Community discussions

MikroTik App

Search found 23615 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 79
by anav
Sun Apr 13, 2025 1:50 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 41
Views: 3792

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

Hi Mozerd, I attempted to rejig the Wireguard GUI in winbox 4 and supplied the advice to MT as you can see here. https://forum.mikrotik.com/viewtopic.php?t=215684: The response I got was not enthusiastic as the peer page was too busy etc. So I resubmitted a simplified approach. SEE post #7 for simpl...
by anav
Sun Apr 13, 2025 1:46 pm
Forum: Beginner Basics
Topic: Question VLAN Setup
Replies: 3
Views: 234

Re: Question VLAN Setup

A good network diagram will help planning as well....
by anav
Sun Apr 13, 2025 1:35 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 9
Views: 155

Re: Using CRS326 as a switch

The example provided is a bit confusing. - why include ports 5 through spf-sfpplus2 if not relevant (not being used) - then I see sfp-sfpplus1 is being used but no indication its a trunk port ( frame types or comment missing ) which is inconsistent from the other entries........ - why are you missin...
by anav
Sun Apr 13, 2025 1:20 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 9
Views: 155

Re: Using CRS326 as a switch

https://www.spiceworks.com/tech/networking/articles/network-switch-vs-router/ Clues to you are routing. -DHCP -WAN and LAN -NAT -all subnets have an address -need firewall rules (layer3) Switch..... Single Ip address provided to switch setup is primarily about vlan traffic only management or trusted...
by anav
Sun Apr 13, 2025 1:07 pm
Forum: Beginner Basics
Topic: likely hitting software-based routing limits
Replies: 10
Views: 458

Re: likely hitting software-based routing limits

I would go a step further, why are people making excuses for a chap thats willing to spend $600 without research and where the nomenclature NEVER stated cloud router. Go to the switch section of mikrotik, pull up the applicable switch page and I bet you wont find mention of cloud router!!!. Would as...
by anav
Sun Apr 13, 2025 2:54 am
Forum: Beginner Basics
Topic: Port forwarding
Replies: 9
Views: 584

Re: Port forwarding

Since you didnt bother to post config, Im outta here good luck. Others have more patience than I.
by anav
Sat Apr 12, 2025 9:24 pm
Forum: Beginner Basics
Topic: Help with NAT
Replies: 5
Views: 290

Re: Help with NAT

Yeah much too busy for me to look at in any detail and wont bother until cleaned up. I did note that this is wrong. add allowed-address= 0.0.0.0/0 client-address=10.194.91.2/32 client-endpoint=xx.xx.xx.xx client-keepalive=10s \ client-listen-port=13834 interface= wireguard_1 name= public-key="&...
by anav
Sat Apr 12, 2025 4:33 pm
Forum: General
Topic: Strange PoE issue between MT router and Omada AP
Replies: 8
Views: 444

Re: Strange PoE issue between MT router and Omada AP

I have a 650 myself but plugged into a socket using the adapter ( luckily my wall mount is close to an electrical outlet on the other side of the wall.) I have used injectors with no issue on other tplink and MT access points. https://www.canadacomputers.com/en/power-injector/188906/tp-link-tl-poe16...
by anav
Sat Apr 12, 2025 3:09 pm
Forum: Beginner Basics
Topic: Can't get URL connections that originate from LAN to work on the LAN side!
Replies: 3
Views: 295

Re: Can't get URL connections that originate from LAN to work on the LAN side!

While waiting for the diagram, if you have users in the same subnet as the servers and they are attempting to reach the server via domainname/url then the easy fix is a. change server or users to a different subnet otherwise b. need a hairpin nat rule /ip firewall nat add chain=srnat action=masquera...
by anav
Sat Apr 12, 2025 3:06 pm
Forum: Beginner Basics
Topic: Help with NAT
Replies: 5
Views: 290

Re: Help with NAT

Would need to see MT config
/export file=anynameyouwish (minus router serial number, any public WANIP information, vpn keys )

The wireguard info you were given to connect to the remote wireguard site.
( minus endpoint address, keys )

Diagram of how all the pieces are connected would be useful.
by anav
Sat Apr 12, 2025 1:56 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 11
Views: 617

Re: hAP AC2 vs. AX2...

If your considering WIFI as a factor then get a hex refresh (or better router) and tplink or zyxel wifi7 APs. No point IMHO of going anything less than wifi7 at this point. By the time MT figures out the dogs breakfast of wifi packages and capsman, wifi8 will be out. In other words, dont tie your ro...
by anav
Sat Apr 12, 2025 1:03 am
Forum: Wireless Networking
Topic: How to update CAP from CAPsMAN v2?
Replies: 5
Views: 420

Re: How to update CAP from CAPsMAN v2?

seppuku may be less painful ;-)
by anav
Sat Apr 12, 2025 12:59 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Hi Ammo, Im assuming the distinction was soley at the LAB Rb 5009 regarding changing the Bridge settings ( and not the CRS326 which I am assuming are set at vlan-tagged only on bridge itself ) .... romon.jpg The admins work around was to ignore the ethernet connection and connect to an AP behind the...
by anav
Sat Apr 12, 2025 12:41 am
Forum: Beginner Basics
Topic: No internet on rb260gs conected to cAP ax [SOLVED]
Replies: 10
Views: 643

Re: No internet on rb260gs conected to cAP ax [SOLVED]

Truth be told you are brave and I am a coward......... when it comes to capsman implementation.
Also, you didnt learn anything from me as I dont know anything, but I have successfully passed on information other 'real' experts provide.
by anav
Fri Apr 11, 2025 11:40 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Well based on the avatar, I guess that post could be considered a dud! ;-)) So what is the summary on why RoMON does not work here? I lost track of the conversation. The OP was trying to use romon from on a PC behind a second rb5009 (that was giving the lab 5009) a WANIP on its flan LAN, to reach t...
by anav
Fri Apr 11, 2025 11:25 pm
Forum: Beginner Basics
Topic: hAP ax lite LTE6 - Security
Replies: 8
Views: 519

Re: hAP ax lite LTE6 - Security

There is nothing about setting up a router for security that is different at home or if travelling.
So ensure on your PC you use vpn for internet and if not at least VPN on the browser or AV software.
by anav
Fri Apr 11, 2025 11:23 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 10
Views: 611

Re: RB5009 drops hardware vpn packets but not through another switch

Well the problem could still be the config, which you have refused to provide. There may be some collision with the box protocols and the MT config for example.
by anav
Fri Apr 11, 2025 11:22 pm
Forum: Beginner Basics
Topic: No internet on rb260gs conected to cAP ax [SOLVED]
Replies: 10
Views: 643

Re: No internet on rb260gs conected to cAP ax [SOLVED]

When you get tired of capsman, I can help get it working....... Its more pain that its worth IMHO. In fact it takes over the config like effing egg plant in a garden. ;-)
by anav
Fri Apr 11, 2025 11:20 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Well based on the avatar, I guess that post could be considered a dud! ;-))
by anav
Fri Apr 11, 2025 7:49 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 10
Views: 611

Re: RB5009 drops hardware vpn packets but not through another switch

Maybe the separate box, does not follow protocols properly?? Bad cables??
by anav
Fri Apr 11, 2025 7:47 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Hi Sindy, I dont think the OP has a problem using ROMON when behind the LAB 5009 to reach the connected CRS326 also part of the lab network. The OP, although didnt provide the pertinent information or the pertinent config, only disclosed the fact that he was actually behind another 5009, that provid...
by anav
Fri Apr 11, 2025 5:19 pm
Forum: General
Topic: Replacing RB2011UiAS-2HnD with hAP ax lite LTE6?
Replies: 5
Views: 320

Re: Replacing RB2011UiAS-2HnD with hAP ax lite LTE6?

There are many factors involved here. a. how often does the main internet go down? b. what throughput or level of Cellular performance is good enough c. what level of wifi connectivity is good enough..... What is shocking to me is that as the IT person of this network, states that that there was a f...
by anav
Fri Apr 11, 2025 4:52 pm
Forum: Beginner Basics
Topic: hAP ax lite LTE6 - Security
Replies: 8
Views: 519

Re: hAP ax lite LTE6 - Security

I would have a home MT router, and use the travel router to use the MT router internet via a wireguard tunnel. There is no special sauce be it on the road or at home to keep the traffic as secure as possible. A layered approach works, so if you dont vpn into home use a vpn on the connected devices, ...
by anav
Fri Apr 11, 2025 1:51 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 10
Views: 611

Re: RB5009 drops hardware vpn packets but not through another switch

Hard to day without seeing your 5009 config
/export file=anynameyouwish ( minus router serial number, and any public IP information)

The router should be transparent to the device and its connectivity through the internet to office site using the office vpn.
by anav
Fri Apr 11, 2025 12:56 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

We are going to connect the PC on the master router to the lab router directly on vlan32. So ensure vlan32 is associated with ether1 as well, on the lab router. To facilitate the idea, lets say on the master 5009, its etherport YY that you have connected to the lab5009. Further, you have our pc on t...
by anav
Fri Apr 11, 2025 12:34 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Only stating there was a second 5009 at play at such a late stage, and that the Romon issue stemmed from the first one to the Switch was a criminal omission. Consider yourself flogged ;-)
Your punishment is having to eat the entire plate of smoked meat served at Katz's.
by anav
Fri Apr 11, 2025 12:16 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

According to CGX, there were no shortcomings to using bridge itself vlan tagged, so I hesitate to completely swallow the information provided by AMMO and maybe in-between is a more accurate answer???? It would appear to me that any data from a PC trying to talk ROMON that is assumed to be on the man...
by anav
Thu Apr 10, 2025 11:12 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Who told you this............... ??????
I need Romon to access the CRS

its clear that even though ROMON should not be affected by vlan tag settings on the bridge itself, they are, so avoid its use is my advice.
by anav
Thu Apr 10, 2025 11:08 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

So what is now on ether7?? What is the conflict? I am having difficulty identifying the conflict. ether7 is the CRS. The config paints a conflicted story? set [ find default-name= sfp-sfpplus1 ] comment= CSS326 Hard to find ether7 tagged for any vlans going to CRS326 ??? /interface bridge vlan add ...
by anav
Thu Apr 10, 2025 8:51 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

