Hi, sorry for the late replied.Looks like too broad masquerade rule.
i'll try it later tks.Maybe you must add rule to forward chain?Code: Select allchain=forward action=accept src-address=0.0.0.0 dst-address=172.16.10.0/24 log=no log-prefix=""
yes it isDoes your DHCP supply gateway address?
already did it in router1. After route i can ping 172.16.10.1 but can't ping client (ex.172.16.10.252)try to add:
172.16.10.0/24 gate 192.168.10.x ( your gateway )
the 2nd router don't have any NAT, try to add once but it's the same result.are you using any NAT on the second router?
How about firewall, on both routers and the destination client?
Hi, thanks for your reply.In case 2
Try to work dhcp-client and select ether who in case 1
And finally try to access hotspot from case 2
Im using tools>bandwidth test in routerOS to testHow do you test? Which tools are you using?
so the internet speed drop because the router RB2011 can't handle it ?You should upgrade to RB1100 or CCR1009
i know i won't give the exact numer but at least it should around 130~150Mbits. My speedtest result only give me 90~100 at best.do you check your configuration?
after all pcc load balance wont give you all of 150mbps
Could you show me how to enable fasttrack ?With fasttrack enabled, it is possible to reach 500 Mbps download at least.
If you use ookla, the speed that you see depends on which server you connect to.
im using 1gbits port (port5) to test but the result only 100Mbits on speedtestWhat ports are involved in your test? Switch 2 has only single 100mbits line to cpu.
it's worked. Thanks alotYou need to specify src-address when pinging from the router.
From Router1:You can also check IpSec "Remote peers" section for phase1 status and "Installed SA" for phase2 status.Code: Select all/ping 172.16.20.X src-address=172.16.10.Y
/ip firewall filter
add action=accept chain=forward dst-address=[IP WAN1] src-address=\
192.168.1.180
add action=drop chain=forward dst-address=[IP WAN2] src-address=\
192.168.1.180
my config on ether5 and vlan is exactly like my 1st post.Show your config for ether5 and the VLAN.
Sory about that. I still new to network so i don't know much about it.I wrote the same thing on Thu Apr 07, 2016 10:35 am but you ignored it...
No choices huhAsk your friend to come by for a beer and fix your network.
Could you show me how to do it plsYou only need to configured Mikrotik as Dns server and assign this DNS via DHCP.
yours worked too.If You don't need access from outside to routerA, problem is solved.
RouterA will be inaccessible because connections from Internet to any port on routerA will be redirected to routerB. The idea of my slution was to give access to routerB keeping access to routerA.
chain=dstnat action=dst-nat to-addresses=192.168.0.33
dst-address=101.99.47.x log=no log-prefix=""
Look more confused now lol =]]. I think i will try to redirect it with nat rule :vthis image shows the conceptcould you be more specific pls. I'm still new to thismake a VPN to another site under your control and with IP public address
Which router should i make a VPN ?
could you be more specific pls. I'm still new to thismake a VPN to another site under your control and with IP public address
i know but ppl says i can ip cloud if i redirect port so i wan to try itYou can use romon
created firewall rules on both router A&B but still not workingHi ,
you are changing ports ! so it's a one way communication , packets reach Router B , but unable to come back , i think we should have 2 NAT here , one in router A , one in B
2 NAT in router A&B with the same config right ?Hi ,
you are changing ports ! so it's a one way communication , packets reach Router B , but unable to come back , i think we should have 2 NAT here , one in router A , one in B
could u show me how to redirecting port to the back routerCheck Romon, I believe it's the thing you need
http://wiki.mikrotik.com/wiki/Manual:RoMON
or you can do some NAT in your "front" router, redirecting some random port to the "back" router.
Could you be more specific plz ???a better way to do this can be assign a master port to each group of ethernet ports and then that master port give the addressing of the corresponding subnet, no bridges
How to use tagged mode ?? i already enabled "Use Service Tag" in Vlan config but it's not working ?i think in your configuration vlans are working but only in tagged mode that is vlan packets are tagged with vlanid
Thanks a lot bajodel and jarda for helping me solved this problemJust open the first pool and set the second to be continued in it...
In other words, set pool2 as "next pool" of pool1. In dhcp server set only pool1. The pool2 should be used automatically when pool1 is exhausted.
that means 2 dhcp in 2 different bridge right?Set two dhcp pools
can u show me how. ThanksUse firewall rules to enable the first pool and disable the scond pool internet access
randomly selected first 4040 listed individuals or randomly selected first 40?