Community discussions

MikroTik App

Search found 667 matches

by Josephny
Fri Nov 01, 2024 12:25 am
Forum: General
Topic: Lets Encrypt
Replies: 5
Views: 183

Re: Lets Encrypt

Wow! That is a beautiful solution. Don't forget you have to install Let's Encrypt's R10 and R11 intermediate CA certificates so that the HTTPS server could send the relevant one of them to the clients along with its own certificate. The issuing intermediate CA is chosen randomly for each renewal. I ...
by Josephny
Thu Oct 31, 2024 11:18 pm
Forum: General
Topic: Lets Encrypt
Replies: 5
Views: 183

Re: Lets Encrypt

While not perfect, this might work if the MT device were connected to the Internet. There is a setup that "will work until it stops", which is based on the fact that the certificate renewal requests are currently sent to acme-v02.api.letsencrypt.org ; as RouterOS sends them automatically,...
by Josephny
Thu Oct 31, 2024 9:55 pm
Forum: General
Topic: Lets Encrypt
Replies: 5
Views: 183

Re: Lets Encrypt

I figured it out: The MT devices to be opened on port 80 (to the Internet). It seems this applies to renewals also. Obviously, we don't want to leave 80 open all the time. What is the recommended solution? Schedule a script that opens 80, runs the certificate renewal command, and then closes 80? Whi...
by Josephny
Thu Oct 31, 2024 9:12 pm
Forum: General
Topic: Lets Encrypt
Replies: 5
Views: 183

Lets Encrypt

I have an environment with a cable modem -> Ubiquity UDMPro -> hEX. The hEX handles the DNS for the entire environment (in addition to other things). The UDM has also been upset when I try access it and throw off errors that there is no certificate and it's unsafe. So I thought I'd install a Let's E...
by Josephny
Thu Oct 31, 2024 7:30 pm
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 61
Views: 70786

Re: Long range wireless links - share your experience

I would love to play around with these types of links, and have plenty of good use for links in the 1-10km (I think in miles, but I'll adapt).

Problem is, I've got nothing but mountains and trees for miles in all directions, so unless I erect 200' towers, my line of sight is limited to 1/2 km.
by Josephny
Thu Oct 31, 2024 5:19 pm
Forum: Beginner Basics
Topic: Trying to wrap my head around VLANs
Replies: 10
Views: 369

Re: Trying to wrap my head around VLANs

I try to keep up with code/acronyms/etc., but huh??? BTW, K6, I'm a KC2 Its not code just a pronounciation schema. Californicators are a tad odd. ;-) Oh! Got it now! Couldn't agree more. Glad to see more people who recognize NYC as the center of the English speaking world and the only non-accented ...
by Josephny
Thu Oct 31, 2024 3:15 pm
Forum: Beginner Basics
Topic: Trying to wrap my head around VLANs
Replies: 10
Views: 369

Re: Trying to wrap my head around VLANs

KAL EYE 4RN EYE EH
I try to keep up with code/acronyms/etc., but huh???

BTW, K6, I'm a KC2
by Josephny
Thu Oct 31, 2024 3:09 am
Forum: Beginner Basics
Topic: Trying to wrap my head around VLANs
Replies: 10
Views: 369

Re: Trying to wrap my head around VLANs

I just want to say that I have never been able to get a useful environment using VLANs. I’ve read the always-recommend post here, reads tons of other articles, watched videos and there is nothing that explains it and instructs in their construction clearly enough. I don’t know why, and I can’t sugge...
by Josephny
Wed Oct 30, 2024 1:00 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Re: Polling?

Update: At the location that prompted me to start this "voltage" investigation, I have frequent (but irregular -- i.e., at random times) losses of internet connectivity. Sometimes it turns out the cable modem needs to be rebooted, and other times, service is restored without intervention i...
by Josephny
Wed Oct 30, 2024 12:53 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Re: Polling?

I do know some stuff like LTE – which also uses "monitor" – may not actually get all value every time. For example, on some modems it's ~50% where the CQI or RSRQ will be included in "monitor once". The "loop" version of monitor for more like voltage over 10 seconds, i...
by Josephny
Tue Oct 29, 2024 6:39 pm
Forum: Beginner Basics
Topic: SSID Name for WiFi 2GHz and 5Ghz
Replies: 10
Views: 336

Re: SSID Name for WiFi 2GHz and 5Ghz

If one needs strong 2.4GHz signal for improved coverage, then the only way of decent mobility (in both directions, i.e. also from 2.4GHz to 5GHz) is to use new drivers (wifi) and rely on mobility functions ... where client still has decisive powers. By "mobility functions" do you mean cli...
by Josephny
Tue Oct 29, 2024 5:52 pm
Forum: Beginner Basics
Topic: SSID Name for WiFi 2GHz and 5Ghz
Replies: 10
Views: 336

Re: SSID Name for WiFi 2GHz and 5Ghz

I always keep the SSID identical and play with transmission power (lower 2.4GHz transmission power a lot). My client devices are smart enough to select the 5GHz radio, or roam to it when available. Another disadvantage of having different SSID's is the lack of roaming. You have to change manually, ...
by Josephny
Tue Oct 29, 2024 12:11 pm
Forum: General
Topic: Voltage?
Replies: 2
Views: 153

Re: Voltage?

I don't know if they all have what You said, but yes: any difference would be due to hardware. Some kits just have more/different sensors than others. Thank you. FYI, I looked at Winbox/ROS on each of these devices and what I wrote reflects what I saw as available. It would be nice if all the hardw...
by Josephny
Tue Oct 29, 2024 2:43 am
Forum: General
Topic: Voltage?
Replies: 2
Views: 153

Voltage?

Am I correct that the RB5009 has /system/health CPU TEMP, VOLTAGE, JAC VOLTAGE, POE-IN VOLTAGE, POE-OUT CONSUMPTION, BOARD-TEMPERATURE1 The hEX has /system/heath TEMPERATURE and VOLTAGE? The AX has/system/health but only CPU-TEMPERATURE (no voltage)? The AC doesn't have /system/health? Cube has /sys...
by Josephny
Mon Oct 28, 2024 5:23 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Re: Polling?

Jokes aside, I don't have any UPS directly connected to a RouterBOARD otherwise I would have helped you better, but if you are not familiar with scripting the 1 second scheduler is more than enough and practically does not consume CPU. Oh, how disappointing! I was hoping you were going to provide a...
by Josephny
Mon Oct 28, 2024 5:17 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Re: Polling?

Need to run Assassin's Creed on your router?
No.
Does setting a infinite loop for every nanosecond create a more large CPU overhead?
No idea.
by Josephny
Mon Oct 28, 2024 5:13 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Re: Polling?

It's quicker to set it in the scheduler every second rather than doing intricate things, especially for those who are not familiar with scripting...
Does setting a scheduler for every second create a large CPU overhead?
by Josephny
Mon Oct 28, 2024 1:26 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Re: Polling?

Remove the "once" and it becomes a ":while (true)" loop, so it will run forever. There is an interval= that control how often the do={} code is run, i.e. 1s or 1m or 1h etc.... You can also make only run for a fixed period like duration=1m. This is useful like in a /system/sched...
by Josephny
Sun Oct 27, 2024 7:06 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Re: Polling?

It looks like there is no solution.
by Josephny
Sat Oct 26, 2024 7:43 pm
Forum: Scripting
Topic: Polling?
Replies: 12
Views: 448

Polling?

Not sure if this is a scripting question. I want to be able to poll the UPS's status. Or, more generally, I want the router to do something if the line (input) voltage to the UPS drops below a threshold and/or the UPS has changed to battery power. I have this code which seems to work, but I am hopin...
by Josephny
Sat Oct 26, 2024 1:34 pm
Forum: Wireless Networking
Topic: WiFi Disconnect Issues with hAP ax² - Seeking Advice on Stable Version and Future Updates
Replies: 8
Views: 1033

Re: WiFi Disconnect Issues with hAP ax² - Seeking Advice on Stable Version and Future Updates

If I may, a meta-question. Why (the heck) are most people here on the forum obsessed with updating? Besides the obvious mistakes the good Mikrotik guys insist on making, pushing out new versions without appropriate testing, and mixing all together, without even an attempt to prioritize them, new fe...
by Josephny
Fri Oct 25, 2024 8:58 pm
Forum: Scripting
Topic: Appending file within foreach
Replies: 10
Views: 329

Re: Appending file within foreach

That is fabulous! I incorporated it into my script (removing the set of brackets so that the variable $allIPs remains), but the output is still repeating. If I write something, it mean is it needed... :put [:tostr $allIPs] Do not forget to correct ALL: add name=systeminfo contents="$resources\...
by Josephny
Fri Oct 25, 2024 5:41 pm
Forum: Scripting
Topic: Appending file within foreach
Replies: 10
Views: 329

Re: Appending file within foreach

If your willing to have the data as JSON, the newer [:serialize] makes quick work of this: /file/add name=test.json contents=[:serialize to=json [/system/resource/print as-value] option=json.pretty] For example, the output looks like: :put [:serialize to=json [/system/resource/print as-value] optio...
by Josephny
Fri Oct 25, 2024 5:14 pm
Forum: Scripting
Topic: Appending file within foreach
Replies: 10
Views: 329

Re: Appending file within foreach

All is useless. Just this: { /ip address :local allIPs [:toarray ""] [pri as-value where [:set allIPs ($allIPs,$address)]] :put [:tostr $allIPs] } That is fabulous! I incorporated it into my script (removing the set of brackets so that the variable $allIPs remains), but the output is stil...
by Josephny
Fri Oct 25, 2024 4:14 pm
Forum: Scripting
Topic: Appending file within foreach
Replies: 10
Views: 329

Re: Appending file within foreach

Still not exactly what I'd like. This code produces the output below: /file remove systeminfo /system :local cdate [clock get date] :local yyyy [:pick $cdate 0 4] :local MM [:pick $cdate 5 7] :local dd [:pick $cdate 8 10] :local identitydate "$[identity get name]_$yyyy-$MM-$dd" # Collect S...
by Josephny
Fri Oct 25, 2024 3:32 pm
Forum: Scripting
Topic: Appending file within foreach
Replies: 10
Views: 329

Re: Appending file within foreach

I've made some progress -- it works, I think: # Collect IP addresses :global ipaddressvalues [:toarray ""] :foreach neighborID in=[/ip address find] do={ :local nb [/ip address get $neighborID] :local id [:pick ("$nb"->".id") 1 99] :foreach key,value in=$nb do={ :local ...
by Josephny
Fri Oct 25, 2024 1:19 pm
Forum: Scripting
Topic: Appending file within foreach
Replies: 10
Views: 329

Appending file within foreach

I would like to save a file with the values discovered during the foreach loop below. But, I'm having a hard time with appending values to the variable. I believe I need to use an array, but it's beyond me at this time. # Collect IP addresses :foreach neighborID in=[/ip address find] do={ :local nb ...
by Josephny
Fri Oct 25, 2024 12:46 am
Forum: Scripting
Topic: Scripting skills
Replies: 15
Views: 633

Re: Scripting skills

You could have avoided many questions by comparing what I wrote with what you wrote. What is wrong with: :local version ([/system resource get version]) Easy: useless parenthesis ( ) that cause other useless calcs... And, I cannot get this line to work: :local newline [:find \$value \"\\\"...
by Josephny
Thu Oct 24, 2024 4:26 pm
Forum: Scripting
Topic: Scripting skills
Replies: 15
Views: 633

Re: Scripting skills

ability to pester those far more knowledgeable One big trick, I think, is using "/system/script/edit <scriptname> source" to use Mikrotik's editor. Unlike Winbox's script editor, it will show red marks if the script is invalid (in realtime in edit). While I like @rextended, I know he uses...
by Josephny
Thu Oct 24, 2024 1:56 am
Forum: Scripting
Topic: Scripting skills
Replies: 15
Views: 633

Re: Scripting skills

Is beter you lost instantly bad habit like :local version ([ /system resource get version ]) and do not post export like a script because on this way is full of errors. Copy & paste from winbox to the forum, or posst all the exported script parts. Also use space indentation, or is hard readable...
by Josephny
Tue Oct 22, 2024 6:29 pm
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 39
Views: 3494

Re: Datasheet for new improved hEX?

