Community discussions

Search found 136 matches

by pokeman
Mon Feb 20, 2012 8:51 am
Forum: General
Topic: v5.13 released
Replies: 64
Views: 8282

Re: v5.13 released

Hi All,

After upgrading my router given kernel panic , already opened Ticket#2012021566000466,no response from last 5 days :(
by pokeman
Sat Dec 31, 2011 7:42 pm
Forum: General
Topic: v5.11 released
Replies: 173
Views: 44567

Re: v5.11 released

5-11 reboot after 12 hours, See the performance difference between 4.17 with 5.11
by pokeman
Fri Dec 30, 2011 9:54 pm
Forum: General
Topic: v5.11 released
Replies: 173
Views: 44567

Re: v5.11 released

Un-stable version 5-11. We are facing issue with Mikrotik with PPTP tunnels. We have core-2-duo machine but they could not handle more than 800 pptp tunnels, even we replaced xeon machine 8 core processor. finally We requested MT support to help us. As per their recomendedation we upgrade 5-11 to co...
by pokeman
Wed Aug 19, 2009 12:04 pm
Forum: General
Topic: Queue Questions + remove limit for specfied domains
Replies: 0
Views: 423

Queue Questions + remove limit for specfied domains

Gday We are running 3.28 i have question related with queue with no limit for FTP domains i am using queue tree for this its not working for me anyone have idea for this My domain ip 208.67.229.0/24 here is configuration /ip firewall address-list add address=10.0.0.0/24 list=client1 /ip firewall add...
by pokeman
Fri Jun 19, 2009 8:35 am
Forum: General
Topic: blocking patten matching
Replies: 3
Views: 663

Re: blocking patten matching

This data grep from packet sniffer . the destination is 72.20.5.98 and packet UDP
by pokeman
Thu Jun 18, 2009 8:57 pm
Forum: General
Topic: blocking patten matching
Replies: 3
Views: 663

blocking patten matching

Hi there should i block this from L7 patten matching ? using MT 3.23 4500 0404 4cbe 0000 8011 15f2 7514 11af E... L.......u... 4814 0562 042d 5000 03f0 d9b2 ddc0 5710 H..b.-P.......W. a940 d870 079f 37cf 66fd 962d c55d f48c .@.p..7.f..-.].. 24bb 53ea 831a b14a e179 11a8 40d8 7007 $.S....J.y..@.p. 9e...
by pokeman
Thu Jun 11, 2009 12:48 pm
Forum: General
Topic: Help with external Squid Proxy with Ubuntu
Replies: 8
Views: 4914

Re: Help with external Squid Proxy with Ubuntu

I realize to setup Ubuntu + Squid but I can not limit speed for clients as I do in Mikrotik web proxy. I mean when clients get staf from Internet they to get in with their real speed, e.g. 512 but when to get staff from Squid (cache content) to get with other speed e.g. 1 M. In this case I tried to...
by pokeman
Mon May 18, 2009 1:20 pm
Forum: Scripting
Topic: Logging Question ?
Replies: 3
Views: 661

Re: Logging Question ?

Thanks normis for your response

i am using 3.x any way to save logs on daily basis like MT backup.
by pokeman
Mon May 18, 2009 7:48 am
Forum: Scripting
Topic: Logging Question ?
Replies: 3
Views: 661

Re: Logging Question ?

any expert here !
by pokeman
Fri May 15, 2009 2:40 pm
Forum: Scripting
Topic: Logging Question ?
Replies: 3
Views: 661

Logging Question ?

Hi There

can any one tell me what is that mean when user log-out from pppoe session

May 13 21:46:45 172.16.0.1 pppoe,ppp,info,account account: john logged out, 2033 1270902 4283787 7668 7267
by pokeman
Tue Apr 21, 2009 12:01 pm
Forum: General
Topic: (ASK) Mikrotik Bridge as Internal Proxy (Un-Solved Mystery)
Replies: 26
Views: 3665

Re: (ASK URGENT) Mikrotik Bridge as Internal Proxy

Intresting
i am not test in MT . i used Linux+squid instead of MT and its work for me. The problem was same as you facing in MT. Add the ip addresses and gateway on bridge interface. the ip range must be your client using. e.g 192.168.1.254/24 gw 192.168.1.1 .
by pokeman
Thu Apr 16, 2009 6:34 pm
Forum: General
Topic: [Help] Non Shaping the local web server linked to the public
Replies: 7
Views: 1002

Re: [Help] Non Shaping the local web server linked to the public

i am not MT expert anyway try to use this

chain=prerouting action=mark-packet new-packet-mark=Web passthrough=no dst-address=172.16.15.15
name="web" parent=global-out packet-mark=WEB limit-at=0 queue=default priority=8 max-limit=0 burst-limit=0 burst-threshold=0 burst-time=0s
by pokeman
Fri Apr 03, 2009 4:15 pm
Forum: General
Topic: External Squid Box Logs
Replies: 5
Views: 1189

External Squid Box Logs

Hello
The following network as much similar with my network http://forum.mikrotik.com/download/file.php?id=1766
.My requirements to save logging information of my clients. In current senario only mikrotik interface ip will show in external squid box. Using x3.17

Thanks in advance
by pokeman
Fri Apr 03, 2009 1:47 pm
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

Hi omega-00


I found in logs many domain are not listed in dailyconficker list . after googing i found this url may be this will be help-out you

http://iv.cs.uni-bonn.de/wg/cs/applicat ... conficker/
by pokeman
Wed Apr 01, 2009 12:53 pm
Forum: Scripting
Topic: 1st script with too many error !
Replies: 4
Views: 805

Re: 1st script with too many error !

Thanks its working :)
by pokeman
Wed Apr 01, 2009 11:30 am
Forum: Scripting
Topic: 1st script with too many error !
Replies: 4
Views: 805

Re: 1st script with too many error !

I can't even understand what you wanted to do with that script.

The Perpose of this script grep windowsupdate host ips from dns cache and add to firewall address-list
by pokeman
Wed Apr 01, 2009 10:25 am
Forum: Scripting
Topic: 1st script with too many error !
Replies: 4
Views: 805

1st script with too many error !

