Community discussions

MikroTik App

Search found 11511 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 39
by sindy
Sun Apr 13, 2025 3:55 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 18
Views: 508

Re: Using CRS326 as a switch

1) if a single IP address is sufficient for the device to do all what you want it to do, the davice acts as a bridge (switch). You may want to access it for management purposes using multiple IP addresses, but another own IP address must not be required to facilitate forwarding of packets/frames fro...
by sindy
Sun Apr 13, 2025 2:54 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 18
Views: 508

Re: Using CRS326 as a switch

My question can be reformulted or restated as: How to I ensure that a CRS ROS configuration is such that the CRS is used as a cloud router SWITCH ? The answer to that question has already come from @mkx - if everything works as required while there is only a single IP address up on the CRS326, it o...
by sindy
Sun Apr 13, 2025 2:31 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 18
Views: 508

Re: Using CRS326 as a switch

The distinction between bridging and routing indeed lays solely in what information is used to determine where to forward the frame/packet. DHCP is not routing, any kind of VPN handling is not routing; even traffic filtering is, strictly speaking, not routing (you may filter bridged traffic and you ...
by sindy
Sun Apr 13, 2025 1:36 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 18
Views: 508

Re: Using CRS326 as a switch

A networking device can take various header fields of an Ethernet frame and of the packet it carries into account when making a decision where to forward that frame. If it only chooses the output interface based on the destination MAC address and, possibly, VLAN ID of the incoming frame, it handles ...
by sindy
Sun Apr 13, 2025 12:51 pm
Forum: General
Topic: Replacing RB2011UiAS-2HnD with hAP ax lite LTE6?
Replies: 5
Views: 352

Re: Replacing RB2011UiAS-2HnD with hAP ax lite LTE6?

Making the assumption the OP has 5G in their area, or is likely to have in the future. There are still many areas where 5G isn't available and isn't likely to eventuate anytime soon, mainly in rural or small towns. For the telecom operators and network providers, it is way cheaper to upgrade the eq...
by sindy
Sat Apr 12, 2025 7:29 pm
Forum: General
Topic: Weird internet problems with Ax-Lite and NordVPN [SOLVED]
Replies: 18
Views: 1101

Re: Weird internet problems with Ax-Lite and NordVPN [SOLVED]

You have to move the action=none policy before (above) the template from which the actual policy is generated dynamically. The dynamically generated policies are placed right next to the templates they are created from, so if you place the action=none policy between the template and the dynamically ...
by sindy
Sat Apr 12, 2025 7:12 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 11
Views: 622

Re: hAP AC2 vs. AX2...

if they're exposed to high temp, sunlight, vapors (anything greasy and especially apolar solvents) ... but they were kept in relatively sane places. Regarding age, the affected one is from the initial series that still had the 256 MB RAM. As for the environment, it has always been in a living room,...
by sindy
Sat Apr 12, 2025 1:23 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 11
Views: 622

Re: hAP AC2 vs. AX2...

And the ax2 doesn't have the touchy-feely (polyurethane?) coating. (nor does the hAP ac lite-TC). Which is actually great, because in a few years, the moleskin layer turns out into the same sticky mess the thickier rubberish soft coats normally do. I liked the moleskin feel very much too until I've...
by sindy
Sat Apr 12, 2025 1:14 pm
Forum: General
Topic: Question about Mikrotik certificates. [SOLVED]
Replies: 3
Views: 269

Re: Question about Mikrotik certificates. [SOLVED]

What I'm trying to achieve here is to not need to send all clients a new OVPN file everytime I have to change my VPS IP. To put @patrikg's suggestion into context: the purpose of using a certificate at server side is to allow the clients to verify that they are connecting (and revealing their crede...
by sindy
Fri Apr 11, 2025 8:05 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4456

Re: ROMON fails with frame-types=admit-only-vlan-tagged

My post intentionally refers to @Amm0's one in particular, just for the case that someone comes searching and gets mislead by it. But unless @Amm0 edits his, few people will probably notice mine.
by sindy
Fri Apr 11, 2025 6:12 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4456

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Logically, RoMON is not a tagged packet, so bridge is dropping it. I've made some tests, and although it sounds perfectly logical, the behavior is actually totally different. Most ROMON frames have destination MAC address 01:80:C2:00:88:BF, which fits into the "link local" MAC address ran...
by sindy
Thu Apr 10, 2025 7:32 pm
Forum: General
Topic: 💡 Proposal to add functionality to IPsec Policies 💡
Replies: 2
Views: 264

Re: 💡 Proposal to add functionality to IPsec Policies 💡

The protocol specification mandates that it would have to create a lot of SAs and associated traffic selectors based on the address lists, which wouldn't be manageable for the protocol. It would be much better to implement VTI like all major vendors did over time. But Mikrotik stays strictly complia...
by sindy
Thu Apr 10, 2025 4:05 pm
Forum: General
Topic: IPsec certification/authentication problem
Replies: 1
Views: 329

Re: IPsec certification/authentication problem

Since the Mikrotik side has rejected the connection, the log on Mikrotik side should be more helpful. On Mikrotik, disable the peer or identity, and enable IPsec logging using /system logging add topics=ipsec,!packet Next, start writing ipsec log into a file: /log print follow-only file=ipsec-start ...
by sindy
Wed Apr 09, 2025 11:35 pm
Forum: General
Topic: DHCP Issues on Port 4 Despite Normal EoIP Operation
Replies: 2
Views: 316

Re: DHCP Issues on Port 4 Despite Normal EoIP Operation

Is the central router a physical one or is it a virtual one running on some virtualisation platform? A common behavior of virtualisation platforms is that they block traffic to/from MAC addresses other than the one of the virtual NIC, so the virtual machine cannot act as a bridge. This is considered...
by sindy
Wed Apr 09, 2025 11:05 pm
Forum: General
Topic: EoIP and MTU
Replies: 19
Views: 5048

Re: EoIP and MTU

What I suspect and suggest is that the PMTUD (Path MTU Discovery) for the affected TCP traffic fails. You cannot discover this by trying with ICMP (ping). If tcpdump on ESXi doesn't show ICMP, run the sniffer on the Mikrotik as I have suggested initially. But if the tcpdump on ESXi shows 1500-byte o...
by sindy
Wed Apr 09, 2025 10:22 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1620

Re: Basic VLAN config question (again)

Sorry, the trigger of my reaction was that use of such term leads to misunderstanding of the actual topology. I would be more than happy if someone created a better set of terms to describe the virtual objects in the software than those somehow bulky ones I came up with, but putting an equation betw...
by sindy
Wed Apr 09, 2025 10:52 am
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1620

Re: Basic VLAN config question (again)

There is no effing CPU port of a software bridge. There indeed is a CPU port of a hardware switch, but it is not the same thing.

There is the router-facing port of the bridge, which is a virtual object within a software running on the CPU. The router software is not the same thing as the CPU.
by sindy
Wed Apr 09, 2025 10:40 am
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1016

Re: Multi-wan multi-ip wireguard setup

Yup sounds familiar and as CGX pointed out we only need to use one LO address/interface to accomplish same.......... no need for bridge!! /ip address add address=10.20.30.40 interface=lo network=10.20.30.40 Does this even belong here? The src-nat rule in input is the key part of @lurker888's soluti...
by sindy
Wed Apr 09, 2025 10:16 am
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1016

Re: Multi-wan multi-ip wireguard setup

only correctly authenticated connections show up at all - ever - as endpoint addresses. Failed handshake attempts never do. (Even if no multiwan/nat is present.) In Wireguard data, this is correct. In the connection tracking, it's different - any connection attempt to the Wireguard port that comes ...
by sindy
Tue Apr 08, 2025 9:08 pm
Forum: General
Topic: EoIP and MTU
Replies: 19
Views: 5048

Re: EoIP and MTU

Do you have any idea what else should I check or what else could be wrong? You can sniff at both end devices of the tunnel, and you should see packets to arrive to one of them that are larger than the IPIP tunnel MTU so the device cannot forward them, so it sends ICMP "fragmentation needed, MT...
by sindy
Tue Apr 08, 2025 8:56 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1016

Re: Multi-wan multi-ip wireguard setup

Only authenticated users show up in the peers as "Current endpoint address". If I understand your solution correctly, thanks to the src-nat rule in input, the current enpoint address is always 172.16.10.2 (as per https://forum.mikrotik.com/viewtopic.php?p=1136875#p1136875) . So to find a ...
by sindy
Sun Apr 06, 2025 1:06 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1016

Re: Multi-wan multi-ip wireguard setup

The only real solution working is from @lurker888 with srcnat. But in this case mikrotik does not see the real IP of connected client.
The Mikrotik does. The Wireguard stack running on that Mikrotik doesn't. Why is it important for you that the Wireguard stack knew the actual address of the peer?
by sindy
Sun Mar 30, 2025 1:33 pm
Forum: General
Topic: LHG-LTE18 nearly dead.
Replies: 17
Views: 5721

Re: My LHG - LTE18 is having a Stroke. :D

Each SIM card is linked to a subscriber account, and each subscriber account has a "service plan" or whatever is the correct term in English, which determines a lot of parameters of your connection; in addition to limits of both bandwidth and total amount of data transported per some unit ...
by sindy
Tue Mar 25, 2025 11:15 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11518

Re: My recent VLAN fiasco [SOLVED]

That means that if you want to handle bridging between untagged ports, you have to assign a VLAN to them internally (possibly with only access ports attached). It is customary to reserve vlan 1 for this purpose. How is it "reserved"? Or, how is "bridging between access ports to VLAN ...
by sindy
Tue Mar 25, 2025 6:11 pm
Forum: General
Topic: General questions about wireguard and connection problems
Replies: 2
Views: 805

Re: General questions about wireguard and connection problems

In another words (now it is my turn not to be sarcastic), your description is so vague that the only feedback you can get is consolation - yes, you are not alone, other people also have various sorts of issues with Wireguard, some of then even looking similar to your ones from the outside. If you ne...
by sindy
Tue Mar 25, 2025 4:34 pm
Forum: General
Topic: No traffic through IPSec tunnel (if opnSense side initiate) [SOLVED]
Replies: 4
Views: 6895

Re: No traffic through IPSec tunnel (if opnSense side initiate) [SOLVED]

For me, it doesn't make sense, that Phase 1 and 2 can be established, but anyway... For Phase 1, it is enough if one of the peers accepts incoming connections and the other one has a stateful firewall that automatically accepts responses to outgoing requests sent by the router itself or by devices ...
by sindy
Tue Mar 25, 2025 3:20 pm
Forum: General
Topic: No traffic through IPSec tunnel (if opnSense side initiate) [SOLVED]
Replies: 4
Views: 6895

Re: No traffic through IPSec tunnel (if opnSense side initiate) [SOLVED]

As both peers are on public addresses and therefore bare ESP is used for Phase 2, you have to make sure that ESP packets coming from the internet are allowed in. The firewall has no way to do that automatically based on information in the IKE (or IKEv2) exhange. So add a rule protocol=ipsec-esp src-...
by sindy
Tue Mar 25, 2025 12:38 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11518

Re: My recent VLAN fiasco [SOLVED]

Sorry for blurring the picture for you, my response was mainly triggered by @erlinden as I am kind of tired of everyone treating VLAN 1 as black magic that has to be avoided by all means, hence that approach spreads as a meme (in the meaning of a "human software" virus, not the funny pictu...
by sindy
Tue Mar 25, 2025 10:49 am
Forum: General
Topic: L7 filtering only working occasionally
Replies: 12
Views: 1055

Re: L7 filtering only working occasionally

You said you had no problem with CPU consumption on the router, so maybe you can try with the action=fasttrack-connection rule disabled. If it starts working that way, you'll know for sure that fasttracking is the cause of the issue. And assuming that the documentation is accurate regarding the L7 m...
by sindy
Mon Mar 24, 2025 11:37 pm
Forum: General
Topic: Using WLAN to bridge two RBs
Replies: 2
Views: 561

Re: Using WLAN to bridge two RBs

Do you indeed need to "bridge" the networks or would "routing" be sufficient? On one hand, you mention "machine" network, which hints on use of some proprietary L2-only protocols so bridging might indeed be required, on the other hand, you mention a distinct subnet on e...
by sindy
Mon Mar 24, 2025 7:25 pm
Forum: General
Topic: L7 filtering only working occasionally
Replies: 12
Views: 1055