If not, is there a chart of which adapters work for which devices? Are you that lazy?? Checking the plain old hex........ pwr1.JPG ... pwr2.JPG ................. Rules of thumb: 1. voltage (dc output of adapter) must be an exact match for device input voltage ( or within the stated range if one is ...
by Josephny
Tue Oct 22, 2024 5:51 pm
Forum: General
Topic: UPS monitor voltage script
Replies: 10
Views: 377

Re: UPS monitor voltage script

For what it's worth, I researched the topic of UPS facility in Mikrotik years ago and haven't revisited the subject much. I've settled on having smart upses be used as dumb ones and only use the UPS facility in Mikrotik for the occasional peek at what it is doing. The reason for why Mikrotik deviat...
by Josephny
Tue Oct 22, 2024 5:05 pm
Forum: Scripting
Topic: Scripting skills
Replies: 15
Views: 633

Re: Scripting skills

Congrats on your scripting journey, seriously! I will say you are braver than I. I have only dabbled in scripting and am mostly content to use functionality as already available, and thus admire anyone that makes the effort. Where I think people are just plain nuts is there love for capsman. I am h...
by Josephny
Tue Oct 22, 2024 4:45 pm
Forum: Scripting
Topic: Scripting skills
Replies: 15
Views: 633

Re: Scripting skills

Why are you posting in the General Forum instead of the Scripting Forum???????

Want a ----> cookie.jpg ??
Apologies.

Yes, please.
by Josephny
Tue Oct 22, 2024 4:08 pm
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 39
Views: 3494

Re: Datasheet for new improved hEX?

... True, it isn't being sold yet. They may very well sell it with a 24V 0,5A power supply, and problem solved. But as of now, the matched power supply can't power it at 100% usage. These external power supply adapters are most common failure point of Mikrotik hardware. When devices with 24V 0,8A/1...
by Josephny
Tue Oct 22, 2024 3:49 pm
Forum: Scripting
Topic: Scripting skills
Replies: 15
Views: 633

Scripting skills

I am at a baby level at scripting and progressing extremely slowly, but I wrote (okay, adapted slightly from @jotne's work) a script to log some basic device info. I know you experts will cringe at a simpleness, but I'm proud of myself. # Collect system resource /system resource :local cpuload [get ...
by Josephny
Tue Oct 22, 2024 12:00 pm
Forum: General
Topic: UPS monitor voltage script
Replies: 10
Views: 377

Re: UPS monitor voltage script

Do your UPS offer the “on-battery” field? While I see it mentioned in the documentation, https://help.mikrotik.com/docs/spaces/ROS/pages/120324130/UPS , my little experience is that the actual UPS implementation on Mikrotik deviates a lot from the documentation. Some of it may be due to the exact m...
by Josephny
Tue Oct 22, 2024 4:52 am
Forum: General
Topic: UPS monitor voltage script
Replies: 10
Views: 377

Re: UPS monitor voltage script

I have the following working: :local voltage (([/system ups monitor 0 once as-value]->"line-voltage")/100) :log info $voltage But when I include a test for "on-battery" being "true" the script does not work. I wonder if it is a simply syntax error or if I need to conver...
by Josephny
Tue Oct 22, 2024 3:19 am
Forum: General
Topic: UPS monitor voltage script
Replies: 10
Views: 377

Re: UPS monitor voltage script

It isn't a property. As an aside I'm not sure why load appears in both properties and monitor values, logically it would only be in the latter with the other measured data. To display from the command line :put ([/system/ups/monitor 0 once as-value]->"line-voltage") If you wish to access ...
by Josephny
Tue Oct 22, 2024 2:18 am
Forum: General
Topic: UPS monitor voltage script
Replies: 10
Views: 377

Re: UPS monitor voltage script

No "line-voltage" [admin@371hEX] /system/ups> print proplist= Flags: X - disabled; I - invalid 0 name="ups1" port=usbhid1 offline-time=0s min-runtime=never alarm-setting=immediate model="Back-UPS RS 700G FW:856.L8 -P.D USB FW:L8 -P" serial="0B2252N07530" manuf...
by Josephny
Tue Oct 22, 2024 2:01 am
Forum: General
Topic: UPS monitor voltage script
Replies: 10
Views: 377

Re: UPS monitor voltage script

I'm supposed to be on my way home already so I'm not going to write it for you. But I'd do it like this: :if(ups on battery) do={:log voltage} Then add it to the scheduler and run it every 00:00:01. Note that this will be a resource hog and will fill a 1000 entries long log in 15 minutes. Setting t...
by Josephny
Mon Oct 21, 2024 11:24 pm
Forum: General
Topic: UPS monitor voltage script
Replies: 10
Views: 377

UPS monitor voltage script

Using the command: /system ups monitor 0 I see "line-voltage" as well as lots of other data. And, when the line voltage drops, I can see log entries: USB UPS AC power on I would like to see how low the line voltage dropped during those times. And, ideally, the line voltage every second (or...
by Josephny
Sun Oct 20, 2024 6:57 pm
Forum: General
Topic: disconnected, register to other interface
Replies: 9
Views: 492

Re: disconnected, register to other interface

It depends on what you want to do. As mkx wrote Note that in new wifi drivers it's not possible to disable legacy radio standards, it's only possible to cap it to certain radio standards and disable newest ones (yes, sometimes this can be necessary). and according to this: https://forum.mikrotik.co...
by Josephny
Sun Oct 20, 2024 4:21 pm
Forum: General
Topic: disconnected, register to other interface
Replies: 9
Views: 492

Re: disconnected, register to other interface

Thank you again everyone. As much as I try, not a day goes by that I don't learn new things :) Does this correct: /interface wifi set [ find default-name=wifi1 ] channel.band=2ghz-g .width=20mhz configuration.mode=ap .ssid=\ MikroTik-95466C-2.4ghz disabled=no name=wifi1-2ghz security=629 security.au...
by Josephny
Sun Oct 20, 2024 2:21 pm
Forum: General
Topic: disconnected, register to other interface
Replies: 9
Views: 492

Re: disconnected, register to other interface

Most threads nowadays are about the wifi-qcom(-ac) driver. You are still using the legacy/old wireless driver. So...no, I don't see a lot of threads nowadays about this driver. For security settings, start with basic before using more advanced stuff: / interface wireless security-profiles set defau...
by Josephny
Sun Oct 20, 2024 3:53 am
Forum: Scripting
Topic: Enhanced IP Scan with Vendor and Additional Name Sources
Replies: 21
Views: 1699

Re: Enhanced IP Scan with Vendor and Additional Name Sources

Beautiful and useful script!

Thank you for writing this.
by Josephny
Sat Oct 19, 2024 3:59 pm
Forum: General
Topic: disconnected, register to other interface
Replies: 9
Views: 492

Re: disconnected, register to other interface

Could you share your config? /export file=anynameyoulike Remove serial and any other private info and post in between code tags by using the </> button. Current config: # 2024-10-19 08:57:00 by RouterOS 7.16.1 # software id = 80FK-6837 # # model = RBD53iG-5HacD2HnD # serial number = E72C0 /interfac...
by Josephny
Sat Oct 19, 2024 12:47 pm
Forum: General
Topic: disconnected, register to other interface
Replies: 9
Views: 492

disconnected, register to other interface

I'm not sure if this problem is one of the other ongoing problems with threads here. This continues to happens, across devices and locations, and after trying everything suggested in threads here. I understand that there is an analysis that this is client-caused. And, the problem does only happen wi...
by Josephny
Sat Oct 19, 2024 4:49 am
Forum: Wireless Networking
Topic: "not responding" - f.k.a. SA Query timeout
Replies: 159
Views: 29609

Re: "not responding" - f.k.a. SA Query timeout

After having months of constant disconnects and i tested every beta versions since 7.15 to 7.17 and tried every possible setting i may discovered something. I changed wireless interfaces default queue type wireless default(SFQ) to CODEL ( /queue/interface>) add fq-codel-ecn=no fq-codel-interval=60m...
by Josephny
Sat Oct 19, 2024 4:30 am
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 38
Views: 4870

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

wAP ax datasheet: https://www.wifihw.cz/img.asp?attid=3848208 Please upload this PDF here, i can't do it. A humble, good-natured suggestion to Mikrotik's marketing people: Don't use the words "drop" or "drop-in" to market a wifi product. "Dropping" (which when spoken s...
by Josephny
Thu Oct 17, 2024 4:49 am
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

I still get this bursts of log entries every few days.

It looks like they are always mac devices (Macbook or iPhone).

Any ideas on what this means?


.
Screenshot 2024-10-16 214723.png
by Josephny
Wed Oct 16, 2024 2:06 pm
Forum: General
Topic: Backup/Export Dude Syslog Filter Rules?
Replies: 3
Views: 207

Re: Backup/Export Dude Syslog Filter Rules?

I see that running export-db also wipes clean the log entries from The Dude client.
by Josephny
Wed Oct 16, 2024 2:04 pm
Forum: General
Topic: Backup/Export Dude Syslog Filter Rules?
Replies: 3
Views: 207

Re: Backup/Export Dude Syslog Filter Rules?

Full backup or nothing.
/dude export-db
Thank you.

So it's a backup (in backup/restore format only), and not a human-readable form?
by Josephny
Wed Oct 16, 2024 1:30 pm
Forum: General
Topic: Backup/Export Dude Syslog Filter Rules?
Replies: 3
Views: 207

Backup/Export Dude Syslog Filter Rules?

I have been playing with The Dude syslog filters rules and have a large enough (finely tuned enough) list that I realize it would be nice to have a backup. I see the rules in /dude/dude.db-wal but it is not easily readable. Is there a way to backup or export these rules? Here's what I have (reminder...
by Josephny
Tue Oct 15, 2024 2:24 am
Forum: General
Topic: Netwatch changes from 7.14 to 7.16?
Replies: 0
Views: 186

Netwatch changes from 7.14 to 7.16?

I finally worked up the courage to upgrade form 7.14 to 7.16 on a bunch of devices. Mostly went just fine. Couple of scripts needed tweaking. One (of the many things) I noticed is that Netwatch is finding "down" states very very often since the upgrade. I assumed something changed. I use t...
by Josephny
Wed Oct 09, 2024 4:24 am
Forum: General
Topic: [GUIDE] Grafana, Prometheus, and snmp_exporter
Replies: 23
Views: 22189

Re: [GUIDE] Grafana, Prometheus, and snmp_exporter

Can this be used to collect data from 20+ MT devices?
by Josephny
Wed Oct 09, 2024 3:49 am
Forum: General
Topic: Which device Verizon LTE/5g in US
Replies: 3
Views: 958

Re: Which device Verizon LTE/5g in US

It is 1 year later and I wonder if anything has changed?

Specifically, is there an LTE/4G device that will work in the US without jumping through hoops?

