Community discussions

MikroTik App

Search found 22337 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 75
by anav
Sat Jan 11, 2025 10:22 pm
Forum: Beginner Basics
Topic: Printer on different VLAN
Replies: 18
Views: 997

Re: Printer on different VLAN

What makes sense is specific to your location. How is the printer connected to the router, via ethernet jack at specific location, are there managed switches in between etc etc...... Clearly if all users are in vlan10, why put it on its own vlan. If untrusted users are allowed to use the printer, no...
by anav
Sat Jan 11, 2025 9:42 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 285
Views: 35093

Re: wAP ax?

Washingstate, Maine, Oregon etc. are more than welcome to Join Canada.
Was going to included California, but its dealing with real issues.

I am likely to replace my TPLink products with this.
https://www.tp-link.com/us/business-net ... da-eap770/
by anav
Sat Jan 11, 2025 9:34 pm
Forum: Beginner Basics
Topic: Is there a simple way to hang a virtual "Out of order" sign?
Replies: 4
Views: 193

Re: Is there a simple way to hang a virtual "Out of order" sign?

All employees have a cell phone......
Send mass text message - internet out restoration time est XX:XX Hrs.
by anav
Sat Jan 11, 2025 8:45 pm
Forum: Beginner Basics
Topic: Separate LANS using Wireless Wire Cube, Non VLAN Router
Replies: 5
Views: 184

Re: Separate LANS using Wireless Wire Cube, Non VLAN Router

You can put another router like hex refresh between ISP router and first 60HZ device.
by anav
Sat Jan 11, 2025 6:49 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 415
Views: 391222

Re: NEW FEATURE: Back to Home VPN

Fresh Questions: Observation: One only needs the APP to create the first user ( the smartphone itself ). It automatically turns on BTH VPN, and creates the first two entries! I had thought one needed to manually turn on BTH VPN in ip cloud first. 1. When creating the the tunnel from the phone it wou...
by anav
Sat Jan 11, 2025 4:29 pm
Forum: Beginner Basics
Topic: Mgmt vlan not available (Crs 328 24p 4s)
Replies: 13
Views: 684

Re: Mgmt vlan not available (Crs 328 24p 4s)

the idea is that 192.168.77.1/30 means only two usable IP addresses 192.168.77.1 and 192.167.77.2 hence plug in your laptop to ether24 and ensure 192.168.77.2 is set manually on the laptops IPV4 settings. This creates a safe spot to do vlan configs on any mikrotik device. You can disable the port af...
by anav
Sat Jan 11, 2025 1:01 am
Forum: Beginner Basics
Topic: Mgmt vlan not available (Crs 328 24p 4s)
Replies: 13
Views: 684

Re: Mgmt vlan not available (Crs 328 24p 4s)

Only management vlan has bridge tagged in /interface bridge vlan. .... model = CRS328-24P-4S+ # serial number = /interface bridge add ingress-filtering=no name=Bridge vlan-filtering=yes /interface ethernet set [ find default-name=ether24 ] name=OffBridge24 /interface vlan add comment="\"MG...
by anav
Fri Jan 10, 2025 10:41 pm
Forum: General
Topic: Wireguard config help
Replies: 13
Views: 592

Re: Wireguard config help

# model = RB952Ui-5ac2nD # serial number = /interface bridge add name=bridge1 /interface list add name=WAN add name=LAN /interface list member add interface=ether1 list=WAN add interface=wg1 list=WAN add interface=bridge1 list=LAN /ip pool add name=bridge-pool ranges=192.168.88.2-192.168.88.254 /ip ...
by anav
Fri Jan 10, 2025 10:27 pm
Forum: Beginner Basics
Topic: Mgmt vlan not available (Crs 328 24p 4s)
Replies: 13
Views: 684

Re: Mgmt vlan not available (Crs 328 24p 4s)

/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc. )
by anav
Fri Jan 10, 2025 10:18 pm
Forum: General
Topic: Failover
Replies: 3
Views: 174

Re: Failover

If WAN1 is primary,,,,, /routing table add fib name=via-WAN2 /ip firewall mangle add chain=input action=mark-connection connection-mark=no-mark in-interface=WAN2 \ new-connection-mark=incoming-wan2 passthrough=yes add chain=output action=mark-routing connection-mark=incoming-wan2 \ new-routing-mark=...
by anav
Fri Jan 10, 2025 9:56 pm
Forum: General
Topic: Issue migrating from RB750Gr3 to rb5009ug_s_in, LAN can't access internet
Replies: 3
Views: 233

Re: Issue migrating from RB750Gr3 to rb5009ug_s_in, LAN can't access internet

You cannot successfully take one configuration from one model and import it into another. The best case is copying bits of the config at a time from the /export file and pasting into the new router. Your subnet is all over the map 192.168.88 or 192.168.3 or 192.168.2 LOL Enable your fricken firewall...
by anav
Fri Jan 10, 2025 9:54 pm
Forum: General
Topic: Wireguard peer sets a default ListeningPort=51820
Replies: 6
Views: 476

Re: Wireguard peer sets a default ListeningPort=51820

Can you post a link to wireguard peer generator. I was unaware that MT had such a tool??
OR
Are you talking about BTH WG vpn??
by anav
Fri Jan 10, 2025 5:51 pm
Forum: Beginner Basics
Topic: Mgmt vlan not available (Crs 328 24p 4s)
Replies: 13
Views: 684

Re: Mgmt vlan not available (Crs 328 24p 4s)

Without seeing any config, no facts, no evidence, impossible to advise further.
by anav
Fri Jan 10, 2025 5:48 pm
Forum: Beginner Basics
Topic: Simple Bridge with Firewall rules for Ether1 (internet))
Replies: 15
Views: 1459

Re: Simple Bridge with Firewall rules for Ether1 (internet))

add a firewall address list
add src-address-list=Name of firewall list above to the dsntnat rul
by anav
Fri Jan 10, 2025 5:08 pm
Forum: General
Topic: Failover
Replies: 3
Views: 174

Re: Failover

In the case of Primary WAN1 and Secondary or Backup WAN2: In this case all traffic exits the router via WAN1 and one thinks primarily of LAN traffic. However, any external originated traffic arriving at the router will go in the appropriate WAN ( by IP address or dyndns url) but will exit WAN1. To e...
by anav
Fri Jan 10, 2025 3:05 am
Forum: General
Topic: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]
Replies: 10
Views: 785

Re: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]

I dont understand the need for step 6. Router B in both BTH and normal wireguard is the client for handshake never the server ????
by anav
Fri Jan 10, 2025 3:04 am
Forum: General
Topic: SMB access while on WireGuard
Replies: 3
Views: 284

Re: SMB access while on WireGuard

Okay, repost config if any issues, bound to be few as changes often take few iterations, ops normal.
by anav
Fri Jan 10, 2025 3:01 am
Forum: General
Topic: Routing issue
Replies: 3
Views: 256

Re: Routing issue

Config of both required if not resolved ( model of switch )

/export file=anynameyouwish (minus router serial number, any public WANIP information, keys etc.)
by anav
Fri Jan 10, 2025 12:40 am
Forum: Beginner Basics
Topic: Mgmt vlan not available (Crs 328 24p 4s)
Replies: 13
Views: 684

Re: Mgmt vlan not available (Crs 328 24p 4s)

Find the appropriate switch example: viewtopic.php?t=143620
Decent video: https://www.youtube.com/watch?v=YLtGQAQ8iS0
by anav
Fri Jan 10, 2025 12:04 am
Forum: General
Topic: Mikrotik and APs VLAN
Replies: 7
Views: 393

Re: Mikrotik and APs VLAN

Why vlan1 on the unifi? Unifi typically accepts whatever traffic is coming to it untagged as the trusted or management vlan and the tagged vlans as data vlans. Therefore on the MT suggest you use three vlans and forget about using vlan1 for anything ( it works in the background ) vlan10 - home ( wir...
by anav
Thu Jan 09, 2025 11:15 pm
Forum: General
Topic: Quick Set Bug v7.16.2
Replies: 3
Views: 318

Re: Quick Set Bug v7.16.2

IMHO quickset should be removed until its actually stable, intuitive and useful.
by anav
Thu Jan 09, 2025 11:13 pm
Forum: General
Topic: Mikrotik and APs VLAN
Replies: 7
Views: 393

Re: Mikrotik and APs VLAN

Brand/Model of Access point?
Config of MT router ( and ap if mt)
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc. )
by anav
Thu Jan 09, 2025 11:10 pm
Forum: General
Topic: Wireguard config help
Replies: 13
Views: 592

Re: Wireguard config help

I suspect you may need the MT to act as a router vice switch/bridge?
by anav
Thu Jan 09, 2025 11:08 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 14
Views: 1800

Re: NORMUNDS FOR PRIME MINISTER

Attempt5: " Damn, I forgot the keys in the car! "
Attempt6: " I wonder if these glasses make me look smarter? "
by anav
Thu Jan 09, 2025 11:04 pm
Forum: Beginner Basics
Topic: Low internet speed when we did PCC load balancing and connecting 2 ISPs on Mikrotik
Replies: 6
Views: 787

Re: Low internet speed when we did PCC load balancing and connecting 2 ISPs on Mikrotik

Concur with jaclaz, its a waste of time for us to chase what ifs. Post your latest config that is not working, then we will provide suggestions. If that doesnt work, post that config with the latest config and we will work from that. We can best work from accurate facts presented....... and after re...
by anav
Thu Jan 09, 2025 10:57 pm
Forum: Beginner Basics
Topic: Printer on different VLAN
Replies: 18
Views: 997

Re: Printer on different VLAN

Hi Whussup..... I review the config from top to bottom and thus its what I noticed first off. Concur it doesnt effect any of the wifi settings. However since you do have those port in /interface bridge ports, it still appears to the reader/reviewer to be in error for them to be disabled! I know for ...
by anav
Thu Jan 09, 2025 1:33 pm
Forum: General
Topic: Quick Set Bug v7.16.2
Replies: 3
Views: 318

Re: Quick Set Bug v7.16.2

Rule of Thumb: Use quickset at your own peril.
by anav
Thu Jan 09, 2025 1:31 pm
Forum: General
Topic: Will MikroTik firewall appliances...
Replies: 4
Views: 474

Re: Will MikroTik firewall appliances...

Yeah nervous that some giant Chinese company will buy MT out and start adding all those nifty features you desire, and of course a hidden back door to the red army.
by anav
Thu Jan 09, 2025 1:25 pm
Forum: Beginner Basics
Topic: Remote Access VPN
Replies: 4
Views: 407

Re: Remote Access VPN

Mikrotik does not block any outgoing LAN to WAN traffic by default, so why are you assuming the MT is the problem? Further how is one supposed to provide any advice on your configuration if its not provided. /export file=anynameyouwish (minus router serial number, any public WANIP information, passw...
by anav
Thu Jan 09, 2025 1:22 pm
Forum: Beginner Basics
Topic: Hotspot on Bridge VLAN
Replies: 12
Views: 851

Re: Hotspot on Bridge VLAN

I am confident you will find the problem then. GLuck.
by anav
Thu Jan 09, 2025 2:32 am
Forum: General
Topic: SMB access while on WireGuard
Replies: 3
Views: 284

Re: SMB access while on WireGuard

1. Wouldnt call my Bridge "LAN" as LAN is already used on the router for standard nomenclature. Personal choice but at least make it bridge-LAN etc. 2. Why do you have two IP pools but only one subnet ( aka the one you attach to the bridge-LAN )? 3. Highly recommend you set this to NONE< a...
by anav
Thu Jan 09, 2025 1:56 am
Forum: Beginner Basics
Topic: Printer on different VLAN
Replies: 18
Views: 997

Re: Printer on different VLAN

/interface ethernet set [ find default-name=ether1 ] name=ether1-WAN set [ find default-name=ether2 ] disabled= yes name=ether2-LAN set [ find default-name=ether3 ] disabled= yes name=ether3-LAN set [ find default-name=ether4 ] disabled= yes name=ether4-LAN set [ find default-name=ether5 ] disabled...
by anav
Wed Jan 08, 2025 11:11 pm
Forum: Beginner Basics
Topic: Hotspot on Bridge VLAN
Replies: 12
Views: 851

Re: Hotspot on Bridge VLAN

Where is the full config, firewall rules etc............ Your diagram is confusing is this all on one device the router, or do you show it being attached to a switch (you state uplink and bonding but to what etc...) If connecting to a switch is it an MT switch? Normally one uses a single trunk port ...
by anav
Wed Jan 08, 2025 11:09 pm
Forum: Beginner Basics
Topic: How to set up VLAN to pass traffic through a managed switch?
Replies: 5
Views: 352

Re: How to set up VLAN to pass traffic through a managed switch?

