Community discussions

MikroTik App

Search found 195 matches

by erkexzcx
Fri Apr 09, 2021 11:00 am
Forum: Beginner Basics
Topic: Route only internal traffic (OpenVPN)
Replies: 2
Views: 141

Re: Route only internal traffic (OpenVPN)

Maybe someone could clarify this, but if I am not mistaken IPSEC is policy-based while OpenVPN is routing-based (has it's own interface and internal IP). I think you should start by looking into "/ip route" or OpenVPN routing settings. I never set up or used OpenVPN on Mikrotik routers, so...
by erkexzcx
Thu Apr 08, 2021 6:11 pm
Forum: Beginner Basics
Topic: New to MikroTIK
Replies: 7
Views: 475

Re: New to MikroTIK

My personal opinion - here is the best learning material I've found/used https://mynetworktraining.com/ (same guy has pretty much all courses in Udemy).

I don't like reading hundreds of pages books. :) I am visual learner.
by erkexzcx
Sat Mar 27, 2021 10:03 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Hi, Try to move below rules to the top and try again. Kill NordVPN IPSEC connection, clear conntrack list and try again. add action=mark-connection chain=prerouting comment="Mark NordVPN IPSec traffic" connection-mark=!ipsec dst-address-list=!localnet,ipsec-remote new-connection-mark=NordV...
by erkexzcx
Sat Mar 27, 2021 10:40 am
Forum: General
Topic: Forward all wan traffic to another firewall
Replies: 9
Views: 666

Re: Forward all wan traffic to another firewall

Sounds like you want to create a bridge out of 2 ethernet ports - first one is WAN, second one is pfsense. Do not assign any IP for such bridge. If you don't use bridge firewall in Mikrotik, then Mikrotik will not analyze traffic at all. Your pfsense will become "main router". Correct me s...
by erkexzcx
Sun Mar 21, 2021 10:29 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

but what about multiple exceptions? Honestly I don't know. If I were you, I would just do something like this: /ip firewall mangle add action=mark-connection chain=prerouting dst-port=80,443 new-connection-mark=novpn passthrough=yes protocol=tcp /ip firewall mangle add action=mark-connection chain=...
by erkexzcx
Sun Mar 21, 2021 6:09 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Does something like this do the trick?
/ip firewall mangle add action=mark-connection chain=prerouting dst-port=!80,443 new-connection-mark=under_nordvpn passthrough=yes protocol=tcp
by erkexzcx
Sun Mar 21, 2021 1:23 am
Forum: General
Topic: Set IP public to server behind mikrotik rb4011 wihtout nat
Replies: 5
Views: 563

Re: Set IP public to server behind mikrotik rb4011 wihtout nat

Graphical scheme would be appreciated. :) I want to attribute the B1 to a server behind the rb4011 without nat Let's say you have ether1 port dedicated for WAN and ether2 dedicated for your server. Create bridge in your Mikrotik router and add eth1 and eth2 interfaces. Consider your created bridge a...
by erkexzcx
Sat Mar 20, 2021 11:40 pm
Forum: General
Topic: NordVPN multi WAN
Replies: 5
Views: 705

Re: NordVPN multi WAN

Not sure what is exactly you are asking.
by erkexzcx
Sat Mar 20, 2021 12:04 am
Forum: General
Topic: Why can't I make my hEX lite into a router?
Replies: 19
Views: 1139

Re: Why can't I make my hEX lite into a router?

Is this router meant to be this difficult to set up? I set up "a lot" of routers. To be honest, I don't really understand what's the point for Mikrotik to provide "Quick settings" in the first place. Remove all the default configuration (reset the router with "remove-defaul...
by erkexzcx
Fri Mar 19, 2021 1:57 pm
Forum: General
Topic: Mikrotik Switch Recommendation for newbie
Replies: 22
Views: 1155

Re: Mikrotik Switch Recommendation for newbie

but not really new in networking in general so to speak There is no need to ask here then :) Look at the price and at the specs in Mikrotik website and this is all you need to know. Also I am a fan of RouterOS, but that's just personal. EDIT: Even 16eur Mikrotik routers have full capabilities with ...
by erkexzcx
Thu Mar 18, 2021 8:50 pm
Forum: General
Topic: I can't connect to my NVRs [SOLVED]
Replies: 12
Views: 724

Re: I can't connect to my NVRs [SOLVED]

Did you even port-forward your NVR ports? I don't see any dstnat rules in your config.

normal dynamic public ip
You are using "/ip cloud" instead of WAN IP, right?
by erkexzcx
Tue Mar 16, 2021 11:21 pm
Forum: General
Topic: Hairpin NAT Not Working
Replies: 5
Views: 398

Re: Hairpin NAT Not Working

by erkexzcx
Sun Mar 14, 2021 1:38 pm
Forum: General
Topic: Winbox on Linux Problems
Replies: 30
Views: 11653

Re: Winbox on Linux Problems

Can anyone elaborate how UFW blocks WinBox? You mean UFW also blocks OUTPUT chain too?
by erkexzcx
Wed Mar 10, 2021 11:54 am
Forum: Scripting
Topic: Mikrotik Script connect mysql server
Replies: 3
Views: 301

Re: Mikrotik Script connect mysql server

Why not the other way around? Connecting to Mikrotik router to write/read config/data?
by erkexzcx
Tue Mar 09, 2021 9:29 am
Forum: General
Topic: Windscribe VPN on Mikrotik
Replies: 1
Views: 281

Re: Windscribe VPN on Mikrotik

I see it's IPSEC/IKE2. Try using these instructions instead, because those are kind of the same, except server, username and password: viewtopic.php?f=23&t=169273
by erkexzcx
Mon Mar 08, 2021 6:29 pm
Forum: General
Topic: Is there a shortage with some Mikrotik products ?
Replies: 3
Views: 424

Re: Is there a shortage with some Mikrotik products ?

Situation in Lithuania: Networking e-shop katalita.lt has the following: https://www.katalita.lt/info/search.html?q=hap+ac3 RBD53GR-5HacD2HnD&R11e-LTE6 - they have in stock RBD53iG-5HacD2HnD - they don't have in stock. Looking at centralized search (for lithuanian shops) there is only one result...
by erkexzcx
Wed Mar 03, 2021 4:11 pm
Forum: General
Topic: IMPROVEMENT: Allow closing Winbox windows with middle click on the title bar
Replies: 1
Views: 209

Re: IMPROVEMENT: Allow closing Winbox windows with middle click on the title bar

TIL: I can close tabs in browser with a middle mouse button. Thanks, but this is totally not needed for WinBox.
by erkexzcx
Fri Feb 26, 2021 3:03 pm
Forum: Beginner Basics
Topic: PC can not reach internet, router can.
Replies: 9
Views: 644

Re: PC can not reach internet, router can.

Show your firewall filter rules.
by erkexzcx
Fri Feb 26, 2021 2:58 pm
Forum: Beginner Basics
Topic: IKEv2 VPN
Replies: 21
Views: 1509

Re: IKEv2 VPN

I wanted to do the same. Basically you need to do majority of steps from this while having this in mind. Finally I end up with this and can't get over it (works fine on Android phone using Strongswan client, but not from Windows PC native IPSEC/IKE2).
by erkexzcx
Tue Feb 23, 2021 10:59 am
Forum: General
Topic: Loss of trafic for a few seconds every 20 minutes in a EoIP tunnel
Replies: 3
Views: 164

Re: Loss of trafic for a few seconds every 20 minutes in a EoIP tunnel

Tried disabling EoIP keepalive (in EoIP interface settings) on both sides?
by erkexzcx
Tue Feb 23, 2021 10:57 am
Forum: General
Topic: Winbox - Darkmode - For the love of God, Please. [SOLVED]
Replies: 12
Views: 1020

Re: Winbox - Darkmode - For the love of God, Please. [SOLVED]

or at least option to reverse colors of WinBox :D
by erkexzcx
Tue Feb 23, 2021 10:45 am
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 774

Re: Double NAT & no public IP for VPN [SOLVED]

I've looked at that topic too, and unless I've missed something, the responder (server) must have a public IP or port-forwarding from a public IP must be possible. So not applicable for your case. User still has to purchase VPS with public IP in order to have public IP. Linode was just an example (...
by erkexzcx
Tue Feb 23, 2021 10:36 am
Forum: General
Topic: block internet access but allow some sites - NOT WORKING
Replies: 7
Views: 444

Re: block internet access but allow some sites - NOT WORKING

Sites blocking is never going to work. At some point user will start using VPN provider and there is no way to block it (e.g. NordVPN can use 443 over TCP as well as obfuscated traffic).
by erkexzcx
Tue Feb 23, 2021 10:24 am
Forum: General
Topic: Is SWOS still in development?
Replies: 0
Views: 214

Is SWOS still in development?

