Community discussions

Search found 73 matches

by dmitris
Sat Nov 16, 2019 10:57 am
Forum: General
Topic: BLock ip When login error [SOLVED]
Replies: 4
Views: 568

Re: BLock ip When login error [SOLVED]

I'm using this one, helps a lot. Look at ssh example.
https://wiki.mikrotik.com/wiki/Brutefor ... prevention
by dmitris
Wed Nov 13, 2019 9:46 am
Forum: Beginner Basics
Topic: Need Help
Replies: 1
Views: 128

Re: Need Help

Hi, i'll suggest you to apply to certified Mikrotik consultants for such large planning and installation solution.

https://mikrotik.com/consultants
by dmitris
Wed Nov 06, 2019 4:28 pm
Forum: General
Topic: MikroTik hAP ac2 - PoE in problem
Replies: 16
Views: 1411

Re: MikroTik hAP ac2 - PoE in problem

I suppose that this one will help you....It's not converting 802.3af/at. It's using power adapter which you received with your hAP ac²
https://mikrotik.com/product/RBGPOE
by dmitris
Wed Nov 06, 2019 11:09 am
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

https://mikrotik.com/product/RBSXTLTE3-7 The SXT LTE (product code RBSXTLTE3-7) is a special variant of our popular SXT device, and doesn’t include a 802.11 wireless device. Instead, it has a built in high quality LTE Category 3 modem for speeds of up to 100Mbit/s downlink and 50 Mbit/s uplink. You ...
by dmitris
Wed Nov 06, 2019 9:15 am
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

This is why i don't like SwOS at all...no logs, no ssh....but it's very cheap :))
by dmitris
Tue Nov 05, 2019 11:31 am
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

In my opinion, Mikrotik switch can't obtain upgrade software info because you defined a static IP on it. As you can see you defined only static IP but there are no fileds for mask, gateway and dns and hence device don't know how to reach update server. P.S Personally i have same behavior on this dev...
by dmitris
Mon Nov 04, 2019 1:28 pm
Forum: Beginner Basics
Topic: Timed Firewall Rul
Replies: 9
Views: 533

Re: Timed Firewall Rul

Go the System>Watchdog is there any IP-address specified ? Watchdog reboot device when your device run in some troubles. (hardware or software). If you didn't specify IP-address under watchdog and reboot was initiated by watchdog then you should see "suppout.rif" under Files menu. https://wiki.mikro...
by dmitris
Mon Nov 04, 2019 12:05 pm
Forum: Beginner Basics
Topic: Timed Firewall Rul
Replies: 9
Views: 533

Re: Timed Firewall Rul

How many times you tried to re-insert address-list already?

i'm also using dynamically created lists with 30 days timeout and they works like a charm until reboot or timeout expiration..
by dmitris
Mon Nov 04, 2019 11:14 am
Forum: Beginner Basics
Topic: Timed Firewall Rul
Replies: 9
Views: 533

Re: Timed Firewall Rul

Why you don't even try to search on the forum? https://forum.mikrotik.com/viewtopic.php?t=37522 When script is ready, you need setup scheduled start of this script. In winbox : System>Scheduler P.S You should know that time-outed address-lists are dynamical entries, if router rebooted then it will d...
by dmitris
Mon Nov 04, 2019 10:35 am
Forum: Beginner Basics
Topic: Timed Firewall Rul
Replies: 9
Views: 533

Re: Timed Firewall Rul

Seems like your router is rebooted every 24h, can you confirm that? If yes this is why your address-list with timeout is gone.

