Community discussions

MikroTik App

Search found 53 matches

by Frederick88
Thu Dec 19, 2024 6:32 am
Forum: Wireless Networking
Topic: Adding new wAP AX to network and setting up CAPsMAN
Replies: 5
Views: 5672

Adding new wAP AX to network and setting up CAPsMAN

Currently running a RB4011 (router/DHCP/DNS), hAP AX3 for wifi & a 3rd party WiFi AP.. Have just purchased a wAP AX to replace the 3rd party WiFi AP, so my wifi network will be served using wAP AX and hAP AX3. Looking to setup CAPsMAN as part of this - with the key feature being able to roam my ...
by Frederick88
Fri Jul 12, 2024 4:34 pm
Forum: Beginner Basics
Topic: Route only 1 VLAN through Proton VPN (Wireguard)
Replies: 1
Views: 968

Re: Route only 1 VLAN through Proton VPN (Wireguard)

viewtopic.php?t=185996

Some key things you'll need to add/change;
  • Routing > Rules
  • Routing > Tables
  • IP > Routes
  • Interfaces > Interface List
  • IP > Firewall > NAT
  • IP > Firewall > Filter Rules
by Frederick88
Wed Jan 10, 2024 5:03 am
Forum: Beginner Basics
Topic: Check for Updates: could not resolve DNS name [SOLVED]
Replies: 5
Views: 3426

Re: Check for Updates: could not resolve DNS name [SOLVED]

actually it seems I have DoH DNS issue..

DoH server connection error: SSL: ssl: no trusted CA certificate found (6) [ignoring repeated messages]

this just started happening earlier before I attempted to update...
by Frederick88
Wed Jan 10, 2024 4:37 am
Forum: Beginner Basics
Topic: Check for Updates: could not resolve DNS name [SOLVED]
Replies: 5
Views: 3426

Re: Check for Updates: could not resolve DNS name [SOLVED]

I found answer and tried deleting original post, but loads a blank page after I click delete?

anyway, for anyone else wondering the same thing, create a static DNS A record
upgrade.mikrotik.com > 159.148.147.204
update
remove A record
by Frederick88
Wed Jan 10, 2024 4:30 am
Forum: Beginner Basics
Topic: Check for Updates: could not resolve DNS name [SOLVED]
Replies: 5
Views: 3426

Check for Updates: could not resolve DNS name [SOLVED]

I'm on 7.13 stable.

what's the easiest way to update to 7.13.1 since the internal dns is broken with 7.13 ?

(considering the bug present in 7.13, I would have thought this info would be readily available on the announcement page along with 7.13.1 update?)

Thanks
by Frederick88
Tue Jun 20, 2023 4:14 pm
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 366
Views: 152179

Re: v7.10 [stable] is released!

updated hAP ax3 to 7.10 stable. WiFI seems a lot better. No "authentication" related errors, and no 5GHz radio malfunctions yet. I also noticed that my laptop picks up the SSID from the hAP instantly now, whereas <7.10 the SSID took a lot longer to show compared to other wifi APs in the ar...
by Frederick88
Sat Jun 17, 2023 6:12 am
Forum: Beginner Basics
Topic: How to connect to a WireGuard server?
Replies: 18
Views: 17144

Re: How to connect to a WireGuard server?

/ip address
add address=10.1.1.2/24 interface=WGinterface
is it not possible to use /32 here instead, since traffic is masqueraded anyway? i’ve always felt using smallest possible subnet is better, more efficient and secure?
by Frederick88
Thu Jun 01, 2023 4:30 am
Forum: Beginner Basics
Topic: Android TV box dont get DHCP from hAP AX3
Replies: 13
Views: 3056

Re: Android TV box dont get DHCP from hAP AX3

Could be a case of cheap Android trash?

