Mikrotik Vodafone NEBA IPTV

Hola a todos,
Me acabo de comprar un Mikrotik RB750GR3 para reemplazar el router Sercomm FG824CD de Vodafone.
Tengo una conexion NEBA de Vodafone asi que empezé siguiendo los manuales de conexion basicas ISP...
He conseguido que me funcioné internet como queria, con algunos puertos abiertos y nat loopback (Hairspin...)
Pero soy incapaz de que me funciona la TV. Bueno, tengo la guia y las apps que van bien, pero no puede sincronizar canales.

He vuelto a conectar de momento el Sercomm ya que me matan en casa sin TV y he aprovechado echar un ojo otra vez a la config.
Mi sorpresa cuando me he dado cuenta que la configuracion de la IPTV habia cambiado :
Antes, una unica Vlan para todo, vlan 24 y punto
Ahora, tengo vlan 24 para data y otro perfil TV se ha activado (FTTH-NEBAMR-TV en lugar de FTTH-NEBA-TV) y en este, tengo Vlan 28 con prioridad 4
tipo de conexion "static" con MTU standard de 1500
en otro apartado de la config, veo que hay rutas estaticas pero estan asosiadas a otro perfil de IPTV (DHCP que no esta activado)
Tb he visto que el IGMP Proxy esta activado...
A pesar de haber leido bastante por aqui, de intentar adaptar configuracion que he visto a mi caso, no doy con la TV...
Añado que tengo un Pi-Hole que gestiona el DHCP y DNS, el IPv6 esta desactivado
Si alguien puede ayudarme, seria genial

Adjunto mi codigo actual :

Código:
# jan/02/1970 03:38:50 by RouterOS 7.1.1
# software id = PIIY-STFR
#
# model = RB750Gr3
# serial number = xxxxxxxxxx
/interface bridge
add admin-mac=2C:xx:xx:xx:xx:01 auto-mac=no comment=defconf igmp-snooping=yes \
    multicast-querier=yes name=bridge
/interface vlan
add interface=ether1 name=INTERNET vlan-id=24
add interface=ether1 name=TIVO vlan-id=28
/interface pppoe-client
add add-default-route=yes disabled=no interface=INTERNET max-mru=1492 \
    max-mtu=1492 name=pppoe-out1 use-peer-dns=yes user=\
    VFAF000000xxxxxx@vodafone
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=default-dhcp ranges=192.168.1.10-192.168.1.254
/ip dhcp-server
add address-pool=default-dhcp disabled=yes interface=bridge name=defconf
/port
set 0 name=serial0
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf fast-leave=yes interface=ether5 pvid=28
add bridge=bridge interface=ether1
/ip neighbor discovery-settings
set discover-interface-list=LAN
/ipv6 settings
set disable-ipv6=yes
/interface bridge vlan
add bridge=bridge untagged=bridge,ether2,ether3,ether4 vlan-ids=1
add bridge=bridge tagged=ether1 untagged=ether5 vlan-ids=28
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=pppoe-out1 list=WAN
/ip address
add address=192.168.1.1/24 comment=defconf interface=bridge network=192.168.1.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
# DHCP client can not run on slave interface!
add comment=defconf interface=ether1
/ip dhcp-server network
add address=192.168.1.0/24 comment=defconf dns-server=192.168.1.1 gateway=192.168.1.1
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.1.1 comment=defconf name=router.lan
/ip firewall address-list
add address=xxxxxxxxxxx.sn.mynetname.net list=WAN-IP
/ip firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
/ip firewall mangle
add action=set-priority chain=postrouting new-priority=4 out-interface=TIVO
add action=set-priority chain=postrouting new-priority=0 out-interface=pppoe-out1
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
    ipsec-policy=out,none out-interface-list=WAN
add action=masquerade chain=srcnat comment=hairpin-nat dst-address=\
    192.168.1.0/24 src-address=192.168.1.0/24
add action=dst-nat chain=dstnat comment=Plex dst-address-list=WAN-IP \
    dst-port=32400 protocol=tcp to-addresses=192.168.1.87
add action=dst-nat chain=dstnat comment=Hassio dst-address-list=WAN-IP \
    dst-port=8123 protocol=tcp to-addresses=192.168.1.68 to-ports=8123
add action=dst-nat chain=dstnat comment=Hassio dst-address-list=WAN-IP \
    dst-port=8123 protocol=udp to-addresses=192.168.1.68 to-ports=8123
add action=dst-nat chain=dstnat comment=ZM dst-address-list=WAN-IP dst-port=\
    8770 protocol=tcp to-addresses=192.168.1.55 to-ports=8770
add action=dst-nat chain=dstnat comment=ZM dst-address-list=WAN-IP dst-port=\
    8770 protocol=udp to-addresses=192.168.1.55 to-ports=8770
/ip route
add distance=1 dst-address=10.8.57.0/24 gateway=TIVO pref-src=10.214.13.28
add distance=1 dst-address=10.8.58.0/24 gateway=TIVO pref-src=10.214.13.28
add distance=1 dst-address=10.8.59.0/24 gateway=TIVO pref-src=10.214.13.28
add distance=1 dst-address=10.10.2.0/24 gateway=10.10.1.2
add distance=1 dst-address=10.15.220.0/24 gateway=TIVO pref-src=10.214.13.28
add distance=1 dst-address=10.179.32.0/23 gateway=TIVO pref-src=10.214.13.28
/routing igmp-proxy
set quick-leave=yes
/routing igmp-proxy interface
add alternative-subnets=0.0.0.0/0 interface=TIVO upstream=yes
/system clock
set time-zone-name=Europe/Madrid
/system ntp client
set enabled=yes
/system ntp client servers
add address=0.es.pool.ntp.org
add address=1.es.pool.ntp.org
add address=2.es.pool.ntp.org
add address=3.es.pool.ntp.org
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN

