Community discussions

MikroTik App

Search found 177 matches

by erkexzcx
Wed Mar 03, 2021 4:11 pm
Forum: General
Topic: IMPROVEMENT: Allow closing Winbox windows with middle click on the title bar
Replies: 1
Views: 131

Re: IMPROVEMENT: Allow closing Winbox windows with middle click on the title bar

TIL: I can close tabs in browser with a middle mouse button. Thanks, but this is totally not needed for WinBox.
by erkexzcx
Fri Feb 26, 2021 3:03 pm
Forum: Beginner Basics
Topic: PC can not reach internet, router can.
Replies: 8
Views: 505

Re: PC can not reach internet, router can.

Show your firewall filter rules.
by erkexzcx
Fri Feb 26, 2021 2:58 pm
Forum: Beginner Basics
Topic: IKEv2 VPN
Replies: 6
Views: 426

Re: IKEv2 VPN

I wanted to do the same. Basically you need to do majority of steps from this while having this in mind. Finally I end up with this and can't get over it (works fine on Android phone using Strongswan client, but not from Windows PC native IPSEC/IKE2).
by erkexzcx
Tue Feb 23, 2021 10:59 am
Forum: General
Topic: Loss of trafic for a few seconds every 20 minutes in a EoIP tunnel
Replies: 3
Views: 140

Re: Loss of trafic for a few seconds every 20 minutes in a EoIP tunnel

Tried disabling EoIP keepalive (in EoIP interface settings) on both sides?
by erkexzcx
Tue Feb 23, 2021 10:57 am
Forum: General
Topic: Winbox - Darkmode - For the love of God, Please. [SOLVED]
Replies: 11
Views: 707

Re: Winbox - Darkmode - For the love of God, Please. [SOLVED]

or at least option to reverse colors of WinBox :D
by erkexzcx
Tue Feb 23, 2021 10:45 am
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 625

Re: Double NAT & no public IP for VPN [SOLVED]

I've looked at that topic too, and unless I've missed something, the responder (server) must have a public IP or port-forwarding from a public IP must be possible. So not applicable for your case. User still has to purchase VPS with public IP in order to have public IP. Linode was just an example (...
by erkexzcx
Tue Feb 23, 2021 10:36 am
Forum: General
Topic: block internet access but allow some sites - NOT WORKING
Replies: 7
Views: 393

Re: block internet access but allow some sites - NOT WORKING

Sites blocking is never going to work. At some point user will start using VPN provider and there is no way to block it (e.g. NordVPN can use 443 over TCP as well as obfuscated traffic).
by erkexzcx
Tue Feb 23, 2021 10:24 am
Forum: General
Topic: Is SWOS still in development?
Replies: 0
Views: 95

Is SWOS still in development?

Just wondering what is the state of SwitchOS of Mikrotik? The last update was from 2020, and when I purchased CRS112-8P-4S-IN it came only with ROS. No option to dual boot.
by erkexzcx
Tue Feb 23, 2021 10:18 am
Forum: Beginner Basics
Topic: EOIP over IPSEC tunnel connection is unstable
Replies: 2
Views: 208

Re: EOIP over IPSEC tunnel connection is unstable

Did you check this? viewtopic.php?f=23&t=169538 I've got it working perfectly fine.
by erkexzcx
Tue Feb 23, 2021 10:16 am
Forum: Beginner Basics
Topic: Setup VPN on a Router
Replies: 2
Views: 259

Re: Setup VPN on a Router

How about going to actual official Mikrotik wiki and using guides from there? Also users in Mikrotik forum posted few as well. e.g. I created this: https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 + https://forum.mikrotik.com/viewtopic.php?t=151188#p839793 One of the best guides online I f...
by erkexzcx
Tue Feb 23, 2021 10:12 am
Forum: Beginner Basics
Topic: help please
Replies: 10
Views: 438

Re: help please

There is something you can do:)
  • Whitelist access for your specific IPs. That's what firewalls are for, not just logging.
  • Auto add such attempts to "address-list" and drop such connections from recorded address-list in "/ip raw"
  • Disable logging and forget.
by erkexzcx
Tue Feb 23, 2021 9:59 am
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 625

Re: Double NAT & no public IP for VPN [SOLVED]

Thanks for the solution. I'm thinking about this in a whole month. And you are right Vultr is the cheapest VPS I found so far Have you tried OpenVPN Cloud? or AWS free tier + OpenVPN Just FYI - Mikrotik ROS can be installed on x86_64 hardware, and I mean virtual machine. What I am trying to say tha...
by erkexzcx
Sat Feb 13, 2021 8:33 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 5
Views: 408

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

I think Windows 10 built-in VPN client still doesn't understand sha256 when doing phase 2 and modp2048 when doing phase 1. Change or add profiles dh-group to modp1024 and proposals auth-algorithms to sha1. I haven't tested it for myself, but you should try this. It logs you can see that VPN connect...
by erkexzcx
Sat Feb 13, 2021 8:32 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 5
Views: 408

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

See my post here.
Nothing that could help me there
by erkexzcx
Sat Feb 13, 2021 3:19 pm
Forum: General
Topic: Speedtest.net - How to bypass
Replies: 10
Views: 10540

Re: Speedtest.net - How to bypass

Let's talk about NordVPN - it allows you to unblock websites & get around throttling on any crappy ISP. :) And you can't block it.

Blocking websites is not going to work.
by erkexzcx
Sat Feb 13, 2021 12:43 pm
Forum: General
Topic: Speedtest.net - How to bypass
Replies: 10
Views: 10540

Re: Speedtest.net - How to bypass

This is what I would do: 1. Use "nslookup speedtest.net" to resolve to IP address. 2. Take a single IP address and google it. Find "ipinfo.io" website in results and check it. Find "ASHandle" value and check it. In this case I've ended up with this link https://ipinfo.i...
by erkexzcx
Sat Feb 13, 2021 12:30 pm
Forum: General
Topic: Problems with IPSec - only one device can connect
Replies: 3
Views: 342

Re: Problems with IPSec - only one device can connect

I just created another thread in here. I've shared the configuration that works for me: https://forum.mikrotik.com/viewtopic.php?f=2&t=172558 On the other hand, I've written few guides there and there, so you can take a look too: https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 https:/...
by erkexzcx
Sat Feb 13, 2021 12:25 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 5
Views: 408

Windows 10 unable to connect to IPSEC/IKE2 VPN

I've setup IPSEC/IKE2 VPN server on my Mikrotik router. This is how I set it up: # Generate CA /certificate add name="My CA" common-name="My CA" key-size=4096 days-valid=3650 key-usage=key-cert-sign,crl-sign # Generate client and server certs /certificate add name="My client...
by erkexzcx
Wed Feb 10, 2021 8:50 am
Forum: Beginner Basics
Topic: NordVPN issue
Replies: 8
Views: 2449

Re: NordVPN issue

viewtopic.php?f=23&t=169273 I think Mikrotik should pin this thread so more people can see.
by erkexzcx
Sun Feb 07, 2021 4:54 pm
Forum: Useful user articles
Topic: Hairpin NAT - the easy way
Replies: 2
Views: 392

Hairpin NAT - the easy way

Decided to write a simple guide on Hairpin NAT, because quite a lot of users struggle to understand how to set it up. I am not a networking professional and I am open to any criticism on how to implement it in a better way. Official wiki page by Mikrotik regarding Hairpin NAT: https://wiki.mikrotik....
by erkexzcx
Sun Feb 07, 2021 4:16 pm
Forum: General
Topic: Firewall mess
Replies: 2
Views: 245

Re: Firewall mess

I am not sure what you are asking, but you should clean it up and rebuild as per instructions here: https://help.mikrotik.com/docs/display/ ... t+Firewall

Also use this to secure your router https://help.mikrotik.com/docs/display/ ... our+router
by erkexzcx
Sun Feb 07, 2021 3:35 pm
Forum: General
Topic: Is my IP blocked on Mikrotik servers, or is it my ISP being crap?
Replies: 1
Views: 190

Is my IP blocked on Mikrotik servers, or is it my ISP being crap?

I have a very strange issue - for some reason I am no longer able access any Mikrotik websites, such as mikrotik.com, forum.mikrotik.com and help.mikrotik.com. I am also unable to fetch any updates directly from Mikrotik routers too. All other websites are loading fine, except Mikrotik's websites. O...
by erkexzcx
Tue Feb 02, 2021 10:55 am
Forum: Beginner Basics
Topic: My last hope.
Replies: 10
Views: 759

Re: My last hope.

