I bought hAP ax Lite 6 for mobile router. I configure it but there is very strange problem with internet. I can ping google from router terminal but there is no internet on connected clients. I've checked firewall rules but I can't find solution. Anyone can help me??
Config:
Code: Select all
# 2024-12-22 12:26:49 by RouterOS 7.16.2
# software id = 1C94-WC90
#
# model = L41G-2axD&FG621-EA
# serial number = removed
/interface bridge
add name=bridge
/interface lte
set [ find default-name=lte1 ] allow-roaming=yes band="" sms-protocol=auto \
sms-read=no
/interface list
add name=LAN
add name=WAN
/interface lte apn
set [ find default=yes ] authentication=chap name=T-Mobile use-network-apn=no
/interface wifi channel
add band=2ghz-ax disabled=no frequency=2417 name="Kanal1 AX" width=20/40mhz
/interface wifi datapath
add bridge=bridge disabled=no name=datapath1
/interface wifi security
add authentication-types=wpa2-psk,wpa3-psk disabled=no encryption=ccmp,gcmp \
name=sec1
/interface wifi configuration
add channel="Kanal1 AX" country=Poland datapath=datapath1 disabled=no mode=ap \
name=cfg1 security=sec1 ssid="ZENLan LTE AX"
/interface wifi
set [ find default-name=wifi1 ] channel.frequency=2417 configuration=cfg1 \
configuration.mode=ap disabled=no
/ip pool
add name=pool1 ranges=192.168.10.2-192.168.10.254
/ip dhcp-server
add address-pool=pool1 interface=bridge lease-time=10m name=server1
/interface bridge port
add bridge=bridge interface=wifi1
add bridge=bridge interface=ether1
add bridge=bridge interface=ether2
add bridge=bridge interface=ether3
add bridge=bridge interface=ether4
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface detect-internet
set internet-interface-list=WAN wan-interface-list=WAN
/interface list member
add interface=bridge list=LAN
add interface=lte1 list=WAN
/ip address
add address=192.168.10.1 interface=bridge network=192.168.10.0
/ip dhcp-server network
add address=192.168.10.0/24 gateway=192.168.10.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/ip firewall filter
add action=accept chain=input comment="Ruch poprawny" connection-state=\
established,related,untracked
add action=accept chain=forward comment="Ruch poprawny" connection-state=\
established,related,untracked
add action=accept chain=input comment="Ping routera z WAN" protocol=icmp
add action=accept chain=input comment=CAPSMAN dst-address=127.0.0.1
add action=fasttrack-connection chain=forward comment=FastTrack \
connection-state=established,related hw-offload=yes
add action=drop chain=input comment="Ruch niepoprawny" connection-state=invalid
add action=drop chain=forward comment="Wszystko co niezdefiniowane" \
connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
add action=drop chain=input comment="Wszystko co nie LAN" in-interface-list=!LAN
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=WAN
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/system clock
set time-zone-name=Europe/Warsaw
/system identity
set name="ZENLan LTE"
/system note
set show-at-login=no