Community discussions

MikroTik App

Search found 46 matches

by arturportella
Thu Aug 13, 2020 5:57 pm
Forum: General
Topic: CRS3xx - Management VLAN stop working
Replies: 3
Views: 1332

Re: CRS3xx - Management VLAN stop working

All our switches are STP disabled, may this can be the problem?
by arturportella
Wed Aug 12, 2020 7:08 pm
Forum: General
Topic: CRS3xx - Management VLAN stop working
Replies: 3
Views: 1332

CRS3xx - Management VLAN stop working

Hello guys. Currently we are facing a lot of issues with CRS switches. Sometimes, they stop forwarding mac addresses and so. We have a huge infrastructure with a lot of VLANS. Our main issue to be solved is that our trunk switches (CRS326) suddenly stop answering at our network (No ping, no mac-teln...
by arturportella
Wed Sep 05, 2018 6:11 pm
Forum: General
Topic: CRS317 series - need help with VLAN forward override
Replies: 0
Views: 706

CRS317 series - need help with VLAN forward override

Hello guys! I'm trying to achieve the following scenario: I have a CRS317 switch forwarding a lot of VLANS to uplink port (SFP-SFPPLUS1). What I want to do, is to create a rule, so untagged packets are isolated from other ports (I give them one ingress vlan translation to TAG 5 for example). Other V...
by arturportella
Wed May 17, 2017 9:27 pm
Forum: General
Topic: How to isolate wireless multicasts? Any Ideas?
Replies: 3
Views: 1229

Re: How to isolate wireless multicasts? Any Ideas?

Hello TonyJr!
For this you will require a proprietary wireless video link from cameramen to base station, and from the video outputs therer
Can you give me more info about this proprietary wireless video link? Do you know any?

Best regards and thank for your patience hahaha...

Artur Portella.
by arturportella
Wed May 17, 2017 5:46 pm
Forum: General
Topic: How to isolate wireless multicasts? Any Ideas?
Replies: 3
Views: 1229

How to isolate wireless multicasts? Any Ideas?

Hello Guys! I have a weird scenario, but I will try to make it simple to understand. I have a customer that works with video streaming. He use a kind of video encoder that sends multicast traffic over the network, so the connection was made to be simple: He take a video source and insert it on the e...
by arturportella
Fri Feb 03, 2017 7:39 pm
Forum: Beginner Basics
Topic: RSTP problem (6.38.1
Replies: 7
Views: 3183

Re: RSTP problem (6.38.1

Hi 49er!

Can you tell us from what older version this problem don't happen? From what version you had no problems?

Regards,
by arturportella
Fri Feb 03, 2017 7:29 pm
Forum: Beginner Basics
Topic: Mikrotik - how to calc the right device to our project
Replies: 1
Views: 835

Re: Mikrotik - how to calc the right device to our project

Hello Renato, The answer is: It depends... Really, there is no such a magic number to calculate that, you need to achieve at least an average amount of rules to be applied in your routing session (routing/filtering/firewalling/queuing). The CCR-1036 is a very powerful device, I heard a lot of good f...
by arturportella
Fri Feb 03, 2017 7:14 pm
Forum: Beginner Basics
Topic: Multiple VPN clients?
Replies: 3
Views: 3225

Re: Multiple VPN clients?

Sounds confusing...

From my understanding, you want to route everything from a vpn session to a specific port, right? Like a bridge through one vpn end to other?

Can you draw a simple diagram on "mspaint" for us? :P

Regards,
by arturportella
Fri Feb 03, 2017 7:07 pm
Forum: Wireless Networking
Topic: SXT to CCR port flapping
Replies: 2
Views: 1059

Re: SXT to CCR port flapping

Try two things: Add a dumb switch in the middle of the path (between SXT and CCR). See if the problem solves. Also check for errors at interfaces (CRS, FCS, etc) on both equipments. And the least but not less important, if the problem persists, try enabling flow control on both equipments. Good luck...
by arturportella
Fri Feb 03, 2017 6:48 pm
Forum: General
Topic: Google Cast (chromecast and youtube) with vlan and bridge filtering.
Replies: 3
Views: 4212

Re: Google Cast (chromecast and youtube) with vlan and bridge filtering.

Can you (if you could) draw it and explain it more clearly?

