Community discussions

MikroTik App

Search found 92 matches

by TheSirStumfy
Thu May 05, 2022 6:34 pm
Forum: General
Topic: WireGuard to Branch office over VPN [SOLVED]
Replies: 6
Views: 1084

Re: WireGuard to Branch office over VPN [SOLVED]

Found it.

The Branch Address space for the OVPN connection had a /24 mask. Since the WG now has a different subnet the mask had to be changed to a /16 bit mask.

Nasty one to find, since the OVPN on the Branch was making a dynamic route (and thats default 24 bit)

Thanks to all for the input.
by TheSirStumfy
Thu May 05, 2022 5:57 pm
Forum: General
Topic: WireGuard to Branch office over VPN [SOLVED]
Replies: 6
Views: 1084

Re: WireGuard to Branch office over VPN [SOLVED]

Also to clear the diagram, every VPN is separate with separate subnets. Its not a VPN in VPN in VPN...
by TheSirStumfy
Thu May 05, 2022 5:53 pm
Forum: General
Topic: WireGuard to Branch office over VPN [SOLVED]
Replies: 6
Views: 1084

Re: WireGuard to Branch office over VPN [SOLVED]

Since WireGuard is a VPN, I don't see why you have two other tunneling layers. Your diagram doesn't make it clear, but it looks like you've got L2TP-in-WG-in-OVPN. That sounds like a recipe for all kinds of problems. If you simply your configuration, some of those problems may go away, and at that ...
by TheSirStumfy
Thu May 05, 2022 5:35 pm
Forum: General
Topic: WireGuard to Branch office over VPN [SOLVED]
Replies: 6
Views: 1084

WireGuard to Branch office over VPN [SOLVED]

I have a problem I can not seem to solve. I have a Branch office router that is making an OVPN to Main. I am making a WG interface to the main. Everything on the Main network works over WG but Branch I can not reach. HOWEVER there is also a L2TP connection to Main, and that one can reach Branch no p...
by TheSirStumfy
Tue Dec 14, 2021 1:47 pm
Forum: General
Topic: Is Mikrotik affected by log4j ?
Replies: 14
Views: 10890

Re: Is Mikrotik affected by log4j ?

Why does MikroTik have to officially announce every completely unrelated thing? MikroTik doesnt have Covid and also doesn't have WIN32/CIH either.

Log4j is a JAVA problem.

Thank god for that.
by TheSirStumfy
Tue Feb 09, 2021 8:39 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

After 3 days of testing it seems that MT finally fixed this in 6.48.1 as stated in the patch notes.

No flaps now for the mentioned 3 days even under heavy load conditions.

Here's hoping it stays that way.
by TheSirStumfy
Thu Jan 28, 2021 11:40 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

Setting speeds does help a bit I noticed as well, but does not fully fix the problem sadly. In my observation I could not find a single definitive evidence what would cause the issue. The flaps just seem completely random. They even happen during the night with almost 0 load on the system. For examp...
by TheSirStumfy
Fri Jan 01, 2021 12:06 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128228

Re: v6.48 [stable] is released!

Hm.. the only thing honestly that could be a problem is a SFP module. Ok thanks for the idea guys, Ill play around with switching if for a different one, perhaps it could be causing problems.. Did not try that, because it works fine.
by TheSirStumfy
Fri Jan 01, 2021 10:25 am
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128228

Re: v6.48 [stable] is released!

Really hope they fix the RB3011 finally. Mine has been flapping for years, I have 2 years of logs to prove it. Some updates ware better some worse, but none fixed it truly. set X cpu-flow-control=no name="Switch x" does help a bit, but never really went away, just went from many flaps a da...
by TheSirStumfy
Tue Sep 15, 2020 8:49 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

So I wonder if anyone happened to see this in the 6.46.7 (long term) changelog: *) switch - correctly enable and disable CPU Flow Control on RB3011UiAS; Apologies if this isn't news, as I typically only pay attention to long term. I also don't want to get anyone's hopes up :) Thanks for that. Yeah ...
by TheSirStumfy
Wed Sep 09, 2020 8:53 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