I access all my downstream devices, ax3 ap, hex switch, etc via neighbours discovery not ROMON (via winbox)
by anav
Thu Apr 10, 2025 8:07 pm
Forum: General
Topic: SmartDNS not working
Replies: 5
Views: 404

Re: SmartDNS not working

Perhaps "smart"dns was just a marketing ploy? ;-)
by anav
Thu Apr 10, 2025 8:05 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

What are you using ROMON for,,,,,,,,,that is not available through neighbours discovery?
by anav
Thu Apr 10, 2025 8:03 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

ROUTER You have a disconnect and duplication when I noted on your trusted listed you had three ports ( vice just one trusted offbridge port ) identified. The fallout of that is 1. a. in ethernet interface settings you identify ether5 as the hapax upstairs, and on /interface bridge ports ( athough m...
by anav
Thu Apr 10, 2025 6:50 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4446

Re: ROMON fails with frame-types=admit-only-vlan-tagged

SWITCH Why are you treating the switch like a router? The only address on the switch is the one given to the switch over the management vlan32 ??? Bridge is not involved............ reminder to look at switch example: https://forum.mikrotik.com/viewtopic.php?t=143620 There is only need of ONE inter...
by anav
Thu Apr 10, 2025 6:41 pm
Forum: Beginner Basics
Topic: interligando RBs
Replies: 2
Views: 245

Re: interligando RBs

For a secure connection suggest wireguard, assuming you have at least on public IP available at one of the routers, or the ISP router in front is capable of forwarding ports.
Alternatively use Zerotier.
by anav
Thu Apr 10, 2025 6:37 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 12
Views: 655

Re: PPPOE with static IP

CGX nailed it........
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1 should be pppoe-out1
WINBOX
IP menu firewall -->NAT

Sorry dont know the CLI commands to change.
by anav
Thu Apr 10, 2025 3:51 pm
Forum: General
Topic: WireGuard - dynamic routes [SOLVED]
Replies: 5
Views: 473

Re: WireGuard - dynamic routes [SOLVED]

RoS is very for giving, many of the default settings are ALLOW by default, so unless you define what is allowed, everything is allowed.
by anav
Thu Apr 10, 2025 3:46 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 12
Views: 655

Re: PPPOE with static IP

Here is one problem........ The termination of the ISP connection is done through pppoe, so the ip address entry for ether1 is incorrect, should be removed. /ip address add address=192.168.88.1/24 interface=bridge1 network=192.168.88.0 add address=cc.220.222.dd/24 interface=ether1 network=91.220.222...
by anav
Thu Apr 10, 2025 2:21 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 12
Views: 655

Re: PPPOE with static IP

What does a duck do on the router? quackNat quacknat quacknat quacknat.
fixed it for ya
by anav
Thu Apr 10, 2025 2:18 pm
Forum: General
Topic: WireGuard - dynamic routes [SOLVED]
Replies: 5
Views: 473

Re: WireGuard - dynamic routes [SOLVED]

1. Typically the recommendation here is loose , not strict! /ip settings set rp-filter= strict 2. Lack of decent set of firewall rules, plus should be organized together in chains and in a coherent order. PLUS security infraction, one does not access winbox from external as you are attempting. Only ...
by anav
Wed Apr 09, 2025 11:54 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 9
Views: 584

Re: Port forwarding

/export file=anynameyouwish ( minus router serial number, any public WANIP information ) It should be quick to find the issue! also. a. confirm you are using LANIP of server to reach from LAN? b. confirm you have a public IP address (static or dynamic) OR you have an ISP router that has a public IP ...
by anav
Wed Apr 09, 2025 11:28 pm
Forum: General
Topic: DHCP Issues on Port 4 Despite Normal EoIP Operation
Replies: 2
Views: 315

Re: DHCP Issues on Port 4 Despite Normal EoIP Operation

Can you post your latest config on both routers.
/export file=anynameyouwish ( minus router serial number, any public WANIP info, keys. )
by anav
Wed Apr 09, 2025 10:59 pm
Forum: Beginner Basics
Topic: How can I configure DHCP on EoIP over Wireguard?
Replies: 1
Views: 210

Re: How can I configure DHCP on EoIP over Wireguard?

I do not believe DHCP in general works over wireguard but there may be ways..........
Check out VXLANs and EOIP as two possibilities ( running over wireguard or L2TP to keep the traffic secure ).
by anav
Wed Apr 09, 2025 10:45 pm
Forum: General
Topic: WireGuard - dynamic routes [SOLVED]
Replies: 5
Views: 473

Re: WireGuard - dynamic routes [SOLVED]

Would need to see the complete config, but it sounds like you want the users on your subnets to use wireguard for specific WANIPs that exist, and where they are not static but dynamic WANIPs. First, please do not use the same name for different RoS funcitonalites, aka the name of the list being the ...
by anav
Wed Apr 09, 2025 10:27 pm
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 708

Re: Need a nat rule

How you sussed that out from the information presented boggles my mind. Glad you are here LOL However, the weak point being, how does the router know that 10.72.22.200 should be assigned to the device ( assuming its now in a VLAN of that subnet structure )?? THe router knows that that address might ...
by anav
Wed Apr 09, 2025 7:22 pm
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 708

Re: Need a nat rule

I probably missed the intent entirely but why not something as simple as: If I have a device with LANIP 192.168.0.X and I want it to go out over wireguard but as 10.10.100.Y address add chain=srcnat action=src-nat src-address=192.168.0.97 to-address=10.72.22.200 AND for return traffic..................
by anav
Wed Apr 09, 2025 7:17 pm
Forum: Beginner Basics
Topic: PCC load balancing
Replies: 1
Views: 220

Re: PCC load balancing

What are your qualifiers in the PCC mangle rules??
by anav
Wed Apr 09, 2025 7:15 pm
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 6735

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

Normis, massina seems to have experience with migrations, and that at least should be made aware to the admins in their deliberations. Thanks for your feedback in this thread, its really good to see!
by anav
Wed Apr 09, 2025 1:27 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1015

Re: Multi-wan multi-ip wireguard setup

To clarify the source nat address part is STILL required. I think he is saying
add action=dst-nat chain=dstnat connection-mark=wg-wan2 to-addresses=10.20.30.40
add action=src-nat chain=input connection-mark=wg-wan2 to-addresses=10.20.30.40
by anav
Wed Apr 09, 2025 1:27 am
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1619

Re: Basic VLAN config question (again)

Interesting, as long as there is no downside, narrowing down the frame type at the bridge, is then viable would be my conclusion. Assuming you mean this is valid for both routers and switches CR3 types when using vlan filtering??? Just to be clear this does not interfere with any situations where a....
by anav
Tue Apr 08, 2025 11:37 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1619

Re: Basic VLAN config question (again)

The first error. 1. is quoting from your config in post #18 EDIT : and is USER OPTIONAL ( without frame limitations vlan-id1 is shown as a dynamic entry but not a concern, as well limit frame types on all bridge ports/wlans - I guess either way is acceptable! 2. is quoting from your confing in post ...
by anav
Tue Apr 08, 2025 10:37 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1015

Re: Multi-wan multi-ip wireguard setup

Yup sounds familiar and as CGX pointed out we only need to use one LO address/interface to accomplish same.......... no need for bridge!!
/ip address
add address=10.20.30.40 interface=lo network=10.20.30.40
by anav
Tue Apr 08, 2025 10:34 pm
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 6735

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

re: ... Anyway, whatever they end up doing... I do hope they host it on their RDS ROSE server(s) as proof-point they work in the real-world. ... If I hosted this server , I would go with Proxmox hypervisors Xeon , 40-Gig or 100-Gig network cards , NFS mounts from a TrueNAS ( 512-Gig Ram or 1-TB-Ram...
by anav
Tue Apr 08, 2025 5:44 pm
Forum: Beginner Basics
Topic: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel
Replies: 11
Views: 624

Re: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel

Looking at the diagram it would appear you have three separate networks/locations. The laptop is a remote device could be anywhere a true remote peer. The MT device is a fixed remote device. The Server is the local wireguard in this discussion. All three are not connected but all three have access t...
by anav
Tue Apr 08, 2025 4:45 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1619

Re: Basic VLAN config question (again)

Speed is not all its cracked up to be, taking ones time mostly results in greater satisfaction,.......... Besides there is an error before that..... and many many after LOL 1. /interface bridge add admin-mac=F4:1E:57:2C:BE:98 auto-mac=no comment=defconf frame-types=\ admit-only-vlan-tagged name=brid...
by anav
Tue Apr 08, 2025 4:01 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

How does it relate to the input chain rule then?? add chain=input action=accept dst-address=127.0.0.1 and you are saying Then 10.20.30.40 can be used instead of both your 172.16.10.1 and 172.16.10.2. Does this mean the following. /ip firewall nat add action=dst-nat chain=dstnat connection-mark=wg-wa...
by anav
Tue Apr 08, 2025 2:41 am
Forum: Beginner Basics
Topic: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel
Replies: 11
Views: 624

Re: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel

Please draw a diagram, I have no clue how everything is hooked up together and to the internet
by anav
Tue Apr 08, 2025 2:39 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Hi CGX...
What the heck is lo LOL, an existing interface on the router that is there all the time??
by anav
Mon Apr 07, 2025 4:44 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

I see no reason to use PCC, if ECMP is ensuring fair usage of all WANs ( they have to be equalish in throughput ). Maybe ECMP circa 7.18, the brewmasters finally got right....................... Better than PCC is actually load balancing which add a layer of additional mangling but you can do it bas...
by anav
Mon Apr 07, 2025 3:22 am
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

Well HA does not use DHCP Option codes, must have coders from the dark ages. In any case you could try something like this simple DNS pointing. IOT Subnet on R2 - 192.168.55.0/24 IP of server on R1 - 10.10.10.15 ON R2 /ip dhcp-server network add address=192.168.55.0/24 dns-server=192.168.55.1 domain...
by anav
Mon Apr 07, 2025 3:11 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

