Community discussions

MikroTik App

Search found 52 matches

by webguyz
Thu Nov 17, 2022 5:43 pm
Forum: General
Topic: Getting 789 errors when trying to access outside VPN's
Replies: 2
Views: 488

Re: Getting 789 errors when trying to access outside VPN's

Found the problem. Had port 500 blocked in my forwarding rule. Disabled and now everything is working.

Thanks!
by webguyz
Thu Nov 17, 2022 4:55 pm
Forum: General
Topic: Getting 789 errors when trying to access outside VPN's
Replies: 2
Views: 488

Getting 789 errors when trying to access outside VPN's

I have some servers on a Mikrotik network that are working fine and they need to connect via VPN to a network outside connecting to a Meraki router. I am using the builtin Windows VPN with L2TP and settings that work fine from other PC's around the network and every time I try accessing I get a 789 ...
by webguyz
Sat Nov 06, 2021 2:34 pm
Forum: Beginner Basics
Topic: Cap input bandwidth to avoid overage charges
Replies: 2
Views: 719

Re: Cap input bandwidth to avoid overage charges

Mispoke, my bandwidth is dedicated 80megabit circuit.
by webguyz
Sat Nov 06, 2021 5:25 am
Forum: Beginner Basics
Topic: Cap input bandwidth to avoid overage charges
Replies: 2
Views: 719

Cap input bandwidth to avoid overage charges

Hi, Have an ISP where I have 80mb with a Mikrotik DUDE router. My isp has capped our bandwidth at their Ciscos in the past but after renewing they said they will no longer do that and recommended I do it on my main router. What ths best way to limit my Mikrotik to no more then 80mb in. My concern if...
by webguyz
Thu May 28, 2020 5:38 am
Forum: General
Topic: Can not login, but router still working
Replies: 3
Views: 1128

Re: Can not login, but router still working

Blocked GRE and UDP connection 500 in forward chain which should block incoming VPN
by webguyz
Thu May 28, 2020 4:12 am
Forum: General
Topic: Can not login, but router still working
Replies: 3
Views: 1128

Re: Can not login, but router still working

Was able to reboot the Dude and get logins again. Seeing a lot of ppp attempts at about when the problem started. Not using ppp or VPN's right now. What port(s) do I block or how to stop anyone trying to log into my ppp ports. Might be the attacks are causing the login auth mechanism to get locked u...
by webguyz
Wed May 27, 2020 8:24 pm
Forum: General
Topic: Can not login, but router still working
Replies: 3
Views: 1128

Can not login, but router still working

have a Mikrotik Dude Edition that been working fine, but today my Cactus Graphs stopped working so I tried to login to the router and was not able to. It just times out after about 30 seconds and says invalid username password. Using WinBox tried to access via Neighbors but not getting a MAC address...
by webguyz
Mon Sep 09, 2019 9:54 pm
Forum: Beginner Basics
Topic: Not getting browser response back on new subnet
Replies: 8
Views: 1775

Re: Not getting browser response back on new subnet

Decided to create rules for well know ports like 22, 3306, etc with the DROP option and then set up access lists for valid users. The subnet is not that large and it will work out best that way.

Thanks!
by webguyz
Mon Sep 09, 2019 6:56 pm
Forum: Beginner Basics
Topic: Not getting browser response back on new subnet
Replies: 8
Views: 1775

Re: Not getting browser response back on new subnet


You should add another rule to allow your outbound traffic.
Can you give me a sample of a rule to allow outbound traffic?
by webguyz
Mon Sep 09, 2019 6:02 pm
Forum: Beginner Basics
Topic: Not getting browser response back on new subnet
Replies: 8
Views: 1775

Re: Not getting browser response back on new subnet

I have a rule #1 RDP port 3389 which is for Windows Remote Desktop. It works great and allows access to the Windows servers on that subnet and all functions on that server. But when I go to Chrome on that server it does not go to the website. if I type google.com.com or ipchicken.com nothing comes b...
by webguyz
Mon Sep 09, 2019 5:32 pm
Forum: Beginner Basics
Topic: Not getting browser response back on new subnet
Replies: 8
Views: 1775

Re: Not getting browser response back on new subnet

You have no rule that allows new traffic from inside the subnet except for ICMP. So that is not surprising. Also the "Drop everything else" comment for rule 3 is misleading because that is not what the rule does. (and because there is a default "Accept" at the end of every rule ...
by webguyz
Mon Sep 09, 2019 4:59 pm
Forum: Beginner Basics
Topic: Not getting browser response back on new subnet
Replies: 8
Views: 1775