I rechecked my logs regarding the issue, and even with CPU flow control off on latest FW/OS I still get flops on SC1. Much more rare now (weeks instead of multi per day) but still. I do have a SFP connection too. Just seems to me this will never be fixed. CRS devices seem to get constant fixes in ev...
by TheSirStumfy
Mon Jul 27, 2020 9:49 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

For me the combination of 6.47 and disabled CPU flow control on both switch chips worked.
by TheSirStumfy
Wed Jun 10, 2020 10:59 am
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121241

Re: DNS over HTTPS

You only need the root certificate of the service you want to use.
by TheSirStumfy
Wed Jun 10, 2020 7:43 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

Now I'm completely clueless ... even now the issues remain present ... so on 6.46.4 the flapping also occurs, although very limited so far. Apparently I don't have enough data in my Splunk to go very far back in time to see when these messages first started to appear... Ok 24h of no flapps after di...
by TheSirStumfy
Tue Jun 09, 2020 10:21 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

For me at least for now the flapping has stopped (for today) after the flow control disable. Need to monitor this for more days. I save logs for 4 months only, but i remembered i have a server on the router since 2019 - 06. So i went to check on those logs and now see that this has been happening al...
by TheSirStumfy
Tue Jun 09, 2020 10:17 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

Double post ignore this one
by TheSirStumfy
Tue Jun 09, 2020 8:31 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

Ok thank you, will give it a try.

I did notice a correlation between flapping and CPU usage.
During down time (at night) i get almost 0 flaps, and at high CPU usage times (mostly VPN clients) during day time, the flaps return.
by TheSirStumfy
Mon Jun 08, 2020 11:41 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

I have one on my office "RouterBOARD 3011UiAS" from 9 Jul 2016, and is still working flawlessly (factory is 6.35.3, now have 6.44.6) Mine was working fine with 6.44.x too, but some days ago I moved to the latest 6.47 stable. Today I was asked by Mikrotik support to make some config-adapti...
by TheSirStumfy
Sun Jun 07, 2020 6:30 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

Now happening also on a all 1G switch, so the "do not mix speeds" workaround does not seem to work.

Capture.JPG
by TheSirStumfy
Sat Jun 06, 2020 7:06 pm
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

After I moved off the AP on port 9 it stopped flapping for the whole day now..

Will continue to monitor, but still this would need to get checked out by MT.
by TheSirStumfy
Sat Jun 06, 2020 10:53 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

Im moving off 100M clients to an external switch 1 by 1 to try to see if this is somehow specific port related. My flapps have been very spread out (over hours) so testing will take some time. But if your config stays stable jvanhambelgium (since you had problems on fabric 1-5) it could be safe to a...
by TheSirStumfy
Sat Jun 06, 2020 9:58 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

Same here! Since upgrade to 6.47 on my RB3011. I've generated supout.rif and forwarded it to Mikrotik. In my case, it seems to be ports ether3 (1Gits/s, Unify AP groundfloor) and ether5 (1Gits/s, some D-LINK 8-port small switch connected on the other end on a floor)seeing transitions, but ether5 mu...
by TheSirStumfy
Sat Jun 06, 2020 9:22 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62441

Re: RB3011 port flopping - bad design

The problem has started for me in 6.47.

Never had problems before.
Capture.JPG
by TheSirStumfy
Sat Jun 06, 2020 9:19 am
Forum: General
Topic: Switch chip random resets RB3011 on 6.47?
Replies: 4
Views: 1887

Re: Switch chip random resets RB3011 on 6.47?

Yep, same here, never had any problems on this RB3011 until 6.47. Reboot did not help, again the whole "right" switch chip (or CPU) flapped. Happened only once now, but im not hopeful it will just stop by itself. Capture.JPG If persistent i will have to try downgrade, if that is even possi...
by TheSirStumfy
Fri Jun 05, 2020 9:54 pm
Forum: General
Topic: Switch chip random resets RB3011 on 6.47?
Replies: 4
Views: 1887

Switch chip random resets RB3011 on 6.47?

