Community discussions

MikroTik App

Search found 263 matches

by erkexzcx
Wed Oct 25, 2023 12:36 pm
Forum: Beginner Basics
Topic: Has anyone QoS'ed Steam downloads?
Replies: 6
Views: 1678

Has anyone QoS'ed Steam downloads?

I have QoS in place and I'd like to set Steam downloads to have lower priority from the rest of the traffic. Now I am scratching my head trying figure it out how do I do it. One option would be to get list of Steam IPs. Another option - list of domains and add them to RouterOS addresses list. Has an...
by erkexzcx
Tue Jul 25, 2023 12:18 am
Forum: Beginner Basics
Topic: Home invasion
Replies: 18
Views: 3886

Re: Home invasion

As my ISP once told me: Everything behind ISP converter (including converter itself) is ISP's responsibility . Everything that goes out of ISP converter (including the Ethernet cable) is your responsibility . So I guess you should really understand the meaning of ISP converter. In my case they even ...
by erkexzcx
Tue Jul 25, 2023 12:03 am
Forum: Beginner Basics
Topic: Need assistance setting up queue tree (QoS) for multiple networks/VLANs [SOLVED]
Replies: 3
Views: 2079

Re: Need assistance setting up queue tree (QoS) for multiple networks/VLANs [SOLVED]

I haven't got any (useful) response from anyone, so I am gonna share my findings here. Goal My Mikrotik router has 5 interfaces: WAN interface LAN SFP+ interface (untagged) - network A VLAN 20 interface (tagged) on SFP+ port - network B VLAN 30 interface (tagged) on SFP+ port - network C VLAN 40 int...
by erkexzcx
Sun Jul 16, 2023 12:48 pm
Forum: Beginner Basics
Topic: Need assistance setting up queue tree (QoS) for multiple networks/VLANs [SOLVED]
Replies: 3
Views: 2079

Re: Need assistance setting up queue tree (QoS) for multiple networks/VLANs [SOLVED]

hello What is the "best practice" here? I've tried building something with the help of ChatGPT but I think I am going nowhere. I also do lack of knowledge of queues/QoS in general, so please be kind with me. 8) really? you have asked bots for your settings? 😂 I'm curious... what did the A...
by erkexzcx
Sat Jul 15, 2023 10:53 pm
Forum: Beginner Basics
Topic: Need assistance setting up queue tree (QoS) for multiple networks/VLANs [SOLVED]
Replies: 3
Views: 2079

Need assistance setting up queue tree (QoS) for multiple networks/VLANs [SOLVED]

I have a router which has 100mbps up and 100mbps down internet. WAN port is ether10. Then I have 4 networks: A - This one should have at least 50% of internet throughput guaranteed. Maximum 100mbps. B - This one should have at least 25% of internet throughput guaranteed. Maximum 100mbps. C - This on...
by erkexzcx
Fri Nov 11, 2022 10:27 pm
Forum: Beginner Basics
Topic: Help needed to configure VLANs using switch features [SOLVED]
Replies: 8
Views: 1518

Re: Help needed to configure VLANs using switch features [SOLVED]

I've got it to work. Very confusing, but I guess it's always like that for a first timers lol. So today I learned: Untagged traffic in Mikrotik switch is considered as VLAN 0. You need to specify switch1-cpu (or whatever your switch has) to let the traffic reach the device itself, so you can access ...
by erkexzcx
Fri Nov 11, 2022 10:07 pm
Forum: Beginner Basics
Topic: Help needed to configure VLANs using switch features [SOLVED]
Replies: 8
Views: 1518

Re: Help needed to configure VLANs using switch features [SOLVED]

After a while I am back to this problem again. Let me upload a chart this time. What I am trying to achieve is quite simple: https://i.imgur.com/zcx2Km8.png For CRS3xx switches ( guide ) it's fairly easy and I got it working just fine, but I am using CRS1xx/2xx series switches ( guide ) and I need t...
by erkexzcx
Fri Jul 29, 2022 7:37 pm
Forum: Beginner Basics
Topic: Help needed to configure VLANs using switch features [SOLVED]
Replies: 8
Views: 1518

Re: Help needed to configure VLANs using switch features [SOLVED]

This does not answer the question. Show me which link shows how to pass both untagged and tagged traffic? :) Maybe this - https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#VLAN_Example_2_(Trunk_and_Hybrid_Ports) Nope, I've tried this already. This example shows 3 tagged VLANs via ether2 an...
by erkexzcx
Fri Jul 29, 2022 7:09 pm
Forum: Beginner Basics
Topic: Help needed to configure VLANs using switch features [SOLVED]
Replies: 8
Views: 1518

Re: Help needed to configure VLANs using switch features [SOLVED]

P. SWITCH CHIP VLANS https://help.mikrotik.com/docs/display/ ... p+Features https://help.mikrotik.com/docs/display/ ... switchchip other refs: https://www.youtube.com/watch?v=Rj9aPoyZOPo - Vlans using the Switch Chip https://www.youtube.com/watch?v=rvQ6o4RfnoU - Configure Vlan on Switch Chip https:...
by erkexzcx
Fri Jul 29, 2022 6:25 pm
Forum: Beginner Basics
Topic: Help needed to configure VLANs using switch features [SOLVED]
Replies: 8
Views: 1518

Help needed to configure VLANs using switch features [SOLVED]

I'd like to configure VLANs using switch features (rather than bridge) for performance reasons. Configuration using bridge is pretty easy and straightforward, however, I find it extremelly difficult to configure using switch features. Here is switch ports description: eth1 - traffic ingoing from the...
by erkexzcx
Thu Mar 17, 2022 1:16 pm
Forum: Useful user articles
Topic: IPSEC/IKE2 (with certificates) VPN server guide for remote access
Replies: 41
Views: 60240

Re: IPSEC/IKE2 (with certificates) VPN server guide for remote access

Also, setting up Windows 10 VPN Client can be greatly simplified. I do not know if that has something to do with different parameters in my Mikrotik setup (as described in previous post), but I was able to setup Windows VPN in more/less usual way, without re-exporting it or using PowerShell command...
by erkexzcx
Mon Feb 28, 2022 12:07 pm
Forum: Useful user articles
Topic: [ROS7] How to get public IP (sort of)
Replies: 26
Views: 11467

Re: [ROS7] How to get public IP (sort of)

...and host/install a Mikrotik CHR on it.
CHR costs money and if you want it free - you are limited to 1mbps only.
by erkexzcx
Sun Feb 20, 2022 10:03 am
Forum: Useful user articles
Topic: [ROS7] How to get public IP (sort of)
Replies: 26
Views: 11467

[ROS7] How to get public IP (sort of)

TL;DR Get a cloud VM with public IP, host wireguard server on it, connect to it from Mikrotik router, port forward everything from VM to Mikrotik via wireguard tunnel. Other notes: Linode provider offers cheapest instance for 5$/month and you get 4TB of monthly TX data. RX data is not counted (free...
by erkexzcx
Fri Nov 26, 2021 8:51 am
Forum: RouterOS beta
Topic: v7.1rc6 [development] is released!
Replies: 145
Views: 56745

Re: v7.1rc6 [development] is released!

Hi. RB4011iGS+ model here with v7.1rc6 - today I wake up with internet not working. Turns out DNS not working everywhere, even in router (nslookup google.com). Querying manually on PC (nslookup google.com 1.1.1.1) also did not return anything. Like - there is no connectivity at all... But I was able...
by erkexzcx
Tue Nov 02, 2021 8:46 am
Forum: General
Topic: Chateau LTE12 suddenly dead
Replies: 3
Views: 1114

Re: Chateau LTE12 suddenly dead

Update device package(s) to the latest ROS7 (as well as routerboard & LET firmwares) and see if this occurs again. My Chateau 12 was unusable for about 6 months until latest update fixed configuration wipeout on each boot.
by erkexzcx
Wed Oct 27, 2021 8:39 pm
Forum: Beginner Basics
Topic: Power resets config file?
Replies: 2
Views: 702

Re: Power resets config file?

If the device that is losing settings is running RouterOS 7.*, update to the latest version from the development branch. It has fixed my issue where config were completely wiped out during each restart.

If you are RouterOS 6.*, please contact Mikrotik Support regarding this issue.
by erkexzcx
Wed Oct 27, 2021 11:48 am
Forum: RouterOS beta
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 49190

Re: v7.1rc5 [development] is released!

OMG this beta release fixed SUP-44801 ( Chateau 12 loses configuration on each reboot ) issue!!!!!!!!!!!!!! Glad I did not return this device to the seller for warranty reasons:))) When did you have that issue? Only with firmwares v7.1*, I suppose... I've had this since "18/Mar/21 3:12 PM"...
by erkexzcx
Wed Oct 27, 2021 11:44 am
Forum: RouterOS beta
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 49190

Re: v7.1rc5 [development] is released!

I was unable to upgrade LTE firmware on my Chateau 12 v7.1rc5 CLI (rebooted and like nothing happened). https://wiki.mikrotik.com/wiki/Manual:Interface/LTE#Modem_firmware_upgrade However, it succeeded when using WinBox GUI, clicking on interfaces -> lte1 -> upgrade firmware. So in other words, all g...
by erkexzcx
Wed Oct 27, 2021 11:19 am
Forum: RouterOS beta
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 49190

Re: v7.1rc5 [development] is released!

OMG this beta release fixed SUP-44801 (Chateau 12 loses configuration on each reboot) issue!!!!!!!!!!!!!!

Glad I did not return this device to the seller for warranty reasons:)))
by erkexzcx
Sat Oct 23, 2021 9:26 am
Forum: Beginner Basics
Topic: Best way to connect Windows 10 OS computers to a Filesystem server
Replies: 3
Views: 1090

Re: Best way to connect Windows 10 OS computers to a Filesystem server

This is classic example of what most of small business needed during the corona virus lockdown. There are few tips I can give you: Go with the easiest way (if possible) - simply setup any popular cloud storage service (Google Drive, OneDrive, DropBox, Mega etc). If above not possible, check if NextC...
by erkexzcx
Mon Oct 18, 2021 10:07 am
Forum: Beginner Basics
Topic: DSL question - can I use DSL to Ethernet adapter to connect to Mikrotik router?
Replies: 1
Views: 776

DSL question - can I use DSL to Ethernet adapter to connect to Mikrotik router?

Hello, Basically I have zero knowledge about DSL (I live in a country where DSL is not used like at all), but I will be setting up the network where DSL is used. Can I purchase "DSL to Ethernet" adapter from Amazon/Ebay/AliExpress and it would simply work? How does router/modem, connected ...
by erkexzcx
Wed Sep 29, 2021 4:34 pm
Forum: General
Topic: CHR instance needed in Germany (or physical MT)
Replies: 3
Views: 970

Re: CHR instance needed in Germany (or physical MT)

Why don't you setup CHR yourself in any cloud provider? It's simple.

I've been able to successfully setup CHR in Linode. https://wiki.mikrotik.com/wiki/Manual:CHR_Linode
by erkexzcx
Mon Sep 20, 2021 5:29 pm
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83305

Re: v7.1rc4 [development] is released!

Out of curiosity - when does the Mikrotik is planning to release v7 as stable?

