Community discussions

MikroTik App

Search found 88 matches

by jphconstantin
Tue May 19, 2020 4:26 pm
Forum: Beginner Basics
Topic: port scanner and VPN
Replies: 5
Views: 522

Re: port scanner and VPN

What do you mean by "between the server and the client" ? Is the client that same IP?
Between the both extremities of the vpn (router to router).
The other router is a Teltonika RUT955. Both routers use openVPN.
which firewall do you mean
The one into the Mikrotik router.
by jphconstantin
Tue May 19, 2020 3:32 pm
Forum: Beginner Basics
Topic: port scanner and VPN
Replies: 5
Views: 522

Re: port scanner and VPN

Hello, Thank you for your answer. I was anxious ! There is no more data in the log with these ip addressees, but only data between the server and the client. Is it preferable to block these scans ? I have seen firewall rules in the wiki but I don't know where to insert them: at the beginning ph the ...
by jphconstantin
Mon May 18, 2020 6:27 pm
Forum: Beginner Basics
Topic: port scanner and VPN
Replies: 5
Views: 522

port scanner and VPN

Hello,
I analysed the log and noted this lines:

ovpn, info connection established from 198.108.67.48
ovpn,debug,packet sent P_CONTROL_HARD_RESET_SERVER ...

also with 198.108.66.202

Does it means that a port scanner has cracked my VPN data link ?
by jphconstantin
Fri Aug 16, 2019 4:26 pm
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 1
Views: 485

Re: VPN/ipsec with strongSwan

Just before the error, the log display this:

Image
by jphconstantin
Thu Aug 15, 2019 6:06 pm
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 1
Views: 485

VPN/ipsec with strongSwan

Hello, I tried to establish a VPN/Ipsec between my Mikrotik router and my Android tablet. Side Android, I installed strongSwan. Side Mikrotik: /ip ipsec mode-config add address-pool=ike2-pool address-prefix-length=32 name=ike2-conf \ split-include=0.0.0.0/0 /ip ipsec policy group add name=ike2-polic...
by jphconstantin
Wed Aug 14, 2019 2:41 pm
Forum: Beginner Basics
Topic: Questions about certificates
Replies: 0
Views: 520

Questions about certificates

Hello,

1) In order to create a new CA, I remove it and ... all certificates have been deleted ! normal or not ?

2) I created a CA, signed it and now I want to modifiy it: how to proceed correctly ?
by jphconstantin
Mon Aug 12, 2019 4:24 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

Hello Jorge, Filezilla: I am using SFTP, not FTP. FTP is in passive mode. /ip firewall filter add action=fasttrack-connection chain=forward connection-state=established,related add action=accept chain=input disabled=yes in-interface=ovpn-vers-eison add action=accept chain=forward disabled=yes in-int...
by jphconstantin
Sun Aug 11, 2019 6:56 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

Hello, I installed ssh on 192.168.2.34, created an incoming rule for port 22 RUT955: lan to vpn accept masquerading=yes / vpn to lan accept masquerading=yes Everything is ok: ping, traceroute, ssh, winscp from 192.168.2.34 and from any server-side machines - filezilla gives still an error - openvpn ...
by jphconstantin
Fri Aug 09, 2019 5:47 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

Hello, traceroute 192.168.2.34 from a serve-side pc stops after 172.22.22.2 ok if I disable the 192.168.2.34 firewall ssh -vv jpc@192.168.2.34 connection refused if firewall disable stays blocking in connecting ... if firewall enable From the server: currently only the ping messages go thru the tunn...
by jphconstantin
Fri Aug 09, 2019 5:13 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

@jorgito Thank you for your compassion ! Yes, I have the 00.06.04 version tcpdump -nn -i tun_c_rut955_ovpn_client returns: no such device exists ip link show display for tun...client: ... mtu 1500 qdisc fq_code1 state UNKNOWN mode DEFAULT group default qlen 100 ip a display: same line + link/none + ...
by jphconstantin
Fri Aug 09, 2019 5:09 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

@csalcedo
Yes, with a great interest !
If you could send me (by MP) the both configs ...
Thanks by advance
best regards,

jean-philippe
by jphconstantin
Fri Aug 09, 2019 3:06 pm
Forum: Beginner Basics
Topic: ovpn packets
Replies: 1
Views: 446

ovpn packets

Crazy question ...