Thanks.
by Josephny
Mon Oct 07, 2024 7:20 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

I think I got it. I added a second bridge, added the 2ghz and 5ghz wifi interfaces to that bridge, told the dhcp server to use that bridge, etc. I think it's working. Here's the new config (made with my handy-dandy Notepad++ sanitizer script): # 2024-10-07 12:11:06 by RouterOS 7.16 # software id = 5...
by Josephny
Mon Oct 07, 2024 4:07 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

For one thing, I would think it would be better to to keep the same ip address when a station roams from 2ghz to 5ghz. I'm not sure whether this works even when the two interfaces are connected to the same bridge because the phone typically uses a different MAC address for its own 2.4 GHz and 5 GHz...
by Josephny
Mon Oct 07, 2024 2:37 pm
Forum: General
Topic: Command line enty for The Dude syslog rules possible?
Replies: 0
Views: 130

Command line enty for The Dude syslog rules possible?

Is it possible to add/remove/modify systog filter rules via a command line entry?

Are The Dude syslog rules contained in a user-readable config file?

Thanks.
by Josephny
Mon Oct 07, 2024 2:13 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Is the fact that there are 2 routes with 0.0.0.0/0 destinations a problem? Two routes with the same destination may be both a desired setup or a wrong one - it depends on circumstances. E.g. if you had two WANs, two default routes could be a desired setup, as the ultimate destination would be the s...
by Josephny
Mon Oct 07, 2024 12:24 pm
Forum: General
Topic: Looking for instrction to isolate guest wifi networks
Replies: 12
Views: 629

Re: Looking for instrction to isolate guest wifi networks

Thanks for instruction. It almost works - however, while 2g guest network works fine (tested by IoT devices and smartphone), 5g guest network rejects WAN request, so smartphone could not connect to internet. Mikrotik hap AC^2, 7.15.3 I'm far from an expert, but I'll try to help. First step is to po...
by Josephny
Sun Oct 06, 2024 11:50 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Is the fact that there are 2 routes with 0.0.0.0/0 destinations a problem? DAd dst-address=0.0.0.0/0 routing-table=main pref-src= gateway=100.38.160.1 immediate-gw=100.38.160.1%ether1 distance=1 scope=30 target-scope=10 vrf-interface=ether1 suppress-hw-offload=no IsH dst-address=0.0.0.0/0 routing-ta...
by Josephny
Sun Oct 06, 2024 11:44 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Depends, If you are assigned a static WANIP, its often easier just to set the IP yourself. If assigned a dynamic WANIP a dhcp client setting can make sense for route, but it depends on the ISP provider. Same with ppppoe type connection... Typically if doing something funky with routes its often bet...
by Josephny
Sun Oct 06, 2024 11:35 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Nothing is 'normal, there are default rules for the very basic setup and the rest are ADMIN decisions. Okay, so it having the DHCP client configured to set up a route on its own the default setting? And, would you recommend changing it? More importantly, do you think that this automatically added r...
by Josephny
Sun Oct 06, 2024 10:20 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Your complete export has revealed that there is a DHCP client attached to ether1 of the 5009 that is allowed to add a dedault route. So which port of the 5009 is connected to FIOS, ether1 or some other one? What does /ip route print detail show on the 5009? Isn't it normal/recommended/needed for th...
by Josephny
Sun Oct 06, 2024 8:04 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Here is a screenshot of last night's log, in case it is useful.

There is only 1 device using this Guestwifi now -- my own iPhone, which works very well with this configuration.

Screenshot 2024-10-06 061750.png
by Josephny
Sun Oct 06, 2024 3:43 pm
Forum: General
Topic: Script or process for sanitizing exports?
Replies: 2
Views: 951

Re: Script or process for sanitizing exports?

If you do /export hide-sensitive, secrets aren't exported that way. Dynamic entries aren't exported with /export too. I wish that worked, but it doesn't. I issued: /export hide-sensitive terse and the following came out. I replaced all the sensitive informaiton with XXXXX (5 capital letters X). The...
by Josephny
Sun Oct 06, 2024 2:20 pm
Forum: General
Topic: Script or process for sanitizing exports?
Replies: 2
Views: 951

Script or process for sanitizing exports?

What process does everyone follow for sanitizing their exports? Mine are full of sensitive information such as wireguard keys, passwords, email address, local and dynamic dns entries/hostnames, serial numbers, mac addresses, dyndns login info, ftp upload info, ip-sec secret, and probably more. I alw...
by Josephny
Sat Oct 05, 2024 11:41 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Okay, here are the full configs. I sure hope I redacted all sensitive info -- there are many, many instances of mac address, email addresses, dynmanic dns names, passwords, wireguard keys, etc. that have to be manually removed. RB5009 # 2024-10-05 10:02:23 by RouterOS 7.14.2 # software id = 2KBD-7ZZ...
by Josephny
Sat Oct 05, 2024 5:26 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

In case the firewall mangle and nat rules might help: RB5009: # 2024-10-05 10:02:23 by RouterOS 7.14.2 # software id = 2KBD-7ZZB # # model = RB5009UPr+S+ /ip firewall mangle add action=mark-connection chain=prerouting comment=\ "Mark connection for hairpin" disabled=yes dst-address-list=dy...
by Josephny
Sat Oct 05, 2024 5:16 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

that is such a fantastic explanation and analysis! [...] It sure seems like it is your #2 explanation: timed out connection resulting in connection-state=new Unfortunately, your conclusion suggests that the explanation wasn't as fantastic as I would like it to be :) Let me reiterate - since the sou...
by Josephny
Sat Oct 05, 2024 3:52 pm
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

To be precise, it actually is a problem, but for sure adding a permissive rule would not be a solution to it. As in IPv4, the majority of user endpoints have private addresses, there are not many useful scenarios where endpoints in the internet would initiate connections to them, as they could only...
by Josephny
Sat Oct 05, 2024 10:28 am
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Re: Need a forward rule

Do not allow. If everything seems to be working do not touch that rule. It could be a leftover of any unexpectedly closed connections etc. It is not suprising that your router is scanned by Apple. I have an issue that my router cut me off the Google services as there were scans initiated from 8.8.8...
by Josephny
Sat Oct 05, 2024 1:32 am
Forum: General
Topic: Need a forward rule
Replies: 25
Views: 1662

Need a forward rule

I have the following config: FIOS -> RB5009 -> ax3 LAN is 192.168.2.0/24 RB5009 is 192.168.2.2 ax3 is 192.168.2.5 ax3 has its own DHCP server for its guest wifi clients at 10.0.0.0/24 that provides guests access only to the internet. It seems to work very well but I am discovering surprising log ent...
by Josephny
Sat Oct 05, 2024 12:08 am
Forum: General
Topic: Looking for instrction to isolate guest wifi networks
Replies: 12
Views: 629

Re: Looking for instrction to isolate guest wifi networks

While I'd love to master VLANS, it seems to be beyond me. @tangent solution works for me (thank you @tangent!). These are the config entries I used (I'm sure you'll want to customize to your environment): /interface wifi configuration add datapath.client-isolation=yes disabled=no name=guestcfg secur...
by Josephny
Sat Oct 05, 2024 12:03 am
Forum: General
Topic: ROS Scripting question
Replies: 6
Views: 472

Re: ROS Scripting question

Thanks Amm0. So (in simple language), the script can be run on a group of routers and: 1) Removes any wireguard interfaces, ip addresses, firewall mangle fules, ip routes, dhcp-servers, wireguard peers, interface lists, and routing rules that have "PROTON" in the comment 2) Adds new entrie...
by Josephny
Wed Oct 02, 2024 4:20 pm
Forum: General
Topic: ROS Scripting question
Replies: 6
Views: 472

Re: ROS Scripting question

The scripting, and the concepts behind it, are way beyond me, but I am curious what this script does?

What problem does it solve?
by Josephny
Wed Oct 02, 2024 1:06 pm
Forum: General
Topic: Dude syslog from 16 MT devices
Replies: 0
Views: 194

Dude syslog from 16 MT devices

I am finally at a place where monitoring the log outputs of 16 different MT devices across 8 different physical locations is reasonably efficient. The specific problem I was having is that I am also using Splunk with @jotne scripts that create a lot of log entries every 5 minutes and did not want to...
by Josephny
Sat Sep 28, 2024 11:46 am
Forum: Scripting
Topic: Add more logged detail to fetch?
Replies: 4
Views: 612

Re: Add more logged detail to fetch?

Wow, thank you Amm0. I now have a much better understanding of the log topics "fetch" and "raw" Unfortunately, I did not do a good job of communicating my goal. I maintain: /system logging set 0 topics=info,!script add action=remote prefix="192.168.2.2 " topics=info,!sc...
by Josephny
Sat Sep 28, 2024 12:22 am
Forum: Scripting
Topic: Add more logged detail to fetch?
Replies: 4
Views: 612

Re: Add more logged detail to fetch?

That loud silence....
by Josephny
Fri Sep 27, 2024 12:57 pm
Forum: Scripting
Topic: Add more logged detail to fetch?
Replies: 4
Views: 612

Add more logged detail to fetch?

I have logging set to !script but would like more details logged for a particular fetch command within the script. Here is the script: /system :local cdate [clock get date] :local yyyy [:pick $cdate 0 4] :local MM [:pick $cdate 5 7] :local dd [:pick $cdate 8 10] :local identitydate "$[identity ...
by Josephny
Mon Sep 23, 2024 2:49 pm
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

forget action dudelog, you don't need it. Somebody else could maybe help. I'm not going to write dedicated cookbook recipes, nor give exact and verified commands to copy/paste With Mikrotik, you better understand what you are doing, or get stuck every time something changes Expected you to do as I ...
by Josephny
Mon Sep 23, 2024 5:51 am
Forum: General
Topic: Networking Advice
Replies: 11
Views: 1103

Re: Networking Advice

I can imagine very few things as "static" as cameras, you have to go there, bring near the spot an ethernet connection, drill holes in the wall or ceiling, screw them tightly, they won't likely change. I agree that it makes sense to use static addresses for cameras, but more for the abili...
by Josephny
Mon Sep 23, 2024 1:47 am
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

Send the logs to DUDE with action "remote" as you do now send them to action "dudelog", forget action dudelog, you don't need it. Make another log entry for the logs now with topic DUDE, and send that to memory buffer, with action "memory" Topic "X" -> action...
by Josephny
Sun Sep 22, 2024 10:59 pm
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

Did you send anything to the syslog server (DUDE) ? Seems like you did not DUDE set to active? (well actually we do not use any other element of DUDE, only it's syslog function) Topic DUDE in the Sytem Logging rules should show the loggings sent to the syslog server (typical action for sending logg...
by Josephny
Sun Sep 22, 2024 12:16 pm
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

Having a hard time getting Dude's syslog filtering (using Syslog Rules) to work. Using /system/logging, without an entry that includes certain topics with an action of DUDELOG, the only entries in the dude log are dude-generated entries such as "syslog: Service ssh on 192.168.2.5 is now down (t...
by Josephny
Sun Sep 22, 2024 11:20 am
Forum: General
Topic: Too many winboxes
Replies: 11
Views: 1175

Re: Too many winboxes

What are you doing that you need to be actively making changes to that many routers at the same time?
Personally I don't think i have ever needed more than two open at the same time.
Improving, learning, experimenting, maintaining, monitoring -- that's the whole point.
by Josephny
Sun Sep 22, 2024 3:05 am
Forum: General
Topic: Too many winboxes
Replies: 11
Views: 1175

Re: Too many winboxes

Do like this

Image
Love it!
by Josephny
Sun Sep 22, 2024 1:30 am
Forum: General
Topic: Too many winboxes
Replies: 11
Views: 1175

Re: Too many winboxes

Not only for looking at logs.

