Community discussions

MUM Europe 2020

Search found 51 matches

by ibrahimovich87
Mon Jan 29, 2018 12:53 pm
Forum: Beginner Basics
Topic: Firewall e Nat Rule - FTP Upload
Replies: 6
Views: 655

Re: Firewall e Nat Rule - FTP Upload

I did a search on this forum, does this topic answer your question? https://forum.mikrotik.com/viewtopic.php?t=61450 No...i need that an internal IP can upload file, wich rule on firewall i have to make or configure? Just create port forwarding rule in NAT, that's all. Sorry...but i can i do it? My...
by ibrahimovich87
Tue Jan 23, 2018 4:21 pm
Forum: Beginner Basics
Topic: Firewall e Nat Rule - FTP Upload
Replies: 6
Views: 655

Re: Firewall e Nat Rule - FTP Upload

I did a search on this forum, does this topic answer your question? https://forum.mikrotik.com/viewtopic.php?t=61450 No...i need that an internal IP can upload file, wich rule on firewall i have to make or configure? Just create port forwarding rule in NAT, that's all. Sorry...but i can i do it?
by ibrahimovich87
Tue Jan 23, 2018 10:36 am
Forum: Beginner Basics
Topic: Firewall e Nat Rule - FTP Upload
Replies: 6
Views: 655

Re: Firewall e Nat Rule - FTP Upload

I did a search on this forum, does this topic answer your question?
viewtopic.php?t=61450
No...i need that an internal IP can upload file, wich rule on firewall i have to make or configure?
by ibrahimovich87
Mon Jan 22, 2018 1:20 pm
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

192.168.98.2[500] used as isakmp port (fd=21)
192.168.98.2[4500] used as isakmp port with NAT-T (fd=18)
failed to begin ISAKMP SA negotiation,

how can i send you a configuration list?
by ibrahimovich87
Mon Jan 22, 2018 11:56 am
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

Chapter 3.3.1 at page 90?
Yes,
i have 1 little problem....activating dhcp client everytime i restart router he give me a different ip how can i fix it???
by ibrahimovich87
Mon Jan 22, 2018 11:44 am
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

Well, as the ports are not forwarded, no wonder that the IPsec cannot establish. Can you send me a link to the manual of that provider's router? Should not matter if it is only in Italian. If it comes out that there is no way to make it work, another possibility would be to keep both connections, t...
by ibrahimovich87
Mon Jan 22, 2018 11:23 am
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

Okay. So you already do have a PPPoE client interface there as expected. What I cannot really understand is how comes that although the modem is connected to ether1, which is not a member port of your bridge named "bridge", it is accessible using an IP address from the same subnet like the rest of ...
by ibrahimovich87
Fri Jan 19, 2018 5:11 pm
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

Okay. So you already do have a PPPoE client interface there as expected. What I cannot really understand is how comes that although the modem is connected to ether1, which is not a member port of your bridge named "bridge", it is accessible using an IP address from the same subnet like the rest of ...
by ibrahimovich87
Fri Jan 19, 2018 4:22 pm
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

A modem in bridge mode in the same subnet as Mikrotik sounds really strange. Can you paste here output of "/interface export hide-sensitive", "/ip address export" and "ip arp print" after replacing any eventual public address there with some p1.p1.p1.p1 value? Interface Export /interface bridge add...
by ibrahimovich87
Fri Jan 19, 2018 3:47 pm
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

Now the modem in bridge mode it's in the same subnet of the Mikrotik,

so i have only re-set the mode in PPoe mode, enable dhcp server on it, disable PPPoE interface on mikrotik, and after??
by ibrahimovich87
Fri Jan 19, 2018 3:29 pm
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

Wait a bit. In the other topic the discussion was about L2TP/IPsec. Do I get you right that the topic now actually does not deal with pure IPsec (without L2TP session setup) as the subject suggests, but merely with replacing the modem between the already configured Mikrotik and the internet while t...
by ibrahimovich87
Fri Jan 19, 2018 1:28 pm
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

You can start by configuring that provider's box to assign a fixed private address to your Routerboard's WAN interface (or by using static configuration on the Routerboard). - It's the same Mikrotik, i can use this configuration IP because the other router that now it's in bridge mode (i have to tes...
by ibrahimovich87
Fri Jan 19, 2018 12:40 pm
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Re: Need To Create VPN IPSEC

