{"id":1537,"date":"2017-04-18T04:28:28","date_gmt":"2017-04-18T04:28:28","guid":{"rendered":"http:\/\/www.mtin.net\/blog\/?p=1537"},"modified":"2017-04-18T04:28:28","modified_gmt":"2017-04-18T04:28:28","slug":"the-importance-of-checking-layer-one-and-two","status":"publish","type":"post","link":"http:\/\/www.mtin.net\/blog\/the-importance-of-checking-layer-one-and-two\/","title":{"rendered":"The importance of checking layer one and two"},"content":{"rendered":"<p>I had a simple network consisting of a Mikrotik hooked to an internet connection along with 3 APs behind it. \u00a0Nothing fancy, \u00a0The network was experiencing drop out in service. \u00a0The internet would just stop. \u00a0One of the most noticeable things would iPhones would drop the wireless link and revert back to LTE, or the internet would just stop working for them. \u00a0This was happening on a very regular basis.<\/p>\n<p>Wireless testing was done, new APs were added, but no one thought to check the ports on the headend router. \u00a0Upon investigation of the logs this was found:<\/p>\n<p><img data-attachment-id=\"1538\" data-permalink=\"http:\/\/www.mtin.net\/blog\/the-importance-of-checking-layer-one-and-two\/screen-shot-2017-04-18-at-12-18-35-am-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2017\/04\/Screen-Shot-2017-04-18-at-12.18.35-AM-2.png?fit=875%2C575\" data-orig-size=\"875,575\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Screen Shot 2017-04-18 at 12.18.35 AM (2)\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2017\/04\/Screen-Shot-2017-04-18-at-12.18.35-AM-2.png?fit=300%2C197\" data-large-file=\"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2017\/04\/Screen-Shot-2017-04-18-at-12.18.35-AM-2.png?fit=580%2C381\" decoding=\"async\" loading=\"lazy\" class=\"alignnone  wp-image-1538\" src=\"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2017\/04\/Screen-Shot-2017-04-18-at-12.18.35-AM-2.png?resize=466%2C309\" alt=\"\" width=\"466\" height=\"309\" data-recalc-dims=\"1\" \/><\/p>\n<p>Normally this would be a slam dunk, however, there was nothing plugged in at all to ether4 to generate these areas. \u00a0No cable, no nothing. \u00a0If you disabled the port the errors would go away. \u00a0Re-enable the port and they would come back. \u00a0Upgrade and downgrade of the OS did not seem to fix the issue. \u00a0A new headend router was installed and everything was back to working normally.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I had a simple network consisting of a Mikrotik hooked to an internet connection along with 3 APs behind it. \u00a0Nothing fancy, \u00a0The network was experiencing drop out in service. \u00a0The internet would just stop. \u00a0One of the most noticeable things would iPhones would drop the wireless link and revert back to LTE, or the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[24],"tags":[],"jetpack_publicize_connections":[],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p6VLMf-oN","jetpack-related-posts":[{"id":2421,"url":"http:\/\/www.mtin.net\/blog\/cambium-and-management-vlans\/","url_meta":{"origin":1537,"position":0},"title":"Cambium and Management vlans","author":"j2sw","date":"September 6, 2018","format":false,"excerpt":"Just a quick diagram on how to separate Management traffic on an ePMP network. The aps\u00a0and CPE are in bridge mode in this setup. The Cambium CPE are in bridge mode with CNPilot routers doing PPPoE, which the ISP has control over as a managed router. Our netonix has a\u2026","rel":"","context":"In &quot;Cambium&quot;","block_context":{"text":"Cambium","link":"http:\/\/www.mtin.net\/blog\/category\/cambium\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2018\/09\/aps_vlans-e1536254028499.jpg?fit=647%2C532&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":2764,"url":"http:\/\/www.mtin.net\/blog\/map-installer-toolbox\/","url_meta":{"origin":1537,"position":1},"title":"mAP installer toolbox","author":"j2sw","date":"January 25, 2019","format":false,"excerpt":"One of the problems installers run into on a few networks we manage is having the right tools to properly test a new install. Sure, an installer can run a test to speedtest.net to verify customers are getting their speed.