Community discussions

MikroTik App

Search found 193 matches

by akarpas
Tue Apr 16, 2024 10:35 am
Forum: General
Topic: ROS V7 PPPoE ststic route
Replies: 1
Views: 193

Re: ROS V7 PPPoE ststic route

ok after doing some labs I found it does gateway checking automatically even if you open immediate gateway on the route it shows gateway is being checked.
by akarpas
Mon Apr 15, 2024 5:23 pm
Forum: General
Topic: ROS V7 PPPoE ststic route
Replies: 1
Views: 193

ROS V7 PPPoE ststic route

In V6 if I use PPPoE with static route gateway ping enabled all worked good, but in V7 if I have gateway check up (ping) enabled it stops working. If I uncheck to check gateway all works good.
Anyone else has the same issue?
by akarpas
Thu Jan 25, 2024 5:59 pm
Forum: General
Topic: Best 4G LTE modem with bridge mode support?
Replies: 0
Views: 377

Best 4G LTE modem with bridge mode support?

Lads , please advise. Whatever who has real experience can advise me what would be the best Mikrotik 4G LTE modem / Router that support bridge mode. Wand to use Ireland (EU)
Thanks in advance.
by akarpas
Fri May 12, 2023 5:16 pm
Forum: General
Topic: Lock VPN user to static IP
Replies: 2
Views: 385

Re: Lock VPN user to static IP

I think user-man with an attribute of framed-ip-address=x.x.x.x for that user. If the number of users is not large and you don't want to set up any Radius, you could also use remote-address=x.x.x.x. yep this is what I used to set remote address, and created a firewall rule what that address may acc...
by akarpas
Fri May 12, 2023 12:18 pm
Forum: General
Topic: Lock VPN user to static IP
Replies: 2
Views: 385

Lock VPN user to static IP

What would be the best option to make sure that VPN user is using statically assigned IP address to his VPN secret. In case user edit VPN client and puts other IP the Mikrotik would disable VPN or would not allow to connect.
by akarpas
Fri Mar 24, 2023 7:30 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140262

Re: v7.8 [stable] is released!

ok more and more people reporting problems so 7.8 is not that stable :) needs a lot of fixes
by akarpas
Thu Mar 23, 2023 5:00 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140262

Re: v7.8 [stable] is released!

Hello guys, I have set up RB1100AHx4 switching so some vlans, some ports tagged some untagged, all works file on 6.49.7 but once i upgrade to 7.8 all vlans stops working , I have to disable vlan filtering on the bridge and to re-enable to start it working but after reboot of the router all stops wo...
by akarpas
Tue Mar 21, 2023 3:55 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140262

Re: v7.8 [stable] is released!

Hello guys, I have set up RB1100AHx4 switching so some vlans, some ports tagged some untagged, all works file on 6.49.7 but once i upgrade to 7.8 all vlans stops working , I have to disable vlan filtering on the bridge and to re-enable to start it working but after reboot of the router all stops wor...
by akarpas
Fri Dec 23, 2022 12:12 am
Forum: General
Topic: What would be correct static routing and NAT for network 192.168.15.0/24 on R2 and why
Replies: 2
Views: 294

What would be correct static routing and NAT for network 192.168.15.0/24 on R2 and why

What would be correct static routing and NAT for network 192.168.15.0/24 on R2 and why. I think this would be handy for anyone learning networks.
by akarpas
Thu Sep 01, 2022 11:40 am
Forum: General
Topic: Help request for VLANs
Replies: 8
Views: 677

Re: VLANS

The only thing I would add is found below....... ................... /interface vlan add name=bridge1.10 interface=bridge1 vlan-id=10 add name=bridge1.20 interface=bridge1 vlan-id=20 /interface bridge vlan add bridge=bridge1 vlan-ids=10 tagged=bridge1,ether2,ether3 untagged=ether4 add bridge=bridge...
by akarpas
Wed Aug 31, 2022 9:34 pm
Forum: General
Topic: Help request for VLANs
Replies: 8
Views: 677

Re: VLANS

Thank you guys, you are stars :) I see now where I did a mistake. Once again a mil thanks for support. I hope this post will help others as well!
by akarpas
Wed Aug 31, 2022 6:01 pm
Forum: General
Topic: Help request for VLANs
Replies: 8
Views: 677

Help request for VLANs

I know where are a lot of topics created but non of them gave me a positive result I might be overthinking something. I work on RB1100AHx4 Dude Edition. Ether1 = WAN connection Ether2 to 5 are members of bridge1 I have VLAN10 and VLAN20 VLAN1 as default. What I want is that VLAN10 and 20 will go tag...
by akarpas
Sun Jul 17, 2022 7:48 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81225

Re: v7.3 and v7.3.1 [stable] is released!

Hey is SSTP broken in version OS V7 ? As it works perfect in version 6 but not in version 7 Certs chain to root problem
by akarpas
Sat Jul 16, 2022 4:37 pm
Forum: General
Topic: Can Mikrotik Radius act as a Radius Server
Replies: 4
Views: 852

Re: Can Mikrotik Radius act as a Radius Server

RADIUS in the ROS menu is about RADIUS client settings (e.g. what RADIUS server to use, and how to connect to that server (port # and secret)) User manager acts as a RADIUS server for RADIUS client requests (is optional package to be installed.) Most services are managed. But for wifi EAP/PEAP (usi...
by akarpas
Fri Jul 15, 2022 7:42 pm
Forum: General
Topic: Can Mikrotik Radius act as a Radius Server
Replies: 4
Views: 852

Re: Can Mikrotik Radius act as a Radius Server

You mean user-manager?
No I was about Radius option in OS menu, but if you started about user manager I will as if this can be used to authenticate 802.1x wired connection on switch
by akarpas
Fri Jul 15, 2022 12:41 pm
Forum: General
Topic: Can Mikrotik Radius act as a Radius Server
Replies: 4
Views: 852

Can Mikrotik Radius act as a Radius Server

Just a dummy question. May or may not Mikrotik Radius act as a Radius server for 802.1X switch port authentication on the network?
Many thanks in advance.
by akarpas
Fri Jun 17, 2022 1:35 pm
Forum: General
Topic: CHR P1 Trial to P1 Perpetual still slow speed
Replies: 0
Views: 408

CHR P1 Trial to P1 Perpetual still slow speed

Hello maybe someone has some experience and may advise on the problem. I have dude on CHR I had a P1 Trial License that I have upgraded to P1 Perpetual. After upgrade my speeds are slow as hell just in kbps and suppose to give me 1Gbps per interface. Have restarted dude server a couple of times, tri...
by akarpas
Tue Jun 14, 2022 11:53 pm
Forum: General
Topic: Winbox creates add.txt file on desktop [SOLVED]
Replies: 6
Views: 962

Re: Winbox creates add.txt file on desktop [SOLVED]

ok have fixed it, had to delete folder Mikrotik/winbox in %appdata%/roaming. After deleting all back normal.
by akarpas
Tue Jun 14, 2022 11:45 pm
Forum: General
Topic: Winbox creates add.txt file on desktop [SOLVED]
Replies: 6
Views: 962

Re: Winbox creates add.txt file on desktop [SOLVED]

What's in the add.txt file? 0o
all info about save connections
by akarpas
Tue Jun 14, 2022 11:43 pm
Forum: General
Topic: Winbox creates add.txt file on desktop [SOLVED]
Replies: 6
Views: 962

Re: Winbox creates add.txt file on desktop [SOLVED]

Probably you have download winbox from wrong site and now you have a surprise with winbox.....
nope downloaded from official Mikrotik site!
by akarpas
Tue Jun 14, 2022 10:13 pm
Forum: General
Topic: Winbox creates add.txt file on desktop [SOLVED]
Replies: 6
Views: 962

Winbox creates add.txt file on desktop [SOLVED]

Downloaded winbox on windows 11 and with a first run it creates add.txt file on desktop and I cant move it anywhere as then you run winbox again it creates new one is it just me getting this annoyed file or others are getting as well as I have winbox on other two windows 10 machines and none of them...
by akarpas
Fri May 27, 2022 11:30 pm
Forum: General
Topic: Where to order RB4011 iGS+RM andRB5009UG+S+IN routers in Ireland?
Replies: 8
Views: 1079

Re: Where to order RB4011 iGS+RM andRB5009UG+S+IN routers in Ireland?

This is the problem "Call" , "Query" but then you call or query or then you ask so then you will have your awaiting stock answer is: "nobody knows, some day sooner or later" :/
by akarpas
Fri May 27, 2022 10:28 pm
Forum: General
Topic: Where to order RB4011 iGS+RM andRB5009UG+S+IN routers in Ireland?
Replies: 8
Views: 1079

Where to order RB4011 iGS+RM andRB5009UG+S+IN routers in Ireland?