Regards,
by arturportella
Fri Feb 03, 2017 6:41 pm
Forum: General
Topic: Port Level Isolation facility on RB951G-2HnD like CRS. Possible?
Replies: 1
Views: 746

Re: Port Level Isolation facility on RB951G-2HnD like CRS. Possible?

No, This is possible with CRS due to a very flexible switch chip inside it, while the RB951G-2HnD doesn't have it. You can do it on RB951G-2HnD by applying the interfaces you want inside a bridge and doing filtering at bridge to isolate between ports. But, of course, it uses your CPU resources to do...
by arturportella
Fri Feb 03, 2017 6:34 pm
Forum: General
Topic: CRS122-8G-4S network speed issue
Replies: 4
Views: 1708

Re: CRS122-8G-4S network speed issue

Ok, I probably know the reason... CPU is too weak to use it as a router :/ I was writing at the time you've posted this hehehehe... Of course you can enable fasttrack to speed up your NAT and reduce cpu usage. Remind that every rule that you put in your Filter / Firewall rules does a huge amount of...
by arturportella
Fri Feb 03, 2017 6:29 pm
Forum: General
Topic: CRS122-8G-4S network speed issue
Replies: 4
Views: 1708

Re: CRS122-8G-4S network speed issue

Hello juhas!

Had you checked your CPU usage? Try checking your system resource while doing a speedtest @ ookla and see if it's a CPU bottleneck. Of course, if your cpu reach 100%, maybe it's something that's using all your box, so we can check up your NAT rules and etc...

Best regards,
by arturportella
Fri Feb 03, 2017 6:12 pm
Forum: General
Topic: DCHP, Radius and /24
Replies: 2
Views: 1307

Re: DCHP, Radius and /24

Good way: OSPF or other dynamic routing protocol.
by arturportella
Fri Feb 03, 2017 6:03 pm
Forum: General
Topic: I locked myself out after activating the hotspot
Replies: 13
Views: 24943

Re: How to login to default hotspot

Are you still able to connect to the router through MAC or IP using winbox -> Neighbors?
by arturportella
Fri Feb 03, 2017 5:52 pm
Forum: General
Topic: RB750Gr3 - rebooted
Replies: 8
Views: 2720

Re: RB750Gr3 - rebooted

I had this problem once. We had a faulty hardware due to bad POE adapter, have you checked it? Check temps, voltage, etc. And of course: supout.rif to Mikrotik's staff.
by arturportella
Fri Feb 03, 2017 5:47 pm
Forum: General
Topic: bridge only for wireless
Replies: 14
Views: 4877

Re: bridge only for wireless

Everything is possible to your scenario, but keep in mind that bridging + acl is not a good idea since it uses your equipment processing power (sometimes, a LOT). I bet that you can use filters in your bridge setup (put everything together) and isolate them. But if you want to just isolate them, why...
by arturportella
Fri Feb 03, 2017 5:39 pm
Forum: General
Topic: Case sensitivity of built-in RADIUS server
Replies: 7
Views: 5588

Re: Case sensitivity of built-in RADIUS server

Lower case the username in an authetnication packet, but leave it as is in an accounting packet? Surely, you are using ACCOUNTING data to send PODs, not AUTHENTICATION data? The company I work today have a control software that uses Accounting data to send the POD to mikrotik. They don't want to ch...
by arturportella
Fri Feb 03, 2017 2:24 pm
Forum: General
Topic: Case sensitivity of built-in RADIUS server
Replies: 7
Views: 5588

Re: Case sensitivity of built-in RADIUS server

Well, I'm trying to make RouterOS accept Radius commands as "non case sensitive". My freeradius accepts requests from my users logins: Potato - PoTaTo - POTATO - potatO, etc and Mikrotik put them online with no clues... But when sending a command from FreeRadius to mikrotik to drop user &q...
by arturportella
Wed Feb 01, 2017 4:26 pm
Forum: Scripting
Topic: How to change inserted login PPP/Hotspot string to another one?
Replies: 0
Views: 845

How to change inserted login PPP/Hotspot string to another one?

