Community discussions

Search found 644 matches

by vecernik87
Wed Oct 16, 2019 7:19 am
Forum: Announcements
Topic: Winbox v3.20 released!
Replies: 24
Views: 3693

Re: Winbox v3.20 released!

*) on update, Winbox will check that code is signed by MikroTik and not somebody else; Unfortunately this check still seems insecure. I remember your report ages ago and I always wondered how long till they fix that. I find this unbelievable that update process is vulnerable like that. Well, good t...
by vecernik87
Wed Oct 16, 2019 7:12 am
Forum: Beginner Basics
Topic: Is there a place where I may ask whitehat to hijack my ROS?
Replies: 3
Views: 300

Re: Is there a place where I may ask whitehat to hijack my ROS?

Does it matter who hijacks it? Just publish your IP here or on FB/Twitter with hashtag #hackChallenge and soon you will have your results.
by vecernik87
Sun Aug 11, 2019 1:15 am
Forum: Beginner Basics
Topic: VLAN / DHCP basics
Replies: 4
Views: 535

Re: VLAN / DHCP basics

Just a follow up on previous answer (which is quite sufficient) Better advice would be to not use vlan 1 at all, as it is used for internal purpose by too many manufacturers. VLANs like 1,2, 4095 etc are quite popular among manufacturers for separating traffic internally and some devices simply stri...
by vecernik87
Thu Aug 08, 2019 12:55 am
Forum: The Dude
Topic: Security Issue in The Dude
Replies: 1
Views: 409

Re: Security Issue in The Dude

Dude is no longer being actively developed and there is no way to protect the password. If you hide the error message, bad guy will simply replace the EXE with custom made program which shows any argument sent to the program. (that is as easy as it sounds)
by vecernik87
Sun Jun 30, 2019 11:04 pm
Forum: General
Topic: vlan on a bridge in a bridge
Replies: 17
Views: 1565

Re: vlan on a bridge in a bridge

One thing that nobody mentioned: vlan interfaces are "dumb" tag injectors. They don't implement any logic. Just inject tag or strip tag, depending on the direction and that pose a risk of tagging already tagged frames. And I am not talking about QinQ. I am talking about 3, 4 or even 5 layers of tags...
by vecernik87
Tue Jun 25, 2019 7:07 am
Forum: General
Topic: DHCPd specific IP addresses to specific physical ETHx ports.
Replies: 5
Views: 491

Re: DHCPd specific IP addresses to specific physical ETHx ports.

DHCP is L2 protocol. To give IP based on port, you will need to separate those ports from bridge (break L2 segment and therefore L2 broadcast/multicast). Next you create separate DHCP server per each port. Last (optional) step is to set ARP proxy for your LAN. That way, it will look like it is still...
by vecernik87
Sun Jun 23, 2019 3:37 pm
Forum: Wireless Networking
Topic: Need Advice to Cover 300 WiFi Users in Banquet Hall
Replies: 6
Views: 833

Re: Need Advice to Cover 300 WiFi Users in Banquet Hall

Ok, we are slowly getting to area, which might get us banned (or at least topic locked/deleted) and I don't feel comfy with that. XG is real beast. I agree with you that 1500 is made up number (together with all other "up to XXX clients"), but truth is, that if any device can handle many clients, it...
by vecernik87
Fri Jun 21, 2019 12:12 pm
Forum: General
Topic: Mikrotik haplite have port 3-4 led lighting up without cable plugged in
Replies: 3
Views: 364

Re: Mikrotik haplite have port 3-4 led lighting up without cable plugged in

If you are experienced and know exactly what you are doing, sure. But I guess in such case, you wouldn't be asking. Also, keep in mind that soldering will certainly void any warranty on the product.. If your product is still under warranty and you don't see bent pins, I would recommend to contact yo...
by vecernik87
Fri Jun 21, 2019 11:33 am
Forum: General
Topic: Disable "Reset All Counters" Button from Winbox GUI
Replies: 4
Views: 2321

Re: Disable "Reset All Counters" Button from Winbox GUI

We had similar discussion earlier - people asking to add a confirmation to "disable" and "remove" buttons, because "what if I accidentally click it" ? Well guess what? You can accidentally add a route, which will break stuff. You can accidentally reorder firewall rules which will break stuff. You ca...
by vecernik87
Fri Jun 21, 2019 10:17 am
Forum: Wireless Networking
Topic: Need Advice to Cover 300 WiFi Users in Banquet Hall
Replies: 6
Views: 833

Re: Need Advice to Cover 300 WiFi Users in Banquet Hall

few cents from my experience: maximum capacity of 300 people that I need to cover with around 250-300 wireless clients Please decide if you really talk about capacity of the room or about expected amount of clients. By my experience, these are not the same. I have several similar rooms around the ci...
by vecernik87
Tue Jun 18, 2019 3:12 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4290

Re: single IP constantly trying to log to my Mikrotik

I wanted to make it non-intrusive but okay - note taken and blame fully accepted :) @krisjanisj Could you please also react to the topic to clear it up? It seems that both sides are pretty confident about their truth and for future reference, it would be good to have a clear solution. Or ideally - c...
by vecernik87
Tue Jun 18, 2019 5:44 am
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4290

Re: single IP constantly trying to log to my Mikrotik

I feel almost bad for providing some feedback.
Sorry for not providing some hard data. And thanks @Emil66 for all explanations and patience. I don't have as much time recently, as I would like. And I would probably ragequit anyway in the process.
by vecernik87
Mon Jun 17, 2019 10:49 am
Forum: General
Topic: 1072/1036 : High CPU :
Replies: 2
Views: 289

Re: 1072/1036 : High CPU :

1) any srcnat (srcnat/masquerade/netmap...) rules with manually specified range of ports? 2) any content/L7 conditions in your firewall rules? if not, what other conditions do you usually use? 3) do you have "accept established/related" filter rule in forward chain on top of your rules? 3) what is t...
by vecernik87
Fri Jun 14, 2019 11:27 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4290

Re: single IP constantly trying to log to my Mikrotik

I wouldn't advise to use raw-prerouting rule. It might have negative impact on speed of all (including fasttracked) connections. Original idea with filter-input rule was was better. It was probably just incorrectly placed on the end of all rules. Raw-prerouting is great for specific purpose - when y...
by vecernik87
Fri Jun 14, 2019 5:50 am
Forum: General
Topic: hAP ac² as switch + ap
Replies: 9
Views: 776

Re: hAP ac² as switch + ap

Thanks a lot for all the help and information. I just needed to know that it's possible but you've given me plenty more than just that info. As long as it's doable I'm sure I can make it work (eventually). I'm going to go ahead and place my order. Absolutely doable. I use this very often. I actuall...
by vecernik87
Fri Jun 14, 2019 4:10 am
Forum: General
Topic: vlan bridge to port [SOLVED]
Replies: 10
Views: 702

Re: vlan bridge to port [SOLVED]

Exactly as Anav said. This is not adidas (more stripes = more adidas = better). More bridges are not better. More bridges are bad and lead to serious misconfigurations
by vecernik87
Fri Jun 14, 2019 3:40 am
Forum: Scripting
Topic: :tobool not working as expected
Replies: 4
Views: 541

Re: :tobool not working as expected

@ADahi : That is not a solution. He clearly wants to work with string . If you do local string true; , then you got variable named "string" containing boolean value. There would be no point in converting it to boolean if it already is boolean. @sin3vil : If you really require it to work with "true"...
by vecernik87
Fri Jun 14, 2019 3:04 am
Forum: General
Topic: Cablelabs Micronets
Replies: 4
Views: 697

Re: Cablelabs Micronets

Any reason to create multiple topics? viewtopic.php?f=2&t=145875

I am really starting to believe that you are shareholder in one of key companies and you want to promote this craziness...
by vecernik87
Fri Jun 14, 2019 2:08 am
Forum: General
Topic: Annoyed with Mikrotik 'Support'
Replies: 8
Views: 651

Re: Annoyed with Mikrotik 'Support'

I have a list of 4 or 5 questions This is typical trouble with ticket-based support. It is not designed for multi-question cases. I did this mistake few times as well (although not with mikrotik) and I learned quickly that putting multiple questions into single ticket is impossible. Even with norma...
by vecernik87
Thu Jun 06, 2019 6:25 am
Forum: General
Topic: Mikrotik Console Port
Replies: 4
Views: 390

Re: Mikrotik Console Port

I am not 100% sure because I didn't test it, but there is protected-routerboot option. This is extremely dangerous as it disables both netinstall and console access. If your device malfunctions and you can't log in via network, you will have little chances to restore it. Due to that, I would also su...
by vecernik87
Thu Jun 06, 2019 6:12 am
Forum: RouterBOARD hardware
Topic: wAP AC (RBwAPG-5HacT2HnD) - How to reduce temperature by 8-10 degrees
Replies: 2
Views: 593

Re: wAP AC (RBwAPG-5HacT2HnD) - How to reduce temperature by 8-10 degrees

If you drilled several holes next to each other (making a little grid), it would have same function but nothing could fall inside.

Maybe I should share my own hack - remove whole cover and temperature will be reduced even more! (what a surprise, right? :D )
by vecernik87
Wed Jun 05, 2019 2:16 am
Forum: General
Topic: EOIP - ethernet over IP protocol
Replies: 3
Views: 335

Re: EOIP - ethernet over IP protocol

Just clarification of previous post - you don't need RouterBoard (physical device), but you need a RouterOS on both ends. Thats because EoIP is proprietary extension of GRE and as far as I know, nobody else supports it except Mikrotik. RouterOS can be either on physical device (RouterBoard) or on vi...
by vecernik87
Tue Jun 04, 2019 4:07 pm
Forum: RouterBOARD hardware
Topic: Cheapest router for home use with 1Gb
Replies: 7
Views: 1125

Re: Cheapest router for home use with 1Gb

I think replies above forgot what "cheapest" means. literary "cheapest" is rb750gr3 (hEX) as it costs only 59 USD. slightly more expensive is already mentioned rbd52g (hAP ac^2) which is 69 USD but gives you twice as many CPU cores and integrated wifi. top "cheap" model would be (again already menti...
by vecernik87
Tue Jun 04, 2019 11:28 am
Forum: General
Topic: dst-nat with changing port
Replies: 20
Views: 1120

Re: dst-nat with changing port

Thanks for feedback! This info is very appreciated. I was really wondering what will be the issue and I definitely didn't expect something like that.
by vecernik87
Sat May 25, 2019 1:17 am
Forum: Forwarding Protocols
Topic: How to block neighbours Advertisment
Replies: 6
Views: 3920

Re: How to block neighbours Advertisment

You can't do it with ip firewall. It works only with bridge filter. That means you must have the nterface in bridge, even if it is a single port bridge
by vecernik87
Tue May 21, 2019 9:17 am
Forum: Beginner Basics
Topic: Bridge -> root bridge
Replies: 20
Views: 1471

Re: Bridge -> root bridge

I thought others might provide answer. well... Do I need to set RSTP bridge too for my CRS (switch) or let my STP protocol mode on my CRS set to NONE since CCR already handle the root bridge? (R)STP is designed to work with non-STP bridges (Setting to "none" will make it behave almost like it is not...
by vecernik87
Tue May 21, 2019 4:36 am
Forum: General
Topic: Mikrotik offering lease continually without success
Replies: 2
Views: 310

Re: Mikrotik offering lease continually without success

DHCP is very simple protocol with just 4 steps: Discovery->Offer->Request->Acknowledge. If anything goes wrong, It is usually very clearly visible. 1) do you have any DHCP relays or is it just pure L2 network? 2) Is there any response or is there no response at all from your client? If the Request c...
by vecernik87
Mon May 20, 2019 2:28 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 155042

Re: RouterOS v7.0 beta1 - when?

