedicated bridges for Ethernet and WiFi
Replies: 4
Views: 298

Re: Dedicated bridges for Ethernet and WiFi

Minimum configuration is one bridge. In most configuration WAN requires single interface which can either be off-bridge or member of common bridge (properly configured). Actually, minimum configuration is no bridge ... if all interfaces are used for connecting different networks (so device is router...
by mkx
Sat Mar 04, 2023 9:56 am
Forum: Wireless Networking
Topic: RB532A in client mode
Replies: 3
Views: 248

Re: RB532A in client mode

Wireless mode "bridge" only works, if AP is mikrotik as well. There are some less favourable alternatives but might not work as intended. Read about them in this article: https://wiki.mikrotik.com/wiki/Manual:Wireless_Station_Modes Reading the document one would assume that "station-p...
by mkx
Fri Mar 03, 2023 10:27 pm
Forum: Beginner Basics
Topic: VLAN tutorial - Understanding menu "/interface bridge vlan"
Replies: 11
Views: 1002

Re: VLAN tutorial - Understanding menu "/interface bridge vlan"

First: it's a bit confusing which bridge personality is meant in which configuration part. Rule of thumb: when property name is "bridge", then it's referring to switch-like personality. When property name is "interface", then it refers to the bridge personality of interface betwe...
by mkx
Fri Mar 03, 2023 9:17 pm
Forum: Beginner Basics
Topic: Dedicated bridges for Ethernet and WiFi
Replies: 4
Views: 298

Re: Dedicated bridges for Ethernet and WiFi

Advantage might be seemingly spmpler setup. But there are plenty of disadvantages, most important one is possible loss of HW offload of wired traffic and thus increase of CPU load and/or decreased throughput.
by mkx
Fri Mar 03, 2023 9:13 pm
Forum: Beginner Basics
Topic: Information about CRS310-1G-5S-4S+
Replies: 3
Views: 244

Re: Information about CRS310-1G-5S-4S+

The idea is simple and only works either a) if all LANs which use same switch but need to be separated on L2 are untagged or b) if LANs include trunk ports, those VLANs are distinct. For case a) one configures part of ports with one PVID and the other ports with another PVID ... only ports with same...
by mkx
Fri Mar 03, 2023 12:12 pm
Forum: SwOS
Topic: inquire about the default behavior of the switch
Replies: 2
Views: 289

Re: inquire about the default behavior of the switch

Switch (with or without VLANs) normally doesn't require a running router for its own operations. Which is switching ethernet frames between ports (according to VLAN configuration if it has VLAN configuration set and enabled). Router offers IP services to connected networks. In the narrow meaning onl...
by mkx
Fri Mar 03, 2023 12:05 pm
Forum: Wireless Networking
Topic: hAP ax2 no WiFi client mode. removed?
Replies: 9
Views: 597

Re: hAP ax2 no WiFi client mode. removed?

.. station on wifiwave2 doesn't work either, selecting a SSID from scan results in a generic winbox error. Well, wifiwave2 driver is a moving target right now and MT's tradition is that those moving targets are really only supported via CLI. So inability to make things work in station mode via winb...
by mkx
Fri Mar 03, 2023 12:01 pm
Forum: Wireless Networking
Topic: Configure dual band interface on cAP manually
Replies: 1
Views: 199

Re: Configure dual band interface on cAP manually

assuming 2.4GHz radio (probably interface wlan1) is provisioned and running ... create new wireless interface which will be virtual and will use wlan1 as master interface. Something like this: /interface wireless add master-interface=wlan1 name=wlan1_guest ssid=<guest SSID> security-profile=<guest ...
by mkx
Fri Mar 03, 2023 9:24 am
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 315
Views: 64121

Re: v7.8 [stable] is released!

Unlike many vocal individuals, who express their opinions on LT version of ROS v7 around here, I can fully understand why MT doesn't release LT version of v7. This forum is full of reports of bugs, missing functionality and what not. And until most of those complaints are closed, ROS v7 is under ver...
by mkx
Fri Mar 03, 2023 9:16 am
Forum: Beginner Basics
Topic: Getting ping and timeout
Replies: 2
Views: 210

Re: Getting ping and timeout

In addition: try pings to a server close to your router (network wise) to exclude possible bottlenecks/congestions on upstream links which are way beyond your administrative reach.
by mkx
Fri Mar 03, 2023 9:13 am
Forum: Beginner Basics
Topic: Information about CRS310-1G-5S-4S+
Replies: 3
Views: 244

Re: Information about CRS310-1G-5S-4S+

When running ROS on this device, if bridge configuration subtree is done correctly, should perform as good as if there was SwOS available for it, i.e. wirespeed. Default config (all ports bridged, no VLANs) is an example of such "wirespeed config". If you add VLANs in the "single brid...
by mkx
Thu Mar 02, 2023 9:14 pm
Forum: Wireless Networking
Topic: hAP ax2 no WiFi client mode. removed?
Replies: 9
Views: 597

Re: hAP ax2 no WiFi client mode. removed?

Are you sure wifiwave2 package is present on that device? Wireless radio on hAP ax 2 is only supported by wifiwave2. So if OP sees any of wireless-related options this means wifiwave2 driver is installed. Yes, it's known that wifiwave2 for now only supports 2 modes: AP and station. Some of those Qu...
by mkx
Thu Mar 02, 2023 8:47 pm
Forum: Beginner Basics
Topic: Firewall Filter tool is not efficent
Replies: 13
Views: 555

Re: Firewall Filter tool is not efficent

Well, so far you got opinion of two forum members. Perhaps some other members will still chime in with different opinions in the next few days. At the end of the day it's up to you to do whatever you decide to do. You can follow those youtube videos and see if that's gonna help you get work done (bu...
by mkx
Thu Mar 02, 2023 8:15 pm
Forum: RouterBOARD hardware
Topic: 40G direct attach cable
Replies: 8
Views: 504

Re: 40G direct attach cable

So you do have dark fiber between the sites? There's a passive 80Gbps to 8x 10Gbps splitter solution and it's called CWDM. Mikrotik offers some CWDM gear. You have to use CWDM SFP+ modules (instead of normal 1310nm SMF modules), a passive MUX which joins/separates different wavelengths at each end o...
by mkx
Thu Mar 02, 2023 7:58 pm
Forum: Wireless Networking
Topic: Channel frequency
Replies: 21
Views: 1333

Re: Channel frequency

Ceee, this means setting center frequency 5500 ... but that still doesn't make channel 100 to be 80MHz wide. Yes it is 80 MHz wide. That is the way Mikrotik does it. It's a matter of notation Not entirely. Either that contigous 80MHz channel is 100+104+108+112 (combination of 4 adjacent 20MHz chann...
by mkx
Thu Mar 02, 2023 7:44 pm
Forum: General
Topic: Block IPv6 Portscans - Rule works for IPv4 but not IPv6
Replies: 8
Views: 510

Re: Block IPv6 Portscans - Rule works for IPv4 but not IPv6

The idea is this: if some remote host tries to connect to IP/port combination which is not allowed (either it's not DST NATed in IPv4 or is blocked in IPv6), then such remote host is added to black list. Hence forth the same host can not connect to otherwise allowed/open IP/port combination (e.g. HT...
by mkx
Thu Mar 02, 2023 7:37 pm
Forum: Beginner Basics
Topic: CRS305-1G-4S+IN 5 Port Desktop Switch config issues
Replies: 3
Views: 233

Re: CRS305-1G-4S+IN 5 Port Desktop Switch config issues

By default, CRS devices are configured to act as switches between all ports. So the problem you're experiencing is most probably not configuration error. I don't have a CRS305, but I believe that the RJ45 port is intended for management. Thus it might not be part of switch ports group. Mikrotiks are...
by mkx
Thu Mar 02, 2023 7:28 pm
Forum: Beginner Basics
Topic: Firewall Filter tool is not efficent
Replies: 13
Views: 555

