Community discussions

Search found 52 matches

by TheSirStumfy
Thu Oct 03, 2019 2:31 pm
Forum: Wireless Networking
Topic: CAPsMAN manager can't manage its own wireless [SOLVED]
Replies: 19
Views: 12473

Re: CAPsMAN manager can't manage its own wireless [SOLVED]

One of those days i guess..

Cable replacement solved all issues.
by TheSirStumfy
Thu Oct 03, 2019 10:32 am
Forum: Wireless Networking
Topic: CAPsMAN manager can't manage its own wireless [SOLVED]
Replies: 19
Views: 12473

Re: CAPsMAN manager can't manage its own wireless [SOLVED]

Hello,

i have similar problems, however i have narrowed it down to a single client causing this (an iPhone).

Everything works fine, but when this client connects it causes this loop, and capsman goes down.

same problem with client to client on or off.

Any ideas?
by TheSirStumfy
Tue Jul 30, 2019 7:20 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 36058

Re: v6.45.2 [stable] is released!

Funny enough this upgrade caused a loop for me, until i also upgraded the firmware, now resolved.

Also as mentioned HAp lite is on the ragged edge of space, i had a backup on it and it could not upgrade until removed.
by TheSirStumfy
Fri Jul 12, 2019 7:43 am
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 767

Re: Network isolation using VRF?

1. what is the difference wrt the load on the CPU for both methods. 2. if i basically in my forward chain simply allow lan to wan traffic and have a generic drop all rule last, - does that stop traffic between bridges and thus don't need many rules just one! Regarding this, perhaps someone with som...
by TheSirStumfy
Fri Jul 12, 2019 7:27 am
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 767

Re: Network isolation using VRF?

Some experience i had with some other routers, the general setup is that if u have 2 networks, they wont see each other until you do routing. But Mikrotik for some reason does this for you. So to break this link all i did was: /ip route rule add action=drop dst-address=192.168.aa.0/24 src-address=19...
by TheSirStumfy
Wed Jul 10, 2019 7:10 pm
Forum: Beginner Basics
Topic: road warrior clients + ikev2 + ipsec
Replies: 1
Views: 273

Re: road warrior clients + ikev2 + ipsec

Id guess that only if the clients are not connected or want to connect at the same time. I use the same client cer for multiple machines in OVPN. However since i am the user they can not connect at the same time.
by TheSirStumfy
Wed Jul 10, 2019 4:52 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 767

Re: Network isolation using VRF?

I ended up just making a routing rule that drops between both networks.

Seems to me the cleanest way to do this.
by TheSirStumfy
Wed Jul 10, 2019 3:22 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 767

Network isolation using VRF?

Hello, Is it possible to do network isolation using VRF? Lets say u have 10.0.10.1 and 10.0.11.1 set up with all the bridges, networks, dhcp etc. As far as I understand Mikrotik will do routing between them automatically. So if u want them to be isolate, can u do it via VRF or do you need rules like...
by TheSirStumfy
Thu Jul 04, 2019 3:51 pm
Forum: General
Topic: Cloud Backup
Replies: 20
Views: 3751

Re: Cloud Backup

Thanks a bunch, the documentation was not updated yet.

Regards.
by TheSirStumfy
Thu Jul 04, 2019 3:22 pm
Forum: General
Topic: Cloud Backup
Replies: 20
Views: 3751

Re: Cloud Backup

Hello, quick question, the change-log states that a "replace" command was added in 6.45.1, however if i do "action=replace" or if i just do action=*tab* no replace command is available.
by TheSirStumfy
Wed Jun 26, 2019 11:38 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4298

Re: single IP constantly trying to log to my Mikrotik

[/quote]

I cannot confirm that....
[/quote]

Well i can, i can give logs. About 3-4 attempts every day, usually 3 tries per attempt.