Hi there i am trying to grep windows update ips from dns cache. can anyone help me out ! :foreach i in= /ip firewall address-list remove [/ip firewall address-list find list=windowsupdate][/ip dns cache find] do={n;log find [/ip dns cache get $i name] "windowsupdate"} > 0) do={info (windowsupdate:[ ...
by pokeman
Tue Mar 31, 2009 4:04 pm
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

oh bugger. Just found out that the :resolve command failing causes a script to halt in 3.X Hey Man , is that means it won't work on 3.x !!? and what about 2.x something else , should i make a firewall filter rule to block any connection to these sites ? i have a deep bad feeling about this mess , M...
by pokeman
Tue Mar 31, 2009 3:54 pm
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

If it gets the failure message it means the :resolve has failed and stops the script from continuing (the bug mentioned in my second post) If you're using opendns servers (208.67.222.222 208.67.220.220) as your dns servers this should not happen as any invalid requests will instead be returned an o...
by pokeman
Tue Mar 31, 2009 12:39 am
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

Hi There

did you found any removal tool for this worm ?
by pokeman
Mon Mar 30, 2009 4:20 pm
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

Thanks Mate Now its working but i think something wrong. The script add duplicate ips . its fine or something missing in script . Dude can you do one more thing can you make simple this script. i have also linux box and make script to fatch and export list to the file with crontab just confuse with ...
by pokeman
Mon Mar 30, 2009 1:19 pm
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

mm strange ! anyway i just tweak with this script with my linux box downloaded files on linux box then retrive to local machine. files are http://192.168.0.1/conficker/www.epicwinrar.com/conficker/ after this get sucess but 20% the script now given this error /system script run daily-conficker-list ...
by pokeman
Mon Mar 30, 2009 11:41 am
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

yeah but the previous post I did was incorrect.. when you ran /system run script XXXXX it didn't run the script at all.. because my syntax was wrong. you need to run /system script run XXXXXX it was my message to you that had an error, I've also tried the script on one of my 3.17 boxes and it works...
by pokeman
Mon Mar 30, 2009 10:32 am
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

arggh sorry, typo /system script run daily-conficker-list is what you want to do. something wrong in script when i run given error. see my last post the worm has been activated on my lan users here is my squid access log. 1238397620.731 0 192.168.0.5 TCP_DENIED/400 1481 NONE NONE:// - NONE/- text/h...
by pokeman
Mon Mar 30, 2009 9:28 am
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

Thanks for your prompt response. actully i have over 2500 user. most of the user are infacted with this virus.

here is terminal output

[admin@MikroTik] > /system run script daily-conficker-list
bad command name run (line 1 column 9)
[admin@MikroTik] >
conf.JPG
by pokeman
Sun Mar 29, 2009 4:11 pm
Forum: General
Topic: blocking windows sharing but how to allow ?
Replies: 2
Views: 581

Re: blocking windows sharing but how to allow ?

dig.JPG
currently my client download data from Ms-portal. local downloading are restricted with 64k . how can i exclude from limit
by pokeman
Sun Mar 29, 2009 2:47 pm
Forum: General
Topic: blocking windows sharing but how to allow ?
Replies: 2
Views: 581

blocking windows sharing but how to allow ?

Hi there I am using Wireless setup x3.17 RouterOS on network the user connect pppoe session. i created a rule in dhcp /32 "address=192.168.0.0/24 gateway=192.168.0.253 netmask=32 " for user blocking sharing now my user getting mask 255.255.255.255 . My Microsoft portal server on 192.168.0.4. perviou...
by pokeman
Sun Mar 29, 2009 12:29 pm
Forum: Scripting
Topic: Change ip
Replies: 1
Views: 522

Change ip

Script not working for me :( chupka you are the expert for scripting

/system scheduler add name=ip interval=24h on-event={
/ip address remove [find address=111.222.333.444/32];
/ip address add address=111.222.333.555/32 interface=wan ;
}
by pokeman
Sun Mar 29, 2009 12:19 pm
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

got error when i post the script on terminal window
conf.JPG
by pokeman
Sun Mar 29, 2009 12:02 pm
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

Yes, as noted in my post above, I only found out after finishing the scrip that the mikrotik :resolve command is currently broken, any failed resolution simple forces the script to quit, hence using opendns is the only way I see to get it to complete at this time.. too bad we've got no other soluti...
by pokeman
Sat Mar 28, 2009 9:42 am
Forum: Scripting
Topic: Script to identify conficker (virus infected) users
Replies: 43
Views: 18046

Re: Script to identify conficker (virus infected) users

Hi there i use this script in x3.17 its not working for me i just modified the script to check they resolve the ips . i created the file name conf.txt and put the all domain which listed on site. i used opendns for nameserver :local content [/file get [/file find name="conf.txt"] contents] ; :local ...
by pokeman
Sun Jan 11, 2009 4:11 pm
Forum: Scripting
Topic: Youtube limit queue
Replies: 4
Views: 2752

Re: Youtube limit queue

can anyone find out the error

youtube.JPG
by pokeman
Mon Dec 29, 2008 12:42 pm
Forum: General
Topic: X86 clock issue
Replies: 12
Views: 2007

Re: X86 clock issue

can you guide me how to setup NTP and sync with system time
by pokeman
Sat Dec 27, 2008 9:59 pm
Forum: General
Topic: how to kick ppp user from CLI
Replies: 1
Views: 548

how to kick ppp user from CLI

Hi There

how to kick ppp user from CLI any one guide me i am trying with this its not working any idea ? e.g user=abcd
/ppp active remove [find user=abcd]
by pokeman
Sat Dec 27, 2008 7:11 am
Forum: General
Topic: ftp attack
Replies: 2
Views: 825

ftp attack

Hi there

here is my log
system,error,critical login failure for user Open from 212.100.64.11 via ftp

ftp server are already disable but still i found the error

how to block host and port from wan interface
by pokeman
Fri Dec 26, 2008 11:13 am
Forum: General
Topic: How to redirect to external proxy
Replies: 30
Views: 38236

