Outline ·
[ Standard ] ·
Linear+
Enterprise Networking Mikrotik Routers (RouterBoard & RouterOS), User and owner discussion group
|
Gaara92
|
May 13 2021, 09:40 AM
|
|
QUOTE(asellus @ May 13 2021, 09:33 AM) Disable IPv6 and see if Mikrotik website can load or not. yup confirmed it is IPv6 problem and it seems from mikrotik ends, so tm unifi is not the problem. it is mikrotik ipv6 address.
|
|
|
|
|
|
Gaara92
|
May 13 2021, 12:58 PM
|
|
QUOTE(mamakap @ May 13 2021, 10:37 AM) Ok is confirm, it is IPv6 issue, I blocked IPv6 traffic on my network, now I can access the website. But I am kinda curious, browsers always use happy eyeballs also called fast fallback when it try to access a website. In case the ipv6 failed it will fallback to ipv4. But not in this situation, this is quite weird.
|
|
|
|
|
|
Gaara92
|
Jun 9 2021, 06:54 PM
|
|
QUOTE(rodyeo @ Jun 4 2021, 09:35 PM) Hi! MikroTik Malaysia Gurus, I need some tips how to get my MikroTik RB750Gr3 (home router) on TMnet Unifi 300Mbps Fiber Internet via PPPoE at ether1 main link to failover to ether2 backup link via neighbour relatives wifi link via MikroTik RBD52G (Router-Bridge) CPE Router mode on wifi 5G link configuration. Thanks Rodyeo There is a lot of ways to do failover. You can use route distance by specifying check gateway or you can use script to check the gateway and disable/enable the default route automatically. Other ways is by using mangle rules to create PCC. Your choice
|
|
|
|
|
|
Gaara92
|
Jun 15 2021, 05:08 PM
|
|
QUOTE(go626201 @ Jun 13 2021, 11:07 PM) Hi guys ,do you think this year will have a new generation(RB5011) to RB4011? Currently using RB750Gr3-800Mbps Unifi,but sometimes the cpu burst to 40%,and vpn client sometimes fast sometimes slow. I want to buy new mikrotik router but scared later the new generation one coming...And I will depressed.... There is another same router called hEX S I use this model with L2TP ipsec vpn 24/7 and the speec and processing is good, I got 100% bandwidth same as my subscription using VPN.
|
|
|
|
|
|
Gaara92
|
Jun 15 2021, 05:09 PM
|
|
QUOTE(delaciox @ Jun 10 2021, 10:43 PM) hi, i want to ask about vrrp and vlan i have 2 unifi tm line, i wan to setup pcc load balance. so i need to vrrp first than vlan or vlan first than vrrp?? router is rb750gr3 lan 1 is empty, netinstall backup lan 2 is btu in lan 3 - 5 bridge LAN out I think PCC load balance need to use mangle rules. While VRRP is for LAN Gateway right, if you have 2 router for redundancy and another one is down, so VRRP will take place and reroute you to another router.
|
|
|
|
|
|
Gaara92
|
Jun 28 2021, 04:08 PM
|
|
QUOTE(Anime4000 @ Jun 24 2021, 05:05 PM) I see... but, RB3011UiAS-RM has port flopping issue, I can't use full speed file transfer and it will cause switch chip to restart. Using RB4011 also have sfp compatibility issue. CCR is your solution. Go adopt one of 'em
|
|
|
|
|
|
Gaara92
|
Jun 28 2021, 04:09 PM
|
|
QUOTE(delaciox @ Jun 16 2021, 10:17 AM) i mean use one btu inout with 2 pppoe unifi which one is correct setting? WAN2 is connect BTU port A. WAN2 -> VRRP1 -> VLAN500 -> PPPOE unifiA ~~~~ -> VRRP2 -> VLAN500 -> PPPOE unifiB B. WAN2 ->VLAN500 -> VRRP1 -> PPPOE unifi A ~~~~~~~ ~~~~ -> VRRP2 -> PPPOE unifi B I didn't know you can use one BTU to connect dual unifi? Have you tried thm?
|
|
|
|
|
|
Gaara92
|
Jul 24 2021, 05:18 AM
|
|
QUOTE(asellus @ Jul 22 2021, 01:35 PM) Should be available very shortly from now. If Australians prices to be taken into context, Malaysia's prices should be similar to RB4011iGS when it first appears in SubTel's shop. Great news! Can't wait to get it hehe My last RB was RB2011 series, since then I just bough the hAP series and hEX
|
|
|
|
|
|
Gaara92
|
Oct 29 2021, 09:00 PM
|
|
QUOTE(asellus @ Oct 22 2021, 12:05 AM) If the SFP+ cage or the 2.5G Ethernet port are directly connected to the CPU (the CPU supports them), then I would have bought it. Therefore, my plan is to just upgrade RB4011iGS to routerOS 7 when it become final. what is the advantages of having the higher speed port connected to the cpu itself? I have seen the comparison in the video it says the performance is doubled compared to rb4011?
