Community discussions

MikroTik App

Search found 47 matches

by jamesw
Fri Mar 31, 2023 8:53 pm
Forum: Virtualization
Topic: CHR License error: General failure #163
Replies: 1
Views: 2665

CHR License error: General failure #163

We’re getting the following error on some (not all) of our Mikrotik CHR systems which is causing the system to be capped at 1Mbps throughput. These systems have a P1 perpetual licence. What does this error mean please? An example is below and its affecting over 25 (out of 140 which are all fine): “E...
by jamesw
Fri Mar 24, 2023 4:19 pm
Forum: Wireless Networking
Topic: Hotspot 2.0 ANQP/OI's missing for Wave2 hap ax3
Replies: 2
Views: 1151

Re: Hotspot 2.0 ANQP/OI's missing for Wave2 hap ax3

Thanks. I can confirm setting via terminal works just fine so it's purely a UI thing.
by jamesw
Fri Mar 24, 2023 11:07 am
Forum: Wireless Networking
Topic: Hotspot 2.0 ANQP/OI's missing for Wave2 hap ax3
Replies: 2
Views: 1151

Hotspot 2.0 ANQP/OI's missing for Wave2 hap ax3

I'm trying to configure my hap ax3 with wave2 support, but on the "Interworking" tab, there is no option for the ANQP to set the Roaming OI's or domains that are used for Hotspot 2.0/Openroaming to function. In non-wave2 radios this configuration is present and can be set. Here is the Mikr...
by jamesw
Wed Mar 01, 2023 10:50 am
Forum: Virtualization
Topic: CHR license - system-id, UUID/MBR questions
Replies: 8
Views: 4071

Re: CHR license - system-id, UUID/MBR questions

When you have to upgrade 300 CHR's and have to manually re-license each one, it's a problem :)

Also, the system-id is staying the same (because we are hardcoding the UUID in the virtual machine XML config before it boots) , it's just saying that the system id can't be licensed.
by jamesw
Mon Feb 27, 2023 11:10 am
Forum: Virtualization
Topic: CHR license - system-id, UUID/MBR questions
Replies: 8
Views: 4071

Re: CHR license - system-id, UUID/MBR questions

I this because the MBR will have changed, or that it somehow thinks its a new system/hardware ID? Both. How can resizing a disk create a new system ID? The UUID of the system/hardware and the UUID of the virtual disk does not change with a resize, so how does the Mikrotik know any different? Perpet...
by jamesw
Mon Feb 27, 2023 10:45 am
Forum: Virtualization
Topic: CHR license - system-id, UUID/MBR questions
Replies: 8
Views: 4071

Re: CHR license - system-id, UUID/MBR questions

Would resizing the disk image of an existing machine generate a new system ID? Exactly. But adding another disk, keeping the original untouched in place, do not change system ID. I this because the MBR will have changed, or that it somehow thinks its a new system/hardware ID? Why should resizing a ...
by jamesw
Sun Feb 26, 2023 10:29 pm
Forum: Virtualization
Topic: CHR license - system-id, UUID/MBR questions
Replies: 8
Views: 4071

CHR license - system-id, UUID/MBR questions

I have a question about how the CHR system id (for licensing purposes) is *really* generated/checked. We purchased over 400 CHR P1 perpetual licenses a few years ago that are used on either VirtualBox/Linux KVM hosts. They have been working fine until it comes to upgrade time... i.e. each reboot the...
by jamesw
Sun Feb 26, 2023 10:18 pm
Forum: General
Topic: Hotspot Rate Limit without dynamic queue?
Replies: 2
Views: 588

Re: Hotspot Rate Limit without dynamic queue?

Anyone have any thoughts on this? Thanks
by jamesw
Wed Feb 22, 2023 2:36 pm
Forum: General
Topic: Hotspot Rate Limit without dynamic queue?
Replies: 2
Views: 588

Hotspot Rate Limit without dynamic queue?

We're currently using Hotspot with RADIUS authentication and returning a bandwidth limit via the Access-Accept reply which in turns creates a dynamic queue (per active user) set at the bandwidth specified. All good so far. We now have a requirement were we need to dynamically modify the bandwidth fo...
by jamesw
Tue Feb 14, 2023 9:59 pm
Forum: Virtualization
Topic: CHR RouterOS v7.6 - showing P1 not trial?
Replies: 1
Views: 2815

CHR RouterOS v7.6 - showing P1 not trial?