Perform ping test from Mikrotik to 1.1.1.1. Then perform the same from your PC. Is the result almost identical?

We can't say what's wrong, unless you share your configuration with us.
by erkexzcx
Tue Jan 26, 2021 1:28 pm
Forum: General
Topic: Slow VPN performance?
Replies: 9
Views: 685

Re: Slow VPN performance?

Your router is not mentioned here: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Hardware_acceleration So it means that you will get terrible performance. I would also suggest bypassing fasttrack (either by using "notrack" or "allowing" traffic before fastrack rule) and tuning M...
by erkexzcx
Tue Jan 26, 2021 1:25 pm
Forum: Beginner Basics
Topic: Switch chip
Replies: 9
Views: 847

Re: Switch chip

After i configured the port as a access port in the switch chip , that particular port can not access the router using by winbox.
Thanks for sharing!
by erkexzcx
Mon Jan 25, 2021 1:38 pm
Forum: General
Topic: IPSEC Forwarding
Replies: 4
Views: 353

Re: IPSEC Forwarding

What?
But what else is required in order for IPSEC to establish a tunnel between these two drayteks when my mikrotik is feeding one of them internet?
by erkexzcx
Sun Jan 24, 2021 11:47 pm
Forum: General
Topic: Buy/Subscirbe VPN GAME Amazon Web Services (AWS)
Replies: 6
Views: 430

Re: Buy/Subscirbe VPN GAME Amazon Web Services (AWS)

Do you even realise what and why you are asking?
by erkexzcx
Sun Jan 24, 2021 11:40 pm
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 625

Re: Double NAT & no public IP for VPN [SOLVED]

You can't access Mikrotik router if it's behind NAT (which is owned by ISP).

But you can open the tunnel from your Mikrotik to VPN server, especially if you have another Mikrotik router with public IP. And I mean this: viewtopic.php?f=23&t=169538
by erkexzcx
Sun Jan 24, 2021 11:36 pm
Forum: Beginner Basics
Topic: IP sec negociation error
Replies: 6
Views: 480

Re: IP sec negociation error

I am probably blind. Where does it say that it fails?

From my own experience - you should check logs on both sides. They might not say anything in one side, but will specify where is the issue on the other side.

EDIT: Your blurred IP is still readable :D
by erkexzcx
Sun Jan 24, 2021 11:34 pm
Forum: Beginner Basics
Topic: NordVPN using IKEv2 - Low speeds and not functional?
Replies: 2
Views: 226

Re: NordVPN using IKEv2 - Low speeds and not functional?

Works perfectly on ROS6: viewtopic.php?f=23&t=169273

Check if you did not forget to bypass FastTrack as well as reduce MSS size. All steps are in the given link.
by erkexzcx
Mon Jan 18, 2021 10:11 am
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 5
Views: 1091

Re: VPN/ipsec with strongSwan

So to clarify things up for everyone - Strongswan app on Android has no option to force ignore this constraint. In order to fix it, you must generate a new certificate for your VPN server, but this time with correct subject-alt-name . E.g. I am always using "/ip cloud" DNS to connect to a ...
by erkexzcx
Sun Jan 17, 2021 9:11 pm
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 5
Views: 1091

Re: VPN/ipsec with strongSwan

+1 Android strongswan client. WTF How to get rid of it.
by erkexzcx
Sat Jan 16, 2021 12:47 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 27
Views: 4462

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Please tell me how to correctly forward the port for example for torrent in this configuration?
1. How is it related to this thread?
2. Why would you need port forward for...torrents?
by erkexzcx
Fri Jan 15, 2021 8:18 pm
Forum: RouterOS v7 BETA
Topic: Any chance to install ROS6 on Chateau 12?
Replies: 6
Views: 936

Any chance to install ROS6 on Chateau 12?

Any chance to get ROS6 working on Chateau 12 router? I know this router is ROS7 only. But let's be honest - this is a bit too aggressive approach from Mikrotik to force users to use beta software in order to get it more tested and more bugs fixed in the long run. Because of some bugs that affects co...
by erkexzcx
Wed Jan 06, 2021 6:24 pm
Forum: General
Topic: Feature request for mobile app. bandwidth limiter set
Replies: 2
Views: 225

Re: Feature request for mobile app. bandwidth limiter set

Wait until they figure out how to change MAC address. Seems they should not worry about VPNs in this case:)

Can you be more specific on what is missing in Mikrotik routers? You want to enable/disable internet access, throttle bandwidth or block certain websites?
by erkexzcx
Wed Jan 06, 2021 9:33 am
Forum: Beginner Basics
Topic: FIFA 21 loosing connection during game play
Replies: 3
Views: 535

Re: FIFA 21 loosing connection during game play

Try changing DHCP server's lease time from default 10min to something 1d or even 7 days.

This was the only fix for crappy company's laptop where pulsesecure VPN app was resetting every 10 minutes and causing very high CPU usage and mostly making laptop impossible to use. Maybe this is related. :)
by erkexzcx
Tue Jan 05, 2021 12:35 am
Forum: General
Topic: Isolate two bridges at Layer 2 [SOLVED]
Replies: 7
Views: 500

Re: Isolate two bridges at Layer 2 [SOLVED]

Correct regarding bridges - they are like separate interfaces. They have nothing common between them so no L2 routing between them is possible if you did not setup any exotic configurations. Instead you should probably use this: add action=drop chain=forward in-interface=bridge1 out-interface=bridge...
by erkexzcx
Mon Jan 04, 2021 11:49 am
Forum: General
Topic: WPA3 on existing Mikrotik routers/APs [SOLVED]
Replies: 23
Views: 20081

Re: WPA3 on existing Mikrotik routers/APs [SOLVED]

Talking about WPA3 security: https://arstechnica.com/information-technology/2019/04/serious-flaws-leave-wpa3-vulnerable-to-hacks-that-steal-wi-fi-passwords/ As long as clients are in transitional mode, they will connect to the WPA2-only access point. As soon as that happens, attackers have the four-...
by erkexzcx
Mon Jan 04, 2021 11:42 am
Forum: Beginner Basics
Topic: Server is not accessable through mikrotik router
Replies: 3
Views: 313

Re: Server is not accessable through mikrotik router

What is not working is I cant access my server ip 192.168.1.10 internally but server have internet.
what?
by erkexzcx
Mon Jan 04, 2021 11:39 am
Forum: RouterOS v7 BETA
Topic: Chateau LTE12 stop work
Replies: 2
Views: 770

Re: Chateau LTE12 stop work

Sometimes hardware fails. What about lights on router?
by erkexzcx
Thu Dec 31, 2020 10:18 am
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 677

Re: L2TP/IPsec Android Second phase problem

Sorry to answer so rarely, but I can only answer in the evenings. Not everyone has all day to spend on this forum :D I can't tell what is wrong from the logs. Unless someone else has anything to add, I would say - Android's native VPN is "faulty". I've had a colleague who was having simil...
by erkexzcx
Wed Dec 30, 2020 9:33 pm
Forum: Beginner Basics
Topic: Approximately 5s delay in TCP connections when using a static route via an address on bridge [SOLVED]
Replies: 5
Views: 584

Re: Approximately 5s delay in TCP connections when using a static route [SOLVED]

Seems your target destination (of your static route) is part of existing bridge. I once had similar issue and all was fixed when I enabled bridge firewall:

/interface bridge settings set use-ip-firewall=yes

It just fixed it for me. Maybe someone has better ways to fix this kind of issue.
by erkexzcx
Wed Dec 30, 2020 9:30 pm
Forum: Beginner Basics
Topic: Chateau LTE12: mtu info
Replies: 2
Views: 223

Re: Chateau LTE12: mtu info

What does field "Actual MTU" shows for lte1 interface? What would happen if you set MTU to 1550 for lte1?
by erkexzcx
Wed Dec 30, 2020 9:27 pm
Forum: Beginner Basics
Topic: OpenVPN weird behavior since changing to Microtik?
Replies: 1
Views: 205

Re: OpenVPN weird behavior since changing to Microtik?