How do you manage multiple MT devices if not by keeping multiple instances of Winbox open?

I'd prefer not to do something foolish, so kindly share how the more experienced people do it.
by Josephny
Sun Sep 22, 2024 1:11 am
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

Wow! That's wonderful! I need to try Dude again.

Thank you.
Screenshot 2024-09-21 180926.png
by Josephny
Sat Sep 21, 2024 8:58 pm
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

Or send your log to syslog [action=remote] (you can add a Prefix also) (eg DUDE has syslog functionality and Syslog Rules that filter on source and Regexp content) (this filtered syslog content can be logged as log topic "dude") I've played with the Dude, and I have Splunk set up, but I c...
by Josephny
Sat Sep 21, 2024 1:42 pm
Forum: General
Topic: Unlock different country in ax3
Replies: 2
Views: 607

Re: Unlock different country in ax3

Devices purchased in the U.S. or Canada cannot be unlocked to use WiFi regulations from other countries, otherwise FCC would not allow them to be sold on those markets.
Thanks.

That is disappointing and surprising.
by Josephny
Sat Sep 21, 2024 1:15 pm
Forum: General
Topic: Too many winboxes
Replies: 11
Views: 1175

Too many winboxes

How do you all deal with keeping winbox connections open to multiple devices?

There's got to be a better solution than how I do it:
toomanywinboxes.png
by Josephny
Sat Sep 21, 2024 12:58 pm
Forum: General
Topic: Networking Advice
Replies: 11
Views: 1103

Re: Networking Advice

You could have the two added cameras on a small, completely different, network, with only three devices in it, let's say 10.0.0.0/29 (ok, six addresses). Then you could use the Hex (or a hap Ax lite) placed near the Windows PC to route or netmap them to 192.168.5.x addresses, but of course this dev...
by Josephny
Sat Sep 21, 2024 12:51 pm
Forum: General
Topic: :find vs. find
Replies: 3
Views: 711

:find vs. find

Does anyone know of a good tutorial (preferably a video) that explains how to use the find command? I am particularly confused with these types of usage: :foreach i in=[/ip addr find] do={ and :foreach i in=[find] and /ip firewall address-list find list="fwaddlist" Thank you.
by Josephny
Sat Sep 21, 2024 12:31 pm
Forum: General
Topic: Unlock different country in ax3
Replies: 2
Views: 607

Unlock different country in ax3

I have an ax3 and can only select country Canada and United States. I would like to experiment with different power outputs and need to select a different country. How can I unlock it? (I am completely rural, so no chance of interfering with others, and have an amateur radio license for experimentin...
by Josephny
Sat Sep 21, 2024 10:08 am
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

It is indeed not possible to filter the messages on their way to be logged by contents, nor to tell the processes generating them (dhcp, wireless in your case) to filter them by some parameters of the object being processed. You can only filter them when watching the log.
Thank you.
by Josephny
Sat Sep 21, 2024 8:53 am
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Re: Exclude 1 MAC address from logging

Is this not possible?
by Josephny
Sat Sep 21, 2024 8:34 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

I get no data showing up for Wireguard errors. But, when I put the following in a search, I see many messages: index=mikrotik module=wireguard | eval host_id=host_name."-".host | fields _time host interface public_key error host_name host_id serial | eval data=serial | stats count by data ...
by Josephny
Fri Sep 20, 2024 11:58 pm
Forum: General
Topic: Networking Advice
Replies: 11
Views: 1103

Re: Networking Advice

Howmany megabit/sec is each camera doing ? 2Mbps ? 4Mbps ? 6Mbps In *theory* you can "split" your CAT6 cable into 2 sets of connection, but limited to 100Mbps !! However this *might* not be a problem is you have 4-6Mbps per cam and 12 cams < 100Mbps. The other 100Mbps "channel" ...
by Josephny
Fri Sep 20, 2024 11:52 pm
Forum: General
Topic: Networking Advice
Replies: 11
Views: 1103

Re: Networking Advice

A switch is L2. IP addresses are L3. For all it matters to the switch you could connect to one of its ports a device with *any* IP address, it is a connection on another level. The issue (or non issue) is only that the two networks won't be anymore physically separated, i.e. the two added cameras w...
by Josephny
Fri Sep 20, 2024 8:25 pm
Forum: General
Topic: Networking Advice
Replies: 11
Views: 1103

Networking Advice

I have a location as follows: Cable modem -> Ubiquiti UDM Pro -> (1) hex providing DNS, DHCP, and Wireguard server; (2) Home Assistant server; (3) Proxmox server; (4) Ubiquiti POE switch; (5) Windows PC. The Ubiquiti POE switch has a bunch of Ubiquiti access points connected to it. LAN uses 192.168....
by Josephny
Thu Sep 19, 2024 11:41 pm
Forum: Virtualization
Topic: Router OS 7 on UEFI
Replies: 65
Views: 13106

Re: Router OS 7 on UEFI

CHR is intended for deployment as a virtual machine - where you need a virtualized router you are familiar with rather than a bare Linux for production, or where you need to simulate some complicated setups, or where you just need a Mikrotik router running on a public IP for some training, which wa...
by Josephny
Thu Sep 19, 2024 9:41 pm
Forum: Virtualization
Topic: Router OS 7 on UEFI
Replies: 65
Views: 13106

Re: Router OS 7 on UEFI

Would some kind person explain to those of us far less knowledgeable what exactly is the situation or use-case for installing ROS in this way?

Do I understand correctly that we are talking about installing ROS on a PC (x86 architecture)?
by Josephny
Thu Sep 19, 2024 2:01 pm
Forum: General
Topic: How to get hostname from /ip arp
Replies: 7
Views: 5018

Re: How to get hostname from /ip arp

Does anyone know how to accomplish this?
by Josephny
Thu Sep 19, 2024 11:21 am
Forum: General
Topic: Exclude 1 MAC address from logging
Replies: 14
Views: 1194

Exclude 1 MAC address from logging

I have 1 iOt device (a fuel oil tank level monitor) that (I believe by design) connects and disconnects intentionally on a regular and frequent basis. My log fills up with connection and dhcp assignment messages. I like to keep logging these those types of events, but I would like to ignore this one...
by Josephny
Wed Sep 18, 2024 2:55 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

I am having a problem with the Netwatch reporting. For me the netwatch script do works fine. It should send a log line each time one device goes up and down. Since the script is very simple, it may be a config error or a bug. Try take som up/down manually and see in the logs. The problem is when mo...
by Josephny
Wed Sep 18, 2024 11:37 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

Ye, the wifi/wireless mess. Not sure how to handle that. One of my problem is that I do not have both types. But will try to look inn to it.
Any news on this?

Sure would be nice to have a table of all connections and disconnections showing the details of each client.

Thank you.
by Josephny
Tue Sep 17, 2024 9:22 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 69
Views: 13824

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

Yes you need a Linux server Debian based (Ubuntu recommended) I was confused about the docker install -- I thought it meant installation as a container on an MT device. I just tried the docker install and it failed as follows: Debian GNU/Linux 11 debian tty1 raw/b1fc4e0f283fd48d78861fa1a665fd1cb19b...
by Josephny
Tue Sep 17, 2024 12:22 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

I am having a problem with the Netwatch reporting. I have 8 Netwatch hosts that I am watching on an RB5009 running 7.14.2 If I cycle through disable/enable on each, only 3 are reflected in Splunk. These are the Netwatch entries: /tool netwatch add comment=Netwatch-8.8.4.4-Splunk disabled=no down-scr...
by Josephny
Mon Sep 16, 2024 9:20 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 69
Views: 13824

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

I was confused about the docker install -- I thought it meant installation as a container on an MT device. I just tried the docker install and it failed as follows: Debian GNU/Linux 11 debian tty1 raw/b1fc4e0f283fd48d78861fa1a665fd1cb19b734d/installer.sh)" rootsercontent.com/s265925/84f8fdc90c8...
by Josephny
Sat Sep 14, 2024 4:50 pm
Forum: 3rd party tools
Topic: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management
Replies: 69
Views: 13824

Re: Introducing MikroWizard: An Open-Source Solution for MikroTik Router Management

I am not well versed in linux. I tried to install this in a Debian LXC under Proxmox and failed. There are too many steps in the installation, and while I appreciate the detail and effort that went into creating the instructions, they did not work for me. I got as far as: psql -U your_username -d yo...
by Josephny
Fri Sep 13, 2024 11:20 pm
Forum: General
Topic: HIDDEN Wifi Networks
Replies: 9
Views: 801

Re: HIDDEN Wifi Networks

I can't say I understand why there is a need in my case for inventing mac addresses. I understand how ROS needs to invent mac addresses for virtual interfaces. I don't know how Ubiquitis are configuired for additional SSIDs on same radio, but the end result is the same as on Mikrotik. And that is m...
by Josephny
Fri Sep 13, 2024 3:49 pm
Forum: General
Topic: HIDDEN Wifi Networks
Replies: 9
Views: 801

Re: HIDDEN Wifi Networks

AA:16:9D is actually A8:16:9D and is a roku tv 1E:1E:E3 is actually 1C:1E:E3 and is also a roku TV 9E:05:D6 is actually 9C:05:D6 and is a U6+ AP The addresses on the left are all "locally administered addresses" (see wiki article on MAC addresses ) where the second most significant value ...
by Josephny
Fri Sep 13, 2024 1:46 pm
Forum: General
Topic: HIDDEN Wifi Networks
Replies: 9
Views: 801

Re: HIDDEN Wifi Networks

BSSID is usually MAC address of a particular radio. So if you somehow create an inventory of all (real and virtual) radios in your network, then you should be able to figure out which SSID is transmitted by which AP. I was able to find them. Most were falsely identifying the MAC addresses because o...
by Josephny
Fri Sep 13, 2024 1:37 pm
Forum: General
Topic: HIDDEN Wifi Networks
Replies: 9
Views: 801

Re: HIDDEN Wifi Networks

I ran a search within wireshark using only the first 3 octets: eth.addr[0:3] == aa:16:9d or eth.addr[0:3] == 9e:05:d6 or eth.addr[0:3] == 68:d7:9a or eth.addr[0:3] == f4:92:bf or eth.addr[0:3] == 6e:d7:9a or eth.addr[0:3] == 9c:05:d6 And see the packets. They are all coming from UI APs. I suspect th...
by Josephny
Fri Sep 13, 2024 1:15 pm
Forum: General
Topic: HIDDEN Wifi Networks
Replies: 9
Views: 801

HIDDEN Wifi Networks

I am trying to identify the HIDDEN wifi networks shown below. I tried Wireshark on the same PC that WinFi is running, searching by MAC address, but it did not capture any packets. Is there a way to get more details about these devices? Interestingly, this environment is all mine (very remote) -- the...
by Josephny
Fri Sep 13, 2024 12:18 pm
Forum: General
Topic: Suggestions to use a public /24
Replies: 0
Views: 514

Suggestions to use a public /24

This is not strictly Mikrotik related, but there are so many extremely knowledgable people here, I hope it's okay to ask. I have a public /24 network (issued by ARIN) under my control/ownership for many years now. I have a number of sites, one served by Verizon FIOS and the others by Spectrum Cable....
by Josephny
Wed Sep 11, 2024 1:14 pm
Forum: Scripting
Topic: /tool fetch vs. :tool fetch and /ping vs. :ping
Replies: 5
Views: 552

Re: /tool fetch vs. :tool fetch and /ping vs. :ping

Short: better use "/" just when you need to change actual path or call functions not directly on root. Just some examples: https://forum.mikrotik.com/viewtopic.php?t=177551 About spaces or / Since 7.x it's all than really done, and for other reasons, better use space for thing shared with...
by Josephny
Wed Sep 11, 2024 11:58 am
Forum: Beginner Basics
Topic: Network traffic gets slower, when adding vlans
Replies: 27
Views: 1680

Re: Network traffic gets slower, when adding vlans

I think I will add this to my Mikrotik Club Rules :wink: :
1) You do not use VLAN1
2) You DO NOT use VLAN1
3) You do not use detect internet
4)...
I want to join!

