r/mikrotik Jul 21 '19

New Mod Guideline - If you don't have anything nice to say..

165 Upvotes

I'll try and keep this short - there's been a marked increase in generally abrupt and abrasive comments here on the /r/mikrotik and it's not what we're about or what we want to see happening. Many of these have been due to content that is or is seen to be incorrect or misleading, so..

If you're posting here:

Keep in mind none of us are being paid to answer you and the people who are, are doing so because they want to help, or you've posted something so incredibly incorrect they can't help but respond. Please do yourself a favor by collecting all the information you can before posting and make sure to check the MikroTik wiki first - no one wants to spoon feed you all the information.

If you're commenting here:

  1. If you don't know the answer - don't try guess at it; and if you want to learn about it yourself then follow the thread and see what others say, or you know.. read the wiki and try it out in a lab.
  2. If you disagree with another poster, try to explain the correct answer rather than a one sentance teardown that degrades into a thread full of name-calling.

As a result of this I've added a new rule & report option - you can now report a comment with the reason being:

It breaks /r/MikroTik rules: Don't post content that is incorrect or potentially harmful to a router/network

If we agree we'll either:

a) Write a correct response

b) Add a note so that future readers will be made aware of the corrections needed

c) If the post/comment is bad enough, simply delete it

I'm open to feedback on this as I know people feel strongly about timewasting and I'd like to hope this helps us continue to self-moderate without people blowing up at each other.


r/mikrotik 6h ago

Atualização de RouterBoard MikroTik hAP lite (Problema de Espaço)

0 Upvotes

Visão Geral do Problema

O modelo hAP lite possui um total de 16 MB de armazenamento. Quando o equipamento está em uso e totalmente configurado, o espaço livre torna-se insuficiente para armazenar o pacote de atualização do RouterOS.

Passo 1: Realizar o Reset do Equipamento (CUIDADO Isso apga toda configuração) FAÇA UM BACKUP ANTES E COPIA PARA FORA DA HAP LITE

Como o espaço ocupado pelas configurações atuais impede o armazenamento do arquivo de atualização, é obrigatório remover todas as configurações da RouterBoard com reset.

  1. Acesse o MikroTik e execute o reset.
  2. No momento do reset, certifique-se de marcar as seguintes opções:
    • Sem configuração de fábrica (No Default Configuration)
    • Sem backup (Do Not Backup)
  3. Aguarde o equipamento reiniciar. Com esse procedimento, o espaço livre será de 8 MB, o suficiente para receber o arquivo.

Passo 2: Conectar à Internet

Após o reset, conecte o hAP lite à rede com acesso à internet para iniciar o procedimento de download do pacote de atualização.

Orientações Específicas para Migração da Versão 6 para a Versão 7

Caso o equipamento esteja rodando o RouterOS v6 e você precise atualizá-lo para a versão 7, o processo exige uma etapa intermediária obrigatória:

  • Atualização via Menu do RouterOS: Ao buscar atualizações diretamente pelo sistema, o próprio RouterOS sugerirá automaticamente a versão 7.12.1 como primeiro passo obrigatório.
  • Atualização Manual (Cópia de Arquivo): Se o procedimento for feito manualmente enviando o arquivo para a RB, você deve carregar e instalar primeiro a versão 7.12.1.

Procedimento Pós-v7.12.1:

  1. Assim que a versão 7.12.1 estiver aplicada, será necessário realizar um novo reset do equipamento seguindo o mesmo procedimento do Passo 1 (sem configuração e sem backup).
  2. Com o espaço devidamente liberado novamente, proceda com a última atualização para a versão mais recente e desejada do RouterOS.

----------------------------------------------

Problem Overview

The hAP lite model has a total of 16 MB of storage. When the device is in use and fully configured, the free space becomes insufficient to store the RouterOS update package.

Step 1: Perform a Device Reset (WARNING: This erases all configurations) MAKE A BACKUP FIRST AND SAVE IT OUTSIDE THE HAP LITE

Because the space occupied by the current configurations prevents the storage of the update file, it is mandatory to remove all configurations from the RouterBoard via reset.

  1. Access the MikroTik and perform the reset.
  2. During the reset, make sure to check the following options:
    • No Default Configuration
    • Do Not Backup
  3. Wait for the device to reboot. With this procedure, the free space will be 8 MB, enough to receive the file.

Step 2: Connect to the Internet

After the reset, connect the hAP lite to a network with internet access to start the update package download procedure.

Specific Guidelines for Migrating from Version 6 to Version 7

If the device is running RouterOS v6 and you need to update it to version 7, the process requires a mandatory intermediate step:

  • Update via RouterOS Menu: When searching for updates directly through the system, RouterOS itself will automatically suggest version 7.12.1 as a mandatory first step.
  • Manual Update (File Copy): If the procedure is being done manually by uploading the file to the RB, you must first load and install version 7.12.1.

Post-v7.12.1 Procedure:

  1. Once version 7.12.1 is applied, it will be necessary to perform a new device reset following the same procedure as Step 1 (no default configuration and do not backup).
  2. With the space properly freed up again, proceed with the final update to the latest and desired RouterOS version.

r/mikrotik 1d ago

CSS326-24G-2S+ Weird Issue

3 Upvotes

Just got a hand-me-down CSS326-24G-2S+RM for my home rack, new 2.5Gbe internet connection, and tried using this switch with 10Gb FS generic branded sfps to pass-thru to my 2.5Gbe router and only getting 100mb of traffic on the wire.

