Community discussions

MikroTik App

Search found 3689 matches

by Jotne
Tue Mar 01, 2022 2:44 pm
Forum: Wireless Networking
Topic: Is hAP AC a wireless router or an access point?
Replies: 12
Views: 1736

Re: Is hAP AC a wireless router or an access point?

PS. There are different License Level, so not all product can do what other can do.
by Jotne
Tue Mar 01, 2022 11:07 am
Forum: Wireless Networking
Topic: Is hAP AC a wireless router or an access point?
Replies: 12
Views: 1736

Re: Is hAP AC a wireless router or an access point?

This is the beauty of RouterOS. You can use nearly all product in the way you like to use it.
Is hAP AC a wireless router or an access point?
Yes
by Jotne
Tue Mar 01, 2022 11:04 am
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43281

Re: v7.2rc4 is released!

Most home ruter does only have 16MB, so to use multiple partition you need a larger router with at least 32MB
https://wiki.mikrotik.com/wiki/Manual:Partitions
by Jotne
Mon Feb 28, 2022 9:51 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43281

Re: v7.2rc4 is released!

I guess that could not be done to all routers?
by Jotne
Mon Feb 28, 2022 9:46 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43281

Re: v7.2rc4 is released!

I took the JUMP and hit the concrete on the bottom with my head!! WTF Mikrotik!! Erase the routing tables (/routing/table), leaving me with setting about 50 different routing-marks all who are all over the place!!!!! I started the recovery but ran out off breath doing them all and will think hard o...
by Jotne
Mon Feb 28, 2022 8:21 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43281

Re: v7.2rc4 is released!

Then it should show up as testing:
development: error: file not found.
long term: error: file not found.

Now you are tricked to belive that 7.1 is a stable long term version. Yes I do now that it is not, but other may think so.
by Jotne
Mon Feb 28, 2022 12:54 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43281

Re: v7.2rc4 is released!

Both 7.2 rc3 and r4 does shows wrong in long term release
long term: 7.1
stable 7.1.3
testing 7.2 rc4
development: error: file not found.
Strange that 7.1.3 is stable and 7.1 is long term :)
.
long term.jpg
by Jotne
Sun Feb 27, 2022 9:45 pm
Forum: Beginner Basics
Topic: Cant port forward or upnp RB951Ui-2HnD
Replies: 13
Views: 1187

Re: Cant port forward or upnp RB951Ui-2HnD

No public IP, so you have a router in front of you. It only shows your LAN part. So you can not get NAT or uPnP to work in this router. You need to configure router in front of your Mikrotik Router. If this is an ISP, you can not configure it, but you can ask if they can bridge it, so you get a publ...
by Jotne
Sun Feb 27, 2022 9:18 pm
Forum: Beginner Basics
Topic: Cant port forward or upnp RB951Ui-2HnD
Replies: 13
Views: 1187

Re: Cant port forward or upnp RB951Ui-2HnD

/8 i havent touched, everything is default except for enabling poe and mucking about trying to get port forwarding and then upnp working. I have never seen /8 as a default configuration. And as 404Network writes, you should start over. PS and do not QUOTE the full post above you. If you have not se...
by Jotne
Sun Feb 27, 2022 8:12 pm
Forum: Beginner Basics
Topic: Cant port forward or upnp RB951Ui-2HnD
Replies: 13
Views: 1187

Re: Cant port forward or upnp RB951Ui-2HnD

/ip address add address=192.168.88.1/8 interface=ether2 network=192.0.0.0 Innside IP should be set on bridge and not on interface part of a bridge. And do you really need a /8 with 16,777,216 IP address.????? For normal home nett /24 with 256 IP should be more than enough. I do not see any DHCP ser...
by Jotne
Sun Feb 27, 2022 5:59 pm
Forum: Scripting
Topic: if enable interface do something
Replies: 4
Views: 1094

Re: if enable interface do something

You can use Netwatch. Give an IP on the other side. If ip goes away, send email.
by Jotne
Sun Feb 27, 2022 11:31 am
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 19083

Re: Script comparability v6<->v7 problems [SOLVED]

Thanks for the update and explanation rextended :)
Now it work both on 7.x and 6.x
by Jotne
Sat Feb 26, 2022 10:11 pm
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 19083

Re: Script comparability v6<->v7 problems [SOLVED]

@Jonte, which one, and what problem you having? I can offer what see in @rextended's examples below, but can't vouch that's all the V7 issues.
My latest postet script do work on both 6 and 7, but version rextended posted does not work on v7.
by Jotne
Sat Feb 26, 2022 5:59 pm
Forum: General
Topic: My Mikrotik HAP ac Have Small Bytes count on IP Accounting
Replies: 1
Views: 3051

Re: My Mikrotik HAP ac Have Small Bytes count on IP Accounting

Not a direct reply to your question, but IP Accounting is going a way (not included in v7). I have used it in my Splunk MikroTik monotoring. Se link in my signature. So to still get accounting data from each client in v7, I moved over to use Kid Control that gives much of the same information (set u...
by Jotne
Sat Feb 26, 2022 5:41 pm
Forum: Announcements
Topic: Mēris botnet information
Replies: 75
Views: 230099

Re: Mēris botnet information

@wongdi Telnet/SSH/Winbox should never ever be open to the router from outside IP. Seeing your logs that someone tries to connect from public IP tells us that its open. VPN is nearly to one good way to work on remote routers. Make a new post (not this thread). Post your complete config and ask for a...
by Jotne
Sat Feb 26, 2022 5:37 pm
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 19083

Re: Script comparability v6<->v7 problems [SOLVED]

My version do work at both 6 and 7. What do I need to make rextendeds script to work on 7.x?
by Jotne
Sat Feb 26, 2022 12:01 pm
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 19083

Re: Script comparability v6<->v7 problems [SOLVED]

Does not work. Tested in 7.1.2

Pasting this to terminal, does not give anything.
:parse "/export show-sensitive file=test.rsc"
But this works:
[:parse "/export show-sensitive file=test.rsc"]
by Jotne
Sat Feb 26, 2022 12:29 am
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 19083

Re: Script comparability v6<->v7 problems [SOLVED]

Perfect. Did learn some new today, so thank you for the help :) Was just what I needed and have tested the script on various version and works fine. # # Created Jotne 2022 v1.3 # # 1.1 Added "show-sensitive" # 1.3 Fixed v6/v7 compability # # Takes two different backup and send then to emai...
by Jotne
Fri Feb 25, 2022 9:03 pm
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 19083

Backup config to Gmail v1.7 [SOLVED]

Backup script to send config to Gmail account. # # Created Jotne 2024 v1.7 # # 1.7 Fixed new CHR naming (Credit bp0 & baragoon) # 1.6 Fixed script for x86 devicews (Credit rextended) # 1.5 Fixed for router missing serial # 1.4 Added Router OS version # 1.3r Revised by rextended # 1.3 / 1.2 try t...
by Jotne
Fri Feb 25, 2022 1:19 pm
Forum: Scripting
Topic: Confirm reboot in script
Replies: 1
Views: 1031

Re: Confirm reboot in script

Why do you need to reboot every day?
by Jotne
Wed Feb 23, 2022 5:17 pm
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 57958

Re: v7.1.3 is released!

Oh, thank you so much!, its possibe to disable or remove? thanks
Why?
by Jotne
Tue Feb 22, 2022 8:06 pm
Forum: Scripting
Topic: Block IP after 3 time hotspot login failures
Replies: 7
Views: 2983

Re: Block IP after 3 time hotspot login failures

How do you see that a user has 3 times login failure? From the log?
If its from the log, you can modify this script to search for log inn errors:
viewtopic.php?p=743875#p743875
by Jotne
Tue Feb 22, 2022 8:00 pm
Forum: Scripting
Topic: How can I write here from line 1 to 50?
Replies: 6
Views: 1245

Re: How can I write here from line 1 to 50?

From this in OPs post "/system/logging/remove", I do assume he is talking about deleting configuration of logging, not logging entries (that can not be deleted).
by Jotne
Tue Feb 22, 2022 3:44 pm
Forum: Scripting
Topic: How can I write here from line 1 to 50?
Replies: 6
Views: 1245

Re: How can I write here from line 1 to 50?

You can do :for i from=0 to=50 do={ :put $i } But take care!! What you see from /system logging print Flags: X - disabled, I - invalid, * - default # TOPICS ACTION PREFIX 0 X* info memory 1 * error memory 2 * warning memory 3 * critical echo 4 dhcp logserver MikroTik 5 !debug logserver MikroTik !pac...
by Jotne
Tue Feb 22, 2022 11:17 am
Forum: Scripting
Topic: How can I write here from line 1 to 50?
Replies: 6
Views: 1245

Re: How can I write here from line 1 to 50?

What is your goal? Remove all logging config?
by Jotne
Tue Feb 22, 2022 11:15 am
Forum: Scripting
Topic: Block IP after 3 time hotspot login failures
Replies: 7
Views: 2983

Re: Block IP after 3 time hotspot login failures

Are anything added to the access list "hotspot_blacklist"
by Jotne
Mon Feb 21, 2022 10:03 pm
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 57958

Re: v7.1.3 is released!

Try to upgrade to latest 6.x, before you look from Upgrade.
by Jotne
Mon Feb 21, 2022 9:33 pm
Forum: Scripting
Topic: Block IP after 3 time hotspot login failures
Replies: 7
Views: 2983

Re: Block IP after 3 time hotspot login failures

1. Do not quote post above you. There is a big Post Reply button under the post to use to reply. 2. Do use code tags when posting code. </> button above the post. I have cleaned up the script and added code tags to be able to read it. #Hotspot IP to MAC binding# :foreach a in=[/ip firewall address-l...
by Jotne
Mon Feb 21, 2022 3:35 pm
Forum: Beginner Basics
Topic: How do I block unknown devices?
Replies: 15
Views: 3010

Re: How do I block unknown devices?

Blocking all and open certain sites may be a way to go. Many sites do not work with just one IP open, everything is interconnected.
But then the kids just use their cellular network, friends cellular network, neighbor wifi etc.
by Jotne
Mon Feb 21, 2022 12:47 pm
Forum: Beginner Basics
Topic: How do I block unknown devices?
Replies: 15
Views: 3010

Re: How do I block unknown devices?

block thing like facebook.com Can not be done. Same as with torrent etc. As long as you do not have 100% control of the clients (typical a corporate network), you are out of luck. You can try block DNS: Client uses another DNS You try to redirect DNS: Clients uses DoH You try to block IP: Facebook ...
by Jotne
Mon Feb 21, 2022 12:40 pm
Forum: Scripting
Topic: Block IP after 3 time hotspot login failures
Replies: 7
Views: 2983

Re: Block IP after 3 time hotspot login failures

If you can see it in the logs, you can make a script for it.
This is nearly the same as block VPN user not authenticate correctly.
See here:
viewtopic.php?t=148397
by Jotne
Sun Feb 20, 2022 8:18 pm
Forum: Scripting
Topic: Random String
Replies: 4
Views: 3062

Re: Random String

This was an old thread to comment.
To get a random password:
viewtopic.php?t=164114
by Jotne
Sat Feb 19, 2022 10:20 pm
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 40215

Re: v7.1.2 is released!

