Hi! I have a similar problem since I updated the router to version 7.9.1. I have RB4011 Mikrotik. It worked perfectly before update. I use the ARP information to communicate to a server if there is someone at home (with Wi-Fi MAC) and since I updated there are always 3 repeated macs (one of the mobi...
Hi! I have a problem since I updated the mikrotik. The script continues working to know macs wich are connected but there is a mac that is duplicated in the arp table with different IPs and it continues in "Complete" and this phone is outside of this network. Captura.jpg Do you know why? T...
Yes, my clients are servers and my mikrotik is the client. The purpose of this configuration is to connect to my clients routers when I need it and to be the same configuration in all client mikrotik. Here my configuration: In this configuration you can see VPN client and VPN server. I'm asking for ...
Hi, I have a question: I have a Master Mikrotik and others Mikrotiks Client. All Client have VPN server (L2TP) with same configuration: VPN Local address: 192.168.30.1 VPN Remote address: 192.168.30.2 Internal LAN: 192.168.20.0/24 WAN (client domestic router): 192.168.1.0/24 When I want to connect t...
Hi, I think internet the problem was from the isp provider. Now with vodafone internet work fine. I have 3 questions about my configuration. I can´t access to "Cliente_2" VPN secret devices if I´m connected to my microtic with VPN to David secret but I can access from my internal LAN When ...
Looks like a device with the private MAC address 00:00:5e:00:01:6F (this belongs to a VRRP interface) is doing proxy-arp. The reply from that MAC address with IP 192.168.2.3 points to a D-Link AP. I'd check its settings. -Chris This mac is ISP router. The next week i´m going to change to vodafone. ...
Hi, I have 2 questions about my mikrotik Occasionally my mikrotik lost internet connection and it comes back in a few minutes. I try doing ping from mikrotik terminal to 8.8.8.8 and doesn´t response. But today I´ve seen something strange, i´ve connected my office mikrotik router to mine to access so...
Thanks a lot!!! I don't have much experience yet and I copy some other people's rules thinking they will work. I have perfectly understood everything you have explained to me, thank you very much for the comments. I have already corrected everything. The "Src_Administradores" list are devi...
Hi!! I´ve reset router to default factory and I´ve only create necesary rules and in right order. I think now is Ok # dec/29/2020 20:38:27 by RouterOS 6.44.5 # software id = E82L-C64C # # model = RB4011iGS+ /interface bridge add comment=LAN_Ppal name=LAN_Ppal /interface ethernet set [ find default-n...
Hi! Thanks for response. I have some questions (I have little experience with mikrotik) I can´t see dhcp server in ether5. In dhcp server i have configured "LAN_Ppal" Bridge with ports 2-6. Where can you see ether5 dhcp? I have an acces point in ether5. 10.xx.xx.xxx is VPN network. I have ...
Hi, I´ve solved MQTT problem changing dst port. But I have the same problem with internet connection. A lot of times I lose internet connection, I try doing ping to 8.8.8.8, or google.com from Mikrotik and it doesn't response. If I reboot Masmovil Router (that is configured in bridge mode) it works ...
Hi!, I have a problem with a dst NAT. I work with MQTT protocol inside and ouside of my network and integrating alexa devices in my server. When I open dst.nat with "In interface:WAN" only work MQTT devices in my network and alexa deviecs and when i remove "In interface: WAN" onl...
If this is all your firewall and if you disable last drop rule, your forward chain is fully open. BTW, last drop rule seems wrong, it drops all not-dstnatted connections coming from any interface, typically you want to drop this only from WAN. Hi, This is all my firewall. but if I disable last drop...
If this is all your firewall and if you disable last drop rule, your forward chain is fully open. BTW, last drop rule seems wrong, it drops all not-dstnatted connections coming from any interface, typically you want to drop this only from WAN. Hi, This is all my firewall. but if I disable last drop...
Hi, I have a problem with device in my network. They say me that the problem is tcp 1883 is droped to internet but I can´t see it... If ai try it outside my network it work perfectly. This is my firewall: /ip firewall address-list add address=10.0.0.20-10.0.0.101 list=Src_Administradores add address...
I'd suggest you to rather whitelist a few remote IP addresses from which you allow access. Create address list (in /ip firewall address-list ), populate it with whitelisted IP addresses, and change your NAT rule to include src-address-list=<name of whitelist> . Your thought is the other way around ...