Re: L7 filtering only working occasionally

am I still missing something? You have to distinguish between packets and connections. A connection consists of multiple packets; the connection tracking module inspects each packet that passes through it and if it concludes that it belongs to an existing connection, it treats it according to the c...
by sindy
Mon Mar 24, 2025 5:01 pm
Forum: General
Topic: L7 filtering only working occasionally
Replies: 12
Views: 1055

Re: L7 filtering only working occasionally

The "fastrack" mangle rules are default rules created by the OS... These dynamically added mangle rules whose comment mentions fasttrack are indeed used only to approximate the amount of fasttracked traffic, but their mere presence is an indicator that somewhere in filter, there is an act...
by sindy
Mon Mar 24, 2025 4:27 pm
Forum: General
Topic: L7 filtering only working occasionally
Replies: 12
Views: 1055

Re: L7 filtering only working occasionally

3. the mangle rules you have posted indicate that fasttracking is enabled in filter; one of the key elements of fasttracking is that most packets that belong to fasttracked connections skip mangle rules completely. A TCP connection gets fasttracked as soon as the "three-way handshake" is c...
by sindy
Mon Mar 24, 2025 3:17 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11518

Re: My recent VLAN fiasco [SOLVED]

In a VLAN world your bridge shouldn't have an IP Address. Since there are /interface/bridge/port rows with the default value of pvid (1) and bridge-the-port also has pvid set to the default value 1, there is nothing wrong about having an IP address attached to bridge-the-router-interface directly. ...
by sindy
Mon Mar 24, 2025 1:29 am
Forum: General
Topic: VLAN question about tagging bridge or ether1
Replies: 16
Views: 1241

Re: VLAN question about tagging bridge or ether1

It is indeed, does it make the description misleading in any way?
by sindy
Mon Mar 24, 2025 12:20 am
Forum: General
Topic: VLAN question about tagging bridge or ether1
Replies: 16
Views: 1241

Re: VLAN question about tagging bridge or ether1

With 7.16+, an /interface/bridge/vlan row is dynamically created for a particular VLAN ID and bridge: whenever an interface is made a member port of that bridge and its pvid is set to that VLAN ID (in this case, the interface name is put to the untagged list on that row) whenever an /interface/vlan ...
by sindy
Sun Mar 23, 2025 10:07 pm
Forum: General
Topic: detect ddos from the wiki
Replies: 2
Views: 722

Re: detect ddos from the wiki

when is chain=detect-ddos processed? First, there is a mistake on the manual page you refer to. In the Configuration Lines section, the rule that invocates the detect-ddos chain is missing, it is only mentioned in the Configuration Explained session: /ip/firewall/filter/add chain=forward connection...
by sindy
Sun Mar 23, 2025 5:07 pm
Forum: General
Topic: VPN on Chateau 5G for spezifisch internal IP and WLAN
Replies: 2
Views: 586

Re: VPN on Chateau 5G for spezifisch internal IP and WLAN

I want to activate VPN (tunnel to a remote VPN server, not provide VPN endpoint on my router). I then want to configure that specific devices (IP address) and a dedicated WLAN connects via VPN, all other devices without VPN. How can i reach this? Thanks. Depending on the type of your VPN (IPsec vs....
by sindy
Sun Mar 23, 2025 4:58 pm
Forum: General
Topic: VLAN question about tagging bridge or ether1
Replies: 16
Views: 1241

Re: VLAN question about tagging bridge or ether1

all should start working the intended way.
(that is, if the actual intention was to make ether1 an access port to VLAN 999, despite having no IP configuration attached to VLAN 999).
by sindy
Sun Mar 23, 2025 4:54 pm
Forum: General
Topic: Looking for a script to prioritize multiple internet interfaces via ping (VDSL, LTE, RJ45)
Replies: 1
Views: 606

Re: Looking for a script to prioritize multiple internet interfaces via ping (VDSL, LTE, RJ45)

Why is this not the answer to your needs? In my opinion, the only part missing is the possibility to specify the roles of the interfaces via variables, but that only makes sense if you want to use a single template to configure lots of devices, which would make perfect sense for simple cases (where ...
by sindy
Sun Mar 23, 2025 3:10 pm
Forum: General
Topic: VLAN question about tagging bridge or ether1
Replies: 16
Views: 1241

Re: VLAN question about tagging bridge or ether1

As soon as you make any interface (in your case, ether1 ) a member port of a bridge, you must not use that interface directly for any other purpose - you must not attach /interface/vlan or an IP address/DHCP client to it, you must not make it a member port of any other bridge, you must not make it a...
by sindy
Sun Mar 23, 2025 2:53 pm
Forum: General
Topic: All IPv6 stops working until I manually renew DHCP6 lease from ISP?
Replies: 5
Views: 1086

Re: All IPv6 stops working until I manually renew DHCP6 lease from ISP?

Probably ISP do not asign static IPv6 etc. etc. etc. Paste this on terminal and reboot, see if solve on long term. /ipv6 nd set [ find default=yes ] hop-limit=64 /ipv6 nd prefix default set preferred-lifetime=45m valid-lifetime=1h30m OP has clearly stated that "nothing changes", which (if...
by sindy
Sun Mar 23, 2025 2:15 pm
Forum: General
Topic: VLAN question about tagging bridge or ether1
Replies: 16
Views: 1241

Re: VLAN question about tagging bridge or ether1

Is this correct? Either yes or no, why? Does the answer to this lie with the question of whether vlan2 frames need to be processed by the CPU, which is accomplished by tagging bridge? But, because the AP is not acting as a router, the CPU is not necessary? Each VLAN only needs to pass through the b...
by sindy
Sun Mar 23, 2025 1:51 pm
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

The policy installed by mode-config is src.address 0.0.0.0/0 and dst.address 0.0.0.0/0 OK. So whereas a "normal" responder waits for the initiator to use the data it got in the mode-config message to construct their own policy and propose it, this one apparently uses some inverse logic - ...
by sindy
Sat Mar 22, 2025 10:42 pm
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

Despite all my efforts the result is still the same: I can see the traffic going out back nothing received from the tunnel. That does not answer what the policy looks like when the tunnel is "up". You don't know what the responder is actually doing, so if it assigns the initiator an addre...
by sindy
Sat Mar 22, 2025 6:26 pm
Forum: General
Topic: IP Neighbors and VLANS
Replies: 9
Views: 1146

Re: IP Neighbors and VLANS

I have admin-mac defined on all devices, and auto-mac=no. OK, but for some reason, it is the MAC of ether1 on the cAP whereas it is the address of some other interface, or unrelated to any interface, on the NetMetal. It is a "locally administered one" (because the least significant digit ...
by sindy
Sat Mar 22, 2025 6:12 pm
Forum: General
Topic: IP Neighbors and VLANS
Replies: 9
Views: 1146

Re: IP Neighbors and VLANS

how and/or why ether1 and bridge share the same mac address on the cAP whereas they have different MAC addresses on the NetMetal? That has nothing to do with discovery protocols but with how the bridge is implemented. Unless you specify a MAC address for a bridge manually, it inherits the MAC addre...
by sindy
Sat Mar 22, 2025 5:54 pm
Forum: General
Topic: IP Neighbors and VLANS
Replies: 9
Views: 1146

Re: IP Neighbors and VLANS

I'd like to understand why there are 2 instances displayed in IP NEIGHBORS on the hEX. Because the neigbor advertisement protocols (any combination of MNDP, LLDP, and CDP depending on the settings) are being sent from all interfaces that are members of the interface list configured in the discover-...
by sindy
Sat Mar 22, 2025 4:03 pm
Forum: General
Topic: Two questions about GPS module for LtAP mini LTE Rev3
Replies: 5
Views: 2082

Re: Two questions about GPS module for LtAP mini LTE Rev3

There were multiple topics in the past that discussed this and the outcome was that even Mikrotik admitted that for LtAP mini, the external antenna for GPS was mandatory, not optional. The current wording in https://mikrotik.com/product/ltap_mini carefully avoids mentioning the existence of the inte...
by sindy
Sat Mar 22, 2025 3:42 pm
Forum: General
Topic: IPsec: no phase2 after a few hours [6.40.4]
Replies: 9
Views: 12152

Re: IPsec: no phase2 after a few hours [6.40.4]

Ok, quick update: after changing the PFS group to "none"...
I guess you have updated a wrong topic?
by sindy
Sat Mar 22, 2025 12:08 pm
Forum: General
Topic: MT Wireguard over VRRP WAN
Replies: 5
Views: 1007

Re: MT Wireguard over VRRP WAN

Wireguard does not respond an incoming request from the same IP address to which that request has arrived because it is actually not a server in the narrow sense. So it treats any packet it sends as a standalone one rather than a part of some connection. So even though the initial hanshake packet fr...
by sindy
Sat Mar 22, 2025 11:12 am
Forum: General
Topic: SSTP VPN Issue ( Mikrotik And Sophos )
Replies: 2
Views: 809

Re: SSTP VPN Issue ( Mikrotik And Sophos )

Well... up... I would rather expect an upgrade of the problem description. What means "if Sophos is a gateway" - for what traffic it is a gateway? What means "if we connect both Sophos and Mikrotik on the network"? Which "connection" is down? After reading it several ti...
by sindy
Sat Mar 22, 2025 10:44 am
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

It could work without mode-config if the responder ("server") was a device that allows you to configure all the aspects of the IPsec connection. Since it is a blackbox, you have to adjust the configuration of the Mikrotik acting as initiator to its expectations. An IPsec "policy"...
by sindy
Tue Mar 18, 2025 8:17 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 60
Views: 20784

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

Despite of many users claiming, that this problem has been resolved in the most recent versions, I am afraid I can't agree. At least for me it is not the case. In order to resolve this issue completely, RouterOS would have to modify the Wireguard behavior to fix 3rd party issues, causing headache t...
by sindy
Tue Mar 18, 2025 1:39 pm
Forum: General
Topic: Unable to get my Map Lite serve as a WLAN to ETH device
Replies: 1
Views: 975

Re: Unable to get my Map Lite serve as a WLAN to ETH device

Remove the DHCP relay and try again. The essence of station-pseudobridge operation is an internal mapping table between IP addresses and MAC addresses on the wired side because it can only use a single MAC address towards the AP. Whatever the source address on the wired side of the bridge, when the ...
by sindy
Tue Mar 18, 2025 9:31 am
Forum: General
Topic: Redundant IPsec tunnel - second tunnel cannot connect - a bug?
Replies: 5
Views: 1212

Re: Redundant IPsec tunnel - second tunnel cannot connect - a bug?

logs are filled with the same errors every 10 seconds ... ipsec,error failed to get proposal from first template Is this expected behaviour? ... should it be trying to establish phase2 (is it establishing phase2?) for peer2 every 10 seconds? The Mikrotik approach is based on an assumption that the ...
by sindy
Tue Mar 18, 2025 9:19 am
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

I have a similat situation Actually, the whole similarity is just "I also have some issue with IPsec". So please re-post the above in a new dedicated topic instead of piggybacking a loosely related one that is still unresolved. And once at it, post also the complete exports of the two IPs...
by sindy
Mon Mar 17, 2025 9:22 pm
Forum: General
Topic: Redundant IPsec tunnel - second tunnel cannot connect - a bug?
Replies: 5
Views: 1212

Re: Redundant IPsec tunnel - second tunnel cannot connect - a bug?