Hello everyone! I've readed a lot about scripting, but I still cant figure a way to get one thing working. The goal is to get inserted user login from hotspot or ppp authentication and put it in router as "uppercase". Let me try to explain what is going on. Today I work with about 1500 use...
by arturportella
Fri Jul 29, 2016 5:55 pm
Forum: General
Topic: CRS - Lost management after Service-Vlan Lookup mode
Replies: 0
Views: 773

CRS - Lost management after Service-Vlan Lookup mode

Hello folks! I was able to do customer vlan very well yesterday between three CRS226. What I did in my setup was setting ether2 as an access port to vlan 100 (ingress-vlan-translation) and took cpu to vlan100 to get management vlan in trunk port + local management access to switch, and in both switc...
by arturportella
Fri Jul 29, 2016 3:53 pm
Forum: RouterBOARD hardware
Topic: CRS125 - How to BOND slave interfaces?
Replies: 5
Views: 2156

Re: CRS125 - How to BOND slave interfaces?

Thank you so much! It works! It's a little bit sad that those switchs doesn't support LACP and IGMP snooping, as well STP with slave/master ports setup.

Still waiting for updates from MK development crew.
So, if I enable trunk in both sides, there is no loop between them?
yes
by arturportella
Wed Jul 27, 2016 5:41 pm
Forum: RouterBOARD hardware
Topic: CRS125 - How to BOND slave interfaces?
Replies: 5
Views: 2156

Re: CRS125 - How to BOND slave interfaces?

So, if I enable trunk in both sides, there is no loop between them?
by arturportella
Wed Jul 27, 2016 5:15 pm
Forum: RouterBOARD hardware
Topic: CRS125 - How to BOND slave interfaces?
Replies: 5
Views: 2156

CRS125 - How to BOND slave interfaces?

Hello everyone! I'm trying to achieve bonding between two switches. They are both CRS125-24G-1S. What I did: SW1 -> All ports to master port Ether2 SW2 -> All ports to master port Ether2 SW1 (ether14,ether15) ============= (ether1,ether2) SW2 But I can't use Bonding because interfaces are slave of e...
by arturportella
Fri Jul 08, 2016 5:53 pm
Forum: General
Topic: CRS125/CRS226/etc - Help with port isolation!
Replies: 5
Views: 2125

Re: CRS125/CRS226/etc - Help with port isolation!

That's right, with other routerboards, I was able to isolate ports just doing this. It's not working with CRS125 or 226.
I use multiple master ports on my RB2011.
by arturportella
Fri Jul 08, 2016 6:43 am
Forum: General
Topic: CRS125/CRS226/etc - Help with port isolation!
Replies: 5
Views: 2125

Re: CRS125/CRS226/etc - Help with port isolation!

You can set more than a Master port ? I think so Hello! I'm trying to isolate port groups with CRS. What happen is if I try to listen the network with wireshark on a port that doesn't have a Master port (Master port set to none) a lot of broadcast leaks to it. I want a uplink in ether1 to isolated ...
by arturportella
Fri Jul 08, 2016 1:40 am
Forum: General
Topic: CRS125/CRS226/etc - Help with port isolation!
Replies: 5
Views: 2125

CRS125/CRS226/etc - Help with port isolation!

Hello! I'm trying to isolate port groups with CRS. What happen is if I try to listen the network with wireshark on a port that doesn't have a Master port (Master port set to none) a lot of broadcast leaks to it. I want a uplink in ether1 to isolated ports between ether2 to ether20. What I did was us...
by arturportella
Tue Jun 28, 2016 7:34 pm
Forum: General
Topic: CRS - PPPoE Filter on switch chip inside VLAN, HOW?
Replies: 6
Views: 2509

Re: CRS - PPPoE Filter on switch chip inside VLAN, HOW?

Here we go: QCA 8513L

Sad to hear/read that. They should mention this in their portfolio, not in the "manual" session.

Edit: Of course I didn't searched for ACL, but far as I know, a "managed" switch should support many wire-speed features like those mentioned before.
by arturportella
Tue Jun 28, 2016 6:21 pm
Forum: General
Topic: CRS - PPPoE Filter on switch chip inside VLAN, HOW?
Replies: 6
Views: 2509

Re: CRS - PPPoE Filter on switch chip inside VLAN, HOW?

OMG, how I didn't saw that? ;(

We bought tons of CRS, but CRS125-24G-1S. Their switch chip doesn't allow ACL. Thats pretty bad! What can I do? There is no plans for their chip switch to support ACL in any way?
by arturportella
Tue Jun 28, 2016 3:37 pm
Forum: General
Topic: CRS - PPPoE Filter on switch chip inside VLAN, HOW?
Replies: 6
Views: 2509

Re: CRS - PPPoE Filter on switch chip inside VLAN, HOW?

