Community discussions

MikroTik App

Search found 229 matches

by mknnoc
Sun Sep 12, 2021 12:31 pm
Forum: General
Topic: is connection-tracking full ?
Replies: 5
Views: 3410

Re: is connection-tracking full ?

6.45.7 at least I hope?
it is fixed after upgrading.
by mknnoc
Sat Sep 11, 2021 8:13 am
Forum: General
Topic: is connection-tracking full ?
Replies: 5
Views: 3410

is connection-tracking full ?

Current max entries is 1048576 while using is around 1057000. Is it full ?

Is there anyway to increase it ? I am using 6.45 on CCR1036.
by mknnoc
Mon Nov 11, 2013 10:32 am
Forum: General
Topic: PPPoE - Simple Queue - Parent Queue in ROS 6.5
Replies: 6
Views: 2797

Re: PPPoE - Simple Queue - Parent Queue in ROS 6.5

any input ?
by mknnoc
Mon Nov 04, 2013 3:50 am
Forum: General
Topic: PPPoE - Simple Queue - Parent Queue in ROS 6.5
Replies: 6
Views: 2797

Re: PPPoE - Simple Queue - Parent Queue in ROS 6.5

Well, it seems not many are interested to use "Parent Queue" in PPPoE deployment.
by mknnoc
Fri Nov 01, 2013 12:21 pm
Forum: General
Topic: PPPoE - Simple Queue - Parent Queue in ROS 6.5
Replies: 6
Views: 2797

Re: PPPoE - Simple Queue - Parent Queue in ROS 6.5

anyone ?
by mknnoc
Mon Oct 28, 2013 4:34 am
Forum: General
Topic: PPPoE - Simple Queue - Parent Queue in ROS 6.5
Replies: 6
Views: 2797

PPPoE - Simple Queue - Parent Queue in ROS 6.5

Hello, I see the latest version of ROS can do "Queue - Parent Queue" in "PPP - Profile" which can i can specify the parent Q to the auto PPP simple queue. 1. What attribute to use if I want to set "Parent Queue" from radius server? 2. if not possible or not yet support,...
by mknnoc
Tue Aug 27, 2013 7:58 am
Forum: General
Topic: Radius Attribute for Address-list
Replies: 0
Views: 743

Radius Attribute for Address-list

Does Mikrotik provide any attribute to add customer's IP to certain address-list ?
by mknnoc
Thu Aug 01, 2013 6:41 am
Forum: Scripting
Topic: API to change rate-limit of PPPoE
Replies: 1
Views: 938

API to change rate-limit of PPPoE

Some people told me that it is possible to change rate-limit of PPPoE session without disconnect the session with API.
Is it true ? Any reference code to do so ?
by mknnoc
Wed Jul 24, 2013 10:17 am
Forum: General
Topic: Does ROS6.x support PPPoE CoA ?
Replies: 0
Views: 639

Does ROS6.x support PPPoE CoA ?

Does ROS6.x support PPPoE CoA ?
by mknnoc
Tue Jul 23, 2013 11:27 am
Forum: General
Topic: Why Simple Queue is better then Queue Tree in ROS 6.x?
Replies: 9
Views: 4992

Re: Why Simple Queue is better then Queue Tree in ROS 6.x?

how about bonding interface HTB ? any experience with it ?
by mknnoc
Tue Jul 23, 2013 10:12 am
Forum: General
Topic: Why Simple Queue is better then Queue Tree in ROS 6.x?
Replies: 9
Views: 4992

Re: Why Simple Queue is better then Queue Tree in ROS 6.x?

yes, it is simpler but which one give better performance ?

PS: if i terminate customer on vlan interface ( 1 customer = 1 vlan), can i just use trunk interface as parent interface for download in Q Tree ?
by mknnoc
Tue Jul 23, 2013 9:36 am
Forum: General
Topic: Why Simple Queue is better then Queue Tree in ROS 6.x?
Replies: 9
Views: 4992

Re: Why Simple Queue is better then Queue Tree in ROS 6.x?

Let say we have a few internet package like 512kbps, 1mbps, 2mbps with 1000 users. What is the best way to limit users ? Simple Queue or Queue tree in ROS6.x?
by mknnoc
Tue Jul 23, 2013 9:23 am
Forum: General
Topic: Why Simple Queue is better then Queue Tree in ROS 6.x?
Replies: 9
Views: 4992

Re: Why Simple Queue is better then Queue Tree in ROS 6.x?

It seems true for both ROS 5.x and ROS 6.x, isn't it?
by mknnoc
Thu Jul 18, 2013 10:44 am
Forum: General
Topic: Why Simple Queue is better then Queue Tree in ROS 6.x?
Replies: 9
Views: 4992

Why Simple Queue is better then Queue Tree in ROS 6.x?

From packet flow diagram, both simple queue and queue tree is located at the same location (post routing, input).
Why Simple Queue is better/faster then Queue Tree in ROS 6.x?
by mknnoc
Wed Jul 03, 2013 6:00 am
Forum: General
Topic: Connection Tracking is not working well in ROS 6.1
Replies: 5
Views: 1660

Re: Connection Tracking is not working well in ROS 6.1

Yes, Connection Tracking is enabled. If i disable, below feature will not work: NAT Firewall: connection-bytes connection-mark connection-type connection-state connection-limit connection-rate layer7-protocol p2p new-connection-mark tarpit p2p matching in simple queues I am aware of that. But the pr...
by mknnoc
Mon Jul 01, 2013 9:36 am
Forum: General
Topic: Connection Tracking is not working well in ROS 6.1
Replies: 5
Views: 1660

Re: Connection Tracking is not working well in ROS 6.1

anyone ?

I did email to support but no response :(
by mknnoc
Sun Jun 30, 2013 8:02 pm
Forum: General
Topic: Connection Tracking is not working well in ROS 6.1
Replies: 5
Views: 1660

Re: Connection Tracking is not working well in ROS 6.1

I believe this is a bug. Anyone facing the same problem?
by mknnoc
Sun Jun 30, 2013 2:48 pm
Forum: General
Topic: Connection Tracking is not working well in ROS 6.1
Replies: 5
Views: 1660

Connection Tracking is not working well in ROS 6.1

I am doing mangle in forward and found that some connection are not listed in the connection tracking table while it is enabled (auto or yes). Attachment is the screenshot.[img]image.jpg[/img] any idea? Let me know if you want see more config. Thanks.
by mknnoc
Wed Jun 26, 2013 8:44 am
Forum: General
Topic: New Packet flow diagram
Replies: 99
Views: 88274

Re: New Packet flow diagram

I am not sure if I understand it correctly. If possible, can you write some explanation under each packet flow diagram?
by mknnoc
Wed Jun 19, 2013 12:12 pm
Forum: General
Topic: Excluding some traffic from simple queue
Replies: 2
Views: 1401

Excluding some traffic from simple queue

I am trying to exclude some traffic from simple queue which is auto created by PPPoE dial-in. Example: user goes to certain websites with extra bandwidth like 50Mbps while he goes Internet is 1Mbps. Is it possible do that simple queue ? or I need to move all to Queue Tree ?

Thanks :)
by mknnoc
Mon Apr 01, 2013 11:39 am
Forum: General
Topic: Can we do limit-at with PCQ ?
Replies: 0
Views: 656

Can we do limit-at with PCQ ?

I am looking for the way to give CIR to my users with PCQ? In PCQ config, I can config below parameter: PCQ parameters: pcq-classifier (dst-address | dst-port | src-address | src-port; default: "") : selection of sub-stream identifiers pcq-rate (number) : maximal available data rate of eac...
by mknnoc
Sun Mar 17, 2013 5:00 am
Forum: The Dude
Topic: Dude monitor bandwidth threshold of link
Replies: 3
Views: 3378

Dude monitor bandwidth threshold of link

Is DUDE able to monitor bandwidth threshold of link ? let say if it drop under 50% or go up to 90% then alert ?
by mknnoc
Tue Mar 12, 2013 6:50 am
Forum: General
Topic: PCQ queue type is tied to connection tracking and now is NAT
Replies: 0
Views: 573

PCQ queue type is tied to connection tracking and now is NAT

Can anyone explain this "PCQ queue type is tied to connection tracking and
now is NAT aware" ? any config example ?
by mknnoc
Wed Mar 06, 2013 10:53 am
Forum: General
Topic: Using L3 device between hotspot gateway and client
Replies: 0
Views: 747

Using L3 device between hotspot gateway and client

Using L3 device between hotspot gateway and client, does it work ? will it function normal?
by mknnoc
Wed Mar 06, 2013 10:03 am
Forum: Wireless Networking
Topic: One big AP to cover whole place, possible ?
Replies: 3
Views: 1325

Re: One big AP to cover whole place, possible ?

Normal device like smart phone or laptop are able to transmit back to the AP ?
by mknnoc
Tue Mar 05, 2013 5:35 am
Forum: Wireless Networking
Topic: One big AP to cover whole place, possible ?
Replies: 3
Views: 1325

One big AP to cover whole place, possible ?