I'd call it a WinBox feature, not a bug.
Table are far from equal.
Bridge/Host has on my test router 40 entry and only mac

IP/Arp has 7 item and do include IP and MAC

I do like that Cli and WinBox show the same at same place in the same menu structure (MT are far off for the latter).
by Jotne
Thu Feb 17, 2022 12:17 pm
Forum: Scripting
Topic: Help with remove Command
Replies: 2
Views: 1260

Re: Help with remove Command

What is the output of:
:put [/ip firewall connection find where connection-type=sip]
and
:put [/ip firewall connection find where connection-mark=SIP]
If its more than one, you may need to loop trough it.
by Jotne
Thu Feb 17, 2022 12:10 pm
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 40215

Re: v7.1.2 is released!

In 7.2.1 (7.x) you can get Bridge Port for the IP arp list. But this seems to work only in WinBox. Is this a bug, or is it a hidden command to see it in the terminal as well? If its a bug, please fix. If I miss some, please enlighten me :)
.
BridgePort.jpg
by Jotne
Tue Feb 15, 2022 5:27 pm
Forum: Announcements
Topic: v6.49.3 [stable] is released!
Replies: 64
Views: 22138

Re: v6.49.3 [stable] is released!

Or some forgot that it was done :) Just another strange notice. I do always open this page with scripts and announcement: https://forum.mikrotik.com/viewforum.php?f=9 to look for new releases and scripts problem. But this time this page does not show the new 6.49.3 post???? But if you look at this p...
by Jotne
Tue Feb 15, 2022 2:24 pm
Forum: Announcements
Topic: v6.49.3 [stable] is released!
Replies: 64
Views: 22138

Re: v6.49.3 [stable] is released!

If this compile time is true, this is the far longest time between compile date and post date. Longest I did found other than this is the 19 day for 6.42.11.
viewtopic.php?t=143805

:)
by Jotne
Tue Feb 15, 2022 1:31 pm
Forum: Announcements
Topic: v6.49.3 [stable] is released!
Replies: 64
Views: 22138

Re: v6.49.3 [stable] is released!

try again, it should work correctly now
Was 6.49.3 really compiled Des 22 2021?
.
6.49.3.jpg
by Jotne
Mon Feb 14, 2022 8:30 pm
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 40215

Re: v7.1.2 is released!

Ping from where to where? If its over internet you do not have much control.
What do you get when you ping from a device connected to the router, to the router? Did that go up?
by Jotne
Mon Feb 14, 2022 8:22 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

You did not post output of my command above. With that I can see if logs looks like what I expect. I did forget to ask on what platform you do run Splunk. Some of my first information in my first post: Installation 1) On your PC Works on Windows and Linux, but use Linux (clearly the best choice and ...
by Jotne
Fri Feb 11, 2022 3:19 pm
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 40215

Re: v7.1.2 is released!

I do see some strange on a 750Gr3 running 6.49.2 When I select upgrade, it shows 7.1.2 That is ok. But when I select testing, it shows 7.1.1??? Why would some one install 7.1.1 when 7.1.2 on the same train is released? 7.2.rc2 is not shown in any of the channels. Development gives ERROR: file not fo...
by Jotne
Fri Feb 11, 2022 10:59 am
Forum: Announcements
Topic: WinBox v3.33 and v3.34 released!
Replies: 102
Views: 26545

Re: WinBox v3.33 and v3.34 released!

I did just take a look at release history of Winbox 3.x since first release in 2015. It's a very clear trend that Winbox upgrade are released in bulk at same short time periods. Then it can goes up to nearly 1 year without new version. Maybe some more testing before release should be a good thing. :)
by Jotne
Fri Feb 11, 2022 8:19 am
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 40215

Re: v7.1.2 is released!

Can't find this update on my RB5009. Have checked for updates in /system packages
Quick Set > Check for updates shows installed version 7.0.5 and latest version 6.49.2
Upgrade to 6.49.2 and you should see 7.1.2
by Jotne
Thu Feb 10, 2022 8:02 pm
Forum: Scripting
Topic: Compute IPv4 addresses in script [SOLVED]
Replies: 2
Views: 1672

Re: Compute IPv4 addresses in script [SOLVED]

A quick google search:
viewtopic.php?t=116253

PS I have not tested it.
by Jotne
Thu Feb 10, 2022 3:43 pm
Forum: Scripting
Topic: need to save simple queue output to a file
Replies: 22
Views: 7258

Re: need to save simple queue output to a file

Try change from :put ("name=\"" . $qName . "\" target=" . $qTarget . " bytes=" . $qBytes . " enabled=" . $qStatus) to: :local logmessage ("name=\"" . $qName . "\" target=" . $qTarget . " bytes=" . $qBytes . &qu...
by Jotne
Thu Feb 10, 2022 11:56 am
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 40215

Re: v7.1.2 is released!

what is 6to4 tunnel? Where did you see this? I do not see any mention on 6to4 in this post. Found on google 6to4 tunnels enable isolated IPv6 sites to communicate across an automatic tunnel over an IPv4 network that does not support IPv6. To use 6to4 tunnels, you must first configure a boundary rou...
by Jotne
Thu Feb 10, 2022 11:27 am
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 40215

Re: v7.1.2 is released!

Upgraded all my devices...no problem upgrading.
If this is a huge production network, you have big balls, 42 min after release :)
I always wait some weeks (reading forums) to see if some goes wrong.
Also test one test router that are like my production routers to make sure all my functions works.
by Jotne
Thu Feb 10, 2022 8:20 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 227353

Re: v7.1.1 is released!

This is fixed in 7.2rc2.
Still very long export time on devices with little CPU in 7.2rc2 (compare to 6.x)
viewtopic.php?p=908897#p908897
by Jotne
Wed Feb 09, 2022 10:04 pm
Forum: General
Topic: Ports open and allowing "Internet" access to Webfig. Shodan.io report.
Replies: 48
Views: 4524

Re: !!! WTF web access?

Interesting. Learned some new to day. So with this type of routers, you have to take even more care and maybe ask some professional to set it up.
by Jotne
Wed Feb 09, 2022 10:01 pm
Forum: Scripting
Topic: TLGRM - combined notifications script & launch of commands
Replies: 7
Views: 7653

Re: TLGRM - combined notifications script & launch of commands

No, someone told me that removing : in front will make some stuff not working
by Jotne
Wed Feb 09, 2022 5:49 pm
Forum: Scripting
Topic: TLGRM - combined notifications script & launch of commands
Replies: 7
Views: 7653

Re: TLGRM - combined notifications script & launch of commands

Thanks for giving me credits and for using code tags and tabs.
But you can remove all ; at end of all lines. Only needed when there are multiple commands on same line.
by Jotne
Wed Feb 09, 2022 5:46 pm
Forum: Scripting
Topic: value of range expects range of ip addresses
Replies: 1
Views: 927

Re: value of range expects range of ip addresses

You try to set a filter where source address is nothing. That will not work and gives error.

This works:
{
/ip firewall filter
:local A 8.8.8.8
:local B This
:local C is
:local D a
:local E test
add action=accept chain=forward comment="$B-$C-$D-$E" src-address="$A"
}
by Jotne
Wed Feb 09, 2022 1:33 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Can you post some line output of
index=* | fillnull value="-" | table _time index sourcetype _raw
That do contains some data from router?

Do you run as this:
Splunk as root and port 514 open to Splunk
or
Splunk as non root, Splunk getting data from rsyslog that listen in 514
by Jotne
Wed Feb 09, 2022 11:20 am
Forum: General
Topic: Ports open and allowing "Internet" access to Webfig. Shodan.io report.
Replies: 48
Views: 4524

Re: !!! WTF web access?

When you get a Mikrotik Router, it has a default configuration that is an OK starting point. I this case some has either removed default config and add own config, or reset the router with opt out default configuration to start to make the config from scratch. It does not go away by it self. So if y...
by Jotne
Tue Feb 08, 2022 7:27 pm
Forum: General
Topic: Feature requests
Replies: 1748
Views: 646438

Re: Feature requests

This is how Cisco works. Any config you are setting will not be stored in a reboot, if you do not "write mem" or "copy running-config startup-config"
by Jotne
Tue Feb 08, 2022 3:55 pm
Forum: Scripting
Topic: Detecting Internet connection
Replies: 1
Views: 3042

Re: Detecting Internet connection

Have you looked at the netwatch function?

https://www.youtube.com/watch?v=UgKfkhyynKk
by Jotne
Mon Feb 07, 2022 5:57 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Did you see the debug section 2h-2? 2h) Debugging 1. See if any data are coming inn to splunk at all. index=* 2. Test if data has correct tag "MikroTik" (Capital M & T) index=* | table _time sourcetype _raw Follow this section 100% 2b) Then select what modules to log. Splunk can listen...
by Jotne
Mon Feb 07, 2022 8:23 am
Forum: General
Topic: rb750gr3 compatible with Router OS v7
Replies: 4
Views: 4268

Re: rb750gr3 compatible with Router OS v7

I was just replying to your question.
Is the rb750gr3 compatible with Router OS v7? I haven't found a way to upgrade to this new version yet.
Yes, it compatible, and showed how to upgrade.

Now your reply.
RouterOS 7 is not an option
Why did you then ask this in first place?
by Jotne
Sun Feb 06, 2022 2:54 pm
Forum: Beginner Basics
Topic: VLAN Setup reasonable?
Replies: 4
Views: 1016

Re: VLAN Setup reasonable?

You do not need 3 cables between Mikrotik and TP-Link. You can send all VLAN in trunk mode over one cable and get same result. (if TP-Link supports VLAN)
by Jotne
Sun Feb 06, 2022 11:12 am
Forum: Scripting
Topic: Script for pinging an IP for 24/7
Replies: 14
Views: 20605

Re: Script for pinging an IP for 24/7

As far as I know, no.
by Jotne
Sat Feb 05, 2022 10:22 pm
Forum: General
Topic: Spambot?
Replies: 3
Views: 779

Re: Spambot?

