Community discussions

MikroTik App

Search found 15 matches

by NovaProspekt
Mon Feb 15, 2021 2:57 pm
Forum: Beginner Basics
Topic: Malicious VPN connection attempts?
Replies: 12
Views: 5548

Re: Malicious VPN connection attempts?

So, I have been adding at least 1 rogue VPN connection attempt to my block list nearly every day. I can see this list growing to hundreds or thousands of IP addresses over time. Would it be more efficient to just white-list the MAC addresses of my devices that would be VPN connecting to the router b...
by NovaProspekt
Sat Feb 13, 2021 5:17 pm
Forum: General
Topic: How to allow remote Wake on LAN through firewall without completely compromising security
Replies: 8
Views: 7369

Re: How to allow remote Wake on LAN through firewall without completely compromising security

With or without VPN , this trick should work: Send your wol packet to some unused LAN IP address (dNAT or vpn), add static ARP table for that address, containing LAN broadcast MAC ff-ff-ff-ff-ff-ff, and of your WOL client will receive the WOL packet This is what I was doing initially, but it felt l...
by NovaProspekt
Thu Feb 11, 2021 9:58 pm
Forum: General
Topic: How to see which firewall rule is allowing traffic
Replies: 1
Views: 1206

How to see which firewall rule is allowing traffic

Hi all, Is there a way to tell which firewall filter rule is allowing certain traffic to pass, other than adding a unique log prefix to every single rule, running a ping, and then checking the logs? I am currently able to ping VPN clients from my main VLAN, which IS the behavior I want, but the fire...
by NovaProspekt
Thu Feb 11, 2021 9:27 pm
Forum: Beginner Basics
Topic: Malicious VPN connection attempts?
Replies: 12
Views: 5548

Re: Malicious VPN connection attempts?

Thank you!
by NovaProspekt
Thu Feb 11, 2021 4:46 pm
Forum: Beginner Basics
Topic: Malicious VPN connection attempts?
Replies: 12
Views: 5548

Re: Malicious VPN connection attempts?

My suggestion to trap and then drop any unsolicited VPN traffic is as follows: Create the following address list named rogue_vpn_hosts Create the following Firewall Filter Rules [this assumes ipsec ... if you are using L2TP/ipse you will need to add more dst-ports ports]: /ip firewall filter add ac...
by NovaProspekt
Thu Feb 11, 2021 4:00 pm
Forum: Beginner Basics
Topic: Malicious VPN connection attempts?
Replies: 12
Views: 5548

Re: Malicious VPN connection attempts?

Here are the entries from my log. I know for a fact I was not attempting any VPN connections at these times. feb/09 21:09:47 ipsec,info respond new phase 1 (Identity Protection): ***MyPublicIPAddress***[500]<=> 216.218.206.74 [51722] feb/09 21:09:47 ipsec SPI size isn't zero, but IKE proposal. feb/0...
by NovaProspekt
Thu Feb 11, 2021 3:29 pm
Forum: Beginner Basics
Topic: Malicious VPN connection attempts?
Replies: 12
Views: 5548

Malicious VPN connection attempts?

Hi all. I am relatively new to Mikrotik routers. I have a hAP ac2, and just recently set up IPsec connectivity so that I can VPN from my phone and use RouterOS's built in Wake on LAN feature while I am away from home. Everything seems to be working. I glanced at my logs in Winbox this morning and no...
by NovaProspekt
Tue Feb 09, 2021 8:45 pm
Forum: General
Topic: How to allow remote Wake on LAN through firewall without completely compromising security
Replies: 8
Views: 7369

Re: How to allow remote Wake on LAN through firewall without completely compromising security

So, after some tinkering I now have a functional IPsec connection between my Android phone and Mikrotik router. I've made some firewall rules to allow my phone to utilize the Pi-hole on my network when it's connect to the VPN and it is working. However, the wake-on-LAN is not working. I wonder if I ...
by NovaProspekt
Tue Feb 09, 2021 4:11 am
Forum: General
Topic: How to allow remote Wake on LAN through firewall without completely compromising security
Replies: 8
Views: 7369