Is it possible to use one big AP + Antennas to cover 1km square ?
Client devices will be Smart Phone or Laptop.
by mknnoc
Mon Feb 18, 2013 10:36 am
Forum: General
Topic: connection tracking is not working in Ros 6.0rc6
Replies: 2
Views: 930

Re: connection tracking is not working in Ros 6.0rc6

i don't see the problem listed in the changelog.
by mknnoc
Mon Feb 18, 2013 6:45 am
Forum: General
Topic: connection tracking is not working in Ros 6.0rc6
Replies: 2
Views: 930

connection tracking is not working in Ros 6.0rc6

I have a lot of connection in/out my box while connection tracking is turn on. but I can not see them in /ip firewall connections. Below is my screenshot. I am using ROS 6.0rc6.
winbox.png
by mknnoc
Wed Jan 09, 2013 3:47 am
Forum: General
Topic: Strange IRQ output in ROS6.0rc6
Replies: 2
Views: 872

Re: Strange IRQ output in ROS6.0rc6

Any input ?
by mknnoc
Tue Jan 08, 2013 10:20 am
Forum: General
Topic: Strange IRQ output in ROS6.0rc6
Replies: 2
Views: 872

Strange IRQ output in ROS6.0rc6

I got 4 physical Gigabit Ethernet port on my server while IRQ display 15 Virtual NICs.
Does it mean one Gigabit Ethernet port can use up to 5 CPU Cores? or is it a bug ?

Below is the screenshot of my winbox.
by mknnoc
Sat Jan 05, 2013 5:01 am
Forum: General
Topic: Anyone put CCR into production yet ?
Replies: 5
Views: 1614

Re: Anyone put CCR into production yet ?

We have dozens of CCR devices in our network, basically all important routers are CCRs and they work great. I just ordered 4 units of CCR36 for testing. If it works well, we will plan to replace all of our x86 boxes. Each of my x86 box supports upto 800Mbps with 400 VLANs, 980 address-list, 250 Man...
by mknnoc
Thu Jan 03, 2013 6:48 am
Forum: General
Topic: Anyone put CCR into production yet ?
Replies: 5
Views: 1614

Anyone put CCR into production yet ?

Anyone put CCR into production yet ? How is the stability and real performance ? buggy ?
by mknnoc
Mon Dec 31, 2012 12:29 pm
Forum: General
Topic: Priority in Queue Tree, Which queue type to use ?
Replies: 2
Views: 952

Priority in Queue Tree, Which queue type to use ?

Should I change Queue Type of Parent Queue from PFIFO to SFQ when I do Priority in Child Queue? or I must do that ?
by mknnoc
Sat Dec 22, 2012 4:45 am
Forum: Wireless Networking
Topic: Which AP is best for Iphone 5?
Replies: 5
Views: 1782

Re: Which AP is best for Iphone 5?

Yes, 5GHz is the point. What is the recommended model?

or I need to do assembly ( RouterBoard, 5GHz and 2.4GHz cards,pig tails, ANTs, case, power adapter) by myself?
by mknnoc
Fri Dec 21, 2012 11:24 am
Forum: Wireless Networking
Topic: Which AP is best for Iphone 5?
Replies: 5
Views: 1782

Which AP is best for Iphone 5?

Which AP or Routerboard solution is best for IPhone 5?
by mknnoc
Tue Sep 11, 2012 5:50 am
Forum: General
Topic: Installing RouterOS on DELL R720
Replies: 1
Views: 1196

Installing RouterOS on DELL R720

Our current server is reaching its limitation. So, i am trying to get new server which is DELL R720.
I am using Netinstall to install the OS to USB then make server to boot from that USB. and i got below result:
IMG_3634.JPG
then It stuck there :(

What is wrong?
by mknnoc
Thu Jul 12, 2012 10:01 am
Forum: General
Topic: Changing Interface MTU
Replies: 3
Views: 12152

Re: Changing Interface MTU

Thanks, I did try again with extra network card beside the built-in one. It works.
by mknnoc
Wed Jul 11, 2012 11:33 am
Forum: General
Topic: Changing Interface MTU
Replies: 3
Views: 12152

Changing Interface MTU

I am using DELL R210 which has interface supports Jumbo Frame. But when I try to change MTU to above 1500 in ROS. It doesn't allow. Why?
I am using ROS 5.9.

Thanks,
by mknnoc
Sat Mar 31, 2012 4:35 am
Forum: Wireless Networking
Topic: The best way to manager wireless key
Replies: 0
Views: 587

The best way to manager wireless key

In our office, most of the users are using wifi for office work and internet. The key is distributed to all PC manually. Of course, user can show the key and pass to anyone. so, anyone can use our network or internet for free or make the wifi network down or do DHPC spoofing. What are the best pract...
by mknnoc
Thu Jan 19, 2012 5:23 pm
Forum: General
Topic: Can DHCPv6 in Mikrotik passing DNS value to client?
Replies: 6
Views: 1990

Re: Can DHCPv6 in Mikrotik passing DNS value to client?

What version of ROS is expected to support this feature ?
by mknnoc
Wed Jan 18, 2012 8:57 am
Forum: General
Topic: Can DHCPv6 in Mikrotik passing DNS value to client?
Replies: 6
Views: 1990

Can DHCPv6 in Mikrotik passing DNS value to client?

Can DHCPv6 in Mikrotik passing DNS value to client?
by mknnoc
Tue Jan 03, 2012 12:16 pm
Forum: General
Topic: Logging application usage
Replies: 3
Views: 1188

Re: Logging application usage

by mknnoc
Tue Jan 03, 2012 10:30 am
Forum: General
Topic: Needed AP to support 50 concurrent users
Replies: 5
Views: 3451

Re: Needed AP to support 50 concurrent users

So, i would need a RB800 with multiple R2N 802.11b/g/n miniPCI card installed on it and using same SSID?
by mknnoc
Tue Jan 03, 2012 9:36 am
Forum: General
Topic: Needed AP to support 50 concurrent users
Replies: 5
Views: 3451

Re: Needed AP to support 50 concurrent users

:lol: Thanks for feedback

What is the best AP that Mikrotik is having on the road now? how any concurrent users? how many throughput per user?
by mknnoc
Tue Jan 03, 2012 5:22 am
Forum: General
Topic: Needed AP to support 50 concurrent users
Replies: 5
Views: 3451

Needed AP to support 50 concurrent users

Can anyone recommend any Mikrotik AP which can support up to 50 concurrent users with ~50 Mbps per users.
I intend to use this wireless system for office users (replacing cable). Thanks
by mknnoc
Sat Nov 19, 2011 3:53 am
Forum: General
Topic: Adding BGP prefix to address-list
Replies: 3
Views: 1392

Re: Adding BGP prefix to address-list

Actually, my idea is the nearly the same as bogon filter. Thanks to ChangeIP for the link :) I am want to give extra bandwidth to domestic network who is peering with Domestic Internet Exchange. Doing static defining is not good idea which can cause some trouble when peering link was failed and all ...
by mknnoc
Fri Nov 18, 2011 10:23 am
Forum: General
Topic: Adding BGP prefix to address-list
Replies: 3
Views: 1392

Adding BGP prefix to address-list

Dear all,

How can we add BGP prefixes to address-list?
by mknnoc
Thu Jul 14, 2011 4:10 am
Forum: General
Topic: Unrestricted some IPs in Hotspot
Replies: 2
Views: 817

Re: Unrestricted some IPs in Hotspot

You may disable hotspot limits and create Queues to limit speed of internet connections based on IP of client - it should be the same, if hotspot user is not connected with multiple sessions (if only one session is allowed). Actually, managing client by IP is what we are doing now but we find it di...
by mknnoc
Wed Jul 13, 2011 9:53 am
Forum: General
Topic: Unrestricted some IPs in Hotspot
Replies: 2
Views: 817

Unrestricted some IPs in Hotspot

Is it possible to unrestricted some ip in Hotspot? If can, how do we do that :D ?

Example: User is able to access to local file server at wire speed while he is limited to internet at 256kbps.
by mknnoc
Mon May 09, 2011 10:07 am
Forum: General
Topic: how test performance of new router?
Replies: 2
Views: 805

Re: how test performance of new router?

I would like test as below:

1. Throughput per Mbps
2. Number of interface VLAN
3. Number of PPPoE
by mknnoc
Sat May 07, 2011 6:38 am
Forum: General
Topic: how test performance of new router?
Replies: 2
Views: 805

how test performance of new router?

I am installing a new router running on ROS v5.2 and DELL R300 (Multicore=Yes).
I want to test the performance of this router but I am not sure what is the correct way or step to do this test.