Hello everyone, today i upgraded to 6.47 on my RB3011. Firmware upgraded as well. Everything looking good but i noticed 3x random switch chip resets (at least i think its the switch chips fault since its only interfaces 6-10) Capture.JPG It happened 3 times at random times for no apparent reason. An...
by TheSirStumfy
Fri Feb 14, 2020 3:50 pm
Forum: General
Topic: Large blacklists for firewall
Replies: 37
Views: 9108

Re: Large blacklists for firewall

Ok, thank you, i see that you both use address list timeouts.

Im i correct in understanding that this is so IPs that never get detected in the list get removed?

Also i see pre routing is used instead of input, this is to save routing overhead of CPU right?
by TheSirStumfy
Fri Feb 14, 2020 12:14 pm
Forum: General
Topic: Large blacklists for firewall
Replies: 37
Views: 9108

Large blacklists for firewall

Hello everyone, Does anyone have any experience with large block lists? I am running an email server and get hit with brute force password attacks from IPs that are commonly found in blacklists. Although the server features and is set up for automatic lockout of IPs that do multiple attempts at pass...
by TheSirStumfy
Mon Feb 10, 2020 10:19 am
Forum: General
Topic: Add DNS over HTTPS (DoH) support
Replies: 130
Views: 117122

Re: Add DNS over HTTPS (DoH) support

Privacy up down, data collected here there...

Can we expect support for this?

Than users themselves can decide who or what thew want to use, DNS DoH DoT...
by TheSirStumfy
Wed Jan 29, 2020 7:37 pm
Forum: Beginner Basics
Topic: Unknown source and destination connections
Replies: 1
Views: 1125

Re: Unknown source and destination connections

Ok i found it. It was a virtual machine, it had a Vswitch that had a random IP. So that was the internal part.
by TheSirStumfy
Wed Jan 29, 2020 4:50 pm
Forum: Beginner Basics
Topic: Unknown source and destination connections
Replies: 1
Views: 1125

Unknown source and destination connections

Hello all, i have a quick question. I sometimes find connections in Firewall Connections that have an unknown source (not LAN - not public IP) and unknown destination (not LAN - not public IP). As far as I understand this would mean that something routed trough my ip to somewhere else? My "drop...
by TheSirStumfy
Mon Jan 27, 2020 5:45 pm
Forum: General
Topic: Email server proper port configuration
Replies: 4
Views: 3328

Re: Email server proper port configuration

Thanks to both for the extensive write up. Very much appreciated it clears up a lot. So the basic gist of it is that server to server happens on 25, than the connection goes into established and is taken over by the default firewall rules. Also from the reply's in getting that is simply impossible t...
by TheSirStumfy
Mon Jan 27, 2020 8:52 am
Forum: General
Topic: Email server proper port configuration
Replies: 4
Views: 3328

Email server proper port configuration

Dear all, i am setting up an email server behind a Mikroitk router, and would like some advice on proper port configuration. Since my primary field is system administration, not networking, I would kindly ask for advice if my config is correct and if i perhaps missed sth. Please bare with me. I set ...
by TheSirStumfy
Fri Jan 03, 2020 6:36 pm
Forum: Beginner Basics
Topic: WIFI encryption question
Replies: 2
Views: 2414

Re: WIFI encryption question

Just to clarify this is on CapsMan, not on device wireless.
by TheSirStumfy
Fri Jan 03, 2020 6:05 pm
Forum: Beginner Basics
Topic: WIFI encryption question
Replies: 2
Views: 2414

WIFI encryption question

Hello i have a quick question about encryption on WIFI. Mikrotik allows you to choose aes ccm or tkip, but also allows to leave the field closed (not unchecked but closed - as in never defined). Since the documentation does not state a default state of security.encryption (aes-ccm | tkip; Default: )...
by TheSirStumfy
Mon Nov 11, 2019 11:44 pm
Forum: General
Topic: WLAN clinet using LAN DHCP
Replies: 8
Views: 1953

