Community discussions

MikroTik App

Search found 986 matches

by mozerd
Sat Oct 05, 2024 1:47 pm
Forum: General
Topic: Can firewall rules slow down bandwidth test?
Replies: 8
Views: 426

Re: Can firewall rules slow down bandwidth test?

How does Fasttrack Help IPv4 FastTrack is a special handler that bypasses Linux facilities allowing for faster packet forwarding. The handler is used for TCP and UDP connections marked with "fasttrack-connection" action. IPv4 FastTrack handler supports NAT (SNAT, DNAT, or both). Note that...
by mozerd
Wed Oct 02, 2024 11:45 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1375
Views: 298101

Re: 📣 WinBox 4 is here 📣

What's new in v4.0beta9: I always check logs and disappointed that the log window still does not scroll with up-arrow-keys down-arrow-keys plus the log window should always open at last log entry For me Logs is a priority ,,, hopefully its a priority with your dev team ... So the up-arrow-keys down...
by mozerd
Fri Sep 27, 2024 10:29 am
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 34
Views: 5185

Re: RoS 7.16 RC4 mDNS

This completely exposes hosts in list, more secure is to allow just needed ports for hosts in list.
in my situation I only allow one to one communication - nope, local hosts [and/or devices] are completely secure from each other unless permitted,

I'm always ready to learn, however ... :D
by mozerd
Fri Sep 27, 2024 12:35 am
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 34
Views: 5185

Re: RoS 7.16 RC4 mDNS

With the current implementation of mDNS I have my Sonos Speakers and Apple Airprint Printers all working flawlessly

Sonos and AirPrint Printer reside on vlan100 --- devices that need access to either one of these reside on vlan20 ...

Using the 2 firewall rules mentioned in my posting here ....
by mozerd
Thu Sep 26, 2024 1:56 pm
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 34
Views: 5185

Re: RoS 7.16 RC4 mDNS

Nope. The server in which Jellyfin runs is a linux machine (firewall disabled) and the client is a smartv. I am not at all familiar with Jellyfin but in reading some stuff on the web I have hits stating that Jellyfin currently does not support multicasting ... https://features.jellyfin.org/posts/17...
by mozerd
Thu Sep 26, 2024 12:37 pm
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 34
Views: 5185

Re: RoS 7.16 RC4 mDNS

/ip firewall filter add action=accept chain=input comment="Allow mDNS" disabled=no dst-address=224.0.0.251 dst-port=5353 log-prefix=mDNS protocol=udp src-port=5353 In my highly restrictive local communication environment I had to add an addition forward rule like following: /ip firewall f...
by mozerd
Tue Sep 24, 2024 2:45 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1375
Views: 298101

Re: 📣 WinBox 4 is here 📣

@rextended, I now see your point .... this Topic is so huge its impossible for me to track all the comments ... thanks for the heads up :-)
by mozerd
Tue Sep 24, 2024 2:21 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1375
Views: 298101

Re: 📣 WinBox 4 is here 📣

Winbox for Windows 4beta6
when I view Logs window I am not able scroll past the Top and Bottom using the up arrow or down arrow ... I have to use the scrolling bar to move back and forth past the top or Bottom of the window ...
by mozerd
Mon Sep 23, 2024 2:12 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 114672

Re: v7.16rc [testing] is released!

I still do not get it. Qualcomm is probably one of the largest wireless chipset manufacturers of the world. ...... Its my OPINION that MikroTik is having issues integrating the Qualcomm drivers with the Tik Hardware due to some hardware compromises in manufacturing ... the great majority of other v...
by mozerd
Mon Sep 23, 2024 11:30 am
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 34
Views: 5185

RoS 7.16 RC4 mDNS

My understanding is that mDNS is crucial for facilitating device discovery and communication within local networks without the need for a dedicated DNS server ... but Tik have not explained how that is implemented under RoS ... why introduce a new feature without some form of direction that is not ...
by mozerd
Fri Sep 13, 2024 2:35 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1375
Views: 298101

Re: 📣 WinBox 4 is here 📣

Under Microsoft Windows version 10 or version 11

I much prefer Winbox 3.x from a productive perspective

The Longer I use Winbox 4 the longer I come to the conclusion that Winbox 4 is very unproductive for me ...
by mozerd
Wed Sep 11, 2024 11:52 am
Forum: General
Topic: Where can I find GOOD documetation of IPSEC in Mikrotik?
Replies: 6
Views: 731

Re: Where can I find GOOD documetation of IPSEC in Mikrotik?

The following is IMO one of the very best guides on creating your IPSec under MikroTik
MikroTik IPSec ike2 VPN server: easy step-by-step guide by Nikita Tarikin
by mozerd
Thu Sep 05, 2024 1:35 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1375
Views: 298101

Re: 📣 WinBox 4 is here 📣

running 4beta4
REQUEST for Winbox version 4 under Windows 11
Please improve the contrast when using default light mode ... dark mode does not work for me ... Thanks
by mozerd
Thu Aug 29, 2024 11:33 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1375
Views: 298101

Re: 📣 WinBox 4 is here 📣

I find it intimidating at first glance ... because the look and feel is very different on my 17inch laptop screen ... perhaps it will grow on me :-)

On my Win 11 Laptop the UI does not follow the Microsoft paradigm ... the look and feel is more Apple Mac like ... IMO this is a mistake ...
by mozerd
Sun Aug 25, 2024 3:23 pm
Forum: Wireless Networking
Topic: Mikrotik or others on AX wifi access point
Replies: 173
Views: 10776

Re: Mikrotik or others on AX wifi access point

Are the mikrotk access point so good or not ?
MikroTik wireless is OK not great but OK

If you want better performance and a great WiFi experience then consider
Ubiquiti U6 Pro or the U7 Pro
TP-Link EAP610 or the EAP783
by mozerd
Wed Aug 07, 2024 10:42 am
Forum: Useful user articles
Topic: ZeroTier on Mikrotik – a rosetta stone [v7.1.1+]
Replies: 43
Views: 39053

Re: ZeroTier on Mikrotik – a rosetta stone [v7.1.1+]

Very nice work @Amm0

But the following is also nice to know
Tailscale vs. ZeroTier: Side-by-Side Comparison
by mozerd
Tue Aug 06, 2024 11:30 pm
Forum: RouterBOARD hardware
Topic: What does the "Cloud" bit mean with Mikrotik switches?
Replies: 8
Views: 1768

Re: What does the "Cloud" bit mean with Mikrotik switches?

The cloud in technology refers to: [1] A global network of remote servers around the globe that operate as a single ecosystem. [2] Servers accessed over the Internet, along with the software and databases that run on those servers. [3] Web-connected servers and software that users can access and use...
by mozerd
Tue Aug 06, 2024 2:19 pm
Forum: General
Topic: The post was removed after approval opening again because didn't get a Convincing answer
Replies: 26
Views: 1645

Re: The post was removed after approval opening again because didn't get a Convincing answer

@normis
Please provide the MikroTik Corporate answer to a legitimate question asked by @MikrowizardOfficial
by mozerd
Mon Jul 22, 2024 3:28 pm
Forum: Wireless Networking
Topic: Does size of antenna matter?
Replies: 64
Views: 4796

Re: Does size of antenna matter?

For any true MIMO indoor system what matters is the DRIVER and how the driver is configured. Antennas matter for OUTDOOR installations but indoor installation the antennas built-in [inside the case] are synced with the specific driver. MOST OEM's like Broadcom and QUALCOMM provide tuned drivers whic...
by mozerd
Fri Jul 05, 2024 3:48 pm
Forum: Beginner Basics
Topic: [NEWBIE] Where to start?
Replies: 3
Views: 686

Re: [NEWBIE] Where to start?

Here is my suggestion for you:
First Time Configuration
and a very nice security guide from Manito Networks Tyler Hart who is a networking and security professional
MikroTik Security Guide
by mozerd
Wed Jul 03, 2024 6:11 pm
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 34
Views: 5185

Re: RoS 7.16 beta3 mDNS

Thanks Amm0 ... I have not had any luck so far My understanding is that mDNS is crucial for facilitating device discovery and communication within local networks without the need for a dedicated DNS server ... but Tik have not explained how that is implemented under RoS ... why introduce a new featu...
by mozerd
Tue Jul 02, 2024 4:48 pm
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 34
Views: 5185

RoS 7.16 RC4 mDNS

Anyone using this version got mDNS working? If YES please tell me how ... I have CCR1009 with 5 vlans that's connected to my CRS326 switch where all my vlans reside either through ethernet or WiFi I want my printer that is AirPrint capable and sitting in vlan100 to be accessed by any apple device si...
by mozerd
Fri Jun 28, 2024 11:51 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 119439

Re: v7.16beta [testing] is released!

There the workaround is "insert a delay" too, but that kind of kludges should not be necessary.
Yes I agree with your assessment — that it’s a bug …
by mozerd
Fri Jun 28, 2024 9:26 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 119439

Re: v7.16beta [testing] is released!

CCR1009 RoS v 7.16beta2 Starting with Ros 7.15 Scheduler is still broken as it tries to launch my on STARTUP script ... all the scripts have been tested and have zero errors ... very annoying ... The issue with the scheduler is now solved . The first script in the “startup” chain had a delay of 10 ...
by mozerd
Mon Jun 24, 2024 11:31 am
Forum: RouterBOARD hardware
Topic: Which router for ~100 clients
Replies: 69
Views: 7280

Re: Which router for ~100 clients

I wanted to know if any professionals here charged that much per hour, and if that's in any way comparable to Serbia. Will also check locally, if someone else says 200e/h, I'm going into networks :D
On my website I advertise my Cost of Service
by mozerd
Sat Jun 22, 2024 6:22 pm
Forum: RouterBOARD hardware
Topic: Which router for ~100 clients
Replies: 69
Views: 7280

Re: Which router for ~100 clients

We have worked with this person/company before, never had an issue (since before I came to the company, and I'm here for almost two years now). The manager just called them, I explained what we wanted and he said it's not a problem and went on to do it. We ordered the equipment to his office, when ...
by mozerd
Thu Jun 13, 2024 1:26 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 119439

Re: v7.16beta [testing] is released!

CCR1009 RoS v 7.16beta2 Starting with ROS 7.16 beta1 and now with RoS v 7.16 beta2 my USB disk gets reset. This causes some of my scripts to fail. Starting with Ros 7.15 Scheduler is still broken as it tries to launch my on STARTUP script ... all the scripts have been tested and have zero errors ......
by mozerd
Tue Jun 11, 2024 5:36 pm
Forum: Scripting
Topic: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno
Replies: 14
Views: 2204

Re: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno

@Amm0
Your NEW code works beautifully ... Thank You ...
by mozerd
Sun Jun 09, 2024 5:28 pm
Forum: Scripting
Topic: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno
Replies: 14
Views: 2204

Re: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno

I have checked all my scripts that are launched from scheduler and each return No syntax errors found in the import file IMO RoS 7.15 and 7.16beta1 the Tik scheduler has a bug and is the issue ... If you want to check your scripts and as Amm0 suggests ... once you create a .rsc file and store it in ...
by mozerd
Sat Jun 08, 2024 2:58 pm
Forum: Scripting
Topic: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno
Replies: 14
Views: 2204

Re: Script Execution Error - Dynu.com 7.13 was fine 7.15 no bueno

Yes I do the very same as you and I get the exact same error.

When I run this script manually it works fine under all versions of 7.x up to and including 7.16beta1

But from the scheduler it’s definitely a problem starting with v7.15 and 7.16beta1
by mozerd
Fri May 31, 2024 9:39 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 655
Views: 259214

Re: v7.15 [stable] is released!

CCR1009 RoS v 7.15 stable All my scripts shown below run without error when launched from scripts or CLI or from scheduler under RoS 7.14.2 Under RoS 7.15 if they are launched from scheduler I get an error in log to check manually … when run from scripts or CLI no issue I have a STARTUP script :dela...
by mozerd
Mon May 27, 2024 12:29 pm
Forum: General
Topic: Building SDWAN for MikroTik: Here's an Honest Account of What It's Like
Replies: 2
Views: 2857

Re: Building SDWAN for MikroTik: Here's an Honest Account of What It's Like

Hannes I tip my Hat off to you ...

