Community discussions

Search found 249 matches

by karlisi
Fri Oct 11, 2019 10:48 am
Forum: General
Topic: ESET AV detect PHP/Obfuscated.E at this forum
Replies: 1
Views: 437

Re: ESET AV detect PHP/Obfuscated.E at this forum

I am using ESET Endpoint Antivirus and have no problems with Mikrotik forum.
by karlisi
Mon Oct 07, 2019 10:20 am
Forum: General
Topic: L2TP/IPSec - Works from Android and Mikrotik but not Windows?
Replies: 3
Views: 1304

Re: L2TP/IPSec - Works from Android and Mikrotik but not Windows?

L2tp/IPSec client on Windows can work withour registry mod. NAT device in this case is whatever you want, all magic is made on Mikrotik VPN server
viewtopic.php?f=2&t=149863#p738129
by karlisi
Mon Sep 16, 2019 9:24 am
Forum: General
Topic: Laptops are trying to hack my router
Replies: 8
Views: 1091

Re: Laptops are trying to hack my router

Start with this
https://wiki.mikrotik.com/wiki/Manual:S ... our_Router
If you want to block access to router from guest network, block in firewall input chain all from this interface or IP range, allowing only needed services, i.e. DHCP, DNS, etc.
by karlisi
Fri Aug 09, 2019 1:25 pm
Forum: RouterBOARD hardware
Topic: Cant connect to RB951G-2HnD [SOLVED]
Replies: 2
Views: 494

Re: Cant connect to RB951G-2HnD [SOLVED]

Hold the reset button about 5 sec, until ACT LED starts flashing. If holded for 10 sec or more and LED stays lit or turns off, it's too long.
https://wiki.mikrotik.com/wiki/Manual:Reset
by karlisi
Mon Aug 05, 2019 5:56 pm
Forum: Announcements
Topic: v6.45.3 [stable] is released!
Replies: 90
Views: 25389

Re: v6.45.3 [stable] is released!

I don't know what smips device is, I have hAP and two hAP lites. Maybe I don't need the whole smips package.
Processor architecture, hAP is mipsbe, hAP Lite is smips.
by karlisi
Fri Aug 02, 2019 3:28 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35924

Re: v6.45.2 [stable] is released!

my RB750Gr3 with 6.41.5 version. After reboot it must be upgraded. But after that he did not start correctly, i can not seen him in winbox
Check Winbox version, it must be at least 3.19
by karlisi
Tue Jul 30, 2019 8:18 am
Forum: The Dude
Topic: can't add winbox as tool to The Dude
Replies: 4
Views: 572

Re: can't add winbox as tool to The Dude

"C:\Program Files (x86)\Dude\winbox.exe" "[Device.FirstAddress]:1234" "[Device.UserName]" "[Device.Password]"
by karlisi
Mon Jul 29, 2019 11:44 am
Forum: RouterBOARD hardware
Topic: Electrical Problems Causing Failure
Replies: 10
Views: 1360

Re: Electrical Problems Causing Failure

Seems like something in network. RB2011 has external PSU which typically fails first on bad electricity.
by karlisi
Wed Jul 17, 2019 12:06 pm
Forum: Wireless Networking
Topic: Lost connection over wireless to remote station after upgrade [SOLVED]
Replies: 1
Views: 406

Re: Lost connection over wireless to remote station after upgrade [SOLVED]

To answer my own question - regulatory domain restrictions. On station wireless installation=outdoor, on AP installation=any, frequency on both 5180 MHz. For country Latvia lowest allowed frequency for outdoor installations is 5500 MHz, so on station frequency was wrong, but older ROS allowed it. Fr...
by karlisi
Tue Jul 16, 2019 9:58 am
Forum: General
Topic: NEED help with FORUM
Replies: 6
Views: 562

Re: NEED help with FORUM

See User control panel -> Board preferences -> Edit notification option
by karlisi
Tue Jul 16, 2019 8:13 am
Forum: The Dude
Topic: Is Dude Communication Secure ?
Replies: 4
Views: 729

Re: Is Dude Communication Secure ?

For example, part of my first question concerns SNMP to the RouterOS device itself. With secure mode enabled, does the Dude poll the RouterOS device's SNMP via the secure connection or across the WAN facing SNMP port ? Only SNMP v3 supports secure communication. Configure Dude server and devices to...
by karlisi
Mon Jul 15, 2019 4:05 pm
Forum: Wireless Networking
Topic: Lost connection over wireless to remote station after upgrade [SOLVED]
Replies: 1
Views: 406

Lost connection over wireless to remote station after upgrade [SOLVED]

Have AP and remote 2 stations to make wireless bridges. Upgraded AP and one of stations from 6.42.12 to 6.44.5 lost connection to upgraded station. Not upgraded station works. Some ideas, what is changed and is it possible to recover connection without physically accessing remote station? configurat...
by karlisi
Mon Jul 15, 2019 10:10 am
Forum: The Dude
Topic: Is Dude Communication Secure ?
Replies: 4
Views: 729

Re: Is Dude Communication Secure ?

Secure mode - Whether to use Secure mode when connecting to a RouterOS device. Uses TLS connection

https://wiki.mikrotik.com/wiki/Manual:T ... e_settings
by karlisi
Thu Jul 11, 2019 8:18 am
Forum: The Dude
Topic: Push logs from Mikrotik to Graylog Server
Replies: 5
Views: 773

Re: Push logs from Mikrotik to Graylog Server

Yes, logs from Mikrotik can be collected on Graylog.
by karlisi
Wed Jul 10, 2019 3:22 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 97
Views: 34126

Re: v6.44.5 [long-term] is released!

Every changelog must contain all changes and fixes from previous same channel release, not from previous release by number. It's about this sentence? For long-term channel there are no other intermediate releases, only long-term. Similarly as for stable channel there is no beta releases. Changelogs...
by karlisi
Wed Jul 10, 2019 2:57 pm
Forum: The Dude
Topic: Push logs from Mikrotik to Graylog Server
Replies: 5
Views: 773

Re: Push logs from Mikrotik to Graylog Server

Are you also writing in Graylog forum? As already said there, first check if messages can reach graylog server at all and if port 2514 is open on the server.
by karlisi
Wed Jul 10, 2019 11:29 am
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 97
Views: 34126

Re: v6.44.5 [long-term] is released!

How do you guys propose we make such a changelog? This is the long term branch, where releases are very rare, and the jumps are very big. Imagine there could be 15 fixes, new bugs, fixes again, then the feature could be already removed, then a new one added, removed again, and then a new feature ma...
by karlisi
Wed Jul 10, 2019 9:51 am
Forum: Wireless Networking
Topic: Equipment for the conference room
Replies: 6
Views: 954

Re: Equipment for the conference room

He's using PoE switch to provide power to APs, in place of 4 PoE injectors.
by karlisi
Tue Jul 09, 2019 2:13 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 97
Views: 34126

Re: v6.44.5 [long-term] is released!

Mikrotik, please, write changelogs properly! Since separating stable and long-term channels they ar incomplete, at least for long-term. Every changelog must contain all changes and fixes from previous same channel release, not from previous release by number. It will eliminate such problems, as in ...
by karlisi
Mon Jul 08, 2019 8:46 am
Forum: General
Topic: L2TP VPN can not connect on Windows 10
Replies: 13
Views: 1481

Re: L2TP VPN can not connect on Windows 10

Thanks, I will test it.

And yes, this should go to separate topic
by karlisi
Fri Jul 05, 2019 2:44 pm
Forum: General
Topic: L2TP VPN can not connect on Windows 10
Replies: 13
Views: 1481

Re: L2TP VPN can not connect on Windows 10

I assume you have good reasons to take all this burden (registry tweaking or implementing my trick) rather than running the L2TP/IPsec directly on the outer Mikrotik.
Don't want to enable proxy-arp on LAN interface, to access devices on internal network.
by karlisi
Fri Jul 05, 2019 1:32 pm
Forum: General
Topic: L2TP VPN can not connect on Windows 10
Replies: 13
Views: 1481

Re: L2TP VPN can not connect on Windows 10

Ah, I see, I should explain better. l2tp server is running on other Mikrotik device behind Mikrotik router. Windows l2tp client -> remote LAN -> SOHO router -> Internet -> Mikrotik router with dst-nat -> LAN -> Mikrotik l2tp server In this setup VPN can't connect without Windows registry modification.
by karlisi
Fri Jul 05, 2019 9:05 am
Forum: General
Topic: L2TP VPN can not connect on Windows 10
Replies: 13
Views: 1481

Re: L2TP VPN can not connect on Windows 10

(optional for clarity) add a bridge interface with no member ports attach the public IP of the NAT behind which the server Mikrotik lives to an interface on the Mikrotik as a /32 one (normally to the portless bridge one created above, but you can use any interface) /ip firewall nat print chain=dstn...
by karlisi
Thu Jul 04, 2019 3:36 pm
Forum: General
Topic: L2TP VPN can not connect on Windows 10
Replies: 13
Views: 1481

Re: L2TP VPN can not connect on Windows 10

it is possible to run an LT2P/IPsec server on a Mikrotik behind a NATing device even without tweaking the Windows registry, the price to pay is that the clients then cannot have public IPs directly on themselves. How? We have many sites with Windows clients behind src-nat and l2tp/ipsec server behi...
by karlisi
Thu Jul 04, 2019 9:23 am
Forum: General
Topic: L2TP VPN can not connect on Windows 10
Replies: 13
Views: 1481

Re: L2TP VPN can not connect on Windows 10

It is not clear from your post, how your network is set up. I assume, L2TP server is behind router with dst-nat to this server, and you are trying to connect from Windows client. If so, Windows registry modification is required on client computer. Read this (although article is about Windows Vista, ...
by karlisi
Fri Jun 28, 2019 8:12 am
Forum: Beginner Basics
Topic: L2TP SERVER BEHIND NAT
Replies: 4
Views: 1096

Re: L2TP SERVER BEHIND NAT

As You already found this is Windows problem. You can't solve it another way, only patching every Windows client.
by karlisi
Tue Jun 25, 2019 4:48 pm
Forum: Beginner Basics
Topic: Firewall rule for accessing winbox
Replies: 7
Views: 479

Re: Firewall rule for accessing winbox

chain=input is for incoming packets destined for router itself.
by karlisi
Wed Jun 19, 2019 4:09 pm
Forum: RouterBOARD hardware
Topic: MTBF of RouterBOARD
Replies: 16
Views: 3929

Re: MTBF of RouterBOARD

UP! Mikrotik APs compliant with the wifi4eu minimum specs? As request from WiFi4EU 9.2.1 What are the technical requirements for the WiFi4EU Access Points? (...) Supports IEEE 802.11r Supports IEEE 802.11k Supports IEEE 802.11v (...) These protocols are missing in Mikrotik products, so they are not...
by karlisi
Wed May 29, 2019 4:23 pm
Forum: General
Topic: Enable NTP Client [SOLVED]
Replies: 4
Views: 372

Re: Enable NTP Client [SOLVED]

Yes
by karlisi
Wed May 29, 2019 9:46 am
Forum: General
Topic: Simple config but Internet not working.
Replies: 1
Views: 159

Re: Simple config but Internet not working.