First, does that provider's device get a public IP address from the provider? Second, is that public address fixed or it may change with each assignment? Third, how exactly does the DMZ work on that device? To act as the "server" side of the IPsec connection, the RouterBoard needs to be able to rec...
by ibrahimovich87
Fri Jan 19, 2018 11:41 am
Forum: General
Topic: Need To Create VPN IPSEC
Replies: 20
Views: 1627

Need To Create VPN IPSEC

Hi, first sorry for my very bad english....need help for create a VPN IPSEC, the problem it's this... in Italy one of ISP that offer VDSL via Fiber only accept to connect to ISP using only Modem/router that he give to us...so i canno't leave it for connection....the second problem it's that not poss...
by ibrahimovich87
Fri Jan 19, 2018 11:35 am
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

can i write in PVT for another question? Yes, if you know how. I cannot use the "contact XXX" link at your user page and haven't found any setting relevant to private message permission in the outgoing direction - in incoming direction, I have them permitted by default. Maybe you have forbidden it ...
by ibrahimovich87
Thu Jan 18, 2018 4:20 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

So what I've suspected has really happened. You've made the change in safe mode, but you haven't pressed the Ctrl-X again to leave the safe mode before leaving the session, and so the change got rolled back. So repeat the steps described in post #26 of this topic, except that after changing the ini...
by ibrahimovich87
Wed Jan 17, 2018 3:45 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

So what I've suspected has really happened. You've made the change in safe mode, but you haven't pressed the Ctrl-X again to leave the safe mode before leaving the session, and so the change got rolled back. So repeat the steps described in post #26 of this topic, except that after changing the ini...
by ibrahimovich87
Wed Jan 17, 2018 1:08 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

what is the result of "/ip address export" right now?
/ip address
add address=192.168.98.4/24 comment=defconf interface=ether2-master network=192.168.98.0
by ibrahimovich87
Wed Jan 17, 2018 10:09 am
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

One more idea, maybe you simply haven't left the safe mode before logging off the RouterBoard or disconnecting after you have changed the interface to which your LAN IP is attached, so it got back to "ether2" from "bridge"? The safe mode works exactly that way - if the management session where the ...
by ibrahimovich87
Tue Jan 16, 2018 6:46 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

Ok,

i've got same problem if i will try to connect via Iphone using 4G connection....i can connect to VPN but i cannot connect to my server the second time i've tried
by ibrahimovich87
Tue Jan 16, 2018 5:56 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

You haven't written whether the problem at home is only with Win10 or also with the iPhone. If iPhone works both at home and in the office/school, the issue may be related to difference between iOS and Windows in handling L2TP over IPsec; if none of the two works at home, something regarding the ne...
by ibrahimovich87
Tue Jan 16, 2018 12:48 pm
Forum: Beginner Basics
Topic: Firewall e Nat Rule - FTP Upload
Replies: 6
Views: 655

Firewall e Nat Rule - FTP Upload

Hi,

need help to configure a FTP (active mode) upload from my server ip 192.168.98.222

that can upload VIA ftp a file outside can anyone help me? Thank you
by ibrahimovich87
Mon Jan 15, 2018 9:58 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

Prego/нема на чему. If a topic's initial issue got resolved, it is a good idea to mark the final answer as "solved" so that other people searching the forum can see that. I assume only the OP (original poster) may set such verdict. Hi sindy...i've got problem connecting from my home with windows 10...
by ibrahimovich87
Mon Jan 15, 2018 3:57 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

Safe mode can only be activated in one management session. So if you have activated it somewhere else than in console (the command line window), deactivate it there, then press Ctrl-X in console window, you should see <SAFE> in the prompt. Then, "/ip address print" shows you all IP addresses with l...
by ibrahimovich87
Mon Jan 15, 2018 2:04 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

So everything in the same subnet except that the server is on the LAN and the client is connected via L2TP. Normally, I would expect that the end of this manual chapter is relevant, you have to permit proxy-arp functionality at the LAN interface to which the server is connected, but your configurat...
by ibrahimovich87
Mon Jan 15, 2018 1:38 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

192.168.98.4 is Mikrotik
192.168.98.70 is the client via L2TP
what is the IP of the server and how is it connected to the Mikrotik?
192.168.98.222
by ibrahimovich87
Mon Jan 15, 2018 1:29 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

