Community discussions

MikroTik App

Search found 47 matches

by pimmie
Mon Nov 25, 2024 8:13 pm
Forum: Wireless Networking
Topic: Security setting with WPA3 breaks 2Ghz on hAP AX2
Replies: 4
Views: 526

Re: Security setting with WPA3 breaks 2Ghz on hAP AX2

It's running wifi-qcom-ac indeed
by pimmie
Mon Nov 25, 2024 6:57 pm
Forum: Wireless Networking
Topic: Security setting with WPA3 breaks 2Ghz on hAP AX2
Replies: 4
Views: 526

Re: Security setting with WPA3 breaks 2Ghz on hAP AX2

What devices/arch are you using, `wifi-qcom` or `wifi-qcom-ac`? As mentioned, similar 2Gz-only devices still connect fine on the AC3 but not on the AX2 since upgrading to v7.16.1. Both devices are fully upgraded to v7.16.1 and both were using shared security profiles with WPA2 & WPA3 since forev...
by pimmie
Mon Nov 25, 2024 6:24 pm
Forum: Wireless Networking
Topic: Security setting with WPA3 breaks 2Ghz on hAP AX2
Replies: 4
Views: 526

Security setting with WPA3 breaks 2Ghz on hAP AX2

Since forever I've been using shared security settings for both 2Ghz & 5Ghz networks, i.e. the security settings set a single password to be used for both WPA2 & WPA3. Unfortunately since upgrading to v7.16.1 (upgraded both ros as rb, didnt try 7.16.0), this shared security setting complete ...
by pimmie
Sat May 04, 2024 4:35 pm
Forum: General
Topic: Bringing my own router to work - idea validation
Replies: 5
Views: 829

Re: Bringing my own router to work - idea validation

There was a similar post some time ago and that op posted more details: https://forum.mikrotik.com/viewtopic.php?p=1068656#p1068656 Ignoring the exact use-case, I have used a mAp lite myself when traveling to 'bridge' hotel wifi networks for my laptop and/or phone. I guess that's similar as what you...
by pimmie
Tue Apr 16, 2024 12:41 pm
Forum: General
Topic: hAP ax3 ruining USB dongles
Replies: 8
Views: 938

Re: hAP ax3 ruining USB dongles

You could try to use a USB-tester to check if the ax3 is at least supplying a normal usb voltage (5V). If for whatever reason the ax3 delivers a higher voltage then that could probably be a reason for your USB dongles getting ruined. Although it seems unlikely, it's not impossible... Did you also pl...
by pimmie
Sun Apr 14, 2024 5:38 pm
Forum: General
Topic: User poll about using Winbox
Replies: 107
Views: 111316

Re: User poll about using Winbox

1) Never (at least not on purpose, I guess I used it as it auto loads/saves per device?) 2) Start a new winbox or user session? 3) As far as I now understand, sessions are basically user-defined UI presets? If so, don't use file options like Open/Save but have a dropdown with all listed presets and ...
by pimmie
Sun Apr 14, 2024 11:55 am
Forum: General
Topic: Can't have OSPF over IPSEC/GRE
Replies: 4
Views: 925

Re: Can't have OSPF over IPSEC/GRE

Have you tried setting the interface template for the gre interface to a network type of ptp-unnumbered instead of just ptp? Have no xp with Juniper, but that resolved it for me a couple of times. Even though the neighbour did have an IP address and each device could ping each other's GRE-tunnel ip
by pimmie
Fri Apr 12, 2024 8:42 pm
Forum: General
Topic: Issue with Auto Upgrade / packages from another MikroTik device
Replies: 7
Views: 3000

Re: Issue with Auto Upgrade / packages from another MikroTik device

Sure, but sometimes that's not how learning new things work. And aren't we all here to learn things we didn't knew yet?
by pimmie
Fri Apr 12, 2024 2:52 pm
Forum: General
Topic: Issue with Auto Upgrade / packages from another MikroTik device
Replies: 7
Views: 3000

