Community discussions

Search found 975 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 20
by Anumrak
Tue Aug 20, 2019 5:58 pm
Forum: General
Topic: IPv6 accept-ra bug
Replies: 2
Views: 405

Re: IPv6 accept-ra bug

I have a few RB951G's which act as APs/bridges (not routers). They have this configuration: /ipv6 settings set accept-router-advertisements=yes forward=no This kind of works, because the devices indeed accept RAs and self-assign IPv6 addresses and default routes, but there are two problems with it:...
by Anumrak
Mon Aug 12, 2019 5:35 pm
Forum: General
Topic: Allow traffic between isolated subnets? [SOLVED]
Replies: 8
Views: 594

Re: Allow traffic between isolated subnets? [SOLVED]

Hey. If you will shut the drop rule off, will the traffic forward between networks? If no, try to check the firewalls on PCs, if yes - try to set the input interface in upper rule.
by Anumrak
Fri Aug 09, 2019 5:49 pm
Forum: Beginner Basics
Topic: IPv6 Tunneling
Replies: 5
Views: 501

Re: IPv6 Tunneling

Hello, Thanks for the reply Yeah I just notice it since My IPv6 will only work when the router still enables the IPv4 address. Are there any references that I can read about this matter? books or papers? IPv4 connectivity as a box and your brand new IPv6 addresses as a items in the box. No box, no ...
by Anumrak
Fri Aug 09, 2019 5:16 pm
Forum: General
Topic: Routing users on MikroTik
Replies: 1
Views: 210

Re: Routing users on MikroTik

On one MikroTik router, I want to divide my users to two groups and assign each group to a separate network (two networks). How do I do that? Any Suggestion ? Thank you. Via one ethernet interface with vlan 2 and 3 networks 192.168.0.0/24 and 192.168.1.0/24 Via 2 interfaces same networks, but witho...
by Anumrak
Fri Aug 09, 2019 5:00 pm
Forum: General
Topic: Port forward for a PPTP VPN user
Replies: 2
Views: 259

Re: Port forward for a PPTP VPN user

Heya All! How do I open a port for a PPTP vpn user? I tried different solution online but it didn't worked. I mean that PPTP VPN user can use a service on that port. Local Address: 192.168.1.251 Remote Address: 192.168.1.250 Target Port: 7268 Thanks! Hey. Can you rephrase a sentance? PPTP server li...
by Anumrak
Wed Jul 17, 2019 10:33 am
Forum: Forwarding Protocols
Topic: OSPF Interface all passive
Replies: 9
Views: 1090

Re: OSPF Interface all passive

Not as easy when you have a few hundred vlans. Not bad to script but would be nice to have a simple checkbox to automatically have all interfaces as passive and then add the ones you want. /routing ospf interfaces add interface=all area=backbone passive=yes Exactly :) https://wiki.mikrotik.com/wiki...
by Anumrak
Tue Jul 16, 2019 11:06 am
Forum: Forwarding Protocols
Topic: OSPF Interface all passive
Replies: 9
Views: 1090

Re: OSPF Interface all passive

I wish there was a simple way to mark all instances as passive except the ones we add manually.
Its easy enough with winbox software as a GUI.
by Anumrak
Tue Jul 16, 2019 11:01 am
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 90
Views: 19942

Re: v6.44.5 [long-term] is released!

I wish the "long-term" channel would only have releases with bugfixes and security fixes, not a bunch of new features and underlying changes that need to be tested before I can apply the update to fix a security vulnerability. IMO, "long-term" channel should stay in 6.43.x branch and just receive f...
by Anumrak
Mon Jul 15, 2019 4:25 pm
Forum: Forwarding Protocols
Topic: PPPoE over VPLS Tunnel - Client Ping mac server pppoe but it does not connect
Replies: 6
Views: 513

Re: PPPoE over VPLS Tunnel - Client Ping mac server pppoe but it does not connect

When you do ping, its travel via IP protocols with ospf support. Try to look at your mpls LSP to your pppoe server.
by Anumrak
Mon Jul 15, 2019 4:18 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 90
Views: 19942

Re: v6.44.5 [long-term] is released!