Try this
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether13WAN
Not related to connection problems, but You have very insecure firewall rules. In input chain You should block everything, allowing only needed inputs. Also, forward chain is empty.
by karlisi
Fri May 24, 2019 10:04 am
Forum: Beginner Basics
Topic: Ban IP's / Drop connections of RDP Brute forcers
Replies: 6
Views: 671

Re: Ban IP's / Drop connections of RDP Brute forcers

Hmmmm, there is no reason why the action drop rule should be in the RAW firewall filter and NOT the input chain. In simple english, why drop is in input chain, not in raw? Perhaps linked wiki is intended to show the principle, not working configuration. You never know what other firewall rules are ...
by karlisi
Fri May 17, 2019 8:26 am
Forum: Wireless Networking
Topic: CAPsMAN channel selection
Replies: 7
Views: 1057

Re: CAPsMAN channel selection

It's OK if these CAPs are far away one from other. You can reduce reselect interval to force CAPs to check more often for less busy frequency.
by karlisi
Mon Apr 29, 2019 3:27 pm
Forum: General
Topic: Ipsec error in Log [SOLVED]
Replies: 4
Views: 361

Re: Ipsec error in Log [SOLVED]

i don't use IPSEC at all how can i disable it?
Review firewall input chain, perhaps you have unnecessary ports or protocols open. Best practice is to close all, except only those you are using.
by karlisi
Mon Apr 29, 2019 1:32 pm
Forum: General
Topic: Ipsec error in Log [SOLVED]
Replies: 4
Views: 361

Re: Ipsec error in Log [SOLVED]

Also what is the TCP connection established towards my router? These are connections to your PPTP server. 'TCP connection established' not necessarily means someone was able to get in, it means someone established connection and was able to begin the authentication process. The same for ipsec error...
by karlisi
Tue Apr 23, 2019 11:03 am
Forum: General
Topic: POE Out [SOLVED]
Replies: 4
Views: 318

Re: POE Out [SOLVED]

Typical RB951 power consumption is about 0.13A on startup and about 0.1A when running. If this is 24V 0.8A power adapter then yes, you can, because both RBs will use 0.26A max.
by karlisi
Mon Apr 15, 2019 5:46 pm
Forum: Beginner Basics
Topic: L2TP with RADIUS
Replies: 8
Views: 855

Re: L2TP with RADIUS

Try to use simpler RADIUS configuration
/radius
add address=192.168.7.70 secret=AgileroSecret123 service=ppp src-address=192.168.7.1

I can't ping my AD Server (192.168.7.70) using udp 1812/1813

You tried this from Mikrotik?
by karlisi
Fri Apr 12, 2019 10:22 am
Forum: Beginner Basics
Topic: L2TP with RADIUS
Replies: 8
Views: 855

Re: L2TP with RADIUS

If L2TP client is Windows, run this command in Windows administrative command window (cmd -> run as administrator), then restart Windows:
reg add HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent /v AssumeUDPEncapsulationContextOnSendRule /t REG_DWORD /d 0x2 /f
by karlisi
Wed Apr 10, 2019 11:48 am
Forum: Beginner Basics
Topic: L2TP with RADIUS
Replies: 8
Views: 855

Re: L2TP with RADIUS

Unable to access LAN from VPN client
viewtopic.php?t=85962
by karlisi
Wed Apr 10, 2019 11:44 am
Forum: Beginner Basics
Topic: L2TP with RADIUS
Replies: 8
Views: 855

Re: L2TP with RADIUS

For Mikrotik and Windows AD integration I used this tutorial
https://mivilisnet.wordpress.com/2018/1 ... indows-ad/
by karlisi
Mon Mar 04, 2019 10:02 am
Forum: Wireless Networking
Topic: CAPSMAN - Upgrade Policy - Require same version - should always work - suggestion
Replies: 3
Views: 510

Re: CAPSMAN - Upgrade Policy - Require same version - should always work - suggestion

You can download and upload the latest release of RouterOS in the files section of your CHR then point cAPs via CAPsMAN to pickup the latest ROS from there and update. Could be MIPSBE or any other. There is one problem. You should first upgrade the CAPsMAN, and after that upload files for other pla...
by karlisi
Mon Feb 25, 2019 4:32 pm
Forum: General
Topic: Upgrade fails if .npk for other platforms are present
Replies: 0
Views: 466

Upgrade fails if .npk for other platforms are present

If I remember correctly, some time ago it was possible to upload to CAPsMAN router all needed packages for APs and router itself. After restart router was upgraded and all APs too, if "suggest same version" upgrade policy was enabled. Now, if there are additional .npk files uploaded RouterOS upgrade...
by karlisi
Thu Feb 21, 2019 4:28 pm
Forum: Wireless Networking
Topic: Identify which CAPsMAN interface belongs to which AP [SOLVED]
Replies: 2
Views: 324

Re: Identify which CAPsMAN interface belongs to which AP [SOLVED]

/caps-man provisioning add name-format=identity
by karlisi
Fri Feb 15, 2019 1:11 pm
Forum: Scripting
Topic: Contribute backup script to FTP [SOLVED]
Replies: 2
Views: 390

Re: Contribute backup script to FTP [SOLVED]

Sometimes it's good to have configuration export too:
/system backup save name=$filename password=xxxxx
:delay 3s
/export file=$filename
by karlisi
Mon Feb 11, 2019 10:52 am
Forum: RouterBOARD hardware
Topic: Mikrotik Poe Cascading
Replies: 6
Views: 670

Re: Mikrotik Poe Cascading

We have in some sites RB260GSP -> RB951Ui-2HnD -> RB951Ui-2HnD chained, somewhere 2 chains on one switch, without problems for more than 3 years. From my experience RB951 power consumption is about 130mA on boot, about 95mA when booted, so theoretically we can put such chains on all 4 outputs.
by karlisi
Fri Feb 08, 2019 2:54 pm
Forum: Beginner Basics
Topic: Cloud Router Switch administration [SOLVED]
Replies: 11
Views: 739

Re: Cloud Router Switch administration [SOLVED]

Use one of combo ports for connection to PC.
Do You see device in Winbox? Try to connect using MAC address.
https://i.mt.lv/cdn/rb_files/1539897967 ... lus-qg.pdf
by karlisi
Fri Feb 01, 2019 2:34 pm
Forum: General
Topic: Winbox Urgent Suggestion
Replies: 15
Views: 1097

Re: Winbox Urgent Suggestion

i have the right to use a winbox version that is compatible with my OS
As the Winbox name suggests, it's a Windows Box.
by karlisi
Thu Jan 10, 2019 10:04 am
Forum: Beginner Basics
Topic: Noob firewall question - being brute forced
Replies: 7
Views: 505

Re: Noob firewall question - being brute forced

If I understand correctly these could be commands I'd need to use after adding all WAN addresses to a custom contacts list MyContactList?(I replaced RDP /w TCP as per @mkx comment and used 8.8.8.8 as server IP for this example) Do I need to use the WinBox software to execute this or can I do it fro...
by karlisi
Fri Dec 28, 2018 3:47 pm
Forum: RouterBOARD hardware
Topic: RB750 Aluminum Electrolytic Capacitor SMD need replacement
Replies: 3
Views: 639

Re: RB750 Aluminum Electrolytic Capacitor SMD need replacement

If there is j not capital J after 330, then it is 330uF 6.3V 105*C
by karlisi
Thu Dec 20, 2018 4:31 pm
Forum: Beginner Basics
Topic: Strange UDP Packet to 81.198.87.240 [SOLVED]
Replies: 1
Views: 358

Re: Strange UDP Packet to 81.198.87.240 [SOLVED]

# nslookup cloud.mikrotik.com
Name: cloud.mikrotik.com
Address: 81.198.87.240
by karlisi
Fri Dec 14, 2018 10:19 am
Forum: General
Topic: Feature request: CAPsManager - roaming
Replies: 79
Views: 23240

Re: Feature request: CAPsManager - roaming

The project requirements for WiFi4EU are:
(..)
support IEEE 802.11r
(..)
But unfortunately Microtik does not meet the requirements.
We also wanted to participate in this project to extend our infrastructure. It seems, EU money will go to another company. Perhaps Mikrotik don't need this money?
by karlisi
Thu Dec 13, 2018 9:46 am
Forum: Wireless Networking
Topic: cAP ac: Alternative brackets
Replies: 4
Views: 626

Re: cAP ac: Alternative brackets

Can you clarify about the cable not bending enough to fit into the wall? I just don't see the issue. Subject: 19.0 What is the Minimum Bending Radius for a Cable? According to EIA SP-2840A (a draft version of EIA-568-x) the minimum bend radius for UTP is 4 x cable outside diameter, about one inch. ...
by karlisi
Tue Dec 11, 2018 2:05 pm
Forum: Beginner Basics
Topic: Router Optimization
Replies: 7
Views: 868

Re: Router Optimization

I hope you have also some rules to protect the router from attacks, not only those shown, and your router isn't transferring any malicious traffic too. IMHO it's enough to have 1 rule instead of 3 in forward chain, not needed to specify ports /ip firewall filter add action=fasttrack-connection chain...
by karlisi
Tue Dec 04, 2018 10:28 am
Forum: General
Topic: Tls host not work
Replies: 9
Views: 2215

Re: Tls host not work

It works, at least on 6.42.10
You should remove port, leaving only tls-host. And this rule must be before 'accept established, related' rule.
by karlisi
Thu Nov 22, 2018 10:40 am
Forum: General
Topic: don´t upgrade last version MKT1100AHx2
Replies: 1
Views: 230

Re: don´t upgrade last version MKT1100AHx2

What's in the log?
by karlisi
Tue Nov 20, 2018 2:00 pm
Forum: Beginner Basics
Topic: MIkrotik backup script
Replies: 4
Views: 562

Re: MIkrotik backup script

I would have added Year :)
It wasn't in OP requirements ;)
by karlisi
Tue Nov 20, 2018 10:10 am
Forum: Beginner Basics
Topic: MIkrotik backup script
Replies: 4
Views: 562

Re: MIkrotik backup script

Something like this? :local filename; :local date [/system clock get date]; :local name [/system identity get name]; :local months ("jan","feb","mar","apr","may","jun","jul","aug","sep","oct","nov","dec"); :local varMonth [:pick $date 0 3]; :set varMonth ([ :find $months $varMonth -1 ] + 1); :if ($v...
by karlisi
Wed Nov 07, 2018 4:42 pm
Forum: General
Topic: Can`t access to remote desktop/fileserver through PPTP/L2TP by hostname
Replies: 17
Views: 1747

Re: Can`t access to remote desktop/fileserver through PPTP/L2TP by hostname

Not related to VPN problems, but /ip firewall rules are not in optimal order. In input chain put allow established, related rules on top.
by karlisi
Wed Nov 07, 2018 4:36 pm
Forum: General
Topic: Can`t access to remote desktop/fileserver through PPTP/L2TP by hostname
Replies: 17
Views: 1747

Re: Can`t access to remote desktop/fileserver through PPTP/L2TP by hostname

Try this
/ppp profile
add dns-server=192.168.90.254 local-address=192.168.90.254 name=vpn-profile \
    remote-address=vpn-pool use-encryption=yes
by karlisi
Wed Nov 07, 2018 3:45 pm
Forum: General
Topic: Can`t access to remote desktop/fileserver through PPTP/L2TP by hostname
Replies: 17
Views: 1747

Re: Can`t access to remote desktop/fileserver through PPTP/L2TP by hostname

It's very hard to guess what is wrong only from video and screens. Can You post output from /export hide-sensitive ?
by karlisi
Tue Nov 06, 2018 10:01 am
Forum: The Dude
Topic: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?
Replies: 6
Views: 1206

Re: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?

