Community discussions

MikroTik App

Search found 56 matches

by cholegm
Tue Dec 12, 2017 4:00 pm
Forum: General
Topic: CRS326-24G-2S+ with RouterOS - Switch and VLAN configuration
Replies: 1
Views: 776

Re: CRS326-24G-2S+ with RouterOS - Switch and VLAN configuration

I forgot to say that I use last stable 6.40.5 version. I tried also with version 6.41rc61 because new hw-offload configuration in bridge settings and than nothing was working (conf. from wiki). Example, after setting VLAN filtering = yes I get lost communication with switch. Print command in bridge ...
by cholegm
Tue Dec 12, 2017 12:20 pm
Forum: General
Topic: CRS326-24G-2S+ with RouterOS - Switch and VLAN configuration
Replies: 1
Views: 776

CRS326-24G-2S+ with RouterOS - Switch and VLAN configuration

Hi, Can somebody explain me why switch configuration of CRS326-24G-2S+ is totally different than on models CRS125-24G-1S or CRS112-8G-4S? I have almost same configuration (CRS326-24G-2S+ don't have same options) on each one, but on CRS326-24G-2S+ I have not communication between hosts on ethernet po...
by cholegm
Fri Mar 08, 2013 3:13 pm
Forum: Scripting
Topic: Dynamic DNS Update Script for ChangeIP.com - two ISP
Replies: 0
Views: 3439

Dynamic DNS Update Script for ChangeIP.com - two ISP

This is dynamic DNS update script for ChangeIP.com with some my changes. I added auto adding of route to ChangeIP.com update server. This is need in case when you have two ISP, one with static IP and second with dynamic IP. # Set your specific ChangeIP.com preferences here. :global ddnsuser "YourCha...
by cholegm
Tue Dec 04, 2012 5:11 pm
Forum: Beginner Basics
Topic: Attached: Mikrotik Visio Stencils
Replies: 31
Views: 87487

Re: Attached: Mikrotik Visio Stencils

Some new MikroTik Visio Stencils...
  • MikroTik RouterBoard 750
    MikroTik RouterBoard 750GL
    MikroTik RouterBoard 450G
    MikroTik RouterBoard 1200
    MikroTik RouterBoard RB2011UAS-RM
    MikroTik RouterBoard 1100AH
    MikroTik RouterBoard 1100AHx2
    MikroTik Cloud Core Router CCR1036-12G-4S
Regards,
Mladen
by cholegm
Mon Aug 02, 2010 3:59 pm
Forum: General
Topic: Installing Proxylizer... PHP error!?
Replies: 1
Views: 1131

Installing Proxylizer... PHP error!?

Hi, I'm just install and configure Proxylizer on the CentOS 5 operating system. I did everything as it should according to instructions (http://wiki.mikrotik.com/wiki/Proxylizer/Getting_Started#Install_method_1) but I have a problem ... When try to access http://ipaddress_of_server/proxylizer/ I get...
by cholegm
Thu Jun 03, 2010 5:48 pm
Forum: General
Topic: API - HotSpot Active Users
Replies: 1
Views: 1013

Re: API - HotSpot Active Users

I find solution... :) In versions from 3.22 to 4.6 i use (in PHP) $API->write('/ip/hotspot/active/print'); $ARRAY = $API->read(); And my result was: [0] => Array ( [.id] => *304A8C0 [server] => ****** [user] => ****** [address] => ****** [mac-address] => ****** [login-by] => http-chap [uptime] => 00...
by cholegm
Thu Jun 03, 2010 4:00 pm
Forum: General
Topic: API - HotSpot Active Users
Replies: 1
Views: 1013

API - HotSpot Active Users

I'm using API with command "/ip/hotspot/active/print" to get statistic from my HotSpot servers. In statistic I have server, username, address, mac-address, uptime, bytes-in, bytes-out. And everything works fine from v3.22 to v4.6 RouterOS. This is array from v3.22 to v4.6 RouterOS. [0] => Array ( [....
by cholegm
Thu May 28, 2009 11:43 am
Forum: Scripting
Topic: API Links
Replies: 135
Views: 106525

Re: API examples

Can anybody make the API for VB (for VB projects and ASP pages)?!