Not getting browser response back on new subnet

Have a new subnet from my isp so I set up a Mikrotik CHR as a VM (on Hyper-v server). It seems to work ok but if I RDP into a windows machine on that subnet I can not get any browser responses back from within that vm. If I disable that final DROP all statement then the browser responses show up. I ...
by webguyz
Sun Mar 03, 2019 6:43 pm
Forum: General
Topic: My mikrotik logins stopped working
Replies: 5
Views: 1281

Re: My mikrotik logins stopped working

Powered off the Mikrotik to reboot. Everything came up ok. The logs showed no access to the Mikrotik other the my own so it was not compromised. Probably of bug of some sort. Will upgrade to the latest and greatest.

Thanks all.
by webguyz
Sat Mar 02, 2019 9:14 pm
Forum: Beginner Basics
Topic: Does a single touch of reset button reboot the Mikrotik router
Replies: 2
Views: 872

Does a single touch of reset button reboot the Mikrotik router

Have had Mikrotik for a while and always rebooted the router using commands in Windbox. Today I can't login to the Mikrotik and want to reboot the router but not redo the configuration. Googling "restart mikrotik" it keeps talking about holding in the reset button and power off the Mikroti...
by webguyz
Sat Mar 02, 2019 7:07 pm
Forum: General
Topic: My mikrotik logins stopped working
Replies: 5
Views: 1281

Re: My mikrotik logins stopped working

I have Cactus monitor and it stopped pulling SNMP data at about 10:30pm last night so something seems to have locked up inside the router.

Again, all networking function are working and I can access all devices behind the Mikrotik but not the Mikrotik itself. Wierd
by webguyz
Sat Mar 02, 2019 6:47 pm
Forum: General
Topic: My mikrotik logins stopped working
Replies: 5
Views: 1281

Re: My mikrotik logins stopped working

It was one less then the current one. The router is about 2 months old and has the OS that came installed on it
by webguyz
Sat Mar 02, 2019 6:36 pm
Forum: General
Topic: My mikrotik logins stopped working
Replies: 5
Views: 1281

My mikrotik logins stopped working

Have a DUDE mikrotik and was working fine until about midnight, now I can no longer login. When I try to connect it just says connecting and never completes All router functions are working and I can access all devices behind the Mikrotik but no longer able to log in to the Mikrotik. I had some list...
by webguyz
Fri Oct 12, 2018 7:57 pm
Forum: Beginner Basics
Topic: Moving config from RB1200 to RB1100AHX4
Replies: 2
Views: 905

Moving config from RB1200 to RB1100AHX4

Currently have an RB1200 and want to replace it with a RB1100AHx4. Was hoping to replicate the routing functions and address lists. What the best way to accomplish this to ensure least amount of problems. Was thinking that i would need to export a complete config and then search and replace the inte...
by webguyz
Wed Mar 08, 2017 4:19 pm
Forum: Beginner Basics
Topic: Hyper-V and Mikrotik
Replies: 3
Views: 3546

Re: Hyper-V and Mikrotik

Installed CHR last night on a test system and its working with Hyper-V. Think this will provide a solution for the colo box.

Thanks!
by webguyz
Tue Mar 07, 2017 5:55 pm
Forum: Beginner Basics
Topic: Hyper-V and Mikrotik
Replies: 3
Views: 3546

Hyper-V and Mikrotik

Was wondering if this would work. Want to create a Hyper-V server that has a single nic and it will be used for colocation. Will be getting a v4 64 IP allotment. Wanted to create a Mikrotik VM that will accept the 64 and route to Hyper-v internal switch. The Mikrotik will have 2 nics, one external s...
by webguyz
Fri Jul 22, 2016 8:20 pm
Forum: General
Topic: Will RB1200 handle a 50 meg internet connection?
Replies: 0
Views: 578

Will RB1200 handle a 50 meg internet connection?

Have a RB1200 that I was thinking of using with a 50 meg connection. It has a lot of ip address lists I use for blocking various services and a few rules but that's it. Should it be able to handle that? Currently have a 5 meg connection  and not wanting to upgrade the router right now if I can help ...
by webguyz
Thu Feb 25, 2016 4:05 pm
Forum: Beginner Basics
Topic: Need a place to start with rate limiting inbound traffic
Replies: 4
Views: 1246

Re: Need a place to start with rate limiting inbound traffic

I have 5000 Ips hitting my one mail server from the outside, I need to rate limit 3 of the incoming IPs.