Instead you can use scheduled script which will disable allowing rule.
by dmitris
Sun Nov 03, 2019 11:03 pm
Forum: Wireless Networking
Topic: how long cable support mikrotik
Replies: 7
Views: 469

Re: how long cable support mikrotik

There is no need of a poe calculator... the omnitik has a psu of 60 watt. The consumption of all the devices ( max ) including the GPeR is less than 50 watt... So? At such distance there will be voltage drop ca 5V and I forget that Mikrotik devices works even in range 11-30V, in theory should work ...
by dmitris
Sun Nov 03, 2019 9:34 pm
Forum: Wireless Networking
Topic: how long cable support mikrotik
Replies: 7
Views: 469

Re: how long cable support mikrotik

This dimitris is just in theory... sorry to dissapoint you but in practice is not exactly like that...! At least you can not be certain... I ve seen UTP CAT5e cables with length of 60-70m perform poorly and i ve seen also UTP cables with length over 100m perform well... Yes, i'm aware about this......
by dmitris
Sun Nov 03, 2019 8:35 pm
Forum: Wireless Networking
Topic: how long cable support mikrotik
Replies: 7
Views: 469

Re: how long cable support mikrotik

Definitely it will not work at all or if it will connection between nodes will be unreliable....
by dmitris
Sun Nov 03, 2019 11:57 am
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

The problem with the switches still does presist: ERROR: Could not determine latest version, probably no internet connection. Use manual upgrade. Don't be concerned about this problem now....It's not related to your current issue at all... Find you iPad MAC address, than log in your AP's and look a...
by dmitris
Sat Nov 02, 2019 5:44 pm
Forum: Beginner Basics
Topic: VPN Routing [SOLVED]
Replies: 7
Views: 1069

Re: VPN Routing [SOLVED]

You need to establish GRE tunnels between A<>B and B<>C and this will be interface, than you should define /30 on these interfaces and than you can route traffic between sites.
by dmitris
Fri Nov 01, 2019 11:57 pm
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

From your logs i see that devices is roaming very often in short time for some reason... f.e this one 22:52:34 wireless,info 24:1B:7A:94:74:AF@wlan2: disconnected, registered to other device in network 22:53:33 wireless,info 24:1B:7A:94:74:AF@wlan2: connected, signal strength -70 22:55:46 wireless,i...
by dmitris
Fri Nov 01, 2019 11:36 pm
Forum: SwOS
Topic: CRS326Q-24S+2Q+ packet drops
Replies: 8
Views: 1208

Re: CRS326Q-24S+2Q+ packet drops

Maybe you have broadcast storm in your environment...configure lacp on sw side too or configure Broadcast Storm Control, by default it's 100% set it to 5%. https://wiki.mikrotik.com/wiki/SwOS/CSS326#LAG Maybe RSTP playing with you rough game, as you said all switches are with def conf. You should co...
by dmitris
Fri Nov 01, 2019 10:52 pm
Forum: SwOS
Topic: CRS326Q-24S+2Q+ packet drops
Replies: 8
Views: 1208

Re: CRS326Q-24S+2Q+ packet drops

Are these PC-s have only single connection to the switches?
by dmitris
Fri Nov 01, 2019 10:05 pm
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

RSTP - Rapid Spanning Tree Protcol, it help prevent bridge loops in networks.
https://en.wikipedia.org/wiki/Spanning_Tree_Protocol
by dmitris
Fri Nov 01, 2019 4:54 pm
Forum: Beginner Basics
Topic: Mesh for security cameras
Replies: 10
Views: 1154

Re: Mesh for security cameras

Do not use CCTV over WiFi, only cabel.
by dmitris
Fri Nov 01, 2019 3:13 pm
Forum: SwOS
Topic: CRS326Q-24S+2Q+ packet drops
Replies: 8
Views: 1208

Re: CRS326Q-24S+2Q+ packet drops

Please make pictures of your configuration and post here.
by dmitris
Fri Nov 01, 2019 1:28 pm
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

First of all it's useless in your network topology, the second one that it can be a source of your current problem...i'm just proposing an ideas what can help you...
by dmitris
Fri Nov 01, 2019 12:21 pm
Forum: SwOS
Topic: MikroTik User for 1 day
Replies: 5
Views: 897

Re: MikroTik User for 1 day

Definetly Mikrotik products is not for all especially for persons whois not tech savvy at all :lol:
by dmitris
Thu Oct 31, 2019 11:19 am
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