Some more difficult parts need to be done and we can release a public beta. @normis : so in another words, the easier parts are done and now we are just couple of decades from release? (nah, don't get offended. I really, really appreciate everything you do as long as you don't lie to us or keep sil...
by vecernik87
Mon May 20, 2019 6:36 am
Forum: General
Topic: Please add basic portScan tool ( port scanner scan )
Replies: 31
Views: 9862

Re: Please add basic portScan tool ( port scanner scan )

... 2x times this week different customers needed us to find a cctv DVR on their system (which is behind our mikrotik). would have been so quick via port scan x/24 for port 80 via a ROS ps tool . but instead had to setup a MT + a VPN setup on both sides and a laptop with nmap (about 20-30min, each ...
by vecernik87
Sun May 19, 2019 5:13 am
Forum: Beginner Basics
Topic: Bridge -> root bridge
Replies: 20
Views: 1471

Re: Bridge -> root bridge

8000 hex (32768 dec) is very common default value all around (cisco, juniper, hp, ubnt) although I am not aware of any specs saying that it must to be this way. I remember very well an issue with UBNT EdgeRouterLite, which had default STP priority 0 on it's LAN bridge. On one hand, it make sense tha...
by vecernik87
Sat May 18, 2019 12:10 pm
Forum: Beginner Basics
Topic: Bridge -> root bridge
Replies: 20
Views: 1471

Re: Bridge -> root bridge

I see, to keep bridge MAC consistency, I'll just enable admin-mac with its original IP MAC then. Personally I keep consistency only of first 3 bytes which denote vendor/function. second 3 bytes are usually just serially increasing and have no function. Thats why I usually change the 4th byte. Keepi...
by vecernik87
Sat May 18, 2019 8:27 am
Forum: Beginner Basics
Topic: Bridge -> root bridge
Replies: 20
Views: 1471

Re: Bridge -> root bridge

So this issue is caused by my CCR Ethernet mac starts with 74::::: No. Your issue was caused by not specifying priority. You cannot depend on MAC addresses because in future, you or anyone else might plug in another device anywhere on the network, which will have even lower MAC address and bang! Yo...
by vecernik87
Sat May 18, 2019 3:20 am
Forum: Beginner Basics
Topic: Bridge -> root bridge
Replies: 20
Views: 1471

Re: Bridge -> root bridge

http://www.firewall.cx/images/stories/stp-root-bridge-election-1.png The lower one of course: 0x8000. 4 C:5E:0C:B3:EA:E5 < 0x8000. 7 4:4D:28:38:AA:0A However, if you change the priority of second bridge with higher MAC, it will be opposite: 0x 8 000.4C:5E:0C:B3:EA:E5 > 0x 1 000.74:4D:28:38:AA:0A As...
by vecernik87
Fri May 17, 2019 5:14 pm
Forum: Beginner Basics
Topic: Bridge -> root bridge
Replies: 20
Views: 1471

Re: Bridge -> root bridge

Will specifying admin-mac can remedy this issue? No, it will not. Theoretically you could find a MAC address which would give it priority but that is wrong approach. And how can I make my bridge as the root bridge (even if there's other root ports in the network?) I already told you - give your bri...
by vecernik87
Fri May 17, 2019 10:14 am
Forum: Beginner Basics
Topic: Bridge -> root bridge
Replies: 20
Views: 1471

Re: Bridge -> root bridge

Each bridge has STP priority. Default is 8000 hex. If you set it lower, it signals to STP protocol, that the bridge is more close to the root. Usually you can see people using numbers like 1000 / 2000 / 4000 etc , to prioritize their root bridge. You can read more about it here: https://wiki.mikroti...
by vecernik87
Fri May 17, 2019 8:51 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 71454

Re: v6.45beta [testing] is released!

If we talk about bare metal, then RouterOS (x86) is vulnerable but there is practically no way to misuse the vulnerability because attacker can't run binary (and if attacker can run binary, it won't matter because your device is already compromised) If we talk about VM, then RouterOS (CHR) vulnerabi...
by vecernik87
Thu May 16, 2019 1:28 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 71454

Re: v6.45beta [testing] is released!

Since you can't run any sort of binary which could misuse this vulnerability on your RouterOS, this is not really concern.
by vecernik87
Thu May 16, 2019 3:28 am
Forum: RouterBOARD hardware
Topic: Can't read Voltage via SNMP on CRS112-8P-4S
Replies: 12
Views: 2016

Re: Can't read Voltage via SNMP on CRS112-8P-4S

Long time? Not even 10 years yet. You seem to be bit impatient, don't you think? :D
by vecernik87
Thu May 16, 2019 1:38 am
Forum: General
Topic: dst-nat with changing port
Replies: 20
Views: 1120

Re: dst-nat with changing port

Thanks for update. Personally I don't think this has something with the version. If you are sure that packet enters Mikrotik on port 8122 but nothing leaves, it is good - that means you can do something with it. I would suspect other firewall rules (all tables except "raw" can contain the culprit). ...
by vecernik87
Wed May 15, 2019 2:54 pm
Forum: Scripting
Topic: Knock secret daily changeable
Replies: 10
Views: 689

Re: Knock secret daily changeable

So as a very simple first layer, why not. You are literary arguing in favour of plain-text passwords. Can you imagine logging into your Gmail or Hotmail on plain old http? :roll: Sorry, I just can't agree with this approach. And I will warn people every time I notice someone promoting port-knocking...
by vecernik87
Wed May 15, 2019 2:30 pm
Forum: Beginner Basics
Topic: bridge + eoip + horizon = loop [SOLVED]
Replies: 10
Views: 585

Re: bridge + eoip + horizon = loop [SOLVED]

"default forwarding" on wlan is something different: default-forwarding=yes - data from one wlan client to another (on the same wlan interface) are passing directly through wlan interface. It does not leave the interface (interface behaves almost like it had an internal bridge) It looks like this: c...
by vecernik87
Wed May 15, 2019 2:18 pm
Forum: General
Topic: RB3011 Optimal Operating temperature
Replies: 4
Views: 334

Re: RB3011 Optimal Operating temperature

let me rephrase, if I understand that correctly (I am also curious about this) "The device is guaranteed to perform the same way, within whole temperature range" Is that right? Or are there any catches? (similar to the "waterproof" phones which must not be submerged despite IP rating) Because I can ...
by vecernik87
Wed May 15, 2019 2:07 pm
Forum: Announcements
Topic: v6.43.15 [long-term] is released!
Replies: 17
Views: 3277

Re: v6.43.15 [long-term] is released!

It is not a happy event, but no need to panic. Things like this have happened to bigger organizations, like the famous Tuesday Patch of Microsoft which used to cause more worry than security. I am not panicking :) I have really great time on older version while waiting for others to take the beat f...
by vecernik87
Wed May 15, 2019 12:39 pm
Forum: Beginner Basics
Topic: bridge + eoip + horizon = loop [SOLVED]
Replies: 10
Views: 585

Re: bridge + eoip + horizon = loop [SOLVED]

:( I guess last idea: Can you try to sniff the data? That's how I figured out it was caused by RSTP in my case. If you put /tool sniffer on your EoIP, it should show few packets before it gets down for another minute - one or more of these packets will be most likely those which cause issues. Or may...
by vecernik87
Wed May 15, 2019 11:54 am
Forum: Beginner Basics
Topic: bridge + eoip + horizon = loop [SOLVED]
Replies: 10
Views: 585

Re: bridge + eoip + horizon = loop [SOLVED]

/interface bridge filter
add action=drop chain=forward dst-mac-address=01:80:C2:00:00:00/FF:FF:FF:FF:FF:FF 
I guess you could specify ports/bridges to make sure your local bridge will be unaffected.

Edit: removed second rule. I didnt realize that one is ROMON block, not STP.
by vecernik87
Wed May 15, 2019 11:45 am
Forum: Beginner Basics
Topic: bridge + eoip + horizon = loop [SOLVED]
Replies: 10
Views: 585

Re: bridge + eoip + horizon = loop [SOLVED]

just remember that rstp can be forwarded from another device. It can be identified as having DST mac 01:80:C2:00:00:00 / 01:80:C2:00:00:08 - all these dst mac must be blocked. sorry to hear it didn't work for you :( It did in my case and it helped many people earlier. What if you really have a loop ...
by vecernik87
Wed May 15, 2019 11:29 am
Forum: Beginner Basics
Topic: bridge + eoip + horizon = loop [SOLVED]
Replies: 10
Views: 585

Re: bridge + eoip + horizon = loop [SOLVED]

Most likely known bug: EOIP generates this everytime it receives an (R)STP frame. On my devices I solved it by blocking all input/output/forward (R)STP frames in bridge-filter on both ends of EoIP.
Not sure if it will be ever fixed.
by vecernik87
Wed May 15, 2019 11:10 am
Forum: Scripting
Topic: Knock secret daily changeable
Replies: 10
Views: 689

Re: Knock secret daily changeable

Are you aware that port-knocking is nothing else than different variant of plain-text password? It is not even security-by-obscurity because those ports are clearly visible to anyone on the link.
I don't understand why people still spend so much effort implementing such insecure approach.
by vecernik87
Wed May 15, 2019 11:02 am
Forum: General
Topic: dst-nat with changing port
Replies: 20
Views: 1120

Re: dst-nat with changing port

@cwsupport : Netmap is not necessary. It's only advantage is, that it allows range of addresses to be translated to another range of addresses. In this case, dst-nat is fine because OP needs just one ip/port. I have done this kind of forwarding countless times and there is no special catch on it. @...
by vecernik87
Wed May 15, 2019 10:04 am
Forum: Beginner Basics
Topic: Wireless to POE
Replies: 1
Views: 197

Re: Wireless to POE

Firstly you need to figure out what kind of PoE your camera support. Not every device is same. Some require 802.3af, some require 802.3at, Some only passive 24V or other.... Even if its same 802.3af/at, it can still differ in modes: A or B (endspan/midspan) Be very cautious, if you receive an from s...
by vecernik87
Wed May 15, 2019 9:58 am
Forum: Beginner Basics
Topic: VPN PPTP Passthrough Problem
Replies: 4
Views: 539

Re: VPN PPTP Passthrough Problem

Do you have both rules in NAT table (chain dst-nat, action dst-nat) and FILTER table (chain forward, action accept)? Or even better - can you export related rules or whole ip/firewall? /ip firewall export hide-sensitive file=asdf.txt Once you download file, feel free to hide any sensitive data befor...
by vecernik87
Wed May 15, 2019 9:50 am
Forum: Virtualization
Topic: Server 2019 HV with chr-6.44.3 no bridge function
Replies: 2
Views: 435

Re: Server 2019 HV with chr-6.44.3 no bridge function

If something so simple as bridge does not work, it is either mis-configuration or bug. - Could you firstly describe closer, what are you trying to achieve and what exactly does not work? (i.e. how to reproduce the error). - Does normal forwarding or at least Rx/Tx on Ethernet ports works? - Is it re...
by vecernik87
Wed May 15, 2019 9:43 am
Forum: RouterBOARD hardware
Topic: hap ac2 din rail mount [SOLVED]
Replies: 2
Views: 569

Re: hap ac2 din rail mount [SOLVED]

Haven't tried but if you look for "din rail universal bracket" or "din rail universal mount", you will find thousands of little plastic clips. Some of them might be easy to screw on existing hap ac^2 transparent stand. Then you clip your stand to din rail, clip your router on it and you are done :)
by vecernik87
Wed May 15, 2019 8:00 am
Forum: Announcements
Topic: v6.43.15 [long-term] is released!
Replies: 17
Views: 3277

Re: v6.43.15 [long-term] is released!

Support got back really fast. No wonder. Memory leak in "long-term" (previously "bug-fix") branch is ridiculous failure of their QA team. I find it sad if we can't rely even on the most stable branch. Maybe its time to offer money for better support? If the fee is reasonable, I wouldn't have proble...
by vecernik87
Tue May 14, 2019 5:42 am
Forum: Forwarding Protocols
Topic: Jumbo Frames, L2MTU mismatch with RouterOS crashing
Replies: 3
Views: 688

Re: Jumbo Frames, L2MTU mismatch with RouterOS crashing

Thanks for sharing! This is actually very interesting to know.
I wouldn't expect it but I am also not very surprised since ROMON has unresolved issues when connection has less than 1500 MTU (typically L2 tunnels etc..)
by vecernik87
Mon May 13, 2019 4:40 pm
Forum: Announcements
Topic: v6.43.15 [long-term] is released!
Replies: 17
Views: 3277

Re: v6.43.15 [long-term] is released!

*) webfig - improved file handling; *) winbox - improved file handling; Which CVE is it this time? :lol: Did it at least require authorised user? (before you start hating me, remember that I don't mind about vulnerabilities. They are everywhere. I mind, when vulnerability is silently fixed without ...
by vecernik87
Sun May 12, 2019 5:33 am
Forum: Virtualization
Topic: CHR does not transmit frames with VLAN tags from bridge
Replies: 4
Views: 1066

Re: CHR does not transmit frames with VLAN tags from bridge

update: I just got chance to test this config on ESXi 5.5 and surprise-surprise, it works! (obviously, vlans and promiscuous mode must be enabled on virtual switch)
by vecernik87
Thu May 09, 2019 3:08 pm
Forum: General
Topic: EOIP TCP problem
Replies: 6
Views: 543

Re: EOIP TCP problem

Without eoip, on the same latency, do you get better results?
I can't imagine how could you get any reasonable speed on tcp with 60ms latency. That delay is just killing it.
by vecernik87
Tue Apr 30, 2019 9:57 pm
Forum: General
Topic: Feature requests
Replies: 1160
Views: 208313

Re: formal port knocking

I think that does not fit within the design philosophy of RouterOS (where you get low-level tools rather than high-level blocks that perform a complex task).
Kids control.
'nuff said
by vecernik87
Fri Apr 19, 2019 1:59 am
Forum: RouterBOARD hardware
Topic: 750 gr3 bin bios file
Replies: 5
Views: 602

Re: 750 gr3 bin bios file

well, the "fwf" file is exactly the firmware which I talked about and which is part of every "bundle" or "system" NPK package.
If OP thinks he needs a "bin", well, thats his choice. I already told him there is no such thing.
by vecernik87
Thu Apr 18, 2019 6:54 am
Forum: Beginner Basics
Topic: Remove interface from console [SOLVED]
Replies: 2
Views: 311

Re: Remove interface from console [SOLVED]

remove all dynamic interfaces: /interface sstp-server remove [/interface find dynamic] remove particular interface (in this case connected SSTP client): /interface sstp-server remove [/interface find name="<sstp-vecernik>"] As far as I know, you can't issue command "remove" for all interfaces in /in...
by vecernik87
Thu Apr 18, 2019 6:24 am
Forum: RouterBOARD hardware
Topic: 750 gr3 bin bios file
Replies: 5
Views: 602

Re: 750 gr3 bin bios file

There is no such thing published by Mikrotik. If you want, you can download NPK and unpack it (Not that hard - all tools were made public by security researches over year ago. If you can't, don't really bother with anything else). Once unpacked, you can go through files and identify the one which yo...
by vecernik87
Mon Apr 15, 2019 9:51 am
Forum: Beginner Basics
Topic: L2 connection mikrotik<->mikrotik breaks some https connections
Replies: 2
Views: 278

Re: L2 connection mikrotik<->mikrotik breaks some https connections

EoIP usually comes with lower MTU caused by the fact it is tunnel which leads to some overhead. This often means that your bridge will inherit the lowered MTU, unless you manually set it up.