Not sure if the topic is in the right place but we are facing a problem. Urgently need some of both mentioned routers. The main reliable distributor in Ireland senetic.ie has no in stock need to require with no answer. Some other promoted distributors are just a joke or has only for their own needs....
by akarpas
Sat Apr 02, 2022 5:14 pm
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40103

Re: v7.1.4 and v7.1.5 is released!

then SD card support will be fixed for CCR1009-7G-1C-1S+ devices????????? or this problem is completely ignored?
by akarpas
Sat Mar 26, 2022 3:48 pm
Forum: The Dude
Topic: Dude client slow loading
Replies: 3
Views: 2572

Re: Dude client slow loading

thanks for the link it has answered fully to the question.
by akarpas
Sat Mar 26, 2022 3:46 pm
Forum: The Dude
Topic: Poor Dude performance.
Replies: 1
Views: 2577

Poor Dude performance.

OK I have Dude installed on CHR (vhdx) on a hyper-v. Assigned 2 CPU's 4GB of RAM 15GB od storage, P1 license to make sure stable 1Gbps connections. So connecting via Dude client from PC who has I7 up to 5Ghz 32GB of RAM SSD and so on. So if the site I add to dude has around or up to 25 hosts per map...
by akarpas
Fri Mar 25, 2022 1:27 pm
Forum: The Dude
Topic: Dude client slow loading
Replies: 3
Views: 2572

Dude client slow loading

Hello Geeks, I have installed a virtual router (dude) an hyper v (vhdx file) and on Synology NAS (vhdx) all works ok nice cool but one what is really anoying is dude client loading times!!!! Its so slow in kbps only . Is it a limitation of free license ? If yes were to get a proper license?
by akarpas
Fri Mar 25, 2022 1:23 pm
Forum: The Dude
Topic: How to import min in to a dude
Replies: 3
Views: 2364

Re: How to import min in to a dude

Thank you lads, used ftp to create folder and transfer files.
by akarpas
Fri Mar 25, 2022 1:19 pm
Forum: The Dude
Topic: Dude client 7.1 and 7.1rc not working in Windows 11
Replies: 16
Views: 13345

Re: Dude client 7.1 and 7.1rc not working in Windows 11

My home Router is CCR 1009 OS v7 I have downloaded The Dude VHDX 6.49.5 and installed it as a virtual router on Synology NAS. All works great no problems crashes monitors whole my home network, having a good play with SNMP as was able to set a network map nearly the same as per physical layout. I'm ...
by akarpas
Thu Mar 24, 2022 5:28 pm
Forum: The Dude
Topic: How to import min in to a dude
Replies: 3
Views: 2364

How to import min in to a dude

I need to import sophos.min.txt to dude mibs folder but do not see any possibilities to do it nor via dude nor via winbox can somebody explain me followed some forum topics but got lost as i do not see ability to create folder dude/mibs/liebert can somebody bring in some light as got lost with such ...
by akarpas
Thu Mar 24, 2022 12:55 pm
Forum: The Dude
Topic: Deleted devices from local map hot to autoscan local network again?
Replies: 2
Views: 2144

Re: Deleted devices from local map hot to autoscan local network again?

Thanks, got that yesterday. Just installed quickly a fresh VHDX type Dude and checked the startup of discovery after proper obsorvation all was clear on how to manage this. But anyway thanks mate good advise.
by akarpas
Wed Mar 23, 2022 12:52 pm
Forum: The Dude
Topic: Deleted devices from local map hot to autoscan local network again?
Replies: 2
Views: 2144

Deleted devices from local map hot to autoscan local network again?

After installing the dude, the local network was scanned by auto and mapped, playing around I made lots of mess and did all devices deletion from local map thinking I will be able to do auto rescan but not only I see I have to add networks to be scanned I do not see the option to auto-scan local net...
by akarpas
Fri Feb 25, 2022 2:30 pm
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 56914

Re: v7.1.3 is released!

SD card still doesnt work on my CCR1009-7G-1C-1S+
by akarpas
Sun Jan 02, 2022 8:54 pm
Forum: General
Topic: Is it necessary for me to install a second firewall?
Replies: 4
Views: 2118

Re: Is it necessary for me to install a second firewall?

Yes, you can add Sophos XG firewall in transparent mode between you Mikrotik facing WAN and LAN. The transparent mode works as a bridge for traffic from Mikrotik and LAN and from LAN to Mikrotik and all this traffic is protected by Sophos XG firewall. Really nice setup to protect a network, one I do...
by akarpas
Tue Dec 28, 2021 2:52 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

question do you have upgrade or clean install ? is you hardware fully supported? Yes, it is fully supported, and I did an upgrade. 7.1 to 7.1.1 I would not expect to give major issues like that. I do not have a tilera based system to test on, but everything I have upgraded has gone fine from 7.1 to...
by akarpas
Tue Dec 28, 2021 2:17 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

it might have a minor bugs , minor is acceptable but not then device gets in to bricked mode were you have to re-image it. What version was it on before you upgraded? Re: Win11 I am on Windows 11 and am experiencing some extremely annoying bugs, mostly to do with 4K scaling and the start menu stops...
by akarpas
Tue Dec 28, 2021 1:57 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

what release its considered to be stable version free of bugs isnt? "Free of bugs"? No, that's not what MikroTik's definition of "stable" means. You won't find any vendor where a "stable" release is 100% free of bugs, it just doesn't happen. "Stable" in Mikro...
by akarpas
Mon Dec 27, 2021 8:27 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

Looks like SD cards still do not mount on CCR1009-7G-1C-1S+, same on 7.2rc1.
for me the same on 7.1.1
by akarpas
Mon Dec 27, 2021 8:25 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

not sure why but after update as I have said my ccr 1009 didnt boot anymore had to use netinstall to reimage and now its not recognising mikrosd car tried 2 of them no luck You could have read both of these things above. It really pays off to read the release topic before attempting to upgrade! wha...
by akarpas
Mon Dec 27, 2021 7:52 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

not sure why but after update as I have said my ccr 1009 didnt boot anymore had to use netinstall to reimage and now its not recognising mikrosd car tried 2 of them no luck
by akarpas
Mon Dec 27, 2021 4:59 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

updated my ccr 1009 now its bricked not booting not loading kernel
Had to reisntall using Netinstall sad had to do it but was a great experience how to recover device from such a problem.
by akarpas
Mon Dec 27, 2021 2:18 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 225770

Re: v7.1.1 is released!

updated my ccr 1009 now its bricked not booting not loading kernel
by akarpas
Thu Sep 09, 2021 4:54 pm
Forum: General
Topic: IKEv2 Picking the wrong client cert installed on local PC cert store
Replies: 1
Views: 1105

Re: IKEv2 Picking the wrong client cert installed on local PC cert store

ok made a query and later on found an answer at this topic: https://forum.mikrotik.com/viewtopic.php?f=2&t=139273&p=878614#p878614 Manage how to tell windows 10 witch cert to use. Now, if you have more than one IKE2 RSA VPN's created, you should specify which certificate Windows should use, ...
by akarpas
Thu Sep 09, 2021 4:52 pm
Forum: General
Topic: IPsec IKE2 can find valid sertificate [SOLVED]
Replies: 13
Views: 9700

Re: IPsec IKE2 can find valid sertificate [SOLVED]

Mate, million thanks to you for sharing the PowerShell part on how to make IKEv2 to use the proper cert. Thanks gain.
by akarpas
Thu Sep 09, 2021 3:43 pm
Forum: General
Topic: IKEv2 Picking the wrong client cert installed on local PC cert store
Replies: 1
Views: 1105

IKEv2 Picking the wrong client cert installed on local PC cert store

Hi geeks, I have IKEv2 set up to site A all works great no problems, connecting, speed is ok, stable. I have made set up to site B and gues what it doesnt work. Cinfig is ok , certs are installed as they have to be installed. But the I click to connect to site B, Windows 10 sends site A client certi...
by akarpas
Tue Jul 13, 2021 9:31 pm
Forum: General
Topic: DUAL WAN no balance / possible errors with this routing config
Replies: 0
Views: 756

DUAL WAN no balance / possible errors with this routing config

I have found this configuration for dual wan with no balance and simplified it see below: Method 2 - Dual WAN failover with MULTIPLE remote host ping check (ISP1 - Static IP; ISP2 - PPPoE) We have two uplinks: MAIN (GW1 IP - 88.196.6.185) and BACKUP (GW2 - PPoE IP: 10.10.1.1) - usually those gateway...
by akarpas
Thu Jul 01, 2021 1:22 pm
Forum: General
Topic: Then would you use arp, proxy-arp and local-proxy-arp
Replies: 4
Views: 1624

Re: Then would you use arp, proxy-arp and local-proxy-arp

Real -world scenario: If you can't distingush the functions, and you do not have any desire to understand, leave the default values. Because if you change them, without any form of knowledge of what you doing, you only risk making a mess. This is very rude answer, I have went via Mikrotik wiki page...
by akarpas
Thu Jul 01, 2021 1:05 pm
Forum: General
Topic: Then would you use arp, proxy-arp and local-proxy-arp
Replies: 4
Views: 1624

Then would you use arp, proxy-arp and local-proxy-arp

Then would you use arp, proxy-arp and local-proxy-arp. Please don refer me to Mikrotik pages, give me a real-world scenario, thank you in advance.
by akarpas
Mon Jun 28, 2021 11:51 pm
Forum: General
Topic: dual wan
Replies: 2
Views: 617