To help eliminate some possibilities,
Have you tried removing TP-Link switch from the equation and connect directly to MT?
Have you tried disconnecting connection from TV and connect to another device, such as laptop. Does it experience same issue?
by Frederick88
Fri May 19, 2023 3:04 am
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 15018

Re: Container/Docker -Adguard/Pihole For REAL.

I was searching for blocky with MikroTik , and came across this topic... I wanted to use blocky over PiHole due to blocky's native DoH support, whereas PiHole needs an additional binary (CloudFlared) for DoH (and probably not possible on the MT?)... Regardless - it seems like running either blocky o...
by Frederick88
Tue May 09, 2023 8:17 am
Forum: General
Topic: VPN Bonding
Replies: 1
Views: 1114

Re: VPN Bonding

Instead of trying to bond two completely different connections such as a fixed PPPoE and wireless cellular connection, you may want to consider using pre-routing and mangle rules instead, whereby you have a VPN connection from each WAN with rules about what traffic goes over what connection... Other...
by Frederick88
Tue May 09, 2023 6:49 am
Forum: General
Topic: DoH DNS redirect not working properly on ROS7.9 and Cloudflare for Family
Replies: 43
Views: 8747

Re: DoH DNS redirect not working properly on ROS7.9 and Cloudflare for Family

@rextended I feel as though using standard DNS as a failover for DoH, defeats the purpose of using DoH in the first place...? @anav once you've imported the cert into RouterOS, it stays there until it expires, regardless of reboot... not sure what you mean by "you will need to put it back in&qu...
by Frederick88
Tue May 09, 2023 2:11 am
Forum: General
Topic: DoH DNS redirect not working properly on ROS7.9 and Cloudflare for Family
Replies: 43
Views: 8747

Re: DoH DNS redirect not working properly on ROS7.9 and Cloudflare for Family

RE: DoH Server Settings I'm successfully using DoH without Server= defined. /ip/dns/set allow-remote-requests=yes use-doh-server=https://1.1.1.1/dns-query verify-doh-cert=yes Therefore I don't believe you need to define the standard (non DoH) DNS server. (even if I clear DNS cache, DoH will still w...
by Frederick88
Fri May 05, 2023 4:42 am
Forum: General
Topic: Unexpected and bizarre Firewall Connection for 169.254.x.x address [SOLVED]
Replies: 3
Views: 1494

Re: Unexpected and bizarre Firewall Connection for 169.254.x.x address [SOLVED]

Thanks guys. I discovered it's something Plex Media Server on the Synology is doing. Nothing in PMS logs suggest what exactly, and everything within PMS is turned off (including DLNA).. maybe some weird combination of Synology & PMS... I'll also look into some blackhole rules to further harden t...
by Frederick88
Thu May 04, 2023 12:21 pm
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 68189

Re: v7.9 [stable] is released!

Any more info on the new radio/reg-info console command?

/interface/wifiwave2/radio/reg-info country=Greenland number=???????????
by Frederick88
Thu May 04, 2023 11:59 am
Forum: General
Topic: Unexpected and bizarre Firewall Connection for 169.254.x.x address [SOLVED]
Replies: 3
Views: 1494

Unexpected and bizarre Firewall Connection for 169.254.x.x address [SOLVED]

I noticed this under ip/firewall/connection, and wondering how it's possible: WTF_169.jpg SETUP Synology NAS ether1 - Connected to network with DHCP IP 172.17.88.200 (LAN interface VLAN88home ) Synology NAS ether2 - PHYSICALLY NOT CONNECTED - Synology self assigned IP 169.254.34.120 Firewall rules: ...
by Frederick88
Sat Apr 22, 2023 6:43 pm
Forum: General
Topic: hAp ax3 POE out?
Replies: 24
Views: 6909

Re: hAp ax3 POE out?

hAP ax3 has POE out on ethr1. You can do WAN from another ether.
Why they made ether1 POE IN AND OUT, I don't understand ...
not to mention on the 2.5Gb port as well.

i can’t see any other logic for it other than cost saving.
by Frederick88
Thu Apr 20, 2023 12:05 am
Forum: General
Topic: RB1100AHx4 VLAN with HW offload with multiple switch chips
Replies: 15
Views: 3717

Re: RB1100AHx4 VLAN with HW offload with multiple switch chips

i was considering doing similar to avoid CPU, but after reading this thread, i’m going to stay with the one bridge.

good read, thanks.
by Frederick88
Wed Apr 19, 2023 3:34 am
Forum: General
Topic: What are these unknown PCI resource on RB4011?
Replies: 5
Views: 2156

Re: What are these unknown PCI resource on RB4011?