By design, bare IPsec does not permit two distinct policies with identical traffic selectors to be bound to two distinct peers. But the solution here should be to use just a single policy and bind it to both peers: peer=peer1,peer2 . With this setup, the router establishes Phase 1 to both remote pee...
by sindy
Sun Mar 16, 2025 7:38 pm
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

What normally happens is that the initiator asks for Mode Config information (which is a name used in the IKE (v1) vernacular, so strictly speaking not correct for IKEv2, but let's ignore that), gets an address, and asks the responder to create a policy with only that single address on its side. So ...
by sindy
Sun Mar 16, 2025 6:58 pm
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

If so, have you set generate-policy on the identity row to something else than no?
by sindy
Sun Mar 16, 2025 6:05 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1877

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

The advantage of ECMP as compared to PCC is simplicity of configuration; the advantage of PCC as compared to ECMP is the possibility to control the distribution more precisely. As for your updated requirements - you can think about the WG tunels as about yet another set of WANs. So one group of LAN ...
by sindy
Sun Mar 16, 2025 4:53 pm
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

If so, go the other way round, enable (recreate) the mode-config and disable the manually configured policy.
by sindy
Sun Mar 16, 2025 2:30 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1877

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

When you wrote you wanted to pass all the LAN traffic to the CHR, it seemed that you didn't want to use the local WANs for anything else but for the Wireguard tunnels. Hence @anav suggested how you can create a WG tunnel via each WAN and use those WG tunnels instead of the actual WANs for all the LA...
by sindy
Sun Mar 16, 2025 11:39 am
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 2169

Re: IPSEC tunnel established, traffic not passing through

Complete exports from both routers would have been much better because configuration issues are typically in those parts of the configuration you do not deem related, which is why you don't post them. In your case, you have set up a "cat-dog", in terms that you use a mode-config row on the...
by sindy
Sat Mar 15, 2025 6:05 pm
Forum: General
Topic: EoIP and MTU
Replies: 19
Views: 5048

Re: EoIP and MTU

Because it is the best thing to do from one perspective and the worst one from another. And there is no ideal solution for all cases due to the number of clueless network administrators out there. TCP is designed to automatically adjust the packet size to the lowest MTU on the path between the clien...
by sindy
Thu Mar 13, 2025 12:16 pm
Forum: General
Topic: hap ax3 random wireless disconnects
Replies: 255
Views: 54578

Re: hap ax3 random wireless disconnects

Have you considerd (or performed) a netinstall I have netinstalled a hAP ac² for other reasons and recreated the configuration from the text exports (i.e. no "invisible" data), nevertheless: the Intel 201ax gets thrown out from an AP no matter what (20 MHz channels, 40 MHz channels, 80 MH...
by sindy
Tue Mar 11, 2025 11:02 pm
Forum: General
Topic: Two IP addresses from one provider „like two ISPs“
Replies: 21
Views: 3685

Re: Two IP addresses from one provider „like two ISPs“

I was thinking about a script that will make the src-nat rules - the DHCP client will get an IP address... Well, there is a script item in the DHCP client configuration, so you can modify the rules, but you can also use the second routing table (with 7.18.x, you can specify the routing table to whi...
by sindy
Tue Mar 11, 2025 9:31 pm
Forum: General
Topic: Two IP addresses from one provider „like two ISPs“
Replies: 21
Views: 3685

Re: Two IP addresses from one provider „like two ISPs“

I just had to hope that my ISP will not change "its own 10.x…" addresses. Well, the possibility that this might happen is exactly the reason why I prefer the solution with two DHCP clients attached to the physical interface and to the macvlan one, although @panisk0's suggestion is fine if...
by sindy
Tue Mar 11, 2025 9:15 am
Forum: General
Topic: Two IP addresses from one provider „like two ISPs“
Replies: 21
Views: 3685

Re: Two IP addresses from one provider „like two ISPs“

Sniffing on WAN would tell you more about what actually happens, but now as I look at your screenshots again, it seems to me that something is rotten in routing - in RouterOS, not in your configuration. While the default route with distance=5 is marked as active and the default route with distance=1...
by sindy
Mon Mar 10, 2025 10:40 pm
Forum: General
Topic: Two IP addresses from one provider „like two ISPs“
Replies: 21
Views: 3685

Re: Two IP addresses from one provider „like two ISPs“

There is no point in obfuscating private addresses (anything that begins with 10. is a private address).

Other than that - since the gateway IP is the same, try the change of srcnat rules I've suggested.
by sindy
Mon Mar 10, 2025 10:23 pm
Forum: General
Topic: Two IP addresses from one provider „like two ISPs“
Replies: 21
Views: 3685

Re: Two IP addresses from one provider „like two ISPs“

Hope everything redacted correctly :) If you enable the second DHCP client temporarily, do both the default routes added dynamically via DHCP have the same IP address as the gateway ? Anyway, as you haven't added a dedicated routing table, neither by creating a VRF (which needs a name of a routing ...
by sindy
Mon Mar 10, 2025 9:43 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 60
Views: 20784

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

wan is on eth2, eth1 is unplugged Well, more importantly, both /interface/wireguard/peer rows say responder=yes so once the connection gets lost, the router itself should not keep updating the pinhole (the tracked connection). So when the Wireguard connection gets interrupted, what are the exact st...
by sindy
Sun Mar 09, 2025 10:57 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 60
Views: 20784

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

If you have masquerade on WAN, there must be something else. Can you post the export of your configuration (anonymized as per the usual instructions, no public addresses, serial numbers, usernames for external services, ...)?
by sindy
Sun Mar 09, 2025 6:44 pm
Forum: General
Topic: Two IP addresses from one provider „like two ISPs“
Replies: 21
Views: 3685

Re: Two IP addresses from one provider „like two ISPs“

I hope I got your requirements properly. First, you can just functionally replicate your previous setup (Mikrotik and the other router) by engaging the VRF functionality of the Mikrotik and using a macvlan interface also on the LAN side. So like before, each device in the LAN subnet would get a dist...
by sindy
Sun Mar 09, 2025 11:43 am
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 60
Views: 20784

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

At least in the case we had a chance to analyse in detail, the behavior that annoys you was not a bug of RouterOS or Wireguard but a direct consequence of how the connection tracking in the firewall handles UDP connections and how temporary connectivity outages interact with that. So there is nothin...
by sindy
Sat Mar 08, 2025 10:20 pm
Forum: General
Topic: Cap AC out of disk space after installing wireless-qcom-ac
Replies: 5
Views: 1428

Re: Cap AC out of disk space after installing wireless-qcom-ac

It's most likely the same issue that is discussed here . It seems that the backups do contain some data that are not actually necessary, but even exporting the configuration as text and certificates as .crt ; .key or as .pkcs12 files and reimporting all that to a netinstalled device does not make th...
by sindy
Sat Mar 08, 2025 9:23 pm
Forum: General
Topic: L2TP site to site cannot reach server's LAN [SOLVED]
Replies: 10
Views: 8660

Re: L2TP site to site cannot reach server's LAN [SOLVED]

the default settings you mentioned for the firewall are maintained in a post [1] within this forum @rextended is indeed doing a good job there. Does anyone happen to know any guides about using the algorithm of WireGuard with IPsec? Would it be recommended? Would it change its behaviour and require...
by sindy
Sun Mar 02, 2025 5:50 pm
Forum: General
Topic: L2TP site to site cannot reach server's LAN [SOLVED]
Replies: 10
Views: 8660

Re: L2TP site to site cannot reach server's LAN [SOLVED]

Please post complete configs of both devices the way they actually are, because "similar" is not good enough - in your "common" firewall export, there is just one of the LAN subnets in the allowed_to_router address list ( add address=192.168.1.1-192.168.1.254 list=allowed_to_rout...
by sindy
Sun Mar 02, 2025 12:14 pm
Forum: General
Topic: Which is the best 5G modem compatible with RoS7.
Replies: 22
Views: 5828

Re: Which is the best 5G modem compatible with RoS7.

That would have been my expectation. Not so much mine, at least not to that extent, given the effort made at Mikrotik side to make the 960 work back then. what I'd check is if fireware upgrade is supported on the Quectel you're using At least for now it is not. So RM520N:FN990 0:0 here. if you ask ...
by sindy
Sat Mar 01, 2025 10:42 pm
Forum: General
Topic: Which is the best 5G modem compatible with RoS7.
Replies: 22
Views: 5828

Re: Which is the best 5G modem compatible with RoS7.

a Telit FN990-A28 is waiting in the box to be tested once an adaptor arrives - it is based on the same Qualcomm chipset, just the AT commands differ. It does work, however, it was not such a smooth ride like with the Quectel. At first, RouterOS saw it as a USB device but ignored it as a modem. The ...
by sindy
Fri Feb 28, 2025 9:25 pm
Forum: General
Topic: Cannot disable preboot-etherboot after updating to ROS 7.18 [SOLVED]
Replies: 4
Views: 5912

Re: Cannot disable preboot-etherboot after updating to ROS 7.18 [SOLVED]

Why is this happening and what is the fix? As part of the "we will make your devices secure no matter whether you like it or not" campaign, certain features now have to be explicitly allowed using exactly the "device mode" setting you haven't touched. So read the manual, check w...
by sindy
Tue Feb 25, 2025 11:07 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

@Larsa, the scripts and search phrases you've suggested do not address the topic of updating the IPsec identity rows whenever the LE certificate gets renewed; the renewal of the LE certificate happens fully automatically in recent versions of RouterOS so scripts are not necessary for that any more. ...
by sindy
Sun Feb 23, 2025 10:50 pm
Forum: General
Topic: VLAN vs. bridge VLAN
Replies: 20
Views: 5647

Re: VLAN vs. bridge VLAN

Mikrotik traffic flow always starts with the ''Input'' chain. This chain defines everything related to incoming traffic. Then follows the ''forward'' chain, which means the traffic flow that goes through the router. This wording is a bit misleading. In reality, it is an exclusive or: a received pac...
by sindy
Sun Feb 23, 2025 10:19 pm
Forum: General
Topic: VLAN vs. bridge VLAN
Replies: 20
Views: 5647

Re: VLAN vs. bridge VLAN

You can use both (in|out)-interface(-list) and (src|dst)-address(-list) in firewall filter rules, but until recently you could not use in-interface or in-interface-list in the srcnat chain of firewall nat for unclear reason, and you cannot use out-interface(-list) in dstnat and prerouting for obviou...
by sindy
Sun Feb 23, 2025 7:20 pm
Forum: General
Topic: IPSec SA issue in 7.12.1
Replies: 2
Views: 3035

Re: IPSec SA issue in 7.12.1

Have you set the level parameter of the policies to unique? Is the remote peer a Mikrotik or a device from another vendor?
by sindy
Sun Feb 23, 2025 6:58 pm
Forum: General
Topic: EoIP and MTU
Replies: 19
Views: 5048

Re: EoIP and MTU

BCP indeed does work but it does not interwork with bridges on which vlan-filtering is enabled (unless something has changed recently). But alone it doesn't help with MTU size - you need to use it in conjunction with another "forgotten protocol", MLPPP. The beauty of MLPPP is that it slice...
by sindy
Sun Feb 23, 2025 6:39 pm
Forum: General
Topic: Language of VLANs please
Replies: 24
Views: 4843

Re: Language of VLANs please

I simply don't understand the points along the way -- e.g., "interface/vlan," "bridge.the.interface," "bridge.the.port" a VLAN (sub)interface (abbreviated to interface/vlan on that scheme) is a functional entity that acts as a tagging/untagging pipe. Its "untagged...
by sindy
Sun Feb 23, 2025 2:32 pm
Forum: General
Topic: Which is the best 5G modem compatible with RoS7.
Replies: 22
Views: 5828

Re: Which is the best 5G modem compatible with RoS7.

I have got my 520(GL), not 502(EU), for about $180 from Ali. I've never tried a 502.
by sindy
Sun Feb 23, 2025 2:17 pm
Forum: General
Topic: Which is the best 5G modem compatible with RoS7.
Replies: 22
Views: 5828

Re: Which is the best 5G modem compatible with RoS7.

This is what I saw in the office the other day: primary-band: B1@20Mhz earfcn: 100 phy-cellid: abc ca-band: n78@80Mhz earfcn: 644640 phy-cellid: def B3@15Mhz earfcn: 1404 phy-cellid: ghi So 3 bands aggregated, one of them n78. In a more rural area where the device has been deployed permanently, stil...
by sindy
Sun Feb 23, 2025 11:44 am
Forum: General
Topic: Which is the best 5G modem compatible with RoS7.
Replies: 22
Views: 5828

Re: Which is the best 5G modem compatible with RoS7.