Re: WLAN clinet using LAN DHCP

Just to add i did notice that the WIFI DHCP has authoritative 2s delay set up. However this does not cause problems to other clients as mentioned.
by TheSirStumfy
Mon Nov 11, 2019 11:42 pm
Forum: General
Topic: WLAN clinet using LAN DHCP
Replies: 8
Views: 1953

Re: WLAN clinet using LAN DHCP

Well the WIFI network has its own Bridge defined, and specified in the CAPS config, so i dont see it as the same L2 network, or do you need to go deeper? Also out of at least 100 WIFI clients only one has this problem. (the client is a "smart speaker" so no real way to configure it by itse...
by TheSirStumfy
Mon Nov 11, 2019 6:14 pm
Forum: General
Topic: WLAN clinet using LAN DHCP
Replies: 8
Views: 1953

Re: WLAN clinet using LAN DHCP

Can you post both router config and CAPAC config?

sadly i can not, against company policy. I can only answer specific questions.
by TheSirStumfy
Mon Nov 11, 2019 4:10 pm
Forum: General
Topic: WLAN clinet using LAN DHCP
Replies: 8
Views: 1953

Re: WLAN clinet using LAN DHCP

This is what is confusing me here. Cap is set to "WIFIBridge" (it has its own IP pool) and DHCPserver is set to "WIFIbridge" with the same pool defined. All clients follow this, and connect to WIFI Dhcp. They also register in CAPsMAN registration table. But one acts like it is pl...
by TheSirStumfy
Mon Nov 11, 2019 3:18 pm
Forum: General
Topic: WLAN clinet using LAN DHCP
Replies: 8
Views: 1953

Re: WLAN clinet using LAN DHCP

Ok let me simplify the question:

What is the best way to force a client to register to the CAP interface?
by TheSirStumfy
Mon Nov 11, 2019 1:01 pm
Forum: General
Topic: WLAN clinet using LAN DHCP
Replies: 8
Views: 1953

WLAN clinet using LAN DHCP

Hello all I have one extremely strange issue. One (and only one) client on my network is constantly connecting to LAN DHCP server even though its connection over CAPsMAN to WLAN. All the settings for the CAP are correct, and other clients correctly report @cap1 join to wifi and WLAN dhcp. However on...
by TheSirStumfy
Thu Oct 03, 2019 2:31 pm
Forum: Wireless Networking
Topic: CAPsMAN manager can't manage its own wireless [SOLVED]
Replies: 29
Views: 54664

Re: CAPsMAN manager can't manage its own wireless [SOLVED]

One of those days i guess..

Cable replacement solved all issues.
by TheSirStumfy
Thu Oct 03, 2019 10:32 am
Forum: Wireless Networking
Topic: CAPsMAN manager can't manage its own wireless [SOLVED]
Replies: 29
Views: 54664

Re: CAPsMAN manager can't manage its own wireless [SOLVED]

Hello,

i have similar problems, however i have narrowed it down to a single client causing this (an iPhone).

Everything works fine, but when this client connects it causes this loop, and capsman goes down.

same problem with client to client on or off.

Any ideas?
by TheSirStumfy
Tue Jul 30, 2019 7:20 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 205
Views: 87285

Re: v6.45.2 [stable] is released!

Funny enough this upgrade caused a loop for me, until i also upgraded the firmware, now resolved.

Also as mentioned HAp lite is on the ragged edge of space, i had a backup on it and it could not upgrade until removed.
by TheSirStumfy
Fri Jul 12, 2019 7:43 am
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 2282

Re: Network isolation using VRF?

1. what is the difference wrt the load on the CPU for both methods. 2. if i basically in my forward chain simply allow lan to wan traffic and have a generic drop all rule last, - does that stop traffic between bridges and thus don't need many rules just one! Regarding this, perhaps someone with som...
by TheSirStumfy
Fri Jul 12, 2019 7:27 am
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 2282

Re: Network isolation using VRF?