Also others are complaining about it here: https://whatismyipaddress.com/ip/141.98.80.115
by TheSirStumfy
Tue Jun 25, 2019 1:51 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4298

Re: single IP constantly trying to log to my Mikrotik

Just to add to this This seems to be a widespread attack, i have it on 3 separate instances. Same IP
by TheSirStumfy
Sun Jun 23, 2019 4:04 pm
Forum: Beginner Basics
Topic: Firewall list performace hit
Replies: 3
Views: 349

Re: Firewall list performace hit

Just to add a nooby question, what is a good place in the FW steps to put such rules? Right on top?
by TheSirStumfy
Sun Jun 23, 2019 3:58 pm
Forum: Beginner Basics
Topic: Firewall list performace hit
Replies: 3
Views: 349

Re: Firewall list performace hit

The performance hit is present but not huge. Address lists are vety effrctive and use RAW filtering so it won't reach connection tracking. I see, guess theres nothing to it than? Im on RB3011 so i guess it should chew trough a list like that no problem? The problem is people also use VPN for missus...
by TheSirStumfy
Sun Jun 23, 2019 1:36 pm
Forum: Beginner Basics
Topic: Firewall list performace hit
Replies: 3
Views: 349

Firewall list performace hit

How much of a hit on performance does a FW drop list make? For example there are lists of VPN servers, but the lists are in the 10s of thousands. One i found is 30.000 lines, with about 20k of those in range form /24. Would such a list kill your router, or not really since it needs to check only inc...
by TheSirStumfy
Mon Feb 18, 2019 11:30 pm
Forum: Beginner Basics
Topic: Open VPN duplicate packet
Replies: 2
Views: 319

Open VPN duplicate packet

Hello just a quick question, on Ovpn connects i get "debug duplicate packet, dropping" every time i connect. The connections does go trough, its just very strange.. Also i am wondering if this can be effecting performance? The connection is not what you would call "full speed of the line". More like...
by TheSirStumfy
Sat Feb 16, 2019 10:35 am
Forum: Beginner Basics
Topic: Finding a firewalled connection [SOLVED]
Replies: 4
Views: 518

Re: Finding a firewalled connection [SOLVED]

Yeah the log! OK got it, thanks, i have a disk set up for logging anyway, memory and space wont be a problem.

Is it normal BTW to see a lot of "drop all not coming from LAN" traffic"?

Regards
by TheSirStumfy
Sat Feb 16, 2019 9:27 am
Forum: Beginner Basics
Topic: Finding a firewalled connection [SOLVED]
Replies: 4
Views: 518

Finding a firewalled connection [SOLVED]

Hello,

Quick question,

If you are getting a lot of hits on a FW rule, what is the best way to find what connection is causing this?

Regards
by TheSirStumfy
Fri Feb 15, 2019 7:25 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Re: Setting up incoming traffic [SOLVED]

You mean there is another router (provide by ISP?) before the mikrotik? If so see if that router can set to "bridge mode"

sometime DMZ won't solve double nat problem
Its seems this DMZ actually does what it says :)
by TheSirStumfy
Fri Feb 15, 2019 7:21 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Re: Setting up incoming traffic [SOLVED]

Yeah in front there is the standard modem/switch/wifi thing the ISP gives you, since they dont allow PPPOE direct on the Microtik.
by TheSirStumfy
Fri Feb 15, 2019 7:14 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Re: Setting up incoming traffic [SOLVED]

Regarding VPN i had to DMZ the main router on the modem/router to get trough, in case anyone in future helps.
by TheSirStumfy
Fri Feb 15, 2019 5:42 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Re: Setting up incoming traffic [SOLVED]

Called ISP, there fault, incorrect gateway settings on there modem.

Facepalm
by TheSirStumfy
Fri Feb 15, 2019 5:17 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Re: Setting up incoming traffic [SOLVED]

tried all of suggested stuff, nothing. still no ping from outside.
by TheSirStumfy
Fri Feb 15, 2019 4:46 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Re: Setting up incoming traffic [SOLVED]

Config removed for safety
by TheSirStumfy
Fri Feb 15, 2019 4:43 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Re: Setting up incoming traffic [SOLVED]

Its a static public IP form ISP. internet on the router works fine, but pinging it form outside seems impossible
by TheSirStumfy
Fri Feb 15, 2019 4:28 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 743

Setting up incoming traffic [SOLVED]

Ok this will be a super noob question, but im having problems setting up a VPN. The setup didnt work, so i tried to just ping my static IP and i get no response even there. I also have no idea what is cutting it off? Ping works if i am connected to the router (to public ip) but from outside (lets sa...
by TheSirStumfy
Tue Feb 05, 2019 11:58 am
Forum: Beginner Basics
Topic: Constant ping from router [SOLVED]
Replies: 2
Views: 319

Re: Constant ping from router [SOLVED]

Oh i see, thanks!
by TheSirStumfy
Tue Feb 05, 2019 11:54 am
Forum: Beginner Basics
Topic: Constant ping from router [SOLVED]
Replies: 2
Views: 319

Constant ping from router [SOLVED]

Is there a way to do a ping -t equivalent on router, that would run regardless of admin signed in or not.