This is great that you are working on new features, but isn't it better to completely stop for now, focus on bug-fixes only and finally release v7 as stable?
by erkexzcx
Sun Sep 19, 2021 9:58 am
Forum: General
Topic: Support for ACME/Let's Encrypt certificate management [SOLVED]
Replies: 114
Views: 73047

Re: Support for ACME/Let's Encrypt certificate management [SOLVED]

I am probably out of the loop and/or just struggling to understand why would someone need ACME on Mikrotik router? Using webUI to manage Mikrotik? Instead one could use WinBox. Do not trust included encryption of WinBox protocol? Just configure all remote Mikrotik routers to be reachable via VPN onl...
by erkexzcx
Sun Sep 19, 2021 9:44 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

My questions is: how can I pass ALL traffic through the tunnel, EXCEPT all traffic meant for 192.168.x.x? I would probably something like this: /ip firewall mangle add action=mark-connection chain=prerouting new-connection-mark=unmarkable_nordvpn passthrough=yes src-address=192.168.x.x /ip firewall...
by erkexzcx
Sun Sep 19, 2021 9:36 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Could this really be the only difference between the 2 methods? Basically both methods are the same and works the same. Except the killswitch - it cannot use connection marking therefore there is difference is between src/dst. If you ignore killswitch part, it should be practically the same (as lon...
by erkexzcx
Sun Sep 19, 2021 9:29 am
Forum: Beginner Basics
Topic: NordVpn extremely slow
Replies: 12
Views: 6035

Re: NordVpn extremely slow

Noone mentioned my guide?

viewtopic.php?f=23&t=169273

The only reason why NordVPN could be slow is because MSS/MTU size issues. All mentioned in the guide.
by erkexzcx
Sat Sep 11, 2021 6:29 pm
Forum: General
Topic: PureVPN Protocol-discontinuation, Mikrotik router useless?!
Replies: 21
Views: 3548

Re: PureVPN Protocol-discontinuation, Mikrotik router useless?!

You are owning one of the shittiest VPNs now and crying that Mikrotik doesn't support specific VPN protocol? How about NordVPN/Surfshark? They do support lots of them, including OpenVPN TCP and IPSEC/IKE2 which works incredibly well and there is a guide too. https://forum.mikrotik.com/viewtopic.php?...
by erkexzcx
Sat Sep 11, 2021 6:21 pm
Forum: Beginner Basics
Topic: PC Gaming, unable to connect to servers [SOLVED]
Replies: 9
Views: 2771

Re: PC Gaming, unable to connect to servers [SOLVED]

Minecraft ... big ones
Try to telnet minecraft server's port. Is it connecting, rejecting or nothing happens (aka "dropping")? This might give you an idea which Mikrotik rule is rejecting traffic.

Also I am not sure about DNS servers. Tried using 1.1.1.1?
by erkexzcx
Sat Aug 28, 2021 3:16 pm
Forum: General
Topic: How to bind EoIP tunnel to IPSec IKEv2 connection?
Replies: 8
Views: 2855

Re: How to bind EoIP tunnel to IPSec IKEv2 connection?

I've done EoIP over IKE2. I've documented in here: viewtopic.php?f=23&t=169538
by erkexzcx
Fri Aug 20, 2021 7:38 pm
Forum: General
Topic: Voip traffic drops when using PPTP PurveVPN
Replies: 3
Views: 955

Re: Voip traffic drops when using PPTP PurveVPN

PureVPN doesn't even have IPSEC/IKE2 protocol... :D OpenVPN is slow, PPTP is insecure, L2TP is okayish.
by erkexzcx
Wed Aug 11, 2021 9:38 am
Forum: Beginner Basics
Topic: is my NAT config is ok?
Replies: 24
Views: 2911

Re: is my NAT config is ok?

/export hide-sensitive file=anynameyouwish As I'm a noob. it will be appreciated if you mention what your code does. In WinBox, there is "Terminal". You can also access terminal using SSH, Telnet, serial etc... After running this command, a new file called "anynameyouwish" would...
by erkexzcx
Wed Aug 11, 2021 9:32 am
Forum: Beginner Basics
Topic: Cyberghost VPN IKE2 config
Replies: 3
Views: 6465

Re: Cyberghost VPN IKE2 config

Same steps for NordVPN: viewtopic.php?f=23&t=169273
by erkexzcx
Wed Aug 11, 2021 9:30 am
Forum: General
Topic: Seperate SSID for VPN access
Replies: 1
Views: 706

Re: Seperate SSID for VPN access

Create new network, setup connectivity from it as usually and use-case 1 from here.
by erkexzcx
Sun Aug 08, 2021 10:05 pm
Forum: Beginner Basics
Topic: VPN IKEv2 Out Specific traffic by source routed through a VPN server [SOLVED]
Replies: 3
Views: 1642

Re: VPN IKEv2 Out Specific traffic by source routed through VPN server [SOLVED]

So basically you built ROS-based IPSEC/IKE2 VPN server like this: https://forum.mikrotik.com/viewtopic.php?f=23&t=175656 <-- proper implementation of Mikrotik IPSEC/IKE2 (certs-based) VPN server https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 <-- Mikrotik to Mikrotik connection, in th...
by erkexzcx
Sun Aug 08, 2021 9:56 pm
Forum: General
Topic: mikrotik.com blocked on our country and mikrotik cloud(ddns) and update check not working
Replies: 21
Views: 4960

Re: mikrotik.com blocked on our country and mikrotik cloud(ddns) and update check not working

https://forum.mikrotik.com/viewtopic.php?f=23&t=169273 Get NordVPN or any other trusted VPN provider subscription, then 2nd method (by destination) to Mikrotik ASN: For example, Mikrotik.com resolves to "159.148.147.196". Quick google revealed the Mikrotik has it's own ASN which contai...
by erkexzcx
Sun Aug 01, 2021 7:44 pm
Forum: Beginner Basics
Topic: How can I make a VPN connection appear to be on my network's IP range?
Replies: 3
Views: 904

Re: How can I make a VPN connection appear to be on my network's IP range?

Are you sure those games are looking for other game servers/clients in L3 and not in L2 layer? If so, L2TP is operating only in L3. If you need L2 functionality, then you might need something like EoIP tunnel on top of it.
by erkexzcx
Tue Jul 27, 2021 11:50 am
Forum: Beginner Basics
Topic: ProtonVPN w/ MacOS Setup on Hex S
Replies: 2
Views: 823

Re: ProtonVPN w/ MacOS Setup on Hex S

Suffice to say this is a decent link
Thaaanks! :D
by erkexzcx
Mon Jul 26, 2021 2:05 pm
Forum: General
Topic: IPSec IKEv2 Tunnel - no internet
Replies: 3
Views: 1716

Re: IPSec IKEv2 Tunnel - no internet

Here are some of my written guides. Check all of them:)
by erkexzcx
Wed Jul 21, 2021 6:47 pm
Forum: Beginner Basics
Topic: IKEV2 IPsec VPN not connecting
Replies: 3
Views: 1550

Re: IKEV2 IPsec VPN not connecting

I've written a guide here. See if it helps. Might be not perfect, but it worked perfectly fine for me. :)
by erkexzcx
Wed Jul 21, 2021 6:46 pm
Forum: Beginner Basics
Topic: How to connect PureVPN IKEV2 Server on Mikrotik router?
Replies: 5
Views: 2979

Re: How to connect PureVPN IKEV2 Server on Mikrotik router?

Yes! First time seeing someone recommending my guide. :)))
by erkexzcx
Thu Jul 15, 2021 5:25 pm
Forum: General
Topic: ProtonVPN config routing [SOLVED]
Replies: 7
Views: 27701

Re: ProtonVPN config routing [SOLVED]

Can you please help me to figure this out?
Yup. viewtopic.php?f=23&t=169273
by erkexzcx
Thu Jul 15, 2021 5:22 pm
Forum: Beginner Basics
Topic: IPSEC tunnel instructions
Replies: 18
Views: 3404

Re: IPSEC tunnel instructions

viewforum.php?f=23 CTRL+F "VPN". I've written at least 3 VPN guides, 1 of them is mostly what you are asking - connecting 2 mikrotik routers.
by erkexzcx
Sun Jul 11, 2021 7:30 pm
Forum: General
Topic: how to use PI-Hole with mikrotik netwrok?
Replies: 17
Views: 24256

Re: how to use PI-Hole with mikrotik netwrok?

2) Perhaps have some scripts on the Mikrotik running to "check" if your Pi-hole can still resolve ? Sort of a "backup" plan, unless you have perhaps 2 Pi-hole devices running on the network? There are several posts on the forum concerning this. Here is the code that automaticall...
by erkexzcx
Tue Jul 06, 2021 12:35 am
Forum: Useful user articles
Topic: IPSEC/IKE2 (with certificates) VPN server guide for remote access
Replies: 41
Views: 60240

Re: IPSEC/IKE2 (with certificates) VPN server guide for remote access

I changed this to a more secure passphrase when entering the command in the terminal for Home client 1. Is it necessary to be secure? Or can I just use what you have used as a passphrase? You can avoid having password at all, but I've heard rumors that it's impossible to import pkcs12 keystore into...
by erkexzcx
Mon Jul 05, 2021 4:12 pm
Forum: Useful user articles
Topic: IPSEC/IKE2 (with certificates) VPN server guide for remote access
Replies: 41
Views: 60240

Re: IPSEC/IKE2 (with certificates) VPN server guide for remote access

When importing the cert. into the android device, it's asking for a password? Step 3. What password is it that I need to enter? /certificate export-certificate "Home client2" file-name="Home client2" type=pkcs12 export-passphrase=1234567890 Note "export-passphrase=123456789...
by erkexzcx
Tue Jun 29, 2021 11:44 pm
Forum: Beginner Basics
Topic: Questions of an IPSec-Noob
Replies: 13
Views: 1681

Re: Questions of an IPSec-Noob

ipsec,error no policy found/generated Can you elaborate on your OS/vpn client? Did you perform client steps as per instructions? https://forum.mikrotik.com/viewtopic.php?f=23&t=175656 :) Maybe someone could comment on ROS part - I do have a feeling that it has something to do with either miscon...
by erkexzcx
Sun Jun 27, 2021 11:23 pm
Forum: Beginner Basics
Topic: Questions of an IPSec-Noob
Replies: 13
Views: 1681

Re: Questions of an IPSec-Noob

I've wrote several guides - you might find some guidance there. :)
by erkexzcx
Sun Jun 27, 2021 1:28 pm
Forum: Beginner Basics
Topic: OVPN for beginner
Replies: 7
Views: 2459

Re: OVPN for beginner

My PC can ping 10.0.0.1 and 90.90.90.1 but can't ping laptop. Router can ping both. It's because you have the following rule in your router that allows to ping it from literally any IP: /ip firewall filter add action=accept chain=input comment="Allow ICMP" protocol=icmp OVpn pool - 10.0.0...
by erkexzcx
Fri Jun 25, 2021 11:59 am
Forum: Beginner Basics
Topic: Route the traffic through a remote Server
Replies: 2
Views: 1083

Re: Route the traffic through a remote Server

So you have a VPS and you have a "MicroTik" router. What you specifically asking is VPN... :D Something like this, except you will be using Strongswan for IPSEC/IKE2 VPN protocol: https://forum.mikrotik.com/viewtopic.php?f=23&t=169273 https://forum.mikrotik.com/viewtopic.php?f=23&t...
by erkexzcx
Wed Jun 23, 2021 5:18 am
Forum: Useful user articles
Topic: IPSEC/IKE2 (with certificates) VPN server guide for remote access
Replies: 41
Views: 60240

Re: IPSEC/IKE2 (with certificates) VPN server guide for remote access

@shahjaufar Windows are unable to find the certificate that could be used to connect to your VPN. You either did not import P12 (cert+CA) to Windows certificate store, or imported to a wrong directory? Also, did you generate & export client certificate from Mikrotik router as per my instructions...
by erkexzcx
Tue Jun 22, 2021 6:56 pm
Forum: General
Topic: Create a VPN gateway
Replies: 9
Views: 4874

Re: Create a VPN gateway

Isn't this what you are basically trying to achieve? https://forum.mikrotik.com/viewtopic.php?f=23&t=169273 Regarding routes, I believe you need to use different routing tables. In Mikrotik the functionality can be achieved by using "routing mark" or something like that. Also there is ...
by erkexzcx
Mon Jun 21, 2021 9:11 pm
Forum: Beginner Basics
Topic: Newbie looking for VPN help
Replies: 5
Views: 2018

Re: Newbie looking for VPN help

Exactly what you are looking for: viewtopic.php?f=23&t=169273

Surfshark steps are almost identical. Link is also there.
by erkexzcx
Mon Jun 21, 2021 8:56 pm
Forum: General
Topic: IPSEC VPN only works one way
Replies: 2
Views: 640

Re: IPSEC VPN only works one way

by erkexzcx
Mon Jun 21, 2021 8:51 pm
Forum: General
Topic: HAP AC2 Multiple IKEv2 IPSec Tunnels Limitation?
Replies: 7
Views: 1713

Re: HAP AC2 Multiple IKEv2 IPSec Tunnels Limitation?