I think I've successfully passed the hazing period....
by Josephny
Wed Sep 11, 2024 11:38 am
Forum: Scripting
Topic: /tool fetch vs. :tool fetch and /ping vs. :ping
Replies: 5
Views: 552

Re: /tool fetch vs. :tool fetch and /ping vs. :ping

Thank you OP for asking this quesiton, and thank you @ammo and @rextended for the answers! I hope it would not be considered hijacking the thread if I added a related question: When would you use a slash ("/") vs. a space (" ")? For example: /tool ping 1.1.1.1 vs. /tool/ping 1.1....
by Josephny
Mon Sep 09, 2024 11:20 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

I just discovered that some of my wifi devices are populating Splunk with the wifi connections and some aren't. It seems the "/interface/wireless" vs. "/interface/wifi" is the issue. If we take the "wireless" section of your script and replace the 2 occurences of the wo...
by Josephny
Mon Sep 09, 2024 11:14 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

Script updated to 5.7 Fixes when a pool is used in more than one DHCP server. Since the pool is the same for one or more DHCP server we only take the first find. Change from: :local dname [/ip dhcp-server get [find where address-pool=$poolname] name] to: :local dname [/ip dhcp-server get [:pick [fi...
by Josephny
Mon Sep 09, 2024 11:12 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

@Josephny To start over/delete the device db, or just edit it, install "Splunk App for Lookup Editing". Open it and find device_kvstore. Here you can mark all and just remove rows or edit them. Thank you. I will look into this. In the meantime, I think the scheduled reindexing solved the ...
by Josephny
Sun Sep 08, 2024 5:46 pm
Forum: General
Topic: www-ssl secure?
Replies: 5
Views: 641

Re: www-ssl secure?

This requires /ip/services/www-ssl to be enabled. Is there any downside? Security risk? As with every ROS service, if enabled it's important to protect it from being available too widely. And that's achieved using firewall. Default firewall allows access to (all) router services from LAN. If firewa...
by Josephny
Sun Sep 08, 2024 3:34 pm
Forum: General
Topic: www-ssl secure?
Replies: 5
Views: 641

www-ssl secure?

I just discovered that I can run a batch file (Windows) to call a series of powershell scripts to remotely run ROS scripts -- and am loving it! This requires /ip/services/www-ssl to be enabled. Is there any downside? Security risk? FYI, this is the thread that helped me: https://forum.mikrotik.com/v...
by Josephny
Sun Sep 08, 2024 12:14 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

I have a script scheduled to run and it generated a log entry that I like to be able to see in the logs. It initially logged to "info" but keeping logging enabled to memory for info produced too many log entries from the Splunk script. I changed my script to log to "warning" just...
by Josephny
Sat Sep 07, 2024 12:50 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

Also had to comment out this section of the script to eliminate the error: # Get detailed command history RouterOS >= v7 # ---------------------------------- #:if ($train > 6 and $CmdHistory) do={ # :global cmd # :local f 0 # :foreach i in=[/system history find] do={ # :if ($i = $cmd) do={ :set f 1 ...
by Josephny
Sat Sep 07, 2024 12:23 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

Using an ax3 running 15.3 and the script fails to run with this error: script error: error - contact MikroTik support and send a supout file (10) I traced it to this section of the script causing the error: # Test if pools is used in DHCP or VPN and show leases used # :local dname [/ip dhcp-server f...
by Josephny
Sat Sep 07, 2024 2:27 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 408
Views: 149987

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊

Just getting Splunk set up and I think I messed something up.

I have over a dozen devices and yet only 2 devices are showing up, but repeated/duplicated.

Is there a way to tell Splunk to completely rebuild the database? Or empty it and start over?

Thanks

Screenshot 2024-09-06 192557.png
by Josephny
Sat Sep 07, 2024 12:21 am
Forum: General
Topic: Convert script to create in terminal
Replies: 4
Views: 544

Re: Convert script to create in terminal

You can also use "/system/script export where name=XXXX" to get the "escaped form" of any script (and then cut-and-paste that as needed).
Good to know, thanks :) .
That is super useful!
by Josephny
Fri Sep 06, 2024 8:06 pm
Forum: General
Topic: Convert script to create in terminal
Replies: 4
Views: 544

Re: Convert script to create in terminal

I think I solved my problem. In order to use single (or double) quotation marks we need an "escape" character. The following, for example, works: \n:local ntpstatus \"\"\r\ And, the following code entered in a terminal creates the script. One trick is the use of \n and \r\ on eac...
by Josephny
Fri Sep 06, 2024 10:19 am
Forum: General
Topic: Convert script to create in terminal
Replies: 4
Views: 544

Convert script to create in terminal

Does anyone have a solution to take a script and convert it so it can be be added in a terminal window? For example, if I have the following script named "script1": # Get NTP status # ---------------------------------- :local ntpstatus "" :if ([:len [/system package find where !d...
by Josephny
Thu Sep 05, 2024 9:51 pm
Forum: General
Topic: lo iface in LAN list
Replies: 11
Views: 780

Re: lo iface in LAN list

Got it.

I re-enabled ND, which I do indeed like.

And I will ignore the !LAN FW log.

Thank you!
by Josephny
Thu Sep 05, 2024 8:02 pm
Forum: General
Topic: lo iface in LAN list
Replies: 11
Views: 780

Re: lo iface in LAN list

If I remove lo from LAN list, the firewall log captures the same message. Running Packet Sniffer with filter set to interface=lo, I see that the packet is: Source: 127.0.0.1 Direction: tx Dst. mac: FF:FF:FF:FF:FF:FF Src port: 5678 Dst port: 5678 Protocol: 2048 IP Protocol: UDP I see that 5678 is the...
by Josephny
Thu Sep 05, 2024 12:57 pm
Forum: General
Topic: lo iface in LAN list
Replies: 11
Views: 780

Re: lo iface in LAN list

You didn't specify for which device this is but for most there should already be an input accept for 127.0.0.1 from default firewall. That covers lo. In case you removed that rule, I suggest you put it back. It's an ax3, but it's just my testing/learning/modeling MT device. I do indeed have the def...
by Josephny
Thu Sep 05, 2024 12:51 pm
Forum: General
Topic: lo iface in LAN list
Replies: 11
Views: 780

Re: lo iface in LAN list

For me it doesn't look ok, because lo doesn't actually represent LAN. Eventually you could have some case when you have to have it separate. So my suggestion is to make an explicit accept rule for lo interface and place it before drop rule: /ip firewall filter add action=accept in-interface=lo I ca...
by Josephny
Thu Sep 05, 2024 12:31 pm
Forum: General
Topic: lo iface in LAN list
Replies: 11
Views: 780

lo iface in LAN list

I have this drop all !LAN input: /ip firewall add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN log=yes log-prefix=not-coming-from-LAN But packets from the "lo" interface was getting dropped. So I put "lo" in the LAN inte...
by Josephny
Wed Sep 04, 2024 5:19 pm
Forum: Useful user articles
Topic: Isolated Guest WiFi Sans VLANs
Replies: 15
Views: 5503

Re: Isolated Guest WiFi Sans VLANs

I was wondering if you had any updates, refinements, suggestions, or comments on this solution? It's still working here, as originally presented. Were you hoping for some change, or just confirming the article's published history , that nothing has changed in half a year? I was not hoping for any s...
by Josephny
Wed Sep 04, 2024 2:22 pm
Forum: Useful user articles
Topic: Isolated Guest WiFi Sans VLANs
Replies: 15
Views: 5503

Re: Isolated Guest WiFi Sans VLANs

I hope it is okay to resurect this old thread. I, too, have struggled with VLANS (and have been unsuccesful) and have wished for a non-VLAN way to create guest wifi networks. I read your very well thought out and well written article here: https://tangentsoft.com/mikrotik/wiki?name=Isolated%20Guest%...
by Josephny
Mon Sep 02, 2024 6:57 pm
Forum: General
Topic: VLAN on ax3 (another attempt)
Replies: 0
Views: 622

VLAN on ax3 (another attempt)

I failed and put on hold my attempts to understand and learn VLANS, but am now trying again. Yes: I did read (about 100 times) @pcunite's wonderful thread. I have an extra hapAx3 that I just set up, wired by ethernet to a minipc that is connected via wifi to my main network (so I have internet acces...
by Josephny
Wed Aug 28, 2024 12:17 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

I don't know is GRE, IPIP, or L2TP would be an alternative to EoIP that would satisfy the needs above, or if there is a better alternative (something without the unnecessary broadcast/multicast traffic problem). I'd suggest you study a bit of the networking basics, like the meaning of L2 and L3 in ...
by Josephny
Wed Aug 28, 2024 12:15 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

There are some users "advertising" the solutions they made for MikroTik monitoring, but of course it is always a bit different from what you would have wanted. As a programmer, I wrote these things using Perl and a Perl Library for MikroTik API use. But of course, Perl is already consider...
by Josephny
Tue Aug 27, 2024 6:04 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

For that function I use API to retrieve things like ARP table, DHCP leases. On a central Linux system I run scheduled jobs that connect to all routers in the network to collect this information and store it in a database, and have a webpage where I get a list of all IP addresses, MAC addresses, hos...
by Josephny
Tue Aug 27, 2024 4:24 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

Sure it is convenient that EoIP transports L2 and thus it may be attractive that routers appear in the Neighbors list or in RoMON, but you should be aware that EoIP is still dependent on IP and so when you do something that would make your router inaccessible in an IP network, would probably still ...
by Josephny
Tue Aug 27, 2024 4:19 pm
Forum: General
Topic: Can't access a single website
Replies: 12
Views: 945

Re: Can't access a single website

That's where selective thinking comes into play - the change (addition of the first EoIP interface to the bridge) was made so long before the issue with access to Yahoo got spotted that the relationship did not pop up immediately, and when thinking back, it was "just adding EoIP to the bridge,...
by Josephny
Tue Aug 27, 2024 4:17 pm
Forum: General
Topic: Can't access a single website
Replies: 12
Views: 945

Re: Can't access a single website

Still, doesn't explain the "ALL of SUDDEN". If it was working all this time with EoIP interfaces, what flipped the switch so to speak ??? sindy knows about another thread of mine where I was asking about (and therefore playing with) EoIP connections, so he correctly deduced that changes w...
by Josephny
Tue Aug 27, 2024 1:55 am
Forum: General
Topic: Can't access a single website
Replies: 12
Views: 945

Re: Can't access a single website

Mysteries like this one often happen if the MTU in your network becomes smaller than the "usual" 1500 for some reason and PMTUD (Path MTU Discovery) is broken (google up "criminally braindead ISP" to learn the details) on the path between the client and the server. So knowing ab...
by Josephny
Mon Aug 26, 2024 9:52 pm
Forum: General
Topic: Can't access a single website
Replies: 12
Views: 945

Re: Can't access a single website

I even changed the DNS on the PCs to use 1.1.1.1 in case it was a DNS problem.
did it work?
No.