Its my sincere wish that you succeed ...
by mozerd
Wed May 15, 2024 6:08 pm
Forum: General
Topic: Feature request : Multipath TCP (MPTCP) support
Replies: 14
Views: 10214

Re: Feature request : Multipath TCP (MPTCP) support

... drumroll please...............
" DPI of encrypted packets "
Would make the gear very expensive and not their market ...

Yes it would be very nice to have but all the Cheap Basterds that love this TiK would have to go elsewhere for an adorable solution ... :D
by mozerd
Thu May 09, 2024 12:13 am
Forum: Beginner Basics
Topic: Too many Wireguard logs from version 7.14beta3
Replies: 7
Views: 6009

Re: Too many Wireguard logs from version 7.14beta3

is-responder (yes | no; Default: no
where is this setting? I do not see it
Using Winbox go to WireGuard / Peers
That’s where you will find Responder
by mozerd
Sun May 05, 2024 3:08 pm
Forum: RouterOS beta
Topic: Feature Request : IPv6 Fasttrack
Replies: 203
Views: 61544

Re: Feature Request : IPv6 Fasttrack

IPv6 Fasttrack is coming once they work out platform issues ... hopefully before end of this year or spring of 2025 ...
by mozerd
Thu May 02, 2024 11:14 am
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 2705

Re: wireguard with vlan bridge

@mozerd. Like in anything else MT, without any entry, all is allowed. The OP has no entries in winbox service entry ( probably just default port ) and thus all IPs are allowed. You are so right ... thanks for the reminder ... I like to use winbox service entry as an extra precaution for specific de...
by mozerd
Wed May 01, 2024 11:40 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 2705

Re: wireguard with vlan bridge

The problem is with the rule: chain=input action=accept src-address-list=Authorized in-interface-list=MGMT log=no log-prefix="" wi-fi is not part of MGMT. I guess I will have to decide vulnerability vs convenience. I have not looked at your config because I am far too lazy right now …. Th...
by mozerd
Mon Apr 29, 2024 3:47 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 2705

Re: wireguard with vlan bridge

... what is valid is what traffic your users and yourself as admin need. Excellent stuff ...... ...... anav STOP in the name ov coding And to innkeeping with your outstanding direction why is so hard for you not to use code tags which makes far easier to follow each of your coded step ... then perh...
by mozerd
Wed Apr 17, 2024 9:01 pm
Forum: General
Topic: Is Mikrotik's Firewall is enough to protect a medium enterprise.?
Replies: 21
Views: 2012

Re: Is Mikrotik's Firewall is enough to protect a medium enterprise.?

….. this is getting very annoying.
@anav
Why is it annoying?
by mozerd
Wed Apr 17, 2024 11:35 am
Forum: General
Topic: Is Mikrotik's Firewall is enough to protect a medium enterprise.?
Replies: 21
Views: 2012

Re: Is Mikrotik's Firewall is enough to protect a medium enterprise.?

My reasons for dissatisfaction with Firewalla have nothing much to do with its capability. Today that J3160, with expanded memory and storage, is reinstalled as just another unix-variant box within the network. @phascogale I 4 1 do not understand your dissatisfaction .... any chance you could be a ...
by mozerd
Tue Apr 16, 2024 10:29 pm
Forum: General
Topic: Is Mikrotik's Firewall is enough to protect a medium enterprise.?
Replies: 21
Views: 2012

Re: Is Mikrotik's Firewall is enough to protect a medium enterprise.?

Okay they are telling me they use their own software coupled with Zeek monitoring software, say they do not use any existing platform???
Their new 10gig box supposedly comes with 8gigs of memory and quad core cpu ???
I will try and get a trial and personally see how it goes ….
by mozerd
Tue Apr 16, 2024 10:27 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2113

Re: 7.14.1 APPLE iOS cannot be static in DHCP

And the declined comes definitely from iOS
I surmise based on the quoted comment you have an IOS app installed that is acting like a firewall preventing the action.

Which version of IOS is running and do u have any security apps running on your Apple device ?
by mozerd
Tue Apr 16, 2024 5:15 pm
Forum: General
Topic: Is Mikrotik's Firewall is enough to protect a medium enterprise.?
Replies: 21
Views: 2012

Re: Is Mikrotik's Firewall is enough to protect a medium enterprise.?

How did you figure it out Mozerd? I attendid a demo ... Yes they have layer 7 capabilities as long as a properly equipped machine is used [3+ Ghz and dedicated asics etc] but not many off the shelf units do not have the power or ASICS to be effective [far too slow] ... With FortiGate etc. the perfo...
by mozerd
Tue Apr 16, 2024 4:47 pm
Forum: General
Topic: Is Mikrotik's Firewall is enough to protect a medium enterprise.?
Replies: 21
Views: 2012

Re: Is Mikrotik's Firewall is enough to protect a medium enterprise.?

The one exception, no subscription fees is something called firewalla... I wonder if anyone has used this device and can comment??
firewalla is just a fork of pfSense --- IMO does not compare to Fortigate/Arista/Juniper/Cisco for layer 7
by mozerd
Tue Apr 16, 2024 4:40 pm
Forum: General
Topic: Is Mikrotik's Firewall is enough to protect a medium enterprise.?
Replies: 21
Views: 2012

Re: Is Mikrotik's Firewall is enough to protect a medium enterprise.?

and the Question is : Is the Mikrotik Firewall Rules is enough to protect my full network ..? or I have to add a firewall to it..? If the firewall is properly configured to meet your business requirements then Yes it is ennough. The Key Point is business requirements. Your business may have require...
by mozerd
Mon Apr 15, 2024 1:39 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2113

Re: 7.14.1 APPLE iOS cannot be static in DHCP

It it were that easy... (already stated in OP - that nobody seems to actually read) Yes I did read your OP. 2 additional things that you can try After turning off Private Wi-Fi Address turn off WiFi on your iPhone In RoS DHCP Leases delete the entry for your iphone Now turn on your iPhone Wi-Fi Loo...
by mozerd
Sat Apr 13, 2024 11:14 am
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2113

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Anybody eny ideas? This is not a RoS Issue ... this is an Apple Setting that you must change if you want the Apple device to get a static IP I will use an iPhone as an example: On the iPhone Go to Settings and Wi-Fi THEN touch the i that is encircled turn off ==>> Private Wi-Fi Address This will en...
by mozerd
Wed Apr 10, 2024 10:10 pm
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1785

Re: BTH basic question

@anav [this Alias is easier for me to remember] :D
I do Agree with you that you have discovered a BTH bug …. Traffic originating on wan2 should return to wan2 ….. surprised that MikroTik have not commented on this behavior…. RouterOS must honor WireGuard Routing Behavior….
by mozerd
Wed Apr 10, 2024 4:18 pm
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1785

Re: BTH basic question

But still more config wizard to create peers & you can see the config it generates in WG so nothing is hidden as @normis points out. BTH is an excellent idea for the home users .... :) @Amm0 For BTH -- From a security perspective the only way to find out exactly what is hidden or not hidden is ...
by mozerd
Wed Apr 10, 2024 3:02 pm
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1785

Re: BTH basic question

Winbox is also not open source. What is your point? With WireGuard users have control over every aspect .... With BTH, users deligate control over to BTH .... I prefer that users have compl;ete control over the process. Yes you make a good point regarding Winbox but at least here users can choose t...
by mozerd
Wed Apr 10, 2024 1:58 pm
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1785

Re: BTH basic question

...... all you need is the router password. No need to connect to router with Winbox or anything else. App does it all for you,
@normis
Very nice ..... but this does beg the security question

Is the BTH app Open Source?
by mozerd
Thu Apr 04, 2024 6:34 pm
Forum: General
Topic: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]
Replies: 35
Views: 4763

Re: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]

This has nothing to with your attempt to assign wireguard to ports vice users/devices etc... What you are talking now is simply to access remote routers for config purposes. If you also need to access subnets at remote devices that will require a bit more work but not that much. JUST a reminder tha...
by mozerd
Tue Apr 02, 2024 8:33 pm
Forum: General
Topic: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]
Replies: 35
Views: 4763

Re: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]

how easy is it to integrate PRO WG MGMT with MT devices?? how many aliases do you have anav? :D The Pro Custodibus agent won't run on MikroTik's RouterOS .... would be very nice if it did 8) .... so if a MikroTik Router is used as a WireGuard hub, Pro Custodibus isn't a good fit. Pro Custodibus wou...
by mozerd
Tue Apr 02, 2024 5:34 pm
Forum: General
Topic: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]
Replies: 35
Views: 4763

Re: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]

KISS = acronym “keep it simple” = ZeroTier ;- )
:D
I guess that you have not tried the PRO WIREGUARD MANAGEMENT solution from someone that you respect highly ???
KISS = acronym “keep it simple” = for PRO's only :D
only when scalling becomes an issue with WireGuard
by mozerd
Tue Apr 02, 2024 3:51 pm
Forum: General
Topic: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]
Replies: 35
Views: 4763

Re: Connectivity to customers mikrotiks via Wireguard. Good idea? [SOLVED]

ZeroTier is easier to setup, but even if idle it ZeroTier does use more bandwidth than WG.
In-my-opinion , WireGuard is far easier to setup and far more efficent to run when KISS is applied .... but if you are a Rocket Scientist then ZeroTier is your cup of Tea. :)
by mozerd
Fri Mar 29, 2024 5:01 pm
Forum: General
Topic: Purchasing on Amazon
Replies: 11
Views: 1272

Re: Purchasing on Amazon

llama (amazon)
323.69+15% = $372.24
Anav where did you get the 15% from? It’s 13%
323.69 x 13% = 365.77

😀
by mozerd
Fri Mar 29, 2024 3:37 pm
Forum: General
Topic: Purchasing on Amazon
Replies: 11
Views: 1272

Re: Purchasing on Amazon

The most recent MT item I bought through Amazon came from Getic , one of MT’s primary distributors, possibly even #1. Getic does a poor job with product descriptions…. Check the link to see how they describe the RB5009 I like buying from Amazon Canada because returns are absolutely hassle free and ...
by mozerd
Tue Mar 19, 2024 1:10 pm
Forum: Beginner Basics
Topic: Lowest price mikrotik home router
Replies: 10
Views: 1763

Re: Lowest price mikrotik home router

Can anyone suggest me the lowest price mikrotik router with WiFi and comes with ros7 ?

As I am going to put wireguard VPN client on it so need router os 7
My suggestion is the AX2 or AX3 - ARM64 using the qcom drivers
by mozerd
Sat Mar 16, 2024 3:18 pm
Forum: General
Topic: Temporary loss of access to network without disconnecting to AP
Replies: 7
Views: 683

Re: Temporary loss of access to network without disconnecting to AP

..... ..... Finally gave in and changed manufactures. .... ..... All the trouble tickets stopped cold. The networks we could set and forget we're back. The only change I had to go back to using another vendor for wifi. @gotsprings -- Yes experience is the best teacher without a doubt ... but I see ...
by mozerd
Thu Mar 07, 2024 7:41 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 85466

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

……. At most they should be implemented by the ISP, because if one or more of those IPs attacks you, all the traffic will reach your home or office anyway, clogging up your connection... @rextended … salute 😀 I agree BUT very few do that …. My subscribing clients are very pleased with my MOAB. Servi...
by mozerd
Thu Mar 07, 2024 7:33 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 85466

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Hi Mozerd, I could really never tell what exactly makes up the MOAB list. I was under the impression it was just the firehol lists. Not sure where I got that impression. Tell me if I'm wrong. @texmeshtexas greetings 😀 You are not wrong …. But do you fully understand what makes up firehol …. [Overla...
by mozerd
Thu Mar 07, 2024 3:27 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 85466

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Hey all, i have a question. For the last couple of years I've been building a system that I've been using for 2 business and my own home office. ......... How many would be interested? I more than welcome the competion ... :D MOAB ... MOAB blocks over 600 million Bad Guys from attacking your Intern...
by mozerd
Thu Mar 07, 2024 3:15 pm
Forum: Wireless Networking
Topic: Wifi 7 - MikroTik when???
Replies: 79
Views: 20462

Re: Wifi 7 - MikroTik when???