I wish the "long-term" channel would only have releases with bugfixes and security fixes, not a bunch of new features and underlying changes that need to be tested before I can apply the update to fix a security vulnerability. IMO, "long-term" channel should stay in 6.43.x branch and just receive f...
by Anumrak
Thu Jul 11, 2019 5:38 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 648

Re: Network isolation using VRF?

I ended up just making a routing rule that drops between both networks.

Seems to me the cleanest way to do this.
or just firewall drop rule(s)

but in general, I agree.
by Anumrak
Thu Jul 11, 2019 4:09 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 90
Views: 19942

Re: v6.44.5 [long-term] is released!

Installed with a first attempt on hAP lite without any problem unlike 6.45.1.
by Anumrak
Wed Jul 03, 2019 8:15 pm
Forum: General
Topic: PPPoE Session packets being broadcast?? [SOLVED]
Replies: 40
Views: 2061

Re: PPPoE Session packets being broadcast?? [SOLVED]

1) It will help alot, especially if both clients in the same broadcast domain. They could interact with one another directly. It's not about direction of traffic. It's about misconfiguration of topic starter and abusing the "network hole" by someone in same vlan. I'm not sure we talk about the same...
by Anumrak
Wed Jul 03, 2019 4:23 pm
Forum: General
Topic: PPPoE Session packets being broadcast?? [SOLVED]
Replies: 40
Views: 2061

Re: PPPoE Session packets being broadcast?? [SOLVED]

My two cents: the target PPPoE client device doesn't send anything in its uplink direction so the ISP gear starts to broadcast frames for it after the record for that MAC in its forwarding table expires (this normally takes minutes after it has seen the last frame with client's MAC as source), wher...
by Anumrak
Wed Jul 03, 2019 3:43 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Hairpin NAT not working as expected
Replies: 5
Views: 601

Re: Hairpin NAT not working as expected

For hairpin NAT you need 3 rules, not just one. Common rule for Internet interface with destiantion nat from public to private for inbound interface Destination nat from public to private with your source for inbound local interface Masquerade nat from your source to private destination for outbound...
by Anumrak
Wed Jul 03, 2019 11:39 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 61307

Re: v6.45.1 [stable] is released!

spacex - We will look into this problem; Anumrak - Yes, hAP lite and similar routers are designed to run RouterOS bundle package and can be upgraded without any problems, as long as you do not store anything else on your router that might fill up the storage. If there is not enough space on the dis...
by Anumrak
Tue Jul 02, 2019 5:19 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 61307

Re: v6.45.1 [stable] is released!

Hey. What about low capacity of space in hAP lite? Watever I did, it says not enough space. Every time.
Try uninstall additional packages, then update. After update install packages.
This is abnormal behavior. I'll wait for a fix for this.
by Anumrak
Tue Jul 02, 2019 2:34 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 61307

Re: v6.45.1 [stable] is released!

Everyone who is experiencing problems with Winbox authorization - we will release a new Winbox loader with a fix for this problem as soon as possible. We are very sorry for any inconvenience caused. Hey. What about low capacity of space in hAP lite? Watever I did, it says not enough space. Every ti...
by Anumrak
Tue Jul 02, 2019 9:46 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 61307

Re: v6.45.1 [stable] is released!

Impossile to upgrade hAP lite. Please fix this. All unnecessary features were disabled. It's not working.
by Anumrak
Thu Jun 27, 2019 3:34 pm
Forum: Forwarding Protocols
Topic: OSPF Interface all passive
Replies: 9
Views: 1090

Re: OSPF Interface all passive

When setting ospf interface "all" as passive is it normal that state is "Down" 1 P interface=all cost=10 priority=1 authentication=none authentication-key="" authentication-key-id=1 network-type=broadcast instance-id=0 retransmit-interval=5s transmit-delay=1s hello-interval=10s dead-interval=40s us...
by Anumrak
Thu Jun 27, 2019 9:49 am
Forum: General
Topic: Mikrotik DHCP with redundant links.
Replies: 4
Views: 491

Re: Mikrotik DHCP with redundant links.