NB! Do backup from all devices before modifying config... 1. On router and all APs define IP-address on the bridge1 not interface. /ip address add address=192.168.88.x/24 comment=defconf interface=bridge1 network=192.168.88.0 - 2. On all APs you have configured dhcp-relay! Why? Disable it because al...
by dmitris
Wed Oct 30, 2019 3:36 pm
Forum: Wireless Networking
Topic: Current operator MCC+MNC
Replies: 6
Views: 662

Re: Current operator MCC+MNC

Go to the interface>lte>cellularTAB
IMSI = 505 90 0202336000
505 == MCC
90 == MNC;
by dmitris
Wed Oct 30, 2019 1:35 pm
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

Thx for precise information...

Do you have any PC's which are connected to this network with cable or all devices using internet only over WiFI?

Also i will suggest to check ether1 port on SXT for link downs. Look at Interfaces>ether1>statusTAB>Link downs= number.
by dmitris
Tue Oct 29, 2019 8:51 pm
Forum: Beginner Basics
Topic: Random connection dropping
Replies: 27
Views: 2218

Re: Random connection dropping

Let's assume that when interruption occurs and you client connected to the "AP Maja" try to ping all others ap's and switches, what is the result than?

BTW try login into your switches and check that you don't have tx/rx errors on ports.

How long is the cable between sw1 and sw2?
by dmitris
Mon Oct 28, 2019 9:17 pm
Forum: Beginner Basics
Topic: Hairpin NAT with DST NAT tcp/80
Replies: 6
Views: 657

Re: Hairpin NAT with DST NAT tcp/80

Hi, HNAT rule must be first under NAT facility. Try to change position of HNAT rule and it should work. /ip firewall nat add action=masquerade chain=srcnat comment="NAT LOOPBACK, pre NAT pravidla neurcovat SRC interface" dst-address=192.168.2.0/24 log=yes log-prefix=NAT_LOOP: out-interface=bridge-ho...
by dmitris
Fri Oct 25, 2019 10:48 am
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 23
Views: 4232

Re: CSS326-24G-2S+RM hangs until power cycle

I'm just curious, maybe anybody from Mikrotik support team can comment on this issue, do you aware about this behavior?

P.S
At this moment i'm afraid to use Mikortik switches for commercial services in our environment....
by dmitris
Thu Oct 24, 2019 10:56 am
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 32
Views: 4696

Re: MikroTik MQS

Hello Rudolfs, thank you for asking me this questions. Yesterday i tried to upgrade MQS only over WiFi, LAN port wasn't connected...
Just tried over LAN connection and upgrade was successful.
Thank you again!
by dmitris
Wed Oct 23, 2019 11:05 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 32
Views: 4696

Re: MikroTik MQS

I just tried to upgrade from versios 1.1p and i receive continuously following message. ERROR: Upgrade failed - invalid firmware file.
Device reseted and no changes made before upgrade...

File name:
firmwareRouterBoard_MQS_v1.4-1571828907.fwf
by dmitris
Sun Oct 13, 2019 11:14 pm
Forum: Beginner Basics
Topic: Philips Hue Stopped Working
Replies: 7
Views: 527

Re: Philips Hue Stopped Working

Maybe Philips Hue have an old gateway ip addr ? Check ip and dns configuration on this device.
by dmitris
Sun Oct 13, 2019 12:15 am
Forum: Beginner Basics
Topic: RB260GS as unmanaged (No IP address)
Replies: 3
Views: 457

Re: RB260GS as unmanaged (No IP address)

I will suggest you to leave mgmt ip in your current subnet so you can monitor switches if some clients start complain and definitely set a password for each switch....
by dmitris
Sat Oct 12, 2019 11:48 am
Forum: Scripting
Topic: Script out entire router configuration or just a section of it?
Replies: 4
Views: 543

Re: Script out entire router configuration or just a section of it?