How is Mikrotik related here?
by erkexzcx
Wed Dec 30, 2020 4:18 pm
Forum: General
Topic: Device on other side of EoIP are not being NATed to the Internet
Replies: 11
Views: 615

Re: Device on other side of EoIP are not being NATed to the Internet

I want device in REMOTE to be on the same subnet as those in CENTRAL. I also want the device from REMOTE to go through CENTRAL to access the internet, so the last NAT is done at CENTRAL. Correct me if I am wrong, but all you want is to add EoIP interface to a LAN bridge on each router, mark it as &...
by erkexzcx
Wed Dec 30, 2020 4:05 pm
Forum: RouterOS v7 BETA
Topic: hAP ac2 back from 7.1b3 failed [SOLVED]
Replies: 2
Views: 1549

Re: hAP ac2 back from 7.1b3 failed [SOLVED]

On the positive side, everyone who purchased Chateau12 is stuck with ROS7 only. To be honest, for home or small office, ROS7 is perfectly fine.

Netinstall should still work tho.
by erkexzcx
Wed Dec 30, 2020 1:08 pm
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 677

Re: L2TP/IPsec Android Second phase problem

I suspect your Android device and Mikrotik does not have overlapping ciphers. Anyway, enable "ipsec" logging in Mikrotik settings. Then try to connect using Android phone to VPN on Mikrotik router. Provide us logs. You should be able to see additional tag "debug" next to "ip...
by erkexzcx
Wed Dec 30, 2020 1:05 pm
Forum: General
Topic: IPsec dynamic IP address
Replies: 3
Views: 408

Re: IPsec dynamic IP address

You should learn how to write your questions in a more organized way. Code formatting is also a thing (useful for displaying a logs). If you want different policies for specific clients, then you should properly setup remote-id matching as well as specific mode configs and policies. I've done simila...
by erkexzcx
Tue Dec 29, 2020 2:54 pm
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 677

Re: L2TP/IPsec Android Second phase problem

Did you check threads like this? viewtopic.php?t=153546
by erkexzcx
Tue Dec 29, 2020 1:45 pm
Forum: Beginner Basics
Topic: Router was rebooted without proper shutdown [SOLVED]
Replies: 2
Views: 348

Re: Router was rebooted without proper shutdown [SOLVED]

Looks like either RouterOS crashed and rebooted (not sure if router reboots in this case, probably due to watchdog), or there was power issues. Maybe PSU is having issues, or your power supply had issues. I closed all the IP services except Winbox Did you whitelist access to router? Hopefully winbox...
by erkexzcx
Tue Dec 29, 2020 12:02 pm
Forum: Beginner Basics
Topic: Looking for a Product (Router)
Replies: 5
Views: 403

Re: Looking for a Product (Router)

A bit hard to recommend. 5G is not supported by Mikrotik, so LTE is the only option. Also Mikrotik support for OpenVPN is kind of "meh" (OpenVPN UDP is only supported in ROS7 which is beta, only TCP mode in ROS6). Would highly recommend sticking to L2TP/IPSEC or IPSEC/IKE2 instead. If you ...
by erkexzcx
Tue Dec 29, 2020 11:47 am
Forum: General
Topic: Can't get Policy based routing VPN to work
Replies: 7
Views: 584

Re: Can't get Policy based routing VPN to work

Does your VPN provider support IPSEC/IKE2? If so, you can configure using this guide: viewtopic.php?f=23&t=169273

I haven't got a chance to play much with PPTP and not sure if I ever will because this protocol is very unsafe.
by erkexzcx
Mon Dec 28, 2020 4:08 pm
Forum: General
Topic: ikev2 2 sessions under one certificate [SOLVED]
Replies: 2
Views: 323

Re: ikev2 2 sessions under one certificate [SOLVED]

Using same certificate might work..? If you ignore remote-id if I am not mistaken. Then VPN server cannot identity any of your client who is who, so just assigns random IP from the pool. Anyway, it's better to generate a separate certificate for each client and select "match-by=certificate"...
by erkexzcx
Mon Dec 28, 2020 4:02 pm
Forum: General
Topic: Can't get Policy based routing VPN to work
Replies: 7
Views: 584

Re: Can't get Policy based routing VPN to work

Few ideas on what's wrong: Netflix detects when you are running through VPN server. It detects when you are using non-residential IP. Netflix has more domains. Not just "netflix.net". You need to route all such traffic using VPN. Not sure, but I think "content" parameter in Mikro...
by erkexzcx
Mon Dec 28, 2020 3:13 pm
Forum: General
Topic: VPN for Mikrotik for game Mobile legend
Replies: 7
Views: 628

Re: VPN for Mikrotik for game Mobile legend

Not sure if you know anything about networking.

Just get a VPN subscription from a VPN provider, like NordVPN. See if it fixes the issue.
by erkexzcx
Mon Dec 28, 2020 2:56 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta3 [development] is released!
Replies: 262
Views: 42887

Re: v7.1beta3 [development] is released!

ipip tunnel still not working wihout disable keepalive When I wrote https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 I was using ROS7 as a VPN client to ROS6 VPN server. EoIP did work, but was silently flapping leading to random disconnects from online multiplayer games. Disabling keepali...
by erkexzcx
Sun Dec 27, 2020 10:25 pm
Forum: RouterOS v7 BETA
Topic: New Feature Request: run script after Wireguard connection status changed. [SOLVED]
Replies: 3
Views: 717

Re: New Feature Request: run script after Wireguard connection status changed. [SOLVED]

Can you use netwatch as a workaround for this (using any internal IP of wireguard)?
by erkexzcx
Sun Dec 27, 2020 5:33 pm
Forum: Beginner Basics
Topic: Questions about "Use host names in firewall rules" [SOLVED]
Replies: 3
Views: 447

Re: Questions about "Use host names in firewall rules" [SOLVED]

This router is so good, I'm really glad I bought it despite of my initial concerns.
Kinda the same here. Thanks to my previous job I had to deal with Mikrotik routers. They significantly boosted my understanding of networking. :)
by erkexzcx
Sun Dec 27, 2020 5:30 pm
Forum: Beginner Basics
Topic: Generate paket lost on specific destination ! [SOLVED]
Replies: 3
Views: 367

Re: Generate paket lost on specific destination ! [SOLVED]

Drops every 2nd packet when user pings to 95.217.228.176:
/ip firewall filter add action=drop chain=forward dst-address=95.217.228.176 nth=2,1
by erkexzcx
Sun Dec 27, 2020 5:20 pm
Forum: General
Topic: IPSEC IKEv2 network-to-network problems
Replies: 11
Views: 830

Re: IPSEC IKEv2 network-to-network problems

Not what you are asking, but it might give you some hints: viewtopic.php?f=23&t=169538
by erkexzcx
Sun Dec 27, 2020 5:15 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 27
Views: 4462

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Thanks for all the input! I've updated instructions accordingly.
by erkexzcx
Sun Dec 27, 2020 12:48 am
Forum: General
Topic: Mikrotik device behind limited ISP modem
Replies: 15
Views: 1104

Re: Mikrotik device behind limited ISP modem

This sounds like a Telia router in Lithuania, isn't it?
by erkexzcx
Sun Dec 27, 2020 12:46 am
Forum: General
Topic: Please finish implementation of OpenVPN protocol (authentication without password, certificates)
Replies: 5
Views: 472

Re: Please finish implementation of OpenVPN protocol (authentication without password, certificates)

I would say the opposite - better focus on other, more imporant things and release a stable ROS7. OpenVPN should start to die. It's one of the slowest VPN protocols. Instead, pick L2TP/IPSEC, IPSEC/IKE2 or Wireguard as an alternative as these are industry standard VPN protocols. OpenVPN has insanely...
by erkexzcx
Sat Dec 26, 2020 6:13 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 27
Views: 4462

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

@msatter - thanks for your input. I don't actually see it as a improvement to my given guide. I mean it does work, but using simple a mangle rule is a more dynamic way of dealing with VPN traffic. e.g. in address-list I gave domain which is being resolved by Mikrotik router. If it's updated, then it...
by erkexzcx
Thu Dec 24, 2020 8:48 pm
Forum: Beginner Basics
Topic: Changing internet provider
Replies: 3
Views: 401

Re: Changing internet provider

No, it does not depend...