Some experience i had with some other routers, the general setup is that if u have 2 networks, they wont see each other until you do routing. But Mikrotik for some reason does this for you. So to break this link all i did was: /ip route rule add action=drop dst-address=192.168.aa.0/24 src-address=19...
by TheSirStumfy
Wed Jul 10, 2019 7:10 pm
Forum: Beginner Basics
Topic: road warrior clients + ikev2 + ipsec
Replies: 1
Views: 843

Re: road warrior clients + ikev2 + ipsec

Id guess that only if the clients are not connected or want to connect at the same time. I use the same client cer for multiple machines in OVPN. However since i am the user they can not connect at the same time.
by TheSirStumfy
Wed Jul 10, 2019 4:52 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 2282

Re: Network isolation using VRF?

I ended up just making a routing rule that drops between both networks.

Seems to me the cleanest way to do this.
by TheSirStumfy
Wed Jul 10, 2019 3:22 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 2282

Network isolation using VRF?

Hello, Is it possible to do network isolation using VRF? Lets say u have 10.0.10.1 and 10.0.11.1 set up with all the bridges, networks, dhcp etc. As far as I understand Mikrotik will do routing between them automatically. So if u want them to be isolate, can u do it via VRF or do you need rules like...
by TheSirStumfy
Thu Jul 04, 2019 3:51 pm
Forum: General
Topic: Cloud Backup
Replies: 23
Views: 24477

Re: Cloud Backup

Thanks a bunch, the documentation was not updated yet.

Regards.
by TheSirStumfy
Thu Jul 04, 2019 3:22 pm
Forum: General
Topic: Cloud Backup
Replies: 23
Views: 24477

Re: Cloud Backup

Hello, quick question, the change-log states that a "replace" command was added in 6.45.1, however if i do "action=replace" or if i just do action=*tab* no replace command is available.
by TheSirStumfy
Wed Jun 26, 2019 11:38 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 10954

Re: single IP constantly trying to log to my Mikrotik

[/quote]

I cannot confirm that....
[/quote]

Well i can, i can give logs. About 3-4 attempts every day, usually 3 tries per attempt.

Also others are complaining about it here: https://whatismyipaddress.com/ip/141.98.80.115
by TheSirStumfy
Tue Jun 25, 2019 1:51 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 10954

Re: single IP constantly trying to log to my Mikrotik

Just to add to this This seems to be a widespread attack, i have it on 3 separate instances. Same IP
by TheSirStumfy
Sun Jun 23, 2019 4:04 pm
Forum: Beginner Basics
Topic: Firewall list performace hit
Replies: 3
Views: 1159

Re: Firewall list performace hit

Just to add a nooby question, what is a good place in the FW steps to put such rules? Right on top?
by TheSirStumfy
Sun Jun 23, 2019 3:58 pm
Forum: Beginner Basics
Topic: Firewall list performace hit
Replies: 3
Views: 1159

Re: Firewall list performace hit

The performance hit is present but not huge. Address lists are vety effrctive and use RAW filtering so it won't reach connection tracking. I see, guess theres nothing to it than? Im on RB3011 so i guess it should chew trough a list like that no problem? The problem is people also use VPN for missus...
by TheSirStumfy
Sun Jun 23, 2019 1:36 pm
Forum: Beginner Basics
Topic: Firewall list performace hit
Replies: 3
Views: 1159

Firewall list performace hit

How much of a hit on performance does a FW drop list make? For example there are lists of VPN servers, but the lists are in the 10s of thousands. One i found is 30.000 lines, with about 20k of those in range form /24. Would such a list kill your router, or not really since it needs to check only inc...
by TheSirStumfy
Mon Feb 18, 2019 11:30 pm
Forum: Beginner Basics
Topic: Open VPN duplicate packet
Replies: 2
Views: 1076

Open VPN duplicate packet

Hello just a quick question, on Ovpn connects i get "debug duplicate packet, dropping" every time i connect. The connections does go trough, its just very strange.. Also i am wondering if this can be effecting performance? The connection is not what you would call "full speed of the l...
by TheSirStumfy
Sat Feb 16, 2019 10:35 am
Forum: Beginner Basics
Topic: Finding a firewalled connection [SOLVED]
Replies: 4
Views: 2453

Re: Finding a firewalled connection [SOLVED]

Yeah the log! OK got it, thanks, i have a disk set up for logging anyway, memory and space wont be a problem.