Can anyone advise?
by mknnoc
Fri Apr 29, 2011 7:45 pm
Forum: General
Topic: Qos with IPv6
Replies: 3
Views: 1047

Re: Qos with IPv6

From which version of ROS?
by mknnoc
Fri Apr 29, 2011 6:54 am
Forum: General
Topic: Windows 7 can not get ipv6 DNS via RA
Replies: 3
Views: 2949

Re: Windows 7 can not get ipv6 DNS via RA

Does Mikrotik have DHCPv6 feature?
by mknnoc
Fri Apr 29, 2011 6:52 am
Forum: General
Topic: Qos with IPv6
Replies: 3
Views: 1047

Qos with IPv6

Does Mikrotik ROS support Qos with IPv6?
by mknnoc
Wed Apr 27, 2011 7:17 am
Forum: General
Topic: Windows 7 can not get ipv6 DNS via RA
Replies: 3
Views: 2949

Windows 7 can not get ipv6 DNS via RA

I am trying to test ipv6 in my network. my PC (Windows 7)can get ipv6 prefix from the route but can not get ipv6 dns via RA.
I did try to set M and O flag but it is still not work. Below is the ICMPv6 RA package capture. How to fix this problem?
ipv6_ra_wireshark.png
by mknnoc
Mon Apr 11, 2011 9:54 am
Forum: General
Topic: Cannot load webfig
Replies: 4
Views: 1801

Cannot load webfig

When i try to open webfig, it keeps saying "Loading...." forever.
my ROS version is 5.1. What is it wrong?
by mknnoc
Sat Feb 26, 2011 5:29 am
Forum: General
Topic: Activate firewall rule on specific time
Replies: 1
Views: 1162

Activate firewall rule on specific time

Hi, I am finding how to activate firewall rule base on a specific time. I run across config as below:
ip firewall extra time.png
Does it mean that I can put start time/send time and select specific date? I have tried but it doesn't work.
Can anyone explain what does this field exactly mean?
by mknnoc
Sat Jan 29, 2011 6:48 am
Forum: General
Topic: Unlimited some services or dst-ip after login (hotspot)
Replies: 5
Views: 2481

Re: Unlimited some services or dst-ip after login (hotspot)

Excellent, It worked!! Many thanks Another question: If i mangled the exempt traffic on prerouting(upload) and postrouting(download) and i did not configure Queue Tree to set the limit. 1. Why the exampt traffic is still captured by Simple Queue (hotspot limit) 2. Why do I need to use SFQ Queue type?
by mknnoc
Sat Jan 22, 2011 5:59 pm
Forum: General
Topic: Unlimited some services or dst-ip after login (hotspot)
Replies: 5
Views: 2481

Unlimited some services or dst-ip after login (hotspot)

Is there a way to unlimited some services or IP after user login to hotpsot?
Unlimited means not count the bandwidth usage, unlimited speed.

Thanks,
by mknnoc
Mon Dec 06, 2010 3:17 am
Forum: General
Topic: Using IPv6 in LAN and NAT to IPv4 to global, is it possible?
Replies: 5
Views: 4042

Re: Using IPv6 in LAN and NAT to IPv4 to global, is it possi

Thanks all for reply.

Actually, I just want to implement in my office and let everyone feel about IPv6.
So, it would be easy to migrate later.

Anyway, thanks again.
by mknnoc
Sat Dec 04, 2010 6:04 am
Forum: General
Topic: Using IPv6 in LAN and NAT to IPv4 to global, is it possible?
Replies: 5
Views: 4042

Using IPv6 in LAN and NAT to IPv4 to global, is it possible?

Using IPv6 in LAN and NAT IPv6 to IPv4 to global, is it possible?
by mknnoc
Mon Nov 29, 2010 8:30 am
Forum: Scripting
Topic: show ip route x.x.x.x
Replies: 11
Views: 39991

Re: show ip route x.x.x.x

I am using ROS4.13 but it doesn't work for me as below:
ip_route_print.png
by mknnoc
Mon Nov 29, 2010 5:07 am
Forum: Scripting
Topic: show ip route x.x.x.x
Replies: 11
Views: 39991

Re: show ip route x.x.x.x

Yes, it is correct that "ip route print where dst=x.x.x.x" can not look up for supernet.
Is there any way to work around to find supernet or exit interface?
by mknnoc
Sat Nov 27, 2010 4:44 am
Forum: Scripting
Topic: show ip route x.x.x.x
Replies: 11
Views: 39991

show ip route x.x.x.x

Is it possible to do "show ip route x.x.x.x"?
by mknnoc
Tue Nov 16, 2010 11:08 am
Forum: General
Topic: a lot of UDP connection are undefined
Replies: 4
Views: 1546

Re: a lot of UDP connection are undefined

It is also possible to select no-mark at queue-tree. if i shape the packet with no-mark, will it work?
by mknnoc
Tue Nov 16, 2010 8:05 am
Forum: General
Topic: slow network today
Replies: 3
Views: 1338

Re: slow network today

you can connect the internet connection directly to you PC and test speed. if we can get full speed 2Mbps, the router/configuration has problem otherwise the internet speed is not enough.
by mknnoc
Tue Nov 16, 2010 7:05 am
Forum: General
Topic: a lot of UDP connection are undefined
Replies: 4
Views: 1546

a lot of UDP connection are undefined

I am using RouterOS 4.x. Currently, i do mangle most of the connection at forward chain. Undefined connection will be captured by no-mark by default. But i still see some connection have wild connection without marking as below attachment file. Why?
no-mark-udp.png
by mknnoc
Wed Nov 10, 2010 7:06 am
Forum: General
Topic: What is connection-limit and limit mean?
Replies: 1
Views: 2319

What is connection-limit and limit mean?

ip_firewall_filter_extra.png
I got it from http://wiki.mikrotik.com/wiki/How_to_au ... MTP_output

But i am not sure that does this property mean. Can anyone explain?
by mknnoc
Sat Oct 16, 2010 8:06 am
Forum: General
Topic: mark-connection+ mark-packet or mark-packet only
Replies: 14
Views: 8186

Re: mark-connection+ mark-packet or mark-packet only

Thanks for the link. It look simple to do but It make me confuse now :( Anyway, Can we go more detail about the mangle and shaping? Based on IP flow below: QoS_Packet_Flow.gif Both upload and download traffic will pass through 1. Mangle at Prerouting and shaping at Global-in or 2. Mangle at Postrout...
by mknnoc
Fri Oct 15, 2010 7:59 am
Forum: General
Topic: mark-connection+ mark-packet or mark-packet only
Replies: 14
Views: 8186

Re: mark-connection+ mark-packet or mark-packet only

Thanks for confirmation. If we do as below: /ip firewall mangle add chain=postrouting src-addrss=1.1.1.1 new-connection-mark=conn-mark connection-mark=no-mark /ip firewall mangle add chain=postrouting connection-mark=conn-mark new-packet-mark=pck-mark /queue tree add name=shaping parent=global-out p...
by mknnoc
Thu Oct 14, 2010 7:05 pm
Forum: General
Topic: mark-connection+ mark-packet or mark-packet only
Replies: 14
Views: 8186

Re: mark-connection+ mark-packet or mark-packet only

if so, download and upload traffic need to mark one time only?

example: /ip firewall mangle add chain=forward src-address=1.1.1.1 new-connection-mark=conn-mark?

conn-mark will caught both download and upload of 1.1.1.1.

Does it work for all protocol like TCP, UDP, ICMP, etc?
by mknnoc
Thu Oct 14, 2010 1:28 pm
Forum: General
Topic: mark-connection+ mark-packet or mark-packet only
Replies: 14
Views: 8186

Re: mark-connection+ mark-packet or mark-packet only

Is connection-mark is unidirectional or bi-directional? example: /ip firewall mangle add chain=forward src-address=1.1.1.1 new-connection-mark=conn-mark if 1.1.1.1 downloads a file from outside, the download connection(outside -> 1.1.1.1) is mark as conn-mark. if 1.1.1.1 ping to outside, the icmp-re...
by mknnoc
Thu Oct 14, 2010 11:09 am
Forum: General
Topic: mark-connection+ mark-packet or mark-packet only
Replies: 14
Views: 8186

mark-connection+ mark-packet or mark-packet only

Dear guru, 1. can anyone explain when we should use mark-connection + mark-packet and mark-packet only? Is there any performance different between the two method? Note: All of the marking will use to do shaping with Queue tree or Simple Queue. 2. Another thing, if we do shaping with mangle + simple ...
by mknnoc
Wed Oct 06, 2010 9:28 am
Forum: Scripting
Topic: Is it possible to have a catch of command execution?
Replies: 4
Views: 1627

Is it possible to have a catch of command execution?

let say we execute a command "/ip firewall address-list add list=abc address=1.0.0.1" from a script.
if this execution failed, the script will :put "Failed" else :put "Success".

Is it possible to catch ?
by mknnoc
Mon Oct 04, 2010 11:57 am
Forum: Scripting
Topic: Is it possible to write a funcation + Arg in mikrotik ?
Replies: 2
Views: 2097

Is it possible to write a funcation + Arg in mikrotik ?