You need to configure your router the same way you configured previously for your current ISP.
by erkexzcx
Thu Dec 24, 2020 8:43 pm
Forum: General
Topic: proton vpn seems not fully functional
Replies: 2
Views: 322

Re: proton vpn seems not fully functional

Try following this guide: viewtopic.php?f=23&t=169273

EDIT: You may need to reduce MSS size and exclude such traffic from fasttrack. Everything is mentioned in the above guide.
by erkexzcx
Thu Dec 24, 2020 12:55 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 27
Views: 4462

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

With use case #2, how to killswitch websites like youtube.com that with multiple IP address? You can't, because: Note: You can't effectively route all the traffic of Youtube, Netflix or any other big websites through VPN. They have many different domains and IP addresses which constantly change. In...
by erkexzcx
Thu Dec 24, 2020 1:47 am
Forum: Scripting
Topic: hairpin with 2 WAN
Replies: 2
Views: 399

Re: hairpin with 2 WAN

How about this? # Add both WAN interfaces to interfaces list. /interface list add name=WAN /interface list member add interface=ether1 list=WAN /interface list member add interface=ether2 list=WAN # Add this script to your Mikrotik router. /system script add name=dhcp_client_script source=":if ...
by erkexzcx
Wed Dec 23, 2020 9:54 am
Forum: Beginner Basics
Topic: Regarding Aggressive mode ipsec not working for peer (0.0.0.0/0) on ros above 6.43.13
Replies: 2
Views: 244

Re: Regarding Aggressive mode ipsec not working for peer (0.0.0.0/0) on ros above 6.43.13

if you enable "ipsec" debug logging in both Mikrotik and OpenWRT, what does the log says?
by erkexzcx
Wed Dec 23, 2020 1:18 am
Forum: General
Topic: Surfshark IKEv2 VPN
Replies: 13
Views: 6201

Re: Surfshark IKEv2 VPN

by erkexzcx
Wed Dec 23, 2020 1:13 am
Forum: General
Topic: Add Christmas lights to Chateau 12 router
Replies: 2
Views: 318

Re: Add Christmas lights to Chateau 12 router

Post a movie
Done. I've updated initial comment.
by erkexzcx
Wed Dec 23, 2020 12:52 am
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that
Replies: 6
Views: 1560

Re: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

1. on both Router A and Router B, you have a NAT rule, like below, why we need this rule: /ip firewall nat add action=src-nat chain=srcnat dst-address=10.22.22.2 to-addresses=10.22.22.1 place-before=0 Ping to internal IP (10.22.22.2) from Router A did not work without this rule, so I added it. 2. I...
by erkexzcx
Wed Dec 23, 2020 12:23 am
Forum: General
Topic: Add Christmas lights to Chateau 12 router
Replies: 2
Views: 318

Add Christmas lights to Chateau 12 router

Since this router does not have beeper and you can't play songs on it, but it does have controllable LEDs, so you can give it some Christmas vibes. Video: https://i.imgur.com/8380H4K.mp4 ( imgur post ). WARNING - High amount of sector writes. It will eventually kill your flash storage with the time....
by erkexzcx
Tue Dec 22, 2020 11:40 pm
Forum: RouterOS v7 BETA
Topic: Chateau Config Backup & Restore
Replies: 14
Views: 1293

Re: Chateau Config Backup & Restore

Backup & Restore always sucked for me. Always use export & restore. Most of the config appears to take except there's no DHCP server set and the network settings appear to be missing I would say remove such lines from the exported config try again? Then connect using MAC address. /tool bandw...
by erkexzcx
Tue Dec 22, 2020 2:35 pm
Forum: Beginner Basics
Topic: Problems with portforwarding.
Replies: 9
Views: 719

Re: Problems with portforwarding.

Sob he already had the default rule in place........ (but I much prefer the cleaner rule you suggested) add action=drop chain=forward comment="Drop incoming packets that are not NATted" connection-nat-state=!dstnat connection-state=new in-interface=ether1 log=yes log-prefix=!NAT Why would...
by erkexzcx
Sun Dec 20, 2020 12:52 pm
Forum: General
Topic: Equivalent Mikrotik IPSEC settings for this Linux config
Replies: 7
Views: 702

Re: Equivalent Mikrotik IPSEC settings for this Linux config

Before someone helps you, i will give you some hints on where to look at. I've written few guidelines here and here on how to connect Mikrotik router using IPSEC/IKEv2. You have have an idea how configuration looks like and what steps you should take (e.g. exclude from fasttrack, add NAT, optionally...
by erkexzcx
Wed Dec 16, 2020 8:09 pm
Forum: General
Topic: Question about VPN, pools and subnets [SOLVED]
Replies: 11
Views: 718

Re: Question about VPN, pools and subnets [SOLVED]

Aren't traffic, which is coming from the VPN clients, picked by these rules? Technically, connections are coming from WAN interfaces. /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=WAN /ip firewall filter add action=drop ch...
by erkexzcx
Wed Dec 16, 2020 7:56 pm
Forum: General
Topic: Password Questions
Replies: 3
Views: 342

Re: Password Questions

if anyone can shed some light or some thoughts on this that would be great. Either you enterred incorrect username/password, or someone has changed username/password which means someone else managed to access Mikrotik device. Instead of creating a new account, put a stronger password for "admi...
by erkexzcx
Wed Dec 16, 2020 7:50 pm
Forum: General
Topic: Remote Access VPN + Site to Site VPN
Replies: 4
Views: 451

Re: Remote Access VPN + Site to Site VPN

Is it possible that user when connects with remote access VPN to access network resources on remote site?
Yes
by erkexzcx
Wed Dec 16, 2020 4:02 pm
Forum: General
Topic: IPsec policy status Invalid [SOLVED]
Replies: 4
Views: 393

Re: IPsec policy status Invalid [SOLVED]

by erkexzcx
Tue Dec 15, 2020 6:32 pm
Forum: Beginner Basics
Topic: VPN config - stopped working.
Replies: 2
Views: 279

Re: VPN config - stopped working.

They have many servers, some of them gets DDOS'ed, some of them get's reconfigured or decommissioned. You likely need to switch to any other server. I've written more complete guide for NordVPN because some steps were missing in official guides: https://forum.mikrotik.com/viewtopic.php?f=23&t=16...
by erkexzcx
Tue Dec 15, 2020 6:29 pm
Forum: Beginner Basics
Topic: bridge got 2 dhcp addrs & mac
Replies: 2
Views: 290

Re: bridge got 2 dhcp addrs & mac

So what is the question?
by erkexzcx
Tue Dec 15, 2020 9:59 am
Forum: Beginner Basics
Topic: setting up router with two AP
Replies: 7
Views: 477

Re: setting up router with two AP

but will the wireless device automatically switch to the strongest signal?
+1 also interested.
by erkexzcx
Sat Dec 12, 2020 9:21 pm
Forum: General
Topic: VPN IKEv2 Client Problem
Replies: 3
Views: 467

Re: VPN IKEv2 Client Problem

Try following this instead: viewtopic.php?f=23&t=169273
by erkexzcx
Wed Dec 09, 2020 8:07 pm
Forum: Beginner Basics
Topic: HAP Ac3 5 Ghz speed problem
Replies: 6
Views: 686

Re: HAP Ac3 5 Ghz speed problem

Version is latest on both devices. There are RouterOS 7 beta, and RouterOS 6 stable... Anyway, I assume you are using ROS6. What would be the correct way to transfer all configuration This way: # 1. Export configuration from old router: /export file=myfile # 2. Download myfile.rsc to your computer....
by erkexzcx
Wed Dec 09, 2020 7:56 pm
Forum: Useful user articles
Topic: Howto wanted - block advertisement like Youtube
Replies: 5
Views: 1050

Re: Howto wanted - block advertisement like Youtube

I am still wondering given all the options of the OS why this should be so hard to do. I am trying to be helpful, but you clearly did not do enough research on your own. This is very wide topic on the internet, especially on the pi-hole forums. See https://discourse.pi-hole.net/t/how-do-i-block-ads...
by erkexzcx
Wed Dec 09, 2020 7:43 pm
Forum: Beginner Basics
Topic: HAP Ac3 5 Ghz speed problem
Replies: 6
Views: 686

Re: HAP Ac3 5 Ghz speed problem

I transferred all the settings that was on Ac2 5 ghz wifi to Ac3 5 ghz wifi but this thing simply don't work ok Just a question: How did you transfer those settings and what RouterOS version you are using? Did you transfer configuration by a backup or export? I've had issues with backup&restore...
by erkexzcx
Wed Dec 09, 2020 7:39 pm
Forum: Beginner Basics
Topic: LetsEncrypt for the Hotspot?
Replies: 3
Views: 377

Re: LetsEncrypt for the Hotspot?