1. You're welcome: viewtopic.php?f=23&t=169273
2. You can have max 5 (or 6, can't recall) simultaneous connections to different NordVPN servers. It will not allow 2nd connection to the same server.
by erkexzcx
Mon Jun 14, 2021 9:05 pm
Forum: Beginner Basics
Topic: OVPN for beginner
Replies: 7
Views: 2459

Re: OVPN for beginner

Let me ask you something offtopic - why OpenVPN? It's slow...

I've wrote guide some time ago a tutorial of IPSEC/IKE2 VPN with certificates for remote access. Slightly slower than Wireguard, but very well supported VPN type.
viewtopic.php?f=23&t=175656
by erkexzcx
Mon Jun 14, 2021 8:58 pm
Forum: Useful user articles
Topic: PoE on CRS112-8P-4S-IN
Replies: 2
Views: 6607

Re: PoE on CRS112-8P-4S-IN

There are few things that might confuse you: There are 2 types of PoE - one is passive , and the other is 802.3af/at . Passive PoE is 18-28v and 802.3af/at is 48-57v. Switch will automatically detect if device supports PoE. This switch/router comes with 28v power supply, so out of the box your 802.3...
by erkexzcx
Sat Jun 12, 2021 2:44 pm
Forum: General
Topic: Issue with DST-NAT (RouterOS 6.47.10)
Replies: 16
Views: 4005

Re: Issue with DST-NAT (RouterOS 6.47.10)

Few thoughts:
  • Isn't that suppossed to work only with HTTP traffic and not with HTTPS?
  • You did not port fotward 443 (HTTPS) traffic, only 80 (HTTP). Most sites use 80 to simply redirect to 443 and serve websites only on 443 port.
by erkexzcx
Tue Jun 08, 2021 9:18 am
Forum: Beginner Basics
Topic: Very large amount of data on WAN being blocked by defconf firewall rule (Hex S)
Replies: 11
Views: 1691

Re: Very large amount of data on WAN being blocked by defconf firewall rule (Hex S)

Not really related, but If you have RPI or some Linux server in your network, you can try to to assert dominance for 22 port in the "is it vulnerable?" world - https://github.com/skeeto/endlessh.
by erkexzcx
Sat Jun 05, 2021 3:39 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Added this note to the main post: Note 2: You might be able to route all traffic of the company, but you might end up routing 30-40% of the websites under NordVPN if company uses popular hosting, e.g. Amazon AWS or Linode. For example, Mikrotik.com resolves to "159.148.147.196". Quick goog...
by erkexzcx
Fri Jun 04, 2021 11:44 pm
Forum: Useful user articles
Topic: Which VPN protocol is best?
Replies: 28
Views: 35890

Re: Which VPN protocol is best?

Let me introduce IPSEC/IKE2 protocol to the VPN zoo... :D Let's see what VPN companies say about IPSEC/IKE2?
AES with 256-bit keys, which is recommended by the NSA for securing classified information, including the TOP SECRET level.

BOOM, clear winner.
by erkexzcx
Mon May 31, 2021 8:34 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

I've updated few steps and done general cleanup. /ip firewall raw add action=notrack chain=prerouting protocol=ipsec-esp src-address-list=IKEVtraffic add action=notrack chain=output protocol=ipsec-esp dst-address-list=IKEVtraffic I cannot get this to work, even with simple "add action=notrack c...
by erkexzcx
Sun May 30, 2021 10:36 pm
Forum: Beginner Basics
Topic: IKEv2 VPN
Replies: 27
Views: 48302

Re: IKEv2 VPN

I wrote this today: viewtopic.php?f=23&t=175656
by erkexzcx
Sun May 30, 2021 10:13 pm
Forum: Beginner Basics
Topic: How Windows 10 decides which client certificate to use when connecting to IKE2 VPN server? [SOLVED]
Replies: 1
Views: 1018

Re: How Windows 10 decides which client certificate to use when connecting to IKE2 VPN server? [SOLVED]

Looks like Windows simply sucks. It is possible to indirectly point to which certificate for which profile to use. I've documented it here: viewtopic.php?f=23&t=175656
by erkexzcx
Sun May 30, 2021 9:35 pm
Forum: Useful user articles
Topic: IPSEC/IKE2 (with certificates) VPN server guide for remote access
Replies: 41
Views: 60240

IPSEC/IKE2 (with certificates) VPN server guide for remote access

Because I've spent hours trying to understand all the details I need to get this working perfectly, I've decided to share the information so you don't have to waste your time. Most common use I can think of: access your home network using the most secure (sort of), fastest and well supported method ...
by erkexzcx
Sat May 29, 2021 11:56 pm
Forum: Beginner Basics
Topic: How Windows 10 decides which client certificate to use when connecting to IKE2 VPN server? [SOLVED]
Replies: 1
Views: 1018

How Windows 10 decides which client certificate to use when connecting to IKE2 VPN server? [SOLVED]

A bit non-Mikrotik question, but I can't understand why my Windows 10 PC is not using a correct certificate when connecting to my Mikrotik router. I have 2 identical Mikrotik routers at 2 different locations. They both have public IP and that's pretty great since once I get something to work on any ...
by erkexzcx
Fri Apr 09, 2021 11:00 am
Forum: Beginner Basics
Topic: Route only internal traffic (OpenVPN)
Replies: 2
Views: 841

Re: Route only internal traffic (OpenVPN)

Maybe someone could clarify this, but if I am not mistaken IPSEC is policy-based while OpenVPN is routing-based (has it's own interface and internal IP). I think you should start by looking into "/ip route" or OpenVPN routing settings. I never set up or used OpenVPN on Mikrotik routers, so...
by erkexzcx
Thu Apr 08, 2021 6:11 pm
Forum: Beginner Basics
Topic: New to MikroTIK
Replies: 8
Views: 1929

Re: New to MikroTIK

My personal opinion - here is the best learning material I've found/used https://mynetworktraining.com/ (same guy has pretty much all courses in Udemy).

I don't like reading hundreds of pages books. :) I am visual learner.
by erkexzcx
Sat Mar 27, 2021 10:03 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Hi, Try to move below rules to the top and try again. Kill NordVPN IPSEC connection, clear conntrack list and try again. add action=mark-connection chain=prerouting comment="Mark NordVPN IPSec traffic" connection-mark=!ipsec dst-address-list=!localnet,ipsec-remote new-connection-mark=NordV...
by erkexzcx
Sat Mar 27, 2021 10:40 am
Forum: General
Topic: Forward all wan traffic to another firewall
Replies: 9
Views: 2329

Re: Forward all wan traffic to another firewall

Sounds like you want to create a bridge out of 2 ethernet ports - first one is WAN, second one is pfsense. Do not assign any IP for such bridge. If you don't use bridge firewall in Mikrotik, then Mikrotik will not analyze traffic at all. Your pfsense will become "main router". Correct me s...
by erkexzcx
Sun Mar 21, 2021 10:29 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

but what about multiple exceptions? Honestly I don't know. If I were you, I would just do something like this: /ip firewall mangle add action=mark-connection chain=prerouting dst-port=80,443 new-connection-mark=novpn passthrough=yes protocol=tcp /ip firewall mangle add action=mark-connection chain=...
by erkexzcx
Sun Mar 21, 2021 6:09 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Does something like this do the trick?
/ip firewall mangle add action=mark-connection chain=prerouting dst-port=!80,443 new-connection-mark=under_nordvpn passthrough=yes protocol=tcp
by erkexzcx
Sun Mar 21, 2021 1:23 am
Forum: General
Topic: Set IP public to server behind mikrotik rb4011 wihtout nat [SOLVED]
Replies: 6
Views: 2355

Re: Set IP public to server behind mikrotik rb4011 wihtout nat [SOLVED]

Graphical scheme would be appreciated. :) I want to attribute the B1 to a server behind the rb4011 without nat Let's say you have ether1 port dedicated for WAN and ether2 dedicated for your server. Create bridge in your Mikrotik router and add eth1 and eth2 interfaces. Consider your created bridge a...
by erkexzcx
Sat Mar 20, 2021 11:40 pm
Forum: General
Topic: NordVPN multi WAN
Replies: 5
Views: 1483

Re: NordVPN multi WAN

Not sure what is exactly you are asking.
by erkexzcx
Sat Mar 20, 2021 12:04 am
Forum: General
Topic: Why can't I make my hEX lite into a router?
Replies: 19
Views: 2598

Re: Why can't I make my hEX lite into a router?

Is this router meant to be this difficult to set up? I set up "a lot" of routers. To be honest, I don't really understand what's the point for Mikrotik to provide "Quick settings" in the first place. Remove all the default configuration (reset the router with "remove-defaul...
by erkexzcx
Fri Mar 19, 2021 1:57 pm
Forum: General
Topic: Mikrotik Switch Recommendation for newbie
Replies: 22
Views: 3198

Re: Mikrotik Switch Recommendation for newbie

but not really new in networking in general so to speak There is no need to ask here then :) Look at the price and at the specs in Mikrotik website and this is all you need to know. Also I am a fan of RouterOS, but that's just personal. EDIT: Even 16eur Mikrotik routers have full capabilities with ...
by erkexzcx
Thu Mar 18, 2021 8:50 pm
Forum: General
Topic: I can't connect to my NVRs [SOLVED]
Replies: 12
Views: 4325

Re: I can't connect to my NVRs [SOLVED]

Did you even port-forward your NVR ports? I don't see any dstnat rules in your config.

normal dynamic public ip
You are using "/ip cloud" instead of WAN IP, right?
by erkexzcx
Sun Mar 14, 2021 1:38 pm
Forum: General
Topic: Winbox on Linux Problems
Replies: 33
Views: 19822

Re: Winbox on Linux Problems

Can anyone elaborate how UFW blocks WinBox? You mean UFW also blocks OUTPUT chain too?
by erkexzcx
Wed Mar 10, 2021 11:54 am
Forum: Scripting
Topic: Mikrotik Script connect mysql server
Replies: 3
Views: 2368

Re: Mikrotik Script connect mysql server

Why not the other way around? Connecting to Mikrotik router to write/read config/data?
by erkexzcx
Mon Mar 08, 2021 6:29 pm
Forum: General
Topic: Is there a shortage with some Mikrotik products ?
Replies: 3
Views: 1223

Re: Is there a shortage with some Mikrotik products ?

Situation in Lithuania: Networking e-shop katalita.lt has the following: https://www.katalita.lt/info/search.html?q=hap+ac3 RBD53GR-5HacD2HnD&R11e-LTE6 - they have in stock RBD53iG-5HacD2HnD - they don't have in stock. Looking at centralized search (for lithuanian shops) there is only one result...
by erkexzcx
Wed Mar 03, 2021 4:11 pm
Forum: General
Topic: IMPROVEMENT: Allow closing Winbox windows with middle click on the title bar
Replies: 1
Views: 666

Re: IMPROVEMENT: Allow closing Winbox windows with middle click on the title bar

TIL: I can close tabs in browser with a middle mouse button. Thanks, but this is totally not needed for WinBox.
by erkexzcx
Fri Feb 26, 2021 3:03 pm
Forum: Beginner Basics
Topic: PC can not reach internet, router can.
Replies: 9
Views: 1698

Re: PC can not reach internet, router can.