Is it possible to write a funcation + Arg in Mikrotik scripting?
if yes, please show me a very simple example.

Thanks,
by mknnoc
Thu Jul 29, 2010 12:59 pm
Forum: The User Manager
Topic: Split user under different customer
Replies: 2
Views: 1711

Split user under different customer

Hi, let say userA is create under customerA and userB is created under customerB. customerA and customerB has different access network(physically). All these users and customers are created under a User Manager. Is possible to limit userA to access only in customerA network and userB can access only...
by mknnoc
Thu Jun 10, 2010 11:50 am
Forum: General
Topic: Exclude some side from hotspot limitation
Replies: 4
Views: 1244

Re: Exclude some side from hotspot limitation

Is it possible to do it? Pls help to light up
by mknnoc
Thu Jun 10, 2010 9:44 am
Forum: General
Topic: Exclude some side from hotspot limitation
Replies: 4
Views: 1244

Re: Exclude some side from hotspot limitation

can u talk more detail about the option 1 and 2?
by mknnoc
Thu Jun 10, 2010 8:55 am
Forum: General
Topic: Exclude some side from hotspot limitation
Replies: 4
Views: 1244

Exclude some side from hotspot limitation

Hi,

Is it possible to exclude some side from hotspot rate limit?
ex: user A can get 512kbps to access internet and he can get 100Mbps to local web servers.

I am using User Manager to manager user account.

Rgds,
by mknnoc
Mon May 24, 2010 8:52 am
Forum: General
Topic: Does Mikrotik still run without Flash?
Replies: 6
Views: 1279

Re: Does Mikrotik still run without Flash?

So, It work if we don't reboot it?

I think flash may not be broken after unplug.
by mknnoc
Mon May 24, 2010 8:26 am
Forum: General
Topic: Does Mikrotik still run without Flash?
Replies: 6
Views: 1279

Does Mikrotik still run without Flash?

Let say we use netinstall to install ROS on flash. Then we let the server to boot from flash.
After booting successful, we take out the flash. Does the Mikrotik router still run?
by mknnoc
Mon Jan 04, 2010 6:04 am
Forum: Scripting
Topic: running script with parameters at run time
Replies: 1
Views: 3646

running script with parameters at run time

Is it possible to run a script with parameters at run time?

example: add_customer <customer_vlan> <cusotmer_ip> <address_list>

So, API application just calls it to use at run time.

Thanks,
by mknnoc
Tue Dec 08, 2009 4:34 am
Forum: General
Topic: Weird! address-list and mangle
Replies: 6
Views: 1415

Re: Weird! address-list and mangle

So, I will need to write another mangle at pre-routing (meaning overwrite mangle at forward) and do shaping. How about customer changing the speed multiple time? connection-mark at prerouting won help? Is it possible to write script to clear connection-mark at connection tracking? example: >clear_co...
by mknnoc
Mon Dec 07, 2009 12:28 pm
Forum: General
Topic: Weird! address-list and mangle
Replies: 6
Views: 1415

Re: Weird! address-list and mangle

you create temporary rules to remark previously marked active connections
Can you point me more detail?
by mknnoc
Mon Dec 07, 2009 9:00 am
Forum: General
Topic: Weird! address-list and mangle
Replies: 6
Views: 1415

Re: Weird! address-list and mangle

So, what should i do? Change from Connection-Mark to Packet-Mark?
by mknnoc
Sat Dec 05, 2009 12:23 pm
Forum: General
Topic: Loop-Back IP Configuration in Mikrotik
Replies: 4
Views: 11001

Re: Loop-Back IP Configuration in Mikrotik

sorry, i mean loopback.
by mknnoc
Sat Dec 05, 2009 12:22 pm
Forum: General
Topic: Loop-Back IP Configuration in Mikrotik
Replies: 4
Views: 11001

Re: Loop-Back IP Configuration in Mikrotik

bridge interface is localback interface.
by mknnoc
Sat Dec 05, 2009 8:10 am
Forum: General
Topic: Weird! address-list and mangle
Replies: 6
Views: 1415

Weird! address-list and mangle

My configuration is exactly the same as Janis presentation (QoS base practise). So, when i want to change speed for user, i just change address-list name (example: from 10.0.0.1 -> 128k_addr_list to 10.0.0.1 -> 256k_addr_list) then pre-defined mangle and pre-defined Queue tree + PCQ will work accord...
by mknnoc
Tue Nov 10, 2009 10:08 am
Forum: Scripting
Topic: Translate scripting to API
Replies: 12
Views: 2533

Re: Translate scripting to API

I was stuck at .tag or passing the result of one command to another.
A complete example would be very helpful. :(
by mknnoc
Tue Nov 10, 2009 2:48 am
Forum: Scripting
Topic: Translate scripting to API
Replies: 12
Views: 2533

Re: Translate scripting to API

can you translate this "/interface vlan remove [/interface vlan find name=<customer_name>]" to
API? (C# language)
by mknnoc
Mon Nov 09, 2009 4:31 pm
Forum: General
Topic: How to QoS extra IP address with PCQ?
Replies: 6
Views: 1766

Re: How to QoS extra IP address with PCQ?

Thanks for quick response.
by mknnoc
Mon Nov 09, 2009 4:13 pm
Forum: Scripting
Topic: Translate scripting to API
Replies: 12
Views: 2533

Re: Translate scripting to API

can you give out an example without .tag? so, we can execute the commands simultaneously.

please!!
by mknnoc
Mon Nov 09, 2009 4:59 am
Forum: General
Topic: How to QoS extra IP address with PCQ?
Replies: 6
Views: 1766

Re: How to QoS extra IP address with PCQ?

Thanks for the links.

Let say PCQ's Limit-At is 512k. That means every single IP will get 512k ( best case scenario).
Can we limit a group of IPs under one PCQ substream? so, they will get 512k to share each other.

Hope, my question is clear.
by mknnoc
Mon Nov 09, 2009 4:41 am
Forum: Scripting
Topic: Translate scripting to API
Replies: 12
Views: 2533

Re: Translate scripting to API

I am not sure about this .tag.

how to take it? So, i will get only the .id value that is easy for to pass to another command.
by mknnoc
Sat Nov 07, 2009 5:20 pm
Forum: Scripting
Topic: Translate scripting to API
Replies: 12
Views: 2533

Re: Translate scripting to API

The return result is not only the .id values but also has other value(.tag...) which i will need to do string manipulation in order to get only the .id value, right?
by mknnoc
Sat Nov 07, 2009 4:56 am
Forum: Scripting
Topic: API - ACL Control
Replies: 37
Views: 21463

Re: API - ACL Control

can you please write the complete code?
by mknnoc
Sat Nov 07, 2009 3:52 am
Forum: Scripting
Topic: Translate scripting to API
Replies: 12
Views: 2533

Translate scripting to API

how to write "/interface vlan remove [/interface vlan find name=<customer_name>]" to API language?
by mknnoc
Thu Nov 05, 2009 12:32 pm
Forum: General
Topic: How to QoS extra IP address with PCQ?
Replies: 6
Views: 1766

Re: How to QoS extra IP address with PCQ?

Hope, you visited Cambodia (Angkor Wat) before 8) Anyway, PCQ is very very helpful in order to manage bandwidth distribution (one rule will catch all) and THANKS to Mikrotik team for their hard working both technologies (PCQ, HTB,...) and documentations :D To my situation, what I did was to write fo...
by mknnoc
Thu Nov 05, 2009 9:44 am
Forum: General
Topic: How to QoS extra IP address with PCQ?
Replies: 6
Views: 1766

How to QoS extra IP address with PCQ?

I have followed Mikrotik QoS Best Practice by Janis. Everything is working perfectly:D What i did was to give one customer one vlan and give one IP for each customers. So, i just do mangle the IP address (address-list with predefined mangle rule) and it will be limit by PCQ. Until customer start req...
by mknnoc
Thu Nov 05, 2009 3:42 am
Forum: General
Topic: RouterOS License and v4 questions
Replies: 115
Views: 57633

Re: RouterOS License and v4 questions

How about new user manager? I can not find it on the ROS v4.
by mknnoc
Thu Aug 20, 2009 7:00 am
Forum: General
Topic: MikroTik User Meeting USA, Indonesia, Brazil and Argentina!
Replies: 16
Views: 6544

Re: MikroTik User Meeting USA, Indonesia, Brazil and Argentina!

I saw training before MUM in Indonesia. Does the class speak English or Indonesian language?
I am not Indonesian. :(
by mknnoc
Fri Jul 31, 2009 5:58 am
Forum: General
Topic: Any special sale package for internet user?
Replies: 0
Views: 577

Any special sale package for internet user?