Not sure whether it is "the best" one but I do successfully use Quectel RM520NGLAA (be careful to obtain the AA version as the USB interface is disabled on the ..AP one). And a Telit FN990-A28 is waiting in the box to be tested once an adaptor arrives - it is based on the same Qualcomm chi...
by sindy
Sun Feb 23, 2025 10:53 am
Forum: Forwarding Protocols
Topic: Two WAN Router with Passing Subnets
Replies: 10
Views: 4905

Re: Two WAN Router with Passing Subnets

Have you resolved the subject of this topic or it's just that the loss of admin access has temporarily prevented you from moving further with this one?
by sindy
Sun Feb 23, 2025 10:45 am
Forum: General
Topic: Language of VLANs please
Replies: 24
Views: 4843

Re: Language of VLANs please

Unfortunately, I don't really understand what is being demonstrated. I think it shows that the hEX router that has this VLAN config knows that each IP network has a different VLAN (10.11.11.x on VLAN1; 10.22.22.x on VLAN2; 10.33.33.x on VLAN3). Perhaps more specifically, that the broadcast traffic ...
by sindy
Sat Feb 22, 2025 11:04 pm
Forum: General
Topic: Vlan tagging
Replies: 34
Views: 6111

Re: Vlan tagging

You have renamed ether3 to OffBridge3, but “a rose by any other name would smell as sweet” - in RouterOS, the configuration items are linked to each other using internal IDs rather than the human-friendly names. So the important point is to disable the /interface bridge port row that makes OffBridge...
by sindy
Sat Feb 22, 2025 10:14 pm
Forum: General
Topic: Vlan tagging
Replies: 34
Views: 6111

Re: Vlan tagging

If you decide to specify the list of untagged ports for a VLAN manually (under /interface bridge vlan ), it still must be consistent with the pvid settings on the /interface bridge port rows, which is not the case e.g. for vlan 4 and ether5 (but other port/VLAN combinations are affected too). If fra...
by sindy
Sat Feb 22, 2025 9:21 pm
Forum: General
Topic: Mikrotik CHR for Wireguard VPN with Static Public IP
Replies: 5
Views: 3267

Re: Mikrotik CHR for Wireguard VPN with Static Public IP

@sokalsondha, do I understand properly that you want Wireguard user A to use an internal address 10.0.0.2, and if he sends a packet through the Wireguard tunnel towards a public destination address, that request gets its source address translated to the public one x.x.x.154, whereas user B will use ...
by sindy
Sat Feb 22, 2025 9:13 pm
Forum: General
Topic: Vlan tagging
Replies: 34
Views: 6111

Re: Vlan tagging

Many vendors allow you to configure a list of VLANs for a given port. So you say "ether5 is a member of VLANs 10,20,27,39" and specify whether it is an "access" or "trunk" member of that VLAN. For just a few VLANs, many users prefer this even if the other way round (spe...
by sindy
Sat Feb 22, 2025 8:10 pm
Forum: General
Topic: Language of VLANs please
Replies: 24
Views: 4843

Re: Language of VLANs please

Can someone please explain, in super clear and complete sentences and throughts (don't be afraid to be overly verbose), the following phrases: Without the surrounding context, those chunks of words alone cannot be translated properly. And some of them may have even been used incorrectly where you h...
by sindy
Sat Feb 22, 2025 1:28 pm
Forum: General
Topic: VPN IKEv2 client router won't route workstation traffic
Replies: 1
Views: 3365

Re: VPN IKEv2 client router won't route workstation traffic

There are multiple issues. First, the IPsec setup. Neither on the responder (home router) nor on the initiator (the roaming hAP) you have configured any particular IPsec policy, you only have templates. So the hAP gets a single address specified by the mode-config row, 10.10.20.41, and since the tem...
by sindy
Sat Feb 22, 2025 12:01 pm
Forum: General
Topic: IPSsec/L2TP
Replies: 3
Views: 2800

Re: IPSsec/L2TP

L2TP/IPsec does work on 7.16.2 so the issue must be something in the configuration or the Windows may have another glitch. Please post the export of the configuration, of course after obfuscating any sensitive information.
by sindy
Sat Feb 22, 2025 8:47 am
Forum: General
Topic: IKEv2 Dual WAN Setup not possible? (2:1 relation) [SOLVED]
Replies: 21
Views: 12822

Re: IKEv2 Dual WAN Setup not possible? (2:1 relation) [SOLVED]

I have the same problem You don't. The OP's problem was that the two connections were killing each other due to the INITIAL_CONTACT notification. According to your description, the INITIAL_CONTACT option is disabled by default. ... The tables are there and the marking rules are there too. However, ...
by sindy
Fri Feb 21, 2025 6:22 pm
Forum: General
Topic: Question related to "RouterOS bridge mysteries explained"
Replies: 13
Views: 5757

Re: Question related to "RouterOS bridge mysteries explained"

The whole OP was aimed to explain that in fact, there is no single "bridge itself", because the "bridge" term actually represents three distinct functional entities that are tightly linked to each other, and that a clear distinction between these entities in the respective contex...
by sindy
Wed Feb 19, 2025 11:36 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

How do i get the intermediate CA (R11) on the mikrotik and how do i make it so that this stays correct when the domaincertificate is renewed? Sorry for late reaction, life is intense these days. The ACME agent in RouterOS requests a new certificate every 60 days, so in any case you need a script th...
by sindy
Wed Feb 19, 2025 11:13 pm
Forum: General
Topic: Different IP address segments cannot be connected in 1 mikrotik
Replies: 3
Views: 2989

Re: Different IP address segments cannot be connected in 1 mikrotik

OK, so you use mangle rules to choose a specific routing table for packets depending on their origin ( source-address(-list) and/or in-interface(-list) ). So you have to make these rules match also on dst-address-list so that they would not act on packets whose destination address is in another loca...
by sindy
Mon Feb 17, 2025 10:18 pm
Forum: General
Topic: MikroTik Chateau 5G R16 capability
Replies: 2
Views: 2446

Re: MikroTik Chateau 5G R16 capability

With bonding, a single connection (TCP session, UDP stream) always uses only one of the bonded paths - unless you use the round robin (balance-rr) mode but that causes other issues. But the aggregate throughput may reach the sum of the bandwidths under favourable conditions (a sufficient number of i...
by sindy
Sun Feb 16, 2025 10:24 am
Forum: General
Topic: Different IP address segments cannot be connected in 1 mikrotik
Replies: 3
Views: 2989

Re: Different IP address segments cannot be connected in 1 mikrotik

Since a router normally allows routing among all networks connected to it unless you explicitly ask it not to do so (using firewall rules and/or routing rules and/or VRF settings), it is clear that something in your configuration is set differently from what you actually want to happen. Until you po...
by sindy
Sun Feb 16, 2025 9:10 am
Forum: General
Topic: Dynamic address lists via srv entry
Replies: 6
Views: 2556

Re: Dynamic address lists via srv entry

Running scripts loads the device several orders of magnitude less than routing packets, so you can literally run the check every second without a noticeable impact. The phone will send the SYN packet to establish a connection to a new server multiple times before giving up so running the script once...
by sindy
Sat Feb 15, 2025 11:14 pm
Forum: General
Topic: Dynamic address lists via srv entry
Replies: 6
Views: 2556

Re: Dynamic address lists via srv entry

The phone must send its SRV query first, or use dig as you did before. The TTL was an hour when I tried a while ago.
by sindy
Sat Feb 15, 2025 10:56 pm
Forum: General
Topic: Dynamic address lists via srv entry
Replies: 6
Views: 2556

Re: Dynamic address lists via srv entry

The only workaround currently available requires scripting. RouterOS is unable to generate a SRV query at all, not just as a way to populate an address list, but it does cache the responses to SRV queries issued by clients. So you can schedule a script that will keep reading the cached responses and...
by sindy
Sat Feb 15, 2025 2:28 pm
Forum: General
Topic: VXLAN inside WireGuard tunnel
Replies: 4
Views: 2659

Re: VXLAN inside WireGuard tunnel

In general yes, in detail not so much. I mean, I could not find any important bit to miss in the configuration, but the actual behavior may not fulfil your expectations. The overhead of Wireguard takes 80 bytes (hence MTU 1420 if the path between the peers has MTU 1500) and the overhead of VXLAN tak...
by sindy
Thu Feb 13, 2025 11:21 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

If there are no VLANs, everything should sit in a single common subnet, so there should be one DHCP server with a single range and a single "network". So assuming it is a /20 network (192.168.0.0-192.168.15.255.255), there would be a gateway on 192.168.0.1/20 and the dynamic pool could spa...
by sindy
Thu Feb 13, 2025 10:20 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

Who is "MSP"? VLANs are an L2 thing. If you want devices in different VLANs, they normally have to be also in different subnets, and each subnet needs an interface of a router with an address within that subnet, to be used as a gateway from that subnet to the rest of the world. So typicall...
by sindy
Thu Feb 13, 2025 9:52 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

Many devices are unable to handle a gateway outside their subnet, so giving all of them 192.168.1.1 is most likely wrong. By giving all a netmask /20 you put all of them to the same subnet, but then having them in distinct VLANs is weird to me - they will be unable to talk to each other that way eve...
by sindy
Thu Feb 13, 2025 9:50 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

When a Mikrotik DHCP server serves an incoming request, it first chooses the pool based on the interface and, if configured, the matcher rules (the pool attached to the DHCP server is used if matcher does not choose another one). Once the address is chosen, it is compared with the address items of t...
by sindy
Thu Feb 13, 2025 9:33 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

Mikrotik should handle only the DHCP part. DNS is dandled by windows domain controller server and Internet by Fortigate. That's OK, but the DHCP server must tell the clients which DNS servers to use. If you are going to give each new device an address from 192.168.12.0/24 and then make that lease s...
by sindy
Thu Feb 13, 2025 9:24 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

When someone says they want "separate VLANs", it normally means they actually want separate subnets. And if so, you need an IP interface in each subnet (typically, a VLAN interface) to which a dedicated DHCP server or a DHCP relay for that subnet is attached, and a router with an IP interf...
by sindy
Thu Feb 13, 2025 8:52 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

I guess it took that too litterally. I installed the LE certificate on the windows VPN-client via import. There is no reason to import the LE certificate issued for the FQDN of the Mikrotik server to the Windows. But as you said you wouldn't take the Let's Encrypt path, I probably did not give enou...
by sindy
Thu Feb 13, 2025 8:21 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

It may be OK if you have some matching rules in place (under ip dhcp-server/matcher) that allow to identify the various classes of hosts as specified in the comments, based on vendor-class-id or some other DHCP options in the clients' requests, and choose the corresponding pool for each class.
by sindy
Thu Feb 13, 2025 5:47 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

For me, it was the simplest possible setup on Windows - no powershell needed. The Windows must have the certificate of the signing CA of the Mikrotik's certificate among its trusted root CAs. No own certificate of the Windows client is required if you choose username/password authentication. The cer...
by sindy
Thu Feb 13, 2025 3:50 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

ID of the peer is not really relevant as in the current configuration, it should be ignored when matching the /ip/ipsec/identity row. As the Windows throw the error upon receiving the certificate from the Mikrotik, you are most likely right that they do not like the contents of the certificate. And,...
by sindy
Thu Feb 13, 2025 3:28 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

Run Wireshark simultaneously with logging on Mikrotik and compare whether the packets shown in firewall log of Mikrotik indeed made it to Windows. It is strange that it behaves different in the individual attempts.
by sindy
Thu Feb 13, 2025 2:46 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

I guess something is wrong there.
If you use the trick with public address on the Mikrotik itself, it must be set as a local-address on the peer. The dst-nat rules are OK.
by sindy
Thu Feb 13, 2025 2:38 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

To me it seems that the initiator (Windows) auth requests (fragment 1 of 3 etc.) do not reach the Mikrotik, as I can see retransmissions in both the Mikrotik log and the Wireshark from Windows. Do you forward also UDP port 4500 from the public IP to Mikrotik's WAN?
by sindy
Thu Feb 13, 2025 2:18 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

Windows are not famous for useful error messages, they report unnacceptable for almost everything :( What I can see in the logs that Windows either do not get the auth response from us or they do not bother to send NOTIFY with rejection payload in response. Can you verify which case it is using Wire...
by sindy
Wed Feb 12, 2025 6:48 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

So what is in the EKU of the my.dnsname.com certificate - is the tls-server bit set? And does the certificate use an ECP key, as you use one in DH-group in Phase 1 and Phase 2 proposals?
by sindy
Wed Feb 12, 2025 6:01 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

Does the log show that IPsec sends a query to RADIUS?
by sindy
Wed Feb 12, 2025 10:44 am
Forum: Forwarding Protocols
Topic: Two WAN Router with Passing Subnets
Replies: 10
Views: 4905

Re: Two WAN Router with Passing Subnets

please let me know when you have free time that i provide you anydesk access and you can check the config.
Can you follow the instructions in viewtopic.php?p=902082#p902082 ?
by sindy
Tue Feb 11, 2025 9:19 pm
Forum: General
Topic: Another Find question
Replies: 4
Views: 1958

Re: Another Find question

What is far more important is that the string that follows the ~ operator is not a text constant - it is a regular expression, so you can e.g. set that string to "e....1" when matching on the interface name and ether1 will still match (but so would e. g. ester1 or eeeee1 ). Why the name~et...
by sindy
Tue Feb 11, 2025 3:41 pm
Forum: Forwarding Protocols
Topic: Two WAN Router with Passing Subnets
Replies: 10
Views: 4905

