The official Mikrotik router thread

Just upgraded to the AC2 for the 1Gbps ports (from a 750) ... will stick with it for a while.
You'll have to approach traffic management a bit differently if you wish to reach your full throughput on the AC2. Always pay very close attention to the Ethernet test results for the device on the mikrotik site.
 
Sitting here going through the settings, etc. Then started wondering about IPv6 for internal networking, just to play around a bit. Is this better than 4, or not worth the effort?
 
Sitting here going through the settings, etc. Then started wondering about IPv6 for internal networking, just to play around a bit. Is this better than 4, or not worth the effort?
Newer protocol but performance should be the same. Main difference is how the ip addresses look. Read up on thisast point first, you will see you need ipv4 still.
 
Thinking of getting one of these as our WAN failover?

R750

Looks like it'll do a decent job, need something at our office to auto switch between 2x fibre links, when one is not working.
 
Thinking of getting one of these as our WAN failover?

R750

Looks like it'll do a decent job, need something at our office to auto switch between 2x fibre links, when one is not working.
What are bandwidths of the links you have available?
 
Thank you.

At the moment it is 5. It could be about 40 in a couple of months.
The best strategy is to get yourself a VPS or KVM instance. There are a few providers that come in just over R100 per month.
You can then use that as a wireguard server which acts as a jump box to the tiks for remote management.
You protect the server using sshguard and level 1 block lists.
If you deploy a local DNS such as pihole you can have an alternative in deploying rport.io
It is a generic solution for remote tunnels.
It's all a bit of effort but secures the management of the tiks.
It's worth it as there are more than hundred thousand tiks in bots out there that have been compromised.
Edit: If you have older tiks you need to use the older VPN protocols instead of wireguard. But they are horrible. However, putting this effort into making sure your management ports aren't directly exposed on public IPs is worth the effort. IMO.
 
Last edited:
It's awfully quiet in here...

How is everyone's Tiks holding up?
 
View attachment 1432577 they just do what they do,no need to interfere:laugh:
Very nice! Yeah, once they are up and running, they just work (tm).

I recently setup a nice Grafana dashboard on Docker that pulls information from the Mikrotik API. It needed some minor tweaking (I had to multiply the one query result with 8 because it was giving me the wrong speed) but otherwise it seems to be a nice collection of info. My low uptime is thanks to an inverter trip a few days back.

1669891991869.png

1669891954685.png

Link here: akpw/mktxp: Prometheus Exporter for Mikrotik RouterOS devices (github.com)
 
What would be the easiest way to achieve the following:

Using the RB4011 ( ether 1 will be connected to the ONT )

PPPOE ether 1

192.169.1.1/24 network on ether 2 ( uses 192.169.1.111 as DNS )

10.0.10.1/22 network on ether 3 ( uses 192.169.1.111 as DNS )

10.0.20.1/22 network on ether 4 ( uses 192.169.1.111 as DNS )

ether 3 and ether 4 networks must not be able to access ether 2 networks.

All DNS requests on the Mikrotik must go to 192.169.1.111 ( Pi-Hole Raspberry Pi )

Port must be opened for Wiregaurd on ( WAN:51820 point to 192.169.1.111:51820 )

Context:

Network 192.169.1.1/24 ( I know 169 is not allowed, but Hik had a typo & to change the IPs of all the cameras and facial readers now after it is set up in Hik Central is too much work ( days and costs ) )
Hikvision NVR ( static IP )
Hikvision Smart POE 24 Port Switch ( static IP )
32 Cameras ( static IPs )
12 Facial Readers ( static IPs )
2 Security APs ( ± 10 users each using DHCP - password protected )
1 Rapsbery Pi ( static IP - pihole and wiregaurd )

Network 10.0.10.1/22 ( Guest )
1 x 8 port unmanaged switch
4 x UniFi APs with Free WiFi ( no password )

Network 10.0.20.1/22 ( Guest )
1 x 8 port unmanaged switch
4 x UniFi APs with Free WiFi ( no password )
 
What would be the easiest way to achieve the following:

Using the RB4011 ( ether 1 will be connected to the ONT )

PPPOE ether 1

192.169.1.1/24 network on ether 2 ( uses 192.169.1.111 as DNS )

10.0.10.1/22 network on ether 3 ( uses 192.169.1.111 as DNS )

10.0.20.1/22 network on ether 4 ( uses 192.169.1.111 as DNS )

ether 3 and ether 4 networks must not be able to access ether 2 networks.

All DNS requests on the Mikrotik must go to 192.169.1.111 ( Pi-Hole Raspberry Pi )

Port must be opened for Wiregaurd on ( WAN:51820 point to 192.169.1.111:51820 )

Context:

Network 192.169.1.1/24 ( I know 169 is not allowed, but Hik had a typo & to change the IPs of all the cameras and facial readers now after it is set up in Hik Central is too much work ( days and costs ) )
Hikvision NVR ( static IP )
Hikvision Smart POE 24 Port Switch ( static IP )
32 Cameras ( static IPs )
12 Facial Readers ( static IPs )
2 Security APs ( ± 10 users each using DHCP - password protected )
1 Rapsbery Pi ( static IP - pihole and wiregaurd )

Network 10.0.10.1/22 ( Guest )
1 x 8 port unmanaged switch
4 x UniFi APs with Free WiFi ( no password )

Network 10.0.20.1/22 ( Guest )
1 x 8 port unmanaged switch
4 x UniFi APs with Free WiFi ( no password )
Sjoe, that is quite a lot of setup, but not too complex. I'll see if I can find some resources for you.
 
Top
Sign up to the MyBroadband newsletter
X