\u00a0 Anyone who has done this long enough knows speedtest.net can\u2026","rel":"","context":"In &quot;Mikrotik&quot;","block_context":{"text":"Mikrotik","link":"http:\/\/www.mtin.net\/blog\/category\/mikrotik\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2019\/01\/IMG_1039-768x1024.jpeg?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":297,"url":"http:\/\/www.mtin.net\/blog\/protecting-your-mikrotik-from-dns-amplification\/","url_meta":{"origin":1537,"position":2},"title":"Protecting your Mikrotik from DNS Amplification","author":"j2sw","date":"May 8, 2015","format":false,"excerpt":"There are several reasons and benefits to using your Mikrotik as a DNS caching server. \u00a0Queries to the client are just a tad faster, which makes the overall user experience seem snappier. \u00a0It also allows you to quickly change upstream DNS servers in the even of an outage, attack, etc.\u2026","rel":"","context":"In \"amplification\"","block_context":{"text":"amplification","link":"http:\/\/www.mtin.net\/blog\/tag\/amplification\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2165,"url":"http:\/\/www.mtin.net\/blog\/ipv6-firewall-rules-for-mikrotik\/","url_meta":{"origin":1537,"position":3},"title":"IPV6 Firewall rules for Mikrotik","author":"j2sw","date":"March 23, 2018","format":false,"excerpt":"Some basic IPV6 Firewall Rules for Mikrotik. Replace in-interface=\"\" with your appropriate interface. \/ipv6 firewall filter add chain=input protocol=icmpv6 add chain=input connection-state=established,related add chain=input dst-port=546 in-interface=ether1-wan protocol=udp src-port=547 add action=drop chain=input connection-state=invalid add action=drop chain=input connection-state=new in-interface=ether1-wan add chain=forward protocol=icmpv6 add chain=forward connection-state=established,related add chain=forward connection-state=new in-interface=!ether1-wan add action=drop chain=forward\u2026","rel":"","context":"In &quot;Mikrotik&quot;","block_context":{"text":"Mikrotik","link":"http:\/\/www.mtin.net\/blog\/category\/mikrotik\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2105,"url":"http:\/\/www.mtin.net\/blog\/my-home-lab-testing-ground\/","url_meta":{"origin":1537,"position":4},"title":"My Home Lab\/Testing ground","author":"j2sw","date":"February 18, 2018","format":false,"excerpt":"A few days ago, my buddy, Greg Sowell posted his Mobile Home Lab. I figured I would show off the rack in my home office. This is a mixture of gear that powers the basic network for the network in my home and for testing, blog posts, support, and videos\\.\u2026","rel":"","context":"In &quot;cisco&quot;","block_context":{"text":"cisco","link":"http:\/\/www.mtin.net\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2018\/02\/IMG_3522.jpg?fit=900%2C1200&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2018\/02\/IMG_3522.jpg?fit=900%2C1200&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.mtin.net\/blog\/wp-content\/uploads\/2018\/02\/IMG_3522.jpg?fit=900%2C1200&resize=700%2C400 2x"},"classes":[]},{"id":2885,"url":"http:\/\/www.mtin.net\/blog\/mikrotik-vulnerability\/","url_meta":{"origin":1537,"position":5},"title":"Mikrotik Vulnerability","author":"j2sw","date":"February 25, 2019","format":false,"excerpt":"On February 2 a CVE issue was published, describing a vulnerability, which allows to proxy a TCP\/UDP request through the routers Winbox port if it's open to the internet. A fix has already been released on February 11, 2019 in all RouterOS release channels. Please keep your device up to\u2026","rel":"","context":"In \"mikrotik\"","block_context":{"text":"mikrotik","link":"http:\/\/www.mtin.net\/blog\/tag\/mikrotik-2\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_likes_enabled":true,"_links":{"self":[{"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/posts\/1537"}],"collection":[{"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/comments?post=1537"}],"version-history":[{"count":1,"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/posts\/1537\/revisions"}],"predecessor-version":[{"id":1539,"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/posts\/1537\/revisions\/1539"}],"wp:attachment":[{"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/media?parent=1537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/categories?post=1537"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.mtin.net\/blog\/wp-json\/wp\/v2\/tags?post=1537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}