Re: Firewall Filter tool is not efficent

Those domains and hosts resolve differently every time somebody resolves them. Which means that address list might be current at some moment in time and awfully obsolete some tens of seconds later. For example, www.facebook.com resolves as CNAME (pointer) to some particular host with TTL of 1 hour (...
by mkx
Thu Mar 02, 2023 5:06 pm
Forum: Beginner Basics
Topic: Firewall Filter tool is not efficent
Replies: 13
Views: 555

Re: Firewall Filter tool is not efficent

I dont want to block the traffic. I just want to provide 200 Mbps bandwidth on Youtube, Facebook, and WhatsApp. OK, so it's not application blocking, it's application throughput shaping. Actually similar concept ... The point of what @anav wrote is that ROS is not up to precise application identifi...
by mkx
Thu Mar 02, 2023 5:02 pm
Forum: Beginner Basics
Topic: Redirect from webfig
Replies: 1
Views: 148

Re: Redirect from webfig

It is possible, but it's not very straight forward. I'll assume a few things: company's main page FQDN points at router's WAN IP address there's a DST NAT rule which forwards access to port 80 from WAN interface to actual web server, which is hosted on a LAN server you're trying to access company's ...
by mkx
Thu Mar 02, 2023 4:37 pm
Forum: Beginner Basics
Topic: Fairly fresh setup. Need help forwarding ports to a reverse proxy.
Replies: 7
Views: 408

Re: Fairly fresh setup. Need help forwarding ports to a reverse proxy.

This setup has a gotcha: it doesn't work if you want to connect to WAN IP address (and have DST NAT working) from within LAN. Neither does the rule by @baragoon on its own (it needs another SRC-NAT rule), but the rule in my post can't be used in this case. I'm gonna assume this is when to use a hai...
by mkx
Thu Mar 02, 2023 9:18 am
Forum: General
Topic: Hotspot and Station Mode
Replies: 5
Views: 529

Re: Hotspot and Station Mode

Post configuration you have so far (execute /export hide-sensitive file=anynameyouwish in terminal window, fetch resulting file and post its contents inside [code] [/code] block).

Just to make sure: the upstream AP doesn't require any special registration of users (apart from knowing WSK)?
by mkx
Wed Mar 01, 2023 11:49 pm
Forum: Wireless Networking
Topic: wAP AC units over POE don't get enough power.
Replies: 4
Views: 503

Re: wAP AC units over POE don't get enough power.

No issues, what voltage do you use to power this up and what is the loaded voltage at the unit? Measured voltage at 23.2VDC at one problematic unit. Voltage is fine if it was measured while wAP ac was drawing power (wAP ac can take as low as 11V). If the measurement was done when wAP ac was off, th...
by mkx
Wed Mar 01, 2023 11:44 pm
Forum: Wireless Networking
Topic: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]
Replies: 25
Views: 1458

Re: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]

... it can detect the location by SIM operator ...

SIM operator doesn't necessarily give current location (think roaming). So it's actually MCC of currenly used network (can even be the "emergency calls only" half-registered network, phone will be able to read MCC anyway).
by mkx
Wed Mar 01, 2023 9:54 pm
Forum: Wireless Networking
Topic: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]
Replies: 25
Views: 1458

Re: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]

The LG G4 I mentiobed in post #15 above got info about rough location from mobile network (MCC says it all). So it doesn't really matter where devicecwas purchased (unless it's crippled to country speciffics), if it's truly "world" device it'll adjust to country regulations according to lo...
by mkx
Wed Mar 01, 2023 9:41 pm
Forum: Beginner Basics
Topic: Fairly fresh setup. Need help forwarding ports to a reverse proxy.
Replies: 7
Views: 408

Re: Fairly fresh setup. Need help forwarding ports to a reverse proxy.

It is fine to have DST NAT set up like this: add action=dst-nat chain=dstnat in-interface-list=WAN dst-port=80,443 protocol=tcp to-addresses=LAN_SERVER_IP WAN interface list is already used in firewall and NAT rules. This setup has a gotcha: it doesn't work if you want to connect to WAN IP address (...
by mkx
Wed Mar 01, 2023 3:11 pm
Forum: Wireless Networking
Topic: How to mitigate WiFi-Bluetooth interference?
Replies: 1
Views: 152

Re: How to mitigate WiFi-Bluetooth interference?

None. The interference happens because both protocols use same open/free radio spectrum. There's no physical property of radio transmitter/receiver that can deal with in-band interference and the possibilities to filter out interference, which is not using same technology, are limited. E.g. typical ...
by mkx
Wed Mar 01, 2023 9:10 am
Forum: General
Topic: HTTP speed test
Replies: 40
Views: 2797

Re: HTTP speed test

2. Using observation of the WAN interface and ping time although not always accurate (see the example of my speedtest results, I guarantee that if the parameters are ping time/latency, anything related to ping then failover will never succeed). You decided to misinterpret what I wrote ... and the p...
by mkx
Tue Feb 28, 2023 11:02 pm
Forum: Wireless Networking
Topic: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]
Replies: 25
Views: 1458

Re: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]

... if the channel width is 80 MHz and the center freq is 5500 it means it starts at 5460 which is outside the range. Nope. Mikrotik shows frequency which is center frequency of Control channel. So clearly control channel was ftom 5490MHz to 5510MHz. The rest is a guess, but if channel layout was C...
by mkx
Tue Feb 28, 2023 10:17 pm
Forum: Beginner Basics
Topic: VLAN tutorial - Understanding menu "/interface bridge vlan"
Replies: 11
Views: 1002

Re: VLAN tutorial - Understanding menu "/interface bridge vlan"

As I noted earlier, these commands add tagging of the VLAN id to the packets which leave the bridge. No, these commands don't add or remove tags. These commands say that frames, tagged with VIDs configured, can pass tagged from bridge (the switch like entity) to bridge interface. The other member p...
by mkx
Tue Feb 28, 2023 10:01 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 315
Views: 64121

Re: v7.8 [stable] is released!

with Huawei MediaPad T5 tablet to use 5GHz band (it used to stick to 2.4GHz a lot).
I thought I was the only one in the world this this damn tablet 😂
Nah, we're two ... and a a few million Chineze ....
by mkx
Tue Feb 28, 2023 9:45 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 315
Views: 64121

Re: v7.8 [stable] is released!

After a quick check on this topic, I see the 7.8 as an ALPHA... not a "stable" release... Could be. But my Audience (running wave2 driver) lijes it very much, since upgrade to 7.8 WiFi works much smoother, I don't have to play tricks with Huawei MediaPad T5 tablet to use 5GHz band (it use...
by mkx
Tue Feb 28, 2023 6:23 pm
Forum: Wireless Networking
Topic: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]
Replies: 25
Views: 1458

Re: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]

I don't know how exactly Israel mandates usage of WiFi, so your guess is as good as mine.
by mkx
Tue Feb 28, 2023 6:19 pm
Forum: General
Topic: HTTP speed test
Replies: 40
Views: 2797

Re: HTTP speed test

How do I know if my bandwidth is dropping or not if WAN utilization is low and ping is good? You can't be sure but if buffers are not filling and thus ping is not increasing, it's pretty safe to assume that bandwidth is higher than required throughput at that particular moment. Meaning that there i...
by mkx
Tue Feb 28, 2023 12:27 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

The way @pe1chl showed actually allows to have different channel parameters depending on selected centre frequency. When simply listing frequencies in single statement all the rest of properties have to be the same. So the new way is not as flexible as the old one ... sigh, I guess we'll have to get...
by mkx
Tue Feb 28, 2023 12:11 pm
Forum: Wireless Networking
Topic: How to create ap groups in CapsMan?
Replies: 13
Views: 958

Re: How to create ap groups in CapsMan?