Re: dual wan

by akarpas
Mon Jun 28, 2021 8:50 pm
Forum: General
Topic: dual wan
Replies: 2
Views: 617

dual wan

Hi guys, testing this conf of dual wan: Before detailed example overview, in a setup where we have private IP addresses behind the public IP, we should configure source NAT: /ip/firewall/nat add chain=srcnat action=masquarade out-interface=ether1 add chain=srcnat action=masquarade out-interface=ethe...
by akarpas
Fri Apr 23, 2021 12:53 pm
Forum: General
Topic: firewall rules in recursive wan failover set up
Replies: 2
Views: 838

firewall rules in recursive wan failover set up

Hei geeks, I have one router with dual wan recursive failover set up, all works ok ut have some issues with some firewall rules. add action=drop chain=forward in-interface=vlan10 out-interface=\ !ether1-WAN add action=drop chain=forward in-interface=vlan11 out-interface=\ !ether1-WAN add action=drop...
by akarpas
Fri Mar 19, 2021 1:25 pm
Forum: Wireless Networking
Topic: New in Mikrotik Wireless need advise
Replies: 3
Views: 1280

New in Mikrotik Wireless need advise

So as I said I'm new to Mikrotik wireless never used it before. One of my clients is in a place where no internet cable can be provided so I'm looking for alternatives. I came to LTE antenna LHGG LTE6 KIT. So is this antenna just LTE modem or its has a fully functioning Mikrotik OS and can be used a...
by akarpas
Thu Mar 18, 2021 5:38 pm
Forum: General
Topic: Mikrotik + Sophos XG FW Winbox blocked if APP filter applied
Replies: 5
Views: 1534

Re: Mikrotik + Sophos XG FW Winbox blocked if APP filter applied

Found it. Winbox app was concidered as: Application Detail Name Torrent Clients P2P Category P2P Risk Very High Characteristics Excessive Bandwidth, Loss of productivity, Vulnerabilities, Transfer files, Transfer files Technology P2P Dependency None Applicable on 16.01.0 Build 101 and above Descript...
by akarpas
Thu Mar 18, 2021 5:11 pm
Forum: General
Topic: Mikrotik + Sophos XG FW Winbox blocked if APP filter applied
Replies: 5
Views: 1534

Re: Mikrotik + Sophos XG FW Winbox blocked if APP filter applied

Winbox is an app, so it makes sense that it would be blocked by whatever list the Sophos has for apps. Where are several levels of policy with different app categories in it. The one I'm applying is level 5 considered the most dangerous apps on the net and winbox should not be in it. I was able to ...
by akarpas
Thu Mar 18, 2021 3:59 pm
Forum: General
Topic: Mikrotik + Sophos XG FW Winbox blocked if APP filter applied
Replies: 5
Views: 1534

Mikrotik + Sophos XG FW Winbox blocked if APP filter applied

I'm gonna be short do not expect too many answers as this is not directly up to Mikrotik but more to Sophos but might be we have people who use Mikrotik with Sophos as well. So scenario: Mikrotik router is an edge router / firewall + Sophos XG Firewall between Mikrotik and LAN in a transparent bridg...
by akarpas
Tue Mar 09, 2021 6:46 pm
Forum: Scripting
Topic: cant get X OR Y AND Z properly working
Replies: 4
Views: 1167

Re: cant get X OR Y AND Z properly working

BODMAS just went out of my mind then it came to Mikrotik scripting :D I'm new to Mikrotik scripting but with your help guys doing progress. Thanks a mill again.
by akarpas
Tue Mar 09, 2021 6:29 pm
Forum: Scripting
Topic: cant get X OR Y AND Z properly working
Replies: 4
Views: 1167

Re: cant get X OR Y AND Z properly working

Note that (A || B && C) means (A || (B && C)) due to operator precedence, not ((A || B) && C). If you want the latter, you need to use parentheses as shown. It's like 1+2*3 is 7, not 9. Emil thanks a mill for clearing this, changed it as per your explanation and it works now...
by akarpas
Tue Mar 09, 2021 5:55 pm
Forum: Scripting
Topic: cant get X OR Y AND Z properly working
Replies: 4
Views: 1167

cant get X OR Y AND Z properly working

:if ([/ping 1.1.1.1 count=5] !=0 || [/ping 2.2.2.2 count=5] != 0 && [/interface vrrp get vrrp2 priority]=90) do={[/interface vrrp set vrrp2 priority=150]} let's say if to change vrrep2 priority to 155 on a line to test if this line works. So by the logic, if host A or Host B is pingable AND ...
by akarpas
Wed Mar 03, 2021 4:22 pm
Forum: Scripting
Topic: else -if
Replies: 6
Views: 9397

Re: else -if

Jotne thank you, this worked like a charm no I have a simple script with two hosts check-up and different do scenarios, I really appreciate your advice's.
by akarpas
Wed Mar 03, 2021 1:05 am
Forum: Scripting
Topic: else -if
Replies: 6
Views: 9397

Re: else -if

Script can be used to nearly all tings, but do not use ping to test for ip up, use netwatch.
https://wiki.mikrotik.com/wiki/Manual:Tools/Netwatch

Do search forum here for example
yeh i understand but i want to test two host instead of one before taking some action
by akarpas
Tue Mar 02, 2021 3:48 pm
Forum: Scripting
Topic: else -if
Replies: 6
Views: 9397

Re: else -if

Yes you can use as many if and else you like. Example :if (version>=6.5) do={ # Do some stuff } else={ # Do some other stuff :if (host=27) do={ # Do some other stuff here } } Thanks, just another question is the syntax ok if I want to ping host A and B and both are down switch of C :if ([/ping 10.1...
by akarpas
Tue Mar 02, 2021 3:15 pm
Forum: Scripting
Topic: else -if
Replies: 6
Views: 9397

else -if

Can I use if after else?
if (safsafasfasfasfasfa);
else:
if(safasfsafasfasf)
or its not possible in Mikrotik scripting?
by akarpas
Wed Feb 17, 2021 11:25 am
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 3111

Re: How to connect vrrp'ed routers to wan (ISP)

The key here is the "policy routing" as mentioned above, which is a shortcut for "routing which takes into account not only the destination address but also other properties of the packet being routed". In particular, you have to distinguish from where a packet came in. If it ca...
by akarpas
Tue Feb 16, 2021 6:40 pm
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 3111

Re: How to connect vrrp'ed routers to wan (ISP)

As suggested by @tdw, you actually don't need any script if the primary default route of each router goes via its own WAN and the secondary one goes via the second router, and you use the script-free monitoring of transparency of both WANs, as described here . Or you can even use any of those fancy...
by akarpas
Tue Feb 16, 2021 11:38 am
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 3111

Re: How to connect vrrp'ed routers to wan (ISP)

need a script which would monitor two host min as 8.8.8.8 and 1.1.1.1 if both, are down disable VRRP bridge and if 8.8.8.8 OR 1.1.1.1 is up do nothing or bring VRRP bridge back up. So I would be hell happy with this scenario. Only I wouldn't be able to script this in Mikrotik environment so need to ...
by akarpas
Fri Feb 12, 2021 6:41 pm
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 3111

Re: How to connect vrrp'ed routers to wan (ISP)

So as I understand the best option would be to stick one ISP on one router let's say cable ISP on master router and DLS on backup router. next to set up Netwatch tool to monitor 8.8.8.8 from master router and if it gets to down state allow it to switch off VLAN for VRRP or switch it back if ping to ...
by akarpas
Fri Feb 12, 2021 11:10 am
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 3111

How to connect vrrp'ed routers to wan (ISP)

Hi guys. I'm playing around with this topology. So on LAN side everything is clear, configured and working.(VRRP + RSTP + DHCP on server). But wats about WAN connections. for ISP 2 Cable broadband I have only 1 static IP issued from ISP and ISP1 DSL connects via PPPoE and again single static IP. So ...
by akarpas
Wed Feb 03, 2021 5:57 pm
Forum: General
Topic: need a cellular backup for CCR1009-7G-1C-1S+PC router
Replies: 7
Views: 1294

Re: need a cellular backup for CCR1009-7G-1C-1S+PC router

From another thread in May 2019 I got a reply from @support: Unfortunately, we cannot recommend any Smart Card for use in MikroTik devices. The Smart Card support in RouterOS requires significant rebuild and currently it is on hold due to higher priority projects. My question for MT staff, nowhere ...
by akarpas
Wed Feb 03, 2021 5:56 pm
Forum: General
Topic: need a cellular backup for CCR1009-7G-1C-1S+PC router
Replies: 7
Views: 1294

Re: need a cellular backup for CCR1009-7G-1C-1S+PC router

No, I think you interpret it wrong. "It can be used with any of our products that have miniPCIe slot". But CCR1009 does not have it. Products RB800 and RB4011 do have miniPCIe slot, but still it cannot be used in those. The CCR1009 has USB. You can use a 4G USB stick (not every model, but...
by akarpas
Wed Feb 03, 2021 3:32 pm
Forum: General
Topic: need a cellular backup for CCR1009-7G-1C-1S+PC router
Replies: 7
Views: 1294