Show your firewall filter rules.
by erkexzcx
Fri Feb 26, 2021 2:58 pm
Forum: Beginner Basics
Topic: IKEv2 VPN
Replies: 27
Views: 48302

Re: IKEv2 VPN

I wanted to do the same. Basically you need to do majority of steps from this while having this in mind. Finally I end up with this and can't get over it (works fine on Android phone using Strongswan client, but not from Windows PC native IPSEC/IKE2).
by erkexzcx
Tue Feb 23, 2021 10:59 am
Forum: General
Topic: Loss of trafic for a few seconds every 20 minutes in a EoIP tunnel
Replies: 3
Views: 576

Re: Loss of trafic for a few seconds every 20 minutes in a EoIP tunnel

Tried disabling EoIP keepalive (in EoIP interface settings) on both sides?
by erkexzcx
Tue Feb 23, 2021 10:57 am
Forum: General
Topic: Winbox - Darkmode - Please [SOLVED]
Replies: 33
Views: 21264

Re: Winbox - Darkmode - For the love of God, Please. [SOLVED]

or at least option to reverse colors of WinBox :D
by erkexzcx
Tue Feb 23, 2021 10:45 am
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 8429

Re: Double NAT & no public IP for VPN [SOLVED]

I've looked at that topic too, and unless I've missed something, the responder (server) must have a public IP or port-forwarding from a public IP must be possible. So not applicable for your case. User still has to purchase VPS with public IP in order to have public IP. Linode was just an example (...
by erkexzcx
Tue Feb 23, 2021 10:36 am
Forum: General
Topic: block internet access but allow some sites - NOT WORKING
Replies: 7
Views: 1533

Re: block internet access but allow some sites - NOT WORKING

Sites blocking is never going to work. At some point user will start using VPN provider and there is no way to block it (e.g. NordVPN can use 443 over TCP as well as obfuscated traffic).
by erkexzcx
Tue Feb 23, 2021 10:24 am
Forum: General
Topic: Is SWOS still in development?
Replies: 0
Views: 542

Is SWOS still in development?

Just wondering what is the state of SwitchOS of Mikrotik? The last update was from 2020, and when I purchased CRS112-8P-4S-IN it came only with ROS. No option to dual boot.
by erkexzcx
Tue Feb 23, 2021 10:18 am
Forum: Beginner Basics
Topic: EOIP over IPSEC tunnel connection is unstable
Replies: 2
Views: 1030

Re: EOIP over IPSEC tunnel connection is unstable

Did you check this? viewtopic.php?f=23&t=169538 I've got it working perfectly fine.
by erkexzcx
Tue Feb 23, 2021 10:16 am
Forum: Beginner Basics
Topic: Setup VPN on a Router
Replies: 2
Views: 708

Re: Setup VPN on a Router

How about going to actual official Mikrotik wiki and using guides from there? Also users in Mikrotik forum posted few as well. e.g. I created this: https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 + https://forum.mikrotik.com/viewtopic.php?t=151188#p839793 One of the best guides online I f...
by erkexzcx
Tue Feb 23, 2021 9:59 am
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 8429

Re: Double NAT & no public IP for VPN [SOLVED]

Thanks for the solution. I'm thinking about this in a whole month. And you are right Vultr is the cheapest VPS I found so far Have you tried OpenVPN Cloud? or AWS free tier + OpenVPN Just FYI - Mikrotik ROS can be installed on x86_64 hardware, and I mean virtual machine. What I am trying to say tha...
by erkexzcx
Sat Feb 13, 2021 8:33 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 6
Views: 6145

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

I think Windows 10 built-in VPN client still doesn't understand sha256 when doing phase 2 and modp2048 when doing phase 1. Change or add profiles dh-group to modp1024 and proposals auth-algorithms to sha1. I haven't tested it for myself, but you should try this. It logs you can see that VPN connect...
by erkexzcx
Sat Feb 13, 2021 8:32 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 6
Views: 6145

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

See my post here.
Nothing that could help me there
by erkexzcx
Sat Feb 13, 2021 3:19 pm
Forum: General
Topic: Speedtest.net - How to bypass
Replies: 10
Views: 16830

Re: Speedtest.net - How to bypass

Let's talk about NordVPN - it allows you to unblock websites & get around throttling on any crappy ISP. :) And you can't block it.

Blocking websites is not going to work.
by erkexzcx
Sat Feb 13, 2021 12:43 pm
Forum: General
Topic: Speedtest.net - How to bypass
Replies: 10
Views: 16830

Re: Speedtest.net - How to bypass

This is what I would do: 1. Use "nslookup speedtest.net" to resolve to IP address. 2. Take a single IP address and google it. Find "ipinfo.io" website in results and check it. Find "ASHandle" value and check it. In this case I've ended up with this link https://ipinfo.i...
by erkexzcx
Sat Feb 13, 2021 12:30 pm
Forum: General
Topic: Problems with IPSec - only one device can connect
Replies: 3
Views: 1099

Re: Problems with IPSec - only one device can connect

I just created another thread in here. I've shared the configuration that works for me: https://forum.mikrotik.com/viewtopic.php?f=2&t=172558 On the other hand, I've written few guides there and there, so you can take a look too: https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 https:/...
by erkexzcx
Sat Feb 13, 2021 12:25 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 6
Views: 6145

Windows 10 unable to connect to IPSEC/IKE2 VPN

I've setup IPSEC/IKE2 VPN server on my Mikrotik router. This is how I set it up: # Generate CA /certificate add name="My CA" common-name="My CA" key-size=4096 days-valid=3650 key-usage=key-cert-sign,crl-sign # Generate client and server certs /certificate add name="My client...
by erkexzcx
Wed Feb 10, 2021 8:50 am
Forum: Beginner Basics
Topic: NordVPN issue
Replies: 8
Views: 5115

Re: NordVPN issue

viewtopic.php?f=23&t=169273 I think Mikrotik should pin this thread so more people can see.
by erkexzcx
Sun Feb 07, 2021 4:54 pm
Forum: Useful user articles
Topic: Hairpin NAT - the easy way
Replies: 45
Views: 74581

Hairpin NAT - the easy way

Decided to write a simple guide on Hairpin NAT, because quite a lot of users struggle to understand how to set it up. I am not a networking professional and I am open to any criticism on how to implement it in a better way. Official wiki page by Mikrotik regarding Hairpin NAT: https://wiki.mikrotik....
by erkexzcx
Sun Feb 07, 2021 4:16 pm
Forum: General
Topic: Firewall mess
Replies: 2
Views: 818

Re: Firewall mess

I am not sure what you are asking, but you should clean it up and rebuild as per instructions here: https://help.mikrotik.com/docs/display/ ... t+Firewall

Also use this to secure your router https://help.mikrotik.com/docs/display/ ... our+router
by erkexzcx
Sun Feb 07, 2021 3:35 pm
Forum: General
Topic: Is my IP blocked on Mikrotik servers, or is it my ISP being crap?
Replies: 1
Views: 643

Is my IP blocked on Mikrotik servers, or is it my ISP being crap?

I have a very strange issue - for some reason I am no longer able access any Mikrotik websites, such as mikrotik.com, forum.mikrotik.com and help.mikrotik.com. I am also unable to fetch any updates directly from Mikrotik routers too. All other websites are loading fine, except Mikrotik's websites. O...
by erkexzcx
Tue Feb 02, 2021 10:55 am
Forum: Beginner Basics
Topic: My last hope.
Replies: 10
Views: 1609

Re: My last hope.

Perform ping test from Mikrotik to 1.1.1.1. Then perform the same from your PC. Is the result almost identical?

We can't say what's wrong, unless you share your configuration with us.
by erkexzcx
Tue Jan 26, 2021 1:28 pm
Forum: General
Topic: Slow VPN performance?
Replies: 9
Views: 6300

Re: Slow VPN performance?

Your router is not mentioned here: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Hardware_acceleration So it means that you will get terrible performance. I would also suggest bypassing fasttrack (either by using "notrack" or "allowing" traffic before fastrack rule) and tuning M...
by erkexzcx
Tue Jan 26, 2021 1:25 pm
Forum: Beginner Basics
Topic: Switch chip
Replies: 9
Views: 1965

Re: Switch chip

After i configured the port as a access port in the switch chip , that particular port can not access the router using by winbox.
Thanks for sharing!
by erkexzcx
Mon Jan 25, 2021 1:38 pm
Forum: General
Topic: IPSEC Forwarding
Replies: 4
Views: 2231

Re: IPSEC Forwarding

What?
But what else is required in order for IPSEC to establish a tunnel between these two drayteks when my mikrotik is feeding one of them internet?
by erkexzcx
Sun Jan 24, 2021 11:47 pm
Forum: General
Topic: Buy/Subscirbe VPN GAME Amazon Web Services (AWS)
Replies: 6
Views: 948

Re: Buy/Subscirbe VPN GAME Amazon Web Services (AWS)

Do you even realise what and why you are asking?
by erkexzcx
Sun Jan 24, 2021 11:40 pm
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 8429

Re: Double NAT & no public IP for VPN [SOLVED]

You can't access Mikrotik router if it's behind NAT (which is owned by ISP).

But you can open the tunnel from your Mikrotik to VPN server, especially if you have another Mikrotik router with public IP. And I mean this: viewtopic.php?f=23&t=169538
by erkexzcx
Sun Jan 24, 2021 11:36 pm
Forum: Beginner Basics
Topic: IP sec negociation error
Replies: 6
Views: 2089

Re: IP sec negociation error

I am probably blind. Where does it say that it fails?

From my own experience - you should check logs on both sides. They might not say anything in one side, but will specify where is the issue on the other side.

EDIT: Your blurred IP is still readable :D
by erkexzcx
Mon Jan 18, 2021 10:11 am
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 5
Views: 4363

Re: VPN/ipsec with strongSwan

So to clarify things up for everyone - Strongswan app on Android has no option to force ignore this constraint. In order to fix it, you must generate a new certificate for your VPN server, but this time with correct subject-alt-name . E.g. I am always using "/ip cloud" DNS to connect to a ...
by erkexzcx
Sun Jan 17, 2021 9:11 pm
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 5
Views: 4363

Re: VPN/ipsec with strongSwan

+1 Android strongswan client. WTF How to get rid of it.
by erkexzcx
Sat Jan 16, 2021 12:47 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Please tell me how to correctly forward the port for example for torrent in this configuration?
1. How is it related to this thread?
2. Why would you need port forward for...torrents?
by erkexzcx
Fri Jan 15, 2021 8:18 pm
Forum: RouterOS beta
Topic: Any chance to install ROS6 on Chateau 12?
Replies: 6
Views: 2083

Any chance to install ROS6 on Chateau 12?

