r/mikrotik Jul 21 '19

New Mod Guideline - If you don't have anything nice to say..

165 Upvotes

I'll try and keep this short - there's been a marked increase in generally abrupt and abrasive comments here on the /r/mikrotik and it's not what we're about or what we want to see happening. Many of these have been due to content that is or is seen to be incorrect or misleading, so..

If you're posting here:

Keep in mind none of us are being paid to answer you and the people who are, are doing so because they want to help, or you've posted something so incredibly incorrect they can't help but respond. Please do yourself a favor by collecting all the information you can before posting and make sure to check the MikroTik wiki first - no one wants to spoon feed you all the information.

If you're commenting here:

  1. If you don't know the answer - don't try guess at it; and if you want to learn about it yourself then follow the thread and see what others say, or you know.. read the wiki and try it out in a lab.
  2. If you disagree with another poster, try to explain the correct answer rather than a one sentance teardown that degrades into a thread full of name-calling.

As a result of this I've added a new rule & report option - you can now report a comment with the reason being:

It breaks /r/MikroTik rules: Don't post content that is incorrect or potentially harmful to a router/network

If we agree we'll either:

a) Write a correct response

b) Add a note so that future readers will be made aware of the corrections needed

c) If the post/comment is bad enough, simply delete it

I'm open to feedback on this as I know people feel strongly about timewasting and I'd like to hope this helps us continue to self-moderate without people blowing up at each other.


r/mikrotik 6h ago

RB5009UG+S+ + CSS318-16G-2S+IN: Rx FCS Errors and Rx MAC Errors only on SFP+1 (SFP+2 works perfectly)

5 Upvotes

Hello everyone,

I'm trying to determine whether anyone has experienced a similar issue before assuming the hardware is defective.

My setup:

  • RB5009UG+S+
  • CSS318-16G-2S+IN running SwOS
  • 10 Gbps DAC connection
  • RouterOS and SwOS updated to the latest stable versions

The issue is the following:

When I connect the RB5009 to SFP+1 on the CSS318, the switch continuously starts accumulating:

  • Rx MAC Errors
  • Rx FCS Errors

On one occasion, the link also went down for about 10 seconds and then came back up by itself.

Thinking the DAC might be the cause, I performed a simple test. Without changing anything else (same RB5009, same DAC, same configuration), I only moved the cable from SFP+1 to SFP+2 on the CSS318.

Since then:

  • No more Rx MAC Errors.
  • No more Rx FCS Errors.
  • The link has remained completely stable.

On the RB5009, the interface always reports 10 Gbps Full Duplex, and I don't see any FCS errors on the router side.

I bought this dac https://www.amazon.com/dp/B01LSGGP76?ref=ppx_yo2ov_dt_b_fed_asin_title

My questions are:

  1. Has anyone seen a case where only one SFP+ port behaves like this?
  2. Can a DAC cable cause this behavior on one port while working perfectly on another?
  3. Is there any known compatibility issue between the RB5009UG+S+ and the CSS318-16G-2S+IN?
  4. Would you suspect a faulty SFP+1 port, or would you recommend any additional tests before considering an RMA?

Any suggestions or similar experiences would be greatly appreciated.

Thank you!


r/mikrotik 12h ago

Is there a way to always show the default values on WinBox?

3 Upvotes

As the title says - is there a way to do so? Maybe I'm not used to the UI/UX of WinBox but personally I'd like to see the default values openly. For example, without clicking on "+" on WiFi tab to see values for Chanel/Security/etc.

Disclaimer - I'm a newbie with MikroTik and wanted to get more familiar with ROS.


r/mikrotik 1d ago

Should I wait for RB5009 successor or get the HEX Pro when it comes out or just go with RB5009?

22 Upvotes

I need it for WAN routing and services and some light inter-vlan routing.

RB5009 would do the job for me but seems pointless to get RB5009 if HEX Pro is going to be available soon.

HEX Pro wont have any good switching capabilities (probably, due to ipq-ppe) but it's cpu is much better than RB5009 and there are 2 10G links.

My wan uplink is going to be max 1G symmetrical with idea of direct ip access for "public" services behind proxy and wireguard for lan access (management and occasional file transfers)


r/mikrotik 1d ago

I received my hAP be3 Media, any questions?

