Community discussions

Search found 26 matches

by icsterm
Thu Aug 01, 2019 4:05 pm
Forum: General
Topic: DHCP error message [SOLVED]
Replies: 4
Views: 266

Re: DHCP error message [SOLVED]

Indeed, I was too lazy removing the dhcp client config. I only use static WAN ip addresses.
Thx a lot !
by icsterm
Thu Aug 01, 2019 3:58 pm
Forum: General
Topic: DHCP error message [SOLVED]
Replies: 4
Views: 266

Re: DHCP error message [SOLVED]

I actually have the dhcp server on the bridge, which has all ethernet ports included in it (except sfp-plus). [admin@MikroTik] > /ip dhcp-server print detail Flags: D - dynamic, X - disabled, I - invalid 0 name="dhcp" interface=bridge lease-time=7h address-pool=default-dhcp bootp-support=dynamic boo...
by icsterm
Thu Aug 01, 2019 3:53 pm
Forum: General
Topic: DHCP error message [SOLVED]
Replies: 4
Views: 266

DHCP error message [SOLVED]

Hi,

How can I fix this DHCP error message?


"dhcp, error temporary moving client ether1 from slave to master port, update your config !!!"

Running v6.44.5 long-term on a RB4011, other than having dhcp server on the bridge interface directly, I can't figure out what is the problem.
by icsterm
Sat Feb 09, 2019 6:42 pm
Forum: Scripting
Topic: If e-mail is sent, true/false variable
Replies: 1
Views: 247

If e-mail is sent, true/false variable

Hello, Can someone cook me a quick script that does the following: If "/tool e-mail send to=me@me.com body="$strName Logs for $strDate" subject="$strName Logs for $strDate $strTime" file=log" is sent successfully, then do: /file remove log log info message="Logs successfully sent via e-mail!" else l...
by icsterm
Fri Feb 08, 2019 11:20 am
Forum: General
Topic: Allow tracert to work, without ICMP hole in firewall?
Replies: 4
Views: 1911

Re: Allow tracert to work, without ICMP hole in firewall?

For anyone wondering, creating input rules for both echo reply and time exceeded allow both ping and traceroute to work fine, while ping and traceroute from internet will be denied.
This is strictly for traffic originating from the router itself.
by icsterm
Thu Jan 24, 2019 3:26 pm
Forum: General
Topic: Srcnat and WAN fallover
Replies: 2
Views: 260

Re: Srcnat and WAN fallover

Judging by how many src-nat rules I use for WAN1 (I have 29 ip interfaces for the /27 provided by the WAN1 ISP), the check-gateway option on routes is not a solution. Checking the Mikrotik wiki I came around Netwatch which can run scripts when a target host is up/down. I will use that to swap around...
by icsterm
Thu Jan 24, 2019 2:30 pm
Forum: General
Topic: Srcnat and WAN fallover
Replies: 2
Views: 260

Srcnat and WAN fallover

I have an RB4011, 2 WAN connections and one private subnet which gets NATed for internet access. WAN1 has a /27 range alocated from ISP, while the secondary WAN2 is mainly for backup, just one IP. WAN1 uses srcnat 'one-to-one' NAT: add action=src-nat chain=srcnat comment="NAT" src-address=192.168.1....
by icsterm
Thu Nov 15, 2018 12:15 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2025

Re: IP Neighbor Discovery

Just filter out UDP broadcast packets with destination 255.255.255.255 & port 5678 on the devices you don't want taking part in MNDP.
by icsterm
Fri Aug 24, 2018 12:26 am
Forum: General
Topic: hAP ac² bridge graphing not working properly
Replies: 3
Views: 474

Re: hAP ac² bridge graphing not working properly

Still, no one?
by icsterm
Tue Aug 21, 2018 10:14 am
Forum: General
Topic: hAP ac² bridge graphing not working properly
Replies: 3
Views: 474

Re: hAP ac² bridge graphing not working properly

No one has ever activated graphs on the bridge on this board??
by icsterm
Mon Aug 20, 2018 6:50 pm
Forum: General
Topic: hAP ac² bridge graphing not working properly
Replies: 3
Views: 474

hAP ac² bridge graphing not working properly

Hi, Is there any limitation in ROS graphing with hAP ac²(ARM) devices? I'm running v6.42.7 ROS version on all my MKT devices. I have one hAP ac² with fastpath+fastforward enabled on a single bridge, all interfaces in the same bridge, and the bridge graph shows less(or almost none at all) traffic tha...
by icsterm
Tue Jun 19, 2018 8:52 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 15851

Re: v6.42.4 [current]

Just script it just be the new Mikrotik slogan :)
by icsterm
Tue Jun 19, 2018 6:14 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 15851

Re: v6.42.4 [current]

It's tested & working just fine on 2 ROS devices I own. It's not my script but I find it usefull. The only bootloop possible is one caused by the new bootloader not being properly written. Which didn't happen to me on 30-40 RC updates. If bootloop happens, just netinstall the router again and make s...
by icsterm
Tue Jun 19, 2018 5:58 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 15851

Re: v6.42.4 [current]

Can anybody make me a solution / script so after the ROS upgrade the unit either in the same reboot, or thereafter reboots again to update the fw version? Now each and every unit has to be rebooted twice. which is a pain if you have to do big amounts.... here you go :log info "Checking firmware..."...
by icsterm
Sat May 26, 2018 4:27 pm
Forum: General
Topic: Search inside the log
Replies: 7
Views: 4593

Re: Search inside the log

This feature is such a pain in the ass, if it's not available under winbox maybe it's available under CLI?
Does anyone know a log filter command?
by icsterm
Wed Apr 25, 2018 11:45 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 43464

Re: v6.42.1 [current]

RouterOS version 6.42.1 has been released in public "current" channel!