Re: How to allow remote Wake on LAN through firewall without completely compromising security

I have attempted a combination of the above linked guides in addition to the document posted here: https://mum.mikrotik.com/presentations/EU18/presentation_5196_1523218211.pdf When I attempt to initiate the VPN connection, I can see packets hitting the IKE firewall rule, but authentication ultimatel...
by NovaProspekt
Mon Feb 08, 2021 2:44 pm
Forum: General
Topic: How to allow remote Wake on LAN through firewall without completely compromising security
Replies: 8
Views: 7369

Re: How to allow remote Wake on LAN through firewall without completely compromising security

Hi mozerd, thanks for the advice. My router obtains its WAN IP as a DHCP client from my modem. I am following the guide you linked for setting up the IPsec mode config method, however I am wondering if that guide on the Mikrotik Wiki was written for an older version of RouterOS. I am at the part whe...
by NovaProspekt
Sun Feb 07, 2021 11:38 pm
Forum: General
Topic: How to allow remote Wake on LAN through firewall without completely compromising security
Replies: 8
Views: 7369

How to allow remote Wake on LAN through firewall without completely compromising security

I have a PC that I want to be able to turn on remotely when I am not home. I have configured the following, and it works, but I want to know if there is a better or more secure way to set this up. The PC is on subnet 10.10.10.0/24. I have taken an IP address outside the DHCP address pool and added i...
by NovaProspekt
Sat Dec 05, 2020 12:07 am
Forum: Wireless Networking
Topic: Can't exceed 200mbps on WiFi cAP ac
Replies: 5
Views: 1930

Re: Can't exceed 200mbps on WiFi cAP ac

I think this may have been a limitation of the radios in my client devices. I just purchased a new Samsung Galaxy S20 FE. Connected it to the 5ghz SSID on the cAP ac and it immediately speedtested at about 420 mbps.
by NovaProspekt
Fri Nov 20, 2020 10:06 pm
Forum: Wireless Networking
Topic: Can't exceed 200mbps on WiFi cAP ac
Replies: 5
Views: 1930

Can't exceed 200mbps on WiFi cAP ac

I just upgraded from a Linksys all in one wireless router to a Mikrotik hAP ac2 plus cAP ac setup. Wireless is disabled on the hAP - it is routing only. All wireless connections are configured on the cAP ac. I have a 400mpbs down 20mbps up connection from my ISP. Plugging a PC via ethernet into the ...
by NovaProspekt
Thu Nov 19, 2020 3:15 pm
Forum: Wireless Networking
Topic: Is CAPsMAN local forwarding conflicting with bridge VLAN filtering on cAP? [SOLVED]
Replies: 1
Views: 1610

Re: Is CAPsMAN local forwarding conflicting with bridge VLAN filtering on cAP? [SOLVED]

Just wanted to give an update. I turned off CAPsMAN and manually configured the virtual WLAN interfaces on the access point. The weird dynamic VLAN tagged/untagged assignments were bothering me and I didn't like that using local forwarding was preventing my from using ingress filtering to block unta...
by NovaProspekt
Wed Nov 18, 2020 2:56 pm
Forum: Wireless Networking
Topic: Is CAPsMAN local forwarding conflicting with bridge VLAN filtering on cAP? [SOLVED]
Replies: 1
Views: 1610

Is CAPsMAN local forwarding conflicting with bridge VLAN filtering on cAP? [SOLVED]

Hi all, I am new to Mikrotik but am enjoying learning its capabilities. I am using CAPsMAN with local forwarding on a hAP ac2 to provision an access point (cAP ac) with multiple WiFi interfaces: 5ghz and 2ghz networks for my trusted VLAN, 5ghz and 2ghz for a guest network, and 2ghz only for IoT devi...