How to display the content of the ovpn packets ?

/system logging add topics=ovpn,packet,debug doesn't display packets content

Thanks by advance
by jphconstantin
Fri Aug 09, 2019 2:24 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

As your suggestion I set the following rules for Teltonika: vpn to lan accept forward traffic lan to vpn accept forward traffic I try to connect a computer from the server lan (with putty or winscp) to the computer 192.168.2.34 with its firewall disable : no success (but ping ok). I also tried filez...
by jphconstantin
Thu Aug 08, 2019 8:26 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

My knowledge is limited indeed. I note in the Teltonika > Traffic rules: 1) allow-ping from any host in wan, to any router IP on this device, input chain 2) allow-vpn-traffic from any host in wan, to any router IP on this device, input chain I turn off the firewall on the 192.168.2.34 and I can ping...
by jphconstantin
Thu Aug 08, 2019 7:42 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

1) Ok I can ping 172.22.22.2 and the router 192.168.2.1 but not the client PCs 2) the client log display every x seconds the following message: daemon.err .... write to TUN/TAP : Invalid argument (code=22) that is why I ask the question about the compression 3) according to Jorge suggestion, I added...
by jphconstantin
Thu Aug 08, 2019 6:47 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

Hello Jorge, For the "server2" certificate I didn't select tls server in key usage For the client certificate I didn't select tls client in key usage Shall I regenerate them ? In /ppp profile I have the option use-compression=default Shall I set use-compression=no because Mikrotik doesn't support LZ...
by jphconstantin
Thu Aug 08, 2019 6:01 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

hello again,
I note that I didn't fill the country, state, ... fields for the ca certificate but I did it for the server.
I also note that the days valid field of the ca is different of the server
Is it a potential source of errors ?

Jean-Philippe
by jphconstantin
Thu Aug 08, 2019 5:02 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

Hello Jorge, Nice to read you again ! This is my network configuration: https://i.imgur.com/y52hH4F.jpg I read carefully (I thought ...) Mikrotik wiki but Here is my Mikrotik server side config: /ppp secret add name=user1 profile=ovpn service=ovpn /ppp profile add name=ovpn local-address=172.22.22.1...
by jphconstantin
Sun Aug 04, 2019 4:13 pm
Forum: Beginner Basics
Topic: Several VPN, several certificates
Replies: 1
Views: 544

Several VPN, several certificates

Hello, I configured a VPN/IPSec according to the wiki https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_using_IKEv2_with_RSA_authentication between my router and an Android tablett: everything is fine. Now I want to add a new VPN (site to site) by using OVPN. 1) Is it possible to hav...
by jphconstantin
Sat Aug 03, 2019 6:38 pm
Forum: Beginner Basics
Topic: Where is openvpn ?
Replies: 4
Views: 724

Re: Where is openvpn ?

@sob: thank you. Therefore nothing to install
@ros44: it is in my signature
by jphconstantin
Sat Aug 03, 2019 4:38 pm
Forum: Beginner Basics
Topic: Where is openvpn ?
Replies: 4
Views: 724

Where is openvpn ?

Hello,
I didn't find in the packages OpenVpn: where is it and how to install it ?
Thank you
by jphconstantin
Fri Aug 02, 2019 8:08 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

Re: site to site ipsec Mikrotik/Teltonika

Thank you Jorge but a fully description of both sides should be appreciable ... Some questions (for the time being ...): 1) The RUT955 has a private IP address because it is a 4G router and my provider doesn't distribute public address. What is/are the consequence(s) in the configuration of the Mikr...
by jphconstantin
Sun Jul 28, 2019 4:41 pm
Forum: General
Topic: site to site ipsec Mikrotik/Teltonika
Replies: 24
Views: 3632

site to site ipsec Mikrotik/Teltonika

Hello,
In the wiki, IPSec section, chapter 17.1, there is an example of "Site to site IPSec tunnel"
In my case the site 2 have openvpn, this is not a Mikrotik router (Teltonika RUT955)

Could you give me a roadmap how to config the site 2 or a reference to a tutorial ?