If your current provisioning rule looks like this: add radio-mac=00:00:00:00:00:00 action=create-dynamic-enabled master-configuration=cfg_5G name-format=prefix-identity name-prefix="5G" then you have to add additional provisioning rule (and move it above the existing one) like this: add ra...
by mkx
Tue Feb 28, 2023 11:55 am
Forum: General
Topic: HTTP speed test
Replies: 40
Views: 2797

Re: HTTP speed test

When the bandwidth that I subscribe to from A drops to 1Mbps, how can I make the internet access route switch to B automatically other than using the speedtest results as a parameter? While uplink to provider A is in use, running speed test a) interferes with normal traffic and b) is inconclusive b...
by mkx
Tue Feb 28, 2023 11:47 am
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 315
Views: 64121

Re: v7.8 [stable] is released!

Nadol - Why? There was no problem description. I don't know why. It start with 7.7, clicking download&install using winbox, reboot and still at 7.6 When upgrade fails, it's usually something in logs about the cause of it. So after you try to upgrade and it fails, immediately after reboot check ...
by mkx
Tue Feb 28, 2023 9:12 am
Forum: Wireless Networking
Topic: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]
Replies: 25
Views: 1458

Re: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]

DFS channels between 5600 MHz and 5650 MHz are so called "weather" DFS channels which require scanning with duration of 10 minutes ... during which no transmission is allowed. So if there's no weather radar in your neighbourhood, WiFi might actually appear ... but after 10 minutes (which i...
by mkx
Tue Feb 28, 2023 9:04 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

Too bad wifiwave2 doesn't allow constructing frequency lists ... or does it? Entries under /interface/wifiwave2/channel don't seem to have property list available?
by mkx
Tue Feb 28, 2023 8:57 am
Forum: General
Topic: HTTP speed test
Replies: 40
Views: 2797

Re: HTTP speed test

Surely if everyone reasoned badly like you, everything would be blocked due to continuous tests that consume bandwidth for nothing. So, how to change internet access routes automatically when the bandwidth on one of the routes is dropping? [/quote] Routing is not the problem, upstream link capacity...
by mkx
Tue Feb 28, 2023 8:53 am
Forum: Beginner Basics
Topic: hardware offload on CRS326
Replies: 8
Views: 949

Re: hardware offload on CRS326

There is a value that I can pay attention? actualy on crs326-24g-2s+ have 600 devices at /in/bridge/host print count-only, and my cpu is reaching 100%, so its already "large"? The value which (in your use scenario) has to be observed is "IPv4 route prefixes" (and "IPv6 rout...
by mkx
Tue Feb 28, 2023 8:45 am
Forum: Beginner Basics
Topic: VLAN tutorial - Understanding menu "/interface bridge vlan"
Replies: 11
Views: 1002

Re: VLAN tutorial - Understanding menu "/interface bridge vlan"

As @anav noted, it is perfectly fine to group lines per VLAN. There's a gotcha: some VLAN ID can only be referred to in single line. So this construct is not possible: /interface bridge vlan add bridge=BR1 tagged=BR1 vlans=10,20,30 add bridge=BR1 tagged=BR1,ether1 vlans=10 this one is fine though: /...
by mkx
Mon Feb 27, 2023 5:08 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 315
Views: 64121

Re: v7.8 [stable] is released!

I have two 64MiB partitions on Audience, after downloading the update (ROS 7.8 + wifiwave2) there was only left 1% free, it barely fit in it. After the actualization 41MiB of 64.3 MiB used (believe me I don't store files on the router). @MIKROTIK Can it be slimmed down? Upgrading ROS+wifiwave2 on m...
by mkx
Mon Feb 27, 2023 11:48 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

Can MT wifiwave2 do this, what Engenius descibes as bandsteering ? I don't think it can ... in current state. Apart from ACLs (which are static) there's no mechanism in ROS to ignore wireless clients when they try to associate ... which is, by the way, the gist of Engenius' implementation: ignore a...
by mkx
Mon Feb 27, 2023 11:31 am
Forum: Beginner Basics
Topic: Fiber selection
Replies: 2
Views: 304

Re: Fiber selection

Mentioned SFP+ modules should do the trick. When it comes to fibre stretch between "civilization and cave", in principle there are two kinds of optical cables: single-mode (SM) and multi-mode (MM). Mentioned SFP+ module works with MM (multi-mode) fibre, so that's the type you need to get. ...
by mkx
Mon Feb 27, 2023 11:22 am
Forum: Beginner Basics
Topic: Newbie with access port configuration
Replies: 4
Views: 297

Re: Newbie with access port configuration

As I said: it's cosmetics. xSTP is actually function of bridge and if a port is member of bridge, it's not possible to "disable xSTP" on that port only. It is, however, possible to set that port as edge and in this case (bugs aside) that port should not participate in any of xSTP communica...
by mkx
Mon Feb 27, 2023 7:55 am
Forum: Wireless Networking
Topic: How to create ap groups in CapsMan?
Replies: 13
Views: 958

Re: How to create ap groups in CapsMan?

Nope. Provisioning doesn't touch radio MAC address. Provisioning can set VAP's MAC address (interface.mac-address) and if it's not set, it's "invented". And I guess it's invented at provisioning time, not at configuration time. So I imagine that if you add radio-mac=<MAC address> copy-from...
by mkx
Sun Feb 26, 2023 9:10 pm
Forum: Wireless Networking
Topic: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!
Replies: 53
Views: 6806

Re: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!

He successfully avoided capsman so far ... karma bit him :wink:
by mkx
Sun Feb 26, 2023 9:08 pm
Forum: Wireless Networking
Topic: How to create ap groups in CapsMan?
Replies: 13
Views: 958

Re: How to create ap groups in CapsMan?

I don't think you can create a group of devices. In provisioning you can add individual devices, each is identified by radio-mac ... which is MAC address of cAP's radio interface. I didn't try, but there's option copy-from ... it might simply copy settings of referenced entry (when executing add com...
by mkx
Sun Feb 26, 2023 8:41 pm
Forum: Wireless Networking
Topic: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!
Replies: 53
Views: 6806

Re: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!

The wifiwave2 configuration tree (in CLI, dunno about GUIs) contains branch called security. There you define a profile. When provisioning wireless interfaces (either master or virtual), refer to the profile instead of setting things directly. This way you can be sure that all interfaces (which use ...
by mkx
Sun Feb 26, 2023 7:52 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

Well, it is possible to make car, driving on a highway lane, to change to another lane by hitting it from a side, but I wouldn't call that "steering". After you configure all the bells of 802.11r (the whistles of k+v are missing), you can configure access-list to kick devices off 2.4GHz ra...
by mkx
Sun Feb 26, 2023 6:31 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 191
Views: 16649

Re: MikroTik hAP ax3 poor WiFi performance

There's no such thing as band steering in WiFiland. But I guess that devices have some preference built in and one can help them to select AP in their favourite band by enabling the whole suite of 802.11 r+k+v ... As far, as I know, MT implemented 802.11r (a.k.a. BSS fast transition) but not the oth...
by mkx
Sun Feb 26, 2023 11:36 am
Forum: Beginner Basics
Topic: Newbie with access port configuration
Replies: 4
Views: 297

Re: Newbie with access port configuration

My understanding is as follows: bridge port in ROS has certain set of properties and those properties will be set always (this way or another). Then it comes to the point whether some of properties actually make sense in certain condition or not. When bridge has any protocol-mode set (other than non...
by mkx
Sun Feb 26, 2023 11:12 am
Forum: Beginner Basics
Topic: No internet guest VLAN [SOLVED]
Replies: 13
Views: 992