That IP in the log says that out of all the Mikrotik's own IPs, this one receives the IPsec packets from the client, so it is fine. You should see somewhere in the ppp server window that client Fabio is connected and which IP address it has been assigned (or use "/interface l2tp-server print"). Als...
by ibrahimovich87
Mon Jan 15, 2018 1:03 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

OK, we're getting somewhere :-) The lines right before the red one saying "Failed to pre-process ph2 packet" are important: no template matches failed to get proposal for responder A look at your exported config shows the following: /ip ipsec policy set 0 disabled=yes So the default policy template...
by ibrahimovich87
Mon Jan 15, 2018 12:49 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

What kind of remote device do you try to connect?
Iphone 5s and i'm trying with Windows 10 too...same error

this is the report
by ibrahimovich87
Mon Jan 15, 2018 12:46 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

OK. And if you try to connect your client now, you still get the same log messages like you did before or something else?
"Failed to pre-process ph2 packet"
"peer sent packet for dead phase2"
by ibrahimovich87
Mon Jan 15, 2018 12:40 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

Well, in your today's export I can see, at the peer in question, "disabled=yes" which was not there in your first export, so I guess you've found how to disable it. Now, "/ip ipsec peer print" should show the static peers and also the dynamic one created by the L2TP server. If the dynamic peer is n...
by ibrahimovich87
Mon Jan 15, 2018 12:21 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

Can't do because you don't know how to do that from Winbox or can't do because it is administratively prohibited? Whatever, the configuration export you've provided earlier contains a static peer configuration with "address=0.0.0.0/0". The L2TP server with IPsec set to "yes" or "required" (the latt...
by ibrahimovich87
Mon Jan 15, 2018 11:05 am
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Re: Problem with L2PT VPN [SOLVED]

Hi guys,

this is my L2TP server configuration (sorry but i can't do the export)
by ibrahimovich87
Fri Jan 12, 2018 5:23 pm
Forum: General
Topic: Problem with L2PT VPN [SOLVED]
Replies: 38
Views: 5309

Problem with L2PT VPN [SOLVED]

Hi i'm trying to configure a VPN L2PT for connect my outside device to my Mikrotik I receive this message when i'm trying to connect "failed to pre-process ph2 packet" "peer sent packet for dead phase 2" This is /export set allow-remote-requests=yes /ip dns static add address=192.168.98.4 name=route...
by ibrahimovich87
Thu Jan 11, 2018 6:10 pm
Forum: General
Topic: IPsec site-site tunnel behind NAT
Replies: 4
Views: 7489

Re: IPsec site-site tunnel behind NAT

mY Mikrotik it's behind a router in bridge mode
by ibrahimovich87
Thu Jan 11, 2018 5:51 pm
Forum: General
Topic: Help Creation VPN IPSEC [Solved]
Replies: 6
Views: 563

Re: Help Creation VPN IPSEC

If it was working, then there is no reason why it would go slow. Unless you have added some kind of queues. Please check CPU and end-to-end latency. I know...but it too very slow...i cannot send o receive packet very quick i've connected via Vnc Client to server and the connection it's impossibile ...
by ibrahimovich87
Thu Jan 11, 2018 5:23 pm
Forum: General
Topic: Help Creation VPN IPSEC [Solved]
Replies: 6
Views: 563

Re: Help Creation VPN IPSEC

Hi yes the current bytes it's increment's but it's very slowly...i think there is a kind of implementation that i didn't do...because yesterday...after all it was completely functionally
by ibrahimovich87
Thu Jan 11, 2018 4:57 pm
Forum: General
Topic: Help Creation VPN IPSEC [Solved]
Replies: 6
Views: 563

Re: Help Creation VPN IPSEC

Hi vince, yes, i can connect to a PC to the other Side but the connection it's very very slow
by ibrahimovich87
Thu Jan 11, 2018 11:05 am
Forum: General
Topic: Help Creation VPN IPSEC [Solved]
Replies: 6
Views: 563

Help Creation VPN IPSEC [Solved]

Hi, need a big help i have to create a VPN IP SEC from my Central to other two site, i have followd a lots of guide but i have two problem The connection it's established but i canno't ping o do other to the Internal IP of the other site the IP that i have it's this Praticamente la situazione è ques...
by ibrahimovich87
Wed Jan 10, 2018 6:35 pm
Forum: General
Topic: Connect RB951G-2HnD
Replies: 2
Views: 278

Re: Connect RB951G-2HnD

Hi, it's possibile to connect directly to ISP without other Modem?? Because i have a Drayteck router directly connect to ISP in Bridge mode with i have attached Mikrotik
by ibrahimovich87
Tue Jan 09, 2018 6:00 pm
Forum: General
Topic: Connect RB951G-2HnD
Replies: 2
Views: 278

Connect RB951G-2HnD

it's Possibile to connect RB951G-2HnD directly via PPoE to my Isp??