What's going on here then? v7.6 on a CHR is showing a P1 licence on both Winbox and Terminal, but it's really on a P1 (Trial): I am sure that it used to say P1 (Trial) in Winbox so you could tell the difference? Tried this on 3 different CHR's and they all show the same P1 when its actually P1 (Tria...
by jamesw
Fri Mar 18, 2022 1:00 pm
Forum: General
Topic: Strange MNDP (Discovery) issue with router+switch+winbox
Replies: 10
Views: 895

Re: Strange MNDP (Discovery) issue with router+switch+winbox

Thanks to both of you. I will indeed not worry bout the switches being "visible" on the network and just allow management via their static IP's from an allowed host.

Cheers
by jamesw
Fri Mar 18, 2022 12:59 am
Forum: General
Topic: Strange MNDP (Discovery) issue with router+switch+winbox
Replies: 10
Views: 895

Re: Strange MNDP (Discovery) issue with router+switch+winbox

Indeed, but this PC is not a dedicated PC just for accessing the management interface, and is gnerally on VLAN100 as the other devices are. I just want to be able to see the switches via Winbox, even though the PC is on VLAN100. I understand your point now about the broadcast only searching the VLAN...
by jamesw
Fri Mar 18, 2022 12:40 am
Forum: General
Topic: Strange MNDP (Discovery) issue with router+switch+winbox
Replies: 10
Views: 895

Re: Strange MNDP (Discovery) issue with router+switch+winbox

So add a VLAN100 interface to all the switches too, and also give them all an IP in the VLAN 100 range? But then what is the point of the VLAN99 management interface to keep things separate? :)
by jamesw
Fri Mar 18, 2022 12:30 am
Forum: General
Topic: Strange MNDP (Discovery) issue with router+switch+winbox
Replies: 10
Views: 895

Re: Strange MNDP (Discovery) issue with router+switch+winbox

So on all switches I have a VLAN 99 interface which is attached to the bridge. the VLAN99 interface is then given an IP address on the switch, like 172.16.99.x I do not have any firewall rules blocking inter-VLAN, so I would have though a broadcast from the PC running Winbox will be able to see all ...
by jamesw
Fri Mar 18, 2022 12:02 am
Forum: General
Topic: Strange MNDP (Discovery) issue with router+switch+winbox
Replies: 10
Views: 895

Strange MNDP (Discovery) issue with router+switch+winbox

I currently have the following 1 x RB2011AHx2 3 x CRS125 1 x CSR326 Screenshot 2022-03-17 215750.png I'm currently using Winbox on the PC (VLAN 100) and the nework is working as expected, I receive an IP from the DHCP on the router from the VLAN 100 interface. All is good. But on Winbox I can only s...
by jamesw
Mon Nov 08, 2021 2:04 pm
Forum: General
Topic: Hotspot reporting incorrect usage on interface, but parent interface correct
Replies: 2
Views: 722

Re: Hotspot reporting incorrect usage on interface, but parent interface correct

Just wondering if anyone is able to assist? Happy to provide any further config as required.

Thanks!
by jamesw
Thu Nov 04, 2021 10:38 am
Forum: General
Topic: Hotspot reporting incorrect usage on interface, but parent interface correct
Replies: 2
Views: 722

Re: Hotspot reporting incorrect usage on interface, but parent interface correct

Some more info, I've realised in the "Queues" the traffic for the client traffic is showing correct, is the queue causing the problem? We're limiting the user/s bandwidth to 2Mbps down/up hence the queue... Comparison of what the queue shows as opposed to the hotspot user: mt_test_3.png Th...
by jamesw
Wed Nov 03, 2021 1:11 pm
Forum: General
Topic: Hotspot reporting incorrect usage on interface, but parent interface correct
Replies: 2
Views: 722

Hotspot reporting incorrect usage on interface, but parent interface correct

Bit of an odd one but hoping someone can help... We have a hotspot set up on a VRRP interface, and everything works great, apart from the traffic that is showing for hotspot clients and on the hotspot interface itself is wrong. It's showing clients using a very small amount of download/upload bytes ...
by jamesw
Tue Jan 19, 2021 11:30 am
Forum: General
Topic: Simple Hotspot with VRRP setup - help!
Replies: 2
Views: 1446

Re: Simple Hotspot with VRRP setup - help!