Re: No internet guest VLAN [SOLVED]

... will using two different SSID names even allow the firewall to distinguish what is connected to Guest from what is connected to IoT? No, firewall doesn't know anything about SSIDs, it only knows about L3+L4 stuff (IP addresses, TCP/UDP ports) and L2 interfaces it's working with. Now, if firewal...
by mkx
Sun Feb 26, 2023 11:05 am
Forum: Beginner Basics
Topic: RouterOS as DNS ONLY SERVER
Replies: 1
Views: 228

Re: RouterOS as DNS ONLY SERVER

What you observe doesn't necessarily mean that all traffic of those clients is actually routed by Mikrotik. It's possible you only see DNS traffic. But it's also possible that MT draws traffic towards itself. But if you want to make a step forward in direction of making sure your Mikrotik does only ...
by mkx
Sat Feb 25, 2023 11:49 pm
Forum: Beginner Basics
Topic: VLAN tutorial - Understanding menu "/interface bridge vlan"
Replies: 11
Views: 1002

Re: VLAN tutorial - Understanding menu "/interface bridge vlan"

1. You are right, probably the code snippet, when applied to default config, does nothing and thus result isn't as intended. On empty config, comnand "add" with similar properties has to be used. 2. Bridge in ROS has two (or more, depends how thoroughly one divides them) personalitues: the...
by mkx
Sat Feb 25, 2023 12:58 pm
Forum: Wireless Networking
Topic: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]
Replies: 25
Views: 1458

Re: hAP ax3 - 5GHz channel not discoverable from MacBook Pro and Pixel 4a [SOLVED]

Remember that there are two DFS ranges, 10 minute (for meteorological radars) and 1 minute (for ATC radars). The 1 minute applies to pretty wide frequency range, so it's almost impossible to avoid it.
by mkx
Sat Feb 25, 2023 12:52 pm
Forum: Wireless Networking
Topic: TX power limits for United States
Replies: 4
Views: 291

Re: TX power limits for United States

And the gain of the antenna where go??? You should only count number of Tx streams once ... and usually that's counted in total Tx power of device, which in my previous post is worded as "output by Tx power amplifier, is limited to 20dBm (or 17 dBm per chain)". So your equation should rea...
by mkx
Sat Feb 25, 2023 12:26 pm
Forum: General
Topic: L41G-2axD /hAP AX Lite/ USB support ?
Replies: 5
Views: 343

Re: L41G-2axD /hAP AX Lite/ USB support ?

I seem to remember @Normis saying that those lite devices feature USB ports only for powering and that they're pretty brain dead when it comes to support for anything but 5V (i.e. no PD support) ... in essence, use the supplied power brick with it. There was a family of such devices which supported ...
by mkx
Sat Feb 25, 2023 12:17 pm
Forum: General
Topic: Mikrotik CRS326-24S+2Q+RM
Replies: 11
Views: 1405

Re: Mikrotik CRS326-24S+2Q+RM

Ease of management, since only "one" switch needs to be configured/monitored/maintained? Is there any performance hit when NOT using MLAG? Nope, MLAG has nothing to do with switch management. Corporate type of switches use some sort of stacking to create a larger "virtual" switc...
by mkx
Sat Feb 25, 2023 12:10 pm
Forum: General
Topic: Help with "Detected conflict by ARP response for" error
Replies: 11
Views: 632

Re: Help with "Detected conflict by ARP response for" error

Another possibility: as MAC address spoofing us really easy to do, it's possible there's some malware around. It should be possible to locate the offending device by examining FDBs on switches to see which ether port is the last one to see it.
by mkx
Sat Feb 25, 2023 12:04 pm
Forum: General
Topic: Help with "Detected conflict by ARP response for" error
Replies: 11
Views: 632

Re: Help with "Detected conflict by ARP response for" error

It seems like device with offending MAC address is (mis)configured to perform proxy ARP (in a buggy way as well). I can't imagine another reason for sone device to systematically claim ownership of IP address which is occupied by another device in same L2 broadcast domain.
by mkx
Sat Feb 25, 2023 11:59 am
Forum: General
Topic: How to make static all leased ip at a time by command
Replies: 1
Views: 215

Re: How to make static all leased ip at a time by command

What about /ip/dhcp-server/lease make-static [ find ] I don't know if this has to be a two-liner or it can be done as one liner (with possible modification of the expression inside square blackets to also include path before find command). In general, whichever command takes index number as unnamed ...
by mkx
Fri Feb 24, 2023 10:13 pm
Forum: Wireless Networking
Topic: hAP ax² and hAP ax³ now support the entire 5 GHz range [SOLVED]
Replies: 28
Views: 1979

Re: hAP ax² and hAP ax³ now support the entire 5 GHz range [SOLVED]

I think an important factor in the ax3 case is the uselessness of the 2Ghz radio if you're not full-on Wifi6. It doesn't support ac.

This is not ax3 specific, it's standard. 802.11ac is only for 5GHz band, just like 802.11a was.
by mkx
Fri Feb 24, 2023 8:57 pm
Forum: Wireless Networking
Topic: TX power limits for United States
Replies: 4
Views: 291

Re: TX power limits for United States

I'm not sure if country limits, burned in ROS running on SXT 2 are special. However, on my RB951G running ROS 7.7, country limits for "united states" says that EIRP is limited to 30dBm on 2.4GHz band. SXT 2 antenna has 10dBi gain meaning that Tx power, output by Tx power amplifier, is limi...
by mkx
Fri Feb 24, 2023 8:46 pm
Forum: General
Topic: 3 subnet or just 2? Could you help me?
Replies: 5
Views: 350

Re: 3 subnet or just 2? Could you help me?

Do you think that changing subnet would not be useful? No. Subnet mask tells device which IP addresses are directly accessible (i.e. IP addresses which fall into same subnet) and for those it does not have to use gateway. If you physically separate devices into 3 networks (and put router in the cen...
by mkx
Fri Feb 24, 2023 3:41 pm
Forum: General
Topic: 3 subnet or just 2? Could you help me?
Replies: 5
Views: 350

Re: 3 subnet or just 2? Could you help me?

One of basic reasons to segment a LAN into multiple (smaller) LANs is to block broadcasts. The rest (control of unicast connectivity between different LANs) is add-on function. So if you really want to use different WAN links for different classes of devices, you can still have all devices in same s...
by mkx
Fri Feb 24, 2023 3:23 pm
Forum: General
Topic: PPPoE CLIENTS CANT ACCESS SITES AFTER ISP BRIDGE MODE
Replies: 1
Views: 202

Re: PPPoE CLIENTS CANT ACCESS SITES AFTER ISP BRIDGE MODE

If your firewall is still largely based on default, then you have to add pppoe-out1 interface (or whatever it's called in your particular setup) to WAN interface list. Hmmm ... the wording used in your post makes me wonder if I understand your use case correctly. So if in doubt, post configuration o...
by mkx
Thu Feb 23, 2023 5:58 pm
Forum: General
Topic: 2 CAPSMANS on the network [SOLVED]
Replies: 8
Views: 573

Re: 2 CAPSMANS on the network [SOLVED]

I just simply want to move all my cAPs from one CAPSMAN to a new one and then remove CAPSMAN on RB951G-2HnD and then replace with ax3. CAPsMAN has this redundancy built in: if there are multiple managers available on L2 network, any of thrm can provision CSPs ... prerequisite is that configuration ...
by mkx
Thu Feb 23, 2023 10:11 am
Forum: General
Topic: 2 CAPSMANS on the network [SOLVED]
Replies: 8
Views: 573

Re: 2 CAPSMANS on the network [SOLVED]