Is it normal BTW to see a lot of "drop all not coming from LAN" traffic"?

Regards
by TheSirStumfy
Sat Feb 16, 2019 9:27 am
Forum: Beginner Basics
Topic: Finding a firewalled connection [SOLVED]
Replies: 4
Views: 2453

Finding a firewalled connection [SOLVED]

Hello,

Quick question,

If you are getting a lot of hits on a FW rule, what is the best way to find what connection is causing this?

Regards
by TheSirStumfy
Fri Feb 15, 2019 7:25 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Re: Setting up incoming traffic [SOLVED]

You mean there is another router (provide by ISP?) before the mikrotik? If so see if that router can set to "bridge mode"

sometime DMZ won't solve double nat problem
Its seems this DMZ actually does what it says :)
by TheSirStumfy
Fri Feb 15, 2019 7:21 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Re: Setting up incoming traffic [SOLVED]

Yeah in front there is the standard modem/switch/wifi thing the ISP gives you, since they dont allow PPPOE direct on the Microtik.
by TheSirStumfy
Fri Feb 15, 2019 7:14 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Re: Setting up incoming traffic [SOLVED]

Regarding VPN i had to DMZ the main router on the modem/router to get trough, in case anyone in future helps.
by TheSirStumfy
Fri Feb 15, 2019 5:42 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Re: Setting up incoming traffic [SOLVED]

Called ISP, there fault, incorrect gateway settings on there modem.

Facepalm
by TheSirStumfy
Fri Feb 15, 2019 5:17 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Re: Setting up incoming traffic [SOLVED]

tried all of suggested stuff, nothing. still no ping from outside.
by TheSirStumfy
Fri Feb 15, 2019 4:46 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Re: Setting up incoming traffic [SOLVED]

Config removed for safety
by TheSirStumfy
Fri Feb 15, 2019 4:43 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Re: Setting up incoming traffic [SOLVED]

Its a static public IP form ISP. internet on the router works fine, but pinging it form outside seems impossible
by TheSirStumfy
Fri Feb 15, 2019 4:28 pm
Forum: Beginner Basics
Topic: Setting up incoming traffic [SOLVED]
Replies: 14
Views: 2962

Setting up incoming traffic [SOLVED]

Ok this will be a super noob question, but im having problems setting up a VPN. The setup didnt work, so i tried to just ping my static IP and i get no response even there. I also have no idea what is cutting it off? Ping works if i am connected to the router (to public ip) but from outside (lets sa...
by TheSirStumfy
Tue Feb 05, 2019 11:58 am
Forum: Beginner Basics
Topic: Constant ping from router [SOLVED]
Replies: 2
Views: 1707

Re: Constant ping from router [SOLVED]

Oh i see, thanks!
by TheSirStumfy
Tue Feb 05, 2019 11:54 am
Forum: Beginner Basics
Topic: Constant ping from router [SOLVED]
Replies: 2
Views: 1707

Constant ping from router [SOLVED]

Is there a way to do a ping -t equivalent on router, that would run regardless of admin signed in or not.

I tried
ping 192.168.xx.xx count 0 interval 5
but if i log out the ping stops. Also ping stops form the ping tool in tools / ping.

Any ideas?
by TheSirStumfy
Tue Dec 11, 2018 8:39 am
Forum: Beginner Basics
Topic: Route all traffic through NordVPN?
Replies: 20
Views: 22632

Re: Route all traffic through NordVPN?

Last i heard about this was "probably in rOs V7"... :(
by TheSirStumfy
Fri Nov 30, 2018 9:19 pm
Forum: Beginner Basics
Topic: Router upgrade error [SOLVED]
Replies: 2
Views: 1213

Re: Router upgrade error [SOLVED]

MVP right here,

Exactly the problem some old package left on the memory.