|
|
|
|
|
|
Gaara92
|
Oct 29 2021, 09:16 PM
|
|
QUOTE(asellus @ Oct 29 2021, 09:12 PM) So that WAN network doesn't have to waste CPU-switch 10Gbps link capacity. With RB4011, I put WAN interface on the SFP+ cage, and all Internet traffic has its own dedicated lane to the CPU (for routing et. al), before going to the two port-multipliers through their own dedicated 2.5Gb links. For RB5009, no matter if you use 2.5Gb port or the SFP+ for WAN interface, all raw Internet traffic will go through the 10Gbps link first for routing or other things before going through the 10Gbps link again to the switches. I think they make the cpu to utilize the container package as v7 can have containers run on it. Otherwise why would the did not put any load on the cpu?
|
|
|
|
|
|
Gaara92
|
Oct 29 2021, 09:20 PM
|
|
QUOTE(Anime4000 @ Oct 23 2021, 03:26 PM) I see, if doing home server should be enough, since switch chip run at 10Gb and GPON ONU SFP Stick run at 1Gb. I been trying EdgeRouter 12 and RB3011UiAS, I prefer Mikrotik way to setting networking, also, when set PPPoE MTU to 1500 bytes, IPv6 on ER12 quite broken, currently my ER12 1500 bytes on IPv4 & 1492 bytes on IPv6, for Mikrotik, 1500 bytes on both IPv4 and IPv6. Just bought the GPON on your link haha. Sebelum ni tak sempat beli, nanti nak follow guide flashing kat github.
|
|
|
|
|
|
Gaara92
|
Oct 31 2021, 12:42 AM
|
|
QUOTE(simon82 @ Oct 30 2021, 06:06 PM) I just bought a used gr3... for beginners, it quite hard to do all the settings... so many functions available.. anyway... i tried to use vpn client in one of my pc... the downloading speed is horrible... is there a way to improve the performance of vpn... I saw in the vpn connection details... it stated IKEv2 protocol... my internet is 300mbps D/50mbps U and is getting 1-5MB download speed... recheck your configuration. I have been using L2TP/IPsec over 100Mbps unifi plan so far I got full speed.
|
|
|
|
|
|
Gaara92
|
Oct 31 2021, 12:44 AM
|
|
QUOTE(Selectt @ Oct 30 2021, 08:52 PM) what enterprise feature for this device that is important for SME? Most of it you can set VLAN, VPN server and clients, some scripting for remote or monitoring. You can do eveything in Mikrotik, even the latest beta version 7 you can run docker container.
|
|
|
|
|
|
Gaara92
|
Nov 1 2021, 11:49 PM
|
|
QUOTE(thankyou @ Nov 1 2021, 12:45 AM) I can't see the dedicated full-duplex 10Gbps Switch<->CPU has disadvantages on RB5011. RB4011 block diagram consists of 2.5 + 2.5 + 10Gbps connecting to CPU so technically it's only 5 Gbps max transfer speed provided you are transferring from SFP+ -> SW1 (2.5Gbps) + SW2 (2.5Gbps)... assuming SFP+ is used for WAN, you'll be using 1Gbps at max... With SFP+ transfer at full 1Gbps speed, still... you have a spare 9Gbps compare to 2.5+2.5 in RB4011. I personally think RB5011 have a better network flow. You mean RB5009, there is no RB5011 haha. Anyhow the chart showing that packets flow is more promising on the latest RB5009
|
|
|
|
|
|
Gaara92
|
Nov 2 2021, 04:27 PM
|
|
QUOTE(wong_86 @ Nov 2 2021, 04:22 PM) I already set pihole IP in DHCP server but unable to resolve address, i stuck in firewall there, try route all DNS service to Pihole to resolve. try exporting your firewall configuration and paste it here. Use this command on mikrotik terminal CODE /ip firewall filter export hide-sensitive CODE /ip firewall nat export hide-sensitive
|
|
|
|
|
|
Gaara92
|
Nov 2 2021, 05:39 PM
|
|