I'm not sure this order (first MAC, then IP) is about the order. I'd say it's by design, autoconfiguration only works via broadcast/MAC and that's the way vast majority of installations are supposed to work. And it's the only way possible when "configuring" AP into CAPsMAN mode by performi...
by mkx
Thu Feb 23, 2023 7:49 am
Forum: Wireless Networking
Topic: hAP ax² and hAP ax³ now support the entire 5 GHz range [SOLVED]
Replies: 28
Views: 1979

Re: hAP ax² and hAP ax³ now support the entire 5 GHz range [SOLVED]

I smell a user article if MKX doesnt make one LOL I'm affraid we'll see another article from @anav's "guides for ROS dummies" series. 1. I don't do articles, 2. I haven't got to the point of installing CAPsMANwave2 and 3. I only got up to ac with my wifiwave2 device (audience). I'll gladl...
by mkx
Thu Feb 23, 2023 7:40 am
Forum: General
Topic: Help with "Detected conflict by ARP response for" error
Replies: 11
Views: 632

Re: Help with "Detected conflict by ARP response for" error

Anything involving IP address is K3. So if switch has IP address associated to a particular port, it'll respond with associated MAC address. Same if switch is L3 switch (IE routing). It may even run something like proxy-arp. Remember that for switching only, swirch doesn't need to use own MAC addres...
by mkx
Thu Feb 23, 2023 7:15 am
Forum: Beginner Basics
Topic: VLAN on hex(RB750Gr3) [SOLVED]
Replies: 21
Views: 1727

Re: VLAN on hex(RB750Gr3) [SOLVED]

Special consideration of LAN interface list is only due to firewall settings (default) and tools mac-server . Otherwise LAN interface list is no magic. Well, perhaps the "detect internet" does something about it, this one is magic to everybody, it's just not clear if it's a good magic or b...
by mkx
Wed Feb 22, 2023 9:22 pm
Forum: Wireless Networking
Topic: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!
Replies: 53
Views: 6806

Re: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!

I was born as senior ... you grumpy old fart :-P
by mkx
Wed Feb 22, 2023 9:04 pm
Forum: General
Topic: VLAN MTU
Replies: 3
Views: 298

Re: VLAN MTU

QinQ is simply double VLAN encapsulation, which makes full ethernet frame size equal to 1526 (when using standard 1500 byte L3 MTU). Which means that switches, involved in such traffic, have to support L2MTU at least this large. However, MTU still remains 1500. The gist of it: router works with IP p...
by mkx
Wed Feb 22, 2023 4:40 pm
Forum: General
Topic: To understand a DHCP behavior in network [SOLVED]
Replies: 7
Views: 687

Re: To understand a DHCP behavior in network [SOLVED]

- a DHCP client stores old lease and lease server. The client will renew DHCP with the used DHCP server, before requesting via broadcast. According to wikipedia article (which includes quite some details), when acquiring DHCP lease DHCP client always sends packets to broadcast MAC address ... even ...
by mkx
Wed Feb 22, 2023 4:28 pm
Forum: Wireless Networking
Topic: RB4011iGS+5HacQ2HnD-IN Max rate & radar detect
Replies: 1
Views: 188

Re: RB4011iGS+5HacQ2HnD-IN Max rate & radar detect

Also AC should be able of something like 500Mbps or even more (833Mbps symbol rate is theoretical max, realistically possible is at least 20% less), but on Mikrotik with legacy wireless driver that's mission impossible, 350Mbps is a decent figure for RB4011. You could install wifiwave2 driver on RB4...
by mkx
Wed Feb 22, 2023 3:21 pm
Forum: Wireless Networking
Topic: hap AX3, WifiWave2 and Legacy clients.
Replies: 7
Views: 806

Re: hap AX3, WifiWave2 and Legacy clients.

In principle wifiwave2 setting of, say, band="2GHz-ax", will support older technology generations (b, g, n). In legacy driver it was possible to disable older technologies, but this doesn't seem to be possible (for now) in wifiwave2. It's best to leave "supported-rates" at defaul...
by mkx
Wed Feb 22, 2023 2:28 pm
Forum: Wireless Networking
Topic: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!
Replies: 53
Views: 6806

Re: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!

As I wrote, differences will be seen in mediocre conditions. Which start to happen when signal strength drops to slightly above receiver sensitivity (and one should take into account also receiver sensitivity of client), where device Tx power capabilities make difference. If signal strength of AP is...
by mkx
Wed Feb 22, 2023 12:00 pm
Forum: Wireless Networking
Topic: Channel frequency
Replies: 21
Views: 1333

Re: Channel frequency

Based on Wiki, channel 100 can be 80Mhz and starts at 5500 (center). No, based on Wiki, channel 100 is 20MHz wide and spans 5490-5510 MHz (with 5500MHz center frequency). Then there's a 40MHz wide channel 102 which happens to overlap 20MHz channels 100 and 104. Nominally channel 102 has center freq...
by mkx
Wed Feb 22, 2023 9:14 am
Forum: Wireless Networking
Topic: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!
Replies: 53
Views: 6806

Re: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!

Radio basics: signal strength budget is S = Tx power + Tx antenna gain - path loss + Rx antenna gain which then has to be greater than receiver sensitivity (for link to work at all). And SINR is ratio between signal (S) and noise (which includes thermal noise, receiver noise figure, unrelated noise ...
by mkx
Wed Feb 22, 2023 8:43 am
Forum: General
Topic: VLAN MTU
Replies: 3
Views: 298

Re: VLAN MTU

Nope. MTU (the layer 3, i.e. IP) for VLAN-driven IP subnet should be the same as if VLAN wasn't used. The universal number on ethernet networks (plain or with VLANs) is 1500. Longer explanation: when using IP over ethernet, as mentioned, standard max packet size (including IP headers) is 1500 bytes....
by mkx
Wed Feb 22, 2023 8:20 am
Forum: Beginner Basics
Topic: VLAN on hex(RB750Gr3) [SOLVED]
Replies: 21
Views: 1727

Re: VLAN on hex(RB750Gr3) [SOLVED]

What I want to achieve is each non-WAN port on hEX having seperate lan address space, and I have several of these 'dumb' switches that I could connect to each of the non-wan ports to get more ports for each of the new lan spaces. If this is so, then use router's ports as completely independent inte...
by mkx
Tue Feb 21, 2023 7:35 pm
Forum: Wireless Networking
Topic: Channel frequency
Replies: 21
Views: 1333

Re: Channel frequency

Wikipedia has a really nice article on WiFi channels ... with shown standard channels according to channel widths. When trying to implement them, keep in mind that on Mikrotik one always sets center frequency of 20MHz control channel and separately adds Channel layout. In particular: 5825MHz is cent...
by mkx
Tue Feb 21, 2023 7:04 pm
Forum: General
Topic: HEX S Issue
Replies: 13
Views: 685

Re: HEX S Issue

As mkx wrote: it might disable HW offloading for every port? I don´t think so, but I am not 100% sure. It's not what I wrote. I wasn't specific about why using SFP as switched/bridged port would be less than ideal, but this is what I had in my mind: SFP port, when in use, is wired directly to CPU. ...
by mkx
Tue Feb 21, 2023 6:49 pm
Forum: Beginner Basics
Topic: how to use EDIT command in terminal?
Replies: 17
Views: 783

Re: how to use EDIT command in terminal?

Well, I tried in /ip firewall filter ... one can not remove comment (i.e. field where empty value is as good as not set) with either of constructs, only setting with empty value does. But for optional property (I tried with in-interface) both ways (unset X in-interface ... and ... set X !in-interfac...
by mkx
Tue Feb 21, 2023 6:41 pm
Forum: Beginner Basics
Topic: how to use EDIT command in terminal?
Replies: 17
Views: 783

Re: how to use EDIT command in terminal?