It's telecom italia (italy)

If it's possible how do i do it?

Thanks all
by ibrahimovich87
Thu Jun 29, 2017 10:15 pm
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Re: Need Help VPN l2tp

[quote="stshaw"]If you cannot ping hosts by IP address, then the VPN is not fully working, and RDP or other services will not work. I would suggest you follow my suggestions above--reset the router, enable basic router settings using Quick Set, then enable VPN using Quick Set. The L2TP VPN should wo...
by ibrahimovich87
Thu Jun 29, 2017 5:17 pm
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Re: Need Help VPN l2tp

Can you ping the RDP server? Is the server a Windows machine? Are you connecting using port 3389? Windows firewall will block connections from different subnets by default, so you might need to turn off the Windows firewall, or modify the rules. No impossibile to ping (firewall completely disactiva...
by ibrahimovich87
Thu Jun 29, 2017 3:17 pm
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Re: Need Help VPN l2tp

Solved.......i have firewall rules :-D

chain:input
dst. port: 500,4500,1701
Protocol UDP
Action: accept

and it's connect to vpn....

so the problem now it's that i canno't connect via RDP to my server (trhought VPN connection)
by ibrahimovich87
Tue Jun 27, 2017 11:19 am
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Re: Need Help VPN l2tp

dho....infact if i try to connect inside my lan i can connect to VPN...if i try to connect via my Iphone...it's not possibile...in log i cannot see any data connection
by ibrahimovich87
Tue Jun 27, 2017 11:16 am
Forum: Beginner Basics
Topic: Nat Rule - FTP Filezilla server
Replies: 5
Views: 6006

Re: Nat Rule - FTP Filezilla server

ok, if i would bind ip address that allow only to connect to my ftp-filezilla server? (or MAC address)
by ibrahimovich87
Tue Jun 27, 2017 1:35 am
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Re: Need Help VPN l2tp

Glad you got it working!
i've celebrete too fast.....from my home i cannot connect to IPSEC VPN.....uff...how can i re-set all? There is a guide to help me?

My internal Ip it's 192.168.1.1 (my mikrotik ip it0s 192.168.1.4)
by ibrahimovich87
Mon Jun 26, 2017 6:21 pm
Forum: Beginner Basics
Topic: Nat Rule - FTP Filezilla server
Replies: 5
Views: 6006

Nat Rule - FTP Filezilla server

Hi,

need help for create a nat rule that allow ftp connection to my serve from Ip Pubblic i've tried to create it, but if i try to upload file via FTP from my server, after activate NAT rule, it's impossibile to upload file
by ibrahimovich87
Mon Jun 26, 2017 11:54 am
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Re: Need Help VPN l2tp

I don't know whether it will work from inside your LAN. Probably not. It's not intended for that purpose. It's hard to help without more details. Here are some things to consider. 1. Did you add the correct firewall filter rule on the Mikrotik to open UDP ports 500 and 4500? This is not covered in ...
by ibrahimovich87
Fri Jun 23, 2017 1:08 pm
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Re: Need Help VPN l2tp

Hi,

i've tried to follow wikihow... if i try to connect from client internal my net i receive this error "xxx.xxx.xx.xx faile to pre-process ph2 packet"

if i try from client external my net in log receive nothing about negotiation or other.....in client i receive error 789
by ibrahimovich87
Thu Jun 22, 2017 6:40 pm
Forum: Beginner Basics
Topic: Need Help VPN l2tp
Replies: 19
Views: 2112

Need Help VPN l2tp

Hi, I am new to this. I need to set a configure a L2tp VPN I have Draytek Vigor in bridge mode and i have microtik with v6.39.2 i have searched on this forum and i have followed most guide but anyone solved my problem... i need to create vpn connection between my site and other PC / iphone /ipad out...