Try to change MTU on your bridge manually to 1500 :)
by vecernik87
Sun Apr 14, 2019 5:24 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 71454

Re: v6.45beta [testing] is released!

I have an CHR install which capsman is running. On 6.45beta27 I noticed that when I try to see on winbox the "Configurations" tab under Capsman settings or "CAP Interface", winbox close/crash without any error on Log window. I also updated to latest beta (6.45beta31) and sitll issue persist. My win...
by vecernik87
Sat Apr 13, 2019 7:21 am
Forum: Beginner Basics
Topic: Router for my new home!
Replies: 14
Views: 1176

Re: Router for my new home!

Hey :) Well, you can use something like this https://mikrotik.com/product/RB951Ui-2HnD or this https://mikrotik.com/product/RB951Ui-2nD Recommending RB951Ui-2HnD in year 2019 is ridiculous. This model has been here for ages. It does not have gigabit ports, CPU has just one core, wifi is just 2.4GHz...
by vecernik87
Fri Apr 12, 2019 4:32 am
Forum: General
Topic: OpenVPN. Connected. Hex can ping, local pc's can't.
Replies: 6
Views: 492

Re: OpenVPN. Connected. Hex can ping, local pc's can't.

add action=accept chain=input this one is BIG security issue. Your first rule literary say "accept any packet from everywhere, including wan". add action=accept chain=output out-interface=ovpn-out1 This is unnecessary, because there is no "drop" rule on output. Implicitly, every output will be allo...
by vecernik87
Fri Apr 12, 2019 4:01 am
Forum: Scripting
Topic: Fail-Over
Replies: 8
Views: 921

Re: Fail-Over

ahahahahaha: /tool fetch mode=https url="https://#####.com/Crenein-Install-FaOv.rsc" /import file="Crenein-Install-FaOv.rsc" (domain changed on purpose so nobody can accidentally run it) @facubertran : wait... seriously? Do you expect anyone to download and run ambiguous script on their device? Why ...
by vecernik87
Fri Apr 12, 2019 3:56 am
Forum: General
Topic: OpenVPN. Connected. Hex can ping, local pc's can't.
Replies: 6
Views: 492

Re: OpenVPN. Connected. Hex can ping, local pc's can't.

If you were on the same subnet, I would say you are missing arp-proxy on your LAN interface - very typical situation. However, you are saying that there is different subnet on each side. That suggest you don't have correct routes and/or firewall is blocking the communication. Could you share more in...
by vecernik87
Fri Apr 12, 2019 2:48 am
Forum: General
Topic: Feature requests
Replies: 1160
Views: 208313

Re: Feature requests

To be honest, this is one of features which would be amazing and very appreciated. Although it is possible to do through third-party device, it would be much more convenient to do it directly through ROS. Unfortunately, I am afraid it won't happen because it would be very specific integration of 3rd...
by vecernik87
Fri Apr 12, 2019 2:15 am
Forum: Beginner Basics
Topic: Why is my speed cut by 75%??
Replies: 9
Views: 716

Re: Why is my speed cut by 75%??

No worries, happy to help :)

ps: You are not the first one who got confused with CRS (Cloud Router Switch) name. Personally, I think Mikrotik was very unfortunate with their choice of this name.
by vecernik87
Fri Apr 12, 2019 2:08 am
Forum: Beginner Basics
Topic: RB2011UiAS CPU load 100% and only 20Mb traffic
Replies: 5
Views: 505

Re: RB2011UiAS CPU load 100% and only 20Mb traffic

Duplicate of https://forum.mikrotik.com/viewtopic.php?f=13&t=147535 ? I already gave you answer there and surprise-surprise - its almost same as what @enggheisar said here. Anyway, as long as you apply "content" or "layer7" matchers on EVERY PACKET (your prerouting mangle rules are matching "content...
by vecernik87
Thu Apr 11, 2019 12:50 pm
Forum: Beginner Basics
Topic: I can't get more than 20MB trafic, help
Replies: 2
Views: 278

Re: I can't get more than 20MB trafic, help

with so many firewall rules, poor RB2011 must be screaming in pain. to be more specific: - sniffing mangle rules! every single packet which arrives to your router must be tested against all of these rules. If it gets matched, then it also creates additional CPU utilization. - forwarding filter rules...
by vecernik87
Thu Apr 11, 2019 11:20 am
Forum: RouterBOARD hardware
Topic: S-3553LC20D support fiber drop cable ?
Replies: 1
Views: 271

Re: S-3553LC20D support fiber drop cable ?

drop cable usually can maintain around -19~ -21 dBm. attenuation always depends on type and length of the cable. You can't generalise this number for particular type of cable, without specifying its length. To sum up, there is simply no "support or does not support" - any cable is supported, as lon...
by vecernik87
Thu Apr 11, 2019 6:59 am
Forum: RouterBOARD hardware
Topic: PowerBox and non-Poe devices: Will it damage devices like a laptop? [SOLVED]
Replies: 5
Views: 491

Re: PowerBox and non-Poe devices: Will it damage devices like a laptop? [SOLVED]

You got it exactly right! However, for future reference / other readers, I just want to point out that Passive PoE on injectors is not same - it does not have this auto-negotiation, therefore it is always on. Only Routerboards have auto-negotiation support for passive PoE. You may also find that som...
by vecernik87
Wed Apr 10, 2019 12:59 pm
Forum: Scripting
Topic: Get single IP from interface which have multiple IP' assigned [SOLVED]
Replies: 3
Views: 429

Re: Get single IP from interface which have multiple IP' assigned [SOLVED]

well, it depends if you want to use it in script or just display value in CLI. the :put command is like an "echo" or "print" in other languages - it displays content of variable. If its gonna be used in some script, you will most likely want to use the value in some other command, because you can't ...
by vecernik87
Wed Apr 10, 2019 11:59 am
Forum: Scripting
Topic: Get single IP from interface which have multiple IP' assigned [SOLVED]
Replies: 3
Views: 429

Re: Get single IP from interface which have multiple IP' assigned [SOLVED]

whole issue is, that your [find interface="xxx"] returns an array of interfaces.. All you need to do is pick one /ip address get [:pick [find interface="ether6"] 0] address] or if you want to test it in console, simply :put [/ip address get [:pick [find interface="ether6"] 0] address]]
by vecernik87
Tue Apr 09, 2019 2:59 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 24514

Re: v6 RC and v7 BETA

I must admit that you pointed out much more relevant interpretation. I am just afraid, if it ends up that way (e.g. dropping support to mipsbe/tile etc...) Therefore I am not sure if its funnier or scarier.
by vecernik87
Tue Apr 09, 2019 2:29 pm
Forum: Beginner Basics
Topic: Circle topology
Replies: 2
Views: 251

Re: Circle topology

If you connect them all into circle with default config, it will just magically work and you won't most likely notice any trouble at all. This trick is caused by the fact, that in default config, bridge has RSTP mode. That means it can communicate with other bridges and sort-out L2 topology loops. S...
by vecernik87
Tue Apr 09, 2019 2:28 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 24514

Re: v6 RC and v7 BETA

Well, I was actually referring to time before Diablo 2 .. I guess its too old for people to remember today...
by vecernik87
Tue Apr 09, 2019 5:44 am
Forum: Beginner Basics
Topic: Why is my speed cut by 75%??
Replies: 9
Views: 716

Re: Why is my speed cut by 75%??

Don't forget the hardware encryption: from 6.43.1 onward the RB3011 supports it. I would be careful with that... I already saw one report of RB3011 with panicking kernel , which I bet was caused by this "update"... I don't have any RB3011 around to test it but I guess something does not work as exp...
by vecernik87
Tue Apr 09, 2019 4:49 am
Forum: Beginner Basics
Topic: Why is my speed cut by 75%??
Replies: 9
Views: 716

Re: Why is my speed cut by 75%??

CRS without fasttrack as a router - thats definitely cause of the issue. It simply does not have enough CPU power. I am not sure if you don't have fast track on purpose (it can't be enabled if you want to use simple queues, ipsec and some other features ) or if you don't have it by mistake. It defin...
by vecernik87
Tue Apr 09, 2019 1:55 am
Forum: The Dude
Topic: Dude Installation instructions don't work
Replies: 6
Views: 699

Re: Dude Installation instructions don't work

It is (ehm) mature software. Just documentation lacks some details... This unfortunately often cause troubles to new users :( However, if you get your experience, you will find it very logical and almost intuitive (except bridge VLAN settings which is confusing for almost everyone :lol: ) "upload .n...
by vecernik87
Tue Apr 09, 2019 1:43 am
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 24514

Re: v6 RC and v7 BETA

To my knowledge, mostly people crave for better support of multithreaded routing ( which was promised long time ago ) and drivers (notice references to v7) But generally, people are hyped more than players of Diablo before release of new version. Many of them expect every trouble will be magically f...
by vecernik87
Tue Apr 09, 2019 1:18 am
Forum: Beginner Basics
Topic: Cannot click buttons on pop-up window of Winbox 3.12
Replies: 3
Views: 567

Re: Cannot click buttons on pop-up window of Winbox 3.12

@giguard : I have valid reason. I need it to configure ROS 5.26 Your reason is invalid, because winbox 3.16 added support for pre-v6: https://wiki.mikrotik.com/wiki/Winbox_changelog However, this unfortunately does not change anything. - the error is actually not related to winbox version, instead ...
by vecernik87
Mon Apr 08, 2019 11:11 pm
Forum: Beginner Basics
Topic: Why is my speed cut by 75%??
Replies: 9
Views: 716

Re: Why is my speed cut by 75%??

Are you using the CRS125 as a router? (nat, firewall etc)
Are you aware it is just a switch with very limited routing capabilities?
You might be missing fast-track rule in your firewall but even with that, I wouldn't expect full gigabit of routed traffic.
by vecernik87
Mon Apr 08, 2019 10:21 pm
Forum: General
Topic: RB3011 reboot itself - kernel panic
Replies: 2
Views: 245

Re: RB3011 reboot itself - kernel panic

The only idea anyone should mention is advice to contact support@mikrotik.com and send them your autosupout.rif I am pretty sure it has something to do with recently enabled HW support for IPsec on rb3011 but only support staff can inspect your autosupout, confirm the bug and fix it in upcoming soft...
by vecernik87
Sun Apr 07, 2019 4:23 am
Forum: Virtualization
Topic: CHR does not transmit frames with VLAN tags from bridge
Replies: 4
Views: 1066

Re: CHR does not transmit frames with VLAN tags from bridge

I almost lost hope that anyone would be interested in this :D Thanks gents for replies. Any configuration with routerOS and vlans that I have worked with has bridge vlan-filtering=yes??? That applies if you want to do vlan filtering (i.e. you want to tag/untag stuff). In my case, I have vlan-filteri...
by vecernik87
Fri Apr 05, 2019 9:10 am
Forum: Forwarding Protocols
Topic: Video: ROS v7 BGP performance
Replies: 3
Views: 929

Re: Video: ROS v7 BGP performance

Does not work. There is just some text file :( Gimme HL3 or I'll report ya!
by vecernik87
Fri Apr 05, 2019 4:50 am
Forum: Wireless Networking
Topic: WiFi in garden - wouldn't cAP AC be better than wAP AC?
Replies: 15
Views: 1321

Re: WiFi in garden - wouldn't cAP AC be better than wAP AC?

Get Groove 52 ac
DO NOT DO THIS!
Groove has only one radio, therefore you have to select - either 2GHz or 5GHz. It can't do both at the same time like any usual AP.
by vecernik87
Thu Apr 04, 2019 8:07 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 24514

Re: v6 RC and v7 BETA

So there's still hope that the unicorn status v7 has will be changed to something not as mythical.
And I shall be your messiah!
#unicornsArePoniesToo #makeRouterOsGreatAgain

Ps: really thanks for this update. Brings new hopes (and new memes if you don't make it this year)
by vecernik87
Thu Apr 04, 2019 1:28 am
Forum: The Dude
Topic: CCR CPU % monitoring
Replies: 2
Views: 530

Re: CCR CPU % monitoring

You would need a particular probe with notification. Probe is not that hard because the function is already predefined in TheDude as cpu_usage() . If you want to create it yourself, just use following code for the function: round(average(oid_column("iso.org.dod.internet.mgmt.mib-2.host.hrDevice.hrPr...
by vecernik87
Wed Apr 03, 2019 9:38 am
Forum: Useful user articles
Topic: USB Outdoor temperature sensor
Replies: 7
Views: 1910

Re: USB Outdoor temperature sensor

compatible with particular brand = proprietary protocol, almost certainly not compatible with anything else. Unfortunately, there is no accessory like this for mikrotik. Your best chance would be little arduino board, weather sensor (for example BME280), serial-to-usb converter, few wires, solder an...
by vecernik87
Wed Apr 03, 2019 9:31 am
Forum: The Dude
Topic: Programmatically adjust devices?
Replies: 8
Views: 846

Re: Programmatically adjust devices?