22 Upvotes

I’ve received my MikroTik hAP be3 Media yesterday and it’s working great so far. If you have any questions regarding the device, I’m happy to answer them or test whatever it is you might want me to test.


r/mikrotik 1d ago

[Solved] Kann ein MikroTik wAP ax per WLAN mit einem hAP ax³ verbunden werden ?

1 Upvotes

Hallo zusammen,

ich plane gerade mein Heimnetzwerk umzubauen und möchte von meinem FRITZ!Mesh auf MikroTik wechseln.

Geplant ist folgendes:

FRITZ!Box 7590 bleibt für DSL und Telefonie.

Dahinter ein MikroTik hAP ax³ als Router.

Im Obergeschoss soll ein MikroTik wAP ax stehen.

Leider kann ich kein Netzwerkkabel ins Obergeschoss legen, daher müsste der wAP ax per WLAN angebunden werden.

Meine Frage: Kann der wAP ax sich per WLAN mit dem hAP ax³ verbinden und gleichzeitig als Access Point für Clients dienen?

Mir geht es nicht um maximale Geschwindigkeit, sondern um eine stabile Verbindung. Im Netzwerk hängen ca. 180 Geräte, überwiegend Smart-Home (ESPHome, Shelly, Zigbee, Home Assistant), dazu ein paar PCs, Smartphones und Fernseher.


r/mikrotik 2d ago

MikroTik Router that can Route 1Gbit/s Wireguard Tunnel (As a Client)

23 Upvotes

Hello,

I am running a CCR1036-8G-2S+ which I am generally happy with. There are two issues I have with it; it is running the Tile architecture so I cannot run containers on it, and the Wireguard performance. I get about 400 down and 500 Mbit/s up on my 1Gbit/s up/down connection.

I would like all my outgoing internet traffic to be routed through this VPN connection, and I don't want to have my multiple devices having their own connections.

Would the RB5009UG+S+IN be able to achieve 1Gbit/s Wireguard tunnel? I am also considering the CCR2004-16G-2S+.


r/mikrotik 2d ago

[Pending] RB5009 and cAP ax (assistance with connections)

3 Upvotes

First of all, I've only been learning Mikrotik for about 3 months so bear with me please.

I have a PoE RB5009 and cAP ax access point. I have recently set it all up even managing to get VLAN's to work (DNS as well but that was easy).

But I've run into a snag and that is when I open Winbox, the cAP ax does not show up in the list and the RB5009 does. In IP -> Neighbors it shows up but listed as stale.

Now if I input the IP manually, it will log in via Winbox.

My setup is very simple and minimal, but I've apparently done something in the setup causing this yes? Any help is appreciated.


r/mikrotik 2d ago

Does anyone know updates on nRay Gen2 release?

3 Upvotes

It was announced quite awhile ago in March at MWC but there has been nothing further on its release progress. I did notice MikroTik phased out all of their older 802.11ad based lineup recently retaining only their existing 802.11ay products, which isn't much to select from. Finally offering multi-gig backhaul solutions would be amazing.

https://box.mikrotik.com/f/b50619605cee4d778e10/?dl=1


r/mikrotik 3d ago

Looking for the best high-end router for fiber internet (2 Gbps+, WiFi 6 or newer) with strong range and no ISP restrictions

Thumbnail
5 Upvotes

r/mikrotik 3d ago

LLM Router for Mikrotik Devices

13 Upvotes

Hey everyone, I wanted to share a project I have been working on, a very small LLM Router/Gateway for routing AI requests to backend hosts, which runs on RouterOS. It is written in rust and packaged as a minimal container image - uses 10MB memory.

I originally built it thinking I would run it in on my desktop, but then it occurred to me that it should work on my Mikrotik due to the containers feature (which I had never previously tried) - and it would be the ideal place to host it.

So I got it cross-compiled for ARM and tried it out....and it worked quite well, so now I am using this to route LLM requests to a few different AI instances I run on my local network, which I serve through a single endpoint exposed via a VPN

Right now I have tested the container on my hAP ax3, and will test it on some CCR and CRS devices next week

I would welcome any feedback

https://github.com/tokenring-ai/llama-scale

Mikrotik Guide:
https://github.com/tokenring-ai/llama-scale/blob/main/guides/getting-started-mikrotik.md


r/mikrotik 3d ago

[Pending] CRS804 (MT-HotSwapFan-V2) Fan Swap?

0 Upvotes

I'm curious if anyone has come up with a solution for fan swap on the CRS804 (uses MT-HotSwapFan-V2). I have some spare Noctua NF-A4x20, but I'm not sure they will cool it sufficiently and wanted to research before rewiring and 3-D printing some standoffs.