Just wondering what is the state of SwitchOS of Mikrotik? The last update was from 2020, and when I purchased CRS112-8P-4S-IN it came only with ROS. No option to dual boot.
by erkexzcx
Tue Feb 23, 2021 10:18 am
Forum: Beginner Basics
Topic: EOIP over IPSEC tunnel connection is unstable
Replies: 2
Views: 269

Re: EOIP over IPSEC tunnel connection is unstable

Did you check this? viewtopic.php?f=23&t=169538 I've got it working perfectly fine.
by erkexzcx
Tue Feb 23, 2021 10:16 am
Forum: Beginner Basics
Topic: Setup VPN on a Router
Replies: 2
Views: 323

Re: Setup VPN on a Router

How about going to actual official Mikrotik wiki and using guides from there? Also users in Mikrotik forum posted few as well. e.g. I created this: https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 + https://forum.mikrotik.com/viewtopic.php?t=151188#p839793 One of the best guides online I f...
by erkexzcx
Tue Feb 23, 2021 10:12 am
Forum: Beginner Basics
Topic: help please
Replies: 10
Views: 554

Re: help please

There is something you can do:)
  • Whitelist access for your specific IPs. That's what firewalls are for, not just logging.
  • Auto add such attempts to "address-list" and drop such connections from recorded address-list in "/ip raw"
  • Disable logging and forget.
by erkexzcx
Tue Feb 23, 2021 9:59 am
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 774

Re: Double NAT & no public IP for VPN [SOLVED]

Thanks for the solution. I'm thinking about this in a whole month. And you are right Vultr is the cheapest VPS I found so far Have you tried OpenVPN Cloud? or AWS free tier + OpenVPN Just FYI - Mikrotik ROS can be installed on x86_64 hardware, and I mean virtual machine. What I am trying to say tha...
by erkexzcx
Sat Feb 13, 2021 8:33 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 5
Views: 477

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

I think Windows 10 built-in VPN client still doesn't understand sha256 when doing phase 2 and modp2048 when doing phase 1. Change or add profiles dh-group to modp1024 and proposals auth-algorithms to sha1. I haven't tested it for myself, but you should try this. It logs you can see that VPN connect...
by erkexzcx
Sat Feb 13, 2021 8:32 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 5
Views: 477

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

See my post here.
Nothing that could help me there
by erkexzcx
Sat Feb 13, 2021 3:19 pm
Forum: General
Topic: Speedtest.net - How to bypass
Replies: 10
Views: 10871

Re: Speedtest.net - How to bypass

Let's talk about NordVPN - it allows you to unblock websites & get around throttling on any crappy ISP. :) And you can't block it.

Blocking websites is not going to work.
by erkexzcx
Sat Feb 13, 2021 12:43 pm
Forum: General
Topic: Speedtest.net - How to bypass
Replies: 10
Views: 10871

Re: Speedtest.net - How to bypass

This is what I would do: 1. Use "nslookup speedtest.net" to resolve to IP address. 2. Take a single IP address and google it. Find "ipinfo.io" website in results and check it. Find "ASHandle" value and check it. In this case I've ended up with this link https://ipinfo.i...
by erkexzcx
Sat Feb 13, 2021 12:30 pm
Forum: General
Topic: Problems with IPSec - only one device can connect
Replies: 3
Views: 373

Re: Problems with IPSec - only one device can connect

I just created another thread in here. I've shared the configuration that works for me: https://forum.mikrotik.com/viewtopic.php?f=2&t=172558 On the other hand, I've written few guides there and there, so you can take a look too: https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 https:/...
by erkexzcx
Sat Feb 13, 2021 12:25 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 5
Views: 477

Windows 10 unable to connect to IPSEC/IKE2 VPN

I've setup IPSEC/IKE2 VPN server on my Mikrotik router. This is how I set it up: # Generate CA /certificate add name="My CA" common-name="My CA" key-size=4096 days-valid=3650 key-usage=key-cert-sign,crl-sign # Generate client and server certs /certificate add name="My client...
by erkexzcx
Wed Feb 10, 2021 8:50 am
Forum: Beginner Basics
Topic: NordVPN issue
Replies: 8
Views: 2630

Re: NordVPN issue

viewtopic.php?f=23&t=169273 I think Mikrotik should pin this thread so more people can see.
by erkexzcx
Sun Feb 07, 2021 4:54 pm
Forum: Useful user articles
Topic: Hairpin NAT - the easy way
Replies: 2
Views: 599

Hairpin NAT - the easy way

Decided to write a simple guide on Hairpin NAT, because quite a lot of users struggle to understand how to set it up. I am not a networking professional and I am open to any criticism on how to implement it in a better way. Official wiki page by Mikrotik regarding Hairpin NAT: https://wiki.mikrotik....
by erkexzcx
Sun Feb 07, 2021 4:16 pm
Forum: General
Topic: Firewall mess
Replies: 2
Views: 265

Re: Firewall mess

I am not sure what you are asking, but you should clean it up and rebuild as per instructions here: https://help.mikrotik.com/docs/display/ ... t+Firewall

Also use this to secure your router https://help.mikrotik.com/docs/display/ ... our+router
by erkexzcx
Sun Feb 07, 2021 3:35 pm
Forum: General
Topic: Is my IP blocked on Mikrotik servers, or is it my ISP being crap?
Replies: 1
Views: 216

Is my IP blocked on Mikrotik servers, or is it my ISP being crap?

I have a very strange issue - for some reason I am no longer able access any Mikrotik websites, such as mikrotik.com, forum.mikrotik.com and help.mikrotik.com. I am also unable to fetch any updates directly from Mikrotik routers too. All other websites are loading fine, except Mikrotik's websites. O...
by erkexzcx
Tue Feb 02, 2021 10:55 am
Forum: Beginner Basics
Topic: My last hope.
Replies: 10
Views: 815

Re: My last hope.

Perform ping test from Mikrotik to 1.1.1.1. Then perform the same from your PC. Is the result almost identical?

We can't say what's wrong, unless you share your configuration with us.
by erkexzcx
Tue Jan 26, 2021 1:28 pm
Forum: General
Topic: Slow VPN performance?
Replies: 9
Views: 768

Re: Slow VPN performance?

Your router is not mentioned here: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Hardware_acceleration So it means that you will get terrible performance. I would also suggest bypassing fasttrack (either by using "notrack" or "allowing" traffic before fastrack rule) and tuning M...
by erkexzcx
Tue Jan 26, 2021 1:25 pm
Forum: Beginner Basics
Topic: Switch chip
Replies: 9
Views: 902

Re: Switch chip

After i configured the port as a access port in the switch chip , that particular port can not access the router using by winbox.
Thanks for sharing!
by erkexzcx
Mon Jan 25, 2021 1:38 pm
Forum: General
Topic: IPSEC Forwarding
Replies: 4
Views: 385

Re: IPSEC Forwarding

What?
But what else is required in order for IPSEC to establish a tunnel between these two drayteks when my mikrotik is feeding one of them internet?
by erkexzcx
Sun Jan 24, 2021 11:47 pm
Forum: General
Topic: Buy/Subscirbe VPN GAME Amazon Web Services (AWS)
Replies: 6
Views: 461

Re: Buy/Subscirbe VPN GAME Amazon Web Services (AWS)

Do you even realise what and why you are asking?
by erkexzcx
Sun Jan 24, 2021 11:40 pm
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 774

Re: Double NAT & no public IP for VPN [SOLVED]

You can't access Mikrotik router if it's behind NAT (which is owned by ISP).

But you can open the tunnel from your Mikrotik to VPN server, especially if you have another Mikrotik router with public IP. And I mean this: viewtopic.php?f=23&t=169538
by erkexzcx
Sun Jan 24, 2021 11:36 pm
Forum: Beginner Basics
Topic: IP sec negociation error
Replies: 6
Views: 534

Re: IP sec negociation error

I am probably blind. Where does it say that it fails?

From my own experience - you should check logs on both sides. They might not say anything in one side, but will specify where is the issue on the other side.

EDIT: Your blurred IP is still readable :D
by erkexzcx
Sun Jan 24, 2021 11:34 pm
Forum: Beginner Basics
Topic: NordVPN using IKEv2 - Low speeds and not functional?
Replies: 2
Views: 264

Re: NordVPN using IKEv2 - Low speeds and not functional?

Works perfectly on ROS6: viewtopic.php?f=23&t=169273

Check if you did not forget to bypass FastTrack as well as reduce MSS size. All steps are in the given link.
by erkexzcx
Mon Jan 18, 2021 10:11 am
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 5
Views: 1204

Re: VPN/ipsec with strongSwan

So to clarify things up for everyone - Strongswan app on Android has no option to force ignore this constraint. In order to fix it, you must generate a new certificate for your VPN server, but this time with correct subject-alt-name . E.g. I am always using "/ip cloud" DNS to connect to a ...
by erkexzcx
Sun Jan 17, 2021 9:11 pm
Forum: General
Topic: VPN/ipsec with strongSwan
Replies: 5
Views: 1204

Re: VPN/ipsec with strongSwan

+1 Android strongswan client. WTF How to get rid of it.
by erkexzcx
Sat Jan 16, 2021 12:47 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Please tell me how to correctly forward the port for example for torrent in this configuration?
1. How is it related to this thread?
2. Why would you need port forward for...torrents?
by erkexzcx
Fri Jan 15, 2021 8:18 pm
Forum: RouterOS v7 BETA
Topic: Any chance to install ROS6 on Chateau 12?
Replies: 6
Views: 1035

Any chance to install ROS6 on Chateau 12?