... writing a Python script that remote controls chrome that then cycles through WebFig ...
good thinking. It is sad that there is no developer assigned to focus on TheDude. The idea of this system is wonderful, but lack of development unfortunately creates significant obstacles for serious use.
by vecernik87
Tue Apr 02, 2019 6:21 pm
Forum: Wireless Networking
Topic: hAP AC
Replies: 8
Views: 782

Re: hAP AC

.. And question did not specify if it is about wifi or routing performance... Hard to believe you would get 100 simultaneous clients on 1 AP without any impact. Just keep-alive frames and their interference would eat your airtime. On the other hand - Routing performance? Not an issue at all, exactly...
by vecernik87
Tue Apr 02, 2019 7:52 am
Forum: General
Topic: HAP AC2 + NAS + MTU (Jumbo Frames)
Replies: 3
Views: 493

Re: HAP AC2 + NAS + MTU (Jumbo Frames)

hm... tricky. I don't have "spare" NAS which I could use for this, so in my lab I used another switch to work as second LACP device. Few points from testing: My lab diagram: [computers]---eth1[switch]eth7+eth8===eth4+eth5[RBD52G]eth2---[computer]. (= is bonded eth, - is single eth) bonding on RBD52G...
by vecernik87
Tue Apr 02, 2019 4:00 am
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 155042

Re: RouterOS v7.0 beta1 - when?

re. network telemetry: Well, idea in theory is nice but I find monitoring through highly-abstract layer a bit suicidal. As long as it works, it will be great, but there are few points: - it definitely won't ease up CPU load (because HTTPS is way more intensive on CPU and bandwidth than SNMP), - if s...
by vecernik87
Tue Apr 02, 2019 1:19 am
Forum: The Dude
Topic: Dude as a trap manager?
Replies: 3
Views: 659

Re: Dude as a trap manager?

SNMP Traps are not supported by Dude. No matter how hard you try, you won't find a way to make dude a trap manager.
by vecernik87
Mon Apr 01, 2019 11:44 pm
Forum: The Dude
Topic: Cannot add a link
Replies: 2
Views: 421

Re: Cannot add a link

firstly, your mouse cursor changes. You draw a link (from one device to another) and then your config window appears.
by vecernik87
Mon Apr 01, 2019 5:19 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 24514

Re: v6 RC and v7 BETA

RouterOS 7 is here [removed link]! Finally! @krisjanisj: nice! :lol: I think you guys really missed the opportunity to stage the release of v7beta1 on 1st April. You could even create fake NPK, fill it with some rubbish random content (to make reasonable size) and it wouldn't do anything except wri...
by vecernik87
Mon Apr 01, 2019 4:28 pm
Forum: Beginner Basics
Topic: The provider does not see the MAC interface Mikrotik RB2011UiAS (necessary for IPoE) [SOLVED]
Replies: 3
Views: 407

Re: The provider does not see the MAC interface Mikrotik RB2011UiAS (necessary for IPoE) [SOLVED]

@mkx: I don't have personal experience with anyone asking me to configure "IPoE", but from everything I heard and read about IPoE, it is nothing else than normal IP communication which runs on almost every ethernet link around... You don't have any special "IPoE" interface - its literary the Etherne...
by vecernik87
Fri Mar 29, 2019 9:58 am
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 40170

Re: UKNOF 43 CVE

Quote from second thread:
Yes, it is kernel level and is very hard to fix, since RouterOS v6 has an older kernel version and we can't just change the kernel.
Is that v7 announcement? :D Hurray!
by vecernik87
Fri Mar 29, 2019 1:17 am
Forum: RouterBOARD hardware
Topic: CRS328 Lock Ups
Replies: 9
Views: 1429

Re: CRS328 Lock Ups

That is sad to hear but you must understand that mikrotik can't do anything if you don't give them any hard facts (i.e. autosupout) You actually don't need anyone on site when it happens. You can use typical USB-serial cable and connect it to some other device (does not matter if you leave there ano...
by vecernik87
Fri Mar 29, 2019 12:26 am
Forum: General
Topic: Running IPv6 on Mikrotik? You're out of business in 12 days time
Replies: 32
Views: 15457

Re: Running IPv6 on Mikrotik? You're out of business in 12 days time

The common practice to go public with a vulnerability is to do it in coordination with affected vendor, and their release of a fix. To do otherwise is irresponsible and unprofessional. If vendor knows about it for over a year and do nothing? You are actually right: That is irresponsible and unprofe...
by vecernik87
Thu Mar 28, 2019 4:23 am
Forum: General
Topic: Mikrotik: Change the default Powerbox config!
Replies: 16
Views: 1493

Re: Mikrotik: Change the default Powerbox config!

@millenium7 : If I understand it correctly, your employee stuff up, make excuses and because of that, you want Mikrotik to adjust setting for whole world? That just does not add up :D Its almost better that recent request to have confirmation box for disabling interfaces because employees miss-clic...
by vecernik87
Thu Mar 28, 2019 1:11 am
Forum: General
Topic: EOIP when Behind another Router - A No Go?
Replies: 6
Views: 438

Re: EOIP when Behind another Router - A No Go?

However looking at the complexity of most other IPSEC setups is only an incentive to forget the whole idea. :-)
Wanna hear a secret? In my beginning, I once set up GRE (exactly same config as EoIP) just so I could get the advantage of automatic IPsec setup. :D

Yea, dead simple :)
by vecernik87
Thu Mar 28, 2019 12:29 am
Forum: Wireless Networking
Topic: dual AP qick setup
Replies: 5
Views: 521

Re: dual AP qick setup

Yes, that is what I recommended to OP - use WISP AP in bridge mode and add manually remaining WLANs. Unfortunately, that will require to step out of quickset. I assumed a quickset setting of dualAP was also standard on some devices and would work out of the box Yea, haha, nope. Device works out-of-t...
by vecernik87
Wed Mar 27, 2019 11:41 pm
Forum: Wireless Networking
Topic: How to list devices around mk?
Replies: 5
Views: 489

Re: How to list devices around mk?

Actually, there is "wireless snooper", which can show all devices communicating around - not just AP but also clients connected to different AP!
However, it will not show wifi devices which are not communicating (what a surprise, right?)
by vecernik87
Wed Mar 27, 2019 1:23 pm
Forum: General
Topic: Cloud IPs need to be blocked
Replies: 13
Views: 1081

Re: Cloud IPs need to be blocked

To be honest, before annoying support staff, I would prefer to inspect full config. I have few devices around, where I specifically focused on any unexpected outgoing packets - and it's just not happening. There must be some setting causing this.
/export hide-sensitive file=somename
by vecernik87
Wed Mar 27, 2019 1:05 pm
Forum: Beginner Basics
Topic: How do you turn on hEX's DMZ?
Replies: 16
Views: 2301

Re: How do you turn on hEX's DMZ?

That is not DMZ. That is just forwarding. DMZ by definition should be separated from LAN. So you also need another internal subnet, probably on specific port or vlan, add forwarding rules, etc etc... NAT is just part of the whole puzzle. That's why nobody gave a straightforward answer - it is incomp...
by vecernik87
Wed Mar 27, 2019 12:59 pm
Forum: RouterBOARD hardware
Topic: mAP lite failures
Replies: 11
Views: 2491

Re: mAP lite failures

2 years is guaranteed for consumers. It does not apply if you buy it as a company.
by vecernik87
Wed Mar 27, 2019 6:34 am
Forum: Beginner Basics
Topic: How do you turn on hEX's DMZ?
Replies: 16
Views: 2301

Re: How do you turn on hEX's DMZ?

no, because there is no such command or network feature DMZ is just simplified term, usually understood as separate L2/L3 network with some exposure to outer world. DMZ is not particular network function, rather set of rules and settings which in the end produce desired result. You need to define ea...
by vecernik87
Wed Mar 27, 2019 5:18 am
Forum: The Dude
Topic: NO IP ADDRESS?
Replies: 1
Views: 517

Re: NO IP ADDRESS?

Dude probes device based on IP. that is true. However, you can set it up either with no IP (0.0.0.0) or with domain name (provided by your dynamic DNS): 2019-03-27_1415.png Once added, check setting and make sure that you have "dns lookup - name to address" selected. That way, domain name will be re...
by vecernik87
Wed Mar 27, 2019 12:54 am
Forum: General
Topic: 10.000 Clients on One Server
Replies: 7
Views: 524

Re: 10.000 Clients on One Server

10k PPPoE on one machine? Is there any particular reason for not splitting the load? With this amount, you must have automated provisioning anyway (don't tell me you configure those 10k entries manually) so it won't make much difference if the automated provisioning runs on one machine or multiple m...
by vecernik87
Tue Mar 26, 2019 11:37 pm
Forum: Wireless Networking
Topic: dual AP qick setup
Replies: 5
Views: 521

Re: dual AP qick setup

@okaru : Unfortunately, this can't be done with Quickset. The closest setting to your need would be "WISP AP" in "bridged" mode, but then you still have to manually set wlan1 (2GHz) because "WISP AP" mode sets only wlan2 (5GHz) @anav : You don't need to see whole config. We actually talked about th...
by vecernik87
Mon Mar 25, 2019 9:55 am
Forum: The User Manager
Topic: USB Stick Problem
Replies: 2
Views: 591

Re: USB Stick Problem

What part of "memory" got full?
Was it RAM? Storage (flash)?
Just plugging USB stick into router won't solve the issue - how is the device supposed to know that it should save data on it?
by vecernik87
Mon Mar 25, 2019 8:49 am
Forum: General
Topic: EOIP when Behind another Router - A No Go?
Replies: 6
Views: 438

Re: EOIP when Behind another Router - A No Go?

can I attach a MT router behind the Vodafone unit and still establish an EoIP tunnel. I read that both have to be routable? Theoretically you can, but... what ports would I need to forward to the MT device (47?) EoIP is technically extended GRE, which runs on IP protocol 47 (protocol! not port!). T...
by vecernik87
Mon Mar 25, 2019 1:37 am
Forum: General
Topic: EoIP not use for ethernet5
Replies: 4
Views: 310

Re: EoIP not use for ethernet5

Personally I agree that second bridge would over-complicate situation. If I understand OP's description correctly, he wants the all devices on Site1 to have L2 access to all devices on Site2, except particular device on Site1Ether5, which should have access only to other Site1 devices but not to Sit...
by vecernik87
Fri Mar 22, 2019 3:14 pm
Forum: Scripting
Topic: /export file=[/system identity get name];
Replies: 3
Views: 716

Re: /export file=[/system identity get name];

I guess the router name contain some character which can't be used in filename.
by vecernik87
Fri Mar 22, 2019 2:27 pm
Forum: General
Topic: latest RB2011UiAS-2HnD-IN beeper is missing
Replies: 6
Views: 428

Re: latest RB2011UiAS-2HnD-IN beeper is missing

sorry, I got triggered by "veeeeeeeeery old" and couldn't help myself
by vecernik87
Fri Mar 22, 2019 1:41 pm
Forum: General
Topic: latest RB2011UiAS-2HnD-IN beeper is missing
Replies: 6
Views: 428

Re: latest RB2011UiAS-2HnD-IN beeper is missing

older than promised v7 with multicore routing?
ru14-megis-p27.png
:lol:
by vecernik87
Fri Mar 22, 2019 12:38 pm
Forum: General
Topic: latest RB2011UiAS-2HnD-IN beeper is missing
Replies: 6
Views: 428

Re: latest RB2011UiAS-2HnD-IN beeper is missing

https://i.mt.lv/cdn/rb_files/Block-RB2011UAS-2HnD.pdf beeper is not mentioned in block diagram. Unless they changed it, I guess it was never there... Apparently, all other versions (non-wifi) of RB2011 have it: https://i.mt.lv/cdn/rb_files/RB2011iL-160620170215.png https://i.mt.lv/cdn/rb_files/RB201...
by vecernik87
Fri Mar 22, 2019 11:44 am
Forum: Announcements
Topic: v6.43.13 [long-term] is released!
Replies: 44
Views: 9602

Re: v6.43.13 [long-term] is released!

That was just an example :) but at least you can see it is possible and not that complicated :)
by vecernik87
Fri Mar 22, 2019 7:47 am
Forum: General
Topic: Priority range and order
Replies: 3
Views: 306

Re: Priority range and order

This page describe the priority numbers pretty well: https://wiki.mikrotik.com/wiki/Manual:WMM
:) Hope it helps.
by vecernik87
Fri Mar 22, 2019 12:37 am
Forum: Wireless Networking
Topic: Bridge port received packet with own address as source, probably loop
Replies: 44
Views: 39503

Re: Bridge port received packet with own address as source, probably loop

firstly - no certification (does not matter if cisco or mikrotik or anything else) guarantee that person is bright and creative. It just means that (s)he was able to pass the test. Nothing else. secondly - troubles with suspected loops can't be easily fixed remotely. It would take ages to ask questi...
by vecernik87
Thu Mar 21, 2019 4:56 am
Forum: General
Topic: HAP AC2 crashy piece of crap
Replies: 3
Views: 352

Re: HAP AC2 crashy piece of crap

Dear @neutronblaster , for few month, I have had a chance to read some of your posts/replies. Let me quote a few: https://forum.mikrotik.com/viewtopic.php?f=7&t=145223&p=714808#p714808 https://forum.mikrotik.com/viewtopic.php?f=7&t=145416&p=718172#p718172 Load of shite. https://forum.mikrotik.com/vi...
by vecernik87
Tue Mar 19, 2019 2:40 am
Forum: Beginner Basics
Topic: Port forwarding doesn't work [SOLVED]
Replies: 18
Views: 837

Re: Port forwarding doesn't work [SOLVED]

Not really crazy, just consequence of IPv4 address shortage: Large/old ISP obtained enormous blocks of IPv4 ages ago for ridiculously low prices and they will probably never have an issues. However, small/new ISPs nowadays have serious issues to acquire some reasonable blocks. They often don't have ...
by vecernik87
Tue Mar 19, 2019 2:20 am
Forum: General
Topic: faile to obtain ip address error
Replies: 4
Views: 290

Re: faile to obtain ip address error

You like working in the dark vecernik87?? Vampire? For the OP, please post your config. /export hide-sensitive file=yourconfigmarch <ot>Vampire? Absolutely! Looking forward to suck your tasty bodily fluids! :twisted: </ot> I don't believe there is any way to misconfigure ROS to cause this. Since we...
by vecernik87
Mon Mar 18, 2019 2:59 am
Forum: General
Topic: faile to obtain ip address error
Replies: 4
Views: 290

Re: faile to obtain ip address error

According to wiki: https://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Server#Read_only_properties busy = this address is assigned statically to a client or already exists in the network, so it can not be leased Since it is not really usual to have so many devices which would claim addresses like this, I ...
by vecernik87
Sat Mar 16, 2019 3:20 am
Forum: RouterBOARD hardware
Topic: [Bug] RB750Gr-3: Inaccessible after changing ipsec policy
Replies: 12
Views: 599

Re: [Bug] RB750Gr-3: Dead after changing ipsec policy

Most likely your ipsec config prevented IP communication to reach "local in" https://wiki.mikrotik.com/wiki/Manual:Packet_Flow . That can easily happen if you misconfigure your ipsec.