Thank you by advance,
by jphconstantin
Wed Jul 10, 2019 6:10 pm
Forum: Beginner Basics
Topic: road warrior clients + ikev2 + ipsec
Replies: 1
Views: 428

road warrior clients + ikev2 + ipsec

Hello,
In the chapter 17.2 of the wiki, there is a good example how to use ipsec without l2tp
Each client shall have a certificate but can the client certificate be the same for all clients ?
Thank you,
by jphconstantin
Fri Jun 21, 2019 7:25 pm
Forum: General
Topic: IKEv2 ROS 6.44.3 (Stable) + android + strongswan
Replies: 3
Views: 766

Re: IKEv2 ROS 6.44.3 (Stable) + android + strongswan

you are lucky ...
by jphconstantin
Tue Jun 18, 2019 1:53 pm
Forum: Beginner Basics
Topic: l2tp/ipsec with Android smartphone
Replies: 2
Views: 1550

Re: l2tp/ipsec with Android smartphone

Thank you for your reply. I set remote-address to 192.168.1.36 as you advice me ! But always the same error: StopCCN code=6 I use an Android smartphone, not Windows Note 1: I followed the "Basic L2TP/IpSec setup" described in https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP Note 2: resume of the...
by jphconstantin
Mon Jun 17, 2019 3:40 pm
Forum: Beginner Basics
Topic: l2tp/ipsec with Android smartphone
Replies: 2
Views: 1550

l2tp/ipsec with Android smartphone

Hello, I try to config my router in L2TP/IPsec in order to interface my Android smartphone. In /ppp secret local-address = gateway address = local router address(192.168.1.1) remote-address = ? the smartphone has an IP address (192.168.1.36) but the phone provider change it (83.x.y.z): what info sha...
by jphconstantin
Mon Jun 17, 2019 3:10 pm
Forum: Beginner Basics
Topic: Config VPN and DDNS + smartphone
Replies: 5
Views: 992

Re: Config VPN and DDNS + smartphone

Have you tried to connect with pc/laptop?
No
L2TP/IPSec
I will follow your advice

But how to clean (reset, delete, ...) what I have defined ?
by jphconstantin
Sun Jun 16, 2019 4:40 pm
Forum: Beginner Basics
Topic: Config VPN and DDNS + smartphone
Replies: 5
Views: 992

Re: Config VPN and DDNS + smartphone

I guess the Mikrotik Tutorial 19 is not anymore up to date and that I must read the wiki or if you can give me references ...
Note that I have installed the 6.44.3 OS version.
by jphconstantin
Fri Jun 14, 2019 4:57 pm
Forum: Beginner Basics
Topic: Config VPN and DDNS + smartphone
Replies: 5
Views: 992

Re: Config VPN and DDNS + smartphone

Yes, the public address is unique. I don't undertand your question ... beginner basics forum -> give me the command please I changed in my smartphone the vpn config: I setup <number>.sn.mynetname.net instead of the public address as the address server: nothing changed Note 1: PPP > interface: empty ...
by jphconstantin
Thu Jun 13, 2019 6:59 pm
Forum: Beginner Basics
Topic: Config VPN and DDNS + smartphone
Replies: 5
Views: 992

Config VPN and DDNS + smartphone

Hello, I followed CAREFULLY the Mikrotik Tutorial 19 for the configuration of my router. I want to establish a connection from my Samsung smartphone. I defined a VPN on it: name: Office Server address: the internet address of my Mikrotik router Password: the password defined in the quick set for the...
by jphconstantin
Fri May 17, 2019 3:32 pm
Forum: General
Topic: sfp parameters missing
Replies: 1
Views: 587

sfp parameters missing

Hi,
How to configure the router in order to have the missing parameters ?
by jphconstantin
Wed May 01, 2019 5:06 pm
Forum: General
Topic: fcs error?????
Replies: 13
Views: 52913

Re: fcs error?????

I also have this message in my log during 6 days
The connected machine is a Raspberry 3b+, I disconnected during 6 days and the message was logged. Now I am back, reconnected the RPI and no message.
The cable is long: 10 meters !
Antenna effect ?
by jphconstantin
Sun Apr 14, 2019 4:18 pm
Forum: Beginner Basics
Topic: check and protect smb from outside
Replies: 2
Views: 588

check and protect smb from outside

Hello, I would like to check if my Mikrotik router is well protected against ports attacks from outside, mainly all concerning smb protocol. What is the best procedure to do that ? Has Mikrotik a tool for checking ? I can define a firewall rule in the input chain but I want to also allow the smb pro...
by jphconstantin
Sun Jan 20, 2019 7:08 pm
Forum: Beginner Basics
Topic: Upgrade after a long time
Replies: 3
Views: 360