Any chance to get ROS6 working on Chateau 12 router? I know this router is ROS7 only. But let's be honest - this is a bit too aggressive approach from Mikrotik to force users to use beta software in order to get it more tested and more bugs fixed in the long run. Because of some bugs that affects co...
by erkexzcx
Wed Jan 06, 2021 6:24 pm
Forum: General
Topic: Feature request for mobile app. bandwidth limiter set
Replies: 3
Views: 276

Re: Feature request for mobile app. bandwidth limiter set

Wait until they figure out how to change MAC address. Seems they should not worry about VPNs in this case:)

Can you be more specific on what is missing in Mikrotik routers? You want to enable/disable internet access, throttle bandwidth or block certain websites?
by erkexzcx
Wed Jan 06, 2021 9:33 am
Forum: Beginner Basics
Topic: FIFA 21 loosing connection during game play
Replies: 4
Views: 702

Re: FIFA 21 loosing connection during game play

Try changing DHCP server's lease time from default 10min to something 1d or even 7 days.

This was the only fix for crappy company's laptop where pulsesecure VPN app was resetting every 10 minutes and causing very high CPU usage and mostly making laptop impossible to use. Maybe this is related. :)
by erkexzcx
Tue Jan 05, 2021 12:35 am
Forum: General
Topic: Isolate two bridges at Layer 2 [SOLVED]
Replies: 7
Views: 549

Re: Isolate two bridges at Layer 2 [SOLVED]

Correct regarding bridges - they are like separate interfaces. They have nothing common between them so no L2 routing between them is possible if you did not setup any exotic configurations. Instead you should probably use this: add action=drop chain=forward in-interface=bridge1 out-interface=bridge...
by erkexzcx
Mon Jan 04, 2021 11:49 am
Forum: General
Topic: WPA3 on existing Mikrotik routers/APs [SOLVED]
Replies: 23
Views: 20840

Re: WPA3 on existing Mikrotik routers/APs [SOLVED]

Talking about WPA3 security: https://arstechnica.com/information-technology/2019/04/serious-flaws-leave-wpa3-vulnerable-to-hacks-that-steal-wi-fi-passwords/ As long as clients are in transitional mode, they will connect to the WPA2-only access point. As soon as that happens, attackers have the four-...
by erkexzcx
Mon Jan 04, 2021 11:42 am
Forum: Beginner Basics
Topic: Server is not accessable through mikrotik router
Replies: 3
Views: 350

Re: Server is not accessable through mikrotik router

What is not working is I cant access my server ip 192.168.1.10 internally but server have internet.
what?
by erkexzcx
Mon Jan 04, 2021 11:39 am
Forum: RouterOS v7 BETA
Topic: Chateau LTE12 stop work
Replies: 2
Views: 838

Re: Chateau LTE12 stop work

Sometimes hardware fails. What about lights on router?
by erkexzcx
Thu Dec 31, 2020 10:18 am
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 711

Re: L2TP/IPsec Android Second phase problem

Sorry to answer so rarely, but I can only answer in the evenings. Not everyone has all day to spend on this forum :D I can't tell what is wrong from the logs. Unless someone else has anything to add, I would say - Android's native VPN is "faulty". I've had a colleague who was having simil...
by erkexzcx
Wed Dec 30, 2020 9:33 pm
Forum: Beginner Basics
Topic: Approximately 5s delay in TCP connections when using a static route via an address on bridge [SOLVED]
Replies: 5
Views: 631

Re: Approximately 5s delay in TCP connections when using a static route [SOLVED]

Seems your target destination (of your static route) is part of existing bridge. I once had similar issue and all was fixed when I enabled bridge firewall:

/interface bridge settings set use-ip-firewall=yes

It just fixed it for me. Maybe someone has better ways to fix this kind of issue.
by erkexzcx
Wed Dec 30, 2020 9:30 pm
Forum: Beginner Basics
Topic: Chateau LTE12: mtu info
Replies: 2
Views: 251

Re: Chateau LTE12: mtu info

What does field "Actual MTU" shows for lte1 interface? What would happen if you set MTU to 1550 for lte1?
by erkexzcx
Wed Dec 30, 2020 9:27 pm
Forum: Beginner Basics
Topic: OpenVPN weird behavior since changing to Microtik?
Replies: 1
Views: 230

Re: OpenVPN weird behavior since changing to Microtik?

How is Mikrotik related here?
by erkexzcx
Wed Dec 30, 2020 4:18 pm
Forum: General
Topic: Device on other side of EoIP are not being NATed to the Internet
Replies: 11
Views: 648

Re: Device on other side of EoIP are not being NATed to the Internet

I want device in REMOTE to be on the same subnet as those in CENTRAL. I also want the device from REMOTE to go through CENTRAL to access the internet, so the last NAT is done at CENTRAL. Correct me if I am wrong, but all you want is to add EoIP interface to a LAN bridge on each router, mark it as &...
by erkexzcx
Wed Dec 30, 2020 4:05 pm
Forum: RouterOS v7 BETA
Topic: hAP ac2 back from 7.1b3 failed [SOLVED]
Replies: 2
Views: 1630

Re: hAP ac2 back from 7.1b3 failed [SOLVED]

On the positive side, everyone who purchased Chateau12 is stuck with ROS7 only. To be honest, for home or small office, ROS7 is perfectly fine.

Netinstall should still work tho.
by erkexzcx
Wed Dec 30, 2020 1:08 pm
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 711

Re: L2TP/IPsec Android Second phase problem

I suspect your Android device and Mikrotik does not have overlapping ciphers. Anyway, enable "ipsec" logging in Mikrotik settings. Then try to connect using Android phone to VPN on Mikrotik router. Provide us logs. You should be able to see additional tag "debug" next to "ip...
by erkexzcx
Wed Dec 30, 2020 1:05 pm
Forum: General
Topic: IPsec dynamic IP address
Replies: 3
Views: 490

Re: IPsec dynamic IP address

You should learn how to write your questions in a more organized way. Code formatting is also a thing (useful for displaying a logs). If you want different policies for specific clients, then you should properly setup remote-id matching as well as specific mode configs and policies. I've done simila...
by erkexzcx
Tue Dec 29, 2020 2:54 pm
Forum: General
Topic: L2TP/IPsec Android Second phase problem
Replies: 7
Views: 711

Re: L2TP/IPsec Android Second phase problem

Did you check threads like this? viewtopic.php?t=153546
by erkexzcx
Tue Dec 29, 2020 1:45 pm
Forum: Beginner Basics
Topic: Router was rebooted without proper shutdown [SOLVED]
Replies: 2
Views: 405

Re: Router was rebooted without proper shutdown [SOLVED]

Looks like either RouterOS crashed and rebooted (not sure if router reboots in this case, probably due to watchdog), or there was power issues. Maybe PSU is having issues, or your power supply had issues. I closed all the IP services except Winbox Did you whitelist access to router? Hopefully winbox...
by erkexzcx
Tue Dec 29, 2020 12:02 pm
Forum: Beginner Basics
Topic: Looking for a Product (Router)
Replies: 5
Views: 427

Re: Looking for a Product (Router)

A bit hard to recommend. 5G is not supported by Mikrotik, so LTE is the only option. Also Mikrotik support for OpenVPN is kind of "meh" (OpenVPN UDP is only supported in ROS7 which is beta, only TCP mode in ROS6). Would highly recommend sticking to L2TP/IPSEC or IPSEC/IKE2 instead. If you ...
by erkexzcx
Tue Dec 29, 2020 11:47 am
Forum: General
Topic: Can't get Policy based routing VPN to work
Replies: 7
Views: 639

Re: Can't get Policy based routing VPN to work

Does your VPN provider support IPSEC/IKE2? If so, you can configure using this guide: viewtopic.php?f=23&t=169273

I haven't got a chance to play much with PPTP and not sure if I ever will because this protocol is very unsafe.
by erkexzcx
Mon Dec 28, 2020 4:08 pm
Forum: General
Topic: ikev2 2 sessions under one certificate [SOLVED]
Replies: 2
Views: 369

Re: ikev2 2 sessions under one certificate [SOLVED]

Using same certificate might work..? If you ignore remote-id if I am not mistaken. Then VPN server cannot identity any of your client who is who, so just assigns random IP from the pool. Anyway, it's better to generate a separate certificate for each client and select "match-by=certificate"...
by erkexzcx
Mon Dec 28, 2020 4:02 pm
Forum: General
Topic: Can't get Policy based routing VPN to work
Replies: 7
Views: 639

Re: Can't get Policy based routing VPN to work

Few ideas on what's wrong: Netflix detects when you are running through VPN server. It detects when you are using non-residential IP. Netflix has more domains. Not just "netflix.net". You need to route all such traffic using VPN. Not sure, but I think "content" parameter in Mikro...
by erkexzcx
Mon Dec 28, 2020 3:13 pm
Forum: General
Topic: VPN for Mikrotik for game Mobile legend
Replies: 8
Views: 840

Re: VPN for Mikrotik for game Mobile legend

Not sure if you know anything about networking.