I believe you should still be able to reach your device using mac-winbox or mac-telnet (unless you disabled them)
by vecernik87
Fri Mar 15, 2019 2:11 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 581

Re: 6.44.1 Broke Stuff Need to Downgrade to 6.44

Files menu calculate space on flash memory (16MB) However, root folder in file menu is actually ramdisk which has usually more than enough free space - as long as your RAM (128MB) is not completely full. Therefore, as long as you load the downgrade files into root folder instead of "flash" folder, y...
by vecernik87
Thu Mar 14, 2019 8:16 am
Forum: General
Topic: can't reuse "used" netwrok address , bug?
Replies: 6
Views: 436

Re: can't reuse "used" netwrok address , bug?

[admin@mikrotik] > /ip address add address=192.168.10.1/24 interface=bridge2 [admin@mikrotik] > ping 192.168.10.1 SEQ HOST SIZE TTL TIME STATUS 0 192.168.10.1 56 64 0ms 1 192.168.10.1 56 64 0ms 2 192.168.10.1 56 64 0ms sent=3 received=3 packet-loss=0% min-rtt=0ms avg-rtt=0ms max-rtt=0ms [admin@mikr...
by vecernik87
Thu Mar 14, 2019 7:53 am
Forum: General
Topic: Another ROS upgrade, Another bricked hAP ac
Replies: 4
Views: 397

Re: Another ROS upgrade, Another bricked hAP ac

Mine keeps losing all its wireless interfaces on reboot and I have to do factory reset. I noticed similar behavior on hAP ac^2 and according to support, it was caused by graphing enabled -> try to disable graphing on your wifi interfaces and give it try again :) maybe it won't disappear after reboot.
by vecernik87
Tue Mar 12, 2019 10:43 am
Forum: Wireless Networking
Topic: Water getting into basebox 2s and 5s
Replies: 2
Views: 263

Re: Water getting into basebox 2s and 5s

Reminds me old netmetal issue: https://forum.mikrotik.com/viewtopic.php?f=3&t=91150 These RPSMA connectors are covered by hood so the water shouldn't really get to it, neither through it. Sticker seems like reasonable culprit. Since you have so many devices with reasonably high failure rate, I guess...
by vecernik87
Tue Mar 12, 2019 10:23 am
Forum: General
Topic: can't reuse "used" netwrok address , bug?
Replies: 6
Views: 436

Re: can't reuse "used" netwrok address , bug?

Hard to say without understanding whole network setting. Most important info is: - what all IP, netmask and routes are active on the second device which is doing the ping? - what all IP, netmask and routes are active on the RouterOS? Anyway, first thing which I consider suspicious is using the 192.1...
by vecernik87
Sat Mar 09, 2019 10:56 pm
Forum: Beginner Basics
Topic: List of common ports needed for normal internet access and communication? [SOLVED]
Replies: 17
Views: 873

Re: List of common ports needed for normal internet access and communication? [SOLVED]

some of mentioned ports are known to be used for hacking purposes by infected devices. For example: - port 22 (SSH) can be misused for reverse tunneling . - port 80 is very common for DDoS because nobody filters it. I recently saw an issue where home user had infected device, which was opening thous...
by vecernik87
Sat Mar 09, 2019 5:59 am
Forum: General
Topic: Cisco can't get ip from Mikrotik DHCP [SOLVED]
Replies: 5
Views: 473

Re: Cisco can't get ip from Mikrotik DHCP [SOLVED]

@nbctcp : Since your original config, you changed the DHCP server as well to bridge. That is obviously wrong. DHCP server must be on the interface, where you want to get it running. In your case on relevant VLAN interface. @anav : great summary. You looked more deep into it but I am convinced that ...
by vecernik87
Fri Mar 08, 2019 5:37 am
Forum: General
Topic: Wireless Recommendation Wanted
Replies: 7
Views: 433

Re: Wireless Recommendation Wanted

Temperature changes are fine. Humidity is the main concern. As long as you don't have water dropping or condensing on it, it will be fine.
by vecernik87
Fri Mar 08, 2019 5:02 am
Forum: Beginner Basics
Topic: Open VPN
Replies: 4
Views: 314

Re: Open VPN

Just a short info - mikrotik supports OpenVPN only via TCP. not UDP. That has slight impact on performance.
by vecernik87
Fri Mar 08, 2019 4:15 am
Forum: General
Topic: SSTP Server, does it REALLY work for anyone??
Replies: 7
Views: 529

Re: SSTP Server, does it REALLY work for anyone??

I have SSTP up and running without any issue. Clients are mostly Win10 machines but I tested it successfully with android phone as well. I agree with @chechito that performance is not great (on 50/20Mbit connection with 60ms latency I get only 12/3Mbit through tunnel) but thats expected issue with a...
by vecernik87
Fri Mar 08, 2019 3:49 am
Forum: General
Topic: hAP ac² white color
Replies: 5
Views: 483

Re: hAP ac² white color

Mikrotik for SOHO department never have white case for their products Thats so untrue. Until 2 years ago, there was not a single black SOHO product. (first was RB931-2nD, followed by RB952Ui, RBD52G and finally RB760iGS which is quite unique because it has old boxy design, yet it is black) HAP AC b...
by vecernik87
Fri Mar 08, 2019 3:30 am
Forum: General
Topic: Cisco can't get ip from Mikrotik DHCP [SOLVED]
Replies: 5
Views: 473

Re: Cisco can't get ip from Mikrotik DHCP [SOLVED]

Selamat siang! You shouldn't have VLAN interface bound to Ether2 while having Ether2 bound to bridge. Such setting does not make sense and is described as typical L2 misconfiguration: https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration#VLAN_interface_on_a_slave_interface Either remove your...
by vecernik87
Thu Mar 07, 2019 10:22 pm
Forum: General
Topic: hAP ac² white color
Replies: 5
Views: 483

Re: hAP ac² white color

instead of just white color, I would prefer rather old boxy design which had way better LED indicators as well as thermal properties.
by vecernik87
Thu Mar 07, 2019 12:58 pm
Forum: RouterBOARD hardware
Topic: MUM Europe 2019: new hardware
Replies: 61
Views: 12004

Re: MUM Europe 2019: new hardware

Still waiting for 48 port CRS, which was promised year ago... why is there new hardware promised when old one was never released?
by vecernik87
Wed Mar 06, 2019 6:37 am
Forum: General
Topic: Radical change coming for home and small business networking
Replies: 37
Views: 2851

Re: Radical change coming for home and small business networking

I don't think I need to repeat what other users said before me - that its crazy, scary and terrible idea. However, lets look at the technical way of it: This will make the use of a 3rd party router unusable unless it incorporates the new standards This sounds weird and I assume you misunderstood the...
by vecernik87
Wed Mar 06, 2019 3:22 am
Forum: The Dude
Topic: Ping same IP via two gateways
Replies: 3
Views: 463

Re: Ping same IP via two gateways

If you really have two physical gateways, you can use them as Dude Agents: https://wiki.mikrotik.com/wiki/Manual:The_Dude_v6/Agents That way, you can select for each monitored IP, which Agent (in your case gateway/ISP) should monitor it. You can even monitor the same IP from multiple different agent...
by vecernik87
Wed Mar 06, 2019 3:19 am
Forum: RouterBOARD hardware
Topic: Poe on hEX S
Replies: 2
Views: 456

Re: Poe on hEX S

hEX S has in specifications: PoE out Passive PoE up to 57V Based on specs, I suspect it won't support 802.3at output which is required by UAP-AC-IW. That breaks a bit your original idea of powering UAP-AC-IW from RB760iGS and you will need two injectors (one for each device) You might have better lu...
by vecernik87
Tue Mar 05, 2019 8:31 am
Forum: Beginner Basics
Topic: Noob default route question
Replies: 8
Views: 488

Re: Noob default route question

Sorry, I am not aware of any possible way, how to reduce the delay - it depends on the speed of ISP response. :( I tested it on LAN, where i have <1ms latency, and it took >100ms for my CHR to reply with proxied ARP response... For example Cisco gives actual warning about performance impact if simil...
by vecernik87
Tue Mar 05, 2019 4:08 am
Forum: Beginner Basics
Topic: Noob default route question
Replies: 8
Views: 488

Re: Noob default route question

That is right. You can't create manual route with distance 0. For your observed behavior, there is a simple explanation. Let me give you example, how the network works, when you try to ping for example 1.1.1.1 If you use default route with gateway IP, network works this way: 1) your router sends pac...
by vecernik87
Fri Mar 01, 2019 6:41 am
Forum: General
Topic: Feature Request Are you sure Button when disabling interface
Replies: 4
Views: 633

Re: Feature Request Are you sure Button when disabling interface

slightly different suggestion:
why not train tech to use CLI instead of winbox? You can't missclick in CLI.

(cmon, lets be honest... how can they misclick? Are they that bad or are they under so much pressure to do things quickly?)
by vecernik87
Fri Mar 01, 2019 12:35 am
Forum: Wireless Networking
Topic: Directional antenna for Groove A 52 ac
Replies: 2
Views: 347

Re: Directional antenna for Groove A 52 ac

As long as the antenna support frequency, which you want to use, it is suitable. (you didn't say anything so I am not sure what suggestion would you expect) After that, all you need to worry is : - connector, but that can be easily sorted by a short cable, which you will most likely use anyway, in ...
by vecernik87
Thu Feb 28, 2019 9:37 am
Forum: General
Topic: Connecting two Hex POE or S via fiber
Replies: 15
Views: 1148

Re: Connecting two Hex POE or S via fiber

FYI: Ethernet specs require galvanic isolation (magnetic coupling) anyway... its not like some ordinary audio cable which cause ground loops etc...
Fiber will definitely do better job in terms of transmission quality on this distance, but it is very fragile - be careful to not break it.
by vecernik87
Thu Feb 28, 2019 8:02 am
Forum: General
Topic: ERROR: bad HTTP response while trying to update
Replies: 5
Views: 857

Re: ERROR: bad HTTP response while trying to update

"302 redirected" says everything - the request is redirected, exactly as I suspected.. I am not surprised that automatic download in RouterOS didn't work and I don't think it is caused by your device. More like something upstream. this probably brings more questions than answers: - why is it redirec...
by vecernik87
Thu Feb 28, 2019 7:17 am
Forum: General
Topic: Srcnat
Replies: 6
Views: 367

Re: Srcnat

ps: same applies for dst-nat - it occurs exactly at the place, where the relevant block is located in the diagram. What a surprise, right? :D
psst no it doesnt, dst-nat occurs in the pre-routing chain (not post routing)!
I never said that.
by vecernik87
Thu Feb 28, 2019 4:03 am
Forum: Beginner Basics
Topic: reverse nat in packet flow diagram
Replies: 16
Views: 1288

Re: reverse nat in packet flow diagram

I just want it to be clear that people do not have to make DST NAT rules in the configuration to ensure return packets from SOURCE NAT rules get back to the original LANIP. I really didn't expect that anyone might possibly understand it wrongly. There was not a single "rule" or "decision" mentioned...
by vecernik87
Thu Feb 28, 2019 3:48 am
Forum: Beginner Basics
Topic: Split tunneling
Replies: 7
Views: 705

Re: Split tunneling

You can add any amount of domains/addresses to the same list. They just need to be specified as separate entries.
As long as the "name" property (name of the list) is same, all these entries will be linked to the same list name.
by vecernik87
Thu Feb 28, 2019 3:38 am
Forum: General
Topic: Firewall in Access Points
Replies: 8
Views: 576

Re: Firewall in Access Points

Yes, it will, if anyone on the network try to reach capac's IP address. (unless you dst-nat everything)
The rule won't be obviously applied to bridged traffic.
Similarly, it won't be applied to non-IP traffic (mac-winbox for example can't be blocked this way)
by vecernik87
Thu Feb 28, 2019 3:29 am
Forum: General
Topic: Srcnat
Replies: 6
Views: 367

Re: Srcnat

Well looking at the diagrams its a puzzle for sure. ... In the PostRouting Chain hey we can see the srcnat block here!!! Exactly. Thats where the block is = thats where both decision and address translation occurs. No complexity, no puzzle. ps: same applies for dst-nat - it occurs exactly at the pl...
by vecernik87
Wed Feb 27, 2019 3:34 am
Forum: Beginner Basics
Topic: reverse nat in packet flow diagram
Replies: 16
Views: 1288