Re: Upgrade after a long time

[admin@MikroTik] > /interface export # jan/20/2019 18:07:12 by RouterOS 6.40.5 # software id = CCV8-MISI # # model = CCR1009-7G-1C # serial number = 7AF40788DE3D /interface bridge add name=bridge1 /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik /interface...
by jphconstantin
Sun Jan 20, 2019 6:31 pm
Forum: Beginner Basics
Topic: Upgrade after a long time
Replies: 3
Views: 360

Upgrade after a long time

Hello, I didn't upgrade my ccr1009-7g-1c-pc since a very long time ... The RouterOs version is 6.40.5 The latest is 6.43.8 As I read in the wiki that some parts have been rewritten then I don't dare upgrade. First of all I shall backup the configuration and, in case of problems, I could reinstall it...
by jphconstantin
Fri Feb 02, 2018 10:37 am
Forum: Beginner Basics
Topic: How to limit the encrypted bittorrent bandwidth
Replies: 0
Views: 438

How to limit the encrypted bittorrent bandwidth

Hello, According to the wiki, the p2p chain properties doesn't work on encrypted bittorrent. Which is the best approach for implementing a bandwidth management in that case ? - define a input port for the download traffic - define a output port for the upload traffic - define mangle rules (connectio...
by jphconstantin
Tue Jan 02, 2018 8:09 pm
Forum: Beginner Basics
Topic: call a function localized in a script
Replies: 1
Views: 254

call a function localized in a script

Hello,
I wrote a lot of functions grouped into a script:
#scriptA
:global fctA do={...}
:global fctB do={...}
etc

How can I call one of these functions in another script ?
#scriptB
.../system script run scriptA ...fctB ...
by jphconstantin
Tue Jan 02, 2018 8:03 pm
Forum: Beginner Basics
Topic: How to debug a script ?
Replies: 6
Views: 3618

Re: How to debug a script ?

Can I display variables ?
by jphconstantin
Fri Dec 29, 2017 6:00 pm
Forum: Beginner Basics
Topic: How to debug a script ?
Replies: 6
Views: 3618

How to debug a script ?

I added script in /system logging but I see nothing in the log window when I execute a script.
What is missing ?
by jphconstantin
Thu Dec 28, 2017 7:38 pm
Forum: Beginner Basics
Topic: change the clock format
Replies: 0
Views: 275

change the clock format

The /system clock get date return a string with this format: mmm/dd/yyyy
How to change the format (i.e dd/mmm/yyyy ) ?

Excepted with the pick function, I don't see any solution.
by jphconstantin
Wed Dec 27, 2017 7:40 pm
Forum: Beginner Basics
Topic: Netinstall process
Replies: 2
Views: 391

Re: Netinstall process

Could you developp ?
by jphconstantin
Thu Dec 21, 2017 7:43 pm
Forum: Beginner Basics
Topic: Netinstall process
Replies: 2
Views: 391

Netinstall process

Question of curiosity ...
How does Netinstall detect a router when winbox isn't able to do it !?
by jphconstantin
Mon Dec 18, 2017 5:23 pm
Forum: Beginner Basics
Topic: My router probably broken ?
Replies: 11
Views: 911

Re: My router probably broken ?

After several attempts (?) , winbox has discovered the router
Thank you very much. You save my life before Xmas !

Next time, I will do a backup OUTSIDE of the router before to upgrade it.
I don't understand this failure during the upgrade.
by jphconstantin
Mon Dec 18, 2017 4:15 pm
Forum: Beginner Basics
Topic: My router probably broken ?
Replies: 11
Views: 911

Re: My router probably broken ?

I downloaded netinstall and installed it I connect my cable on ether7 port (because ccr) I turn the power off With Net booting, I set an IP (192.168.1.199) I pressed the reset button and turn on the power ... Now I see the mac address with the status of ready !!!!! Yes it was really the time for net...
by jphconstantin
Mon Dec 18, 2017 3:50 pm
Forum: Beginner Basics
Topic: My router probably broken ?
Replies: 11
Views: 911

Re: My router probably broken ?

no antivirus !
no wifi
just the router connected on a switch to a computer

Note: I downloaded and installed mactelnet on linux debian
I typed the mac address of the router: connection failed
I tried both mac addresses
by jphconstantin
Mon Dec 18, 2017 3:26 pm
Forum: Beginner Basics
Topic: My router probably broken ?
Replies: 11
Views: 911

Re: My router probably broken ?