Any chance to get ROS6 working on Chateau 12 router? I know this router is ROS7 only. But let's be honest - this is a bit too aggressive approach from Mikrotik to force users to use beta software in order to get it more tested and more bugs fixed in the long run. Because of some bugs that affects co...
by erkexzcx
Wed Jan 06, 2021 6:24 pm
Forum: General
Topic: Feature request for mobile app. bandwidth limiter set
Replies: 2
Views: 1688

Re: Feature request for mobile app. bandwidth limiter set

Wait until they figure out how to change MAC address. Seems they should not worry about VPNs in this case:)

Can you be more specific on what is missing in Mikrotik routers? You want to enable/disable internet access, throttle bandwidth or block certain websites?
by erkexzcx
Tue Jan 05, 2021 12:35 am
Forum: General
Topic: Isolate two bridges at Layer 2 [SOLVED]
Replies: 7
Views: 2340

Re: Isolate two bridges at Layer 2 [SOLVED]

Correct regarding bridges - they are like separate interfaces. They have nothing common between them so no L2 routing between them is possible if you did not setup any exotic configurations. Instead you should probably use this: add action=drop chain=forward in-interface=bridge1 out-interface=bridge...
by erkexzcx
Mon Jan 04, 2021 11:49 am
Forum: General
Topic: WPA3 on existing Mikrotik routers/APs [SOLVED]
Replies: 27
Views: 38075

Re: WPA3 on existing Mikrotik routers/APs [SOLVED]

Talking about WPA3 security: https://arstechnica.com/information-technology/2019/04/serious-flaws-leave-wpa3-vulnerable-to-hacks-that-steal-wi-fi-passwords/ As long as clients are in transitional mode, they will connect to the WPA2-only access point. As soon as that happens, attackers have the four-...
by erkexzcx
Mon Jan 04, 2021 11:42 am
Forum: Beginner Basics
Topic: Server is not accessable through mikrotik router
Replies: 3
Views: 1000

Re: Server is not accessable through mikrotik router

What is not working is I cant access my server ip 192.168.1.10 internally but server have internet.
what?
by erkexzcx
Mon Jan 04, 2021 11:39 am
Forum: RouterOS beta
Topic: Chateau LTE12 stop work
Replies: 2
Views: 1649

Re: Chateau LTE12 stop work

Sometimes hardware fails. What about lights on router?
by erkexzcx
Thu Dec 31, 2020 10:18 am
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 2200

Re: L2TP/IPsec Android Second phase problem

Sorry to answer so rarely, but I can only answer in the evenings. Not everyone has all day to spend on this forum :D I can't tell what is wrong from the logs. Unless someone else has anything to add, I would say - Android's native VPN is "faulty". I've had a colleague who was having simil...
by erkexzcx
Wed Dec 30, 2020 9:33 pm
Forum: Beginner Basics
Topic: Approximately 5s delay in TCP connections when using a static route via an address on bridge [SOLVED]
Replies: 9
Views: 2979

Re: Approximately 5s delay in TCP connections when using a static route [SOLVED]

Seems your target destination (of your static route) is part of existing bridge. I once had similar issue and all was fixed when I enabled bridge firewall:

/interface bridge settings set use-ip-firewall=yes

It just fixed it for me. Maybe someone has better ways to fix this kind of issue.
by erkexzcx
Wed Dec 30, 2020 9:30 pm
Forum: Beginner Basics
Topic: Chateau LTE12: mtu info
Replies: 6
Views: 1962

Re: Chateau LTE12: mtu info

What does field "Actual MTU" shows for lte1 interface? What would happen if you set MTU to 1550 for lte1?
by erkexzcx
Wed Dec 30, 2020 9:27 pm
Forum: Beginner Basics
Topic: OpenVPN weird behavior since changing to Microtik?
Replies: 1
Views: 480

Re: OpenVPN weird behavior since changing to Microtik?

How is Mikrotik related here?
by erkexzcx
Wed Dec 30, 2020 4:18 pm
Forum: General
Topic: Device on other side of EoIP are not being NATed to the Internet
Replies: 11
Views: 1789

Re: Device on other side of EoIP are not being NATed to the Internet

I want device in REMOTE to be on the same subnet as those in CENTRAL. I also want the device from REMOTE to go through CENTRAL to access the internet, so the last NAT is done at CENTRAL. Correct me if I am wrong, but all you want is to add EoIP interface to a LAN bridge on each router, mark it as &...
by erkexzcx
Wed Dec 30, 2020 4:05 pm
Forum: RouterOS beta
Topic: hAP ac2 back from 7.1b3 failed [SOLVED]
Replies: 2
Views: 2765

Re: hAP ac2 back from 7.1b3 failed [SOLVED]

On the positive side, everyone who purchased Chateau12 is stuck with ROS7 only. To be honest, for home or small office, ROS7 is perfectly fine.

Netinstall should still work tho.
by erkexzcx
Wed Dec 30, 2020 1:08 pm
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 2200

Re: L2TP/IPsec Android Second phase problem

I suspect your Android device and Mikrotik does not have overlapping ciphers. Anyway, enable "ipsec" logging in Mikrotik settings. Then try to connect using Android phone to VPN on Mikrotik router. Provide us logs. You should be able to see additional tag "debug" next to "ip...
by erkexzcx
Wed Dec 30, 2020 1:05 pm
Forum: General
Topic: IPsec dynamic IP address
Replies: 3
Views: 2041

Re: IPsec dynamic IP address

You should learn how to write your questions in a more organized way. Code formatting is also a thing (useful for displaying a logs). If you want different policies for specific clients, then you should properly setup remote-id matching as well as specific mode configs and policies. I've done simila...
by erkexzcx
Tue Dec 29, 2020 2:54 pm
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 2200

Re: L2TP/IPsec Android Second phase problem

Did you check threads like this? viewtopic.php?t=153546
by erkexzcx
Tue Dec 29, 2020 1:45 pm
Forum: Beginner Basics
Topic: Router was rebooted without proper shutdown [SOLVED]
Replies: 2
Views: 4134

Re: Router was rebooted without proper shutdown [SOLVED]

Looks like either RouterOS crashed and rebooted (not sure if router reboots in this case, probably due to watchdog), or there was power issues. Maybe PSU is having issues, or your power supply had issues. I closed all the IP services except Winbox Did you whitelist access to router? Hopefully winbox...
by erkexzcx
Tue Dec 29, 2020 12:02 pm
Forum: Beginner Basics
Topic: Looking for a Product (Router)
Replies: 5
Views: 811

Re: Looking for a Product (Router)

A bit hard to recommend. 5G is not supported by Mikrotik, so LTE is the only option. Also Mikrotik support for OpenVPN is kind of "meh" (OpenVPN UDP is only supported in ROS7 which is beta, only TCP mode in ROS6). Would highly recommend sticking to L2TP/IPSEC or IPSEC/IKE2 instead. If you ...
by erkexzcx
Tue Dec 29, 2020 11:47 am
Forum: General
Topic: Can't get Policy based routing VPN to work
Replies: 8
Views: 2212

Re: Can't get Policy based routing VPN to work

Does your VPN provider support IPSEC/IKE2? If so, you can configure using this guide: viewtopic.php?f=23&t=169273

I haven't got a chance to play much with PPTP and not sure if I ever will because this protocol is very unsafe.
by erkexzcx
Mon Dec 28, 2020 4:08 pm
Forum: General
Topic: ikev2 2 sessions under one certificate [SOLVED]
Replies: 2
Views: 1218

Re: ikev2 2 sessions under one certificate [SOLVED]

Using same certificate might work..? If you ignore remote-id if I am not mistaken. Then VPN server cannot identity any of your client who is who, so just assigns random IP from the pool. Anyway, it's better to generate a separate certificate for each client and select "match-by=certificate"...
by erkexzcx
Mon Dec 28, 2020 4:02 pm
Forum: General
Topic: Can't get Policy based routing VPN to work
Replies: 8
Views: 2212

Re: Can't get Policy based routing VPN to work

Few ideas on what's wrong: Netflix detects when you are running through VPN server. It detects when you are using non-residential IP. Netflix has more domains. Not just "netflix.net". You need to route all such traffic using VPN. Not sure, but I think "content" parameter in Mikro...
by erkexzcx
Mon Dec 28, 2020 3:13 pm
Forum: General
Topic: VPN for Mikrotik for game Mobile legend
Replies: 9
Views: 4099

Re: VPN for Mikrotik for game Mobile legend

Not sure if you know anything about networking.

Just get a VPN subscription from a VPN provider, like NordVPN. See if it fixes the issue.
by erkexzcx
Mon Dec 28, 2020 2:56 pm
Forum: RouterOS beta
Topic: v7.1beta3 [development] is released!
Replies: 261
Views: 79985

Re: v7.1beta3 [development] is released!

ipip tunnel still not working wihout disable keepalive When I wrote https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 I was using ROS7 as a VPN client to ROS6 VPN server. EoIP did work, but was silently flapping leading to random disconnects from online multiplayer games. Disabling keepali...
by erkexzcx
Sun Dec 27, 2020 10:25 pm
Forum: RouterOS beta
Topic: New Feature Request: run script after Wireguard connection status changed. [SOLVED]
Replies: 3
Views: 2515

Re: New Feature Request: run script after Wireguard connection status changed. [SOLVED]

Can you use netwatch as a workaround for this (using any internal IP of wireguard)?
by erkexzcx
Sun Dec 27, 2020 5:33 pm
Forum: Beginner Basics
Topic: Questions about "Use host names in firewall rules" [SOLVED]
Replies: 3
Views: 1554

Re: Questions about "Use host names in firewall rules" [SOLVED]

This router is so good, I'm really glad I bought it despite of my initial concerns.
Kinda the same here. Thanks to my previous job I had to deal with Mikrotik routers. They significantly boosted my understanding of networking. :)
by erkexzcx
Sun Dec 27, 2020 5:30 pm
Forum: Beginner Basics
Topic: Generate paket lost on specific destination ! [SOLVED]
Replies: 3
Views: 1182

Re: Generate paket lost on specific destination ! [SOLVED]

Drops every 2nd packet when user pings to 95.217.228.176:
/ip firewall filter add action=drop chain=forward dst-address=95.217.228.176 nth=2,1
by erkexzcx
Sun Dec 27, 2020 5:20 pm
Forum: General
Topic: IPSEC IKEv2 network-to-network problems
Replies: 11
Views: 2123

Re: IPSEC IKEv2 network-to-network problems

Not what you are asking, but it might give you some hints: viewtopic.php?f=23&t=169538
by erkexzcx
Sun Dec 27, 2020 5:15 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Thanks for all the input! I've updated instructions accordingly.
by erkexzcx
Sun Dec 27, 2020 12:48 am
Forum: General
Topic: Mikrotik device behind limited ISP modem
Replies: 18
Views: 4596

Re: Mikrotik device behind limited ISP modem

This sounds like a Telia router in Lithuania, isn't it?
by erkexzcx
Sun Dec 27, 2020 12:46 am
Forum: General
Topic: Please finish implementation of OpenVPN protocol (authentication without password, certificates)
Replies: 5
Views: 1688

Re: Please finish implementation of OpenVPN protocol (authentication without password, certificates)

I would say the opposite - better focus on other, more imporant things and release a stable ROS7. OpenVPN should start to die. It's one of the slowest VPN protocols. Instead, pick L2TP/IPSEC, IPSEC/IKE2 or Wireguard as an alternative as these are industry standard VPN protocols. OpenVPN has insanely...
by erkexzcx
Sat Dec 26, 2020 6:13 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

@msatter - thanks for your input. I don't actually see it as a improvement to my given guide. I mean it does work, but using simple a mangle rule is a more dynamic way of dealing with VPN traffic. e.g. in address-list I gave domain which is being resolved by Mikrotik router. If it's updated, then it...
by erkexzcx
Thu Dec 24, 2020 8:48 pm
Forum: Beginner Basics
Topic: Changing internet provider
Replies: 3
Views: 1133

Re: Changing internet provider

No, it does not depend...