Cheers.
by TheSirStumfy
Fri Nov 30, 2018 9:12 pm
Forum: Beginner Basics
Topic: Router upgrade error [SOLVED]
Replies: 2
Views: 1213

Router upgrade error [SOLVED]

Im trying to upgrade an CRS 125 from 6.43.2 to 6.43.4 and get error

20:04:41 system,error can not install wireless-fp-6.19: system-6.19 is not installed, but is required

after it reboots.

Im doing install straight from System / packages.

Any idea what could cause this?
by TheSirStumfy
Wed Nov 21, 2018 11:26 am
Forum: Beginner Basics
Topic: Specific setting reset
Replies: 1
Views: 883

Specific setting reset

Is there a way to reset only a specific set of settings on the router.

for example can i reset only CAPsMAN or only Interfaces to default settings, without touching the reset of the setting?

Regards.
by TheSirStumfy
Tue Nov 13, 2018 11:40 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 3157

Re: DHCP issue [SOLVED]

I would like to thank everyone for the help.

the issue was in fact that the ISP router was set to the same SSID and pwd as the Mikrotik.

This of course made devices wander around.

Regards.
by TheSirStumfy
Tue Nov 13, 2018 10:19 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 3157

Re: DHCP issue [SOLVED]

The ether1 where the ISP is does not seem to be bridged.
Capture.JPG
I understand there is a hide sensitive export, but still it has many external IP addresses for VPN, OVPN client names, SSIDs etc... Still a bit too sensitive for internet.
by TheSirStumfy
Tue Nov 13, 2018 9:03 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 3157

Re: DHCP issue [SOLVED]

The config is very long and includes a lot of info id not put on the internet, is there really not a specific section to post? Also yes i was thinking it could be the ISP router. Problem is this is an "inherited" network from previous admin, so i need to dig up the router pwd somehow, to c...
by TheSirStumfy
Mon Nov 12, 2018 9:45 pm
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 3157

Re: DHCP issue [SOLVED]

What part of config would you like?
by TheSirStumfy
Mon Nov 12, 2018 9:42 pm
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 3157

DHCP issue [SOLVED]

Hello, i have a strange issue where devices connected to the router sometimes switch DHCP network to the gateway from the ISP router. A device on the MT router would be on xx.xx.88.1 gateway, than just after a disconnect and reconnect it would jump to IPS gateway of xx.xx.1.1, but trough the same Wi...
by TheSirStumfy
Fri Nov 09, 2018 9:22 am
Forum: Beginner Basics
Topic: Exclude a static IP from the internet. [SOLVED]
Replies: 2
Views: 1169

Exclude a static IP from the internet. [SOLVED]

Here is a newbie question for all. :D What would be a good firewall rule to exclude a single static IP from the internet, but still maintain full LAN network functionality of said IP address? Would a rule like add chain=forward src-address="staicIPofPC" dst-address=!"LAN" action=...
by TheSirStumfy
Wed Nov 07, 2018 11:53 am
Forum: General
Topic: OpenVPN Client Adds Peer DNS Servers
Replies: 4
Views: 3286

Re: OpenVPN Client Adds Peer DNS Servers

Can confirm:
Capture.JPG
by TheSirStumfy
Wed Nov 07, 2018 11:52 am
Forum: Beginner Basics
Topic: Disabling Dynamic DNS Servers... [SOLVED]
Replies: 8
Views: 27237

Re: Disabling Dynamic DNS Servers... [SOLVED]

I see. No way to turn it off than i presume? I do have one idea now and will test. The openVPN clients are used to connect remote routers (out of main HQ) to the main netowrk, Could it be that remote router DHCPclient is pushing the DNSs to the main one? Will test and will add to mentioned thread. T...
by TheSirStumfy
Wed Nov 07, 2018 11:40 am
Forum: Beginner Basics
Topic: Disabling Dynamic DNS Servers... [SOLVED]
Replies: 8
Views: 27237

Re: Disabling Dynamic DNS Servers... [SOLVED]

OpenVPN clients and L2TP client for VPN.
by TheSirStumfy
Wed Nov 07, 2018 11:30 am
Forum: Beginner Basics
Topic: Disabling Dynamic DNS Servers... [SOLVED]
Replies: 8
Views: 27237

Re: Disabling Dynamic DNS Servers... [SOLVED]

sorry to drag this thread out of the basement but i have a question.