Thank you @BartoszP
I clicked Neighbours: no discovered device
I tried refresh: idem
Note:cable on ether1, bip every 10 seconds after power off/on
by jphconstantin
Mon Dec 18, 2017 2:46 pm
Forum: Beginner Basics
Topic: My router probably broken ?
Replies: 11
Views: 911

Re: My router probably broken ?

Sorry but I don't understand: be explicit please
by jphconstantin
Mon Dec 18, 2017 1:55 pm
Forum: Beginner Basics
Topic: My router probably broken ?
Replies: 11
Views: 911

My router probably broken ?

Hello, Yesterday I tried to upgrade to the last stable version. When I pressed "Download and Install" button, then nothing happens. After a few seconds I hear a bip. - The sfp led was off. - The PWR blue led on - bip every 10 secondes I asked my neighbour: his fiber connection was ok. I decided to d...
by jphconstantin
Mon Dec 11, 2017 6:42 pm
Forum: Beginner Basics
Topic: denied winbox/dude message
Replies: 7
Views: 12098

Re: denied winbox/dude message

I believed that the fasttrack rules should be the first ones ?
by jphconstantin
Mon Dec 11, 2017 4:01 pm
Forum: Beginner Basics
Topic: denied winbox/dude message
Replies: 7
Views: 12098

Re: denied winbox/dude message

No I don't want any access to winbox from the WAN.
I suppose I will find how to fix that in the wiki.
Thank you.
by jphconstantin
Sun Dec 10, 2017 7:50 pm
Forum: Beginner Basics
Topic: icmp messages in log
Replies: 1
Views: 473

icmp messages in log

Found in my log several messages such as:
input: in: combo1 out:(none) src-mac: f8:66:f2:28:9a:ff proto ICMP (type 8, code 0) 46.234.125.89 > my_ip_address
Shall I consider as an attack ?
by jphconstantin
Sun Dec 10, 2017 7:39 pm
Forum: Beginner Basics
Topic: denied winbox/dude message
Replies: 7
Views: 12098

denied winbox/dude message

Hello,
Found in my log:
denied winbox/dude connect from 5.39.218.37
Shall I consider that as an attempt of attack ?
Shall I protect better my router ?

Thank you,
by jphconstantin
Thu Nov 16, 2017 1:59 pm
Forum: Beginner Basics
Topic: NAT doesn't work when IP ranges are specified
Replies: 16
Views: 1334

Re: NAT doesn't work when IP ranges are specified

Illogical ?
Forward the Voip traffic to a group of phones: how do you make that ?
by jphconstantin
Wed Nov 15, 2017 8:26 pm
Forum: General
Topic: [Answered] Where are ip firewall address-list timeout values documented
Replies: 5
Views: 4608

Re: [Answered] Where are ip firewall address-list timeout values documented

For me, "1d 00:00:00" works but "1w2d3h4m5s" and "1d 2h 12:30" don't work in the winbox. OK in the CLI.
The correct syntax is not described in the wiki !
by jphconstantin
Thu Oct 12, 2017 4:06 pm
Forum: Beginner Basics
Topic: forward chain: no packets go through [SOLVED]
Replies: 10
Views: 1571

Re: forward chain: no packets go through [SOLVED]

But in the manual, in the firewall rules examples, the "connection-type" is not set.
In service-ports, I disabled sip
I am not PPPoE


I turn off my sip phone and turn on: now the sip phone is registered !
I can call it and can call with

Thank you for everybody.
It's hard to be beginner !
by jphconstantin
Thu Oct 12, 2017 3:18 pm
Forum: Beginner Basics
Topic: forward chain: no packets go through [SOLVED]
Replies: 10
Views: 1571

Re: forward chain: no packets go through [SOLVED]

all ports in my bridge. ether1,3,4 have devices. /ip firewall nat print Flags: X - disabled, I - invalid, D - dynamic 0 chain=srcnat action=masquerade out-interface=combo1 log=no log-prefix="" 1 X ;;; VOIP chain=dstnat action=dst-nat to-ports=5060 protocol=tcp src-address-list=Phones dst-address-lis...
by jphconstantin
Thu Oct 12, 2017 1:47 am
Forum: Beginner Basics
Topic: forward chain: no packets go through [SOLVED]
Replies: 10
Views: 1571