You need to configure your router the same way you configured previously for your current ISP.
by erkexzcx
Thu Dec 24, 2020 8:43 pm
Forum: General
Topic: proton vpn seems not fully functional
Replies: 2
Views: 1447

Re: proton vpn seems not fully functional

Try following this guide: viewtopic.php?f=23&t=169273

EDIT: You may need to reduce MSS size and exclude such traffic from fasttrack. Everything is mentioned in the above guide.
by erkexzcx
Thu Dec 24, 2020 12:55 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

With use case #2, how to killswitch websites like youtube.com that with multiple IP address? You can't, because: Note: You can't effectively route all the traffic of Youtube, Netflix or any other big websites through VPN. They have many different domains and IP addresses which constantly change. In...
by erkexzcx
Thu Dec 24, 2020 1:47 am
Forum: Scripting
Topic: hairpin with 2 WAN
Replies: 2
Views: 2542

Re: hairpin with 2 WAN

How about this? # Add both WAN interfaces to interfaces list. /interface list add name=WAN /interface list member add interface=ether1 list=WAN /interface list member add interface=ether2 list=WAN # Add this script to your Mikrotik router. /system script add name=dhcp_client_script source=":if ...
by erkexzcx
Wed Dec 23, 2020 9:54 am
Forum: Beginner Basics
Topic: Regarding Aggressive mode ipsec not working for peer (0.0.0.0/0) on ros above 6.43.13 [SOLVED]
Replies: 2
Views: 1187

Re: Regarding Aggressive mode ipsec not working for peer (0.0.0.0/0) on ros above 6.43.13 [SOLVED]

if you enable "ipsec" debug logging in both Mikrotik and OpenWRT, what does the log says?
by erkexzcx
Wed Dec 23, 2020 1:18 am
Forum: General
Topic: Surfshark IKEv2 VPN
Replies: 13
Views: 14703

Re: Surfshark IKEv2 VPN

by erkexzcx
Wed Dec 23, 2020 1:13 am
Forum: General
Topic: Add Christmas lights to Chateau 12 router
Replies: 2
Views: 691

Re: Add Christmas lights to Chateau 12 router

Post a movie
Done. I've updated initial comment.
by erkexzcx
Wed Dec 23, 2020 12:52 am
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 (with certs) tunnel + EoIP
Replies: 11
Views: 21844

Re: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

1. on both Router A and Router B, you have a NAT rule, like below, why we need this rule: /ip firewall nat add action=src-nat chain=srcnat dst-address=10.22.22.2 to-addresses=10.22.22.1 place-before=0 Ping to internal IP (10.22.22.2) from Router A did not work without this rule, so I added it. 2. I...
by erkexzcx
Wed Dec 23, 2020 12:23 am
Forum: General
Topic: Add Christmas lights to Chateau 12 router
Replies: 2
Views: 691

Add Christmas lights to Chateau 12 router

Since this router does not have beeper and you can't play songs on it, but it does have controllable LEDs, so you can give it some Christmas vibes. Video: https://i.imgur.com/8380H4K.mp4 ( imgur post ). WARNING - High amount of sector writes. It will eventually kill your flash storage with the time....
by erkexzcx
Tue Dec 22, 2020 11:40 pm
Forum: RouterOS beta
Topic: Chateau Config Backup & Restore
Replies: 14
Views: 3191

Re: Chateau Config Backup & Restore

Backup & Restore always sucked for me. Always use export & restore. Most of the config appears to take except there's no DHCP server set and the network settings appear to be missing I would say remove such lines from the exported config try again? Then connect using MAC address. /tool bandw...
by erkexzcx
Tue Dec 22, 2020 2:35 pm
Forum: Beginner Basics
Topic: Problems with portforwarding.
Replies: 9
Views: 1511

Re: Problems with portforwarding.

Sob he already had the default rule in place........ (but I much prefer the cleaner rule you suggested) add action=drop chain=forward comment="Drop incoming packets that are not NATted" connection-nat-state=!dstnat connection-state=new in-interface=ether1 log=yes log-prefix=!NAT Why would...
by erkexzcx
Sun Dec 20, 2020 12:52 pm
Forum: General
Topic: Equivalent Mikrotik IPSEC settings for this Linux config
Replies: 7
Views: 1315

Re: Equivalent Mikrotik IPSEC settings for this Linux config

Before someone helps you, i will give you some hints on where to look at. I've written few guidelines here and here on how to connect Mikrotik router using IPSEC/IKEv2. You have have an idea how configuration looks like and what steps you should take (e.g. exclude from fasttrack, add NAT, optionally...
by erkexzcx
Wed Dec 16, 2020 8:09 pm
Forum: General
Topic: Question about VPN, pools and subnets [SOLVED]
Replies: 11
Views: 2472

Re: Question about VPN, pools and subnets [SOLVED]

Aren't traffic, which is coming from the VPN clients, picked by these rules? Technically, connections are coming from WAN interfaces. /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=WAN /ip firewall filter add action=drop ch...
by erkexzcx
Wed Dec 16, 2020 7:56 pm
Forum: General
Topic: Password Questions
Replies: 3
Views: 1193

Re: Password Questions

if anyone can shed some light or some thoughts on this that would be great. Either you enterred incorrect username/password, or someone has changed username/password which means someone else managed to access Mikrotik device. Instead of creating a new account, put a stronger password for "admi...
by erkexzcx
Wed Dec 16, 2020 7:50 pm
Forum: General
Topic: Remote Access VPN + Site to Site VPN
Replies: 4
Views: 1091

Re: Remote Access VPN + Site to Site VPN

Is it possible that user when connects with remote access VPN to access network resources on remote site?
Yes
by erkexzcx
Wed Dec 16, 2020 4:02 pm
Forum: General
Topic: IPsec policy status Invalid [SOLVED]
Replies: 4
Views: 5603

Re: IPsec policy status Invalid [SOLVED]

by erkexzcx
Tue Dec 15, 2020 6:32 pm
Forum: Beginner Basics
Topic: VPN config - stopped working.
Replies: 2
Views: 957

Re: VPN config - stopped working.

They have many servers, some of them gets DDOS'ed, some of them get's reconfigured or decommissioned. You likely need to switch to any other server. I've written more complete guide for NordVPN because some steps were missing in official guides: https://forum.mikrotik.com/viewtopic.php?f=23&t=16...
by erkexzcx
Tue Dec 15, 2020 6:29 pm
Forum: Beginner Basics
Topic: bridge got 2 dhcp addrs & mac
Replies: 2
Views: 575

Re: bridge got 2 dhcp addrs & mac

So what is the question?
by erkexzcx
Tue Dec 15, 2020 9:59 am
Forum: Beginner Basics
Topic: setting up router with two AP
Replies: 7
Views: 2086

Re: setting up router with two AP

but will the wireless device automatically switch to the strongest signal?
+1 also interested.
by erkexzcx
Sat Dec 12, 2020 9:21 pm
Forum: General
Topic: VPN IKEv2 Client Problem
Replies: 3
Views: 1626

Re: VPN IKEv2 Client Problem

Try following this instead: viewtopic.php?f=23&t=169273
by erkexzcx
Wed Dec 09, 2020 8:07 pm
Forum: Beginner Basics
Topic: HAP Ac3 5 Ghz speed problem
Replies: 7
Views: 3503

Re: HAP Ac3 5 Ghz speed problem

Version is latest on both devices. There are RouterOS 7 beta, and RouterOS 6 stable... Anyway, I assume you are using ROS6. What would be the correct way to transfer all configuration This way: # 1. Export configuration from old router: /export file=myfile # 2. Download myfile.rsc to your computer....
by erkexzcx
Wed Dec 09, 2020 7:56 pm
Forum: Useful user articles
Topic: Howto wanted - block advertisement like Youtube
Replies: 6
Views: 14726

Re: Howto wanted - block advertisement like Youtube

I am still wondering given all the options of the OS why this should be so hard to do. I am trying to be helpful, but you clearly did not do enough research on your own. This is very wide topic on the internet, especially on the pi-hole forums. See https://discourse.pi-hole.net/t/how-do-i-block-ads...
by erkexzcx
Wed Dec 09, 2020 7:43 pm
Forum: Beginner Basics
Topic: HAP Ac3 5 Ghz speed problem
Replies: 7
Views: 3503

Re: HAP Ac3 5 Ghz speed problem

I transferred all the settings that was on Ac2 5 ghz wifi to Ac3 5 ghz wifi but this thing simply don't work ok Just a question: How did you transfer those settings and what RouterOS version you are using? Did you transfer configuration by a backup or export? I've had issues with backup&restore...
by erkexzcx
Wed Dec 09, 2020 7:32 pm
Forum: General
Topic: DNS over HTTPS, round robin support
Replies: 19
Views: 3558

Re: DNS over HTTPS, round robin support

Stupid question, but how does router know to which IP address to resolve cloudflare-dns.com domain, if you use only DoH?
by erkexzcx
Wed Dec 09, 2020 1:29 pm
Forum: Beginner Basics
Topic: access pfsense router behind mikrotik
Replies: 4
Views: 1291

Re: access pfsense router behind mikrotik

Allow access to 172.18.0.1 in Mikrotik firewall from your LAN. This means you need to edit existing firewall rules. Add DST-NAT rule in Mikrotik so when reaching 172.18.0.1 your src-ip is rewritten to 172.18.0.3. Also your configuration is questionable in overall, but above solution should work.
by erkexzcx
Wed Dec 09, 2020 11:58 am
Forum: Useful user articles
Topic: Howto wanted - block advertisement like Youtube
Replies: 6
Views: 14726

Re: Howto wanted - block advertisement like Youtube

How would I do this best and with as simple as possible a solution?

Buy Youtube premium.

What you are asking is not possible and totally unrelated to Mikrotik.
by erkexzcx
Wed Dec 09, 2020 12:09 am
Forum: General
Topic: clients->ipsec router no internet [SOLVED]
Replies: 3
Views: 1272

Re: clients->ipsec router no internet [SOLVED]

Aren't you supposed to specify out interface for it?
/ip firewall nat
...
add action=masquerade chain=srcnat
by erkexzcx
Tue Dec 08, 2020 12:55 am
Forum: Beginner Basics
Topic: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?
Replies: 5
Views: 2289

Re: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?

Could it be related to software installed on the PC (virtualization systems, etc.)?

How each virtual machine gets IP addresses? From the router?
by erkexzcx
Tue Dec 08, 2020 12:38 am
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 (with certs) tunnel + EoIP
Replies: 11
Views: 21844

Re: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

According to your issue(s) description - you are not having any issues.
by erkexzcx
Mon Dec 07, 2020 1:49 am
Forum: Beginner Basics
Topic: OVPN Client not connected
Replies: 2
Views: 738

Re: OVPN Client not connected

How did you import certificates? Do you have CA? Did Mikrotik import private key? Double check:
/certificate print
by erkexzcx
Mon Dec 07, 2020 1:41 am
Forum: General
Topic: Ipsec dh group modp 1024 android no suitable proposal found
Replies: 2
Views: 3343

Re: Ipsec dh group modp 1024 android no suitable proposal found

Enable ipsec logging and show full log when attempting to connect from smartphone:
/system logging add topics=ipsec action=memory
by erkexzcx
Sun Dec 06, 2020 1:26 pm
Forum: Scripting
Topic: Telegram
Replies: 8
Views: 4449

Re: Telegram

Answer is: No I did not manage to send directly from Mikrotik, because "fetch" tool does not support sending files. I managed to send using Raspberry Pi: Generate SSH keys on raspberry Pi and its upload public key to each router. Then pretty much use this bash script: #!/bin/bash ROUTER=$1...
by erkexzcx
Sun Dec 06, 2020 1:10 pm
Forum: Beginner Basics
Topic: travel router
Replies: 20
Views: 7973

Re: travel router

Your device is fine. It will work. Since you want encrypted tunnel to your home, I would suggest picking a router with IPSEC hardware acceleration, something like HAP AC2 would be great because it's cheap and supports both 5ghz/2.4ghz wifi. Everything else that you mentioned is possible. Even if you...
by erkexzcx
Sun Dec 06, 2020 1:01 pm
Forum: General
Topic: IPSec tunnel from mikrotik behind NAT with Cisco
Replies: 4
Views: 2585

Re: IPSec tunnel from mikrotik behind NAT with Cisco

Since you've tried already (I assume), which part do you think is failing/not working?

When I started learning about IPSEC the only way to move forward was to enable ipsec logs in both Mikrotik routers and see what is actually failing or happening.