I don't think they overlap and I would implement Dude, Splunk and, in place of Cacti, Zabbix.
Dude for management and very basic monitoring but it can do more.
Splunk (I am using it's alternative Graylog) for log collecting, log analyzing and alerting.
Zabbix for monitoring, graphing and alerting.
by karlisi
Thu Oct 25, 2018 4:39 pm
Forum: General
Topic: Redirect request by source IP in a scenario with Server Microsoft (DC)
Replies: 3
Views: 333

Re: Redirect request by source IP in a scenario with Server Microsoft (DC)

For domain-joined workstations it is mandatory to have AD aware DNS servers configured. If You will configure DNS server on them, which knows nothing about AD, it will break domain authentication.
by karlisi
Wed Oct 24, 2018 10:30 am
Forum: Beginner Basics
Topic: Mikrotik as a switch with wifi
Replies: 8
Views: 1026

Re: Mikrotik as a switch with wifi

Try this
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n frequency=2422 name=wlan2.4 \
ssid=NETGEAR48 mode=station-pseudobridge
by karlisi
Thu Sep 20, 2018 2:34 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 89021

Re: Winbox vulnerability: please upgrade

would check firewall rules for unsafe entries on every upgrade
What is considered unsafe entry? And how would you determine that particular entry is unsafe in specific firewall?
Everything outside default protection rules. It should be only warning, nothing else.
by karlisi
Thu Sep 20, 2018 12:41 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 89021

Re: Winbox vulnerability: please upgrade

In some cases Windows 10 forces user to restart computer not letting to do anything else. It's almost the same, except if user wants to sit and look at smth like "You must restart Your computer to finish important update" forever. It's offtopic, imho. Mikrotik should not change upgrade to automatic ...
by karlisi
Fri Sep 14, 2018 12:14 pm
Forum: General
Topic: NAT Setup: Access from internal network is OK, but from internet show mikrotik login page
Replies: 1
Views: 438

Re: NAT Setup: Access from internal network is OK, but from internet show mikrotik login page

First, it's not good to open all webserver's ports to whole world. dst-nat rules should be something like this chain=dstnat action=dst-nat to-addresses=192.168.89.254 to-ports=443 protocol=tcp dst-address=2.184.70.46 dst-port=443 log=no chain=dstnat action=dst-nat to-addresses=192.168.89.254 to-port...
by karlisi
Wed Aug 29, 2018 10:57 am
Forum: Wireless Networking
Topic: CAPsMAN - can't get 5GHz band on wAP ac to work [SOLVED]
Replies: 14
Views: 1878

Re: CAPsMAN - can't get 5GHz band on wAP ac to work [SOLVED]

See the CAPsMAN configuration below. The wAP ac has only ever been configured as CAP using the button. To me the configuration looks fine, and I'm not seeing any errors (such as "no supported channel"). But I'm new to CAPsMAN, probably I'm missing something obvious? [admin@MikroTik] /caps-man chann...
by karlisi
Tue Jul 31, 2018 3:10 pm
Forum: General
Topic: MT Forum problems (posting/upload)
Replies: 4
Views: 605

Re: MT Forum problems (posting/upload)

After posting, a white screen is shown instead of the usual next screen.
However, the posting appears when reloading the forum.
It's fixed, nice
by karlisi
Tue Jul 31, 2018 9:53 am
Forum: Beginner Basics
Topic: Troublesome Firewall rule (NAT?)
Replies: 6
Views: 698

Re: Troublesome Firewall rule (NAT?)

Perhaps it's a typo, in text you have 10.0.0.155, in NAT rule IP is 10.0.0.55 Remove from NAT rule src-port=8082 and add in-interface=your-wan-interface (or dst-address=your-wan-ip) to it. And, you don't need this firewall rule, except, if you are blocking all tcp ports in forward chain (unlikely). ...
by karlisi
Mon Jul 30, 2018 10:48 am
Forum: General
Topic: problem accessing the mikrotik VM
Replies: 1
Views: 192

Re: problem accessing the mikrotik VM

You can log in from VM management.
BTW version 6.38.3 is vulnerable to at least 2 threats, consider to upgrade, more on https://blog.mikrotik.com/security/
by karlisi
Mon Jul 16, 2018 11:44 am
Forum: General
Topic: How do i access mikrotik, i forwarded the only service port (winbox) to an nother ip by accident [SOLVED]
Replies: 3
Views: 344

Re: How do i access mikrotik, i forwarded the only service port (winbox) to an nother ip by accident [SOLVED]

If You can access router physically and know IP address from which it is accessible, connect it directly to Your computer, set on computer this (wrong) IP address and that's all. If not, ask ISP, sorry.
by karlisi
Fri Jul 13, 2018 3:28 pm
Forum: General
Topic: Automatically upgrade CAPs MIPSBE over CAPsMAN ARM
Replies: 2
Views: 715

Re: Automatically upgrade CAPs MIPSBE over CAPsMAN ARM

Upload mipsbe package to RB3011.
Configure CAPsMAN accordingly (change path if needed)
/caps-man manager
set enabled=yes package-path=/ upgrade-policy=suggest-same-version
That's all. The upgrade process will start immediatelly, all CAPs will restart as a result.
by karlisi
Wed Jul 11, 2018 8:45 am
Forum: Beginner Basics
Topic: Connecting routers through POE ports
Replies: 4
Views: 661

Re: Connecting routers through POE ports

Seems like it's quite possible to have two units daisy-chained (even using PoE injector), but not more. I can confirm this, we have daisy chained two RB951Ui-2HnD and two hAP in many places. On startup they are consuming from power unit about 150mA each, so, perhaps 3 units chained are acceptable, ...
by karlisi
Wed Jul 11, 2018 8:22 am
Forum: General
Topic: PPTP question [SOLVED]
Replies: 3
Views: 480

Re: PPTP question [SOLVED]

It means someone trying to get in. These messages are written for every attempt, successful or unsuccessful. For unsuccessful authentication typically there are no additional messages (default configuration). If authentication was successful, there should be message like 'username logged in'.
by karlisi
Tue Jul 10, 2018 10:51 am
Forum: Beginner Basics
Topic: How specific do you make your FW rules?
Replies: 4
Views: 594

Re: How specific do you make your FW rules?

I have from 9 to 60 rules on different sites, it depends. 30 rules for 2 WANs is not so much, I think.
by karlisi
Fri Jul 06, 2018 2:42 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 27671

Re: Winbox v3.16 released!

Hello everybody,
Faton
Start new topic, please! This is for problems with Winbox v3.16 only!
by karlisi
Wed Jul 04, 2018 10:32 am
Forum: Wireless Networking
Topic: CAPsMAN very bad performance
Replies: 2
Views: 1338

Re: CAPsMAN very bad performance

Try a different channel.
Or better, let the CAP choose the channel and to avoid conflicts with other devices set reselect channel every 1 minute
/caps-man channel
add band=2ghz-g/n reselect-interval=1m name="ch 2"
by karlisi
Fri Jun 22, 2018 12:30 pm
Forum: General
Topic: The security flaw for Hajime is closed by the firewall
Replies: 37
Views: 17033

Re: The security flaw for Hajime is closed by the firewall

maybe it infected the backup file ?
Do you restored from .backup file not from configuration backup (.rsc file)?
by karlisi
Wed Jun 13, 2018 3:58 pm
Forum: Beginner Basics
Topic: Windows Domain Controller blocked by Mikrotik firewall?
Replies: 9
Views: 1116

Re: Windows Domain Controller blocked by Mikrotik firewall?

Your AD DC IP is 192.168.0.200 and have DHCP server on it? If so, why to use DHCP on Mikrotik? 2 DHCP servers in one network is a big mess. Disable DHCP server and DHCP relay on Mikrotik and use Windows DHCP. Configure it properly to give Windows DNS server address as only DNS server for clients. Re...
by karlisi
Mon Jun 11, 2018 5:15 pm
Forum: Scripting
Topic: Capsman scheduler
Replies: 17
Views: 1752

Re: Capsman scheduler

And if you disable all provisioning rules by hand and execute provision on all radios, the interfaces are still there?
by karlisi
Mon Jun 11, 2018 1:20 pm
Forum: General
Topic: MT Router honeypot.
Replies: 20
Views: 2047

Re: MT Router honeypot.

This can be fun :) I suggest to forward the log to some syslog server, for some analysis later.
by karlisi
Mon Jun 11, 2018 8:39 am
Forum: Scripting
Topic: Capsman scheduler
Replies: 17
Views: 1752

Re: Capsman scheduler

Are you sure your APs are managed by CAPsMAN? Are they on /capsman interface ?
by karlisi
Fri Jun 08, 2018 8:33 am
Forum: Scripting
Topic: Capsman scheduler
Replies: 17
Views: 1752

Re: Capsman scheduler

Post export from /capsman provisioning and /capsman configuration please.
by karlisi
Tue Jun 05, 2018 11:14 am
Forum: RouterBOARD hardware
Topic: CRS317 vertical operation? [SOLVED]
Replies: 3
Views: 629

Re: CRS317 vertical operation? [SOLVED]

There are heat pipes inside the case to transfer heat to external radiator. There is no fan on radiator and radiator ribs are designed for horizontal use of the case. You can use it vertically but it needs temp monitoring and perhaps some additional fan for external cooling.
by karlisi
Tue Jun 05, 2018 9:34 am
Forum: Scripting
Topic: Capsman scheduler
Replies: 17
Views: 1752

Re: Capsman scheduler

So, something wrong with configurations included in these provisionings.
by karlisi
Mon Jun 04, 2018 2:19 pm
Forum: Scripting
Topic: Capsman scheduler
Replies: 17
Views: 1752

Re: Capsman scheduler

Only the first enabled provisioning rule will be in effect, if no additional filtering parameters (hw-supported-modes, identity-regexp, etc.) are set. If you want to disable all 4 provisioning rules at once, try my scripts: /caps-man provisioning enable numbers=[find] :delay 1 /caps-man radio provis...
by karlisi
Mon Jun 04, 2018 10:34 am
Forum: Scripting
Topic: Capsman scheduler
Replies: 17
Views: 1752

Re: Capsman scheduler

Try on first line
/caps-man provisioning disable numbers=[find]
And on second script too. This should disable and enable all configurations.
by karlisi
Wed May 30, 2018 11:05 am
Forum: Scripting
Topic: Capsman scheduler
Replies: 17
Views: 1752

Re: Capsman scheduler

You already have provisioning rules configured. Create these scripts and schedule to run them.

to enable
/caps-man provisioning enable 0    
:delay 1
/caps-man radio provision numbers=[find]
to disable
/caps-man provisioning disable 0 
:delay 1
/caps-man radio provision numbers=[find]
by karlisi
Wed May 23, 2018 2:13 pm
Forum: General
Topic: ICMP issue in src-nat
Replies: 2
Views: 360

Re: ICMP issue in src-nat

This is expected, src-nat works for outgoing packets from internal network to outside. To deliver packets from outside to internal network You need dst-nat rule.
by karlisi
Mon May 21, 2018 3:53 pm
Forum: Beginner Basics
Topic: What do i need to learn to become proficient quickly?
Replies: 20
Views: 1772

Re: What do i need to learn to become proficient quickly?

