Community discussions

MikroTik App

Search found 180 matches

by tomislav91
Tue Feb 23, 2021 4:21 pm
Forum: Scripting
Topic: get src ip from destination in firewall
Replies: 3
Views: 178

Re: get src ip from destination in firewall

Do you get any output from running this form command prompt
:put [/ip firewall nat find where dst-address=192.168.0.0/16]
nope
by tomislav91
Tue Feb 23, 2021 11:10 am
Forum: Scripting
Topic: get src ip from destination in firewall
Replies: 3
Views: 178

get src ip from destination in firewall

:local LocalSubnet [:pick [/ip firewall nat find where dst-add ress=192.168.0.0/16] src-address]]; idea is to use local subnet for further scripting and i have one rule in nat and i want to exclude from that, so src subnets are different but that dst subnet are the same allways, so i want to get th...
by tomislav91
Tue Feb 23, 2021 11:04 am
Forum: General
Topic: block internet access but allow some sites - NOT WORKING
Replies: 7
Views: 385

Re: block internet access but allow some sites - NOT WORKING

Sites blocking is never going to work. At some point user will start using VPN provider and there is no way to block it (e.g. NordVPN can use 443 over TCP as well as obfuscated traffic). we are speaking about users inside company, for sure they will not use vpns. i just wanted to use outlook web, n...
by tomislav91
Mon Feb 22, 2021 11:27 pm
Forum: General
Topic: block internet access but allow some sites - NOT WORKING
Replies: 7
Views: 385

block internet access but allow some sites - NOT WORKING

i have two rules add action=accept chain=forward dst-address-list=\ AllowedSites dst-port=80,443 protocol=tcp \ src-address=192.168.50.181 add action=drop chain=forward dst-address=0.0.0.0/0 \ src-address=192.168.50.181 and in AllowedSites list is a list of IPs for outlook from their website https:/...
by tomislav91
Fri Feb 05, 2021 11:28 am
Forum: General
Topic: should i put parent queue
Replies: 0
Views: 140

should i put parent queue

Should i put parent queue if i enable only one client or i can only put it in lower ID?
So if i have 192.168.5.0/24 and client 192.168.5.22, my q is is it neccesary to put in advanced tab Parent queue?
by tomislav91
Tue Jan 26, 2021 8:55 pm
Forum: General
Topic: can i assign pool for some mac addresses?
Replies: 0
Views: 133

can i assign pool for some mac addresses?

I am having several end devices and i want to get some range of pool of somesubnet, i will create seperate pool, but how to force that those mac adresses use that pool? I am aware that only first 3 octet in MAC define device, but i will script it somehow, but cant figure out how to force dhcp pool w...
by tomislav91
Tue Dec 29, 2020 8:42 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 61388

Re: v6.48 [stable] is released!

Does this affect some Stellaris microcontrollers, because i am having some issue with communication? Maybe some have information?
by tomislav91
Tue Dec 29, 2020 2:42 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 61388

Re: v6.48 [stable] is released!

Trusted checkbox appears twice in Bridge -> Ports -> <interface> -> General
What that use for?
by tomislav91
Thu Dec 24, 2020 11:05 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

I'm afraid it's the in-state-sequence-errors value - it doesn't sound related, but apparently there is no separate counter for packets encrypted using a wrong key. So whenever this counter increases, there is at least one "miskeyed" SA. Go to command line of the pfsense and try ip xfrm st...
by tomislav91
Mon Dec 21, 2020 2:51 pm
Forum: Scripting
Topic: Auto update problems
Replies: 3
Views: 439

Re: Auto update problems

This is what i use /system script add dont-require-permissions=no name=firmware-updater owner=admin policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="\ \r\ \n\r\ \n\r\ \n# Script name: firmware-updater\r\ \n\r\ \n########## Set variables\r\ \n\r\ \n\r\ \n## Backu...
by tomislav91
Mon Dec 21, 2020 2:47 pm
Forum: Scripting
Topic: Disable and Enable interface
Replies: 16
Views: 1228

Re: Disable and Enable interface

msatter understood your question and pointed you in the right direction. The linked post contains all you need to know to create a failover solution. Next time, don't quite entire posts especially if it's the most recent post you are replying to.. thanks :) I understand what you say friend, but the...
by tomislav91
Thu Dec 17, 2020 9:33 pm
Forum: Scripting
Topic: Disable and Enable interface
Replies: 16
Views: 1228

Re: Disable and Enable interface

Very limited info you provide, but if my understanding is correct, then there is a problem with your logic. i.e. you ping 8.8.8.8 from ether 2, if no response, you disable interface, with this interface disabled, you will not be able to ping from it. If reasons for doing this is dual WAN purposes, ...
by tomislav91
Thu Dec 17, 2020 2:48 pm
Forum: Scripting
Topic: Disable and Enable interface
Replies: 16
Views: 1228

Re: Disable and Enable interface

Greetings friends: I have the following script that disables an interface of my RB when it pings google DNS and they do not respond, I need that same interface to be enabled when google DNS respond to ping, someone can help me. I leave the script that I have. :if ( [/ping 8.8.8.8 interface= "E...
by tomislav91
Thu Dec 17, 2020 2:43 pm
Forum: Scripting
Topic: most useful script in reallife scenarios
Replies: 0
Views: 247

most useful script in reallife scenarios

What are those scripts that really help in some various problems you had? We have a topic useful scripts but that topic goes off road.
So just post scripts and tell what did or do use for.
by tomislav91
Tue Dec 15, 2020 12:57 pm
Forum: General
Topic: Winbox-OpenVPN [SOLVED]
Replies: 7
Views: 449

Re: Winbox-OpenVPN [SOLVED]

do you add allow ip in /ip services?
by tomislav91
Fri Dec 11, 2020 11:18 pm
Forum: Useful user articles
Topic: which book to buy
Replies: 2
Views: 545

which book to buy

Do you have some propose of which book to buy. Not for completely beginers. I found this https://www.amazon.com/Theory-laboratories-exercises-Mikrotik-RouterOS/dp/1686046960 https://www.amazon.com/Networking-MikroTik-MTCNA-Study-Guide/dp/1973206358/ref=pd_sbs_14_2/139-7552241-6977159?_encoding=UTF8&...
by tomislav91
Tue Dec 01, 2020 11:44 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

None of those firewall rules blocks IPsec as such, nor do they block traffic to/from the subnets reachable via IPsec (unless you've added them to the shodan or pingers or @Services_Phase3 address lists). In fact, the firewall rules block almost nothing. In the printout of the security associations,...
by tomislav91
Tue Dec 01, 2020 10:09 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

That's magic. First, the IPsec control packets and transport packets are handled by chains input and output. Payload packets from/to external devices, which get extracted from IPsec transport packets, and which are going to be encapsulated into IPsec transport packets, are handled by chain forward....
by tomislav91
Fri Nov 20, 2020 9:43 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

I migrate ether1 to ether5 and ether2 to ether6 and now seems ok. I will be waiting to Monday to check all, but it seems ok for now. Thanks sindy. Can we somehow improve firewall rules? # nov/02/2020 13:32:24 by RouterOS 6.47.4 add action=fasttrack-connection chain=forward connection-mark=!ipsec \ c...
by tomislav91
Thu Nov 19, 2020 11:37 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

just for info, how you get 410 or 160mbit/s if total traffic is inclued? What you summarize here? ( in first case of 410Mbit i cant get that if i summarize ether1+ether2 tx and rx bits /s) Assuming that the own traffic of the router (sent by the router itself or received by the router itself) is ne...
by tomislav91
Wed Nov 18, 2020 8:24 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