It seems that unset is only available in menus where items have optional parameters. In IP address, only optional parameter is comment. Any other missing and configuration item doesn't make any sense. Other configuration items (like firewall filter) have many properties and not all have to be presen...
by mkx
Tue Feb 21, 2023 6:33 pm
Forum: Beginner Basics
Topic: how to use EDIT command in terminal?
Replies: 17
Views: 783

Re: how to use EDIT command in terminal?

Well, the example above is one of those where setting to empty value does the trick, hence no unset command. And setting !comment doesn't do the trick either. I'd really like to see the example where setting property to empty value isn't the same as unsetting it ... and that it is not possible to un...
by mkx
Tue Feb 21, 2023 6:26 pm
Forum: Beginner Basics
Topic: Extending WiFi network with additional AP
Replies: 2
Views: 230

Re: Extending WiFi network with additional AP

  • hAP ax3 has 5dB higher Tx power than ax2 ... in mediocre radio conditions (i.e. everywhere but in direct vicinity of AP) this means higher speeds in direction from AP towards clients.
by mkx
Tue Feb 21, 2023 6:16 pm
Forum: Beginner Basics
Topic: how to use EDIT command in terminal?
Replies: 17
Views: 783

Re: how to use EDIT command in terminal?

Unset? from 2007 i never used that command or remember that exist... Well, I've never thought of using set !<property> . It seems non-intuitive to me, to me "set not something" is different than "unset something". The same way as "set something to empty" is different t...
by mkx
Tue Feb 21, 2023 12:07 pm
Forum: Beginner Basics
Topic: how to use EDIT command in terminal?
Replies: 17
Views: 783

Re: how to use EDIT command in terminal?

Could be that edit is supposed to work like set, but without first (manually) checking old contents ... and interactively so. I most likely won't even try to find out about it :wink: Don't forget about "unset" command ... sometimes setting of certain property is undone by setting it to emp...
by mkx
Tue Feb 21, 2023 9:25 am
Forum: SwOS
Topic: Multicast problem on RB260GSP
Replies: 6
Views: 992

Re: Multicast problem on RB260GSP

My ISP provides IPTV over separate VLAN as well. I tried with IGMP snooping and, as noted by @rime, IGMP snooping on Mikrotik is broken in different ways. So I reverted to simply switch that VLAN and I live with "multicast flooding" ... I don't bother much, most IPTV streams are at around ...
by mkx
Tue Feb 21, 2023 9:19 am
Forum: General
Topic: HEX S Issue
Replies: 13
Views: 685

Re: HEX S Issue

hEXes (most of them) also make pretty decent 1Gbps switches, even VLAN-enabled if one uses ROS v7.x on them. hEX S not so much though, if one wants to use SFP it hampers switch-CPU interconnect and SFP is not switched with other ports.
by mkx
Tue Feb 21, 2023 9:12 am
Forum: General
Topic: 5009 high CPU vs. CCR1009
Replies: 5
Views: 488

Re: 5009 high CPU vs. CCR1009

Hadn't thought about the route cache, however it has less than 400 routes total. Route cache is not about routing protocols, it's about deciding next hop for every individual packet passing router. The same problem happens even if router only has one single static route set (0.0.0.0/0 gw <ISP route...
by mkx
Tue Feb 21, 2023 9:03 am
Forum: Beginner Basics
Topic: how to add services / services ports
Replies: 11
Views: 530

Re: how to add services / services ports

Also, cannot find the printer in the network to install it although it gets an IP - I see it connected to the new WiFi. Autodiscovery works using broadcast traffic. And that doesn't work accross IP subnet boundaries. So having printers contained in separate (wireless) LAN segment you broke autodisc...
by mkx
Tue Feb 21, 2023 8:57 am
Forum: Beginner Basics
Topic: CAT5E wire only clocking 100Mbs
Replies: 13
Views: 914

Re: CAT5E wire only clocking 100Mbs

100Mbps is actually magic number for 2-pair ethernet runs (up to 100Base-TX only pairs 1-2 and 3-6 were used, 1000Base-T requires also pairs 4-5 and 7-8). cat3, if all 4 pairs are wired correctly, can sustain Gbps on short runs (likely possibly with errors in frames which makes switches drop frames)...
by mkx
Tue Feb 21, 2023 8:50 am
Forum: Beginner Basics
Topic: how to use EDIT command in terminal?
Replies: 17
Views: 783

Re: how to use EDIT command in terminal?

I'm not really sure what "edit" command does, I never used it. In ROS 6.49.7 (and ROS 7.7) it doesn't even have short description shown: [user@mikrotik] /ip pool> edit .. -- go up to ip add -- Create a new item comment -- Set comment for items edit -- export -- Print or save an export scri...
by mkx
Mon Feb 20, 2023 7:01 pm
Forum: General
Topic: Is fast track-connection working? Doubts about rules' matching
Replies: 7
Views: 468

Re: Is fast track-connection working? Doubts about rules' matching

L3HW offloading is not supported by any of "small" routers, only by CRS3xx, CRS5xx and some CCR2xxx. Configuration does indicate the presence of L3HW, but even if you set it to enabled in config, it just won't be enabled in reality.
by mkx
Sun Feb 19, 2023 11:09 pm
Forum: General
Topic: 5009 high CPU vs. CCR1009
Replies: 5
Views: 488

Re: 5009 high CPU vs. CCR1009

ROS v7 comes with newer linux kernel which doesn't support route cache any more. So it is expected to see slightly higher CPU load for same amount of routing in most cases. It might not explain larger difference (e.g. 30% vs. 10% CPU load) in same traffic conditions though.
by mkx
Sun Feb 19, 2023 11:03 pm
Forum: General
Topic: Back to front or Front to back air flow
Replies: 3
Views: 271

Re: Back to front or Front to back air flow

At the same time it's pretty hard to get any cool air to the back of the rack, specially to top back. And for this reason server racks most often feature patch pannels at back (either top or bottom, depending on installation layout of server room; either RJ45 or optical or both), while network gear ...
by mkx
Sun Feb 19, 2023 10:45 pm
Forum: General
Topic: RB5009UPr - PoE management
Replies: 2
Views: 252

Re: RB5009UPr - PoE management

I think product page has all the answers: input voltage range for RB5009UPr is 24V-57V. So yes, you can use 24V power supply. It's on the lower edge of allowed range so device might get unstable if voltage drops below 24V (if power brick won't be able to sustain the load ... my advice is to get a pr...
by mkx
Sun Feb 19, 2023 10:14 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 125
Views: 21099

Re: how does L3HW actually works?

If you want to HW offload routing between LANs and WAN, then indeed all relevant interfaces have to be members of same bridge. Having two SFP28 connections between switch and CCR has potential for loops if both links are members of same bridge on both sides. And any xSTP except MSTP will detect it a...
by mkx
Sun Feb 19, 2023 9:30 pm
Forum: General
Topic: Is fast track-connection working? Doubts about rules' matching
Replies: 7
Views: 468

Re: Is fast track-connection working? Doubts about rules' matching

True forum guru @sindy mentioned in another topic that filter rule with action=fasttrack doesn't accept the packet (same as action=accept which terminates rule evaluation), it rather marks connection for fasttracking. This affects subsequent packets of same connection (allowing them to skip firewall...
by mkx
Sun Feb 19, 2023 9:15 pm
Forum: Beginner Basics
Topic: WiFi - When to use "main interface", when to use "virtual interfaces"
Replies: 4
Views: 345

Re: WiFi - When to use "main interface", when to use "virtual interfaces"

