Community discussions

MUM Europe 2020

Search found 37 matches

by Solusan
Mon Mar 05, 2007 12:46 pm
Forum: General
Topic: MD5-CHAP | Radius Server
Replies: 2
Views: 2816

Well, Testing, Windows 2003 Server is only able to do login if the protocol is PAP, which is without encryption, and does not give much security. Is possible that Windows 2000 Server if it support? (MD5-CHAP). http://msdn.microsoft.com/library/default.asp?url=/library/en-us/randz/protocol/md5-chap.a...
by Solusan
Mon Mar 05, 2007 10:37 am
Forum: General
Topic: MD5-CHAP | Radius Server
Replies: 2
Views: 2816

Nobody? :) I get the issue in english. Event Type: Warning Event Source: IAS Event Category: None Event ID: 2 Date: 01/03/2007 Time: 12:06:15 User: N/A Computer: ESPRED01RD05 Description: User es46524944s was denied access. Fully-Qualified-User-Name = RADIUS\es42376944h NAS-IP-Address = 172.27.246.4...
by Solusan
Fri Mar 02, 2007 3:31 pm
Forum: General
Topic: MD5-CHAP | Radius Server
Replies: 2
Views: 2816

MD5-CHAP | Radius Server

Hi, I have followed the instructions of: http://forum.mikrotik.com/viewtopic.php?t=12180&highlight=mschap&sid=1169593719275f163bb59e397bcdd5ea But 2003 Server says me: Tipo de suceso: Advertencia Origen del suceso: IAS Categoría del suceso: Ninguno Id. suceso: 2 Fecha: 02/03/2007 Hora: 13:50...
by Solusan
Fri Feb 02, 2007 11:31 am
Forum: General
Topic: cannot make pings at my radius server
Replies: 4
Views: 818

Hmm, this is not quite right way to do masquerading. I would at least add outgoing interface to each NAT rule, but since these are all private networks, I would rather do routing instead of NAT-ing. How many network cards you have in this machine?
I have 3 networkcards.

How could it be?

txs.
by Solusan
Thu Feb 01, 2007 4:35 pm
Forum: General
Topic: cannot make pings at my radius server
Replies: 4
Views: 818

cannot make pings at my radius server

Hi, I'm following this tutorial: http://wiki.mikrotik.com/wiki/How_to_setup_up_RADIUS_for_use_with_MikroTik_-_By_Ramona But ... i can't make ping at my radius server, i'ts strange cause I have this NAT rules: [admin@MikroTik] ip firewall nat> print Flags: X - disabled, I - invalid, D - dynamic 0 cha...
by Solusan
Thu Feb 01, 2007 11:09 am
Forum: General
Topic: Simple question (PHP)
Replies: 12
Views: 1591

you can whatever you want with the login page .. just leave the username and password fields as it is or in another place and you can add anything you want.
very many thanks.

:)
by Solusan
Wed Jan 31, 2007 10:58 am
Forum: General
Topic: Simple question (PHP)
Replies: 12
Views: 1591

by the way

Can you helpme with this post?

http://forum.mikrotik.com/viewtopic.php ... highlight=


I'm little bit desperate.... :'(

txs.
by Solusan
Wed Jan 31, 2007 10:55 am
Forum: General
Topic: Simple question (PHP)
Replies: 12
Views: 1591

inside hotspot login pages you can only use html and javasctipt. basically you are limited to just editing the provided files.
ooookay txs!!!
by Solusan
Wed Jan 31, 2007 10:45 am
Forum: General
Topic: Simple question (PHP)
Replies: 12
Views: 1591

no, inside mikrotik you cannot store any html,xhtml,php,java,javascript,css,txt or any other files that you want to be displayed on it's webpage. please explain what would like to do, so that i can give a better answer. RouterOS is not a webserver of any kind. oh, sorry, I mean: Inside hotspot file...
by Solusan
Wed Jan 31, 2007 10:24 am
Forum: General
Topic: Simple question (PHP)
Replies: 12
Views: 1591

umm, no! you can't put your own webpages on the router
I see, but.... inside mikrotik i cannot make php pages, just javascript & html.