Just get a VPN subscription from a VPN provider, like NordVPN. See if it fixes the issue.
by erkexzcx
Mon Dec 28, 2020 2:56 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta3 [development] is released!
Replies: 262
Views: 44888

Re: v7.1beta3 [development] is released!

ipip tunnel still not working wihout disable keepalive When I wrote https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 I was using ROS7 as a VPN client to ROS6 VPN server. EoIP did work, but was silently flapping leading to random disconnects from online multiplayer games. Disabling keepali...
by erkexzcx
Sun Dec 27, 2020 10:25 pm
Forum: RouterOS v7 BETA
Topic: New Feature Request: run script after Wireguard connection status changed. [SOLVED]
Replies: 3
Views: 839

Re: New Feature Request: run script after Wireguard connection status changed. [SOLVED]

Can you use netwatch as a workaround for this (using any internal IP of wireguard)?
by erkexzcx
Sun Dec 27, 2020 5:33 pm
Forum: Beginner Basics
Topic: Questions about "Use host names in firewall rules" [SOLVED]
Replies: 3
Views: 499

Re: Questions about "Use host names in firewall rules" [SOLVED]

This router is so good, I'm really glad I bought it despite of my initial concerns.
Kinda the same here. Thanks to my previous job I had to deal with Mikrotik routers. They significantly boosted my understanding of networking. :)
by erkexzcx
Sun Dec 27, 2020 5:30 pm
Forum: Beginner Basics
Topic: Generate paket lost on specific destination ! [SOLVED]
Replies: 3
Views: 411

Re: Generate paket lost on specific destination ! [SOLVED]

Drops every 2nd packet when user pings to 95.217.228.176:
/ip firewall filter add action=drop chain=forward dst-address=95.217.228.176 nth=2,1
by erkexzcx
Sun Dec 27, 2020 5:20 pm
Forum: General
Topic: IPSEC IKEv2 network-to-network problems
Replies: 11
Views: 867

Re: IPSEC IKEv2 network-to-network problems

Not what you are asking, but it might give you some hints: viewtopic.php?f=23&t=169538
by erkexzcx
Sun Dec 27, 2020 5:15 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Thanks for all the input! I've updated instructions accordingly.
by erkexzcx
Sun Dec 27, 2020 12:48 am
Forum: General
Topic: Mikrotik device behind limited ISP modem
Replies: 15
Views: 1211

Re: Mikrotik device behind limited ISP modem

This sounds like a Telia router in Lithuania, isn't it?
by erkexzcx
Sun Dec 27, 2020 12:46 am
Forum: General
Topic: Please finish implementation of OpenVPN protocol (authentication without password, certificates)
Replies: 5
Views: 512

Re: Please finish implementation of OpenVPN protocol (authentication without password, certificates)

I would say the opposite - better focus on other, more imporant things and release a stable ROS7. OpenVPN should start to die. It's one of the slowest VPN protocols. Instead, pick L2TP/IPSEC, IPSEC/IKE2 or Wireguard as an alternative as these are industry standard VPN protocols. OpenVPN has insanely...
by erkexzcx
Sat Dec 26, 2020 6:13 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

@msatter - thanks for your input. I don't actually see it as a improvement to my given guide. I mean it does work, but using simple a mangle rule is a more dynamic way of dealing with VPN traffic. e.g. in address-list I gave domain which is being resolved by Mikrotik router. If it's updated, then it...
by erkexzcx
Thu Dec 24, 2020 8:48 pm
Forum: Beginner Basics
Topic: Changing internet provider
Replies: 3
Views: 430

Re: Changing internet provider

No, it does not depend...

You need to configure your router the same way you configured previously for your current ISP.
by erkexzcx
Thu Dec 24, 2020 8:43 pm
Forum: General
Topic: proton vpn seems not fully functional
Replies: 2
Views: 376

Re: proton vpn seems not fully functional

Try following this guide: viewtopic.php?f=23&t=169273

EDIT: You may need to reduce MSS size and exclude such traffic from fasttrack. Everything is mentioned in the above guide.
by erkexzcx
Thu Dec 24, 2020 12:55 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

With use case #2, how to killswitch websites like youtube.com that with multiple IP address? You can't, because: Note: You can't effectively route all the traffic of Youtube, Netflix or any other big websites through VPN. They have many different domains and IP addresses which constantly change. In...
by erkexzcx
Thu Dec 24, 2020 1:47 am
Forum: Scripting
Topic: hairpin with 2 WAN
Replies: 2
Views: 479

Re: hairpin with 2 WAN

How about this? # Add both WAN interfaces to interfaces list. /interface list add name=WAN /interface list member add interface=ether1 list=WAN /interface list member add interface=ether2 list=WAN # Add this script to your Mikrotik router. /system script add name=dhcp_client_script source=":if ...
by erkexzcx
Wed Dec 23, 2020 9:54 am
Forum: Beginner Basics
Topic: Regarding Aggressive mode ipsec not working for peer (0.0.0.0/0) on ros above 6.43.13
Replies: 2
Views: 274

Re: Regarding Aggressive mode ipsec not working for peer (0.0.0.0/0) on ros above 6.43.13

if you enable "ipsec" debug logging in both Mikrotik and OpenWRT, what does the log says?
by erkexzcx
Wed Dec 23, 2020 1:18 am
Forum: General
Topic: Surfshark IKEv2 VPN
Replies: 13
Views: 6516

Re: Surfshark IKEv2 VPN

by erkexzcx
Wed Dec 23, 2020 1:13 am
Forum: General
Topic: Add Christmas lights to Chateau 12 router
Replies: 2
Views: 345

Re: Add Christmas lights to Chateau 12 router

Post a movie
Done. I've updated initial comment.
by erkexzcx
Wed Dec 23, 2020 12:52 am
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that
Replies: 7
Views: 2083

Re: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

1. on both Router A and Router B, you have a NAT rule, like below, why we need this rule: /ip firewall nat add action=src-nat chain=srcnat dst-address=10.22.22.2 to-addresses=10.22.22.1 place-before=0 Ping to internal IP (10.22.22.2) from Router A did not work without this rule, so I added it. 2. I...
by erkexzcx
Wed Dec 23, 2020 12:23 am
Forum: General
Topic: Add Christmas lights to Chateau 12 router
Replies: 2
Views: 345

Add Christmas lights to Chateau 12 router

Since this router does not have beeper and you can't play songs on it, but it does have controllable LEDs, so you can give it some Christmas vibes. Video: https://i.imgur.com/8380H4K.mp4 ( imgur post ). WARNING - High amount of sector writes. It will eventually kill your flash storage with the time....
by erkexzcx
Tue Dec 22, 2020 11:40 pm
Forum: RouterOS v7 BETA
Topic: Chateau Config Backup & Restore
Replies: 14
Views: 1420

Re: Chateau Config Backup & Restore

Backup & Restore always sucked for me. Always use export & restore. Most of the config appears to take except there's no DHCP server set and the network settings appear to be missing I would say remove such lines from the exported config try again? Then connect using MAC address. /tool bandw...
by erkexzcx
Tue Dec 22, 2020 2:35 pm
Forum: Beginner Basics
Topic: Problems with portforwarding.
Replies: 9
Views: 773

Re: Problems with portforwarding.

Sob he already had the default rule in place........ (but I much prefer the cleaner rule you suggested) add action=drop chain=forward comment="Drop incoming packets that are not NATted" connection-nat-state=!dstnat connection-state=new in-interface=ether1 log=yes log-prefix=!NAT Why would...
by erkexzcx
Sun Dec 20, 2020 12:52 pm
Forum: General
Topic: Equivalent Mikrotik IPSEC settings for this Linux config
Replies: 7
Views: 747

Re: Equivalent Mikrotik IPSEC settings for this Linux config

Before someone helps you, i will give you some hints on where to look at. I've written few guidelines here and here on how to connect Mikrotik router using IPSEC/IKEv2. You have have an idea how configuration looks like and what steps you should take (e.g. exclude from fasttrack, add NAT, optionally...
by erkexzcx
Wed Dec 16, 2020 8:09 pm
Forum: General
Topic: Question about VPN, pools and subnets [SOLVED]
Replies: 11
Views: 769

Re: Question about VPN, pools and subnets [SOLVED]

Aren't traffic, which is coming from the VPN clients, picked by these rules? Technically, connections are coming from WAN interfaces. /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=WAN /ip firewall filter add action=drop ch...
by erkexzcx
Wed Dec 16, 2020 7:56 pm
Forum: General
Topic: Password Questions
Replies: 3
Views: 372

Re: Password Questions

if anyone can shed some light or some thoughts on this that would be great. Either you enterred incorrect username/password, or someone has changed username/password which means someone else managed to access Mikrotik device. Instead of creating a new account, put a stronger password for "admi...
by erkexzcx
Wed Dec 16, 2020 7:50 pm
Forum: General
Topic: Remote Access VPN + Site to Site VPN
Replies: 4
Views: 484

Re: Remote Access VPN + Site to Site VPN

Is it possible that user when connects with remote access VPN to access network resources on remote site?
Yes
by erkexzcx
Wed Dec 16, 2020 4:02 pm
Forum: General
Topic: IPsec policy status Invalid [SOLVED]
Replies: 4
Views: 467

Re: IPsec policy status Invalid [SOLVED]

by erkexzcx
Tue Dec 15, 2020 6:32 pm
Forum: Beginner Basics
Topic: VPN config - stopped working.
Replies: 2
Views: 309

Re: VPN config - stopped working.