Strange link that was.
Perhaps, but I found it very useful. And it's from Mikrotik :)
by karlisi
Wed May 09, 2018 8:22 am
Forum: Virtualization
Topic: how to install chr on xen server
Replies: 1
Views: 806

Re: how to install chr on xen server

I imported OVA package, went smooth.
by karlisi
Wed Mar 14, 2018 3:01 pm
Forum: The Dude
Topic: Is possible to analyze a network with PC with Windows and The Dude?
Replies: 1
Views: 553

Re: Is possible to analyze a network with PC with Windows and The Dude?

No, You will need Windows for Dude client and one Mikrotik RouterOS device with dude package installed. It is not necessary to purchase Mikrotik hardware, if You haven't one. You can use CHR on virtual machine https://wiki.mikrotik.com/wiki/Manual:CHR
by karlisi
Fri Feb 16, 2018 10:11 am
Forum: Beginner Basics
Topic: Block websites http and https without Web Proxy / 100% works.
Replies: 17
Views: 13121

Re: Block websites http and https without Web Proxy / 100% works.

You can check this configuration, all IPs are Facebook IPs. Not exactly. Big names, as FB, Google, Microsoft, hosts their data on many data-centers worldwide, which hosts also data for many other organizations. By blocking their addresses, You will block all services from these IP, i.e., software u...
by karlisi
Thu Jan 25, 2018 8:35 am
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 77933

Re: v6.41 [current]

Could we expect that 6.40.5 will become "bugfix" or 6.40.6 with fixes from 6.41?

6.40.5 is the last with "old-known-bridge-implementation" technology and not all want to upgrade to "new-better-but-not-too-familiarized" one.
+1001
by karlisi
Mon Jan 22, 2018 9:08 am
Forum: Beginner Basics
Topic: How to block SSH attackers after 3 bad logins?
Replies: 16
Views: 2836

Re: How to block SSH attackers after 3 bad logins?

This will block ssh after 2nd time. To block after 4th time using this method, use 3 temporary stages and then add to blacklist. I made something like this, don't know if it's ok. I somebody try to ssh 4 times in 15 seconds, it will block him. What do you think? add action=drop chain=input comment="...
by karlisi
Mon Jan 15, 2018 2:50 pm
Forum: Beginner Basics
Topic: How to block SSH attackers after 3 bad logins?
Replies: 16
Views: 2836

Re: How to block SSH attackers after 3 bad logins?

If You want to keep ssh wide open, this is working configuration to add some brute-forcers to blacklist. Then You can use this blacklist to fully block these addresses (be careful, You can block yourself too) or only block ssh and perhaps some other sensitive ports. add action=jump chain=input comme...
by karlisi
Fri Jan 12, 2018 10:26 am
Forum: General
Topic: capsman V2 package - cant find it to update my routerboard and Cap [SOLVED]
Replies: 1
Views: 519

Re: capsman V2 package - cant find it to update my routerboard and Cap [SOLVED]

CAPsMAN v2 is included by default in latest routeros (both bugfix and current).
by karlisi
Wed Dec 20, 2017 4:55 pm
Forum: Wireless Networking
Topic: CAPsMAN with two SSIDs
Replies: 10
Views: 2639

Re: CAPsMAN with two SSIDs

Perahps try simpler configuration /caps-man configuration add channel=loader datapath=loader mode=ap name=cfg1 security=security1 ssid=loader-new add datapath=free mode=ap name=free-new security=security2 ssid=free-new /caps-man provisioning add action=create-dynamic-enabled master-configuration=cfg...
by karlisi
Wed Dec 20, 2017 10:26 am
Forum: Wireless Networking
Topic: CAPsMAN with two SSIDs
Replies: 10
Views: 2639

Re: CAPsMAN with two SSIDs

Try without specifying interfaces
by karlisi
Wed Dec 20, 2017 8:23 am
Forum: Wireless Networking
Topic: CAPsMAN with two SSIDs
Replies: 10
Views: 2639

Re: CAPsMAN with two SSIDs

It's impossible to see Your configuration from screenshots. Please post output from /caps-man export
by karlisi
Fri Dec 08, 2017 10:21 am
Forum: General
Topic: Using Splunk to analyse MikroTik logs
Replies: 98
Views: 16761

Re: Using Splunk to analyse MikroTik logs

Took little test yesterday. Great tool for log analysis. One big problem for free licence, no email alerts :(
by karlisi
Fri Nov 24, 2017 10:47 am
Forum: General
Topic: Tool: Realtime per IP traffic monitor for home/office
Replies: 289
Views: 305149

Re: Tool: Realtime per IP traffic monitor for home/office

Many thanks for this tool!
by karlisi
Fri Nov 24, 2017 9:41 am
Forum: Beginner Basics
Topic: Separation of traffic from different networks to different external addresses on 1 WAN port
Replies: 2
Views: 373

Re: Separation of traffic from different networks to different external addresses on 1 WAN port

You should have 2 IP addresses on WAN interface, then dst-nat like this add action=src-nat chain=srcnat out-interface=WAN src-address=10.1.1.0/24 to-addresses=1.1.1.9/29 add action=src-nat chain=srcnat out-interface=WAN src-address=10.2.1.0/24 to-addresses=1.1.1.10/29 Your example for example for ne...
by karlisi
Wed Nov 08, 2017 9:56 am
Forum: Wireless Networking
Topic: CAPsMAN manager can't manage its own wireless [SOLVED]
Replies: 19
Views: 12350

Re: CAPsMAN manager can't manage its own wireless [SOLVED]

Check discovery interface on CAP settings. Should be LAN interface.
by karlisi
Fri Nov 03, 2017 1:58 pm
Forum: General
Topic: DNS in mikrotik and DC on Windows Server
Replies: 3
Views: 4813

Re: DNS in mikrotik and DC on Windows Server

I understand why you want Mikrotik to be the second DNS server, but in Windows AD this is not good idea. You should configure Windows AD DCs as only DNS servers for your LAN. You can then configure Windows DNS to forward requests to your provider's DNS servers directly, or to Mikrotik. On Mikrotik u...
by karlisi
Mon Oct 30, 2017 10:04 am
Forum: General
Topic: Backup and restore Router OS
Replies: 1
Views: 353

Re: Backup and restore Router OS

Do not restore backup on another device. To transfer configuration to another device use export and import
https://wiki.mikrotik.com/wiki/Manual:C ... Management
by karlisi
Fri Oct 27, 2017 8:10 am
Forum: General
Topic: Article about new "Reaper" or "loTroop" Botnet
Replies: 6
Views: 1215

Re: Article about new "Reaper" or "loTroop" Botnet; lists Mikrotik as vulnerable

If You read carefully, these are issues not related to this attack, only can be potentially exploited (at least, Checkpoint thinks so). As said before in one of posts in this forum, if You are on latest versions of ROS, You are OK.
by karlisi
Thu Oct 12, 2017 11:04 am
Forum: Beginner Basics
Topic: forward chain: no packets go through [SOLVED]
Replies: 10
Views: 1037

Re: forward chain: no packets go through [SOLVED]

Which ports are in your bridge?
Also post nat rules.
by karlisi
Thu Oct 12, 2017 10:56 am
Forum: Wireless Networking
Topic: CAPSMAN + Guest WiFi
Replies: 15
Views: 5803

Re: CAPSMAN + Guest WiFi

Next time don't post sensitive data, like passwords, publicly.
Disable this nat rule and check if problem is resolved
add action=masquerade chain=srcnat out-interface=bridgeopen src-address=\
    10.35.0.0/24
by karlisi
Mon Oct 02, 2017 10:02 am
Forum: General
Topic: does PPTP Server requires GRE srcnat masquerading ?
Replies: 2
Views: 645

Re: does PPTP Server requires GRE srcnat masquerading ?

but the question is do i need to srcnat masquerade GRE protocol to outside in firewal nat rules and if so how do i do this ? do i need to specify source address ranges ? connection type pptp for this masquerading ? how does the GRE protocol goes back to the internet ? No special src-nat rules for P...
by karlisi
Mon Oct 02, 2017 9:54 am
Forum: General
Topic: does PPTP Server requires GRE srcnat masquerading ?
Replies: 2
Views: 645

Re: does PPTP Server requires GRE srcnat masquerading ?

Hi
I have setup pptp server with ip pool, ppp profile, secret and pptp server and firewall filter rules for tcp port 1732 and protocol GRE
PPTP port is 1723. I have only this port open and no rules for GRE.
by karlisi
Thu Sep 28, 2017 8:17 am
Forum: General
Topic: CAPsMAN provisioning problem
Replies: 1
Views: 530

Re: CAPsMAN provisioning problem

Try to change order of provisioning rules, put now first rule with both interfaces on the bottom of list.
by karlisi
Wed Sep 27, 2017 4:04 pm
Forum: General
Topic: One Eth Port - 2 gateway addresses
Replies: 6
Views: 864

Re: One Eth Port - 2 gateway addresses

Don't mess with routes, make src-nat rules for each of subnets like this: /ip firewall nat add action=src-nat chain=srcnat out-interface=WAN \ src-address=192.168.10.0/24 to-addresses=172.16.1.1/32 add action=src-nat chain=srcnat out-interface=WAN \ src-address=192.168.20.0/24 to-addresses=172.16.2....
by karlisi
Tue Sep 26, 2017 12:21 pm
Forum: General
Topic: 2 IP adresses on 1 Eth port
Replies: 1
Views: 367

Re: 2 IP adresses on 1 Eth port

Yes and yes.
by karlisi
Tue Sep 26, 2017 10:40 am
Forum: Wireless Networking
Topic: Caps selecting same channel
Replies: 31
Views: 7297

Re: Caps selecting same channel

This has revealed two other issues that I think are bugs. Those two are: 1) reset-configuration deletes all files on unit. This is causing problem when I want a script to run after reset - the script file is no longer there! This not a bug. Place files inside flash directory and they will be there ...
by karlisi
Mon Sep 25, 2017 9:39 am
Forum: Wireless Networking
Topic: Caps selecting same channel
Replies: 31
Views: 7297

Re: Caps selecting same channel

As far as I understand, Mikrotik chooses least busy wireless channel only on startup and after that never checks if it is the best (least busy). So, after CAPsMAN restart, if both APs are starting simultaneously, they can choose the same free channel. Starting from version 6.39 it is possible to tel...
by karlisi
Mon Sep 25, 2017 8:33 am
Forum: SwOS
Topic: CSS switch multicast problem in classrom ?
Replies: 3
Views: 880

Re: CSS switch multicast problem in classrom ?