Well, Here in Brazil, most ISPs starts with the same infrastructure: Local network with few customers sharing a network. You start adding more devices to your network and so, sooner you will have problems. Now we are a ISP with an ASN with a lot of customers with the same initial structure. That's w...
by arturportella
Tue Jun 28, 2016 2:43 pm
Forum: General
Topic: CRS - PPPoE Filter on switch chip inside VLAN, HOW?
Replies: 6
Views: 2509

CRS - PPPoE Filter on switch chip inside VLAN, HOW?

Hello guys! After a lot of researching through forums, I still can't find some "easy" tasks found in another L2/L3 switches. Of course, CRS have a very powerful chip inside the box, but the routerOS is not really prepared for noobs in mikrotik like me. Well, let's get started with one thin...
by arturportella
Tue Jun 28, 2016 2:24 pm
Forum: General
Topic: CPU OVER CCR1036 and PPPoe Intermitente in 6.36rc30
Replies: 1
Views: 1170

Re: CPU OVER CCR1036 and PPPoe Intermitente in 6.36rc30

Hello! Welcome to MikroTik forums! I bet your translate tool is falhando for some reason hahahah.. I think that you need to take a look at "Tools -> Profile" to see what is locking up your system. Because you know, reasons. You need to search what task inside your router is bottlenecking u...
by arturportella
Tue May 17, 2016 4:26 pm
Forum: General
Topic: How to block HTTP port scanner?
Replies: 2
Views: 1374

How to block HTTP port scanner?

Hello! I'm facing some dificulties to block external IP addresses from scanning HTTP ports on our network. We have a /24 subnet with valid IP addresses and all port scanners scripts works only for few ports. How can I create a rule to add src. addresses that scan my entire subnet at HTTP 80? I have ...
by arturportella
Tue Mar 29, 2016 3:04 pm
Forum: Scripting
Topic: (Draft) IPv6 Authentication for Hotspots
Replies: 5
Views: 9217

Re: (Draft) IPv6 Authentication for Hotspots

Awww, that's sad. Well, by the way, your tutorial works very well for it's purpose. Let's wait for some update in this scenario. I guess that on Hotspot (dual stacked customers) this is a very important thing to work on. I will grab my popcorn here and wait hahaha.. Thanks a lot!
by arturportella
Mon Mar 28, 2016 3:59 pm
Forum: Scripting
Topic: (Draft) IPv6 Authentication for Hotspots
Replies: 5
Views: 9217

Re: (Draft) IPv6 Authentication for Hotspots

Amazing tutorial! But I'm facing some issues. As I have a Radius server giving all my customers the correct access-list with blocked connections (blocked-access) and etc, how can I use this script to work on? I can't use "address list" on User profile because this can suppress my Radius-se...
by arturportella
Fri Dec 11, 2015 2:16 pm
Forum: General
Topic: CRS125-24G-1S - HOW TO VLAN BYPASS WITH PORT ISOLATON?
Replies: 2
Views: 1031

Re: CRS125-24G-1S - HOW TO VLAN BYPASS WITH PORT ISOLATON?

I guess that with a diagram the problem will be more easy to solve: DOUBT.png In this scenario, I have 1 to 8 acting as promiscuous isolated ports in port profile 0 as uplink ports, and from 9 to 24 + sfp as isolated ports in port profile 1. But, what if I want to create a rule to bypass from port 9...
by arturportella
Thu Dec 10, 2015 1:35 pm
Forum: General
Topic: CRS125-24G-1S - HOW TO VLAN BYPASS WITH PORT ISOLATON?
Replies: 2
Views: 1031

Re: CRS125-24G-1S - HOW TO VLAN BYPASS WITH PORT ISOLATON?

Let me add some details, or just simplify my question :P I want every interface from ether1 to ether8 to be uplink ports (they can see every interface of the switch), and from ether9 to ether24 + sfp1 to be isolated between them. But, what if I want to get untagged traffic accessing uplink ports and...
by arturportella
Wed Dec 09, 2015 9:22 pm
Forum: General
Topic: CRS125-24G-1S - HOW TO VLAN BYPASS WITH PORT ISOLATON?
Replies: 2
Views: 1031

CRS125-24G-1S - HOW TO VLAN BYPASS WITH PORT ISOLATON?