Hey. You can practice with HSRP in Cisco Packet Tracer. And with VRRP in MikroTik world. There is nothing to practice both vrrp and hasrp brings in to the same problem thats why i dont want to put dhcp on L3 switches on cisco both vrrp and hsrp is supported. What problem do you have with it?
by Anumrak
Thu Jun 27, 2019 9:41 am
Forum: General
Topic: IPv6 DHCP Server Not Leasing IP
Replies: 11
Views: 4308

Re: IPv6 DHCP Server Not Leasing IP

Should this work now in RouterOS v6.44.3? It's not working for me. I get an /48 range from Hurrican Electric ipv6 Tunnel. Everything works, but not the DHCP Server. I have set the address advertise=yes. But the firewall shows in the logs that there is no other traffic than ICMP. No DHCP traffic or ...
by Anumrak
Thu Jun 27, 2019 9:31 am
Forum: Forwarding Protocols
Topic: OSPF Loopback + MPLS Loopback
Replies: 7
Views: 1047

Re: OSPF Loopback + MPLS Loopback

To have two loopback addresses on a router (ospf + mpls) or will the ospf loopback do for mpls?
You need only one loopback address. You might need second one for second ospf process, but in correct network design you don't need second one.
by Anumrak
Wed Jun 26, 2019 5:06 pm
Forum: Forwarding Protocols
Topic: Combination of Static Routing and Dynamic!
Replies: 3
Views: 307

Re: Combination of Static Routing and Dynamic!

@Anumrak Thanks for your reply! On re-reading my question I will have to rephrase, Static routing for L2 bridged and Dynamic for OSPF, I want the options that if static routing is unreachable that OSPF dynamic routing will take over until static is reachable? Of course! =) Just manage administrativ...
by Anumrak
Wed Jun 26, 2019 3:03 pm
Forum: General
Topic: PPPoE Session packets being broadcast?? [SOLVED]
Replies: 40
Views: 2061

Re: PPPoE Session packets being broadcast?? [SOLVED]

Now I think I get it. I think the only way it's possible in ISP network is mac address learning of legit client on your ether1 port. Somehow. or it's a bug in ROS that allows you to see PADI frames with 8863 ethernet protocol numbers like 8864. Few months ago I saw a bug that prevent to watch data w...
by Anumrak
Wed Jun 26, 2019 2:02 pm
Forum: Forwarding Protocols
Topic: Combination of Static Routing and Dynamic!
Replies: 3
Views: 307

Re: Combination of Static Routing and Dynamic!

Of ourse it can. it's all about administrative distance of a static route over ad dynamic one. For example, AD of OSPF is 110 and exernal EIGRP has 170. You can "win" both with only 1 to increment. For example you can manage reserve static route for ospf with 111 and 171 with eigrp.
by Anumrak
Wed Jun 26, 2019 1:24 pm
Forum: General
Topic: PPPoE Session packets being broadcast?? [SOLVED]
Replies: 40
Views: 2061

Re: PPPoE Session packets being broadcast?? [SOLVED]

PPP frames inside ethernet providing unique layer 2 tunnel based on unicast frames on session level. Why torch should show you destination IP, when PPP tunnel operates only with mac address? Not sure I understand your post, is your question directed at me? Well yeah. I thought you didn't get why ds...
by Anumrak
Tue Jun 25, 2019 7:20 pm
Forum: General
Topic: PPPoE Session packets being broadcast?? [SOLVED]
Replies: 40
Views: 2061

Re: PPPoE Session packets being broadcast?? [SOLVED]

PPP frames inside ethernet providing unique layer 2 tunnel based on unicast frames on session level. Why torch should show you destination IP, when PPP tunnel operates only with mac address?
by Anumrak
Tue Jun 25, 2019 5:14 pm
Forum: General
Topic: Mikrotik DHCP with redundant links.
Replies: 4
Views: 491

Re: Mikrotik DHCP with redundant links.