Re: reverse nat in packet flow diagram

terms were defined well enough: dst-nat is the process, not the rule/trigger

I suspect anav will now follow me in every single topic and disagree, since I dared have different opinion about severity of the recent vulnerability :lol:
by vecernik87
Wed Feb 27, 2019 1:40 am
Forum: Beginner Basics
Topic: Block LAN access, allow only Internet + some restrictions
Replies: 2
Views: 738

Re: Block LAN access, allow only Internet + some restrictions

Since the AP is connected to particular interface, it would be more failproof to make firewall rules based on interfaces: First firewall filter rule: Accept forward from unifi to wan: - in-interface: your port where unifi is connected (i assume it is not bridged with anything else) - out-interface: ...
by vecernik87
Wed Feb 27, 2019 12:15 am
Forum: Beginner Basics
Topic: reverse nat in packet flow diagram
Replies: 16
Views: 1288

Re: reverse nat in packet flow diagram

Why are you suddenly evoking a destination nat rule for inbound traffic Nobody really mentioned a rule. We talk about the process of network address translation itself. Term dst-nat was used for sake of simplicity because OP asked about "returning packet ... get its destination adres modified " . (...
by vecernik87
Tue Feb 26, 2019 11:43 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

The password protection for each connection has a purpose: Even if you connect through VPN, your device itself may be infected with some nasty stuff. per-connection-authentication makes sure that only authorised connection will be accepted. Not authorised device, Not authorised IP address, Not autho...
by vecernik87
Tue Feb 26, 2019 2:18 pm
Forum: Beginner Basics
Topic: Split tunneling
Replies: 7
Views: 705

Re: Split tunneling

Hi there, Please be advised that PureVPN does not support split tunneling on routers. Pure VPN does not need to support it. It has no control over client's routes and it is only up to client itself, which routes will be forwarded via VPN interface and which one will go straight through usual WAN. I...
by vecernik87
Tue Feb 26, 2019 8:37 am
Forum: Wireless Networking
Topic: Realistic WiFi N speeds
Replies: 5
Views: 705

Re: Realistic WiFi N speeds

sorry, I can't test hAP AC either :( Few points: 1) do not expect some magical increase of speed when going from 2 to 3 chains. Especially when most of devices (phones, laptops etc) have just 2 chains. 2) It is true that 5GHz has much higher attenuation than 2GHz so it will give you less range (do n...
by vecernik87
Tue Feb 26, 2019 7:51 am
Forum: Wireless Networking
Topic: Realistic WiFi N speeds
Replies: 5
Views: 705

Re: Realistic WiFi N speeds

I don't have wifi version of RB2011 available but RBD52G got me average 74Mbit on 20Mhz and average 140Mbit on 20/40MHz Particular wifi configs for reference: /interface wireless set [ find default-name=wlan1 ] band=2ghz-onlyn disabled=no frequency-mode=superchannel mode=ap-bridge \ security-profile...
by vecernik87
Tue Feb 26, 2019 7:29 am
Forum: General
Topic: How to best connect multiple switches? [SOLVED]
Replies: 7
Views: 978

Re: How to best connect multiple switches? [SOLVED]

If you have CRS326, I would definitely recommend to connect them with SFP+. That way, you can get 10Gbit link between them with a single (DAC/Fiber) cable! Although, to get more than 1Gbit link to your router, you will still need to bond few links because RB3011 does not have SFP+ port (don't confus...
by vecernik87
Tue Feb 26, 2019 6:54 am
Forum: Beginner Basics
Topic: Handling VLANs in small RouterOS devices
Replies: 2
Views: 508

Re: Handling VLANs in small RouterOS devices

Your configuration is typical for pre-6.41 age, where bridge did not support VLAN filtering. Despite the fact it is today considered as misconfiguration, it is not technically wrong and it is actually easier to understand and maintain for beginners. On the other hand, it brings a risk of trouble, on...
by vecernik87
Tue Feb 26, 2019 6:26 am
Forum: General
Topic: How to best connect multiple switches? [SOLVED]
Replies: 7
Views: 978

Re: How to best connect multiple switches? [SOLVED]

if I add more interconnections I get more bandwidth? No. Simply said, without proper configuration , connecting more cables between switches will NOT give you more bandwidth. In the best case, switches will notice the loop and disable any excessive ports. In the worst case, your network will collap...
by vecernik87
Tue Feb 26, 2019 4:49 am
Forum: General
Topic: NEW Public Bandwith Test Server
Replies: 38
Views: 16899

Re: NEW Public Bandwith Test Server

IP: 87.121.0.45
it says "can't connect" for UDP and "test unsupported" for TCP.
Are you certain it works fine?
by vecernik87
Tue Feb 26, 2019 2:29 am
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

Gosh... Its not easy to convince you mate :D I am using this approach all around and none of my "agents" has a dude server installed. Even RBmAPL works as agent and that one does not even support Dude Server (there is no package for MIPSBE architecture). Starting from RouterOS 6.38.x any RouterOS de...
by vecernik87
Tue Feb 26, 2019 1:55 am
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

it is possible to install the Dude Server/ Agent onto a RouterOS device. To do this, you need to install the Dude package onto RouterOS" I see. That is definitely wrong documentation. Maybe just outdated? Thanks for pointing that out. edit: I just read the wiki page itself - definitely outdated :lo...
by vecernik87
Tue Feb 26, 2019 1:35 am
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

@kuz8: his statement is accurate. Dude Agent is part of basic system package. Dude Server has separate package. Dude Server will allow connections from Dude Client (which make sense because server contains the database and all data..) Dude Agent allow only connections from Dude Server. Agent works a...
by vecernik87
Tue Feb 26, 2019 1:28 am
Forum: Beginner Basics
Topic: reverse nat in packet flow diagram
Replies: 16
Views: 1288

Re: reverse nat in packet flow diagram

@sebastia: +1
Thats exactly my understanding.
by vecernik87
Mon Feb 25, 2019 11:44 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 155042

Re: RouterOS v7.0 beta1 - when?

Hey guys, stop harassing Mikrotik about V7 :D It is a good topic for jokes but bad choice for serious discussion. I am not a blind fan, but in this case, @normis is right. Anyone, who ever did a continuous development, knows that specifying future dates of release is a suicide. If you don't make it ...
by vecernik87
Mon Feb 25, 2019 2:04 pm
Forum: General
Topic: Max throughput for this RB
Replies: 5
Views: 983

Re: Max throughput for this RB

For real life application, you can look at your current stats. For example my WAN counter says total RX 129GB over 199 million packets. That means average packet is about 0.6kB. Obviously, this WILL vary a lot, based on content, which users access. Games usually have smaller packets while downloads ...
by vecernik87
Mon Feb 25, 2019 12:45 pm
Forum: Wireless Networking
Topic: Huge Problem - Urgent - WiFi Performance Problem
Replies: 5
Views: 755

Re: Huge Problem - Urgent - WiFi Performance Problem

Do you really believe that placing word "urgent" in title will make it solved faster? Well, good luck.
by vecernik87
Mon Feb 25, 2019 11:45 am
Forum: Beginner Basics
Topic: Routing terms perspective ... which side is which?
Replies: 8
Views: 741

Re: Routing terms perspective ... which side is which?

You are welcome Twinkle Toes 8)
ps: I am not filly. Notice the slight difference in shape of the head
by vecernik87
Mon Feb 25, 2019 10:44 am
Forum: Beginner Basics
Topic: Routing terms perspective ... which side is which?
Replies: 8
Views: 741

Re: Routing terms perspective ... which side is which?

Would it then be correct to overly simply things by saying that the source and destination referred to in the NAT/Mangle etc. settings, are from the perspective of the point of origin (which ever side starts the conversation)? I guess you could say that but it is really overly simplified and thus b...
by vecernik87
Mon Feb 25, 2019 10:24 am
Forum: Beginner Basics
Topic: Meaning of Orig./Repl. in Firewall Connections
Replies: 2
Views: 522

Re: Meaning of Orig./Repl. in Firewall Connections

https://wiki.mikrotik.com/wiki/Manual:I ... Properties
there is full list of all properties including description.
by vecernik87
Mon Feb 25, 2019 10:06 am
Forum: RouterBOARD hardware
Topic: How much bandwidth can be controlled using RB750GR3?
Replies: 6
Views: 1106

Re: How much bandwidth can be controlled using RB750GR3?

@chechito I am pretty confident he should achieve more unless he stuffs up. I simulated it on RB951G(1*600MHz) instead of RB750Gr3 (2*880MHz) and I reached continuous 100Mbps with TCP iPerf. To be precise, the config was similar as the one you described (basic NAT and firewall, software bridge, no f...
by vecernik87
Mon Feb 25, 2019 8:28 am
Forum: General
Topic: Cambium L2GRE with Mikrotik Problem
Replies: 5
Views: 691

Re: Cambium L2GRE with Mikrotik Problem

UPDATE1: -Cambium said L2GRE in Mikrotik is not open standard. They only test L2GRE with Cisco and Linux I said that long time ago :D Anyway, they are right: Firstly, there is no L2GRE in RouterOS. Secondly, most similar are EoIP and old plain GRE, both are different and incompatible with L2GRE.
by vecernik87
Mon Feb 25, 2019 5:49 am
Forum: Beginner Basics
Topic: Routing terms perspective ... which side is which?
Replies: 8
Views: 741

Re: Routing terms perspective ... which side is which?

It is the side that started the connection. Thats true only for conntrack. (proof: on computer 1.1.1.1 I will write: "ping 2.2.2.2". If you capture such packets you will see ICMP packet ECHO_REQUEST with SRC_IP 1.1.1.1 and DST_IP 2.2.2.2 and after that there will be second ICMP packet, this time EC...
by vecernik87
Mon Feb 25, 2019 4:19 am
Forum: RouterBOARD hardware
Topic: How much bandwidth can be controlled using RB750GR3?
Replies: 6
Views: 1106

Re: How much bandwidth can be controlled using RB750GR3?

Maximum bandwidth which RB750Gr3 can handle is 1,972.2 Mbps (for details see https://mikrotik.com/product/RB750Gr3#fndtn-testresults ) That is the simple and exact answer to your question. That is the number, which should be compared with any other manufacturers or models. However, in reality you ca...
by vecernik87
Sat Feb 23, 2019 12:18 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

It was fixed before Tenable made the issue public. MikroTik and Tenable gave users time to upgrade before making any announcements. The first sentence is irrelevant truth and the second one is like a slap in everyone's face. - Users were given just 10 days (respectively 14 days for stable branch) w...
by vecernik87
Fri Feb 22, 2019 5:35 am
Forum: General
Topic: CVE-2019–3924 (firewall nat bypass)
Replies: 1
Views: 471

Re: CVE-2019–3924 (firewall nat bypass)

already done. Just not properly described.
viewtopic.php?f=2&t=145600#p716522
by vecernik87
Fri Feb 22, 2019 5:28 am
Forum: General
Topic: Cambium L2GRE with Mikrotik Problem
Replies: 5
Views: 691

Re: Cambium L2GRE with Mikrotik Problem

Mikrotik suports GRE and EoIP. Technically, EoIP is very similar to L2GRE but its not same. EoIP also supports L2 and is based originaly on GRE, but the protocol is proprietary and most likely there will be difference (I can't tell for sure because L2GRE is also poprietary protocol) Same way, GRE is...
by vecernik87
Fri Feb 22, 2019 2:38 am
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

@msatter To me Tenable went public to soon. Absolutely agree, however, I wonder why would they do it... This is pure hypothesis : Maybe Tenable originally agreed to keep it secret for some period of time, but after they saw that the security fix was silently released as "improvement", they decided ...
by vecernik87
Thu Feb 21, 2019 11:14 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

@mkx: I don't think full detail disclosure is necessary. I even agree that it is not wise. (however that is what actually happened) All I ask, is having correct info in changelog which will at least give me info that it might be good to upgrade the router for security reasons. Given current situatio...
by vecernik87
Thu Feb 21, 2019 8:35 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5962

Re: Security issue when Winbox exposed

@anav Until then, all this rhetoric does is feed trolls --- don't become one ............... There is no troll feeding. @mrz admitted it was fixed so it is confirmed issue. (if there is not and issue, there wouldn't need to be a fix, right?) Page with CVE contains timeline which shows how fast it wa...
by vecernik87
Thu Feb 21, 2019 12:15 pm
Forum: General
Topic: Can't change username on ROS 6.43 [SOLVED]
Replies: 21
Views: 3841

Re: Can't change username on ROS 6.43 [SOLVED]

I think maybe I didn't state this entirely clearly.
Ohh! now it makes way more sense! :D thanks heaps for this clarification! you really deserve cookies (or internetz or kudos or whatever currency you like)!
by vecernik87
Thu Feb 21, 2019 12:06 pm
Forum: General
Topic: Unauthorized access to MikroTiK
Replies: 20
Views: 2718

Re: Unauthorized access to MikroTiK

There was a version 6.42.5
vs
It is confirmed that this was another case of hacked router due to a insecure firewall configuration in combination with old RouterOS version


these two statements seems mutually exclusive.. how is that possible?
by vecernik87
Thu Feb 21, 2019 6:28 am
Forum: General
Topic: Problem with DHCP Mikrotik RB962UIGS-5HACT2HNT
Replies: 11
Views: 607

Re: Problem with DHCP Mikrotik RB962UIGS-5HACT2HNT

Personally, I would just run the sniffer which will give all answers: /tool sniffer start interface=ether1-uplink port=68 and after some time (look at logs and wait until you lose and reacquire your IP few times) /tool sniffer save file-name=dhcp.pcap /tool sniffer stop In the file, there will be DH...
by vecernik87
Wed Feb 20, 2019 11:47 am
Forum: Scripting
Topic: power cycle ping ip address [SOLVED]
Replies: 3
Views: 443

Re: power cycle ping ip address [SOLVED]

"print" is just a list of entries. To get a full config, you need to use an "export" command:
/interface ethernet export
or
/interface ethernet poe export
(I don't have RB with poe available right now so I can't check which one is it)
by vecernik87
Wed Feb 20, 2019 8:32 am
Forum: Scripting
Topic: How do you negate a command?
Replies: 1
Views: 228

Re: How do you negate a command?