Wifi 7 actually has some nice features... Lot's of improvements and shouldn't be snuffed at as just another speed bump :) Yes ... and I can predict that WiFi 7 will be an enormus success, first with the high end and Middle Class market ... I am aware that all the BIG names are in a ready set go sta...
by mozerd
Tue Mar 05, 2024 2:06 pm
Forum: Useful user articles
Topic: mDNS between VLANs with just bridge filters - Look Mum, no containers!
Replies: 84
Views: 27722

Re: mDNS between VLANs with just bridge filters - Look Mum, no containers!

I stopped wasting my time on legacy IPv4 years ago. I would suggest you play with IPv6 multicast routing going forward. IPv4 should, one day, be removed from the network stack. While I agree with your sentiments wholeheartedly MANY ISP's still do not support ipv6 .... very sad to say .... My old IS...
by mozerd
Sun Mar 03, 2024 3:08 pm
Forum: General
Topic: WireGuard useful learning [Linux]
Replies: 8
Views: 1161

WireGuard useful learning [Linux]

YET ANOTHER SYSADMIN WEBSITE The basics to know about wireguard routing Introduction Now that we learned how to configure wireguard on multiple operating systems, let’s take a break and review what running wireguard does to your routing table. Wireguard routing basics The most important thing to un...
by mozerd
Mon Feb 26, 2024 8:25 pm
Forum: Beginner Basics
Topic: VLANS creation and testing-AX2
Replies: 186
Views: 11002

Re: VLANS creation and testing-AX2

but iguess anyone that finds my url on the internet somehow.. can at lkeast gain access to my NAS and from there try to hack it? @ antoniocerasuolo Apparently you do not comprehend how quick connect works …. And apparently All you want is to be hand held by others … Without the proper userdID and P...
by mozerd
Mon Feb 26, 2024 3:03 pm
Forum: Beginner Basics
Topic: VLANS creation and testing-AX2
Replies: 186
Views: 11002

Re: VLANS creation and testing-AX2

and i have abilitated the synology quick connect from internet How secure is the quick connect on Synology? QuickConnect Web Portal is secured by end-to-end encryption when the browser is redirected to the Synology NAS using LAN or WAN connection. Otherwise, the request is directed to the Portal Se...
by mozerd
Sun Feb 25, 2024 1:01 pm
Forum: Beginner Basics
Topic: VLANS creation and testing-AX2
Replies: 186
Views: 11002

Re: VLANS creation and testing-AX2

probably becasue the CRS310 has the 2.5 Gibit ports?
@antoniocerasuolo
The Switch Chip is the reason
by mozerd
Thu Feb 22, 2024 3:06 pm
Forum: Beginner Basics
Topic: VLANS creation and testing-AX2
Replies: 186
Views: 11002

Re: VLANS creation and testing-AX2

yes DPI /IDP for home use of course budget .. max 400Euro
https://eu.store.ui.com/eu/en/pro/products/ucg-ultra

Yes there is a yearly license fee and to find that out you will need to contact UI
by mozerd
Tue Feb 20, 2024 3:28 pm
Forum: Scripting
Topic: Scripts cannot run with permission denied V7.13.4
Replies: 12
Views: 6057

Re: Scripts cannot run with permission denied V7.13.4

3) Add "ftp" policy. I run the dynu script and do not have ftp policy checked and my script runs without issue. @rextended ... so why are you stateing point # 3) ? I have not seen the OP's script .... my dynu script is below: /system script add dont-require-permissions=no name=Dynu owner=...
by mozerd
Sun Feb 18, 2024 1:00 pm
Forum: Announcements
Topic: v7.14rc [testing] is released!
Replies: 176
Views: 58624

Re: v7.14rc [testing] is released!

But I am curiouse by that "check default script" api.ipify.org Mystery SOLVED .... I have a script that checks my WAN IP Address for changes ... in that script a call is made to api.ipify.org .... For some reason v7.14rc is now showing log info from this script that I have not seen before...
by mozerd
Sun Feb 18, 2024 11:42 am
Forum: Announcements
Topic: v7.14rc [testing] is released!
Replies: 176
Views: 58624

Re: v7.14rc [testing] is released!

But it "could" be CCR only ... Upgrade again to 7.14rc and check default script (which might already be pretty empty, I guess ?). What do you mean by "check default script" ? If this api is not appearing on your devices when running v7.14rc THEN its tied to something else and I ...
by mozerd
Sun Feb 18, 2024 11:30 am
Forum: Announcements
Topic: v7.14rc [testing] is released!
Replies: 176
Views: 58624

Re: v7.14rc [testing] is released!

Malware infected box. Do a clean netinstall and null config, then configure from scratch.
Thanks for your feedback but I do not agree just yet ... I am monitrring the LAB CCR1009 with wireshark and so far I do not see any activity from api.ipify.org under v7.13.4 [stable]
by mozerd
Sun Feb 18, 2024 11:05 am
Forum: Announcements
Topic: v7.14rc [testing] is released!
Replies: 176
Views: 58624

Re: v7.14rc [testing] is released!

CCR1009 LAB Testing v7.14rc A new log entry appears that I have never seen before: Download from api.ipify.org FINISHED Is this injected by MikroTik in THIS RC and for what reason ? api.ipify[.]org and similar domains have long been used by malware to look up an infected device’s public IP. In resea...
by mozerd
Thu Feb 15, 2024 5:30 pm
Forum: General
Topic: Wireguard from Linux not working [SOLVED]
Replies: 37
Views: 4743

Re: Wireguard from Linux not working [SOLVED]

I absolutely love the format of the Pro Custodibus blogs ! A brilliantly elaborate pedagogy using images in combination with a well-thought-out flow of explanatory text is among the best resources you can find on the internet. This is how I think User Guides and examples should look like on the Mik...
by mozerd
Thu Feb 15, 2024 2:07 pm
Forum: General
Topic: Wireguard from Linux not working [SOLVED]
Replies: 37
Views: 4743

Re: Wireguard from Linux not working [SOLVED]

When testing your Linux WireGuard Config following link provides you with excellent clues
by mozerd
Mon Feb 12, 2024 8:46 pm
Forum: General
Topic: WireGuard throughput depending on running torch [SOLVED]
Replies: 9
Views: 1625

Re: WireGuard throughput depending on running torch [SOLVED]

I use a hAP ax^3 since 2023-10 and have the following issue: I followed basically this blog post (https://scholz.ruhr/blog/mullvad-as-second-wan-on-mikrotik/, thanks to the author) to setup WG tunnel to my friends place. Everything was working like a charm with RouterOS v7.11.2. Yesterday I updated...
by mozerd
Sun Feb 11, 2024 7:57 pm
Forum: Beginner Basics
Topic: Unable to get VLAN working between RB5009 and AX2
Replies: 16
Views: 1288

Re: Unable to get VLAN working between RB5009 and AX2

There was a good tutorial for this scenario... Unfortunately it's taken down...
https://web.archive.org/web/20231216022 ... p?t=182373
by mozerd
Mon Feb 05, 2024 5:53 pm
Forum: General
Topic: [Discussion] MikroTik configuration abstraction complexity
Replies: 164
Views: 15099

Re: [Discussion] MikroTik configuration abstraction complexity

MikroTik sells boxes with ASICs that are advertised for 100Gbps ASIC switching, that's a foot in the door of carrier-class network engineering. And you need product managers, good ones. @DarkNate IMO Mikrotik has ZERO interest in CARRIER-CLASS networking ... MikroTik Market is 1 .. Third World entr...
by mozerd
Thu Feb 01, 2024 2:32 pm
Forum: Beginner Basics
Topic: need help with choosing right hardware stack for a home office [SOLVED]
Replies: 12
Views: 1881

Re: need help with choosing right hardware stack for a home office [SOLVED]

question 3 - if all my concerns will be true....I mean it will be impossible to do what I want with mikrotik wireless, I've read a lot messages like "MikroTik for routing, unifi for wireless" - maybe I need to grab two U6 and connect them to rb5009? I understand that MikroTik forum is not...
by mozerd
Sat Jan 13, 2024 12:17 pm
Forum: Announcements
Topic: v7.14beta [testing] is released!
Replies: 510
Views: 168871

Re: v7.14beta [testing] is released!

WireGuard is a Peer-to-Peer protocol with built-in 4in6/6in4 mechanisms for easy encapsulation. There's no such thing as “server” or “client” in WireGuard protocol. There are only peers. You are 100% correct. But unfortunately many people [including so called gurus] on this forum refuse to accept t...
by mozerd
Tue Jan 09, 2024 1:21 pm
Forum: General
Topic: Brute Force Attacks
Replies: 16
Views: 2796

Brute Force Attacks

FYI

The following IP address 95.214.54.110 is trying very hard to gain access to my Tik via VPN [port 500] each and every day now for months ...

Just a FYI

How many are seeing the very same intrusion attempt on their Tiks ?
by mozerd
Wed Jan 03, 2024 11:46 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 2330

Re: Purchase recommendation

@anav
Your UK friend has the correct answer
viewtopic.php?t=148825#p733499

@gabacho4
Yes the CCR1009 is discontinued and replaced by the CCR2004-16G-2S+PC (I think ?)
But I only have experience with the CCR1009 with gaming clients …
by mozerd
Wed Jan 03, 2024 11:21 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 2330

Re: Purchase recommendation

I suggest that you consider the RB5009 or the CCR1009 … I have quite a few CCR1009 in homes where gaming is the number one priority … the tricky part will be for you to arrive a the correct QoS configuration but with some trial and error I’m sure you will arrive at a balance that will please your fa...
by mozerd
Wed Jan 03, 2024 4:41 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 2330

Re: Purchase recommendation

@Denigor777
How much bandwidth does your primary ISP provide you with Download and Upload ?
by mozerd
Fri Dec 22, 2023 2:25 pm
Forum: Announcements
Topic: v7.14beta [testing] is released!
Replies: 510
Views: 168871

Re: v7.14beta [testing] is released!

Why is MikroTik loading wireless package into CCR models? Please explain WHY! This makes ABSOLUTLY no sense to me ...
by mozerd
Tue Dec 19, 2023 7:53 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 85466

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

@kevinds. “Anybody else having this issue? Or just me?”

Yes this version 7.13 is a problem that’s already reported in the 7.13 upgrade thread

I has to downgrade to 7.12.1 where all my scripts worked ….
by mozerd
Tue Dec 19, 2023 12:48 am
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

If after this you do not understand it open a support ticket with Mikrotik. @diamuxin, you are correct ... I did not fully comprehend the meaning of your comment " You have to delete (uninstall) the existing packages except the "routeros" package, then do the downgrade ." Please...
by mozerd
Tue Dec 19, 2023 12:43 am
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

My CCR1009 shows under /system/packages routeros wireless I do not see a match under 7.12.1 in the archive Plus why would CCR1009 load a wireless package ? OK so I finally succeeded downgrading to 7.12.1 I had to uninstall the wireless package then reboot THEN my downgrade worked to 7.12.1. It was ...
by mozerd
Tue Dec 19, 2023 12:00 am
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

If you do try to upgrade/downgrade RouterOS manually, then router do expect 1:1 packages match. If that is not possible (for example, wifi-qcominstalled on 7.13) then on packages menu schedule these packages for uninstall. Uploadpackages that you want to install and execute downgrade command. My CC...
by mozerd
Mon Dec 18, 2023 8:45 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

You did upload the downgrade package to files before hitting "Downgrade", did you ? Yes I did upload the downgrade package to Files before hitting the “Downgrade” … Very annoying that the MikroTik instructions as shown in the link I provided earlier did not work … my only recourse now if ...
by mozerd
Mon Dec 18, 2023 6:57 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

In v7.13 the package "routeros" already exists in System > Package. You have to delete (uninstall) the existing packages except the "routeros" package, then do the downgrade.
OK followed your suggestion but that did not work ... thanks but now i will wait for 7.13.1 :-)
by mozerd
Mon Dec 18, 2023 6:13 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

What process did you follow? 1st step is copy file routeros-7.12.1-tile.npk to Files except I renamed the file like you suggested routeros 2nd step is via terminal issue /system/package/downgrade This did not work The procedure that is outlined in the MikroTiK Docs as follows also did not work for ...
by mozerd
Mon Dec 18, 2023 5:45 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

Hi friend, to downgrade from 7.13 to 7.12.X you only have to have in /system/package the package "routeros" and delete the rest, then the downgrade works.
Hi diamuxin
Your suggested fix did not work for me ...
by mozerd
Mon Dec 18, 2023 2:52 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

on my CCR1009 After upgrade to 7.13 from 7.12.1 when I attempt to downgrade back to 7.12.1 the downgrade fails. Log file shows omitting package system-7.12.1: newer package system-7.13 is already installed I tried 2 methods for the downgrade 1. via terminal 2. via Packages Both return the same resul...
by mozerd
Mon Dec 18, 2023 2:36 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

[ ] > :put ([/tool fetch url="https://upgrade.mikrotik.com/routeros/NEWEST7.stable" as-value output=user]->"data") 7.12.1 1700221125 It should report: 7.13 and epoch date: 1702542240 approx. Yes you are correct .... even through My CCR1009 is on 7.13 your code reports 7.12.1 170...
by mozerd
Fri Dec 15, 2023 5:34 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 293928

Re: v7.13 [stable] is released!