Have you tried this? https://www.google.com/search?q=hotspot+ssl

There are tutorials from non-mikrotik sites as well as mikrotik wiki pages.
by erkexzcx
Wed Dec 09, 2020 7:32 pm
Forum: General
Topic: DNS over HTTPS, round robin support
Replies: 19
Views: 1304

Re: DNS over HTTPS, round robin support

Stupid question, but how does router know to which IP address to resolve cloudflare-dns.com domain, if you use only DoH?
by erkexzcx
Wed Dec 09, 2020 1:29 pm
Forum: Beginner Basics
Topic: access pfsense router behind mikrotik
Replies: 4
Views: 403

Re: access pfsense router behind mikrotik

Allow access to 172.18.0.1 in Mikrotik firewall from your LAN. This means you need to edit existing firewall rules. Add DST-NAT rule in Mikrotik so when reaching 172.18.0.1 your src-ip is rewritten to 172.18.0.3. Also your configuration is questionable in overall, but above solution should work.
by erkexzcx
Wed Dec 09, 2020 11:58 am
Forum: Useful user articles
Topic: Howto wanted - block advertisement like Youtube
Replies: 5
Views: 1050

Re: Howto wanted - block advertisement like Youtube

How would I do this best and with as simple as possible a solution?

Buy Youtube premium.

What you are asking is not possible and totally unrelated to Mikrotik.
by erkexzcx
Wed Dec 09, 2020 12:09 am
Forum: General
Topic: clients->ipsec router no internet [SOLVED]
Replies: 3
Views: 353

Re: clients->ipsec router no internet [SOLVED]

Aren't you supposed to specify out interface for it?
/ip firewall nat
...
add action=masquerade chain=srcnat
by erkexzcx
Tue Dec 08, 2020 12:55 am
Forum: Beginner Basics
Topic: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?
Replies: 5
Views: 539

Re: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?

Could it be related to software installed on the PC (virtualization systems, etc.)?

How each virtual machine gets IP addresses? From the router?
by erkexzcx
Tue Dec 08, 2020 12:38 am
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that
Replies: 6
Views: 1560

Re: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

According to your issue(s) description - you are not having any issues.
by erkexzcx
Mon Dec 07, 2020 1:49 am
Forum: Beginner Basics
Topic: OVPN Client not connected
Replies: 2
Views: 345

Re: OVPN Client not connected

How did you import certificates? Do you have CA? Did Mikrotik import private key? Double check:
/certificate print
by erkexzcx
Mon Dec 07, 2020 1:41 am
Forum: General
Topic: Ipsec dh group modp 1024 android no suitable proposal found
Replies: 2
Views: 307

Re: Ipsec dh group modp 1024 android no suitable proposal found

Enable ipsec logging and show full log when attempting to connect from smartphone:
/system logging add topics=ipsec action=memory
by erkexzcx
Sun Dec 06, 2020 1:26 pm
Forum: Scripting
Topic: Telegram
Replies: 6
Views: 1010

Re: Telegram

Answer is: No I did not manage to send directly from Mikrotik, because "fetch" tool does not support sending files. I managed to send using Raspberry Pi: Generate SSH keys on raspberry Pi and its upload public key to each router. Then pretty much use this bash script: #!/bin/bash ROUTER=$1...
by erkexzcx
Sun Dec 06, 2020 1:10 pm
Forum: Beginner Basics
Topic: travel router
Replies: 14
Views: 1375

Re: travel router

Your device is fine. It will work. Since you want encrypted tunnel to your home, I would suggest picking a router with IPSEC hardware acceleration, something like HAP AC2 would be great because it's cheap and supports both 5ghz/2.4ghz wifi. Everything else that you mentioned is possible. Even if you...
by erkexzcx
Sun Dec 06, 2020 1:01 pm
Forum: General
Topic: IPSec tunnel from mikrotik behind NAT with Cisco
Replies: 4
Views: 488

Re: IPSec tunnel from mikrotik behind NAT with Cisco

Since you've tried already (I assume), which part do you think is failing/not working?

When I started learning about IPSEC the only way to move forward was to enable ipsec logs in both Mikrotik routers and see what is actually failing or happening.

Can you show us some logs/configuration exports?
by erkexzcx
Sat Dec 05, 2020 7:50 pm
Forum: Beginner Basics
Topic: Vpn Site To Site With Vlan
Replies: 8
Views: 696

Re: Vpn Site To Site With Vlan

So how can I do to make the two microtiks communicate directly without NAT.
I need to connect the two VLANs as well.
There's a way?
I've done this. In both ends EoIP interface is added to main LAN bridges and basically LANs are connected.
by erkexzcx
Sat Dec 05, 2020 3:57 pm
Forum: General
Topic: IPSec tunnel from mikrotik behind NAT with Cisco
Replies: 4
Views: 488

Re: IPSec tunnel from mikrotik behind NAT with Cisco

Maybe this could help? Not really what you are asking, but you might get some hints.
by erkexzcx
Sat Dec 05, 2020 3:55 pm
Forum: General
Topic: PWR-LINE PRO
Replies: 15
Views: 2563

Re: PWR-LINE PRO

Sorry for hijacking thread, but for those who use PWR-LINE PRO - do you get additional latency? I've never used EoP devices before.

I've heard stories that when using such devices you might get somewhat 30ms latency, even tho internet connectivity is rock stable. Just want to hear if it's true.
by erkexzcx
Sat Dec 05, 2020 3:25 pm
Forum: Beginner Basics
Topic: How to block an IP range? [SOLVED]
Replies: 4
Views: 403

Re: How to block an IP range? [SOLVED]

Should I want to reverse this, what would be the code? You should not copy/paste code given by the stranger to your Mikrotik router and expect it to work. This means you should understand what those commands do and how to undo them. Hopefully you are using Winbox. WebFix is also an option, but I fi...
by erkexzcx
Sat Dec 05, 2020 3:01 pm
Forum: Beginner Basics
Topic: Issues with Mikrotik hAP AC2
Replies: 17
Views: 1525

Re: Issues with Mikrotik hAP AC2

I would also like to add that Mikrotik is not that messy. Obviously not perfect, but it isn't that buggy as users say. Pretty much sums up to this: Users: I want to do something with Mikrotik that I barely understand. Also users: Mikrotik is buggy I mean you are dealing with enterprise-grade equipme...
by erkexzcx
Fri Dec 04, 2020 8:45 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1069

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

I confirm that beta3 fixes this issue.
by erkexzcx
Thu Dec 03, 2020 9:08 pm
Forum: Beginner Basics
Topic: PCQ queue is better than without any queue?
Replies: 5
Views: 453

Re: PCQ queue is better than without any queue?

+1 interested in more information about it. From my understanding, queues are great when there is constantly not enough bandwidth for everyone, so someone always has to wait for other users to finish transmitting data. Queues would help because everyone will get fair amount of time to transmit data,...
by erkexzcx
Thu Dec 03, 2020 6:40 pm
Forum: General
Topic: Peplink to mikrotik VPN
Replies: 4
Views: 358

Re: Peplink to mikrotik VPN

https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP

Either ask something more specific, or that's all we could help.
by erkexzcx
Wed Dec 02, 2020 9:56 pm
Forum: Beginner Basics
Topic: RouterBOARD Emulator?
Replies: 2
Views: 365

Re: RouterBOARD Emulator?

Yes, they are called virtual machines and CHR images.

There are some other options as well.

Hopefully your router has already arrived. :)
by erkexzcx
Wed Dec 02, 2020 9:51 pm
Forum: Beginner Basics
Topic: How to block an IP range? [SOLVED]
Replies: 4
Views: 403

Re: How to block an IP range? [SOLVED]

First, you need to realise the networks you specified. The range "157.175.0.0-157.175.255.255" is the same as network "157.175.0.0/16". On the other hand, Mikrotik does support ranges (just do not use spaces). Make address list out of them: /ip firewall address-list add address=1...
by erkexzcx
Wed Dec 02, 2020 9:21 pm
Forum: Beginner Basics
Topic: Pivpn wireguard portforwarding problem [SOLVED]
Replies: 3
Views: 452

Re: Pivpn wireguard portforwarding problem [SOLVED]

Please use this for code. Helps if you want to receive help faster: [code] my code goes here [//code] I have few questions: Why would you need Mikrotik router for your setup in the first place? You are using modem, which means you don't have public IP (aka "direct access"), right? Why is y...
by erkexzcx
Wed Dec 02, 2020 9:08 pm
Forum: Beginner Basics
Topic: L2PT server won't work - Local clients won't connect
Replies: 4
Views: 402