Hey. You can practice with HSRP in Cisco Packet Tracer. And with VRRP in MikroTik world.
by Anumrak
Thu May 30, 2019 5:39 pm
Forum: General
Topic: Zen Internet IPv6 example?
Replies: 1
Views: 172

Re: Zen Internet IPv6 example?

Hey. Have you seen info on Mikrotik wiki?
by Anumrak
Wed May 29, 2019 5:36 pm
Forum: Beginner Basics
Topic: Blocking a mac address from getting internet [SOLVED]
Replies: 4
Views: 357

Re: Blocking a mac address from getting internet [SOLVED]

IP > Firewall uses IP addresses, not MAC addresses. If you want to block a MAC address the interface will have to be in a bridge, then use Bridge > Filter The ! means NOT - for example !192.168.1.42 means 'any address except 192.168.1.42' Actually, IP - Firewall - Filter can block mac addresses, al...
by Anumrak
Wed May 15, 2019 2:01 pm
Forum: Beginner Basics
Topic: Direct specific content through VPN
Replies: 4
Views: 277

Re: Direct specific content through VPN

Hey. It is better by IP addresses, because you deal with a router, not specific hardware. Content is a layer 7, so it can be done, but it's very hard to do on a CPU. You should google for topics "layer 7 filtering/marking on mikrotik".
by Anumrak
Wed May 15, 2019 1:58 pm
Forum: Beginner Basics
Topic: Bruteforce login prevention doesn't work
Replies: 1
Views: 187

Re: Bruteforce login prevention doesn't work

Hey. Are you sure that all 5 rules added to your firewall section in right order? Like drop, blcklst, s3,2,1. Drop on the top and the stage 1 on the bottom.
by Anumrak
Wed May 15, 2019 11:38 am
Forum: Beginner Basics
Topic: A little help to configure a NAT
Replies: 3
Views: 285

Re: A little help to configure a NAT

Why just don't use VRRP or VRRP+OSPF?
by Anumrak
Wed May 15, 2019 11:29 am
Forum: Beginner Basics
Topic: VPN PPTP Passthrough Problem
Replies: 4
Views: 361

Re: VPN PPTP Passthrough Problem

Hello, i have a rather simple setup here with a Mikrotik router, and a SBS 2008 with a PPTP vpn server. I'm trying to get pptp vpn passthrough to work, but it doesn't seem to work. Port 1723 forwarding seems to work, but data doesn't seem to pass through. I've seen many references to a PPTP helper,...
by Anumrak
Wed May 15, 2019 11:26 am
Forum: General
Topic: facebook and instagram problem..
Replies: 1
Views: 129

Re: facebook and instagram problem..

Aaaand...a tech diag?
by Anumrak
Wed May 15, 2019 11:18 am
Forum: General
Topic: dst-nat with changing port
Replies: 20
Views: 916

Re: dst-nat with changing port

We're all here to help ;)
by Anumrak
Wed May 15, 2019 11:12 am
Forum: Beginner Basics
Topic: Open all ports on all devises [SOLVED]
Replies: 6
Views: 455

Re: Open all ports on all devises [SOLVED]

It does not work that way. A NAT forwards to a target IP. However in most situations, if the game is talking to a server somewhere else, the client initiates the connection and the router will forward responses to the IP that originated the request. No special setup is normally required. If you are...
by Anumrak
Wed May 15, 2019 10:48 am
Forum: General
Topic: dst-nat with changing port
Replies: 20
Views: 916

Re: dst-nat with changing port

You should check availability of your changed port from outside, for example, on some web site that can check it. If it closed then your ISP just filtering unknown ports. Also you have to have a global unique IP address, not from private range.
by Anumrak
Wed May 15, 2019 10:08 am
Forum: Beginner Basics
Topic: [solved] VLAN-subnet over 3 devices / routing? switching?
Replies: 3
Views: 256

Re: VLAN-subnet over 3 devices / routing? switching?