I was referring ONLY to the display vlan1, where you only change the port from U to Nothing (no affiliation) for any ports that are untagged (access ports for other vlans). In addition you would need to change the pvid of that port from1 to the untagged port vlan id. For review post pages for each v...
by anav
Wed Jan 08, 2025 10:59 pm
Forum: General
Topic: Automatically updating DST NAT when IP changes
Replies: 8
Views: 504

Re: Automatically updating DST NAT when IP changes

Yes. /ip firewall address-list add address=DYNDNSURL (like mynetname.net) list= MyWAN /ip firewall nat add chain=dstnat action=dst-nat dst-address-list=MyWAN \ dst-port=xxxxx protocol=abc to-address=ServerIP Check for yourself, in the IP firewall address list. you will see it automatically creates a...
by anav
Wed Jan 08, 2025 9:13 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 14
Views: 1800

Re: NORMUNDS FOR PRIME MINISTER

MKX you need to watch the psychedelic videos from Viktors!!
by anav
Wed Jan 08, 2025 9:10 pm
Forum: General
Topic: Curious ssh errors
Replies: 2
Views: 533

Re: Curious ssh errors

What ranges are you getting and speeds, and how does it hold up with heavy rain or snow??
Is the 5ghz backup good, what range??
by anav
Wed Jan 08, 2025 9:07 pm
Forum: Beginner Basics
Topic: Long Distance Wifi
Replies: 2
Views: 212

Re: Long Distance Wifi

Do not have or endorse this product but looking at the product page it may be the quick and easy solution. https://mikrotik.com/product/wireless_wire_cube_pro Powering it at the far side will be the challenge but you seem to have some ideas. What I dont like is that within the same website they prov...
by anav
Wed Jan 08, 2025 8:30 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 285
Views: 35093

Re: wAP ax?

But I had 0 problems with new wAP ax so far. They are rock solid :D
Just to be clear, you are not using them as paperweights?
by anav
Wed Jan 08, 2025 7:31 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 14
Views: 1800

Re: NORMUNDS FOR PRIME MINISTER

I am more curious as to what Normands is thinking.....

Attempt1: I forgot my schnapps in the car.........
Attempt2: I always have my hand in my pocket to protect my manhood.....
Attempt3: Where is the bathroom?
Attempt4: Why did I volunteer to attend this event for Viktors......
by anav
Wed Jan 08, 2025 7:28 pm
Forum: General
Topic: NORMUNDS FOR PRIME MINISTER
Replies: 14
Views: 1800

Re: NORMUNDS FOR PRIME MINISTER

Why would you want to hinder progress on cloudflare ????
by anav
Wed Jan 08, 2025 6:04 pm
Forum: General
Topic: Wireguard peer sets a default ListeningPort=51820
Replies: 6
Views: 476

Re: Wireguard peer sets a default ListeningPort=51820

Ahh that makes sense! Understand good plan still to netinstall fresh firmware 7.16.2 prior to do anything else. Then install a basic firewall setup. Then connect to the internet. On the router, in the wireguard setting, establish a listening port ( this is an accurate word in the case of the device ...
by anav
Wed Jan 08, 2025 5:57 pm
Forum: General
Topic: VLAN Trunk port config
Replies: 11
Views: 979

Re: VLAN Trunk port config

The only times that one needs to use a hybrid port is if the offending attached device a. accepts ONLY the untagged data for the main connection and a tagged connection for other connections. ( an internet phone where the untagged data is for the phone and the tagged data is for a connected PC ) b. ...
by anav
Wed Jan 08, 2025 5:50 pm
Forum: General
Topic: The Road Warrior 4G/Wifi Companion
Replies: 2
Views: 269

Re: The Road Warrior 4G/Wifi Companion

To be picky its the hap ax lite LTE6

What do you have at home? MT router? Public IP, or ISP router that can forward port to MT router??
by anav
Wed Jan 08, 2025 5:48 pm
Forum: General
Topic: RoS 7.16 RC4 mDNS
Replies: 37
Views: 9405

Re: RoS 7.16 RC4 mDNS

Wireguard does not support multicast, and mDNS needs multicast... so not possible. The mDNS support in 7.16 is just an "mDNS repeater", so the resulting "repeated" multicast can not be forwarded over WG. And why I've long argued that /ip/dns should act as mDNS/DNS-SD "Disco...
by anav
Wed Jan 08, 2025 5:39 pm
Forum: Beginner Basics
Topic: Hotspot on Bridge VLAN
Replies: 12
Views: 851

Re: Hotspot on Bridge VLAN

One bridge,
identify all the data vlans required and one management vlan ( unless you intend to use one of the data vlans as a trusted vlan)

viewtopic.php?t=143620
by anav
Wed Jan 08, 2025 5:36 pm
Forum: Beginner Basics
Topic: Remote Access VPN
Replies: 4
Views: 407

Re: Remote Access VPN

Corporate IT should be able to assist.
by anav
Wed Jan 08, 2025 5:30 pm
Forum: Beginner Basics
Topic: How to set up VLAN to pass traffic through a managed switch?
Replies: 5
Views: 352

Re: How to set up VLAN to pass traffic through a managed switch?

To setup vlan filtering on both RB4011 and CAP products use this guide: --> https://forum.mikrotik.com/viewtopic.php?t=143620 Recommend for each MT device you do the config from a safe location, namely an off bridge port. So in case of Caps, use ether2 off bridge, on RB4011 use ether8 and remove fro...
by anav
Mon Jan 06, 2025 9:12 pm
Forum: Beginner Basics
Topic: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch
Replies: 15
Views: 2105

Re: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch

Read the reference again and watch the video again.......
viewtopic.php?t=143620
https://www.youtube.com/watch?v=YLtGQAQ8iS0

Devices (switches APs) should only get IP addresses from the trusted vlan ( for their own IP )
by anav
Mon Jan 06, 2025 9:10 pm
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

Maybe there are two admins??? So you have an unknown VPN on your router??
I would disconnect from the internet and netinstall the latest firmware to be on the safe side.
by anav
Mon Jan 06, 2025 9:07 pm
Forum: Beginner Basics
Topic: Problem with ping using interfaces
Replies: 10
Views: 621

Re: Problem with ping using interfaces

In plain english, the recursive checks if you can actually reach the WWW.
We have to go through the closest hop as that is what we know. what in between is immaterial.
The key is can the route reach the www, if not switch to WAN2 etc....
by anav
Mon Jan 06, 2025 5:03 pm
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

Seems okay on a quick look. what is not currently working???
by anav
Mon Jan 06, 2025 4:58 pm
Forum: General
Topic: How can Mikrotik/RouterOS send emails using Gmail?
Replies: 15
Views: 8060

Re: How can Mikrotik/RouterOS send emails using Gmail?

Well if you ever need me to ping your router and let you know its not available let me know LOL
Just make sure to give me a non-MT dyndns URL LOL, seems like the MT ecosystem is vulnerable to shenanigans.
by anav
Mon Jan 06, 2025 4:32 pm
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 12
Views: 3844

Re: Feature Request: Wireguard over VRF

Tongue in cheek Chaos, of course you guys (real IT and not homeowners) are stuck with dealing with such stupid setups such as below: A use-case for such functionality would be for example when having two uplinks (eg DSL modem/routers) with conflicting IPs, that you cannot control/change their subnet...
by anav
Mon Jan 06, 2025 4:28 pm
Forum: General
Topic: Wireguard - access from VRF [SOLVED]
Replies: 13
Views: 4322

Re: Wireguard - access from VRF [SOLVED]

Was just poking you in the eye LOL.
by anav
Mon Jan 06, 2025 4:25 pm
Forum: General
Topic: Wireguard confusion (still)
Replies: 8
Views: 557

Re: Wireguard confusion (still)

Hi Mozerd, I believe that is what the OP has done in fact. Each pair of routers A,B A,C A,D A,E and A,F have their own wireguard connection but are able to initiate a connection in both directions so each has endpoint address, endpoint port and keep alive set. I would assume each of the interfaces h...
by anav
Mon Jan 06, 2025 4:14 pm
Forum: General
Topic: Wireguard peer sets a default ListeningPort=51820
Replies: 6
Views: 476

Re: Wireguard peer sets a default ListeningPort=51820

Well the default setup out of the box is secure so, its not a matter of not locking it down you undid something that caused the router then become open. I hope you used netinstall to put 7.16.2 on the router, and if not, not interested in assisting until a clean version of firmware is installed in t...
by anav
Mon Jan 06, 2025 4:10 pm
Forum: General
Topic: Home networking suggestions
Replies: 8
Views: 533

Re: Home networking suggestions

I would ditch Bruno and simply use Wireguard on the MT device. Its adding a layer of complication for no reason.
by anav
Mon Jan 06, 2025 4:09 pm
Forum: General
Topic: How can Mikrotik/RouterOS send emails using Gmail?
Replies: 15
Views: 8060

Re: How can Mikrotik/RouterOS send emails using Gmail?

Okay AMMO how does your router send you an email when your WAN goes down ;-PP
by anav
Mon Jan 06, 2025 4:06 pm
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

masquerade rule already exists above with out-interface-list=WAN. You do not need another masquerade rule is the point, unless you have a specific VPN outgoing that needs to be masqueraded. ONLY the to-port can be removed if same as dst-port. ( the dst-port is mandatory LOL, the router reads the dst...
by anav
Mon Jan 06, 2025 3:59 pm
Forum: General
Topic: Wireguard confusion (still)
Replies: 8
Views: 557

Re: Wireguard confusion (still)

BTW: No one is more astounded, perplexed, and disoriented by the persistence of NYC's desireability than me (lifelong, multi-generational NYC'er). That's my soap-box response to your coffee comment. That is to say, coffee (and everything) is much better elsewhere. Nonetheless, anytime you're in the...
by anav
Mon Jan 06, 2025 3:12 am
Forum: Beginner Basics
Topic: Problem with ping using interfaces
Replies: 10
Views: 621

Re: Problem with ping using interfaces

What type of ISP connection is the primary......... Recursive allows one to verify www connectivity General format: /ip route add checkgateway=ping distance=1 dst-address=0.0.0.0/0 gateway=1.1.1.1 routing-table=main scope=10 target-scope=12 add checkgateway=ping distance=2 dst-address=0.0.0.0/0 gate...
by anav
Mon Jan 06, 2025 2:38 am
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

Hosting your own mail server is a very bad idea......I suspect that may the cause of people getting shut down by their ISPs abuse on port 25. Port 25 is often used to spam email and ISPs shut it down. Work arounds, dont attempt to be everything. Have your mail server set to something else..............
by anav
Mon Jan 06, 2025 2:34 am
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

So brand up wifi AP up top ( is it smart or dumb, brand/model )
Switch to far right ( managed??? brand/model )
wifi bridge device bottom (brand/model)
wifi APs very bottome smart or dumb (brand/model)
by anav
Mon Jan 06, 2025 2:31 am
Forum: Beginner Basics
Topic: Wireguard + Hairpin NAT issue
Replies: 15
Views: 696

Re: Wireguard + Hairpin NAT issue

Note: Routing rules works well for a small group of IPs........... or entire subnets,
however if the number grows to big, then mangling will be used to replace routing rules.
by anav
Mon Jan 06, 2025 2:27 am
Forum: General
Topic: Wireguard confusion (still)
Replies: 8
Views: 557