Re: need a cellular backup for CCR1009-7G-1C-1S+PC router

Yes it has a SIM card slot, but I am not aware that it has a PCIe slot where you could install the R11e-LTE6. Where did you find that information? The SIM card slot on the CCR routers is afaik only used to store certificates for encryption protocols, and even that seems seldomly used and difficult ...
by akarpas
Wed Feb 03, 2021 2:51 pm
Forum: General
Topic: need a cellular backup for CCR1009-7G-1C-1S+PC router
Replies: 7
Views: 1294

need a cellular backup for CCR1009-7G-1C-1S+PC router

Hi guys. Have cable broadband connected to CCR1009-7G-1C-1S+PC. Now thinking about the possibility to get cellular backup from any 4G provider. I see a device R11e-LTE6 PCIe card that might be installed on CCR1009-7G-1C-1S+PC and CCR1009-7G-1C-1S+PC has a SIM card slot (smart card(mini-sim)). I can'...
by akarpas
Fri Jan 29, 2021 10:37 pm
Forum: General
Topic: Mikrotik PCI DSS External Vulnerability Scan
Replies: 5
Views: 1239

Re: Mikrotik PCI DSS External Vulnerability Scan

Thank you kindly for this link to the proper post where it was already answered by Mikrotik.
by akarpas
Thu Jan 28, 2021 6:35 pm
Forum: General
Topic: Mikrotik PCI DSS External Vulnerability Scan
Replies: 5
Views: 1239

Re: Mikrotik PCI DSS External Vulnerability Scan

You should check if your firewall is configured properly, because normally a router should have little reason to reply to UDP packets sent to it from internet. it says the problem is with kernel the way IP stack sends UDP packets, I doubt its firewall problem, I will extract firewall configuration ...
by akarpas
Thu Jan 28, 2021 5:55 pm
Forum: General
Topic: Mikrotik PCI DSS External Vulnerability Scan
Replies: 5
Views: 1239

Mikrotik PCI DSS External Vulnerability Scan

Today we have got a PCI DSS External Vulnerability Scan on one of the sites where we have Mikrotik Router. All went ok except this: THREAT: The host transmits UDP packets with a constant IP Identification field. This behavior may be exploited to discover the operating system and approximate kernel v...
by akarpas
Sun Jul 19, 2020 11:40 pm
Forum: General
Topic: OpenVPN sloooow
Replies: 14
Views: 20585

Re: OpenVPN sloooow

by default, OpenVPN uses pfifo type queue, with queue size ~50packets. Make your openvpn interface static (if the link comes up, do copy and rename it). Now you have an interface, where you can change interface queue. Make a new queue type called openvpn-default, with type pfifo and size ~250 set t...
by akarpas
Sat Jul 18, 2020 12:17 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

As I said works as a charm, no problems. Ok, I see. It works because you use only one port of the bridge (you basically can omit the bridge completely). Keep in mind, that in general, when multiple ports are used, that won't work properly without bridge vlan filtering: https://wiki.mikrotik.com/wik...
by akarpas
Sat Jul 18, 2020 2:01 am
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

https://wiki.mikrotik.com/wiki/Manual:Interface/VLAN simple interVLAN trunking as cisco say router on a stick
by akarpas
Sat Jul 18, 2020 1:49 am
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

I completely skipped the switch part of the config, assuming that it was copied from my first posts in this thread regarding the OP case. But now, as I see that the whole part is missing, I have only one question - how on earth does it work in the first place? I guess it can somehow, if downstream ...
by akarpas
Sat Jul 18, 2020 1:38 am
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

I completely skipped the switch part of the config, assuming that it was copied from my first posts in this thread regarding the OP case. But now, as I see that the whole part is missing, I have only one question - how on earth does it work in the first place? I guess it can somehow, if downstream ...
by akarpas
Sat Jul 18, 2020 12:22 am
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

Its actually lack of vlan-filtering=yes setting on bridge. Without it, bridge doesn't enforce any VLAN settings.
Thanks mkx will play around for study purpose but the problem is resolved now, you advise is much appreciated!
by akarpas
Sat Jul 18, 2020 12:09 am
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

so proxy arp is the problem? but i need it for VPN! Yes and no. Proxy arp together with lack of proper firewall rules are a reason of what you described above. it does ! add action=drop chain=forward out-interface=!ether1-WAN src-address=\ 192.168.11.0/24 this rule allows guest wifi only access to ...
by akarpas
Fri Jul 17, 2020 11:31 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

And btw your firewall also doesn't restrict communication between vlans. it does ! add action=drop chain=forward out-interface=!ether1-WAN src-address=\ 192.168.11.0/24 this rule allows guest wifi only access to internet out want port all other is blocked/droped So how to resolve bridge arp problem...
by akarpas
Fri Jul 17, 2020 11:23 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

First line, and that's your answer:

/interface bridge
add arp=proxy-arp name=bridge-lan
so proxy arp is the problem? but i need it for VPN!
by akarpas
Fri Jul 17, 2020 11:17 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

I don't want to start arguing here I know your expertise in Mikrotik is 100times better my one, but then this lad created this topic I have tested and yes then I'm logged to public tagged wifi and change IP corresponding to my internal untagged LAN my wifi connected devise gets full connectivity !!...
by akarpas
Fri Jul 17, 2020 10:59 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

So then the guest connects to guests WIFI and if he changes IP received from guest DHCP to static corresponding to bridge LAN guest gets access to bridge LAN Nope, it does not. Even if your firewall is not operating with interfaces instead of addresses. I don't want to start arguing here I know you...
by akarpas
Fri Jul 17, 2020 10:38 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

If you dont want the VLANs to be able to communicate with each other on layer 3, i.e. ICMP traffic, you should block this with firewall rules Then regarding "duplicate ping packets", think it will be best to show this in a packet capture as evidence, I personally dont think you should dis...
by akarpas
Fri Jul 17, 2020 6:28 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

Disable IP forwarding on mikrotik or on end devise?
On mikrotik.
could you be more specific on disabling IP forwarding, thank you in advance, this topic is very good.
by akarpas
Fri Jul 17, 2020 4:54 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 11641

Re: VLAN Isolation

Disable IP forwarding on the device.
Disable IP forwarding on mikrotik or on end devise?
by akarpas
Thu Jul 16, 2020 2:26 pm
Forum: General
Topic: OpenVPN local traffic goes via local WAN
Replies: 0
Views: 672

OpenVPN local traffic goes via local WAN

Ok, in short, I have configured OpenVPN (client to server) all good connection established I may ping and access all I need on the remote side. But the problem is my local client-side traffic goes not via tunnel but just out via local WAN connection. If I check IP shows local WAN IP, not OpenVPN ser...
by akarpas
Sat Jun 27, 2020 7:49 pm
Forum: General
Topic: Slow road worrior VPN speed from client to server
Replies: 7
Views: 4278

Re: Slow road worrior VPN speed from client to server

In Site 1 via VPN tunnel 40Mbps of download and 30Mbps of upload is maximum you can theoretically get (restricted by Site 1 and Site 2 upload speeds). it should not be the case but sounds logical but I have said if I use Sophos router on site 2 I'm getting more then 100Mbps speed on-site 1 via L2TP...
by akarpas
Sat Jun 27, 2020 7:19 pm
Forum: General
Topic: Proper firewall rule to block outgoing port 25.
Replies: 4
Views: 6312

Re: Proper firewall rule to block outgoing port 25.

In the default firewall configuration, adding it to the end of the forward chain will do.
Thank you kindly!!!
by akarpas
Sat Jun 27, 2020 7:12 pm
Forum: General
Topic: Proper firewall rule to block outgoing port 25.
Replies: 4
Views: 6312

Re: Proper firewall rule to block outgoing port 25.

If placed to a correct position in the chain, and if ether2 is your WAN interface, then yes. And the protocol=tcp one should be sufficient, I don't think any SMTP server listens at UDP. By saying "correct position" what it should be" If lets say default firewall configuration is used?
by akarpas
Sat Jun 27, 2020 7:01 pm
Forum: General
Topic: Proper firewall rule to block outgoing port 25.
Replies: 4
Views: 6312

Proper firewall rule to block outgoing port 25.