Re: How to redirect to external proxy

send me your msn addresses latter on we will do a remote session

I tried this but does not worked.
by pokeman
Thu Dec 25, 2008 9:47 pm
Forum: Scripting
Topic: script not working 3.17
Replies: 1
Views: 487

script not working 3.17

script not working any one please correct
:for i from=2 to=254 do={/queue simple add target-address=(192.168.0 . $i /32 ) max-limit=20000/64000}
by pokeman
Thu Dec 25, 2008 7:42 pm
Forum: General
Topic: How to redirect to external proxy
Replies: 30
Views: 38236

Re: How to redirect to external proxy

try out this with policy routing setup you linux external server with transparent proxy with NAT and mark 80 traffic and redirect to the linux gateway /ip firewall mangle add chain=prerouting protocol=tcp dst-port=80 action=mark-routing new-routing-mark=HTTP passthrough=yes comment="" disabled=no /i...
by pokeman
Thu Dec 25, 2008 9:29 am
Forum: General
Topic: X86 clock issue
Replies: 12
Views: 2007

Re: X86 clock issue

HI There

i have issue system clock they reset every day 00:00 and the time was default Jan/11/2004
by pokeman
Tue Dec 23, 2008 8:00 pm
Forum: Scripting
Topic: Netwatch with some modification required
Replies: 9
Views: 1162

Re: Netwatch with some modification required

SurferTim waiting for script !
by pokeman
Mon Dec 22, 2008 10:45 am
Forum: Scripting
Topic: Netwatch with some modification required
Replies: 9
Views: 1162

Re: Netwatch with some modification required

you are right !
by pokeman
Mon Dec 22, 2008 8:48 am
Forum: Scripting
Topic: Netwatch with some modification required
Replies: 9
Views: 1162

Re: Netwatch with some modification required

thanks for your response actually some of our client using DDC Mirc chat due to some issue the admin block the ip addresses. e.g host addresses irc.eunet.net now i need if the ping not answer with the following host my ip public ip change then trying to ping again. 2nd time again ping to host again ...
by pokeman
Sun Dec 21, 2008 1:21 pm
Forum: General
Topic: how to block voip using L7
Replies: 1
Views: 894

how to block voip using L7

Hi there

can i block voip applicaiton using L7. sip now using random port we cannot block by port :(
by pokeman
Sun Dec 21, 2008 1:04 pm
Forum: Scripting
Topic: Netwatch with some modification required
Replies: 9
Views: 1162

Re: Netwatch with some modification required

hi there

waiting for solution
Chupaka ! normis ! scripting master !!
by pokeman
Fri Dec 19, 2008 1:26 pm
Forum: Scripting
Topic: Netwatch with some modification required
Replies: 9
Views: 1162

Netwatch with some modification required

Hi There i need script to change interface ip if the destination ping timeout we have 4 public ip e.g 10.0.0.2, 10.0.0.3, 10.0.0.4 and single gateway 10.0.0.1 According to check every ip one by one :local i 0; {:do {:set i ($i + 1)} while (($i < 5) && ([/ping 72.14.207.104 interval=3 count=1]=1)}; :...
by pokeman
Wed Dec 17, 2008 12:40 pm
Forum: General
Topic: Rate limit of PPPoE
Replies: 12
Views: 2945

Re: Rate limit of PPPoE

simple queue based on single ip can we manage based on network /24 /23 . please give me some examples
by pokeman
Tue Dec 16, 2008 12:39 pm
Forum: General
Topic: Rate limit of PPPoE
Replies: 12
Views: 2945

Re: Rate limit of PPPoE

any other way to manage bandwidth instead of PCQ
increase it upto 7000-10000 at least and see whether drops conlinue
by pokeman
Tue Dec 16, 2008 12:14 pm
Forum: General
Topic: Rate limit of PPPoE
Replies: 12
Views: 2945

Re: Rate limit of PPPoE

around 350 to 500 session currently set 'pcq-total-limit=2000
if you have many concurrent users, increase 'pcq-total-limit=' value
by pokeman
Tue Dec 16, 2008 11:51 am
Forum: General
Topic: Rate limit of PPPoE
Replies: 12
Views: 2945

Re: Rate limit of PPPoE

normis can you give me idea about this ? using MT 3.17 i have same issue with this when i was creating user queue with dynamic its working perfectly but when i change to static entry with pcq is getting packet drop on client . lots of dynamic queue takes system usage thats why we need to set static ...
by pokeman
Tue Dec 16, 2008 11:28 am
Forum: General
Topic: Rate limit of PPPoE
Replies: 12
Views: 2945

Re: Rate limit of PPPoE

i have same issue with this when i was creating user queue with dynamic its working perfectly but when i change to static entry with pcq is getting packet drop on client . lots of dynamic queue takes system usage thats why we need to set static entry. i need CIR bandwidth to every user /queue type p...
by pokeman
Mon Dec 15, 2008 10:19 am
Forum: General
Topic: how to stop network sharing between pppoe user
Replies: 4
Views: 726

Re: how to stop network sharing between pppoe user

can you give me idea ? how can i build
I am not familiar with usermanagement in mikrotik. i am using a dedicated radiusserver to manage useraccounts and limitations.
by pokeman
Mon Dec 15, 2008 9:46 am
Forum: General
Topic: how to stop network sharing between pppoe user
Replies: 4
Views: 726

Re: how to stop network sharing between pppoe user

thx captainproton its working can you give me idea how can i manage different PPP profile with usermanager let say we have different packages and have to manage with usermanager. usermanager create dynamic bandwidth i using static entry for different pool
by pokeman
Sun Dec 14, 2008 6:12 pm
Forum: General
Topic: how to stop network sharing between pppoe user
Replies: 4
Views: 726

how to stop network sharing between pppoe user

hi there
i have following question related with MT

1. ) i am using 3.17 L5 i want stop sharing between pppoe client only selected host allow for sharing

2. ) how to import hotspot user accounts in user-manager

3. ) can i create custom page for client reset own password ?
by pokeman
Wed Sep 03, 2008 10:43 pm
Forum: General
Topic: Pain of Fail-Over (second route)
Replies: 2
Views: 825

Re: Pain of Fail-Over (second route)

AOA
find netwatch and use custom scripts to check your external host
by pokeman
Sun Aug 31, 2008 12:36 pm
Forum: General
Topic: How to Login
Replies: 5
Views: 856