Re: Wireguard confusion (still)

Sure thats very logical. THe problem is how to do that depends on the current setup. If it was connect to router A via wireguard and then over existing tunnels go to any other device or any other LAN on any device is TOO easy. This assumes device A is the server for handshake, and device B,C,D,E,F a...
by anav
Mon Jan 06, 2025 1:06 am
Forum: General
Topic: Wireguard confusion (still)
Replies: 8
Views: 557

Re: Wireguard confusion (still)

Well it all depends doesnt it. Do you wish to be able to reach all devices by accessing one MT device in particular, or do you want to be able to reach all the configs when connecting to any device. The hub and spoke method you didnt use, makes connecting to all device stupid simple as one connects ...
by anav
Mon Jan 06, 2025 12:44 am
Forum: Beginner Basics
Topic: Wireguard + Hairpin NAT issue
Replies: 15
Views: 696

Re: Wireguard + Hairpin NAT issue

Thx for the clarification. By the way, could you find a smart way to add rules such add chain=dstnat action=dstnat src-address=192.168.88.5 dst-port=53 protocol=udp to-address=198.18.0.1 add chain=dstnat action=dstnat src-address=192.168.88.5 dst-port=53 protocol=tcp to-address=198.18.0.1 But inste...
by anav
Mon Jan 06, 2025 12:42 am
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

Other routers?? Can you provide a network diagram to see what is in play!
by anav
Sun Jan 05, 2025 11:43 pm
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

post the latest config, so that one can investigate.
by anav
Sun Jan 05, 2025 11:40 pm
Forum: Beginner Basics
Topic: Wireguard + Hairpin NAT issue
Replies: 15
Views: 696

Re: Wireguard + Hairpin NAT issue

Because its a function of ensuring the path through the 3rdparty provider from the single PC to the Www is working properly MTU wise. Nothing to do with bridge. Also note an improvement on the schema already provided:\ /ip nat add chain=dstnat action=dstnat src-address=192.168.88.5 dst-port=53 proto...
by anav
Sun Jan 05, 2025 11:38 pm
Forum: General
Topic: Home networking suggestions
Replies: 8
Views: 533

Re: Home networking suggestions

Can you forward a port from the ISP router to the mikrotik.
by anav
Sun Jan 05, 2025 11:31 pm
Forum: General
Topic: Multi WAN routing problem with CHR. Help please
Replies: 8
Views: 474

Re: Multi WAN routing problem with CHR. Help please

Your answer is too vague to be of any use.

Describe the traffic,
USER A,USER B, USERC< from external wants to do what!!
Identify users and describe traffic needed.

- config 750
- config RB5009
- reach servers on LAN of 750
- reach servers on LAN of RB5009
by anav
Sun Jan 05, 2025 11:22 pm
Forum: Beginner Basics
Topic: Wireguard + Hairpin NAT issue
Replies: 15
Views: 696

Re: Wireguard + Hairpin NAT issue

To prevent leaking is difficult as the rest of the router goes out the normal local WAN. To accomplish no leaking try this.......... Option1: If 3rd party provided a DNS address to use........ /ip nat add chain=dstnat action=dstnat src-address=192.168.88.5 dst-port=53 protocol=udp to-address=198.18....
by anav
Sun Jan 05, 2025 10:51 pm
Forum: Beginner Basics
Topic: Wireguard + Hairpin NAT issue
Replies: 15
Views: 696

Re: Wireguard + Hairpin NAT issue

Can you confirm what the 3rd party provider gave you for information Apparently besides endpoint address and endpoint port and private key to use ( so same public key is generated for their end etc...) Specifically ip address of 100.96.1.09 was given, DID they provide anything else? I see you have n...
by anav
Sun Jan 05, 2025 10:45 pm
Forum: General
Topic: Multi WAN routing problem with CHR. Help please
Replies: 8
Views: 474

Re: Multi WAN routing problem with CHR. Help please

What is the purpose of the LAN on the CHR?? Are you using the CHR as WAN2 for the RB750 ??? Are you port forwarding to servers on the RB via the CHR connection ( through the wireguard tunnel between the two devices ) Are you using the wireguard tunnel to remotely connect to both RB750 and RB5009 for...
by anav
Sun Jan 05, 2025 10:26 pm
Forum: Beginner Basics
Topic: hAP ax lite LTE6 internet via ethernet ports but not on wifi
Replies: 15
Views: 903

Re: hAP ax lite LTE6 internet via ethernet ports but not on wifi

Concur jac, that learning is important. If the OP takes the time to understand each line of the completed config and what it does, the learning will come. 1. In terms of the config the offbridge settings are in three places ( plus remove from bridge ) a. name the ethernet port ( OffBridge4 ) b. add ...
by anav
Sun Jan 05, 2025 10:10 pm
Forum: Beginner Basics
Topic: Wireguard + Hairpin NAT issue
Replies: 15
Views: 696

Re: Wireguard + Hairpin NAT issue

As per my recent post above, cat, was working on it this morning and got caught up doing other things... I am avoiding using the prefix thing for several reasons. a. there is a bug when you do modifications after the fact to the prefix rules that do not actually stick on the router ( what is shown i...
by anav
Sun Jan 05, 2025 8:12 pm
Forum: Beginner Basics
Topic: Wireguard + Hairpin NAT issue
Replies: 15
Views: 696

Re: Wireguard + Hairpin NAT issue

What is the purpose of Wireguard? Is it for your remote devices to access the router and LAN while away or are you connecting to some third party vpn to access internet somewhere else.?? Will assume the latter case!! Fixes: 1. EDIT, nm this is okay 2. These rules make no sense the first rule says --...
by anav
Sun Jan 05, 2025 8:11 pm
Forum: Beginner Basics
Topic: Router on a stick struggles
Replies: 6
Views: 585

Re: Router on a stick struggles

This is basic vlan filtering........ Read the bible (has examples for both switch and router) --> https://forum.mikrotik.com/viewtopic.php?t=143620 A decent video for switch -- > https://www.youtube.com/watch?v=YLtGQAQ8iS0 I will hold you responsible for reading and applying the above knowledge. :-)...
by anav
Sun Jan 05, 2025 7:58 pm
Forum: General
Topic: Home networking suggestions
Replies: 8
Views: 533

Re: Home networking suggestions

Can you forward ports from ISP modem/router to the mikrotik??
What is at the other end of the VPN connection? You have some unknown local brun device whatever it is handling some sort of VPN behind the MT.
Is it a router, or what? what kind of VPN does it have.
by anav
Sun Jan 05, 2025 7:55 pm
Forum: General
Topic: Can i change Zerotier port number?
Replies: 5
Views: 314

Re: Can i change Zerotier port number?

It would appear the zerotier network assumes default port number which does not appear changeable as that may be set on zerotier servers?? However they also communicate on two other ports, a random high number port based somewhat on zerotier address and also another high random port number if you pe...
by anav
Sun Jan 05, 2025 4:41 pm
Forum: Beginner Basics
Topic: hAP ax lite LTE6 internet via ethernet ports but not on wifi
Replies: 15
Views: 903

Re: hAP ax lite LTE6 internet via ethernet ports but not on wifi

1. Establish basic requirements a. one subnet for HOME b. one subnet for HOME wifi c. one subnet for IOT (such devices should be separate from home users ) d. one subnet for guest wifi (obviously should be isolated from rest )' It would appear that you need three vlans ( as home wired and home wifi ...
by anav
Sun Jan 05, 2025 3:58 pm
Forum: Beginner Basics
Topic: Rate my config
Replies: 20
Views: 1311

Re: Rate my config

Hi Cat, Sort of, note that one should be accurate when possible and for example for traffic to the router we dont even use prerouting --> input chain and output chain PCC traffic is coming from the LAN marking connections (forward chain) THe mark routing is YES, prerouting chain Similar to traffic t...
by anav
Sun Jan 05, 2025 3:52 pm
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

Fixed thanks! ALso this: I only want to access those ports from lan, not for internet where I didn't make an entry, for example samba share. You still need the same structure as the rest of the dstnat rules! If you want to limit to LAN only, then add a qualifier. add chain=dstnat action=dst-nat dst-...
by anav
Sun Jan 05, 2025 4:01 am
Forum: Beginner Basics
Topic: Configuring a network with tagged/untagged VLANs separation and rules for interconnection
Replies: 3
Views: 671

Re: Configuring a network with tagged/untagged VLANs separation and rules for interconnection

post your config if you want it reviewed/improved /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc. ) The reference is good follow it for success. One other thing I do for configuring vlans and bridge is to take a port off bridge lets say ether8 /inter...
by anav
Sun Jan 05, 2025 3:59 am
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

Well I took a look at the config and your dstnat rules are all over the place. If you are using a DYNDNS name to describe your WANIP, why not use mynetname from IP cloud. In any case if using a DYNDNS name one does NOT also use in-interface-list=WAN ( one or the other ) a. in much of the dstnat rule...
by anav
Sun Jan 05, 2025 3:40 am
Forum: Beginner Basics
Topic: Rate my config
Replies: 20
Views: 1311

Re: Rate my config

Note the config added in post #10. Look at the entire config first, then go line by line and write down any questions you have for posting. I am not 100% sure of the syntax for the IP static DNS... The idea being that anyone putting www.schoolweb.com in their browser would get directed to the server...
by anav
Sun Jan 05, 2025 2:03 am
Forum: Beginner Basics
Topic: Did the Mikrotik firewall block the open ports?
Replies: 33
Views: 1748

Re: Did the Mikrotik firewall block the open ports?

That is how MT works.
Any port forwarding will show up on scans but will have status as closed. ( NORMAL! )
Any port forwarding with also a source address or source address limitation on the dstnat config will be invisible on scans.
by anav
Sun Jan 05, 2025 2:01 am
Forum: General
Topic: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]
Replies: 10
Views: 785

Re: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]

Hmmm,,,,,,,, I suppose as long as the config contains the endpoint address and endpoint port for the Cloud relay. Manual in any case.
by anav
Sat Jan 04, 2025 11:53 pm
Forum: General
Topic: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]
Replies: 10
Views: 785

Re: Bridging two MikroTik router LANs via back-to-home-vpn [SOLVED]

You cannot. The BTH feature is for individual devices only ( smartphones, ipads, laptops, PCs ) If you have two wireguard devices that you wish to connect together, then, a. change one of the ISPs so that you can get a public IP either on the MT itself or at least on the ISP modem/router where it ca...
by anav
Sat Jan 04, 2025 10:52 pm
Forum: Beginner Basics
Topic: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch
Replies: 15
Views: 2105

Re: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch

MikroTik is just acting as a switch between router and the AP. No wifi on the MikroTik itself. I tried to follow the configuration in the reference post and it just turns off internet access on all the ports so that's why my configuration is the way it is now. Just that the access point is only abl...
by anav
Sat Jan 04, 2025 10:48 pm
Forum: General
Topic: VLAN Trunk port config
Replies: 11
Views: 979

Re: VLAN Trunk port config

Remove router serial number and switch serial number from posts made of configs. SWITCH model = CRS328-24P-4S+ # serial number = DNACHSOS4 /interface bridge add admin-mac=08:55:31:20:4A:06 auto-mac=no comment=defconf \ ingress-filtering=yes name=bridge vlan-filtering=yes /interface vlan add interfac...
by anav
Sat Jan 04, 2025 10:25 pm
Forum: General
Topic: VLAN Trunk port config
Replies: 11
Views: 979

Re: VLAN Trunk port config

ROUTER: model = RB4011iGS+ In summary sort out why the subnets you use in various places dont match the address subnets ???] Not sure why you show ether2 being tagged for both vlans, You never noted what is connected to ether2 ???? I will asssume for now its some other kind of smart device and not a...
by anav
Sat Jan 04, 2025 9:40 pm
Forum: Beginner Basics
Topic: Router on a stick struggles
Replies: 6
Views: 585