Mail server is installed on the network , need to block outgoing 25 but allowing this for the mail server? Are these two rules enough to make sure nobody else except mail server can do port 25 out? add action=drop chain=forward comment=\ "Drop Non Mail Srv SMTP Out 25" dst-port=25 out-inte...
by akarpas
Wed Jun 24, 2020 10:43 pm
Forum: General
Topic: Slow road worrior VPN speed from client to server
Replies: 7
Views: 4278

Re: Slow road worrior VPN speed from client to server

anyone else any ideas?
by akarpas
Sun Jun 21, 2020 2:39 pm
Forum: General
Topic: Slow road worrior VPN speed from client to server
Replies: 7
Views: 4278

Re: Slow road worrior VPN speed from client to server

Could it be something related to firewall FastTrack rule? Even I have two IPSec IN and OUT excluding rules above fasttrack rule and it doesn't count any packets as it would if I had a site to site tunnel. Fasttracking only interferes with IPsec processing, queueing, and marking in firewall of packe...
by akarpas
Sat Jun 20, 2020 3:43 pm
Forum: General
Topic: Slow road worrior VPN speed from client to server
Replies: 7
Views: 4278

Re: Slow road worrior VPN speed from client to server

The only thing to come to my mind - the default-profile under /interface l2tp-server server is set to default-encryption by default. But this activates the MPPE encryption, which is a) done in software, so may slow down the connection, and b) is useless as the L2TP packets are encrypted using IPsec...
by akarpas
Fri Jun 19, 2020 6:13 pm
Forum: General
Topic: Slow road worrior VPN speed from client to server
Replies: 7
Views: 4278

Slow road worrior VPN speed from client to server

L2TP VPN.PNG Hello Guys! So in the picture, I have described the L2TP Road Warrior connection. Device models used. ISP service provided. Set up is ok connection is ok stable no problems. The only problem is slow VPN speed. In Site 1 PC (L2TP client) is able to receive only max 40Mbps of download an...
by akarpas
Wed Jun 03, 2020 10:21 pm
Forum: General
Topic: How to exclude more then one Connection Mark in Firewall fasttrack rule?
Replies: 2
Views: 1393

Re: How to exclude more then one Connection Mark in Firewall fasttrack rule?

As you probably want to exclude any marked connections from fasttracking, you can set connection-mark=no-mark in the action=fasttrack-connection rule, instead of connection-mark=!vpn-mark.
Thank you a mill, will test tomorrow.
by akarpas
Wed Jun 03, 2020 8:48 pm
Forum: General
Topic: How to exclude more then one Connection Mark in Firewall fasttrack rule?
Replies: 2
Views: 1393

How to exclude more then one Connection Mark in Firewall fasttrack rule?

How to exclude more than one Connection Mark in Firewall Fasttrack rule? I have Express VPN set up on my Mikrotik all works good, but if I want to change location all the time I have to go to P"TP client and change server URL. I got and the idea just to create two L2TP clients pointing to diffe...
by akarpas
Fri Mar 27, 2020 2:44 pm
Forum: General
Topic: /system routerboard ypgrade
Replies: 1
Views: 1153

Re: /system routerboard ypgrade

ok found solution
/system routerboard upgrade
/yes

worked as a charm
by akarpas
Fri Mar 27, 2020 2:41 pm
Forum: General
Topic: /system routerboard ypgrade
Replies: 1
Views: 1153

/system routerboard ypgrade

Hi guys, I want to do a bulk Mikrotik router board firmware upgrades. The thing is stopping me after the line: /system routerboard upgrade I have to hit enter and type in yes or no as confirm. Is anyhow I can write in the same line and be accepted something like: /system routerboard upgrade | yes or...
by akarpas
Thu Feb 20, 2020 7:19 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 16
Views: 6908

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

/ip firewall mangle add chain=prerouting action=mark-routing new-routing-mark=vpn passthrough=no src-address=192.168.x.x/24 comment=xxx connection-state=new add action=fasttrack-connection routing-mark=vpn connection-state=new If you switch to IKEv2 the you double the speed of 70 MBit/s to around 1...
by akarpas
Thu Feb 20, 2020 5:58 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 16
Views: 6908

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

/ip firewall mangle add chain=prerouting action=mark-routing new-routing-mark=vpn passthrough=no src-address=192.168.x.x/24 comment=xxx connection-state=new add action=fasttrack-connection routing-mark=vpn connection-state=new If you switch to IKEv2 the you double the speed of 70 MBit/s to around 1...
by akarpas
Thu Feb 20, 2020 4:54 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 16
Views: 6908

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

/ip firewall mangle add chain=prerouting action=mark-routing new-routing-mark=vpn passthrough=no src-address=192.168.x.x/24 comment=xxx connection-state=new add action=fasttrack-connection routing-mark=vpn connection-state=new If you switch to IKEv2 the you double the speed of 70 MBit/s to around 1...
by akarpas
Wed Feb 19, 2020 6:38 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 16
Views: 6908

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

BTW they also support IKEv2 which is much better. You can follow the NordVPN instructions. You have to find out which root certificate ExpressVPN is using and load that in the router. Yeh IKEv2 would better but at first, I want to understand snd this to the end, as if I disable FastTrack on firewal...
by akarpas
Wed Feb 19, 2020 6:16 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 16
Views: 6908

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

This done in Mangle by Mark routing in your case. Then only fasttrack traffic that is not marked to be routed through that VPN connection. Only mark new traffic for fasttracking. BTW they also support IKEv2 which is much better. You can follow the NordVPN instructions. You have to find out which ro...
by akarpas
Wed Feb 19, 2020 4:41 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 16
Views: 6908

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

Traffic going through a VPN can not be fasttracked so please check if your traffic is not fasttracked. ok maybe my question will be too silly but how I should make that LAN witch goes via VPN is not fast-tracked while all other traffic going not via VPN is fast-tracked, thanks for the advice in adv...
by akarpas
Wed Feb 19, 2020 11:25 am
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 16
Views: 6908

Unusable speed Mikrotik-ExpressVPN(L2TP)

So quickly I need some advice. Did a set up L2TP client to ExpressVPN all works but the speed is very slow basically unusable, broadband speed is 70Mbps not much but Tunnel speed drops to something like 3-to10Mbps but the thing that looks like it has connection gaps or DNS problems as connectivity t...
by akarpas
Wed Feb 12, 2020 2:31 pm
Forum: General
Topic: Hotspot captive portal prevent automatic close on redirect after login
Replies: 28
Views: 31481

Re: Hotspot captive portal prevent automatic close on redirect after login

I found a way around this. It works like charm and have no issues.
so what is a work around
by akarpas
Tue Feb 11, 2020 10:45 pm
Forum: General
Topic: hotspot without login and redirection to promotional website
Replies: 0
Views: 2914

hotspot without login and redirection to promotional website

Hi guys. So I decided to play around with the Mikrotik feature: hotspot! Basically what I need is then the user connects to wifi he doesn't have to authenticate and is redirected to the promotional website. I found this locked topic. "That's much simpler than you think. First, create a user pro...
by akarpas
Tue Jun 25, 2019 5:42 pm
Forum: General
Topic: Mikrotik DHCP with redundant links.
Replies: 4
Views: 1500

Re: Mikrotik DHCP with redundant links.

Hey. You can practice with HSRP in Cisco Packet Tracer. And with VRRP in MikroTik world.
There is nothing to practice both vrrp and hasrp brings in to the same problem thats why i dont want to put dhcp on L3 switches
on cisco both vrrp and hsrp is supported.
by akarpas
Tue Jun 25, 2019 4:42 pm
Forum: General
Topic: Mikrotik DHCP with redundant links.
Replies: 4
Views: 1500

Mikrotik DHCP with redundant links.

So in the picture you may see the structure of the network. Any advice is appreciated . What would be the best way to set up DHCP so that VLAN devices are getting IP if one of the L3 devices is down, at the moment i see only one option to supernet IP and divide in to half and create two DHCP's with ...
by akarpas
Wed Jun 12, 2019 2:31 pm
Forum: General
Topic: IKEv2 RW VPN set up number limitation in WIN 10 [SOLVED]
Replies: 3
Views: 2165

Re: IKEv2 RW VPN set up number limitation in WIN 10 [SOLVED]

Thank you, would you have more info on powershell workaround?
sorted out , thank you again.
by akarpas
Wed Jun 12, 2019 2:31 pm
Forum: General
Topic: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED]
Replies: 7
Views: 10458

Re: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED] [SOLVED]

Hi, I have found the solution if someone should came accros the same problem. So the solution is to use powerShell and specify the CA to use: here is the example. Set-VpnConnection -Name "My VPN Connection" -MachineCertificateIssuerFilter 'C:\mycerts\cert_export_MikrotikIKEv2-CA.crt' Now ...
by akarpas
Wed Jun 12, 2019 1:35 pm
Forum: General
Topic: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED]
Replies: 7
Views: 10458

Re: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED] [SOLVED]

Hi, I have found the solution if someone should came accros the same problem. So the solution is to use powerShell and specify the CA to use: here is the example. Set-VpnConnection -Name "My VPN Connection" -MachineCertificateIssuerFilter 'C:\mycerts\cert_export_MikrotikIKEv2-CA.crt' Now ...
by akarpas
Wed Jun 12, 2019 1:12 pm
Forum: General
Topic: IKEv2 RW VPN set up number limitation in WIN 10 [SOLVED]
Replies: 3
Views: 2165

Re: IKEv2 RW VPN set up number limitation in WIN 10 [SOLVED]

Thank you, would you have more info on powershell workaround?
by akarpas
Wed Jun 12, 2019 12:35 pm
Forum: General
Topic: IKEv2 RW VPN set up number limitation in WIN 10 [SOLVED]
Replies: 3
Views: 2165

IKEv2 RW VPN set up number limitation in WIN 10 [SOLVED]

So i have IKEv2 RW set up to my home based on cert all works perfect, I have IKEv2 RW set up on office mikrotik router as well, so then i set up profile on win 10 t connect to office im getting error "IKE authentication credentials are unacceptable. Does this mean IKEv2 is not able to take the ...
by akarpas
Fri May 24, 2019 11:35 am
Forum: General
Topic: IKEv2 for Windows and iOS
Replies: 10
Views: 2012