/caps conf unset [find where name="somethingsomething"] datapath.local-forwarding
by vecernik87
Wed Feb 20, 2019 8:09 am
Forum: General
Topic: Unable to print oid for Queue Tree
Replies: 13
Views: 1105

Re: Unable to print oid for Queue Tree

that is just syntax error: There is no "interface" parameter for simple queues. You can easily list all available parameters with "TAB" key: [admin@mikrotik] > /queue simple add {[PRESSED TAB KEY]} bucket-size burst-threshold comment disabled limit-at name parent priority time target burst-limit bur...
by vecernik87
Wed Feb 20, 2019 2:21 am
Forum: Beginner Basics
Topic: Using MikroTik hAP as simple switch plus wireless AP
Replies: 36
Views: 12655

Re: Using MikroTik hAP as simple switch plus wireless AP

@ukracer : Well, this config is clearly default one. I wrongly assumed that you did the config reset with "no-defaults" as mentioned in the original text which you quoted: This can be easaly done by resetting the device with no default configuration: viewtopic.php?t=71522 If you start with some con...
by vecernik87
Tue Feb 19, 2019 11:53 pm
Forum: General
Topic: How to allocate one ONT to two different routers
Replies: 6
Views: 599

Re: How to allocate one ONT to two different routers

@olivier2831: there is nice summary about the bypass function with pictures: https://forum.mikrotik.com/viewtopic.php?t=106092 It even mentions how the user applied bypass, to achieve WAN redundancy - I assume that is very similar to your case. Only single thing worth mentioning myself - if you get ...
by vecernik87
Tue Feb 19, 2019 10:24 am
Forum: General
Topic: redirect subdomain(NAT)
Replies: 11
Views: 1107

Re: redirect subdomain(NAT)

@sob: good point. I automatically expected he talks about HTTP because the domain is completely irrelevant in ICMP and most other protocols. @vklpt: Nope. Layer7 communication starts AFTER the L4 is established. And NAT has to occur on first packet of connection. Even the definition of L7 matcher di...
by vecernik87
Tue Feb 19, 2019 10:09 am
Forum: Beginner Basics
Topic: Using MikroTik hAP as simple switch plus wireless AP
Replies: 36
Views: 12655

Re: Using MikroTik hAP as simple switch plus wireless AP

True :( Unfortunately the "Home AP" or "Home AP dual" is not just pure AP but router+AP. This seems to be solved in the "WISP AP" which offers choice between "router" and "bridge" mode (and really adds everything into one bridge) Unfortunately it offers only 5G wifi config within quickset, so user h...
by vecernik87
Tue Feb 19, 2019 5:57 am
Forum: General
Topic: Can't change username on ROS 6.43 [SOLVED]
Replies: 21
Views: 3841

Re: Can't change username on ROS 6.43 [SOLVED]

@macsrwe: gosh! I didnt know :( i wrongly assumed that any inner instance of curly brackets will inherit all variables from outside.
Thanks for pointing that out. I didn't really want to use "global" variable to avoid messing with rest of system, but I guess there is not much choice, is there?
by vecernik87
Tue Feb 19, 2019 12:10 am
Forum: RouterBOARD hardware
Topic: RB4011 twin-tray 1U
Replies: 7
Views: 969

Re: RB4011 twin-tray 1U

board looks way smaller than the case: http://km.mk/1533335167_12_mikrotik_rb4011_interbal_view.png From the picture it seems like 215mm, which means you can easily put two boards into one case, next to each other and it will nicely fit! If you believe there is such market potential (which I politel...
by vecernik87
Mon Feb 18, 2019 11:15 pm
Forum: General
Topic: redirect subdomain(NAT)
Replies: 11
Views: 1107

Re: redirect subdomain(NAT)

Not possible on router due to the way how TCP connection works: When the TCP connection is being established, there is not a single mention of domain/subdomain. So during that, router can't decide, whether it should redirect it or not. Once TCP connection is up and running, client sends HTTP request...
by vecernik87
Mon Feb 18, 2019 11:05 pm
Forum: Beginner Basics
Topic: Using MikroTik hAP as simple switch plus wireless AP
Replies: 36
Views: 12655

Re: Using MikroTik hAP as simple switch plus wireless AP

It is actually not that hard, as it may look. Basic knowledge of network is recommended. (I thought there is some basic manual on wiki but I couldn't find one... I assume you are asking for such simple questions that nobody ever thought to write it up...) Create Bridge - well, this literary says wha...
by vecernik87
Mon Feb 18, 2019 2:40 pm
Forum: General
Topic: WireGuard Released !
Replies: 9
Views: 4011

Re: WireGuard Released !

I knew it! It will happen!
... and then the rest of bugs I mentioned plzzzz
by vecernik87
Mon Feb 18, 2019 1:20 pm
Forum: General
Topic: WireGuard Released !
Replies: 9
Views: 4011

Re: WireGuard Released !

That's not true! I personally used MikroTik's OpenVPN over UTP... ... at least Cat 5E and Cat6, also S/FTP and possibly others, various 802.11something, even 10BASE2 coax, I think. And yes, I know it's childish joke. :) You owe me 15 minutes of my life! :D I was looking for post from Normis where h...
by vecernik87
Mon Feb 18, 2019 12:55 pm
Forum: General
Topic: Firewall on Mikrotik box outbound connection?
Replies: 9
Views: 655

Re: Firewall on Mikrotik box outbound connection?

I checked it (hey, I practically memorized the whole thing) but dismissed it because it says "This is a workaround that allows to set-up policy routing in mangle chain output". If it is just a workaround, I guess it won't do proper routing decision. I mean - why would they run the same code twice, r...
by vecernik87
Mon Feb 18, 2019 11:37 am
Forum: General
Topic: don't have ping but see the IP on scan?
Replies: 4
Views: 443

Re: don't have ping but see the IP on scan?

IP scan does firstly ARP requests which are usually not blocked because that would deny a bit whole purpose of the network. I am sure if you do ARP ping, it will get replies as well, while normal ping won't. Personally, I am pretty confident this is usual Windows firewall issue - When you connected ...
by vecernik87
Mon Feb 18, 2019 10:54 am
Forum: General
Topic: Unable to print oid for Queue Tree
Replies: 13
Views: 1105

Re: Unable to print oid for Queue Tree

That would make sense. Unless you define the queue (simple or tree) yourself, there won't be any. Personally, I had to always create it from scratch to suit my needs, and as far as I know, there are no predefined/defconf queues. However, even without queues, you can kind-of guess what OID will be us...
by vecernik87
Mon Feb 18, 2019 9:38 am
Forum: General
Topic: Unable to print oid for Queue Tree
Replies: 13
Views: 1105

Re: Unable to print oid for Queue Tree

FIY, I tried to replicate it and there is following result: 6.42.7 - /queue simple print oid works 6.43.2 - /queue simple print oid works 6.43.8 - /queue simple print oid works 6.44beta61 - /queue simple print oid works All of them have practically same output which looks fine: [admin@mikrotik] > /q...
by vecernik87
Mon Feb 18, 2019 9:10 am
Forum: General
Topic: WireGuard Released !
Replies: 9
Views: 4011

Re: WireGuard Released !

quoting OP: All platform released that !!!!! vs quoting article which OP linked: But sadly on the Linux front, the kernel bits still have yet to be mainlined. Windows client is still on its way but is taking a while due to writing a new TUN driver for Windows 7 and newer. lets summarize it: Specs ar...
by vecernik87
Mon Feb 18, 2019 7:56 am
Forum: General
Topic: Firewall on Mikrotik box outbound connection?
Replies: 9
Views: 655

Re: Firewall on Mikrotik box outbound connection?

I see.. so whole magic is, that iptables allow DST-NAT/REDIRECT action in OUTPUT chain which is apparently missing in RouterOS. I must admit that it sounds useful. Unfortunately, according to RouterOS' packet-flow diagram , OUTPUT chain happens straight before POSTROUTING, therefore after routing de...
by vecernik87
Mon Feb 18, 2019 4:18 am
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1027

Re: 3rd party LTE modems known working?

https://wiki.mikrotik.com/wiki/Manual:Peripherals The MC7455 is not mentioned but there are other models (7430, 73xx, 7710 ...), which suggest there is possibility that 7455 will work as well, either as LTE interface or at least as PPP Similarly LM940 is not mentioned but LE910 is. Despite the fact ...
by vecernik87
Mon Feb 18, 2019 12:14 am
Forum: Announcements
Topic: v6.44rc [testing] is released!
Replies: 67
Views: 12494

Re: v6.44rc [testing] is released!

@heizer ... when will this new function be available? [i mean, out of beta]... its a bit OT, but since more people might be interested... It is not that significant improvement as it may seem. It works as an envelope command to usual ping and btest. These commands runs on background and speedtest ju...
by vecernik87
Sat Feb 16, 2019 3:49 am
Forum: General
Topic: Config Review - Security Conscience Home User
Replies: 19
Views: 1284

Re: Config Review - Security Conscience Home User

I think it is more about the particular way of thinking, instead of how is it implemented: We assume that port scanners are bad, so we try hard to detect them and block them. Now, My way of thinking is this: if you don't have ports open (which you shouldn't have), why would you care about open ports...
by vecernik87
Sat Feb 16, 2019 3:01 am
Forum: RouterBOARD hardware
Topic: Why people pair UBNT APs with MikroTik routers?
Replies: 55
Views: 29928

Re: Why people pair UBNT APs with MikroTik routers?

@mkx: Interesting! similar happened to me when I tried to limit bandwidth to one particular port via switch menu! Whole unit was disconnecting on regular basis.. I guess the switch in RBD52G is not that good after all
by vecernik87
Fri Feb 15, 2019 9:21 am
Forum: General
Topic: Config Review - Security Conscience Home User
Replies: 19
Views: 1284

Re: Config Review - Security Conscience Home User

using RAW for this kind of drops is very dangerous. keep in mind that attacker with spoofed address can easily add to the list important addresses like 8.8.8.8 or 1.1.1.1 And due to the fact it is in prerouting, it happens before connection tracking and therefore even connections initiated from your...
by vecernik87
Fri Feb 15, 2019 8:33 am
Forum: Virtualization
Topic: PCI passthrough and USB passthrough not working [SOLVED]
Replies: 5
Views: 876

Re: PCI passthrough and USB passthrough not working [SOLVED]

I thought that whole idea of CHR was to get rid of driver issues and implement only basic drivers for virtual interfaces...
(I mean thats why the original idea of x86 architecture is not recommended anymore)
by vecernik87
Fri Feb 15, 2019 6:59 am
Forum: General
Topic: Hardware for 6000 concurrent users
Replies: 9
Views: 781

Re: Hardware for 6000 concurrent users

I assume if managers/owners want to block something, it will be competition websites. Not porn :lol:
I mean... can you imagine hotel blocking porn? They would be doomed to bankrupcy from their very first day
by vecernik87
Fri Feb 15, 2019 2:29 am
Forum: General
Topic: Can't change username on ROS 6.43 [SOLVED]
Replies: 21
Views: 3841

Re: Can't change username on ROS 6.43 [SOLVED]

@anav: this pony can kick really hard :lol: @mascrwe: good point! thank you. I actually haven't think this way and it might bite me in the ass later. fixed: /user group add name=temppolicy :local defpolicy [:tostr [/user group get temppolicy value-name=policy]] :local fullpolicy :for i from=0 to=([:...
by vecernik87
Fri Feb 15, 2019 1:05 am
Forum: General
Topic: Hardware for 6000 concurrent users
Replies: 9
Views: 781

Re: Hardware for 6000 concurrent users

@Anav is right - there is no buildin HA solution which would take care of everything. VRRP is good example of standartized HA functionality, but it takes care only of IP addresses. It does not sync config etc.. It is possible, to some extent, do almost full-blown HA by yourself with scripts which wi...
by vecernik87
Thu Feb 14, 2019 1:33 pm
Forum: RouterBOARD hardware
Topic: Why people pair UBNT APs with MikroTik routers?
Replies: 55
Views: 29928

Re: Why people pair UBNT APs with MikroTik routers?