This the most useful post in every technical forum - "thanks, problem solved!"... and no details, no followup, nothing :evil:
by karlisi
Thu Sep 14, 2017 11:46 am
Forum: General
Topic: SNTP client, unable to synchronize time, error: server-ip-mismatch
Replies: 24
Views: 4379

Re: SNTP client, unable to synchronize time, error: server-ip-mismatch

SNTP client cannot synchronize time, error server-ip-mismatch.(
This error is on router? Or You are using router as NTP server and this error is on clients?
by karlisi
Thu Aug 31, 2017 1:35 pm
Forum: General
Topic: Is missing connection-state=invalid hugely bad?
Replies: 5
Views: 2961

Re: Is missing connection-state=invalid hugely bad?

So should I be worried that my initial Firewall configuration missing those "Drop Invalid connections" rules?
No.
These examples are a little outdated, i.e., established and related can be in one rule.
add action=accept chain=forward comment="" connection-state=established,related
by karlisi
Wed Aug 23, 2017 10:36 am
Forum: Wireless Networking
Topic: CAPsMAN and guestwifi, no internet on guestwifi
Replies: 20
Views: 1957

Re: CAPsMAN and guestwifi, no internet on guestwifi

What is not working:
Connect to internet from "wifiguests"
What exactlynot working? http? ping to 8.8.8.8? ping to external ip of router? everything?
by karlisi
Tue Aug 22, 2017 4:00 pm
Forum: General
Topic: CHR doesn't survive XenServer live migration.
Replies: 4
Views: 1375

Re: CHR doesn't survive XenServer live migration.

Yes, still no xentools available for CHR, still crashing on live migration.
by karlisi
Tue Aug 22, 2017 3:55 pm
Forum: Wireless Networking
Topic: CAPsMAN and guestwifi, no internet on guestwifi
Replies: 20
Views: 1957

Re: CAPsMAN and guestwifi, no internet on guestwifi

You need only one rule in nat chain srcnat.
/ip firewall nat
add action=masquerade chain=srcnat out-interface=WAN
Just curiosity - there are any dropped connections in output chain (rule with many email related ports)? IMHO this rule is useless.
by karlisi
Tue Aug 22, 2017 8:55 am
Forum: Wireless Networking
Topic: CAPsMAN and guestwifi, no internet on guestwifi
Replies: 20
Views: 1957

Re: CAPsMAN and guestwifi, no internet on guestwifi

Please post export of nat rules. In similar configuration I have only one nat rule, not 2, perhaps there is something wrong.
by karlisi
Mon Jul 31, 2017 10:21 am
Forum: General
Topic: Zabbix SNMP OID - Interface Traffic
Replies: 1
Views: 3214

Re: Zabbix SNMP OID - Interface Traffic

https://share.zabbix.com/search?searchw ... arch_cat=1
From my experience none of them are perfect without some modifications. Just experiment.
by karlisi
Thu Jul 20, 2017 11:34 am
Forum: Beginner Basics
Topic: Is it possible to script when Wireless WLAN comes on?
Replies: 14
Views: 1111

Re: Is it possible to script when Wireless WLAN comes on?

What exactly is not working?
by karlisi
Mon Jul 03, 2017 11:30 am
Forum: Beginner Basics
Topic: Routing requests from LAN back into LAN
Replies: 29
Views: 11253

Re: Routing requests from LAN back into LAN

You should add address list entry exactly as said, using DNS name not IP address
/ip firewall address-list
add address=sam9s.synology.me list=host_synology
If router have correct DNS entries (IP -> DNS), it will resolve IP address and add them to this entry.
Then address_list will work correctly.
by karlisi
Wed Jun 21, 2017 10:24 am
Forum: RouterBOARD hardware
Topic: Repair of RB2011UAS-2HiD-IN
Replies: 1
Views: 521

Re: Repair of RB2011UAS-2HiD-IN

Ask Your distributor.
https://mikrotik.com/rma
by karlisi
Wed Jun 21, 2017 8:43 am
Forum: RouterBOARD hardware
Topic: USB Battery to power routerboard
Replies: 18
Views: 2803

Re: USB Battery to power routerboard

Thank you all for your responses. I was hoping to use the main grid to power the devices and when the power went down shift to the usb battery. So we would not need to be charging the batteries and using them at the same time. Sure, You can, but You should go to device and plug in this battery ever...
by karlisi
Tue Jun 13, 2017 2:54 pm
Forum: Beginner Basics
Topic: Block DST-NAT RDS Users
Replies: 10
Views: 1594

Re: Block DST-NAT RDS Users

There is something wrong with configuration. Post your configuration /ip firewall filter export and /ip firewall nat export here.
by karlisi
Fri May 12, 2017 9:09 am
Forum: Wireless Networking
Topic: CAPsMAN Setup Advice Please
Replies: 9
Views: 1355

Re: CAPsMAN Setup Advice Please

One suggestion - don't use 'capsman' as name for bridge, it can bring some confusion later. Actually this bridge serves as interface for entire LAN not only for CAPsMAN.
by karlisi
Fri May 12, 2017 9:04 am
Forum: Wireless Networking
Topic: CAPsMAN Setup Advice Please
Replies: 9
Views: 1355

Re: CAPsMAN Setup Advice Please

No, remove this address from ether1 and assign to bridge. Bridge is the master interface for included interfaces (ether1). In configuration You should use master interfaces, not slaves.
by karlisi
Thu May 11, 2017 1:28 pm
Forum: Wireless Networking
Topic: CAPsMAN Setup Advice Please
Replies: 9
Views: 1355

Re: CAPsMAN Setup Advice Please

Also LAN side IP address should be assigned to bridge and DHCP server should give addresses to bridge not to ether1.
by karlisi
Thu May 11, 2017 10:01 am
Forum: General
Topic: Policy-based routing with dual WAN - Mikrotik update fails
Replies: 5
Views: 1430

Re: Policy-based routing with dual WAN - Mikrotik update fails

Are configured DNS servers accessible trough both WAN interfaces?
by karlisi
Mon May 08, 2017 10:59 am
Forum: General
Topic: RDP Problem behind Mikrotik
Replies: 4
Views: 1684

Re: RDP Problem behind Mikrotik

Are You using default RDP port 3389 on server 192.168.1.252 when connecting from inside network and want to connect to port 4001 from outside? If so, rule should be
chain=dstnat action=dst-nat to-addresses=192.168.1.252 to-ports=3389 
      protocol=tcp dst-port=4001
by karlisi
Thu Feb 16, 2017 10:09 am
Forum: General
Topic: SFP Interfaces
Replies: 3
Views: 837

Re: SFP Interfaces

You should use similar SFP modules on both ends of optical link. These modules are very different, S+85DLC03D is 10Gbps 850nm multi mode, S-31DLC20D is 1.25Gbps 1310nm single mode.
by karlisi
Wed Feb 15, 2017 4:28 pm
Forum: Beginner Basics
Topic: Scheduling a script whose content is in the scripts/ directory
Replies: 5
Views: 2016

Re: Scheduling a script whose content is in the scripts/ directory

AFAIK .rsc scripts are for configuration tasks only. If you need run script on regular basis, make new script under /system scripts, then schedule it with /system schedule as Chris wrote. More about scripting in RouterOS see in Wiki http://wiki.mikrotik.com/wiki/Manual:Scripting http://wiki.mikrotik...
by karlisi
Wed Feb 15, 2017 9:31 am
Forum: Scripting
Topic: Synch Address-lists with Master Router
Replies: 4
Views: 752

Re: Synch Address-lists with Master Router

There is topic on this forum about blacklisting, You can use this or use it for Your own solution
Blacklist Filter update script
by karlisi
Tue Feb 14, 2017 2:14 pm
Forum: General
Topic: Access local servers on same subnet.
Replies: 6
Views: 648

Re: Access local servers on same subnet.

Perhaps not Mikrotik problem. Connect to servers directly without router and check if it works.
by karlisi
Fri Feb 03, 2017 9:41 am
Forum: Announcements
Topic: Winbox 3.10 released!
Replies: 70
Views: 39919

Re: Winbox 3.10 released!

Winbox 3.x is OK, only one problem which I have is - durig upload file (for example new Router OS) is not posible working in active window.
After file is uploaded, then is possible working.
In winbox 2.2.18 this works. Can you fix it?
+1
This is very annoying on slow connections.
by karlisi
Fri Jan 20, 2017 8:32 am
Forum: General
Topic: RB2011uias-RM Redundant Power Supply with Internal PSU and external PSU
Replies: 9
Views: 1583

Re: RB2011uias-RM Redundant Power Supply with Internal PSU and external PSU

It is possible to use two power sources, though it is not supported by manufacturer, of course. Connect both power sources trough diodes like 1N4002 - 1N4007. Anodes to power sources, cathodes connected together and to external power input of RB. Disclaimer: I am not responsible if You damage someth...
by karlisi
Thu Dec 22, 2016 8:17 am
Forum: Beginner Basics
Topic: Configuring TR-069 CWMP
Replies: 1
Views: 984

Re: Configuring TR-069 CWMP

It's added in 6.38rc24 (2016-Nov-03 13:01):
!) tr069-client - initial implementation (as separate package);
by karlisi
Tue Dec 13, 2016 8:50 am
Forum: General
Topic: Help. both LAN and WLAN must have internet connection.
Replies: 4
Views: 500

Re: Help. both LAN and WLAN must have internet connection.

Your interface WAN2 have no IP address assigned.
by karlisi
Tue Nov 22, 2016 9:31 am
Forum: Beginner Basics
Topic: help
Replies: 1
Views: 303

Re: help

At first read tthe documentation http://wiki.mikrotik.com/wiki/Manual:RouterOS_FAQ I have a rb951g-2hnd router, I want to have two wan, does it work? Yes I want to use it as an antivirus, does it work? No I want to back up the network, does it work? ??? Please explain what You mean by this I want to...
by karlisi
Mon Nov 21, 2016 4:45 pm
Forum: Beginner Basics
Topic: How To Stop Attack to Server And Control User internet Usage
Replies: 8
Views: 2960

Re: How To Stop Attack to Server And Control User internet Usage

Make sure in server network settings there are only internal DNS server IP addresses. AD DC should not know about any external DNS servers. To access Internet resources there should be forwarders configured on DNS server.
by karlisi
Wed Nov 09, 2016 2:36 pm
Forum: Beginner Basics
Topic: Multi WAN on same Gateway
Replies: 3
Views: 623

Re: Multi WAN on same Gateway

Plese post Your configuration export /ip firewall nat
by karlisi
Wed Nov 09, 2016 11:16 am
Forum: Beginner Basics
Topic: Multi WAN on same Gateway
Replies: 3
Views: 623

Re: Multi WAN on same Gateway

Try this add action=src-nat chain=srcnat out-interface=WAN1 src-address=192.168.1.0/24 \ to-addresses=10.0.0.1 add action=src-nat chain=srcnat out-interface=WAN2 src-address=192.168.2.0/24 \ to-addresses=10.0.0.2 add action=src-nat chain=srcnat out-interface=WAN3 src-address=192.168.3.0/24 \ to-addr...
by karlisi
Wed Nov 09, 2016 10:59 am
Forum: Beginner Basics
Topic: CAPsMAN begginer
Replies: 2
Views: 508

Re: CAPsMAN begginer

In CAPsMAN leave channel not configured, APs will choose channels automatically.
by karlisi
Wed Nov 02, 2016 9:33 am
Forum: Announcements
Topic: v6.36.4 [bugfix] is released!
Replies: 51
Views: 15009

Re: v6.36.4 [bugfix] is released!