Never said it was, but to think up such trickery, you are on the spectrum somewhere ;-P You have answered my question, there is no rhyme or reason, it is not controllable and thus the faux bridge approach is STILL required even in ECMP. Thus, the answer is dont have multiple WANS, ;-) Good, so you h...
by anav
Mon Apr 07, 2025 1:08 am
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1619

Re: Basic VLAN config question (again)

What?? Well the physical port ether1 is a trunk port carrying multiple vlans to the local device. Why would you not think that vlan32 should be allowed to ingress in ether1?? A. its on the trunk port leaving the upstream device. B. its noted as a tagged vlan id on ether1 in /interface bridge vlan s...
by anav
Mon Apr 07, 2025 1:04 am
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

You miss the point entirely, The two options presented DHCP and DNS are to inform the iot device, what is the IP address of the HA server, not to change the local subnet IP the iot device is using. And how would DHCP or DNS be used to inform the IoT device the address of the HA server? I stated it ...
by anav
Mon Apr 07, 2025 1:01 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

I am saying I have 3 ISPs all different all relatively 1gig connections. I load balance via ECMP /ip route ( main table ) add dst-address=0.0.0.0/0 gateway=gatewayIP-wan1 routing table=main add dst-address=0.0.0.0/0 gateway=gatewayIP-wan2 routing table=main add dst-address=0.0.0.0/0 gateway=gatewayI...
by anav
Mon Apr 07, 2025 12:39 am
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 6735

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

Hahaha, I thought it was simply my browser, I keep forgetting they use a haplite to run their website, the free schnapps in the web lounge is not helping work output either.
by anav
Mon Apr 07, 2025 12:37 am
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

You miss the point entirely,
The two options presented DHCP and DNS are to inform the iot device, what is the IP address of the HA server, not to change the local subnet IP the iot device is using.
by anav
Sun Apr 06, 2025 11:13 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

Sorry I meant EMP of course. Does it work during a nuclear blast in the atmosphere??? Of course I meant ECMP, you know this feature --> Equal Cost Multi-Path...... My question is germane, not dry (german), because we are not sure of how the router decides which interface/route it decides to use on t...
by anav
Sun Apr 06, 2025 10:25 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

Maybe, home assistant appears to be a dogs breakfast with differing information wherever you look. One place says the server scans the network for devices...................
by anav
Sun Apr 06, 2025 10:23 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

So lurker did you test like 3 WANS with ECMP load balancing
Basic mangle rule in wan3 out wan3 generic all traffic to WAN back out same WAN.
What does the wireguard process choose for source address in this case, alway the correct WAN?? ( regardless if you put wireguard on wan1, wan2, or wan3 )
by anav
Sun Apr 06, 2025 9:44 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

By the way, Home Assistant devices typically obtain IP addresses from the Home Assistant server through the network's DHCP server, which is usually the router, rather than directly from the Home Assistant server itself. This sounds much like the UNIFI approach where one can use a. create dhcp option...
by anav
Sun Apr 06, 2025 9:38 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

@lurker888, does EOIP really have the same handshake issue as WG, like I described above?
Since when does EOIP have a handshake, I use EOIP within a wireguard tunnel LOL, not outside of it.
by anav
Sun Apr 06, 2025 9:02 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1619

Re: Basic VLAN config question (again)

Not your concern mkx, its hard to keep straight incomplete questions without context................
by anav
Sun Apr 06, 2025 8:57 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 7
Views: 12579

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Rereading your first post, BOLLOCKS..... Prerequisites A Mikrotik router running RouterOS v7.x A Linux system (e.g., Debian) to retrieve necessary keys An active NordVPN subscription Why?? NordVPN will give you the private key to use on the Mikrotik Router Interface creation. That creates a public k...
by anav
Sun Apr 06, 2025 8:46 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

I have a better idea, why not just live in my office I have a spare chair and desk and I can setup a tent outside, winter is almost over.
Payment in good food and beer LOL
by anav
Sun Apr 06, 2025 8:41 pm
Forum: Beginner Basics
Topic: Home network configuration through Mikrotik hAp ax3
Replies: 1
Views: 321

Re: Home network configuration through Mikrotik hAp ax3

Sure, the default setup is quite good, in that it is safe to connect ether1 to you internet connection and use ports 2-5 for internet. If you need more than one network on your home you will need bridge vlan filtering.. This is the best article to read --> https://forum.mikrotik.com/viewtopic.php?t=...
by anav
Sun Apr 06, 2025 8:23 pm
Forum: Useful user articles
Topic: How to export your Mikrotik config and share it (Step-by-Step guide)
Replies: 14
Views: 916

Re: How to export your Mikrotik config and share it (Step-by-Step guide)

I have seeing lots of timezones in shared configs, that also may expose your location.
And of course wifi country settings.
Good point, the somali gang members probably dont want people to know they are in Sweden.,.........shhhhh its a secret.
by anav
Sun Apr 06, 2025 8:20 pm
Forum: Beginner Basics
Topic: Kids Control
Replies: 5
Views: 3959

Re: Kids Control

Kid control is not really intuitive.
Have you notifed MT by a suggestion on their support website.
If not, get on with it. ;-)
by anav
Sun Apr 06, 2025 6:56 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1619

Re: Basic VLAN config question (again)

Why would a frame tagged with VID=32 ingressing to ether1 be accepted? What?? Well the physical port ether1 is a trunk port carrying multiple vlans to the local device. Why would you not think that vlan32 should be allowed to ingress in ether1?? A. its on the trunk port leaving the upstream device....
by anav
Sun Apr 06, 2025 6:19 pm
Forum: Useful user articles
Topic: How to export your Mikrotik config and share it (Step-by-Step guide)
Replies: 14
Views: 916

Re: How to export your Mikrotik config and share it (Step-by-Step guide)

The point being, silly goose is that Jaclaz is talking about a. the items in the config that are not already removed by RoS ( RoS removes passwords and ipsec stuff for example ) b. the items you added or router added, NEEDED not whimsically added, to make the config work, be it public IP address, ga...
by anav
Sun Apr 06, 2025 6:06 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

No worries there Larsa, no I have not tested the hard down theory, but I trust Larsa has, as he seems to be a testing machine, highly motivated. I am starting to think he is an AI brain attached to an MT network. I sent a suggestion to MT to fix the issue based on the fact that 'fwmark' already exis...
by anav
Sun Apr 06, 2025 4:12 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

BartoszP aka devil colours would be more appropriate ;-) But please answer my questions here --> viewtopic.php?t=215918#p1137048
by anav
Sun Apr 06, 2025 4:10 pm
Forum: Beginner Basics
Topic: Remote WinBox access over WireGuard?
Replies: 9
Views: 601

Re: Remote WinBox access over WireGuard?

If Joseph you are asking a different question, can one see all the routers at one time via winbox, via wireguard, in order to select for configuring, the answer is no. Those protocols dont go over wireguard.
by anav
Sun Apr 06, 2025 4:09 pm
Forum: Beginner Basics
Topic: Remote WinBox access over WireGuard?
Replies: 9
Views: 601

Re: Remote WinBox access over WireGuard?

duplicate.
by anav
Sun Apr 06, 2025 3:35 pm
Forum: Beginner Basics
Topic: Remote WinBox access over WireGuard?
Replies: 9
Views: 601

Re: Remote WinBox access over WireGuard?

Yes /export file=anynameyouwish ( minus serial number, any public WANIP information, wireguard keys ). WHich mean a. serial number one entry at beginning of config b. WANIP information, so removed any PUBLIC wan ip information --> could be in IP DHCP Client text, IP route text ( public IP address or...
by anav
Sun Apr 06, 2025 3:30 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 2977

Re: MikroTik RB5009 setting up remotely first time

Bartosz you make me laugh................. this is a non-paid gig, dont complain about playing consultant for free. ;-P
Your stamina is commendable. :-)
by anav
Sun Apr 06, 2025 3:27 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

I assumed as always, that you are short of time and thus want to getter done. If you have time to read novels, that is a different story '=)
Wait till you hit the chapters on VRRP VXLAN and BGP.
by anav
Sun Apr 06, 2025 3:14 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1015

Re: Multi-wan multi-ip wireguard setup

Mimiko read this post please --> viewtopic.php?p=1136686#p1136996
by anav
Sun Apr 06, 2025 3:13 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 905

Re: Split DNS

It may or may not be applicable for what you are trying to do.
My question is why do you need split DNS for the IOT subnet?
Do you have different IOT devices on the same subnet?
Are there are other ways to target those specific IOT devices......
by anav
Sun Apr 06, 2025 2:39 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

RIGHT, you proved me right again thank Bartosz........ A config is based on a set of established requirements, not vapour future wishes. If the op wants efficiency, the shortest path to get his 10 routers up and running as they are now, DNS is stewpid. If the op wants to tinker with DNS, which is mo...
by anav
Sun Apr 06, 2025 2:19 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

The problem with Sindys excellent approach is that it relies on the dstnat rule to un-dst the WAN1 IP to the WAN2IP so that the source of the response traffic leaving the router is correct. The mangle is fine and working as the route chosen is still good. The crux of the problem is how the router de...
by anav
Sun Apr 06, 2025 2:10 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1619

Re: Basic VLAN config question (again)

Somewhere along the line MT must have changed the default to YES, hard on us ole-timers LOL
by anav
Sun Apr 06, 2025 1:16 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

THis is the most interesting part about your post. The packet is annotated with the connection mark in the conntrack phase. Until then, there is no associated connection mark. (On normal linux, wg interfaces have a property fwmark, which allows all packets emitted by wg to be marked on creation - th...
by anav
Sun Apr 06, 2025 1:09 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

(I see what you are doing with wireguard just dont agree with it. There is no case where both sides of a connection need 50.0/24 that I can see.) Regarding the contrack and wireguard and dual WAN etc......... I approached it from a different angle so it makes sense to me. The initial problem before ...
by anav
Sat Apr 05, 2025 9:25 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

My bad that is valid, but this is assuming the remote router is an MT router. ( client peer for handshake) ........ makes sense, so other peers connecting to the local router can easily re-enter the tunnel and reach the remote router via the local router, so to speak. The local router needs allowed ...
by anav
Sat Apr 05, 2025 8:44 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