Re: How to Login

if the static ip on the ADSL interface use Portforwording option from your ADSL modem .or if you have dynamic ip on ADSL configure dynamic dns client and create dns name for your modem ip
by pokeman
Thu Aug 28, 2008 1:16 pm
Forum: General
Topic: high priority
Replies: 14
Views: 3126

Re: high priority

Any time :D
can you give me idea about this
http://forum.mikrotik.com/viewtopic.php?f=2&t=25958
by pokeman
Wed Aug 27, 2008 9:46 pm
Forum: General
Topic: high priority
Replies: 14
Views: 3126

Re: high priority

thanks mate this really help me out to Qos
by pokeman
Wed Aug 27, 2008 2:38 pm
Forum: General
Topic: firewall feature suggestion
Replies: 4
Views: 1824

Re: firewall feature suggestion

i was working on a script and address-list to do this, if i ever finish it i will post it.
hi changeip your script its really important please post it
by pokeman
Wed Aug 27, 2008 10:34 am
Forum: General
Topic: high priority
Replies: 14
Views: 3126

Re: high priority

These are queue trees not simple queues. if you mark just one type of traffic and set it to priority 1 it takes no priority over non-prioritized traffic. Thats why you have to mark all traffic as 8 or so and just up the priority on what you want to have priority (with other mangle rules). thanks fo...
by pokeman
Wed Aug 27, 2008 10:10 am
Forum: Beginner Basics
Topic: I want to show Google page to the customer only once
Replies: 10
Views: 2117

Re: I want to show Google page to the customer only once

Suppose That : I want to show Google page to the customer only once. When I request any page showing me first page Google. For example: When I write in the first request for me ---> http://www.YAHOO.com ---showing---->www.google.com When I write in the Second request for me ---> http://www.YAHOO.co...
by pokeman
Wed Aug 27, 2008 10:08 am
Forum: Beginner Basics
Topic: External Proxy
Replies: 10
Views: 1897

Re: External Proxy

can you post the configuration
by pokeman
Wed Aug 27, 2008 6:40 am
Forum: General
Topic: high priority
Replies: 14
Views: 3126

Re: high priority

Hi NickOlsen

if you are creating the simple queue the default priority is 8 then why we are going to mark other traffic ?
by pokeman
Tue Aug 26, 2008 12:30 pm
Forum: General
Topic: More ways to earn free licenses!
Replies: 162
Views: 73893

Re: More ways to earn free licenses!

pokeman: thanks, looks much better now!
omega: not sure why is that. can you paste the ticket number?
Ticket # 2008082366000135
Mikrotik Login # abakali
by pokeman
Tue Aug 26, 2008 8:05 am
Forum: General
Topic: high priority
Replies: 14
Views: 3126

Re: high priority

Hi There i am not geek for MT but here is configuration. if i am getting wrong please correct this ether1 = WAN /ip firewall mangle add chain=prerouting in-interface=ether1 protocol=tcp src-port=15779 action=mark-packet new-packet-mark=silkroad_in passthrough=no add chain=postrouting out-interface=e...
by pokeman
Tue Aug 26, 2008 7:52 am
Forum: General
Topic: Squid + Mikrotik = problem load images
Replies: 2
Views: 1854

Re: Squid + Mikrotik = problem load images

Hi There please explane your network. what i thing that you have 3 gateway ip and mark packet route to the specfied gateway and this gateway install squid box if you have single gateway this article might be help you out http://wiki.mikrotik.com/wiki/External_Squid_Box_with_No_Limit_Cache_HIT_Object...
by pokeman
Mon Aug 25, 2008 6:26 pm
Forum: General
Topic: hotspot dynamic queue multiple profile
Replies: 5
Views: 2535

Re: hotspot dynamic queue multiple profile

Hey, I haven't used hotspot ;) But if you have packet mark it makes everything very simple. 1) Create pcq queue types for each profile 2) Create simple queues for each pcq queue type and assign unique packet mark 3) Assign packet mark for each hotspot user 4) Disable dynamic rate-limit Later I'll t...
by pokeman
Mon Aug 25, 2008 2:33 pm
Forum: General
Topic: More ways to earn free licenses!
Replies: 162
Views: 73893

Re: More ways to earn free licenses!

Squid Configure with Mark cache hit object in 2.9x http://wiki.mikrotik.com/wiki/How_to_configure_External_Squid_Box_setup_Cache_HIT_with_No_Limits_with_Mikrotik_2.9 1. try to make short URLs that explain the theme, but are not as long as this one 2. use proper WIKI formating, get inspiration from ...
by pokeman
Mon Aug 25, 2008 10:17 am
Forum: Scripting
Topic: Please can anybody make script?
Replies: 3
Views: 1120

Re: Please can anybody make script?

If you could please give more detail and when you would use such a script.

-Louis
here is link http://forum.mikrotik.com/viewtopic.php?f=9&t=26169
by pokeman
Mon Aug 25, 2008 10:16 am
Forum: General
Topic: hotspot dynamic queue multiple profile
Replies: 5
Views: 2535

Re: hotspot dynamic queue multiple profile

Hey, Create static queues and assign users a static ip address instead of dynamic queues. It'll solve your problem. Regards, KT thx for your reply i am using hotsopt and clients are dhcpd in hotsopt have different profile ref to this url http://wiki.mikrotik.com/wiki/Different_limits_for_Local/Over...
by pokeman
Sun Aug 24, 2008 10:01 pm
Forum: Scripting
Topic: adding ip in Addresses list
Replies: 0
Views: 978

adding ip in Addresses list

i am using hotsopt on login i set the script to add ip in address-list my firewall only allow the address-list ip below script is not working any one give me idea ?


/ip firewall address-list add address= $(ip) list=new
by pokeman
Sun Aug 24, 2008 9:18 pm
Forum: Scripting
Topic: Please can anybody make script?
Replies: 3
Views: 1120

Re: Please can anybody make script?

Hi, please could you make script to look for ip address in address list(in ROS 2.9) and if there will be that ip then to enable the rule in firewall.