Re: Router on a stick struggles

The switch should tag the traffic coming from comcast on a single vlan and carry it through to the trunk port to the router. The router simply needs to terminate this vlan on the WAN settings be it DHCP server, or pppoe etc.... On the trunk port between them are also a. the management or trusted sub...
by anav
Sat Jan 04, 2025 9:37 pm
Forum: Beginner Basics
Topic: Rate my config
Replies: 20
Views: 1311

Re: Rate my config

What do you mean ether4 is connected to LAN, one port serves the whole school, every cable spliced off a single cable???
Or is LAN a brand name for a managed switch??
by anav
Sat Jan 04, 2025 9:05 pm
Forum: Beginner Basics
Topic: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch
Replies: 15
Views: 2105

Re: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch

Due to the lack of network diagram and overall clarity. Is the mikrotik device simply between the main router and the AP. ( a switch only, no WIFI) So the mikrotik gets a trunk port on the router with lets say 3 vlans, managment, homewifi guest wifi etc... Or is it doing wifi as well. THere should b...
by anav
Sat Jan 04, 2025 7:07 pm
Forum: Beginner Basics
Topic: Rate my config
Replies: 20
Views: 1311

Re: Rate my config

Really for proper security they can OPT IN, and in a few easy steps compared to all other methods have access to the internal school info while at home or NOT and have to go to school to access. WHat router is it that you will have for real ( model, firmware )............ how many ports? What is eth...
by anav
Sat Jan 04, 2025 7:05 pm
Forum: Beginner Basics
Topic: Rate my config
Replies: 20
Views: 1311

Re: Rate my config

Well from a security perspective http is a very bad idea. In that at some point you have to login...... then you probably have a simple username and password login which in 2025 is not the way to go. So it depends if you have third party authentication etc........... How that is done, is the key. ??...
by anav
Sat Jan 04, 2025 4:06 pm
Forum: Beginner Basics
Topic: Rate my config
Replies: 20
Views: 1311

Re: Rate my config

Some clarification required. f. Is it one office PC that needs to be static or one printer that needs to be static. And the reason give doesnt make sense, 'due to scanning of printer' Do you mean the printer is also a scanner? Do you meant the printer initiates a search?? Do you mean the printer nee...
by anav
Sat Jan 04, 2025 3:37 pm
Forum: Beginner Basics
Topic: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch
Replies: 15
Views: 2105

Re: Issues using VLAN SSIDs on Access Point on a MikroTik device acting as a managed switch

As noted, if its a switch why are you configuring it like a router ( no pools required )
The only vlan that needs to be defined is the management or trusted vlan where the mT gets its IP address from.
Find the appropriate example here --> viewtopic.php?t=143620
by anav
Sat Jan 04, 2025 3:35 pm
Forum: General
Topic: VLAN Trunk port config
Replies: 11
Views: 979

Re: VLAN Trunk port config

Its not a matter of like or dislike, its a matter of meeting requirements.
by anav
Sat Jan 04, 2025 5:06 am
Forum: General
Topic: VLAN Trunk port config
Replies: 11
Views: 979

Re: VLAN Trunk port config

There is no need to use hybrid ports unless dealing with ubiquiti etc.. Classic error, once you go vlans, DONT mix bridge with DHCP. Whatever subnet you have there just assign it as a vlan and then complete the config. Ingress filtering should be yes on every port and frame types be either vlan tagg...
by anav
Sat Jan 04, 2025 12:09 am
Forum: Beginner Basics
Topic: Simple Bridge with Firewall rules for Ether1 (internet))
Replies: 15
Views: 1459

Re: Simple Bridge with Firewall rules for Ether1 (internet))

You need to disconnect from the internet and implement at least the default firewall ASAP because now you're an open door to the world. After that we can talk about port forwarding (allowing access to internal service through public IP) That is the intent of CO-PILOT, to CO-OPT every mikrotik new u...
by anav
Sat Jan 04, 2025 12:06 am
Forum: Beginner Basics
Topic: two isp active at the same time
Replies: 2
Views: 292

Re: two isp active at the same time

Very doable we help users all the time achieve success, As noted, please post config for starters. /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys, long assed dchp lease lists etc.) I would not comment further also without knowing the requirements in more...
by anav
Sat Jan 04, 2025 12:03 am
Forum: Beginner Basics
Topic: HAP ax3 Wi:Fi working but no internet via LAN ports
Replies: 5
Views: 700

Re: HAP ax3 Wi:Fi working but no internet via LAN ports

Three other considerations. Do you want the guest users on 2.4 to see other guest users on 2.4 Do you want the guest users on 5ghz to see other guest users on 5 ghz Do you wan the guest users on 2.4 to see guest users on 5ghz. IF NO. a. on wifi create datapath1 and check client isolation. then on wi...
by anav
Fri Jan 03, 2025 11:31 pm
Forum: Beginner Basics
Topic: HAP ax3 Wi:Fi working but no internet via LAN ports
Replies: 5
Views: 700

Re: HAP ax3 Wi:Fi working but no internet via LAN ports

Changes to your config. 1. You have guest wifi but no subnet for the guest network so that has been added. 2. Recommend to not use bridge filters to control traffic, use standard ip firewall filter rules (bridge filters are for advanced users for niche cases). 3. So the solution is one of two choice...
by anav
Fri Jan 03, 2025 10:43 pm
Forum: Beginner Basics
Topic: Rate my config
Replies: 20
Views: 1311

Re: Rate my config

I would not comment on a config without knowing the requirements a. identify all the devices/users, groups of users, external and internal users including the admin b. identify the traffic they all require c. be sure to cover any port forwarding or VPN traffic. d. detail WAN setup, how many type ( s...
by anav
Fri Jan 03, 2025 10:34 pm
Forum: General
Topic: Trunking a vlan
Replies: 16
Views: 726

Re: Trunking a vlan

You can also ask Admiral for support they are supposed to be expert at applying their platform on mikrotik appliances.
by anav
Fri Jan 03, 2025 10:31 pm
Forum: General
Topic: Hap ax3
Replies: 3
Views: 327

Re: Hap ax3

No there is a little pull out tab on the ax3 if I recall correctly.
by anav
Fri Jan 03, 2025 10:28 pm
Forum: General
Topic: MT Firewall & DST NAT question [SOLVED]
Replies: 10
Views: 840

Re: MT Firewall & DST NAT question [SOLVED]

This --> You can even combine the approaches, where rules in raw drop packets whose source address matches an address list, and rules in other tables populate that address list Speaks to creating lists of addresses to block. I prefer knowing the incoming source address but you did give me additional...
by anav
Fri Jan 03, 2025 6:33 pm
Forum: General
Topic: NTP Synchronization Issue with HMI in a Router-Switch Setup
Replies: 6
Views: 849

Re: NTP Synchronization Issue with HMI in a Router-Switch Setup

I think you are confused...... Either the item is a switch or a router MAKE UP YOUR MIND. If its a switch the only thing the device can do is point to the gateway of the trusted vlan to get NTP itself, the MT device. Getting Time to devices on vlans is the responsibility of the main router. Do you h...
by anav
Fri Jan 03, 2025 6:28 pm
Forum: General
Topic: Trunking a vlan
Replies: 16
Views: 726

Re: Trunking a vlan

,,,,,,,,,,,,,,
Screenshot 2025-01-03 122746.jpg
by anav
Fri Jan 03, 2025 6:22 pm
Forum: General
Topic: Configuring VLAN tagged/untagged
Replies: 11
Views: 896

Re: Configuring VLAN tagged/untagged

What do you mean exactly?? ETher1 is simply capturing the internet traffic stuffing the untagged traffic into vlan187 through the hex and bringing it to your router to be terminated as vlan187 traffic. VLAN 18 is your managment subnet and also your main subnet. The hex gets its address from here. Yo...
by anav
Fri Jan 03, 2025 6:14 pm
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 12
Views: 3844

Re: Feature Request: Wireguard over VRF

Why, network better -- dont create overlapping subnets............
Wireguard works just fine, if done properly.
(caveat home user, dont support real work)
by anav
Fri Jan 03, 2025 6:13 pm
Forum: General
Topic: Wireguard - access from VRF [SOLVED]
Replies: 13
Views: 4322

Re: Wireguard - access from VRF [SOLVED]

I agree nichky, seems like people just dont know how to use wireguard properly ;-)
Truth be told I havent used VRF but I think thats a BGP issue. Attempting to use BGP and wireguard VPN .........

As to my first statement, dont use overlapping subnets ;-PPP
by anav
Fri Jan 03, 2025 6:04 pm
Forum: General
Topic: Trunking a vlan
Replies: 16
Views: 726

Re: Trunking a vlan

Draw a diagram of what you wish to achieve! There are so many what ifs in your description, its hard to pick out facts from fiction.
by anav
Fri Jan 03, 2025 3:51 am
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

If you can point out where the mistakes were or where the corrections were made it will help others.
by anav
Thu Jan 02, 2025 11:51 pm
Forum: Beginner Basics
Topic: upgrading from 6.49.17 to 7.12.1
Replies: 4
Views: 535

Re: upgrading from 6.49.17 to 7.12.1

sure if you do it thru the router, will take you to 7.12 first, if you do it manually go to 7.12 first, then 7.16.2.
by anav
Thu Jan 02, 2025 7:47 pm
Forum: General
Topic: Configuring VLAN tagged/untagged
Replies: 11
Views: 896

Re: Configuring VLAN tagged/untagged

I only know so much, more to learn.
by anav
Thu Jan 02, 2025 6:32 pm
Forum: Beginner Basics
Topic: Simple Bridge with Firewall rules for Ether1 (internet))
Replies: 15
Views: 1459

Re: Simple Bridge with Firewall rules for Ether1 (internet))

cat12 are you better than AI>>> COpilot copying does not equal learning!!
by anav
Thu Jan 02, 2025 6:30 pm
Forum: General
Topic: MT Firewall & DST NAT question [SOLVED]
Replies: 10
Views: 840

Re: MT Firewall & DST NAT question [SOLVED]

We cannot change how RoS works..... As for filtering the forward chain typically should have a rule like. add chain=forward action=accept comment="port forwarding" connection-nat-state=dstnat There is no security settings done typically in dstnat rules. However, if you wish to limit extern...
by anav
Thu Jan 02, 2025 6:13 pm
Forum: General
Topic: Configuring VLAN tagged/untagged
Replies: 11
Views: 896

Re: Configuring VLAN tagged/untagged

Remove serial number from your posted config!! Ether3 has to be a trunk port carrying all vlans between hex switch and Router. Ether1 and Ether5 are access ports, untagged as required when leaving the port. I dont understand this nomenclature add address=10.87.2.28 /28 interface=MGMT_VLAN network=10...
by anav
Thu Jan 02, 2025 4:36 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

You have yet to respond??? As this made no sense to me I had to assume some NAT on the fortigate and thus the config of the two mikrotiks will link the two fortigates as you requested. Its simply a matter of proper configuration of the two Fortigates to ensure the traffic arriving at the Fortigates ...
by anav
Thu Jan 02, 2025 4:22 pm
Forum: Beginner Basics
Topic: Simple Bridge with Firewall rules for Ether1 (internet))
Replies: 15
Views: 1459

Re: Simple Bridge with Firewall rules for Ether1 (internet))

/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc. )
by anav
Thu Jan 02, 2025 4:20 pm
Forum: Beginner Basics
Topic: No connection with winbox
Replies: 4
Views: 631

Re: No connection with winbox

Sure, get the AX3 router and use the hex as a switch, or if just looking for an AP only choose between capax (indoor) and wapax (indoor or outdoor).
If you want wifi7, keep the hex and look at tplink wifi7 products.
by anav
Thu Jan 02, 2025 4:17 pm
Forum: Beginner Basics
Topic: inter connect two subnets
Replies: 2
Views: 405

Re: inter connect two subnets

Clearly the OP wants some degree of separation between the subnets and a way of accessing the APs from a management perspective.
I am of course leaning towards vlans to do so.