Sorry to dig up old thread, but I'm wondering very similar... /system/resource/pci> print detail 0 device="00:00.0" name="SFP+ 10G Ethernet Adapter (rev: 1)" vendor="Annapurna Labs Ltd." category="Ethernet controller" vendor-id="0x1c36" device-id=&qu...
by Frederick88
Sun Apr 16, 2023 6:57 am
Forum: General
Topic: Two hAP ac3's and Ubiquti radios - tips for sharing FTTH connection
Replies: 4
Views: 632

Re: Two hAP ac3's and Ubiquti radios - tips for sharing FTTH connection

no need to double NAT.

just create two LANs, one for each property.

eg
property 1 uses VLAN 111
property 2 uses VLAN 222

you can present vlan 222 as an untagged native port for the wireless point to point

viewtopic.php?p=781603
by Frederick88
Sun Apr 16, 2023 5:43 am
Forum: Beginner Basics
Topic: UPnP vs Static NAT Rules [SOLVED]
Replies: 9
Views: 1678

Re: UPnP vs Static NAT Rules [SOLVED]

what’s the advantage of
reject-with=icmp-admin-prohibited
vs sending traffic black hole?

will devices on LAN stop trying UPnP if they receive the icmp prohibited message?
by Frederick88
Sat Apr 15, 2023 7:39 pm
Forum: Beginner Basics
Topic: srcnat is undesiredly applied with mark-routing
Replies: 21
Views: 2295

Re: srcnat is undesiredly applied with mark-routing

i think you either need a second WAN external IP,
OR you put one router behind the other.

with only one external WAN IP, and two routers in the network, you’re gonna have to double NAT at some point….
by Frederick88
Thu Apr 13, 2023 3:19 pm
Forum: Beginner Basics
Topic: Can a mikrotik be a Wireguard server and a client in the same time?
Replies: 14
Views: 3505

Re: Can a mikrotik be a Wireguard server and a client in the same time?

you can create second peers on each MikroTik Wireguard interface.

viewtopic.php?p=920105
Scenario 4 - (MEDIUM) Peer to Peer tunnelling with one Wireguard interface & Use of IP addresses for Wireguard interfaces.
by Frederick88
Thu Apr 13, 2023 11:02 am
Forum: Beginner Basics
Topic: UPnP vs Static NAT Rules [SOLVED]
Replies: 9
Views: 1678

UPnP vs Static NAT Rules [SOLVED]

OVERVIEW RB4011 running ROS 7.8. Gaming Console that requires open ports for internet related gaming features. Gaming Console (with static IP) on its own network VLAN90, connected directly to RB4011 ether3 (untagged port, PVID90). GOAL Provide necessary open ports for Gaming Console, with as little...
by Frederick88
Wed Apr 12, 2023 4:43 pm
Forum: Beginner Basics
Topic: max-MTU Question [SOLVED]
Replies: 113
Views: 18604

Re: max-MTU Question [SOLVED]

so long story short - don't fuck with larger MTU sizes within a network that at some point might access the internet. Something like a network between |Server| and |Shared Storage/MAS|, could easily have jumbo frames on, providing |Server| and |Shared Storage| use separate dedicated NICS with MTU150...
by Frederick88
Wed Apr 12, 2023 11:24 am
Forum: MikroTik hardware questions
Topic: hAP ax3 - 802.11ax 160MHz ??
Replies: 14
Views: 12183