Thanks a lot and sorry but I have no idea how to do that.


good questions ! i am looking same thing :S
by pokeman
Sun Aug 24, 2008 12:05 pm
Forum: General
Topic: CIR bandwidth ?
Replies: 7
Views: 2080

Re: CIR bandwidth ?

I dont know why the client cant get the CIR ??
we already sell CIR , our clients got a straight line at the graph ..

Samsoft can you review this post

http://forum.mikrotik.com/viewtopic.php?f=2&t=25958
by pokeman
Sat Aug 23, 2008 8:33 pm
Forum: General
Topic: CIR bandwidth ?
Replies: 7
Views: 2080

Re: CIR bandwidth ?

Yes you can get CIR bandwidth .. if you have available bandwidth for that .. but if you want to test it you have to download more than 1 file at the same time to reach the max speed , anyway the bandwidth in your case which is 128k it doesnt need more than 1 file to test the CIR .. hi samsoft the c...
by pokeman
Sat Aug 23, 2008 2:43 pm
Forum: General
Topic: CIR bandwidth ?
Replies: 7
Views: 2080

Re: CIR bandwidth ?

You can not force a computer to download at a minimum speed....thats why I think CIR i s somehow stupid.
but the client end downloading fluctuating speed e.g 8, 16, 14, 10, 7 kb
by pokeman
Sat Aug 23, 2008 1:23 pm
Forum: General
Topic: More ways to earn free licenses!
Replies: 162
Views: 73893

Re: More ways to earn free licenses!

Squid Configure with Mark cache hit object in 2.9x

http://wiki.mikrotik.com/wiki/How_to_co ... krotik_2.9
by pokeman
Sat Aug 23, 2008 8:49 am
Forum: General
Topic: CIR bandwidth ?
Replies: 7
Views: 2080

CIR bandwidth ?

Hi All its a very strange problem i am using hotspot dynamic queues are bandwidth problem here is attached snapshot .how can i set CIR bandwidth
by pokeman
Thu Aug 21, 2008 1:04 pm
Forum: General
Topic: hotspot dynamic queue multiple profile
Replies: 5
Views: 2535

Re: hotspot dynamic queue multiple profile

no reply since 2 weeks :( any expert here
by pokeman
Thu Aug 14, 2008 1:36 pm
Forum: General
Topic: hotspot dynamic queue multiple profile
Replies: 5
Views: 2535

hotspot dynamic queue multiple profile

we have multiple hotspot user profile /ip hotspot user profile print Flags: * - default 0 * name="dimond" idle-timeout=4h keepalive-timeout=none status-autorefresh=20m shared-users=1 rate-limit="384k/384k" transparent-proxy=no 1 name="super" idle-timeout=8h keepalive-timeout=none status-autorefresh=...
by pokeman
Mon Feb 25, 2008 2:13 pm
Forum: General
Topic: load balance with hotspot
Replies: 2
Views: 600

load balance with hotspot

anybody works with hotspot with loadbalance. currently i am using hotspot on 4000 users all are connected with one subnet how to load balance with 2 hotspot server
by pokeman
Sat Feb 23, 2008 9:18 pm
Forum: General
Topic: too many close connection
Replies: 4
Views: 1615

Re: too many close connection

well i think you are not here to support the issue. perviously post my issue
http://forum.mikrotik.com/viewtopic.php?f=2&t=21188
byetheway where the place i am comming in few mins :)))))
by pokeman
Tue Feb 12, 2008 1:10 pm
Forum: General
Topic: Marking traffic 80 and others
Replies: 0
Views: 657

Marking traffic 80 and others

Hello MT with reference to the link http://wiki.mikrotik.com/wiki/Load_Balancing_over_Multiple_Gateways i am making some marking tarffic with different gateways i am using squid proxy another machine here is my conf this configuration is correct all traffic out from ether2 except 80 port ? ether 1 L...
by pokeman
Sat Feb 02, 2008 4:40 pm
Forum: General
Topic: same ip same gateway !
Replies: 4
Views: 680

Re: same ip same gateway !

its pptp client first my isp given ip and gateway ip 192.168.101.50 subnet 255.255.255.0 gw 192.168.101.1 dns 192.168.101.1 when dial pptp connection my ip change ip 10.10.10.3 subnet 255.255.255.255 gw 10.10.10.3 dns xxx.xxx.xxx.xxx i test on my xp machine its working then i setup to mt first i cre...
by pokeman
Sat Feb 02, 2008 3:43 pm
Forum: General
Topic: same ip same gateway !
Replies: 4
Views: 680

same ip same gateway !

hello MT gurus

its very strange my isp given me same ip and the same gateway e.g

ip 10.10.10.5
subnet 255.255.255.255
gw 10.10.10.5

dns xxx.xxx.xxx.xxx

can anybody tell me how to add this in my Mt i am using mt 2.9
by pokeman
Sun Jan 27, 2008 6:44 pm
Forum: General
Topic: critical issue 98mb flood packets
Replies: 11
Views: 2176

Re: critical issue 98mb flood packets

hi mate
by pokeman
Sun Jan 27, 2008 1:36 pm
Forum: General
Topic: critical issue 98mb flood packets
Replies: 11
Views: 2176

Re: critical issue 98mb flood packets

no result still attacker on my interface their is any way to limit this attacker packet this is udp packet actully user infacted with BHO virus
by pokeman
Sat Jan 26, 2008 8:31 am
Forum: General
Topic: critical issue 98mb flood packets
Replies: 11
Views: 2176

Re: critical issue 98mb flood packets

again attack !!!

i already make this rule
/ip firewall mangle print
chain=prerouting tos=normal packet-size=1052 action=mark-packet new-packet-mark=DROPITHBO passthrough=no

/ip firewall filter print
chain=forward packet-mark=DROPITHBO action=drop
by pokeman
Wed Jan 23, 2008 11:53 am
Forum: General
Topic: Help with bandwidth control in mikrotik + external proxy
Replies: 23
Views: 11680