Before going down any path, are these smart or dumb APs.......... ( brand and model )
by anav
Thu Jan 02, 2025 4:12 pm
Forum: Beginner Basics
Topic: upgrading from 6.49.17 to 7.12.1
Replies: 4
Views: 535

Re: upgrading from 6.49.17 to 7.12.1

Yup there are going to be some hicckups along the way for sure.........
Now time to go to 7.16.2 LOL
by anav
Thu Jan 02, 2025 4:03 pm
Forum: General
Topic: Configuring VLAN tagged/untagged
Replies: 11
Views: 896

Re: Configuring VLAN tagged/untagged

Before fixing the config, Is the ISP giving you two WANIPs ??? WHY the second router doing pppoe. ( why do you need it, all could be done via hex for example ) Is the hex acting as a switch or router? I am thinking without a proper understanding of the setup and your intent, this could be a chasing ...
by anav
Thu Jan 02, 2025 4:00 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 104
Views: 10581

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

At least they had the decency of NOT calling it "Mikrotik 365" :wink: . Luv it! If I was a betting man, I would say its been orchestrated by Cloudflare, for what purpose I do not know, but I swear I did not bribe them to do so, in order to get MT to capitulate and put zerotrust cloudflare...
by anav
Thu Jan 02, 2025 3:58 pm
Forum: General
Topic: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]
Replies: 104
Views: 10581

Re: FOR THE LOVE OF "DEITY OF CHOICE" FIX YOUR FRIGGEN (forum) WEBSITE [SOLVED]

It’s a lucky dip if it’s online when I come on here. Brings a bit of excitement and variation to my day.
Did you buy a boat yet............ I hear all the excitement one needs is the free water Brits are getting.
by anav
Thu Jan 02, 2025 3:55 pm
Forum: General
Topic: NAT challenge
Replies: 6
Views: 502

Re: NAT challenge

Actually mostly asking cause it pains me to see Sindy guessing. ;-) @sjoram has been around for a while, so I figure he enjoys the journey as much as the goal, so I play along. Yes, thats why I thought a round of jousting would be entertaining. But not around for that long, the lad looks to be abou...
by anav
Thu Jan 02, 2025 3:53 pm
Forum: General
Topic: MT Firewall & DST NAT question [SOLVED]
Replies: 10
Views: 840

Re: MT Firewall & DST NAT question [SOLVED]

It was asked nicely to see the full config to make a proper assessment using facts and evidence. Like it or not, MT config elements are interrelated. No one is asking to see anything revealing. /export file=anynameyouwish (minus router serial number, any public WANIP information, keys, long assed dh...
by anav
Thu Jan 02, 2025 3:50 pm
Forum: General
Topic: Weird problem with vlan access to wAP ax.
Replies: 8
Views: 660

Re: Weird problem with vlan access to wAP ax.

Still could help to have a look at that topic.
Amen to that brother, a vlan is a vlan except when using RoS and then mysteriously people get confused.
by anav
Thu Jan 02, 2025 3:48 pm
Forum: General
Topic: NAT challenge
Replies: 6
Views: 502

Re: NAT challenge

As usual, without the context of the config, and often a detailed network diagram, the chap from essex wants to play whackamole. Perhaps being waterlogged has clouded the approach! /export file=anynameyouwish ( minus router serial number, any public WANIP info, keys etc.) ( for BOTH mt devices ) Act...
by anav
Thu Jan 02, 2025 3:42 pm
Forum: General
Topic: Weird problem with vlan access to wAP ax.
Replies: 8
Views: 660

Re: Weird problem with vlan access to wAP ax.

Simplify, have main router provide all vlans and rules etc. Use wapAX simply as a switch AP, the objective of giving one branch of office isolated access to internet is accomplished. This simply means a vlan only for them and the MT device gets an IP address from the trusted vLAN. ONE BRIDGE, rest ...
by anav
Wed Jan 01, 2025 9:04 pm
Forum: Beginner Basics
Topic: Problem on routing RB5900
Replies: 2
Views: 374

Re: Problem on routing RB5900

I could try but do not understand your setup. What seems to be true is that there is an upstream ISP modem/router that provides you with a private IP address. For some strange reason you are feeding a cisco switch instead of the RB5009 directly. Not sure why you are having multiple links from the sw...
by anav
Tue Dec 31, 2024 8:42 pm
Forum: General
Topic: [BTH] - "Back to Home" share (without limit) already "expired"
Replies: 2
Views: 328

Re: [BTH] - "Back to Home" share (without limit) already "expired"

Perhaps never expire is not an option??
by anav
Tue Dec 31, 2024 1:19 am
Forum: Beginner Basics
Topic: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]
Replies: 8
Views: 1301

Re: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]

Copying is not learning, but glad you have success.
by anav
Tue Dec 31, 2024 1:16 am
Forum: General
Topic: Problem: Removing routes to fast breaks routing table?
Replies: 3
Views: 4965

Re: Problem: Removing routes to fast breaks routing table?

sounds like bad scripts,,,,,,
Do what rextended recommended

/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys, long dhcp leases etc. )
by anav
Mon Dec 30, 2024 8:31 pm
Forum: General
Topic: Managed Dell switch to CRS326
Replies: 7
Views: 584

Re: Managed Dell switch to CRS326

Not required, all the support I can provide has been given.
by anav
Mon Dec 30, 2024 8:21 pm
Forum: Beginner Basics
Topic: VLAN and Smart home stuff block from internet only for BTH VPN
Replies: 9
Views: 1582

Re: VLAN and Smart home stuff block from internet only for BTH VPN

As long as your not in a rush, I may be able to assist, via discord, or skype and anydesk etc...
Just contact anav_ds on discord,
by anav
Mon Dec 30, 2024 8:17 pm
Forum: Beginner Basics
Topic: RB5009 in the hands of a newbie, Gateway problem
Replies: 19
Views: 1820

Re: RB5009 in the hands of a newbie, Gateway problem

That is correct, what you did was employ loopback NAT or hairpin NAT. This can be solved by simply moving users or server to a different subnet/vlan. Since these cost nothing, it something I would certainly do. LIke a shared printer, I put those on their own vlan for best security. However, the rule...
by anav
Mon Dec 30, 2024 8:09 pm
Forum: General
Topic: Guest WiFi with VLAN on UniFi AP
Replies: 18
Views: 1260

Re: Guest WiFi with VLAN on UniFi AP

Sindy is the expert, I am just learning.
However, his level of genius is not always needed for basic config issues.
I am searching for the big lump of cow poop in the haystack, his eyes are trained to look for needles....... He might not even notice the cow poop LOL
Unless its very fresh ;-))
by anav
Mon Dec 30, 2024 8:07 pm
Forum: General
Topic: Problem: no downloads from download.mikrotik.com
Replies: 6
Views: 1130

Re: Problem: no downloads from download.mikrotik.com

I think the firewall rules are fine because other files, even bigger, are working and I have more or less the default/factory firewall rules. Any hints to help me? The answer is the same as always, you can think what you like and give an opinion but we need the facts...........(evidence - aka FULL ...
by anav
Mon Dec 30, 2024 8:01 pm
Forum: General
Topic: Managed Dell switch to CRS326
Replies: 7
Views: 584

Re: Managed Dell switch to CRS326

First of all why the heck are you paying for and using managed switches if you just have one vlan, aka one flat network. Big waste of money and time configuring................... and even have a second CRS326............... In any case not interested in supporting such a whacko concept, but will pr...
by anav
Mon Dec 30, 2024 2:56 pm
Forum: Beginner Basics
Topic: Hex as Switch; VLANs Can't Access Winbox
Replies: 8
Views: 1549

Re: Hex as Switch; VLANs Can't Access Winbox

In a vlan filtering scenario, when a device is acting as a switch or AP switch only the trusted or base vlan needs to be tagged in /interface bridge vlan settings. As for untaggings, technically nothing needs to be untagged if the pvid has been entered on the port in /interface bridge port settings ...
by anav
Mon Dec 30, 2024 6:09 am
Forum: Beginner Basics
Topic: Setting up MikroTik hEX Refresh 2024 and hAP ac2 with Upcoming Sky Gigafast - Seeking Advice.
Replies: 2
Views: 511

Re: Setting up MikroTik hEX Refresh 2024 and hAP ac2 with Upcoming Sky Gigafast - Seeking Advice.

Why dont you ask on the gigafast forums, this is a mikrotik forum ( note there are no gigafast specific settings on MT devices ).
by anav
Mon Dec 30, 2024 6:07 am
Forum: Beginner Basics
Topic: Reset rb5009 and no WAN or DHCP
Replies: 3
Views: 421

Re: Reset rb5009 and no WAN or DHCP

Sure, based on the evidence presented, buy a new 5009 and it should work out of the box. Dont touch anything after as it seems you have the kiss of death.
Will send you a prepaid package for the 5009 to my address.
by anav
Mon Dec 30, 2024 6:05 am
Forum: General
Topic: Guest WiFi with VLAN on UniFi AP
Replies: 18
Views: 1260

Re: Guest WiFi with VLAN on UniFi AP

p.s. my guess about previous problems is that UniFi AP be need to connected to BASE LAN, not BLUE as I do at first. Stated clearly in post 6 of this thread............ First: Please remove router serial number from your post! Second: Config is incomplete, the base subnet is missing typical networki...
by anav
Sun Dec 29, 2024 9:49 pm
Forum: General
Topic: Send only certain traffic into Wireguard-tunnel
Replies: 9
Views: 708

Re: Send only certain traffic into Wireguard-tunnel

Glad you found the issue and its resolved and also to re-affirm for the gazillionth time that the config is interrelated and relevant to review.
by anav
Sun Dec 29, 2024 8:37 pm
Forum: RouterBOARD hardware
Topic: hardware purchase advice is needed for intervlan routing needs?
Replies: 3
Views: 524

Re: Hardware purchase advice is needed for intervlan routing needs?

Yes! One create as many vlans as required. For management or base vlan you can use a trusted home vlan or a separate one. The CRS will get an IP address on this trusted vlan For vlan setup check out the appropriate example here --> CRS326-24G-2S+RM For decent vid on the topic --> https://www.youtube...
by anav
Sun Dec 29, 2024 8:27 pm
Forum: General
Topic: dstnat doesn't work on L009UiGS-RM Router [SOLVED]
Replies: 40
Views: 1822

Re: dstnat doesn't work on L009UiGS-RM Router [SOLVED]

Nice to know at the last minute that the server is directly connected to the ONT. That is a slap upside your head moment. So besides two bizarro connections from the MT to the ISP device, you have a third ISP connection directly to the Server. Suggestion, remove connection directly to the ISP device...
by anav
Sun Dec 29, 2024 7:31 pm
Forum: General
Topic: Remote access to LAN with VPN IPsec
Replies: 3
Views: 302

Re: Remote access to LAN with VPN IPsec

I believe he is just reposting...from here............. should keep it to one thread!!!
viewtopic.php?t=213562
by anav
Sun Dec 29, 2024 6:40 pm
Forum: General
Topic: Send only certain traffic into Wireguard-tunnel
Replies: 9
Views: 708

Re: Send only certain traffic into Wireguard-tunnel

Sindy is extremely factual and kind.
I am neither ( more like logical and blunt ), it is plain arrogant of you to assume you know what or what shouldn't be presented ref the config.
If you were so prescient there would be no need to come here and ask for help would there ??
by anav
Sun Dec 29, 2024 6:39 pm
Forum: General
Topic: Send only certain traffic into Wireguard-tunnel
Replies: 9
Views: 708

Re: Send only certain traffic into Wireguard-tunnel

edit: duplicate removed
by anav
Sun Dec 29, 2024 3:15 pm
Forum: Beginner Basics
Topic: Could anyone audit my setup? [SOLVED]
Replies: 12
Views: 2147

Re: Could anyone audit my setup? [SOLVED]

Please use [ code ] tag under </> button in the editor instead of quote one. If you use forum theme like "silver" one then your posts are more than half a meter/several screens long :). Code tags do the job for every theme. You can always do cut out most of the quote and leave the crucial...
by anav
Sun Dec 29, 2024 3:12 pm
Forum: General
Topic: Site-to-Site WireGuard VPN handshake failing
Replies: 5
Views: 451

Re: Site-to-Site WireGuard VPN handshake failing

When you post full config on both
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc.)
I will gladly address some of the errors shown.
by anav
Sun Dec 29, 2024 3:10 pm
Forum: General
Topic: dstnat doesn't work on L009UiGS-RM Router [SOLVED]
Replies: 40
Views: 1822

Re: dstnat doesn't work on L009UiGS-RM Router [SOLVED]

One option: use source address list on dstnat rule to make ports appear closed on scans and of course limits access........ ( external wanips can be spoofed ) Second option: have users wireguard in to the router and then access servers Third option: Future case when Mikrotik adds zerotrust cloudflar...
by anav
Sun Dec 29, 2024 4:01 am
Forum: General
Topic: Site-to-Site WireGuard VPN handshake failing
Replies: 5
Views: 451

Re: Site-to-Site WireGuard VPN handshake failing

Purpose of your wireguard network??
Only one end needs to act as client SERVER for handshake.......... which one?
by anav
Sun Dec 29, 2024 4:00 am
Forum: Beginner Basics
Topic: Two LANs configuration, wireguard?
Replies: 6
Views: 546

Re: Two LANs configuration, wireguard?