Re: hAP ax3 - 802.11ax 160MHz ??

what spec refers to channel width 80MHz?

nothing I can see explicitly mentions channel width specification/limitation.
by Frederick88
Wed Apr 12, 2023 10:47 am
Forum: Beginner Basics
Topic: Redoing Bridge VLAN Setup
Replies: 12
Views: 1939

Re: Redoing Bridge VLAN Setup

VST should work without too much hassle... From existing router, trunk VLANs to ESXI host. Configure VST accordingly, ensuring it includes the physical NIC that the trunk is connected too... The vSwitch/vmkernel NIC should then hand off each VLAN's network tot he guestOS as untagged native traffic. ...
by Frederick88
Wed Apr 12, 2023 5:46 am
Forum: MikroTik hardware questions
Topic: hAP ax3 - 802.11ax 160MHz ??
Replies: 14
Views: 12183

Re: hAP ax3 - 802.11ax 160MHz ??

also in Winbox, the GUI doesn't show option for 160MHz.. another reason I'm thinking it's not supported? [admin] /interface/wifiwave2> export # RouterOS 7.8 # removed I've tried with removing Country as well. I use frequency 5490-5650, which covers channel 100 to 128. . [admin] /interface/wifiwave2>...
by Frederick88
Wed Apr 12, 2023 5:31 am
Forum: Beginner Basics
Topic: max-MTU Question [SOLVED]
Replies: 113
Views: 18604

Re: max-MTU Question [SOLVED]

yes sorry, increase latency - diminish was a poor choice of word. . MSS is computed per tcp connection, not per packet. so once tcp connection has been established and MSS calculated/computed, is there still ongoing compute each time it "pre-fragments" the ongoing packets within the establ...
by Frederick88
Wed Apr 12, 2023 5:15 am
Forum: General
Topic: Tagged VLANs not needing Untagged interfaces
Replies: 15
Views: 1851

Re: Tagged VLANs not needing Untagged interfaces

LAN and WAN are separate networks, regardless if they're on different VLAN / no VLAN. Even if both WAN and LAN are no NO VLAN (native, untagged), that's still not the reason why LAN can send and receive traffic out of WAN... The routing table is what does this, see IP Routes.. this is based on IP ne...
by Frederick88
Wed Apr 12, 2023 2:52 am
Forum: MikroTik hardware questions
Topic: hAP ax3 - 802.11ax 160MHz ??
Replies: 14
Views: 12183

hAP ax3 - 802.11ax 160MHz ??

Recently purchased hAP ax3 - trying to set 802.11ax with 160MHz channel width - says "unable to find suitable channel", even if I set channel frequency wide enough for 160MHz... The more I look into it, the more I'm beginning to think the ax3 doesn't support 160MHz channel width, 802.11ax ...
by Frederick88
Wed Apr 12, 2023 2:43 am
Forum: Beginner Basics
Topic: max-MTU Question [SOLVED]
Replies: 113
Views: 18604

Re: max-MTU Question [SOLVED]

Does MSS Clamping cause much overhead on the router - or rather, does it diminish your WAN latency in any way, and negate any potential advantages of using larger MTU within the LAN to begin with?
by Frederick88
Tue Apr 11, 2023 5:25 am
Forum: Beginner Basics
Topic: max-MTU Question [SOLVED]
Replies: 113
Views: 18604

Re: max-MTU Question [SOLVED]

This thread has been an interesting read leading me to look into MTU... PMTUD does its job and correctly sends packets/frames in correct size based on the path. We've never had any fragmentation in the networks I deployed large MTU on. This has me wondering, if I change my computers NIC to Jumbo MTU...
by Frederick88
Mon Apr 10, 2023 4:16 pm
Forum: Beginner Basics
Topic: Redoing Bridge VLAN Setup
Replies: 12
Views: 1939