It doesn't matter which SSID is on master and which on slave. The important things are the following: All properties of "physical" radio (frequency, channel width, AFAIK wifi generation (i.e. A, B, G, N, AC, ...) as well, etc.) are set only on master interface, slaves inherit them every sl...
by mkx
Sat Feb 18, 2023 10:11 pm
Forum: Wireless Networking
Topic: Could not configure xap ax^3 as a access repeater
Replies: 4
Views: 277

Re: Could not configure xap ax^3 as a access repeater

No, old driver doesn't work with ax hardware. Wifiwave2 is only optional on ac hardware.
by mkx
Sat Feb 18, 2023 10:04 pm
Forum: Wireless Networking
Topic: Could not configure xap ax^3 as a access repeater
Replies: 4
Views: 277

Re: Could not configure xap ax^3 as a access repeater

Newest Mikrotik wireless devices (i.e. any model with "ax" in name) use new wireless driver (wifiwave2). This dtiver lacks a few functionalities, one is mode support limited to ap and station. So it do4sn't support any of *bridge modes, needed for repeater mode. So in short: ax devices can...
by mkx
Sat Feb 18, 2023 11:34 am
Forum: Beginner Basics
Topic: Question about Masqurade Rule
Replies: 9
Views: 588

Re: Question about Masqurade Rule

The most important feature of masquerade (as compared to "normal" SRC NAT) is "WAN link state awareness". Meaning that if WAN link goes down, masquerade prepares for WAN IP address change (which is what often happens). And preparation for IP address change includes tearing down a...
by mkx
Fri Feb 17, 2023 9:25 pm
Forum: General
Topic: To understand a DHCP behavior in network [SOLVED]
Replies: 7
Views: 687

Re: To understand a DHCP behavior in network [SOLVED]

But I still don't understand how it was possible, mainly when I was connected in wifi. If someone could have a clarification ? I didn't actually test my hypothesis below so take it with a grain of doubt.... So when DHCP client requests a lease (it's a 4-way handshake) and it previously had interfac...
by mkx
Wed Feb 15, 2023 3:20 pm
Forum: General
Topic: DHCP Server in Container Disables Bridge Fast Path/L3 HW Offload
Replies: 3
Views: 294

Re: DHCP Server in Container Disables Bridge Fast Path/L3 HW Offload

In this specific case, the only offloading I use is for fasttrack connections, so L3 shouldn't be interfering.
Doesn't matter which kind of offloading, L2 offloading, fasttrack, L3 offloading, anything ... for this particular case those packets should be passed from hardware to CPU.
by mkx
Wed Feb 15, 2023 3:14 pm
Forum: Beginner Basics
Topic: ROS versions - i'm confused [SOLVED]
Replies: 9
Views: 700

Re: ROS versions - i'm confused [SOLVED]

My question is why did you purchase a cap XL???
Is there a problem with it?
Not really. It's just that it's a generation old ... the newest MT wireless devices are <anything> ax, e.g. cAP ax.
by mkx
Wed Feb 15, 2023 3:09 pm
Forum: Beginner Basics
Topic: DHCP Offer takes time to be sent to the client
Replies: 3
Views: 259

Re: DHCP Offer takes time to be sent to the client

By doing steps #1 and #5 you are not benchmarking performance of mikrotik DHCP server but rather boot time of ROS. And yes, it does take some time for ROS device to boot (length depends on particular MT device type). Even if ROS kernel enables switch chip (and ports can get "link up"), oth...
by mkx
Tue Feb 14, 2023 9:46 pm
Forum: General
Topic: DHCP Server in Container Disables Bridge Fast Path/L3 HW Offload
Replies: 3
Views: 294

Re: DHCP Server in Container Disables Bridge Fast Path/L3 HW Offload

DHCP server listens to broadcasts and hooks pretty low in network stack (in principle it's a normal layer 7 service but for technical reasons DHCP server hooks between L2 and L3 in order to process ingress packets as those might be mistreated by normal IP stack, return packets are special as well). ...
by mkx
Tue Feb 14, 2023 12:27 am
Forum: Beginner Basics
Topic: CAT5E wire only clocking 100Mbs
Replies: 13
Views: 914

Re: CAT5E wire only clocking 100Mbs

If you use different gear on the same cable, do those negotiate 1Gbps? If they do, it means that all wires are continous. If they don't, then check wire continuity first. Next thing is to verify proper twisting of all pairs right to last milimetre of cable. Even a few centimetres of untwisted wires ...
by mkx
Mon Feb 13, 2023 2:14 pm
Forum: Announcements
Topic: v7.8rc is released!
Replies: 125
Views: 35796

Re: v7.8rc is released!

Why is that so important for you? This is all static info that you can get from the relevant authorities... Info from authorities sometimes doesn't exactly match limitation built in ROS. Sometimes is thus very useful to get this info to verify what are actual limits imposed by ROS in actual device.
by mkx
Mon Feb 13, 2023 9:12 am
Forum: Beginner Basics
Topic: VLAN on hex(RB750Gr3) [SOLVED]
Replies: 21
Views: 1727

Re: VLAN on hex(RB750Gr3) [SOLVED]

If the rest of LAN gear doesn't support VLANs, then quite probably introducing VLANs on hEX won't do any good. If you want to separate devices into several LAN subnets, you can't have different subnets behind same unmanaged switch because that device alone will allow end devices to communicate direc...
by mkx
Sun Feb 12, 2023 11:42 pm
Forum: Wireless Networking
Topic: Please help me choose between hap ax2 and ax3 as access points [SOLVED]
Replies: 42
Views: 2867

Re: Please help me choose between hap ax2 and ax3 as access points [SOLVED]

The difference in specced antenna gains between ax2 and ax3 is not really significant (around 1dB; ax2 is better on 2.4GHz, ax3 is better on 5GHz). What is significant is 5dB lower Tx power available on ax2 (17dBm-24dBm on 2.4GHz, 15dBm-23dBm on 5GHz) compared to ax3 (22dBm-29dBm on 2.4GHz, 20dBm-28...
by mkx
Sun Feb 12, 2023 10:57 pm
Forum: Beginner Basics
Topic: DHCP and ICMP in RAW table instead of standard Firewall
Replies: 7
Views: 383

Re: DHCP and ICMP in RAW table instead of standard Firewall

As already noted, that page describing firewall raw rules is a pretry bad substitute fir something to be done. But if you want to study ROS routing and firewalling in detail, you can start at packet flow . And other help pages. As I already mentioned: it0s much easier to create safe firewall by usin...
by mkx
Sun Feb 12, 2023 5:15 pm
Forum: Beginner Basics
Topic: DHCP and ICMP in RAW table instead of standard Firewall
Replies: 7
Views: 383

Re: DHCP and ICMP in RAW table instead of standard Firewall

Basic difference between raw rules and filter rules is that the former are stateless while the later are stateful. Very simple firewalls can be done effectively using stateless firewall, but more complex (and safer) firewall setups can be done much easier using stateful firewall - some things can't ...
by mkx
Fri Feb 10, 2023 7:45 pm
Forum: General
Topic: ROS switch-mode CLI commands?
Replies: 4
Views: 316

Re: ROS switch-mode CLI commands?

Currently exists a way of doing steps 2-5 in single command without down time. Step #1 still needs to be done to make sure the following command does not break existing config: /interface bridge vlan set [ find bridge=bridge vlan-ids=10 ] tagged=ether1,ether8,ether24 With set command one sets indivi...
by mkx
Thu Feb 09, 2023 4:21 pm
Forum: Beginner Basics
Topic: hap ax3 wifi interfaces
Replies: 2
Views: 253

Re: hap ax3 wifi interfaces

Wireless driver for ax devices is wifiwave2 which is generally optional package in additional packages archive, available from download.mikrotik.com ... once optional package is installed, upgrade (from within ROS) does it for those packages as well.
by mkx
Wed Feb 08, 2023 5:11 pm
Forum: RouterBOARD hardware
Topic: heX-S High CPU usage with Bridge VLAN switching.
Replies: 10
Views: 828

Re: heX-S High CPU usage with Bridge VLAN switching.