Well when you have a real network, I may be of assistance. Not going to chase fake GNS3 musings.
by anav
Sat Dec 28, 2024 11:04 pm
Forum: General
Topic: Send only certain traffic into Wireguard-tunnel
Replies: 9
Views: 708

Re: Send only certain traffic into Wireguard-tunnel

Suggest full config for review is optimal, not into guessing.
/file=anynameyouwish (minus router serial number, any public WANIP information, keys etc. )
by anav
Sat Dec 28, 2024 11:02 pm
Forum: General
Topic: dstnat doesn't work on L009UiGS-RM Router [SOLVED]
Replies: 40
Views: 1822

Re: dstnat doesn't work on L009UiGS-RM Router [SOLVED]

1. The first problem I see is that you have both an IP address for WAN on ether1 AND a dhcp client on ether1. It cannot be both!!! If your certain about the IP address disable the dhcp client. 2 Suggest changing this default rule to three rules which are clearer as to the functionality and a bit mor...
by anav
Sat Dec 28, 2024 10:48 pm
Forum: Beginner Basics
Topic: VPN ipsec - no local LAN client access
Replies: 8
Views: 613

Re: VPN ipsec - no local LAN client access

Is this CHR in a cloud somewhere or local to you???
by anav
Sat Dec 28, 2024 9:13 pm
Forum: Beginner Basics
Topic: VPN ipsec - no local LAN client access
Replies: 8
Views: 613

Re: VPN ipsec - no local LAN client access

If CHR, you are probably safe removing firewall rules at least on the forward chain, I would keep all the input chain rules. already provided the idea of only allowing Admin relate IP addresses to access the router for config purposes.............. how you want to move forward is up to you. Just don...
by anav
Sat Dec 28, 2024 9:11 pm
Forum: Beginner Basics
Topic: Two LANs configuration, wireguard?
Replies: 6
Views: 546

Re: Two LANs configuration, wireguard?

What I would do is use vlans from the getgo on the first MT. Trunk POrt to AX lite ( acting as an ap/switch ) Ax lite ether1 - trunk from MT router ether2 -Access port to dumb switch one which feeds PC1 LINUS and PC2 ether3 - Access port to dumb switch two which feeds Wifi Server and PC3 OFF BRIDGE ...
by anav
Sat Dec 28, 2024 8:44 pm
Forum: Beginner Basics
Topic: Could anyone audit my setup? [SOLVED]
Replies: 12
Views: 2147

Re: Could anyone audit my setup? [SOLVED]

Should be good as is, will take a quick peek. Yup all secure! 1. Not wrong but I prefer to be clear about all settings /interface bridge vlan add bridge=Bridge-LAN tagged=Bridge-LAN untagged=ether2-LAN,ether3-LAN,ether4-LAN,ether5-LAN,Wifi1-5ghz,Wifi2-2.4ghz vlan-ids=10 add bridge=Bridge-LAN tagged=...
by anav
Sat Dec 28, 2024 8:42 pm
Forum: Beginner Basics
Topic: Problem with VLANs and Bridge
Replies: 20
Views: 2271

Re: Problem with VLANs and Bridge

Late to the game but I see you need rescuing LOL Assumes the management subnet is being sent to the MT as vlan and I am using vlan11. Ether8 is not the managment subnet is the same subnet so taking this as an offbridge safe place to do the config etc. DCHP client should be disabled!! ..................
by anav
Sat Dec 28, 2024 7:28 pm
Forum: Beginner Basics
Topic: Two LANs configuration, wireguard?
Replies: 6
Views: 546

Re: Two LANs configuration, wireguard?

Does the Mikrotik get a public IP??
Are both switches, managed (smart devices)? If so what brand?
Why do you have the AX lite acting as router instead of an AP/Switch ???
by anav
Sat Dec 28, 2024 7:24 pm
Forum: Beginner Basics
Topic: VPN ipsec - no local LAN client access
Replies: 8
Views: 613

Re: VPN ipsec - no local LAN client access

Everything looks decent so will focus on firewall rules....... Keep it simple............ Also missing entirely any forward chain rules!! EDIT: Also noted, nowhere do you assign a local IP address to the VPN ????? One should keep rules in a proper order and for organization purposes and easy trouble...
by anav
Sat Dec 28, 2024 5:26 pm
Forum: General
Topic: Cannot access Lan devices over vpn client
Replies: 22
Views: 21680

Re: Cannot access Lan devices over vpn client

Use wireguard if you have access to a public IP, or can get a port forwarded from upstream router with public IP.

Oopsie, of course one would have to upgrade the router firmware out of the stone age.
by anav
Sat Dec 28, 2024 4:08 am
Forum: Beginner Basics
Topic: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]
Replies: 8
Views: 1301

Re: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]

Main Router: You have no LAN structure for bridgecast and thus I dont expect any traffic on ports 3,4,5. Why do you keep putting full info on the wireguard settings?? PLUS THE ONE FOR THE DEVICE IS WRONG........ the only source IP coming from the device is its wireguard IP address!!!! On the server...
by anav
Fri Dec 27, 2024 10:08 pm
Forum: Beginner Basics
Topic: Wireguard Site to Site VPN
Replies: 8
Views: 657

Re: Wireguard Site to Site VPN

Post both configs
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys etc. )
by anav
Fri Dec 27, 2024 10:06 pm
Forum: Forwarding Protocols
Topic: WireGuard - multiple instances
Replies: 8
Views: 1078

Re: WireGuard - multiple instances

Mozerd I think your saying one wireguard interface and simply use two IP addresses for each purpose with same interface name.
by anav
Fri Dec 27, 2024 7:06 pm
Forum: General
Topic: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard
Replies: 9
Views: 850

Re: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard

Thats why I put separate names so that you can see if all four are being seen.
It must be something else in the config, will look at it later when I have time.
by anav
Fri Dec 27, 2024 3:54 pm
Forum: General
Topic: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard
Replies: 9
Views: 850

Re: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard

Routes are incorrect...... From /ip route add check-gateway=ping comment=WAN1 dst-address=0.0.0.0/0 gateway=192.168.18.1 routing-table=main scope=10 target-scope=12 add check-gateway=ping comment=WAN2 distance= 2 dst-address=0.0.0.0/0 gateway=81.134.176.1 routing-table=main scope=10 target-scope=12 ...
by anav
Fri Dec 27, 2024 3:40 pm
Forum: Forwarding Protocols
Topic: WireGuard - multiple instances
Replies: 8
Views: 1078

Re: WireGuard - multiple instances

Cannot help further without some context. Draw a diagram showing the devices at both ends of the tunnel. Also the full config of the MT and the second device if MT and if not at least the wireguard settings minus any actual public WANIP information or keys. /export file=anynameyouwish ( minus router...
by anav
Fri Dec 27, 2024 3:35 pm
Forum: Wireless Networking
Topic: cAP ax - Multiple SSID + VLAN - No CAPsMAN - No DHCP
Replies: 2
Views: 725

Re: cAP ax - Multiple SSID + VLAN - No CAPsMAN - No DHCP

First thing I would do is take ether2 off the bridge, give it a unique IP address add it to trusted interface list and then plug in laptop to ether2 with 192.168.56.2 set on IPV4 settings and then do all the config from there, a safe spot. example: .................... # model =MTwifi /interface bri...
by anav
Fri Dec 27, 2024 3:21 pm
Forum: Wireless Networking
Topic: MikroTik VPN connection
Replies: 4
Views: 998

Re: MikroTik VPN connection

Can your mikrotik access a public IP, or get a port forwarded to it from the upstream ISP router? Additionally what is the flow direction of the VPN?? External customers from everywhere to reach machines? External router to reach machines? Local Machines to go out internet of another router? Local M...
by anav
Fri Dec 27, 2024 4:22 am
Forum: Beginner Basics
Topic: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]
Replies: 8
Views: 1301

Re: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]

You should really prescribe to vlan filtering but will focus on other things for now. 1. You have three bridges but only use two, so get rid of LAN-Bridge! 2. The second MCAST bridge has no structure, IP address, pool etc........but will ignore that as well. 3. You do not understand how wireguard wo...
by anav
Fri Dec 27, 2024 2:59 am
Forum: General
Topic: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard
Replies: 9
Views: 850

Re: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard

Okay so WAN1 works as is.... Suspect for WAN2 you will need the same thing. So see if this works........ a. a similar script to capture the change of IP address ---> find comment=\ "PPOE-Wan \ b. put the current pppoe gateway in on the config so it would look like... /ip route { main table rout...
by anav
Thu Dec 26, 2024 11:02 pm
Forum: Beginner Basics
Topic: VLAN routes on RB5009
Replies: 7
Views: 747

Re: VLAN routes on RB5009

if you want help post the config not snippets or jpegs
/export file=anynamwyouwish ( minus router serial number, any public WANIP information, keys etc. )
by anav
Thu Dec 26, 2024 11:01 pm
Forum: Beginner Basics
Topic: How to specify an Address List for all ip addresses?
Replies: 4
Views: 408

Re: How to specify an Address List for all ip addresses?

To be blunt, doing what you propose would be plain dumb. If you have a public IP address ( or can forward a port from the upstream ISP router ) you can use normal wireguard. If you get a private IP and no other options BTH wireguard by MT is an excellent option as noted. How do you wish to proceed. ...
by anav
Thu Dec 26, 2024 10:58 pm
Forum: General
Topic: What device should I buy for this use-case?
Replies: 6
Views: 445

Re: What device should I buy for this use-case?