Simple queues are for rate limiting IP's behind the Mikrotik, need a way to rate limit 3 or more incoming IP's to my mail server which is behind the Mikrotik.

Thanks!
by webguyz
Thu Feb 25, 2016 6:56 am
Forum: Beginner Basics
Topic: Need a place to start with rate limiting inbound traffic
Replies: 4
Views: 1246

Re: Need a place to start with rate limiting inbound traffic

I have tried this before but there is no traffic showing on the queue

In your example is the 10.10.9.3/32 address behind the Mikrotik or outside the Mikrotik?

I think I have to do something with marking packets but the process is not being understood by me.

Thanks.
by webguyz
Thu Feb 25, 2016 6:00 am
Forum: Beginner Basics
Topic: Need a place to start with rate limiting inbound traffic
Replies: 4
Views: 1246

Need a place to start with rate limiting inbound traffic

Totally confused about the different ways to limit traffic. Hoping if I explain what I'm trying to do someone can point me in the right direction. We have customers connecting to an IMAP server behind our Mikrotik and some of them are taking a lot of bandwidth to the point its maxing out my bandwidt...
by webguyz
Mon Feb 01, 2016 6:24 am
Forum: Scripting
Topic: Trying to delete an ip address in a list using ftp
Replies: 1
Views: 787

Re: Trying to delete an ip address in a list using ftp

I found what I is what I was looking for:

/ip firewall address-list remove [find address=X.X.X.X list=remote_evilhosts]

Thanks!
by webguyz
Mon Feb 01, 2016 4:49 am
Forum: Scripting
Topic: Trying to delete an ip address in a list using ftp
Replies: 1
Views: 787

Trying to delete an ip address in a list using ftp

I am successfully adding IP address using an ftp upload scrip, but now sure how to create a script to remove an ip from a specific list tried this but it wiped out my list so it must be close. Need to specify in the script the IP address to remove but not sure where to put it. "/ip firewall add...
by webguyz
Fri Sep 04, 2015 6:58 pm
Forum: Beginner Basics
Topic: Limit all FTP traffic for my servers
Replies: 1
Views: 887

Limit all FTP traffic for my servers

Have a number of vm's behind my Mitrotik and need to limit ALL ftp traffic to all IP. I use Simple queues to limit certain IP, but not sure how to limit a protocol network wide. having customer use FTP and its saturating my overall Internet Bandwidth. If anyone could point me to a link that explains...
by webguyz
Sat Oct 04, 2014 4:04 pm
Forum: General
Topic: Question about DST-NAT
Replies: 3
Views: 1294

Re: Question about DST-NAT

I think that's what it needed. I restarted the Mikrotik and it worked.

Thanks!
by webguyz
Sat Oct 04, 2014 5:58 am
Forum: General
Topic: Question about DST-NAT
Replies: 3
Views: 1294

Question about DST-NAT

I have a Mikrotik with a DST-NAT rule where the inbound IP is 72.249.59.40:587 -> 72.249.59.40:2525 and its working great. I move the application to another IP and it stopped working I changed the dst-nat action from IP 72.249.59.40:2525 to 72.249.59.45:2525 and it refused to forward the packets. My...
by webguyz
Mon Nov 05, 2012 4:42 pm
Forum: Beginner Basics
Topic: Having problems getting src-nat and dst-nat with a single ip
Replies: 5
Views: 1741

Re: Having problems getting src-nat and dst-nat with a singl

Thats what I'm doing now. I have over a 100 vm's all with a dedicated IPs. Lets say tomorrow I move to another data center and I am given new sets of Public Internet IP's. Now imagine having to go to each virtual server and manually changing each set of IP's. Been there and done that before and its ...
by webguyz
Sun Nov 04, 2012 11:54 pm
Forum: Beginner Basics
Topic: Having problems getting src-nat and dst-nat with a single ip
Replies: 5
Views: 1741

Re: Having problems getting src-nat and dst-nat with a singl

Doing some more reading it appears I can accomplish what I need by using the action=netmap to do 1:1 mapping 1:1 mapping If you want to link Public IP subnet 11.11.11.0/24 to local one 2.2.2.0/24, you should use destination address translation and source address translation features with action=netm...
by webguyz
Sun Nov 04, 2012 10:26 pm
Forum: Beginner Basics
Topic: Having problems getting src-nat and dst-nat with a single ip
Replies: 5
Views: 1741