They have many servers, some of them gets DDOS'ed, some of them get's reconfigured or decommissioned. You likely need to switch to any other server. I've written more complete guide for NordVPN because some steps were missing in official guides: https://forum.mikrotik.com/viewtopic.php?f=23&t=16...
by erkexzcx
Tue Dec 15, 2020 6:29 pm
Forum: Beginner Basics
Topic: bridge got 2 dhcp addrs & mac
Replies: 2
Views: 313

Re: bridge got 2 dhcp addrs & mac

So what is the question?
by erkexzcx
Tue Dec 15, 2020 9:59 am
Forum: Beginner Basics
Topic: setting up router with two AP
Replies: 7
Views: 515

Re: setting up router with two AP

but will the wireless device automatically switch to the strongest signal?
+1 also interested.
by erkexzcx
Sat Dec 12, 2020 9:21 pm
Forum: General
Topic: VPN IKEv2 Client Problem
Replies: 3
Views: 510

Re: VPN IKEv2 Client Problem

Try following this instead: viewtopic.php?f=23&t=169273
by erkexzcx
Wed Dec 09, 2020 8:07 pm
Forum: Beginner Basics
Topic: HAP Ac3 5 Ghz speed problem
Replies: 6
Views: 772

Re: HAP Ac3 5 Ghz speed problem

Version is latest on both devices. There are RouterOS 7 beta, and RouterOS 6 stable... Anyway, I assume you are using ROS6. What would be the correct way to transfer all configuration This way: # 1. Export configuration from old router: /export file=myfile # 2. Download myfile.rsc to your computer....
by erkexzcx
Wed Dec 09, 2020 7:56 pm
Forum: Useful user articles
Topic: Howto wanted - block advertisement like Youtube
Replies: 5
Views: 1243

Re: Howto wanted - block advertisement like Youtube

I am still wondering given all the options of the OS why this should be so hard to do. I am trying to be helpful, but you clearly did not do enough research on your own. This is very wide topic on the internet, especially on the pi-hole forums. See https://discourse.pi-hole.net/t/how-do-i-block-ads...
by erkexzcx
Wed Dec 09, 2020 7:43 pm
Forum: Beginner Basics
Topic: HAP Ac3 5 Ghz speed problem
Replies: 6
Views: 772

Re: HAP Ac3 5 Ghz speed problem

I transferred all the settings that was on Ac2 5 ghz wifi to Ac3 5 ghz wifi but this thing simply don't work ok Just a question: How did you transfer those settings and what RouterOS version you are using? Did you transfer configuration by a backup or export? I've had issues with backup&restore...
by erkexzcx
Wed Dec 09, 2020 7:39 pm
Forum: Beginner Basics
Topic: LetsEncrypt for the Hotspot?
Replies: 3
Views: 407

Re: LetsEncrypt for the Hotspot?

Have you tried this? https://www.google.com/search?q=hotspot+ssl

There are tutorials from non-mikrotik sites as well as mikrotik wiki pages.
by erkexzcx
Wed Dec 09, 2020 7:32 pm
Forum: General
Topic: DNS over HTTPS, round robin support
Replies: 19
Views: 1435

Re: DNS over HTTPS, round robin support

Stupid question, but how does router know to which IP address to resolve cloudflare-dns.com domain, if you use only DoH?
by erkexzcx
Wed Dec 09, 2020 1:29 pm
Forum: Beginner Basics
Topic: access pfsense router behind mikrotik
Replies: 4
Views: 437

Re: access pfsense router behind mikrotik

Allow access to 172.18.0.1 in Mikrotik firewall from your LAN. This means you need to edit existing firewall rules. Add DST-NAT rule in Mikrotik so when reaching 172.18.0.1 your src-ip is rewritten to 172.18.0.3. Also your configuration is questionable in overall, but above solution should work.
by erkexzcx
Wed Dec 09, 2020 11:58 am
Forum: Useful user articles
Topic: Howto wanted - block advertisement like Youtube
Replies: 5
Views: 1243

Re: Howto wanted - block advertisement like Youtube

How would I do this best and with as simple as possible a solution?

Buy Youtube premium.

What you are asking is not possible and totally unrelated to Mikrotik.
by erkexzcx
Wed Dec 09, 2020 12:09 am
Forum: General
Topic: clients->ipsec router no internet [SOLVED]
Replies: 3
Views: 386

Re: clients->ipsec router no internet [SOLVED]

Aren't you supposed to specify out interface for it?
/ip firewall nat
...
add action=masquerade chain=srcnat
by erkexzcx
Tue Dec 08, 2020 12:55 am
Forum: Beginner Basics
Topic: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?
Replies: 5
Views: 571

Re: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?

Could it be related to software installed on the PC (virtualization systems, etc.)?

How each virtual machine gets IP addresses? From the router?
by erkexzcx
Tue Dec 08, 2020 12:38 am
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that
Replies: 7
Views: 2083

Re: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

According to your issue(s) description - you are not having any issues.
by erkexzcx
Mon Dec 07, 2020 1:49 am
Forum: Beginner Basics
Topic: OVPN Client not connected
Replies: 2
Views: 378

Re: OVPN Client not connected

How did you import certificates? Do you have CA? Did Mikrotik import private key? Double check:
/certificate print
by erkexzcx
Mon Dec 07, 2020 1:41 am
Forum: General
Topic: Ipsec dh group modp 1024 android no suitable proposal found
Replies: 2
Views: 360

Re: Ipsec dh group modp 1024 android no suitable proposal found

Enable ipsec logging and show full log when attempting to connect from smartphone:
/system logging add topics=ipsec action=memory
by erkexzcx
Sun Dec 06, 2020 1:26 pm
Forum: Scripting
Topic: Telegram
Replies: 6
Views: 1161

Re: Telegram

Answer is: No I did not manage to send directly from Mikrotik, because "fetch" tool does not support sending files. I managed to send using Raspberry Pi: Generate SSH keys on raspberry Pi and its upload public key to each router. Then pretty much use this bash script: #!/bin/bash ROUTER=$1...
by erkexzcx
Sun Dec 06, 2020 1:10 pm
Forum: Beginner Basics
Topic: travel router
Replies: 14
Views: 1490

Re: travel router

Your device is fine. It will work. Since you want encrypted tunnel to your home, I would suggest picking a router with IPSEC hardware acceleration, something like HAP AC2 would be great because it's cheap and supports both 5ghz/2.4ghz wifi. Everything else that you mentioned is possible. Even if you...
by erkexzcx
Sun Dec 06, 2020 1:01 pm
Forum: General
Topic: IPSec tunnel from mikrotik behind NAT with Cisco
Replies: 4
Views: 526

Re: IPSec tunnel from mikrotik behind NAT with Cisco

Since you've tried already (I assume), which part do you think is failing/not working?

When I started learning about IPSEC the only way to move forward was to enable ipsec logs in both Mikrotik routers and see what is actually failing or happening.

Can you show us some logs/configuration exports?
by erkexzcx
Sat Dec 05, 2020 7:50 pm
Forum: Beginner Basics
Topic: Vpn Site To Site With Vlan
Replies: 8
Views: 743

Re: Vpn Site To Site With Vlan

So how can I do to make the two microtiks communicate directly without NAT.
I need to connect the two VLANs as well.
There's a way?
I've done this. In both ends EoIP interface is added to main LAN bridges and basically LANs are connected.
by erkexzcx
Sat Dec 05, 2020 3:57 pm
Forum: General
Topic: IPSec tunnel from mikrotik behind NAT with Cisco
Replies: 4
Views: 526

Re: IPSec tunnel from mikrotik behind NAT with Cisco

Maybe this could help? Not really what you are asking, but you might get some hints.
by erkexzcx
Sat Dec 05, 2020 3:55 pm
Forum: General
Topic: PWR-LINE PRO
Replies: 15
Views: 2666

Re: PWR-LINE PRO

Sorry for hijacking thread, but for those who use PWR-LINE PRO - do you get additional latency? I've never used EoP devices before.

I've heard stories that when using such devices you might get somewhat 30ms latency, even tho internet connectivity is rock stable. Just want to hear if it's true.
by erkexzcx
Sat Dec 05, 2020 3:25 pm
Forum: Beginner Basics
Topic: How to block an IP range? [SOLVED]
Replies: 4
Views: 445

Re: How to block an IP range? [SOLVED]

Should I want to reverse this, what would be the code? You should not copy/paste code given by the stranger to your Mikrotik router and expect it to work. This means you should understand what those commands do and how to undo them. Hopefully you are using Winbox. WebFix is also an option, but I fi...
by erkexzcx
Sat Dec 05, 2020 3:01 pm
Forum: Beginner Basics
Topic: Issues with Mikrotik hAP AC2
Replies: 17
Views: 1627

Re: Issues with Mikrotik hAP AC2

I would also like to add that Mikrotik is not that messy. Obviously not perfect, but it isn't that buggy as users say. Pretty much sums up to this: Users: I want to do something with Mikrotik that I barely understand. Also users: Mikrotik is buggy I mean you are dealing with enterprise-grade equipme...
by erkexzcx
Fri Dec 04, 2020 8:45 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1199

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

I confirm that beta3 fixes this issue.
by erkexzcx
Thu Dec 03, 2020 9:08 pm
Forum: Beginner Basics
Topic: PCQ queue is better than without any queue?
Replies: 5
Views: 497

Re: PCQ queue is better than without any queue?