Nothing has fixed this problem.

And I've checked dozens of web sites and they all work except yahoo.com and finance.yahoo.com
by Josephny
Mon Aug 26, 2024 9:20 pm
Forum: General
Topic: Can't access a single website
Replies: 12
Views: 945

Can't access a single website

I'm pulling my hair out here. I have an RB5009 connected to Verizon FIOS internet for years now and it's been working great. All of a sudden, none of the computers on the LAN can access yahoo.com or finance.yahoo.com in any web browser. This includes hardwired (cat6) computers to the 5009 as well as...
by Josephny
Sun Aug 25, 2024 2:28 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

Advice? You can use EoIP just like any other L2 ("ethernet-like") interface without adding it to a bridge. And as an alternative (to Wireguard) way to access devices, there is also SSTP, L2TP/IPsec*, IPIP/IPsec* or even bare IPsec*... those marked with an asterisk can be set up using a pr...
by Josephny
Sun Aug 25, 2024 2:17 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

I obviously don't have a firm grasp of what is going on, but I am concerned about this unnecessary DHCP traffic over the Wireguard and/or EoIP connections. That is why I am concerned about your network design involving many EoIP connections in a bridge. This DHCP issue is only the first one you not...
by Josephny
Sun Aug 25, 2024 1:52 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

I created 2 bridge filters: One INPUT and one FORWARD to block ports 67-68 on the interface list DHCPdisabled. It appears that the DHCP servers from each location (with MT device at each location) broadcasts (i.e., 255.255.255.255) on the bridge the DHCP requests that come into it. The bridge filter...
by Josephny
Sat Aug 24, 2024 3:33 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

The bridge filter also uses chains, so if you block the server responses in forward , the Mikrotik itself will receive them, whilst other devices on the same bridge will not. Does this mean that using a bridge filter will not block traffic to/from ports 67/68 getting to/from the Mikrotik device? I ...
by Josephny
Sat Aug 24, 2024 3:16 pm
Forum: General
Topic: List for interface type
Replies: 2
Views: 435

Re: List for interface type

Wow, that is powerful.

I'm still struggling with the DHCP ROGUE server detected, so I need to put this on the back burner for now.

You are, as always, a generous fountain of help.
by Josephny
Sat Aug 24, 2024 2:28 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

Hmm... It seems the filter is working: forward: in:eoip-tunnel-to-212 out:ether4, connection-state:invalid src-mac 18:fd:xx:xx:xx:xx, dst-mac ff:ff:ff:ff:ff:ff, eth-proto 0800, UDP, 192.168.2.2:67->255.255.255.255:68, len 328 But I still get a log entry from the DHCP ALERT: dhcp alert on bridge: dis...
by Josephny
Sat Aug 24, 2024 12:04 pm
Forum: General
Topic: List for interface type
Replies: 2
Views: 435

List for interface type

Is there a way to add all eoip interfaces to a bridge without specifying each interface name? That is, is there a way to add an interfaces to a bridge by type? I have multiple eoip interfaces, and would like to add them to a bridge and add them to an interface list. This is what I have now: /interfa...
by Josephny
Sat Aug 24, 2024 12:01 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

Make an interface list for dhcp-enabled or dhcp-disabled interfaces and create an appropriate rule for the specified interface list (rule template above).
That works -- thank you.
by Josephny
Fri Aug 23, 2024 4:25 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Re: Firewall drop DHCP across EoIP

/interface bridge filter add action=drop chain=forward comment=dhcp dst-port=67-68 ip-protocol=udp mac-protocol=ip Use bridge filter. Also you may try to use a specific in/out interface in this rule. My concern is that the bridge has many interfaces, and I need to block DHCP on only some of which. ...
by Josephny
Fri Aug 23, 2024 2:44 pm
Forum: General
Topic: Firewall drop DHCP across EoIP
Replies: 27
Views: 1710

Firewall drop DHCP across EoIP

Does anyone know the best way to drop DHCP requests and offerings across an EoIP connection?

I assume a firewall rule. If so, by port? Or is there a better way?

I have a bunch of EoIP interfaces, and they are all members of the bridge.

Thanks.
by Josephny
Thu Aug 22, 2024 3:07 pm
Forum: General
Topic: Winbox neighbors with EoIP
Replies: 2
Views: 357

Re: Winbox neighbors with EoIP

Should be doable if you enable neighbor discovery for eoip in IP->Neighbors and add your eoip to bridge
Perfect!

neighbor discovery was already enabled, but I didn't have the eoip interface in the bridge.

Thank you very much!
by Josephny
Thu Aug 22, 2024 2:06 pm
Forum: General
Topic: Winbox neighbors with EoIP
Replies: 2
Views: 357

Winbox neighbors with EoIP

I'm sure I have huge gaps in my understanding, so hopefully you good folks could help. I have a number of physical locations each with an MT device and all devices are connected with both Wireguard and EoIP. When running Winbox on a Windows PC at one location, I can see in Neighbors the local MT dev...
by Josephny
Wed Aug 21, 2024 9:28 pm
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Re: Fetch returns "failure: Unexpected payload received"

I figured it out: "http-auth-scheme=digest" made it work. The following command works: :tool fetch http-method=get user="admin" password="<my_password>" url="http://192.168.0.144/relay/0?turn=on" http-header-field="Content-Type: application/x-www-form-url...
by Josephny
Wed Aug 21, 2024 5:39 pm
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Re: Fetch returns "failure: Unexpected payload received"

In a Windows command prompt, curl does not work with the Shelly authentication enabled. It works fine with the Shelly authentication disabled. Post the exact CURL command you are using. No error provided when it fails? Under Windows, try running. curl -v -u "user" http://192.168.0.144/.. ...
by Josephny
Wed Aug 21, 2024 4:19 pm
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Re: Fetch returns "failure: Unexpected payload received"

In a Windows command prompt, curl does not work with the Shelly authentication enabled.

It works fine with the Shelly authentication disabled.
by Josephny
Wed Aug 21, 2024 3:45 pm
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Re: Fetch returns "failure: Unexpected payload received"

The user:password actually works from a browser. Very likely because the browser itself manages to encrypt/encode/hash/whatever the username/password before sending it to the Shelly. https://reqbin.com/req/c-fkj7kdqi/curl-request-with-credentials Try with curl: curl http://192.168.0.144 --user &quo...
by Josephny
Wed Aug 21, 2024 2:57 pm
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Re: Fetch returns "failure: Unexpected payload received"

The user:password actually works from a browser. This is the capture: GET /relay/0?turn=on HTTP/1.1 Host: 192.168.0.144 Connection: keep-alive Cache-Control: max-age=0 Authorization: Digest username="admin", realm="shellyplus1-b8d61a886a74", nonce="1724241354", uri=&quo...
by Josephny
Wed Aug 21, 2024 2:49 pm
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Re: Fetch returns "failure: Unexpected payload received"

What I had in mind was to capture (sniff) the communication with Shelly when the request is sent from the browser and when it is sent from the Tik and use Wireshark to "find 10 differences" between the two cases. "Plaintext" means that the communication is not encrypted (you use...
by Josephny
Wed Aug 21, 2024 12:18 pm
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Re: Fetch returns "failure: Unexpected payload received"

I actually tried it without content-type and the result was the same.

Not sure what I should be looking for in the Shelly’s response.

As for plain text, I tried using http://user:pass@<ip> and got a 401 error
by Josephny
Wed Aug 21, 2024 11:40 am
Forum: General
Topic: Fetch returns "failure: Unexpected payload received"
Replies: 14
Views: 906

Fetch returns "failure: Unexpected payload received"

I am trying to using Netwatch to call a script that will turn a Shelly relay off and then back on when internet connectivity is lost. This will power-cycle a cable modem. The Shelly 1 uses an http-post with an ON or an OFF: http://192.168.0.144/relay/0?turn=off When issued from a web browser, it ret...
by Josephny
Tue Apr 16, 2024 2:02 pm
Forum: General
Topic: Watchdog log entries
Replies: 4
Views: 951

Re: Watchdog log entries

Any way to create a log entry that persists a reboot when watchdog is about to reboot?

Or send an email with date/time?
by Josephny
Tue Apr 16, 2024 2:01 pm
Forum: Scripting
Topic: Netwatch down script can't email
Replies: 4
Views: 1550

Re: Netwatch down script can't email

I'm batting around .500 (my usual), which in baseball is fantastic, but in programming, not so much.... Here's my down script: /system :local cdate [clock get date] :local yyyy [:pick $cdate 0 4] :local MM [:pick $cdate 5 7] :local dd [:pick $cdate 8 10] :local identitydate "$[identity get name...
by Josephny
Sat Apr 13, 2024 12:06 am
Forum: Scripting
Topic: Netwatch down script can't email
Replies: 4
Views: 1550

Re: Netwatch down script can't email

Send email on status up instead of on status down.
When go down memorize the datetime in a global variable,
when up send mail with the global variable value
Fantastic solution!

Will attempt to create.

Thank you.
by Josephny
Sat Apr 13, 2024 12:05 am
Forum: General
Topic: Watchdog log entries
Replies: 4
Views: 951

Re: Watchdog log entries

No solutions?
by Josephny
Fri Apr 12, 2024 12:46 pm
Forum: General
Topic: Watchdog log entries
Replies: 4
Views: 951

Watchdog log entries

I have Watchdog set up as shown below. I notice that when a Watchdown timeout occurs, the MT device reboots but (1) I don't get a supout emailed and (2) I get the following in the log upon booting up: System rebooted because of ping watchdog timeout How can I either get a log entry that persists a r...
by Josephny
Fri Apr 12, 2024 12:39 pm
Forum: Scripting
Topic: Netwatch down script can't email
Replies: 4
Views: 1550

Netwatch down script can't email

I use the script below and I notice that when Netwatch runs it's "Down" script and tries to send the notification email, it fails due to a "timeout." I understand that it can't send an email if the connection is down, but I'm wondering what the solution is for getting notified (v...
by Josephny
Wed Apr 10, 2024 1:35 pm
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1786

Re: BTH basic question

The technical benefit was well explained above, but another benefit (does not apply in your case) is that BTH is easy to set up, if you do not know how to configure Wireguard and would like to avoid learning RouterOS. BTH app does it in a few steps, all you need is the router password. No need to c...
by Josephny
Wed Apr 10, 2024 10:59 am
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1786

Re: BTH basic question

Thank you guys!
by Josephny
Wed Apr 10, 2024 2:35 am
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1786

Re: BTH basic question

I think I understand. In all locations I have ever worked at, there has been a public IP -- FIOS, Cable, cell phone. Do you mean an environment where access to the WAN router is not available, so that ports cannot be opened or forwarded? This sounds like desktop remote control solutions where the ap...
by Josephny
Wed Apr 10, 2024 2:12 am
Forum: General
Topic: BTH basic question
Replies: 19
Views: 1786

BTH basic question

Can someone please explain (in simple terms) if there is any benefit or reason one would set up BTH is one already has a Wireguard vpn set up?

Thanks.
by Josephny
Sun Apr 07, 2024 8:26 pm
Forum: Scripting
Topic: Script not working
Replies: 5
Views: 1252

Re: Script not working

*) console - replace reserved characters in file and script names with underscores;
Wow, as if the proper usage of "$" and "[" weren't complicated enough in filenames/variable-names.
by Josephny
Sun Apr 07, 2024 8:11 pm
Forum: Scripting
Topic: Script not working
Replies: 5
Views: 1252

Re: Script not working

I don't know what sanitize means in this context?