Re: IKEv2 for Windows and iOS

Next is i found that one location from where ikev2 refuses to connect has double nat. Is where some how to go through double nat? as l2tp does it successful. Double NAT should not be an issue as such, but maybe one of the NATs is doing more or less than a plain NAT. Hm, the site from witch i cant c...
by akarpas
Thu May 23, 2019 6:01 pm
Forum: General
Topic: IKEv2 for Windows and iOS
Replies: 10
Views: 2012

Re: IKEv2 for Windows and iOS

I have 3 cert, Certificate authority, Server and Client. Now wait - 3 cert exactly as listed (CA, Server, Client) or 3 cert, one per each client (1 × Win and 2 × iOS) plus CA plus Server? Using the same certificate for all 3 clients may not be wrong but would be unusual. devices are not on the same...
by akarpas
Thu May 23, 2019 2:47 pm
Forum: General
Topic: IKEv2 for Windows and iOS
Replies: 10
Views: 2012

Re: IKEv2 for Windows and iOS

I have 3 cert, Certificate authority, Server and Client. Now wait - 3 cert exactly as listed (CA, Server, Client) or 3 cert, one per each client (1 × Win and 2 × iOS) plus CA plus Server? Using the same certificate for all 3 clients may not be wrong but would be unusual. devices are not on the same...
by akarpas
Thu May 23, 2019 11:43 am
Forum: General
Topic: IKEv2 for Windows and iOS
Replies: 10
Views: 2012

Re: IKEv2 for Windows and iOS

Does "on the same network" mean "coming from the same public IP as seen by the IPsec responder because the Windows and iOS devices are on a LAN of some NATing router"? devices are not on the same LAN, but under the same Public IP and the same NAT, I have 3 cert, Certificate auth...
by akarpas
Wed May 22, 2019 5:53 pm
Forum: General
Topic: IKEv2 for Windows and iOS
Replies: 10
Views: 2012

IKEv2 for Windows and iOS

is it possible to configure IKEv2 to work for windows and iOS paltforms at the same time.
I have Ikev2 working for windows but cant get working for iOS and whatever i do then i try to connect ipad it kills connection on windows pc's within the same network
by akarpas
Sun Mar 10, 2019 12:54 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

thanks for mangle rule, yes it register or logs packets coming via firewall from outside (internet). That mangle rule sees packets from outside that already passed through router and are leaving via the interface where y.y.y.y is connected to. You try reverse rule, to see if anything is coming back...
by akarpas
Sat Mar 09, 2019 3:39 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

akarpas I dont think you need any of those rules for the following reasons. Layer two separation is achieved by using different LANs, using Bridges, using VLANS. Thus two LANS are not layer 2 connected Two Bridges are not layer 2 connected A lan(subnet) and a bridge are not layer two connected A VL...
by akarpas
Sat Mar 09, 2019 3:32 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

akarpas I dont think you need any of those rules for the following reasons. Layer two separation is achieved by using different LANs, using Bridges, using VLANS. Thus two LANS are not layer 2 connected Two Bridges are not layer 2 connected A lan(subnet) and a bridge are not layer two connected A VL...
by akarpas
Sat Mar 09, 2019 3:20 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

Means I accidentally posted the same thing twice!
Please provide a diagram as I do not understand your setup.
Have attached simple network diagram
by akarpas
Sat Mar 09, 2019 2:49 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

You can either use Tools->Torch on interface where y.y.y.y is connected to and look for packets to y.y.y.y:<2000-2015> or you can do the same using logging rule: /ip mangle add chain=postrouting dst-address=y.y.y.y protocol=tcp dst-port=2000-2015 action=log If you see any packets, it means they suc...
by akarpas
Fri Mar 08, 2019 11:34 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

duplicate post
why duplikate post ?
by akarpas
Fri Mar 08, 2019 11:33 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

Okay some things I noted. In general only use the word LAN for one particular purpose you have LAN all over the place and its confusing. (1)/interface bridge port for WIFI missing (and by the way ethernet definition for wlan also missing)??? something like /interface bridge port add bridge=bridge L...
by akarpas
Fri Mar 08, 2019 10:07 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

post your complete config /export hide-sensitive file=yourlatestconfig # mar/08/2019 19:50:36 by RouterOS 6.44 # software id = GJR0-2DJD # # model = RouterBOARD 3011UiAS # serial number = xxxxxxxxxx /interface bridge add arp=proxy-arp name="bridge LAN" add name="bridge LAN CCTV"...
by akarpas
Fri Mar 08, 2019 6:23 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

add action=dst-nat chain=dstnat connection-type="" dst-address=a.a.a.a \ dst-port=2000-2015 in-interface=ether1-WAN protocol=tcp to-addresses=\ y.y.y.y Other than the bolded bit your rule looks right, not saying the bolded part is incorrect just dont use it. For your information, all port...
by akarpas
Fri Mar 08, 2019 4:01 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

Re: forwarded ports are closed

- ISP can be blocking some ports (check dstnat rule's packet counter if there's incoming traffic) - you may have some mistake in "/ip firewall filter" (check with torch or logging rule in postrouting if packets pass through router) - there can be some problem on a.a.a.a, service not runni...
by akarpas
Fri Mar 08, 2019 3:02 pm
Forum: General
Topic: forwarded ports are closed
Replies: 20
Views: 4413

forwarded ports are closed

/ip firewall nat add action=masquerade chain=srcnat out-interface=ether1-WAN src-address=\ x.x.x.x/24 add action=masquerade chain=srcnat out-interface=ether1-WAN src-address=\ y.y.y.y/24 add action=masquerade chain=srcnat out-interface=ether1-WAN src-address=\ z.z.z.z/22 add action=dst-nat chain=dst...
by akarpas
Sat Mar 02, 2019 12:25 pm
Forum: General
Topic: huge amount of TCP DNS queries from outside
Replies: 6
Views: 1514

huge amount of TCP DNS queries from outside

So we found that router was compromised so we have cleaned it and properly secured, but from this moment router is receiving a huge amount of packets coming form outside to DNS TCP , afcourse as i have said all this is secured and outside DNS queries are dropped. But all this traffic comming to my r...
by akarpas
Thu Dec 20, 2018 5:00 pm
Forum: General
Topic: Microtik ISP failower with the same IP
Replies: 0
Views: 745

Microtik ISP failower with the same IP

My question is : is it possible with mikrotik to configure wan failover keeping the main isp IP working. What i mean is lets say we have 2 ISP's ISP 1 gives IP x.x.x.x/x ISP2 gives IP y.y.y.y/y So if ISP 1 fails ISP2 takes over but IP of ISP 1 is still working and used as a main. Im asking this ques...
by akarpas
Wed Dec 12, 2018 4:45 pm
Forum: General
Topic: Cant ping scales from A to B but can fro C to B via IPSEC tunel
Replies: 0
Views: 651

Cant ping scales from A to B but can fro C to B via IPSEC tunel

So in short I have scales in site B, i can ping scales from any other site bur not from site A. Pinging via IPSec tunel. From site A i may ping any other device on the network as switch AP PC all of them are ok to ping but not scales . As mentioned I able to ping scales from any other site via IPSec...
by akarpas
Mon Oct 22, 2018 12:46 pm
Forum: General
Topic: what vpn protocol in client to server conf supports multi connection from the same network behind the NAT
Replies: 0
Views: 620

what vpn protocol in client to server conf supports multi connection from the same network behind the NAT

what vpn protocol in client to server conf supports multi connection from the same network behind the NAT.

PPTP is not an oprion
L2TP doesnt support not an oprtion
OpenVPN doesnt support UDP not an option.
IKEv2 what about this one??????????
by akarpas
Thu Oct 18, 2018 9:16 am
Forum: General
Topic: Cant ping one network device via GRE while able to ping all other devices.
Replies: 3
Views: 1128

Re: Cant ping one network device via GRE while able to ping all other devices.

And nothing special about x.x.x.10 in mikrotikB config?
No firewall/NAT?
On router B on NAT i have just a usual masquerada rule, and some port forward rules, on firewall just basic firewall nothing what would stop computers on A to ping specific device an site B even i can ping it from A router.
by akarpas
Wed Oct 17, 2018 11:59 pm
Forum: General
Topic: Cant ping one network device via GRE while able to ping all other devices.
Replies: 3
Views: 1128

Cant ping one network device via GRE while able to ping all other devices.