Hey. If your routers are far from each other, then maybe you will need EoIP + OSPF. You can use iBGP too, but you really need to think first, why do you need that. In order to reach other host on layer 2, all you need is create vlan interface and tag it with appropriate vlan, also choose correct eth...
by Anumrak
Wed May 15, 2019 10:00 am
Forum: General
Topic: RB750GR3 for a 30 PCs Gaming event?
Replies: 10
Views: 513

Re: RB750GR3 for a 30 PCs Gaming event?

Nope, Gr3 won't do. Since you want ot balance, you'll need to skip FastTrack. Without it gr3 won't be able to cope with bandwidth.

You need more power. 4011 will do for example
I don't get why you think hEX won't handle it.
by Anumrak
Tue Apr 30, 2019 2:00 pm
Forum: Beginner Basics
Topic: Gateway Issue
Replies: 1
Views: 143

Re: Gateway Issue

by Anumrak
Fri Apr 26, 2019 5:02 pm
Forum: Forwarding Protocols
Topic: MPLS does not mark anything in the table
Replies: 3
Views: 356

Re: MPLS does not mark anything in the table

Did you enable mpls on interfaces?
by Anumrak
Fri Apr 26, 2019 4:27 pm
Forum: Beginner Basics
Topic: Forward traffic to another router
Replies: 4
Views: 298

Re: Forward traffic to another router

I don't understand how you directly connect 1.10 and 1."something" on server second interface. Because your router doesn't have any 1.0 ip address on ether4 interface. And second note - server from 2.0 network can not interact with 1.0 without a route(specific or default one). You need fix this thing.
by Anumrak
Fri Apr 26, 2019 3:53 pm
Forum: Beginner Basics
Topic: Forward traffic to another router
Replies: 4
Views: 298

Re: Forward traffic to another router

Hey. Paste your ipv4 route list here pls :)

Does your pfSense server have a default route?
by Anumrak
Fri Apr 26, 2019 3:49 pm
Forum: General
Topic: WinBox memory consumption
Replies: 1
Views: 178

Re: WinBox memory consumption

:O have to check out my consumption :)
by Anumrak
Tue Apr 23, 2019 3:46 pm
Forum: General
Topic: Ping IPSEC host from router
Replies: 20
Views: 856

Re: Ping IPSEC host from router

What about accept nat rule for your host in the tunnel before main src-nat rule? That would be one way to solve it; the other one, consistent with the approach already used, is to add an action=notrack dst-address-list=corp_nets rule also to chain=output of /ip firewall raw . The explanation is tha...
by Anumrak
Tue Apr 23, 2019 1:59 pm
Forum: General
Topic: Ping IPSEC host from router
Replies: 20
Views: 856

Re: Ping IPSEC host from router

Hey. What about accept nat rule for your host in the tunnel before main src-nat rule? You are nating your requests into global IP address.
by Anumrak
Tue Apr 23, 2019 1:29 pm
Forum: General
Topic: Ping Loss at line 9
Replies: 6
Views: 544

Re: Ping Loss at line 9

Thank you for your reply. However you say that data flows much faster through them than in them, does this include pings that are passed through the routers to later routers but with higher latencies that persist to the end of the traceroute. Are real packets suffering the same latency? Gamers are ...
by Anumrak
Tue Apr 23, 2019 9:40 am
Forum: Beginner Basics
Topic: IPSec tunnel failing
Replies: 7
Views: 445

Re: IPSec tunnel failing

What IP address do you get from your ISP? Is it from private range or global? Or from 100.64.0.0/12? And yeah can you simply ping another router? Or can you ping yourself from other side?
  • 1
  • 2
  • 3
  • 4
  • 5
  • 20