Do your linux server run any form for SMTP (mail server)? On the linux server, run: ss -topan | grep ":25" Si if you have some LISTEN 0 128 0.0.0.0:25 0.0.0.0:* That mean you have an SMTP server running. If you have many of this: ESTAB 0 0 serverIP:22343 publicIP:25 users:(("xxxxx,pid...
by Jotne
Sat Feb 05, 2022 3:15 pm
Forum: Scripting
Topic: Script for pinging an IP for 24/7
Replies: 14
Views: 20605

Re: Script for pinging an IP for 24/7

The topic of this thread is "ping", it is logical that we are only talking about that command... :roll: :wink: :lol:
I do know, but not all read all detail ;)
by Jotne
Sat Feb 05, 2022 11:10 am
Forum: Scripting
Topic: Script for pinging an IP for 24/7
Replies: 14
Views: 20605

Re: Script for pinging an IP for 24/7

Just a small correction.

as-value do exist on 6.x, but not in ping.

This is from 6.48.4
:put [/interface vlan print as-value ]
.id=*c;arp=enabled;interface=Bridge1;mtu=1500;name=VLAN20;vlan-id=20
by Jotne
Sat Feb 05, 2022 10:43 am
Forum: Beginner Basics
Topic: How to write idempotent script
Replies: 23
Views: 3431

Re: How to write idempotent script

Its better to test to see if vlan is already created, and if not, create it. I was told (by rextended) its better to fix the problem and do not use on-error { /interface vlan :if ([:len [find where interface=bridge1 vlan-id=2]]=0) do={ add interface=bridge1 name=vlan2 vlan-id=2 } } Script tries to f...
by Jotne
Fri Feb 04, 2022 8:21 pm
Forum: General
Topic: Block WAN Access to port 53? [SOLVED]
Replies: 54
Views: 13488

Re: Block WAN Access to port 53? [SOLVED]

Wow Anav are reading log lines :) I do see that the config is complex and it may be better to start all over and make it as simple as possible. Make a drawing that shows all your rules. From/To/Nat/Blocked etc. Here are firewall rules on one of my Router. (This is one with a rather complex setup) FW...
by Jotne
Fri Feb 04, 2022 5:58 pm
Forum: General
Topic: Block WAN Access to port 53? [SOLVED]
Replies: 54
Views: 13488

Re: Block WAN Access to port 53? [SOLVED]

We're talking about inbound DNS requests from the Internet.
53 should not be open to internt by default.
@pyeager Please post full config and what you are trying to do and why.
by Jotne
Fri Feb 04, 2022 5:55 pm
Forum: Scripting
Topic: script send logs with l2tp connections no work
Replies: 2
Views: 1621

Re: script send logs with l2tp connections no work

I can not see any obvious reason for the script has stopped. But please use code tags when post data </> button above the post. I have reformatted the post and removed unneeded ; at the end of lines to make it easier to read. ###/log print file=ppplog.0.txt :global voldvlist :global l2tplist "L...
by Jotne
Fri Feb 04, 2022 2:57 pm
Forum: General
Topic: Block WAN Access to port 53? [SOLVED]
Replies: 54
Views: 13488

Re: Block WAN Access to port 53? [SOLVED]

Why?
OP has not replayed to that.
If some blocks 53, its to block DNS. Then use DoH (or DoT ) and bypass this block.
So why block it?
by Jotne
Fri Feb 04, 2022 1:36 pm
Forum: General
Topic: If you have a Mikrotik home lab, I have a question for you.
Replies: 17
Views: 3444

Re: If you have a Mikrotik home lab, I have a question for you.

I can not say anything about the other. Have only used EVE-NG to make labs. Its easy to configure, upload new images. For me it does what I like to test. Have only free version, but would like the full version (no limit in transfere speed and no limits in number of nodes). You can connect devices to...
by Jotne
Thu Feb 03, 2022 11:15 pm
Forum: General
Topic: If you have a Mikrotik home lab, I have a question for you.
Replies: 17
Views: 3444

Re: If you have a Mikrotik home lab, I have a question for you.

My home lab is free :) EVE-NG is the best you can get to learn and to experiments on MikroTik Routers. (Wifi may be the only thing missing) It shows up as real routers in your network. You can even use VPN from this virtual routers to the outside world. You do loose some function on the free version...
by Jotne
Thu Feb 03, 2022 10:17 pm
Forum: Scripting
Topic: Function to convert B, KiB, MiB or GiB in a script
Replies: 18
Views: 4002

Re: Function to convert B, KiB, MiB or GiB in a script

I have not used time to study the eval code, so there I can not help you. :)
by Jotne
Thu Feb 03, 2022 7:46 pm
Forum: Scripting
Topic: Function to convert B, KiB, MiB or GiB in a script
Replies: 18
Views: 4002

Re: Function to convert B, KiB, MiB or GiB in a script

You are welcome. If you need it as a function to do the you for multiple use. Here is a simplified "to human" version. Without the not needed ; every where ;) :global human do={ # Converts a number to SI-Prefix number :local INP [:tonum $1] :local Co 0 :while ($INP > 1024) do={ :set $INP (...
by Jotne
Thu Feb 03, 2022 5:52 pm
Forum: Scripting
Topic: Function to convert B, KiB, MiB or GiB in a script
Replies: 18
Views: 4002

Re: Function to convert B, KiB, MiB or GiB in a script

This is one good one :) PS I learned most of my stuff from copy/past and study... { :local Bytes ([/interface get pppoe-out1]->"rx-byte") :local Type [:toarray "B,KB,MB,GB,TB,PB,EB"] :local Counter 0 :while ($Bytes > 1024) do={ :set $Bytes ($Bytes/1024) :set $Counter ($Counter+1)...
by Jotne
Thu Feb 03, 2022 5:21 pm
Forum: Scripting
Topic: Function to convert B, KiB, MiB or GiB in a script
Replies: 18
Views: 4002

Re: Function to convert B, KiB, MiB or GiB in a script

This should convert the data to your need: { :local Type :local Bytes ([/interface get pppoe-out1]->"rx-byte") :if (($Bytes/1073741824)>0) do={ :set $Bytes ($Bytes/1073741824) :set $Type "GB" } else={ :if (($Bytes/1048576)>0) do={ :set $Bytes ($Bytes/1048576) :set $Type "MB&...
by Jotne
Thu Feb 03, 2022 2:48 pm
Forum: General
Topic: RouterOS v7.0 released (april fools joke)
Replies: 2
Views: 1090

RouterOS v7.0 released (april fools joke)

Found this on a site. Posted 1 April 2014 :) I guess at that time, many were tired of waiting for v7 in 2014!! Interesting to see the suggestion of what was added, compare to what we have today. What's new in 7.0: *) dude - 5.0 package released for PPC and CCR platforms *) ppp - LNS/LAC support adde...
by Jotne
Wed Feb 02, 2022 10:53 pm
Forum: General
Topic: RouterOS release history
Replies: 11
Views: 2090

Re: RouterOS release history

Ok Some more time spend on unneeded stuff.... Found correct compile date and post date for nearly all version, except the first 7.0 betas. For some reason posting of the 7.x betas and rc has been different from all other releases and was hard to find correct info. My table now has both compile time ...
by Jotne
Wed Feb 02, 2022 3:39 pm
Forum: General
Topic: RouterOS release history
Replies: 11
Views: 2090

Re: RouterOS release history

If I do find some more time ;) I will look at the post date.
Some version are announced before they are compiled like 7.1.1 here:
viewtopic.php?t=181472
by Jotne
Tue Feb 01, 2022 11:07 pm
Forum: General
Topic: RouterOS release history
Replies: 11
Views: 2090

Re: RouterOS release history

Updated post #1 with renaming 6.46 normal release to 6.46re to get it better sorted and med graph some thicker. Found various 7.x beta (some did have date some not. For those without date, I used first post found as date) I get the impression that new stable releases are often released on Friday aft...
by Jotne
Tue Feb 01, 2022 9:59 pm
Forum: General
Topic: RouterOS release history
Replies: 11
Views: 2090

Re: RouterOS release history

Do agree, but then I need to rename the version. Splunk do default sort by name, so 6.46 berfore 6.46beta before 6.46rc. Timestamp is from forum announcement post What's new in 7.1.1 (2021-Dec-21 13:53) Timezone should not matter since its what written in the post and not time of post in the forum. ...
by Jotne
Tue Feb 01, 2022 7:58 pm
Forum: General
Topic: RouterOS release history
Replies: 11
Views: 2090

RouterOS release history

Just for fun I have made a map of the RouterOS release history the last years. Every bar i one version.
Beta version are mostly released in the morning, RC and normal version some later in the day.
.
RouterOS.jpg
.
RouterOS2.jpg
by Jotne
Tue Feb 01, 2022 7:53 pm
Forum: Scripting
Topic: How to calculate quantity of routes ?
Replies: 2
Views: 1354

Re: How to calculate quantity of routes ?

This is how to print number of routes:
:put [:len [/ip route find where dst-address="0.0.0.0/0"]]
to get it inn to a variable
:local Routes  [:len [/ip route find where dst-address="0.0.0.0/0"]]
by Jotne
Tue Feb 01, 2022 7:36 pm
Forum: Beginner Basics
Topic: Why not a definitive solution to block Youtube?
Replies: 55
Views: 21425

Re: Why not a definitive solution to block Youtube?

When you have done all that, they can just setup a VPN or Proxy.
Why not just turn off secure filter on google or bing search. Then just search for any pron you like and select pictures.
There are no way to prevent this (can be controlled some on a company pc with forced policy)
by Jotne
Tue Feb 01, 2022 5:30 pm
Forum: Scripting
Topic: need to save simple queue output to a file
Replies: 22
Views: 7258

Re: need to save simple queue output to a file

You can send each data line to syslog server instead of a file. Then you can use an external server to examine logs. Should be easy to implement to my Splunk/Mikrotik prosjekt. See signature. Here is an example to test on your terminal: { /queue simple :local queueList [find] :foreach q in=$queueLis...
by Jotne
Mon Jan 31, 2022 8:25 am
Forum: General
Topic: Force reboot
Replies: 31
Views: 111001

Re: Force reboot

You can even remove the not needed semi column.
:execute {/system reboot}
Works on latest 7.2rc3 as well
by Jotne
Mon Jan 31, 2022 8:16 am
Forum: Scripting
Topic: HowToScript to create new wireless interface, set new ssid, update ssid with another name,
Replies: 1
Views: 1108

Re: HowToScript to create new wireless interface, set new ssid, update ssid with another name,

Please edit your post and use code tag button </> to make formatting of post better. Some like this:
{
	:local PutString do={
		:put function
	}

	:for i from=1 to=3 do={
		:put $i
		$PutString
	}
}
by Jotne
Sun Jan 30, 2022 12:47 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 87246

Re: v7.2rc2 and v7.2rc3 is released!