Is it?

txs
by Solusan
Tue Jan 30, 2007 4:56 pm
Forum: General
Topic: Simple question (PHP)
Replies: 12
Views: 1591

Re: Simple question (PHP)

Does Mikrotik support PHP (hotspot).
On the router itself? No.

--Tom
Just HTML & Javascript?

txs
by Solusan
Tue Jan 30, 2007 3:09 pm
Forum: General
Topic: Simple question (PHP)
Replies: 12
Views: 1591

Simple question (PHP)

Hi,

Does Mikrotik support PHP (hotspot).

Thanks.
by Solusan
Tue Jan 30, 2007 12:55 pm
Forum: General
Topic: Transparent proxy
Replies: 5
Views: 6935

Hi, Talking abut this topic i have a question: I have this configuration in mi Mikrotik system. Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set for 'guest' user profile, 'ip hotspot user profile set profile_name incoming-filter=1 outgoing-fi...
by Solusan
Tue Jan 30, 2007 10:31 am
Forum: General
Topic: Trying to understand destination NAT
Replies: 0
Views: 611

Trying to understand destination NAT

Hi, i have this configuration in mi Mikrotik system. Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set for 'guest' user profile, 'ip hotspot user profile set profile_name incoming-filter=1 outgoing-filter=1', that will redirect current profile...
by Solusan
Mon Jan 29, 2007 5:38 pm
Forum: Scripting
Topic: do I need a script for this?
Replies: 0
Views: 1100

do I need a script for this?

Hi, i have this configuration in mi Mikrotik system. Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set for 'guest' user profile, 'ip hotspot user profile set profile_name incoming-filter=1 outgoing-filter=1', that will redirect current profile...
by Solusan
Mon Jan 29, 2007 10:22 am
Forum: Scripting
Topic: how to run Nighty firewall
Replies: 7
Views: 2776

Well I'll try to explain better: I did this: Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set for 'guest' user profile, 'ip hotspot user profile set profile_name incoming-filter=1 outgoing-filter=1', that will redirect current profile traffoc...
by Solusan
Mon Jan 29, 2007 10:17 am
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Well: I'll try to expliain better: I did this: Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set for 'guest' user profile, 'ip hotspot user profile set profile_name incoming-filter=1 outgoing-filter=1', that will redirect current profile traff...
by Solusan
Mon Jan 29, 2007 10:16 am
Forum: The User Manager
Topic: Problem NAT an user
Replies: 1
Views: 1234

Well i try to explain better: I did this: Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set for 'guest' user profile, 'ip hotspot user profile set profile_name incoming-filter=1 outgoing-filter=1', that will redirect current profile traffoc to...
by Solusan
Sun Jan 28, 2007 11:25 pm
Forum: General
Topic: dst-nat question
Replies: 11
Views: 1644

Can you describe exactly what you are trying to accomplish? Are you trying to access 192.168.0.1 from the internet using public IP 66.94.234.13? Hi, I have a question about this: I did this: Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set f...
by Solusan
Fri Jan 26, 2007 2:41 pm
Forum: The User Manager
Topic: Problem NAT an user
Replies: 1
Views: 1234

Problem NAT an user

Hi,

I have a problem.

I'd need restrict an user (guest) to a certain rank ip 172.0.0.0/8

I get it, but the user geta a 'drop' if he try to access.

I'd need to redirect at: 192.168.1.1

This is the post related:


http://forum.mikrotik.com/viewtopic.php?t=13487

very many thanks.
by Solusan
Fri Jan 26, 2007 2:11 pm
Forum: General
Topic: dst-nat question
Replies: 11
Views: 1644

Hi...


I have a little proble with NAT.

The post is in:

http://forum.mikrotik.com/viewtopic.php?p=62693#62693


I'm a little bit desperate.....


very many thanks.
by Solusan
Fri Jan 26, 2007 1:48 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

I am not having much luck with the tests that I am doing.

Any idea about, this?