Re: L2PT server won't work - Local clients won't connect

I am not sure if you show all available logs, or you just did not enable logging. Enable more logging using below command and share wider log:
/system logging add topics=ipsec,l2tp
by erkexzcx
Wed Dec 02, 2020 8:52 pm
Forum: Beginner Basics
Topic: Suggestions for new network
Replies: 2
Views: 242

Re: Suggestions for new network

Looks like you are trying to do something called "Security over obscurity". I am not sure what VPN you are using, but looks like you can do this (see 2nd use case). Set static IPs for your TVs, then add connection mark for your TVs traffic which is found by their their static source IP. Th...
by erkexzcx
Wed Dec 02, 2020 8:40 pm
Forum: Beginner Basics
Topic: 4011 affecting outbound services
Replies: 45
Views: 2733

Re: 4011 affecting outbound services

Maybe totally unrelated, don't by mad at me, but once I had to setup another router on my LAN which would act as a gateway. Then I setup static route in my main Mikrotik router, so if device is accessing <some_network>, route through that gateway on the LAN. Else - route as usual to the WAN. Turned ...
by erkexzcx
Wed Dec 02, 2020 8:30 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1069

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

erkexzcx: At home I have "Mikrotik RB4011iGS+RM" router and Netgear R7800 with OpenWRT acting as access point only. This setup is rock stable . Now I have "Mikrotik RB4011iGS+RM" working as router and "Mikrotik Chateau 12" as access point only. And this setup is causin...
by erkexzcx
Sun Nov 29, 2020 12:29 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1069

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

Disabling and re-enabling Wireless interface temporarily fixes the issue...
by erkexzcx
Sun Nov 29, 2020 11:22 am
Forum: General
Topic: 2 locations IPSEC, internet acces via tunnel
Replies: 5
Views: 678

Re: 2 locations IPSEC, internet acces via tunnel

I just can't miss opportunity to share my written guide :D https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 EDIT : See the bottom of that post. Basically you need to disable DHCP server in parents router, add estalbished EoIP interface to main LAN bridges in both your home and parents rout...
by erkexzcx
Sat Nov 28, 2020 6:44 pm
Forum: RouterOS v7 BETA
Topic: Chateau LTE12, Router OS v7.1beta2, packet loss
Replies: 6
Views: 947

Re: Chateau LTE12, Router OS v7.1beta2, packet loss

Let's make problem's description simple - you are getting packet loss only when you ping anything on the internet via LTE interface?
by erkexzcx
Sat Nov 28, 2020 5:54 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1069

Chateau 12 - WiFi no longer connects for a random device [SOLVED]

Description I have Chateau 12 Mikrotik router with latest ROS 7.1 beta2, which I am using as access point. I setup 2 WiFis - one for 2.4Ghz and the other one for 5Ghz. Since I have no point to use 2.4Ghz for now, I only use 5Ghz WiFi only. I don't know if this issue happens with 2.4Ghz. Main router...
by erkexzcx
Sat Nov 28, 2020 12:32 am
Forum: Beginner Basics
Topic: Using DHCP "Active Host Name" for local IP resolution
Replies: 3
Views: 697

Re: Using DHCP "Active Host Name" for local IP resolution

More or less you are looking at DNS server functionality. It's called "resursive DNS server" and that's what clients are using when they are getting resolutions from Mikrotik router. I am not sure if this is possible with Mikrotik directly, but you can set static entries in ip>dhcp server>...
by erkexzcx
Fri Nov 27, 2020 9:08 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 26
Views: 1442

Re: Ipsec not traffic passing

Not Working!
So what logs say? Enable ipsec logging and show the logs. What is happening in overall?
by erkexzcx
Fri Nov 27, 2020 7:36 pm
Forum: Beginner Basics
Topic: Understanding the Firewall rules. [SOLVED]
Replies: 3
Views: 459

Re: Understanding the Firewall rules. [SOLVED]

The rules you see in Mikrotik are kinda the same as you would see in Linux servers. E.g. https://github.com/trimstray/iptables-essentials https://gist.github.com/Tristor/ed0f6867d2b0fa4c1f80300af6e0e12e#file-iptables-sh It might help if you need additional resources regarding firewalls in Linux syst...
by erkexzcx
Fri Nov 27, 2020 6:49 pm
Forum: General
Topic: Transparent IP Mode
Replies: 2
Views: 315

Re: Transparent IP Mode

Isn't that the same as:
  1. Bridging 2 interfaces
  2. Giving IP address to the bridge
  3. Enabling bridge firewall (in bridge settings) and setting up such bridge firewall rules?
by erkexzcx
Fri Nov 27, 2020 4:36 pm
Forum: Announcements
Topic: v6.47.8 [stable] is released!
Replies: 56
Views: 13172

Re: v6.47.8 [stable] is released!

RBD52G-5HacD2HnD (HAP AC2) does not even show "health" option under "System" in Winbox. This is what happens when I check from CLI: [admin@name] > /system health print [admin@name] > But it works on RB4011iGS+: [admin@surname] > /system health print voltage: 23.5V temperature: 36...
by erkexzcx
Fri Nov 27, 2020 4:27 pm
Forum: General
Topic: Very frequent cloud.mikrotik.com activity [SOLVED]
Replies: 4
Views: 469

Re: Very frequent cloud.mikrotik.com activity [SOLVED]

https://wiki.mikrotik.com/wiki/Manual:IP/Cloud DDNS or Dynamic DNS is a service that updates the IPv4 address for A records and the IPv6 address for AAAA records periodically. Such a service is very useful when your ISP has provided a dynamic IP address that changes periodically, but you always need...
by erkexzcx
Fri Nov 27, 2020 4:22 pm
Forum: General
Topic: VPN solution for small office issues
Replies: 10
Views: 812

Re: VPN solution for small office issues

I've checked all your configuration once again and not sure what could it be. It's the worst type of incidents when they happen randomly... For now I suggest providing logs from client/server regarding IPSEC/L2TP. I have a feeling that it might happen when lifetime expires in "/ip ipsec profile...
by erkexzcx
Fri Nov 27, 2020 3:38 pm
Forum: General
Topic: IPsec to Fortigate
Replies: 1
Views: 191

Re: IPsec to Fortigate

For a person which is new to IPSEC or even new to VPNs it's near impossible to get it right at first several tries. I've jumped into similar thing when I was asked to connect Mikrotik router to strongswan VPN server and it was nightmare. I have no experience with Fortigate, but since you are doing s...
by erkexzcx
Fri Nov 27, 2020 3:27 pm
Forum: General
Topic: VPN solution for small office issues
Replies: 10
Views: 812

Re: VPN solution for small office issues

Can this be related? viewtopic.php?t=132823

Mikrotik support commented that instead of dealing with all that mess one should switch to IPSEC/IKE2.
by erkexzcx
Fri Nov 27, 2020 3:19 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 26
Views: 1442

Re: Ipsec not traffic passing

Try again. At least you are missing NAT rule.
by erkexzcx
Fri Nov 27, 2020 3:03 pm
Forum: General
Topic: How to change internet address to local, reverse NAT
Replies: 12
Views: 969

Re: How to change internet address to local, reverse NAT

It's called Hairpin NAT . Here is the example: /ip firewall nat add action=masquerade chain=srcnat comment="Hairpin NAT" dst-address=172.18.17.0/24 src-address=172.18.17.0/24 /ip firewall nat add action=masquerade chain=srcnat comment="Main NAT" out-interface-list=ether1 /ip fire...
by erkexzcx
Fri Nov 27, 2020 2:52 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 26
Views: 1442

Re: Ipsec not traffic passing

Check my guide: viewtopic.php?f=23&t=169538

I think you are missing bridge/interface for VPN server as well as NAT rule for internal networks. I've mentioned everything there.
by erkexzcx
Fri Nov 27, 2020 12:03 am
Forum: Beginner Basics
Topic: OVPN +LAN
Replies: 1
Views: 213

Re: OVPN +LAN

First of all, RouterOS 6.* only supports TCP mode, while RouterOS 7.* supports UDP as well (if I am not mistaken). See https://wiki.mikrotik.com/wiki/OpenVPN#Features. Another thing is that you will get a terrible performance out of OpenVPN as it is one of the slowest VPN protocols. Instead you shou...
by erkexzcx
Thu Nov 26, 2020 11:47 am
Forum: Beginner Basics
Topic: Manual DNS for individual clients? [SOLVED]
Replies: 6
Views: 569

Re: Manual DNS for individual clients? [SOLVED]

Who would have thought you could do this on a router! Prior Mikrotik I had OpenWRT experience and there in DHCP server setting you have custom DHCP options and under the field there is a suggestion that "type this in order to give custom DNS to clients". When I noticed DHCP options in Mik...
by erkexzcx
Thu Nov 26, 2020 10:26 am
Forum: General
Topic: Winbox on Apple Silicon first try [SOLVED]
Replies: 12
Views: 2103

Re: Winbox on Apple Silicon first try [SOLVED]

I suggest using web browser for Mikrotik control, or CLI (e.g. SSH) for now as workaround.