Can confirm that it does not work on 7.2rc3, but do work on 7.1. Send an email to support@mikrotik.com so they make a support case out of it.
by Jotne
Sun Jan 30, 2022 9:22 am
Forum: General
Topic: Question - How many interfaces can be bonded together? [SOLVED]
Replies: 4
Views: 1868

Re: Question - How many interfaces can be bonded together? [SOLVED]

I am attempting to setup redundancy.
Then two interface bound together should be enough. :)
by Jotne
Sat Jan 29, 2022 10:50 pm
Forum: General
Topic: Force reboot
Replies: 31
Views: 111001

Re: Force reboot

The OP never claimed that it is done to solve a problem.
That is why I ask why he need to reboot, to adopt the answer to what the need is. Not guess it just for fun. :)
by Jotne
Sat Jan 29, 2022 4:51 pm
Forum: General
Topic: Force reboot
Replies: 31
Views: 111001

Re: Force reboot

If I do decide to do an upgrade, yes I can schedule a reboot, but only after I have chosen to do so. No automatic upgrade of anything.
But if OP replay that its due to a problem, he should clearly find the root cause and fix that first.
by Jotne
Sat Jan 29, 2022 12:22 pm
Forum: General
Topic: Question - How many interfaces can be bonded together? [SOLVED]
Replies: 4
Views: 1868

Re: Question - How many interfaces can be bonded together? [SOLVED]

Do you need to bound all interface? What do you try to achieve?
by Jotne
Sat Jan 29, 2022 12:19 pm
Forum: General
Topic: Force reboot
Replies: 31
Views: 111001

Re: Force reboot

Is it possible to force reboot on RouterOS?
This thread is missing a question.
Why?


If its due to a problem, its better to fix the problem, so reboot are not needed.
I never reboot my routers (only when upgrade).
by Jotne
Sat Jan 29, 2022 12:16 pm
Forum: RouterOS beta
Topic: 7.1.1 - CAKE breaks IPv6
Replies: 18
Views: 13265

Re: 7.1.1 - CAKE breaks IPv6

Have you tested latest beta? If so add these information as well to support@mikrotik.com
by Jotne
Sat Jan 29, 2022 12:13 pm
Forum: Scripting
Topic: How to script "Home" ssid updated to "Office" ssid as time-event or GPS event ?
Replies: 4
Views: 1661

Re: How to script "Home" ssid updated to "Office" ssid as time-event or GPS event ?

SSID can easily be change by a scrip scheduled at fixed time.
Not sure how to do it by GPS location,.
by Jotne
Fri Jan 28, 2022 3:51 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 87246

Re: v7.2rc2 is released!

/export on older ruters like SXT 5HPnD (400Mhz) still does not work. Start slow and just hangs, or take very long time. Cpu show 100% the whole time Sometimes it may show the config after 15 min other times it shows this: Console has crashed; please log in again. Device works and have some basic co...
by Jotne
Fri Jan 28, 2022 2:00 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 87246

Re: v7.2rc2 is released!

Still no ZeroTier for mips...
by Jotne
Thu Jan 27, 2022 12:43 pm
Forum: Scripting
Topic: Script for down & up interfaces
Replies: 5
Views: 5182

Re: Script for down & up interfaces

Not sure what you mean.
What I posted was a manual change.

Do you like a script that automatically change port? Try Netwatch
by Jotne
Thu Jan 27, 2022 8:20 am
Forum: Scripting
Topic: Script for down & up interfaces
Replies: 5
Views: 5182

Re: Script for down & up interfaces

Fixed in above post.
by Jotne
Wed Jan 26, 2022 9:10 am
Forum: Scripting
Topic: Getting Bridge Port from DHCP Leases in Terminal
Replies: 17
Views: 4510

Re: Getting Bridge Port from DHCP Leases in Terminal

This is clearly a bug on 7.1.1 and 7.2.rc1. Please report this to support@mikrotik.com I did try to find it and its not in termial. :put [/ip dhcp-server/lease get *1 ] active-address address-lists block-access dhcp-option-set insert-queue-before queue-type src-mac-address active-client-id agent-cir...
by Jotne
Wed Jan 26, 2022 8:25 am
Forum: Scripting
Topic: Script for down & up interfaces
Replies: 5
Views: 5182

Re: Script for down & up interfaces

Here you go: Disable sfp-sfpplus1, enable ether10 { /interface/ethernet/disable [find where name=sfp-sfpplus1] /interface/ethernet/enable [find where name=ether10] } Disable ether10, enable sfp-sfpplus1 { /interface/ethernet/disable [find where name=ether10] /interface/ethernet/enable [find where na...
by Jotne
Tue Jan 25, 2022 5:54 pm
Forum: Scripting
Topic: getting/setting vlan for port
Replies: 1
Views: 1127

Re: getting/setting vlan for port

To get pvid for an IF ether3 { :local IF [/interface bridge port find where interface=ether3] :put [/interface bridge port get $IF pvid] } Or in one line: :put [/interface bridge port get [find where interface=ether2] pvid] To set pvid 20 for interface ether3 /interface bridge port set [find where i...
by Jotne
Mon Jan 24, 2022 11:43 pm
Forum: Scripting
Topic: bgp peer disable/enable script based on packet loss [SOLVED]
Replies: 2
Views: 2891

Re: bgp peer disable/enable script based on packet loss [SOLVED]

Post it in Code tags and tabs, makes it easier to read. PS I have not tested it. fixed: elese-else removed extra: } removed: do removed not needed ; at end of lines # VARIABLES :local asr1 "212.2.33.84" :local pingCount 20 :local stableConnectionFrom 95 :local quality ([/ping count=$pingCo...
by Jotne
Sun Jan 23, 2022 10:39 pm
Forum: General
Topic: Frequent reboots of hAP ac2 [SOLVED]
Replies: 24
Views: 5199

Re: Frequent reboots of hAP ac2 [SOLVED]

To see memory problem, write down memmory usage every 30 min or 1 hour (depends how often it reboots.) If memory usage goes up and not goes down again, you may have a problem. You can use an external program like SNMP tools or use Splunk from my signature to monitor the router. I had a memory proble...
by Jotne
Sun Jan 23, 2022 7:27 pm
Forum: General
Topic: Frequent reboots of hAP ac2 [SOLVED]
Replies: 24
Views: 5199

Re: Frequent reboots of hAP ac2 [SOLVED]

Do it reboot with default config?
My guess is that here are some config/function that do eat memory or other resources. Router the reboots.

Do you need to use 7.x?
by Jotne
Sat Jan 22, 2022 10:20 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Some times MT do change stuff, so it does not work. Since I do not have capsman, I need some help to debug it.
Can you post a list of log line here?

Example output of:
index=* "caps,info"
by Jotne
Sat Jan 22, 2022 9:55 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 65
Views: 35946

Re: Black list for failed login to IPSec VPN

Here is how you can convert the IP. Since there are no easy way to find last dot, I need to find all and count. It may be a faster way { :local ip "64.128.34.17" :local A1 [:find $ip "."] :local A2 [:find $ip ($A1+1)] :local A3 [:find $ip "." ($A2+1)] :local new ([:pick...
by Jotne
Thu Jan 20, 2022 1:50 pm
Forum: Wireless Networking
Topic: question about how to use a private proxy on a mikrotik router as a client proxy.
Replies: 4
Views: 2598

Re: question about how to use a private proxy on a mikrotik router as a client proxy.

Yup.
This will not give you much, since most sites today uses 443
by Jotne
Wed Jan 19, 2022 4:36 pm
Forum: Scripting
Topic: Covert week to day
Replies: 1
Views: 1448

Re: Covert week to day

Some like this could do:
{
:local UP "45w1h3m49s"
:local days ([:tonum [:pick $UP 0  [:find $UP "w"]]]*7)
:local UPdays ($days.[:pick $UP [:find $UP "w"] 999])
:put "Weeks $UP -  Days $UPdays"
}
Weeks 45w1h3m49s -  Days 315w1h3m49s
by Jotne
Wed Jan 19, 2022 3:25 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 65
Views: 35946

Re: Black list for failed login to IPSec VPN

Updated to 1.5 so its easy to see what is the latest :) +4 and +5 is correct. If you look at how the pick works, you will see it gives the position on the first found letter. from 8.8.8.8 x1234567890 for 8.8.8.8 x1234567890 So for the "from" , you need to add 5 to get the first part of 8.8...
by Jotne
Wed Jan 19, 2022 1:49 pm
Forum: Scripting
Topic: how to get only IP from print lease [SOLVED]
Replies: 14
Views: 6933

Re: how to get only IP from print lease [SOLVED]

This will add one by one IP to the address list "Blocking" { :local c3 "PC4SHOPS" :local IP :foreach i in=[/ip dhcp-server lease find where host-name="$c3"] do={ :set $IP ([/ip dhcp-server lease get $i address]) /ip firewall address-list add list="Blocking" ad...
by Jotne
Wed Jan 19, 2022 1:44 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 65
Views: 35946

Re: Black list for failed login to IPSec VPN

You are 100% correct. Here is a fixed version. Thanks :) # Created Jotne && rextended 2022 v1.5 # # This script add ip of user who with "IPSEC negotiation failed", "SPI* not registered" and "Invalid exchange" to a block list for 7 days # Schedule the script to r...
by Jotne
Wed Jan 19, 2022 11:29 am
Forum: Scripting
Topic: how to get only IP from print lease [SOLVED]
Replies: 14
Views: 6933

Re: how to get only IP from print lease [SOLVED]

Its how local variable work. Global variable are "permanent" and works everywhere Local variable works fine in script, but if you cut an past it to a terminal session, you need to put it in brakets like this: { :local c3 "PC4SHOPS" :local IP :foreach i in=[/ip dhcp-server lease f...
by Jotne
Wed Jan 19, 2022 10:59 am
Forum: Scripting
Topic: how to get only IP from print lease [SOLVED]
Replies: 14
Views: 6933

Re: how to get only IP from print lease [SOLVED]

Instead if put, use set to put it inn to a variable.
:global c3 "PC4SEARCH"
:local IP
:foreach i in=[/ip dhcp-server lease find where comment="$c3"] do={:set $IPAddress ([/ip dhcp-server lease get $i address])}
by Jotne
Wed Jan 19, 2022 8:06 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Should work.
Only comment is that you should not run splunk as root user, and use rsyslog to listen on port 514.
by Jotne
Tue Jan 18, 2022 10:19 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Mine never needs to be restarted. Have one version where Splunk listen on port 514 (not recommended as it needs to be root) Other version have rsyslog server as input and Splunk reads rsyslog logs. Both running fine.' Do you pass any firewall on the way from MikroTik to the Splunk server? What do yo...
by Jotne
Mon Jan 17, 2022 11:23 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 227353

Re: v7.1.1 is released!