Muchas Gracias de antemano
 
Última edición:
Yo estoy intentando hacerlo pero aun me falta acabar de configurar el hap mini.
Crees que si le pongo esta configuración tuya,cambiando el user y password, valdria para el mio ??
A mi me da igual la tele y el fijo.
Saludos y gracias


Enviado desde mi iPhone utilizando Tapatalk
 
Yo estoy intentando hacerlo pero aun me falta acabar de configurar el hap mini.
Crees que si le pongo esta configuración tuya,cambiando el user y password, valdria para el mio ??
A mi me da igual la tele y el fijo.
Saludos y gracias


Enviado desde mi iPhone utilizando Tapatalk
Funcionaria si, pero hay cosas aqui inutiles para ti...
Lo que he hecho, despues de actualizar Mikrotik a la version v7 es seguir los pasos de la configuracion basica, con algunas modificacion, ya que no usa el servidor DHCP del Mikrotik y que tengo mi red local en 192.168.1.0/24 (y no como por defecto en 192.168.88.0/24).

Mira por aqui : MANUAL: Mikrotik, configuraciones básicas ISPs - RouterOS v7

Hay que aplicar esa configuracion después de un reset sin marcar la opción del no default configuration.

No dudes en preguntas te sigue fallando.
 
Funcionaria si, pero hay cosas aqui inutiles para ti...
Lo que he hecho, despues de actualizar Mikrotik a la version v7 es seguir los pasos de la configuracion basica, con algunas modificacion, ya que no usa el servidor DHCP del Mikrotik y que tengo mi red local en 192.168.1.0/24 (y no como por defecto en 192.168.88.0/24).

Mira por aqui : MANUAL: Mikrotik, configuraciones básicas ISPs - RouterOS v7

Hay que aplicar esa configuracion después de un reset sin marcar la opción del no default configuration.

No dudes en preguntas te sigue fallando.