Thanks,
Mladen
by cholegm
Tue Apr 21, 2009 8:22 pm
Forum: General
Topic: VPN trough mikrotik router - please help :)
Replies: 10
Views: 2254

Re: VPN trough mikrotik router - please help :)

Try with specified src-addresses... I have 3.22 with hotspot (Service ports.. all enabled by defaulth) and masquerade with specified src-address of my network.
And I don't have problem
/ip firewall nat add chain=srcnat src-address=192.168.1.0/24 out-interface=HSDPA action=masquerade 
by cholegm
Tue Apr 21, 2009 8:04 pm
Forum: General
Topic: VPN trough mikrotik router - please help :)
Replies: 10
Views: 2254

Re: VPN trough mikrotik router - please help :)

:)

Now I looking in my routers...

In versions 3.xx there is no GRE :/

Sorry!

Can you post your NAT configuration?
by cholegm
Tue Apr 21, 2009 7:51 pm
Forum: General
Topic: Hide real ip
Replies: 5
Views: 1728

Re: Hide real ip

No.

Protect router and your network with some filter rules...

Look at Mikrotik Wiki...
http://wiki.mikrotik.com/wiki/Firewall
by cholegm
Tue Apr 21, 2009 7:40 pm
Forum: General
Topic: VPN trough mikrotik router - please help :)
Replies: 10
Views: 2254

Re: VPN trough mikrotik router - please help :)

Use print before this command.

And see what you have in list (It not the same names in all versions of MT)
by cholegm
Tue Apr 21, 2009 7:27 pm
Forum: General
Topic: VPN trough mikrotik router - please help :)
Replies: 10
Views: 2254

Re: VPN trough mikrotik router - please help :)

Try
/ip firewall service-port enable gre,pptp
by cholegm
Wed Apr 15, 2009 2:15 pm
Forum: General
Topic: Remove active user hotspot - PHP API
Replies: 16
Views: 13737

Re: Remove active user hotspot - PHP API

It working!!!


Thanks very much!!!

You have a beer :D
by cholegm
Wed Apr 15, 2009 1:57 pm
Forum: General
Topic: Remove active user hotspot - PHP API
Replies: 16
Views: 13737

Re: Remove active user hotspot - PHP API

Same question. I need to disconnect some user from my administration page "Active users". And when I say remove .id=(calculated line id number - same as telnet line id) or .id=(id from API print)... No error and nothing happens. Problem is maybe in API. If I understand .id must be same as line id fr...
by cholegm
Mon Oct 15, 2007 6:50 pm
Forum: General
Topic: Problem with MAC address
Replies: 2
Views: 809

Re: Problem with MAC address

EoIP should be used for this case. - I know... I'm using EoIP (between mt1 and mt2). In case correct interfaces are bridged for EoIP between HotSpot and end-client - MT1 is connected to MT2 with EoIP. On MT2 is address lists (traffic and flat) with mark routing ( users IPs in traffic goes to MT4, w...
by cholegm
Sun Oct 14, 2007 9:14 pm
Forum: General
Topic: Problem with MAC address
Replies: 2
Views: 809

Problem with MAC address

Hi everybody, I have a big problem! My setup: http://www.uploadgeek.com/uploads456/1/aw_mikrotik_layout.jpg USER >>>>> MT1 >>>>> MT2 >>>>> MT3 When user (00:00:00:00:00:11) wants internet he goes to mt1 then with EoIP tunnel goes to mt2 and from mt2 with Ethernet goes to mt3 where is Hotspot with MA...
by cholegm
Sun Aug 12, 2007 12:35 pm
Forum: General
Topic: How to bind mac address in bridge mode
Replies: 1
Views: 748

Re: How to bind mac address in bridge mode

Try to find something on this post http://forum.mikrotik.com/viewtopic.php?f=2&t=17317
by cholegm
Thu Aug 09, 2007 7:42 pm
Forum: General
Topic: Transparent Web proxy
Replies: 13
Views: 5137