Link state shows 10G on the Mikrotik ports with no errors.

CSS326-24G-2S+
SwOS 2.18
Dedicated Sfp Vlan
Flow control on
FS SFP-10G-T 30m
30 foot run Cat6a

Moved those same two ethernet cords to my tester unmanaged multi-gig Linksys switch and no issues getting my expected multi-gig traffic. Was really hoping for the rack solution to work on
the Mikrotik.

Open to any thoughts?


r/mikrotik 2d ago

Help with VLAN configuration - RB750Gr3

6 Upvotes

Having some difficulties getting 2 vlans (ID 2 and 3) running with my Mikrotik router, specifically with DHCP. Both should also have routability to the internet. New to MikroTik routers, while I'm pretty sure my network VLAN configuration is correct and thus my issue is the Mikrotik configuration - I'll still share it as I'm about 10 years removed from network management professionally so I'm rusty AF and definitely could have screwed something up. Appreciate any help!

Network:

Layout: Access Point -> Managed Switch -> Mikrotik.

Switch's uplink to the Mikrotik and the access point's ports are configured as Untagged on vlans 1, 2, and 3.

Access point has two SSIDs, one assigned vlan 2 and one assigned vlan 3.

Plugging a device into a different port and configuring it as tagged on either vlan 2 or 3 results in the same problem (not pulling an IP from the Mikrotik)

Mikrotik

I will note that I have left the defconf assigned to interface bridge, and related defconfs in the sections below active in case that's my problem.

I have configured the VLANs in the following locations:

Interfaces -> VLAN: Interface is set to ether5, the uplink to the switch.

IP -> DHCP Server -> DHCP: Vlan2 has Server Address set to 172.24.0.1, vlan2 to 192.168.0.1 IP -> DHCP Server -> Networks: Same as above, with netmask /24 IP -> Addresses: Same as above, interface assigned to the vlan in question.


r/mikrotik 2d ago

TCP ACKs eating airtime, searching for wifiwave2 fix

10 Upvotes

Been chasing this one for over a week and I've hit the "ask the internet before I do something rash to a perfectly good AP" stage.

Setup is four MikroTik APs, two hAP ax S and two wAP ax, all on 7.23.2, wifiwave2, one of them running CAPsMAN with local forwarding, everything bridged onto a flat network. A FRITZ!Box does the routing and NAT. Nothing exotic.

The problem: any WiFi client pulling a download off the internet tops out around 150Mbit. Doesn't matter which client (tested a Linux laptop and a Galaxy phone, both land in the same 110-180 range), doesn't matter which AP or whether it's the MediaTek or the Qualcomm radio. Same story everywhere.

What makes it weird is it's ONLY WiFi + internet + download:

WiFi -> internet download ~150 Mbit

WiFi -> internet upload ~400 Mbit

WiFi -> LAN host (iperf3) 500 Mbit

wired -> internet 900 Mbit

So the air is clearly fine (500 to a local box), and the router and WAN are fine (900 over the wire through the same FRITZ and the same NAT). It's specifically wireless plus a high-RTT internet path pulling a download.

I ran a pile of tests and the one that cracked it open was this: I forced the client's TCP ACKs out over its ethernet port while the actual download data kept coming over WiFi. Same server, same minute. It jumped from 150 to 540. The only thing that moved off the air was the little return stream of ACKs. I checked the interface counters and all the actual payload still crossed the radio, only about 150k tiny ACK packets went to the wire, and that alone was worth 3.5x.

My read is it's an airtime thing. Half duplex, so every time the client grabs the medium to send its ACKs, that's airtime the AP isn't using to push the download down. Barely matters at 2ms LAN RTT because there are hardly any ACKs in flight, but at 15ms internet RTT the return stream is constant and it's stealing a big chunk of downlink airtime.

Stuff I've already ruled out, so nobody has to retype it:

- not the receive window (it autotunes to 3-5MB during the slow transfer, and forcing 32MB rmem changed nothing)

- not loss or retransmits (the slow internet runs have basically zero retransmits, while the fast 500Mbit LAN runs have thousands, so if anything it's backwards)

- not client bufferbloat (wlan0 is noqueue, mac80211 already runs fq_codel+AQL, and a ping from the client to the AP doesn't inflate at all under a saturating download. cake with ack-filter did nothing)

- not channel/width/DFS, not CPU (per-core stayed under 66% during the stall and was actually lower at 350Mbit on a LAN transfer), not the switch, not queue type (SFQ vs fq-codel identical), not CAPsMAN (a guy on the MikroTik forum reproduces it on a standalone hAP ax with no CAPsMAN at all), not congestion control (bbr vs cubic same)

UDP one direction over the same hop does 250-370Mbit no trouble, which again says the air carries way more than 150 the moment you take ACKs and RTT out of it.