This AM i upgraded my CCR1009 from version 7.12.1 to version 7.13 now getting the following error when running a script Download from https://view.sentinel.turris.cz/greylist-data/greylist-latest.csv to RAM FAILED: Fetch failed with status 206 The same script was working fine under 7.12.1 and earlie...
by mozerd
Sat Dec 09, 2023 4:14 pm
Forum: General
Topic: New ROuter suggestion please
Replies: 15
Views: 3102

Re: New ROuter suggestion please

I doubt it even comes close to the granularity achievable on the MT. True that MT RouterOS provides SIGNIFICANT granularity …. However when that granularity is exploited there is no guarantee that it will be reliable persistently and consistently with each iteration of the firmware …. Especially si...
by mozerd
Sat Dec 02, 2023 11:11 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 5849

Re: Wireguard tunnel - speed problem

The following is some performance specs … look at WireGuard …. This is a TPLINK ER8411
https://www.tp-link.com/ca/business-net ... ifications

Impressive IMO … YEP I am now considering switching from my CCR1009 to this TPLINK router ….
by mozerd
Fri Oct 13, 2023 4:48 pm
Forum: RouterBOARD hardware
Topic: Search for new mikrotik router
Replies: 11
Views: 3741

Re: Search for new mikrotik router

My sugestion for you is the Mikr0Tik RB5009UG+S+IN ... and for great WiFi get youself the TP-Link AXE11000
by mozerd
Fri Oct 06, 2023 1:02 am
Forum: Beginner Basics
Topic: Hybrid VLAN and bridging in ROSv7 [SOLVED]
Replies: 18
Views: 6409

Re: Mikrotik VLAN routing for dummies [SOLVED]

Bla bla bla
@llamajaja … aka @anav …. Did they ban you AGAIN ??? goodness gracious great 👍
by mozerd
Tue Oct 03, 2023 3:36 pm
Forum: SwOS
Topic: Help with VLans.
Replies: 10
Views: 3584

Re: Help with VLans.

Thank you for the help guys, but I said to hell with it and bought an Aruba switch. I'm well versed in Aruba and understand the untagged/tagged/trunk far better than I do Mikrotik. HPE Aruba make EXCELLENT switches … nothing in the MikroTik switch line up can even compare … you made a very wise cho...
by mozerd
Fri Sep 29, 2023 1:43 pm
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 6331

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

MikroTik can sell reasonably priced support agreement. 1/2 the price of Cisco or Juniper. Any business [especially manufacturers] that hopes to be alive for a long time operates with a sustainable gross margin model. What my be reasonable to techies is certainly not reasolnable to a business man .....
by mozerd
Thu Sep 28, 2023 1:35 pm
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 6331

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

For gross margins on manufacturing, not my area of expertise, but I am willing to pay MikroTik thousands of dollars if they get their shit together. The business - use case is one very obviouse and important consideration that you have articulated clearly --- the deal maker for any manufactures is ...
by mozerd
Tue Sep 26, 2023 11:47 am
Forum: General
Topic: Why are there no production-grade L3 switches from MikroTik in 2023?
Replies: 26
Views: 6331

Re: Why are there no production-grade L3 switches from MikroTik in 2023?

Can you make a business case for a production-grade L3 switch ? If you could make that BC [at a high level] then I suspect that might tweek Tik interetest :D ... Although I do suspect that they already have such BC and have decided that its not worth the investment. Do you have any idea whatsoever t...
by mozerd
Fri Sep 22, 2023 5:52 pm
Forum: General
Topic: Should moderators redact sensitive info, and how much?
Replies: 49
Views: 4396

Re: Should moderators redact sensitive info, and how much?

Im 100% with holvoe/tangent etc and 100% against mkx.
What a subtle way to say that you're 100% against me as well :lol: Given the fact that I usually don't agree with your vision of pedagogy, I must say that I'm not disappointed :D
@kraal and @mkx
I 100% agree with you both ...
by mozerd
Sun Sep 17, 2023 2:39 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 89
Views: 18997

Re: Mikrotik SUCKS

It seems popular to attack the person that complains instead of taking it serious....... We have here persons that work indirect for the government that act the same and attack and supress opinions from citizen. I get the same feeling here, as with that. @msatter ... I could not agree more !!! To t...
by mozerd
Sat Aug 05, 2023 2:54 pm
Forum: General
Topic: Connecting 2 mikrotiks over internet [SOLVED]
Replies: 37
Views: 9472

Re: Connecting 2 mikrotiks over internet [SOLVED]

Add one to the mix
Wireguard. A lot faster then all the rest.
100% better solution is WireGuard just as @holvoetn stated plus WireGuard Security is second to none without sacrificing performance ...
by mozerd
Wed Jul 26, 2023 3:47 pm
Forum: Announcements
Topic: Click here
Replies: 35
Views: 12296

Re: Click here

Nicely done Normis ....
by mozerd
Wed Jul 19, 2023 2:11 pm
Forum: General
Topic: Question: Prevent passwords in scripts from SUPOUT.RIF
Replies: 2
Views: 450

Re: Question: Prevent passwords in scripts from SUPOUT.RIF

Any and all passwords are revealed in a supout.rif The only way to avoid exposing your passwords is to --- create dummy password's in all areas, then generate the support-rif ... after you submit the support.rif change back to your real passwords ... yep this is a Hassel but its the only way when a ...
by mozerd
Fri Jul 14, 2023 4:07 pm
Forum: RouterBOARD hardware
Topic: Chateau LTE18 ax external antenna conn. for LTE or WIFI?
Replies: 6
Views: 5686

Re: Chateau LTE18 ax external antenna conn. for LTE or WIFI?

I do not know the answer to your question because I do not have any experience with this particular device. For Celluar devices External Antennas are still a must so i venture to state that the LTE18 antennas are for the Cell Service. For WiFi and specifically for AC. AX and wifi 7 devices external ...
by mozerd
Wed May 31, 2023 2:48 pm
Forum: General
Topic: Help Desk support.
Replies: 14
Views: 1526

Re: Help Desk support.

@webequipped I understand how you feel ... :( Did you buy MikroTik because the product provided great features at a very inexpensive price compared to the big boys in this industry? If the answer is yes then you have to expect failure because the components used are very cheap throughout ... persist...
by mozerd
Sat May 27, 2023 4:24 pm
Forum: General
Topic: Which the best IP 10.0.0.1 or 192.168.20.1 for local network?!
Replies: 10
Views: 2734

Re: Which the best IP 10.0.0.1 or 192.168.20.1 for local network?!

@Taleb
In the Private Address space there is no preferred or best … use whichever suites your intuition.
by mozerd
Fri Apr 21, 2023 3:06 pm
Forum: RouterOS beta
Topic: v7 and BFD, any ETA?
Replies: 150
Views: 31440

Re: v7 and BFD, any ETA?

You don't understand how stupid that remark is, don't you? I believe that MikroTik does understand how very stupid that remark is/was -- but are to ashamed to admit that MikroTik is having Network competency issues implementing the protocol in RoS 7.x .... Perhaps the expertise is finally coming in...
by mozerd
Thu Apr 13, 2023 5:50 pm
Forum: Beginner Basics
Topic: Can a mikrotik be a Wireguard server and a client in the same time?
Replies: 14
Views: 2757

Re: Can a mikrotik be a Wireguard server and a client in the same time?

For the initial handshake one side has to ACT as server and the other end a client. Peer to Peer means: Decentralized peer-to-peer programs (such as WireGuard) allow pushing files, which means the calling Peer initiates the data transfer rather than the receiving Peer. No SERVER is involved ...... ...
by mozerd
Thu Apr 13, 2023 4:23 pm
Forum: Beginner Basics
Topic: Can a mikrotik be a Wireguard server and a client in the same time?
Replies: 14
Views: 2757

Re: Can a mikrotik be a Wireguard server and a client in the same time?

In the WireGuard world of VPN's there is no such thing as Client/Server .... WireGuard is strictly Peer to Peer ... Any WireGuard Peer can communicate with any other WireGuard Peer .... A Peer does not talk to itself ... a Peer only communicates with it's other permitted Peers ... So your Raspberry ...
by mozerd
Wed Apr 12, 2023 8:48 pm
Forum: General
Topic: The problem that upnp does not work [SOLVED]
Replies: 12
Views: 3305

Re: The problem that upnp does not work [SOLVED]

I have another question, how to isolate the input traffic of upnp. yes you can restrict the trafic to only allow specific devices access to UPnP. The way that I do it it 1st create an address list of permitted devices by their IP address Then only allow UPnP interaction for those devices … I use 2 ...
by mozerd
Wed Apr 12, 2023 11:25 am
Forum: General
Topic: The problem that upnp does not work [SOLVED]
Replies: 12
Views: 3305

Re: The problem that upnp does not work [SOLVED]

If it has something to do with firewall policies, can you tell me which ports upnp needs to open on the firewall.
udp port 1900
tcp port 2828
by mozerd
Mon Apr 10, 2023 11:04 am
Forum: Beginner Basics
Topic: max-MTU Question [SOLVED]
Replies: 113
Views: 14892

Re: max-MTU Question [SOLVED]

It really should.
Should I mark in anyway, or it's a moderator's job?
DeDMorozzzz YOU should mark it as solved because you are the initiator ....

BTW, DarkNate is a very knowledgeable person and I 4 1 admire his many contributions regardless
...
by mozerd
Fri Apr 07, 2023 5:16 pm
Forum: General
Topic: CRS 354-48g-4s+2q+rm as a core router in a company
Replies: 6
Views: 860

Re: CRS 354-48g-4s+2q+rm as a core router in a company

A router's main objective is to establish a connection between various networks in a simultaneous manner and it works on the network layer. A switch's main objective is to establish a simultaneous connection among various devices. Some Switches have the ability to act both as a Switch and a Router a...
by mozerd
Mon Apr 03, 2023 7:14 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 55331

Re: MikroTik hAP ax3 poor WiFi performance

So how do you propose to string that comm line to the moon?? No need for wired tech … NASA plus many MANY others rely very heavily on wireless. Once WiFi 7 becomes mainstream the wired world will become obsolete… 98% of my current business clients use wireless exclusively …. Many ISP will be transi...
by mozerd
Sat Apr 01, 2023 8:08 pm
Forum: Forwarding Protocols
Topic: BGP with BFD
Replies: 27
Views: 8447

Re: BGP with BFD

What does this all mean?
It’s an encrypted message for @DarkNate that states the following
“You catch more flies with honey than with vinegar.”