Re: forward chain: no packets go through [SOLVED]

yes. I think I am obliged to use a bridge (correct me if i am wrong) if not, ether3 and ether4 don't communicate with internet and ether1 doesn't "see" these ports (ping fails). i created the bridge in the "interface list" window: correct ? The bridge button display the created bridge. I do: bridge ...
by jphconstantin
Thu Oct 12, 2017 12:01 am
Forum: Beginner Basics
Topic: forward chain: no packets go through [SOLVED]
Replies: 10
Views: 1571

Re: forward chain: no packets go through [SOLVED]

I have one ccr1009-7g-1c-pc connected to internet through combo1 (sfp). On the ether4 I connect a cisco phone (spa301). The SIP Provider has 8 servers. On the ether3 I connect an access point (tablett, notebook, ...). On the ether1 a physical machine with virtual machines. All these things are in th...
by jphconstantin
Wed Oct 11, 2017 7:53 pm
Forum: Beginner Basics
Topic: forward chain: no packets go through [SOLVED]
Replies: 10
Views: 1571

Re: forward chain: no packets go through [SOLVED]

Yes this is the question: why ?
I should answer myself but ...
I think my ccr is not correctly configured and this explains that.
May I submit what I want to connect to my ccr and could you help me to configure the base ?
by jphconstantin
Wed Oct 11, 2017 7:09 pm
Forum: Beginner Basics
Topic: forward chain: no packets go through [SOLVED]
Replies: 10
Views: 1571

forward chain: no packets go through [SOLVED]

I think I didn't understand the flow across the chains. The manual has a good scheme (packet flow) but not easy for beginners. There are my rules: 1 ;;; Accept all establish related connection chain=input action=accept connection-state=established,related log=no log-prefix="" 2 X ;;; Drop port scann...
by jphconstantin
Wed Oct 11, 2017 6:56 pm
Forum: Beginner Basics
Topic: why ipv4-fasttrack-active set to no ?
Replies: 9
Views: 2626

Re: why ipv4-fasttrack-active set to no ?

Yes. 8) CCR support conditions are met Does the position of the rule important ? (for me dummy=0, fasttrack=1) /ip firewall filter> print Flags: X - disabled, I - invalid, D - dynamic 0 D ;;; special dummy rule to show fasttrack counters chain=forward action=passthrough 1 chain=forward action=fastt...
by jphconstantin
Wed Oct 11, 2017 4:00 pm
Forum: Beginner Basics
Topic: why ipv4-fasttrack-active set to no ?
Replies: 9
Views: 2626

Re: why ipv4-fasttrack-active set to no ?

I had a glance at the forum and noted that many people have problem with fasttrack.
Shall I understand that this function is not yet operational ?
by jphconstantin
Tue Oct 10, 2017 5:03 pm
Forum: Beginner Basics
Topic: why ipv4-fasttrack-active set to no ?
Replies: 9
Views: 2626

Re: why ipv4-fasttrack-active set to no ?

No I checked it as mentionned in the manual.
But the log is set for drop rules
by jphconstantin
Tue Oct 10, 2017 4:12 pm
Forum: Beginner Basics
Topic: why ipv4-fasttrack-active set to no ?
Replies: 9
Views: 2626

Re: why ipv4-fasttrack-active set to no ?

Yes. 8) CCR support conditions are met Does the position of the rule important ? (for me dummy=0, fasttrack=1) /ip firewall filter> print Flags: X - disabled, I - invalid, D - dynamic 0 D ;;; special dummy rule to show fasttrack counters chain=forward action=passthrough 1 chain=forward action=fasttr...
by jphconstantin
Tue Oct 10, 2017 3:50 pm
Forum: Beginner Basics
Topic: why ipv4-fasttrack-active set to no ?
Replies: 9
Views: 2626

why ipv4-fasttrack-active set to no ?

