Even to same hardware that is mean to replace the original ?Also, it is not a good practice to return a .backup from one router to another.
Ok... what woud be your approach to this ?Very feasible, the only question I have is why are the two VLANS 'open' to each other.
Fair question question - we want to be able to filter between the two or even to split (obviously loosing the redudency)Why not just have one LAN then?
Yep - good idea.VLANs would be another option, with everything on the same bridge but VLAN'ed off from each other.
add name=dhcp-Net2 ranges=192.168.0.101-192.198.0.199
That's rather impressive.i recommend you use CHR. I already use several CHR routers on 1Gbps WAN links with GRE+IPsec tunnels (aes-128 gcm). Even with 1vCPU routers can 950Mbps.
This is mikrotik to mikrotik - are there ovpn config files involved (I only ibnteract with the Winbox GUI or CLI) ?You can include them in the .ovpn configuration, e.g. route 192.168.99.0 255.255.255.0 vpn_gateway
Yep - I guess we will have to settle to that solution. IP could be assigned based on the MAC of each device (there are not that many of them)... but we would have loved to step it up :)Typing in the IP of any shared resource connects to and from... But you have to know what you are looking for.
04:47:41 ipsec,debug -an acceptable proposal found-
04:47:41 ipsec,debug dh(modp1024)
04:47:41 ipsec,debug -agreed on pre-shared key auth-
Aha - yes they do get IP from the same pool that serves the LAN subnet. Is that not best practice ?It depends. In case the client gets IP address from LAN subnet, you need proxy ARP on LAN interface. Firewall can also be the cause.
More than happy to do so and to learn but quite frankly had no idea how to change the default route distance on a DHCP client... Thanks for your help there !Some things you should try to do yourself atleast, below is where you can change the default route distance on a DHCP client
Anyone ... ?Next question is how do I achieve it ? Those automatic routes don't seem to be "editable", at least not from Winbox...
Oh- was about to ask for an upgrade from our electric providerCosmetic error on a RB1100AHx4 in Winbox under System>Health. It's showing 49.5 amps. Terminal is showing 495 ma.
[me@mikrotik.contoso.com] /ip firewall nat> add action=accept chain=srcnat comment="Something" dst-address=<172.16.175.0/24> src-address=<172.16.100.0/24>
value of range must have ip address before '/'