Mañana empezaremos por actualizar a la ultima versión del routerOS.
Gracias y saludos


Enviado desde mi iPhone utilizando Tapatalk
 
Yo he conseguido hacer funcionar IPTV + VoIP en NEBA con vodafone, en mi caso solo tengo VLAN24, con la TV fuera del PPPoE. En tu config veo que te falta poner el IGMP proxy en el bridge,
 
Yo he conseguido hacer funcionar IPTV + VoIP en NEBA con vodafone, en mi caso solo tengo VLAN24, con la TV fuera del PPPoE. En tu config veo que te falta poner el IGMP proxy en el bridge,
Hola,
He vuelto a conectar el Sercomm y mirar si podia volver a la VLAN24 unica (FTTH-NEBA-TV) para probar lo que me dijiste :

wlan.PNG


Y he visto que todo me funciona. Entonces, he reseteado el Mokrotik y puso la config solo con VLAN24 pero sigue fallando.
Me he dado cuenta de que si pongo la interface "INTERNET" en el bridge, me funciona la TV pero pierdo la conexion pppoe.
Si quito "INTERNET" del bridge, recupero la conexion pppoe (et internet) pero la TV ya no va...

Ya voy un poco perdido la verdad....
Me pondrias tu config ?
 
Hola,
He vuelto a conectar el Sercomm y mirar si podia volver a la VLAN24 unica (FTTH-NEBA-TV) para probar lo que me dijiste :

Ver el adjunto 91692

Y he visto que todo me funciona. Entonces, he reseteado el Mokrotik y puso la config solo con VLAN24 pero sigue fallando.
Me he dado cuenta de que si pongo la interface "INTERNET" en el bridge, me funciona la TV pero pierdo la conexion pppoe.
Si quito "INTERNET" del bridge, recupero la conexion pppoe (et internet) pero la TV ya no va...

Ya voy un poco perdido la verdad....
Me pondrias tu config ?

Claro, aquí te debajo te dejo mi config. Si reseteas el mikrotik te recomiendo dejar la configuración por defecto y partir de ahí, levantar la vlan 24 y el pppoe, activar el igmp proxy con el upstream en la vlan24, y el downstream en el bridge, y algo que hice yo pero no se si es 100% necesario es configurar las rutas multicast, que la mayoría se pueden sacar del router de vodafone y otras mirando el listado de intentos de conexiones en el firewall de mikrotik, así como las reglas para permitir el tráfico igmp.

Saludos!