So the actual question: is there anything in wifiwave2 that touches uplink airtime scheduling, TXOP, MU-EDCA, trigger frames / UL-OFDMA, anything that would let the AP hand the client airtime for its ACK stream more efficiently? I've been through /interface/wifi pretty thoroughly and can't find a knob for it. Or is this just where the driver is right now and I should stop looking and live with it?

I've got a support ticket open with MikroTik but figured I'd ask here too, redditors bailed me out before and you lot are usually quicker than the queue. Happy to post any config or test output if it helps.


r/mikrotik 2d ago

[Pending] TCP ACKs eating airtime. Searching for wifiwave2 fix

5 Upvotes

Been chasing this one for over a week and I've hit the "ask the internet before I do something rash to a perfectly good AP" stage.

Setup is four MikroTik APs, two hAP ax S and two wAP ax, all on 7.23.2, wifiwave2, one of them running CAPsMAN with local forwarding, everything bridged onto a flat network. A FRITZ!Box does the routing and NAT. Nothing exotic.

The problem: any WiFi client pulling a download off the internet tops out around 150Mbit. Doesn't matter which client (tested a Linux laptop and a Galaxy phone, both land in the same 110-180 range), doesn't matter which AP or whether it's the MediaTek or the Qualcomm radio. Same story everywhere.

What makes it weird is it's ONLY WiFi + internet + download:

WiFi -> internet download ~150 Mbit

WiFi -> internet upload ~400 Mbit

WiFi -> LAN host (iperf3) 500 Mbit

wired -> internet 900 Mbit

So the air is clearly fine (500 to a local box), and the router and WAN are fine (900 over the wire through the same FRITZ and the same NAT). It's specifically wireless plus a high-RTT internet path pulling a download.

I ran a pile of tests and the one that cracked it open was this: I forced the client's TCP ACKs out over its ethernet port while the actual download data kept coming over WiFi. Same server, same minute. It jumped from 150 to 540. The only thing that moved off the air was the little return stream of ACKs. I checked the interface counters and all the actual payload still crossed the radio, only about 150k tiny ACK packets went to the wire, and that alone was worth 3.5x.

My read is it's an airtime thing. Half duplex, so every time the client grabs the medium to send its ACKs, that's airtime the AP isn't using to push the download down. Barely matters at 2ms LAN RTT because there are hardly any ACKs in flight, but at 15ms internet RTT the return stream is constant and it's stealing a big chunk of downlink airtime.

Stuff I've already ruled out, so nobody has to retype it:

- not the receive window (it autotunes to 3-5MB during the slow transfer, and forcing 32MB rmem changed nothing)

- not loss or retransmits (the slow internet runs have basically zero retransmits, while the fast 500Mbit LAN runs have thousands, so if anything it's backwards)

- not client bufferbloat (wlan0 is noqueue, mac80211 already runs fq_codel+AQL, and a ping from the client to the AP doesn't inflate at all under a saturating download. cake with ack-filter did nothing)

- not channel/width/DFS, not CPU (per-core stayed under 66% during the stall and was actually lower at 350Mbit on a LAN transfer), not the switch, not queue type (SFQ vs fq-codel identical), not CAPsMAN (a guy on the MikroTik forum reproduces it on a standalone hAP ax with no CAPsMAN at all), not congestion control (bbr vs cubic same)

UDP one direction over the same hop does 250-370Mbit no trouble, which again says the air carries way more than 150 the moment you take ACKs and RTT out of it.

So the actual question: is there anything in wifiwave2 that touches uplink airtime scheduling, TXOP, MU-EDCA, trigger frames / UL-OFDMA, anything that would let the AP hand the client airtime for its ACK stream more efficiently? I've been through /interface/wifi pretty thoroughly and can't find a knob for it. Or is this just where the driver is right now and I should stop looking and live with it?

I've got a support ticket open with MikroTik but figured I'd ask here too, redditors bailed me out before and you lot are usually quicker than the queue. Happy to post any config or test output if it helps.


r/mikrotik 2d ago

How do you handle user tracking/logging on a shared MikroTik network?

4 Upvotes

Hi everyone,

I manage a small shared network for an apartment building (~60 apartments).

The setup is:

  • MikroTik router
  • UniFi APs
  • separate management and client VLANs
  • client isolation enabled
  • users are behind NAT

I'm wondering how others handle logging/accountability in this kind of setup.

If one user does something bad, I would like to be able to understand which apartment/user was behind a specific private IP at a specific time.

How do you usually handle this?

I'm not interested in monitoring user activity or browsing history, I just want to be able to correlate:

  • a private IP address → a specific user/apartment
  • a "bad" public IP address reached → back to my private IP/user

r/mikrotik 3d ago

HELP! Mikrotik APs, no DHCP responses when roaming.

4 Upvotes

Intro

New to Mikrotik and I feel like we're "just about to get along". I'm learning a lot and I could really use some help with my config on this one.

I'm posting on r/mikrotik because my devices roamed normally with previous APs (HP 560) and negotiating DHCP between them worked acceptably with all my client devices on, what I can only assume, are default configs. I've had the HPs for ~6 years now, and they were old when I got them, so it was time for an upgrade. I chose Mikrotik because I was given an RB951 to play with many moons ago and I needed to scratch that itch again 😄

Purchased and installed two cAP-ax, one in the house and one in the shed (approx 40m between them, wireless linkup connected by Ubiquiti Nanostation AC Locos). These are the only two Mikrotik device in the network - I want to use CAPsMAN to keep configs alligned between them and future APs.