I don't get why you are so fond of images where text is much more useful for post-processing. So roughly, when the DVR/monitor wall receiving the streams from the cameras is reachable (when the external switch is connected to ether3), the machine routes about 410 Mbit/s of traffic (and decrypts a g...
by tomislav91
Wed Nov 18, 2020 8:10 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

That's magic. First, the IPsec control packets and transport packets are handled by chains input and output. Payload packets from/to external devices, which get extracted from IPsec transport packets, and which are going to be encapsulated into IPsec transport packets, are handled by chain forward....
by tomislav91
Wed Nov 18, 2020 8:09 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

That's magic. First, the IPsec control packets and transport packets are handled by chains input and output. Payload packets from/to external devices, which get extracted from IPsec transport packets, and which are going to be encapsulated into IPsec transport packets, are handled by chain forward....
by tomislav91
Tue Nov 17, 2020 11:02 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

So the additional CPU spent on IPsec encryption and decryption per packet does not explain the non-linear growth of the CPU load as the video traffic is added to the mix. At this moment I've got no further ideas. The product page provides no information regarding IPsec throughput of your CCR1009-8G...
by tomislav91
Tue Nov 17, 2020 6:53 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

Is the other (non-video) traffic coming IPsec-encrypted as well? they are just in terms of ipsec watching cameras. Any other job is standard job as in any office. Sorry, I understand every single word but not the answer as a whole. So again - does any other traffic except the one from cameras need ...
by tomislav91
Tue Nov 17, 2020 3:41 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

I don't get why you are so fond of images where text is much more useful for post-processing. So roughly, when the DVR/monitor wall receiving the streams from the cameras is reachable (when the external switch is connected to ether3), the machine routes about 410 Mbit/s of traffic (and decrypts a g...
by tomislav91
Tue Nov 17, 2020 11:16 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

Looking at the file, those about 250 Mbit/s sent out via ether3 are sent as 21000 packets/s in 1500-byte packets, hence I assume the cameras send the video using TCP. The ACK traffic in the opposite direction takes some 9000 packets/s in 64-byte frames (which is fine, TCP doesn't necessarily acknow...
by tomislav91
Mon Nov 16, 2020 4:03 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

no, that bridge is for video surveillance center. So there is no much l2 traffic in the bridge there. Funny thing is that when i disable that bridge or just pull out cables, cpu level is OK, about 10-20%. As you've mentioned video surveillance, two things come to my mind - the cameras may be sendin...
by tomislav91
Mon Nov 16, 2020 1:04 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

You may misunderstand that tx and rx. In the list of interfaces, the bridge is an interface through which the router (L3) part of the software sends data to external devices connected to the physical ports included into the bridge, which is the download direction for those devices. Or in generic ca...
by tomislav91
Sun Nov 15, 2020 4:49 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

can you explain, in the bridge i can see that Tx (transmit=upload) is 246Mb and in queue for that subnet Download is 233Mbps. Like is vice versa? Or I missunderstand that tx and rx? Also when try to speedtest from that 192.168.90.0 subnet upload is 0 (all switches changed) 2020-11-15 15_46_43-Window...
by tomislav91
Fri Nov 13, 2020 11:35 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

i changed switches, but no signifcally changes
2020-11-13 22_34_55-Window.png
by tomislav91
Mon Nov 09, 2020 9:31 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

Officially, the 192.168.90.1/24 should be attached to bridgeVN rather than ether3_HQCAM . Practically I have never seen this wrong setup to cause any issues, and even the ROS upgrade script migrating configurations from old "master port" to current "bridge with hardware acceleration&...
by tomislav91
Sun Nov 08, 2020 8:29 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

Then why doesn't the picture match the configuration? 192.168.90.0/24 is attached to ether3_HQCAM in that configuration; the bridge exists there but has no member ports and no IP configuration is attached to it. Are you constantly updating the configuration? Yeah, i am seeing that now in the my pos...
by tomislav91
Sun Nov 08, 2020 8:12 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

Not knowing what linux distribution pfSense is based on, nor which IPsec implementation it uses (openswan, strongswan, something else), I cannot give you a more targeted suggestion. Did you issue that command as a linux user with root privileges, or is there some restricted command line of the pfSe...
by tomislav91
Sun Nov 08, 2020 4:48 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

Are we still talking about the machine where the IPsec tunnels are running? I'm asking because in its configuration export, I've found just an empty bridge with no ports at all. It is theoretically possible that there is so much traffic towards the devices connected to the switches with only 100 Mb...
by tomislav91
Sat Nov 07, 2020 12:32 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

Što si htio da rekneš ovom rječenicom: "I notice that one bridge when disable cpu goes regular about 10%."? i have one bridge with ports and 200Mb+ bandwidth within. when i disable it, cpu % is ok, there is no loop in network, log also dont write anything. can be problem within 100mb swit...
by tomislav91
Fri Nov 06, 2020 3:30 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

I am getting cpu about 70%.
I notice that one bridge when disable cpu goes regular about 10%.
2020-11-06 14_28_09-Window.png
is it possibly because link is more than 100mb and pc are only 100mb and thats what suffocate a router cpu?
by tomislav91
Mon Nov 02, 2020 2:50 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

but fasttrack connection for that is disabled, should i enable that also? No, don't enable the fasttrack connection. The steps need to be taken one by one to see where is the issue. So first you enable only the additional mangle rules and the additional rules in input in filter. If that works, we c...
by tomislav91
Mon Nov 02, 2020 2:39 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

With. They are in forward, aren't they? yes, they are add action=mark-connection chain=prerouting connection-mark=no-mark dst-port=53 \ layer7-protocol=*4 new-connection-mark=block_connection passthrough=yes \ protocol=udp add action=mark-packet chain=prerouting connection-mark=block_connection \ n...
by tomislav91
Mon Nov 02, 2020 2:31 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

That's magic. First, the IPsec control packets and transport packets are handled by chains input and output. Payload packets from/to external devices, which get extracted from IPsec transport packets, and which are going to be encapsulated into IPsec transport packets, are handled by chain forward....
by tomislav91
Mon Nov 02, 2020 1:13 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

OK, and with these three mangle rules enabled, everything works fine? What about the difference in CPU load when the "accept connection-state=!new" is enabled and when it is disabled, is there any? no no, it wasnt fine. I added this with /ip firewall filter add action=fasttrack-connection...
by tomislav91
Mon Nov 02, 2020 1:03 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

I'm afraid it's the in-state-sequence-errors value - it doesn't sound related, but apparently there is no separate counter for packets encrypted using a wrong key. So whenever this counter increases, there is at least one "miskeyed" SA. Go to command line of the pfsense and try ip xfrm st...
by tomislav91
Mon Nov 02, 2020 12:08 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

Without the actual encryption and authentication keys in use, it is not sufficient, as you can only confirm that it is a rekey issue by comparing the keys at both ends for same SPIs. Can you show me you /ip ipsec statistics print ? There is a counter which grows with each packet coming through the ...
by tomislav91
Mon Nov 02, 2020 12:06 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

i cant enable JUST those three in mangle, because here i mangle some subnet and force it to another ISP in routes and also using for VOIP, so i cant disable it. I had in mind "out of the rules added by my recommendation, enable only the three added to mangle, not the drop ones in filter"....
by tomislav91
Mon Nov 02, 2020 11:22 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

Let's keep the threads (firewall and IPsec) separate. Here, try to enable only the three mangle rules you've added, but keep those drop ones, which you've eventually added since the point in time when it was working, disabled, and tell me how it works. i cant enable JUST those three in mangle, beca...
by tomislav91
Mon Nov 02, 2020 11:17 am
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