+1 interested in more information about it. From my understanding, queues are great when there is constantly not enough bandwidth for everyone, so someone always has to wait for other users to finish transmitting data. Queues would help because everyone will get fair amount of time to transmit data,...
by erkexzcx
Thu Dec 03, 2020 6:40 pm
Forum: General
Topic: Peplink to mikrotik VPN
Replies: 4
Views: 392

Re: Peplink to mikrotik VPN

https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP

Either ask something more specific, or that's all we could help.
by erkexzcx
Wed Dec 02, 2020 9:56 pm
Forum: Beginner Basics
Topic: RouterBOARD Emulator?
Replies: 2
Views: 546

Re: RouterBOARD Emulator?

Yes, they are called virtual machines and CHR images.

There are some other options as well.

Hopefully your router has already arrived. :)
by erkexzcx
Wed Dec 02, 2020 9:51 pm
Forum: Beginner Basics
Topic: How to block an IP range? [SOLVED]
Replies: 4
Views: 445

Re: How to block an IP range? [SOLVED]

First, you need to realise the networks you specified. The range "157.175.0.0-157.175.255.255" is the same as network "157.175.0.0/16". On the other hand, Mikrotik does support ranges (just do not use spaces). Make address list out of them: /ip firewall address-list add address=1...
by erkexzcx
Wed Dec 02, 2020 9:21 pm
Forum: Beginner Basics
Topic: Pivpn wireguard portforwarding problem [SOLVED]
Replies: 3
Views: 551

Re: Pivpn wireguard portforwarding problem [SOLVED]

Please use this for code. Helps if you want to receive help faster: [code] my code goes here [//code] I have few questions: Why would you need Mikrotik router for your setup in the first place? You are using modem, which means you don't have public IP (aka "direct access"), right? Why is y...
by erkexzcx
Wed Dec 02, 2020 9:08 pm
Forum: Beginner Basics
Topic: L2PT server won't work - Local clients won't connect
Replies: 4
Views: 450

Re: L2PT server won't work - Local clients won't connect

I am not sure if you show all available logs, or you just did not enable logging. Enable more logging using below command and share wider log:
/system logging add topics=ipsec,l2tp
by erkexzcx
Wed Dec 02, 2020 8:52 pm
Forum: Beginner Basics
Topic: Suggestions for new network
Replies: 2
Views: 272

Re: Suggestions for new network

Looks like you are trying to do something called "Security over obscurity". I am not sure what VPN you are using, but looks like you can do this (see 2nd use case). Set static IPs for your TVs, then add connection mark for your TVs traffic which is found by their their static source IP. Th...
by erkexzcx
Wed Dec 02, 2020 8:40 pm
Forum: Beginner Basics
Topic: 4011 affecting outbound services
Replies: 45
Views: 2879

Re: 4011 affecting outbound services

Maybe totally unrelated, don't by mad at me, but once I had to setup another router on my LAN which would act as a gateway. Then I setup static route in my main Mikrotik router, so if device is accessing <some_network>, route through that gateway on the LAN. Else - route as usual to the WAN. Turned ...
by erkexzcx
Wed Dec 02, 2020 8:30 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1199

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

erkexzcx: At home I have "Mikrotik RB4011iGS+RM" router and Netgear R7800 with OpenWRT acting as access point only. This setup is rock stable . Now I have "Mikrotik RB4011iGS+RM" working as router and "Mikrotik Chateau 12" as access point only. And this setup is causin...
by erkexzcx
Sun Nov 29, 2020 12:29 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1199

Re: Chateau 12 - WiFi no longer connects for a random device [SOLVED]

Disabling and re-enabling Wireless interface temporarily fixes the issue...
by erkexzcx
Sun Nov 29, 2020 11:22 am
Forum: General
Topic: 2 locations IPSEC, internet acces via tunnel
Replies: 5
Views: 709

Re: 2 locations IPSEC, internet acces via tunnel

I just can't miss opportunity to share my written guide :D https://forum.mikrotik.com/viewtopic.php?f=23&t=169538 EDIT : See the bottom of that post. Basically you need to disable DHCP server in parents router, add estalbished EoIP interface to main LAN bridges in both your home and parents rout...
by erkexzcx
Sat Nov 28, 2020 6:44 pm
Forum: RouterOS v7 BETA
Topic: Chateau LTE12, Router OS v7.1beta2, packet loss
Replies: 6
Views: 1045

Re: Chateau LTE12, Router OS v7.1beta2, packet loss

Let's make problem's description simple - you are getting packet loss only when you ping anything on the internet via LTE interface?
by erkexzcx
Sat Nov 28, 2020 5:54 pm
Forum: RouterOS v7 BETA
Topic: Chateau 12 - WiFi no longer connects for a random device [SOLVED]
Replies: 10
Views: 1199

Chateau 12 - WiFi no longer connects for a random device [SOLVED]

Description I have Chateau 12 Mikrotik router with latest ROS 7.1 beta2, which I am using as access point. I setup 2 WiFis - one for 2.4Ghz and the other one for 5Ghz. Since I have no point to use 2.4Ghz for now, I only use 5Ghz WiFi only. I don't know if this issue happens with 2.4Ghz. Main router...
by erkexzcx
Sat Nov 28, 2020 12:32 am
Forum: Beginner Basics
Topic: Using DHCP "Active Host Name" for local IP resolution
Replies: 3
Views: 1026

Re: Using DHCP "Active Host Name" for local IP resolution

More or less you are looking at DNS server functionality. It's called "resursive DNS server" and that's what clients are using when they are getting resolutions from Mikrotik router. I am not sure if this is possible with Mikrotik directly, but you can set static entries in ip>dhcp server>...
by erkexzcx
Fri Nov 27, 2020 9:08 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 26
Views: 1514

Re: Ipsec not traffic passing

Not Working!
So what logs say? Enable ipsec logging and show the logs. What is happening in overall?
by erkexzcx
Fri Nov 27, 2020 7:36 pm
Forum: Beginner Basics
Topic: Understanding the Firewall rules. [SOLVED]
Replies: 3
Views: 489

Re: Understanding the Firewall rules. [SOLVED]

The rules you see in Mikrotik are kinda the same as you would see in Linux servers. E.g. https://github.com/trimstray/iptables-essentials https://gist.github.com/Tristor/ed0f6867d2b0fa4c1f80300af6e0e12e#file-iptables-sh It might help if you need additional resources regarding firewalls in Linux syst...
by erkexzcx
Fri Nov 27, 2020 6:49 pm
Forum: General
Topic: Transparent IP Mode
Replies: 2
Views: 336

Re: Transparent IP Mode

Isn't that the same as:
  1. Bridging 2 interfaces
  2. Giving IP address to the bridge
  3. Enabling bridge firewall (in bridge settings) and setting up such bridge firewall rules?
by erkexzcx
Fri Nov 27, 2020 4:36 pm
Forum: Announcements
Topic: v6.47.8 [stable] is released!
Replies: 56
Views: 13749

Re: v6.47.8 [stable] is released!

RBD52G-5HacD2HnD (HAP AC2) does not even show "health" option under "System" in Winbox. This is what happens when I check from CLI: [admin@name] > /system health print [admin@name] > But it works on RB4011iGS+: [admin@surname] > /system health print voltage: 23.5V temperature: 36...
by erkexzcx
Fri Nov 27, 2020 4:27 pm
Forum: General
Topic: Very frequent cloud.mikrotik.com activity [SOLVED]
Replies: 4
Views: 512

Re: Very frequent cloud.mikrotik.com activity [SOLVED]

https://wiki.mikrotik.com/wiki/Manual:IP/Cloud DDNS or Dynamic DNS is a service that updates the IPv4 address for A records and the IPv6 address for AAAA records periodically. Such a service is very useful when your ISP has provided a dynamic IP address that changes periodically, but you always need...
by erkexzcx
Fri Nov 27, 2020 4:22 pm
Forum: General
Topic: VPN solution for small office issues
Replies: 10
Views: 856

Re: VPN solution for small office issues

I've checked all your configuration once again and not sure what could it be. It's the worst type of incidents when they happen randomly... For now I suggest providing logs from client/server regarding IPSEC/L2TP. I have a feeling that it might happen when lifetime expires in "/ip ipsec profile...
by erkexzcx
Fri Nov 27, 2020 3:38 pm
Forum: General
Topic: IPsec to Fortigate
Replies: 1
Views: 220

Re: IPsec to Fortigate

For a person which is new to IPSEC or even new to VPNs it's near impossible to get it right at first several tries. I've jumped into similar thing when I was asked to connect Mikrotik router to strongswan VPN server and it was nightmare. I have no experience with Fortigate, but since you are doing s...
by erkexzcx
Fri Nov 27, 2020 3:27 pm
Forum: General
Topic: VPN solution for small office issues
Replies: 10
Views: 856

Re: VPN solution for small office issues

Can this be related? viewtopic.php?t=132823

Mikrotik support commented that instead of dealing with all that mess one should switch to IPSEC/IKE2.
by erkexzcx
Fri Nov 27, 2020 3:19 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 26
Views: 1514

Re: Ipsec not traffic passing

Try again. At least you are missing NAT rule.
by erkexzcx
Fri Nov 27, 2020 3:03 pm
Forum: General
Topic: How to change internet address to local, reverse NAT
Replies: 12
Views: 1027