Further to this, it appears when the VRRP and the hotspot are on the same interface (ether3) the VRRP doesn't work or auto-switch master/backup, probably because the hotspot is running or blocking the traffic. As soon as the hotspot server is disabled, VRRP immediately works again. Any thoughts? Tha...
by jamesw
Mon Jan 18, 2021 11:36 pm
Forum: General
Topic: Simple Hotspot with VRRP setup - help!
Replies: 2
Views: 1446

Simple Hotspot with VRRP setup - help!

I am trying to get a simple hotspot with VRRP with two CHR Virtualbox VM's The plan is to run a two routers as master/slave, both with hotspot running for guest users. I've configured it as I thought it should be, however when I create a hotspot and set it to run on the vrrp interface, although the ...
by jamesw
Wed Oct 23, 2019 1:40 am
Forum: General
Topic: Cisco NAT outside to Mikrotik NAT rule
Replies: 3
Views: 1350

Re: Cisco NAT outside to Mikrotik NAT rule

The ISP's controller is a slightly odd set up, in that it's sitting behind IP 203.203.203.60 but configured to identify itself as 103.103.103.60. So, I tell my AP to join a controller at 203.203.203.60. It talks to the controller fine, but because the controller identifies itself as 103.103.103.60, ...
by jamesw
Wed Oct 23, 2019 1:08 am
Forum: General
Topic: Cisco NAT outside to Mikrotik NAT rule
Replies: 3
Views: 1350

Cisco NAT outside to Mikrotik NAT rule

I'm trying to have a Cisco AP in my lab connect to a remote controller hosted by our ISP for testing. I've been advised by my ISP that I need to use the following rule in order for it to work correctly, but this is intended for a Cisco IOS device: ip nat outside source static 103.103.103.60 203.203....
by jamesw
Sun Jul 28, 2019 3:42 pm
Forum: General
Topic: IPSEC / Xauth on Mikrotik problem
Replies: 5
Views: 1821

Re: IPSEC / Xauth on Mikrotik problem

Actually, turns out I was using the wrong PSK! Doh!
by jamesw
Wed Jul 24, 2019 11:12 am
Forum: General
Topic: IPSEC / Xauth on Mikrotik problem
Replies: 5
Views: 1821

Re: IPSEC / Xauth on Mikrotik problem

Anyone able to help or give me a steer?

Thanks!
by jamesw
Tue Jul 23, 2019 1:47 pm
Forum: General
Topic: IPSEC / Xauth on Mikrotik problem
Replies: 5
Views: 1821

Re: IPSEC / Xauth on Mikrotik problem

Would any additional logs help? Just tying to make some progress on this :)

Thanks in advance

J
by jamesw
Mon Jul 22, 2019 2:32 pm
Forum: General
Topic: IPSEC / Xauth on Mikrotik problem
Replies: 5
Views: 1821

IPSEC / Xauth on Mikrotik problem

RouterOS 6.45.2 I'm having trouble getting macOS and Android devices to connect to our VPN server hosted by the Mikrotik 110AHx2 in our office. It works fine for Windows and Ubuntu using the Shrew VPN software. The same appears in te logs for both Android and macOS clients (using their built-in VPN ...
by jamesw
Wed Jul 03, 2019 2:23 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 415
Views: 205056

Re: v6.45.1 [stable] is released!

We are also facing the same issue with Hotspot / RADIUS authentication broken because the Password that is send to RADIUS is garbage/corrupt.

This is affecting 1000+ customers to a big issue.

Case raised; ticket #2019070322005393

Thanks for any help.

James
by jamesw
Wed Mar 20, 2019 10:40 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Great explanations guys. Really appreciate the informative replies.

James
by jamesw
Wed Mar 20, 2019 2:55 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Yep, I added a drop rule and then some specific forward rules for what I want open externally. Thanks!
by jamesw
Wed Mar 20, 2019 1:32 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Strangely, in my testing, I removed those rules completely and the server still have access behind the assigned public IP, so seems it lets everything through. Guess I need to drop all and then allow just what I need through... Weird as I thought it wouldn't work at all without the following: add ac...
by jamesw
Wed Mar 20, 2019 12:34 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Its working now - not sure why but ARP is just set to the default "enabled" instead of proxy-arp. Sob and co, thanks for the help. Last question - can I still limit the inbound traffic to the public IP using the MT firewall or is everything just "passed through" to the server now...
by jamesw
Wed Mar 20, 2019 9:53 am
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Indeed. With proxy-arp on its working, but without it's not. I'd like to avoid having to use proxy-arp if I can as it shouldn't be required I think?