I am thinking of offering special package to my internet user by using Mikrotik solution.
currently, i am using Mik as Bandwidth management. My current package is as below:

1. Exclusive package -> 1:4
1. Corporate package -> 1:1

please share your strategy.
by mknnoc
Wed Jun 03, 2009 6:44 pm
Forum: General
Topic: Does web caching really improve internet quality?
Replies: 3
Views: 1229

Re: Does web caching really improve internet quality?

is it mikrotik proxy or external proxy?
by mknnoc
Tue Jun 02, 2009 10:06 am
Forum: General
Topic: Does web caching really improve internet quality?
Replies: 3
Views: 1229

Does web caching really improve internet quality?

Does web caching really improve internet quality (web surfing)?
How long does it need for web caching to show real improvement?

I have tried some time to test web proxy but customers always complained.
by mknnoc
Mon May 18, 2009 8:13 am
Forum: General
Topic: Howto exclude data transfer counting from internal servers ?
Replies: 2
Views: 1387

Howto exclude data transfer counting from internal servers ?

i have a network as below: diagram.png The network will be splitted into 4 segments; LAN-1, LAN-2, LAN-3 and Servers. Each routers will function as hotspot gateway to control each users internet usuage. all routers will use M-RT User Manager for hotspot AAA. Each users will need to access to Servers...
by mknnoc
Mon May 18, 2009 7:36 am
Forum: General
Topic: how to block file bigger then 5MB from downloading?
Replies: 9
Views: 2195

Re: how to block file bigger then 5MB from downloading?

we actually can forward to external proxy like squid to do the filter base on reply_body_max_size directive. example: reply_body_max_size 5000000 allow all.
by mknnoc
Sun May 17, 2009 2:24 pm
Forum: General
Topic: Freeradius: Sending command to Mtk
Replies: 6
Views: 3243

Re: Freeradius: Sending command to Mtk

01:30:46 hotspot,error,info,debug Radius disconnect with no ip provided
try to send disconnect packet with ip of the client. it will work.
by mknnoc
Tue May 12, 2009 8:45 pm
Forum: General
Topic: how to block file bigger then 5MB from downloading?
Replies: 9
Views: 2195

Re: how to block file bigger then 5MB from downloading?

ok, i got it.

So, what i should do is using Simple Queue with Bursting by setting Burst time,burst threshold and burst max. but what should the value be? Example: burst max limit > max limit?

How about hotspot user? What should i do to apply the same policy?
by mknnoc
Tue May 12, 2009 1:21 pm
Forum: General
Topic: how to block file bigger then 5MB from downloading?
Replies: 9
Views: 2195

Re: how to block file bigger then 5MB from downloading?

how about 'connection-bytes' in firewall? can it help?
by mknnoc
Tue May 12, 2009 1:08 pm
Forum: General
Topic: how to block file bigger then 5MB from downloading?
Replies: 9
Views: 2195

Re: how to block file bigger then 5MB from downloading?

is it in the process of downloading or already downloaded?
by mknnoc
Tue May 12, 2009 1:04 pm
Forum: General
Topic: how to block file bigger then 5MB from downloading?
Replies: 9
Views: 2195

Re: how to block file bigger then 5MB from downloading?

how about HTTP proxy?
by mknnoc
Tue May 12, 2009 11:52 am
Forum: General
Topic: how to block file bigger then 5MB from downloading?
Replies: 9
Views: 2195

how to block file bigger then 5MB from downloading?

how to block file bigger then 5MB from downloading?
by mknnoc
Mon May 11, 2009 11:33 am
Forum: Scripting
Topic: How to schedule a script to run only on Saturday and Sunday
Replies: 2
Views: 1428

How to schedule a script to run only on Saturday and Sunday

How to schedule a script to run only on Saturday and Sunday?
by mknnoc
Tue Apr 21, 2009 10:58 am
Forum: General
Topic: The Next MUM
Replies: 11
Views: 2020

Re: The Next MUM

any plan for Asia country?
by mknnoc
Mon Apr 20, 2009 1:20 pm
Forum: General
Topic: When will new user manager release?
Replies: 4
Views: 936

Re: When will new user manager release?

thanks!! please let me know when it is available for test.
by mknnoc
Mon Apr 20, 2009 1:09 pm
Forum: General
Topic: When will new user manager release?
Replies: 4
Views: 936

Re: When will new user manager release?

is it available for test in the beta release?
by mknnoc
Mon Apr 20, 2009 1:05 pm
Forum: General
Topic: When will new user manager release?
Replies: 4
Views: 936

When will new user manager release?

When will new user manager release? which version of ROS?
by mknnoc
Fri Apr 17, 2009 7:05 am
Forum: General
Topic: MUM photos and videos
Replies: 19
Views: 8879

Re: MUM photos and videos

I really appreciate the video quality. Great arrangement!!
by mknnoc
Fri Apr 17, 2009 7:02 am
Forum: General
Topic: Bandwidth Restriction for a Pool
Replies: 6
Views: 1728

Re: Bandwidth Restriction for a Pool

so, 4mb will be shared to /29 equally? if has only one user using, he will get 4mb full?
if yes, PCQ is your answer.
by mknnoc
Fri Apr 03, 2009 4:01 am
Forum: General
Topic: Change of Authorization
Replies: 2
Views: 846

Re: Change of Authorization

Mikrotik only supports CAO with Hotspot and POD with PPP.
by mknnoc
Sun Mar 22, 2009 5:35 am
Forum: The User Manager
Topic: UM Users bandwidth different in day n nigh ??
Replies: 8
Views: 3035

Re: UM Users bandwidth different in day n nigh ??

in the mean time, you use script to archieve the idea.
by mknnoc
Wed Mar 18, 2009 1:40 pm
Forum: Scripting
Topic: PPPoE server and UM
Replies: 1
Views: 754

Re: PPPoE server and UM

it is in interim-update.
/ppp aaa set interim-update=xx:xxx:xx
by mknnoc
Wed Mar 18, 2009 4:24 am
Forum: Scripting
Topic: PPPoE server and UM
Replies: 1
Views: 754

PPPoE server and UM

I am writing script to get user statistic like download-used and upload-used.

Question:
- How long will UM get the statistic from PPPoE server?
- What is the interval?
by mknnoc
Tue Mar 17, 2009 12:57 pm
Forum: Scripting
Topic: Get all users from User Manager -- strange output
Replies: 2
Views: 972

Re: Get all users from User Manager -- strange output

Thanks, it worked
by mknnoc
Tue Mar 17, 2009 12:55 pm
Forum: Scripting
Topic: Reset-counters in UM
Replies: 1
Views: 732

Re: Reset-counters in UM

well, it worked now. :lol:
by mknnoc
Tue Mar 17, 2009 12:54 pm
Forum: Scripting
Topic: How to store array in comment field???
Replies: 2
Views: 947

Re: How to store array in comment field???

Thanks, it worked.
by mknnoc
Tue Mar 17, 2009 7:23 am
Forum: Scripting
Topic: Reset-counters in UM
Replies: 1
Views: 732

Reset-counters in UM

i am writing script to reset counters a user in UM.

/tool user-manager user reset-counters $usr

BUT it doesn't work.

any idea?
by mknnoc
Tue Mar 17, 2009 5:25 am
Forum: Scripting
Topic: How to store array in comment field???
Replies: 2
Views: 947

How to store array in comment field???

I want to store some values in comment field of each user in UM.
the plan is:

Input values to array and input array to comment field.
Output comment to array and output array to varialbles.

Is it possible in Mikrotik? if yes, can you me tell to do it?
by mknnoc
Sun Mar 15, 2009 4:30 am
Forum: Scripting
Topic: Get all users from User Manager -- strange output
Replies: 2
Views: 972

Get all users from User Manager -- strange output

I want to get all users from usermanager. Below is the script. [admin@MikroTik] > tool user-manager user print Flags: X - disabled, A - active, I - incomplete 0 subscriber=admin name="abc" password="123" group-name="512k" uptime-used=10m37s download-used=231834 upload-u...
by mknnoc
Mon Mar 09, 2009 10:51 am
Forum: The User Manager
Topic: Changing Users Speeds
Replies: 2
Views: 1508

Re: Changing Users Speeds

can you give a sample script to do that?
by mknnoc
Sun Mar 08, 2009 4:36 pm
Forum: The User Manager
Topic: UM Users bandwidth different in day n nigh ??
Replies: 8
Views: 3035

Re: UM Users bandwidth different in day n nigh ??

Is there update about this feature requested?
by mknnoc
Wed Feb 25, 2009 5:28 pm
Forum: General
Topic: Blocking SIP traffic
Replies: 15
Views: 5696

Re: Blocking SIP traffic

No, it is not done yet. I don't want to provide SIP proxy to the client. Client will connect to the server only for initial connection. After the connection established, client will talk directly to peer by other ports beside 5060 as you know.
by mknnoc
Tue Feb 24, 2009 5:54 pm
Forum: General
Topic: Blocking SIP traffic
Replies: 15
Views: 5696

Re: Blocking SIP traffic

Thanks, that is closer to the solution.