Re: How to change internet address to local, reverse NAT

It's called Hairpin NAT . Here is the example: /ip firewall nat add action=masquerade chain=srcnat comment="Hairpin NAT" dst-address=172.18.17.0/24 src-address=172.18.17.0/24 /ip firewall nat add action=masquerade chain=srcnat comment="Main NAT" out-interface-list=ether1 /ip fire...
by erkexzcx
Fri Nov 27, 2020 2:52 pm
Forum: General
Topic: Ipsec not traffic passing
Replies: 26
Views: 1514

Re: Ipsec not traffic passing

Check my guide: viewtopic.php?f=23&t=169538

I think you are missing bridge/interface for VPN server as well as NAT rule for internal networks. I've mentioned everything there.
by erkexzcx
Fri Nov 27, 2020 12:03 am
Forum: Beginner Basics
Topic: OVPN +LAN
Replies: 1
Views: 235

Re: OVPN +LAN

First of all, RouterOS 6.* only supports TCP mode, while RouterOS 7.* supports UDP as well (if I am not mistaken). See https://wiki.mikrotik.com/wiki/OpenVPN#Features. Another thing is that you will get a terrible performance out of OpenVPN as it is one of the slowest VPN protocols. Instead you shou...
by erkexzcx
Thu Nov 26, 2020 11:47 am
Forum: Beginner Basics
Topic: Manual DNS for individual clients? [SOLVED]
Replies: 6
Views: 619

Re: Manual DNS for individual clients? [SOLVED]

Who would have thought you could do this on a router! Prior Mikrotik I had OpenWRT experience and there in DHCP server setting you have custom DHCP options and under the field there is a suggestion that "type this in order to give custom DNS to clients". When I noticed DHCP options in Mik...
by erkexzcx
Thu Nov 26, 2020 10:26 am
Forum: General
Topic: Winbox on Apple Silicon first try [SOLVED]
Replies: 16
Views: 2905

Re: Winbox on Apple Silicon first try [SOLVED]

I suggest using web browser for Mikrotik control, or CLI (e.g. SSH) for now as workaround.

This should be addressed to Wine as well because it's more or less issue with Wine.
by erkexzcx
Wed Nov 25, 2020 9:23 pm
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that
Replies: 7
Views: 2083

Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

Overview Notes: I've been using latest ROS6 (6.47.8) for this guide. Steps might be different on ROS7. Tutorial shows how to connect 2 routers, but at the end of this guide there are steps on how to connect 3rd router. Router A (internal VPN IP 10.22.22.1) - VPN server. Has public IP. Router B (int...
by erkexzcx
Tue Nov 24, 2020 9:30 pm
Forum: General
Topic: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]
Replies: 1
Views: 399

Re: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]

I was about to write to RouterOS7 forum because I suspected it's a bug with routeros7, but seems it's not: This is how I solved: Waste 2 days trying to understand where is the issue. Turn off Router B, get another Mikrotik router with ROS6 and configure identical IPSEC/IKE2 client setup. It connects...
by erkexzcx
Tue Nov 24, 2020 1:15 pm
Forum: General
Topic: Nordvpn IPsec Mikrotik Routing
Replies: 15
Views: 2495

Re: Nordvpn IPsec Mikrotik Routing

when connected to NordVPN UK host BBC detects it as if I am not in the UK and blocks the UK contentet such as Iplayer.
Make sure you are using NordVPN DNS provided by VPN server.
by erkexzcx
Tue Nov 24, 2020 12:12 pm
Forum: General
Topic: EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]
Replies: 1
Views: 399

EoIP/GRE tunnel not establishing over IPSEC/IKE2 [SOLVED]

So I have 2 Mikrotik routers: Router A: has public IP and hosting IPSEC/IKE2 VPN server. Latest RouterOS6. Router B: does not have public IP (behind other router's NAT) and acting as VPN client to Router A. Latest RouterOS 7 (beta2). Goal: LAN over internet, so I connect PC to router B and get IP fr...
by erkexzcx
Sun Nov 22, 2020 9:20 pm
Forum: Beginner Basics
Topic: Need help setting up EoIP over IPSEC
Replies: 0
Views: 210

Need help setting up EoIP over IPSEC

Classic scenario: router A is headquarters router, and router B is branch office router. Router A has public IP and should act as a main router. Router B does not have any firewall and is under NAT (another router), so no direct access. I want router B to be connected to router A: Encrypted connecti...
by erkexzcx
Sat Nov 21, 2020 4:41 pm
Forum: General
Topic: Features in the winbox
Replies: 6
Views: 390

Re: Features in the winbox

You can cycle windows, but the shortcut is a bit strange for me:
F6
Quick google search suggested even more results: viewtopic.php?t=147994#p728955
by erkexzcx
Fri Nov 20, 2020 4:45 pm
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: [Guide] How to setup NordVPN (IPSEC/IKEv2) + killswitch

Should I see traffic when I torch the bridge acting as blackhole for the VPN when it is going up or down? The only traffic I saw was ARP. When I re-enable my own killswitch lines (dst 100.69.69.69) then those lines in NAT do catch traffic. I see the same... Looking in /IP routing the PPPoE-out has ...
by erkexzcx
Fri Nov 20, 2020 9:42 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

Re: [Guide] How to setup NordVPN (IPSEC/IKEv2) + killswitch

That killswitch is not great. Quite dangerous in fact. Thank you for your feedback. I completely agree with you, and after testing your provided commands seems that it's working perfectly. +1 for brief explanation. I've updated commands in initial post. If someone has any better suggestions - let m...
by erkexzcx
Fri Nov 20, 2020 2:52 am
Forum: General
Topic: Nordvpn IPsec Mikrotik Routing
Replies: 15
Views: 2495

Re: Nordvpn IPsec Mikrotik Routing

I wrote a mini guide here that covers fasttrack, MSS reduction and killswitch: viewtopic.php?f=23&t=169273
by erkexzcx
Fri Nov 20, 2020 2:51 am
Forum: Useful user articles
Topic: NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)
Replies: 41
Views: 6456

NordVPN (IPSEC/IKEv2) + killswitch (For ROS6)

Overview Notes: I've had quite a lot of headaches making Mikrotik to work perfectly with NordVPN server, so decided to write this guide and mention all the steps which are not mentioned in the official guide. :) You must have RouterOS 6. It must be minimum version of 6.45. Some steps in ROS7 will b...
by erkexzcx
Thu Nov 19, 2020 5:24 pm
Forum: General
Topic: Feature request: Run script from firewall event
Replies: 10
Views: 3822

Re: Feature request: Run script from firewall event

I would not find it useful right now, but this would open up so much possibilities. +1 from me.
make your router prone to DoS/DDoS attacks
Not true if Mikrotik adds frequency option. E.g. "Do not run script if it already has run in the past X seconds".
by erkexzcx
Tue Nov 17, 2020 1:19 pm
Forum: Beginner Basics
Topic: How do I make highly-available AP that becomes LTE router in case of internet downtime?
Replies: 3
Views: 291

Re: How do I make highly-available AP that becomes LTE router in case of internet downtime?

Difficult to be specific without actual IP addresses. But let's assume your main router is .1 and your Chateau is .2 on the same subnet. Default gateway for your devices is .1 so your main router is the decision making point. - On Chateau, make sure it has a default route to the Internet via LTE. I...
by erkexzcx
Tue Nov 17, 2020 10:41 am
Forum: Beginner Basics
Topic: How do I make highly-available AP that becomes LTE router in case of internet downtime?
Replies: 3
Views: 291

How do I make highly-available AP that becomes LTE router in case of internet downtime?

In the house there is a main Mikrotik router and few (Ubiquiti) wireless access points. In one room there is "Mikrotik Chateau 12" router set-up as a wireless access point. I added SIM card to that "Chateau" router and now I want to make it highly available wireless access point ...
by erkexzcx
Sat Nov 14, 2020 2:55 am
Forum: Beginner Basics
Topic: Config restore
Replies: 2
Views: 254

Re: Config restore

Looks like you have no choice - reset the router. :)

From my experience, resetting Mikrotik router does not wipe internal storage.
by erkexzcx
Sat Nov 14, 2020 2:49 am
Forum: Beginner Basics
Topic: Blacklist all but one IP? [SOLVED]
Replies: 4
Views: 340

Re: Blacklist all but one IP? [SOLVED]

If your WAN interface is ether1 and your IP is 123.123.123.123 , then it would look like this: add action=accept chain=forward out-interface=ether1 dst-address=123.123.123.123 add action=drop chain=forward out-interface=ether1 This is very basic rule. I suggest learning more about firewalls. :)
by erkexzcx
Thu Nov 12, 2020 7:32 pm
Forum: Beginner Basics
Topic: Newbie: Access to modem behind router
Replies: 26
Views: 1222

Re: Newbie: Access to modem behind router

Is this what you are trying to achieve?