In the past, there was an issue in IKEv2 rekey between two Mikrotiks, where in a few percent of rekeys the peers ended up with different keys for the same SA, hence the receiver was rejecting the packets. This particular issue has been fixed somewhere in late 6.43 version. You have one policy per e...
by tomislav91
Sun Nov 01, 2020 5:11 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

i added that firewall mangle rule before those ipsec. I got aproblem that tunnels goes down, msg1 sent error and i must disable all that i newly created and restart peer and than tunnels go up. I can't get how a rule in forward chain of mangle should break IPsec transport and control traffic which ...
by tomislav91
Sun Nov 01, 2020 4:21 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

i tried to make like this :set time [/system clock get time] :local file [/ip ipsec installed-sa print] <--- this fills a (string) variable called file with the output of the print command :local contents [/file get $file contents] <--- this tries to extract the contents of a file whose name is the...
by tomislav91
Sun Nov 01, 2020 3:49 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

is this better? i missread the ipsec in and out in forward. first i add mangle to capture ipsec, router is now at 25,30% Yes, this is yet another way how to do that. With this setup, a packet transported using IPsec is inspected by 1.5 mangle rule on average (those matching on ipsec-policy=out,ipse...
by tomislav91
Sat Oct 31, 2020 11:45 pm
Forum: General
Topic: limit bandwidth on ubiquiti or mikrotik?
Replies: 3
Views: 362

Re: limit bandwidth on ubiquiti or mikrotik?

I prefer to let my router perform routing functionality. Assuming you only use Ubiquiti as accesspoint(s), I would use queues. As you mention subnets...are you using VLAN's (already)? yeah, i am using vlan for guest wifi and private. So i just remove user groups and put unlimited to all networks an...
by tomislav91
Sat Oct 31, 2020 11:37 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

but then i got problem then with dude just "getting stuff" but nothing happend than, and when disable fasttrackk it came and everything is ok. I have explained this in the previous post, which you've quoted as a whole (no idea why you do that) but apparently haven't read or understood it....
by tomislav91
Sat Oct 31, 2020 8:22 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

So you think this is the best rules to put it on top There is no such thing as "the top of filter". There is the top of chain input in filter, and there is the top of chain forward in filter. Packets always only go through one of these rule chains, not both. So the default firewall of the...
by tomislav91
Sat Oct 31, 2020 6:07 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

my q was, does it something thats a MUST HAVE this input chain rules to have most of the benefits of the firewall. Is there some updated firewall rules for preventing intrusions?Maybe someone to share their firewall without sensitive data ofc Short answer: yes, it is a must have. Long answer: Fastt...
by tomislav91
Sat Oct 31, 2020 5:56 pm
Forum: General
Topic: limit bandwidth on ubiquiti or mikrotik?
Replies: 3
Views: 362

limit bandwidth on ubiquiti or mikrotik?

i have limit on wireless networks on my unify controler. Is it better to put it unlimited and then queue that subnet on mikrotik?
by tomislav91
Sat Oct 31, 2020 3:14 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

Re: are this rules on the top mandatory?

First two rules are for input chain, the 3rd, fasttrack is for forward chain and has nothing to do with first 2 rules. Also not sure I understand your question? my q was, does it something thats a MUST HAVE this input chain rules to have most of the benefits of the firewall. Is there some updated f...
by tomislav91
Fri Oct 30, 2020 11:17 pm
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 3002

are this rules on the top mandatory?

/ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid add action=fasttrack-connection chain=for...
by tomislav91
Fri Oct 30, 2020 11:11 pm
Forum: General
Topic: Unable to update CCR
Replies: 93
Views: 11818

Re: Unable to update CCR

how is your cpu handle with this rules at the top /ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=...
by tomislav91
Tue Oct 27, 2020 10:49 am
Forum: Scripting
Topic: Useful scripts
Replies: 81
Views: 135884

Re: Useful scripts

Hi All, OK not really a script, but I thought it may be in the same flavour. I created this Dynamic Blacklist firewall rule set that counts excessive connection attempts from the same IP within a given time frame and eventually blocks them for X number of days. I was initially going to put in a geo...
by tomislav91
Thu Oct 22, 2020 3:32 pm
Forum: Scripting
Topic: put all IPs from one ether to address table
Replies: 0
Views: 177

put all IPs from one ether to address table

hi guys, i am just wondering how to stress out one isp from another (some kind of load balancing). If router has 3 LAN interfaces, just maybe to test if second ISP is avaliable catch all IPs from one ether and than i will mangle that address list to another ISP. Any idea from where to start, i thoug...
by tomislav91
Thu Oct 22, 2020 3:16 pm
Forum: The Dude
Topic: Probe Thread
Replies: 328
Views: 262902

Re: Probe Thread

ping over200 dude.jpg
I wanted to get an info message when there is a ping more than 250ms on isp to know and change to another ISP mannualy.
Why this dont work? I didnt get any notification....
by tomislav91
Wed Oct 21, 2020 2:55 pm
Forum: The Dude
Topic: Alerts based on throughput threshold
Replies: 9
Views: 5023

Re: Alerts based on throughput threshold

Hello tomislav91 What do you mean by "created your own Traffic Monitor items for inbound / outbound, high / normal)"? What did you label/name the traffic monitor items in your example? Can you at least provide an example with screenshots? Thanks a lot. Regards, M Thats it? 2020-10-21 13_4...
by tomislav91
Wed Oct 21, 2020 11:07 am
Forum: Scripting
Topic: script dont create file?
Replies: 2
Views: 410

Re: script dont create file?

Most likely you are trying to get more than 4096 bytes into a variable: :local contents [/file get $file contents] https://forum.mikrotik.com/viewtopic.php?t=127093 It is limit not to file - it is limit for variable size... If you write text variable to file - you can write maximum 4096 bytes. But,...
by tomislav91
Wed Oct 21, 2020 11:00 am
Forum: General
Topic: how to speed up bgp convergence
Replies: 0
Views: 188

how to speed up bgp convergence

does it possible to speed up bgp change from one isp to another? Or more specific, that time which routes push traffic thorugh that isp? Ofcoure on CCR routers.
by tomislav91
Fri Oct 16, 2020 11:21 am
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

i tried to make like this :set time [/system clock get time] :local file [/ip ipsec installed-sa print] <--- this fills a (string) variable called file with the output of the print command :local contents [/file get $file contents] <--- this tries to extract the contents of a file whose name is the...
by tomislav91
Wed Oct 14, 2020 1:30 pm
Forum: Scripting
Topic: script dont create file?
Replies: 2
Views: 410

script dont create file?

Hi, in the thread "tunnel troubleshot" in the General tab, i posted some issue with tunneling, and i want to get some script to have monitoring ipsec installed sa and append to existing file, but when I run script manualy via GUI, nothing happend, where is mistake? :set time [/system clock...
by tomislav91
Tue Oct 13, 2020 1:42 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

Could you please create another script which will contain only the /ip ipsec installed-sa print file=ipsec append part and nothing else, run that new one twice, and see whether the file ipsec.txt is there and what is it contents?
yeah, its there.
by tomislav91
Tue Oct 13, 2020 1:34 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

there should be somefilename.txt if you followed my suggestion literally... what exact command did you type? yeah, so this is a script which i created :set time [/system clock get time] :local file [/ip ipsec installed-sa print file=ipsec append] :local contents [/file get $file contents] :set cont...
by tomislav91
Tue Oct 13, 2020 1:02 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

i tried to make like this :set time [/system clock get time] :local file [/ip ipsec installed-sa print] <--- this fills a (string) variable called file with the output of the print command :local contents [/file get $file contents] <--- this tries to extract the contents of a file whose name is the...
by tomislav91
Tue Oct 13, 2020 11:28 am
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

Yes, the mature ones are in use. And yes, you need one per direction. The dying ones should not exist for more than a couple of seconds, so if they do, it is already weird (or the traffic volume is so low - the dying SA is normally there after a rekey until the first packet arrives through the new ...
by tomislav91
Tue Oct 13, 2020 8:32 am
Forum: The Dude
Topic: Why is my equipment down?
Replies: 2
Views: 373

Re: Why is my equipment down?