The plan is allowed only SIP traffic. Even though, users is using my SIP service, he can only use SIP traffic to outside. All others protocol will be blocked.
by mknnoc
Tue Feb 24, 2009 3:32 pm
Forum: General
Topic: Blocking SIP traffic
Replies: 15
Views: 5696

Re: Blocking SIP traffic

Everyone can connect to the wireless. There won have any key or login page.
BUT customers can only use SIP service that provide by us.
Other services like http, smtp,skype,... will be blocked.
by mknnoc
Tue Feb 24, 2009 3:56 am
Forum: General
Topic: Blocking SIP traffic
Replies: 15
Views: 5696

Re: Blocking SIP traffic

If the SIP account gets verified Then add the IP address of the user to a an address list and set the firewall rules to accept traffic destined to those devices when the session is established. You can do that from your firewall rules. please post the sample configuration! you can use l7 and drop t...
by mknnoc
Mon Feb 23, 2009 5:31 pm
Forum: General
Topic: Blocking SIP traffic
Replies: 15
Views: 5696

Re: Blocking SIP traffic

Detail please!!
by mknnoc
Mon Feb 23, 2009 5:06 pm
Forum: General
Topic: Blocking SIP traffic
Replies: 15
Views: 5696

Re: Blocking SIP traffic

SIP client uses 5060 to talk to the SIP servers. and it will use other ports to talk with other SIP client after connection established. if other ports are blocked, SIP won work.
by mknnoc
Mon Feb 23, 2009 10:31 am
Forum: General
Topic: Blocking SIP traffic
Replies: 15
Views: 5696

Blocking SIP traffic

Hi,

i want to set up a free wireless hotspot network for my VoIP customers to make a VoIP call.
but i want to allow only those customers who are using my SIP servers. and they can only use VoIP only. all other traffics like http, http, skype,... will be blocked.

any suggestion about firewall rules?
by mknnoc
Tue Feb 17, 2009 9:29 am
Forum: General
Topic: bgp question
Replies: 2
Views: 994

Re: bgp question

if i use default-originate=always or if-installed, do i need to filter (to give out only 0.0.0.0/0)on BGP out to the peer?
by mknnoc
Mon Feb 16, 2009 8:09 pm
Forum: General
Topic: Traffic shaper
Replies: 17
Views: 6227

Re: Traffic shaper

please write wiki!!! that would be great help..
by mknnoc
Thu Feb 12, 2009 4:03 am
Forum: General
Topic: identify packets marked by another MT, is it possible?
Replies: 3
Views: 1264

Re: identify packets marked by another MT, is it possible?

you can use DSCP(TOS).
by mknnoc
Thu Feb 12, 2009 3:45 am
Forum: General
Topic: cacti: Mikrotik RouterOS Statistics (Update 11/19/2013)
Replies: 85
Views: 81991

Re: cacti: Mikrotik RouterOS Statistics (Update 01/18/2008)

mojiro, i mean can we monitor on queue child of the queue tree both by packet and traffic(Byte)?
by mknnoc
Thu Feb 12, 2009 3:39 am
Forum: General
Topic: web proxy debug???
Replies: 17
Views: 6382

Re: web proxy debug???

why don't you test out? and report the result.
by mknnoc
Wed Feb 11, 2009 6:50 pm
Forum: General
Topic: Proxylizer Proxy log analysis for RouterOS Web Proxy
Replies: 7
Views: 5834

Re: Proxylizer Proxy log analysis for RouterOS Web Proxy

I finished the installation already. i can access to th web page, connect to database,..
I also configure my web proxy to point to syslog-ng server.

but i cannot see any log in status page of proxylizer.

what should be wrong with my configuration?
by mknnoc
Wed Feb 11, 2009 6:05 pm
Forum: General
Topic: BGP routing - how can I manually weight a route?
Replies: 4
Views: 1526

Re: BGP routing - how can I manually weight a route?

You also need to think about both inbound and outbound traffic.
by mknnoc
Wed Feb 11, 2009 5:53 pm
Forum: Forwarding Protocols
Topic: MPLS/VPLS testing
Replies: 14
Views: 8897

Re: MPLS/VPLS testing

how long do you need? i have 7200 only
by mknnoc
Wed Feb 11, 2009 12:34 pm
Forum: General
Topic: web proxy debug???
Replies: 17
Views: 6382

Re: web proxy debug???

Try to put dstnat before srcnat. Just put dstnat in the first row.
by mknnoc
Wed Feb 11, 2009 12:11 pm
Forum: General
Topic: Proxylizer Proxy log analysis for RouterOS Web Proxy
Replies: 7
Views: 5834

Re: Proxylizer Proxy log analysis for RouterOS Web Proxy

I can install it. see below:
syslog-ng.png
by mknnoc
Wed Feb 11, 2009 8:57 am
Forum: General
Topic: cacti: Mikrotik RouterOS Statistics (Update 11/19/2013)
Replies: 85
Views: 81991

Re: cacti: Mikrotik RouterOS Statistics (Update 01/18/2008)

That is real great job. thanks for that!! Anyway, i have some question regarding Queue Tree. On winbox, i see my traffic is hitting 20M while Cacti report about 2m only. :( please see below: total-download-cacti.png total-download.png what is wrong here? By the way, can we monitor each queue tree le...
by mknnoc
Sun Feb 01, 2009 4:17 am
Forum: General
Topic: Active/Passive Hardware Clustering Mikrotik ROS
Replies: 6
Views: 2992

Re: Active/Passive Hardware Clustering Mikrotik ROS

At customer side, they can only access to the VLAN that was assigned (access port).
All the access layer switches are secured by ACL, password, security guard and finger print 8) (Remote and Direct Access).
by mknnoc
Sat Jan 31, 2009 11:24 am
Forum: General
Topic: Active/Passive Hardware Clustering Mikrotik ROS
Replies: 6
Views: 2992

Re: Active/Passive Hardware Clustering Mikrotik ROS

Why VLAN: 1. easy local loop (2L,3L, MPLS) 2. lease line service (transit, corperate customer) 3. graphing (interface VLAN), customer self-care 4. no need PPPoE supported device which is less overhead 5. CPE managed by VLAN (1CPE=1VLAN) Why not PPPoE, because it doesn't have what VLAN has. :D
by mknnoc
Fri Jan 30, 2009 5:12 pm
Forum: General
Topic: Service Selection Gateway(SSG)
Replies: 0
Views: 719

Service Selection Gateway(SSG)

Does Mikrotik BRAS support SSG like Cisco SSG?
by mknnoc
Fri Jan 30, 2009 1:16 pm
Forum: General
Topic: Active/Passive Hardware Clustering Mikrotik ROS
Replies: 6
Views: 2992

Re: Active/Passive Hardware Clustering Mikrotik ROS

VRRP is good for a single gateway.

In my case, i create one vlan for one customer. so, if i have 1000 customers, i will create 1000 VLAN.

it is really hard work to do with VRRP.
by mknnoc
Thu Jan 29, 2009 4:31 pm
Forum: General
Topic: Mikrotik 3.x on a rack mount server
Replies: 2
Views: 1047

Re: Mikrotik 3.x on a rack mount server

HP DL360 G5p (SATA HDD) worked perfectly.
by mknnoc
Thu Jan 29, 2009 4:10 pm
Forum: General
Topic: VOIP & QOS
Replies: 16
Views: 13944

Re: VOIP & QOS

connection-type cannot work. it can caught any SIP or H323.
any idea??
by mknnoc
Tue Jan 27, 2009 7:17 am
Forum: General
Topic: VOIP & QOS
Replies: 16
Views: 13944

Re: VOIP & QOS

i have created the rule as below: chain=prerouting action=passthrough connection-type=sip chain=prerouting action=passthrough connection-type=h323 but i don't see any bytes or packets counter increased. and i am sure that there are a lot of SIP/H323 traffic are forwarded by my router. any idea? any...
by mknnoc
Mon Jan 26, 2009 6:13 pm
Forum: General
Topic: VOIP & QOS
Replies: 16
Views: 13944

Re: VOIP & QOS

i have created the rule as below: chain=prerouting action=passthrough connection-type=sip chain=prerouting action=passthrough connection-type=h323 but i don't see any bytes or packets counter increased. and i am sure that there are a lot of SIP/H323 traffic are forwarded by my router. any idea? PS: ...
by mknnoc
Fri Jan 23, 2009 6:33 am
Forum: General
Topic: iBGP and eBGP
Replies: 3
Views: 6334

Re: iBGP and eBGP

what is your bandwidth for both transits?
by mknnoc
Fri Jan 23, 2009 4:03 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

if i use private IP, it would be NAT problem. but why public IP also has problem?
by mknnoc
Thu Jan 22, 2009 12:04 pm
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

cont.

on the cisco, it was simple routing configuration only.
by mknnoc
Thu Jan 22, 2009 11:53 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