Re: Two WAN Router with Passing Subnets

OK. This is in fact very similar to having two uplinks connected directly to CCR2 and using each of them for access to internet from another set of local subnets. In another words, you can think of CCR1 as of another ISP router providing internet access for CCR2. The key here is that the routing mus...
by sindy
Mon Feb 10, 2025 4:11 pm
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 3777

Re: /interface print where [find name=ehter2] -- not correct

I don't understand what the addition of "->0" does. A list is implicitly also an array indexed by integers starting from 0. So ($thisList->0) is a reference to the first ("zeroth") element of thisList . To make it even crazier, you can mix different types of indice in the same a...
by sindy
Mon Feb 10, 2025 11:46 am
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 3777

Re: /interface print where [find name=ehter2] -- not correct

I would add ... Well, this is actually a bit more complicated. If you issue a command that refers to the user-friendly ID before you use the first print for that configuration branch, RouterOS silently assigns the user-friendly IDs the same way it would if you issued a print for that branch without...
by sindy
Mon Feb 10, 2025 9:18 am
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 3777

Re: /interface print where [find name=ehter2] -- not correct

Almost correct, except that there are two kinds of IDs - the internal one that stays the same as long as the object exists and is shown as *1fe or something alike (a 32-bit number in hexadecimal representation prefixed with an asterisk). These are the IDs that [find ...] returns. As @mkx has already...
by sindy
Sun Feb 09, 2025 10:28 pm
Forum: General
Topic: IPSec Tunnel established no Rx bytes/packets [SOLVED]
Replies: 13
Views: 3795

Re: IPSec Tunnel established no Rx bytes/packets [SOLVED]

I am not a cryptographic expert so I cannot suggest which of the encryption algorithms is more secure. When it comes to throughput and CPU load, the available information is quite inconsistent. The Mikrotik product page does not mention support of encryption in hardware for the L009, but its block d...
by sindy
Sun Feb 09, 2025 8:09 pm
Forum: General
Topic: Startlink Business with Mikrotik issue
Replies: 4
Views: 4170

Re: Startlink Business with Mikrotik issue

What does "my Mikrotik" mean in terms of model number? How many client devices are connected to the Mikrotik? What tools do you use to test the speed? Is the Mikrotik itself the WiFi AP or you use some external one?
by sindy
Sun Feb 09, 2025 8:05 pm
Forum: General
Topic: IPSec Tunnel established no Rx bytes/packets [SOLVED]
Replies: 13
Views: 3795

Re: IPSec Tunnel established no Rx bytes/packets [SOLVED]

OK, so most likely the 7.17.2 IPsec doesn't like something about the ESP packets it receives from 7.15.x and doesn't decrypt them. Since you use an individual proposal for each peer even though their contents is the same, it will not affect the other connections if you change the relevant proposals ...
by sindy
Sun Feb 09, 2025 6:58 pm
Forum: General
Topic: IPSec Tunnel established no Rx bytes/packets [SOLVED]
Replies: 13
Views: 3795

Re: IPSec Tunnel established no Rx bytes/packets [SOLVED]

OK. So run /ip/ipsec/statistics/print interval=1s on Router 1, then start pinging the private address in Router 1 LAN from Router 2, then stop again. Does any value in the statistics grow while the ping is running and stays the same while it is not?
by sindy
Sun Feb 09, 2025 6:34 pm
Forum: General
Topic: IPSec Tunnel established no Rx bytes/packets [SOLVED]
Replies: 13
Views: 3795

Re: IPSec Tunnel established no Rx bytes/packets [SOLVED]

You forgot to obfuscate the addresses in the /tool sniffer command.

Do the ESP packets come synchronously with the ping ones, i.e. when you stop the pings, do the ESP ones stop coming?
by sindy
Sun Feb 09, 2025 5:12 pm
Forum: General
Topic: IPSec Tunnel established no Rx bytes/packets [SOLVED]
Replies: 13
Views: 3795

Re: IPSec Tunnel established no Rx bytes/packets [SOLVED]

I wasn't precise enough. Do ping from one LAN (private) address to another, but sniff for the public address of the remote router. It is enough to show Router 1 and the opposite router (2 or 3). And make the windows where you run the /tool sniffer as wide as your screen allows - Mikrotik dynamically...
by sindy
Sun Feb 09, 2025 4:55 pm
Forum: General
Topic: Multiple PPPoE over VLAN
Replies: 16
Views: 2738

Re: Multiple PPPoE over VLAN

return a single blank line I just wanted to check that VLAN "filtering" was indeed disabled on bridgeWAN as the configuration export suggested, so a blank line is a correct result. but now works.... is possibly that connecting Fritz to ONT for the test and re-connecting on Eth8...? Maybe ...
by sindy
Sun Feb 09, 2025 4:26 pm
Forum: General
Topic: Multiple PPPoE over VLAN
Replies: 16
Views: 2738

Re: Multiple PPPoE over VLAN

Looks fine to me, so what does /interface bridge vlan print where bridge=bridgeWAN show?
by sindy
Sun Feb 09, 2025 2:36 pm
Forum: General
Topic: Multiple PPPoE over VLAN
Replies: 16
Views: 2738

Re: Multiple PPPoE over VLAN

If so, moving the VLAN 200 subinterface from ether1 to br-wan1 should be all you need to do.
by sindy
Sun Feb 09, 2025 2:25 pm
Forum: General
Topic: Multiple PPPoE over VLAN
Replies: 16
Views: 2738

Re: Multiple PPPoE over VLAN

So in my words: the ISP will see two MAC addresses trying to establish a PPPoE connection in VLAN 200; one will be the PPPoE client on RB4011 (using one set of credentials) and the other one will be the PPPoE client behind the Fritzbox in bridge mode (using another set of credentials)? is it OK if V...
by sindy
Sun Feb 09, 2025 2:01 pm
Forum: General
Topic: Multiple PPPoE over VLAN
Replies: 16
Views: 2738

Re: Multiple PPPoE over VLAN

I don't think it is a matter of English. First you have mentioned that the Fritzbox uses VLAN 300, now you mention VLAN 200; from the first post I've got an impression that the Frizbox is in bridge mode and provides a second WAN to the 4011, now it seems that you want to provide a second WAN to the ...
by sindy
Sun Feb 09, 2025 1:55 pm
Forum: General
Topic: IPSec Tunnel established no Rx bytes/packets [SOLVED]
Replies: 13
Views: 3795

Re: IPSec Tunnel established no Rx bytes/packets [SOLVED]

To check that, start pinging the LAN address of Router1 from Router2 and the LAN address of Router2 from Router1, specifying the correct source address so that the ping request packets would match the respective IPsec policies. While the two pings are running, run the following command on both route...
by sindy
Sun Feb 09, 2025 1:28 pm
Forum: General
Topic: Multiple PPPoE over VLAN
Replies: 16
Views: 2738

Re: Multiple PPPoE over VLAN

Why you cannot copy the existing setup, where the subinterface for VLAN 200 is directly attached to ether1, also for the other uplink, i.e. attach the subinterface for VLAN 300 directly to ether8? What am I missing?
by sindy
Sun Feb 09, 2025 11:31 am
Forum: General
Topic: IPSec Tunnel established no Rx bytes/packets [SOLVED]
Replies: 13
Views: 3795

Re: IPSec Tunnel established no Rx bytes/packets [SOLVED]

Since Router1 uses DHCP to obtain its WAN address, it is not clear whether said address is a public one. The way you describe it, it seems most likely to me that it is a public one and that the ISP serving Router1 is blocking ESP, but that's just a feeling based on some experience from the past. So ...
by sindy
Sun Feb 09, 2025 10:44 am
Forum: Forwarding Protocols
Topic: Two WAN Router with Passing Subnets
Replies: 10
Views: 4905

Re: Two WAN Router with Passing Subnets

I have my 172.16.0.0/16, 172.17.0.0/16, 172.18.0.0/16, and other prefixes in the Router B routing table with /16 subnet and I want to send prefixes shared in the image with /24 subnet. So after all it is not that simple as you've outlined in your first post, thus my suspicion that I was missing som...
by sindy
Sat Feb 08, 2025 9:30 pm
Forum: General
Topic: /interface print where [find name=ether2] -- not correct
Replies: 19
Views: 3777

Re: /interface print where [find name=ehter2] -- not correct

/interface ethernet print where name=ether2 (no find required/allowed here)

but

/interface ethernet set [find where name=ether2] comment="this is ether2, yay!"
by sindy
Sat Feb 08, 2025 6:46 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 46
Views: 18236

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

My gut says the same, I have even experienced it practically while still in ROS 6 - I haven't noticed those complaints but after a reboot, everything was running fine except that I have lost a few ppp secrets I have added over last several weeks. Since I am using the command line almost exclusively,...
by sindy
Sat Feb 08, 2025 4:39 pm
Forum: General
Topic: Hapax3, no sleep
Replies: 21
Views: 4149

Re: Hapax3, no sleep

"While passing, they may either retain the tag (trunk mode) or lose it on egress and obtain it on ingress (access mode)" What does that mean? Sorry, the bold words went missing as I was editing the sentence multiple times to make it clearer 🤦 A single port may be a member of multiple VLAN...
by sindy
Sat Feb 08, 2025 4:29 pm
Forum: General
Topic: Hapax3, no sleep
Replies: 21
Views: 4149

Re: Hapax3, no sleep

I would like to know, for my clarity, if multiple PVIDs can be placed on a single frame? A P VID is not a property of a frame. It is a property of a bridge port that says "if a frame without any VLAN tag arrives through the cable, attach a tag with this VID (Virtual LAN IDentifier) to it while...
by sindy
Sat Feb 08, 2025 3:16 pm
Forum: General
Topic: Hapax3, no sleep
Replies: 21
Views: 4149

Re: Hapax3, no sleep

I personally don't have a problem comprehending the adding or stripping of a tag to a frame, the presence or absense of which guides devices to make routing (or availability) decisions. My understanding of VLANS fails after that. But VLANs are nothing more than that... Each VLAN is a collection of ...
by sindy
Sat Feb 08, 2025 2:44 pm
Forum: General
Topic: Hapax3, no sleep
Replies: 21
Views: 4149

Re: Hapax3, no sleep

I'm just still trying to understand.... So what about the colored cars - are they helpful or not? Instead of cars, you can be given a flower at an entry, you can only carry a single flower at a time, etc., but it is still a matter of obtaining some attribute when entering the maze and being strippe...
by sindy
Sat Feb 08, 2025 2:37 pm
Forum: General
Topic: Hapax3, no sleep
Replies: 21
Views: 4149

Re: Hapax3, no sleep

All analogies suck. What if I go along the lines "a bridge is a system of roads where no pedestrians are allowed; the only way for a person can travel across the bridge is to board a car at an entry point and let the car bring it to the destination exit point. The cars are of different colors, ...
by sindy
Sat Feb 08, 2025 12:41 pm
Forum: General
Topic: Hapax3, no sleep
Replies: 21
Views: 4149

Re: Hapax3, no sleep

While vlan-filtering is set to no on a bridge, no stripping or adding a VLAN tag happens on the bridge ports. So when a tagless frame gets in, through a physical interface, it stays tagless until it hits the IP stack listening at the internal port of the bridge (the "switch-facing interface of ...
by sindy
Sat Feb 08, 2025 12:10 pm
Forum: General
Topic: Issues with "station bridge" mode on hAP ax Lite
Replies: 2
Views: 1926

Re: Issues with "station bridge" mode on hAP ax Lite

I then attempted to connect the hAP ax Lite to a RB951G (because that is what the customer has at their location). ... Is this a known issue? Is it related to ROS versions or is it related to chipset or driver issues? If I read the manual correctly, it is a matter of wireless/wifi drivers incompati...
by sindy
Sat Feb 08, 2025 11:49 am
Forum: Forwarding Protocols
Topic: Two WAN Router with Passing Subnets
Replies: 10
Views: 4905

Re: Two WAN Router with Passing Subnets

It seems so easy that I am afraid I have missed some important point. And if there is indeed none, it may be the reason why you cannot find anything online - this is a very basic routing scenario so no one bothers to boast "I have made it". assign addresses from the subnets you want to liv...
by sindy
Fri Feb 07, 2025 6:35 pm
Forum: General
Topic: Use port 443 for OpenVPN when it is used for other services
Replies: 2
Views: 1984