Re: Transparent Web proxy

Check you configuration! Check your proxy port 3124 or 8080 Check your redirect rule. In redirect rule "to-ports=" is your proxy port. / ip firewall nat add chain=dstnat protocol=tcp dst-port=80 in-interface=local2 action=redirect to-ports=8080 or ip firewall nat add chain=dstnat protocol=tcp dst-po...
by cholegm
Thu Aug 09, 2007 7:26 pm
Forum: General
Topic: [ask]how to block *.exe
Replies: 9
Views: 5167

Re: [ask]how to block *.exe

MikroTik Proxy (webproxy-test package) when you install it you can find on the menu / ip proxy If you want to deny access to some page: / ip proxy access add dst-host=www.msn.com action=deny And if you want to deny some page with redirect to your one polici page / ip proxy access add dst-host=www.ms...
by cholegm
Sun Aug 05, 2007 1:04 pm
Forum: General
Topic: Problems with hotmail / windows live mail and hotspot?
Replies: 7
Views: 1520

Re: Problems with hotmail / windows live mail and hotspot?

/ ip firewall mangle
add chain=forward in-interface=local protocol=tcp tcp-flags=syn action=change-mss new-mss=1360
add chain=forward out-interface=public protocol=tcp tcp-flags=syn action=change-mss new-mss=1360

Regards,
Mladen
by cholegm
Sat Aug 04, 2007 3:07 pm
Forum: General
Topic: [ask]how to block *.exe
Replies: 9
Views: 5167

Re: [ask]how to block *.exe

Where is the problem?! :)
by cholegm
Fri Aug 03, 2007 8:41 pm
Forum: General
Topic: PC configuration for ROS
Replies: 1
Views: 706

PC configuration for ROS

I don't know where to post this question. Sorry about that. But?! Will MikroTik ROS work on this configuration? 1. ATX kućište rack-mount 19"/4U - staje u rek dubine 600mm, isporučuje se bez napajanja 2. MB LGA775 iG33, Foxconn Intel G33M VGA/PCIe/DualDDR2/FSB1333/Conroe/Quad/SATA2/GLAN/SB 3. CPU LG...
by cholegm
Thu Aug 02, 2007 11:09 am
Forum: General
Topic: Using the internet only through web proxy
Replies: 4
Views: 1018

Re: Using the internet only through web proxy

But this is only for port 80 (default port for www)
Your clients can run mail, ftp, p2p, ... :(
by cholegm
Thu Aug 02, 2007 9:29 am
Forum: General
Topic: [ask]how to block *.exe
Replies: 9
Views: 5167

Re: [ask]how to block *.exe

hmm I thy to use webproxy-test package (mods say that is faster then webproxy because, and i't is) Check configuration or here you are conf for webproxy-test package: http://forum.mikrotik.com/viewtopic.php?f=2&t=17471 What you can do more. Deny exe and redirect him to some page ;) Everyting works o...
by cholegm
Thu Aug 02, 2007 9:20 am
Forum: General
Topic: Blocking Web Based Proxys
Replies: 8
Views: 1519

Re: Blocking Web Based Proxys

Try to drop dst-port=3128,8080
by cholegm
Wed Aug 01, 2007 1:42 pm
Forum: General
Topic: Blocking Sites
Replies: 6
Views: 1120

Re: Blocking Sites

Some of moderators on forum say that webproxy is based on sqirl proxy, and proxy is MikroTik proxy! He say that proxy is much faster then webproxy. I have about 100-150 users in the moment. And I don't have problems with that. But thy to use proxy (install webproxy-test package) Look for config here...
by cholegm
Wed Aug 01, 2007 9:41 am
Forum: General
Topic: Access to a MT winbox behind another Network?
Replies: 4
Views: 880

Re: Access to a MT winbox behind another Network?