NetworkPro, many thanks for your support. Really appreciate that!!! My customer is using Cisco Router that is impossible me for to down again and interrupt him for test again. by the way, can i know you email address? will drop you an email if i have change to test with that customer again. my purpo...
by mknnoc
Thu Jan 22, 2009 11:21 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

From what i wonder is that if i change to other router like Cisco Router, the connection works well. so, i think it should have some wrong with the mikrotik router.
by mknnoc
Thu Jan 22, 2009 5:10 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

Inside the equipment itself, voip device, has some tools that can test the connection from client side to server. the testing reported success all steps. but when the client try to connect and get service, the client report Error connection. that error reports that the connection was filtered by fir...
by mknnoc
Wed Jan 21, 2009 4:37 pm
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

That could be!

but i tried with public IP, it doesn't work also. :?
by mknnoc
Wed Jan 21, 2009 12:53 pm
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

pls see below: [badmin@MKN-BM-2] /ip firewall filter> print Flags: X - disabled, I - invalid, D - dynamic 0 ;;; basic firewall chain=input action=accept connection-state=established 1 chain=input action=accept connection-state=related 2 chain=input action=drop connection-state=invalid 3 chain=forwar...
by mknnoc
Wed Jan 21, 2009 11:36 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

you can tell me what do you want to see? i will post it on the forum. so, it is easier to read.
by mknnoc
Wed Jan 21, 2009 11:15 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

no, it works as router and shaping only
by mknnoc
Wed Jan 21, 2009 9:23 am
Forum: General
Topic: Active/Passive Hardware Clustering Mikrotik ROS
Replies: 6
Views: 2992

Active/Passive Hardware Clustering Mikrotik ROS

Does anyone ever do hardware cluster to insure HA for Mikrotik box?
if yes, can you share how you do it ? :D
by mknnoc
Wed Jan 21, 2009 5:38 am
Forum: General
Topic: How to using Serial0 interface on Mikrotik
Replies: 6
Views: 2164

Re: How to using Serial0 interface on Mikrotik

great job
by mknnoc
Wed Jan 21, 2009 3:58 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

Re: VoIP Passthrough Problem with Mikrotik ROS

My customer is using www.vonage.com product.
by mknnoc
Tue Jan 20, 2009 11:03 am
Forum: General
Topic: VoIP Passthrough Problem with Mikrotik ROS
Replies: 30
Views: 11029

VoIP Passthrough Problem with Mikrotik ROS

I am having problem with VoIP passthrough Mikrotik Router. the phone cannot register to the server. there is not firewall filter. i have tried with: 1. private ip 2. public ip 3. disable H323 4. disable SIP 5. disable H323 and SIP. but it doesn't help. if i change to router like Cisco, it can work w...
by mknnoc
Mon Jan 19, 2009 1:28 pm
Forum: General
Topic: how 3.19 update to 3.17??
Replies: 4
Views: 1364

Re: how 3.19 update to 3.17??

old package cannot be found on mikrotik.com now, isn't it?
by mknnoc
Thu Jan 15, 2009 6:55 am
Forum: General
Topic: How to using Serial0 interface on Mikrotik
Replies: 6
Views: 2164

Re: How to using Serial0 interface on Mikrotik

perfect!!

it worked now.
by mknnoc
Thu Jan 15, 2009 6:45 am
Forum: General
Topic: How to using Serial0 interface on Mikrotik
Replies: 6
Views: 2164

Re: How to using Serial0 interface on Mikrotik

is it possible to do on x86?

on my x86 machine, i have one serial which serail0. then i try serail0 connection to cisco router.
then i use /system serail-terminal serail0, but the device is busy. why?
by mknnoc
Thu Jan 15, 2009 6:19 am
Forum: General
Topic: How to using Serial0 interface on Mikrotik
Replies: 6
Views: 2164

How to using Serial0 interface on Mikrotik

i want to connection some device like Cisco router to Mikrotik serial. so, i can remote to mikrotik and console to cisco via console cable.

does anyone how know to do that?
by mknnoc
Tue Jan 13, 2009 7:38 am
Forum: General
Topic: Bridge & Traffic Shaping
Replies: 5
Views: 1805

Re: Bridge & Traffic Shaping

you can try L7 protocol.
by mknnoc
Sun Jan 11, 2009 2:07 pm
Forum: General
Topic: Bandwidth limiting accross VLAN
Replies: 4
Views: 11560

Re: Bandwidth limiting accross VLAN

you can try with In-Interface and Out-Interface for mangle both connection-mark and parket-mark.
by mknnoc
Thu Jan 08, 2009 5:23 am
Forum: General
Topic: A gift to our best forum users
Replies: 23
Views: 11340

Re: A gift to our best forum users

It is difficult for me to travel to some European countries since they don't have Embassy in my country. i have to go to the third country to get VISA. :(

Hopefully, someone will post those presentation slices(like advance bandwidth control,..) in this forum!!

Thanks,
by mknnoc
Sat Jan 03, 2009 4:09 am
Forum: General
Topic: BUG(?) v3.1x - Prerouting chain (mangle) freezes router.
Replies: 8
Views: 3372

Re: BUG(?) v3.1x - Prerouting chain (mangle) freezes router.

I used to have this kind of problem. Receiving only default route from BGP peer will help.
by mknnoc
Sun Dec 21, 2008 6:34 am
Forum: General
Topic: Is it possible by using MPLS or EoIP???
Replies: 2
Views: 1105

Re: Is it possible by using MPLS or EoIP???

Is it possible or not?
by mknnoc
Fri Dec 19, 2008 5:09 am
Forum: General
Topic: Is it possible by using MPLS or EoIP???
Replies: 2
Views: 1105

Is it possible by using MPLS or EoIP???

First, i want to tell that I don't have any experience with MPLS or EoIP yet :lol: . BUT i am looking for the possibility of both technology, so i will ahead to that one without looking around 8) . please take a look at the below diagram: Drawing1.jpg 1. Each customer will have one VLAN (ex. VLAN100...
by mknnoc
Thu Dec 18, 2008 11:47 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

As i know so far, Priority will work only if bandwidth is full(100%). isn't it?
by mknnoc
Thu Dec 18, 2008 9:01 am
Forum: General
Topic: PCQ limit & total limit settings
Replies: 36
Views: 56031

Re: PCQ limit & total limit settings

maybe this new article will give you some insight:
http://wiki.mikrotik.com/wiki/Queue_Size
Queue Size=Unlimited, Is it good for UDP or Voice?
by mknnoc
Wed Dec 17, 2008 11:25 am
Forum: General
Topic: L7 signature source
Replies: 1
Views: 1038

L7 signature source

As everyone know, ROS is able to identify traffic (mark and shape) by using L7 protocol BUT we need to rely on external source (like wiki) for application signature like skype and so on. Sometime, it is difficult to find those signatures or cannot find at all for new application like P2P,... Is ther...
by mknnoc
Wed Dec 17, 2008 5:45 am
Forum: General
Topic: Graphing for HTB (Parent and Child Q)
Replies: 4
Views: 1171

Re: Graphing for HTB (Parent and Child Q)

is it possible in V.4?
by mknnoc
Tue Dec 16, 2008 12:18 pm
Forum: General
Topic: Graphing for HTB (Parent and Child Q)
Replies: 4
Views: 1171

Re: Graphing for HTB (Parent and Child Q)

i think Mikrotik should add this feature to ROS Graphing.
by mknnoc
Tue Dec 16, 2008 10:38 am
Forum: General
Topic: Graphing for HTB (Parent and Child Q)
Replies: 4
Views: 1171

Graphing for HTB (Parent and Child Q)

Is it possible to create graph for HTB (Parent and Child Q) like Simple Queue graphing??
by mknnoc
Sun Dec 14, 2008 3:38 pm
Forum: General
Topic: syn flood simply bypasses the shaper
Replies: 1
Views: 799

Re: syn flood simply bypasses the shaper

try to filter invalid connection in /ip firewall filter
by mknnoc
Fri Dec 12, 2008 12:13 pm
Forum: General
Topic: Mikrotik Customer References
Replies: 7
Views: 1403

Re: Mikrotik Customer References

ok, pls take out company name or web site.
by mknnoc
Fri Dec 12, 2008 11:59 am
Forum: General
Topic: Mikrotik Customer References
Replies: 7
Views: 1403

Re: Mikrotik Customer References

i only need this information:
How many of you are using Mikrotik as Bandwidth Management or Core router??
your company name or web site, total throughput, Server model or RouterBoard, ROS version are appreciated answer.
by mknnoc
Fri Dec 12, 2008 11:55 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

Sorry that make you confuse about my configuration. actually, i have been used queue=pcq-*** for test-user-upload and test-user-download. i pasted wrong config, which is queue=default, to the post. however, i have tested with queue=pcq-***. but customer still can uses over bandwidth if i do HTTP pri...
by mknnoc
Fri Dec 12, 2008 11:06 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

i am waiting for the answer or suggestion. anyone???
by mknnoc
Fri Dec 12, 2008 11:03 am
Forum: General
Topic: Mikrotik Customer References
Replies: 7
Views: 1403