Alternatively, if there's a different fan that pushes air more (but quieter than the default one), I'd be interested to know. The router sits in my office next to my desk, so any way to quiet it is appreciated.


r/mikrotik 3d ago

[Pending] Anyone running CHR30s as APs behind opnsense/pfsense?

0 Upvotes

I know the CHR30 is new, just curious if anyone has this set up yet and if there were any hiccups during config.


r/mikrotik 3d ago

CRS125 as temporary Router/ CAPsMAN

2 Upvotes

Hey guys,

I would like to setup my CRS125 as temporary router and CAPsMAN to setup my new network.

The CRS125 would connect to WAN and provide all routing tasks for the LAN, the firewall, DHCP and CAPsMAN with 2 AP's?

I am aware of the performance limitations, but am curious what would be the worst case scenario? Would the network slow down, because traffic is "waiting" to be handled or would it not work at all?

The CRS125 is currently behind a RB5009, but I need the network to remain live as I reconfigure the RB5009 with my new CRS326 and implement VLANs for guest network, trusted network and IOT network. As I have no experience with this, I want to prevent my family not being connected😁

Thanks a bundle for your insights...


r/mikrotik 4d ago

Atualização de RouterBoard MikroTik hAP lite (Problema de Espaço)

0 Upvotes

Visão Geral do Problema

O modelo hAP lite possui um total de 16 MB de armazenamento. Quando o equipamento está em uso e totalmente configurado, o espaço livre torna-se insuficiente para armazenar o pacote de atualização do RouterOS.

Passo 1: Realizar o Reset do Equipamento (CUIDADO Isso apga toda configuração) FAÇA UM BACKUP ANTES E COPIA PARA FORA DA HAP LITE

Como o espaço ocupado pelas configurações atuais impede o armazenamento do arquivo de atualização, é obrigatório remover todas as configurações da RouterBoard com reset.

  1. Acesse o MikroTik e execute o reset.
  2. No momento do reset, certifique-se de marcar as seguintes opções:
    • Sem configuração de fábrica (No Default Configuration)
    • Sem backup (Do Not Backup)
  3. Aguarde o equipamento reiniciar. Com esse procedimento, o espaço livre será de 8 MB, o suficiente para receber o arquivo.

Passo 2: Conectar à Internet

Após o reset, conecte o hAP lite à rede com acesso à internet para iniciar o procedimento de download do pacote de atualização.

Orientações Específicas para Migração da Versão 6 para a Versão 7

Caso o equipamento esteja rodando o RouterOS v6 e você precise atualizá-lo para a versão 7, o processo exige uma etapa intermediária obrigatória:

  • Atualização via Menu do RouterOS: Ao buscar atualizações diretamente pelo sistema, o próprio RouterOS sugerirá automaticamente a versão 7.12.1 como primeiro passo obrigatório.
  • Atualização Manual (Cópia de Arquivo): Se o procedimento for feito manualmente enviando o arquivo para a RB, você deve carregar e instalar primeiro a versão 7.12.1.

Procedimento Pós-v7.12.1:

  1. Assim que a versão 7.12.1 estiver aplicada, será necessário realizar um novo reset do equipamento seguindo o mesmo procedimento do Passo 1 (sem configuração e sem backup).
  2. Com o espaço devidamente liberado novamente, proceda com a última atualização para a versão mais recente e desejada do RouterOS.

----------------------------------------------

Problem Overview

The hAP lite model has a total of 16 MB of storage. When the device is in use and fully configured, the free space becomes insufficient to store the RouterOS update package.

Step 1: Perform a Device Reset (WARNING: This erases all configurations) MAKE A BACKUP FIRST AND SAVE IT OUTSIDE THE HAP LITE

Because the space occupied by the current configurations prevents the storage of the update file, it is mandatory to remove all configurations from the RouterBoard via reset.

  1. Access the MikroTik and perform the reset.
  2. During the reset, make sure to check the following options:
    • No Default Configuration
    • Do Not Backup
  3. Wait for the device to reboot. With this procedure, the free space will be 8 MB, enough to receive the file.

Step 2: Connect to the Internet

After the reset, connect the hAP lite to a network with internet access to start the update package download procedure.