Like Sergejs say, You must have Public IP (if you useing pppoe as your gateway, in most cases your pppoe ISP give you an Dynamic/Static public IP address. You must use/have static public ip address.). I used PPPOe client and I can access to MT from internet but the users behind MT can not browsing! ...
by cholegm
Tue Jul 31, 2007 11:00 pm
Forum: General
Topic: Mac Address Filtering on Transparent Bridge (routerOS)
Replies: 6
Views: 2008

Re: Mac Address Filtering on Transparent Bridge (routerOS)

I don't understund what you say me (from configuration print). You are bridge all your interfaces :? I never do that... I don't have WDS links... My networks is based on ap/client wireless! I never make my MT as SWITCH :D I allways have one public interface with IP and that inerface are connected to...
by cholegm
Tue Jul 31, 2007 9:09 pm
Forum: General
Topic: Mac Address Filtering on Transparent Bridge (routerOS)
Replies: 6
Views: 2008

Re: Mac Address Filtering on Transparent Bridge (routerOS)

Simple: / interface print Flags: X - disabled, D - dynamic, R - running # NAME TYPE RX-RATE TX-RATE MTU 0 R public ether 0 0 1500 1 R local1 ether 0 0 1500 2 R local2 ether 0 0 1500 3 R bridge bridge 0 0 1500 / interface bridge port print Flags: X - disabled, I - inactive, D - dynamic # INTERFACE BR...
by cholegm
Tue Jul 31, 2007 9:20 am
Forum: General
Topic: Transparent Web proxy
Replies: 13
Views: 5137

Re: Transparent Web proxy

/ ip web-proxy set enabled=yes src-address=0.0.0.0 port=8080 hostname="proxy.domain.com" transparent-proxy=yes \ parent-proxy=0.0.0.0:0 cache-administrator="webmaster@domain.com" \ max-object-size=4096KiB cache-drive=system max-cache-size=none \ max-ram-cache-size=unlimited But... Better use the we...
by cholegm
Tue Jul 31, 2007 9:01 am
Forum: General
Topic: Not re-directing but modifying traffic...
Replies: 12
Views: 1787

Re: Not re-directing but modifying traffic...

In this post you can find it http://forum.mikrotik.com/viewtopic.php?f=2&t=17411

But here you are:
You must have instaled webproxy-test package!!!
/ ip proxy access
add action=deny dst-host="www.domain.com" redirect-to="www.mydomain.com" 


Regards,
Mladen
by cholegm
Mon Jul 30, 2007 11:17 pm
Forum: General
Topic: Blocking Sites
Replies: 6
Views: 1120

Re: Blocking Sites

Thanks for the friendly reply cholegm Sorry ChildOTK, But nobody try the search first. That question is posted a few days ago. And i't on the first page. You are not a first who do that on forums like this! I just wont to say... First try the search (play with words) then post the question! Regards...
by cholegm
Mon Jul 30, 2007 11:12 am
Forum: General
Topic: Can I change proxy redirect pages?
Replies: 7
Views: 2354

Re: Can I change proxy redirect pages?

Problem resolved! Thanks for help! You have beer from me! :) / ip proxy access add action=deny path=:\\.zip$ redirect-to=www.domain.com I use webproxy because I don't know that url= (in webproxy) and path= (in proxy) it same (can do the same job)! Now I use only Proxy (webproxy-test)! End every work...
by cholegm
Mon Jul 30, 2007 10:00 am
Forum: General
Topic: Can I change proxy redirect pages?
Replies: 7
Views: 2354

Re: Can I change proxy redirect pages?

OK I know for that. But i config webproxy with rule to deny *.exe files. I must make rule to redirect from MT proxy page to mypage... Because webproxy don't have option redirect-to I set as parent proxy my second MT with configured proxy. And every works for a pages. But for rules to deny download s...
by cholegm
Mon Jul 30, 2007 9:30 am
Forum: General
Topic: Can I change proxy redirect pages?
Replies: 7
Views: 2354

Re: Can I change proxy redirect pages?

OK :( (maybe will be in 3.xxx :) )

Can you write a simple code. To understand how to do that.

Thanks
by cholegm
Mon Jul 30, 2007 9:13 am
Forum: General
Topic: Can I change proxy redirect pages?
Replies: 7
Views: 2354

Re: Can I change proxy redirect pages?