Re: Help with bandwidth control in mikrotik + external proxy

hello sunday idajili thanks for your guidness the following steps are complete ! 1 . patch my external squid cache with ZPH 2. add ZPH setting in squid.conf step 3 are not working i can see any packets in my mangle here is mangle rule /ip firewall mangle print chain=output out-interface=lan tos=48 a...
by pokeman
Tue Jan 22, 2008 9:49 am
Forum: General
Topic: critical issue 98mb flood packets
Replies: 11
Views: 2176

Re: critical issue 98mb flood packets

thanks for your suggestion !
by pokeman
Mon Jan 21, 2008 3:32 pm
Forum: General
Topic: critical issue 98mb flood packets
Replies: 11
Views: 2176

Re: critical issue 98mb flood packets

hello MT

nobody have any clue about this issue ?
by pokeman
Sat Jan 19, 2008 12:37 pm
Forum: General
Topic: Help with bandwidth control in mikrotik + external proxy
Replies: 23
Views: 11680

Re: Help with bandwidth control in mikrotik + external proxy

well let me clear my senario 3 interface card Mkrotik 1 Lan connection xxx.xxx.xxx.1/23 2 wan connection a.b.c.112/29 3 Cache connection 10.10.10.1/24 squid box connected with this interface squid box 1 cache connection 10.10.10.2/24 squid running 8080 2 wan connection a.b.c.113/29 /ip filter nat pr...
by pokeman
Sat Jan 19, 2008 8:14 am
Forum: General
Topic: Help with bandwidth control in mikrotik + external proxy
Replies: 23
Views: 11680

Re: Help with bandwidth control in mikrotik + external proxy

hi GuJack20

This rule not working i am using 2.9.27

chain=output out-interface=lan tos=48 action=mark-packet new-packet-mark=proxy-hit passthrough=no
by pokeman
Sat Jan 19, 2008 12:06 am
Forum: General
Topic: critical issue 98mb flood packets
Replies: 11
Views: 2176

Re: critical issue 98mb flood packets

i just set this mangle rule **** Mangle Rule chain=prerouting tos=normal packet-size=1052 action=mark-packet new-packet-mark=DPHBO passthrough=yes *****firewall rule chain=forward packet-mark=DROPITHBO action=drop chain=input packet-mark=DROPITHBO action=drop after this rule my system goes 100% when...
by pokeman
Fri Jan 18, 2008 9:03 pm
Forum: General
Topic: critical issue 98mb flood packets
Replies: 11
Views: 2176

critical issue 98mb flood packets

dear all this is critical issue my lan interface is block .then i sniff the packets here is detail . how to block this packets from my lan interface 0 0.26 ether1 10.0.6.253:1377 218.30.20.210:5909 udp 1052 1 0.26 ether1 10.0.6.253:1383 218.30.20.210:5909 udp 1052 2 0.26 ether1 10.0.6.253:1395 218.3...
by pokeman
Fri Jan 18, 2008 7:46 pm
Forum: General
Topic: Routing Mark Problem/Question for incoming connections
Replies: 11
Views: 1493

Re: Routing Mark Problem/Question for incoming connections

hello

hi urbi still this issue not resolve

waiting your reply
by pokeman
Fri Jan 18, 2008 3:43 pm
Forum: General
Topic: web Traffic different gateway
Replies: 1
Views: 495

web Traffic different gateway

dear all

i have 2 isp bandwidth how to transfer web traffic on the isp 1 and all traffic goes to isp 2 i know this will make posible using mangle rules any one explane in detail
by pokeman
Fri Jan 18, 2008 3:17 pm
Forum: General
Topic: too many close connection
Replies: 4
Views: 1615

Re: too many close connection

thx normis what about this connections actully i have arround 15455 connection at the moment and lots of virus attacks what are the best practices for this condition 1993 0 10.0.5.92 24.150.225.112 23h59m44s 1994 0 10.0.4.162 83.178.27.213 23h59m44s 1995 0 10.0.3.228 83.20.231.195 23h59m44s 1996 0 1...
by pokeman
Fri Jan 18, 2008 9:25 am
Forum: General
Topic: too many close connection
Replies: 4
Views: 1615

too many close connection

hello community here is my connection tracking setting /ip firewall connection tracking print enabled: yes tcp-syn-sent-timeout: 5s tcp-syn-received-timeout: 5s tcp-established-timeout: 1d tcp-fin-wait-timeout: 10s tcp-close-wait-timeout: 10s tcp-last-ack-timeout: 10s tcp-time-wait-timeout: 10s tcp-...
by pokeman
Wed Jan 16, 2008 5:14 pm
Forum: General
Topic: bind another mac on ether1
Replies: 1
Views: 555

bind another mac on ether1

dear all

i am using MT 2.9.27 can anybody tell me how to change my ether1 actully i bind my ip and mac on client pcs suddenly my ether1 lan card failed
by pokeman
Mon Jan 14, 2008 1:41 pm
Forum: General
Topic: arp poisner
Replies: 3
Views: 662

Re: arp poisner

yes zaymran its working with multipul gateway you are apply this rule on your lan interface.
by pokeman
Sat Jan 12, 2008 7:32 pm
Forum: General
Topic: arp poisner
Replies: 3
Views: 662

Re: arp poisner

hello


go to your dhcp server and select add arp then disable arp request on your lan card then make a static entry for MT server at your client end
by pokeman
Tue Jan 08, 2008 9:30 am
Forum: General
Topic: Traffic priority
Replies: 5
Views: 6568

Re: Traffic priority

hi Hasbullah

please read my pervious post i send my conf please correct this
by pokeman
Sat Jan 05, 2008 12:13 pm
Forum: General
Topic: Traffic priority
Replies: 5
Views: 6568

Re: Traffic priority

hello this is is not working may be some mistake any body correct this mangle rule chain=forward action=mark-packet new-packet-mark=other passthrough=yes chain=forward connection-mark=HTTP_Traffic action=mark-packet new-packet-mark=HTTP_Packet passthrough=no chain=prerouting protocol=tcp dst-port=80...
by pokeman
Thu Jan 03, 2008 3:56 pm
Forum: General
Topic: Traffic priority
Replies: 5
Views: 6568

Traffic priority

hello

how to priority 1 below ports rest of all traffic on low priority . how can i do this ???