Having problems getting src-nat and dst-nat with a single ip

I have a debian server ip address 10.0.59.201 with minimal IPTABLES (dns, ping, ssh) I have a Mikrotik fw that has a Public IP range 73.250.59.0/24 I want to expose this private local server to the internet and have inbound outbound traffic go thru a single IP (73.250.59.201). I did for outgoing: ch...
by webguyz
Wed Jul 25, 2012 5:01 pm
Forum: Scripting
Topic: Fetch upload auto.rsc between routers not executing
Replies: 11
Views: 10254

Re: Fetch upload auto.rsc between routers not executing

Simple fix was to just add a blank line at the end of the script. Now its working as expected.
by webguyz
Wed Jul 25, 2012 9:53 am
Forum: Scripting
Topic: Fetch upload auto.rsc between routers not executing
Replies: 11
Views: 10254

Re: Fetch upload auto.rsc between routers not executing

Any resolution to this? Running into the same problem with ftp. Have to upload it twice.

Thanks!
by webguyz
Thu Feb 16, 2012 5:02 pm
Forum: General
Topic: Need a reporting package to show Internet usage per user
Replies: 4
Views: 1982

Re: Need a reporting package to show Internet usage per user

I have worked with PRTG and its too much for my customers. They use Active Directory for authentication. The Mikrotik is just a basic router and NAT firewall. My best bet is to find a Proxy server that has Active Directory intergration. Ran across this yesterday and it looks promising. http://www.wa...
by webguyz
Thu Feb 16, 2012 12:41 am
Forum: General
Topic: Need a reporting package to show Internet usage per user
Replies: 4
Views: 1982

Need a reporting package to show Internet usage per user

Have a customer with a Mikrotik router who wants nice graphs of internet usage by user. Can anyone recommend a nice windows based proxy software (they are a windows shop) that will allow outgoing traffic to the Mikrotik be re-routed to a standalone proxy for getting stats, etc. and then being sent o...
by webguyz
Sun Nov 20, 2011 5:35 am
Forum: Beginner Basics
Topic: Possible to limit IP to certain MAC addresses?
Replies: 2
Views: 1164

Re: Possible to limit IP to certain MAC addresses?

Thanks! thats just what I needed.
by webguyz
Sat Nov 19, 2011 6:00 am
Forum: Beginner Basics
Topic: Possible to limit IP to certain MAC addresses?
Replies: 2
Views: 1164

Possible to limit IP to certain MAC addresses?

I have a number of VPS servers behind a Mikrotik router. I have a Class C and give out 1 IP addresses to each VPS. I would like to prevent a user from an adding additional IP to his VPS without my approval. Anyone who is network savy would see that their IP is on a class C and they could try to bind...
by webguyz
Fri Aug 05, 2011 12:30 am
Forum: General
Topic: Mikrotik / Ntop / Sawmill: trying to get them to work togeth
Replies: 5
Views: 2961

Re: Mikrotik / Ntop / Sawmill: trying to get them to work to

I ended up getting the freeware version of PRTG (up to 10 devices) and it supports Netflow. Not sure I can get everything I need with syslog.
by webguyz
Wed Aug 03, 2011 4:30 pm
Forum: General
Topic: Mikrotik / Ntop / Sawmill: trying to get them to work togeth
Replies: 5
Views: 2961

Re: Mikrotik / Ntop / Sawmill: trying to get them to work to

Doing more digging it appears that Sawmill can read in ascii logs, but ntop puts out raw data. Need a tool like nfdump to convert the rae data to ascii. Unfortunately they have no Linux at their shop and cant seem to find a netflow ascii exporter that runs under windows.
by webguyz
Wed Aug 03, 2011 7:29 am
Forum: General
Topic: Mikrotik / Ntop / Sawmill: trying to get them to work togeth
Replies: 5
Views: 2961

Mikrotik / Ntop / Sawmill: trying to get them to work togeth

Hi, Trying to collect Netflow info via Ntop on my V5 OS. Set up Ip/Traffic Flow to use Version 5 and its going to my server where I have Ntop running and its collecting what looks like raw data with a .flow extension. Supposedly Sawmill supports Mikrotik log format, but when I try and create a profi...
by webguyz
Tue Jul 12, 2011 6:33 pm
Forum: General
Topic: SSTP Questions in RoS5beta1 (bug?)
Replies: 11
Views: 12850

Re: SSTP Questions in RoS5beta1 (bug?)