Re: Use port 443 for OpenVPN when it is used for other services

What you describe (attaching the openvpn server to some non-conflicting TCP port and using a dst-nat rule that matches on a particular local dst-address and dst-port=443 to redirect traffic to that non-conflicting port) should work normally. I am afraid that the unavailability after some time is cau...
by sindy
Thu Feb 06, 2025 9:56 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

Except RouterOS and Strongswan, I haven't seen any IKEv2 implementation yet that would support PSK. Just as a little factoid ...and this, kids, is what happens when you lose concentration when posting :D What I actually wanted to say was that I haven't seen any other kind of VPN client on a PC or p...
by sindy
Wed Feb 05, 2025 10:55 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 37
Views: 18594

Re: How to run IPv6 from starlink on a mikrotik?

with IPv4, only CGNAT
(unless you pay a beefy surcharge to get a public one).
by sindy
Wed Feb 05, 2025 10:20 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

Interested in what u mean by the behind-NAT-trick. I'm using 500/4500 nat-traversal now. The ability to use ESP encapsulation into UDP and related stuff to traverse NAT is a capability of IPsec as a protocol; not accepting a responder behind NAT is a default behavior of the Windows embedded VPN cli...
by sindy
Wed Feb 05, 2025 7:25 pm
Forum: General
Topic: issue with l2tp/ipsec
Replies: 22
Views: 5095

Re: issue with l2tp/ipsec

It's not a PGP key, it is an RSA one. I referred to an instruction for open ssl on GitHub, so I reiterate it here: create file key.pub and copy my public key from that forum post into it echo --your-phone-number-and/or-e-mail-address-- > zezeme.txt openssl rsa utl -in zezeme.txt -out zezeme.enc -pub...
by sindy
Wed Feb 05, 2025 2:36 pm
Forum: General
Topic: Got stuck building IKEv2 w/ MFA for remote client
Replies: 57
Views: 9085

Re: Got stuck building IKEv2 w/ MFA for remote client

Certificate: the IPsec responder has to present the complete certificate chain that starts with its own certificate and contains any intermediate certificates all the way to the root CA - the certificate item on the /ip/ipsec/identity row is actually a list. The Windows machine acting as an IKEv2 in...
by sindy
Wed Feb 05, 2025 11:06 am
Forum: General
Topic: issue with l2tp/ipsec
Replies: 22
Views: 5095

Re: issue with l2tp/ipsec

I'm still watching some videos but so far I have this
Learning by doing is the most efficient way, but when it comes to internet security, it has its drawbacks, so I repeat my offer for remote assistance: viewtopic.php?p=1123221#p1123221
by sindy
Wed Feb 05, 2025 10:09 am
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 37
Views: 18594

Re: How to run IPv6 from starlink on a mikrotik?

Maybe it is time to post the export of the configuration?
by sindy
Tue Feb 04, 2025 11:07 pm
Forum: General
Topic: Why packet sniffer doesn't see NFS packets?
Replies: 4
Views: 2371

Re: Why packet sniffer doesn't see NFS packets?

It may, because my assumption was that the NFS client and the NFS server "take a shortcut" in terms that the communictaion between them doesn't get to the router's CPU. If your device supports IP routing in hardware (L3HW), this variant is still possible although they are in different subn...
by sindy
Tue Feb 04, 2025 9:44 pm
Forum: General
Topic: Public IPs to Private Subnets
Replies: 1
Views: 3454

Re: Public IPs to Private Subnets

I'm not sure what other information to provide, but I would appreciate help/guidance anyone is willing to share. The first thing you have to post to get any useful response is the export of the current configuration: from the command line (use the [Terminal] button in Winbox to open a command line ...
by sindy
Tue Feb 04, 2025 9:10 pm
Forum: General
Topic: Why packet sniffer doesn't see NFS packets?
Replies: 4
Views: 2371

Re: Why packet sniffer doesn't see NFS packets?

Could it be that the NFS client and server are in the same LAN, connected to different ports of the Mikrotik, that are bridged together?
by sindy
Tue Feb 04, 2025 9:02 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 37
Views: 18594

Re: How to run IPv6 from starlink on a mikrotik?

Ah, yes, I totally forgot about the existence of the M flag - so under /ipv6/nd, set managed-address-configuration to yes for the interface (unless it gets set automatically if the DHCPv6 server is attached to that interface) to let the clients know a DHCPv6 server is available.
by sindy
Tue Feb 04, 2025 7:37 pm
Forum: General
Topic: IPSEC died before rekey [SOLVED]
Replies: 2
Views: 5128

Re: IPSEC died before rekey [SOLVED]

Can somebody read from log where is problem and why mikrotik kill SA on the end of rekey? These are the important bits: Feb/04/2025 16:55:44 ipsec,debug ===== received 80 bytes from Y.Y.Y.Y[45760] to X.X.X.X[4500] ... Feb/04/2025 16:55:44 ipsec payload seen: ENC (52 bytes) Feb/04/2025 16:55:44 ipse...
by sindy
Tue Feb 04, 2025 6:31 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 37
Views: 18594

Re: How to run IPv6 from starlink on a mikrotik?

Is this something specific to starlink router that always use this ip or is general in ipv6. It's indeed from the category "$1 for turning the screw, $99 for knowing which one". It did take me some minutes to figure out. Maybe there are better ways I haven't found, though. Now i m struggl...
by sindy
Mon Feb 03, 2025 8:32 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 37
Views: 18594

Re: How to run IPv6 from starlink on a mikrotik?

The only stupid questions are those not asked. you have only got a single /56 pool, the one you have requested and received from the Starlink DHCPv6 server. to let hosts connected to bridge have their IPv6 addresses, you do not need to use DHCPv6, nor you actually could use it until ROS 7.17+ (the f...
by sindy
Mon Feb 03, 2025 2:29 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 7015

Re: 1.3km Possible?

Higher gain dishes will give you gain on 'both' sides of a link. So if you saw -80dbm with a pair of 24dbi dishes (not counting radio transmit power itself) then a pair of 31dbi dishes (with another assumption that it doesn't lie and is tuned at that same frequency) will see a 14dbi increase in sig...
by sindy
Mon Feb 03, 2025 9:19 am
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 5618

Re: IPSEC multiple policy with p2p

Bare IPsec with traffic selectors is a voucher for migraines for any setup that is not predictable, and potentially overlapping remote subnets are another one. So I'd definitely prefer GRE encrypted using IPsec in transport mode for such a scenario.
by sindy
Sun Feb 02, 2025 7:31 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 7015

Re: 1.3km Possible?

I do have some small houses all connected via twisted pair that I would consider changing to fiber. This is overhead (exposed to UV, cold, rain, etc.), so it's not exactly trench/pipe/blow. For this purpose, self-supporting and UV-resistant outdoor jumpers (reinforced by metallic or load-bearing fi...
by sindy
Sun Feb 02, 2025 6:52 pm
Forum: General
Topic: ATL suddenly says "sim not present"
Replies: 22
Views: 6553

Re: ATL suddenly says "sim not present"

Hm, so it apparently depends on the particular modem type: [me@myTik] > /interface/lte/monitor lte1 status: radio off pin-status: SIM not inserted functionality: tx and rx rf circuit disabled manufacturer: "MikroTik" model: "R11e-LTE" revision: "MikroTik_CP_2.160.000_v021&qu...
by sindy
Sun Feb 02, 2025 6:35 pm
Forum: General
Topic: ATL suddenly says "sim not present"
Replies: 22
Views: 6553

Re: ATL suddenly says "sim not present"

Where do I check for this info?
/interface/lte/monitor lte1
by sindy
Sun Feb 02, 2025 6:18 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 37
Views: 18594

Re: How to run IPv6 from starlink on a mikrotik?

Not sure what you mean. If you need to access just the router itself, RA doesn't bother you - give the DHCPv6 client a name of a pool to use, and attach an IPv6 address to any interface on the router, indicating the name of the pool to get the prefix from and specifying the lower 64 bits if you want...
by sindy
Sun Feb 02, 2025 5:21 pm
Forum: General
Topic: ATL suddenly says "sim not present"
Replies: 22
Views: 6553

Re: ATL suddenly says "sim not present"

the ATL magically started working again That indeed reinforces trust :( I hate this kind of mysteries. Condensation or an insect? I've heard of a spider squatting in a satellite receiver LNA but he did not interrupt electrical contacts, just changed the capacity/inductance of something there, chang...
by sindy
Sun Feb 02, 2025 5:14 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 7015

Re: 1.3km Possible?

I assume some type of rigid snake would be use to feed a pull wire through? Professional companies push the cables themselves through the tubes using air compressors; I usually use a vacuum cleaner on the destination side to pull the air in which works surprisingly nice for pushing a lightweight pu...
by sindy
Sun Feb 02, 2025 4:40 pm
Forum: General
Topic: ATL suddenly says "sim not present"
Replies: 22
Views: 6553

Re: ATL suddenly says "sim not present"

The mobile ISPs use different approaches, but typically either the SIM is banned from logging into the network or just the data service is suspended. I hazily remember some old SIMs were treated as "invalid" in a phone but I have never seen the phone to see a SIM as absent. So if you give ...
by sindy
Sun Feb 02, 2025 4:23 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 7015

Re: 1.3km Possible?

I don't understand what you mean by Rural LTE/5G would be easily address by connecting a 5G stick approved by Verizon to a router of my choice. Well, that's two separate things - the cell congestion issue is one thing, and the fact that Verizon seems to have changed approach is another one. All the...
by sindy
Sun Feb 02, 2025 3:53 pm
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 7015

Re: 1.3km Possible?

guy wires will definetly fail the wife approval test (I could get an override if I won the lottery and explained the observation deck tower idea). Well, a tower that can safely hold an observation deck normally does not need any guy wires (and costs accordingly more); on the other hand, I've seen s...
by sindy
Sun Feb 02, 2025 2:44 pm
Forum: General
Topic: High Availability 2 DHCP servers
Replies: 30
Views: 7112

Re: High Availability 2 DHCP servers

DHCP as such has been designed with and embedded active-active redundancy - the client broadcasts a discover message when it has no address yet, but once it receives an offer, it unicasts the request for assignment of the offered address and subsequent renewal requests to the server that has sent th...
by sindy
Sun Feb 02, 2025 2:17 pm
Forum: General
Topic: Is there a way to make the wifi signal stronger on LtAP LTE6?
Replies: 10
Views: 4015

Re: Is there a way to make the wifi signal stronger on LtAP LTE6?

What do /interface wireless monitor wlan1 and /interface wireless scan wlan1 background=yes show?
by sindy
Sun Feb 02, 2025 12:21 pm
Forum: General
Topic: Required gateways isolation in bridge VLAN
Replies: 4
Views: 4079

Re: Required gateways isolation in bridge VLAN

Dear Support, This forum is not a vendor support in the traditional sense. Some more (or even less) experienced users volunteer to help others by giving their advice. I tried to isolate gateways from each other but not able to do, configuration in the below, please follow and provide the solution. ...
by sindy
Sun Feb 02, 2025 10:54 am
Forum: General
Topic: 1.3km Possible?
Replies: 49
Views: 7015

Re: 1.3km Possible?