I have DHCP client disabled, but im still getting some dynamic DNSs. is there somewhere other settings that can effect this?
Capture.JPG
by TheSirStumfy
Fri Oct 19, 2018 12:49 pm
Forum: Beginner Basics
Topic: Router shows used space, but no files are on it
Replies: 3
Views: 1253

Re: Router shows used space, but no files are on it

Ok, never-mind i downloaded the wrong package,

FACEPLAM.
by TheSirStumfy
Fri Oct 19, 2018 12:45 pm
Forum: Beginner Basics
Topic: Router shows used space, but no files are on it
Replies: 3
Views: 1253

Re: Router shows used space, but no files are on it

Ok i ended up giving it a USB drive to store the upgrades: The CAP was manually upgraded (so it is already running the new version) but i tried to trigger it again and i get: 11:34:43 caps,error [xxx:5C/11/5cde,Run,[xxx:5C]] upgrade status: failed, failed to download file 'routeros-smips-6.43.4.npk'...
by TheSirStumfy
Fri Oct 19, 2018 12:15 pm
Forum: Beginner Basics
Topic: Router shows used space, but no files are on it
Replies: 3
Views: 1253

Router shows used space, but no files are on it

Hello, my router is showing it has 11MB used, but i dont see any files on it

Is it counting the OS instalation as well? I wanted to upload the package for a CAPsMAN install to CAPS on it but i have no space:
Capture.JPG
by TheSirStumfy
Mon Oct 15, 2018 10:18 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4695

Re: Router dropping traffic as "drop invalid"

I resolved the issue.

Turns out a driver update on the wifi card on the PC side resolved the issue. Very strange it was only happening in this service and everything else was fine.

Thanks for the help.
by TheSirStumfy
Mon Oct 15, 2018 4:27 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4695

Re: Router dropping traffic as "drop invalid"

Steveocee suggested disabling fasttrack, it sadly did not work.
by TheSirStumfy
Mon Oct 15, 2018 4:26 pm
Forum: Beginner Basics
Topic: Need help with an online game
Replies: 2
Views: 896

Re: Need help with an online game

I have re posted the question to another post, because this one took almost a day to appear here.

Please refer to viewtopic.php?f=13&t=140438

also a mod can close this, so there wont be 2 same questions.
by TheSirStumfy
Mon Oct 15, 2018 3:54 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4695

Re: Router dropping traffic as "drop invalid"

Here is the FW setup > /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=\ invalid add action=ac...
by TheSirStumfy
Mon Oct 15, 2018 1:50 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4695

Re: Router dropping traffic as "drop invalid"

I will post the firewall in 1h, when i get back to the router, but i can tell you now its a QucikSet default rule set found in defconf. Also nothing except the routers quickset was changed. (noob - thats why i need help :D ) What really confuses me is that it was working fine than just out of nowher...
by TheSirStumfy
Mon Oct 15, 2018 1:31 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4695

Router dropping traffic as "drop invalid"

I really need some help please. Yesterday i was using a service that uses UDP ports in the 20000 ranges. Everything works fine, than after 10 min of usage the connection was dropped. After that it was impossible to reconnect. When i check the router the traffic seems to go into the "drop invali...
by TheSirStumfy
Sun Oct 14, 2018 8:02 pm
Forum: Beginner Basics
Topic: Need help with an online game
Replies: 2
Views: 896

Need help with an online game

Ok im a noob when it comes to MikroTik but i have a problem. I was trying to play a game after upgrading to a MikroTik router. It worked fine for a bout 15 min then disconnected. I checked the firewall and i see that the login packets get sent into the defconf: drop invalid. Strange thing is that it...