Re: Mikrotik Customer References

Company name, Web site, total throughput, Server model, ROS version are appreciated answer.
i need more detail information.
by mknnoc
Fri Dec 12, 2008 6:05 am
Forum: General
Topic: Core Router Hardware
Replies: 62
Views: 19147

Re: Core Router Hardware

We have typically pre-installed ROS on the flash drives with different system. You also need to make sure that the SATA controller is set to "native" or "legacy" if there is an option. I installed successfully with HP DL320 G5p. the system is running in Quad-core Intel Xeon proc...
by mknnoc
Fri Dec 12, 2008 4:36 am
Forum: General
Topic: Mikrotik Customer References
Replies: 7
Views: 1403

Mikrotik Customer References

Hi there,

How many of you are using Mikrotik as Bandwidth Management or Core router??
Company name, Web site, total throughput, Server model, ROS version are appreciated answer.
by mknnoc
Thu Dec 11, 2008 5:25 pm
Forum: General
Topic: Urgent Help Needed: Can't ping MAP Public IP from Internet
Replies: 9
Views: 1834

Re: Urgent Help Needed: Can't ping MAP Public IP from Internet

you need assign .194 to outside interface also.
by mknnoc
Thu Dec 11, 2008 12:20 pm
Forum: General
Topic: Core Router Hardware
Replies: 62
Views: 19147

Re: Core Router Hardware

Very interesting topic that i am looking for!

i never install ROS on any servers like DELL or HP because most of the time i did it. it cannot recognize the HDD(SATA). so, can anyone let me know what to change to let ROS recognize R200 or PE860 HDD(SATA)?
by mknnoc
Thu Dec 11, 2008 5:23 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

Thanks Samsoft for your suggestion! i will use it for my last resort. :D anyway, here corrected and tested configuration: >ip firewall mangle print 136 ;;; icmp-packet-upload chain=prerouting action=mark-packet new-packet-mark=icmp-packet-upload passthrough=no protocol=icmp in-interface=vlan5-noc 13...
by mknnoc
Wed Dec 10, 2008 11:18 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

Ok, corrected. pls see below: >ip firewall mangle print 136 ;;; icmp-packet-upload chain=prerouting action=mark-packet new-packet-mark=icmp-packet-upload passthrough=no protocol=icmp 137 ;;; icmp-packet-download chain=prerouting action=mark-packet new-packet-mark=icmp-packet-download passthrough=no ...
by mknnoc
Wed Dec 10, 2008 3:57 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

Here we go > ip firewall managle print 136 ;;; icmp-packet-download chain=prerouting action=mark-packet new-packet-mark=icmp-packet-download passthrough=no protocol=icmp 137 ;;; icmp-packet-upload chain=prerouting action=mark-packet new-packet-mark=icmp-packet-upload passthrough=no protocol=icmp in-...
by mknnoc
Tue Dec 09, 2008 12:12 pm
Forum: General
Topic: RouterOS v3.17, v4.0beta1, The Dude v3 released
Replies: 57
Views: 19844

Re: RouterOS v3.17, v4.0beta1, The Dude v3 released

is it possible to change User Manager Logo in ROS4.0?
by mknnoc
Tue Dec 09, 2008 10:15 am
Forum: General
Topic: ROS as DNS Cache
Replies: 1
Views: 906

Re: ROS as DNS Cache

Since you have a lot of users, BIND is preferred.
by mknnoc
Tue Dec 09, 2008 10:00 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

according to http://forum.mikrotik.com/viewtopic.php?f=2&t=27555&st=0&sk=t&sd=a&start=100 as below: here is from janis In my presentation I told that creating priorities seperatly for each client is suicide - there are no hardware that can handle small queue tree for every user (...
by mknnoc
Sat Dec 06, 2008 5:23 pm
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

By doing mangle ICMP with passthrought=NO, we will extra bandwidth to customer (the IP). it should be ok since ICMP will eat a little bandwidth only. How about other protocol which will eat a lot of bandwidth like VoIP, Video Conferencing? i mean those protocol that need be prioritied. Is ROS3.17 re...
by mknnoc
Fri Dec 05, 2008 12:16 pm
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

If i do like that, my customer(the IP) will get extra bandwidth if he uses ICMP or other protocols that i gave priority. i don't think it is the way to go.

please add more!!
by mknnoc
Fri Dec 05, 2008 8:57 am
Forum: General
Topic: 2 gateway vsat and fiber load balancing
Replies: 2
Views: 1260

Re: 2 gateway vsat and fiber load balancing

i think Yahoo or Hotmail has a lot of IP.
by mknnoc
Fri Dec 05, 2008 6:44 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

YES, we can limit the traffic by mark-packet in forward only and do queue in outgoing interface (upload) and incoming interface(download). if i mark traffic type like ICMP or other protocols in prerouting in order to give priority, ICMP will get a good ping result even thought I DID NOT GIVE PRIORIT...
by mknnoc
Thu Dec 04, 2008 9:18 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

Re: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

anyone has any idea?
i have been looking around like Doc and this forum, but i can not find the answer.
by mknnoc
Thu Dec 04, 2008 6:06 am
Forum: General
Topic: How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16
Replies: 33
Views: 13319

How to Mangle, Priority with HTB (Queue Tree) in ROS 3.16

First, thanks for reading! :) pls see my scenario below: 1. I want do limitation to one IP. let say 172.16.31.89. so, i do mangle(connection-mark and packet-mark) in prerouting(upload) and postrouting(download) with Passthrought=NO and then apply it in global-in(upload), global-out(download) in Queu...
by mknnoc
Tue Nov 25, 2008 12:50 pm
Forum: General
Topic: Bandwith Management with Ratio like 1:4 or 1:2
Replies: 0
Views: 854

Bandwith Management with Ratio like 1:4 or 1:2

i have been heart about bandwidth management with Ratio like 1:4 or 1:2. i also do some configuration like be below: The scenario is each customer will have one vlan. i do limit for customer by IP address. i am trying to limit customer 1:2 (1MB share to 2 customer). >ip firewall mangle print chain=f...
by mknnoc
Wed May 07, 2008 9:58 am
Forum: General
Topic: ISP Bandwidth Management
Replies: 4
Views: 2416

Re: ISP Bandwidth Management

can you advise more like sample diagram, configuration tip and trick? :lol:
by mknnoc
Mon May 05, 2008 9:45 am
Forum: General
Topic: Fiail-Over Internet Connection with 2 ISPs
Replies: 2
Views: 1305

Re: Fiail-Over Internet Connection with 2 ISPs

thanks for your reply
by mknnoc
Tue Apr 29, 2008 7:44 am
Forum: General
Topic: Fiail-Over Internet Connection with 2 ISPs
Replies: 2
Views: 1305

Fiail-Over Internet Connection with 2 ISPs

Dear All, Let suppose i have 2 ISPs(2 AS) for fail-over connection. i have one web server in DMZ. that web server using public IP from ISP1. i am worry if ISP1 is down. that public IP putting for my web server can not route through ISP2. :lol: However, LAN users will can use internet because i use V...
by mknnoc
Tue Apr 29, 2008 7:10 am
Forum: General
Topic: ISP Bandwidth Management
Replies: 4
Views: 2416

ISP Bandwidth Management

Hi All, Currently,i have problem with Cisco Router Rate-limit. Basically, the router will drop the packet if the provided bandwidth exceeds. some of my customers who subscribe from 1MB to 4MB, have specified application which does not support if got Request Time Out . I want to change bandwidth mana...
by mknnoc
Fri Apr 18, 2008 7:56 pm
Forum: General
Topic: Limit PPPoE User by Time and Bandwidth Base
Replies: 3
Views: 1592

Re: Limit PPPoE User by Time and Bandwidth Base

thanks guy
by mknnoc
Thu Mar 06, 2008 2:53 am
Forum: General
Topic: Limit PPPoE User by Time and Bandwidth Base
Replies: 3
Views: 1592

Limit PPPoE User by Time and Bandwidth Base

Hi,

Can we limit PPPoE user by Time or total bandwidth usage base? Ex. User A can use only 2 hours. User B can use only 2000MB/month. :D

Regards,
by mknnoc
Wed Mar 05, 2008 5:57 pm
Forum: General
Topic: looking for frequency planning tool
Replies: 2
Views: 1260

Re: looking for frequency planning tool

you can try RadioMobile
by mknnoc
Thu Feb 28, 2008 7:05 am
Forum: General
Topic: Disallow non-authenticated user - Setup PPPoE Server
Replies: 1
Views: 865

Disallow non-authenticated user - Setup PPPoE Server

hi, i just setup a PPPoE server + NAT(mas). Everything works well. :D but i wonder how to disallow non-authenticated user to access internet. because currently, user just obtains the IP from PPPoE server then he can go to internet already without PPPoE connection. :( any one has any idea? regards, m...