Not a quick fix, but if you do run RouterOS x86 you can change to RouterOS CHR (run on VmWare).
by Jotne
Mon Jan 17, 2022 10:53 pm
Forum: General
Topic: Firewall Rule
Replies: 10
Views: 2328

Re: Firewall Rule

You can put pfsense behind Mikrotik and let the Mikrotik be the main router.
I do use HAproxy as a reverse proxy for many websites placed behind the Mikrotik

If you nat in both pfsense and Mikrotik, I do suggest that you remove nat in the second device and use Mikrotik without nat.
by Jotne
Mon Jan 17, 2022 9:50 pm
Forum: General
Topic: Firewall Rule
Replies: 10
Views: 2328

Re: Firewall Rule

Why do you need the pfsense box? Mikrotik can do it all.
by Jotne
Sat Jan 15, 2022 11:04 pm
Forum: Announcements
Topic: WinBox v3.32 released!
Replies: 65
Views: 94436

Re: WinBox v3.32 released!

I did always use Shift-Ins and Ctrl-Ins until I did get a HP computer without a dedicated ins key.
So now I do use Ctrl-c Ctrl-v
And after starting using Teams I have learned
Shift-Ctrl-V that is paste without format.
by Jotne
Sat Jan 15, 2022 10:45 am
Forum: Scripting
Topic: ppp sync script
Replies: 4
Views: 2807

Re: ppp sync script

So you like to have all ppp user profile stored to an SQL base?
Why?
by Jotne
Sat Jan 15, 2022 12:12 am
Forum: Scripting
Topic: Variables - why does it not work? [SOLVED]
Replies: 8
Views: 3709

Re: Variables - why does it not work? [SOLVED]

Remove the underscore in the variable name.
Use
:local wginterface wireguard_s2s_ag
And
1. You can remove ; at end of all line. Only needed while there are multiple command on same line.
2. :delay 4000ms is the same as :delay 4s
by Jotne
Fri Jan 14, 2022 2:56 pm
Forum: Scripting
Topic: Monitor Mikrotik log by Telegram
Replies: 65
Views: 37036

Re: Monitor Mikrotik log by Telegram

Capital should work fine as in "Uptime"
by Jotne
Fri Jan 14, 2022 1:16 pm
Forum: Scripting
Topic: DynDNS Script from Mikrotik Wiki (correction)
Replies: 30
Views: 32488

Re: DynDNS Script from Mikrotik Wiki (correction)

Remove one or all of these lines: # print some debug info :log info ("UpdateDynDNS: username = $username") :log info ("UpdateDynDNS: password = $password") :log info ("UpdateDynDNS: hostname = $hostname") :log info ("UpdateDynDNS: previousIP = $previousIP")
by Jotne
Fri Jan 14, 2022 11:43 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 65
Views: 35946

Re: Black list for failed login to IPSec VPN

Its to make dot a dot and not just any character. (see regex info)
I RouterOS you need to double escape.
by Jotne
Fri Jan 14, 2022 7:36 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 65
Views: 35946

Re: Black list for failed login to IPSec VPN

Error found. Here is some data from the log: 64.62.197.52 phase1 negotiation failed. 64.62.197.217 phase1 negotiation failed. 65.49.20.109 phase1 negotiation failed. phase1 negotiation failed due to time up 92.200.200.100[500]<=>27.115.124.10[48536] 0011223344556677:5c5c77ed781bf459 phase1 negotiati...
by Jotne
Thu Jan 13, 2022 2:32 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 65
Views: 35946

Re: Black list for failed login to IPSec VPN

There is an 1.3 in this thread as well. Test it out. (Do not remember what was changed from 1.2 to 1.3)
by Jotne
Thu Jan 13, 2022 1:12 pm
Forum: General
Topic: rb750gr3 compatible with Router OS v7
Replies: 4
Views: 4268

Re: rb750gr3 compatible with Router OS v7

If you upgrade to latest 6.x (6.49.2 at the moment), you will see 7.1.1 under testing and upgrade train.
.
7.1.1.jpg
by Jotne
Wed Jan 12, 2022 11:44 am
Forum: General
Topic: Securing your router
Replies: 66
Views: 7691

Re: Securing your router

Old system that I use for som backup purpose. Should have been upgraded ;)
by Jotne
Wed Jan 12, 2022 11:23 am
Forum: General
Topic: Securing your router
Replies: 66
Views: 7691

Re: Securing your router

@jotne, waste of time, my drop all rule works just fine for scans.. If you have an open port then at least put a source address list on it, and the port wont appear on scans. If you have port forwarding also ensure its an encrypted type of connection for login, not just plain user name. If you thin...
by Jotne
Tue Jan 11, 2022 10:57 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

DNS logs comes from the Router log, so to stop it change from:
/system logging add action=logserver prefix=MikroTik topics=!debug,!packet,!snmp
to
/system logging add action=logserver prefix=MikroTik topics=!debug,!packet,!snmp,!dns
by Jotne
Mon Jan 10, 2022 6:46 pm
Forum: General
Topic: Securing your router
Replies: 66
Views: 7691

Re: Securing your router

Here is one tip that I like to add to my router: https://forum.mikrotik.com/viewtopic.php?f=23&t=178496 If someone tries any port on my router that is not open (typical a scan script), then this IP will be blocked for 24 hour on all ports. This way the can not continue to hack on open ports like...
by Jotne
Mon Jan 10, 2022 6:41 pm
Forum: Beginner Basics
Topic: Network drawing program, what are you using?
Replies: 21
Views: 5476

Re: Network drawing program, what are you using?

Here is another from EVE NG (paid version), taken from the Network Bergs lab.
All is working as an ISP with BGP ++
.
EVE_NG2.jpg
Link to source:
https://www.youtube.com/watch?v=_e1Fdvcd-P4
by Jotne
Mon Jan 10, 2022 5:13 pm
Forum: Beginner Basics
Topic: Network drawing program, what are you using?
Replies: 21
Views: 5476

Re: Network drawing program, what are you using?

Visio can be used like this:
.
FW.jpg
Also the EVE NG is a cool tool. It not just draw your config, but it s actual Mikrotik Router / Cisco or other that do works and can be configured.
Free version have some limitation. (Speed/number of nodes)
.
EVE NG.jpg
by Jotne
Mon Jan 10, 2022 4:53 pm
Forum: General
Topic: Securing your router
Replies: 66
Views: 7691

Re: Securing your router

Some FW tips from me.

Use config that has been posted in this thread.
Have a block rule as last rule.
Make a diagram of all the rules, and understand what they do.

Here is an example from one of my Routers.
.
FW.jpg
by Jotne
Sun Jan 09, 2022 5:45 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

@reinerotto

To solve this discussion. Give me a VPN to a site that you control and is porn secure, and I can send you some print screen show what I can get when using your VPN. (As long as you have standard usable open net. Not all IP blocked.)
by Jotne
Sun Jan 09, 2022 11:18 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

I do not spread wrong information.

Question: How do I block pornographic images in my RB?
Answer: Only in some degree. (Far from 99.9%)

You are dragging with other solutions, no me.
by Jotne
Sun Jan 09, 2022 5:12 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

If you are not using RouterOS, what are your doing here?
by Jotne
Sat Jan 08, 2022 5:49 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

What are you trying to prove? Yes, you can block some with DNS, yes you can block some with IP, Yes you can block some more with Safe Search and you can even block more with control of the clients. But not 99.9% To get around Forced Safe search: * Login to your Google account and disable "Safe ...
by Jotne
Sat Jan 08, 2022 5:33 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

As repeatedly posted many times. Block porn with DNS helps just some. As more and more OS (IOS 14) starts to use DoH/DoT, it bypass it without any problem. Also I have seen that devices like Chormecast that is hard coded to DNS 8.8.8.8 stops working if its redirected. You are wrong, in regards regar...
by Jotne
Sat Jan 08, 2022 6:19 am
Forum: General
Topic: Will there be a Ros v6.50?
Replies: 6
Views: 1459

Re: Will there be a Ros v6.50?

There will be some routers that can not be upgraded, so there may be more 6.x version'.
by Jotne
Sat Jan 08, 2022 5:53 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

Bad example: Various methods to force "Safe Search" for bing, google, etc. For details, google "How to force safe search google". And you are off topic again. How do I block pornographic images in my RB? To do what you suggest, you have to do some with the clients. This was not ...
by Jotne
Fri Jan 07, 2022 8:09 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

Correct is: "Porn is not 100% blockable, but 99.9%". Assuming proper knowledge and tools, of course. I would say closer to 80%, not 99.9% Example when search for "sex" in google.com using any browser, how would you block that. If you do not control the PC, typical a company PC, ...
by Jotne
Thu Jan 06, 2022 6:04 am
Forum: Scripting
Topic: Password for ssh [SOLVED]
Replies: 6
Views: 7262

Re: Password for ssh [SOLVED]

by Jotne
Wed Jan 05, 2022 8:24 pm
Forum: Scripting
Topic: Read contents of rsc file
Replies: 4
Views: 4070

Re: Read contents of rsc file

I do recommend SFTP instead.
by Jotne
Wed Jan 05, 2022 8:13 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

We are far out of what was asked for.

Block pornographic on the Router OS.
Can be done in some degree (by setting DNS to sites that filter it). But can be bypassed with simple steps.
And for the rest. Is it possible to block some permanent. No, without doing some with all clients.
by Jotne
Wed Jan 05, 2022 8:05 pm
Forum: Scripting
Topic: Password for ssh [SOLVED]
Replies: 6
Views: 7262

Re: Password for ssh [SOLVED]

I think he was talking about not put a password on the remote router, and then use the script without password.
Not recommended.
by Jotne
Wed Jan 05, 2022 9:52 am
Forum: Scripting
Topic: Read contents of rsc file
Replies: 4
Views: 4070

Re: Read contents of rsc file

After you get config inn to an variable, who would you then use it from there, to what?
by Jotne
Wed Jan 05, 2022 6:46 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

Intercept of https and de-crypt/ inspect/ en-crypt requires cert installs on clients, as decribed. This is what I was looking for. Since you need to do some with the clients, this is more or less the same as how Palo Alto or Forcepoint works. Only a solution for company that has 100% controls of th...
by Jotne
Wed Jan 05, 2022 6:35 am
Forum: Scripting
Topic: Password for ssh [SOLVED]
Replies: 6
Views: 7262

Re: Password for ssh [SOLVED]

Password is a must and on newer RouterOS you are forced to set password. No password, no security.
by Jotne
Tue Jan 04, 2022 9:06 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

And no change on the clients, no control, no modification, no policies added/changed? RB + Untangle gives 100% control (or close to)? Can you give a quick description on how it does it? Does it open and examine all https package (how)? If I search for porn in google, how does it block it? Untangle s...
by Jotne
Tue Jan 04, 2022 8:09 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pornographic images in my RB?