Try this command:
/interface wireless export
by dmitris
Sat Oct 12, 2019 11:45 am
Forum: Beginner Basics
Topic: RB260GS as unmanaged (No IP address)
Replies: 3
Views: 457

Re: RB260GS as unmanaged (No IP address)

Why you are so concerned about mgmt ip?
Just change swos mgmt ip addres to something like 10.10.10.10 and uncheck all "Allow From Ports".
by dmitris
Fri Oct 11, 2019 8:16 pm
Forum: General
Topic: Cannot open ports / access router externally
Replies: 1
Views: 365

Re: Cannot open ports / access router externally

I checked your configuration and i don't see any granting rule to ssh. /ip firewall filter add action=accept chain=input comment="Allow SSH" dst-port=22 protocol=\ tcp * * Second thing i would not recommend to expose Winbox service to all, it's very insecure... Also you can check remotely, does port...
by dmitris
Fri Oct 11, 2019 2:45 pm
Forum: Beginner Basics
Topic: Dual Wan config on my router
Replies: 21
Views: 2578

Re: Dual Wan config on my router

in contradictory i want to say that DST-NAT in PREROUTING chain and it is done before routing decision, not after as you said, check packet flow diagram.... DST-NAT is indeed in prerouting. However, the NAT rules are about SRC-NAT and that's done in postrouting which comes after routing decision. S...
by dmitris
Fri Oct 11, 2019 1:34 pm
Forum: Beginner Basics
Topic: Dual Wan config on my router
Replies: 21
Views: 2578

Re: Dual Wan config on my router

When subnets is made, you can simply add src-nat for each subnet.. Is it really this simple? My impression is that dst-nat is done after routing decision is made (which actually selects the out-interface). Which means that src-address property in NAT rules example doesn't help. Instead it would be ...
by dmitris
Fri Oct 11, 2019 11:59 am
Forum: Beginner Basics
Topic: Dual Wan config on my router
Replies: 21
Views: 2578

Re: Dual Wan config on my router

in contradictory i want to say that DST-NAT in PREROUTING chain and it is done before routing decision, not after as you said, check packet flow diagram....
by dmitris
Fri Oct 11, 2019 11:40 am
Forum: General
Topic: Allow access to devices from other network
Replies: 8
Views: 1626

Re: Allow access to devices from other network

I just checked your rule and i think it will not work, correct one is:
/ip firewall nat
add action=dst-nat chain=dstnat dst-port=8080 dst-address=192.168.88.246 in-interface=ether1 protocol=tcp to-addresses=192.168.88.246 to-ports=8080
by dmitris
Fri Oct 11, 2019 11:07 am
Forum: Beginner Basics
Topic: Dual Wan config on my router
Replies: 21
Views: 2578

Re: Dual Wan config on my router

Now i see, the simplest way to do that is divide 1 x /24 to 2 x /25 it will give you two separate subnet spaces: IP-s: 192.168.1.2 - 192.168.1.126 MASK 255.255.255.128 GW LAN1 == 192.168.1.1/25 IP-s: 192.168.1.130 - 192.168.1.254 MASK 255.255.255.128 GW LAN2 == 192.168.1.129/25 When subnets is made,...
by dmitris
Fri Oct 11, 2019 10:01 am
Forum: Beginner Basics
Topic: Dual Wan config on my router
Replies: 21
Views: 2578

Re: Dual Wan config on my router

Can you make a network diagram? Maybe than we'll understand better what you want to achieve.
by dmitris
Thu Oct 10, 2019 5:44 pm
Forum: General
Topic: Allow access to devices from other network
Replies: 8
Views: 1626

Re: Allow access to devices from other network

Good, so you problem is solved? Please mark this thread as solved.
by dmitris
Thu Oct 10, 2019 5:06 pm
Forum: General
Topic: Low speed
Replies: 4
Views: 929