Re: Issue with Auto Upgrade / packages from another MikroTik device

Shouldnt you be using `/system/package/update/check-for-updates` and `/system/package/update/download` ? Or is that v7 only?
by pimmie
Fri Apr 12, 2024 10:35 am
Forum: General
Topic: Router Leaking Packets (ICMP) Marked for Wireguard Tunnel
Replies: 35
Views: 5366

Re: Router Leaking Packets (ICMP) Marked for Wireguard Tunnel

Can you reproduce the issue with a site like this too: https://websocketking.com/? After loading the page make sure to connect to the demo/echo endpoint and wait for the log to say `Connected to wss://echo.websocket.org`. Asking because the youtube streaming platform might bring quite a bit of compl...
by pimmie
Fri Apr 12, 2024 9:41 am
Forum: General
Topic: V 7.14.2 - firewall rules layout unusable
Replies: 11
Views: 1491

Re: V 7.14.2 - firewall rules layout unusable

You should also be able to change the width of each column yourself? Hover with your mouse between two column headers, note that the mouse pointer turns into a double arrow and then drag left/right while holding the left mouse button to change the column width. If that doesn't work maybe one of styl...
by pimmie
Fri Apr 12, 2024 9:30 am
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2363

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Ok, with such an attitude I guess you are not seriously trying to resolve the issue then. If you are serious, be nice towards people who are trying to help you and read up on https://debug.guide/.

Debugging like that guide specifies is part of real life for technicians too!
by pimmie
Thu Apr 11, 2024 10:00 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2363

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Can you reproduce the issue on a clean RouterOS install with a minimal configuration?

Do you have Private Wifi enabled on iOS? Also latest iOS installed, I think that's 17.4.1?
by pimmie
Thu Apr 11, 2024 12:20 pm
Forum: General
Topic: AmneziaWG in RouterOS?
Replies: 42
Views: 23405

Re: AmneziaWG in RouterOS?

Their privacy policy starts with The company Amnezia (hereinafter – the "company", "we", "us") , but nowhere do they seem to give more information about that company, like where are they located (ie under which jurisdiction to they fall)? They say that data can be trans...
by pimmie
Wed Apr 10, 2024 9:28 am
Forum: General
Topic: Trouble connecting Android phone to MikroTik IKEv2 VPN server: Need assistance with log analysis
Replies: 4
Views: 1841

Re: Trouble connecting Android phone to MikroTik IKEv2 VPN server: Need assistance with log analysis

Why would you still use IKEv2 as opposed to wireguard? For a site-to-site I can see why IKEv2 might still have some advantages, but not sure why it would be beneficial for a phone/road warrior?
by pimmie
Wed Apr 10, 2024 9:23 am
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2363

Re: 7.14.1 iOS cannot be static in DHCP

To be clear, are you taking about Apple iOS or Cisco IOS?
by pimmie
Wed Apr 10, 2024 9:14 am
Forum: General
Topic: Port Forward based on Destination Interface
Replies: 15
Views: 1470

Re: Port Forward based on Destination Interface

The dst-address are not needed in the routing rules, you should remove those. Only add a rule that says `interface=ether2-Client1 action=lookup-only-in-table table=to_Client1` etc It might help to divide the task up into smaller steps so you limit the amount of complexity and things that can go wron...
by pimmie
Tue Apr 09, 2024 1:57 pm
Forum: General
Topic: Up 200 CAP
Replies: 12
Views: 1361

Re: Up 200 CAP

Installed in a village-hotel with around 180 rooms.
...
1) Powers tx at 10/16 dBm,
- 180 rooms and 200 APs? Does that mean that every room has a single AP, how big are those rooms?!
- How did you decide on 10/16 dBm?
by pimmie
Tue Apr 09, 2024 1:50 pm
Forum: General
Topic: Address list for dst nat
Replies: 10
Views: 1395

Re: Address list for dst nat

I don't think that's possible currently unless you implement a script to monitor the address list for you and update the dst-nat rule if needed. I agree with you that it would be nice if it was possible to use (single) host aliases everywhere (ie also outside ip firewall) using either an ip or mac a...
by pimmie
Tue Apr 09, 2024 1:45 pm
Forum: General
Topic: Site-to-site VPN within strange network [SOLVED]
Replies: 4
Views: 742