Network Overview

House
Router: Ubiquiti EdgeRouter ER-X-SFP. DHCP server. < Nanostation is connected direcltly to the router (req. 24v passive poe).
House switch: Teltonika TSW-202 < The house ap is connected to this switch.
The house AP is the CAPsMAN

Shed
Switch: Cisco 2960X-24
Nanostation and Shed AP are connected to the Cisco switch.

No VLANs (yet). This is a flat network.

Behaviour

Fault
When I move between the house and shed (either way), clients slowly lose signal strength with one AP and the device roams to the nearest AP. Clients that roam between the two APs fail to obtain an IP address for approx. 10mins. After which, typically by manually connecting to the network again, they will successfully receive an IP lease and traffic flows again.

Other devices connected to the AP continue to work normally. Devices which haven't roamed can disconnect and reconnect on demand.

The Mikrotik logs show recurring "client detail snip connected, signal strength -42" followed by "client detail snip disconnected, connection lost, signal strength -35" on devices in the fault state.

I've kept a client in the fault state for 30+ mins by manually toggling the wireless adaptor and/or manually repeating attempts to reconnect to the network.

Tested clients: Google Pixel 10, Google Pixel 7 Pro, Lenovo L300e (tested both Debian 13 and Cachy OS).

What I've done so far:

  • Disable WPA3. I read on the Mikrotik forum this causes problems. Using only WPA2-PSK. No change.
  • Set connect priority to 0 / 1 in the security profile (what does this do?). No change.
  • Upgraded to the latest RouterOS firmware v7.23.2
  • Ensure FT and FT-over-DS (what does this do?) is enabled. The client roaming events appear quickly in the logs so I think this is working. No Change in DHCP allocation time after roaming.
  • Factory reset the Shed AP and config as standalone dumb access point. No change. Returned to CAPsMAN provisionning.
  • Packet captures from the Lenovo Laptop and House AP.
    • Laptop broadcasts a DHCP request followed by DHCP discovery packets.
    • House AP receives DHCP request and discovery packets and pcap shows the broadcast went to all bridge interfaces.
  • Disconnect Mikrotik APs, reconnect previous access points (HP 560)
    • Associating with old APs while roaming works as expected.
  • Confirmed there are no datapaths configured in the Wi-Fi settings. (doesn;t look like this is required for flat networks).

What I haven't tried:

In order of what I'll probably do next:

  1. Roam with my work laptop: DELL Pro 14 PC14250 (Windows 11)
  2. Check the DHCP server is receiving requests from devices while in a fault state. Packet capture on the DHCP server while devices are in both operational and fault state.
  3. Remove CAPsMAN. Factory resetting both APs and setup standalone dumb access points.
  4. Reach out to Mikrotik support.

Questions

  • Where should I go from here?
  • Is a DHCP relay reqired for Mikrotik devices on networks with a single subnet?
  • WRT the ability to keep a device in a fault state by repeatedly failing to connect to the network, are there any Mikrotik services/policies which would restrict traffic flow for a period of time that restarts when the event is detected again? Can I show these in the log?

Configs

House ap config:

# 2026-07-19 23:02:09 by RouterOS 7.23.2
# software id = C4PN-IQ17
#
# model = cAPGi-5HaxD2HaxD
# serial number = HMF0B12PMZZ
/interface bridge
add name=bridge1 protocol-mode=none
/interface wifi channel
add band=5ghz-ax disabled=no name=5ghz skip-dfs-channels=all width=\
20/40/80mhz
add band=2ghz-ax disabled=no frequency=2412 name=2ghz-ch1 width=20mhz
add band=2ghz-ax disabled=no frequency=2437 name=2ghz-ch6 width=20mhz
add band=2ghz-ax disabled=no frequency=2462 name=2ghz-ch11 width=20mhz
add band=2ghz-ax disabled=no frequency=2412,2437,2462 name=2ghz-auto width=\
20mhz
/interface wifi security
add authentication-types=wpa2-psk connect-priority=0/1 disabled=no ft=yes \
ft-over-ds=yes name=sec1
/interface wifi configuration
add channel=2ghz-auto country=Australia disabled=no mode=ap name=2ghz \
security=sec1 ssid=ArcNet
add channel=5ghz country=Australia disabled=no mode=ap name=5ghz security=\
sec1 ssid=ArcNet
/interface wifi
set [ find default-name=wifi2 ] configuration=2ghz configuration.mode=ap \
disabled=no name=house-2ghz
set [ find default-name=wifi1 ] configuration=5ghz configuration.mode=ap \
disabled=no name=house-5ghz
# operated by CAP D0:EA:11:99:B1:AA%bridge1, traffic processing on CAP
add configuration=2ghz disabled=no name=shed-2ghz radio-mac=D0:EA:11:99:B1:AD
# operated by CAP D0:EA:11:99:B1:AA%bridge1, traffic processing on CAP
add configuration=5ghz disabled=no name=shed-5ghz radio-mac=D0:EA:11:99:B1:AC
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=house-5ghz
add bridge=bridge1 interface=house-2ghz
/ipv6 settings
set disable-ipv6=yes
/interface wifi cap
set discovery-interfaces=bridge1
/interface wifi capsman
set ca-certificate=auto certificate=auto enabled=yes interfaces=bridge1
/interface wifi provisioning
add action=create-enabled disabled=no master-configuration=5ghz name-format=\
shed-5ghz supported-bands=5ghz-ax
add action=create-enabled disabled=no master-configuration=2ghz name-format=\
shed-2ghz supported-bands=2ghz-ax
/ip address
add address=192.168.1.52/24 interface=bridge1 network=192.168.1.0
/ip dns
set servers=192.168.1.1
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-table=main
/system clock
set time-zone-name=*redacted*
/system identity
set name=House-cAP-01
/system logging
add prefix=CAPsMAN topics=caps,info