All a waste of time. Simply input chain last rule drop all else Simply forward chain last rule drop all else WInbox services, include all subnets that are TRUSTED, management vlan, offbridge port, and any other subnet where you may be coming from to access winbox and the router (like wireugard subne...
by anav
Sat Apr 05, 2025 4:58 pm
Forum: General
Topic: Device got hacked 1 min after connected to internet
Replies: 57
Views: 9167

Re: Device got hacked 1 min after connected to internet

They like blinking lights?
by anav
Sat Apr 05, 2025 4:54 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

My problem is not properly understanding connection tracking, Nothing more you can do LOL.
At least I kind of grasp your use of faux bridge and how traffic gets there, its after, the response traffic and mangle and routing that eludes me completely.
by anav
Sat Apr 05, 2025 2:00 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

It goes to root reason. As I stated, WAN1 being primary WAN2 secondary wanting to use WAN2 for wireguard. We only need to mangle for WAN2 and the problem was the router was sending return traffic via WAN1........ Thus we dsnatted to fool router to send traffic back out WAN2....... You pointed out th...
by anav
Sat Apr 05, 2025 1:55 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Well the drop all rule will certainly cut out non trusted vlan access to winbox, since the interface list allows only trusted vlans, but without the drop all rule, nothing is really blocked, mac-server winbox-mac-server is used in conjunction with neighbours discovery to make all smart MT devices sh...
by anav
Sat Apr 05, 2025 5:07 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

So in your example you have to manipulate both wans, not just wan2??
by anav
Sat Apr 05, 2025 5:04 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 1723

Re: Wireguard Peer not able to reach internet

To config vlan filtering always a good idea to take an unused port or temporarily use a lesser important port and take it off the bridge, Give it an Ip address and config from there safely. Okay how to create an offbridge port. REMOVE ether5 from /interface bridge ports /interface ethernet set [ fin...
by anav
Sat Apr 05, 2025 1:29 am
Forum: Beginner Basics
Topic: internet speed
Replies: 8
Views: 818

Re: internet speed

Suggest you send supouts to MT as possible bug reports.
by anav
Sat Apr 05, 2025 1:27 am
Forum: Beginner Basics
Topic: Best gear to receive 4G/5G signal to a cottage
Replies: 13
Views: 2114

Re: Best gear to receive 4G/5G signal to a cottage

The top of the tree may tend to sway significantly so not sure if thats ideal, in my experience its always windy. :-(
A pole on a fixed object like house may be better unless there is an earthquake every time you want to use the connection.
by anav
Sat Apr 05, 2025 1:25 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 1723

Re: Wireguard Peer not able to reach internet

Best thing is to repost your latest for review!
by anav
Sat Apr 05, 2025 1:24 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 1723

Re: Wireguard Peer not able to reach internet

Perfect so netmask 28 works for you !! As for the rest looking at post #3 your worK! /interface bridge port add bridge=bridge comment=defconf ingress-filtering=no interface= ether2 \ internal-path-cost=10 path-cost=10 /ip address add address= 192.168.88.1/24 comment=defconf interface=bridge network=...
by anav
Sat Apr 05, 2025 1:20 am
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 904

Re: Question about interface lists

As surmized: Behaviour is normal: MAC server MAC server section allows you to configure MAC Telnet Server, MAC WinBox Server and MAC Ping Server on RouterOS device. MAC Telnet is used to provide access to a router that has no IP address set. It works just like IP telnet. MAC telnet is possible betwe...
by anav
Sat Apr 05, 2025 1:18 am
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 904

Re: Question about interface lists

Yes, that should not happen, You should only be able to access the router via Winbox from the management VLAN with those settings.......... I would need to see your whole config to comment accurately though.... /export file=anynameyouwish ( minus router serial number, any public WANIP information, k...
by anav
Sat Apr 05, 2025 1:01 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 1723

Re: Wireguard Peer not able to reach internet

Just started reading the post and yes, MANY ERRORS in the config which are not all yet sorted. Clearly your wireguard IP address is hosed. It should be assuming you only need/want one peer as such add address=192.168.89. 1/30 interface=wireguard1 network=192.168.89.0 { allows only two useable IPs .1...
by anav
Sat Apr 05, 2025 12:52 am
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Why security of course! If you dont want any security
then simply

have two firewall rules
add chain=input action=accept comment="eviscerate me"
add chain=forward action=accept comment="bugger me
"
by anav
Fri Apr 04, 2025 11:43 pm
Forum: General
Topic: Issues with MikroTik L009 Configuration – Firewall & PPPoE
Replies: 1
Views: 637

Re: Issues with MikroTik L009 Configuration – Firewall & PPPoE

setting up pppoe should be easy peasy, go to ppp settings and hit the plus sign and select pppoe client I think near the bottom of the list. This shows a more complex scenario where they use a vlan to send the traffic, whereas in your case you dont need to replace ether1 as the interface. https://ww...
by anav
Fri Apr 04, 2025 11:40 pm
Forum: General
Topic: Cannot reach access point on tagged management vlan
Replies: 3
Views: 449

Re: Cannot reach access point on tagged management vlan

In a switch scenario. One should normally only identify the management vlan! This vlan in /interface bridge vlans is the ONLY vlan-id that requires the bridge to be tagged, the rest are tagged on etherX and go out etherY or WLAN1/WLAN2 etc.. This vlans address is the address of the switch for manage...
by anav
Fri Apr 04, 2025 11:31 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Basic firewall for Router BUT FIRST YOU NEED to add missing pieces!! /interface list add name=WAN add name=LAN add name=TRUSTED /interface list member add interface=ether1 list=WAN add interface=general_vlan list=WAN add interface=media_vlan list=WAN add interface=management_vlan list=WAN add interf...
by anav
Fri Apr 04, 2025 11:11 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Okay matt that clears up that perspective. Firewall rules will speed things up actually, especially with use of fastrack etc.. I mean on the router, switch requires no firewall rules. Save turn OFF ipv6 if not using it. Going back to the configs... then switch 326 1. modify the first line for consis...
by anav
Fri Apr 04, 2025 8:38 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Router . Summary ( incomplete, not ready for deployment ) 1. Not necessary, as the router dynamically untag the port, but it shows you understand the vlan filtering. /interface bridge vlan add bridge=bridge1 comment="General VLAN" tagged=bridge1,bonding1 untagged=ether3 vlan-ids=10 2. Fir...
by anav
Fri Apr 04, 2025 7:41 pm
Forum: Beginner Basics
Topic: NAT mikrotik allowing connexions from another network
Replies: 1
Views: 286

Re: NAT mikrotik allowing connexions from another network

Its easy for computers behind the MT to reach other computers because all traffic out the MT is natted to the WANP of the MT .156, which is on the LAN of box devices. Their return traffic goes back to the MT, and the MT un-sourcenats that back to the originators. However consider the reverse, when t...
by anav
Fri Apr 04, 2025 7:29 pm
Forum: Beginner Basics
Topic: VLANS Through Managed Switches - Beginner Config [SOLVED]
Replies: 11
Views: 9032

Re: VLANS Through Managed Switches - Beginner Config [SOLVED]

Create your own EVE-NG or GNS3 type lab environment..........
by anav
Fri Apr 04, 2025 7:21 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Lurker, gone down many a rabbit hole, I cannot seem to work my way through the noise of your solution.......... Context: Two WANS, WAN1 primary, and WAN2 secondary and wishing to use WAN2 as the wireguard connection. If given a faux bridge 192.168.66.0/32 address and given a listening port of 55555,...
by anav
Fri Apr 04, 2025 1:39 pm
Forum: Beginner Basics
Topic: beginner - i'm trying to build a vlan
Replies: 10
Views: 809

Re: beginner - i'm trying to build a vlan

By rereading the article, where are frame types list on bridge ports, also basic networking, you got the pools but dont you realize each subnet needs
a. pool
b. dhcp server
c. dhpc server network
d. address
by anav
Fri Apr 04, 2025 1:30 pm
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 904

Re: Question about interface lists

Correct, manually entered. Typically, once you have vlans, one has to indicate which is a Trusted or the Management vlan, if nothing else for proper security. This is done through creating a TRUSTED interface list........ This ripples through the config a. the input chain, users ONLY need access to ...
by anav
Fri Apr 04, 2025 1:22 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 18591

Re: WireGuard Multi-WAN Policy Routing

Hi Larsa, I think we need to go to Lurkers solution as the correct answer as Sindys, does not deal with the issue of the primary WAN being not available, and how that screws up the single dsntnat rule.
by anav
Fri Apr 04, 2025 12:37 am
Forum: Beginner Basics
Topic: Returning Newbie :) - Optimizing Bandwidth Config
Replies: 9
Views: 1245

Re: Returning Newbie :) - Optimizing Bandwidth Config

Sorry couldnt get past the router........ ;-)
by anav
Thu Apr 03, 2025 11:51 pm
Forum: Beginner Basics
Topic: beginner - i'm trying to build a vlan
Replies: 10
Views: 809

Re: beginner - i'm trying to build a vlan

First do not ask any questions and only show snippets on the config of what you think we should see, if you dont know the problem how can you know where to look. You now have almost duplicate SrcNAT Rules and that is redundant, get rid of the second one. For the export to see what is causing your is...
by anav
Thu Apr 03, 2025 11:47 pm
Forum: Wireless Networking
Topic: Wifi Bridge
Replies: 1
Views: 333

Re: Wifi Bridge

Not possible across brands.
Your best bet is
a. to drill (best)
b. to use moca adapters if there is rgb6 coax in the house (okay) Trendnet makes some
c. use powerline adapters over electrical wiring (mileage will vary) best are https://www.techradar.com/news/the-best ... e-adaptors
by anav
Thu Apr 03, 2025 11:41 pm
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 904

Re: Question about interface lists

Yup the correct vlan reference article was provided! If you will notice, there is one bridge all vlans, so the bridge does no dhcp or subnet work............. simply create a vlan for that subnet as well. To make changes worry free!!! Actually the best thing to do is take ether5 off the bridge and d...
by anav
Thu Apr 03, 2025 7:58 pm
Forum: General
Topic: Mikrotik iOS app - connection refused
Replies: 3
Views: 440