OK have added a simple network picture to simplify my description. 3 sites A, B and C GRE tunnel between A and B GRE tunnel Between C and B GRE tunnels works no problem! on site B i have device x.x.x.10 i'm able to ping that device from site C via tunnel as well as all other devices on that network....
by akarpas
Tue Oct 09, 2018 6:49 pm
Forum: General
Topic: GRE with IPSec only one ntwork works second no
Replies: 1
Views: 675

Re: GRE with IPSec only one ntwork works second no

this can be closed found the problem all networks works great now
by akarpas
Tue Oct 09, 2018 5:30 pm
Forum: General
Topic: GRE with IPSec only one ntwork works second no
Replies: 1
Views: 675

GRE with IPSec only one ntwork works second no

ok i have site A and B Created GRE Tunnel between site A and B site A networks x.x.x.x and y.y.y.y site B networks c.c.c.c so have routed networks via tunnel. x.x.x.x works with c.c.c.c with no problem all good y.y.y.y doesn't work. c.c.c.c doesn't see y.y.y.y.y while y.y.y.y is able to ping c.c.c.c...
by akarpas
Wed Sep 19, 2018 1:02 pm
Forum: General
Topic: IPSec with preshared key security warning os. 6.43.1
Replies: 6
Views: 13023

Re: IPSec with preshared key security warning os. 6.43.1

since 6.43
*) ipsec - added warning messages for incorrect peer configuration;

You can use what you want, it's just reminder.
I understand this a reminder , I know that everything can be broken, so let say i would like to know how insecure it is now lets say in scale from 1 to 10.
by akarpas
Wed Sep 19, 2018 12:34 pm
Forum: General
Topic: IPSec with preshared key security warning os. 6.43.1
Replies: 6
Views: 13023

IPSec with preshared key security warning os. 6.43.1

I have GRE with IPSec enabled with preshared key. After OS update to 6.43.1 im getting a warning that its not secure configuration and i should use certificates. But i don't see option to use certificates for GRE secured with IPSec. Let say my secret is 30 symbols long so how successful hacker would...
by akarpas
Tue Sep 18, 2018 1:18 am
Forum: General
Topic: IPsec IKE2 can find valid sertificate [SOLVED]
Replies: 13
Views: 9700

Re: IPsec IKE2 can find valid sertificate [SOLVED]

You need to import also CA, not just client cert.
you are 100% right this what i have done today and it works perfectly, you just confirmed it and you are right as always, really appreciate your input.
by akarpas
Mon Sep 17, 2018 4:38 pm
Forum: General
Topic: IPsec IKE2 can find valid sertificate [SOLVED]
Replies: 13
Views: 9700

Re: IPsec IKE2 can find valid sertificate [SOLVED]

Could someone show all steps creating certs for ikev2 for windows 10
by akarpas
Mon Sep 17, 2018 4:37 pm
Forum: General
Topic: IPsec IKE2 can find valid sertificate [SOLVED]
Replies: 13
Views: 9700

Re: IPsec IKE2 can find valid sertificate [SOLVED]

On Windows, do you have the certificate in "local machine" store? If you put it in "local user" store, which I definitely did at first, because it was more logical when I wanted VPN only for that one user, it doesn't work.
Cert is installed on local machine not user
by akarpas
Sun Sep 16, 2018 5:50 pm
Forum: General
Topic: IPsec IKE2 can find valid sertificate [SOLVED]
Replies: 13
Views: 9700

IPsec IKE2 can find valid sertificate [SOLVED]

Setting up ikev2 road worrior set up. Following step on mikrotik wiki. Cteated CA signed, created server cert signed with CA, created windows client cert signed with CA. Exported windows client cert and installed on windows 10 . No matter what i do getting error ike failed to find vald cert on local...
by akarpas
Fri Aug 31, 2018 4:48 pm
Forum: General
Topic: Mikrotik bridge vlan and tp link switch +EAP
Replies: 0
Views: 871

Mikrotik bridge vlan and tp link switch +EAP

Hi geeks need some help. I want to test and run on TP Link EAP tow wifi lans one tagged one not. 1. Mikrotik has a bridge , ports 2 to 4 are members of the bridge. 2. Bridge has assigned LAN IP adress 3 Vlan is created 1010 and goes via bridge 4 . no vlan filtering enabled This mikrtoik conf works g...
by akarpas
Wed Jun 13, 2018 5:49 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Do you have location's C IP address added as ipsec peer on the server or not??
ok i have disabled peer with C site IP address on L2tp server and it worked but this mean my ipsec tunel is down (site to site) and its not good.
by akarpas
Wed Jun 13, 2018 5:44 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Do you have location's C IP address added as ipsec peer on the server or not??
I have ipsec tunel between server and site C so yes there is ip on site to site peer ,i have disabled tunel on both sites i mean peers, ipsec policies , proposals on both sides it didnt help
by akarpas
Wed Jun 13, 2018 5:20 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

The settings on the router in the office don't matter. The settings on the home router do. If one of the home router's peers has the remote attribute set to the public IP address of the office, any IPsec ISAKMP request coming from that address matches on that peer rather than the one with remote=0....
by akarpas
Wed Jun 13, 2018 4:53 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Check if any of configured specific ipsec peer addresses do not match office address you are connecting from. Looks to me that you have peer with that IP and specified aes + modp1024 yes i have on the mikrotik router from where im connecting several IPSec tunnels (site to site) but they have their ...
by akarpas
Wed Jun 13, 2018 2:20 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

I don't get it. My settings are: /system logging add topics=ipsec and I filter the log using /log print follow-only where topics~"ipsec" And I have debug messages in the log which show the proposal coming from the peer, see example below. In your case, there are no debug messages. So some...
by akarpas
Wed Jun 13, 2018 2:09 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

I don't get it. My settings are: /system logging add topics=ipsec and I filter the log using /log print follow-only where topics~"ipsec" And I have debug messages in the log which show the proposal coming from the peer, see example below. In your case, there are no debug messages. So some...
by akarpas
Wed Jun 13, 2018 1:39 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Logs say where the error is. ROS side has configured AES and MODP 1024, remote peer supports only 3des and 2048-bit MODP , 256-bit ECP, 384-bit ECP
no where is no aes and modp 1024 set up at all 3 des and mod2048 is set up and vpn works from other 2 or 3 sites but not form this one.
by akarpas
Wed Jun 13, 2018 1:10 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

What are your exact /system logging settings? I am surprised not to see the full list of transforms in the log, only the list of rejected ones.

all the debug and log settings are as you have asked me to set up
by akarpas
Wed Jun 13, 2018 12:07 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

As said, I would like to see the log from proposal comparison for the successful and unsuccessful cases, otherwise we won't get anywhere. One thing one could easily imagine is some packet size limitation on one of the paths, causing the proposal to be truncated, except that the recipient should not...
by akarpas
Tue Jun 12, 2018 11:35 am
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

The same error or exactly the same complaints in the log? 10:23:02 ipsec rejected dh_group: DB(prop#1:trns#1):Peer(prop#1:trns#1) = 1024-bit MODP group:384-bit random ECP group 10:23:02 ipsec rejected dh_group: DB(prop#1:trns#1):Peer(prop#1:trns#2) = 1024-bit MODP group:256-bit random ECP group 10:...
by akarpas
Mon Jun 11, 2018 8:17 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

The same error or exactly the same complaints in the log? 10:23:02 ipsec rejected dh_group: DB(prop#1:trns#1):Peer(prop#1:trns#1) = 1024-bit MODP group:384-bit random ECP group 10:23:02 ipsec rejected dh_group: DB(prop#1:trns#1):Peer(prop#1:trns#2) = 1024-bit MODP group:256-bit random ECP group 10:...
by akarpas
Mon Jun 11, 2018 2:44 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

OK. The log shows you what the peer (the windows client) proposes, so configure the Mikrotik's peer proposal in a compatible way (keep Hash Algorithm unchanged as there are no complaints, add 3des to Encryption Algorithm, and add modp2048 to DH Group) and try again. I tried the same results and if ...
by akarpas
Mon Jun 11, 2018 1:43 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

So the Windows client in the office is a different one from the one you use to test it at home? Or it is the very same laptop you use at both places?
yes its the same laptop used in both places
by akarpas
Mon Jun 11, 2018 12:29 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

OK. So do the same what you did with l2tp: /system logging add topics=ipsec Then, start /log print follow-only file=ipsec-log where topics~"ipsec" , try to connect the VPN client, and when it fails, stop the /log print and download the file. Then use find&replace to obfuscate the addr...
by akarpas
Mon Jun 11, 2018 11:30 am
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Does the 'Tik running the L2TP/IPsec server have a public IP address directly on itself or you use dst-nat on some device between that 'Tik and the internet?
Mikrotik router is bridged with ISP gateway device, so static IP is on Mikrotik, all NAT is done by Mikrotik
by akarpas
Mon Jun 11, 2018 11:00 am
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Glad to help. tunnel in IPsec is related to the way how plaintext packets are encapsulated into IPsec transport ones, and it is correct that for the L2TP the tunnel mode is not used. As the establishment of L2TP session got that far, the ISP had nothing to do with the issue, as everything L2TP-rela...
by akarpas
Sun Jun 10, 2018 1:25 pm
Forum: General
Topic: self signed cert for IKE2
Replies: 5
Views: 1408