Can you show us some logs/configuration exports?
by erkexzcx
Sat Dec 05, 2020 7:50 pm
Forum: Beginner Basics
Topic: Vpn Site To Site With Vlan
Replies: 8
Views: 5071

Re: Vpn Site To Site With Vlan

So how can I do to make the two microtiks communicate directly without NAT.
I need to connect the two VLANs as well.
There's a way?
I've done this. In both ends EoIP interface is added to main LAN bridges and basically LANs are connected.
by erkexzcx
Sat Dec 05, 2020 3:57 pm
Forum: General
Topic: IPSec tunnel from mikrotik behind NAT with Cisco
Replies: 4
Views: 2585

Re: IPSec tunnel from mikrotik behind NAT with Cisco

Maybe this could help? Not really what you are asking, but you might get some hints.
by erkexzcx
Sat Dec 05, 2020 3:55 pm
Forum: General
Topic: PWR-LINE PRO
Replies: 26
Views: 6075

Re: PWR-LINE PRO

Sorry for hijacking thread, but for those who use PWR-LINE PRO - do you get additional latency? I've never used EoP devices before.

I've heard stories that when using such devices you might get somewhat 30ms latency, even tho internet connectivity is rock stable. Just want to hear if it's true.
by erkexzcx
Sat Dec 05, 2020 3:25 pm
Forum: Beginner Basics
Topic: How to block an IP range? [SOLVED]
Replies: 4
Views: 2581

Re: How to block an IP range? [SOLVED]

Should I want to reverse this, what would be the code? You should not copy/paste code given by the stranger to your Mikrotik router and expect it to work. This means you should understand what those commands do and how to undo them. Hopefully you are using Winbox. WebFix is also an option, but I fi...
by erkexzcx
Sat Dec 05, 2020 3:01 pm
Forum: Beginner Basics
Topic: Issues with Mikrotik hAP AC2
Replies: 17
Views: 6264

Re: Issues with Mikrotik hAP AC2

I would also like to add that Mikrotik is not that messy. Obviously not perfect, but it isn't that buggy as users say. Pretty much sums up to this: Users: I want to do something with Mikrotik that I barely understand. Also users: Mikrotik is buggy I mean you are dealing with enterprise-grade equipme...
by erkexzcx
Fri Dec 04, 2020 8:45 pm
Forum: RouterOS beta
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 3753

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

I confirm that beta3 fixes this issue.
by erkexzcx
Thu Dec 03, 2020 9:08 pm
Forum: Beginner Basics
Topic: PCQ queue is better than without any queue?
Replies: 5
Views: 2414

Re: PCQ queue is better than without any queue?

+1 interested in more information about it. From my understanding, queues are great when there is constantly not enough bandwidth for everyone, so someone always has to wait for other users to finish transmitting data. Queues would help because everyone will get fair amount of time to transmit data,...
by erkexzcx
Thu Dec 03, 2020 6:40 pm
Forum: General
Topic: Peplink to mikrotik VPN
Replies: 4
Views: 1591

Re: Peplink to mikrotik VPN

https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP

Either ask something more specific, or that's all we could help.
by erkexzcx
Wed Dec 02, 2020 9:56 pm
Forum: Beginner Basics
Topic: RouterBOARD Emulator?
Replies: 2
Views: 8684

Re: RouterBOARD Emulator?

Yes, they are called virtual machines and CHR images.

There are some other options as well.

Hopefully your router has already arrived. :)
by erkexzcx
Wed Dec 02, 2020 9:51 pm
Forum: Beginner Basics
Topic: How to block an IP range? [SOLVED]
Replies: 4
Views: 2581

Re: How to block an IP range? [SOLVED]

First, you need to realise the networks you specified. The range "157.175.0.0-157.175.255.255" is the same as network "157.175.0.0/16". On the other hand, Mikrotik does support ranges (just do not use spaces). Make address list out of them: /ip firewall address-list add address=1...
by erkexzcx
Wed Dec 02, 2020 9:21 pm
Forum: Beginner Basics
Topic: Pivpn wireguard portforwarding problem [SOLVED]
Replies: 3
Views: 1907

Re: Pivpn wireguard portforwarding problem [SOLVED]

Please use this for code. Helps if you want to receive help faster: [code] my code goes here [//code] I have few questions: Why would you need Mikrotik router for your setup in the first place? You are using modem, which means you don't have public IP (aka "direct access"), right? Why is y...
by erkexzcx
Wed Dec 02, 2020 9:08 pm
Forum: Beginner Basics
Topic: L2PT server won't work - Local clients won't connect
Replies: 4
Views: 949

Re: L2PT server won't work - Local clients won't connect

I am not sure if you show all available logs, or you just did not enable logging. Enable more logging using below command and share wider log:
/system logging add topics=ipsec,l2tp
by erkexzcx
Wed Dec 02, 2020 8:52 pm
Forum: Beginner Basics
Topic: Suggestions for new network
Replies: 2
Views: 623

Re: Suggestions for new network

Looks like you are trying to do something called "Security over obscurity". I am not sure what VPN you are using, but looks like you can do this (see 2nd use case). Set static IPs for your TVs, then add connection mark for your TVs traffic which is found by their their static source IP. Th...
by erkexzcx
Wed Dec 02, 2020 8:40 pm
Forum: Beginner Basics
Topic: 4011 affecting outbound services
Replies: 45
Views: 5469

Re: 4011 affecting outbound services

Maybe totally unrelated, don't by mad at me, but once I had to setup another router on my LAN which would act as a gateway. Then I setup static route in my main Mikrotik router, so if device is accessing <some_network>, route through that gateway on the LAN. Else - route as usual to the WAN. Turned ...
by erkexzcx
Wed Dec 02, 2020 8:30 pm
Forum: RouterOS beta
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 3753

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

erkexzcx: At home I have "Mikrotik RB4011iGS+RM" router and Netgear R7800 with OpenWRT acting as access point only. This setup is rock stable . Now I have "Mikrotik RB4011iGS+RM" working as router and "Mikrotik Chateau 12" as access point only. And this setup is causin...
by erkexzcx
Sun Nov 29, 2020 12:29 pm
Forum: RouterOS beta
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 3753

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

Disabling and re-enabling Wireless interface temporarily fixes the issue...
by erkexzcx
Sun Nov 29, 2020 11:22 am
Forum: General
Topic: 2 locations IPSEC, internet acces via tunnel
Replies: 5
Views: 1576

Re: 2 locations IPSEC, internet acces via tunnel

I just can't miss opportunity to share my written guide :D https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 EDIT : See the bottom of that post. Basically you need to disable DHCP server in parents router, add estalbished EoIP interface to main LAN bridges in both your home and parents rout...
by erkexzcx
Sat Nov 28, 2020 6:44 pm
Forum: RouterOS beta
Topic: Chateau LTE12, Router OS v7.1beta2, packet loss
Replies: 6
Views: 2248

Re: Chateau LTE12, Router OS v7.1beta2, packet loss

Let's make problem's description simple - you are getting packet loss only when you ping anything on the internet via LTE interface?
by erkexzcx
Sat Nov 28, 2020 5:54 pm
Forum: RouterOS beta
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 3753

Chateau 12 - WiFi no longer connects for a random device [SOLVED]

Description I have Chateau 12 Mikrotik router with latest ROS 7.1 beta2, which I am using as access point. I setup 2 WiFis - one for 2.4Ghz and the other one for 5Ghz. Since I have no point to use 2.4Ghz for now, I only use 5Ghz WiFi only. I don't know if this issue happens with 2.4Ghz. Main router...
by erkexzcx
Sat Nov 28, 2020 12:32 am
Forum: Beginner Basics
Topic: Using DHCP "Active Host Name" for local IP resolution
Replies: 3
Views: 7546

Re: Using DHCP "Active Host Name" for local IP resolution

More or less you are looking at DNS server functionality. It's called "resursive DNS server" and that's what clients are using when they are getting resolutions from Mikrotik router. I am not sure if this is possible with Mikrotik directly, but you can set static entries in ip>dhcp server>...
by erkexzcx
Fri Nov 27, 2020 9:08 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 33
Views: 5215

Re: Ipsec not traffic passing

Not Working!
So what logs say? Enable ipsec logging and show the logs. What is happening in overall?
by erkexzcx
Fri Nov 27, 2020 7:36 pm
Forum: Beginner Basics
Topic: Understanding the Firewall rules. [SOLVED]
Replies: 3
Views: 1317

Re: Understanding the Firewall rules. [SOLVED]

The rules you see in Mikrotik are kinda the same as you would see in Linux servers. E.g. https://github.com/trimstray/iptables-essentials https://gist.github.com/Tristor/ed0f6867d2b0fa4c1f80300af6e0e12e#file-iptables-sh It might help if you need additional resources regarding firewalls in Linux syst...
by erkexzcx
Fri Nov 27, 2020 6:49 pm
Forum: General
Topic: Transparent IP Mode
Replies: 2
Views: 1007

Re: Transparent IP Mode

Isn't that the same as:
  1. Bridging 2 interfaces
  2. Giving IP address to the bridge
  3. Enabling bridge firewall (in bridge settings) and setting up such bridge firewall rules?
by erkexzcx
Fri Nov 27, 2020 4:36 pm
Forum: Announcements
Topic: v6.47.8 [stable] is released!
Replies: 54
Views: 31580

Re: v6.47.8 [stable] is released!

RBD52G-5HacD2HnD (HAP AC2) does not even show "health" option under "System" in Winbox. This is what happens when I check from CLI: [admin@name] > /system health print [admin@name] > But it works on RB4011iGS+: [admin@surname] > /system health print voltage: 23.5V temperature: 36...
by erkexzcx
Fri Nov 27, 2020 4:27 pm
Forum: General
Topic: Very frequent cloud.mikrotik.com activity [SOLVED]
Replies: 4
Views: 1140

Re: Very frequent cloud.mikrotik.com activity [SOLVED]

https://wiki.mikrotik.com/wiki/Manual:IP/Cloud DDNS or Dynamic DNS is a service that updates the IPv4 address for A records and the IPv6 address for AAAA records periodically. Such a service is very useful when your ISP has provided a dynamic IP address that changes periodically, but you always need...
by erkexzcx
Fri Nov 27, 2020 4:22 pm
Forum: General
Topic: VPN solution for small office issues
Replies: 10
Views: 1717

Re: VPN solution for small office issues

I've checked all your configuration once again and not sure what could it be. It's the worst type of incidents when they happen randomly... For now I suggest providing logs from client/server regarding IPSEC/L2TP. I have a feeling that it might happen when lifetime expires in "/ip ipsec profile...
by erkexzcx
Fri Nov 27, 2020 3:38 pm
Forum: General
Topic: IPsec to Fortigate
Replies: 1
Views: 570

Re: IPsec to Fortigate

For a person which is new to IPSEC or even new to VPNs it's near impossible to get it right at first several tries. I've jumped into similar thing when I was asked to connect Mikrotik router to strongswan VPN server and it was nightmare. I have no experience with Fortigate, but since you are doing s...
by erkexzcx
Fri Nov 27, 2020 3:27 pm
Forum: General
Topic: VPN solution for small office issues
Replies: 10
Views: 1717

Re: VPN solution for small office issues

Can this be related? viewtopic.php?t=132823

Mikrotik support commented that instead of dealing with all that mess one should switch to IPSEC/IKE2.
by erkexzcx
Fri Nov 27, 2020 3:19 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 33
Views: 5215

Re: Ipsec not traffic passing

Try again. At least you are missing NAT rule.
by erkexzcx
Fri Nov 27, 2020 3:03 pm
Forum: General
Topic: How to change internet address to local, reverse NAT
Replies: 12
Views: 3292

Re: How to change internet address to local, reverse NAT

It's called Hairpin NAT . Here is the example: /ip firewall nat add action=masquerade chain=srcnat comment="Hairpin NAT" dst-address=172.18.17.0/24 src-address=172.18.17.0/24 /ip firewall nat add action=masquerade chain=srcnat comment="Main NAT" out-interface-list=ether1 /ip fire...
by erkexzcx
Fri Nov 27, 2020 2:52 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 33
Views: 5215

Re: Ipsec not traffic passing

Check my guide: viewtopic.php?f=23&t=169538

I think you are missing bridge/interface for VPN server as well as NAT rule for internal networks. I've mentioned everything there.
by erkexzcx
Fri Nov 27, 2020 12:03 am
Forum: Beginner Basics
Topic: OVPN +LAN
Replies: 1
Views: 484

Re: OVPN +LAN

First of all, RouterOS 6.* only supports TCP mode, while RouterOS 7.* supports UDP as well (if I am not mistaken). See https://wiki.mikrotik.com/wiki/OpenVPN#Features. Another thing is that you will get a terrible performance out of OpenVPN as it is one of the slowest VPN protocols. Instead you shou...
by erkexzcx
Thu Nov 26, 2020 11:47 am
Forum: Beginner Basics
Topic: Manual DNS for individual clients? [SOLVED]
Replies: 6
Views: 3206

Re: Manual DNS for individual clients? [SOLVED]

Who would have thought you could do this on a router! Prior Mikrotik I had OpenWRT experience and there in DHCP server setting you have custom DHCP options and under the field there is a suggestion that "type this in order to give custom DNS to clients". When I noticed DHCP options in Mik...
by erkexzcx
Thu Nov 26, 2020 10:26 am
Forum: General
Topic: Winbox on Apple Silicon first try [SOLVED]
Replies: 22
Views: 26419

Re: Winbox on Apple Silicon first try [SOLVED]

I suggest using web browser for Mikrotik control, or CLI (e.g. SSH) for now as workaround.