Thanks for the link, it is really useful. But as I said before: I don't care about many changes let's say in 6.35.4 which are fixing 6.35.3 bugs, I just need to see summary of changes from 6.34.6 to 6.36.4.
Agree to this. Consolidated changelog for bugfix versions would be very useful.
by karlisi
Fri Oct 28, 2016 9:27 am
Forum: Announcements
Topic: v6.36.4 [bugfix] is released!
Replies: 51
Views: 15009

Re: v6.36.4 [bugfix] is released!

The same. On some devices upgrade to newest bugfix is available, on some not, regardless of currently installed version or processor type.
by karlisi
Wed Oct 26, 2016 2:11 pm
Forum: Virtualization
Topic: CHR on bare metal
Replies: 13
Views: 2452

Re: CHR on bare metal

A single licensing scheme would be nice. Something to the effect of this: You purchase X number of licenses, which are tracked through a support portal. When you install an instance of ROS (virtual or bare metal), you input a key obtained from the support portal that is linked to your account. The ...
by karlisi
Tue Oct 18, 2016 10:57 am
Forum: Wireless Networking
Topic: mikrotik access point / controlling on the time of wireless authentication
Replies: 20
Views: 3324

Re: post to the support of the mikrotik

Try this
/interface wireless access-list
add interface=wlan1 mac-address=00:23:4D:76:8F:F5
add interface=wlan1 mac-address=00:23:4D:76:8F:F5 time=8h-20h,sun,mon,tue,wed,thu,fri,sat \
    vlan-mode=no-tag
by karlisi
Mon Oct 03, 2016 9:49 am
Forum: Wireless Networking
Topic: Capsman Host cannot see host
Replies: 1
Views: 407

Re: Capsman Host cannot see host

Enable client to client forwarding in Capsman datapath.
by karlisi
Wed Sep 28, 2016 4:55 pm
Forum: Forwarding Protocols
Topic: Mikrotik SMTP Traffic block except mail server
Replies: 3
Views: 1129

Re: Mikrotik SMTP Traffic block except mail server

It should work. Post Your firewall rules here.
by karlisi
Wed Sep 28, 2016 2:46 pm
Forum: Forwarding Protocols
Topic: Mikrotik SMTP Traffic block except mail server
Replies: 3
Views: 1129

Re: Mikrotik SMTP Traffic block except mail server

chain=forward protocol=tcp src-address=172.16.5.5 dst-port=25 action=accept
chain=forward protocol=tcp src-address=172.16.5.0/24 dst-port=25 action=drop
by karlisi
Thu Sep 22, 2016 9:54 am
Forum: Beginner Basics
Topic: Upgrade Firmware for Mikrotik Router
Replies: 2
Views: 620

Re: Upgrade Firmware for Mikrotik Router

AFAIK no impact on configuration. All my CCR1009 running 2.37 firmware without problems.
by karlisi
Mon Sep 19, 2016 10:01 am
Forum: Beginner Basics
Topic: help needed IP phone VLAN
Replies: 13
Views: 1579

Re: help needed IP phone VLAN

Have You srcnatted bridgetel? It is separate interface, check firewall rules for it. In general they should be the same as for bridge-local.
by karlisi
Mon Sep 12, 2016 9:37 am
Forum: Virtualization
Topic: CHR feature requests
Replies: 55
Views: 9666

Re: CHR feature requests

Support for Citrix XenServer.
by karlisi
Mon Sep 05, 2016 9:23 am
Forum: Wireless Networking
Topic: Upgrading APs in CAPsMAN configuration
Replies: 1
Views: 990

Re: Upgrading APs in CAPsMAN configuration

If You can connect via Winbox, upgrade using it (download from Mikrotik site to workstation, copy/paste to Winbox -> Files, then reboot router).
by karlisi
Thu Jul 28, 2016 9:34 am
Forum: General
Topic: Mikrotik rb1100 only giving internet to 5 devices.
Replies: 4
Views: 634

Re: Mikrotik rb1100 only giving internet to 5 devices.

Are You sure all these addresses from dhcp pool are Yours? They are public addresses and typically not used for internal LANs. From configuration I guess Your public addressses are 12.175.41.48/29 which means 6 IP addresses in total, one for gateway and 5 addresses left for computers.
by karlisi
Mon Jul 25, 2016 11:59 am
Forum: Beginner Basics
Topic: Mikrotik Router dhcp-client on wan (ether1) interface
Replies: 1
Views: 3557

Re: Mikrotik Router dhcp-client on wan (ether1) interface

I think dhcp-client section should look like this
/ip dhcp-client
add add-default-route=yes default-route-distance=0 dhcp-options=hostname,clientid interface=eth1
Now You have eth9 defined as dhcp client interface
by karlisi
Fri Jul 22, 2016 9:29 am
Forum: Beginner Basics
Topic: error : dhcp offering lease without success ?
Replies: 7
Views: 3220

Re: error : dhcp offering lease without success ?

I have not any static DHCP entries.
by karlisi
Thu Jul 21, 2016 12:43 pm
Forum: Beginner Basics
Topic: error : dhcp offering lease without success ?
Replies: 7
Views: 3220

Re: error : dhcp offering lease without success ?

No, different hardware, Windows laptops, Samsung smartphones with different Android versions.
by karlisi
Thu Jul 21, 2016 10:09 am
Forum: Beginner Basics
Topic: error : dhcp offering lease without success ?
Replies: 7
Views: 3220

Re: error : dhcp offering lease without success ?

I've seen this error appearing on my networks and after some investigation concluded it's something on client side.One day this error appears on one client regardless of site. Next day this client is OK.It never appears if client is connected by wire, only if wirelessly.
by karlisi
Thu Jul 21, 2016 10:00 am
Forum: General
Topic: Help setting up Capsman
Replies: 7
Views: 1173

Re: Help setting up Capsman

/caps-man channel
add band=2ghz-onlyn extension-channel=Ce frequency=2412 name=channel1 tx-power=30 width=20
add band=5ghz-a/n/ac extension-channel=Ceee frequency=5210 name=channel42 tx-power=10 width=20
Remove frequency from channel settings, it will let CAPs themselves choose the best channel.
by karlisi
Thu Jul 21, 2016 9:49 am
Forum: General
Topic: Capsman install help?
Replies: 4
Views: 589

Re: Capsman install help?

Use cm2, fp will be discontinued.
by karlisi
Mon Jul 18, 2016 4:44 pm
Forum: Beginner Basics
Topic: No internet access after configuring DHCP and a few other questions
Replies: 7
Views: 872

Re: No internet access after configuring DHCP and a few other questions

Add this before other forward chain rules
/ip firewall filter
add chain=forward connection-state=established,related
by karlisi
Thu Jul 07, 2016 8:31 am
Forum: General
Topic: CAPSMan v2 - monitoring channels
Replies: 2
Views: 1043

Re: CAPSMan v2 - monitoring channels

Winbox -> Capsman -> Interfaces, column Current Channel
by karlisi
Wed Jun 08, 2016 1:01 pm
Forum: General
Topic: IPv4 Addresses Change Interfaces
Replies: 6
Views: 818

Re: IPv4 Addresses Change Interfaces

Perhaps interfaces ether2 to ether4 are in bridge-local?
by karlisi
Mon May 30, 2016 3:28 pm
Forum: General
Topic: PPTP
Replies: 2
Views: 354

Re: PPTP

You should disable 'Use default gateway on remote network' option in VPN settings on client computer.
How to
by karlisi
Thu May 12, 2016 10:00 am
Forum: Beginner Basics
Topic: Beginner Basics
Replies: 4
Views: 774

Re: Beginner Basics

by karlisi
Fri Mar 11, 2016 9:30 am
Forum: General
Topic: how to remote controlled router mikrotik behind another router
Replies: 26
Views: 4006

Re: how to remote controlled router mikrotik behind another router

If You don't need access from outside to routerA, problem is solved.
RouterA will be inaccessible because connections from Internet to any port on routerA will be redirected to routerB. The idea of my slution was to give access to routerB keeping access to routerA.
by karlisi
Thu Mar 10, 2016 12:50 pm
Forum: General
Topic: how to remote controlled router mikrotik behind another router
Replies: 26
Views: 4006

Re: how to remote controlled router mikrotik behind another router

So i won't be able to connect to routerB from other network outside of routerA ???
I don't mean physically accessible. If You can connect to router A from outside, also router B will be accessible.
by karlisi
Thu Mar 10, 2016 10:46 am
Forum: General
Topic: how to remote controlled router mikrotik behind another router
Replies: 26
Views: 4006

Re: how to remote controlled router mikrotik behind another router

Thanks for your replied. If i config like that i will be able to connect to routerB wherever i go right ? what about DNS name in ip cloud ? Can i use it ? i couldn't not test it right now :( I think yes, DNS name should work, if resolved correctly. And yes, You will be able connect to router B from...
by karlisi
Wed Mar 09, 2016 2:43 pm
Forum: General
Topic: how to remote controlled router mikrotik behind another router
Replies: 26
Views: 4006

Re: how to remote controlled router mikrotik behind another router

At first You should give router B, interface ether1 fixed IP address, i.e. 172.16.10.2, else it will not work, except You made reservation in router A DHCP server for router B (very probably, not). Second, if You want to connect to it with Winbox, here is dst-nat rule for router A /ip firewall nat a...
by karlisi
Thu Feb 25, 2016 10:40 am
Forum: General
Topic: wiki firewall update
Replies: 2
Views: 805

Re: wiki firewall update

i got some firewall filters that i add from the wiki: http://wiki.mikrotik.com/wiki/Securing_your_router i got a error in the line icmp: "/ip firewall filter> add chain=input protocol=icmp limit=50/5s,2 comment="Allow limited pings" expected : (line 1 column 44)" Have You copy/paste the script from...
by karlisi
Thu Feb 18, 2016 8:51 am
Forum: Beginner Basics
Topic: TikTool for MikroTik
Replies: 10
Views: 1744

Re: TikTool for MikroTik

Sorry for misinterpretation.
by karlisi
Wed Feb 17, 2016 8:42 am
Forum: Beginner Basics
Topic: TikTool for MikroTik
Replies: 10
Views: 1744

Re: TikTool for MikroTik

:-)
I dont understand because its declared by Kiawe that TikTool alows to manage/admin MikroTik routers...isnt it?
I can declare my SuperManagementTool works with Microsoft Server, does it mean it is supported by Microsoft?
by karlisi
Mon Feb 15, 2016 9:27 am
Forum: Beginner Basics
Topic: TikTool for MikroTik
Replies: 10
Views: 1744

Re: TikTool for MikroTik

TikTool - Mobile Winbox
By Kiawe Tech, LLC


As said already, not developed or supported by MikroTik.
by karlisi
Mon Feb 15, 2016 9:20 am
Forum: Forwarding Protocols
Topic: Internet Not allow client use to pop and smtp mail server use outlook.
Replies: 1
Views: 886

Re: Internet Not allow client use to pop and smtp mail server use outlook.