Re: Redoing Bridge VLAN Setup

i think instead of trying to understand all the possibilities and ways it can be done - what is your goal and requirements…. explain what you’re trying to achieve and why.. based on this. we can minimise your options and provide a clearly list of examples how it could be done, along with the pros an...
by Frederick88
Mon Apr 10, 2023 4:12 pm
Forum: Beginner Basics
Topic: Redoing Bridge VLAN Setup
Replies: 12
Views: 1939

Re: Redoing Bridge VLAN Setup

well i think you have quite a few different options and ways you can do this… i guess first question is, how much “control” or influence you have over the whole network, from ISP connection to you…? if you have freedom to do anything you want, it might be worth considering bridging your ISP modem/ro...
by Frederick88
Sun Apr 09, 2023 10:53 am
Forum: Beginner Basics
Topic: Bridge WAN connection through RB4011 to hAP ax3 for routing [SOLVED]
Replies: 14
Views: 1636

Re: Bridge WAN connection through RB4011 to hAP ax3 for routing [SOLVED]

thanks guys... I think I've been trying to overcomplicate things instead of keeping it a bit more KISS... my original thought for doing this was to minimise VLAN routing latency (ie. avoiding CPU as much as possible) to the computers connected directly to hAP... but I now realise traffic has to go t...
by Frederick88
Sat Apr 08, 2023 3:21 pm
Forum: Beginner Basics
Topic: Bridge WAN connection through RB4011 to hAP ax3 for routing [SOLVED]
Replies: 14
Views: 1636

Re: Bridge WAN connection through RB4011 to hAP ax3 for routing [SOLVED]

how does wifiwave2 affect things if the hAP is the one responsible for routing?
by Frederick88
Sat Apr 08, 2023 4:53 am
Forum: Beginner Basics
Topic: Bridge WAN connection through RB4011 to hAP ax3 for routing [SOLVED]
Replies: 14
Views: 1636

Bridge WAN connection through RB4011 to hAP ax3 for routing [SOLVED]

This might sounds like a silly idea... but in any case, I'm interested how it would be possible, if possible... Objective: assign hAP ax3 as router, using the internet connection "bridged" through RB4011.. and on the same ethernet connection, trunk back LANs from hAP to RB4011. Is it possi...
by Frederick88
Fri Apr 07, 2023 6:57 pm
Forum: Beginner Basics
Topic: Redoing Bridge VLAN Setup
Replies: 12
Views: 1939

Re: Redoing Bridge VLAN Setup

depends what you want responsible for the routing of the “private network” within the ESXI host… if it’s your ISP router, you need to trunk from router to ESXI host and then assign each vlan network to your guest OSes. otherwise you could virtualise a router within the ESXI host, create virtual inte...
by Frederick88
Fri Apr 07, 2023 2:49 pm
Forum: Beginner Basics
Topic: setup a wireguard tunnel between Mikrotik router and Cloude server
Replies: 5
Views: 643

Re: setup a wireguard tunnel between Mikrotik router and Cloude server

i think each wg connection will need its own peer. and each peer needs its own address.

eg
wgpeer1 192.168.85.2/24
wgpeer2 192.168.85.3/24
wgpeer3 192.168.85.4/24
by Frederick88
Wed Apr 05, 2023 3:33 am
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan through gateway-wireguard only

No need, In fact you should be able to ping the gateway of any vlan from any vlan device and the wg interface. The reason is that interfaces on the MT are considered Router interfaces and thus if one has connectivity to the router, then one should be able to ping the interfaces. As you already disc...
by Frederick88
Tue Apr 04, 2023 7:14 am
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan through gateway-wireguard only

(1) For VLAN separation at Layer3, firewall rules apply. Easiest is to drop all at the end of the forward chain. I added the drop all. Can't ping devices on other VLANs, however I can ping the address of wireguard interface. Example, I'm on VLAN89 and can ping 10.140.35.150 (wireguard51 interface I...
by Frederick88
Mon Apr 03, 2023 11:54 am
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan5 through gateway-wireguard only