I'm sure there was no version that would have given be a health problem (except maybe psychological problems).
by Josephny
Sun Apr 07, 2024 6:47 pm
Forum: Scripting
Topic: Script not working
Replies: 5
Views: 1252

Script not working

I just cannot get this to work. identify of MT device is: 125-hAP The script creates the file: _125-hAP_2024-04-07_.txt Including the underline characters at the beginning and end of the file But the fetch command cannot find the file. /system :local cdate [clock get date] :local yyyy [:pick $cdate ...
by Josephny
Sat Apr 06, 2024 3:22 am
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1210

Re: Firewall/Routing Question

Because if you have lots of users, its easier to give them and have them remember a name than a number. I do understand that it is easier to remember BlueIris:81 than 192.168.0.1:81; but he doesn't want this accessible from the internet, so I don't see any advantage to using the public ip. So why n...
by Josephny
Sat Apr 06, 2024 3:18 am
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1210

Re: Firewall/Routing Question

Is there a way to make it so that I can browse to A.dyndns.org:81 There are many things that can be done, but I have to ask; what is the advantage of accessing it via the "external" A.dyndns.org ip address? To me, this just seems like added complexity with no real benefit. That's an easy ...
by Josephny
Fri Apr 05, 2024 4:15 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1210

Re: Firewall/Routing Question

Trying to understand, but it will take time. In the meantime, I'm using these 2 rules. Port 81 points to the internal to LAN A BI server at .101 Port 8123 points to the internal to LAN A Home Assistant server at .162 /ip firewall nat add action=dst-nat chain=dstnat comment=a.dyndns.org:81 dst-addres...
by Josephny
Fri Apr 05, 2024 2:12 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1210

Re: Firewall/Routing Question

Is there a way to make it so that I can browse to A.dyndns.org:81 It may be possible to construct a DST-NAT combination on router of site B which would work most of time ... except in time periods after change of A public IP address (because A.dyndns.org has to be updated and TTL of the old record ...
by Josephny
Thu Apr 04, 2024 5:43 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1210

Re: Firewall/Routing Question

Thank you for your help. Your explanation is not complete or maybe just lacks some clarity. Are you saying that a. Users at Device B, via wireguard, successfully access the Iris Server on the LAN at Device A? Note: Assuming the users simply put in their APP or browser 192.168.0.1 : 81 and the connec...
by Josephny
Thu Apr 04, 2024 3:04 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1210

Firewall/Routing Question

I have multiple locations, but for the purpose of this question, let's just call them A and B. A and B get a public IP from their upstream provider and we use dyndns.org for dynamic DNS. A's LAN side is at 192.168.0.0/24 B's LAN side is at 192.168.2.0/24 A and B have a nice reliable Wireguard and Eo...
by Josephny
Wed Apr 03, 2024 1:11 pm
Forum: General
Topic: EoIP Log Entries explanation requested
Replies: 2
Views: 341

Re: EoIP Log Entries explanation requested

Great, thank you.

Now I've got to go and google IPIP -- so I can have a clue (;-)
by Josephny
Wed Apr 03, 2024 1:06 pm
Forum: General
Topic: Watchdog smtp.gmail.com
Replies: 1
Views: 352

Re: Watchdog smtp.gmail.com

Just read the manual section for the SMTP Server:

"send-smtp-server (string; Default: )
SMTP server address to send the support output file through. If not set, the value set in /tool e-mail is used."

Will try it with empty field for "smtp-server"
by Josephny
Wed Apr 03, 2024 1:00 pm
Forum: General
Topic: EoIP Log Entries explanation requested
Replies: 2
Views: 341

EoIP Log Entries explanation requested

Having recently set up EoIP, I'm curious about the regular log entries (below). Is this normal? Should I change the timeout/retries in the EoIP tunnel configs (they are now the default 10 seconds/10 retries)? 04-02 21:21:03 ipsec,info ISAKMP-SA dying 100.38.xxx.xxx[500]-67.245.xxx.xxx[500] spi:xxxxx...
by Josephny
Wed Apr 03, 2024 12:45 pm
Forum: General
Topic: Watchdog smtp.gmail.com
Replies: 1
Views: 352

Watchdog smtp.gmail.com

I have watchdog set up and it appears to be working except for the "auto send supout" I'm guessing gmail doesn't like me (even though I'm a google workspace (formerly google apps) subscriber). /system watchdog set auto-send-supout=yes ping-start-after-boot=10m \ ping-timeout=10m send-email...
by Josephny
Tue Apr 02, 2024 11:39 pm
Forum: General
Topic: Wireguard DNS re-resolution script
Replies: 4
Views: 727

Re: Wireguard DNS re-resolution script

So I don't need the script at all, right?
by Josephny
Tue Apr 02, 2024 1:37 pm
Forum: General
Topic: Wireguard DNS re-resolution script
Replies: 4
Views: 727

Wireguard DNS re-resolution script

I've had the script below (reload the endpoint's DNS) set in scheduler to run every 30 minutes. Lately I've noticed that the "if...do" is triggered (i.e., the "if" resolves to "yes") every time the script is run, despite $LastHandshake being less than 5m. Pretty sure $L...
by Josephny
Sat Mar 30, 2024 10:37 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

I'm an idiot.

I'm scouring the exports to compare 355 and 255 MT device's configs and I see that the GRE FW rule was set to FORWARD (instead of INPUT).

Sorry for the false alarm.
by Josephny
Sat Mar 30, 2024 9:55 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

More info:

On the 355 device, under IP | IPSEC | ACTIVE PEERS, both tunnels show as ESTABLISHED, with both tx and rx bytes and packets.

If I'm reading this correctly, the IPsec tunnels are established between the 355 device and the 212 (and 371) device(s) but the EoIP tunnel is not.

Any ideas?
by Josephny
Sat Mar 30, 2024 9:39 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

Still working on this, but no success yet. I even tried removing the IPsec secret on both sides of the EoIP tunnel and still could not get a Running status on the 355 side. Does that change the analysis about the UDM not allowing IPsec through? I don't see any differences in between the UDM at 255 a...
by Josephny
Sat Mar 30, 2024 7:46 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

I just set things up here so the router I call 212 has an EoIP connection to a bunch of others (76, 125, 629, 371, 255, 355). All but 255 and 355 are MT devices and work great. 255 and 355 are Ubiquiti UDM-Pro routers with hEX's behind them (essentially providing WG services; and now EoIP connectivi...
by Josephny
Sat Mar 30, 2024 7:28 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

Note that when I added an ipsec key, I was forced to turn off "Allow Fast Path"
Which is okay, you're really just using it for management. But all encryption has to flow through the CPU anyway.
Makes perfect sense -- thanks.
by Josephny
Sat Mar 30, 2024 5:39 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

Good thing for me that you guys pointed out the ipsec entry.

I had left it empty.

Note that when I added an ipsec key, I was forced to turn off "Allow Fast Path"
by Josephny
Sat Mar 30, 2024 4:45 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

I like the idea of EoIP because of the advantages of layer 2 connectivity to all devices, but I am concerned about traffic or taxing the MT devices with firewall rules. The idea is EoIP just carries RoMON protocol. If EoIP is NOT bridge to anything, and each end has a unique IP address in same subn...
by Josephny
Sat Mar 30, 2024 4:18 pm
Forum: General
Topic: Watchdog, or alternative?
Replies: 8
Views: 844

Re: Watchdog, or alternative?

My situation does not use LTE. Mine are Verizon FIOS and Charter Spectrum cable connections. I'd really like to play around with LTE connectivity, but I could never get a clear answer that there is a straightforward way to get this done here in the USA. But now I'm confused about how the ping-timeou...
by Josephny
Sat Mar 30, 2024 3:48 pm
Forum: General
Topic: Watchdog, or alternative?
Replies: 8
Views: 844

Re: Watchdog, or alternative?

LOL! Yes indeed, a UPS is a good thing.

The problem is that I don't know what exactly is going on.

I just had someone go again this morning to power cycle the entire network environment, and now it is up and running.

Just trying to add as many layers of protection as possible.

Disagree?
by Josephny
Sat Mar 30, 2024 3:23 pm
Forum: General
Topic: Watchdog, or alternative?
Replies: 8
Views: 844

Re: Watchdog, or alternative?

Does this look good: /system watchdog set auto-send-supout=yes ping-start-after-boot=10m ping-timeout=2m send-email-from=joseph@xxxxx.com \ send-email-to=joseph@xxxx.com send-smtp-server=smtp.gmail.com watch-address=1.1.1.1 Do I understand correctly that by including the watch-address I have enabled...
by Josephny
Sat Mar 30, 2024 12:43 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

SSTP sounds very interesting. Renewing a certificate every 3 months does like a recipe for disaster. Any downside to using SSTP without a cert? I like the idea of EoIP because of the advantages of layer 2 connectivity to all devices, but I am concerned about traffic or taxing the MT devices with fir...
by Josephny
Fri Mar 29, 2024 8:20 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

It sounds like a great.

I’m concerned (don’t know if justified) that doing this will create one large broadcast lan. I’m sure there are good ways to prevent all traffic on all eoip-connected devices from hearing each other. Something better than a firewall drop rule.
by Josephny
Fri Mar 29, 2024 7:12 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

So the dyndns address check out to the current WANIP of the remote device and you can ping the device but WG does not come up?? Did you make any changes to the config prior to losing connectivity as there is no clear reason I can think of that would cause loss of connectivity. Well, I can’t be sure...
by Josephny
Fri Mar 29, 2024 7:09 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

I have been had on my to-do list to play with EoIP for a while.

Can EoIP be set up between MT devices independently of Wireguard?

I ask because the WG tunnel is not up to that device, so if EoIP relied on it, EoIP would not work.

I don’t know how to set it up.
by Josephny
Fri Mar 29, 2024 6:54 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

Re: How insecure of 8791?

Telnet is not enabled on any of my devices. The only way to access any of my devices is by being on the LAN or connected via WG. Many of my devices are hEX, so not ARM. I had someone go and cycle the power, and I know it comes back up because I have a netwatch script that emails when connectivity to...
by Josephny
Fri Mar 29, 2024 6:14 pm
Forum: General
Topic: How insecure of 8791?
Replies: 39
Views: 2358

How insecure of 8791?

I have (yet another) location where the MT device is unresponsive. I lost Wireguard connectivity, but I can ping it. No response to telnet, ssh or mac telnet. I understand it is not advised, and there has been a (warranted) scare of two, but how insecure is leaving port 8291 (Winbox) open to the Int...
by Josephny
Thu Mar 28, 2024 4:12 pm
Forum: General
Topic: Watchdog, or alternative?
Replies: 8
Views: 844

Re: Watchdog, or alternative?

Great, I'll do exactly that.

Thank you.
by Josephny
Thu Mar 28, 2024 11:53 am
Forum: General
Topic: Watchdog, or alternative?
Replies: 8
Views: 844

Watchdog, or alternative?