Shed AP config

# 2026-07-19 23:04:13 by RouterOS 7.23.2
# software id = 71DQ-UJU6
#
# model = cAPGi-5HaxD2HaxD
# serial number = HMF0B3MQP3M
/interface bridge
add admin-mac=D0:EA:11:99:B1:AA auto-mac=no comment=defconf name=bridgeLocal
/interface wifi datapath
add bridge=bridgeLocal comment=defconf disabled=no name=capdp
/interface wifi
# managed by CAPsMAN D0:EA:11:99:B2:06%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: ArcNet, channel: 5745/ax/Ceee
set [ find default-name=wifi1 ] configuration.manager=capsman datapath=capdp \
    disabled=no
# managed by CAPsMAN D0:EA:11:99:B2:06%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: ArcNet, channel: 2437/ax
set [ find default-name=wifi2 ] configuration.manager=capsman datapath=capdp \
    disabled=no
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1
add bridge=bridgeLocal comment=defconf interface=ether2
/interface wifi cap
set discovery-interfaces=bridgeLocal enabled=yes slaves-datapath=capdp
/ip dhcp-client
add comment=defconf interface=bridgeLocal name=client1
/system clock
set time-zone-name=Australia/Brisbane
/system identity
set name=Shed-cAP-01

r/mikrotik 4d ago

be3 media MA53UG+HbeH - ports randomly flapping and WinBox becomes unusable slow

Thumbnail
gallery
29 Upvotes

I finally got my be3 media MA53UG+HbeH a few days ago after waiting for months, and honestly, I’m having a pretty rough experience with it so far.

The setup is as basic as it gets: internet connection and a simple bridge. There’s almost no CPU or memory usage, but the router gets quite hot. After an hour or two, the Ethernet ports start randomly dropping and reconnecting. The connected devices stay on; it looks like the router ports themselves are the problem.

I reset it and tried again with a completely clean, minimal configuration, but the exact same thing happened.

When this starts, WinBox also becomes incredibly laggy. Even typing in the terminal has a delay of several seconds per letter, which makes it almost unusable.

I’ve worked with quite a few MikroTik devices and installed dozens at different locations, but I’ve never seen behavior like this. I put my ax3 back in with the exact same setup and it has been running perfectly.

Has anyone else had similar issues with the be3 media?


r/mikrotik 3d ago

CRS310 and IGMP snooping

1 Upvotes

I was doing some experimenting in my homelab setup and when I enabled IGMP snooping on the CRS310 it became completely unresponsive (safe mode saved me).

Does anyone know why enabling IGMP snooping would cause issues like this? The CRS310 setup is really basic, it is purely used as a switch so IGMP snooping being turned op perhaps doesn't give any benefits anyway. I was just curious on why it would become unresponsive.


r/mikrotik 4d ago

Mikrotik QOS in front of Ubiquity setup

6 Upvotes

Ok I have been looking around for advice on this and I am either not searching properly or not understanding what I am reading.

I have a whole Ubiquity Dream Machine setup but the QoS on the dream machine is kinda crappy. I would love to be able to use CAKE. I have some experience with Mikrotik hardware and I love it. But I don't want to change how my Ubiquity setup works. Is there a way to put a Mikrotik router in front of my setup. Thinking of getting the RB5009UG+S+IN

Basically like this:
Cable modem > QOS (Mikrotik) > Routing/Firewall/Switching (Ubiquity Dream Machine SE) > WIFI Access Points/Switches (Ubiquity)

Instead of the typical setup:

Cable modem > Firewall/Routing/QOS (Mikrotik) > Switching (Ubiquity Dream Machine SE) > WIFI Access Points/Switches (Ubiquity)

The reason for this is I have a windows server where I have friends who run game servers on it. I really like being able to change my firewall settings remotely with the Ubiquity app if I am not home. If this is impossible or too much of a hassle I will just have to put all the required firewall ports on the Mikrotik. I do know how to disable the NAT of the Dream Machine but realized this will be a bit of work even with that.

Side note, I have seen a post where somebody said that people buy dream machines when they should have gotten a cloud key instead and I agree but I am too deep to replace this now lol

Thanks


r/mikrotik 4d ago

[Pending] How to properly make use of the CAP mode on my hAP ax S?

2 Upvotes

Hello.

I've gotten a used RB009UPr+S+ and replaced my hAP ax S which was serving as the main router and decided to use the hAP as a cAP with the RB controlling it.