*) led - added "dark-mode" functionality for hAP ac and hAP ac^2 devices;

Still can't turn off the port led indicators in the hap ac2, winbox returns error that the board doesn't have this functionality.
by icsterm
Fri Apr 20, 2018 10:11 pm
Forum: RouterBOARD hardware
Topic: HAP ac2 vs rb750gr3 cpu power
Replies: 3
Views: 2608

Re: HAP ac2 vs rb750gr3 cpu power

i have both, the hap ac2 is faster by a substantial amount.
on a 1gbit pppoe link, the rb750gr3 loads the cpu at max ~50% while the hap ac2 loads the cpu at 25-30%.
can't tell about the encryption, according to mikrotik the ipsec acceleration is also faster.
by icsterm
Tue Apr 17, 2018 11:59 am
Forum: RouterOS v6 RC and v7 BETA
Topic: OpenVPN SHA256 + UDP
Replies: 36
Views: 19859

Re: OpenVPN SHA256 + UDP

I'd consider switching to L2TP+ipsec or EoIP+ipsec(for mikrotik on both sides), both use UDP and encryption and should perform the same or better in performance. OpenVPN on UDP has been requested years ago and won't come too soon on Mikrotik, probably never. SHA256 is supported on the mentioned prot...
by icsterm
Tue Apr 17, 2018 10:18 am
Forum: RouterOS v6 RC and v7 BETA
Topic: L2TP VPN set up on MT so that they cannot detect it's a VPN
Replies: 2
Views: 633

Re: L2TP VPN set up on MT so that they cannot detect it's a VPN

1. Try changing MTU so MSS is changed also accordingly to some random uncommon value. 2. Test with http://witch.valdikss.org.ru/ and https://ipleak.net/ If it fails, maybe your external ip is probed for common vpn ports and the vpn provider app uses some other ip that doesn't expose those ports. Or ...
by icsterm
Wed Apr 11, 2018 8:33 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 287
Views: 56278

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

I find the same poor performance in 5G on the hAP ac^2, I have 1Gbps WAN connection but the 5G connection on AC/80MHz at one metter from the router only throughputs at about 220Mbps download and 270Mbps upload. If I connect a similar priced Asus RT-AC1200G+, use same wireless settings as on the hAP ...
by icsterm
Wed Mar 21, 2018 2:45 pm
Forum: Beginner Basics
Topic: Block web site with Firewall
Replies: 8
Views: 12066

Re: Block web site with Firewall

I would just add all the facebook and youtube prefix list in the routing table with type unreachable, keeping fasttrack and call it a day. But it seems a lot of youtube servers share the same subnet with google.com, so it's hard to do. One way around is to block youtube and facebook domains in the m...
by icsterm
Wed Mar 21, 2018 2:13 pm
Forum: Beginner Basics
Topic: Bypass VPN for Netflix?
Replies: 17
Views: 6581

Re: Bypass VPN for Netflix?

Here is the config for bypassing netflix on VPN. It includes all Netflix + Amazon CDN aggregated prefixed worldwide (326 summarized routes instead of ~1.2K routes). Don't forget to add default route through VPN too. Tested and working 100%, netflix bypasses VPN by CIDR matching in the route table. I...
by icsterm
Tue Mar 20, 2018 11:38 pm
Forum: General
Topic: L2TP VPN selective routing using mangle filters
Replies: 1
Views: 297

L2TP VPN selective routing using mangle filters

Hi, Here is my setup: RB750Gr3 running 6.42rc46, PPPoE WAN connection, NAT with fasttrack enabled, and a L2TP client for selective NAT routing. Config: /ip firewall filter add action=fasttrack-connection chain=forward comment="fasttrack non-vpn" connection-state=established,related \ in-interface=!l...
by icsterm
Mon Mar 19, 2018 2:52 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: 6.42rc43 breaks fasttrack [SOLVED]
Replies: 3
Views: 992

Re: 6.42rc43 breaks fasttrack [SOLVED]

I'm having some sort of similar scenario on my RB750Gr3, after the same RC update I get some mixed bag of performance, despite "IP -> firewall -> Connections" show my IP sessions with the fasttrack flag, I can only saturate 70% of my gigabit pppoe line, before it was saturating just fine at over 90%...
by icsterm
Mon Mar 19, 2018 2:45 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: RB750Gr3 SSH
Replies: 4
Views: 927

Re: RB750Gr3 SSH

indeed, i had security package disabled that's why ssh was missing.
thanks guys !
by icsterm
Sun Mar 11, 2018 11:13 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: RB750Gr3 SSH
Replies: 4
Views: 927

RB750Gr3 SSH

Hello,

I decided to enable SSH server on the RB750Gr3 router, using 6.42rc39 build, but the /system ssh and /ip ssh commands are not accepted. Before buying this router the spec sheet of this model stated SSH on most websites that sold it.
Does it support SSH server/client at all?