LAN <--> Mikrotik router <--> Modem <--> Internet
by erkexzcx
Thu Nov 12, 2020 7:24 pm
Forum: Wireless Networking
Topic: TX Power Mikrotik Lhg Xl 5 Ac 802.11a/n/ac
Replies: 3
Views: 499

Re: TX Power Mikrotik Lhg Xl 5 Ac 802.11a/n/ac

Did you check downloads page? https://mikrotik.com/product/lhg_xl_5_ac#fndtn-downloads There is brochure available. Also, correct me if I am wrong, but TX Power is something you should not be looking for when choosing a wireless device: https://www.draytek.co.uk/support/guides/difference-between-db-...
by erkexzcx
Thu Nov 12, 2020 7:17 pm
Forum: Beginner Basics
Topic: Port 22 / SFTP/SSH Being Blocked
Replies: 34
Views: 1867

Re: Port 22 / SFTP/SSH Being Blocked

Can you give us an example or diagram on what are you trying to achieve?
by erkexzcx
Thu Nov 12, 2020 12:02 am
Forum: Wireless Networking
Topic: Some help from you Mikrotik lovers please
Replies: 4
Views: 708

Re: Some help from you Mikrotik lovers please

This should go into newbie section. :) Anyway, it looks like you understand networking well enough in order to start using Mikrotik on your own: 1. Get WinBox app. Works well on Mac and Linux. https://mikrotik.com/download 2. Connect to your router (either via MAC or IP - google the difference). 3. ...
by erkexzcx
Wed Nov 04, 2020 8:41 am
Forum: General
Topic: Question about TCP Established and Call of Duty disconnects [SOLVED]
Replies: 26
Views: 1599

Re: Question about TCP Established and Call of Duty disconnects [SOLVED]

I think that if you are unable to handle large amount of connections, then you need a more powerful router?

I mean you are applying workarounds, this is impacting users and here you are trying to figure out what's the problem.
by erkexzcx
Tue Nov 03, 2020 10:26 pm
Forum: Scripting
Topic: disable a rule when a provider crashes?
Replies: 2
Views: 416

Re: disable a rule when a provider crashes?

I am not sure what you are asking, but I would say "yes, it's possible".
by erkexzcx
Sat Aug 29, 2020 9:38 pm
Forum: Beginner Basics
Topic: Tunnel traffic through VPN
Replies: 20
Views: 5268

Re: Tunnel traffic through VPN

1) Is it possible to tunnel all the traffic trough a VPN provider? 2) Which VPN provider is supported by Mikrotik? 3) Are there any providers which already have filters for illegal BitTorrent websites? Or the possibility to block Bittorent at all? 4) Can I block somehow Bittorent with my Mikrotik r...
by erkexzcx
Sat Aug 29, 2020 9:32 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 387
Views: 99812

Re: v7.1beta2 [development] is released!

Does this beta release work great with Winbox? Or is it console-only while it's beta?
by erkexzcx
Mon Jun 29, 2020 9:02 am
Forum: Beginner Basics
Topic: EoIP setup
Replies: 3
Views: 959

Re: EoIP setup

Hi sir. would it be possible if you can give me some advice on how to go about it. Sure. EoIP instructions: https://wiki.mikrotik.com/wiki/Manual:Interface/EoIP GRE tunnel instructions: https://wiki.mikrotik.com/wiki/Manual:Interface/Gre L2TP instructions: https://wiki.mikrotik.com/wiki/Manual:Inte...
by erkexzcx
Wed Jun 24, 2020 9:20 pm
Forum: Beginner Basics
Topic: [SOLVED] Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)
Replies: 1
Views: 648

Re: Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)

Right, so instructions are unclear (I got confused) by Manual:IP/IPsec#NAT_and_Fasttrack_Bypass instructions: Solution is to use IP/Firewall/Raw to bypass connection tracking, that way eliminating need of filter rules listed above It actually means that eliminating need of Fasttrack bypass rules. Us...
by erkexzcx
Wed Jun 24, 2020 9:30 am
Forum: Beginner Basics
Topic: Cannot ping interface IP
Replies: 1
Views: 541

Re: Cannot ping interface IP

I believe author meant packet marking in mangle section. I don't know what command he added, but seems you are going to find required info here: https://wiki.mikrotik.com/wiki/Load_Bal ... ll_marking
by erkexzcx
Wed Jun 24, 2020 12:51 am
Forum: Beginner Basics
Topic: [SOLVED] Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)
Replies: 1
Views: 648

[SOLVED] Need help setting up site 2 site IPsec/IKEv2 VPN (with certificates, manually)

So I've literally spent last few weeks, almost every evening trying to setup IPsec/IKEv2 site 2 site VPN. After hundreds of Google searches, unsuccessful and semi-successful attempts I finally gave up and came to this Mikrotik forum... So basically I have 2 routers, one has public IP, and another on...
by erkexzcx
Sun Jun 14, 2020 5:17 pm
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 2603

Re: Hairpin with port forwarding

good video tutorial
https://www.youtube.com/watch?v=_kw_bQyX-3U&t=177s

or specify in-interface (to be your WAN interface) on your dst-nat rule so you don't mess up LAN connection to the private IP.
That youtube video is legendary...
by erkexzcx
Sat Jun 06, 2020 12:44 pm
Forum: Beginner Basics
Topic: Help! How do I delete dynamic DNS servers? [SOLVED]
Replies: 12
Views: 7335

Re: Help! How do I delete dynamic DNS servers? [SOLVED]

If anyone is using some sort of VPN provider and you connected your router to it, go to IP --> IPsec --> Mode Configs Then open up your mode config that you are using for your VPN provider, change "Use responder DNS" from "exclusively" to "No". Kill active connection (i...
by erkexzcx
Thu Jun 04, 2020 1:26 pm
Forum: Beginner Basics
Topic: Firewall Layer 7 Filter
Replies: 4
Views: 1706

Re: Firewall Layer 7 Filter

This is not what you want to hear, but using Layer7 is generally a bad practice, because: 1. You can get around this filtering by using VPN 2. You can get around this by (sometimes) doing nothing. See "DNS Over HTTPS" and some browsers do it by default now. 3. Specifically your case, you c...
by erkexzcx
Sun May 31, 2020 7:44 pm
Forum: Scripting
Topic: [Script] Automatically change DNS if Pi-hole is no longer working
Replies: 23
Views: 4771

Re: [Script] Automatically change DNS if Pi-hole is no longer working

Thank you. I updated my initial comment with your suggestions. :)
by erkexzcx
Sun May 31, 2020 2:44 pm
Forum: Scripting
Topic: [Script] Automatically change DNS if Pi-hole is no longer working
Replies: 23
Views: 4771

[Script] Automatically change DNS if Pi-hole is no longer working

I've wrote a script that detects when Pi-Hole is no longer working, and automatically switches to public DNS 1.1.1.2,1.0.0.2. Disclaimer : I am aware of possibility to set multiple DNS servers, but for Pi-Hole to work you need to set only Pi-Hole IP address. Use case : Set-up Mikrotik and RPI with P...
by erkexzcx
Fri May 29, 2020 10:48 am
Forum: Beginner Basics
Topic: [Solved] "Resource Temporarily Unavailable" when Mikrotik used as a simple router
Replies: 1
Views: 1090

Re: "Resource Temporarily Unavailable" when Mikrotik used as a simple router

Issue solved.

I've set port forwardings without in-interface. Once I set it - everything is working again. I've set port 80, and since 443 was unused - HTTPS traffic worked fine, while 80 failed due to misconfiguration.
by erkexzcx
Fri May 29, 2020 9:32 am
Forum: Beginner Basics
Topic: [Solved] "Resource Temporarily Unavailable" when Mikrotik used as a simple router
Replies: 1
Views: 1090

[Solved] "Resource Temporarily Unavailable" when Mikrotik used as a simple router

Hey, So basically I replaced Cisco RV320 router with Mikrotik RB4011iGS and everything seems fine - internet works just fine, except speedtest always fail. When I try to run from Linux CLI client, I get this output: erikas@btwOS  ~  speedtest Speedtest by Ookla [error] Error: [11] Cannot read from...
by erkexzcx
Sun Jan 26, 2020 11:50 am
Forum: Scripting
Topic: ISP Throttle Speed YouTube [SOLVED]
Replies: 2
Views: 2183

Re: ISP Throttle Speed YouTube [SOLVED]

You should look at VPN side. Talking about VPN providers, such as NordVPN. You can configure your router to connect to their VPN server and whitelist only youtube.com or all traffic to go under VPN. Then your ISP won't have any chance to throttle specific sites.
by erkexzcx
Sun Jan 26, 2020 11:48 am
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 166
Views: 57529

Re: Feature Request - Wireguard Protocol

+1. I also do have additional SBC next to Mikrotik router just for Wireguard VPN server.
by erkexzcx
Tue Oct 08, 2019 9:22 pm
Forum: General
Topic: IPSec VPN fails to start - shows errors that I don't know how to solve
Replies: 2
Views: 1499

Re: IPSec VPN fails to start - shows errors that I don't know how to solve

The last rule appears to be an IPv6 ipsec issue. Are you trying to terminate the tunnel on IPv4 or IPv6? Hi, What I was going to do is to create an interface, where all traffic is being routed through VPN server. VPN IPSec connection is established from Mikrotik router, so the only thing needed to ...
by erkexzcx
Mon Oct 07, 2019 11:49 pm
Forum: General
Topic: IPSec VPN fails to start - shows errors that I don't know how to solve
Replies: 2
Views: 1499

IPSec VPN fails to start - shows errors that I don't know how to solve

Hi, I've setup IPSec VPN on Mikrotik router. Everything works fine, so I backed up configuration and restored on same model, but different router. Internet works just fine, but this is what I get (taken from logs): 21:02:16 ipsec,debug ipsec: 0.0.0.0[500] used as isakmp port (fd=25) 21:02:16 ipsec,d...