Many very thanks.
by Solusan
Fri Jan 26, 2007 12:55 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

I tried this:
 chain=dstnat src-address=178.0.0.0/8 hotspot=to-client action=dst-nat to-addresses=192.168.1.1 to-ports=0-65535 
It's correct?
by Solusan
Fri Jan 26, 2007 12:34 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Who is user guest ? 1) Clients who do not have HotSpot login/password, they will get HotSpot page instead of internet access. 2) Specific client is using 'guest' login, then you can specify particular dst-address in the following rule. The called user 'guest' is that one that will not be able to ac...
by Solusan
Fri Jan 26, 2007 12:11 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Yes, it can be done by NAT, e.g. to redirect user with address=1.1.1.1 to web-page with address=2.2.2.2, 'ip firewall nat add action=dstnat dst-address=1.1.1.1 action=dst-nat to-addresses=2.2.2.2' Then for my it would be: ip firewall nat add action=dstnat dst-address=172.0.0.0/8 action=dst-nat to-a...
by Solusan
Fri Jan 26, 2007 10:20 am
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Can it be with the NAT menu?

I'm triying....
by Solusan
Thu Jan 25, 2007 7:36 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

great!!! it works!!!!


I'd need one more a functionality:

If 'geust' try to access at 172.0.0.0 /8 then, he must be returned at advertise URL that must to say 'You Don't have permission' or somethig like this.

Can it be ?

thanks a lot!
by Solusan
Thu Jan 25, 2007 6:30 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Add one rule to chain=forward, 'ip firewall filter add action=jump jump-target=hotspot chain=forward', set for 'guest' user profile, 'ip hotspot user profile set profile_name incoming-filter=1 outgoing-filter=1', that will redirect current profile traffoc to chain=1. Add rule to chain 1 to drop tra...
by Solusan
Thu Jan 25, 2007 5:43 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Do you want to block unauthorized users to get displayed HotSpot login page ? No, I just want to block the 172.0.0.0/8 network to those users who are called 'guest' (or logged as 'guest') I didi try this.... without no positive result :'( [admin@MikroTik] ip firewall filter> print Flags: X - disabl...
by Solusan
Thu Jan 25, 2007 5:27 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

I mean:

I have 2 kind of users in the hotspot:

admin (they can browse all)

guest --> this user must not browse by 172.0.0.0/8

:)
by Solusan
Thu Jan 25, 2007 4:48 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

If you want to drop 172.0.0.0/8 network for all users or for the specific users, use simple rule, 'ip firewall filter add chain=forward dst-address=172.0.0.0/8 action=drop'. Specify src-address, if you need to block access for the specific users. As well self created chain does accept any traffic u...
by Solusan
Thu Jan 25, 2007 2:25 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Well ... I put: [admin@MikroTik] ip firewall filter> print Flags: X - disabled, I - invalid, D - dynamic 0 chain=no_172 in-interface=LAN src-address=192.168.0.0/16 dst-address=!172.0.0.0/8 protocol=tcp connection-state=new hotspot=auth action=return but, doesen't works. Can anybody help me pplase?
by Solusan
Thu Jan 25, 2007 12:14 pm
Forum: Scripting
Topic: how to run Nighty firewall
Replies: 7
Views: 2776

Hello,

Sorry by the invonvenience, but i have a little desperate.

I'd need to make filter for a user that could not enter in 172.0.0.0/8 networks.

This is the post related:

http://forum.mikrotik.com/viewtopic.php?t=13487

Txs a lot.
by Solusan
Thu Jan 25, 2007 11:51 am
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Any idea... it's little bit urgent..... txs a lot.
by Solusan
Wed Jan 24, 2007 7:13 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

I think that i can do that


I think that t I can do this, making a filter rules by firewall, and putting them in:

IP hotspot profile>

, how must be the rule?

thanks a lot.
by Solusan
Wed Jan 24, 2007 5:34 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

could you be more specific what is your needs, what you already achieved, what needs to be accessed and what has to be denied? before nothing, very many thanks to answer:). I explain to you: In my case, hotspot I need to discriminate between corporative users and normal user (invited or host), the ...
by Solusan
Wed Jan 24, 2007 1:58 pm
Forum: General
Topic: Trying not to let pass to an user group to certain network
Replies: 21
Views: 4416

Trying not to let pass to an user group to certain network

Hello, I have a small problem, would like to be able to deny the access to all type of user wishes to enter to enter at 172.0.0.0 rank, but that could access to all the other resources. I have tried to form the guest profile, but I do not see it very clear. :shock: Somebody can help me? From already...