From my expirience problem is firewall rules. Try to find out which one. Also, dont know where is dude server, in the same subnet or some remote? Maybe tunnel?
by tomislav91
Mon Oct 12, 2020 4:26 pm
Forum: The Dude
Topic: Alerts based on throughput threshold
Replies: 9
Views: 5023

Re: Alerts based on throughput threshold

Here is what I have built from jspool's head start (thanks, I owe you a beer). I hope this helps someone else. It is a high bandwidth alert with secondary alert when bandwidth has returned to normal levels... (it assumes you have Tools > Email worked out and you have created your own Traffic Monito...
by tomislav91
Mon Oct 05, 2020 6:16 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

Yes, the mature ones are in use. And yes, you need one per direction. The dying ones should not exist for more than a couple of seconds, so if they do, it is already weird (or the traffic volume is so low - the dying SA is normally there after a rekey until the first packet arrives through the new ...
by tomislav91
Mon Oct 05, 2020 2:54 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

i cant ping from mikrotik because vlans are on the cisco below mikrotik, not on router itself. How can you forward traffic using IPsec if the Mikrotik isn't configured as a gateway, i.e. if it doesn't have an IP address in the sender's subnet? The 'Tik must first receive the packet in order to matc...
by tomislav91
Mon Oct 05, 2020 12:29 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

it looks like a mission impossible so, what we can do than? Maybe the best start is to switch on logging of the IPsec and to run a netwatch pinging through the tunnel which will log failures ( on-down={:log warning message="ping through tunnel down"} ) to see in the logs whether the issue...
by tomislav91
Mon Oct 05, 2020 10:44 am
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

Razmišljam da nebi bio razgovor po telefonu mnogo brži... What do you mean by "lower are L2" So this MikroTik have a tunnel between PfSense from another HQ and on that PfSense is created openvpn servers which are remote shops connection (they are using mikrotiks also, but smaller ones, no...
by tomislav91
Sun Oct 04, 2020 10:55 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

Firewall od the other router are the same, it has just more src or dst nat there, so rules which are for us interesting are the same. But now at this point, tunnel is established thorugh pfsense and there is no much rules on the WAN side except one that we are using for internal purpoeses What tunn...
by tomislav91
Sun Oct 04, 2020 10:43 am
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

lifetime on pfsense is 1800sec,and on mikrotik is 30 min. I've only mentioned the lifetime as a troubleshooting hint - if the connections break in 80-100 % of the SA lifetime configured after the connection establishes, it makes sense to look at the PFS settings, as the first rekeying takes place a...
by tomislav91
Sat Oct 03, 2020 12:46 am
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

Re: tunnel troubleshoot

A blind shot here would be a mismatch of PFS settings, causing the first rekeying of the SAs to fail (so the tunnel would work for just about 25 minutes after establishing if default lifetime=30m is set in /ip ipsec proposal ). Another blind shot would be that pinholes in some external firewall on ...
by tomislav91
Fri Oct 02, 2020 7:29 pm
Forum: General
Topic: tunnel troubleshoot
Replies: 34
Views: 1663

tunnel troubleshoot

so guys, i am struggling quite some time with my tunnels(ipsec). Status is established, but there is no traffic allowed, I must disable/enable to get that working. So, what is first step, what to do? What i tried? I have several tunnels Mikrotik - Mikrotik, and I change it to Mikrotik - PFSense rout...
by tomislav91
Mon Sep 14, 2020 2:20 pm
Forum: Scripting
Topic: block watch video streams
Replies: 0
Views: 302

block watch video streams

Hello guys, i am strugle with block users to watch films, tv show,etc . online. I tried with layer7 but it is a bunch of sites which i want to block and it is impossible to block all of it, and ofc cpu load is problem. this also came as a good solution /ip firewall filter add chain=forward dst-port=...
by tomislav91
Mon Sep 07, 2020 10:00 pm
Forum: Scripting
Topic: get dst-address from src-address
Replies: 1
Views: 307

Re: get dst-address from src-address

i solve it
 :global srcIP [/ip firewall nat get [find where dst-address="192.168.0.0/16"] src-address];
by tomislav91
Mon Sep 07, 2020 4:35 pm
Forum: Scripting
Topic: get dst-address from src-address
Replies: 1
Views: 307

get dst-address from src-address

hi, i am having rules like this add chain=srcnat dst-address=192.168.0.0/16 src-address=192.168.1.0/24 and idea is to get src-addres because it is different on all routers, but this dst address is same. i tried something like this :global Forbid [ip firewall nat find src-address where dynamic src-ad...
by tomislav91
Wed Aug 12, 2020 3:49 pm
Forum: General
Topic: ping static dns name from local machine?
Replies: 1
Views: 449

ping static dns name from local machine?

is it possible to set a static dns entry and use it for machines?
So i can ping dns entry from router and i get my ip, but i cant ping that static ip dns name from another machine?
by tomislav91
Tue Jun 30, 2020 11:13 am
Forum: General
Topic: arp table flash?
Replies: 1
Views: 378

arp table flash?

Hello guys, i have several ip which i put static IP, but in arp table there are entries for that mac for that STATIC and DYNAMIC ip.
I have restarted device, but result is the same.

How much time i must wait for arp table to be updated
by tomislav91
Thu May 07, 2020 10:53 am
Forum: General
Topic: cpu % is high but with this rules my up/down are bad
Replies: 1
Views: 557

cpu % is high but with this rules my up/down are bad

i wanted to get a bit more down a cpu usage, and put this in this order some rules where local are my local subnets, and remote is ipsec remote subnets (without those lists i have a issues to connect to remote subnets its a verrryyyy slow) add action=accept chain=forward dst-address-list=Remote src-...
by tomislav91
Wed Feb 12, 2020 10:09 am
Forum: Scripting
Topic: pick only address from arp
Replies: 1
Views: 1777

Re: pick only address from arp

i solved it and put into variable
:global test ([:pick [/ip arp print as-value where mac-address~"^AA:BB:CC"] 0]->"address")
by tomislav91
Mon Feb 10, 2020 10:55 am
Forum: Scripting
Topic: pick only address from arp
Replies: 1
Views: 1777

pick only address from arp

I want to pick all address which devices from ARP but i got only one IP :put [ip arp print where mac-address~"^AA:BB:CC"] Flags: X - disabled, I - invalid, H - DHCP, D - dynamic, P - published, C - complete # ADDRESS MAC-ADDRESS INTERFACE 0 DC 10.11.138.130 AA:BB:CC:D7:08:35 lan_bridge 1 D...
by tomislav91
Sun Feb 09, 2020 10:54 pm
Forum: Scripting
Topic: dhcp lease with know MAC set to queue
Replies: 0
Views: 2335

dhcp lease with know MAC set to queue

Hi guys, i want to automate script which are going to queue ip whenever is come to dhcp lease, reason is simple. I have a bunch of rotuers and one device is going to be on all that routers attached. So I dont want to queue it all 1 by one. I stuck here: I have part of good output for the appropriate...
by tomislav91
Sun Feb 09, 2020 7:56 pm
Forum: General
Topic: get IP from part of MAC address from dhcp lease
Replies: 5
Views: 1489

Re: get IP from part of MAC address from dhcp lease

Idea behind all is to use that ip and set a queue. Do u have idea how to use that IP and set it to queue
by tomislav91
Fri Feb 07, 2020 7:09 pm
Forum: General
Topic: get IP from part of MAC address from dhcp lease
Replies: 5
Views: 1489