Firewall rules are applied from top, your third rule drops all connections from MailAllow address list and next two rules are not in effect. To allow connections to ports 110 and 25 (SMTP port is 25, not 26) and block all other connections add action=drop chain=forward src-address-list=MailAllow sho...
by karlisi
Fri Feb 12, 2016 9:09 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 102068

Re: CAPsMAN v2 ready for testing

You can use any bridge if You integrate CAPsMAN in existing network.
by karlisi
Tue Feb 02, 2016 12:03 pm
Forum: Beginner Basics
Topic: Problem with basic CAPsMAN configuration
Replies: 8
Views: 9080

Re: Problem with basic CAPsMAN configuration

Sorry, I have no ideas. Only difference from me I see is, You added wlan1 to bridge1 in /interface bridge and also in /capsman datapath. I have only second one.
by karlisi
Mon Feb 01, 2016 9:42 am
Forum: Beginner Basics
Topic: Problem with basic CAPsMAN configuration
Replies: 8
Views: 9080

Re: Problem with basic CAPsMAN configuration

What if You set discovery interface to Eth1? This is my working configuration for RB2011UiAS-2HnD with CAPsMAN and CAP enabled (interface LAN is a bridge containing all Ethernet ports, excluding Internet): /interface wireless cap set discovery-interfaces=LAN enabled=yes interfaces=wlan1 /caps-man ma...
by karlisi
Fri Jan 29, 2016 2:11 pm
Forum: Beginner Basics
Topic: Problem with basic CAPsMAN configuration
Replies: 8
Views: 9080

Re: Problem with basic CAPsMAN configuration

To deliver your configuration to APs you shoud make at least one provision rule, i.e.:
/caps-man provisioning
add action=create-dynamic-enabled master-configuration=Config1 name-format=identity
by karlisi
Fri Jan 08, 2016 1:37 pm
Forum: Beginner Basics
Topic: CaPsMAN wlan interface on/off with sheduler SOLVED
Replies: 4
Views: 2034

Re: CaPsMAN wlan interface on/off with sheduler

You should enable or disable provisioning rules, not configurations. If You have first rule with both wlans and second rule wih wlan1 only, then first script enables first rule and second script disables it. /caps-man provisioning enable 0 :delay 1 /caps-man radio provision numbers=[find] /caps-man ...
by karlisi
Fri Jan 08, 2016 11:07 am
Forum: Beginner Basics
Topic: CaPsMAN wlan interface on/off with sheduler SOLVED
Replies: 4
Views: 2034

Re: CaPsMAN wlan interface on/off with sheduler

In CAPsMAN configuration create 2 configurations - one for wlan1, another for wlan2.
In provisioning create 2 rules, one with both wlans, one with wlan1 only.
Create 2 scripts and corresponding schedules - one will enable the first configuration, another will disable the first configuration.
by karlisi
Fri Jan 08, 2016 10:53 am
Forum: RouterBOARD hardware
Topic: RB260GSP POE max output?
Replies: 2
Views: 1384

Re: RB260GSP POE max output?

CRS power consumption seems OK, but You should test it. The lowest supported input voltage for CRS125-24G is 8 V, it means current about 1.9 A if power consumption is 15 W.
by karlisi
Fri Nov 13, 2015 9:13 am
Forum: Beginner Basics
Topic: Traffic between builtin radio and ethernet in bridge are skipping bridge
Replies: 2
Views: 753

Re: Traffic between builtin radio and ethernet in bridge are skipping bridge

AFAIK if interfaces are in the same bridge they aren't processed by forward chain.
by karlisi
Wed Nov 11, 2015 4:01 pm
Forum: Wireless Networking
Topic: wireless-fp vs wireless-cm2
Replies: 5
Views: 3538

Re: wireless-fp vs wireless-cm2

I am using it because of CAPsMAN v2. We can't resolve traffic forwarding problem if AP and CAPsMAN controller are on the same device with CAPsMAN v1 from wireless-fp package.
by karlisi
Fri Nov 06, 2015 1:09 pm
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 1737

Re: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

Blocked outgoing? Just guess, DHCP uses UDP, perhaps You forgot it? It would be easier if You will give
/ip firewall filter print
and
/ip dhcp-client print
here.
by karlisi
Thu Nov 05, 2015 9:46 am
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 1737

Re: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

Hello, today I tried to block everything except Winbox port. 1) When I rebooted the RB2011 the WAN port got an IP from the DHCP server. Why is it possible for the WAN port to request an IP (discover to 255.255.255.255) when everything is blocked by firewall rules? The WAN port can enter <requesting...
by karlisi
Wed Oct 28, 2015 4:08 pm
Forum: Wireless Networking
Topic: CApsMAN problem
Replies: 13
Views: 2135

Re: CApsMAN problem

Here it is my configuration, but I don't know how to determine my capsman version. I suppose it should be the embedded version of the router firmware mipsbe v6.25 . Look in /system/packages wireless-cm2 -> CAPsMAN v.2 wireless-fp -> CAPsMAN v.1 (not recommended) Be sure router and all AP have the s...
by karlisi
Wed Oct 28, 2015 3:58 pm
Forum: General
Topic: firewall/connections - what does the first column mean
Replies: 5
Views: 5647

Re: firewall/connections - what does the first column mean

[admin@] /ip firewall connection> print
Flags: E - expected, S - seen-reply, A - assured, C - confirmed, D - dying, F - fasttrack, 
s - srcnat, d - dstnat 
by karlisi
Wed Oct 28, 2015 3:51 pm
Forum: Beginner Basics
Topic: Dual wan with load balancing
Replies: 4
Views: 1129

Re: Dual wan with load balancing

From my experience, with dynamic WAN You are out of luck. In some examples there are interface names in routes instead of gateway IP, I tried this without success.
by karlisi
Fri Oct 09, 2015 10:41 am
Forum: Beginner Basics
Topic: Question regarding firewall rules and NAT
Replies: 2
Views: 508

Re: Question regarding firewall rules and NAT

3 chain=dstnat action=dst-nat to-addresses=10.0.0.104 to-ports=25 protocol=tcp in-interface=ether5 dst-port=25 log=no log-prefix="" What if You modify NAT rule? chain=dstnat action=dst-nat to-addresses=10.0.0.104 to-ports=25 protocol=tcp in-interface=ether5 dst-port=25 log=no log-prefix="" src-addr...
by karlisi
Wed Sep 30, 2015 10:32 am
Forum: General
Topic: Different Option in CAPsMAN Provisioning
Replies: 2
Views: 540

Re: Different Option in CAPsMAN Provisioning

The first is from CAPsMAN version 1 (wireless-fp package), second fron version 2 (wireless-cm2 package).
by karlisi
Thu Sep 10, 2015 1:14 pm
Forum: Wireless Networking
Topic: CAPsMAN and 4 CAP devices
Replies: 13
Views: 2273

Re: CAPsMAN and 4 CAP devices

I don't get it. Only thing I can imagine that could be problem is that those 2 devices were configured to work before I bought another 3 (RB750 and 2 RB951). They had 6.1 version and it was CAPsMAN v2 on them installed. Then I configured new ones and just tried to reconfigure that devices and conne...
by karlisi
Thu Sep 10, 2015 1:05 pm
Forum: Wireless Networking
Topic: CAPsMAN and 4 CAP devices
Replies: 13
Views: 2273

Re: CAPsMAN and 4 CAP devices

Have You tried to create at least one provisioning rule?
http://wiki.mikrotik.com/wiki/Manual:CA ... ovisioning
by karlisi
Wed Aug 12, 2015 1:49 pm
Forum: General
Topic: how to configure seagate NAS in microtik router?
Replies: 2
Views: 495

Re: how to configure seagate NAS in microtik router?

In winbox go to DHCP Server -> Leases, find already assigned lease for your device, righ-click on it and in menu click Make Static. If IP address should be different from automatically assigned, open this lease with doubleclick and edit IP address. It must be in DHCP address range. Then restart NAS ...
by karlisi
Wed Aug 05, 2015 8:12 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 102068

Re: CAPsMAN v2 ready for testing

We are running CAPsMAN v2 controllers on CCR1009 with no problems. Also have one on RB1100 (1 CPU), works OK. One difference, our controllers are traffic forwarders too.
by karlisi
Fri Jul 24, 2015 1:09 pm
Forum: Beginner Basics
Topic: RDP
Replies: 25
Views: 4052

Re: RDP

First place to learn about RouterOS is Mikrotik Wiki, there are many examples. About firewall here
by karlisi
Fri Jul 24, 2015 9:14 am
Forum: Beginner Basics
Topic: RDP
Replies: 25
Views: 4052

Re: RDP

Do you have the same rule in forward chain?
by karlisi
Thu Jul 23, 2015 3:34 pm
Forum: Wireless Networking
Topic: CAPSMAN prevent clients from automatically connecting
Replies: 2
Views: 406

Re: CAPSMAN prevent clients from automatically connecting

Under 'Access List' create rules for each allowed client with action=accept and one last rule with action=reject for all clients.
by karlisi
Thu Jul 23, 2015 1:44 pm
Forum: Beginner Basics
Topic: RDP
Replies: 25
Views: 4052

Re: RDP

NAT is OK. Post
/ip firewall filter print chain=input
by karlisi
Wed Jul 22, 2015 2:04 pm
Forum: General
Topic: DNS is changing to 195.3.144.115
Replies: 6
Views: 657

Re: DNS is changing to 195.3.144.115

It can be some malware, this IP address belongs to RN Data SIA (195.3.144.0/22) and it is connected with ZeroAccess Botnet.
by karlisi
Tue Jul 21, 2015 9:58 am
Forum: Beginner Basics
Topic: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall
Replies: 17
Views: 1612

Re: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall

So, back to OP. I discovered if i connect my Laptop (is connected only wired) directly with the cisco my Internet (50Mbit) runs like speedy Gonzales, but when i have also connected my Router with my Laptop loading Internet sites take for instance a few seconds more. In the house i have also 2 Intern...
by karlisi
Tue Jul 21, 2015 7:58 am
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 4690