tcp 80,443,1863,5100
udp 53
by pokeman
Wed Jan 02, 2008 3:40 pm
Forum: General
Topic: Routing Mark Problem/Question for incoming connections
Replies: 11
Views: 1493

Re: Routing Mark Problem/Question for incoming connections

well i post my issue in my pervious post please read !!!
by pokeman
Tue Jan 01, 2008 9:51 pm
Forum: General
Topic: mangle rules stop web traffic
Replies: 2
Views: 605

Re: mangle rules stop web traffic

still waiting ?
by pokeman
Sun Dec 30, 2007 8:02 pm
Forum: General
Topic: mangle rules stop web traffic
Replies: 2
Views: 605

mangle rules stop web traffic

hello i setup load balance from the following link http://wiki.mikrotik.com/wiki/Load_Balancing_over_Multiple_Gateways its working fine now i turn on web-proxy and setup to 80 port traffic to 8080 chain=dstnat in-interface=ether1 protocol=tcp dst-port=80 action=redirect to-ports=8080 mt squid its no...
by pokeman
Sun Dec 30, 2007 12:27 am
Forum: General
Topic: Routing Mark Problem/Question for incoming connections
Replies: 11
Views: 1493

Re: Routing Mark Problem/Question for incoming connections

thanks dude for your prompt reply lets assume both are dsl and i forworded 8291 from uplink1 connection ether2 , ether 3 dsl don't have static ip . i hope you understand my question . send me your email i am online right now at msn Does your MT have the public IPs assigned to its interfaces and did ...
by pokeman
Sat Dec 29, 2007 11:32 pm
Forum: General
Topic: Routing Mark Problem/Question for incoming connections
Replies: 11
Views: 1493

Re: Routing Mark Problem/Question for incoming connections

i have 2 dsl 1 is static ip and second is on dhcpd isp assing ip . i make port forwording 8291 to the dsl 1 ether2 simple senario all traffic route to ether3 except 80 on ether1 and i could connect winbox from remote location i apply this rules based on your rules. this not working make any mistake ...
by pokeman
Sat Dec 29, 2007 6:50 pm
Forum: General
Topic: PPTP question ?
Replies: 3
Views: 654

Re: PPTP question ?

thanks

its working now . another task cisco vpn with mt .. any example paste me


Turn on Proxy ARP on the LAN interface of the MT VPN box.

Regards

Andrew
by pokeman
Sat Dec 29, 2007 6:48 pm
Forum: General
Topic: Routing Mark Problem/Question for incoming connections
Replies: 11
Views: 1493

Re: Routing Mark Problem/Question for incoming connections

hi dude can you post you conf ? I tried about an hour, than I posted the topic and a few minutes later, I found out that I just have to add the "default" gateway again without a routing mark. Well, it's far past midnight here ;-) Thanks, uebi PS: I didn't delete the topic, because maybe somebody has...
by pokeman
Sat Dec 29, 2007 6:32 pm
Forum: General
Topic: load balance with muliple dsl .. really this is matrix
Replies: 10
Views: 1556

Re: load balance with muliple dsl .. really this is matrix

thx patagonia well today i just add 2 more lan card in the machine can you please give me some example how to make this ??? thanks and regards Hi Pokeman the best solution is an rb153, you can put the lan in ether1 and ether2,3 & 4 the adsl routers, don't forget to change the ip ranges, then rot to ...
by pokeman
Mon Dec 24, 2007 4:05 pm
Forum: General
Topic: PPTP question ?
Replies: 3
Views: 654

PPTP question ?

i setup pptp from http://www.mikrotik.com/testdocs/ros/2.9/interface/pptp_content.php#5.29.5.4 Connecting a Remote Client via PPTP Tunnel my client sucessfully connected with my pptp server but i could not ping my network machine excepted my mikrotik server i check the client configuration the ip an...
by pokeman
Mon Dec 24, 2007 8:24 am
Forum: General
Topic: load balance with muliple dsl .. really this is matrix
Replies: 10
Views: 1556

Re: load balance with muliple dsl .. really this is matrix

So....where is the question?

i edit my post see the top
by pokeman
Sun Dec 23, 2007 10:15 pm
Forum: General
Topic: load balance with muliple dsl .. really this is matrix
Replies: 10
Views: 1556

Re: load balance with muliple dsl .. really this is matrix

... and it's working well as desire? If yes thanks to mikrotik.

hello dude

i need solution ?????
by pokeman
Sun Dec 23, 2007 6:15 pm
Forum: General
Topic: load balance with muliple dsl .. really this is matrix
Replies: 10
Views: 1556

load balance with muliple dsl .. really this is matrix

Need Solution for this !!! i have 2 interface 1 is connected with our lan and 1 is connected with wan on wan connection I have 3 dsl connection nated with dsl DSL ips 1. 192.168.0.2/24 2. 192.168.0.3/24 3. 192.168.0.4/25 Mikrotik ip Wan 192.168.0.5/24 ether2 lan 10.10.10.0/23 ether1 Write now I add ...
by pokeman
Tue Oct 16, 2007 7:57 pm
Forum: General
Topic: Mikrotik + Web Proxy Queueing is Impossible ?
Replies: 101
Views: 28217

Re: Mikrotik + Web Proxy Queueing is Impossible ?

thanks mac86

for your give hint . i make posible this to my linux box ! :) over 20 mb wan link and 2000 users are running well since 3 days ! thanks again
by pokeman
Thu Oct 04, 2007 2:28 pm
Forum: General
Topic: Mikrotik + Web Proxy Queueing is Impossible ?
Replies: 101
Views: 28217

Re: Mikrotik + Web Proxy Queueing is Impossible ?

thanks mac
i am apply this on my linux box i am getting some error .please check your email

waiting your positive response
by pokeman
Tue Oct 02, 2007 10:45 am
Forum: General
Topic: no-bandwidth limit for selected destination websites
Replies: 6
Views: 1172

Re: no-bandwidth limit for selected destination websites

i create this rules ... still not working mangle rules 0 chain=forward src-address-list=bandwidth dst-address-list=bandwidth action=mark-connection new-connection-mark=limit_conn passthrough=yes 1 chain=forward connection-mark=limit_conn action=mark-packet new-packet-mark=nolimit passthrough=yes 2 c...
by pokeman
Mon Oct 01, 2007 1:27 pm
Forum: General
Topic: Mikrotik + Web Proxy Queueing is Impossible ?
Replies: 101
Views: 28217