And I had a telepathic message from BFD developer that stated —- RoS 8.0 will be BFD production ready ….
by mozerd
Thu Mar 30, 2023 11:35 pm
Forum: RouterBOARD hardware
Topic: RB5009UPr+S+ Eth2 Lit up by itself
Replies: 13
Views: 2217

Re: RB5009UPr+S+ Eth2 Lit up by itself

I had a similar experience on a CCR1009 where ether1 stopped working but kept lighting up with no cable plugged in. What is strange is that I could assign an ip address to it and ping that address which would respond properly but connect a cable to that port with device but no response. I could disa...
by mozerd
Thu Mar 30, 2023 7:36 pm
Forum: RouterOS beta
Topic: BGP Confederation on Mikrotik V7
Replies: 27
Views: 11951

Re: BGP Confederation on Mikrotik V7

@404network …. What happened to you ??? Did they ban your remarkable friend “Anav” again for being a PITA? I can’t believe Anav is in the penalty box … tell me it ain’t so!
by mozerd
Mon Mar 27, 2023 5:22 pm
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 8177

Re: House wifi6 network with Mikrotik AX or Audience

Did you have chance to test AX3?
@Rox169
You did not see "I tried a couple of times and got so bogged down in the menus that I gave up." learn how to read :D
by mozerd
Wed Mar 22, 2023 1:04 pm
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 8177

Re: House wifi6 network with Mikrotik AX or Audience

@eazysnatch Some very good suggestions made by @Rox169 and @gotsprings I also have a suggestion that I believe will work extremely well for You ... its the TP-Link EHP660HD ... based on my experience the EHP660HD runs circles over the Mikrotik AX3 or Audience - in every way shape and form - and I he...
by mozerd
Mon Mar 20, 2023 12:20 am
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 3038

Re: Wireguard help (again)

Perhaps by studying the following
https://www.procustodibus.com/blog/2021 ... and-spoke/
You may get some ideas how to properly implement your objectives …
by mozerd
Sat Mar 18, 2023 10:32 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 12779

Re: Container/Docker -Adguard/Pihole For REAL.

And it's unclear what issues you're actually run into...
My bad Amm0 … not binary —- but refer to viewtopic.php?p=985966&hilit=Docker+update#p985966
by mozerd
Sat Mar 18, 2023 5:49 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 12779

Re: Container/Docker -Adguard/Pihole For REAL.

Lets forget Pi-hole its so yesterday (betamax). Either discuss adguard or blocky for example. How is Pi-hole so yesterday? Blocky uses the very same hosts file as PiHole and Adguard is very hit and miss IMO .... Pi-Hole does what it supposed to do BUT its not an end-user Tool ... meaning that it mu...
by mozerd
Sat Mar 11, 2023 12:26 pm
Forum: Beginner Basics
Topic: logging in without actual login
Replies: 11
Views: 1525

Re: logging in without actual login

You need to follow MikroTik Advice as stated in the following otherwise you are asking for serious hacking trouble ... and its got nothing to do with your ISP ...
Securing Your Router
by mozerd
Fri Mar 10, 2023 4:42 pm
Forum: General
Topic: USB Disk management [SOLVED]
Replies: 4
Views: 2107

Re: USB Disk management [SOLVED]

For the hAPac2 the solution was to Reformat the USB memory stick then use
/disk/set x slot=disk2
Then Reformat top most named ID and make sure MBR is left unchecked … this worked to resolve the issue …
by mozerd
Fri Mar 10, 2023 12:29 pm
Forum: Scripting
Topic: Command to create directory?
Replies: 14
Views: 33437

Re: Command to create directory?

The flowing will do it for you
/ip smb shares add name=sharethis directory=moab
/ip smb shares remove [find name=sharethis]
The 1st directive will create the directory while the 2nd directive will remove the share that is not needed.
by mozerd
Thu Mar 09, 2023 3:00 pm
Forum: General
Topic: USB Disk management [SOLVED]
Replies: 4
Views: 2107

Re: USB Disk management [SOLVED]

What is really annoying about this specific CHANGE is that on many devices the change is transparent -- meaning the MOAB control file is stored successfully under disk2 -- while on some device like the hAPac2 I have lots of complaints that MOAB control file no longer get stored in disk2 ,,, they get...
by mozerd
Wed Mar 08, 2023 10:29 pm
Forum: General
Topic: USB Disk management [SOLVED]
Replies: 4
Views: 2107

Re: USB Disk management [SOLVED]

Thank you ..

You are correct … disk1 is no longer used …the naming convention has changed … it’s like you stated.
by mozerd
Wed Mar 08, 2023 10:19 pm
Forum: General
Topic: USB Disk management [SOLVED]
Replies: 4
Views: 2107

USB Disk management [SOLVED]

Assuming the USB memory stick was formated and named disk1 In RouterOS version 6.x the following command sequence worked to rename disk1 to Disk2 /disk set 0 name=disk2 In RouterOS ver7.8 the above does not work .. name= is no longer valid Can anyone tell me how to rename disk1 to Disk2 under router...
by mozerd
Sun Mar 05, 2023 8:11 pm
Forum: General
Topic: Turn Mikrotik into a POWERFULL FireWall with BlackList Firehol [SOLVED]
Replies: 5
Views: 3226

Re: Turn Mikrotik into a POWERFULL FireWall with BlackList Firehol [SOLVED]

@khalildelavaran Nice work Just a few comments 1. There are many many duplicate IP when all the lists are brought in 2. Your script does not check for file size of the list so some of them could hit a wall 3 .Some of the Tik models do not have enough memory to store large lists of IP addresses If yo...
by mozerd
Fri Mar 03, 2023 6:28 pm
Forum: General
Topic: PETITION: Request to Forum Admins to prohibit posting of ChatGPT scripts on the forum, without specify the source.
Replies: 75
Views: 7963

Re: PETITION: Request to Forum Admins to prohibit posting of ChatGPT scripts on the forum, without specify the source.

I started programming when I was a child with Assembler and CPM/86 with MSDOS 3.0 and "debug"...
"With Assembler and CPM/86" ... very impressive my Italian Friend ... your RouterOS code is very nice ... but you need to make it very fast not only NICE ... :) :) :)
by mozerd
Fri Mar 03, 2023 2:01 am
Forum: General
Topic: Feature requests
Replies: 1769
Views: 665929

Re: Feature requests

North Idaho Tom Jones You really care about your name, it's always the most prominent thing in each of your posts and it's repeated in a completely useless way, since it's also the nickname and on the avtar... I see that you as a moderator are attacking North Idaho Tom Jones because he like to see ...
by mozerd
Fri Mar 03, 2023 1:47 am
Forum: Beginner Basics
Topic: Firewall Filter tool is not efficent
Replies: 13
Views: 2365

Re: Firewall Filter tool is not efficent

Now give me the solution or recommend me another hardware or equipment which full fill my need My suggestion for you is Untangle by Arista … can select the appliance plus the software based on your particular need. https://wiki.edge.arista.com/index.php/NG_Firewall_User_Guide https://edge.arista.co...
by mozerd
Thu Mar 02, 2023 2:56 am
Forum: General
Topic: how does L3HW actually works?
Replies: 128
Views: 36774

Re: how does L3HW actually works?

MikroTik needs to make some changes to their UI/CLI/UX logic and docs to help make L3 offloading as simple, straightforward and clear as possible.
DarkNate …
I could not agree more …
by mozerd
Sun Feb 26, 2023 8:35 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 55331

Re: MikroTik hAP ax3 poor WiFi performance

So I am gun shy of that functionality.
Anav my friend 😀 you are wasting your valuable retirement time with this … I know that you want to conquer this bugger but tell me something …. Is it really worth the struggle ??? Poke poke POKE 😀
by mozerd
Sun Feb 26, 2023 1:56 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 55331

Re: MikroTik hAP ax3 poor WiFi performance

So .what gear do you sell then?
My primary focus in gear is as follows all depending on circumstances:
Routing + Firewall : MikroTik, UBNT, Custom Build with OPNsense or Arista [untangle]
Wireless AP's : UBNT, TP-Link, Ruckus [CommScope]
Switches : Tik, UBNT, Cisco
by mozerd
Sat Feb 25, 2023 11:49 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 55331

Re: MikroTik hAP ax3 poor WiFi performance

People get addicted too fast to speed... And I'm not taking about that other thing. My clients expects 3 features …. And that is what I deliver 1. Stability 2. Performance 3. PERFORMANCE And that is in every aspect … In my market 90% have the very same expectation The mainframe/Terminal days of hor...
by mozerd
Sat Feb 25, 2023 3:36 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 55331

Re: MikroTik hAP ax3 poor WiFi performance

I have the Vodafone Pro II Ultrahub 6E MikroTik does not have any WiFi device that can compete with the Vodafone Pro II Ultrahub 6E. For excellent Router I suggest the RB5009 and for WiFi I suggest the TP-Link EAP660 HD ... this combination will provide excellent Routing and EXCELLENT WiFi equivale...
by mozerd
Fri Feb 24, 2023 2:18 pm
Forum: General
Topic: hEX as Standalone Wireguard Server
Replies: 25
Views: 2472

Re: hEX as Standalone Wireguard Server

My only contribution to this thread is JUST a reminder that WireGurad is not Rocket Science ,,, WireGuard is best utilized when YOU KISS it. There is no need to manage connections, be concerned about state, manage daemons, or worry about what's under the hood. WireGuard presents an extremely basic y...
by mozerd
Sun Feb 12, 2023 10:40 pm
Forum: General
Topic: Zerotier and Streaming
Replies: 42
Views: 9231

Re: Zerotier and Streaming

My question for the gurus, if I have a wireguard connection between two places or from iphone to home, what would adding zerotier bring to the mix that I cannot already do ?? It’s a virtual private switch in the cloud … so anything that you attach to that switch is now accessible For system integra...
by mozerd
Tue Feb 07, 2023 4:56 pm
Forum: General
Topic: Support for replacing OTHER enterprise manufacurer gear
Replies: 9
Views: 1252

Re: Support for replacing OTHER enterprise manufacurer gear

Until RouterOS 7 becomes actually STABLE I would not recommend the Tik Gear in Your Industry Sector ... Enterprise usage is dramatically different from SOHO usage from a reliability/performance perspective. Routing : SOHO - OK ..... Enterprise - NO Switching : SOHO - OK ..... Enterprise - ABSOLUTLY ...
by mozerd
Mon Jan 30, 2023 5:20 pm
Forum: RouterOS beta
Topic: Zerotier on CCR1xxx TILE?
Replies: 27
Views: 5710

Re: Zerotier on CCR1xxx TILE?

this makes it all easier and makes development faster
If that was true THEN your developers would have BGP/BFD done by now on 7.x .... and very surprising that it is not for ARM ...
by mozerd
Sat Jan 28, 2023 7:33 pm
Forum: General
Topic: Block Youtube on computers and smartphone apps
Replies: 85
Views: 23283

Re: Block Youtube on computers and smartphone apps

DPI (Deep Packet Inspection) is currently impossible to perform on standard encrypted payloads which is what almost all traffic is these days, thus you have just IP address and port number to play with. Also, there is no hardware that can crack today's encryption algorithms and decrypt traffic in r...
by mozerd
Sat Jan 28, 2023 5:24 pm
Forum: General
Topic: Block Youtube on computers and smartphone apps
Replies: 85
Views: 23283

Re: Block Youtube on computers and smartphone apps

@yahyamemeh MikroTik Routers and RouterOS cannot do Deep Packet Inspection [DPI] so any site that uses HTTPS:\\ [like YouTube, Facebook, etc.] cannot be inspected and blocked .... to do that you need to have the Router/Hardware capable of doing DPI efficiently without impacting performance greatly ....
by mozerd
Wed Jan 25, 2023 4:18 pm
Forum: General
Topic: How to monitor for attacks
Replies: 10
Views: 1867

Re: How to monitor for attacks

Perhaps you should consider MOAB blocks over 600 million Bad Guys from attacking your Internet » Here's how «
by mozerd
Mon Jan 23, 2023 12:44 am
Forum: General
Topic: Pros/Cons using RAW vs Filter [SOLVED]
Replies: 37
Views: 8495

Re: Pros/Cons using RAW vs Filter [SOLVED]

I disagree with your summary: this is not rocket science and the answer is very straightforward… Stateful firewalls are capable of monitoring and detecting states of all traffic on a network to track and defend based on traffic patterns and flows. Stateless firewalls, however, only focus on individu...
by mozerd
Sat Jan 07, 2023 10:19 pm
Forum: RouterOS beta
Topic: Feature Request: Zero Trust Tunnel - Cloudflare Version
Replies: 28
Views: 12223

Re: Feature Request: Zero Trust Tunnel

@anav … excellent suggestion and I agree that MT should fix the WG issue … long overdue …
by mozerd
Tue Jan 03, 2023 5:02 pm
Forum: General
Topic: CCR Frozen for electrical disconnection
Replies: 7
Views: 665

Re: CCR Frozen for electrical disconnection

First you need to protect the CCR from power outages by utilizing a Uninterrupted Power Supply otherwise known as a UPS ... A good quality UPS with AVR that will protect your CCR, Switches and ISP gear starts arround $1,000 or more depending on how many hours of uptime you expect from the UPSfor all...
by mozerd
Fri Dec 16, 2022 5:21 pm
Forum: Beginner Basics
Topic: Pi-Hole worth using?
Replies: 19
Views: 10563

Re: Pi-Hole worth using?