So then back to OPs request.
How do I block pornographic images in my RB?
Can't be done.
by Jotne
Tue Jan 04, 2022 7:53 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

Without 100% control of all clients in a network, you can not control what they can do or can not do. Example. Here in Dubai (vacation), they have blocked video/audio on Whats app/MSN ++, but had no problem finding a way to get around it. In Turkey they blocked various sites, like Wikipedia. DoH fix...
by Jotne
Tue Jan 04, 2022 12:47 pm
Forum: Scripting
Topic: send log entry to external website
Replies: 15
Views: 4877

Re: send log entry to external website

If you look at my script here, you see how to search last 5 min to get some from the log. Run a script every 5 min.
viewtopic.php?p=743875#p743875

The Splunk page (signature link), there are a view to see status in graphics all PPPoE logged inn/out + much more. 100% free.
by Jotne
Tue Jan 04, 2022 12:05 pm
Forum: Scripting
Topic: send log entry to external website
Replies: 15
Views: 4877

Re: send log entry to external website

Why not syslog? Its created for that purpose: sending logs to other systems.
See my Splunk prosjekt in my signature for how to sending syslog and monitor your solution.
by Jotne
Tue Jan 04, 2022 7:42 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 65
Views: 35946

Re: Black list for failed login to IPSec VPN

:local ipS [:pick $logMessageS ([:find $logMessageS ">"]+1) ([:find $logMessageS "["]-1)] ==> it does not work You are close. Problem is the second find , it does find the first [ (before 500), not the second [ (before 30992) that you need. This works: { :local test "phase1...
by Jotne
Mon Jan 03, 2022 7:19 pm
Forum: Beginner Basics
Topic: Blocking TikTok [SOLVED]
Replies: 9
Views: 33428

Re: Blocking TikTok [SOLVED]

And I English that will become? Any solution that involves DNS will not work if client do use DoH/DoT (IOS 14 as an example) There are no any simple solutions to 100% block any thing on your network without removing the cable, or if you are a lager company that you have 100% control of all devices o...
by Jotne
Mon Jan 03, 2022 7:01 pm
Forum: General
Topic: Mikrotik on x86 sees only 1920Mb of RAM
Replies: 10
Views: 2807

Re: Mikrotik on x86 sees only 1920Mb of RAM

It's silly because the OP came here asking to get his current setup to work better, not asking for recommendations on upgrades. The "upgrading to a better system then it will work better" answer is kind of obvious. That's like going around and telling people the sky is blue. This is not s...
by Jotne
Sun Jan 02, 2022 8:26 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 313052

Re: ZeroTier added to RouterOS v7.1rc2

No need to quote my post for asking that. You are not replying to my post.
An I already asked for the same (other routers)


And one link to same paid product in link is enough.
Stop spamming with new post everywhere. Have some forum etikette.

9 post today to promote your monitor solution.
by Jotne
Sun Jan 02, 2022 6:32 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

There are many solution.

With Splunk you have 100% control of everything. You server, your setup. And free (up to 500MB/day)
Store as much data as long as you like.
by Jotne
Sun Jan 02, 2022 7:36 am
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14378

Re: Where is UPS?

@kubotor

This is all your fault that you run inn to problems.

As an ISP you should know that you should test every upgrade on devices not in production. If all does work and there are no showstoppers, then upgrade the routers, if its needed.
by Jotne
Fri Dec 31, 2021 6:48 pm
Forum: Scripting
Topic: how to get only IP from print lease [SOLVED]
Replies: 14
Views: 6933

Re: how to get only IP from print lease [SOLVED]

RouterOS v7 understand v6 script so this works for both: :global c3 "PC4SEARCH" :foreach i in=[/ip dhcp-server lease find where comment="$c3"] do={:put ([/ip dhcp-server lease get $i address])} And recommend to change from ~$c3 that means contain (example it will hits on "PC...
by Jotne
Fri Dec 31, 2021 6:28 pm
Forum: Scripting
Topic: Script that get the Network Value
Replies: 1
Views: 2835

Re: Script that get the Network Value

Dont use print in script:

try this:
:local LaRed [/ip address get [find  where interface="bridge"] network ]
If this does not get any result, post output of:
/ip address print
by Jotne
Wed Dec 29, 2021 8:53 pm
Forum: Scripting
Topic: script for check links down pppoe client
Replies: 1
Views: 2316

Re: script for check links down pppoe client

Its possible to do, but do not have pppoe setup. You can make a script that add counter to global variable (one for each users) or add number to comments of the user. Then test every 5 min and see if user logins passes a limit. I have made a Dashboard for Splunk that do show all user when they login...
by Jotne
Wed Dec 29, 2021 6:23 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 162469

Re: v7.2rc1 is released!

socks5 now ok in 7.2rc1 is, but 7.1.1 still problem
Why do you ask about this here? What is fixed is clear that its fixed for 7.2rc1. Not anything is mention about this in 7.1.1 thread.
by Jotne
Wed Dec 29, 2021 12:46 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

OPs question "How do I block pornographic images in my RB?" Simple answer: Can not be done. As Anav writes: Do educate your user. I would guess DoH/DoT will become standard and automatically for more and more products, so any attempts to block/control det old, non encrypted, obsoleted DNS,...
by Jotne
Wed Dec 29, 2021 12:41 pm
Forum: Scripting
Topic: ppp sync script
Replies: 4
Views: 2807

Re: ppp sync script

Not sure what you like to have done?
by Jotne
Wed Dec 29, 2021 11:46 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

Can you explain how this is done? Can it be done one RouterOS? I am not sure how to block this without having 100% control of the clients. You can setup as many DoH server as you like on the internett. Since this is https packets, I do not see how you can block them without opening the https packets...
by Jotne
Wed Dec 29, 2021 10:40 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

This will help some.
Problem is that you can set your own DNS (that could be redirected using rules to your DNS)
Some clients are using DoH/DoT and will not use normal DNS server at all. (example iOS >=14)
https://paulmillr.com/posts/encrypted-dns/
by Jotne
Wed Dec 29, 2021 9:23 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

True, better to educate than to deny because deny doesn't work in our society especially if you have money. Best word as far in this thread. I guess they don't permit their children to have friends either? Because it they do, whole thing is in vain. ;) Also a good comment :) Friends share their mob...
by Jotne
Tue Dec 28, 2021 9:07 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

Untangle can also do man-in-the-middle SSL decryption and re-encryption, like Palo Alto and Fortinet devices. You have to trust the certificate of course in order for this to work properly without throwing scary errors to the user. So then you need to have control of the clients (PC/Phone ++++). No...
by Jotne
Tue Dec 28, 2021 8:32 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

An this will open google search (https/quic) packets and block search for "sex nude"?
How can I the trust https?

I can understand how this can block sites, but not some part of data from a site.
It will not help OP that like to do it with a MT Router.
by Jotne
Tue Dec 28, 2021 6:50 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

So untangle will help here? (I have not looked at it)
by Jotne
Tue Dec 28, 2021 6:45 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 313052

Re: ZeroTier added to RouterOS v7.1rc2

This is where Zerotier can help
And when will we get Zerotier on other Routers, (MIPS)?
by Jotne
Tue Dec 28, 2021 2:19 pm
Forum: Scripting
Topic: Cool console
Replies: 4
Views: 2992

Re: Cool console

Here is script rewritten to work with 7.x RouterOS Output You are logged into: Link123-Remote ############### system health ############### Uptime: 6d06:02:27 d:h:m:s | CPU: 100% RAM: 41504/65536M | Voltage: 12.2 v | Temp: 14c ############# user auth details ############# Hotspot online: 0 | PPP onl...
by Jotne
Tue Dec 28, 2021 1:34 pm
Forum: Scripting
Topic: Cool console
Replies: 4
Views: 2992

Re: Cool console

The script gives a login page with info about Router health and a list of hotspot and ppp users. Its ok for a single router management. The way system resources are being presented are change in v7. This shows how I collect it from RouterOS in a script to get it inn to Splunk (that I do use to monit...
by Jotne
Tue Dec 28, 2021 11:45 am
Forum: Scripting
Topic: Cool console
Replies: 4
Views: 2992

Re: Cool console

Do you have the script, page is blank?
by Jotne
Tue Dec 28, 2021 9:13 am
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

The Untangle admin will never turn Web Filter off ,,,, the level of sophistication is significant: So this solution does not work if you do not have 100% control of all clients in the network. PaloAlto and Forcepoint (and other) also have solution that change the certificate and examines all the pa...
by Jotne
Mon Dec 27, 2021 8:11 pm
Forum: General
Topic: Port forwarding not working.
Replies: 3
Views: 1193

Re: Port forwarding not working.

Do you need two firewall? If not remove one.
by Jotne
Mon Dec 27, 2021 8:08 pm
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14378

Re: Where is UPS?

You can downgrade, but not sure if config would be ok. Going from 6.x to 7.x router my convert some config.
So a backup before upgrade. And do not upgrade on production equipment before you have test that an upgrade goes well on a test system.
by Jotne
Mon Dec 27, 2021 8:06 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

You can block porn by using a solution like Untangle running in conjunction with your RB Router ... Can this block porn when you do a google search for "sex nude" and search filter is turned off? How should Untangle see the different from a search fro "Nasa" or for "sex&quo...
by Jotne
Sun Dec 26, 2021 8:38 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 162469

Re: v7.2rc1 is released!

Here I have a router with around 10 000 addresses in the blocked address list. I have a rule that add any IP that tries any port on my router that is not open, to a bloc list for 24 hour. They have nothing to do on my router. 6.49.2
.
List.jpg
by Jotne
Sun Dec 26, 2021 7:11 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 162469

Re: v7.2rc1 is released!

This not crash an X86 (running on a VmWare Workstation), it takes it down completely and router will not come back up again.
So DO NOT RUN this on a production router.
by Jotne
Sun Dec 26, 2021 7:08 pm
Forum: General
Topic: Shutdown or not to shutdown
Replies: 6
Views: 3262

Re: Shutdown or not to shutdown

Tested "shutdown" on a SXT 5HPnD and it just made a reboot.
So for me "shutdown" could be removed.
by Jotne
Sun Dec 26, 2021 12:59 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 227353

Re: v7.1.1 is released!

You see what i did reply to in the quote. All v7 are still in early stage. If you do not need it, and all are ok with 6.x, use 6.x
And if 7.x works fine, no problem use it. Its up to you to test to see if it fits your needs.
by Jotne
Sun Dec 26, 2021 12:24 pm
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14378

Re: Where is UPS?

RB951G still works fine with v6.x of software, so you do not need to upgrade.
by Jotne
Sun Dec 26, 2021 12:22 pm
Forum: General
Topic: Shutdown or not to shutdown
Replies: 6
Views: 3262

Shutdown or not to shutdown

When you like to reboot or take down the router, are there any need for do a shutdown?
I can see message after reboot that the router was not properly shutdown.