Hello, I set a fasttrack rule and there is no effect. Could you explain why the ipv4-fasttrack-active is set to no and how can set it to yes or which are the conditions to have yes ? ip setting print ip-forward: yes send-redirects: yes accept-source-route: no accept-redirects: no secure-redirects: y...
by jphconstantin
Mon Oct 09, 2017 7:56 pm
Forum: Beginner Basics
Topic: how to remove the fasttrack dummy rule ? [SOLVED]
Replies: 2
Views: 4809

Re: how to remove the fasttrack dummy rule ? [SOLVED]

I forgot the reboot !
Thank you

Any idea why I cannot improve the download speed (I could go to 900Mbps) ?
by jphconstantin
Mon Oct 09, 2017 6:01 pm
Forum: Beginner Basics
Topic: how to remove the fasttrack dummy rule ? [SOLVED]
Replies: 2
Views: 4809

how to remove the fasttrack dummy rule ? [SOLVED]

Hello, I discovered fasttrack on google and read: "have more then doubled the throughput of MicroTik Routers." I created a new rule at the beginning: chain forward, connection-state establish-related,action fasttrack connection Two new rules have been inserted: a dummy one and a forward one I run te...
by jphconstantin
Sat Oct 07, 2017 1:30 am
Forum: Beginner Basics
Topic: Forward from a list to another list
Replies: 2
Views: 455

Re: Forward from a list to another list

If I do that I have an error because the field "to addresses" must not be empty.
And if I enter the name of an address list in the field "to addresses" then it's refused.
by jphconstantin
Fri Oct 06, 2017 4:32 pm
Forum: Beginner Basics
Topic: Forward from a list to another list
Replies: 2
Views: 455

Forward from a list to another list

Hello, I have a SIP provider who has 8 servers. Then I created an addres-list called SIP_Provider I have three phones (one ip phone and two softphones) on my lan 192.168.1.0. Then I created an address-list called Phones I want to forward the voip traffic (sip+rtp) from SIP_Provider to Phones In the ...
by jphconstantin
Fri Oct 06, 2017 3:50 pm
Forum: Beginner Basics
Topic: Mangle function for phones ?
Replies: 4
Views: 673

Re: Mangle function for phones ?

What I want to do: I have a SIP provider who has 8 servers. Then I created an addres-list called SIP_Provider I have three phones (one ip phone and two softphones) on my lan 192.168.1.0. Then I created an address-list called Phones I want to forward the voip traffic (sip+rtp) from SIP_Provider to Ph...
by jphconstantin
Fri Oct 06, 2017 12:47 am
Forum: Beginner Basics
Topic: Mangle function for phones ?
Replies: 4
Views: 673

Re: Mangle function for phones ?

But without a PBX on the LAN, what is the interest to mark the VOIP traffic ?
by jphconstantin
Thu Oct 05, 2017 6:54 pm
Forum: Beginner Basics
Topic: Mangle function for phones ?
Replies: 4
Views: 673

Mangle function for phones ?

Hello,
From the wiki:
Mangle is a kind of 'marker' that marks packets for future processing with special marks
Does it mean that mangle is useless if we have one ip phone and one softphone on the lan ?
by jphconstantin
Thu Oct 05, 2017 5:38 pm
Forum: Beginner Basics
Topic: update time (log and clock) with ntp doesn't work
Replies: 1
Views: 491

Re: update time (log and clock) with ntp doesn't work

Forget my question: I didn't wait long enough

It is surely possible to force the updating 8)
by jphconstantin
Thu Oct 05, 2017 5:16 pm
Forum: Beginner Basics
Topic: how to set a master port and a slave port
Replies: 10
Views: 29684

Re: how to set a master port and a slave port

Yes they belong to it.
Is it possible to disable one of ports ?
If yes, is it usefull ? i.e personnalized the port for the voip traffic
by jphconstantin
Thu Oct 05, 2017 4:47 pm
Forum: Beginner Basics
Topic: update time (log and clock) with ntp doesn't work
Replies: 1
Views: 491

update time (log and clock) with ntp doesn't work

Hello, On my ccr9 I installed the ntp package (mite, version 6.40.4). Log told me verified and installed npk package. With system, ntp client, I set two european ntp servers, mode unicast. Before that I check their ip addresses with a ping. I enabled ntp client. With system, clock, I set deliberatel...
by jphconstantin
Wed Oct 04, 2017 7:28 pm
Forum: Beginner Basics
Topic: how to set a master port and a slave port
Replies: 10
Views: 29684

Re: how to set a master port and a slave port

You can't do master/slave on a CCR.