I was sticking as close as possible to the budget margin of the OP!
by anav
Thu Dec 26, 2024 10:49 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

Still confusing. If the Foritgates have no NAT, then how does it get an IP address from the MT, and yet have other subnets behind it???? I think the idea is to push the data to the fortigates and let them deal with it. So Removed the Port forwarding (dstnat) and doing it through firewall rules and r...
by anav
Thu Dec 26, 2024 9:52 pm
Forum: General
Topic: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard
Replies: 9
Views: 850

Re: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard

Good questions! I believe this should address the dynamic nature of the WAN1 gateway as per your script!! When installing the config the for wan1 use the actual current gateway IP . The script you made will keep the routes up to date. /ip route { main table routes recursive } add check-gateway=ping ...
by anav
Thu Dec 26, 2024 9:42 pm
Forum: General
Topic: Guest WiFi with VLAN on UniFi AP
Replies: 18
Views: 1260

Re: Guest WiFi with VLAN on UniFi AP

First: Please remove router serial number from your post! Second: Config is incomplete, the base subnet is missing typical networking items, ip pool etc..... THird: remove or set to NO the ip bridge firewall settings! This is an advanced menu that is normally not needed. Fourth: Normally "allow...
by anav
Thu Dec 26, 2024 9:14 pm
Forum: Beginner Basics
Topic: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]
Replies: 8
Views: 1301

Re: Mikrotik Wireguard VPN ping/routing Problems [SOLVED]

Post both configs full
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys etc. )
by anav
Thu Dec 26, 2024 9:11 pm
Forum: Beginner Basics
Topic: CRS309 Setup Guest VLAN with VLAN hardware offloading
Replies: 16
Views: 1048

Re: CRS309 Setup Guest VLAN with VLAN hardware offloading

My question is on these devices with bridge vlan filtering, is what will the performance of vlan to vlan traffic be, when typically access between vlans is done at Layer 3. So for example with the CRS309 what will be: a. the speed from user on ether4 to user on ether5 if both are on same vlan. b. th...
by anav
Thu Dec 26, 2024 9:01 pm
Forum: Beginner Basics
Topic: Tips from a home user
Replies: 6
Views: 659

Re: Tips from a home user

Jaclaz helped me figure out that ROS is actually being written in "WHOVILLE" and Normis is actually The GRINCH!!
by anav
Thu Dec 26, 2024 8:59 pm
Forum: Beginner Basics
Topic: VLAN routes on RB5009
Replies: 7
Views: 747

Re: VLAN routes on RB5009

The reference is excellent. ONE BRIDGE Once you go vlans, dont have the bridge handle anything (no dhcp) so whatever subnet you had on the bridge assign it a vlan...... Advice; Take one port off the bridge (at least temporarily) give it an IP address and do all the configuration from there for vlans...
by anav
Thu Dec 26, 2024 8:50 pm
Forum: General
Topic: What device should I buy for this use-case?
Replies: 6
Views: 445

Re: What device should I buy for this use-case?

I would get another hex as I dont really like the 260GS, the other option seems very cagey.......
by anav
Wed Dec 25, 2024 11:01 pm
Forum: General
Topic: I have problem with NordVPN.
Replies: 4
Views: 468

Re: I have problem with NordVPN.

Post your config for review
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc.)
by anav
Wed Dec 25, 2024 10:56 pm
Forum: General
Topic: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard
Replies: 9
Views: 850

Re: Dual WAN (Dynamic & PPPOE) PCC & Dual Wireguard

THere is no need to provide two wireguard connections...... Simply use WAN1 and if WAN1 fails wireguard has the capacity to move traffic to WAN2 for any current connection. HOwever if someone attempts to establish a tunnel while WAN1 is down, then having the backup is a decent option but let them kn...
by anav
Wed Dec 25, 2024 10:18 pm
Forum: General
Topic: How to reach a router behind a CGNAT? [SOLVED]
Replies: 23
Views: 1829

Re: How to reach a router behind a CGNAT? [SOLVED]

Why is CHR necessary just for Wireguard peer? It can be setup on Linux running on cloud server and save some money for CHR licence. Once setup on Linux is created, image can be made of it for reuse. Initially some time will be spent to create setup, but later it should be more faster and charge mor...
by anav
Wed Dec 25, 2024 10:17 pm
Forum: General
Topic: How to reach a router behind a CGNAT? [SOLVED]
Replies: 23
Views: 1829

Re: How to reach a router behind a CGNAT? [SOLVED]

All the best to you and your loved ones in 2025 there AtomD.
by anav
Tue Dec 24, 2024 7:56 pm
Forum: Beginner Basics
Topic: Ros 7.16.1 pcc dual wan on dhcp clients, problem.
Replies: 2
Views: 508

Re: Ros 7.16.1 pcc dual wan on dhcp clients, problem.

Diagram and requirements needed to assess if your config actually works a. identify all users and devices , external and internal, including admin b. identify all traffic flow required. c. detail WAN situation public private, static dynamic etc......... Would not even look at your config without kno...
by anav
Tue Dec 24, 2024 7:52 pm
Forum: Beginner Basics
Topic: Assistance Needed with MikroTik Cloud Router Configuration
Replies: 11
Views: 1022

Re: Assistance Needed with MikroTik Cloud Router Configuration

To be clear, what comes directly out of the ISP router. a. a public IP to terminate on the MT b. a private IP on the ISP router LAN ( seems to be the case, and if so what IP has been given to the MT router ) c. What is the purpose of the switch?? Do you control the switch? Type of switch....what els...
by anav
Tue Dec 24, 2024 7:45 pm
Forum: General
Topic: WireGuard and Port Forwarding
Replies: 3
Views: 425

Re: WireGuard and Port Forwarding

Most excellent. The work needs to be done at his/her end to some extent. Basically on the CHR /ip firewall nat add chain=srcnat action=masquerade out-interface=wireguard-interface-name add chain=dstnat action=dst-nat dst-address=CHR-IP-ADDRESS dst-port=ServerPort protocol=??? to-address=ServerLAN-IP...
by anav
Tue Dec 24, 2024 3:52 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

Okay so the fortigates are behind the MT routers and they have double NAT on them not the MT devices. AKA the internet for fortigate is through the MT and you simply want to connect the private LANs behind each fortigate to each other? Which LAN are the fortigates on at each router, what is their IP...
by anav
Tue Dec 24, 2024 5:08 am
Forum: General
Topic: WireGuard and Port Forwarding
Replies: 3
Views: 425

Re: WireGuard and Port Forwarding

Not sure what you mean by given wireguard. Do you have access to CHR on cloud server. Do you have access to a friends MT router?? Or do you have a third party VPN server like nordvpn. If its the latter thats a one way transmission out from your device and out the nordvpn end for internet. There is n...
by anav
Mon Dec 23, 2024 11:34 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

You should have been clear from the start. Firstly, to keep things simple, just connect to WAN 2 for all wireguard clients. There is no need to connect to WAN1 for anybody. So now we know that there is no LAN to LAN connectivity at all between the subnets on both routers correct?? So basically the s...
by anav
Mon Dec 23, 2024 2:05 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

Perhaps a bit more clarity can help avoid getting complex. What I understand. a. you have RouterA server peer for handshake and its lan users can access lan of router B. b. you have RouterB client peer for handshake and its lan users can access lan of router A. c. you have remote wireguard users tha...
by anav
Sun Dec 22, 2024 4:52 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

Okay, I see what Sindy means now.......... possible due to all static public IP addresses... Further its simply router to router connectivity no need to go out internet of the other..... Thus Router B being peer client will send wireguard handshake and due to SIndys rule go out its WAN2 ( heading fo...
by anav
Sun Dec 22, 2024 2:47 pm
Forum: General
Topic: How to reach a router behind a CGNAT? [SOLVED]
Replies: 23
Views: 1829

Re: How to reach a router behind a CGNAT? [SOLVED]

Concur with Sindy, if you are providing a paid service, then having your own cloud wireguard to support all your clients ( shared cost ), is the smart way to go.
by anav
Sun Dec 22, 2024 2:53 am
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

Before I get two into it.... You never mentioned two wireguard networks, what is the purpose please. I dont see any value in dual connections between the same two routers, if one router has an isssue, 50 wireguard networks between the two will still not be fruitful. Also is the intention for Router ...
by anav
Sun Dec 22, 2024 1:47 am
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 2010

Re: Help needed - How to mitigate DDOS atacks with dns

1. Would agree Nothing major to pick out,,,,,,,,, so.. a. start by turning ip cloud DDNS off. b. change dns setting to. /ip dhcp-server network add address=10.44.73.0/24 dns-server=10.44.73.1 gateway=10.44.73.1 c. REMOVE raw rules d. add dstnat rules /ip firewall nat add action=masquerade chain=srcn...
by anav
Sun Dec 22, 2024 1:37 am
Forum: General
Topic: How to reach a router behind a CGNAT? [SOLVED]
Replies: 23
Views: 1829

Re: How to reach a router behind a CGNAT? [SOLVED]

A bit over the top, but it should not be used as a business entity as on occasion, not very frequently the Mikrotik servers have gone offline. A couple of times a year is probably a safe bet. Nothing for you to worry about unless your a hospital, a bank or any business requiring 24/7 VPN up time. If...
by anav
Sat Dec 21, 2024 6:12 pm
Forum: General
Topic: Mangle & Routing RoS 7
Replies: 2
Views: 571

Re: Mangle & Routing RoS 7

I would if I could instead what you were rambling about. I have no clue as to what you are trying to accomplish. a. identify users/devices, groups of users/devices, including external and internat and admin b. identify what traffic each needs c. identify any vpn traffic or port fowarding traffic d. ...
by anav
Sat Dec 21, 2024 4:06 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

MAIN ROUTER A ( server peer for wireguard handshake ) /routing table add disabled=no fib name=use-WAN2 /ip route ( minimum ) add distance=2 check-gateway=ping dst-address=0.0.0.0/0 gateway=pppoe-out1 add distance=4 dst-address=0.0.0.0/0 gateway=WAN2-gateway-ip add dst-address=0.0.0.0/0 gateway=WAN2-...
by anav
Sat Dec 21, 2024 3:22 pm
Forum: General
Topic: Wireguard VPN on dual WAN [SOLVED]
Replies: 37
Views: 3236

Re: Wireguard VPN on dual WAN [SOLVED]

Before replying....... Is there any port forwarding going on (aka external users) or just VPN coming in externally? Both WAN1s are static PPPOE addresses, so confirm a. they dont change b. they are indeed public not private IP addresses. Both WAN2s are ????? a. static or private IP addresses??? b. p...
by anav
Fri Dec 20, 2024 10:59 pm
Forum: General
Topic: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]
Replies: 47
Views: 3025

Re: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]

I would probably upgrade to 7.16.2 but its not absolutely necessary.
However doing so would allow you to remotely reach via BTH wireguard VPN, both the router and the LXT for configuration/troubleshooting issues.

This is the bible on vlans.... viewtopic.php?t=143620
by anav
Fri Dec 20, 2024 10:19 pm
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 2010

Re: Help needed - How to mitigate DDOS atacks with dns

Its seems to be a truism Rextended. Poster come here for help but insist they know where the problem is, which begs the question why come here in the first place....... EIther that or 95% of poster are illiterate or believe in fiction writing. I never say Without seeing the config ( but please only ...
by anav
Fri Dec 20, 2024 10:13 pm
Forum: General
Topic: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]
Replies: 47
Views: 3025

Re: Failover between Routerboard Hex(Starlink) and a SXT LTE6 [SOLVED]

Well I suspect you will need to setup vlans, as the connection to the remote site ( the backup internet part ) will have to come on the same port and on a vlan to be terminated as a WAN connection on the HEX.,
by anav
Fri Dec 20, 2024 5:16 pm
Forum: Beginner Basics
Topic: Help needed - How to mitigate DDOS atacks with dns
Replies: 21
Views: 2010

Re: Help needed - How to mitigate DDOS atacks with dns

More than likely the issue is someone within the network is causing the issues.
Without seeing the config its hard to say if you have something missing in terms of proper security setup.

/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc.)
by anav
Fri Dec 20, 2024 4:54 pm
Forum: Beginner Basics
Topic: RB5009 in the hands of a newbie, Gateway problem
Replies: 19
Views: 1820

Re: RB5009 in the hands of a newbie, Gateway problem

This does not look good at all. /ip address add address= 192.168.88.1/24 comment=defconf interface=bridge network=\ 192.168.88.0 add address= 192.168.88.1 i nterface=ether8 network=192.168.88.1 If your plan was to use ether8 as a safe place to config, a. it needs to be removed from the bridge ( whic...
by anav
Fri Dec 20, 2024 4:39 pm
Forum: General
Topic: RB4011iGS - 3 VLANS one not working
Replies: 7
Views: 632

Re: RB4011iGS - 3 VLANS one not working

So the MT device incoming trunk port (from upstream) is on etherX and on that port incoming is 2 vlans and 1 untagged flow of data? So its getting a hybrid port from the 60G? Is there a trunk port exiting the MT device, aka is it feeding any other smart devices and if so which ports...... Assuming y...
by anav
Fri Dec 20, 2024 4:27 pm
Forum: Announcements
Topic: Newsletter #122 | December 2024
Replies: 78
Views: 30167

Re: Newsletter #122 | December 2024

I talked to Santa --> Normis's cat has been very very good and will be getting lots of presents, Normis, however, has been naughty and might get a lump of coal, unless Santa said, he provides cloudflare zero trust tunnel as an options package.