Re: Mikrotik iOS app - connection refused

Problem would be in the config settings, which are all gone now so cannot really help.......
by anav
Thu Apr 03, 2025 5:27 pm
Forum: Beginner Basics
Topic: beginner - i'm trying to build a vlan
Replies: 10
Views: 809

Re: beginner - i'm trying to build a vlan

If you will notice, there is one bridge all vlans, so the bridge does no dhcp or subnet work............. simply create a vlan for that subnet as well. Actually the best thing to do is take ether5 off the bridge and do all the config from a safe location. Okay how to create an offbridge port. REMOVE...
by anav
Thu Apr 03, 2025 5:24 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1015

Re: Multi-wan multi-ip wireguard setup

Sorry no context provided, why are you mangling for example.......
Do you have a network diagram
by anav
Thu Apr 03, 2025 1:21 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

If you want help with your setup post a new thread and will need your traffic requirements and current config.
by anav
Wed Apr 02, 2025 11:22 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

WRONG you do not get to set a false narrative. BE HONEST. First, let's leave out the variable of going to each IoT device. This is something that I will need to do regardless of which solution is implemented. Bullpucky, there is nothing you have to do at each device if they are all currently pointin...
by anav
Wed Apr 02, 2025 10:11 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

That is the point I am making, the work required for firewall rules and routing and allowed IPs needs to be done reqardless of which method is used to get information from the iot device to the home assistant server. What I am saying is that you need to really do a comparison SETUP from where you ar...
by anav
Wed Apr 02, 2025 9:03 pm
Forum: Wireless Networking
Topic: Guest Network: VLAN vs. Bridge
Replies: 10
Views: 1906

Re: Guest Network: VLAN vs. Bridge

Probably more granularity than standard firewall filter rules can provide, although since I dont use bridge filters nothing comes to mind.
by anav
Wed Apr 02, 2025 8:57 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Thanks much lurker, that is most helpful for me and will take the time to digest traffic flows as you have manipulated them!!

Any thoughts on what the responder checkbox is trying to do??
by anav
Wed Apr 02, 2025 8:54 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

The question is about DNS configuration, not how to configure and pass the traffic from branches to main place using VPNs.
You miss the point, the OP does not intend on reaching the home assistant server over the WWW, he wants all traffic to go over wireguard tunnels between the routers.
by anav
Wed Apr 02, 2025 8:51 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

yup, I understand that you have 100 devices, that you dont need to touch, they are already set for 192.168.0.x There is no need to touch DNS or add DNS servers or make any DNS rules to ANY of the nine routers to get their traffic to the host router for the home assistant server. The home assistant s...
by anav
Wed Apr 02, 2025 7:13 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

Hi Bartosz, Trying to understand your advice and with Larsa endorsement, of course! I too like Joseph, being not IT professional need some conceptual guidance. What I think your saying, in techno speak, is in static DNS we attach or identify an IP address with an URL or domain name that we have give...
by anav
Wed Apr 02, 2025 6:58 pm
Forum: General
Topic: What hardware to buy?
Replies: 3
Views: 403

Re: What hardware to buy?

How many ISPs or how may WANIPs will you have and what are the throughputs. Right now I would look at the hex refresh and two or three wifi7 TP link or zyxel APs. If the WAN throughput is greater than what the hex refresh can provide I would look at the RB5009. If you want to look at using MT wifi, ...
by anav
Wed Apr 02, 2025 6:33 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 8659

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

HI Larsa and Lurker, have been attempting to follow these entangled threads but not making much headway other than Lurker seems to have come up with a way regardless of scenario to basically ensure that in a multi-wan scenario, RoS can be manipulated to ensure wireguard connections work properly. No...
by anav
Wed Apr 02, 2025 5:01 pm
Forum: Wireless Networking
Topic: access point won't start
Replies: 12
Views: 1616

Re: access point won't start

I bet if you got a TPLINK access point and plugged it into one of the ports it would work just fine. My bet is on the wifi settings........... they are designed for the new user to fail, almost as if, if we want to discourage people from using our wifi.
by anav
Wed Apr 02, 2025 4:50 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

@anav: I see no savings at all :) Concur, in fact its actually more work to create DNS servers at each location and then modify each IOT device to look for a specific URL. Once done, any change to IP address of the home assistant server would require changes to every local DNS server to match, vice...
by anav
Wed Apr 02, 2025 2:39 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

I dont see the savings............... In fact call BS on Bartoz and Larsa :-) (please prove me wrong, so I can eat egg off my face !!) Right now you can simply NOT touch a single device, lets say there are 100 devices and get the job done. All you need to do on each router is /ip route add dst-addr...
by anav
Wed Apr 02, 2025 1:56 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2058

Re: Public DNS to private IP

So are you stating that you wish all the traffic from the locations will go out the WWW to reach the home assistant server at location Y?
by anav
Wed Apr 02, 2025 3:16 am
Forum: Beginner Basics
Topic: Best gear to receive 4G/5G signal to a cottage
Replies: 13
Views: 2114

Re: Best gear to receive 4G/5G signal to a cottage

There is also ATL LTE18 KIT ?
by anav
Wed Apr 02, 2025 3:13 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 2977

Re: MikroTik RB5009 setting up remotely first time

An accurate description of context is always appreciated from the get go!!
by anav
Wed Apr 02, 2025 2:17 am
Forum: Beginner Basics
Topic: DHCP server for VLAN not working [SOLVED]
Replies: 5
Views: 4557

Re: DHCP server for VLAN not working [SOLVED]

Dont understand your diagram, and dont even know which devices you have....... If you are going to provide config /export file=anynameyouwish ( minus router serial number, any publicWANIP information, keys ) You have a trunk port to an AP in the garage which model of AP You dont show a trunk to a sw...
by anav
Tue Apr 01, 2025 10:53 pm
Forum: General
Topic: is it really necesary to mangle wan traffic in a dual ISP scenario?
Replies: 4
Views: 569

Re: is it really necesary to mangle wan traffic in a dual ISP scenario?

If you keep changing the requirements and questions of course the answers will change. The original question was about load balancing the use of the WANs NOT external users access to the LANs or to the routers for config. Vague request beget general answers. Well detailed articulated requirements be...
by anav
Tue Apr 01, 2025 10:37 pm
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 2210

Re: Device-mode changes are hilarious

... just to change de cpu speed, i need to visit all the country for do that.

Consider yourself lucky. France is not so big. Imagine @anav visiting e.g. Whitehorse suburbs to change cpu speed :wink:
Nothing a trained cat cannot salvage.
Just hire mkx ;-)
......
mkxyes.jpg
by anav
Tue Apr 01, 2025 9:26 pm
Forum: Beginner Basics
Topic: RB951G-2HnD - DUAL Wan Static IP
Replies: 4
Views: 519

Re: RB951G-2HnD - DUAL Wan Static IP

Objective still not fulfilled LARSA, the response from the secondary WAN will still have a source IP of the secondary WAN.
by anav
Tue Apr 01, 2025 9:23 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 2977

Re: MikroTik RB5009 setting up remotely first time

If there is a computer in House 1 it would be easiest to use something like TeamViewer to get remote access to the computer, from where you can configure the RB5009 using Winbox.
See post #21 --> Or use anydesk behind a PC that can reach the config.
by anav
Tue Apr 01, 2025 9:21 pm
Forum: General
Topic: WinBox 4 export list of Devices
Replies: 1
Views: 333

Re: WinBox 4 export list of Devices

Take a screenshot?
by anav
Tue Apr 01, 2025 9:20 pm
Forum: General
Topic: Device-mode changes hit or miss? Mikrotik strategy?
Replies: 38
Views: 2210

Re: Device-mode changes are hilarious

If your complaining about you run your support business, wont get much sympathy from here.
There are tools within RoS to accomplish much and if not so technically astute sign up for something like this......... https://admiralplatform.com/
by anav
Tue Apr 01, 2025 2:42 pm
Forum: Beginner Basics
Topic: RB951G-2HnD - DUAL Wan Static IP
Replies: 4
Views: 519

Re: RB951G-2HnD - DUAL Wan Static IP

So you dont want to use the throughput of the secondary WAN at all?
Just the primary router......... is that becasue the secondary WAN is of little throughput?

If the primary goes down, then you will have to use the second WAN, and it will not be possible to hide this fact.
by anav
Tue Apr 01, 2025 12:57 am
Forum: Beginner Basics
Topic: lan ip to wan ip scenario
Replies: 2
Views: 512

Re: lan ip to wan ip scenario

Are you saying you get 9 WANIP addresses from a single provider?
Are you saying the gateway for all 9 is the same?

Why do some have ip address starting with 92.x and some have 88.y ??

PS. wireguard is not an interface that gets a pool, no dhcp etc..
by anav
Mon Mar 31, 2025 10:02 pm
Forum: Wireless Networking
Topic: Guest Network: VLAN vs. Bridge
Replies: 10
Views: 1906

Re: Guest Network: VLAN vs. Bridge

Your funeral to go off on tangents, and no bridge filters are for advanced users only, I dont touch them being an intermediate user.
Quickset should have been name quicksand :-)
by anav
Mon Mar 31, 2025 8:36 pm
Forum: Beginner Basics
Topic: internet speed
Replies: 8
Views: 818

Re: internet speed

What model of access points? The config is basically default so there should be no difference between wired or wifi clients based on the config.
So the issue is a the AP side............
by anav
Mon Mar 31, 2025 8:03 pm
Forum: Beginner Basics
Topic: CRS326 powerful enough?
Replies: 12
Views: 1016

Re: CRS326 powerful enough?

Can your ISP router even do vlans?
by anav
Mon Mar 31, 2025 8:02 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 2977

Re: MikroTik RB5009 setting up remotely first time

Or string two soup cans together and shoot one over to the remote location and get a person at that end to put it near the MT device.
Or use anydesk behind a PC that can reach the config.
by anav
Mon Mar 31, 2025 3:19 pm
Forum: General
Topic: VRRP Stuck in Master in both devices
Replies: 14
Views: 2360

Re: VRRP Stuck in Master in both devices

Mimiko, I call BS, you didnt originate the thread, popped in to complain, and have not provided the configs of your devices......
/export file=anynameyouwish ( minus router serial number, any public WANIP information,keys)
by anav
Mon Mar 31, 2025 6:02 am
Forum: General
Topic: is it really necesary to mangle wan traffic in a dual ISP scenario?
Replies: 4
Views: 569

Re: is it really necesary to mangle wan traffic in a dual ISP scenario?