@anav Much appreciate your previous configuration, works like a charm on a recently purchased hAP ax3... I used the fresh default config of the hAP ax3 and added wireguard and VLAN configuration as you outlined previously, with the addition of another wireguard interface and LAN.. Massive help, than...
by Frederick88
Sun Jul 24, 2022 5:25 pm
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan5 through gateway-wireguard only

It's been a while, so to summarise: 2 LANs on MikroTik: vlan1 : routes via standard ISP WAN only vlan5 : routes via WireGuard VPN connection only EDIT: Can i send you the actual WireGuard configuration file with private key for you to try, assuming you have a test environment? Might be easier than t...
by Frederick88
Thu May 26, 2022 4:01 am
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan5 through gateway-wireguard only

WireGuard VPN Configuration file (wg-vpn-server_UDP.conf) from the VPN Server Provider: [Interface] Address = 10.75.178.228/10 PrivateKey = blahPrivateKeyblahblah= DNS = 10.64.0.1 [Peer] PublicKey = blahPublicKeyblahblah= PresharedKey = blahPresharedKeyblahblah= Endpoint = endpoint.vpnserver.address...
by Frederick88
Wed May 25, 2022 10:16 am
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan5 through gateway-wireguard only

Im astonished that the VPN provider would give you over 4,000 addresses for internet access vice ONE! are you sure thats correct??? Yeah I thought a /10 was quite a lot as well, but I've double checked config and that's what they've given me... From my understanding, this just means that their side...
by Frederick88
Tue May 24, 2022 2:29 pm
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan5 through gateway-wireguard only

Appreciate your help, you've got me past a few hurdles I was stuck on and it's all making a bit more sense now, especially with firewall rules which I've cleaned up as you've suggested.. Cheers - I am used to working with all vlans if working with any vlans, anything else gets confusing right quick....
by Frederick88
Mon May 23, 2022 5:59 am
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan5 through gateway-wireguard only

is what I'm trying to achieve, possible with RouterOS 7?
by Frederick88
Tue May 17, 2022 5:13 am
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

Re: isolate and route vlan5 through gateway-wireguard only

Luv to help when you explain WTF vlan0 is?? Also unable to assist without the config? /export file=anynameyouwish Thanks and sorry for bad terminology - by "vlan0" I mean the default LAN, which I guess should be called "vlan1"... LAN 192.168.88.1/24 | native on ports eth2 to 10 ...
by Frederick88
Mon May 16, 2022 12:18 pm
Forum: Beginner Basics
Topic: isolate and route vlan through gateway-wireguard only
Replies: 21
Views: 4569

isolate and route vlan through gateway-wireguard only

I have read https://forum.mikrotik.com/viewtopic.php?t=182340&sid=884e4039a8973770ded8fdbc61032f3d which was very well written and detailed, thank you. However I'm still having trouble trying to set up a WG connection and isolate one of my LANs to use this gateway only. Example of what I'm tryin...
by Frederick88
Sat Jun 26, 2021 10:15 am
Forum: Beginner Basics
Topic: Routing certain networks over VPN only
Replies: 0
Views: 654

Routing certain networks over VPN only

Hi, I'm fairly new to routerOS after purchasing a new 4011... I must say, the learning curve is a little more than I expected, but I'm enjoying it for the most part... My current set up is ISP > routerOS ether1 (WAN) LAN network = 192.168.88.1/24 I'm looking at creating another LAN, say, 192.168.70....
by Frederick88
Thu Jun 24, 2021 12:50 pm
Forum: Beginner Basics
Topic: Xbox One NAT woes
Replies: 10
Views: 21227

Re: Xbox One NAT woes

so I keep reading how UPnP can be a security risk... I have Xbox connected to ether9, WAN via ether1. If I enable UPnP for just external port=ether1 and internal port=ether9, would it still be considered a security risk since UPnP is only enabled for the xbox and therefore can't effect any other LAN...