@ sirbryan over 40 million raspberry pi devices have been sold and very few are complaining that their SD memory cards are failing. Certainly it's happening but your experience is not that common. Would I put a Raspberry Pi board in a Enterprise environment --- ABSOLUTLY not -- but I certainly would...
by mozerd
Fri Dec 16, 2022 3:55 pm
Forum: Beginner Basics
Topic: Pi-Hole worth using?
Replies: 19
Views: 10563

Re: Pi-Hole worth using?

Please accept my apology for using the term "Bogging" .... it was far too harsh of a term ... what I should have used is 'additional strain" .... regardless if only one container is used THEN that strain will be negligible 4 sure .... I am far more concerned with the security implicat...
by mozerd
Thu Dec 15, 2022 12:50 pm
Forum: Beginner Basics
Topic: Pi-Hole worth using?
Replies: 19
Views: 10563

Re: Pi-Hole worth using?

I do recommend PiHole + Unbound and I also recommend that PiHole + Unbound be installed on a Raspberry Pi Zero I do not believe that you will have performance improvement but you will have much better privacy and better control over unsolicited ads coming into your network. Containers are very nice ...
by mozerd
Fri Dec 09, 2022 11:10 pm
Forum: General
Topic: Enabling also IPv6 in RouterOS [SOLVED]
Replies: 2
Views: 1745

Re: Enabling also IPv6 in RouterOS [SOLVED]

Using Winbox Check under system/packages then you should see ipv6 … enable this then reboot …
by mozerd
Sun Nov 27, 2022 8:05 pm
Forum: Beginner Basics
Topic: SSTP vs. WireGuard
Replies: 9
Views: 2829

Re: SSTP vs. WireGuard

My recommendation is to use WireGuard because it is VERY secure and performance is outstanding …
by mozerd
Sun Nov 27, 2022 12:45 pm
Forum: Beginner Basics
Topic: SSTP vs. WireGuard
Replies: 9
Views: 2829

Re: SSTP vs. Watchguard

Which Model of WatchGuard are you comparing to the MikroTik CCR1016-12S-1S+ ? WatchGuard are typically purchased for their UTM capability ... but WatchGuard can be purchased without the UTM License .... MikroTik do not have UTM capability in any way shape or form .... WatchGuard Firewall is excellen...
by mozerd
Fri Nov 18, 2022 6:47 pm
Forum: Containers
Topic: Unbound container setup
Replies: 6
Views: 10290

Re: Unbound container setup

You should install Pi and unbound into one container … a much better approach.

https://github.com/chriscrowe/docker-pi ... -container
by mozerd
Thu Oct 06, 2022 6:11 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 73718

Re: v7.5 [stable] is released!

Hi mozerd, can you confirm its easy to implement 2FA with tailscale, vice wireguard which seems to be a bit of a challenge. Greetings anav When you establish an account with Tailscale you are provided with a number of options including the most popular 2FA identity provider like google, Microsoft T...
by mozerd
Sun Oct 02, 2022 4:52 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 73718

Re: v7.5 [stable] is released!

If we need to start doing netinstalls before sending them out in the field... I wanna see a big f--king warning on the top of EVERYTHING from the Mikrotik domain. @gotsprings .... My speculation is that over the last 2 years many personnel changes have take place in the Tik developer domain so the ...
by mozerd
Sat Sep 24, 2022 5:58 pm
Forum: RouterOS beta
Topic: Feature Request NAT-PMP
Replies: 18
Views: 13787

Re: Feature Request NAT-PMP

+1 for PCP

This one is very important to include under ROS …..
by mozerd
Fri Sep 02, 2022 7:05 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 73718

Re: v7.5 [stable] is released!

How is Disk2 and Disk3 connected?
You only seem to have one usb device connected with one partition.
Good catch Znevna …. In fact disk3 is microSD card and disk2 is microUSB …..
by mozerd
Fri Sep 02, 2022 5:18 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 73718

Re: v7.5 [stable] is released!

CCR1009 ... upgrade from 7.4.1 to 7.5 stable Under Winbox v3.37 Disks do not show the installed number of Disks .... attached image shows that under Files does show the proper number of disks but under Disks only 2 disks are visible disks.GIF Disk2 is USB and named Disk2 but as shown in screen shot ...
by mozerd
Tue Aug 16, 2022 1:34 pm
Forum: Announcements
Topic: Newsletter 107
Replies: 50
Views: 28029

Re: Newsletter 107

@normis This newsletter has very exciting devices especially the ax stuff ... IMO the Chateau LTE18 ax AND the Chateau 5G ax will be a real winners assuming RoS7.x and the ax drivers are truly in effective sync when out the door and in the hands of the consumer. BTW, the Linux Kernel is now in v6 RC...
by mozerd
Sat Aug 13, 2022 2:47 am
Forum: General
Topic: A place for poetry
Replies: 63
Views: 248119

Re: A place for poetry

Here I site broken hearted
Paid my dime and only started
My Tik would not boot
RoS 7 to the rescue
Darn it it only farted
by mozerd
Sat Aug 13, 2022 12:33 am
Forum: RouterBOARD hardware
Topic: hAP ax² dual band Wi-Fi 6 (802.11ax)
Replies: 287
Views: 71246

Re: hAP ax² dual band Wi-Fi 6 (802.11ax)

….. nobody is going to run containers on it.
The hAP ax2 was designed for the home user and not the Network nerd ….
by mozerd
Fri Aug 12, 2022 1:31 pm
Forum: Beginner Basics
Topic: Is MikroTik a good start for a complete noob?
Replies: 10
Views: 2845

Re: Is MikroTik a good start for a complete noob?

I am working on building up my home network. I was all set to press "buy" on a $2k Ubiquiti setup (home network and NVR) until the wife shot that down. For a person like you the Ubiquiti UDM-Pro setup etc. is the proper solution ... complete hassle free and will work just GREAT. If you do...
by mozerd
Sat Aug 06, 2022 4:47 pm
Forum: General
Topic: How to prevent random SIP attacks on default port 5060
Replies: 36
Views: 5331

Re: How to prevent random SIP attacks on default port 5060

@tahmidul I provide a VoIP Blacklist service that has successfully prevented SIP Attacks in 99% of cases ... there is a 10 day free trial period available ... see my sig. My current voipTIK blacklist list contains 39K+ IP addresses ... in your case you will need to whitelist all your core servers fo...
by mozerd
Wed Aug 03, 2022 3:19 pm
Forum: Wireless Networking
Topic: Early For April Fools, Mikrotik WIFI 6
Replies: 6
Views: 994

Re: Early For April Fools, Mikrotik WIFI 6

I just tried to buy the hAP ax2 from ISP Supplies for testing but they do not show this device in inventory ..... the very same for Baltic Networks etc.
by mozerd
Sun Jul 31, 2022 10:24 pm
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 6885

Re: Should I switch my APs from Ubiquiti to MT

No you should not switch … Ubiquiti are excellent AP’s …. If you want another suggestion TP-Link EAP245 or EAP660HD are outstanding AP’s. The only MT wireless device I do at times suggest is the Audiance other than that the othe Tik AP’s suck. Unifi is a system … so to exploite that system everythin...
by mozerd
Sat Jul 30, 2022 1:18 pm
Forum: General
Topic: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN
Replies: 55
Views: 22419

Re: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN

@anav Pro Custodibus also have a Docker Container. https://hub.docker.com/r/procustodibus/agent and some very good info by Pro Custodibus on containers .... https://www.procustodibus.com/blog/2021/11/wireguard-containers/ I have no idea how this impacts Tik memory .... What I like about Pro Custodib...
by mozerd
Fri Jul 29, 2022 3:17 pm
Forum: General
Topic: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN
Replies: 55
Views: 22419

Re: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN

@Znevna
I was not aware of the TailScale official container [excellent] .. thank you for posting the info ...
by mozerd
Fri Jul 29, 2022 2:45 pm
Forum: General
Topic: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN
Replies: 55
Views: 22419

Re: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN

My point is that they adopted zerotier but it has limited applicability, not all MT devices can run it. If tailscale can run on more devices, then it should be adopted if they are relatively equal otherwise. Let the user decide which package they want to load! There is an active Tik user [cannot re...
by mozerd
Mon Jul 25, 2022 3:28 pm
Forum: General
Topic: Router Suggestion for Serviced Office
Replies: 13
Views: 1070

Re: Router Suggestion for Serviced Office

Which of these devices is the best for this type of setup: 1. RB1100AHX4 2. CCR2004-16G-2S+ 3. CCR1009-7G-1C-1S+ Can you recommend which one is the best router for our setup. From the above 3 you selected I would suggest the CCR1009-7G-1C-1S+ .... this will be an excellent choice .... I also sugges...
by mozerd
Fri Jul 22, 2022 3:30 pm
Forum: Announcements
Topic: v7.4 [stable] is released!
Replies: 224
Views: 59692

Re: v7.4 [stable] is released!

Netinstall is not working.
You may need to run Netinstall 5 or 6 times ... and switch Netinstall to 1 version lower ..... that's been my experience with Netinstall on some version of Tik devices.
by mozerd
Tue Jul 19, 2022 1:03 pm
Forum: Announcements
Topic: v7.4rc is released!
Replies: 116
Views: 32509

Re: v7.4rc is released!

The talk about an "entirely new routing engine" already started ~10 years ago, when the mythical v7 was introduced that would solve all our problems and fulfill all our wishes. I believe that when MT Developers adopted the newer Linux Kernel [the very heart of the OS ] for version RoS v7 ...
by mozerd
Sun Jul 17, 2022 1:26 pm
Forum: Wireless Networking
Topic: Best wireless AP for 500-1000 mbit MT connection.
Replies: 35
Views: 4307

Re: Best wireless AP for 500-1000 mbit MT connection.

@PKSpeleo The following is my suggestion for YOU that will work well with the RB5009 you are considering ... your wireless Clients [all of them] that are capable can achieve between 600 - 800 Mbps TP-Link EAP660 HD AX3600 Gigabit Dual Band WiFi 6 WLAN Access Point. Integrated in Omada SDN: Critical ...
by mozerd
Sat Jul 16, 2022 4:33 pm
Forum: Wireless Networking
Topic: Best wireless AP for 500-1000 mbit MT connection.
Replies: 35
Views: 4307

Re: Best wireless AP for 500-1000 mbit MT connection.

"rextended" has gone awry and starts abusing his forum admin privileges. He comments on other people writing things that MikroTik never have said are not allowed, and is editing other people's post to remove such things. He attacks others for writing the truth about some MikroTik problems...
by mozerd
Sat Jul 02, 2022 11:50 pm
Forum: General
Topic: DNS request through wireguard
Replies: 57
Views: 8330

Re: DNS request through wireguard

@mozerd
Did you copy-paste your post? Perhaps a more relevant proverb in English is 'All roads lead to Rome".
Yes, in fact I did.
BTW, very beautiful women live in the mountains of Iran and love their cooking skills …
https://youtu.be/vMeQ1oSixIU
by mozerd
Sat Jul 02, 2022 8:40 pm
Forum: General
Topic: DNS request through wireguard
Replies: 57
Views: 8330

Re: DNS request through wireguard

There is a proverb in Persian "هر جا بری آسمون همین رنگه" (Wherever you go, the sky is the same color). Publius Ovidius Naso The concept of the proverb can be traced as far back as the poetry of Publius Ovidius Naso, better known as Ovid (43 BC – 17 AD), who wrote Fertilior seges est alen...
by mozerd
Fri Jun 17, 2022 11:02 pm
Forum: RouterBOARD hardware
Topic: Any plans for a small size SoHo router managing Gigabit WAN capacity?
Replies: 19
Views: 2720

Re: Any plans for a small size SoHo router managing Gigabit WAN capacity?