Re: Site-to-site VPN within strange network [SOLVED]

It's never advisable to try to circumvent restrictions put by your employer on your business laptop, often this can be grounds for a discharge. For many, many reasons it's best to just not use your business laptop for private stuff, and giving your diagram it seems you are even trying to pull this o...
by pimmie
Tue Apr 09, 2024 1:29 pm
Forum: General
Topic: Address list for dst nat
Replies: 10
Views: 1395

Re: Address list for dst nat

Your example rule might be a bit too minimalistic, what are you trying to do exactly? A list means N addresses, but dst-nat can only forward traffic to 1 address.
by pimmie
Tue Apr 09, 2024 1:18 pm
Forum: General
Topic: Port Forward based on Destination Interface
Replies: 15
Views: 1470

Re: Port Forward based on Destination Interface

@patterno

You are at least missing a routing rule, you've created a routing table but those are empty atm and you have to add each client ethX to the correct table using a routing rule (with action=lookup-only-in-table).

And the static routes you added should be tweaked a bit more too
by pimmie
Sun Apr 07, 2024 12:47 pm
Forum: General
Topic: Up 200 CAP
Replies: 12
Views: 1361

Re: Up 200 CAP

Write a blog post about the DO's and DONT's you experienced while setting this up so that others can learn from your experience and maybe even prevent them from making the same mistakes you did. F.e. how did you implement routing and authentication?
by pimmie
Sat Apr 06, 2024 9:27 pm
Forum: General
Topic: Allow port forwarding to work while using VPN as main gateway
Replies: 8
Views: 624

Re: Allow port forwarding to work while using VPN as main gateway

So I have set a VPN interface as the default 0.0.0.0/0 route on the main routing table Personally I have a strong preference for the other way around, just let the main/default routing table handle 'normal' traffic and use a custom routing table for vpn's and other complicated routes. That way it's...
by pimmie
Sat Apr 06, 2024 12:01 pm
Forum: General
Topic: Port Forward based on Destination Interface
Replies: 15
Views: 1470

Re: Port Forward based on Destination Interface

Yeah, it's starting to get confusing but I also meant the dst-address of the business client not network client. As in I assume that client 1 has their own external ip A.B.C.1 that was being forwarded to 192.168.150.150 and client 2 had A.B.C.2 that was also being forwarded to 192.168.150.150. In an...
by pimmie
Sat Apr 06, 2024 11:44 am
Forum: General
Topic: Wireguard and, I think, DNS
Replies: 13
Views: 1832

Re: Wireguard and, I think, DNS

Also when trying to start Webex conference calls with the Routing turned on, it takes about 3 minutes to start the call @howdey57 If speed is ok then why did you mention the above? Which DNS servers do you expect the clients to exit in the UK to use? In your config all 65.x clients seem to use `dns...
by pimmie
Sat Apr 06, 2024 11:10 am
Forum: General
Topic: Port Forward based on Destination Interface
Replies: 15
Views: 1470

Re: Port Forward based on Destination Interface

@tangent OP said the following and I assume he meant that each client has a separate external ip / network range they are on entirely separate networks @pattemo Assuming the two servers can already be reached at the moment, can you draw a network diagram of how it works now? And how/why does the new...
by pimmie
Fri Apr 05, 2024 3:49 pm
Forum: General
Topic: Port Forward based on Destination Interface
Replies: 15
Views: 1470

Re: Port Forward based on Destination Interface

I think you should be able to add two routing tables, add each interface to their own routing table (using a routing rule) and then use a mangle rule to forward incoming traffic to either routing table using a routing mark.
by pimmie
Fri Apr 05, 2024 1:25 pm
Forum: General
Topic: What is the best way to learn RouterOS?
Replies: 2
Views: 445

Re: What is the best way to learn RouterOS?