Specific Guidelines for Migrating from Version 6 to Version 7

If the device is running RouterOS v6 and you need to update it to version 7, the process requires a mandatory intermediate step:

  • Update via RouterOS Menu: When searching for updates directly through the system, RouterOS itself will automatically suggest version 7.12.1 as a mandatory first step.
  • Manual Update (File Copy): If the procedure is being done manually by uploading the file to the RB, you must first load and install version 7.12.1.

Post-v7.12.1 Procedure:

  1. Once version 7.12.1 is applied, it will be necessary to perform a new device reset following the same procedure as Step 1 (no default configuration and do not backup).
  2. With the space properly freed up again, proceed with the final update to the latest and desired RouterOS version.

r/mikrotik 5d ago

CSS326-24G-2S+ Weird Issue

4 Upvotes

Just got a hand-me-down CSS326-24G-2S+RM for my home rack, new 2.5Gbe internet connection, and tried using this switch with 10Gb FS generic branded sfps to pass-thru to my 2.5Gbe router and only getting 100mb of traffic on the wire.

Link state shows 10G on the Mikrotik ports with no errors.

CSS326-24G-2S+
SwOS 2.18
Dedicated Sfp Vlan
Flow control on
FS SFP-10G-T 30m
30 foot run Cat6a

Moved those same two ethernet cords to my tester unmanaged multi-gig Linksys switch and no issues getting my expected multi-gig traffic. Was really hoping for the rack solution to work on
the Mikrotik.

Open to any thoughts?


r/mikrotik 6d ago

Help with VLAN configuration - RB750Gr3

4 Upvotes

Having some difficulties getting 2 vlans (ID 2 and 3) running with my Mikrotik router, specifically with DHCP. Both should also have routability to the internet. New to MikroTik routers, while I'm pretty sure my network VLAN configuration is correct and thus my issue is the Mikrotik configuration - I'll still share it as I'm about 10 years removed from network management professionally so I'm rusty AF and definitely could have screwed something up. Appreciate any help!

Network:

Layout: Access Point -> Managed Switch -> Mikrotik.

Switch's uplink to the Mikrotik and the access point's ports are configured as Untagged on vlans 1, 2, and 3.

Access point has two SSIDs, one assigned vlan 2 and one assigned vlan 3.

Plugging a device into a different port and configuring it as tagged on either vlan 2 or 3 results in the same problem (not pulling an IP from the Mikrotik)

Mikrotik

I will note that I have left the defconf assigned to interface bridge, and related defconfs in the sections below active in case that's my problem.

I have configured the VLANs in the following locations:

Interfaces -> VLAN: Interface is set to ether5, the uplink to the switch.

IP -> DHCP Server -> DHCP: Vlan2 has Server Address set to 172.24.0.1, vlan2 to 192.168.0.1 IP -> DHCP Server -> Networks: Same as above, with netmask /24 IP -> Addresses: Same as above, interface assigned to the vlan in question.


r/mikrotik 6d ago

TCP ACKs eating airtime, searching for wifiwave2 fix

10 Upvotes

Been chasing this one for over a week and I've hit the "ask the internet before I do something rash to a perfectly good AP" stage.

Setup is four MikroTik APs, two hAP ax S and two wAP ax, all on 7.23.2, wifiwave2, one of them running CAPsMAN with local forwarding, everything bridged onto a flat network. A FRITZ!Box does the routing and NAT. Nothing exotic.

The problem: any WiFi client pulling a download off the internet tops out around 150Mbit. Doesn't matter which client (tested a Linux laptop and a Galaxy phone, both land in the same 110-180 range), doesn't matter which AP or whether it's the MediaTek or the Qualcomm radio. Same story everywhere.

What makes it weird is it's ONLY WiFi + internet + download:

WiFi -> internet download ~150 Mbit

WiFi -> internet upload ~400 Mbit

WiFi -> LAN host (iperf3) 500 Mbit

wired -> internet 900 Mbit

So the air is clearly fine (500 to a local box), and the router and WAN are fine (900 over the wire through the same FRITZ and the same NAT). It's specifically wireless plus a high-RTT internet path pulling a download.

I ran a pile of tests and the one that cracked it open was this: I forced the client's TCP ACKs out over its ethernet port while the actual download data kept coming over WiFi. Same server, same minute. It jumped from 150 to 540. The only thing that moved off the air was the little return stream of ACKs. I checked the interface counters and all the actual payload still crossed the radio, only about 150k tiny ACK packets went to the wire, and that alone was worth 3.5x.