Re: Low speed

Wire speed can be achieved only on first bridge, all others bridges are software this is why you have low perfomance. /interface bridge add name=TRUNK add name="b-LAN OLD" add name="bridge I/OT" add name="bridge guest WIFI" here explained how to correctly setup Switch Router https://wiki.mikrotik.co...
by dmitris
Thu Oct 10, 2019 4:44 pm
Forum: General
Topic: Allow access to devices from other network
Replies: 8
Views: 1626

Re: Allow access to devices from other network

In particular situation it's just for example. Basically this rule will make dst-nat from WAN network to host 192.168.88.x and port 80, you can modify host and port as you need it. Also as "Anumrak" said, you can use static routes on both ends to achieve net to net connection. On router with subnet ...
by dmitris
Thu Oct 10, 2019 4:27 pm
Forum: General
Topic: can mikrotik router be a voip\sip server?
Replies: 8
Views: 1512

Re: can mikrotik router be a voip\sip server?

At least on Mikortik RouterOS packages web page, nothing about SIP...
https://wiki.mikrotik.com/wiki/Manual:System/Packages
by dmitris
Thu Oct 10, 2019 1:22 pm
Forum: General
Topic: Allow access to devices from other network
Replies: 8
Views: 1626

Re: Allow access to devices from other network

It's very simple use dst-nat on router with subnet 192.168.88.0/24
/ip firewall nat add chain=dstnat in-interface=ether1-WAN to-addresses=192.168.88.100 to-ports=80
by dmitris
Wed Oct 09, 2019 5:25 pm
Forum: SwOS
Topic: MAC port lock reset?
Replies: 6
Views: 1157

Re: MAC port lock reset?

For CRS3xx and CSS326, the port lock will restrict MAC address learning (a static host addresses should be configured). You can allow the switch to learn the first frame it receives, this requires both options enabled. Learning of the first MAC address will reset every time an interface status chan...
by dmitris
Wed Oct 09, 2019 9:34 am
Forum: Beginner Basics
Topic: Connecting Two Mikrotik routers / Two Subnets
Replies: 11
Views: 2865

Re: Connecting Two Mikrotik routers / Two Subnets

Thank you, this is what i expected to see =)
by dmitris
Mon Oct 07, 2019 11:38 pm
Forum: Beginner Basics
Topic: Connecting Two Mikrotik routers / Two Subnets
Replies: 11
Views: 2865

Re: Connecting Two Mikrotik routers / Two Subnets

Can you run commands on your R2 and post here output :
/ip route print detail
/ip dhcp-client print detail
by dmitris
Mon Oct 07, 2019 11:24 pm
Forum: Beginner Basics
Topic: hap2 ac firewall rules for Fronius Solar Inverter
Replies: 4
Views: 581

Re: hap2 ac firewall rules for Fronius Solar Inverter

If i understood correctly....This rule will forward udp 49049 port from WAN to your LAN solar inverter
/ip firewall nat
add action=dst-nat chain=dstnat in-interface=ether1-gateway dst-port=49049 protocol=udp to-addresses=IP-OF-SOLAR-DEVICE to-ports=49049
by dmitris
Mon Oct 07, 2019 10:54 pm
Forum: Beginner Basics
Topic: Connecting Two Mikrotik routers / Two Subnets
Replies: 11
Views: 2865

Re: Connecting Two Mikrotik routers / Two Subnets

I checked your configuration of R1 and R2 and i'm totally confused. Your configuration should not work.... On R1 ether5 removed from bridge ... and on R2 ether1 used as WAN with dhcp-client on it.....it means that R2 will not get WAN ip and will not work.. Are u sure that R2 connected to eth5 on R1?...
by dmitris
Mon Oct 07, 2019 7:09 pm
Forum: General
Topic: how to allow pop3 from WAN1 and others from WAN 2
Replies: 4
Views: 626

Re: how to allow pop3 from WAN1 and others from WAN 2

try to add ...
dst-port=25,587,465,110,995,143,993
by dmitris
Mon Oct 07, 2019 4:59 pm
Forum: General
Topic: Hotspot allow addresslist and drop rest [SOLVED]
Replies: 6
Views: 811

Re: Hotspot allow addresslist and drop rest [SOLVED]

Sorry my fault..