Each product has page with official test results, so does hEX S . The rule of thumb is that number under "routing, 25 filter rules, 512 byte packet size" best represents average real life performance. Numbers for older devices were obtained with ROS v6 runnung, and that one was a bit bette...
by mkx
Wed Feb 08, 2023 4:25 pm
Forum: RouterBOARD hardware
Topic: heX-S High CPU usage with Bridge VLAN switching.
Replies: 10
Views: 828

Re: heX-S High CPU usage with Bridge VLAN switching.

If hEX S is used as router, then seeing traffic travelling between different VLANs hitting CPU is normal. Routing is not HW offloaded on hEX S, only switching within same VLAN is.
by mkx
Tue Feb 07, 2023 8:44 pm
Forum: General
Topic: Wrong log message order for DHCP messages.
Replies: 7
Views: 394

Re: Wrong log message order for DHCP messages.

The log entries probably followed each other with short time difference, small enough to have timestamp (stored with a second resolution) the same. If you'd let winbox show logs without sorting, you'd get them in order as they were recorded. Since you enabled sorting, you get it ... but entries with...
by mkx
Sun Feb 05, 2023 7:22 pm
Forum: Beginner Basics
Topic: fiber cable to connect 2 routers
Replies: 6
Views: 455

Re: fiber cable to connect 2 routers

Fiber is bidirectional in principle. If one wants to use single strand for both directions, then Tx and Rx have to use different wavelengths. In multimode using different wavelengths is not common while in single mode many wavelength tricks are played. BiDi is one of them, CWDM and DWDM are another....
by mkx
Sat Feb 04, 2023 8:12 pm
Forum: General
Topic: Feature request: Moving operations to RAM memory
Replies: 2
Views: 284

Re: Feature request: Moving operations to RAM memory

Since ages ROS can use RAM as disk. But only on devices with less than 32MB flash and more than 64MB RAM. For example haP ac2 uses RAM disk as root of storage and mounts flash under /flash. In such cases ROS stores exported files in RAM disk by default, upload goes to RAM disk by default as well. Wh...
by mkx
Sat Feb 04, 2023 12:24 pm
Forum: SwOS
Topic: Mounting two CSS610 units in a single U?
Replies: 6
Views: 935

Re: Mounting two CSS610 units in a single U?

You're right, the non-PoE version is smaller. Height of 46mm still exceeds 1U height (44.45mm max) so it would really be "violence against other rack gear" if one wanted to mount those in 1U space between other rack gear. Let alone if one wanted to mount several of these units in adjacent ...
by mkx
Sat Feb 04, 2023 12:11 am
Forum: SwOS
Topic: Mounting two CSS610 units in a single U?
Replies: 6
Views: 935

Re: Mounting two CSS610 units in a single U?

CSS610 seems to be a tad too high to fit 1U. Brochure says height is 50mm while 1U net height is 44.45 (minus fraction of a mm for inter-device gap). Yes, it does come with rack mount ears, but will obviously eat into space below and above. It also seems too wide to fit two horizontally in parallel ...
by mkx
Fri Feb 03, 2023 7:36 pm
Forum: Beginner Basics
Topic: fiber cable to connect 2 routers
Replies: 6
Views: 455

Re: fiber cable to connect 2 routers

SFPs S-3553LC20D LC come as complementary pair of modules which then communicate via single fibre strand (so called BiDi modules). This is achieved so that one transmits with wavelength of 1310nm and the other transmits with wavelength of 1550nm ... receiving wavelengths are reversed. So the cable y...
by mkx
Thu Feb 02, 2023 8:19 pm
Forum: Beginner Basics
Topic: hAP ax2 link speed problem [SOLVED]
Replies: 14
Views: 1011

Re: hAP ax2 link speed problem [SOLVED]

If it was only one port doing it, I'd bet on cable/connector issues. Having two ports behave the same way at the same time I'd say switch chip had a hiccup. I'd first have a look at logs ( /log print to verify time sequence ... also look at events a few minutes prior to link speed renegotiations), t...
by mkx
Thu Feb 02, 2023 2:34 pm
Forum: RouterBOARD hardware
Topic: RBM33G antena amplifying
Replies: 3
Views: 266

Re: RBM33G antena amplifying

The nice thing about directional antennae, used in mobile networks, is that using it doesn't limit Tx power from transmitter.[*] So unlike in WiFi (where EIRP is limited pretty low and using high-gain antenna doesn't end up with stronger signal, but rather greater sensitivity of receiver) using dire...
by mkx
Thu Feb 02, 2023 12:44 pm
Forum: General
Topic: CAPsMan Configuration
Replies: 4
Views: 441

Re: CAPsMan Configuration

I am seeing my AP's showing the same IP address as my gateway router. If APs actually use same address as router, then this is clearly the major problem in your network. And this part is not handled by CAPsMAN, so you'll have to change IP addresses of all APs to unique values. And this is the part ...
by mkx
Thu Feb 02, 2023 8:45 am
Forum: Beginner Basics
Topic: Help me visually understand routing
Replies: 43
Views: 2956

Re: Help me visually understand routing

But the docs do say which implies a "hidden untag" within the packet flow diagram: Tagged packets might get decapsulated on the "BRIDGING DECISION" block, which means these packets will no longer match the mac-protocol=vlan and vlan-encap settings. Decapsulation can happen if th...
by mkx
Wed Feb 01, 2023 11:59 pm
Forum: Beginner Basics
Topic: Help me visually understand routing
Replies: 43
Views: 2956

Re: Help me visually understand routing

Packets passing through device in DIFFERENT VLAN are bridged according to VLAN Table by switch and bypass CPU (firewall) when "use-ip-firewall=no". Conceptually this is not true. Packets passing through device in different VLAN are routed and thus have to pass all the routing machinery. U...
by mkx
Wed Feb 01, 2023 11:52 pm
Forum: Beginner Basics
Topic: Help me visually understand routing
Replies: 43
Views: 2956

Re: Help me visually understand routing

Looking at overall packet flow diagram most of time: When physical in-interface receives VLAN-tagged frame, it passes the bridging magic (which determines it's destined to router itself ... so passing points A and B), then passes all those diamonds via "NO" branch until reaching diamond &q...
by mkx
Wed Feb 01, 2023 7:49 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 39
Views: 3595

Re: hAP ax lite

Already 802.11 N specified MIMO up to 4x4, in reality many N devices implement 2x2 MIMO. With 2x2 MIMO it's very hard (next to impossible) to implement MU-MIMO (which, BTW, doesn't increase speed for individual stations, it may increase speed of whole AP and can improve latency as noted by @psannz)....
by mkx
Wed Feb 01, 2023 7:31 pm
Forum: RouterBOARD hardware
Topic: RBM33G antena amplifying
Replies: 3
Views: 266

Re: RBM33G antena amplifying

Per standard, LTE mobile devices are expected to transmit at around 23dBm. Which is 200mW. Even if we assume 50% efficiency of Tx power amplifier, that's around 0.5W when transmitting at its fullest. Add a Watt or so for DSP consumption (both Tx and Rx) and it's still less than 2 Watts. Ancient devi...
by mkx
Wed Feb 01, 2023 2:26 pm
Forum: Beginner Basics
Topic: Unable to stop Inter-VLAN traffic
Replies: 6
Views: 461

Re: Unable to stop Inter-VLAN traffic

A few things: are you sure that the passing connection is over IPv4? You don't have a matching drop rule for IPv6 try to disable l3-hw-offloading under /interface ethernet switch while debugging things. L3HW offloading is a fairly new functionality and it might still contain some minor bugs make sur...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 32