Community discussions

MikroTik App

Search found 11 matches

by MTv
Thu Mar 17, 2022 11:00 am
Forum: General
Topic: MT7621A HW Offload ROS v7
Replies: 3
Views: 894

Re: MT7621A HW Offload ROS v7

The site of this cpu does not even say what kind of qos is supported. I came across this video and got curious.. But there, to be honest, as it seemed to me, there is not a very big difference (apparently due to the small number of NAT connections). CRS3 series, NAT rules applied to the offloaded Fa...
by MTv
Wed Mar 16, 2022 3:08 pm
Forum: General
Topic: MT7621A HW Offload ROS v7
Replies: 3
Views: 894

MT7621A HW Offload ROS v7

Hi. Many people have devices on this CPU. It would be great if the developers in v7 ROS, in addition to Vlan Offload, implemented HW NAT, Routing, QoS. Is there hope for these features in future releases? For example, OpenWRT has released firmware for hEX with HW NAT support.
Link - MT7621A.
by MTv
Fri Dec 10, 2021 6:31 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226812

Re: v7.1 is released!

Interestingly, added the ability from the vpn server (l2tp/ipsec) to transfer routes to remote clients? For example dnsmasq can do this.
by MTv
Wed Aug 04, 2021 2:56 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082270

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Made a simple script that processes the generated Suricata eve-log in real time and, based on alerts, adds an ip-address to the MikroTik Address Lists for a specified time for subsequent blocking. #!/usr/bin/env bash # Bashcata Variables; router="" # mikrotik ip; login="" # user ...
by MTv
Fri May 14, 2021 8:32 pm
Forum: General
Topic: Option "!" Does not work in rules with a drop action. [SOLVED]
Replies: 11
Views: 2312

Re: Option "!" Does not work in rules with a drop action. [SOLVED]

Got it, thank you all for the clarification!
by MTv
Fri May 14, 2021 8:28 pm
Forum: General
Topic: Option "!" Does not work in rules with a drop action. [SOLVED]
Replies: 11
Views: 2312

Re: Option "!" Does not work in rules with a drop action. [SOLVED]

Port forwarding won't work! Sure it will. That's the part of the default config, and it works perfectly fine. Meant this: +(3) (1) add action=accept chain=forward connection-state=established,related (2) add action=drop chain=forward connection-nat-state=!dstnat connection-state=new in-interface-li...
by MTv
Fri May 14, 2021 8:10 pm
Forum: General
Topic: Option "!" Does not work in rules with a drop action. [SOLVED]
Replies: 11
Views: 2312

Re: Option "!" Does not work in rules with a drop action. [SOLVED]

Port forwarding won't work! (1) add action=accept chain=forward connection-state=established,related (2) add action=drop chain=forward connection-nat-state=!dstnat connection-state=new in-interface-list=WAN Port forwarding will work! But the second rule is not needed for port forwarding to work. (1)...
by MTv
Fri May 14, 2021 7:06 pm
Forum: General
Topic: Option "!" Does not work in rules with a drop action. [SOLVED]
Replies: 11
Views: 2312

Re: Option "!" Does not work in rules with a drop action. [SOLVED]

This symbol (!) Means not .. (1) add action=accept chain=forward connection-state=established,related (2) add action=drop chain=forward connection-nat-state=!dstnat connection-state=new in-interface-list=WAN (3) add action=drop chain=forward in-interface-list=WAN comment="drop all else" Sh...
by MTv
Thu May 13, 2021 3:19 pm
Forum: General
Topic: Option "!" Does not work in rules with a drop action. [SOLVED]
Replies: 11
Views: 2312

Option "!" Does not work in rules with a drop action. [SOLVED]

Hi! This does not work on my router. Collected a simple circuit in GNS3. There are 2 CHR with such settings. Ros 6.48.2 Based on the documentation on: help.mikrotik Brief firewall filter rule explanation: drop incoming packets that are not NAT`ed, ether1 is public interface, log attempts with "...
by MTv
Mon Apr 19, 2021 3:00 pm
Forum: Announcements
Topic: v6.48.2 [stable] is released!
Replies: 141
Views: 62477

Re: v6.48.2 [stable] is released!

Hey! On the device hEX (rb750gr3) there is a similar problem with the display of "system health" in winbox .. Also noticed that after the is rebooted, the information may appear or disappear. CF: 6.48.2.
by MTv
Sat Oct 24, 2020 10:19 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082270

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Thanks zbe for your script. I wrote a mini instruction for setting up Suricata in conjunction with ROS+Mikrocata on Debian Buster.