Código:
# feb/09/2022 19:36:12 by RouterOS 7.1.1
# software id = 5JAP-H0JL
#
# model = RB750Gr3
# serial number = CC210E71200E
/interface bridge
add admin-mac=XXXXXXXXXXXXXXX auto-mac=no igmp-snooping=yes igmp-version=3 \
    multicast-querier=yes name=bridge protocol-mode=none
/interface ethernet
set [ find default-name=ether1 ] name=WAN-ether1
/interface wireguard
add listen-port=13232 mtu=1420 name=wireguard-pc
add listen-port=13231 mtu=1420 name=wireguard-s20
add listen-port=13230 mtu=1420 name=wireguard-tun
/interface vlan
add interface=WAN-ether1 name=vodafone-neba vlan-id=24
/interface pppoe-client
add add-default-route=yes disabled=no interface=vodafone-neba max-mru=1492 \
    max-mtu=1492 name=pppoe-vodafone use-peer-dns=yes user=\
    VFAF00XXXXXXXXXXXXX@vodafone
/interface list
add name=WAN
add name=WIREGUARD
add include=WIREGUARD name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp-lan ranges=192.168.1.120-192.168.1.250
/ip dhcp-server
add address-pool=dhcp-lan interface=bridge lease-time=1d name=dhcp-lan
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface detect-internet
set detect-interface-list=all
/interface list member
add interface=bridge list=LAN
add interface=WAN-ether1 list=WAN
add interface=pppoe-vodafone list=WAN
add interface=wireguard-s20 list=WIREGUARD
add interface=wireguard-pc list=WIREGUARD
add interface=wireguard-tun list=WIREGUARD
/interface wireguard peers
add allowed-address=192.168.50.2/32 interface=wireguard-s20 public-key=\
    "XXXXXXXXXXXXXXXXXXXXXXX="
add allowed-address=192.168.51.2/32 interface=wireguard-pc public-key=\
    "XXXXXXXXXXXXXXXXXXXXXXX="
add allowed-address=0.0.0.0/0 endpoint-address=XXXXXXXXXXXX.sn.mynetname.net \
    endpoint-port=13230 interface=wireguard-tun public-key=\
    "XXXXXXXXXXXXXXXXXXXXXXX="
/ip address
add address=192.168.1.1/24 interface=bridge network=192.168.1.0
add address=225.0.0.0 interface=vodafone-neba network=225.0.0.0
add address=10.8.57.0 interface=vodafone-neba network=10.8.57.0
add address=10.8.58.0 interface=vodafone-neba network=10.8.58.0
add address=10.8.59.0 interface=vodafone-neba network=10.8.59.0
add address=10.15.220.0 interface=vodafone-neba network=10.15.220.0
add address=10.179.32.0 interface=vodafone-neba network=10.179.32.0
add address=224.0.0.22 interface=vodafone-neba network=224.0.0.22
add address=224.0.0.1 interface=vodafone-neba network=224.0.0.1
add address=239.192.251.77 interface=vodafone-neba network=239.192.251.77
add address=192.168.50.1/24 interface=wireguard-s20 network=192.168.50.0
add address=192.168.51.1/24 interface=wireguard-pc network=192.168.51.0
add address=172.16.1.1/30 interface=wireguard-tun network=172.16.1.0
/ip cloud
set ddns-enabled=yes ddns-update-interval=2m
/ip dhcp-client
add comment=defconf disabled=yes interface=WAN-ether1
/ip dhcp-server config
set store-leases-disk=24m
/ip dhcp-server lease
add address=192.168.1.100 lease-time=1w mac-address=XXXXXXXXXXXXXXXX server=\
    dhcp-lan
add address=192.168.1.250 mac-address=XXXXXXXXXXXXXXXXX server=dhcp-lan
add address=192.168.1.99 mac-address=XXXXXXXXXXXXXXXXXX server=dhcp-lan
add address=192.168.1.5 mac-address=XXXXXXXXXXXXXXXXXXX server=dhcp-lan
add address=192.168.1.251 mac-address=XXXXXXXXXXXXXXXXX server=dhcp-lan
add address=192.168.1.8 mac-address=XXXXXXXXXXXXXXXXXXX server=dhcp-lan
add address=192.168.1.7 mac-address=XXXXXXXXXXXXXXXXXX server=dhcp-lan
/ip dhcp-server network
add address=192.168.1.0/24 dns-server=192.168.1.100,192.168.1.1 gateway=\
    192.168.1.1 netmask=24 ntp-server=150.214.94.5
/ip dns
set allow-remote-requests=yes use-doh-server=\
    https://cloudflare-dns.com/dns-query verify-doh-cert=yes
/ip dns static
add address=192.168.1.1 comment=defconf name=router.lan
add address=104.16.248.249 name=cloudflare-dns.com
add address=104.16.249.249 name=cloudflare-dns.com
/ip firewall address-list
add address=13XXXXXXXXX list=XXXXXXXXXXXXX
add address=152.XXXXXXXX list=XXXXXXXXXXXXXX
add address=192.168.1.0/24 list=LAN
add address=192.168.50.0/24 list=LAN
add address=10.6.0.0/24 list=LAN
add address=192.168.51.0/24 list=LAN
add address=192.168.10.0/24 list=LAN
/ip firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=accept chain=input in-interface=vodafone-neba protocol=igmp
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMP" in-interface=\
    pppoe-vodafone protocol=icmp src-address-list=rXXXXXXXXXXXX
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=accept chain=input comment="accept wireguard traffic" dst-port=\