For the CAPsMAN configuration I've mainly followed this guide (in polish) and helped myself with the ROS docs. In the video he showcases how to configure the cAP (add a bridge, datapath etc.), but when I went to the hAP manual under buttons and jumpers it says this:

Keep holding the reset button until the LED turns solid, then release it to enable CAP mode. The device will then start searching for a CAPsMAN server.

Now I could do the configuration stated in the video but I was wondering how does one make use of this feature? Obviously this would be much more pleasant to do rather than configuring each access point (especially if/when I add more access points). Thanks a lot


r/mikrotik 6d ago

TikMan – free/open-source LAN discovery + topology for RouterOS (not a Dude replacement, but it fills part of the gap)

40 Upvotes

I'm the author. It's free, MIT-licensed, and there's nothing to buy — no pro tier, no account, no telemetry.

Built with heavy AI assistance (it's in the README and the first commit); tested against multiple real mixed-vendor networks. It exists because I kept missing it in day-to-day support work: something that speaks as many discovery protocols as possible at once and for free, so that an unfamiliar or messy network gives you a picture in a minute instead of an afternoon — rather than guessing which protocol a given box happens to answer to.

Available on GitHub (hopefully soon available for Linux and macOS as well):
https://github.com/pgadient/TikMan/releases

Discovery view for IPv4
Topology view (accessible after providing login, currently only Mikrotik supported)

Since Dude was classified as legacy in March ("provided on an 'as-is' basis, no further updates or enhancements planned") with no successor named, I thought I'd show what I've been building. It still runs, so this isn't a "you must switch" post.

What TikMan is not, first:

It is not a monitoring server. No history, no alerting, no notifications, nothing running 24/7 on your router. If that's what you need from Dude, look at LibreNMS, Zabbix or Observium — I'm not competing with those and won't pretend to.

What it is: the part of Dude I actually used every day — what is on this network, what is it, where is it plugged in, and how do I get into it — as a desktop app that starts in two seconds.

  • Auto-discovery, no protocol picking. It probes MNDP, mDNS/Bonjour, SSDP/UPnP, SNMP, WMI and Zyxel's ZON in parallel and classifies from the strongest evidence it has: model line beats running services, services beat the MAC vendor. An iPhone, an iPad, a HomePod and an Apple TV share one OUI and have no open ports between them — they still come out as four different things. A copier stays a printer even though it serves a web UI, SNMP and SMTP.
  • A physical topology map. Not "these 40 IPs exist", but which switch port each device actually hangs off, read from the bridge forwarding tables — via RouterOS with credentials, or plain SNMP without any login, which also works for non-MikroTik switches. Traceroute can't see L2; the FDB can. Export as PNG or vector PDF.
  • Broken RouterOS HTTPS doesn't stop it. When the TLS handshake fails — and we all know how often it does — TikMan reads over the encrypted SSH CLI instead: resource/CPU/RAM, bridge FDB, neighbours, Wi-Fi SSIDs (CAPsMAN included), logs. Config export and full binary backup go over SSH too.
  • HTTP is a decision, not a default. Plain HTTP works and is fully supported — it's just off by default in the settings. With it off, credentials and configs only ever travel over HTTPS or SSH, and if a device answers on neither, TikMan says so and points at the setting instead of quietly sending your password in clear text. Your network, your call — just not behind your back.
  • Backups: config .rsc and the full binary .backup, with a wizard for picking devices and order.
  • Built-in web server: the same UI in a browser, including an SSH terminal (xterm.js) and a VNC viewer (noVNC). Everything that touches a password is HTTPS-only there.
  • Wake-on-LAN, RouterOS update checks and installs, logs, 7 languages.

Honest limitations: Windows only (WPF/.NET 10). The binaries are unsigned, so SmartScreen will complain on first run. Zyxel ZON discovery needs Npcap — licensing means I can't bundle it, and ZON is Layer 2, so the scanning PC has to sit in the same segment.

Device passwords are stored DPAPI-encrypted locally and are never sent anywhere but the device itself.

Happy to hear what it gets wrong on your network — the classifier is the part that always has one more edge case, and RouterOS boxes are the ones I have fewest of.


r/mikrotik 6d ago

hAP be3 Media: MA53UG+HbeH

6 Upvotes

My newly ordered wi-fi 7 router just arrived. I am a total newbie to Mikrotik and would to see how to install this in my home and the best ways to manage it? I am also planning to plug TP-Link TL-SG116E behind it to manage different vlans etc.


r/mikrotik 6d ago

Problems with the DNS failover script

1 Upvotes

Hi everyone,

The script below had been working for ages on my Mikrotik router:

# set variables
:local primaryDNS "172.16.20.10";
:local fallbackDNS "1.1.1.1,8.8.8.8";
:local currentDNS;
:set $currentDNS [/ip dns get servers];
#:log warning "What I got is: $currentDNS"
#:log warning "What I want to see is: $primaryDNS"
:do {
:put [resolve google.com server=$primaryDNS];
if ($currentDNS!=$primaryDNS) do={
:log warning "DNS Failover: Switching to primaryDNS";
/ip dns set servers $primaryDNS
} else={}
} on-error={ :set $currentDNS [/ip dns get servers];
if ($currentDNS!=$fallbackDNS) do={
:log error "DNS Failover: Switching to FallbackDNS";
/ip dns set servers $fallbackDNS;
} else={:log info "Using Failover DNS, Primary Unavailable"}
}
#try to reach google through the primaryDNS
#if it works and we are on a different DNS, set the DNS server to the primaryDNS
#if it works and we are already on the primaryDNS, do nothing
#if we can't reach google and we aren't already on our FallbackDNS, switch to fallback
#if we can't reach google through primaryDNS and we are on the fallback, log that primaryDNS is unavailable# set variables
:local primaryDNS "172.16.20.10";
:local fallbackDNS "1.1.1.1,8.8.8.8";
:local currentDNS;
:set $currentDNS [/ip dns get servers];
#:log warning "What I got is: $currentDNS"
#:log warning "What I want to see is: $primaryDNS"
:do {
:put [resolve google.com server=$primaryDNS];
if ($currentDNS!=$primaryDNS) do={
:log warning "DNS Failover: Switching to primaryDNS";
/ip dns set servers $primaryDNS
} else={}
} on-error={ :set $currentDNS [/ip dns get servers];
if ($currentDNS!=$fallbackDNS) do={
:log error "DNS Failover: Switching to FallbackDNS";
/ip dns set servers $fallbackDNS;
} else={:log info "Using Failover DNS, Primary Unavailable"}
}
#try to reach google through the primaryDNS
#if it works and we are on a different DNS, set the DNS server to the primaryDNS
#if it works and we are already on the primaryDNS, do nothing
#if we can't reach google and we aren't already on our FallbackDNS, switch to fallback
#if we can't reach google through primaryDNS and we are on the fallback, log that primaryDNS is unavailable

I configured a script in the MikroTik scheduler that points to my Ubuntu Server, which runs Pi-hole in Docker. If the server goes down, the DNS IPs are supposed to failover to 1.1.1.1 and 8.8.8.8. However, it recently stopped working correctly; the system is now stuck on the fallback IPs even though the server is fully operational. When I disable the script and manually set the DNS to the Ubuntu Server IP (172.16.20.10), Pi-hole receives the queries perfectly. But the moment I re-enable the script, the DNS settings immediately switch back to 1.1.1.1 and 8.8.8.8. Maybe updates broke something.

Could you please help me troubleshoot this?
Thanks


r/mikrotik 6d ago

[Pending] How do I assign a fixed LAN IP to Apps containers?

2 Upvotes

Hi,

I recently became a proud owner of a hAP be³ media — just mentioning it to flex a little :) Joking!

I have a question about the Apps feature. How can I assign an app container a specific IP address from my LAN?

I change the address on the VETH interface and restart the container, but it still keeps using 172.18.0.2. Is this IP supposed to be changeable at all when using Apps?

I understand that I can do it with a manually created container, but why does it not work through Apps? Maybe I’m missing something obvious.

Thanks!


r/mikrotik 7d ago

The problem of ipv4 neighbor table overflow, please consider increasing max-neighbor-entries in logs

Thumbnail
gallery
0 Upvotes
Hi, I’m hoping for some help here :). I’m at a loss as to what to do without breaking anything. I work for a security company, and we have tens of thousands of security devices connected to the network via port forwarding to exchange data with the server; lately, these messages have become a real nuisance. I realize that solving this might require more information, and I’m ready to provide it.
And by the way, all those security devices show up in the ARP table, and they all have the same MAC address.

UPD.: These tens of thousands of devices are not on my local LAN; they are remote security panels connecting over the internet. The issue isn't a flat local network.


r/mikrotik 8d ago

mDNS repeater does not work across VLANs

8 Upvotes

I've read every post Google will dig up, tried every setting.

Take any modern router, e.g. a RB5009. defconf it.

Create VLAN 10, and VLAN 20. Add both to the mDNS setting on the DNS config page.

Do the normal setup stuff to get a subnet running on each VLAN with DHCP.

Any device connected to a port on VLAN 10 will only ever see discovery within its own subnet/VLAN
any device connected to a port on VLAN 20 will only ever see discovery within its own subnet/VLAN

I cannot figure out why or how to get mDNS traffic to cross the VLANs.

HOW does one actually make this work in the real world, in real life?

Yes, I've tried firewall rules. Yes, I've tried interface lists. No, they do not work.


r/mikrotik 8d ago

Console cable compatibility

1 Upvotes

I've ordered a console cable for my CRS112 from eBay. ChatGPT is saying it may not be compatible with a Mikrotik router and could even result in damage to my switch. Is it compatible?

Title "USB To RJ45 Console Cable For Cisco Router Switch Serial Network Configuration"

Specifications:

  • Interface: USB Type-A To RJ45
  • Connection Type: USB To Serial Console
  • Chipset: FTDI Compatible
  • Cable Type: Console Programming Cable
  • Compatibility: Cisco Routers Switches Network Devices
  • Operating System: Windows Linux macOS
  • Application: Router Switch Console Configuration
  • Features: Plug And Play Stable Connection Durable Flexible

r/mikrotik 8d ago

[Pending] CRS309-1G-8S and multi-rate SFP+ RJ45

1 Upvotes

Hello, I recently purchased a CRS309-1G-8S with the intent of future-proofing my home network which currently runs ethernet and wireless. I got these multi-rate SFP+ (1/2.5/5/10) with the expectation that the switch would automatically adjust the speed rate to the maximum allowed by negotiation on the other side of the switch.