Re: get IP from part of MAC address from dhcp lease

No, "~" is a matching operator. Use it instead of "=", not as a part of the expression - which may be as simple as "^B0:6E:BF", meaning any string that begins with "B0:6E:BF".
thats it! THANKS!!!!
by tomislav91
Fri Feb 07, 2020 4:35 pm
Forum: General
Topic: get IP from part of MAC address from dhcp lease
Replies: 5
Views: 1489

Re: get IP from part of MAC address from dhcp lease

You can use regular expressions with "~" operator -- https://wiki.mikrotik.com/wiki/Manual:Scripting#Other_Operators i tried like this put [ip dhcp-server lease get [find mac-address=B0:6E:BF~"^([0-9a-fA-F][0-9a-fA-F]:){5}([0-9a-fA-F][0-9a-fA-F])$" address] but nothing.. Where i...
by tomislav91
Fri Feb 07, 2020 12:49 am
Forum: General
Topic: get IP from part of MAC address from dhcp lease
Replies: 5
Views: 1489

get IP from part of MAC address from dhcp lease

Hi guys, i am having same device on many routers, can I somehow get IP when use only first 3 octets of mac address? put [ip dhcp-server lease get [find mac-address=B0:6E:BF:1D:A1:2D] address] this output me IP, but every device has different last 3 octet. Can I somehow trick this code to use whateve...
by tomislav91
Tue Nov 19, 2019 2:26 pm
Forum: General
Topic: block teamviewer on routers
Replies: 5
Views: 3224

block teamviewer on routers

Is there some address list or rules for forbid users to connect via teamviewer?
i found some, but somehow it goes throguh.
by tomislav91
Fri Oct 18, 2019 8:06 pm
Forum: General
Topic: ipsec tunnel expired
Replies: 1
Views: 721

ipsec tunnel expired

I got sometimes my ipsec tunnel status expired or established but i cant ping from one subnet to another. Dont sure what causes it. When I disable/enable a couple of time, it works. Can I use maybe
/ip ipsec installed-sa flush
?
by tomislav91
Fri Oct 18, 2019 8:56 am
Forum: General
Topic: defend from large icmp requests
Replies: 4
Views: 850

Re: defend from large icmp requests

Yes, i am having a drop rule which drop address list. Yes, i wanted to say a many requests. Problem wasnt in too much traffic on interface, problem is that icmp flood with many connections (arround 100k) add action=drop chain=input comment="IN-Defend from Ping" src-address-list=ping-evil-p...
by tomislav91
Thu Oct 17, 2019 5:26 pm
Forum: General
Topic: defend from large icmp requests
Replies: 4
Views: 850

Re: defend from large icmp requests

Just to add this with my rules?
Can i block somehow connection with same source, but must be a large number of connection, because i dont want to affect my traffic
by tomislav91
Thu Oct 17, 2019 4:21 pm
Forum: General
Topic: defend from large icmp requests
Replies: 4
Views: 850

defend from large icmp requests

hi, can you redirect me on best way to defend against icmp packets which came to router, not only ping, or traceroute, and so on. i am having firewall rules add action=accept chain=input comment="Allow ICMP" protocol=icmp src-address-list=mylist add action=accept chain=output comment="...
by tomislav91
Sat Sep 28, 2019 12:30 am
Forum: General
Topic: speed up local subnet-server subnet
Replies: 2
Views: 682

Re: speed up local subnet-server subnet

so genneraly i can add fasttrack when source is ip of server and destination is my local subnet that use that server every day and also add accept for same src and dest?
I just want to somehow speedup connection to my server, as fast as i can with filter.
by tomislav91
Thu Sep 26, 2019 10:54 pm
Forum: General
Topic: speed up local subnet-server subnet
Replies: 2
Views: 682

speed up local subnet-server subnet

does it play any role in faster connection between two subnets with this commands /ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related src-address=192.168.2.0/24 dst-address=192.168.3.0/24 add chain=forward action=fasttrack-connection connection-stat...
by tomislav91
Thu Sep 05, 2019 9:18 pm
Forum: Scripting
Topic: CCR Health Monitoring
Replies: 5
Views: 5511

Re: CCR Health Monitoring

I cant get psu state, just empty field.
by tomislav91
Wed Mar 13, 2019 12:32 pm
Forum: The Dude
Topic: dont want alert for all services
Replies: 1
Views: 2047

dont want alert for all services

Hi, i found alert configuration manual on https://wiki.mikrotik.com/wiki/Manual:T ... ifications, and it is ok, working as charm, but i get for all services alert when router is down. I want only for ping, can I somehow change it?
by tomislav91
Fri Nov 23, 2018 9:33 pm
Forum: General
Topic: access to wifi subnet via lan subnet
Replies: 2
Views: 494

Re: access to wifi subnet via lan subnet

Please list your configuration, so it's clear what is where... /export compact hide-sensitive # model = 951Ui-2HnD # serial number = 815708D04500 /interface bridge auto-mac=no comment="created from master port" name=bridge1 protocol-mode=none /interface ethernet set [ find default-name=et...
by tomislav91
Fri Nov 23, 2018 9:07 pm
Forum: General
Topic: access to wifi subnet via lan subnet
Replies: 2
Views: 494

access to wifi subnet via lan subnet

I am having a 10.106.0/24 local subnet in bridge for my devices, and some pc connected to wifi which subnet is 192.168.100.0/24. How can i manage to get a wifi 192.168.100.40 see local subnet or just one IP 10.10.6.50/24 I tried to add src nat masqaraude but not working add action=masquerade chain=s...
by tomislav91
Tue Nov 20, 2018 5:31 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

Re: secure winbox port access only by wan ip

What really means phases from 1 to 3 in defence of brute force? After phase 3 ip is forwarding to address list which has been dropped via rule. But what really means phase 1 2 and 3? I have allways ip in addreess list from phase 1 and dissapear because of timeout. Never goes to phase 2 and 3 and fin...
by tomislav91
Sun Nov 18, 2018 7:31 pm
Forum: General
Topic: best way to control script email for firewall rule
Replies: 0
Views: 462

best way to control script email for firewall rule

I am having a firewall rules add action=jump chain=input comment="Jump to RFC SSH Chain" jump-target=\ "RFC SSH Chain" log=yes log-prefix=PSD add action=add-src-to-address-list address-list="Black List (SSH)" \ address-list-timeout=none-dynamic chain="RFC SSH Chain...
by tomislav91
Tue Nov 13, 2018 11:38 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

Re: secure winbox port access only by wan ip

Winbox is to control the router and the router setup. It should not be done via WAN connection (direct), it should be done with a VPN or at the very minimum the Port Knocking technique. Theese are okay if you are using just a few mikrotiks. But when you get plenty of them in different places around...
by tomislav91
Mon Nov 12, 2018 11:55 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

Re: secure winbox port access only by wan ip

What about this?
https://rickfreyconsulting.com/basic-mi ... e-version/

I found basic firewall settings.
Can I add this to my routers?
by tomislav91
Mon Nov 12, 2018 10:48 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

Re: secure winbox port access only by wan ip

If you need to use winbox from the outside you do not have many option. 1. VPN (best option) 2. Open Winbox but: a. change to other port than 8291 b. set an access list to reduce who can access it c. use port knocking d. setup some monitoring. example getting email every time some logs inn. Hi, i a...
by tomislav91
Mon Nov 12, 2018 7:22 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

Re: secure winbox port access only by wan ip

To begin with, remove the value entered with "/ip services set winbox address=X.X.X.X/Y". That's just plain bad! Even if you're coming in from other offices, don't see it as coming in through the WAN port. You're coming in through a point-to-point link (L2TP/IPSEC, which is great) from an...
by tomislav91
Sat Nov 10, 2018 10:56 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