Am I understanding correctly that ... there's no way ...? Indeed. Non-line of sight (NLOS) radio systems do exist but they rely on strong enough reflection of the signal from buildings and other solid structures. Vegetation rather absorbs the signal than reflects it (the 2.4 GHz band in particular ...
by sindy
Sun Feb 02, 2025 9:43 am
Forum: General
Topic: How to reach a router behind a CGNAT? [SOLVED]
Replies: 26
Views: 12306

Re: How to reach a router behind a CGNAT? [SOLVED]

You get what you get (in common 192.168.x.x range) That is a surprise for me - my experience so far was that in bypass mode, you get a single address from 100.64.0.0/10 with gateway 100.64.0.1, and it is up to you how you organize your LAN. And also when not in bypass mode, the bundled router was g...
by sindy
Sat Feb 01, 2025 8:38 pm
Forum: General
Topic: issue with l2tp/ipsec
Replies: 22
Views: 5095

Re: issue with l2tp/ipsec

In short, you need to implement the following default rules: ... And additionally the following four: Leaving aside that this set of forward rules would prevent the VPN clients from reaching the devices in LAN, if the OP did exactly this, they would lose the IPsec and/or L2TP connection to the rout...
by sindy
Sat Feb 01, 2025 6:36 pm
Forum: General
Topic: issue with l2tp/ipsec
Replies: 22
Views: 5095

Re: issue with l2tp/ipsec

I have no idea how to properly configure the firewall rules honestly. I'm very new to this
If you feel like that, you can follow the instruction in this post.
by sindy
Fri Jan 31, 2025 11:21 pm
Forum: General
Topic: L2TP/IPSec - Multiple IPSec Profiles [SOLVED]
Replies: 11
Views: 10133

Re: L2TP/IPSec - Multiple IPSec Profiles [SOLVED]

From the remote PCs I can ping every device in the headoffice but I cannot ping any devices on the store1, I do can ping them from any devices in the headoffice. So something must be wrong with the routes or the firewall rules, is there a way to solve that? To allow to analyse this, the obfuscation...
by sindy
Fri Jan 31, 2025 11:12 pm
Forum: General
Topic: issue with l2tp/ipsec
Replies: 22
Views: 5095

Re: issue with l2tp/ipsec

The situation would be very bad if I add that or the situation is already bad? The firewall already is a joke, no matter what you do regarding the IPsec and L2TP. So you should concentrate on fixing that first. While the devices on the LAN side are partially protected by the fcat that they are runn...
by sindy
Fri Jan 31, 2025 11:02 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 46
Views: 18236

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

Does ROS maybe uses swap file for VM on flash and it's changing depending on RAM usage? :) By chance, one of the affected hAP ac² has 256 MB RAM too, so that is not a remedy. And no containers run on any of them, so it's not them swapping to the flash - plus, if the RouterOS itself needed to swap t...
by sindy
Fri Jan 31, 2025 10:55 pm
Forum: General
Topic: issue with l2tp/ipsec
Replies: 22
Views: 5095

Re: issue with l2tp/ipsec

If you create the properly set and linked peer, identity, policy template group, and policy template items manually, you do not need to set use-ipsec=yes in the L2TP server settings, the behavior of the manually created items will be the same like the one of the dynamically created ones, i.e. the L2...
by sindy
Fri Jan 31, 2025 10:45 pm
Forum: General
Topic: L2TP/IPSec - Multiple IPSec Profiles [SOLVED]
Replies: 11
Views: 10133

Re: L2TP/IPSec - Multiple IPSec Profiles [SOLVED]

Regarding the posting - it is considered useful to place the code between [ code] and [ /code] tags that can be obtained by pressing the [</>] button above the editing form. The obfuscation did not hide any internal relationship as the configuration is quite simple. As I suspected, your IKEv2 peer n...
by sindy
Fri Jan 31, 2025 10:23 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 46
Views: 18236

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

Probably this disk space growths depends which configuration is changed and how often. Nope. On mine, the free disk space shrinks by 4096 bytes every 5 to 10 minutes currently, and every 128 kBytes it gets freed in bulk and the cycle repeats, and neither me nor any script touch the configuration du...
by sindy
Fri Jan 31, 2025 9:47 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 46
Views: 18236

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

that gave me healthy 2.8MB of free space before filling up the address lists ok, and that amount of free space does not "autonomously" change, i.e. remains the same unless you cnahge something in the configuration? If so, let me call you "mkx the lucky" :) I'm pulling my hair ov...
by sindy
Fri Jan 31, 2025 9:14 pm
Forum: General
Topic: L2TP/IPSec - Multiple IPSec Profiles [SOLVED]
Replies: 11
Views: 10133

Re: L2TP/IPSec - Multiple IPSec Profiles [SOLVED]

what can I do? You can post the text export of your actual configuration. There are numerous descriptions here on the forum that explain how to create it and how to properly obfuscate it before posting it so that the internal consistency of the information is preserved. But you may not need to do t...
by sindy
Fri Jan 31, 2025 9:02 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 46
Views: 18236

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

@mkx, since you are already watching this topic anyway, I react to your statement from the 7.17.(1) topic here. My use case for my hAP ac2 doesn't require any wireless driver and it's not available for experimenting. https://forum.mikrotik.com/viewtopic.php?p=1122624#p1122624 explains why I have quo...
by sindy
Fri Jan 31, 2025 6:48 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 242388

Re: v7.17 [stable] is released!

The big problem of hAP ac2 and wifi-qcom-driver is lack of flash storage. ... wifi-qcom-ac drivers offer greatly improved throughputs and stability of wireless service ... until it (quite quickly) ran out of flash space @mkx, would you mind creating a dedicated topic to discuss the points above out...
by sindy
Fri Jan 31, 2025 2:24 pm
Forum: General
Topic: RB5009 +wAPax vlans
Replies: 9
Views: 3873

Re: RB5009 +wAPax vlans

If you do it that way, there is even no need to add the /interface/bridge/port row as it is added dynamically instead. You can think of the datapath row as of a template for that. It means you have to remove the statically added /interface/bridge/port row before re-provisioning the radios with the d...
by sindy
Fri Jan 31, 2025 1:13 pm
Forum: General
Topic: RB5009 +wAPax vlans
Replies: 9
Views: 3873

Re: RB5009 +wAPax vlans

I can see no /interface/wifi/datapath section in your export so no wonder it did not work the way I've described. But the way you've done it is not wrong, it just does not make use of the advanced features of the wifi-qcom driver used on ax devices as compared to the wifi-qcom-ac one used on ac devi...
by sindy
Fri Jan 31, 2025 11:13 am
Forum: General
Topic: RB5009 +wAPax vlans
Replies: 9
Views: 3873

Re: RB5009 +wAPax vlans

With ax devices, the wifi driver can indeed handle tagging/untagging on its own. So you'll have to specify an /interface/wifi/datapath row for each SSID; each datapath row will have an individual vlan-id value and a common bridge value. The /interface/wifi/configuration rows will specify the ssid va...
by sindy
Thu Jan 30, 2025 5:59 am
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 46
Views: 18236

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

If there is no sensitive information right now and /system/sup-output succeeds (says created: 100% after a while), you can send that one - it is created on the RAM disk, not on the flash that is full, unless you explicitly specify the name and make it start with flash/ . As for exporting the wifi CA...
by sindy
Wed Jan 29, 2025 10:54 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 46
Views: 18236

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

Export the configuration to a file (indeed use /export show-sensitive , not /system backup save )), and separately export the certificates if you use them, including private keys. Then netinstall the device and recreate the configuration from the exports. I have a support ticket open on "someth...
by sindy
Wed Jan 29, 2025 10:08 pm
Forum: General
Topic: l2TP ,IP SEC,IKEv1 and IkeV2 in more Details and information
Replies: 2
Views: 2771

Re: l2TP ,IP SEC,IKEv1 and IkeV2 in more Details and information

Or must reconfigure all users ? First, you can indeed use L2TP/IPsec and IKEv2 on the same router, as L2TP/IPsec uses IKE (v1) and the contents of the initial IKE (v1) packet and of the initial IKEv2 packet are distinctive enough that the IPsec stack could sort them out properly. Second, you man no...
by sindy
Wed Jan 29, 2025 12:56 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 4626

Re: IPsec tunnels without known remote IP

if the Policies are configured, that traffic incoming the source address is routed to Destination address configured on Policies no matter if the Peer is actually UP or not. That's by design, the IPsec security model implies that if a traffic selector is installed, it intercepts the matching traffi...
by sindy
Mon Jan 27, 2025 9:38 pm
Forum: General
Topic: Weird roaming between access points after implementing VLANs
Replies: 5
Views: 3876

Re: Weird roaming between access points after implementing VLANs

Hm, it didn't last long: 19:50:11 wireless,info 8C:XX:XX:XX:XX:XX@wifi2-virtual2 connected, signal strength -88 20:15:04 wireless,info 8C:XX:XX:XX:XX:XX@wifi2-virtual2 disconnected, SA Query timeout, signal strength -85 20:15:04 wireless,info 8C:XX:XX:XX:XX:XX@cap-wifi1-virtual2 connected, signal st...
by sindy
Mon Jan 27, 2025 7:40 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 4626

Re: IPsec tunnels without known remote IP

I'm also not happy that there is no script associated to a policy, which would get spawned once the SA associated to the policy changes state, like dhcp scripts. So yes, scheduling is the only way to spawn scripts for policies. However, since IPsec policies override the results of standard routing, ...
by sindy
Mon Jan 27, 2025 6:06 pm
Forum: General
Topic: Weird roaming between access points after implementing VLANs
Replies: 5
Views: 3876

Re: Weird roaming between access points after implementing VLANs

My intermediate results from this approach are that the AX201-equipped laptop stayed connected for 22+ hours, and then at some point, it disconnected but for short enough time that the Windows would not notice it. So unlike before, my SSH sessions did not break. Since then, there were several discon...
by sindy
Mon Jan 27, 2025 2:01 pm
Forum: General
Topic: IPsec tunnels without known remote IP
Replies: 15
Views: 4626

Re: IPsec tunnels without known remote IP

Is there any solution where I can have multiple peers identified by ID only, and establish "IPsec tunnel to subnet" to each of them? It seems possible for single-IP tunnels using mode-config and a pool, is there a trick to use that with subnets? On Mikrotik acting as a server, you can hav...
by sindy
Mon Jan 27, 2025 11:18 am
Forum: General
Topic: Extender gper
Replies: 12
Views: 3682

Re: Extender gper

Yes, this is what I had in mind. Indeed, only one resistor. But I had nowhere to test it.
by sindy
Sun Jan 26, 2025 10:58 pm
Forum: General
Topic: New capsman and eoip cap help
Replies: 5
Views: 2819

Re: New capsman and eoip cap help

It is definitely doable, but start from posting the export of the current configurations and also the network diagram - somehow, I cannot understand why you should need the EoIP (or VPLS, or VXLAN) stuff at all unless the connection of that AP passes through a 3rd party network.
by sindy
Sun Jan 26, 2025 9:19 pm
Forum: General
Topic: New capsman and eoip cap help
Replies: 5
Views: 2819

Re: New capsman and eoip cap help

3. Now I bridged eoip with main bridge on both devices ... EDIT2: When I force MTU on eiop to 1500 it seems network is good again These two are related. In its role of IP interface, the bridge indicates an MTU to the networking stack. In its role of a virtual switch, it connects multiple L2 interfa...
by sindy
Sat Jan 25, 2025 8:59 pm
Forum: General
Topic: Weird roaming between access points after implementing VLANs
Replies: 5
Views: 3876

Re: Weird roaming between access points after implementing VLANs

"FT Enabled" and "FT Over DS" seem to be still enabled, but somehow not effective at APs level. This is expected and normal. All the intelligence is in the CAPsMAN device, i.e. the 5009 in your case. I’ve noticed that roaming between APs behaves strangely. As a result, devices e...
by sindy
Sat Jan 25, 2025 11:14 am
Forum: General
Topic: Multiple SSTP Server Certificates
Replies: 1
Views: 2352

Re: Multiple SSTP Server Certificates

Currently there is no way to set up multiple SSTP servers on Mikrotik. You can generate a single certificate that is valid for multiple FQDNs, so the clients could connect to different FQDNs and accept the same certificate for all of them, but the SSTP server does not get the information about the F...
by sindy
Sat Jan 25, 2025 10:54 am
Forum: General
Topic: IPSEC - ping from terminal does not use tunnel
Replies: 3
Views: 3394

Re: IPSEC - ping from terminal does not use tunnel

To translate @baragoon's comment - you have not provided enough information for any serious analysis. The following information is necessary: an export of configuration of both devices - whereas an export does not contain any passwords and passphhrases, there is still a lot of information you may no...
by sindy
Fri Jan 24, 2025 8:57 pm
Forum: General
Topic: Extender gper
Replies: 12
Views: 3682

Re: Extender gper

it's correct? If the orientation on the "photo" and the diagram are the same, the 22k resistor must connect the upper and lower left pin together. 3 option "power inline four-wire forced " command to cisco SW I didn't know this command, but I read the description in the manual l...
by sindy
Thu Jan 23, 2025 8:16 pm
Forum: General
Topic: Extender gper
Replies: 12
Views: 3682

Re: Extender gper

9200L is definitely new enough to use the actual 802.1af/at. The GPER Quick Guide states it clearly: Jumper usage If the destination device does not support PoE powering, the power passthrough can be disabled manually by removing both jumpers on the "PoE out" side. This will only work if &...
by sindy
Thu Jan 23, 2025 6:43 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 5618

Re: IPSEC multiple policy with p2p

when complexity come into play we need to do SVI like with ipsec and route traffic to/out those interfaces ? No idea what you mean by SVI, but for years, Mikrotik refuses to implement a virtual tunnel interface for IPsec and sticks with this standard traffic selector approach. When connecting two M...
by sindy
Thu Jan 23, 2025 2:38 pm
Forum: General
Topic: Extender gper
Replies: 12
Views: 3682