Look at mikrotik packet flow diagramm:
https://wiki.mikrotik.com/wiki/Manual:Packet_Flow

"hotspot-in" on prerouting chain and it's first stage where packet goes this is why u can't block others ip. I think you should setup ip blocking in hotspot itself....
by dmitris
Mon Oct 07, 2019 2:59 pm
Forum: General
Topic: Unstable IPSEC over PPPOE interface
Replies: 10
Views: 1250

Re: Unstable IPSEC over PPPOE interface

What encryption and ciphers on ipsec configured ?

viewtopic.php?t=94931
by dmitris
Mon Oct 07, 2019 2:45 pm
Forum: General
Topic: Hotspot allow addresslist and drop rest [SOLVED]
Replies: 6
Views: 811

Re: Hotspot allow addresslist and drop rest [SOLVED]

Try in mangle on prerouting chain...
/ip firewall mangle
add action=drop chain=prerouting in-interface=ether5 log=yes log-prefix="Dropped " src-address-list="!ether5 allowed ip"
by dmitris
Mon Oct 07, 2019 2:30 pm
Forum: General
Topic: how to allow pop3 from WAN1 and others from WAN 2
Replies: 4
Views: 626

Re: how to allow pop3 from WAN1 and others from WAN 2

If you want reach mail server outside you organization, you can use src-nat for this... /ip firewall nat add action=masquerade chain=srcnat disabled=no dst-port=25,587,465,110,995 \ out-interface=WAN1 protocol=tcp add action=masquerade chain=srcnat disabled=no src-address=YOUR-SUBNET-HERE \ out-inte...
by dmitris
Mon Oct 07, 2019 2:19 pm
Forum: General
Topic: Unstable IPSEC over PPPOE interface
Replies: 10
Views: 1250

Re: Unstable IPSEC over PPPOE interface

check under /tool profile, what exactly using RB CPU so heavily
by dmitris
Mon Oct 07, 2019 11:34 am
Forum: General
Topic: Unstable IPSEC over PPPOE interface
Replies: 10
Views: 1250

Re: Unstable IPSEC over PPPOE interface

indeed, rb2011 don't support ipsec hw acceleration at all. When CPU usage is permanently 100% than router behaves unpredictable (internal facilities like nat, dhcp, ipsec,etc not working) BTW what encryption are used under ipsec peer and policies. Do you use encryption on PPPoE also? Look at PPPoE p...
by dmitris
Mon Oct 07, 2019 11:07 am
Forum: General
Topic: Unstable IPSEC over PPPOE interface
Replies: 10
Views: 1250

Re: Unstable IPSEC over PPPOE interface

What is CPU load on both sides when you copying files?
by dmitris
Mon Oct 07, 2019 10:38 am
Forum: Wireless Networking
Topic: Point to Point Wireless Security
Replies: 10
Views: 2380

Re: Point to Point Wireless Security

Also i will suggest using for each site different VLAN\subnet, than you can have fine tuned firewall between sites. Also use on wireless PtP strong password and hide SSID on receiving side it will help you from passers by, but not from directed attacks.
by dmitris
Sun Oct 06, 2019 10:31 pm
Forum: Beginner Basics
Topic: Best way to distribute ip block
Replies: 2
Views: 931

Re: Best way to distribute ip block

Maybe this one will be helpful for you?

https://youtu.be/YJxVm6jZYiU?list=PLfpN ... EM5&t=1678
by dmitris
Sun Oct 06, 2019 10:18 pm
Forum: Beginner Basics
Topic: Connecting Two Mikrotik routers / Two Subnets
Replies: 11
Views: 2865