+1 for the hEX OR hEX S … excellent router ….
by mozerd
Fri Jun 10, 2022 7:12 pm
Forum: Beginner Basics
Topic: Is MikroTik good for home use?
Replies: 28
Views: 10402

Re: Is MikroTik good for home use?

There are some downsides, sort of. You can do more, but in order to do so, you need to know more, or be willing to learn a bit. And also be careful, because if you decide to shoot your own foot, system will be happy to help, meaning that it won't say "no". But there's no need to be too sc...
by mozerd
Fri Jun 10, 2022 5:38 pm
Forum: Beginner Basics
Topic: Is MikroTik good for home use?
Replies: 28
Views: 10402

Re: Is MikroTik good for home use?

Absolutely, if you're good to face some pretty hard challenges when things doesn't work as expected (for a regular SOHO user that is). The very same can be said for any so called consumer brand device like Netgear, TP-Link, Asus, D-Link. etc. regardless of the fact that all these brands are PHD . P...
by mozerd
Fri Jun 10, 2022 3:36 pm
Forum: Beginner Basics
Topic: Is MikroTik good for home use?
Replies: 28
Views: 10402

Re: Is MikroTik good for home use?

Need Wifi, the house is not very big - 3 bedrooms. 3 gadgets (tablets and laptop). Internet is needed for everyday use, Watching movies, sometimes working from home. @Marvinjul, you need to provide much more info: 1 ... Where are you located [USA, Canada, Europe, Middle East etc.] 2 ... What speed ...
by mozerd
Fri Jun 10, 2022 3:14 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 86907

Re: v7.3 and v7.3.1 [stable] is released!

Most of times when we receive such reports simply router/switch have a too complex configuration in order to run RouterOS, process traffic, and do everything that is configured on the device. The beauty of RouterOS is that we do not limit you with random limitations, but at the same time you have t...
by mozerd
Wed Jun 08, 2022 12:23 am
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5665

Re: v7.3 [stable] is released!

@DarkeNate The 2 parts that make up the solution for Tik gear is: 1… The functional software that drives the capability 2… The Firmware [drivers] that enables the functional software to exploit the capability So When upgrading it’s MANDATORY to always do both parts sequentially otherwise the capabil...
by mozerd
Thu May 26, 2022 2:45 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 86882

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

@Larsa IMO I believe that Tik management understand the cost equation ... the more people you hire in mgmt positions the les comparative you will become.. MikroTik are doing a GREAT Job with the resources they do have --- consequently very competitive and an unbeatable value proposition to boot. But...
by mozerd
Wed May 25, 2022 1:21 am
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

That was a bit unfair since hell will freez to ice already tomorrow and I don't really have time to fix it. : )
@Larsa, without one shadow of doubt I really like your sense of humor …. :lol:

Are you a ZT employee?
by mozerd
Tue May 24, 2022 11:51 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

Still waiting for that "right" config LOL
Hell will freeze over before @Larsa will provide that “right” config for you …. simplicity, performance, reduced costs ONLY in Larsa’s dreams.
by mozerd
Tue May 24, 2022 9:52 pm
Forum: Beginner Basics
Topic: Road Warrior Config by the Network Berg
Replies: 5
Views: 1112

Road Warrior Config by the Network Berg

Outstanding WireGuard Video by the one and only Network Berg
Using RoS 7.2.3
https://m.youtube.com/watch?v=CH10spRyG ... e=youtu.be
by mozerd
Tue May 24, 2022 7:09 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

So ZeroTier cannot meet ANY of those 3 CRITICAL advantages.

TZ meets all these requirements by definition.
@Larsa … word games do not work ?.. but you can dream all you want because in dreams everything is possible.
by mozerd
Tue May 24, 2022 7:03 pm
Forum: Wireless Networking
Topic: Compatible APs?
Replies: 23
Views: 6674

Re: Compatible APs?

Yeah shied away from netgear ….. Netgear Orbi is the finest WiFi on earth without exception …. No need to shy away …. I do not like Netgear dedicated AP’s just yet but if they move their AP line to to the Orbi TECH then that will be my go to line … however Orbi is very expensive … but if one want t...
by mozerd
Tue May 24, 2022 5:05 pm
Forum: Wireless Networking
Topic: Compatible APs?
Replies: 23
Views: 6674

Re: Compatible APs?

I certainly will endorse the use of Ubiquiti U6 AP's and the Ubiquiti GenKey Controller ... will work very nicely with Any Tik Router. The only problem with Ubiquiti U6 AP's is that they are very difficult to get since they sell out very fast -- faster than a speeding bullet. My second choice is the...
by mozerd
Tue May 24, 2022 12:39 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

Of course there might be advantages to other alternatives, but at the moment ZT is the only available solution for Mikrotik (so far). So ZeroTier cannot meet ANY of those 3 CRITICAL advantages ..... otherwise you @Larsa would be singing from the Tree Tops :) To bad that TailScale is not integrated ...
by mozerd
Tue May 24, 2022 11:22 am
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

When it comes to SD-WAN, I think there are other important factors to take into account than just pure speed. Benefits of SD-WAN SD-WAN offers many benefits to geographically distributed organizations, including: Simplicity : Because each device is centrally managed, with routing based on applicati...
by mozerd
Tue May 24, 2022 12:30 am
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

There are plenty of other more more in depth and serious tests than this one IMHO. @Larsa … IMHO Netmaker test are COMPREHENSIVE and very credible …. I do not understand why YOU would think otherwise … why because my comparison made some time ago showed TailScale being FAR superior to ZeroTier … by...
by mozerd
Sat May 21, 2022 3:28 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

What gives?
Just for You @Znevna
Battle of the VPNs: Which one is fastest? (speed test)
Perhaps you can learn something from Netmaker .... :)
by mozerd
Sat May 21, 2022 1:42 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

...... I have all the time in the world and don't have a stop button. :-) @anav The following mikrotik ZeroTier document has very extensive information on howto configure ZeroTier to work in the kind of scenario you want ... the complexity is not trivial perhaps because it cannot be so but I 4 1 am...
by mozerd
Fri May 20, 2022 7:42 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

Since I'm always right, there is really no reason for me to make an argument. ;-) @Larsa .... so YOu do not want to prove it ..... shame shame shame and a smart fellow like you could easily help @anav to prove that you are RIGHT. Common Larsa help our fellow guru use ZeroTier ... show your expertis...
by mozerd
Fri May 20, 2022 1:53 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

@Larsa SAID: And it's a proven fact, whatever you say! ;-) OK I will bite ... Prove it that ZeroTier is easier to administer .... provide @anav with the solution to his ZeroTier dilemma ! BTW, I did forget to mention that WireGuard is integrated into the current Linux Kernel plus WireGuard is avail...
by mozerd
Thu May 19, 2022 9:39 pm
Forum: Beginner Basics
Topic: ZeroTier SD-WAN / Network Orchestration [SOLVED]
Replies: 37
Views: 8148

Re: ZeroTier SD-WAN / Network Orchestration [SOLVED]

TILE
ZeroTier is NOT available on the Tile architecture……

WireGuard is faster, better and works GREAT ….
by mozerd
Tue May 17, 2022 5:14 pm
Forum: Beginner Basics
Topic: Need product recommendation
Replies: 9
Views: 1506

Re: Need product recommendation

Can your ISP provided Router operate in BRIDGE mode?
What Bandwidth does your ISP provide you and is that throughput symmetrical or asymmetrical?
How many users will you need to support?
by mozerd
Sat May 14, 2022 5:08 pm
Forum: General
Topic: Wireguard VPN
Replies: 13
Views: 2780

Re: Wireguard VPN

Yes, but I cannot help if you requirements are wishy washy. Detailed clear requirements I can work with and a config that is cleaned up and organized is much more conducive to problem solving ......... .......... If you get organized, gladly will help. otherwise its not productive. Amen brother AME...
by mozerd
Mon May 09, 2022 1:45 pm
Forum: General
Topic: Securing a small network
Replies: 27
Views: 3845

Re: Securing a small network

Regular office, ......
If the Office is high security then measures can be taken to protect the nodes etc ... it all depends on the budget and network access control via Network Intrusion Detection systems ...
Money and knowledge determines what will be done.
by mozerd
Mon May 09, 2022 12:25 pm
Forum: General
Topic: Securing a small network
Replies: 27
Views: 3845

Re: Securing a small network

@Sob
Nope. Let me clarify ... Router. Switches are in secure area. If Zero Trust then Cameras are used to monitor and staff are properly trained. The security paradigm can be as tight as budget allows.
by mozerd
Mon May 09, 2022 2:15 am
Forum: General
Topic: Securing a small network
Replies: 27
Views: 3845

Re: Securing a small network

@tangent Yes I understand but I will not accept poor security disciplines …. I made that clear earlier. Physical device security is a must as is credential security. If the business cannot afford effective security disciplines no amount of technical hoops will prevent rogue intentions who gain physi...
by mozerd
Sun May 08, 2022 11:33 pm
Forum: General
Topic: Securing a small network
Replies: 27
Views: 3845

Re: Securing a small network

@rules
For VPN I strongly suggest WireGuard … you do not need certificates …. You do not need VPN for internal … VPN for road worrier on demand only … use Radius only if you have mission critical otherwise it’s overkill … mission critical where money or valuable secrets …..
by mozerd
Sun May 08, 2022 9:20 pm
Forum: General
Topic: Securing a small network
Replies: 27
Views: 3845

Re: Securing a small network

@rules Lots of stuff others have provided. My suggestion is KISS … keep it simple …. Unless you have a handle on your network users requirements in line with the bosses objectives you will run into trouble. Once requirements are understood the rest is easy since the objectives must match the capabil...
by mozerd
Sat May 07, 2022 2:17 pm
Forum: General
Topic: Securing a small network
Replies: 27
Views: 3845

Re: Securing a small network

MikroTik provide some very good guidance in the following link Securing your router
And pay specific attention to the subsections Titled:
Building Your First Firewall
Building Advanced Firewall

Another excellent source that you will find may be helpful The DEFACTO DEFAULT FIREWALL Setup
by mozerd
Thu May 05, 2022 3:47 pm
Forum: General
Topic: RB4011 together with ASUS RT-AX89X
Replies: 8
Views: 2231

Re: RB4011 together with ASUS RT-AX89X

hahahaha, how big is your house? Two TPLINKS could do the same job ;-PP 1665 sq ft with a detached garage. Most of the house is covered from the AP here in the family room (very back wall of the house). There is an outdoor AP on the front wall of the house under the eve. It's there primarily for th...
by mozerd
Thu May 05, 2022 2:41 am
Forum: General
Topic: RB4011 together with ASUS RT-AX89X
Replies: 8
Views: 2231

Re: RB4011 together with ASUS RT-AX89X

You should place the Asus in AP mode only … this turns of the NAT and router functions of the Asus. Then you can exploit the Ethernet ports on the Asus … the WiFi of the Asus will become available to everyone on your network … in AP mode you can exploit the Asus WAN port … it just becomes another Et...
by mozerd
Tue May 03, 2022 11:16 pm
Forum: General
Topic: Best ACCESS POINT
Replies: 12
Views: 2962

Re: Best ACCESS POINT

@balancer For reliable wifi that can fully exploit your bandwidth for all your users the only mikrotik product I can recommend is the Audience using the wifi2 drivers running under RoS 7. The very best wifi currently is made by Netgear called the Orbi but it is expensive …after the Orbi I suggest TP...
by mozerd
Tue May 03, 2022 1:17 pm
Forum: General
Topic: 3rd party say he can log into my router using default credentials.
Replies: 5
Views: 874

Re: 3rd party say he can log into my router using default credentials.