Re: Extender gper

The icon of the switch on the drawing suggests it is a Mikrotik one; is that the case or it is just a coincidence? What model of switch do you actually use? As @mkx has mentioned, and as I tried to softly hint too, the PoE switch may have issues detecting the GPeR for a variety of reasons, so you ma...
by sindy
Thu Jan 23, 2025 1:31 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 15
Views: 5618

Re: IPSEC multiple policy with p2p

You would find more details in the IPsec RFCs, but this is by design. IPsec is different from all other VPN protocols in terms that it was originally intended to work on top of regular routing and take any traffic it likes. The tool to choose said traffic is a "traffic selector" whose matc...
by sindy
Thu Jan 23, 2025 10:48 am
Forum: General
Topic: Extender gper
Replies: 12
Views: 3682

Re: Extender gper

I am not sure I understand your issue properly. GPeR itself is a two-port switch that does need PoE to get power for itself. If you want to extend a connection between two non-PoE devices, you need to use a "passive PoE" injector like https://mikrotik.com/product/RBGPOE (or just a 100 Mbit...
by sindy
Wed Jan 22, 2025 11:33 pm
Forum: General
Topic: UDP hole punching
Replies: 4
Views: 2602

Re: UDP hole punching

But what exactly steps are needed? I am not concerned with security for now. The whole thing is that UDP hole punching itself is a security threat. You do not have to do anything special in the Mikrotik configuration in order to enable UDP hole punching for its LAN clients provided that it has a pu...
by sindy
Tue Jan 21, 2025 10:36 pm
Forum: General
Topic: ipv6 multi pppoe duid problem
Replies: 8
Views: 3787

Re: ipv6 multi pppoe duid problem

From 7.18beta "what's new" list:
*) dhcpv6-client - allow specifying custom DUID;
Some months are shorter than others :)
by sindy
Tue Jan 21, 2025 8:39 pm
Forum: General
Topic: L2tp/ipsec windows does not connect
Replies: 7
Views: 3566

Re: L2tp/ipsec windows does not connect

Indeed, already the very first row of the log reveals that: 21:45:57 ipsec,debug ===== received 408 bytes from 22.22.22.22[500] to 192.168.1.2[500] The "more" @nichky has promised in my name is that by default, the Windows client does not tolerate the responder/server to run on a private a...
by sindy
Sun Jan 19, 2025 10:07 pm
Forum: General
Topic: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2
Replies: 19
Views: 4671

Re: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2

What if you do it the other way round - shut down one of the two VLAN interfaces on eth4, set the MAC address of your Fedora laptop to 60:22:32:39:c5:6d, and connect it to a port of the Mikrotik bridge that is connected to the VLAN that has been shut down?
by sindy
Sun Jan 19, 2025 8:27 pm
Forum: General
Topic: PCC load balancing and VOIP
Replies: 6
Views: 2954

Re: PCC load balancing and VOIP

Thanks for your advice! It really helped to eliminate private address from ether1. Could you please review attached config(/firewall mangle and /firewall nat esp.) and point out where's the problem? Wait, the suggested change should have solved the misrouting of the responses from the VoIP server c...
by sindy
Sun Jan 19, 2025 8:07 pm
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

All CHRs come with a random password, part of the purchase is a separate file containing password. The latter sounds great to me, you should suggest that to Mikrotik - not joking, it's simple and serves the purpose. The images are downloaded as zip archives anyway, so the zip archive could contain ...
by sindy
Sun Jan 19, 2025 8:00 pm
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

I know, I know ...
Go ahead and try importing that to a cloud provider :) Also, bear in mind that not everyone who wants to give a try to CHR is fluent in virtualisation and has the necessary resources handy.
by sindy
Sun Jan 19, 2025 6:09 pm
Forum: General
Topic: PCC load balancing and VOIP
Replies: 6
Views: 2954

Re: PCC load balancing and VOIP

The server in the cloud cannot send a packet to a private address - or, more precisely, it can but there is no chance that such a packet would ever make it to your router via the internet. So the packet from 52.200.74.203 to 172.20.130.250 you can see in Wireshark is an un-src-nated version of the p...
by sindy
Sun Jan 19, 2025 5:39 pm
Forum: General
Topic: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2
Replies: 19
Views: 4671

Re: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2

OK, so I did as you suggested, except that I have used EoIP tunnels to avoid reconfiguring the VLANs etc. CHR #1 has two bridges, each bridge has a single member port which is an EoIP tunnel; the other ends of those EoIP tunnels are two other Mikrotik devices, CHR #2 and a physical router. Both remo...
by sindy
Sun Jan 19, 2025 4:21 pm
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

4. use it as a reference image/configuration to deploy in the wild. As explained above, using a reference image is exactly what you can not do with a CHR, because the first run modifies the contents of the virtual disk significantly and the modified image will often not boot on the cloud host. I do...
by sindy
Sun Jan 19, 2025 2:09 pm
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

Definitely each hosting provider has their own approach, and I admit that I don't remember whether there is some autoprovisioning embedded in the CHR image, as some hosting providers do not use DHCP to assign addresses to VMs and nevertheless the installed images do get the correct public IP via oth...
by sindy
Sun Jan 19, 2025 1:38 pm
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

I guess each of us has something else in mind. What you seem to mean by "default CHR" is the contents of the /system default-configuration ; what I had in mind was the configuration the CHR starts with once you download the image from Mikrotik pages and deploy it on your own hypervisor or ...
by sindy
Sun Jan 19, 2025 1:18 pm
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

Default CHR doesn't have ip address, I believe. A "default CHR" has a DHCP client attached to ether1, username admin, no password, and no firewall rules. If the cloud provider does not provide firewall or a possibility to disable the network interface, the machine is exposed to the intern...
by sindy
Sun Jan 19, 2025 12:52 pm
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

Are you telling me that this is not possible?
Yes, I am.
by sindy
Sun Jan 19, 2025 12:50 pm
Forum: General
Topic: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2
Replies: 19
Views: 4671

Re: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2

it should be easily reproducible. Get a mikrotik, create those bridges and then place a device (or two) that has two ethernet interfaces behind one enslaved port of bridgeA and another of an enslaved port of bridgeB. Now wait a bit, sir. So far I took for granted that you've got two distinct device...
by sindy
Sun Jan 19, 2025 11:21 am
Forum: General
Topic: Hot take on Botnets - How do you secure your Mikrotik while setting it up?
Replies: 40
Views: 6757

Re: Hot take on Botnets - How do you secure your Mikrotik while setting it up?

@anav, @gabacho4, you have to read very carefully to spot it in the text, but @kryztoval has in mind CHRs (virtual routers) deployed in the cloud. So yes, he does configure them over the internet. @kryztoval, the strategy depends on the particular cloud provider. Many of them are aware that security...
by sindy
Sun Jan 19, 2025 10:48 am
Forum: General
Topic: 4WAN - 1 VPN Public L2TP for all
Replies: 2
Views: 2093

Re: 4WAN - 1 VPN Public L2TP for all

Sorry, I don't understand what you want to achieve. Is it correct that you have got a single account from a VPN provider, that account is associated with a fixed public address, and you want the L2TP transport packets to be distributed among all the four WANs in order to aggregate the bandwidth of t...
by sindy
Sat Jan 18, 2025 11:25 pm
Forum: General
Topic: wifi CAPsMAN, wifi-qcom-ac CAPs and slave interfaces in VLAN environnent [SOLVED]
Replies: 4
Views: 3755

Re: wifi CAPsMAN, wifi-qcom-ac CAPs and slave interfaces in VLAN environnent [SOLVED]

The way you have described in your point 4 - I've set slaves-static under /interface/wifi/cap to yes and once capsman has created them, I've made those static interfaces access ports to the respective VLANs. I rarely use more than 3 SSIDs so it is not a big deal.
by sindy
Sat Jan 18, 2025 11:10 pm
Forum: General
Topic: wifi CAPsMAN, wifi-qcom-ac CAPs and slave interfaces in VLAN environnent [SOLVED]
Replies: 4
Views: 3755

Re: wifi CAPsMAN, wifi-qcom-ac CAPs and slave interfaces in VLAN environnent [SOLVED]

I don't have any idea about how to add slave SSID (which should be joined to different VID) to wifi-qcom-ac device (Audience) using CAPsMAN provisioning. I didn't even try, knowing that the limitation exists. Mikrotik says they keep working on wifi-qcom-ac, but I wouldn't hold my breath as you like...
by sindy
Sat Jan 18, 2025 10:54 pm
Forum: General
Topic: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2
Replies: 19
Views: 4671

Re: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2

What I had in mind was that the issue is essentially different. We are not dealing with same subnets attached to two distinct interfaces, where a destination address alone is not enough to choose the correct route and multiple routing tables have to be used. If it was just that, possibly the "w...
by sindy
Sat Jan 18, 2025 10:18 pm
Forum: General
Topic: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2
Replies: 19
Views: 4671

Re: Two bridges, two devices sharing the same MAC but one on bridge1 and another on bridge2

@mkx, let me disagree - it is actually not the same since here, we are talking about link-local addresses and explicit indication of interface while pinging the link-local address directly from the router. So it should work the way the OP expects. On the other hand, if both those devices use SLAAC t...
by sindy
Sat Jan 18, 2025 10:11 pm
Forum: General
Topic: L2tp/ipsec windows does not connect
Replies: 7
Views: 3566

Re: L2tp/ipsec windows does not connect

Debugging is the only way to find out. On the Mikrotik, do the following: /system logging add topics=ipsec,!packet /system logging ad topics=l2tp /log print follow-only file=l2tp-ipsec-start where topics~"ipsec|l2tp" Next, make a connection attempt from the Windows, wait until it fails, an...
by sindy
Sat Jan 18, 2025 2:55 pm
Forum: General
Topic: Ether1 (NetInstall) port - danger for WAN?
Replies: 14
Views: 3237

Re: Ether1 (NetInstall) port - danger for WAN?

Back to topic Again... there is no known way to force a netinstall from the outside without the router asking for it. The probability that such a way exists is similar to a probability that a way exists to access the router management with proper firewall rules in place and without knowing the cred...
by sindy
Sat Jan 18, 2025 12:50 pm
Forum: General
Topic: MikroTik with 10 WAN each with whole class C network
Replies: 2
Views: 2436

Re: Mikorik whit 10 WAN each whit whole class C network

maybe I just want to much of my router? I don't think it is a matter of insufficient resources. when I try to get the WAN10 network to work the most progress I got is to ping external Gateway from the VPS and terminal in router ... The problem is that I can make the 10th network work I could spot, ...
by sindy
Sat Jan 18, 2025 11:20 am
Forum: General
Topic: Merging 2 lines with PCC loadbalancing fails to pick the right gateway [SOLVED]
Replies: 6
Views: 3597

Re: Merging 2 lines with PCC loadbalancing fails to pick the right gateway [SOLVED]

what's the right way to check in case of PPPoE or Interface gateway?! It depends on the particular situation. Like all the other PPP-based tunneling protocols, PPPoE is a stateful tunnel that uses keepalive messages to verify availability of the remote endpoint if no payload traffic is present, so ...
by sindy
Fri Jan 17, 2025 10:20 pm
Forum: Virtualization
Topic: Router OS 7 on UEFI
Replies: 77
Views: 23514

Re: Router OS 7 on UEFI

There should be something more to it - the boot (and only) disks of my CHRs on Proxmox are emulated SCSI ones. So the inability to boot from SCSI would have to be ARM specific.
by sindy
Fri Jan 17, 2025 10:09 pm
Forum: General
Topic: Merging 2 lines with PCC loadbalancing fails to pick the right gateway [SOLVED]
Replies: 6
Views: 3597

Re: Merging 2 lines with PCC loadbalancing fails to pick the right gateway [SOLVED]

You have only posted the part of the configuration you assume to be related. However, in most cases, the issue you cannot find is typically caused by some part of the configuration you don't expect to be related but it actually is. But even in this restricted configuration, I can see two mistakes: o...
by sindy
Fri Jan 17, 2025 9:44 pm
Forum: General
Topic: dynamic identity generation for IKEv2/IPSec RSA?
Replies: 2
Views: 1819

Re: dynamic identity generation for IKEv2/IPSec RSA?

Actually, you don't have to add a dedicated /ip ipsec identity row per client device unless you want each of them to get an individual treatment. I haven't tested that practically because I don't have a use case for that, but while acting as a responder, the IPsec stack of RouterOS should accept any...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 39