By doing it. But most importantly learn about how network technologies work in general, not just how to do something in RouterOS. F.e. if you want to setup a VPN connection, do you mean Wireguard, Ipsec or OpenVPN? Learn about the differences, then read up about the one you choose. Only after that y...
by pimmie
Fri Apr 05, 2024 12:47 pm
Forum: General
Topic: hAP ax³
Replies: 13
Views: 2768

Re: hAP ax³

Personally I would probably just wait unless the lower wireless speed is actually costing you (more than) the cost of an ax3. Afaik Mikrotik hasn't announced anything yet but given that WIFI7 devices are being certified, Qualcomm already has multiple WIFI7 platforms available, I wouldn't be surprise...
by pimmie
Fri Apr 05, 2024 12:35 pm
Forum: General
Topic: Wireguard and, I think, DNS
Replies: 13
Views: 1832

Re: Wireguard and, I think, DNS

Slow network could also be an indication of a MTU/MSS issue. You dont seem to have any change-mss mangle rules? My advise would be to start with a ping and follow those packets to see if they follow the expected path both in FR as UK using torch/tcpdump. If a standard ping works, try to set the size...
by pimmie
Fri Apr 05, 2024 12:23 pm
Forum: General
Topic: Network design advise - multipoint vxlan over wireguard or something else?
Replies: 0
Views: 940

Network design advise - multipoint vxlan over wireguard or something else?

Im not super well adversed in network design and am looking for advise how to setup this following network diagram (diagrams.net link) Couple of remarks: Each site / router RN is connected with each other through a (partial) mesh wireguard setup The routers will be a mix of routeros and linux device...
by pimmie
Fri Mar 01, 2024 2:11 pm
Forum: General
Topic: Missing packet summary in ping output with count=2
Replies: 0
Views: 365

Missing packet summary in ping output with count=2

Is the difference in output for the ping command when using count=2 vs count=3 expected? See output below, for count=2 there is no summary line printed. For count=1 I can understand why RouterOS doesn't print a summary, even though for scripting purposes it would be nice to be able to always toggle ...
by pimmie
Wed Mar 07, 2018 12:04 am
Forum: RouterBOARD hardware
Topic: Any 10GBase-T switches?
Replies: 3
Views: 2922

Re: Any 10GBase-T switches?

Although that is a workaround/solution for now it rounds up to a bit of a hacked together switch. With that said, for myself, I plan on buying a CRS328-24P-4S+RM to solve my POE and 10Gbit needs for now. With it's 4x SFP+ it will allow me to uplink my router (CCR1009) with 10Gbps and then my deskto...
by pimmie
Fri Dec 23, 2016 12:54 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 55095

Re: RB750Gr3 - Report and questions

Well that seems slightly silly. Why the double NAT? Just have the Hex do all the routing and turn the 2011 into a switch and AP (if your's is wireless). The Hex has a better CPU and more memory. I fully agree with this, the Hex is much faster in (almost?) all aspects. What I did was export my confi...
by pimmie
Wed Dec 21, 2016 5:10 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 55095

Re: RB750Gr3 - Report and questions

Not bad at all. Wish they'd make a "cheap rackmount" version of this too!
Maybe someone will make a bracket that can hold 1-3 of these in a 1U panel?
Could be made to fit some other MikroTik models as well...
Already exists, MaxxWave MW-RA-750-3 ;)
by pimmie
Wed Dec 21, 2016 12:44 pm
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 113
Views: 55095

Re: RB750Gr3 - Report and questions

So just to confirm what i am reading, Hex v3 to Strongswan ipsec in transport will yeild somewhere around 100Mbits, and in tunnel can yield more? I want to put one of these in front of my 2011 for the aes128 HW encryption wanna make sure i can hit at least 75/75 Finally received a RB750Gr3 yesterda...
by pimmie
Fri Sep 25, 2015 2:23 pm
Forum: Wireless Networking
Topic: CAPsMAN with VLAN no DHCP
Replies: 1
Views: 2887