    13230,13231,13232 protocol=udp
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
add action=accept chain=input comment="Aceptar winbox por vpn" dst-port=8291 \
    protocol=tcp src-address=192.168.51.0/24
/ip firewall mangle
add action=set-priority chain=postrouting new-priority=0 out-interface=\
    vodafone-neba passthrough=yes
add action=set-priority chain=postrouting new-priority=0 out-interface=\
    pppoe-vodafone
/ip firewall nat
add action=masquerade chain=srcnat ipsec-policy=out,none out-interface-list=\
    WAN
add action=dst-nat chain=dstnat dst-port=443 in-interface=pppoe-vodafone \
    protocol=tcp to-addresses=192.168.1.100 to-ports=443
add action=dst-nat chain=dstnat dst-port=80 in-interface=pppoe-vodafone \
    protocol=tcp to-addresses=192.168.1.100 to-ports=80
add action=dst-nat chain=dstnat dst-port=161 in-interface=pppoe-vodafone \
    protocol=udp to-addresses=192.168.1.250 to-ports=161
add action=dst-nat chain=dstnat dst-port=10001 in-interface=pppoe-vodafone \
    protocol=udp to-addresses=192.168.1.250 to-ports=10001
add action=dst-nat chain=dstnat dst-port=10002 in-interface=pppoe-vodafone \
    protocol=udp to-addresses=192.168.1.250 to-ports=10002
add action=dst-nat chain=dstnat dst-port=5060 in-interface=pppoe-vodafone \
    protocol=udp to-addresses=192.168.1.151 to-ports=5060
add action=dst-nat chain=dstnat dst-port=5095 in-interface=pppoe-vodafone \
    protocol=udp to-addresses=192.168.1.151 to-ports=5095
add action=dst-nat chain=dstnat dst-port=16400 in-interface=pppoe-vodafone \
    protocol=udp to-addresses=192.168.1.151 to-ports=16400
add action=dst-nat chain=dstnat dst-port=2609 in-interface=pppoe-vodafone \
    protocol=udp to-addresses=192.168.1.100 to-ports=2609
add action=dst-nat chain=dstnat dst-port=853 in-interface=pppoe-vodafone \
    protocol=tcp to-addresses=192.168.1.100 to-ports=853
/ip route
add disabled=no distance=1 dst-address=192.168.10.0/24 gateway=172.16.1.2 \
    pref-src="" routing-table=main scope=30 suppress-hw-offload=no \
    target-scope=10
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www port=90
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=pppoe-vodafone type=external
add interface=bridge type=internal
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=\
    icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" port=\
    33434-33534 protocol=udp
add action=accept chain=input comment=\
    "defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=\
    udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 \
    protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=\
    ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=\
    ipsec-esp
add action=accept chain=input comment=\
    "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment=\
    "defconf: drop everything else not coming from LAN" in-interface-list=\
    !LAN
add action=accept chain=forward comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment=\
    "defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" \
    hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=\
    icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=\
    500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=\
    ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=\
    ipsec-esp
add action=accept chain=forward comment=\
    "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment=\
    "defconf: drop everything else not coming from LAN" in-interface-list=\
    !LAN
/routing igmp-proxy
set quick-leave=yes
/routing igmp-proxy interface
add alternative-subnets=0.0.0.0/0 interface=vodafone-neba upstream=yes
add alternative-subnets=0.0.0.0/0 interface=bridge
/system clock
set time-zone-name=Europe/Madrid
/system identity
set name=rspn-apolo
/system ntp client
set enabled=yes
/system ntp client servers
add address=150.214.94.5
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
 
Ya me funciona !
por lo visto, como decias, me faltaba el downstream en el bridge...
Por alguna razon al primer intento, aunque habia suprimido toda referencia a 192.168.88.0/24 y 192.168.88.1, seguia presente en el downstream como "source IP Address".
Despues de un segundo reinicio, todo OK.
Tambien, he cambiado el igmp-version a la version 3, que se pone por defecto a v2 (no se muy bien si es relevante)
he notado que he ganado en velocidad (contrato 600Mb) :
1644499613752.png

Tenia antes 358Mbps en download y 269Mbps en upload :p
Muchas gracias otra vez.
 
Arriba