I tried
ping 192.168.xx.xx count 0 interval 5
but if i log out the ping stops. Also ping stops form the ping tool in tools / ping.

Any ideas?
by TheSirStumfy
Tue Dec 11, 2018 8:39 am
Forum: Beginner Basics
Topic: Route all traffic through NordVPN?
Replies: 19
Views: 9345

Re: Route all traffic through NordVPN?

Last i heard about this was "probably in rOs V7"... :(
by TheSirStumfy
Fri Nov 30, 2018 9:19 pm
Forum: Beginner Basics
Topic: Router upgrade error [SOLVED]
Replies: 2
Views: 389

Re: Router upgrade error [SOLVED]

MVP right here,

Exactly the problem some old package left on the memory.

Cheers.
by TheSirStumfy
Fri Nov 30, 2018 9:12 pm
Forum: Beginner Basics
Topic: Router upgrade error [SOLVED]
Replies: 2
Views: 389

Router upgrade error [SOLVED]

Im trying to upgrade an CRS 125 from 6.43.2 to 6.43.4 and get error

20:04:41 system,error can not install wireless-fp-6.19: system-6.19 is not installed, but is required

after it reboots.

Im doing install straight from System / packages.

Any idea what could cause this?
by TheSirStumfy
Wed Nov 21, 2018 11:26 am
Forum: Beginner Basics
Topic: Specific setting reset
Replies: 1
Views: 253

Specific setting reset

Is there a way to reset only a specific set of settings on the router.

for example can i reset only CAPsMAN or only Interfaces to default settings, without touching the reset of the setting?

Regards.
by TheSirStumfy
Tue Nov 13, 2018 11:40 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 883

Re: DHCP issue [SOLVED]

I would like to thank everyone for the help.

the issue was in fact that the ISP router was set to the same SSID and pwd as the Mikrotik.

This of course made devices wander around.

Regards.
by TheSirStumfy
Tue Nov 13, 2018 10:19 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 883

Re: DHCP issue [SOLVED]

The ether1 where the ISP is does not seem to be bridged.
Capture.JPG
I understand there is a hide sensitive export, but still it has many external IP addresses for VPN, OVPN client names, SSIDs etc... Still a bit too sensitive for internet.
by TheSirStumfy
Tue Nov 13, 2018 9:03 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 883

Re: DHCP issue [SOLVED]

The config is very long and includes a lot of info id not put on the internet, is there really not a specific section to post? Also yes i was thinking it could be the ISP router. Problem is this is an "inherited" network from previous admin, so i need to dig up the router pwd somehow, to check whats...
by TheSirStumfy
Mon Nov 12, 2018 9:45 pm
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 883

Re: DHCP issue [SOLVED]

What part of config would you like?
by TheSirStumfy
Mon Nov 12, 2018 9:42 pm
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 883

DHCP issue [SOLVED]

Hello, i have a strange issue where devices connected to the router sometimes switch DHCP network to the gateway from the ISP router. A device on the MT router would be on xx.xx.88.1 gateway, than just after a disconnect and reconnect it would jump to IPS gateway of xx.xx.1.1, but trough the same Wi...
by TheSirStumfy
Fri Nov 09, 2018 9:22 am
Forum: Beginner Basics
Topic: Exclude a static IP from the internet. [SOLVED]
Replies: 2
Views: 440

Exclude a static IP from the internet. [SOLVED]

Here is a newbie question for all. :D What would be a good firewall rule to exclude a single static IP from the internet, but still maintain full LAN network functionality of said IP address? Would a rule like add chain=forward src-address="staicIPofPC" dst-address=!"LAN" action=reject be correct? A...
by TheSirStumfy
Wed Nov 07, 2018 11:53 am
Forum: General
Topic: OpenVPN Client Adds Peer DNS Servers
Replies: 4
Views: 890

Re: OpenVPN Client Adds Peer DNS Servers

Can confirm:
Capture.JPG
by TheSirStumfy
Wed Nov 07, 2018 11:52 am
Forum: Beginner Basics
Topic: Disabling Dynamic DNS Servers... [SOLVED]
Replies: 8
Views: 7688

Re: Disabling Dynamic DNS Servers... [SOLVED]