What ended up happening is that, for some reason, the switch reports that the SFP+ RJ45 was successful at negotiating a 10G link (which is not possible against a 1G device) but no data can be send out or it seems to send data but not receive anything. Did I misread the capabilities of the SFP+ or am I missing something?

I tried disabling auto-negotiation on the switch port and hardcoding that only 1GBaseTFull as available but this results on the link never being established, if I add the 10GBaseCR to the list of available speeds, then the link becomes available but no data can be send over.


r/mikrotik 8d ago

Short distance Point to Multipoint vacation home

Thumbnail gallery
12 Upvotes

r/mikrotik 8d ago

Installeren wireless bridge met twee ST5817H

0 Upvotes

Kan iemand mij helpen met de installatie van een wireless bridge met twee ST5817H 5200 MHz zenders?
Ik hoop dat iemand in deze groep iets weet.
Ik heb een beschrijving van ieder tabblad, instellingen maar niet van hoe richt je nu die twee apparaten in zodat ik over een afstand van 200 meter kan internetten
De master krijg ik wel ingericht met een werkende wifi maar de slave geeft de melding wifi disabled or not associated.


r/mikrotik 9d ago

RouterOS 7.24rc2 [testing] released

45 Upvotes

What's new in 7.24rc2 (2026-Jul-10 11:58):

!) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;
*) bridge - fixed MLAG MAC address handling issues related to aging, flushing and moving (additional fixes);
*) certificate - added "ISRG Root X2", "Root YE" and "Root YR" to SMIPS built-in root certificate authorities store;
*) certificate - added "Root YE" and "Root YR" to built-in root certificate authorities store;
*) dhcpv4-server - fixed "expires-after" field for disabled static lease (introduced in v7.23);
*) dns - fixed an issue where the resolve command was not functional when the "type" was specified (introduced in v7.24beta2);
*) fastpath - properly fall back to SlowPath when FastPath is not possible due to fragmentation;
*) ipsec,ike2 - use peer certificates also when identity has one set for peer matching;
*) l3hw - allow VLAN tagged traffic inside VXLAN tunnel (additional fixes);
*) netinstall - added Netinstall package (additional fixes);
*) snmp - added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIB;
*) snmp - improved SNMPv3 request processing logic;
*) ssh - make SSH packet validation more strict (additional fixes);
*) system - improved handling of data re-sending on authorization requests (introduced in v7.22);
*) system - improved stability;
*) system - updated certificate for Windows executable signing;
*) tftp - limit maximum simultaneous session count to 100;
*) usb - fixed USB Ethernet interface default-name;
*) wifi - improved roaming/steering behavior for WiFi 7 MLO (additional fixes);
*) wireguard - added support for domain names in client-dns;
*) wireguard - added warning when allowed-address overlaps with another peer on the same interface;
*) wireguard - fixed wg-export comments output and case when endpoint is not set;
*) wireguard - fixed whitespace handling in AllowedIPs during wg-import;
*) wireguard - improved wg-export to print endpoint domain name;
*) wireguard - improved wg-import to quietly ignore wg-quick specific keys;
*) wireguard - reconfigure peer only when meaningful changes are detected;

View changelogs


r/mikrotik 9d ago

MikroTik's Advanced Firewall broke my Wireguard connections: why?

0 Upvotes

I have set up a site-to-site Wireguard VPN between an HQ site and three branches.
Up until this point I only had simple rules for the NAT and Firewall:

  • Masquerade all outgoing WAN
  • Allow UDP on the Wireguard port
  • Drop all Input WAN, not Established

My VPNs have been working great for a couple of weeks.

On Saturday, I decided to follow the MikroTik "Building Advanced Firewall" User Guide.

Everything continued to work fine until yesterday / this morning.

  • One branch still maintains the Wireguard VPN.
  • One branch's Last Handshake was 16 hours ago.
  • One branch's Last Handshake was 4 hours ago.

Absolutely nothing on the configuration side of the VPNs has changed: only the Firewall and NAT rules as dictated in the guide above.

  • I tried Disabling-and-Enabling the broken peers on the "server".
  • I tried Disabling-and-Enabling the Wireguard "server".
  • I tried Disabling-and-Enabling the Wireguard interface on the "server".

None of these fixed the problem.

I then Disabled all the entries I had Added on Saturday to Filter Rules and Raw.
The two broken Wireguard peers almost immediately started working.

  • Which of the rules likely broke my Wireguard connections and why?
  • How can I fix my rules to follow MikroTik's guide, and still work with Wireguard?

r/mikrotik 9d ago

Chateau LTE7 no external SMA connectors

0 Upvotes

Hi all. I purchased the above but it came with no external SMA connectors. The holes are there for them though. Can I easily add the connectors so that I can get better LTE signal strength ?

If so, is it relatively easy to do. Any advice or thoughts gratefully received.

Thanks all