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"> <TITLE>ERROR: The requested URL could not be retrieved</TITLE> <STYLE type="text/css"><!--BODY{background-color...
by cholegm
Sat Jul 28, 2007 7:02 pm
Forum: General
Topic: Blocking Sites
Replies: 6
Views: 1120

Re: Blocking Sites

by cholegm
Sat Jul 28, 2007 12:18 am
Forum: General
Topic: Can I change proxy redirect pages?
Replies: 7
Views: 2354

Can I change proxy redirect pages?

Now I need help!? :) I have MT with configured web proxy. Can I change proxy redirect pages??? Simple: I have rule to deny *.exe and when somebody (client) thy to download exe file proxy redirect him to error the page "Access deny..." I wont to translate that page and add some text about ruls on net...
by cholegm
Fri Jul 27, 2007 11:55 pm
Forum: General
Topic: something killing my ap
Replies: 9
Views: 2277

Re: something killing my ap

Your customers as client have MTs or some other routers!? And if is like that every customer have an public IP. If you set rule "connection-limit=100/32 on your AP. That means that every your customer is limited to 100 sesions! (100 sesions per host). And if you set connection limit 50,32. You limit...
by cholegm
Fri Jul 27, 2007 12:51 pm
Forum: General
Topic: Enabling user registration and payment
Replies: 5
Views: 985

Re: Enabling user registration and payment

If I understand you question…

First of all you must use HotSpot!

In hotspot configuration you have “walled garden”. You can add some site or host (access some sites without authorization).
by cholegm
Fri Jul 27, 2007 12:39 pm
Forum: General
Topic: [ask]how to block *.exe
Replies: 9
Views: 5167

Re: [ask]how to block *.exe

Yes, you can!
With transparent web proxy!

http://forum.mikrotik.com/viewtopic.php?f=2&t=17312
by cholegm
Wed Jul 25, 2007 4:53 pm
Forum: General
Topic: packet marking on mangle
Replies: 7
Views: 1442

Re: packet marking on mangle

Second one! First mark ICMP Second mark non-ICMP /ip firewall mangle add chain=prerouting src-address=192.168.0.0/24 protocol=icmp action=mark-connection \ new-connection-mark=icmp-conn add chain=forward connection-mark=icmp-conn action=mark-packet \ new-packet-mark=icmp add chain=prerouting src-add...
by cholegm
Wed Jul 25, 2007 12:03 pm
Forum: General
Topic: something killing my ap
Replies: 9
Views: 2277

Re: something killing my ap

That smtp connections is some SPAMER! Kill that IP... And find that host... And reinstall OS!!! IF?! You have customer with some IP, you customer have router with that IP, and customer have network behind router (Cybercafe PCs)?! And if you set connection limit 50,32. You limit connections for that ...
by cholegm
Wed Jul 25, 2007 11:41 am
Forum: General
Topic: drop by time
Replies: 4
Views: 1204

Re: drop by time

Ok

I see that I must write the script.
/ip firewall filter
add chain=forward action=accept p2p=all-p2p time=00:00-07:59,mon,tue,wed,thu,fri,sat,sun \
      comment="accept p2p from 00h-8h AM"
add chain=forward action=drop p2p=all-p2p comment="drop all p2p"
Try this!
by cholegm
Tue Jul 24, 2007 7:00 pm
Forum: General
Topic: something killing my ap
Replies: 9
Views: 2277

Re: something killing my ap

First of all, what routerboard you have? may be is to slow to do the JOB! And use torch (/tool torch) from winbox... select are box... and look for ip with hight bandwidth, or meny connections... If you find something... Drop it and check MT... If noting... :/ You can try this: /queue interface set ...
by cholegm
Tue Jul 24, 2007 5:54 pm
Forum: General
Topic: Connection mark (none)
Replies: 7
Views: 1121

Re: Connection mark (none)

Moze i tako :)

Nego da ne razmisljas... Sutra slucajno premestis mesta... i opet... :/
by cholegm
Tue Jul 24, 2007 5:50 pm
Forum: General
Topic: MAC address filtering
Replies: 6
Views: 1386