ECMP is perfectly fine to use for dual or more wans. Its the least complicated approach. With version 7 firmware it should be the first go to approach.
Mangling and PCC come into play for more complex user needs or if the admin has wan throughputs that are wildly dissimilar
by anav
Mon Mar 31, 2025 4:30 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 2977

Re: MikroTik RB5009 setting up remotely first time

Guidance provided based on your answer above!!
You have lots to learn prior to trying to remotely configuring a 5009.
If you are truly DYI then get GNS3 or EVE-NG and setup a lab type setting where you can practice learning about RoS.
by anav
Mon Mar 31, 2025 3:36 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 2977

Re: MikroTik RB5009 setting up remotely first time

Have you ever used Mikrotik and configured it before?
No
https://mikrotik.com/consultants
by anav
Mon Mar 31, 2025 12:48 am
Forum: Wireless Networking
Topic: access point won't start
Replies: 12
Views: 1616

Re: access point won't start

something wrong with the ignition coil no doubt. ;-) I will have a look at the config. This if for L1009 with wifi, since its the only config provided. 1. REMOVE bridge from interface list! It is no longer required as it is the vlans that need to be identified as members. add interface=bridge_router...
by anav
Mon Mar 31, 2025 12:45 am
Forum: General
Topic: Wireguard setup for both internal and external access
Replies: 3
Views: 529

Re: Wireguard setup for both internal and external access

If you can port forward then you can host wireguard which you will need to do. AirVPN and other types of VPN are NOT for connecting to Air VPN and then to your home router. They are of the type of VPN service that simply provides internet out a different location/country, by either users on the rout...
by anav
Sun Mar 30, 2025 11:52 pm
Forum: Wireless Networking
Topic: Mikrotik hAP LTE6 as a travel router setup?
Replies: 10
Views: 1381

Re: Mikrotik hAP LTE6 as a travel router setup?

More importantly can some one wifi expertise please help the OP. Geez!!
by anav
Sun Mar 30, 2025 11:51 pm
Forum: Wireless Networking
Topic: WiFi 2.4GHz b/g/n Setup
Replies: 3
Views: 594

Re: WiFi 2.4GHz b/g/n Setup

I believe AX covers all, in other words it defaults and covers off whatever signal comes in and is thus equivalent to ALL Not really sure, but I also believe that whatever signal is processed then that is the lowest commen denominator. AKA if our processing B, then all other connections after will c...
by anav
Sun Mar 30, 2025 11:44 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1319

Re: VPN with relay on a VPS - working around the CGNAT

I use winbox all the time from PC behind my router to reach distant devices. If you need to connect to devices behind the router, then type in their applicable IP address, in this case its management IP address. Once connected to the 5009 over wireguard try this ( critical first step ) For example t...
by anav
Sun Mar 30, 2025 11:40 pm
Forum: Beginner Basics
Topic: Basic settings for PCC [SOLVED]
Replies: 4
Views: 4094

Re: Basic settings for PCC [SOLVED]

ECMP on MT not to be confused with EMP LOL
by anav
Sun Mar 30, 2025 11:38 pm
Forum: Wireless Networking
Topic: RB2011 with a router switch and hap ax2 as aps
Replies: 5
Views: 674

Re: RB2011 with a router switch and hap ax2 as aps

Typical AP setup will assume 99 is management vlan, 10 is home 20 is guest wifi and 30 is IOT wifi, and ether2 is a wired port for home user. /interface bridge add ingress-filtering=no name=bridgegym port-cost-mode=short vlan-filtering=yes /interface ethernet set [ find default-name=ether5 ] name=Of...
by anav
Sun Mar 30, 2025 11:05 pm
Forum: General
Topic: routerOS & Mirkotik for the noobs
Replies: 6
Views: 1048

Re: routerOS & Mirkotik for the noobs

When working with vlans and bridge the best approach is take one port Off the Bridge and do all the configuring from this safe spot. The best thing you can do is take one port off the bridge and do your config from there, a safe spot. 1. Take ether5off the bridge at /interface bridge port 2. Make th...
by anav
Sun Mar 30, 2025 11:00 pm
Forum: Wireless Networking
Topic: RB2011 with a router switch and hap ax2 as aps
Replies: 5
Views: 674

Re: RB2011 with a router switch and hap ax2 as aps

I do not know with any certainty but I would think that having all devices on the same version of firmware will be helpful. I am not a capsman guy but to get your RB2011 and 6 APs working, I can provide assistance without capsman to at least get you to a working config. While you have that, suggest ...
by anav
Sun Mar 30, 2025 10:57 pm
Forum: Wireless Networking
Topic: Unifi access point
Replies: 16
Views: 3063

Re: Unifi access point

My first instinct was correct still have my lama sense workin. /file=anynameyouwish ( minus router serial number, any public WANIP information, keys ). Answer is the same, it will work if you configure it properly. The problem is you have not provided the FACTS, or EVIDENCE with which folks here can...
by anav
Sun Mar 30, 2025 10:45 pm
Forum: Wireless Networking
Topic: 7.18 CAPSMAN v2 VLAN provisioning problem to WAP ax
Replies: 9
Views: 1047

Re: 7.18 CAPSMAN v2 VLAN provisioning problem to WAP ax

Yup, hair turned grey, or loss of hair, skin aged, and suddenly it works. to bad the OP has no clue why, nothing learned. caps SUCKETH the big bone.
by anav
Sun Mar 30, 2025 10:43 pm
Forum: Wireless Networking
Topic: Wifi connects, but no internet
Replies: 9
Views: 863

Re: Wifi connects, but no internet

The best thing you can do is take one port off the bridge and do your config from there, a safe spot. 1. Take ether5 off the bridge at /interface bridge port 2. Make the following additions/mods /interface ethernet set [ find default-name=ether5] comment=OffBridge5 /interface list member add interfa...
by anav
Sun Mar 30, 2025 10:36 pm
Forum: Beginner Basics
Topic: HAP AC3 Error in Master - selection expected!
Replies: 1
Views: 398

Re: HAP AC3 Error in Master - selection expected!

Thats nice, and how do you suppose we are supposed to assist without seeing what you have done on the config to cause this?? Im assuming you at least created a wifi profile for wifi1 or wifi2 such that a master would exist. /export file=anynameyouwish (minus router serial number, any public WANIP in...
by anav
Sun Mar 30, 2025 10:34 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 964

Re: VLAN issue(s)

Good to hear, others prefer insanity, greying of hair and hair loss, to get capsman going. Is it worth it, not to me!
by anav
Sun Mar 30, 2025 10:08 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1319

Re: VPN with relay on a VPS - working around the CGNAT

As for your switch which port on the 5009 goes to the switch........ SAME ISSUE for discover,... WRONG /tool mac-server set allowed-interface-list= MGMT /tool mac-server mac-winbox set allowed-interface-list= none /tool mac-server set allowed-interface-list= none /tool mac-server mac -winbox set all...
by anav
Sun Mar 30, 2025 10:07 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1319

Re: VPN with relay on a VPS - working around the CGNAT

Not sure what you mean.......... You have this on the config, which is a good start. /ip neighbor discovery-settings set discover-interface-list=MGMT BUT THE ERROR comes later. You reversed the settings /tool mac-server set allowed-interface-list= MGMT /tool mac-server mac-winbox set allowed-interfa...
by anav
Sun Mar 30, 2025 10:01 pm
Forum: Beginner Basics
Topic: Basic settings for PCC [SOLVED]
Replies: 4
Views: 4094

Re: Basic settings for PCC [SOLVED]

No PCC is for load balancing multiple WAN connections for: a. the purpose of redundancy so that if one ISP goes down you have a backup ( clearly not useful if all the WANs come from the same provider ) b. to provide a greater overall bandwidth to share with users, so there are less bottlenecks in tr...
by anav
Sun Mar 30, 2025 9:57 pm
Forum: Beginner Basics
Topic: Wireguard roadwarrior on LTE router- Handshake failed
Replies: 3
Views: 492

Re: Wireguard roadwarrior on LTE router- Handshake failed

Without seeing your config, hard to see what you have done??
Assuming you have a public WANIP or you can forward ports from an ISP router that has a public IP??
by anav
Sun Mar 30, 2025 9:55 pm
Forum: Beginner Basics
Topic: Disable CAP mode without UI
Replies: 7
Views: 3964

Re: Disable CAP mode without UI

Another reason to avoid anything cap like the plague.
by anav
Sun Mar 30, 2025 9:53 pm
Forum: General
Topic: Wireguard setup for both internal and external access
Replies: 3
Views: 529

Re: Wireguard setup for both internal and external access

Draw a diagram because you seem to want opposed uses. Wireguard to a third party server Wireguard to home. Which is it or both? ++++++++++++++ It sounds like you need two wireguard interfaces one for third party and one for home. Do you have a public IP address or can you forward ports from an ISP r...
by anav
Sun Mar 30, 2025 5:11 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1319

Re: VPN with relay on a VPS - working around the CGNAT

Easy Peasy now that I have facts to work with! :-) /interface list member add interface=ether7 list=WAN add interface=PRIVATE_VLAN list=VLAN add interface=GUEST_VLAN list=VLAN add interface=IOT_VLAN list=VLAN add interface=SECURITY_VLAN list=VLAN add interface=MGMT_VLAN list=VLAN add interface=MGMT_...
by anav
Sun Mar 30, 2025 2:34 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1319

Re: VPN with relay on a VPS - working around the CGNAT

Then add access to the management vlan.
add action=accept chain=forward comment="remote admin to trusted vlan" in-interface=BTHWireguard out-interface=vlan-mgmt
by anav
Sun Mar 30, 2025 2:27 am
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1319