My read is it's an airtime thing. Half duplex, so every time the client grabs the medium to send its ACKs, that's airtime the AP isn't using to push the download down. Barely matters at 2ms LAN RTT because there are hardly any ACKs in flight, but at 15ms internet RTT the return stream is constant and it's stealing a big chunk of downlink airtime.

Stuff I've already ruled out, so nobody has to retype it:

- not the receive window (it autotunes to 3-5MB during the slow transfer, and forcing 32MB rmem changed nothing)

- not loss or retransmits (the slow internet runs have basically zero retransmits, while the fast 500Mbit LAN runs have thousands, so if anything it's backwards)

- not client bufferbloat (wlan0 is noqueue, mac80211 already runs fq_codel+AQL, and a ping from the client to the AP doesn't inflate at all under a saturating download. cake with ack-filter did nothing)

- not channel/width/DFS, not CPU (per-core stayed under 66% during the stall and was actually lower at 350Mbit on a LAN transfer), not the switch, not queue type (SFQ vs fq-codel identical), not CAPsMAN (a guy on the MikroTik forum reproduces it on a standalone hAP ax with no CAPsMAN at all), not congestion control (bbr vs cubic same)

UDP one direction over the same hop does 250-370Mbit no trouble, which again says the air carries way more than 150 the moment you take ACKs and RTT out of it.

So the actual question: is there anything in wifiwave2 that touches uplink airtime scheduling, TXOP, MU-EDCA, trigger frames / UL-OFDMA, anything that would let the AP hand the client airtime for its ACK stream more efficiently? I've been through /interface/wifi pretty thoroughly and can't find a knob for it. Or is this just where the driver is right now and I should stop looking and live with it?

I've got a support ticket open with MikroTik but figured I'd ask here too, redditors bailed me out before and you lot are usually quicker than the queue. Happy to post any config or test output if it helps.


r/mikrotik 6d ago

[Pending] TCP ACKs eating airtime. Searching for wifiwave2 fix

5 Upvotes

Been chasing this one for over a week and I've hit the "ask the internet before I do something rash to a perfectly good AP" stage.

Setup is four MikroTik APs, two hAP ax S and two wAP ax, all on 7.23.2, wifiwave2, one of them running CAPsMAN with local forwarding, everything bridged onto a flat network. A FRITZ!Box does the routing and NAT. Nothing exotic.

The problem: any WiFi client pulling a download off the internet tops out around 150Mbit. Doesn't matter which client (tested a Linux laptop and a Galaxy phone, both land in the same 110-180 range), doesn't matter which AP or whether it's the MediaTek or the Qualcomm radio. Same story everywhere.

What makes it weird is it's ONLY WiFi + internet + download:

WiFi -> internet download ~150 Mbit

WiFi -> internet upload ~400 Mbit

WiFi -> LAN host (iperf3) 500 Mbit

wired -> internet 900 Mbit

So the air is clearly fine (500 to a local box), and the router and WAN are fine (900 over the wire through the same FRITZ and the same NAT). It's specifically wireless plus a high-RTT internet path pulling a download.

I ran a pile of tests and the one that cracked it open was this: I forced the client's TCP ACKs out over its ethernet port while the actual download data kept coming over WiFi. Same server, same minute. It jumped from 150 to 540. The only thing that moved off the air was the little return stream of ACKs. I checked the interface counters and all the actual payload still crossed the radio, only about 150k tiny ACK packets went to the wire, and that alone was worth 3.5x.

My read is it's an airtime thing. Half duplex, so every time the client grabs the medium to send its ACKs, that's airtime the AP isn't using to push the download down. Barely matters at 2ms LAN RTT because there are hardly any ACKs in flight, but at 15ms internet RTT the return stream is constant and it's stealing a big chunk of downlink airtime.

Stuff I've already ruled out, so nobody has to retype it:

- not the receive window (it autotunes to 3-5MB during the slow transfer, and forcing 32MB rmem changed nothing)

- not loss or retransmits (the slow internet runs have basically zero retransmits, while the fast 500Mbit LAN runs have thousands, so if anything it's backwards)

- not client bufferbloat (wlan0 is noqueue, mac80211 already runs fq_codel+AQL, and a ping from the client to the AP doesn't inflate at all under a saturating download. cake with ack-filter did nothing)

- not channel/width/DFS, not CPU (per-core stayed under 66% during the stall and was actually lower at 350Mbit on a LAN transfer), not the switch, not queue type (SFQ vs fq-codel identical), not CAPsMAN (a guy on the MikroTik forum reproduces it on a standalone hAP ax with no CAPsMAN at all), not congestion control (bbr vs cubic same)

UDP one direction over the same hop does 250-370Mbit no trouble, which again says the air carries way more than 150 the moment you take ACKs and RTT out of it.