All the best to the Latvian crew over the holidays.
by anav
Thu Dec 19, 2024 11:54 pm
Forum: Virtualization
Topic: Looking for CloudHosted VPS host
Replies: 7
Views: 899

Re: Looking for CloudHosted VPS host

I use IsHosting.
CHR VPS for 5 EUR /month with fixed ip4.
I am using it as wireguard gateway only for now.
Can I sublet a Wireguard tunnel LOL
by anav
Thu Dec 19, 2024 11:49 pm
Forum: Virtualization
Topic: Looking for CloudHosted VPS host
Replies: 7
Views: 899

Re: Looking for CloudHosted VPS host

Similar is vultr with servers world wide.
I think one can get a decent CHR setup for about $7us a month
by anav
Thu Dec 19, 2024 11:46 pm
Forum: Beginner Basics
Topic: RB5009 in the hands of a newbie, Gateway problem
Replies: 19
Views: 1820

Re: RB5009 in the hands of a newbie, Gateway problem

Now plug in your laptop into ether9, change ipv4 settings to 192.168.65.2 and you should be in!!!
Don't think so.
Not on RB5009 with 8 ether ports :lol:
Then they should have called it the RB5008 LOL
Then use port 8, use your imagination, drink some moose milk!!!
by anav
Thu Dec 19, 2024 11:24 pm
Forum: Beginner Basics
Topic: RB5009 in the hands of a newbie, Gateway problem
Replies: 19
Views: 1820

Re: RB5009 in the hands of a newbie, Gateway problem

THis is the bible on vlans - https://forum.mikrotik.com/viewtopic.php?t=143620 Two things, always use safemode when configuring the router. Basically invoke it, make changes, wait 5 seconds and if the router doesnt blow up, unselect safe mode, which captures the config (saves it) and then continue. ...
by anav
Thu Dec 19, 2024 11:18 pm
Forum: General
Topic: Wireguard VPN Site2Site can't access LAN
Replies: 5
Views: 662

Re: Wireguard VPN Site2Site can't access LAN

What was not clear to me was the purpose of the subnet on ether2 of both routers????/
by anav
Thu Dec 19, 2024 11:17 pm
Forum: General
Topic: Wireguard VPN Site2Site can't access LAN
Replies: 5
Views: 662

Re: Wireguard VPN Site2Site can't access LAN

ROUTERA 1. Most points in Router B also applicable to Router A, changes made. Only rule to add is relay rule for wireguard so you can come in remotely on 10.2.2.2 and then reach routerB. 2. Still need WAN list entry 3. stick to standard neighours discovery for the most part........ 4. allowed ip for...
by anav
Thu Dec 19, 2024 10:55 pm
Forum: General
Topic: Wireguard VPN Site2Site can't access LAN
Replies: 5
Views: 662

Re: Wireguard VPN Site2Site can't access LAN

ROUTERB 1. Main problem is two bridges, dont need one and shouldnt have one, simply assign the second subnet to ether8. 2. Why is .88 subnet hanging around??? You should get rid of all old stuff which becomes noise on the config. PLUS you are using .88 on Router A, so B should not have that at all. ...
by anav
Thu Dec 19, 2024 10:10 pm
Forum: General
Topic: RB4011iGS - 3 VLANS one not working
Replies: 7
Views: 632

Re: RB4011iGS - 3 VLANS one not working

Lots of blank holes have to guess at as config is not clear in intentions. but assuming ethe1 is the wan port and the Bridge LAN, now vlan10 is the TRUSTED subnet. Where are the rest of the rules.......... firewall rules, dhcp server, pool etc.............. Is this not a router facing the internet.....
by anav
Thu Dec 19, 2024 9:44 pm
Forum: General
Topic: Sending guest VLAN to VPN
Replies: 5
Views: 556

Re: Sending guest VLAN to VPN

Depends on comfort level of poster........ I assume beginner, which as evidenced is not always the case.
by anav
Thu Dec 19, 2024 3:01 pm
Forum: Beginner Basics
Topic: Incorporating a backup gateway into my setup
Replies: 14
Views: 1235

Re: Incorporating a backup gateway into my setup

Now, I wish this forum had a mechanism to mark multiple messages as answers because there is no one answer to this thread. <smile Thanks again everyone Well there is no control over the quality of the "hired help" in the forums, tis a journey... but we get you to your destination eventual...
by anav
Thu Dec 19, 2024 2:59 pm
Forum: Beginner Basics
Topic: Unable to access internet when Wireguard is activated
Replies: 6
Views: 1314

Re: Unable to access internet when Wireguard is activated

Correct, my mistake, too much copy and paste.......... Good eye!!
by anav
Thu Dec 19, 2024 2:58 pm
Forum: Beginner Basics
Topic: route all traffic from interface though vpn
Replies: 5
Views: 568

Re: route all traffic from interface though vpn

Are we sure a device acting as a switch an be a WIreguard device? ( no routing, no nat etc.........)
by anav
Thu Dec 19, 2024 2:55 pm
Forum: Beginner Basics
Topic: problem with vlan configuration
Replies: 10
Views: 731

Re: problem with vlan configuration

If you want answers provide more complete information starting with /export file=anynameyouwish (minus router serial number, any public WANIP information, keys etc.) THe config is interrelated showing what you thing we need to see is NOT helpful. By the way, a bridge is not absolutely required but i...
by anav
Thu Dec 19, 2024 2:26 pm
Forum: General
Topic: Sending guest VLAN to VPN
Replies: 5
Views: 556

Re: Sending guest VLAN to VPN

when you post the complete config I will reply /export file=anynameyouwish (minus router serial number, any public WANIP information, keys etc. ) What you are asking should be easily done. Did the third party server provide a specific DNS to use? @cracow, this is a normal setup for the MT going out ...
by anav
Thu Dec 19, 2024 2:21 pm
Forum: General
Topic: RB4011iGS - 3 VLANS one not working
Replies: 7
Views: 632

Re: RB4011iGS - 3 VLANS one not working

Before too much confusion, simply post your current config, sounds like you are fine.

/export file=anynameyouwish ( minus router serial#, any public WANIP information, keys etc. )
by anav
Thu Dec 19, 2024 2:46 am
Forum: Beginner Basics
Topic: make user connect to specific ISP
Replies: 3
Views: 1118

Re: make user connect to specific ISP

Post config, people here do not visit links....... ( use notepadd ++ to paste )
by anav
Wed Dec 18, 2024 9:14 pm
Forum: General
Topic: wireguard config issues
Replies: 8
Views: 950

Re: wireguard config issues

Thats because it should be lower case none, which is available as a chooseable entry. On the hap device, add this mangle rule....... see if it helps accessing sites. /ip firewall mangle add action=change-mss chain=forward comment="Clamp MSS to PMTU for Outgoing packets" new-mss=clamp-to-pm...
by anav
Wed Dec 18, 2024 7:02 pm
Forum: General
Topic: VLAN 1 IP and dedicated MGMT Port IP in same subnet
Replies: 8
Views: 1177

Re: VLAN 1 IP and dedicated MGMT Port IP in same subnet

As the saying goes, garbage in garbage out.

By the way your conclusion is wrong, but since you seem content with it.........
by anav
Wed Dec 18, 2024 5:32 pm
Forum: Forwarding Protocols
Topic: 7.16 firewall issues
Replies: 3
Views: 781

Re: 7.16 firewall issues

/ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=accept chain=input comment="defconf...
by anav
Tue Dec 17, 2024 11:27 pm
Forum: Beginner Basics
Topic: Assign IP address to a bridge?
Replies: 5
Views: 831

Re: Assign IP address to a bridge?

The advantage is when you only have one LAN subnet and the router comes default configured to dish out IP addresses to all ports on the bridge with this subnet. If you want to use vlans, take bridge off any DHCP assignments and attach all vlans to bridge and vlans get address, dhcp server, ip pool e...
by anav
Tue Dec 17, 2024 8:05 pm
Forum: General
Topic: wireguard config issues
Replies: 8
Views: 950

Re: wireguard config issues

OKAY then some assumptions. Ether5 will be an off bridge port to ensure access to the HAP. It will be the sole IP that can access the local internet wherever you are. - Plug laptop into port 5, change IPV4 settings to 192.168.55.2 Ether2-4 will be LAN devices going out WIREGUARD for internet through...
by anav
Tue Dec 17, 2024 5:48 pm
Forum: General
Topic: wireguard config issues
Replies: 8
Views: 950

Re: wireguard config issues

Before addresssing the HAP. Will it be used when you are travelling, or will it be in place statically. Just to ensure that there is not going to be any access to its subnets or devices from other remote users or from the main router as more than likely it will be you with the hap somewhere...........
by anav
Tue Dec 17, 2024 5:12 pm
Forum: General
Topic: wireguard config issues
Replies: 8
Views: 950

Re: wireguard config issues

HOME DEVICE: 1. MAIN Problem is the allowed IPs on the peer settings for the HAP. The allowed IPs is to indentify the client peer by its wireguard IP address, and also a. any subnets that are going to hit your router b. any subnets on the other device that local users will need to reach. SO REPLACE ...
by anav
Tue Dec 17, 2024 4:23 pm
Forum: General
Topic: Route traffic behind double NAT
Replies: 14
Views: 996

Re: Route traffic behind double NAT

He has no vpn tunnel between the mikrotiks, the tunnel is between the two ISP routers.
by anav
Tue Dec 17, 2024 4:21 pm
Forum: General
Topic: Issues with MikroTik Router Upgrades
Replies: 6
Views: 648

Re: Issues with MikroTik Router Upgrades

Hmmmm perhaps join the latest century............. take advantage of wireguard and other features.........
by anav
Tue Dec 17, 2024 4:17 pm
Forum: Beginner Basics
Topic: RouterOS without CAPsMAN?
Replies: 5
Views: 810

Re: RouterOS without CAPsMAN?

I thought this thread was a request to remove capsman from ROS, for a second there I was jumping with joy. More room for cloudlfare zero trust tunnel as an options package.
by anav
Mon Dec 16, 2024 11:10 pm
Forum: Beginner Basics
Topic: Need help setting up a hAP ax3
Replies: 10
Views: 1358

Re: Need help setting up a hAP ax3

Before stating what is wrong, I will say that the wifi setup is horrendous on these things, not logical or intuitive. Okay You seem to be missing the wifi channel settings, the wifi security settings, the wifi configuration settings. Also your use of vlans and bridge is not quite there. Why do you h...
by anav
Mon Dec 16, 2024 6:43 pm
Forum: General
Topic: Wireguard - Half devices reachable
Replies: 8
Views: 808

Re: Wireguard - Half devices reachable

Understood, just wanted you to be safe, looks like all well in hand. Ensure on client peer windows device you have persistent keep alive set. Yes, the switch issue is weird. Its an un-managed switch right?? Check the cable from router to switch ??? I would adjust slightly the rules I gave you though...
by anav
Mon Dec 16, 2024 5:23 pm
Forum: General
Topic: L009 - don't like it...
Replies: 16
Views: 1416

Re: L009 - don't like it...

You dont get it... HexS: The port #5 can power other passive PoE capable devices with the same voltage as applied to the unit There is no such standard as passive POE, as soon as one reads that the red flag goes up, no mention of any standard there..... and limited by input as well.....................
by anav
Mon Dec 16, 2024 5:11 pm
Forum: General
Topic: Wireguard - Half devices reachable
Replies: 8
Views: 808

Re: Wireguard - Half devices reachable

We are not in your head and thus the ramblings of devices is moot. A network diagram would have been far more helpful. Is the mikrotik being used as a wireguard server for handshake or are you connecting to a third part VPN etc.. How many mikrotiks are involved? Where is the config of both MTs? If t...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 75