This should be addressed to Wine as well because it's more or less issue with Wine.
by erkexzcx
Wed Nov 25, 2020 9:23 pm
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that
Replies: 6
Views: 1560

Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

Overview Notes: I've been using latest ROS6 (6.47.8) for this guide. Steps might be different on ROS7. Tutorial shows how to connect 2 routers, but at the end of this guide there are steps on how to connect 3rd router. Router A (internal VPN IP 10.22.22.1) - VPN server. Has public IP. Router B (int...
by erkexzcx
Tue Nov 24, 2020 9:30 pm
Forum: General
Topic: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]
Replies: 1
Views: 365

Re: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]

I was about to write to RouterOS7 forum because I suspected it's a bug with routeros7, but seems it's not: This is how I solved: Waste 2 days trying to understand where is the issue. Turn off Router B, get another Mikrotik router with ROS6 and configure identical IPSEC/IKE2 client setup. It connects...
by erkexzcx
Tue Nov 24, 2020 1:15 pm
Forum: General
Topic: Nordvpn IPsec Mikrotik Routing
Replies: 15
Views: 2226

Re: Nordvpn IPsec Mikrotik Routing

when connected to NordVPN UK host BBC detects it as if I am not in the UK and blocks the UK contentet such as Iplayer.
Make sure you are using NordVPN DNS provided by VPN server.
by erkexzcx
Tue Nov 24, 2020 12:12 pm
Forum: General
Topic: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]
Replies: 1
Views: 365

EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]

So I have 2 Mikrotik routers: Router A: has public IP and hosting IPSEC/IKE2 VPN server. Latest RouterOS6. Router B: does not have public IP (behind other router's NAT) and acting as VPN client to Router A. Latest RouterOS 7 (beta2). Goal: LAN over internet, so I connect PC to router B and get IP fr...
by erkexzcx
Sun Nov 22, 2020 9:20 pm
Forum: Beginner Basics
Topic: Need help setting up EoIP over IPSEC
Replies: 0
Views: 191

Need help setting up EoIP over IPSEC

Classic scenario: router A is headquarters router, and router B is branch office router. Router A has public IP and should act as a main router. Router B does not have any firewall and is under NAT (another router), so no direct access. I want router B to be connected to router A: Encrypted connecti...
by erkexzcx
Sat Nov 21, 2020 4:41 pm
Forum: General
Topic: Features in the winbox
Replies: 6
Views: 374

Re: Features in the winbox

You can cycle windows, but the shortcut is a bit strange for me:
F6
Quick google search suggested even more results: viewtopic.php?t=147994#p728955
by erkexzcx
Fri Nov 20, 2020 4:45 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 27
Views: 4462

Re: [Guide] How to setup NordVPN (IPSEC/IKEv2) + killswitch

Should I see traffic when I torch the bridge acting as blackhole for the VPN when it is going up or down? The only traffic I saw was ARP. When I re-enable my own killswitch lines (dst 100.69.69.69) then those lines in NAT do catch traffic. I see the same... Looking in /IP routing the PPPoE-out has ...
by erkexzcx
Fri Nov 20, 2020 9:42 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 27
Views: 4462

Re: [Guide] How to setup NordVPN (IPSEC/IKEv2) + killswitch

That killswitch is not great. Quite dangerous in fact. Thank you for your feedback. I completely agree with you, and after testing your provided commands seems that it's working perfectly. +1 for brief explanation. I've updated commands in initial post. If someone has any better suggestions - let m...
by erkexzcx
Fri Nov 20, 2020 2:52 am
Forum: General
Topic: Nordvpn IPsec Mikrotik Routing
Replies: 15
Views: 2226

Re: Nordvpn IPsec Mikrotik Routing

I wrote a mini guide here that covers fasttrack, MSS reduction and killswitch: viewtopic.php?f=23&t=169273
by erkexzcx
Fri Nov 20, 2020 2:51 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 27
Views: 4462

NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Overview Notes: I've had quite a lot of headaches making Mikrotik to work perfectly with NordVPN server, so decided to write this guide and mention all the steps which are not mentioned in the official guide. :) You must have RouterOS 6. It must be minimum version of 6.45. Some steps in ROS7 will b...
by erkexzcx
Thu Nov 19, 2020 5:24 pm
Forum: General
Topic: Feature request: Run script from firewall event
Replies: 10
Views: 3766

Re: Feature request: Run script from firewall event

I would not find it useful right now, but this would open up so much possibilities. +1 from me.
make your router prone to DoS/DDoS attacks
Not true if Mikrotik adds frequency option. E.g. "Do not run script if it already has run in the past X seconds".
by erkexzcx
Tue Nov 17, 2020 1:19 pm
Forum: Beginner Basics
Topic: How do I make highly-available AP that becomes LTE router in case of internet downtime?
Replies: 3
Views: 267

Re: How do I make highly-available AP that becomes LTE router in case of internet downtime?

Difficult to be specific without actual IP addresses. But let's assume your main router is .1 and your Chateau is .2 on the same subnet. Default gateway for your devices is .1 so your main router is the decision making point. - On Chateau, make sure it has a default route to the Internet via LTE. I...
by erkexzcx
Tue Nov 17, 2020 10:41 am
Forum: Beginner Basics
Topic: How do I make highly-available AP that becomes LTE router in case of internet downtime?
Replies: 3
Views: 267

How do I make highly-available AP that becomes LTE router in case of internet downtime?

In the house there is a main Mikrotik router and few (Ubiquiti) wireless access points. In one room there is "Mikrotik Chateau 12" router set-up as a wireless access point. I added SIM card to that "Chateau" router and now I want to make it highly available wireless access point ...
by erkexzcx
Sat Nov 14, 2020 2:55 am
Forum: Beginner Basics
Topic: Config restore
Replies: 2
Views: 235

Re: Config restore

Looks like you have no choice - reset the router. :)

From my experience, resetting Mikrotik router does not wipe internal storage.
by erkexzcx
Sat Nov 14, 2020 2:49 am
Forum: Beginner Basics
Topic: Blacklist all but one IP? [SOLVED]
Replies: 4
Views: 315

Re: Blacklist all but one IP? [SOLVED]

If your WAN interface is ether1 and your IP is 123.123.123.123 , then it would look like this: add action=accept chain=forward out-interface=ether1 dst-address=123.123.123.123 add action=drop chain=forward out-interface=ether1 This is very basic rule. I suggest learning more about firewalls. :)
by erkexzcx
Thu Nov 12, 2020 7:32 pm
Forum: Beginner Basics
Topic: Newbie: Access to modem behind router
Replies: 26
Views: 1170

Re: Newbie: Access to modem behind router

Is this what you are trying to achieve?

LAN <--> Mikrotik router <--> Modem <--> Internet
by erkexzcx
Thu Nov 12, 2020 7:24 pm
Forum: Wireless Networking
Topic: TX Power Mikrotik Lhg Xl 5 Ac 802.11a/n/ac
Replies: 3
Views: 457

Re: TX Power Mikrotik Lhg Xl 5 Ac 802.11a/n/ac

Did you check downloads page? https://mikrotik.com/product/lhg_xl_5_ac#fndtn-downloads There is brochure available. Also, correct me if I am wrong, but TX Power is something you should not be looking for when choosing a wireless device: https://www.draytek.co.uk/support/guides/difference-between-db-...
by erkexzcx
Thu Nov 12, 2020 7:17 pm
Forum: Beginner Basics
Topic: Port 22 / SFTP/SSH Being Blocked
Replies: 26
Views: 1289

Re: Port 22 / SFTP/SSH Being Blocked

Can you give us an example or diagram on what are you trying to achieve?
by erkexzcx
Thu Nov 12, 2020 12:02 am
Forum: Wireless Networking
Topic: Some help from you Mikrotik lovers please
Replies: 4
Views: 636

Re: Some help from you Mikrotik lovers please

This should go into newbie section. :) Anyway, it looks like you understand networking well enough in order to start using Mikrotik on your own: 1. Get WinBox app. Works well on Mac and Linux. https://mikrotik.com/download 2. Connect to your router (either via MAC or IP - google the difference). 3. ...
by erkexzcx
Wed Nov 04, 2020 8:41 am
Forum: General
Topic: Question about TCP Established and Call of Duty disconnects [SOLVED]
Replies: 26
Views: 1510

Re: Question about TCP Established and Call of Duty disconnects [SOLVED]

I think that if you are unable to handle large amount of connections, then you need a more powerful router?