Re: secure winbox port access only by wan ip

Winbox is to control the router and the router setup. It should not be done via WAN connection (direct), it should be done with a VPN or at the very minimum the Port Knocking technique. If you want access to a LAN from the WAN side, then again if its to a specific server use DESTINATION NAT. In oth...
by tomislav91
Sat Nov 10, 2018 8:41 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

Re: secure winbox port access only by wan ip

Hello, Do you realize that by giving your public IP address, you basically invited everybody to test your security? Make sure you have a strong firewall and have secured your router. Best regards, Sent from Tapatalk can you than tell me how to secure winbox port? I want access only within my local ...
by tomislav91
Sat Nov 10, 2018 8:08 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 4881

secure winbox port access only by wan ip

I added to ip services winbox that address is my WAN IP.
But i cant access it.
Why?
I wrote this
set winbox address=x.x.x.x/29
by tomislav91
Mon Sep 24, 2018 3:06 pm
Forum: Beginner Basics
Topic: no such item when disable/enable peer from terminal
Replies: 1
Views: 345

no such item when disable/enable peer from terminal

Hi, i want to enable one and disable another policy.
Can you check it why give me error no such item?
ip ipsec policy set disabled=no numbers=2
no such item
I have policies
#1 and #2 in IPsec policy tab...
by tomislav91
Tue Aug 21, 2018 3:17 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

Thanks all for you replies! appreciate!!! I did it like this. Get in the first way, all dhcp lease, and than with some command filter only IP addresses grep -i -w kl locations.txt > locations1.txt;cat locations1.txt | awk -F " " '{print $2, $3}' > locations2.txt; sed 's/D//g' locations2.tx...
by tomislav91
Tue Aug 21, 2018 11:19 am
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

I'm not familiar with sshpass but judging from the on-line documentation it will return stdout from remote process just like ssh does. You have two possibilities: you can take whole output from your script (I don't know how exactly does it look like, are data fields comma-separated within single li...
by tomislav91
Tue Aug 21, 2018 10:31 am
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

Because a dash was missing in what I wrote. Now I got home and tried using the Tab button:
[me@MyTik] > put [ip dhcp-server lease get [find host-name=my-HP] address]
192.168.88.254
if I have more than one with same name, it throws me
invalid internal item number
by tomislav91
Tue Aug 21, 2018 10:08 am
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

If you're going to fetch lease info from linux box via ssh, then you can easily do filtering with some simple commands on linux box itself. One-liner that does the trick: WANTED=my-host-name; LEASES=$( ssh user@routerboard.my.domain '/ip dhcp-server lease { :foreach i in=[find (!dynamic && ...
by tomislav91
Tue Aug 21, 2018 8:35 am
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

If you really do want the file name to be sourced from variable n as you suggest, you have to do what I wrote earlier. There is no file modifier to put , nor there is a way to make print print a single value. So you have to generate a file with any bogus contents: /routing print file=$n and then re...
by tomislav91
Mon Aug 20, 2018 11:55 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

:global n [ip dhcp-server lease get [find host-name=PC] address];/file print file=$n This line of code says: - set the value of a global-scoped variable named n to the ip address leased to device with hostname PC - print the list of existing files into a file whose name is retrieved from the global...
by tomislav91
Mon Aug 20, 2018 11:30 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

thanks for reply. Problem lies somewhere alse abvious. When sshpass this command ip dhcp-server lease print file=$n my script execute without problem. I use that variable n in later lines of code. But i dont need all dhcp lease, only with PC hostname, we solve that, but what is difference with that ...
by tomislav91
Mon Aug 20, 2018 10:05 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

Because a dash was missing in what I wrote. Now I got home and tried using the Tab button: [me@MyTik] > put [ip dhcp-server lease get [find host-name=my-HP] address] 192.168.88.254 thanks man! It works now. Only last problem, i must put that into file. sshpass -p $pass ssh -o $log -n $user@$h -p 41...
by tomislav91
Mon Aug 20, 2018 8:23 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

it throws me "no such item"
by tomislav91
Mon Aug 20, 2018 8:02 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

I got via

ip dhcp-server lease print where host-name="pc"

but you help me how to get only Ip address without unnecessary information from result of command?
by tomislav91
Mon Aug 20, 2018 7:24 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

Sorry, can you use another wording? It is not clear to me what you need. Ok, look, i have my dhcp lease on several computers. I want to get Ip address of hostname PC. SO i wrote a bash script that connect via ssh to mikrotik and run a terminal command. Problem is that I dont know how to get IP addr...
by tomislav91
Mon Aug 20, 2018 7:22 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

That looks to me as an insufficient indication to bash what it should handle and what not.. Try to place the whole command for Mikrotik into quotes and escape the symbols ",$,\ you need to make it to Mikrotik: sshpass -p $pass ssh -o $log -n $user@$h -p 4111 " /ip dhcp-server lease { :for...
by tomislav91
Mon Aug 20, 2018 7:11 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

does it possible from that script to get only ip addresses with hostname i define?
by tomislav91
Mon Aug 20, 2018 3:39 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

sshpass -p $pass ssh -o $log -n $user@$h -p 4111 /ip dhcp-server lease { :foreach i in=[find (!dynamic && status="bound")] do={ :local activeAddress [get $i active-address]; :local activeMacAddress [get $i active-mac-address]; :local hostname [get $i host-name]; :put ($outputConte...
by tomislav91
Mon Aug 20, 2018 3:36 pm
Forum: General
Topic: export dhcp lease with only hostname
Replies: 1
Views: 933

export dhcp lease with only hostname

can i get via terminal ip address of hostname only?

part of my script is
ip dhcp-server lease print file=$n
but this give me all dhcp lease addresses. can I find somehow ip of hostname="pc"?
My all devices have all the same hostname, and i need all ip addresses for all pc's.
by tomislav91
Mon Aug 20, 2018 3:27 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

Re: multiple lines into one

It gives me error. It works directly to mirkotik but from ssh i cant do it.
Does it possible to resolve that issue?
by tomislav91
Mon Aug 20, 2018 3:07 pm
Forum: General
Topic: multiple lines into one
Replies: 30
Views: 3123

multiple lines into one

How it possible to do it in one line of code in terminal this command i found here on forum /ip dhcp-server lease { :foreach i in=[find (!dynamic && status="bound")] do={ :local activeAddress [get $i active-address] :local activeMacAddress [get $i active-mac-address] :local hostnam...
by tomislav91
Tue Jan 30, 2018 11:18 am
Forum: General
Topic: change configuration addresses via terminal
Replies: 0
Views: 403

change configuration addresses via terminal

i need to change a several address from a mikrotik via terminal. I find how to change a ip address /ip address set [/ip address find address="10.0.0.1/24"] address=20.0.0.1/24 I need also to change /ip dhcp-server network add address=10.10.0.0/24 gateway=10.10.0.1 /ip pool add name=dhcp_po...
by tomislav91
Thu Dec 28, 2017 11:53 am
Forum: Scripting
Topic: show ip address from a hostname
Replies: 2
Views: 752

Re: show ip address from a hostname

binding is not priority for now. Mikrotik reads hostname from a netbios name and it is ok.

Just curious how to make a script to make it easier. I will do it via bash, but how to search it in mikrotik terminal? If for example hostname is "warrior".
by tomislav91
Mon Dec 25, 2017 12:08 pm
Forum: Scripting
Topic: show ip address from a hostname
Replies: 2
Views: 752

show ip address from a hostname

Hello, i was wondering does ti possible to have some script which will show a IP address from a hostame.
So if I have pcs and want ip of it, just to search by hostname "PC" and to find an ip.
I have several hostnames, and just want to make things quicker.
by tomislav91
Fri Dec 08, 2017 11:09 am
Forum: The Dude
Topic: dude for router ccr
Replies: 2
Views: 1393

dude for router ccr

which version must i install and put it into router? it is a server.
In download section is more than 1 version
by tomislav91
Thu Nov 09, 2017 11:25 am
Forum: Beginner Basics
Topic: how to two subnet to communicate?
Replies: 10
Views: 2104

Re: how to two subnet to communicate?