This question apply to RouterBoard as well as CHR/X86 routes.
by Jotne
Sun Dec 26, 2021 11:45 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 227353

Re: v7.1.1 is released!

So 7.1.1 and 7.2rc1 are versions to stay away from?
If you read the may comments in the 7.x threads, you see the following comments.

Do your router work fine with 6.x software and you do not need any of the new 7.x functions, stick with 6.x
by Jotne
Sun Dec 26, 2021 9:42 am
Forum: Announcements
Topic: Happy holidays!
Replies: 29
Views: 19736

Re: Happy holidays!

The new logo?
.
channels4_profile.jpg
by Jotne
Sun Dec 26, 2021 9:32 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 227353

Re: v7.1.1 is released!

If look more carefully %) - on one screenshot above you can see profile open for 7.1.1
From latest picture, it seems that 7.1.1 uses one CPU compare to the 6.49 that uses 8?
by Jotne
Sun Dec 26, 2021 9:28 am
Forum: Scripting
Topic: Mikrotik synthesizer/piano programs
Replies: 23
Views: 20620

Re: Mikrotik synthesizer/piano programs

If you could use array for creating commands like here in this post, could would be much shorter.
viewtopic.php?p=900392#p900392
by Jotne
Sat Dec 25, 2021 11:01 pm
Forum: Scripting
Topic: Super Mario Theme
Replies: 49
Views: 66989

Re: Super Mario Theme

Isn't this just the same, but just with more wrapped lines?
by Jotne
Sat Dec 25, 2021 10:20 pm
Forum: Scripting
Topic: Super Mario Theme
Replies: 49
Views: 66989

Re: Super Mario Theme

Jingle Bells based on data posted by ALIEN360 and format by Eworm :local Beeps { { 659; 150 }; 300; { 659; 150 }; 300; { 659; 500 }; 600; { 659; 150 }; 300; { 659; 150 }; 300; { 659; 500 }; 600; { 659; 150 }; 300; { 783; 150 }; 300; { 523; 400 }; 500; { 587; 75 }; 100; { 659; 950 };1200; { 698; 150 ...
by Jotne
Sat Dec 25, 2021 9:24 pm
Forum: General
Topic: Nat Hairpin in Router OS 7.1.1
Replies: 16
Views: 7754

Re: Nat Hairpin in Router OS 7.1.1

In nat, you do not need to specify to-port while its equal to dst-port add action=dst-nat chain=dstnat dst-address=217.72.x.xxx dst-port=80 protocol=tcp to-addresses=192.168.29.174 to-ports=80 could be written: add action=dst-nat chain=dstnat dst-address=217.72.x.xxx dst-port=80 protocol=tcp to-addr...
by Jotne
Sat Dec 25, 2021 5:08 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

It was just to show that trying to block some are more complicated and nearly impossible today.
by Jotne
Sat Dec 25, 2021 4:34 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 19136

Re: How do I block pronographic images in my RB?

Turn off safe search on your google search

Do a search for example for "sex nude"
Select picture.

To block this, you need to have 100% control of the PC.
You can block google.com, but then just use bing.com instead. Same problem.
by Jotne
Sat Dec 25, 2021 1:19 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 227353

Re: v7.1.1 is released!

You dont have a picture of "Profile" while CPU running high try to see what module cause the problem?
I only see picture while all are ok.
by Jotne
Fri Dec 24, 2021 11:20 pm
Forum: Announcements
Topic: v6.49.2 [stable] is released!
Replies: 64
Views: 125074

Re: v6.49.2 [stable] is released!

Mine works fine with:
https://dns.nextdns.io/dns-query
and Verify Certificate selected.
by Jotne
Thu Dec 23, 2021 3:40 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Also usable for example to monitor ZeroTier participants on your "cloud" LAN.
Do ZeroTier work more or less like Wireguard with no logging on connecting/up/down etc?
If yes, this can be used for ZeroTier as well.
by Jotne
Thu Dec 23, 2021 2:51 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

Your script are fine. Have got many tips from your posts over time, so keep up the good work. :)

Lets say some hack your server where your script are stored and add some extra code. (ref Solarwinds)
Off course you can read through what has been downloaded, but its not easy to debug scripts :)
by Jotne
Thu Dec 23, 2021 1:58 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Next version will have a dashboard for Netwatch. With that you can keep track of when devices goes up and down.
It can also be used to monitor the stateless Wireguard VPN that can not be monitored as normal VPN can.
.
netwatch.jpg
by Jotne
Thu Dec 23, 2021 1:43 pm
Forum: General
Topic: How do you configure RouterOS? Poll
Replies: 11
Views: 2235

Re: How do you configure RouterOS? Poll

Ups, all votes gone while updating poll. You can rewote.
by Jotne
Thu Dec 23, 2021 1:20 pm
Forum: General
Topic: How do you configure RouterOS? Poll
Replies: 11
Views: 2235

How do you configure RouterOS? Poll

This is just a small poll to see how people are configuring their RouterOS.
by Jotne
Thu Dec 23, 2021 1:14 pm
Forum: Beginner Basics
Topic: Upgraded to 6.49.2 - no more access - "Wrong Username or Password" [SOLVED]
Replies: 22
Views: 9617

Re: Upgraded to 6.49.2 - no more access - "Wrong Username or Password" [SOLVED]

And the password printed on the outside of the Cube 60 .... :? :shock:
And good to know the password while it hanging outside of the house as well :)
by Jotne
Thu Dec 23, 2021 12:34 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

You are promoting Splunk for Mikrotik. Would you expect someone interested to copy and paste manually every single file required to use it? True. But when I see how many MT routers that has been hacked and that script has been installed, I am very carefully on what is going on in my router. How may...
by Jotne
Thu Dec 23, 2021 12:31 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

Trail and error.
by Jotne
Thu Dec 23, 2021 11:20 am
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

You need to take out the host variable to a new variable before using it. After more rewriting and simplifying this would be ok for me: :local Host $host /tool netwatch :local Status [get [find where host="$Host"] status] :local Comment [get [find where host="$Host"] comment] :lo...
by Jotne
Thu Dec 23, 2021 8:31 am
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

Hmm.

I do not see the scripts on the linked page. I do not want to install some script from a remote site using script.
Its importante for me to see trough anything that will be used on my router. So for me its cut/past.
by Jotne
Thu Dec 23, 2021 8:16 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 227353

Re: v7.1.1 is released!

romon doesn't work btw v6 and v7 Connect Rommon -> RB750Gr3 6.48.4 -> Rommon to SXT 5HPnDr2 7.2rc1 OK Connect Rommon -> RB750Gr3 6.48.4 -> Rommon to CHR 7.1 OK Connect Rommon -> RB750Gr3 6.48.4 -> Rommon to CHR 7.2rc1 OK Connect Rommon -> SXT 5HPnDr2 7.2rc1 -> Rommon to RB750Gr3 6.48.4 OK Connect R...
by Jotne
Wed Dec 22, 2021 11:29 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

Quote around myComment is needed if the comment has space.
by Jotne
Wed Dec 22, 2021 10:35 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

Off course it works directly. It just that more heads works better than one. :D This version works fine thanks to pe1chl guiding in correct direction. /tool netwatch :local myStatus [get [find where host="$host"] status] :local myComment [get [find where host="$host"] comment] :i...
by Jotne
Wed Dec 22, 2021 10:04 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

Here is my version that can be used with my Splunk. ######################################################################### # A single script to manage Netwatch ######################################################################### :local myStatus "" :local myComment "" # Ha...
by Jotne
Wed Dec 22, 2021 8:41 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

@howdey57 Nice script. Just simplified it some. /tools netwatch not needed in all command. Just go to correct location before script. number= not needed, removed. ######################################################################### # A single script to manage Netwatch ##########################...
by Jotne
Wed Dec 22, 2021 8:25 pm
Forum: Scripting
Topic: Find function with IP address condition [SOLVED]
Replies: 4
Views: 4689

Re: [SOLVED] - Find function with IP address condition [SOLVED]

And also in missing = after in.
None of my routers works without the =
by Jotne
Wed Dec 22, 2021 2:18 pm
Forum: General
Topic: WireGuard config not shown in export (7.1 and 7.2rc1)
Replies: 7
Views: 4873

Re: WireGuard config not shown in export (7.1 and 7.2rc1)

Ok So after import the private key, it will then generate the public key. And a print on the interface show both key. Still learning some every day :) /interface/wireguard> print Flags: X - disabled; R - running 0 R name="wireguard1" mtu=1420 listen-port=13231 private-key="xxxxxxxx/b6...
by Jotne
Wed Dec 22, 2021 2:04 pm
Forum: General
Topic: WireGuard config not shown in export (7.1 and 7.2rc1)
Replies: 7
Views: 4873

Re: WireGuard config not shown in export (7.1 and 7.2rc1)

Did not know about that command, but still does not give the public key?
/interface/wireguard> export  show-sensitive
/interface wireguard
add listen-port=13231 mtu=1420 name=wireguard1 private-key="xxxxxxxxxxxxxx/b6WPzqcBXUeMClAQiBjZZ7YSKVfnQ="
by Jotne
Wed Dec 22, 2021 1:08 pm
Forum: Announcements
Topic: Happy holidays!
Replies: 29
Views: 19736

Re: Happy holidays!

Happy Hollidays to MT as well. And tanks for all the good work and get the 7.x released :)

🎄
by Jotne
Wed Dec 22, 2021 1:07 pm
Forum: General
Topic: WireGuard config not shown in export (7.1 and 7.2rc1)
Replies: 7
Views: 4873

WireGuard config not shown in export (7.1 and 7.2rc1)

When you do an export of WireGuard config on 7.1 and 7.2rc2, it does not show the public and private keys doing an export. As far as I have seen only way to get the keys are in WinBox. Peer configuration shows the remote key: /interface wireguard add listen-port=13231 mtu=1420 name=wireguard1 /inter...
by Jotne
Tue Dec 21, 2021 11:07 pm
Forum: General
Topic: Forum is suddenly slow
Replies: 12
Views: 2196

Re: Forum is suddenly slow

Was down some minutes ago for me as well. 15 min later and forum started to work again.
by Jotne
Tue Dec 21, 2021 11:03 pm
Forum: RouterOS beta
Topic: socks5 not working in routeros7 ! [SOLVED]
Replies: 68
Views: 26111

Re: socks5 not working in routeros7 ! [SOLVED]

A good tip, block it once and for all.
by Jotne
Tue Dec 21, 2021 10:57 pm
Forum: RouterOS beta
Topic: v7.1 "STABLE" Cosmetic Bug - MNDP - Neighbor Version Hardcoded - Forgotten [SOLVED]
Replies: 14
Views: 6928

Re: v7.1 "STABLE" Cosmetic Bug - MNDP - Neighbor Version Hardcoded - Forgotten [SOLVED]

Seems to me that you should start read more forum posts. 7.1 was released in test train. But after som more testing it was decided that it was stable enough to call stable. So at the download page it was moved from testing to stable without updating the software it self. How hard could that be to un...
by Jotne
Tue Dec 21, 2021 6:51 pm
Forum: Scripting
Topic: Find function with IP address condition [SOLVED]
Replies: 4
Views: 4689

Re: Find function with IP address condition [SOLVED]

I have not time or possibility to test all, but for me the script does not work at all without = after in. No need to add ; after all lines, only between multiple commands on same line. You can save some by go to correct folder before running commands so some rewriting Edit as eworm writes, it may b...
by Jotne
Tue Dec 21, 2021 5:46 pm
Forum: RouterOS beta
Topic: socks5 not working in routeros7 ! [SOLVED]
Replies: 68
Views: 26111

Re: socks5 not working in routeros7 ! [SOLVED]

socks5 now ok in 7.2rc1 is, but 7.1.1 still problem
There are no need to post the same in 3 threads!!!!
We can all read the change logs.
by Jotne
Tue Dec 21, 2021 3:54 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 162469

Re: v7.2rc1 is released!