Re: Creating a Single Blacklist of Multiple IP

AFAIK this is not possible, address lists are made from separate entries for each address. This form is more manageable as one entry with multiple values.
by karlisi
Mon Jul 20, 2015 10:08 am
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 4690

Re: Creating a Single Blacklist of Multiple IP

Your firewall rule uses address-list, there is no need for more rules. In Blacklist address list you will put all addresses to be blocked by this rule. Like this /ip firewall filter add action=drop chain=input comment="drop blacklisted addresses" \ src-address-list=Blacklist disabled=no /ip firewall...
by karlisi
Fri Jul 17, 2015 9:27 am
Forum: Beginner Basics
Topic: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall
Replies: 17
Views: 1612

Re: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall

OK, nothing wrong with bridge configuration.
I mentioned in Your first post there are no DNS servers configured. Please post /ip dns print output here.
by karlisi
Thu Jul 16, 2015 11:30 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 102068

Re: CAPsMAN v2 ready for testing

After successfull update there will be cm2 package file in /files, AFAIK it is for compatibility purposes, you can delete it, otherwise you will receive error "package already installed" on every reboot.
by karlisi
Thu Jul 16, 2015 11:26 am
Forum: Beginner Basics
Topic: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall
Replies: 17
Views: 1612

Re: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall

Nope, they're all in the bridge, therefore they are not standalone and are in the same L2 network. It says it *right here* in the code they posted: /interface bridge port add bridge=bridge-local interface=ether2 add bridge=bridge-local interface=ether3 add bridge=bridge-local interface=ether4 add b...
by karlisi
Thu Jul 16, 2015 8:20 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 102068

Re: CAPsMAN v2 ready for testing

where do I find cm2 package for 6.30 6.30.1?
didn't find it on the download page.
Starting from 6.30 it's included in main package.
by karlisi
Thu Jul 16, 2015 8:17 am
Forum: Beginner Basics
Topic: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall
Replies: 17
Views: 1612

Re: MikroTik_RB2011UiAS-2HnD-IN Internet Configuration + Firewall

Your bridge configuration is wrong and is causing your DHCP server to be exposed to the Internet interface where your cable modem lives. You have configured the 100Mb/s switch properly by the look of it, with ether6 as a master and ether7-10 as slaves. What I don't see is you configuring ports 2-5 ...
by karlisi
Tue Jul 14, 2015 8:42 am
Forum: Beginner Basics
Topic: Capsman controller problems
Replies: 4
Views: 684

Re: Capsman controller problems

There any way that if the controller fails, the wireless network continue working, as is the case with the driver Ubiquiti?
In my tests, if CAP loses connection to CAPsMAN, it shuts down the radio. So, You are right, CAPsMAN device availability is critical in such network.
by karlisi
Mon Jul 13, 2015 10:45 am
Forum: Beginner Basics
Topic: Capsman controller problems
Replies: 4
Views: 684

Re: Capsman controller problems

Yes, it's normal. Shutting down CAPsMAN disables wireless on CAP enabled devices which are managed by it.
by karlisi
Fri Jul 10, 2015 2:33 pm
Forum: General
Topic: Best way to move configuration to another router
Replies: 3
Views: 1155

Re: Best way to move configuration to another router

I would try to export -> edit configuration file -> import
Not easy because of different hardware and default configuration, sometimes building from scratch can be easier.
by karlisi
Fri Jul 10, 2015 8:48 am
Forum: General
Topic: [HOW] One DHCP for RB1100's two switch group
Replies: 2
Views: 375

Re: [HOW] One DHCP for RB1100's two switch group

Set DHCP for local bridge, not for port1
by karlisi
Thu Jul 09, 2015 8:25 am
Forum: Wireless Networking
Topic: Bad wireless reception with RB2011UAS-2HnD-IN
Replies: 50
Views: 20637

Re: Bad wireless reception with RB2011UAS-2HnD-IN

For me RB2011 (RouterOS version 6.27) wireless works OK, we have 6 sites with it. Have you tried 6.30rc, perhaps there are problems with 6.29? Dear thank you for your reply. I was looking in the forum for any issue with the 6.29.1 and didn't find anything. But will try 6.30rc. Could you share your ...
by karlisi
Wed Jul 08, 2015 11:24 am
Forum: Wireless Networking
Topic: Bad wireless reception with RB2011UAS-2HnD-IN
Replies: 50
Views: 20637

Re: Bad wireless reception with RB2011UAS-2HnD-IN

For me RB2011 (RouterOS version 6.27) wireless works OK, we have 6 sites with it. Have you tried 6.30rc, perhaps there are problems with 6.29?
by karlisi
Wed Jul 01, 2015 4:23 pm
Forum: Wireless Networking
Topic: Бесшовность сети при настройке CAPsMAN
Replies: 2
Views: 2395

Re: Бесшовность сети при настройке CAPsMAN

In access list add one more rule with action=reject and signal range -76..-120, put this rule as first.
by karlisi
Mon Jun 29, 2015 9:30 am
Forum: Wireless Networking
Topic: importing and exporting config files
Replies: 20
Views: 118007

Re: importing and exporting config files

All installed packages are the same? Because import goes as scripted, row by row, i would check all settings, beginning from first line. Where configuration is not changed, carefully inspect your script. For me typically there was some settings for non defined item, i.e., make new DHCP server where ...
by karlisi
Thu Jun 25, 2015 11:07 am
Forum: Wireless Networking
Topic: importing and exporting config files
Replies: 20
Views: 118007

Re: importing and exporting config files

If you want to import exported configuration, you should do it on empty device - no default configuration when doing full reset.
/system reset-configuration no-defaults=yes
You shoudn't use backup/restore to transfer configuration to another device.
by karlisi
Wed Jun 17, 2015 11:10 am
Forum: General
Topic: [Ask] NAT doesn't work
Replies: 3
Views: 890

Re: [Ask] NAT doesn't work

In mikrotik: /ip firewall nat add action=src-nat chain=srcnat src-address=192.168.1.0/24 to-addresses=\ x.x.x.2 add action=src-nat chain=srcnat src-address=192.168.2.3 to-addresses=\ x.x.x.3 add action=dst-nat chain=dstnat disabled=yes dst-address=x.x.x.3 \ dst-port=443 protocol=tcp to-addresses=19...
by karlisi
Tue Jun 16, 2015 9:07 am
Forum: RouterBOARD hardware
Topic: RB2011UiAS-2HnD-IN and USB connected APC Back UPS CS 500
Replies: 2
Views: 1078

Re: RB2011UiAS-2HnD-IN and USB connected APC Back UPS CS 500

You need SmartUPS for this.

From RouterOS manual:
"The UPS monitor feature works with APC UPS units that support “smart” signalling over serial RS232 or USB connection"

From APC BackUPS CS 500 technical specification:
"Simple Signalling RS232 cable, USB"
by karlisi
Thu May 21, 2015 1:08 pm
Forum: Wireless Networking
Topic: Capsman, no ping
Replies: 2
Views: 736

Re: Capsman, no ping

Hello, please, help. I configure capsman with 2 SSID for staff and guest. Mode Local forfarding. All it's work. Wireless clients staff dont see clients guest, but wireless clients can't see each other inside staff network.
Enable client-to-client forwarding for staff network.
by karlisi
Tue May 19, 2015 10:20 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 102068

Re: CAPsMAN v2 ready for testing

Hi!

Where can I get package of CAPsMan v2 for 6.29 (RC20)? in all_files is not there..

Thank you.
http://www.mikrotik.com/download/share/ ... mipsbe.npk

Change "mispbe" with you router architecture.
by karlisi
Mon May 18, 2015 10:09 am
Forum: General
Topic: Winbox 3 RC
Replies: 639
Views: 123967

Re: Winbox 3 RC

1. "taskbar" for windows inside winbox. Now bigger windows cover smaller all the time. All admins I talk to are pissed of because of this.
Or at least 'Windows' menu where we can see all open sub-windows and switch between them.
by karlisi
Wed May 13, 2015 3:22 pm
Forum: Announcements
Topic: RouterOS v6.28 released
Replies: 229
Views: 62064

Re: RouterOS v6.28 released

2. now i use wireless-fp to use capsman, and i got 2 routers in configuration, and i got 2 bridges in master router i got datapath1 configurated to add all master-wifi's in first bridge_work and cap on master router did it, but no packets pass through router to, even when cap is in bridge_work, ine...
by karlisi
Wed Apr 08, 2015 9:22 am
Forum: Beginner Basics
Topic: CapsManager on CCR1009
Replies: 2
Views: 531

Re: CapsManager on CCR1009

Yes. Actually I am using this exact router as CAPsMAN in some places. You don't need wireless on-board for this.
by karlisi
Thu Apr 02, 2015 11:33 am
Forum: Beginner Basics
Topic: Load Balancing Questions and Help
Replies: 14
Views: 1721

Re: Load Balancing Questions and Help

In Winbox open Interface list, open ether3, in Master Port choose 'none'. Then open ether4 and ether5, and change master port to ether3. If I remember correctly, You will need configure them twice, choosing 'none' at first, because MikroTik allows only one master port per switch.
by karlisi
Fri Feb 17, 2006 7:40 am
Forum: General
Topic: What version of MikroTik do you use?
Replies: 17
Views: 2770

Ooops, double post :)
by karlisi
Fri Feb 17, 2006 7:40 am
Forum: General
Topic: What version of MikroTik do you use?
Replies: 17
Views: 2770

I am using 2.7 and I am happy :) Why fix if nothing is broken... why? first - you cant get support or help from forums :) Why worry about support if all works :D Of course, there are many new features in latest versions, but they are not critical for my network, so... MT should be proud if older ve...
by karlisi
Thu Feb 16, 2006 7:34 am
Forum: General
Topic: What version of MikroTik do you use?
Replies: 17
Views: 2770

I am using 2.7 and I am happy :)
Why fix if nothing is broken...
by karlisi
Thu Nov 10, 2005 7:56 am
Forum: General
Topic: Syslog by Mikrotik !!!
Replies: 5
Views: 1428

Kiwi works great on Windows. Free version have many restrictions so you might want to buy it.
by karlisi
Wed Aug 17, 2005 7:18 am
Forum: Scripting
Topic: How to schedule by winbox ?
Replies: 12
Views: 4158

Perhaps two schedules - 0am to 10am and 10pm to 12pm
by karlisi
Fri Mar 04, 2005 8:03 am
Forum: General
Topic: web proxy and password protected websites
Replies: 2
Views: 1120

Its by design. From RouterOS manual:
"Only HTTP traffic is supported in web proxy transparent mode. HTTPS and FTP are not going to work this way."
http://www.mikrotik.com/docs/ros/2.8/ip ... xy.content
by karlisi
Sun Nov 14, 2004 10:37 am
Forum: General
Topic: NTP server issue
Replies: 1
Views: 972

Yes, you can. You dont need additional firewall rules or services. You need NTP package loaded on Mikrotik and NTP server. In NTP client configuration define NTP servers to synchronize with and enable unicast mode. You can find a list of public time servers here http://ntp.isc.org/bin/view/Servers/W...