Re: VPN with relay on a VPS - working around the CGNAT

Well the way it works is you enable BTH on the router. Take the first created user and install that on your smart phone, any other users have to be created on the smartphone as well. You will need to go to the router at your parents place allows the subnet of wireguard access on the input chain add ...
by anav
Sun Mar 30, 2025 2:21 am
Forum: General
Topic: Wireguard tunnel stopping on its own
Replies: 10
Views: 2525

Re: Wireguard tunnel stopping on its own

There is a responder checkbox in winbox I think, try checking that, and see if the issue persists.
.........
Screenshot 2025-03-29 212138.png
by anav
Sat Mar 29, 2025 11:22 pm
Forum: Beginner Basics
Topic: Choice of VPN
Replies: 1
Views: 376

Re: Choice of VPN

Look at zerotier to share gaming server............
by anav
Sat Mar 29, 2025 11:21 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 1095

Re: Noob can't seem to integrate VLAN, despite following guide

The arubas will need to be setup with vlans. They should get their IP address on the VLAN99
by anav
Sat Mar 29, 2025 11:12 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 1095

Re: Noob can't seem to integrate VLAN, despite following guide

So theree switches means three trunk ports BUT................. The unifi expects the trusted or managament vlan untagged and the data vlans tagged. If they are consistent in setup. I'm assuming the arubas are more standard switches. What are the AP types?? /interface bridge port add bridge=bridge1 ...
by anav
Sat Mar 29, 2025 11:07 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 964

Re: VLAN issue(s)

I dont use capsman because its too difficult and a headache for me. I use what works. Capsman is better if you do it successfully as it allows for better handoff between APs, I could care less in my own house. This will get you setup and working, and then you can implement capsman and whatever else ...
by anav
Sat Mar 29, 2025 10:01 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1319

Re: VPN with relay on a VPS - working around the CGNAT

Well the VPS aka a CHR in a cloud is about $6 a month to rent plus the CHR license and use Wireguard VPN, and is a great way to do what you want to do without third party servers. Preferred option 4 You could do it right now with VPN WIREGUARD BTH depending upon what router you bought your parents a...
by anav
Sat Mar 29, 2025 9:55 pm
Forum: General
Topic: What's using the memory?
Replies: 10
Views: 892

Re: What's using the memory?

I have an ax3
Total memory 1024 MiB
Avail Free memory: 651.2 MiB

Meaning used memory is 373.

I do not use any logging or at least minimize it if all possible.
Do not expect the ax3 to be any zippier, unless your holvoe, the rest of us mere mortals get around what you are getting.
by anav
Sat Mar 29, 2025 7:42 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11514

Re: My recent VLAN fiasco [SOLVED]

Even more pertinent in Basic but based on your lack of experience on the forum ( clearly IT trained and more knowledgeable than I will ever be ) I disagree. :-)
by anav
Sat Mar 29, 2025 7:37 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 964

Re: VLAN issue(s)

CAPAC, same concept using offbridge on etherport 2. ALso I always wire the capac on ether2 to a spot where I can at least plug in a laptop, could be a closet etc...... emerg config when the capac is very hard to reach etc. Where you set the cap address statically to 192.168.1.xx .......................
by anav
Sat Mar 29, 2025 6:51 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 964

Re: VLAN issue(s)

Why are you using the capax as a router. All the router stuff should be done on the chateau and the capax as an ap/switch ?? If this is the chateaux then.............. concur the simple approach works and should be the starting point...... Will stick to one trusted vlan and one untrusted vlan. Note ...
by anav
Sat Mar 29, 2025 6:48 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 1095

Re: Noob can't seem to integrate VLAN, despite following guide

1. Adjusted as required. add name=bridge1 port-cost-mode=short vlan-filtering=yes { add the YES as last rule change) /interface ethernet set [ find default-name=ether8 ] name=OffBridge8 /interface vlan add interface=bridge1 name=BASE_VLAN vlan-id=99 add comment="Guest VLAN" interface=bridg...
by anav
Sat Mar 29, 2025 4:51 pm
Forum: Beginner Basics
Topic: firewall rules advices
Replies: 7
Views: 785

Re: firewall rules advices

Before you apply anything one must understand the purpose of the chains. Input chain is traffic TO the router, so to router services. None of your servers behind the router and on the LAN have anything to do with router services and thus seeing their rules in the input chain is ridonkulous. So from ...
by anav
Sat Mar 29, 2025 4:44 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

That is weird behaviour, perhaps the power cord or supply is wonky? Cables wonky? or maybe the router is toasted??
Suggest try netsinstall as well.
by anav
Sat Mar 29, 2025 4:34 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11514

Re: My recent VLAN fiasco [SOLVED]

I think mkx said it best in poetry, just make your config look like mine and all will be happy. ;-)
What we need, no joke, is for new users to be educated prior to making their first posting, and a sandbox where posts can be reviewed prior to posting live.
by anav
Fri Mar 28, 2025 6:35 pm
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 2155

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

Haha,
My answer to your question is simple, Welcome to Canada, South BC ( formerly North Idaho ). :-)

I see what your getting at, try to merge SwoS simplicity within RoS for vlans.
I like the concept.

PS. Working on my Teeter Accent, in case things go awry.
by anav
Fri Mar 28, 2025 3:50 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11514

Re: My recent VLAN fiasco [SOLVED]

I wouldnt know eltikpad, I have never had to resort to putting an address on the bridge while using vlans. I prefer clean separation of bridge from DHCP etc, once I start using vlans.
by anav
Fri Mar 28, 2025 3:15 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 1095

Re: Noob can't seem to integrate VLAN, despite following guide

Two recommendations
a. take one port off the bridge and safely do all configuration from this port
b. go all vlans, remove bridge from dhcp etc, and simple move this subnet to another vlan.

Willing to go this route let me know.
by anav
Fri Mar 28, 2025 3:10 pm
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 2155

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

Tom, these engineers are not all that resourceful, they never came here for help! ;-) I do know that Mikrotik has been making advancements in the automation of setting up vlans on multiple connected devices and automations on interface lists etc...... But nothing towards what you are looking at ... ...
by anav
Fri Mar 28, 2025 3:04 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1876

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

If you dont post the complete config I dont bother looking.

/export file=anynameyouwish ( minus router serial number, any public WANIP information, vpn keys, long dchp lease lists )
by anav
Fri Mar 28, 2025 3:02 pm
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 835

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

Sorry sippan, what is BS is false hope and promises.
If you are unable to inspect encrypted traffic, then do pray tell what effing magic do you use........
by anav
Fri Mar 28, 2025 2:45 pm
Forum: General
Topic: Winbox timeout with wireguard
Replies: 3
Views: 941

Re: Winbox timeout with wireguard

Why do you think that the firewall is where the problem is...............
by anav
Fri Mar 28, 2025 2:30 am
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 835

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

Probably neither you need an expensive router add then pay for subscription services to handle DPI etc.........
by anav
Thu Mar 27, 2025 9:47 pm
Forum: General
Topic: Make WireGuard VPN accessible from anywhere
Replies: 2
Views: 557

Re: Make WireGuard VPN accessible from anywhere

Your request is not clear.
Do you host a wireguard server on your router or are you connecting to a 3rd party server for example.
What are the use cases for wireguard, who uses it and for what purposes.
by anav
Thu Mar 27, 2025 5:25 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11514

Re: My recent VLAN fiasco [SOLVED]

For me its clear enough, /interface bridge ports and /interface bridge vlans tells a story, the combination informs the router ( and the reader ) how to distribute subnets on the device. Nothing hidden all up front. The two groups of settings cross-check each other for a consistent story. Really the...
by anav
Thu Mar 27, 2025 4:07 pm
Forum: General
Topic: rOS for L2 switches
Replies: 6
Views: 827

Re: rOS for L2 switches

Doesnt show up in winbox, and cannot open it in winbox................ Finicky as shit when playing with access permissions.........
by anav
Thu Mar 27, 2025 2:47 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11514

Re: My recent VLAN fiasco [SOLVED]

Not hyping it down, but its actual use as a data vlan is very niche (rare).
by anav
Thu Mar 27, 2025 12:56 pm
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 2155

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

Hi Nathan, great summary. However I am helping mostly new persons and they dont understand the basic entry method (manual) which uses both /interface bridge port and vlan to tell a coherent story. In fact by cross-checking the two sets of entries, a consistent approach and understanding is solidifie...
by anav
Thu Mar 27, 2025 2:56 am
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

On the switch, are all ports used, if not dont include them in config.
Why is ether2 part of an LACP and yet you have an address assigned to it.....

More to the point are all these other ports using 10.10.1.X addresses
by anav
Thu Mar 27, 2025 2:49 am
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Okay how to create an offbridge port. REMOVE ether4 from /interface bridge ports /interface ethernet set [ find default-name=ether4 ] comment=OffBridge4 /interface list add list=TRUSTED /interface list member add interface=OffBridge4 list=TRUSTED add interface=mgmt_vlan list=TRUSTED add interface=mg...
by anav
Thu Mar 27, 2025 1:43 am
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Looking at it more closely I dont see any vlans assigned in your cap so maybe tis okay....... Just didnt want to put my foot in it, so to speak., Happy to take a look and pretend its not there LOL. The first problem is that there is only one VLAN, the management vlan. Where is the vlan for the WIFI>...
by anav
Thu Mar 27, 2025 1:30 am
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Cant help you since using capsman. Dont know how that interacts with bridges and vlans sorry.
by anav
Wed Mar 26, 2025 10:54 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1876

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

It should work with the settings I provided via CLI at the end of the post. Additional note for CHR Traffic. To ensure stable connectivity with all types of internet sites (banking etc.) Suggest try the default L3 hash on ECMP as that should provide optimal results. If that doesnt work you can try L...
by anav
Wed Mar 26, 2025 10:52 pm
Forum: Beginner Basics
Topic: Wireguard, Routing Tables and Mangle
Replies: 3
Views: 759

Re: Wireguard, Routing Tables and Mangle

Duplicate Thread, please follow here............ viewtopic.php?p=1135310#p1135262
by anav
Wed Mar 26, 2025 10:47 pm
Forum: Beginner Basics
Topic: Wireguard Client to remote Ubuntu Wireguard [SOLVED]
Replies: 6
Views: 8201