Even though this is an old thread I am having the exact same problem and the same 0x80070320 error when attempting to connect to my SSTP server which is a RB1200 with os 5.5 from a Windows 7 client. I have a cert from rapidssl and the cert status when I do a /certificate print of cert1 (my cert that...
by webguyz
Sun Jul 10, 2011 5:25 pm
Forum: RouterBOARD hardware
Topic: RB 1200 Crash
Replies: 5
Views: 1936

Re: RB 1200 Crash

Have you tried unplugging the power and waiting 30 seconds. On our RB1200 if you unplug the power and don't wait a few extra seconds it won't come up. Count to 30 before plugging it back in. :?
by webguyz
Wed Jul 06, 2011 2:22 am
Forum: RouterBOARD hardware
Topic: RB1100AH power cycle required on upgrade
Replies: 7
Views: 3748

Re: RB1100AH power cycle required on upgrade

Just happened to me on RB1200 upgrading from 5.2 to 5.5. Did this remotely so I had the remote hands guys unplug the rb1200 and plug it back in and it still would not come up. Finally I had my tech go down to the datacenter and unlplug the power and wait for almost a minute before plugging the power...
by webguyz
Tue Jul 05, 2011 3:57 am
Forum: RouterBOARD hardware
Topic: Just checking to make sure the file type when ugrading
Replies: 1
Views: 801

Just checking to make sure the file type when ugrading

Have an RB1200 and doing an OS upgrade on this box for the first time. Just wanted to confirm that the files I need to upload all have the -ppc- in the name. The exisiting package list says routeros-powerpc on the top line. Was wondering if I'm missing something. Don't want to screw up my production...
by webguyz
Sat Jul 02, 2011 10:24 pm
Forum: RouterBOARD hardware
Topic: Anyone have a RB1200 in a rack?
Replies: 20
Views: 6904

Re: Anyone have a RB1200 in a rack?

Thanks for the info!!
by webguyz
Thu Jun 30, 2011 10:11 pm
Forum: RouterBOARD hardware
Topic: Anyone have a RB1200 in a rack?
Replies: 20
Views: 6904

Anyone have a RB1200 in a rack?

I have my RB1200 here in my lab and noticed the temperature is about 50c. According to the specs it can handle up to 65c. My concern is that this is going to get installed in the back of our rack facing the hot aisle and handling a lot of traffic. Concerned that this may be kind of high and wonderin...
by webguyz
Thu Jul 08, 2010 1:41 am
Forum: Wireless Networking
Topic: Trying to add wireless R52n to my old 532a routherboard
Replies: 1
Views: 762

Trying to add wireless R52n to my old 532a routherboard

Hi, Have a faithful old 532A router in my lab thats working fine. Wanted to add a wireless bridge capability to it so I got a R52n wireless card so I could extend my network further in my office to my lab. I assumed the wirelss card would just be picked up in the list of interfaces, but not so. I ha...
by webguyz
Fri Dec 14, 2007 2:47 pm
Forum: Scripting
Topic: How do I add rules remotely? Need to block spammers
Replies: 4
Views: 1943

How do I add rules remotely? Need to block spammers

Hi, I have a server tool that harvests spammers IP's and would like to be able to script adding firewall rules to my Mikrotik. Every few minutes I would like to connect to my Mikrotik and add new IPs and the port number 25 to have them be blocked. Can I do this using telnet or FTP? Is it even possib...
by webguyz
Mon Oct 15, 2007 9:20 pm
Forum: Beginner Basics
Topic: Question about defining multiple default gateways
Replies: 2
Views: 1601

Re: Question about defining multiple default gateways

A google of "mikrotik routing marks" brought me to a page which I think describes what I'm trying to do:

http://wiki.mikrotik.com/wiki/Load_Bala ... e_Gateways

Thanks!
by webguyz
Mon Oct 15, 2007 8:14 pm
Forum: Beginner Basics
Topic: Question about defining multiple default gateways
Replies: 2
Views: 1601

Question about defining multiple default gateways

Hi, Have a network at a colo facility where I was given 5 different Clas C subnets, 2 on one network and 3 on a second network. My Mikrotik has 2 NICs, one going to each ISP provider A = nets 110.x.x.x, 82.x.x.x provider B = nets 111.x.x.x, 113.x.x.x, 121.x.x.x Any traffic from 113. network has to g...