I manage to succeed something. I add in routes of these two routers in destinatiom address whole subnet of second router amd gateway set to l2tp, which I with main router have access to them. Do in my main router i have l2tp connection over ipsec. And now two routers can communicate and can see any...
by tomislav91
Sun Oct 15, 2017 1:59 am
Forum: Beginner Basics
Topic: How to send a backup to email [SOLVED]
Replies: 13
Views: 6773

Re: How to send a backup to email [SOLVED]

i make virtual linux machine which connect through ssh to router and backup all..:)
by tomislav91
Fri Oct 13, 2017 11:25 pm
Forum: Beginner Basics
Topic: how to two subnet to communicate?
Replies: 10
Views: 2104

Re: how to two subnet to communicate?

i have also linux machines and no ping as well..
by tomislav91
Fri Oct 13, 2017 7:29 pm
Forum: Beginner Basics
Topic: how to two subnet to communicate?
Replies: 10
Views: 2104

Re: how to two subnet to communicate?

I manage to succeed something. I add in routes of these two routers in destinatiom address whole subnet of second router amd gateway set to l2tp, which I with main router have access to them. Do in my main router i have l2tp connection over ipsec. And now two routers can communicate and can see anyt...
by tomislav91
Fri Oct 13, 2017 9:52 am
Forum: Beginner Basics
Topic: how to two subnet to communicate?
Replies: 10
Views: 2104

Re: how to two subnet to communicate?

no subnets are for the different routers, two routers and two subnets, each for router. These two routers are connected via vpn to the main router.
by tomislav91
Thu Oct 12, 2017 4:17 pm
Forum: Beginner Basics
Topic: how to two subnet to communicate?
Replies: 10
Views: 2104

how to two subnet to communicate?

Hello, i have two routers in two different networks. 10.0.8.0/24 and 10.0.58.0/24 I want to manage that that two subnet see each other. I added ip firewall filter add action=accept chain=forward dst-address=10.0.58.0/24 and different in another router, but there is no connection between them. Where ...
by tomislav91
Wed Oct 11, 2017 9:36 am
Forum: Beginner Basics
Topic: how to check bandwidth usage?
Replies: 0
Views: 396

how to check bandwidth usage?

How can I check which device consume most upload in my network? And which column should I look for.
by tomislav91
Mon Sep 18, 2017 10:16 am
Forum: Scripting
Topic: failover script without public ip on the mikrotik
Replies: 2
Views: 1066

Re: failover script without public ip on the mikrotik

why do u use script?

just use route
/ip route
add check-gateway=ping distance=1 gateway=8.8.8.8
add check-gateway=ping distance=2 gateway=8.8.4.4
add distance=2 dst-address=8.8.4.4/32 gateway=192.168.1.1 scope=10
add distance=1 dst-address=8.8.8.8/32 gateway=192.168.0.1 scope=10
by tomislav91
Fri Sep 08, 2017 12:58 pm
Forum: Beginner Basics
Topic: RB1100AHx2 upload and download limit issue
Replies: 4
Views: 907

Re: RB1100AHx2 upload and download limit issue

i think that u need is in Queue, than in simple queues click + sign and than choose target and bottom you have max limit. There you can do it, if this is what you want
by tomislav91
Wed Sep 06, 2017 8:05 pm
Forum: General
Topic: why i cant see switches via l2tp?
Replies: 6
Views: 1321

Re: why i cant see switches via l2tp?

can anyone give me idea what to try?
by tomislav91
Tue Sep 05, 2017 4:46 pm
Forum: General
Topic: why i cant see switches via l2tp?
Replies: 6
Views: 1321

Re: why i cant see switches via l2tp?

But i have connected to l2tp and have access to the internet. So l2tp is working, just i cant cant access to 88 where are switches
by tomislav91
Tue Sep 05, 2017 3:36 pm
Forum: General
Topic: why i cant see switches via l2tp?
Replies: 6
Views: 1321

Re: why i cant see switches via l2tp?

no? Must I?
And where to configure? ON my router where are switches connected?
I often use l2tp and all works just fine
by tomislav91
Tue Sep 05, 2017 11:48 am
Forum: General
Topic: why i cant see switches via l2tp?
Replies: 6
Views: 1321

why i cant see switches via l2tp?

I have connected to my router via l2tp. To that router is connect several switches with adresses in range 192.168.88.1-254. I set dhcp pool with that l2tp profile to range which switches are configured. But I cant see switches, i cant ping, but tp link easy smart configuration utility cant see them....
by tomislav91
Thu Aug 31, 2017 10:42 am
Forum: General
Topic: monitoring network
Replies: 2
Views: 804

monitoring network

Hi guys, i wanted to have some monitor my network.
Configuration is next:
i have my main router and clients routers and i want to have some maybe windows-linux based web server to monitor my rotuers and traffic between (which app users open, downloaded, etc).
by tomislav91
Thu Jul 27, 2017 5:12 pm
Forum: Beginner Basics
Topic: Connect two switches not workong trunk
Replies: 1
Views: 575

Connect two switches not workong trunk

I have problem with connecting several switches. I have internet connection to one switch and want to share with all because there is no possibility to connect all,cable goes through wall. I connect main switch where is internrt connection from mikrotik router, on port 24 to port 23 of another switc...
by tomislav91
Mon Jul 10, 2017 11:01 pm
Forum: Scripting
Topic: edit function for high ping
Replies: 0
Views: 413

edit function for high ping

https://drive.google.com/file/d/0Bxq9Ym ... JCYkk/view

Can I make a change of this function to test a more than 1 peek? At least 4, because maybe ping is 24ms,23ms,222ms,10ms, and alert me. I want to have alert, yeah, but when high ping is at leasst 4 passes.
by tomislav91
Mon Jul 10, 2017 3:01 pm
Forum: General
Topic: how to set vlans to see each other
Replies: 1
Views: 583

how to set vlans to see each other

Hi, can you please help me how to set if i need to my vlan1 see vlan2? How can I configure that?
by tomislav91
Fri Jul 07, 2017 3:15 pm
Forum: Beginner Basics
Topic: pc in vlan dont get vlan dhcp pool address
Replies: 0
Views: 407

pc in vlan dont get vlan dhcp pool address

i want to configure mikrotik to have a vlan and setup is : mikrotik port1 is WAN cable, and access to internet, port2 is configured dhcp pool 88.0/24 and bridged with port4 to have access via port2 to my laptop. Port 4 is connected in port 24 with smart swtich, and in switch port 8 is on my pc. Prob...
by tomislav91
Wed Jul 05, 2017 10:07 pm
Forum: Scripting
Topic: impossible scripte - notify when caller id from l2tp changed
Replies: 0
Views: 387

impossible scripte - notify when caller id from l2tp changed

Hello, i am having an idea, but i think that is impossible :D So, whole idea is when my l2tp client change wan address i must that address put in ipsec in my mikrotik router. Can I make some script or you can help me, to notify me when some device l2tp client changed wan address? In case of l2tp cli...
by tomislav91
Wed Jul 05, 2017 9:41 pm
Forum: Scripting
Topic: pop up when ping is lost
Replies: 1
Views: 558