Re: Wireguard Client to remote Ubuntu Wireguard [SOLVED]

allright so to be clear its not the entire subnet but only two Ip addresses, this should work for you /routing table add fib name=useWG / ip route add dst-address=0.0.0.0/0 gateway=WG_Interface routing-table=useWG /routing rules add min-prefix=0 action=lookup-only-in-bridge table=main { permits any ...
by anav
Wed Mar 26, 2025 9:39 pm
Forum: General
Topic: wireguard went down after advanced guide
Replies: 6
Views: 746

Re: wireguard went down after advanced guide

No worries, many parts of a config are interrelated and thus a snippet really never tells the whole story.
by anav
Wed Mar 26, 2025 9:22 pm
Forum: General
Topic: wireguard went down after advanced guide
Replies: 6
Views: 746

Re: wireguard went down after advanced guide

Ironic, that you were comfortable applying advances pages but dont understand what they are doing, but less so, for experienced users that are willing to provide some practical advice. There is nothing in an anonimized configuration that renders your network to any danger. /export file=anynameyouwis...
by anav
Wed Mar 26, 2025 7:58 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 1313

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

On feedback from MT, some changes could be made to re-arrange the menus and thus the next attempt will be to do so, while preserving the overall concept of form follows function. The approach to the wireguard interface is simply superior and should be adopted, including the option to add IP address ...
by anav
Wed Mar 26, 2025 7:51 pm
Forum: Beginner Basics
Topic: Can't get VLAN trunk working
Replies: 10
Views: 1019

Re: Can't get VLAN trunk working

Bingo! Many thanks @CGGXANNX I was working from the assumption (stupid me) that setting the untagged VLAN was sufficient, but effectively it also needed to be manually assigned the PVID and I hadn't even looked into that submenu as the VID title didn't make me think of everything. If only the title...
by anav
Wed Mar 26, 2025 7:06 pm
Forum: General
Topic: wireguard went down after advanced guide
Replies: 6
Views: 746

Re: wireguard went down after advanced guide

Instead of describing hypotheticals, and rules completely out of context, please provide the use-cases, aka actual traffic requirements. a. identify user(s)/groups of users including admin, external, internal b. identify all the traffic they require to execute. c. detail particulars about wan connec...
by anav
Wed Mar 26, 2025 6:51 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 13
Views: 1350

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

Good point tdw,
The Unifi Gateway (its wanip) can be on the same mikrotik vlan as the Unifi AP for example which should simplify matters.
by anav
Wed Mar 26, 2025 6:35 pm
Forum: Useful user articles
Topic: Optimizing MikroTik hAP ax³ (C53UiG+5HPaxD2HPaxD) WiFi Speeds
Replies: 4
Views: 7297

Re: Optimizing MikroTik hAP ax³ (C53UiG+5HPaxD2HPaxD) WiFi Speeds

Strictly wifi, correct, no capsman right!
by anav
Wed Mar 26, 2025 6:31 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 13
Views: 1350

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

For example this OP seems to be doing just that................
viewtopic.php?t=215720
by anav
Wed Mar 26, 2025 6:13 pm
Forum: Beginner Basics
Topic: Wireguard Client to remote Ubuntu Wireguard [SOLVED]
Replies: 6
Views: 8201

Re: Wireguard Client to remote Ubuntu Wireguard [SOLVED]

https://forum.mikrotik.com/viewtopic.php?t=143620 Bridge should not normally do DHCP in a vlan setup......... simply create another vlan, amend any associated config lines. It is not clear yet what subnet or user(s) are supposed to go out wireguard. I do see an attempt so sourcneat wireguard traffic...
by anav
Wed Mar 26, 2025 6:03 pm
Forum: Beginner Basics
Topic: When is connection-nat-state applied (default firewall rule)?
Replies: 13
Views: 1979

Re: When is connection-nat-state applied (default firewall rule)?

What you probably realized somewhere through the long winded explanations of my colleagues ;-P, is that the rule actually provides three functions. a. allows traffic from the wan that is for port forwarding ( obtainable understanding ) b. drops any other traffic from the wan ( kinda obscure ) c. all...
by anav
Wed Mar 26, 2025 5:47 pm
Forum: Beginner Basics
Topic: Wireguard, Routing Tables and Mangle
Replies: 3
Views: 759

Re: Wireguard, Routing Tables and Mangle

Not sure what you are connecting to, that is the missing link
3rd party VPN, a friends server, a Cloud based wireguard ????
by anav
Wed Mar 26, 2025 5:19 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1876

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

Sorry cannot help you. I have provided enough information to give you a load balance of ALL users going to CHR and a load balance of any users not going through CHR.
Not my problem you are fixated on PCC, when its not required and far more complex.
by anav
Wed Mar 26, 2025 5:04 pm
Forum: General
Topic: Which switch?
Replies: 20
Views: 1526

Re: Which switch?

You can read specifications as well as anyone else, depends on your requirements etc.
For me since I love, setting up vlans on mikrotik products via RoS, its the one I would go with.
If you want a plugNplay setup, then I would go with the zyxel ( but only because of that killer sale price )
by anav
Wed Mar 26, 2025 5:03 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 13
Views: 1350

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

I would throw away the ubiquiti gateway ultra. Pretty dumb if you cannot buy an AP and get it to work, but instead you have to buy a second ubiquiti product to talk to the AP. To unlock the full potential of UniFi APs, including advanced features and centralized management, you'll need to use a UniF...
by anav
Wed Mar 26, 2025 4:54 pm
Forum: General
Topic: Block OpenVPN connection
Replies: 6
Views: 810

Re: Block OpenVPN connection

Try a more useful set of firewall rules. /ip firewall filter {default rules to keep} add action=accept chain=input connection-state=established,related,untracked add action=drop chain=input connection-state=invalid add action=accept chain=input protocol=icmp (admin rules) add action=accept chain=inp...
by anav
Wed Mar 26, 2025 4:39 pm
Forum: General
Topic: Which switch?
Replies: 20
Views: 1526

Re: Which switch?

Looking at competitors, the only one that comes close to the 328 is this one in terms of price and features..
Personally, If you prefer RoS, then MT is the way to go. If not using RoS, then at the price prefer the latter.
https://www.zyxelguard.com/XGS1930-28HP.asp
by anav
Wed Mar 26, 2025 4:22 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2380

Re: Beginner VLAN questions

Repost both configs for review and use code tags for both.
by anav
Wed Mar 26, 2025 4:19 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 11514

Re: My recent VLAN fiasco [SOLVED]

Thanks Nathan, that is the practical answer and enough technical description I was looking for to continue a general approach to all configs. Very often there is a mix of different vendor switches involved downstream from an MT router. Luckily, thus far I have not needed a config that required vlan1...
by anav
Wed Mar 26, 2025 4:07 pm
Forum: General
Topic: VRRP Best Practices
Replies: 3
Views: 742

Re: VRRP Best Practices

Counter opinion, or at least different, TWO VRRF instances. RouterA - VRRF1 - Primary Router and used by VLANs from Router A RouterB - VRRF2 - Primary Router and used by VLANS from Router B. In this way the throughput of both providers is utilized ( why not paying for both!!) and the router vlans do...
by anav
Sat Mar 22, 2025 12:59 am
Forum: General
Topic: hAP ac2 vs ax2 or ax3 ethernet performance
Replies: 8
Views: 1458

Re: hAP ac2 vs ax2 or ax3 ethernet performance

I have no reason to doubt that the AX3 is best followed by hapac2 followed by hapax2 based on those tests.
Your in Riga, pop over to MT to confirm!!
by anav
Sat Mar 22, 2025 12:57 am
Forum: General
Topic: MT Wireguard over VRRP WAN
Replies: 5
Views: 1007

Re: MT Wireguard over VRRP WAN

Well endpoint has to be a specific WAN for the client to reach the right ROUTER.
The VRRP is for the inside facing users from what I understand.
But its a good point for discussion. Looking forward to what comes out of this thread.
by anav
Fri Mar 21, 2025 10:30 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 8775

Re: WireGuard with CloudFlare DNS [SOLVED]

Nice!!
by anav
Fri Mar 21, 2025 10:28 pm
Forum: General
Topic: Expired SSL cert locks you out of 7.18.2 GUI
Replies: 7
Views: 1008

Re: Expired SSL cert locks you out of 7.18.2 GUI

Use wireguard.
by anav
Fri Mar 21, 2025 6:58 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 8775

Re: WireGuard with CloudFlare DNS [SOLVED]

Sure that makes sense, if you have misconfigured your wireguard.
If the router is server peer for handshake and it has a number of peers, and one of the peer client settings on the ROUTER, has the error of 0.0.0.0/0 set in Allowed addresses, then this type of problem occurs.
by anav
Fri Mar 21, 2025 6:56 pm
Forum: Beginner Basics
Topic: SRC-Nat confused
Replies: 2
Views: 701

Re: SRC-Nat confused

Your trying to stuff a pre-conceived solution for an unknown problem into the MT, the worst way to proceed.
Suggest you detail the USER TRAFFIC requirements, the use-cases that are driving your request.

It may very well be that other tools and methods make sense.
by anav
Fri Mar 21, 2025 6:49 pm
Forum: General
Topic: dst-nat to local server with clients on same VLAN
Replies: 1
Views: 628

Re: dst-nat to local server with clients on same VLAN

For all IPs that either should not or admin wants not to get forced out of server. /ip firewall address-list add address=IPofDNS list= Exempt comment=" the dns server itself" add address=someOtherUser list=Exempt comment="user to router DNS not my server" /ip firewall nat add cha...
by anav
Fri Mar 21, 2025 3:50 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 8775

Re: WireGuard with CloudFlare DNS [SOLVED]

Its not wireguard, that is the problem.
Reset your config to defaults then add wireguard and see if it works.
by anav
Fri Mar 21, 2025 3:06 pm
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN end of life?
Replies: 5
Views: 1727

Re: RB4011iGS+5HacQ2HnD-IN end of life?

Thats the European polite answer or part of anyway. This is the German answer!!! This is why if the OP came to me, offering their business I would run for the hills ( okay drive to the Swiss Alps in my Audi ) Tying the router to wifi is STEWPID, wifi technology changes much more quickly and ideal pl...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 79