I mean you are applying workarounds, this is impacting users and here you are trying to figure out what's the problem.
by erkexzcx
Tue Nov 03, 2020 10:26 pm
Forum: Scripting
Topic: disable a rule when a provider crashes?
Replies: 2
Views: 366

Re: disable a rule when a provider crashes?

I am not sure what you are asking, but I would say "yes, it's possible".
by erkexzcx
Sat Aug 29, 2020 9:38 pm
Forum: Beginner Basics
Topic: Tunnel traffic through VPN
Replies: 20
Views: 5085

Re: Tunnel traffic through VPN

1) Is it possible to tunnel all the traffic trough a VPN provider? 2) Which VPN provider is supported by Mikrotik? 3) Are there any providers which already have filters for illegal BitTorrent websites? Or the possibility to block Bittorent at all? 4) Can I block somehow Bittorent with my Mikrotik r...
by erkexzcx
Sat Aug 29, 2020 9:32 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 97081

Re: v7.1beta2 [development] is released!

Does this beta release work great with Winbox? Or is it console-only while it's beta?
by erkexzcx
Mon Jun 29, 2020 9:02 am
Forum: Beginner Basics
Topic: EoIP setup
Replies: 3
Views: 927

Re: EoIP setup

Hi sir. would it be possible if you can give me some advice on how to go about it. Sure. EoIP instructions: https://wiki.mikrotik.com/wiki/Manual:Interface/EoIP GRE tunnel instructions: https://wiki.mikrotik.com/wiki/Manual:Interface/Gre L2TP instructions: https://wiki.mikrotik.com/wiki/Manual:Inte...
by erkexzcx
Wed Jun 24, 2020 9:20 pm
Forum: Beginner Basics
Topic: [SOLVED] Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)
Replies: 1
Views: 623

Re: Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)

Right, so instructions are unclear (I got confused) by Manual:IP/IPsec#NAT_and_Fasttrack_Bypass instructions: Solution is to use IP/Firewall/Raw to bypass connection tracking, that way eliminating need of filter rules listed above It actually means that eliminating need of Fasttrack bypass rules. Us...
by erkexzcx
Wed Jun 24, 2020 9:30 am
Forum: Beginner Basics
Topic: Cannot ping interface IP
Replies: 1
Views: 522

Re: Cannot ping interface IP

I believe author meant packet marking in mangle section. I don't know what command he added, but seems you are going to find required info here: https://wiki.mikrotik.com/wiki/Load_Bal ... ll_marking
by erkexzcx
Wed Jun 24, 2020 12:51 am
Forum: Beginner Basics
Topic: [SOLVED] Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)
Replies: 1
Views: 623

[SOLVED] Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)

So I've literally spent last few weeks, almost every evening trying to setup IPsec/IKEv2 site 2 site VPN. After hundreds of Google searches, unsuccessful and semi-successful attempts I finally gave up and came to this Mikrotik forum... So basically I have 2 routers, one has public IP, and another on...
by erkexzcx
Sun Jun 14, 2020 5:17 pm
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 2414

Re: Hairpin with port forwarding

good video tutorial
https://www.youtube.com/watch?v=_kw_bQyX-3U&t=177s

or specify in-interface (to be your WAN interface) on your dst-nat rule so you don't mess up LAN connection to the private IP.
That youtube video is legendary...
by erkexzcx
Sat Jun 06, 2020 12:44 pm
Forum: Beginner Basics
Topic: Help! How do I delete dynamic DNS servers? [SOLVED]
Replies: 12
Views: 6812

Re: Help! How do I delete dynamic DNS servers? [SOLVED]

If anyone is using some sort of VPN provider and you connected your router to it, go to IP --> IPsec --> Mode Configs Then open up your mode config that you are using for your VPN provider, change "Use responder DNS" from "exclusively" to "No". Kill active connection (i...
by erkexzcx
Thu Jun 04, 2020 1:26 pm
Forum: Beginner Basics
Topic: Firewall Layer 7 Filter
Replies: 4
Views: 1537

Re: Firewall Layer 7 Filter

This is not what you want to hear, but using Layer7 is generally a bad practice, because: 1. You can get around this filtering by using VPN 2. You can get around this by (sometimes) doing nothing. See "DNS Over HTTPS" and some browsers do it by default now. 3. Specifically your case, you c...
by erkexzcx
Sun May 31, 2020 7:44 pm
Forum: Scripting
Topic: [Script] Automatically change DNS if Pi-hole is no longer working
Replies: 23
Views: 4252

Re: [Script] Automatically change DNS if Pi-hole is no longer working

Thank you. I updated my initial comment with your suggestions. :)
by erkexzcx
Sun May 31, 2020 2:44 pm
Forum: Scripting
Topic: [Script] Automatically change DNS if Pi-hole is no longer working
Replies: 23
Views: 4252

[Script] Automatically change DNS if Pi-hole is no longer working

I've wrote a script that detects when Pi-Hole is no longer working, and automatically switches to public DNS 1.1.1.2,1.0.0.2. Disclaimer : I am aware of possibility to set multiple DNS servers, but for Pi-Hole to work you need to set only Pi-Hole IP address. Use case : Set-up Mikrotik and RPI with P...
by erkexzcx
Fri May 29, 2020 10:48 am
Forum: Beginner Basics
Topic: [Solved] "Resource Temporarily Unavailable" when Mikrotik used as a simple router
Replies: 1
Views: 984

Re: "Resource Temporarily Unavailable" when Mikrotik used as a simple router

Issue solved.

I've set port forwardings without in-interface. Once I set it - everything is working again. I've set port 80, and since 443 was unused - HTTPS traffic worked fine, while 80 failed due to misconfiguration.
by erkexzcx
Fri May 29, 2020 9:32 am
Forum: Beginner Basics
Topic: [Solved] "Resource Temporarily Unavailable" when Mikrotik used as a simple router
Replies: 1
Views: 984

[Solved] "Resource Temporarily Unavailable" when Mikrotik used as a simple router

Hey, So basically I replaced Cisco RV320 router with Mikrotik RB4011iGS and everything seems fine - internet works just fine, except speedtest always fail. When I try to run from Linux CLI client, I get this output: erikas@btwOS  ~  speedtest Speedtest by Ookla [error] Error: [11] Cannot read from...
by erkexzcx
Sun Jan 26, 2020 11:50 am
Forum: Scripting
Topic: ISP Throttle Speed YouTube [SOLVED]
Replies: 2
Views: 2157

Re: ISP Throttle Speed YouTube [SOLVED]

You should look at VPN side. Talking about VPN providers, such as NordVPN. You can configure your router to connect to their VPN server and whitelist only youtube.com or all traffic to go under VPN. Then your ISP won't have any chance to throttle specific sites.
by erkexzcx
Sun Jan 26, 2020 11:48 am
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 165
Views: 55311

Re: Feature Request - Wireguard Protocol

+1. I also do have additional SBC next to Mikrotik router just for Wireguard VPN server.
by erkexzcx
Tue Oct 08, 2019 9:22 pm
Forum: General
Topic: IPSec VPN fails to start - shows errors that I don't know how to solve
Replies: 2
Views: 1436

Re: IPSec VPN fails to start - shows errors that I don't know how to solve

The last rule appears to be an IPv6 ipsec issue. Are you trying to terminate the tunnel on IPv4 or IPv6? Hi, What I was going to do is to create an interface, where all traffic is being routed through VPN server. VPN IPSec connection is established from Mikrotik router, so the only thing needed to ...
by erkexzcx
Mon Oct 07, 2019 11:49 pm
Forum: General
Topic: IPSec VPN fails to start - shows errors that I don't know how to solve
Replies: 2
Views: 1436

IPSec VPN fails to start - shows errors that I don't know how to solve

Hi, I've setup IPSec VPN on Mikrotik router. Everything works fine, so I backed up configuration and restored on same model, but different router. Internet works just fine, but this is what I get (taken from logs): 21:02:16 ipsec,debug ipsec: 0.0.0.0[500] used as isakmp port (fd=25) 21:02:16 ipsec,d...