Mikrotik employees many times stated that they are not using built-in kernel module for TILE architecture. Instead, they are using their own module developed in cooperation with manufacturer of those CPU. Dropping TILE support from new kernel is not relevant to RouterOS.
by vecernik87
Thu Feb 14, 2019 8:29 am
Forum: General
Topic: Can't change username on ROS 6.43 [SOLVED]
Replies: 21
Views: 3841

Re: Can't change username on ROS 6.43 [SOLVED]

And for those of us who have already been doing that for years with an initialization script, MikroTik has just made that even more difficult. :-( Not really. I implemented my init script this way before it was enforced: /user group set full name=full policy=local,telnet,ssh,ftp,reboot,read,write,p...
by vecernik87
Thu Feb 14, 2019 7:53 am
Forum: General
Topic: Guide to (possibly) hack RouterOS ... If yes please protect it
Replies: 10
Views: 1006

Re: Guide to (possibly) hack RouterOS ... If yes please protect it

gosh.. again.. https://forum.mikrotik.com/viewtopic.php?f=2&t=145278&p=714963#p714963 https://forum.mikrotik.com/viewtopic.php?f=2&t=145272&p=714906#p714906 We should start betting how many duplicates are gonna appear in upcoming month. And all that because of someone showing how to hack YOUR OWN ro...
by vecernik87
Thu Feb 14, 2019 4:57 am
Forum: Wireless Networking
Topic: Help Hacker sending deauth packet
Replies: 6
Views: 793

Re: Help Hacker sending deauth packet

I guess you are looking for this: https://wiki.mikrotik.com/wiki/Manual:Interface/Wireless#Management_frame_protection However, I am not certain whether it will help since it is proprietary algorithm and is supported only by RouterOS devices. (To work, it must be supported by both AP and Client) Unf...
by vecernik87
Thu Feb 14, 2019 4:33 am
Forum: General
Topic: ERROR: bad HTTP response while trying to update
Replies: 5
Views: 857

Re: ERROR: bad HTTP response while trying to update

"Bad http response" sounds weird. It is like ROS received unexpected reply. Fortunately, this can be debugged very easily with packet sniffer. If you don't want to dig into that, you can just download the package manually: http://upgrade.mikrotik.com/routeros/6.43.12/routeros-x86-6.43.12.npk or stra...
by vecernik87
Thu Feb 14, 2019 3:43 am
Forum: Beginner Basics
Topic: ROMON Troubleshooting [SOLVED]
Replies: 3
Views: 407

Re: ROMON Troubleshooting [SOLVED]

That is true. ROMON frames are not forwarded by UNIFI. In terms of your magical "-200% packet loss" i have really simple explanation: You are pinging MAC address. Since you did not specify which interface you want to transmit, it will transmit on ALL interfaces. including bridged ethernets or vlans....
by vecernik87
Thu Feb 14, 2019 1:06 am
Forum: Wireless Networking
Topic: How to measure WiFi coverage with a Mac or Windows notebook? [SOLVED]
Replies: 5
Views: 491

Re: How to measure WiFi coverage with a Mac or Windows notebook? [SOLVED]

Did you at least have a look at the site? There is a link to free "lite" version: https://www.metageek.com/products/inssider/free/ If you want to see history of channel strength but don't want to pay, you can also go for old "home" version which was also free in the past and can be still downloaded ...
by vecernik87
Thu Feb 14, 2019 12:24 am
Forum: The Dude
Topic: Dude v6 - Feature request list
Replies: 66
Views: 18081

Re: Dude v6 - Feature request list

* Multiple connections between two devices, why is it limited to one? For example, how to monitor multiple physical etherchannel connections? @Masyanich I have solved this by using "static" element(s) between two devices. That way I can do non-straight lines as well as multiple lines between two de...
by vecernik87
Wed Feb 13, 2019 4:13 am
Forum: Beginner Basics
Topic: why we don't drop bogons address form input rules??
Replies: 3
Views: 551

Re: why we don't drop bogons address form input rules??

@sebastia: rp-filter=strict is not a defence against bogons coming from WAN because, you most likely have 0.0.0.0/0 route there, which will give a green light to any bogon.... @shujanster: we don't want to use drop everything in input. That isn't good approach and I would strongly recommend to recon...
by vecernik87
Tue Feb 12, 2019 2:18 pm
Forum: General
Topic: Tunnel which generates least traffic when IDLE
Replies: 13
Views: 1174

Re: Tunnel which generates least traffic when IDLE

here we go... :) So maybe, just maybe, the ISP is billing more than you really consume... can you find exact billing conditions? what is the smallest billing unit? If your packets are small and sporadic, while smallest billing unit is large enough, then each packet can be billed in separate unit whi...
by vecernik87
Tue Feb 12, 2019 10:02 am
Forum: General
Topic: System issues RB1100ahx4
Replies: 13
Views: 1591

Re: System issues RB1100ahx4

Another RB1100AHx4 rebooted tonight. ... I need comments from Mikrotik team what we need to do. I always get comment from their support. After crash, there is autosupout.rif file... all you need to do is send it to them and describe your situation. They will likely find the issue and either tell yo...
by vecernik87
Tue Feb 12, 2019 9:23 am
Forum: RouterBOARD hardware
Topic: Powerline with 1gbit
Replies: 10
Views: 1235

Re: Powerline with 1gbit

wow, I don't want to see the interference produced by 1Gbit flowing via non-twisted and non-shielded wiring...
How is it possible that these things even get certification? https://www.youtube.com/watch?v=kyYeTWHUnUk
by vecernik87
Tue Feb 12, 2019 9:14 am
Forum: RouterBOARD hardware
Topic: Mikrotik Poe Cascading
Replies: 6
Views: 672

Re: Mikrotik Poe Cascading

That sounds like usual hotel scenario for AP+Phone for each room with extra step... Are you sure that those "48 routers" are necessary? Are they gonna work only as PoE splitters and switches or will it really have some routing task? fiy - for example CAP ac can do poe-out (passive only!) so if your ...
by vecernik87
Tue Feb 12, 2019 8:34 am
Forum: General
Topic: DHCP Client brige l2tp tunnel [SOLVED]
Replies: 12
Views: 1390

Re: DHCP Client brige l2tp tunnel [SOLVED]

This is very long-shot guess but based on the comment in config, I understand your Ether2 might have something to do with VLAN .. can you confirm/deny whether Ether2 receives (and passes to the bridge) tagged frames? If there are VLAN tags involved, where do you add/strip tags? I think that might ch...
by vecernik87
Tue Feb 12, 2019 5:55 am
Forum: General
Topic: [Lost Interface] IP->Routes
Replies: 8
Views: 857

Re: [Lost Interface] IP->Routes

I knew the answer would eventually surface! I wrote it earlier but I guess bad words were chosen - I did not specifically mention how to create the static interface, despite the fact I had it in mind the whole time. Anyway, I am happy that it helped at least you :) hopefully @JordanR will confirm t...
by vecernik87
Tue Feb 12, 2019 12:14 am
Forum: General
Topic: [Lost Interface] IP->Routes
Replies: 8
Views: 857

Re: [Lost Interface] IP->Routes

I am more and more convinced that @JordanR and @Cvan are talking about dynamic interfaces. Not static ones which I earlier identified as most probable solution. In both cases (both dynamic and static), the interface is marked as as "PPTP/L2TP/SSTP Server Binding" so it may be not easy to understand,...
by vecernik87
Mon Feb 11, 2019 7:21 am
Forum: General
Topic: VPN PPTP ANDROID
Replies: 4
Views: 3595

Re: VPN PPTP ANDROID

Despite the fact PPTP is not recommended due to security reasons, sometime it is useful due to its simplicity. I tried to configure it and it works with my android phone (Xiaomi running Miui 9.5 which is based on Android 6.0.1) without any issue: /ip pool add name=pool-pptp ranges=192.168.101.10-192...
by vecernik87
Mon Feb 11, 2019 2:09 am
Forum: The Dude
Topic: The Dude IS Dead, really, isn't it?
Replies: 30
Views: 5558

Re: The Dude IS Dead, really, isn't it?

Something that big as open source? ... "that big" ?? Cmon, it is NOT that big. Server does not do anything else than scheduling and sending packets based on DB entries. Client does not do anything else than visualizing the DB. What I admire is the simple and configurable approach, which is missed b...
by vecernik87
Fri Feb 08, 2019 6:16 am
Forum: General
Topic: [Lost Interface] IP->Routes
Replies: 8
Views: 857

Re: [Lost Interface] IP->Routes

I assume we are talking about home site, where you assigned the route to dynamic interface (which gets created for every connected client), right? Anything assigned to particular dynamic interface will get broken with any reconnection of that VPN. There is a "L2TP server binding" interface which wil...
by vecernik87
Fri Feb 08, 2019 3:39 am
Forum: Beginner Basics
Topic: dhcp - dns problem
Replies: 7
Views: 692

Re: dhcp - dns problem

this is definitely wrong and must be fixed: /ip dns set allow-remote-requests=yes servers=192.168.88.1 Parameter "servers" in /ip dns is supposed to hold list of DHCP servers, where your mikrotik will send requests. This list is also passed to DHCP-clients, in case you didn't fill parameter "dns-se...
by vecernik87
Fri Feb 08, 2019 1:58 am
Forum: Wireless Networking
Topic: HELP with Nstreme
Replies: 2
Views: 332

Re: HELP with Nstreme

Can we get clarification of "stop pushing traffic" ? - device(s) shuts down? - devices are on but the link(s) fails? - devices are on, links are on but data are not transmitted? - devices are on, links are on, data are transmitted but nothing is received? - any other way to interpret your words? In ...
by vecernik87
Thu Feb 07, 2019 10:22 am
Forum: Wireless Networking
Topic: WiFi4EU
Replies: 8
Views: 1800

Re: WiFi4EU

Since there is absolutely no support of 802.11k in RouterOS, answer is pretty clear - Routerboards are not compliant.
by vecernik87
Thu Feb 07, 2019 10:04 am
Forum: Beginner Basics
Topic: Vlan Tag injecter
Replies: 5
Views: 357

Re: Vlan Tag injecter

the way presented above is quite simpler to set-up. @mkx: The way presented above is not recommended: https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration#VLAN_in_bridge_with_a_physical_interface Despite it is easier, vlan filtering on bridge will be safer. btw: isn't it weird that there a...
by vecernik87
Thu Feb 07, 2019 8:55 am
Forum: General
Topic: Use a Routerboard to tag packets for a management VLAN
Replies: 7
Views: 802

Re: Use a Routerboard to tag packets for a management VLAN

Laptop ---> Ether1 - Ether2 ----> Network In this scenario (Ether1/Ether2 being your bridge Mikrotik) you'd create a vlan interface on Ether2 with vlanID on 100, then create a bridge interface, and add Ether1 and Vlan100 interface, so you are being bridged straight into the VLAN tagged interface. T...
by vecernik87
Thu Feb 07, 2019 8:18 am
Forum: General
Topic: Mikrotik sending out rogue DHCP requests [SOLVED]
Replies: 11
Views: 1093

Re: Mikrotik sending out rogue DHCP requests [SOLVED]

Anything can be blocked with bridge-filter (including BPDU frames, neighbor discovery, MAC server etc...). All you need to do is put your WAN port as a single port into new bridge (obviously, make it non-STP) and hook all your firewall rules, dhcp-client and other things on the bridge, instead of Et...
by vecernik87
Thu Feb 07, 2019 6:44 am
Forum: General
Topic: Detect-internet causing internal packet loss
Replies: 10
Views: 1760

Re: Detect-internet causing internal packet loss

First thing I do on any router is disable "detect internet". (well, technically I always wipe whole config but hey... same thing, right?) It is another "clever yet limited black-box" function, similar as kid control, cloud, netwatch or hotspot - all these things can be scripted and scheduled relativ...
by vecernik87
Wed Feb 06, 2019 6:43 am
Forum: Scripting
Topic: HELP! My Static IP gets changes to Dynamic everyday automatically.
Replies: 10
Views: 853

Re: HELP! My Static IP gets changes to Dynamic everyday automatically.

If someone is changing your dhcp-server config, why do you think he will not change delete/disable the script as well?
Trying to fix the consequence is usually doomed to fail. Fixing the cause is way more important.
by vecernik87
Wed Feb 06, 2019 5:30 am
Forum: Scripting
Topic: HELP - Get name by addres-list from a name of user in ppp secret
Replies: 1
Views: 242

Re: HELP - Get name by addres-list from a name of user in ppp secret

Depends on what you want to do with the address list. one possible way is this: :foreach myuser in=[/ppp secret print as-value where name="YOUR_USERNAME"] do={:foreach myprofile in=[/ppp profile print as-value where name=($myuser->"profile")] do={:put ($myprofile->"address-list")}} But to be honest,...
by vecernik87
Wed Feb 06, 2019 5:06 am
Forum: Scripting
Topic: Why this script do not run?
Replies: 1
Views: 269

Re: Why this script do not run?

because arrays are bit messy and it is not easy to debug them: First thing to understand is, that result of /ppp secret print as-value where name="username" is actually an array of arrays. That is caused by the fact that the code can return multiple rows if there are multiple entries with same name....
by vecernik87
Wed Feb 06, 2019 1:32 am
Forum: General
Topic: Mikrotik sending out rogue DHCP requests [SOLVED]
Replies: 11
Views: 1093

Re: Mikrotik sending out rogue DHCP requests [SOLVED]

Good catch! I missed that one :)
Although it does not change the fact I don't see any unusual requests on a network with many mikrotiks. Not saying that there is no bug, it just seems unlikely.
by vecernik87
Wed Feb 06, 2019 12:53 am
Forum: Wireless Networking
Topic: Clarification needed---Superchannel
Replies: 5
Views: 1039

Re: Clarification needed---Superchannel

superchannel is a mode, not a frequency. Superchannel removes some restrictions and should be used ONLY in laboratory for testing. To be specific, Superchannel will allow you to use any frequency supported by your wifi chip/card, including licensed frequencies. (i.e. you will most likely break a law...