I.ve allowed acces to a server on my home network by dstnat because VPN is not easy for my family to share NAS media (I know is safer with VPN).
Is there any way to control this open port connection? How can I add to blacklist IP´s who attack in this port?
I don't have much time right now, so I just skimmed through your configs, but what I was describing was (for client router): /ip firewall mangle add action=mark-connection chain=prerouting connection-state=new in-interface=pptp-client new-connection-mark=vpn-conn add action=mark-routing chain=prero...
A little, yes. Let's say a client with address 1.2.3.4 connects to <your server>:80. Server forwards packet to 10.0.1.150 and assuming that everything else is configured correctly, it will reach target device. Device sends response to 1.2.3.4, and what do you think will happen? It sends it directly...
Hi, I have a question about Port Forwarding. I have a Mikrotik with PPTP VPN Server with local address 10.0.0.1 Mikrotiok with PPTP Client with IP address 10.0.1.1 and LAN 10.0.1.0/24 I have routes from mikrotik server to mikrotik client and vice versa and I can acces from Mikrotik server (in VPN) t...
I have a question about winbox log.
I have a schedule that sends 6 http comands each 1s and I see all logs as memory info.
How can I remove this log to see the others?
To support@mikrotik.com Oks, Thanks If you can return the 2011 to the place you bought it from and get a refund Or exchange for a better model like the 3011 I suggest you do that ... if on the other hand you can no longer get a refund or exchange for a 3011 then good luck with all the hassles you w...
Are there any other ports in switch group 1 (ether1-ether5,sfp1) linked lower than 1 Gbps? No, there isn´t. You might want to create supout.rif of the device, running full bandwidth test and send it to support. Your device should be able to handle at least 3x those numbers with this config. I´ll do...
Whats the version of RouterOS? Why are you blocking output chain? You're e.g. blocking router originating DNS requests now. Also you may want to exclude ipsec from fasttracking, from default config: /ip firewall filter add chain=forward action=accept ipsec-policy=in,ipsec comment="defconf: acc...
Ok @nescafe2002, you can then let Mikrotik know that the test results are wrong! :lol: https://mikrotik.com/product/RB2011UiAS-2HnD-IN#fndtn-testresults They are not wrong, these are just synthetical tests with certain preconditions. Fasttrack follows (semi-) fastpath for most of (*) the establishe...
The Mikrotik hAP ac² is better than my router? Is the best option for me? I thought a router was better option than wireless system. Actualy I have my ISP router as bridge and Mikrotik as router. The best option for YOU is the MikroTik RB3011UiAS-RM and Yes I agree that a dedicated Router - like th...
According to the test results that @mkx correctly indicated and since the CPU goes as high as 70% we can conclude that thats the best RB2011 can do... Imagine that even if it goes a little bit higher your CPU will go to 100% which means that the router will perform really really bad... Ok, thanks. ...
Official test results , with my added interpretation[*], show that RB2011 hits its ceiling at around 200Mbps (give or take) routing speed, exact number depends on number and type of firewall filter rules. A faster router is needed for WAN speed you've got. I suggest you to look at hAP ac² , it offe...
Hi, I have a problem with my ISP internet speed. I have 500/50Mb and when I connect directly to my ISP router I get 400/50 aprox but when I do the speed test connected to mikrotik I get 160/50 more or less. Before adding fastrack connection in filter rules y got 100/50. /ip firewall filter add chain...
My purpose is to send "1" or "0" by http to another server if a mac is connected to the router or not. This is the code that I currently have in scheduler: { :local iPhone [/int wire reg find mac-address="11:22:33:44:55:66"]; :if ($iPhone!="") do={ /tool fetch...
Hi, I have a microtik router that gives DHCP and I would like to know the MAC of connected devices. The following script tells me if a device is connected to the microtic by Wlan: :local iPhone [/int wire reg find mac-address="A8:9C:ED:CD:F8:12"]; But I want to know dhcp clients. In IP / A...
Hi, I need help with my code... I get the MAC from the Wifi devices of the Microtic but I need the ones from the ISP router. I'm trying with your code but it does not work for me. Somebody could help me? This is my code: { :local iPhone [/int wire reg find mac-address="38:71:DE:E4:F8:FB"];...
Hi, I need help with my code. I get mac adress from microtik wifi client to do some actions but I need to know mac adress from my ISP router. I have conected this router to ether1 and I´ve tried your code but doesn´t work. Can you help me? My code is the following: { :local iPhone [/int wire reg fin...