This should be addressed to Wine as well because it's more or less issue with Wine.
by erkexzcx
Wed Nov 25, 2020 9:23 pm
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 (with certs) tunnel + EoIP
Replies: 11
Views: 21844

Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 (with certs) tunnel + EoIP

Overview Notes: I've been using latest ROS6 (6.47.8) for this guide. Steps might be different on ROS7. Tutorial shows how to connect 2 routers, but at the end of this guide there are steps on how to connect 3rd router. Router A (internal VPN IP 10.22.22.1) - VPN server. Has public IP. Router B (int...
by erkexzcx
Tue Nov 24, 2020 9:30 pm
Forum: General
Topic: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]
Replies: 1
Views: 1173

Re: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]

I was about to write to RouterOS7 forum because I suspected it's a bug with routeros7, but seems it's not: This is how I solved: Waste 2 days trying to understand where is the issue. Turn off Router B, get another Mikrotik router with ROS6 and configure identical IPSEC/IKE2 client setup. It connects...
by erkexzcx
Tue Nov 24, 2020 1:15 pm
Forum: General
Topic: Nordvpn IPsec Mikrotik Routing
Replies: 15
Views: 5679

Re: Nordvpn IPsec Mikrotik Routing

when connected to NordVPN UK host BBC detects it as if I am not in the UK and blocks the UK contentet such as Iplayer.
Make sure you are using NordVPN DNS provided by VPN server.
by erkexzcx
Tue Nov 24, 2020 12:12 pm
Forum: General
Topic: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]
Replies: 1
Views: 1173

EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]

So I have 2 Mikrotik routers: Router A: has public IP and hosting IPSEC/IKE2 VPN server. Latest RouterOS6. Router B: does not have public IP (behind other router's NAT) and acting as VPN client to Router A. Latest RouterOS 7 (beta2). Goal: LAN over internet, so I connect PC to router B and get IP fr...
by erkexzcx
Sun Nov 22, 2020 9:20 pm
Forum: Beginner Basics
Topic: Need help setting up EoIP over IPSEC
Replies: 0
Views: 426

Need help setting up EoIP over IPSEC

Classic scenario: router A is headquarters router, and router B is branch office router. Router A has public IP and should act as a main router. Router B does not have any firewall and is under NAT (another router), so no direct access. I want router B to be connected to router A: Encrypted connecti...
by erkexzcx
Sat Nov 21, 2020 4:41 pm
Forum: General
Topic: Features in the winbox
Replies: 6
Views: 883

Re: Features in the winbox

You can cycle windows, but the shortcut is a bit strange for me:
F6
Quick google search suggested even more results: viewtopic.php?t=147994#p728955
by erkexzcx
Fri Nov 20, 2020 4:45 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: [Guide] How to setup NordVPN (IPSEC/IKEv2) + killswitch

Should I see traffic when I torch the bridge acting as blackhole for the VPN when it is going up or down? The only traffic I saw was ARP. When I re-enable my own killswitch lines (dst 100.69.69.69) then those lines in NAT do catch traffic. I see the same... Looking in /IP routing the PPPoE-out has ...
by erkexzcx
Fri Nov 20, 2020 9:42 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

Re: [Guide] How to setup NordVPN (IPSEC/IKEv2) + killswitch

That killswitch is not great. Quite dangerous in fact. Thank you for your feedback. I completely agree with you, and after testing your provided commands seems that it's working perfectly. +1 for brief explanation. I've updated commands in initial post. If someone has any better suggestions - let m...
by erkexzcx
Fri Nov 20, 2020 2:52 am
Forum: General
Topic: Nordvpn IPsec Mikrotik Routing
Replies: 15
Views: 5679

Re: Nordvpn IPsec Mikrotik Routing

I wrote a mini guide here that covers fasttrack, MSS reduction and killswitch: viewtopic.php?f=23&t=169273
by erkexzcx
Fri Nov 20, 2020 2:51 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 97
Views: 59748

NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Overview I've wasted hours making RouterOS to work perfectly with NordVPN and I wrote this guide, so you don't have to waste your time. You must have RouterOS 6. It must be minimum version of 6.45. Some steps in ROS7 will be different. Nearly identical setup is possible with Surfshark . See here . ...
by erkexzcx
Thu Nov 19, 2020 5:24 pm
Forum: General
Topic: Feature request: Run script from firewall event
Replies: 10
Views: 4891

Re: Feature request: Run script from firewall event

I would not find it useful right now, but this would open up so much possibilities. +1 from me.
make your router prone to DoS/DDoS attacks
Not true if Mikrotik adds frequency option. E.g. "Do not run script if it already has run in the past X seconds".
by erkexzcx
Tue Nov 17, 2020 1:19 pm
Forum: Beginner Basics
Topic: How do I make highly-available AP that becomes LTE router in case of internet downtime?
Replies: 5
Views: 1683

Re: How do I make highly-available AP that becomes LTE router in case of internet downtime?

Difficult to be specific without actual IP addresses. But let's assume your main router is .1 and your Chateau is .2 on the same subnet. Default gateway for your devices is .1 so your main router is the decision making point. - On Chateau, make sure it has a default route to the Internet via LTE. I...
by erkexzcx
Tue Nov 17, 2020 10:41 am
Forum: Beginner Basics
Topic: How do I make highly-available AP that becomes LTE router in case of internet downtime?
Replies: 5
Views: 1683

How do I make highly-available AP that becomes LTE router in case of internet downtime?

In the house there is a main Mikrotik router and few (Ubiquiti) wireless access points. In one room there is "Mikrotik Chateau 12" router set-up as a wireless access point. I added SIM card to that "Chateau" router and now I want to make it highly available wireless access point ...
by erkexzcx
Sat Nov 14, 2020 2:55 am
Forum: Beginner Basics
Topic: Config restore
Replies: 2
Views: 550

Re: Config restore

Looks like you have no choice - reset the router. :)

From my experience, resetting Mikrotik router does not wipe internal storage.
by erkexzcx
Sat Nov 14, 2020 2:49 am
Forum: Beginner Basics
Topic: Blacklist all but one IP? [SOLVED]
Replies: 4
Views: 982

Re: Blacklist all but one IP? [SOLVED]

If your WAN interface is ether1 and your IP is 123.123.123.123 , then it would look like this: add action=accept chain=forward out-interface=ether1 dst-address=123.123.123.123 add action=drop chain=forward out-interface=ether1 This is very basic rule. I suggest learning more about firewalls. :)
by erkexzcx
Thu Nov 12, 2020 7:32 pm
Forum: Beginner Basics
Topic: Newbie: Access to modem behind router
Replies: 26
Views: 5679

Re: Newbie: Access to modem behind router

Is this what you are trying to achieve?

LAN <--> Mikrotik router <--> Modem <--> Internet
by erkexzcx
Thu Nov 12, 2020 7:24 pm
Forum: Wireless Networking
Topic: TX Power Mikrotik Lhg Xl 5 Ac 802.11a/n/ac
Replies: 3
Views: 1197

Re: TX Power Mikrotik Lhg Xl 5 Ac 802.11a/n/ac

Did you check downloads page? https://mikrotik.com/product/lhg_xl_5_ac#fndtn-downloads There is brochure available. Also, correct me if I am wrong, but TX Power is something you should not be looking for when choosing a wireless device: https://www.draytek.co.uk/support/guides/difference-between-db-...
by erkexzcx
Thu Nov 12, 2020 7:17 pm
Forum: Beginner Basics
Topic: Port 22 / SFTP/SSH Being Blocked
Replies: 34
Views: 5190

Re: Port 22 / SFTP/SSH Being Blocked

Can you give us an example or diagram on what are you trying to achieve?
by erkexzcx
Thu Nov 12, 2020 12:02 am
Forum: Wireless Networking
Topic: Some help from you Mikrotik lovers please
Replies: 4
Views: 1514

Re: Some help from you Mikrotik lovers please

This should go into newbie section. :) Anyway, it looks like you understand networking well enough in order to start using Mikrotik on your own: 1. Get WinBox app. Works well on Mac and Linux. https://mikrotik.com/download 2. Connect to your router (either via MAC or IP - google the difference). 3. ...
by erkexzcx
Wed Nov 04, 2020 8:41 am
Forum: General
Topic: Question about TCP Established and Call of Duty disconnects [SOLVED]
Replies: 26
Views: 5523

Re: Question about TCP Established and Call of Duty disconnects [SOLVED]

I think that if you are unable to handle large amount of connections, then you need a more powerful router?

I mean you are applying workarounds, this is impacting users and here you are trying to figure out what's the problem.
by erkexzcx
Tue Nov 03, 2020 10:26 pm
Forum: Scripting
Topic: disable a rule when a provider crashes?
Replies: 2
Views: 800

Re: disable a rule when a provider crashes?

I am not sure what you are asking, but I would say "yes, it's possible".
by erkexzcx
Sat Aug 29, 2020 9:38 pm
Forum: Beginner Basics
Topic: Tunnel traffic through VPN
Replies: 20
Views: 7442

Re: Tunnel traffic through VPN

1) Is it possible to tunnel all the traffic trough a VPN provider? 2) Which VPN provider is supported by Mikrotik? 3) Are there any providers which already have filters for illegal BitTorrent websites? Or the possibility to block Bittorent at all? 4) Can I block somehow Bittorent with my Mikrotik r...
by erkexzcx
Sat Aug 29, 2020 9:32 pm
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 154568

Re: v7.1beta2 [development] is released!

Does this beta release work great with Winbox? Or is it console-only while it's beta?
by erkexzcx
Mon Jun 29, 2020 9:02 am
Forum: Beginner Basics
Topic: EoIP setup
Replies: 3
Views: 1322

Re: EoIP setup

Hi sir. would it be possible if you can give me some advice on how to go about it. Sure. EoIP instructions: https://wiki.mikrotik.com/wiki/Manual:Interface/EoIP GRE tunnel instructions: https://wiki.mikrotik.com/wiki/Manual:Interface/Gre L2TP instructions: https://wiki.mikrotik.com/wiki/Manual:Inte...
by erkexzcx
Wed Jun 24, 2020 9:20 pm
Forum: Beginner Basics
Topic: [SOLVED] Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)
Replies: 1
Views: 960

Re: Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)

Right, so instructions are unclear (I got confused) by Manual:IP/IPsec#NAT_and_Fasttrack_Bypass instructions: Solution is to use IP/Firewall/Raw to bypass connection tracking, that way eliminating need of filter rules listed above It actually means that eliminating need of Fasttrack bypass rules. Us...