I have one location that occasionally loses power and (I don't know why but) when the power is restored, connectivity to the MT device is not. It requires physically going to the location and power cycling the MT device. I was thinking of using Watchdog to have the device reboot itself. Maybe use a ...
by Josephny
Wed Mar 27, 2024 9:50 pm
Forum: General
Topic: AX3 Wifi confusion
Replies: 9
Views: 1180

Re: AX3 Wifi confusion

In the heart of an incredibly RF and people dense city, in a huge apartment building, I don't have a choice but to use DFS channels. Well, then set this to skip-dfs-channels=disabled ... only then will your ax3 try to use DFS channels (note the wording of property, it includes "skip"). Wo...
by Josephny
Wed Mar 27, 2024 2:05 pm
Forum: General
Topic: AX3 Wifi confusion
Replies: 9
Views: 1180

Re: AX3 Wifi confusion

well, your issue is all about "skip-dfs-channels=all". No experience with Russia, but maybe they don't have DFS regulation and that's why it works for you. In the heart of an incredibly RF and people dense city, in a huge apartment building, I don't have a choice but to use DFS channels. ...
by Josephny
Wed Mar 27, 2024 10:55 am
Forum: General
Topic: AX3 Wifi confusion
Replies: 9
Views: 1180

Re: AX3 Wifi confusion

Sorry about not identifying the error. I started a new thread because it was a new topic that the original thread morphed into, from here: https://forum.mikrotik.com/viewtopic.php?p=1065645#p1065645 The error is: "NO SUPPORTED CHANNELS" Upon further playing around, I discovered that if I c...
by Josephny
Wed Mar 27, 2024 2:06 am
Forum: General
Topic: AX3 Wifi confusion
Replies: 9
Views: 1180

AX3 Wifi confusion

I've moved on from the bottleneck issue (other thread) -- which means I can't stop focusing on the wifi channel issue. I have reset the radio provisioning and recreated the wifi interface for 5ghz. Tried 5Ghz N, AC, and AX Left the Channel Width empty. And tried all frequencies from 5160 to 5885 in ...
by Josephny
Sun Mar 24, 2024 5:32 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

The following work: 5180 5745 The following result in the "no supported channels" error: 5260 5500 5580 5660 5825 Problem is that 5180 is already busy 5745 is less busy than 5180, but still not empty. Yes, this is not addressing the wired throughput problem. Not ready to wipe the device cl...
by Josephny
Sun Mar 24, 2024 5:14 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

I have been playing around with frequencies. I found the following that do not result in an error: 5240-5320 5560-5895 5735-5895 5765 5220 /interface wifi set [ find default-name=wifi1 ] channel.band=5ghz-ax .frequency=5560-5895 \ .skip-dfs-channels=all .width=20/40/80mhz configuration.country=\ &qu...
by Josephny
Sun Mar 24, 2024 4:06 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

Yes, US.

BTW, I just installed and ran inSSIDer and this is what my wifi environment looks like:
Screenshot 2024-03-24 100423.png
by Josephny
Sun Mar 24, 2024 3:56 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

Using wifi-qcom 7.14
by Josephny
Sun Mar 24, 2024 3:55 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

Band options include:
A
A/N
AC
AX

Width options are:
20/40/80Mhz
20/40Mhz
20/40Mhz Ce
20/40Mhz eC
20Mhz

Entering 5260 with AX and 20/40/80Mhz results in "no supported channels"
by Josephny
Sun Mar 24, 2024 3:31 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

THank you for the great analysis. I try not to use 2.4 for anything other than IoT devices, so my interest is almost entirely in the 5ghz band. When I enter 5250 as the frequency, I get the red message at the bottom of the INTERFACE <wifi1> box that says "no supported channels" I've played...
by Josephny
Sun Mar 24, 2024 1:16 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

Good -- makes perfect sense to focus on the wired connection between the ax3 and 5009. I will need to set aside time to focus and remain calm for the process of resetting the AX3. (Things like this tend to take 4 times longer and be 8 times as frustrating as they should.) In the meantime, I ran a fr...
by Josephny
Sun Mar 24, 2024 12:56 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

As always, thank you so very much! AX3: The AX3 is used exclusived as (1) a wifi AP and (2) a switch. ether1 on the AX3 is connected to the RB5009 port 4. ether3 and ether4 to a tv set top box The second bridge called "Guest-Bridge" is disabled and hasn't been enabled in a very long time. ...
by Josephny
Sun Mar 24, 2024 1:07 am
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

I've played with the Mikrotik Home Assistant integration a while ago, but RouterOS's upgrade broke it.

https://github.com/tomaae/homeassistant ... issues/328
by Josephny
Sat Mar 23, 2024 10:23 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

Anything in the below config can explain a connectivity/throughput slowdown? Here's the AX3 config: . # 2024-03-23 16:05:29 by RouterOS 7.14 # software id = 5NRD-V1QF # # model = C53UiG+5HPaxD2HPaxD # serial number = HDxxxxxx /interface bridge add disabled=yes name=Guest-Bridge port-cost-mode=short ...
by Josephny
Sat Mar 23, 2024 6:10 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

Okay, connected the laptop via cable to the AX3. The test setup is: Laptop - cable - AX3 - cable - RB5009 - cable - desktop iperf from laptop to desktop is now: 500Mbit/s (62MB/s) Not great, but much, much faster. Then I took another laptop and wired it to the AX3, so the set up is: Laptop via cable...
by Josephny
Sat Mar 23, 2024 4:51 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

You guys know so much! I just ran iperf on a Windows 11 laptop connected via wifi to the AX3, on one side. On the other side, a Windows 11 desktop connected via ethernet cable to the 5009. That means: Laptop (wifi to) -> AX3 (wired to) -> RB5009 (wired to) -> Desktop Result from running test a few t...
by Josephny
Sat Mar 23, 2024 3:34 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Re: Where's my bottleneck?

Hey Anav -- thanks! Usual disclaimer that I know nothing.... My understanding is that iperf should not be run on the MT device, but rather on devices connected immediately to MT devices. As such, the test would look something like: DEVICE-RUNNING-IPERF -> MT-DEVICE -> INTERNET -> MT-DEVICE -> DEVICE...
by Josephny
Sat Mar 23, 2024 2:55 pm
Forum: General
Topic: Where's my bottleneck?
Replies: 29
Views: 9313

Where's my bottleneck?

I'm running 7.14 stable on an RB5009, wired to an AX3 (also running 7.14). Most local clients connect via wifi to the AX3. I'm experiencing less than desirable performance and trying to figure out why. Speed test from the AX3 to the 5009 results in: 265us / 360us / 515us Bandwidth test average: 956....
by Josephny
Sat Mar 02, 2024 2:54 pm
Forum: General
Topic: VLAN struggles (continued)
Replies: 7
Views: 877

Re: VLAN struggles (continued)

I just watched:

https://www.youtube.com/watch?v=4Z32oOPqCqc

Fantastic video.

Too bad my head overheated and melted down 1/2 way through.
by Josephny
Sat Mar 02, 2024 1:37 pm
Forum: General
Topic: VLAN struggles (continued)
Replies: 7
Views: 877

Re: VLAN struggles (continued)

Bump
by Josephny
Fri Mar 01, 2024 2:39 pm
Forum: General
Topic: VLAN struggles (continued)
Replies: 7
Views: 877

Re: VLAN struggles (continued)

Thank you so much for the help/education in how to ask for help -- nothing more valuable! I understand that there are 2 main components of the solution: VLAN filters and firewall rules. Here's my attempt to put to use your advice. I hope I've at least come somewhat close to doing it well. My goal is...
by Josephny
Fri Mar 01, 2024 1:29 pm
Forum: General
Topic: VLAN struggles (continued)
Replies: 7
Views: 877

VLAN struggles (continued)

Every now and then I (re)decide to learn VLANs. And it always ends in frustration. Yes, I've read and watched and listened and thought.... I'm thinking maybe I need a real world task to get the concepts and techniques to sink in to my brain. Maybe some kind soul would help me. Below is simplified di...
by Josephny
Mon Feb 26, 2024 9:00 pm
Forum: General
Topic: How to change WG handshake timeout
Replies: 8
Views: 988

Re: How to change WG handshake timeout

Wow! What a deep reference.

Thank you.
by Josephny
Mon Feb 26, 2024 8:16 pm
Forum: General
Topic: How to change WG handshake timeout
Replies: 8
Views: 988

Re: How to change WG handshake timeout

I certainly don't see any setting that can do this.

Hard coded?
by Josephny
Mon Feb 26, 2024 10:12 am
Forum: General
Topic: How to change WG handshake timeout
Replies: 8
Views: 988

How to change WG handshake timeout

Is there any way to change the timeout from 5 seconds to give the system a little more time before logging the error:

"handshake for peer did not complete after 5 seconds, retrying"

Thanks.
by Josephny
Tue Feb 20, 2024 3:36 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

Yes, I send a configured device and the local guy was able to replace the non-functioning one with it. So, the site has been up and running just fine, but I just got here so I wanted to see the state of the old device. Corrupted file system makes sense. It happened during a remote RouterOS upgrade. ...
by Josephny
Tue Feb 20, 2024 2:12 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) - UPDATE [SOLVED]

I finally made it to the site. Powered up the hEX and the green power LED lit up. Then, every ~30 seconds, it beeped and the USR light would go on for ~1 second. This cycle repeated continuously. I don't know what state this is, but it did not have an ip address in the 192.168.0.0/16 range nor did i...
by Josephny
Mon Feb 12, 2024 2:02 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

Yes indeed, always learning. Great in many ways, but tiring. Netinstall is nice (in part) because you get to select the RouterOS version, and then can readily paste the .rsc file into a blank config. This is what I wound up doing. Shipping the device to the site today and hopefully plugging it in wi...
by Josephny
Mon Feb 12, 2024 12:56 am
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

Well, after several attempts and realizing that a netinstall using at least a newer version of routeros and not adding the default config I was able to simply copy and paste the saved rsc.

Thanks for all the help everyone.
by Josephny
Sun Feb 11, 2024 10:36 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

I ordered a new hEX and just got it. I have a recent export (.rsc) and am trying to use it, but I'm getting a lot of error messages that some commands fail because of existing config. Is there a straightforward way to import a .rsc to a new MT device without any concern for overwriting the default c...
by Josephny
Sat Feb 10, 2024 10:38 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

The problem is if I set up the pc with a direct cable (or even through the UDM acting as a switch) it will require changing the ip settings on the pc and that would eliminate my remote access to the pc. Well, you already said you did not see the router in winbox or netinstall so no need trying IP. ...
by Josephny
Sat Feb 10, 2024 7:00 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

The problem is if I set up the pc with a direct cable (or even through the UDM acting as a switch) it will require changing the ip settings on the pc and that would eliminate my remote access to the pc.
by Josephny
Sat Feb 10, 2024 5:34 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

I've got you all beat. Had the same experience with a router 11265.4 kilometers away from my location. Fortunately I had someone at the location who was able to reset the router and do a simple config so that I could connect and finalize the configuration. Unfortunately it was someone who is not te...
by Josephny
Sat Feb 10, 2024 5:33 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

Is one of the ports off the bridge....... Then the remote person could plug in a laptop and access the router that way......... I don't recall if I left a port off of the bridge. Regardless, plugging a cable from a port on the hEX to a laptop and running anything is way above the skill level of the...
by Josephny
Sat Feb 10, 2024 5:28 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Re: Can't access hEX (pretty urgent) [SOLVED]

100 miles ? I've had it once with an SXT serving cAP AC and cAP mini over 900km away. No remote connection anymore, nobody onsite. Small problem. Luckily just the week before I was going towards that location so no major problems caused. Netinstall should be done 1) putting Hex in netinstall mode (...
by Josephny
Sat Feb 10, 2024 4:07 pm
Forum: General
Topic: Can't access hEX (pretty urgent) [SOLVED]
Replies: 30
Views: 3720

Can't access hEX (pretty urgent) [SOLVED]

I've gone and done it now. I have a hEX at a location 100 miles away. I was fiddling (remotely) and issues a reboot command. Now it is unreachable. Luckily, it is not the primary router. It essentially is only a Wireguard device. But, it's still pretty important. I can remote into both the main rout...