If the 3rd party cannot produce evidence that they were able to access your router(s) THAT is all the evidence you need. If the 3rd party is using a backdoor and you are not aware of that backdoor into the router there is nothing that you can do --- according to MikroTik no backdoor exists or has be...
by mozerd
Sun May 01, 2022 4:34 pm
Forum: General
Topic: Wireguard slow speed
Replies: 39
Views: 13157

Re: Wireguard slow speed

@holvoetn assessment is 100% correct. Throughput is always subject to the weakest link plus ISP idiosyncrasies Symmetrical connections enjoyed by both PEERS under WireGuard will under excellent circumstance provide 90% or better performance of the subscribed bandwidth assuming peers are capable. Asy...
by mozerd
Tue Apr 26, 2022 2:56 am
Forum: Wireless Networking
Topic: Wireless interface (wlan1) not present at CCR1009 MikroTik Router
Replies: 3
Views: 1158

Re: Wireless interface (wlan1) not present at CCR1009 MikroTik Router

First you must purchase the TP-Link EAP660HD Wireless Access Point ... mount that in your ceiling of your venue as central as possible ... now run a Cat6 Ethernet Cable from the EAP660HD to the location of your CCR1009 and connect that Cable to either5 .... once connected to either5 on your CCR1009 ...
by mozerd
Wed Apr 20, 2022 1:05 am
Forum: Wireless Networking
Topic: WiFi with Apple Products
Replies: 102
Views: 39760

Re: WiFi with Apple Products

I have 4 Apple Extreme WiFi Routers connected to hAP AC2 in client sites … all work well 1. Make sure that you Apple wireless Router is in bridge mode In all my cases the Tik device has its WiFi disabled …. For WiFi strictly relying on the Apple WiFi. The reason the Extreme WiFi is far superior to t...
by mozerd
Wed Apr 13, 2022 12:51 am
Forum: General
Topic: IPv6 and NAT - how I changed my mind
Replies: 59
Views: 32345

Re: IPv6 and NAT - how I changed my mind

@msatter My knowledge oh Hotmail/Live is very poor so I cannot answer to those specific services … office 365 and all other Windows systems provide 100% support for ipv6 …. 90% of US government mail systems are now ipv6 …. Where MS now has a dominate position by 2023 all US government depts will be ...
by mozerd
Tue Apr 12, 2022 9:57 pm
Forum: Beginner Basics
Topic: Remote management on WAN
Replies: 22
Views: 6016

Re: Remote management on WAN

@anav The admin wants to eliminate the threat posed by the WAN and the Winbox Port … by not allowing any “outside” connection to hit that port no need to change the default port. VPN on the other hand provides the needed security and path for “trusted devices” so that any interface inside can be acc...
by mozerd
Tue Apr 12, 2022 6:38 pm
Forum: General
Topic: IPv6 and NAT - how I changed my mind
Replies: 59
Views: 32345

Re: IPv6 and NAT - how I changed my mind

As of March 2022, according to Google, the IPv6 adoption rate globally is around 34%, but in the U.S. it’s at about 46%.

What is IPv6, and why is adoption taking so long?
by mozerd
Tue Apr 12, 2022 5:31 pm
Forum: Beginner Basics
Topic: Remote management on WAN
Replies: 22
Views: 6016

Re: Remote management on WAN

The llama has arrived...... ...... add chain=input action=accept in-interface-list=Trusted dst-port=winboxport protocol=tcp src-address-list=authorized My suggestion for this rule is as follows: add chain=input action=accept in-interface-list=!WAN dst-port=8291 protocol=tcp src-address-list= Truste...
by mozerd
Sat Apr 09, 2022 7:08 pm
Forum: General
Topic: clickbite: How do members of the Forum feel about this article?
Replies: 54
Views: 4800

Re: How MikroTik Routers Became a Cybercriminal Target

By the way unlike most Canadians, I would have put our troops side by side with Ukranians as soon as the border was crossed so no I am not an average Cdn, like yourself sitting in their comfy homes 1000s. of miles from danger, much like we were when General Dallaire was begging for help in Rwanda a...
by mozerd
Fri Apr 08, 2022 7:06 pm
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 56
Views: 47773

Re: NEWSLETTER 105

The new masthead is very professional and LOOKS G R E A T
by mozerd
Thu Apr 07, 2022 4:36 pm
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 56
Views: 47773

Re: NEWSLETTER 105

The new masthead is very cool :)

The LHG LTE18 kit .... when will this become available?
TheNewTik.gif
by mozerd
Tue Apr 05, 2022 6:25 pm
Forum: General
Topic: Which product can support at least 200 hotspot users?
Replies: 16
Views: 3136

Re: Which product can support at least 200 hotspot users?

non-critical social media activity, no VOIP / no gaming.
It's not strictly simultaneous, just typical coffee shop free wifi activities.
The hEX will serve for your purposes as the Router.

The following Internet Data Usage Guide should be of interest to you ....
by mozerd
Tue Apr 05, 2022 6:15 pm
Forum: General
Topic: Which product can support at least 200 hotspot users?
Replies: 16
Views: 3136

Re: Which product can support at least 200 hotspot users?

I am looking for a router that can support at least 200 simultaneous hotspot users, is hAP lite good enough for this? 200 simultaneous hotspot users ---- simultaneous ---- means occurring, operating, or done at the same time ... What activity will these 200 simultaneous users be involved in? And do...
by mozerd
Tue Apr 05, 2022 5:45 pm
Forum: General
Topic: clickbite: How do members of the Forum feel about this article?
Replies: 54
Views: 4800

Re: How MikroTik Routers Became a Cybercriminal Target

My opinion: How MikroTik Routers Became a Cybercriminal Target ? Simply: is the best software for routers and can do many things than the other competitoirs can not do or price/features is too high... How Microsoft Windows Became a Cybercriminal Target ? Simply: Is the most simple and used OS... Ye...
by mozerd
Mon Mar 28, 2022 2:12 pm
Forum: RouterBOARD hardware
Topic: Mikrotik hardware shortage - official statement?
Replies: 36
Views: 8666

Re: Mikrotik hardware shortage - official statement?

China has everyone [mfgs & vendors] by the short hairs ... geopolitics is causing a very significant realignment so until that is sorted out China will use all of its commercial weapons' to gain the upper hand. Since EVERYONE in this game relied on the very cheap labour that China offered and de...
by mozerd
Wed Mar 23, 2022 6:24 pm
Forum: RouterOS beta
Topic: WIREGUARD Routes & DNS Resolve
Replies: 2
Views: 3515

Re: WIREGUARD Routes & DNS Resolve

@anav Errr --- you mean the ("Peer" server) -- right? why? because WG is a p2p protocol :) Which version of Linux is under the RoS hood? Me thinks its 5.6 but I am not 100% sure .... Does RoS run independently of Linux or does it rely on Linux but uses its own abstraction to run Linux so t...
by mozerd
Wed Mar 23, 2022 5:40 pm
Forum: Announcements
Topic: v7.2rc5 is released!
Replies: 91
Views: 26025

Re: v7.2rc5 is released!

Do you also update the MT Apps in RC releases ( like missing allowed IP addresses in peer settings )?
*) ios app - text
Many many data fields are not populated with the MT App under IOS on my iPhone ... far too many to take pics .... I do not think that MikroTik look at this frequently.
by mozerd
Wed Mar 23, 2022 4:36 pm
Forum: RouterOS beta
Topic: Wireguard use Hostname in endpoint
Replies: 63
Views: 22735

Re: Wireguard use Hostname in endpoint

The WireGuard Tools script addresses the following scenario When the WireGuard interface of the ("Peer" client) starts up, it will resolve the DNS record for myvpn.myddns.com , and select one of the IP addresses to use as its endpoint for the ("Peer" server). Let’s say it selects...
by mozerd
Wed Mar 23, 2022 3:35 pm
Forum: RouterOS beta
Topic: Wireguard use Hostname in endpoint
Replies: 63
Views: 22735

Re: Wireguard use Hostname in endpoint

The only built-in way for a WireGuard ("Peer" client) to detect a change to an endpoint’s IP address is if the endpoint proactively initiates a connection to the ("Peer" client) from its new IP address (which NAT or other firewall rules make impossible in a typical ("Peer&qu...
by mozerd
Tue Mar 22, 2022 9:49 pm
Forum: Wireless Networking
Topic: Future owner(?) of hAP ac3
Replies: 18
Views: 2336

Re: Future owner(?) of hAP ac3

I suggest you consider the MikroTik RB5009 as your router. I do no recommend Tik wireless because they generally underperform … for your wireless and based on your network diagram the TP-Link EAP660HD will provide excellent wireless performance to all your wireless devices. RoS supports vlans and al...
by mozerd
Mon Mar 21, 2022 4:23 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

@mozerd: The part you keep missing is that while WG may be peer-to-peer "at heart", ............ it's clearly client-server behaviour. @Sob ... I believe you are brilliant .... as is mkx .... and anav is very smart :) If its Pure WG Lets not call it C/S .... lets call it a communication r...
by mozerd
Mon Mar 21, 2022 3:56 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

Everyone is a peer The Author is Vladimír Záhradník .... my type of tech guy :) ------------------------------------------------------- In WireGuard, there is no client-server relationship. WireGuard introduces a concept of peers, which are interconnected clients, and by definition, there is no sup...
by mozerd
Sun Mar 20, 2022 8:07 pm
Forum: General
Topic: NAT in output chain for Wireguard [SOLVED]
Replies: 13
Views: 5902

Re: NAT in output chain for Wireguard [SOLVED]

In the Tik world WG has 2 states for Routing Table … either off or by default on …. When the WG interface has a IP address Routes are added automatically … when the WG interface does not have IP address assigned Table is off and you must add routes manually. [edit] forgot to mention that cryptokey r...
by mozerd
Sun Mar 20, 2022 6:28 pm
Forum: General
Topic: NAT in output chain for Wireguard [SOLVED]
Replies: 13
Views: 5902

Re: NAT in output chain for Wireguard [SOLVED]

@anav: The idea with routes was inspired by @mozerd, poor guy now has constant nightmares that WG in RouterOS is incomplete, so this option would save him, and it's true that I saw other people miss adding routes before.
@Sob .... :lol:
Understanding modern Linux routing (and wg-quick)
by mozerd
Thu Mar 17, 2022 7:10 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

What a shame that MikroTik did not integrate WireGuard completely—- by taking advantage of every aspect provided by its creator. Every Linux disto that includes WireGuard takes complete advantage of the Donenfeld creation except RoS. Yes, the Donenfeld wg tools that for example effectively generate ...
by mozerd
Tue Mar 15, 2022 2:25 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

In Winbox Tools and using the Ping tool if no static route is added for 10.10.50.99 in my test scenario 10.10.50.99 is pingable but as soon as a static route is added 10.10.50.99 becomes host unreachable ….. why? Because you're trying to take torch from @anav and continue his previous adventure. ;)...
by mozerd
Mon Mar 14, 2022 11:26 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

One other very interesting observation In Winbox Tools and using the Ping tool if no static route is added for 10.10.50.99 in my test scenario 10.10.50.99 is pingable but as soon as a static route is added 10.10.50.99 becomes host unreachable ….. why? Yes in the configuration all subnets are isolate...
by mozerd
Mon Mar 14, 2022 9:59 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

@larsa I agree that it’s cryptic … I also believe that RoS fully supports WireGuard but a lot of the stuff like the Tools the Donenfeld provides with WireGuard is encapsulated within RoS otherwise allowed IPs would not work the way that is expressed in the WireGuard docs. A very simple test for exam...
by mozerd
Mon Mar 14, 2022 7:44 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

I have contacted MikroTik and requested information as to how the Following WireGuard fundamental Principle is supported in RoS .... When I receive a response I will post it here assuming that they will permit me doing that. Today I received a response from MikroTik …. Cryptokey routing is fully su...
by mozerd
Sat Mar 12, 2022 11:20 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

@anav
Very sorry but I can no longer recommend your link because I absolutely disagree with your wg approach …..
by mozerd
Sat Mar 12, 2022 7:20 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

I hope you can see now where your thinking went off the rails..................
Goodness Gracious Great Balls of Fire .... @anav -- The configuration Guru is back and kicking .... :)
by mozerd
Sat Mar 12, 2022 6:51 pm
Forum: Beginner Basics
Topic: WireGuard: allowed IPs - Unofficial WireGuard Documentation
Replies: 112
Views: 62010

Re: WireGuard: allowed IPs - Unofficial WireGuard Documentation

@Larsa ... I ABSOLUTLY agree with you 100% :)