You will need to create a bridge and add all the ports to that if you want to switch them. The CCR's don't have a switch chip.
A bridge already exist by default (bridge1). All ports have the "S" mention.
Shall I create a new bridge ?
by jphconstantin
Wed Oct 04, 2017 7:24 pm
Forum: Beginner Basics
Topic: how to set a master port and a slave port
Replies: 10
Views: 29684

Re: how to set a master port and a slave port

because I am a newbie :lol:
by jphconstantin
Wed Oct 04, 2017 5:53 pm
Forum: Beginner Basics
Topic: attacks had corrupted my router ? [SOLVED]
Replies: 4
Views: 858

Re: attacks had corrupted my router ? [SOLVED]

yes, good lesson for me :?
by jphconstantin
Wed Oct 04, 2017 4:37 pm
Forum: Beginner Basics
Topic: attacks had corrupted my router ? [SOLVED]
Replies: 4
Views: 858

Re: attacks had corrupted my router ? [SOLVED]

No reaction ?
by jphconstantin
Wed Oct 04, 2017 4:10 pm
Forum: Beginner Basics
Topic: how to set a master port and a slave port
Replies: 10
Views: 29684

Re: how to set a master port and a slave port

Not me ! Note I have a ccr1009-7g-1c-pc
I don't know how to paste an image to show you :(
by jphconstantin
Wed Oct 04, 2017 3:53 pm
Forum: Beginner Basics
Topic: attacks had corrupted my router ? [SOLVED]
Replies: 4
Views: 858

attacks had corrupted my router ? [SOLVED]

Hello, HELP !!!!! I began the configuration with the quick set menu but I didn't define a password. Suddently I noted that my routes list was empty ! I opened the log and notes attacks (red color) on ssh, ftp, telnet "login failure ...." that means that the attack failed I suppose :D "user admin log...
by jphconstantin
Wed Oct 04, 2017 2:53 pm
Forum: Beginner Basics
Topic: Rename interfaces [SOLVED]
Replies: 2
Views: 697

Rename interfaces [SOLVED]

Hello,
Is it a good practice to rename the interfaces or is it mendatory ?
by jphconstantin
Wed Oct 04, 2017 1:57 pm
Forum: Beginner Basics
Topic: how to set a master port and a slave port
Replies: 10
Views: 29684

Re: how to set a master port and a slave port

As I wrote, I connected AP on ether3 but no access to internet !?
Shall I declare ether3 as slave of ether2 ?
If yes, I didn't find the method in the gui (no options in the interfaces window.
by jphconstantin
Wed Oct 04, 2017 3:09 am
Forum: Beginner Basics
Topic: how to set a master port and a slave port
Replies: 10
Views: 29684

how to set a master port and a slave port

hello, I have this situation: internet ---- router --(eth1)-- switch ---- machines The lan is 192.168.1.0 The local address of the router is 192.168.1.1 I configured address list, routes, nat and everything is ok Now I want to connect direcly on the router (eth2) a wifi AP Actually the ip address of...
by jphconstantin
Mon Sep 25, 2017 4:38 pm
Forum: Beginner Basics
Topic: First router mikrotik and first questions: ps4,balance, port forwarding
Replies: 5
Views: 1094

Re: First router mikrotik and first questions: ps4,balance, port forwarding

Strange: you have two machines with the same private address ?
by jphconstantin
Mon Sep 25, 2017 4:23 pm
Forum: Beginner Basics
Topic: upgrade the router as it was a simple machine [SOLVED]
Replies: 4
Views: 724

Re: upgrade the router as it was a simple machine [SOLVED]

Why '35: because on the switch I have a DNS server and it's working ! My internet connection is working: I am posting this message ... The others machines have access to internet. / tool ping 8.8.8.8 gives "no route to host" ah ah ... / route display for the first line: 0 xs 0.0.0.0/0 ...... if I cl...
by jphconstantin
Sun Sep 24, 2017 5:25 pm
Forum: Beginner Basics
Topic: upgrade the router as it was a simple machine [SOLVED]
Replies: 4
Views: 724

upgrade the router as it was a simple machine [SOLVED]

I am just receiving my new router, an CCR1009 model. As I am waiting for my sfp module, I would like to use this time to upgrade the firmware. The ccr1009 is connected in my network like this: internet ---my_actual_router --- switch --- ccr1009 (192.168.1.1) (192.168.1.5) (port:eth2) I did: quick se...