Re: CAPsMAN with VLAN no DHCP

As a follow up for other people facing this problem, after help from Uldis he found the issue to be the vlan interfaces on the cap device (the rb2011 in my case). Their interface should be bridge-local and not ether1, so like this: rb2011 config (cap): /interface vlan add interface=bridge-local l2mt...
by pimmie
Mon Sep 21, 2015 12:08 pm
Forum: Wireless Networking
Topic: CAPsMAN with VLAN no DHCP
Replies: 1
Views: 2887

CAPsMAN with VLAN no DHCP

I have been looking at this for a couple of days and unfortunately I can't find what I am doing wrong, hopefully someone here can point me in the right direction. I am trying a simple setup, a CRS125-24G-1S as CAPsMAN and a RB2011 as CAP. The test I am running is for two ssid's, a public ssid (ssid-...
by pimmie
Sat Sep 05, 2015 11:56 am
Forum: General
Topic: SNMP queries for MAC->port mapping table
Replies: 19
Views: 9059

Re: SNMP queries for MAC->port mapping table

Resolution I received by email from Mikrotik support:
in RouteroS 6.x it will not be possible to bring all this information together. You will have to wait till RouterOS 7.x release to see what hosts on what port are available.
by pimmie
Thu Sep 03, 2015 3:32 pm
Forum: General
Topic: SNMP queries for MAC->port mapping table
Replies: 19
Views: 9059

Re: SNMP queries for MAC->port mapping table

the oid mac-address / .1.3.6.1.2.1.2.2.1.6.1
Sorry, I copied the wrong oid. It should be .1.3.6.1.2.1.17.4.3.1.2
by pimmie
Tue Sep 01, 2015 11:53 pm
Forum: RouterBOARD hardware
Topic: rb3011 based on ARM CPU
Replies: 57
Views: 35841

Re: rb3011 based on ARM CPU

As I also have some projects coming up, I wonder if Mikrotik/Normis could give some rough estimate when the 3011 and hAP ac will become available? A small follow up for fellow anxious waiters; we gave Mikrotik a call and on the phone they said both devices should be available end of Q3 / last week ...
by pimmie
Tue Sep 01, 2015 11:49 pm
Forum: General
Topic: SNMP queries for MAC->port mapping table
Replies: 19
Views: 9059

Re: SNMP queries for MAC->port mapping table

I have been using the oid mac-address / .1.3.6.1.2.1.2.2.1.6.1 as well to monitor connected devices on my switches and experienced the same issue with RouterOS as pe1chl describes. To me this sounds as a bug in the system. As pe1chl indicates the correct information is actually available in WinBox (...
by pimmie
Mon Aug 17, 2015 11:46 am
Forum: RouterBOARD hardware
Topic: rb3011 based on ARM CPU
Replies: 57
Views: 35841

Re: rb3011 based on ARM CPU

As I also have some projects coming up, I wonder if Mikrotik/Normis could give some rough estimate when the 3011 and hAP ac will become available? Allthough I understand that you can't give us an exact date, it should be possible to give us a 'within 1, 2 or 3 months' date range. E.g. if you already...
by pimmie
Fri Apr 03, 2015 12:41 pm
Forum: Announcements
Topic: MUM Europe 2015 (live video)
Replies: 75
Views: 37986

Re: MUM Europe 2015 (live video)

RB3011 is cool upgrade for 2011 (esp all gigabit and full-size USB), but why not go for dual-band AC wi-fi as well. Maybe not in all versions, but at least as a top one? With such it can be an outstanding home/soho router, without - just very nice one. :) P.S. It is somewhat strange to have dual-ba...
by pimmie
Fri Mar 27, 2015 5:50 pm
Forum: Announcements
Topic: MUM Europe 2015 (live video)
Replies: 75
Views: 37986

Re: MUM Europe 2015 (live video)

Does the 3011 series also include dual band 5Ghz by default or do we need to buy/switch miniPCIe cards ourselves? As the specs of the 2011 are quite similair to the CRS125 series, are there plans to upgrade the CRS125 series as well with the new ARM processor? A 3011 or CRS125v2 with dual band 2.4/5...