Thanks
by jamesw
Wed Mar 20, 2019 1:01 am
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Thanks So without adding some dummy ip to the ether9 interface and then using this ip as the gateway on the server nothing would be routed, correct? I tried what you said but it still doesnt work without enabling proxy arp on ether9. Once I get this working, can I still use input firewall rules to b...
by jamesw
Tue Mar 19, 2019 10:18 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

I enabled proxy-arp on ether9 and it now works. But should I need to do this? Is this strictly required? Does it introduce any issues?

Thanks
by jamesw
Tue Mar 19, 2019 9:52 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

The torch tool shows a ping i am running to 2.1.1.1 (real ip 62.252.x.x in screenshot) from outside is being sent to ether9 and it appears it is responding but the ping fails, so, is it a firewall issue where traffic from ether9 cant go back out, like some nat or forward rule?
by jamesw
Tue Mar 19, 2019 9:31 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Heh.

Managed to add it by removing the /32 from the network, so its just 2.2.2.1 but still not working.

The server at 2.2.2.1 plugged in to ether9 cant get any Internet. ping to 8.8.8.8 shows request timed out...
by jamesw
Tue Mar 19, 2019 7:45 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Doesn't like it:

/ip address> add address=1.1.1.1/32 network=2.2.2.1/32 interface=ether9
invalid value for argument network
by jamesw
Tue Mar 19, 2019 7:40 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

Thanks. Even though I have 1.1.1.1 assigned as the ether5 static WAN IP already?

Thanks
by jamesw
Tue Mar 19, 2019 7:24 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Re: Need help routing public subnet IP to internal server

I had a look at that along with many other posts but it wasn't clear of the final outcome and how it should be configured. Ideally I just want to map an IP from my routed subnet directly to a physical server plugged in to ether9 - no PPPoE in this case or NAT/IP tunnels. Is that possible?

Thanks
by jamesw
Tue Mar 19, 2019 6:33 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2785

Need help routing public subnet IP to internal server

I've spent all day trying to get this to work, and still struggling, even though its a simple task. What I want is to use a public IP from my routed subnet directly on a server inside my network (without NAT). Current setup is: The ISP provides the following over the connection (IP's changed): Stati...
by jamesw
Wed Jul 05, 2017 1:48 pm
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 2275

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

Another question... if I am only using 1 port as the trunk port on the RB1100AHx2, is eth10 (part of switch1) faster/better than just using eth11/12/13 which are directly connected to the CPU?

Would there be any benefit?

Thanks
by jamesw
Wed Jul 05, 2017 1:11 pm
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 2275

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

Setting egress is not enough. When you switch to "vlan" tab (the first to the left of "eg. vlan tag"- as on the last image you send), what can you see there? Actually, your points made me check something. On the uplink siwtch, I only had "sfp1" as an egress vlan. So, a...
by jamesw
Wed Jul 05, 2017 12:36 pm
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 2275

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

You need to configure a port you plugged your AP to as a trunk port for vlan 10, 30 and 40 (I'm assuming this will be a port on one of your 14 switches). Since your vlans are working OK with a cable connection I'm assuming your uplink switch and RB and configured correctly. I thought setting the eg...
by jamesw
Wed Jul 05, 2017 11:54 am
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 2275

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

Hi, Did you add eth9-meraki... port to relevant VLANs (Vlan tab on your Image 2)? On the CRS125 switch its plugged in to, or the RB1100? I have eth9-meraki listed in the egress table, so it should just pass those VLAN IDs to SFP1 (which connects to ether10 on the RB), and then the DHCP server on th...
by jamesw
Wed Jul 05, 2017 10:04 am
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 2275

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

Really hoping for some help so I can kick-start our network :) I'm sure its just a setting or tweak required. Or, is there just no way at all without using a bridge? (I am only using a single trunk port on the RB - eth10), so don't really want to have a bridge with one port and force software routin...
by jamesw
Tue Jul 04, 2017 4:52 pm
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 2275

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

Image 4 (Topology) attached
by jamesw
Tue Jul 04, 2017 3:25 pm
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 2275

VLAN Trunk issue with CRS-125 and RB100AHx2

Hi guys. I'm coming up against an issue but I've exhausted my understanding on the topic. Basically, we have 14 x CRS125 switches all handing traffic from the patch panels. We set most of the ports on these switches to VLAN 10 using the Ingress VLAN table. We also have a couple of ports on each swit...