Re: Mikrotik + Web Proxy Queueing is Impossible ?

hello

can anyone guide me how can i do this on my linux machine i have 700 clients i switch my clients on MT but not running fine and getting lots of system resources . thats way i want to done on linux distro
by pokeman
Mon Oct 01, 2007 12:16 pm
Forum: General
Topic: no-bandwidth limit for selected destination websites
Replies: 6
Views: 1172

Re: no-bandwidth limit for selected destination websites

i create this rule
/queue simple

name="test-no-limit" dst-address=xxx.xxx.xxx.xxx/32 interface=all parent=none direction=both priority=8
queue=default-small/default-small limit-at=0/0 max-limit=0/0 total-queue=default-small

this not working any idea ?
by pokeman
Fri Sep 28, 2007 10:45 am
Forum: General
Topic: no-bandwidth limit for selected destination websites
Replies: 6
Views: 1172

Re: no-bandwidth limit for selected destination websites

Hi,

Use static DNS entries to lock hotmail to one IP, then simply slap a queue on that IP and Bob's your uncle.

i am asking to gurus .. :shock:
by pokeman
Fri Sep 28, 2007 8:12 am
Forum: General
Topic: no-bandwidth limit for selected destination websites
Replies: 6
Views: 1172

no-bandwidth limit for selected destination websites

hello my senario is using Hotsopt and client set bandwidth via hotsopt profile and create Dynamic rules for bandwidth . the bandwidth is 128k down / 64 up . my question their is any way to exclude some website to unlimit access e.g client open hotmail.com 128k down /64k up client open mkrotik.com no...
by pokeman
Tue Sep 25, 2007 11:46 am
Forum: General
Topic: System hangs !
Replies: 1
Views: 421

System hangs !

hello system conf uptime: 2d23h4m57s version: "2.9.27" free-memory: 787464kB total-memory: 905768kB cpu: "Intel(R)" cpu-frequency: 1794MHz cpu-load: 3 free-hdd-space: 37428528kB total-hdd-space: 38448304kB write-sect-since-reboot: 240168 write-sect-total: 3215408 web-proxy conf enabled: yes src-addr...
by pokeman
Fri Sep 21, 2007 10:27 am
Forum: General
Topic: Load Balance with Fail Over
Replies: 15
Views: 9921

Re: Load Balance with Fail Over

hello
paste me only Fail over scripts i have 2 adsl for different isp
by pokeman
Sat Sep 15, 2007 10:56 am
Forum: General
Topic: Web Proxy Caching Performance setting !
Replies: 7
Views: 1511

Re: Web Proxy Caching Performance setting !

hello inoX

can you please paste your web-proxy setting
by pokeman
Fri Sep 14, 2007 8:23 am
Forum: General
Topic: P2p Limiting
Replies: 0
Views: 706

P2p Limiting

hello as per mikrotik guide i am implementing p2p with mangle rules when i try to add /queue the following error "input does not match any value of parent" i don't have any parrent queue /queue tree print Flags: X - disabled, I - invalid Empty my question is what kind of parrent queue required curre...
by pokeman
Fri Sep 14, 2007 7:17 am
Forum: General
Topic: Web Proxy Caching Performance setting !
Replies: 7
Views: 1511

Re: Web Proxy Caching Performance setting !

Hey guys haven't you ppl seen the topic "Mikrotik + Web Proxy Queueing is Impossible ?"

you will find everything about web proxy in that topic, and it's really a very helpful topic.

Thanks
hi hulk

guide me how to improve my cache performance mention ealier my proxy conf and system conf
by pokeman
Thu Sep 13, 2007 10:28 am
Forum: General
Topic: HotSpot Advertisement
Replies: 7
Views: 1339

Re: HotSpot Advertisement

It will be the next page displayed once they go to another site/link. It will happen as often as you have the duration set. So if you are reading mikrotik.com and hit a link after x minutes, it will send you to your advertise link. Sir, I am NOt getting you, Please explain me in Details hello ashis...
by pokeman
Thu Sep 13, 2007 10:22 am
Forum: General
Topic: Web Proxy Caching Performance setting !
Replies: 7
Views: 1511

Web Proxy Caching Performance setting !

hello i am using MT with web proxy feature my currently system configuration version: "2.9.27" free-memory: 312020kB total-memory: 451712kB cpu: "AMD" cpu-frequency: 2200MHz cpu-load: 11 free-hdd-space: 37399664kB total-hdd-space: 38448304kB write-sect-since-reboot: 5848168 write-sect-total: 6064680...
by pokeman
Thu Sep 13, 2007 9:33 am
Forum: General
Topic: HotSpot Advertisement
Replies: 7
Views: 1339

Re: HotSpot Advertisement

hello

how to configure when my client login via hotspot user page always go first my isp home page
by pokeman
Thu Sep 13, 2007 8:52 am
Forum: General
Topic: Mikrotik + Web Proxy Queueing is Impossible ?
Replies: 101
Views: 28217

Re: Mikrotik + Web Proxy Queueing is Impossible ?

hello , i dont know if read my past topic or not ? it has been solved my friends , and i'm monitoring the results , and it is perfect .. its by marking traffic coming from proxy with TOS = 4 , its the traffic generated in local process ( hard disk cache ) .. for example i downloaded a file for the ...
by pokeman
Mon Sep 10, 2007 12:35 pm
Forum: General
Topic: Salam (I Need Help)
Replies: 11
Views: 1439

Re: Salam (I Need Help)

salam I have a Mikrotik Router Some people have a program that is scan all the Mac and Ip's that connect with my network. So the hacker change his Mac and Ip same as my clients and then receive the internet directly. I am trying Avery thing I know it like fixed the Mac with the user name and passwo...
by pokeman
Mon Sep 10, 2007 9:09 am
Forum: General
Topic: use mikrotik Lan Sip server
Replies: 1
Views: 532

use mikrotik Lan Sip server

hello
my clients have softphones can they talk localy using MK . if yes guide me how to ?