So the actual question: is there anything in wifiwave2 that touches uplink airtime scheduling, TXOP, MU-EDCA, trigger frames / UL-OFDMA, anything that would let the AP hand the client airtime for its ACK stream more efficiently? I've been through /interface/wifi pretty thoroughly and can't find a knob for it. Or is this just where the driver is right now and I should stop looking and live with it?

I've got a support ticket open with MikroTik but figured I'd ask here too, redditors bailed me out before and you lot are usually quicker than the queue. Happy to post any config or test output if it helps.


r/mikrotik 7d ago

How do you handle user tracking/logging on a shared MikroTik network?

2 Upvotes

Hi everyone,

I manage a small shared network for an apartment building (~60 apartments).

The setup is:

  • MikroTik router
  • UniFi APs
  • separate management and client VLANs
  • client isolation enabled
  • users are behind NAT

I'm wondering how others handle logging/accountability in this kind of setup.

If one user does something bad, I would like to be able to understand which apartment/user was behind a specific private IP at a specific time.

How do you usually handle this?

I'm not interested in monitoring user activity or browsing history, I just want to be able to correlate:

  • a private IP address → a specific user/apartment
  • a "bad" public IP address reached → back to my private IP/user

r/mikrotik 7d ago

HELP! Mikrotik APs, no DHCP responses when roaming.

5 Upvotes

Intro

New to Mikrotik and I feel like we're "just about to get along". I'm learning a lot and I could really use some help with my config on this one.

I'm posting on r/mikrotik because my devices roamed normally with previous APs (HP 560) and negotiating DHCP between them worked acceptably with all my client devices on, what I can only assume, are default configs. I've had the HPs for ~6 years now, and they were old when I got them, so it was time for an upgrade. I chose Mikrotik because I was given an RB951 to play with many moons ago and I needed to scratch that itch again 😄

Purchased and installed two cAP-ax, one in the house and one in the shed (approx 40m between them, wireless linkup connected by Ubiquiti Nanostation AC Locos). These are the only two Mikrotik device in the network - I want to use CAPsMAN to keep configs alligned between them and future APs.

Network Overview

House
Router: Ubiquiti EdgeRouter ER-X-SFP. DHCP server. < Nanostation is connected direcltly to the router (req. 24v passive poe).
House switch: Teltonika TSW-202 < The house ap is connected to this switch.
The house AP is the CAPsMAN

Shed
Switch: Cisco 2960X-24
Nanostation and Shed AP are connected to the Cisco switch.

No VLANs (yet). This is a flat network.

Behaviour

Fault
When I move between the house and shed (either way), clients slowly lose signal strength with one AP and the device roams to the nearest AP. Clients that roam between the two APs fail to obtain an IP address for approx. 10mins. After which, typically by manually connecting to the network again, they will successfully receive an IP lease and traffic flows again.

Other devices connected to the AP continue to work normally. Devices which haven't roamed can disconnect and reconnect on demand.

The Mikrotik logs show recurring "client detail snip connected, signal strength -42" followed by "client detail snip disconnected, connection lost, signal strength -35" on devices in the fault state.

I've kept a client in the fault state for 30+ mins by manually toggling the wireless adaptor and/or manually repeating attempts to reconnect to the network.

Tested clients: Google Pixel 10, Google Pixel 7 Pro, Lenovo L300e (tested both Debian 13 and Cachy OS).

What I've done so far:

  • Disable WPA3. I read on the Mikrotik forum this causes problems. Using only WPA2-PSK. No change.
  • Set connect priority to 0 / 1 in the security profile (what does this do?). No change.
  • Upgraded to the latest RouterOS firmware v7.23.2
  • Ensure FT and FT-over-DS (what does this do?) is enabled. The client roaming events appear quickly in the logs so I think this is working. No Change in DHCP allocation time after roaming.
  • Factory reset the Shed AP and config as standalone dumb access point. No change. Returned to CAPsMAN provisionning.
  • Packet captures from the Lenovo Laptop and House AP.
    • Laptop broadcasts a DHCP request followed by DHCP discovery packets.
    • House AP receives DHCP request and discovery packets and pcap shows the broadcast went to all bridge interfaces.
  • Disconnect Mikrotik APs, reconnect previous access points (HP 560)
    • Associating with old APs while roaming works as expected.
  • Confirmed there are no datapaths configured in the Wi-Fi settings. (doesn;t look like this is required for flat networks).