Re: MAC address filtering

Check your wireless interface for "default-authentication=no" if YES enybody can connect to your network! In "/interface wireless access-list" you can add MAC addresses of divices who you wont to connect to your network! /interface wireless access-list add mac-address=xx:xx:xx:xx:xx:xx interface="ap...
by cholegm
Tue Jul 24, 2007 2:50 pm
Forum: General
Topic: Connection mark (none)
Replies: 7
Views: 1121

Re: Connection mark (none)

PRICAJ SRPSKI DA TE CEO SVET RAZUME :)

Problem was in second rule!
first rule mark p2p conn, second rule mark all conn!
that is the problem!

how to fix problem,
Just add in second rule p2p=!all-p2p (make second rule to don't mark p2p conn)
by cholegm
Tue Jul 24, 2007 2:09 pm
Forum: General
Topic: Mac Address Filtering on Transparent Bridge (routerOS)
Replies: 6
Views: 2008

Re: Mac Address Filtering on Transparent Bridge (routerOS)

You must use ARP!

In configuration of interface ARP=reply-only

In /IP ARP

Fasten up IP with MAC on specific interface (bridge)
by cholegm
Tue Jul 24, 2007 1:55 pm
Forum: General
Topic: Connection mark (none)
Replies: 7
Views: 1121

Re: Connection mark (none)

Da da...

P.S.
odao si se :)

Ime address list-e "LOKALNI" :)
by cholegm
Tue Jul 24, 2007 1:36 pm
Forum: General
Topic: Simple queue do not work
Replies: 1
Views: 568

Re: Simple queue do not work

Try this! Problem can be in queue-tx=user-rx queue-rx=user-tx :/ / queue simple add name="184-tx" target-addresses=xx.xx.xx.184/32 dst-address=0.0.0.0/0 interface=all \ parent=none packet-marks=internet direction=both priority=8 \ queue=default-small/default-small limit-at=512000/512000 max-limit=51...
by cholegm
Tue Jul 24, 2007 1:29 pm
Forum: General
Topic: Connection mark (none)
Replies: 7
Views: 1121

Re: Connection mark (none)

Ispravio sam ti! / ip firewall mangle add chain=prerouting p2p=all-p2p dst-address-list=!Lokalni action=mark-connection \ new-connection-mark=p2p_conn passthrough=yes comment="" disabled=no add chain=prerouting connection-mark=p2p_conn action=mark-packet new-packet-mark=p2p \ passthrough=no comment...
by cholegm
Tue Jul 24, 2007 1:10 pm
Forum: General
Topic: Filter content *.iso, *.rar, etc
Replies: 5
Views: 3543

Re: Filter content *.iso, *.rar, etc

/ip firewall nat add chain=dstnat protocol=tcp dst-port=80 in-interface="name of interface" action=redirect to-ports=3128 (3128 or 8080, port of your web proxy server) / ip web-proxy access add url=":\\.mp\[3g\]\$" action=deny comment="" disabled=no add url=":\\.wm\[av\]\$" action=deny comment="" d...
by cholegm
Tue Jul 24, 2007 11:00 am
Forum: General
Topic: something killing my ap
Replies: 9
Views: 2277

Re: something killing my ap

1. Use torch to see what makes big ping! 2. Is that wireless or ethernet link? Write me with results! P.S. You can drop port scaners, p2p, connection limit (=15,32), ... , and drop every second connection on some port! But with that you slowdown your MikroTik RB/PC and your network! Regards, Mladen
by cholegm
Mon Jul 23, 2007 7:55 pm
Forum: General
Topic: drop by time
Replies: 4
Views: 1204

Re: drop by time

Sorry but I don’t understand your question fully! If I don’t wrong you want this! You have priority numbers 0,1,2,3,... 0 is height 3 is lower 0 will be accept rule (ALLOW ALL P2P BETWEEN 00:00 TO 7:59AM) 1 will be drop rule (totally drop of P2P) You can add more accept rules !!! place before 1 !!! ...