Hello guys! :D I have created rules to isolate ports on CRS in this following scenario: FROM 1 to 8 -> UPLINK PORTS FROM 9 TO 24 + SFP -> ISOLATED PORTS (they can see uplink ports but no traffic between them) Well, my doubt is about port to port vlan bypass. I have a group of isolated ports, so, how...
by arturportella
Mon May 11, 2015 10:12 pm
Forum: General
Topic: CRS VLAN bypass + untagged traffic.
Replies: 10
Views: 2870

Re: CRS VLAN bypass + untagged traffic.

when you say bridgind vlans do you refer to do hardware switching?? Ok CRS can do that at wire speed with no CPU usage I refer to the software bridges in router OS configuration, its not the purpose of a hardware switch to do software bridging YES, I mean hardware switching! How can I link a VLAN i...
by arturportella
Mon May 11, 2015 8:27 pm
Forum: General
Topic: CRS VLAN bypass + untagged traffic.
Replies: 10
Views: 2870

Re: CRS VLAN bypass + untagged traffic.

How about bridging vlans? There will be no packet processing. I used to have HP 1910 switches here, and this setup was easily achieved in their web interface. We had no CPU issues at all, but all our infrastructure are Mikrotik based (except for wireless networking). So, we are moving from HP to MK....
by arturportella
Mon May 11, 2015 5:19 pm
Forum: General
Topic: CRS VLAN bypass + untagged traffic.
Replies: 10
Views: 2870

Re: CRS VLAN bypass + untagged traffic.

RouterOS default behaviour is all ports are trunks and let everything pass. No specific setting is needed unless you start setting VLANs. I've tried the following (winbox): Add a VLAN (ex: Vlan ID 100) to ether5 and ether11. Created a Bridge named "Vlan 100", add ports ether5.100 and ther...
by arturportella
Mon May 11, 2015 3:35 pm
Forum: General
Topic: CRS VLAN bypass + untagged traffic.
Replies: 10
Views: 2870

Re: CRS VLAN bypass + untagged traffic.

please specify on every port of the topology which vlan goes tagged or untagged Hello Chechito! Now, for experiences purposes (but actually in production), our CRS is active in our main network. ether2 is a Master Port and every other port are slave of it. We are an ISP here, so we have more than o...
by arturportella
Sat May 09, 2015 4:11 pm
Forum: General
Topic: CRS VLAN bypass + untagged traffic.
Replies: 10
Views: 2870

CRS VLAN bypass + untagged traffic.

Hello, My scenario is the following: vlan example.png I want to pass untagged through all ports of CRS, but leave VLAN passing only through one port. Is this possible? On older RouterBoards I could set up a port to port vlan + untagged just adding them to both ports and brigding them, but on CRS thi...
by arturportella
Mon Nov 17, 2014 7:26 pm
Forum: General
Topic: Transparent Firewall - How to not use public addr?
Replies: 0
Views: 958

Transparent Firewall - How to not use public addr?

Hello everyone! Actually I use Mikrotik in my entire network. We are an ISP, around 3k customers. I need to solve the following scenario: Put two IP addresses in the same routerboard (public addresses) in transparent mode, so the RB would work as an "Transparent Filter". One port would be ...
by arturportella
Mon Nov 17, 2014 6:36 pm
Forum: General
Topic: Transparent Bridge Filter - Two Public Addr and same GW
Replies: 0
Views: 708

Transparent Bridge Filter - Two Public Addr and same GW

Hello everyone! Actually I use Mikrotik in my entire network. We are an ISP, around 3k customers. I need to solve the following scenario: Put two IP addresses in the same routerboard (public addresses) in transparent mode, so the RB would work as an "Transparent Filter". One port would be ...
by arturportella
Wed Oct 30, 2013 3:33 pm
Forum: General
Topic: SNMP - "bytes-in" on simple queue issues
Replies: 0
Views: 956

SNMP - "bytes-in" on simple queue issues

Hello everyone! I'm trying to monitor some mikrotik router through SNMP. I'm actually monitoring a lot of them individually. However, when I try to get some values from a queue that uses network instead of a simple address (xxx.xxx.xxx.xxx/XX), I get weird values that screws up all my graphs. I'm u...