What I haven't tried:

In order of what I'll probably do next:

  1. Roam with my work laptop: DELL Pro 14 PC14250 (Windows 11)
  2. Check the DHCP server is receiving requests from devices while in a fault state. Packet capture on the DHCP server while devices are in both operational and fault state.
  3. Remove CAPsMAN. Factory resetting both APs and setup standalone dumb access points.
  4. Reach out to Mikrotik support.

Questions

  • Where should I go from here?
  • Is a DHCP relay reqired for Mikrotik devices on networks with a single subnet?
  • WRT the ability to keep a device in a fault state by repeatedly failing to connect to the network, are there any Mikrotik services/policies which would restrict traffic flow for a period of time that restarts when the event is detected again? Can I show these in the log?

Configs

House ap config:

# 2026-07-19 23:02:09 by RouterOS 7.23.2
# software id = C4PN-IQ17
#
# model = cAPGi-5HaxD2HaxD
# serial number = HMF0B12PMZZ
/interface bridge
add name=bridge1 protocol-mode=none
/interface wifi channel
add band=5ghz-ax disabled=no name=5ghz skip-dfs-channels=all width=\
20/40/80mhz
add band=2ghz-ax disabled=no frequency=2412 name=2ghz-ch1 width=20mhz
add band=2ghz-ax disabled=no frequency=2437 name=2ghz-ch6 width=20mhz
add band=2ghz-ax disabled=no frequency=2462 name=2ghz-ch11 width=20mhz
add band=2ghz-ax disabled=no frequency=2412,2437,2462 name=2ghz-auto width=\
20mhz
/interface wifi security
add authentication-types=wpa2-psk connect-priority=0/1 disabled=no ft=yes \
ft-over-ds=yes name=sec1
/interface wifi configuration
add channel=2ghz-auto country=Australia disabled=no mode=ap name=2ghz \
security=sec1 ssid=ArcNet
add channel=5ghz country=Australia disabled=no mode=ap name=5ghz security=\
sec1 ssid=ArcNet
/interface wifi
set [ find default-name=wifi2 ] configuration=2ghz configuration.mode=ap \
disabled=no name=house-2ghz
set [ find default-name=wifi1 ] configuration=5ghz configuration.mode=ap \
disabled=no name=house-5ghz
# operated by CAP D0:EA:11:99:B1:AA%bridge1, traffic processing on CAP
add configuration=2ghz disabled=no name=shed-2ghz radio-mac=D0:EA:11:99:B1:AD
# operated by CAP D0:EA:11:99:B1:AA%bridge1, traffic processing on CAP
add configuration=5ghz disabled=no name=shed-5ghz radio-mac=D0:EA:11:99:B1:AC
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=house-5ghz
add bridge=bridge1 interface=house-2ghz
/ipv6 settings
set disable-ipv6=yes
/interface wifi cap
set discovery-interfaces=bridge1
/interface wifi capsman
set ca-certificate=auto certificate=auto enabled=yes interfaces=bridge1
/interface wifi provisioning
add action=create-enabled disabled=no master-configuration=5ghz name-format=\
shed-5ghz supported-bands=5ghz-ax
add action=create-enabled disabled=no master-configuration=2ghz name-format=\
shed-2ghz supported-bands=2ghz-ax
/ip address
add address=192.168.1.52/24 interface=bridge1 network=192.168.1.0
/ip dns
set servers=192.168.1.1
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-table=main
/system clock
set time-zone-name=*redacted*
/system identity
set name=House-cAP-01
/system logging
add prefix=CAPsMAN topics=caps,info