CODE add action=dst-nat chain=dstnat dst-address=!192.168.88.253 dst-port=53 protocol=udp src-address=!192.168.88.253 to-addresses=192.168.88.253 add action=dst-nat chain=dstnat dst-address=!192.168.88.253 dst-port=53 protocol=tcp src-address=!192.168.88.253 to-addresses=192.168.88.253 add action=masquerade chain=srcnat dst-address=192.168.88.253 dst-port=53 protocol=udp src-address=192.168.88.0/24 add action=masquerade chain=srcnat dst-address=192.168.88.253 dst-port=53 protocol=tcp src-address=192.168.88.0/24 these 4 lines change it to: CODE add action=dst-nat chain=dstnat dst-port=53 protocol=udp src-address=!192.168.88.253 to-addresses=192.168.88.253 to-ports=53 add action=dst-nat chain=dstnat dst-port=53 protocol=tcp src-address=!192.168.88.253 to-addresses=192.168.88.253 to-ports=53 add action=masquerade chain=srcnat dst-address=192.168.88.253 dst-port=53 protocol=udp src-address=!192.168.88.253 add action=masquerade chain=srcnat dst-address=192.168.88.253 dst-port=53 protocol=tcp src-address=!192.168.88.253 Your dst-nat dont need to put dst address, just needed the source and to-address. This post has been edited by Gaara92: Nov 2 2021, 05:45 PM
|
|
|
|
|
|
Gaara92
|
Nov 6 2021, 10:52 PM
|
|
QUOTE(loonsave @ Nov 5 2021, 04:56 PM) Hi Sifu, I used to use pfsense for more that 10 years. But I am going to turn off my VM to reduce energy usage. Please recommend me an entry-level of Mikrotik router to achieve function below. I am subscribing to 300Mbps Tm UniFi. 1. Site-to-Site VPN to Surfshark with destination route for certain websites via the VPN tunnel. 2. Road warrior VPN, prefer OpenVPN/Wireguard. 3. Block access to certain websites at certain hour. 4. Working well with TP-Link Deco X20 AP Mode. 5. VLAN separation for IoT/Security devices. Thank you.  What is your budget? If below rm1k then get the latest new model RB5009 equipped with 10Gbps SFP+ FTW. Otherwise you can get a hEX S, or hAP ac2 or hAP ac3. But it would be a waste since you already got your own Deco AP, get an RB5009 instead it is using native RouterOS v7 already and support WireGuard and ZeroTier also!
|
|
|
|
|
|
Gaara92
|
Nov 7 2021, 12:15 AM
|
|
QUOTE(go626201 @ Nov 6 2021, 11:22 PM) Currently ROS7 still at beta stage... IPv6- DHCPv6 PD not working for Unifi. Better wait for 6month later to get ROS7 only device... So i suggest in current state and for his requirements just get a device that cost about RM300 is enough for now since it is his first time to join Mikrotik. Why would you use DHCPv6? Isn't unifi provide IPv6 using stateless SLAAC mode?
|
|
|
|
|
|
Gaara92
|
Nov 7 2021, 01:08 PM
|
|
QUOTE(soonwai @ Nov 7 2021, 12:38 PM) Getting RB5009 soon. Later I check how to configure IPv6 or why it doesn’t work. I also follow the guides previously posted. Already got mine, but can't test yet because my main router has builtin AP inside it so I don't want to disrupt my family's work since they all wfh and using wifi. Am waiting for y U6-LR haven't reach yet.  QUOTE(go626201 @ Nov 7 2021, 12:45 PM) ROS 7 bug,Mikrotik forum already have people talks about that,and the latest beta version still not fixed. Other than that,i also still try to learn how to use the Wireguard as client on ROS7...Trying to redirect china traffic with vpn service to mitigate the crap routing on unifi. Currently using IKEv2 IPsec VPN on Mikrotik but the cpu usage is quite high when the speed is higher without fasttrack.(VPN usage does not work with fasttrack so cpu usage will be higher) Nothing has even been stable if you are using ROS, even the their stable version v6 also got bug. This post has been edited by Gaara92: Nov 7 2021, 01:11 PM
|
|
|
|
|
|
Gaara92
|
Nov 7 2021, 02:22 PM
|
|
QUOTE(loonsave @ Nov 7 2021, 01:44 PM) This is one of the reason why I switched from pfsense + ubiquiti to a simple Deco setup. I always test various configuration and it interrupt the home network. Sometimes power outage cause the pfsense not boot up correctly in day time. End up I decided to moved to a simple solution that my parent know how to reboot a router when I not around. But after switched for months, I feel paranoid when I don't have access to logs and information from my router, I can't see why the Deco not connect to the PPPoE, no snmp to monitor the usage, etc.  I know right. Being a network admin/engineer is the lust and urge to watch the logs and also the data transfer rate haha
|
|
|
|
|