LandyMan
Honorary Master
Eish ... that does look niceI think this one will do what you want: https://mikrotik.com/product/rb5009ug_s_in Theoretically should get to 500mbs on queuing.
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Eish ... that does look niceI think this one will do what you want: https://mikrotik.com/product/rb5009ug_s_in Theoretically should get to 500mbs on queuing.
Probably maxing out on a single core then. Check the individual cpu cores.CPU maxes out at 52% when queues are on
You'll have to approach traffic management a bit differently if you wish to reach your full throughput on the AC2. Always pay very close attention to the Ethernet test results for the device on the mikrotik site.Just upgraded to the AC2 for the 1Gbps ports (from a 750) ... will stick with it for a while.
Good luck finding stock at the momentI think this one will do what you want: https://mikrotik.com/product/rb5009ug_s_in Theoretically should get to 500mbs on queuing.
I'm good. I have x86.Good luck finding stock at the moment
Newer protocol but performance should be the same. Main difference is how the ip addresses look. Read up on thisast point first, you will see you need ipv4 still.Sitting here going through the settings, etc. Then started wondering about IPv6 for internal networking, just to play around a bit. Is this better than 4, or not worth the effort?
mikrotik.com
No guide but some hints.Can anyone please provide me with a up to date guide/rules on how to secure a Mikrotik router?
What are bandwidths of the links you have available?Thinking of getting one of these as our WAN failover?
R750![]()
hAP ac² | MikroTik
Dual-Concurrent 2.4/5GHz AP, 802.11a/b/g/n/ac, Five Gigabit Ethernet ports, USB for 3G/4G support, universal tower case and IPsec hardware encryption supportmikrotik.com
Looks like it'll do a decent job, need something at our office to auto switch between 2x fibre links, when one is not working.
200Mb, 20Mb and LTEWhat are bandwidths of the links you have available?
Thank you.No guide but some hints.
- Never expose any management ports to public IPs.
- Rather use pihole or similar and turn of the tik's DNS.
How many tiks are there to protect?
The best strategy is to get yourself a VPS or KVM instance. There are a few providers that come in just over R100 per month.Thank you.
At the moment it is 5. It could be about 40 in a couple of months.
Very nice! Yeah, once they are up and running, they just work (tm).View attachment 1432577 they just do what they do,no need to interfere![]()


Sjoe, that is quite a lot of setup, but not too complex. I'll see if I can find some resources for you.What would be the easiest way to achieve the following:
Using the RB4011 ( ether 1 will be connected to the ONT )
PPPOE ether 1
192.169.1.1/24 network on ether 2 ( uses 192.169.1.111 as DNS )
10.0.10.1/22 network on ether 3 ( uses 192.169.1.111 as DNS )
10.0.20.1/22 network on ether 4 ( uses 192.169.1.111 as DNS )
ether 3 and ether 4 networks must not be able to access ether 2 networks.
All DNS requests on the Mikrotik must go to 192.169.1.111 ( Pi-Hole Raspberry Pi )
Port must be opened for Wiregaurd on ( WAN:51820 point to 192.169.1.111:51820 )
Context:
Network 192.169.1.1/24 ( I know 169 is not allowed, but Hik had a typo & to change the IPs of all the cameras and facial readers now after it is set up in Hik Central is too much work ( days and costs ) )
Hikvision NVR ( static IP )
Hikvision Smart POE 24 Port Switch ( static IP )
32 Cameras ( static IPs )
12 Facial Readers ( static IPs )
2 Security APs ( ± 10 users each using DHCP - password protected )
1 Rapsbery Pi ( static IP - pihole and wiregaurd )
Network 10.0.10.1/22 ( Guest )
1 x 8 port unmanaged switch
4 x UniFi APs with Free WiFi ( no password )
Network 10.0.20.1/22 ( Guest )
1 x 8 port unmanaged switch
4 x UniFi APs with Free WiFi ( no password )