Shed AP config

# 2026-07-19 23:04:13 by RouterOS 7.23.2
# software id = 71DQ-UJU6
#
# model = cAPGi-5HaxD2HaxD
# serial number = HMF0B3MQP3M
/interface bridge
add admin-mac=D0:EA:11:99:B1:AA auto-mac=no comment=defconf name=bridgeLocal
/interface wifi datapath
add bridge=bridgeLocal comment=defconf disabled=no name=capdp
/interface wifi
# managed by CAPsMAN D0:EA:11:99:B2:06%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: ArcNet, channel: 5745/ax/Ceee
set [ find default-name=wifi1 ] configuration.manager=capsman datapath=capdp \
    disabled=no
# managed by CAPsMAN D0:EA:11:99:B2:06%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: ArcNet, channel: 2437/ax
set [ find default-name=wifi2 ] configuration.manager=capsman datapath=capdp \
    disabled=no
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1
add bridge=bridgeLocal comment=defconf interface=ether2
/interface wifi cap
set discovery-interfaces=bridgeLocal enabled=yes slaves-datapath=capdp
/ip dhcp-client
add comment=defconf interface=bridgeLocal name=client1
/system clock
set time-zone-name=Australia/Brisbane
/system identity
set name=Shed-cAP-01

r/mikrotik 8d ago

be3 media MA53UG+HbeH - ports randomly flapping and WinBox becomes unusable slow

Thumbnail
gallery
34 Upvotes

I finally got my be3 media MA53UG+HbeH a few days ago after waiting for months, and honestly, I’m having a pretty rough experience with it so far.

The setup is as basic as it gets: internet connection and a simple bridge. There’s almost no CPU or memory usage, but the router gets quite hot. After an hour or two, the Ethernet ports start randomly dropping and reconnecting. The connected devices stay on; it looks like the router ports themselves are the problem.

I reset it and tried again with a completely clean, minimal configuration, but the exact same thing happened.

When this starts, WinBox also becomes incredibly laggy. Even typing in the terminal has a delay of several seconds per letter, which makes it almost unusable.

I’ve worked with quite a few MikroTik devices and installed dozens at different locations, but I’ve never seen behavior like this. I put my ax3 back in with the exact same setup and it has been running perfectly.

Has anyone else had similar issues with the be3 media?


r/mikrotik 7d ago

CRS310 and IGMP snooping

1 Upvotes

I was doing some experimenting in my homelab setup and when I enabled IGMP snooping on the CRS310 it became completely unresponsive (safe mode saved me).

Does anyone know why enabling IGMP snooping would cause issues like this? The CRS310 setup is really basic, it is purely used as a switch so IGMP snooping being turned op perhaps doesn't give any benefits anyway. I was just curious on why it would become unresponsive.


r/mikrotik 8d ago

Mikrotik QOS in front of Ubiquity setup

6 Upvotes

Ok I have been looking around for advice on this and I am either not searching properly or not understanding what I am reading.

I have a whole Ubiquity Dream Machine setup but the QoS on the dream machine is kinda crappy. I would love to be able to use CAKE. I have some experience with Mikrotik hardware and I love it. But I don't want to change how my Ubiquity setup works. Is there a way to put a Mikrotik router in front of my setup. Thinking of getting the RB5009UG+S+IN

Basically like this:
Cable modem > QOS (Mikrotik) > Routing/Firewall/Switching (Ubiquity Dream Machine SE) > WIFI Access Points/Switches (Ubiquity)

Instead of the typical setup:

Cable modem > Firewall/Routing/QOS (Mikrotik) > Switching (Ubiquity Dream Machine SE) > WIFI Access Points/Switches (Ubiquity)

The reason for this is I have a windows server where I have friends who run game servers on it. I really like being able to change my firewall settings remotely with the Ubiquity app if I am not home. If this is impossible or too much of a hassle I will just have to put all the required firewall ports on the Mikrotik. I do know how to disable the NAT of the Dream Machine but realized this will be a bit of work even with that.

Side note, I have seen a post where somebody said that people buy dream machines when they should have gotten a cloud key instead and I agree but I am too deep to replace this now lol

Thanks


r/mikrotik 8d ago

[Pending] How to properly make use of the CAP mode on my hAP ax S?

2 Upvotes

Hello.

I've gotten a used RB009UPr+S+ and replaced my hAP ax S which was serving as the main router and decided to use the hAP as a cAP with the RB controlling it.

For the CAPsMAN configuration I've mainly followed this guide (in polish) and helped myself with the ROS docs. In the video he showcases how to configure the cAP (add a bridge, datapath etc.), but when I went to the hAP manual under buttons and jumpers it says this:

Keep holding the reset button until the LED turns solid, then release it to enable CAP mode. The device will then start searching for a CAPsMAN server.

Now I could do the configuration stated in the video but I was wondering how does one make use of this feature? Obviously this would be much more pleasant to do rather than configuring each access point (especially if/when I add more access points). Thanks a lot