Thanks,
RB5009 ok and can finally see temp.
Can you post the output of this command, Just to see what info a RB50090 gives out:
{
:put [/system/routerboard/get model]
:foreach id in=[/system health find] do={
	:local health "$[/system health get $id]"
	:put "$health"
}
}
by Jotne
Tue Dec 21, 2021 3:22 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 162469

Re: v7.2rc1 is released!

What a long list of fixes. A nice x-mas present :) Still very slow export on some routes with limited CPU Nearly same "simple" configuration on two test 5Hz routers. SXT 5HPnD r2 600mHz Export: 4seconds SXT 5HPnD 400mHz Export: First run: around 4-5 min. Second run after 6min and only 30% ...
by Jotne
Tue Dec 21, 2021 2:08 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

1. Look up the $host IP address on your DHCP leases. Give the lease a name. (I do that)
I use Netwatch to ping WireGuard tunnel IP and that is not DHCP based.
So based on your tips, I can add it to DNS and do a lookup from the Script and get the name from there.
by Jotne
Tue Dec 21, 2021 12:08 pm
Forum: General
Topic: Winbox GUI Filter Feature / Button
Replies: 17
Views: 6247

Re: Winbox GUI Filter Feature / Button

But there is a bug with "contains". We will fix that
Jippi

Contains should work like the tilde ~ in most program.
by Jotne
Tue Dec 21, 2021 12:02 pm
Forum: General
Topic: feature request: expose variables to netwatch scripts
Replies: 39
Views: 10004

Re: feature request: expose variables to netwatch scripts

I would like that comment also are sent from the netwatch to the sctipt. This way I would get both IP ($host) and device to watch using comment ($comment) My up/down netwatch scipt used with WireGuard add dont-require-permissions=yes name=WireGuard_down source=\ ":log info message=\"vpn=wi...
by Jotne
Tue Dec 21, 2021 11:46 am
Forum: Scripting
Topic: Script INFO connection Wireguard?
Replies: 17
Views: 10193

Re: Script INFO connection Wireguard?

If you have many WireGuard VPN, it will be very cluttered with may scripte (2 fore each vpn). So you can use $host in the script that will then show the IP of the monitored VPN server. Here is my up down script that I use to monitor VPN. Just add one netwatch for each VPN to monitor. add dont-requir...
by Jotne
Tue Dec 21, 2021 9:04 am
Forum: General
Topic: Remote Logging and Kiwi Syslog [SOLVED]
Replies: 26
Views: 8442

Re: Remote Logging and Kiwi Syslog [SOLVED]

Post your complete configuration. As Sob writes, normally there are no rules blocking outgoing traffic, so you has added some your self.
/export hide-sensitive
by Jotne
Mon Dec 20, 2021 2:39 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Upgraded to 3.5 Happy Xmas 🎄 🎁 # 3.5 (20.12.2021) # Changed from IP Accounting to Kid Control to get accounting data to work with 7.x RouterOS # Renamed "MikroTik Volt/Temperature" to "MikroTik Health" # Added more info to "Mikrotik Health" Since the new app now uses Ki...
by Jotne
Mon Dec 20, 2021 9:21 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.4 (Graphing everything) &#128190; &#128736; &#128187; &#1282

# Script version 4.8 # Change to kid kontroll for accounting (needs to be fixed) # Fixed possibility to turn off account data # Updated health section to get all health info on old and new system to work better with 7.x To upgrade, just cut/past the script to all router. (script found in first post)...
by Jotne
Fri Dec 17, 2021 3:28 pm
Forum: Beginner Basics
Topic: Scheduler Wi-Fi Off/On at Night
Replies: 5
Views: 5735

Re: Scheduler Wi-Fi Off/On at Night

turning off at night 23:00-07:00 every day.
This worked 10 years ago to keep children from using internet.
Now day everyone has Mobil Internet, or they connect to friends phone or neighbors wifi :)
by Jotne
Fri Dec 17, 2021 11:28 am
Forum: RouterOS beta
Topic: Export on Hap lite
Replies: 4
Views: 2379

Re: Export on Hap lite

Seems many post about this. It looks like its not fixed, and are very slow on Routers with limited CPU. For me it works, just takes loong time on a 400Mhz A radio. Same radio with 600Mhz is better.
by Jotne
Thu Dec 16, 2021 3:30 pm
Forum: Beginner Basics
Topic: Firewall question.
Replies: 10
Views: 1733

Re: Firewall question.

Try to move the drop rule higher in the rule stack.
Firewall rules are always tested from top to bottom, so if it hits a rule higher up, your block rule will not hit anything.
by Jotne
Thu Dec 16, 2021 3:25 pm
Forum: Beginner Basics
Topic: Minecraft server not accessible from WAN
Replies: 37
Views: 9223

Re: Minecraft server not accessible from WAN

Since some routes give 8 and other 9, for sure some will fail.
I would have talked to my ISP and asked why this happens.
by Jotne
Thu Dec 16, 2021 2:37 pm
Forum: Scripting
Topic: Dates manipulation module
Replies: 6
Views: 7975

Re: Dates manipulation module

This
viewtopic.php?t=181327
may simplify everything.
by Jotne
Thu Dec 16, 2021 2:34 pm
Forum: Beginner Basics
Topic: Minecraft server not accessible from WAN
Replies: 37
Views: 9223

Re: Minecraft server not accessible from WAN

The external IP address given by canyouseeme is not the same as when I google "my ip". The IP's are identical except for the last number which is 9 instead of 8. Then you have a problem. It may seems that you have several public IP? Try some other locator: https://www.whatismyip.com/ http...
by Jotne
Thu Dec 16, 2021 11:36 am
Forum: Scripting
Topic: time parsing in 7.1
Replies: 8
Views: 6001

Re: time parsing in 7.1

I noticed the new :timestamp function in v7.1 Interesting. I have used time in a script here https://forum.mikrotik.com/viewtopic.php?p=743875#p743875 to get a 5 min window. Problem with the standard time function is that it only gives hour, but when it passes midnight it uses full date/time. This ...
by Jotne
Thu Dec 16, 2021 10:56 am
Forum: Beginner Basics
Topic: Minecraft server not accessible from WAN
Replies: 37
Views: 9223

Re: Minecraft server not accessible from WAN

Use this to test your port config.
https://canyouseeme.org/

Add your MC port and click check. If all is ok, you should get a green success.
by Jotne
Wed Dec 15, 2021 2:58 pm
Forum: Scripting
Topic: WireGuard peer auto generation
Replies: 1
Views: 5544

Re: WireGuard peer auto generation

Just a quick programming note.

You do not need the ; at end of each line. Only needed when there are multiple commands on same line.
by Jotne
Mon Dec 13, 2021 7:12 am
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 229748

Re: v7.1 is released!

Hi, The new NTP client in 7.1 is having a very hard time synchronising the clock on an RB750Gr3. Is this a problem with the new NTP client or is it showing an issue with the hardware clock in the device? Did you have a problem with 6.x software? I have no problem with my 7.x clients (not RB750Gr3) ...
by Jotne
Sun Dec 12, 2021 9:17 pm
Forum: General
Topic: Blocking Youtube Mobile and QUIC Protocol 2021
Replies: 2
Views: 4760

Re: Blocking Youtube Mobile and QUIC Protocol 2021

Did you read this thread?
viewtopic.php?t=166748
by Jotne
Sat Dec 11, 2021 6:27 pm
Forum: Announcements
Topic: v6.48.6 [long-term] is released!
Replies: 126
Views: 277975

Re: v6.48.6 [long-term] is released!

The question is what was the CAUSE that anything prior to 6.41.4 was bricked.
Why did you not upgrade before? 6.41.4 was released more than 3 1/2 year ago.
You have missed out lots of security fixes.
by Jotne
Sat Dec 11, 2021 6:21 pm
Forum: Announcements
Topic: Mēris botnet information
Replies: 75
Views: 230099

Re: Mēris botnet information

What if the upgrade on a remote router goes wrong. Who would fix that and who would pay for some to fix it.
by Jotne
Sat Dec 11, 2021 5:22 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 369
Views: 128354

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.4 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Next version will have better health and works better with 7.1

Here is an example on Routers giving PSU State
.
psu_state.jpg
by Jotne
Sat Dec 11, 2021 4:44 pm
Forum: RouterOS beta
Topic: Health readings with v7 [SOLVED]
Replies: 50
Views: 26090

Re: Health readings with v7 [SOLVED]

Anyone know what this shows when a PSU is bad?
.id=*1ce9;name=psu1-state;type=;value=ok
Edit:
It may be "fail" as show in this post:
viewtopic.php?t=141553
by Jotne
Sat Dec 11, 2021 3:39 pm
Forum: Announcements
Topic: v6.48.6 [long-term] is released!
Replies: 126
Views: 277975

Re: v6.48.6 [long-term] is released!

Thank You Mikrotik staff for releasing routeros in long-term branch that makes my life so much more interesting. And you did test the software on equal routers with same config and software version at a local site before you did the upgrade? And you did also upgrade at the same time as software was...
by Jotne
Sat Dec 11, 2021 3:32 pm
Forum: Announcements
Topic: Mēris botnet information
Replies: 75
Views: 230099

Re: Mēris botnet information

Or remove AVAST. I never have had any problem with built in Microsoft Defender. Not sure if AVAST is better or worse than MD, but what I know is that many running both and that is not good at all. So if you pay (there are free version) for AVAST and it does not give any more than MD why pay. Also MD...