Re: pop up when ping is lost

I did it.
Just in add in services with your function and notification.
by tomislav91
Tue Jul 04, 2017 2:58 pm
Forum: Scripting
Topic: pop up when ping is lost
Replies: 1
Views: 558

pop up when ping is lost

I have earlier post when take a function which all it does is that pop up me when ping is over 200ms (ping 8.8.8.8). I have a probe name ping with type ICMP, packet size 56, retry count 3 and interval 1000. Can I make a function or service that notife me. can I just in services with type "ping&...
by tomislav91
Tue Jun 13, 2017 9:34 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Or any other solution for my general problem, to get informed if router has bad ping to 8.8.8.8.
Yeah, I have internet, but when ping is 100,200,300ms it is slow and bad, and want to switch to another interface where is another isp provider. That's whole idea.
by tomislav91
Tue Jun 13, 2017 8:24 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Can you just tell me about Dude. Does it possible to get an alert for maybe ping to create alarms? Just ask because of much queries to router... yes, you can use it. for example i use it to send e-mail for warnings and not very critical events. and most important are also send to telegram. but if y...
by tomislav91
Tue Jun 13, 2017 8:08 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

it means that you have only one ROS device in dude. so, ping rtt from your dude server to 8.8.8.8 is also >100 when you test? I can choose instead of default a device which is in the Device. But it is the same. to device. Problem is when server has higher ping. i can't test with values more than 20...
by tomislav91
Tue Jun 13, 2017 7:16 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

in agent is only default. it means that you have only one ROS device in dude. so, ping rtt from your dude server to 8.8.8.8 is also >100 when you test? I can choose instead of default a device which is in the Device. But it is the same. to device. Problem is when server has higher ping. i can't tes...
by tomislav91
Tue Jun 13, 2017 6:52 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

in agent is only default. it means that you have only one ROS device in dude. so, ping rtt from your dude server to 8.8.8.8 is also >100 when you test? I can choose instead of default a device which is in the Device. But it is the same. to device. Problem is when server has higher ping. Dude server...
by tomislav91
Tue Jun 13, 2017 6:38 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

very strange. on history tab of the service you can see graph with values. what values does it get (when ping is > 100ms)? This is a graphgra.png I cant see there is more than 100ms? ok. and our "default" agent is the mikrotik from that site (it also will have >100ms to 8.8.8.8) or it is ...
by tomislav91
Tue Jun 13, 2017 6:15 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

very strange. on history tab of the service you can see graph with values. what values does it get (when ping is > 100ms)? This is a graphgra.png I cant see there is more than 100ms? ok. and our "default" agent is the mikrotik from that site (it also will have >100ms to 8.8.8.8) or it is ...
by tomislav91
Tue Jun 13, 2017 6:09 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

very strange. on history tab of the service you can see graph with values. what values does it get (when ping is > 100ms)?
This is a graph
gra.png
I cant see there is more than 100ms?
by tomislav91
Tue Jun 13, 2017 5:46 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

glad to help you can try to change "probe interval", "probe down count", "probe timeout" to have faster response also notifications to telegram come faster than e-mail i putted notification pop up, but when put a 10ms it give me pop up, but when 100ms there is no pop u...
by tomislav91
Tue Jun 13, 2017 5:13 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Must I put an Agent to be like Device in drop down menu? It is a routers.
by tomislav91
Tue Jun 13, 2017 4:55 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

in error line - you deleted ) at the end i found it, and response with a bit delay notification popup. But it works. Thanks glad to help you can try to change "probe interval", "probe down count", "probe timeout" to have faster response also notifications to telegram c...
by tomislav91
Tue Jun 13, 2017 4:39 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

sorry for that, but again parse error.. in error line - you deleted ) at the end i found it, and response with a bit delay notification popup. But it works. Thanks glad to help you can try to change "probe interval", "probe down count", "probe timeout" to have faster r...
by tomislav91
Tue Jun 13, 2017 3:36 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+


sorry for that, but again parse error..
in error line - you deleted ) at the end

i found it, and response with a bit delay notification popup. But it works. Thanks
by tomislav91
Tue Jun 13, 2017 3:18 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

look this: https://drive.google.com/open?id=0Bxq9Ym3e0mk-bXptQXRXX2JCYkk i modified this probe to your needs. add it to all devices from which you want to monitor ping to 8.8.8.8 actually, i don,t know what to do if this devices are not RB or there are no RB in this site, but if it is mikrotik - as...
by tomislav91
Tue Jun 13, 2017 3:11 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Is this that? How can I decide on which device this working? Or that work on all devices in Dude? look this: https://drive.google.com/open?id=0Bxq9Ym3e0mk-bXptQXRXX2JCYkk i modified this probe to your needs. add it to all devices from which you want to monitor ping to 8.8.8.8 actually, i don,t know...
by tomislav91
Tue Jun 13, 2017 2:56 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Is this that? How can I decide on which device this working? Or that work on all devices in Dude? look this: https://drive.google.com/open?id=0Bxq9Ym3e0mk-bXptQXRXX2JCYkk i modified this probe to your needs. add it to all devices from which you want to monitor ping to 8.8.8.8 actually, i don,t know...
by tomislav91
Tue Jun 13, 2017 2:33 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

yes, you can use it. for example i use it to send e-mail for warnings and not very critical events. and most important are also send to telegram. but if you want to have a message when 200+ms then you have to make a probe for that also you should remember that you will monitor "ping" from...
by tomislav91
Tue Jun 13, 2017 2:02 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Can you just tell me about Dude. Does it possible to get an alert for maybe ping to create alarms? Just ask because of much queries to router... yes, you can use it. for example i use it to send e-mail for warnings and not very critical events. and most important are also send to telegram. but if y...
by tomislav91
Tue Jun 13, 2017 12:10 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Can you just tell me about Dude. Does it possible to get an alert for maybe ping to create alarms? Just ask because of much queries to router... yes, you can use it. for example i use it to send e-mail for warnings and not very critical events. and most important are also send to telegram. but if y...
by tomislav91
Mon Jun 12, 2017 6:28 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Thanks all for reply. Just tell me, maybe here needs a space: to=to@mail.co mf rom=from@mail.com I have updated it can you just tell me one thing. Server IP for email. What should I put here? If i want to send to gmail, i need to put gmail SMTP wan ip? #Mikrotik Ping more than 200ms to send mail #h...
by tomislav91
Sun Jun 11, 2017 6:45 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Thanks all for reply. Just tell me, maybe here needs a space:
I have updated it
can you just tell me one thing. Server IP for email. What should I put here? If i want to send to gmail, i need to put gmail SMTP wan ip?
by tomislav91
Sun Jun 11, 2017 5:58 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

Re: send mail when ping is 200ms+

Thanks all for reply. Just tell me, maybe here needs a space:
by tomislav91
Sun Jun 11, 2017 5:55 pm
Forum: Scripting
Topic: external ip from another interface
Replies: 4
Views: 1789

Re: external ip from another interface

Does it possible to get some modification of scripts to see external ip from another interface?
by tomislav91
Fri Jun 09, 2017 11:40 am
Forum: Scripting
Topic: external ip from another interface
Replies: 4
Views: 1789

external ip from another interface

Hi, i found a script to get me an ext ip from interface { /tool fetch url="http://myip.dnsomatic.com/" mode=http dst-path=mypublicip.txt local ip [file get mypublicip.txt contents ] put $ip } Also find # Set needed variables :global extinterface "ether1-gateway" :global ExtIpList...
by tomislav91
Fri May 26, 2017 12:52 pm
Forum: Scripting
Topic: send mail when ping is 200ms+
Replies: 45
Views: 5903

send mail when ping is 200ms+

Hi,

i am having a failover over mikrotik router, and want to send me an email when ping to 8.8.8.8 over ethernet 1 / gw 1 send me an email? I am having script to send me email when there is no ping.