I see. No way to turn it off than i presume? I do have one idea now and will test. The openVPN clients are used to connect remote routers (out of main HQ) to the main netowrk, Could it be that remote router DHCPclient is pushing the DNSs to the main one? Will test and will add to mentioned thread. T...
by TheSirStumfy
Wed Nov 07, 2018 11:40 am
Forum: Beginner Basics
Topic: Disabling Dynamic DNS Servers... [SOLVED]
Replies: 8
Views: 7688

Re: Disabling Dynamic DNS Servers... [SOLVED]

OpenVPN clients and L2TP client for VPN.
by TheSirStumfy
Wed Nov 07, 2018 11:30 am
Forum: Beginner Basics
Topic: Disabling Dynamic DNS Servers... [SOLVED]
Replies: 8
Views: 7688

Re: Disabling Dynamic DNS Servers... [SOLVED]

sorry to drag this thread out of the basement but i have a question.

I have DHCP client disabled, but im still getting some dynamic DNSs. is there somewhere other settings that can effect this?
Capture.JPG
by TheSirStumfy
Fri Oct 19, 2018 12:49 pm
Forum: Beginner Basics
Topic: Router shows used space, but no files are on it
Replies: 3
Views: 386

Re: Router shows used space, but no files are on it

Ok, never-mind i downloaded the wrong package,

FACEPLAM.
by TheSirStumfy
Fri Oct 19, 2018 12:45 pm
Forum: Beginner Basics
Topic: Router shows used space, but no files are on it
Replies: 3
Views: 386

Re: Router shows used space, but no files are on it

Ok i ended up giving it a USB drive to store the upgrades: The CAP was manually upgraded (so it is already running the new version) but i tried to trigger it again and i get: 11:34:43 caps,error [xxx:5C/11/5cde,Run,[xxx:5C]] upgrade status: failed, failed to download file 'routeros-smips-6.43.4.npk'...
by TheSirStumfy
Fri Oct 19, 2018 12:15 pm
Forum: Beginner Basics
Topic: Router shows used space, but no files are on it
Replies: 3
Views: 386

Router shows used space, but no files are on it

Hello, my router is showing it has 11MB used, but i dont see any files on it

Is it counting the OS instalation as well? I wanted to upload the package for a CAPsMAN install to CAPS on it but i have no space:
Capture.JPG
by TheSirStumfy
Mon Oct 15, 2018 10:18 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 1157

Re: Router dropping traffic as "drop invalid"

I resolved the issue.

Turns out a driver update on the wifi card on the PC side resolved the issue. Very strange it was only happening in this service and everything else was fine.

Thanks for the help.
by TheSirStumfy
Mon Oct 15, 2018 4:27 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 1157

Re: Router dropping traffic as "drop invalid"

Steveocee suggested disabling fasttrack, it sadly did not work.
by TheSirStumfy
Mon Oct 15, 2018 4:26 pm
Forum: Beginner Basics
Topic: Need help with an online game
Replies: 2
Views: 305

Re: Need help with an online game

I have re posted the question to another post, because this one took almost a day to appear here.

Please refer to viewtopic.php?f=13&t=140438

also a mod can close this, so there wont be 2 same questions.
by TheSirStumfy
Mon Oct 15, 2018 3:54 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 1157

Re: Router dropping traffic as "drop invalid"

Here is the FW setup > /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=\ invalid add action=accept chain=input com...
by TheSirStumfy
Mon Oct 15, 2018 1:50 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 1157

Re: Router dropping traffic as "drop invalid"

I will post the firewall in 1h, when i get back to the router, but i can tell you now its a QucikSet default rule set found in defconf. Also nothing except the routers quickset was changed. (noob - thats why i need help :D ) What really confuses me is that it was working fine than just out of nowher...
by TheSirStumfy
Mon Oct 15, 2018 1:31 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 1157

Router dropping traffic as "drop invalid"

I really need some help please. Yesterday i was using a service that uses UDP ports in the 20000 ranges. Everything works fine, than after 10 min of usage the connection was dropped. After that it was impossible to reconnect. When i check the router the traffic seems to go into the "drop invalid" fi...
by TheSirStumfy
Sun Oct 14, 2018 8:02 pm
Forum: Beginner Basics
Topic: Need help with an online game
Replies: 2
Views: 305

Need help with an online game

Ok im a noob when it comes to MikroTik but i have a problem. I was trying to play a game after upgrading to a MikroTik router. It worked fine for a bout 15 min then disconnected. I checked the firewall and i see that the login packets get sent into the defconf: drop invalid. Strange thing is that it...