Re: Connecting Two Mikrotik routers / Two Subnets

On R1: /interface bridge port add bridge=bridge comment=defconf disabled=no interface=ether5 This should help you... When you enable ether5 back, try to ping on R2, 8.8.8.8 Basicaly your R2 should get ip from R1 and use it as WAN ip. If it still not working, please post here export from R2: /interfa...
by dmitris
Sun Oct 06, 2019 10:12 pm
Forum: General
Topic: DHCP Clinet is working on Basic router setup but not static setup [SOLVED]
Replies: 7
Views: 2452

Re: DHCP Clinet is working on Basic router setup but not static setup [SOLVED]

Can you post your configuration here not in PDF file ? Example conf /interface bridge add admin-mac=4C:5E:0C:25:00:00 auto-mac=no name=bridge protocol-mode=none /interface wireless set [ find default-name=wlan1 ] antenna-gain=3 band=2ghz-b/g/n channel-width=\ 20/40mhz-Ce country=etsi distance=indoor...
by dmitris
Sun Oct 06, 2019 7:12 pm
Forum: General
Topic: problem hma vpn and rb 951
Replies: 8
Views: 2678

Re: problem hma vpn and rb 951

If you want solve this issue, you need post here 2 things:

1. HMA Requirements for PPTP
2. You RB configuration
by dmitris
Sun Oct 06, 2019 6:56 pm
Forum: General
Topic: problem hma vpn and rb 951
Replies: 8
Views: 2678

Re: problem hma vpn and rb 951

So, then you should check configuration of your RB under these options, look below.

/interface pptp-client
/ppp secret
/ppp profile
by dmitris
Sun Oct 06, 2019 6:30 pm
Forum: General
Topic: problem hma vpn and rb 951
Replies: 8
Views: 2678

Re: problem hma vpn and rb 951

Check on your RB server allowed encryption types and then on your client side that that might be issue. What is saying your client logs? Also post here your RB config parts. /interface pptp-server export hide-sensitive /interface pptp-client export hide-sensitive /ppp secret export hide-sensitive /p...
by dmitris
Sun Oct 06, 2019 5:53 pm
Forum: General
Topic: youtube upload/download stats not showing in queue tree
Replies: 5
Views: 1727

Re: youtube upload/download stats not showing in queue tree

I think you are using wrong config to detect youtube traffic with L7 protocol, because this traffic is encrypted, and you can't simply see detail in the packet
You should look at TLS Host option in advanced tab.
by dmitris
Sun Oct 06, 2019 5:33 pm
Forum: General
Topic: problem hma vpn and rb 951
Replies: 8
Views: 2678

Re: problem hma vpn and rb 951

You should provide more information about your environment, both client and server.
What saying RB log?
by dmitris
Sun Oct 06, 2019 4:56 pm
Forum: Beginner Basics
Topic: Connecting Two Mikrotik routers / Two Subnets
Replies: 11
Views: 2865

Re: Connecting Two Mikrotik routers / Two Subnets

Maybe you need something like this?

On R2:

/ip dhcp-client
add comment=uplink dhcp-options=hostname,clientid disabled=no interface=\
ether1
/ip firewall nat
add action=masquerade chain=srcnat comment="Masq LAN" out-interface=\
ether1 src-address=10.0.1.0/24
by dmitris
Sun Oct 06, 2019 3:54 pm
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 23
Views: 4232

Re: CSS326-24G-2S+RM hangs until power cycle

We are also using in our production 10 x CRS326-24G-2S+ and two of them experienced the same issue. The devices itself are not at heavy load, on uplink max 5Mbit/s and cpu load 0-5%....BTW i can connect to hanged devices over console port, logs are ok but traffic is not passing in/out....Last hang 0...
by dmitris
Thu Feb 28, 2019 11:09 am
Forum: Scripting
Topic: Suppress output from ping in script?
Replies: 3
Views: 1773

Re: Suppress output from ping in script?

use execute {command}
if ([execute {ping 8.8.8.8 count=3}]!= 0) do={put "ok"}

Hi There, seems this solution not working as expected. Does anybody solve this task in other manner ?

[admin@mtik] > :put [:execute {/ping 192.168.88.1 count=5}]
Output:
*d3