Re: self signed cert for IKE2

Have you imported the CA public cert to your Win machine?
no i have imported only the one signed with CA
by akarpas
Sat Jun 09, 2018 8:32 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Glad to help. tunnel in IPsec is related to the way how plaintext packets are encapsulated into IPsec transport ones, and it is correct that for the L2TP the tunnel mode is not used. As the establishment of L2TP session got that far, the ISP had nothing to do with the issue, as everything L2TP-rela...
by akarpas
Sat Jun 09, 2018 8:23 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Glad to help. tunnel in IPsec is related to the way how plaintext packets are encapsulated into IPsec transport ones, and it is correct that for the L2TP the tunnel mode is not used. As the establishment of L2TP session got that far, the ISP had nothing to do with the issue, as everything L2TP-rela...
by akarpas
Sat Jun 09, 2018 8:10 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Out of ideas, everything here seems fine to me. Just check one more time whether the username in Windows client matches the name in /ppp secret and whether the password settings match between the two. ok got connected , what i did ? deleted vpn profile on windows and recreated . And it worked. Than...
by akarpas
Sat Jun 09, 2018 8:03 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Out of ideas, everything here seems fine to me. Just check one more time whether the username in Windows client matches the name in /ppp secret and whether the password settings match between the two. Yep I don't understand why it doesn't work as well, as on other site it works with no problem with...
by akarpas
Sat Jun 09, 2018 7:17 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

The log shows that the Windows client doesn't respond to some of our requests after the session got established; I'm not an L2TP specialist so I don't know whether ignoring what you don't understand is a legal behaviour or not. So please post the output of the following: /interface l2tp-server serv...
by akarpas
Sat Jun 09, 2018 6:40 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

OK. Let's ignore for a while that your firewall is not safe because there is no "drop the rest" rule in input chain (i.e. you let in anything except known threats which is not a good idea), but the firewall is not the reason why the L2TP does not come up. By default, only events with seve...
by akarpas
Sat Jun 09, 2018 5:57 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Yes, there is a lot of "default" items and a complex structure of references/dependencies in the IPsec configuration. It needs some experience to realize all the relationships. If the Mikrotik reports no error but the Windows client gives up, it suggests that IPsec is already fine and the...
by akarpas
Sat Jun 09, 2018 5:50 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Yes, there is a lot of "default" items and a complex structure of references/dependencies in the IPsec configuration. It needs some experience to realize all the relationships. If the Mikrotik reports no error but the Windows client gives up, it suggests that IPsec is already fine and the...
by akarpas
Sat Jun 09, 2018 5:25 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

/log print where topics~"ipsec" is much more useful than screenshots. The log says searching for policy for selector x.x.x.x:1701 ip proto:17 <=> y.y.y.y:1701 ip proto:17 no template matches So it points back to what I've written before: Bear in mind that the automatically created peer al...
by akarpas
Sat Jun 09, 2018 5:20 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

/log print where topics~"ipsec" is much more useful than screenshots. The log says searching for policy for selector x.x.x.x:1701 ip proto:17 <=> y.y.y.y:1701 ip proto:17 no template matches So it points back to what I've written before: Bear in mind that the automatically created peer al...
by akarpas
Sat Jun 09, 2018 1:43 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Disable the manually created one and set use-ipsec to yes or require and configure the ipsec-secret in the L2TP configuration. Bear in mind that the automatically created peer always uses the policy template group called "default" and the proposal of the policy template belonging to that ...
by akarpas
Fri Jun 08, 2018 6:51 pm
Forum: General
Topic: self signed cert for IKE2
Replies: 5
Views: 1408

Re: self signed cert for IKE2

https://wiki.mikrotik.com/wiki/Manual:IP/IPsec Very detailed info that I used and works on Blackberry OS10 and Win10 clients as well. Be careful with the settings for windows clients as Microsoft does not allow very tight security regarding Phase 1 (Peer) and Phase 2 (Proposal) proposal sets. The a...
by akarpas
Fri Jun 08, 2018 5:52 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Well, you haven't pasted the log, but let's try without if first. The first issue is that you have two peers with (remote) address=0.0.0.0/0 , the one for L2TP and another one for IKEv2. I'm not sure whether the fact that the L2TP one is declared first is sufficient to let incoming connections be m...
by akarpas
Fri Jun 08, 2018 5:46 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Well, you haven't pasted the log, but let's try without if first. The first issue is that you have two peers with (remote) address=0.0.0.0/0 , the one for L2TP and another one for IKEv2. I'm not sure whether the fact that the L2TP one is declared first is sufficient to let incoming connections be m...
by akarpas
Thu Jun 07, 2018 5:45 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Use the "terminal" window of Winbox or WebFig, or a command line connection (ssh), and place the following command: /log print where topics~"ipsec" file=some-file-name Then download the file and use "find&replace" in text editor to systematically replace the public...
by akarpas
Thu Jun 07, 2018 5:08 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

Re: L2TP IPSec (no suit proposal found)

Use the "terminal" window of Winbox or WebFig, or a command line connection (ssh), and place the following command: /log print where topics~"ipsec" file=some-file-name Then download the file and use "find&replace" in text editor to systematically replace the public...
by akarpas
Thu Jun 07, 2018 4:11 pm
Forum: General
Topic: self signed cert for IKE2
Replies: 5
Views: 1408

self signed cert for IKE2

Can someone help me to create proper certificate on mikrotik to use with IKE2 on mikrotik and client.
The one i have created following mikrotik doesnt work
Thank you.
by akarpas
Thu Jun 07, 2018 1:52 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 59
Views: 61035

L2TP IPSec (no suit proposal found)

Hi guys. I have setting up L2TP IPSec tunel (client-server type). connecting form windows 10 PC. L2TP server , prifile, secret, settings I believe are ok. Then i try to connect im getting error no good proposal found phase1 failing. I did debug see attached picture. Can someone explain what is wrong...
by akarpas
Thu May 31, 2018 11:37 pm
Forum: General
Topic: RouterBOARD 962UiGS-5HacT2HnT slow speed
Replies: 0
Views: 707

RouterBOARD 962UiGS-5HacT2HnT slow speed

Hi, guys, I have RouterBOARD 962UiGS-5HacT2HnT router. My ISP give me 360Mbps download. I have basic firewall configured. ip firewall filter add action=accept chain=input comment="defconf: accept established,related" \ connection-state=established,related add action=drop chain=input commen...
by akarpas
Sun May 20, 2018 6:29 pm
Forum: General
Topic: some of ipsec tunels stopped working
Replies: 6
Views: 1643

Re: some of ipsec tunels stopped working

I've noticed a recent change around 6.42. Previously, if one side was set to tunnel 10.10.0.0/24, and the other side was set for 10.0.0.0/16, the side with the /16 defined would accept the /24 proposal. Around 6.42, it seems that flexibility disappeared. Now both routers have to have matching subne...
by akarpas
Sun May 20, 2018 6:27 pm
Forum: General
Topic: some of ipsec tunels stopped working
Replies: 6
Views: 1643

Re: some of ipsec tunels stopped working

I suspect your IPSec tunnels go down during the evening as there are no "interesting" traffic flowing through. There should be no reason to restart routers, a ping through the tunnel should suffice. Without seeing your config, very difficult to say what your current problem is Thanks for ...
by akarpas
Fri May 18, 2018 2:39 pm
Forum: General
Topic: some of ipsec tunels stopped working
Replies: 6
Views: 1643

some of ipsec tunels stopped working

I have ipsec tunnels configured , they were working fine for a long time , the sat few days every morning i come to office some of ipsec tunnels are not working after router restart they comes's back . On the next morning the same. This morning total disaster. Router was upgraded to newest version 6...
by akarpas
Tue May 15, 2018 5:10 pm
Forum: General
Topic: services are slow as hell or even unusable via ipsec tunel with this firewall conf
Replies: 2
Views: 769

Re: services are slow as hell or even unusable via ipsec tunel with this firewall conf

Disable the action=fasttrack-connection rule. If it fixes the "slow VPN" problem, read the IPsec manual one more time to learn how to disable it selectively only for traffic which needs to be matched by the IPsec policy, because otherwise you'll have an "fast VPN but slow everything ...
by akarpas
Tue May 15, 2018 3:43 pm
Forum: General
Topic: services are slow as hell or even unusable via ipsec tunel with this firewall conf
Replies: 2
Views: 769

services are slow as hell or even unusable via ipsec tunel with this firewall conf

so two sites , ipsec tunel between them, on site A we have service that is accessed from site B via ipsec tunel firewall basic recommended configuration. /ip firewall filter add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=accept chain=input comment=&qu...
by akarpas
Mon May 14, 2018 11:07 am
Forum: General
Topic: add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ [SOLVED]
Replies: 3
Views: 2381

Re: add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat  [SOLVED]

Thank you guys I really appreciated your help, both of you are right and your advise resolved my problem.
by akarpas
Sat May 12, 2018 5:38 pm
Forum: General
Topic: add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ [SOLVED]
Replies: 3
Views: 2381

add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ [SOLVED]

So i have 3(A, B, C) sites, ipsec tunnels between sites. On site C i have this rule enabled add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface=pppoe On site A i have PRTG monitoring. So PRTG icmp ...
by akarpas
Sat Apr 28, 2018 7:32 pm
Forum: General
Topic: RB962UiGS-5HacT2HnT slow LAN speed
Replies: 0
Views: 546

RB962UiGS-5HacT2HnT slow LAN speed

So need some light on about this device. Got it week ago, using basically the default configuration just with slight changes on port naming and addressing the rest seems to be good for me. Device itself works good no troubles. All LAN goes in 1Gbps negotiation with other end. I have service of 360Mb...