Community discussions

MikroTik App

Search found 207 matches

by yancho
Sun Oct 11, 2020 4:07 pm
Forum: Wireless Networking
Topic: PTP LHG 5 problem [SOLVED]
Replies: 3
Views: 1458

Re: PTP LHG 5 problem [SOLVED]

You need to add routing information:
https://wiki.mikrotik.com/wiki/Manual:S ... ic_Routing
by yancho
Mon Sep 07, 2020 8:39 pm
Forum: General
Topic: RB in loop
Replies: 14
Views: 1923

Re: RB in loop

1) unplug the device from power
2) press and hold the reset button and power up the device
3) hold hold hold :) ~15..20sec or until the device shows up in Netinstall
by yancho
Mon Sep 07, 2020 6:09 pm
Forum: General
Topic: RB in loop
Replies: 14
Views: 1923

Re: RB in loop

I've had a number of similar cases. Last time yesterday. Neinstall has always helped.
Network should remain stable after entering Etherboot
by yancho
Fri Nov 02, 2018 11:46 am
Forum: General
Topic: Winbox-Traffic - 200kbit/s
Replies: 14
Views: 2464

Re: Winbox-Traffic - 200kbit/s

Yes, but with only one window, I already see 200 kbps...
Torch? :)
by yancho
Mon Jul 16, 2018 9:31 pm
Forum: Beginner Basics
Topic: I want to be able to adjust my settings to block external access the admin panel.
Replies: 8
Views: 2834

Re: I want to be able to adjust my settings to block external access the admin panel.

/ip service set winbox address=192.168.88.0/24 /user set 0 address=192.168.88.0/24 Also CLI has autocompleation. Start typing user like /us press [TAB] you should see /user then /user [TAB] "aaa group add disable enable find removeactive ssh-keys comment edit export print set " all availa...
by yancho
Thu Jul 05, 2018 8:45 pm
Forum: Wireless Networking
Topic: Wireless Wire/LHG 60 distance - expected signal
Replies: 14
Views: 11036

Re: Wireless Wire/LHG 60 distance - expected signal

WW
frequency: 58320
mcs: 8
phy-rate: 2.3Gbps
signal: 50
rssi: -68
tx-sector: 28
tx-sector-info: center
rx-sector: 96
distance: 124.56m
by yancho
Sat Jun 16, 2018 10:41 am
Forum: General
Topic: Mikrotik Router Dual IP
Replies: 1
Views: 721

Re: Mikrotik Router Dual IP

Assuming there are no other gateway routers or subnets minimum configuration could be
Untitled.png
by yancho
Mon May 21, 2018 9:17 pm
Forum: General
Topic: mac-telnet client for Windows [SOLVED]
Replies: 20
Views: 12517

Re: mac-telnet client for Windows [SOLVED]

If you want Telnet https://en.wikipedia.org/wiki/Telnet then use any Telnet client. If you want MAC Telnet MikroTik RouterOS proprietary protocol https://wiki.mikrotik.com/wiki/MAC_access then use Winbox and type Mikrotik router MAC address https://en.wikipedia.org/wiki/MAC_address in "Connect ...
by yancho
Mon May 21, 2018 7:53 pm
Forum: General
Topic: mac-telnet client for Windows [SOLVED]
Replies: 20
Views: 12517

Re: mac-telnet client for Windows [SOLVED]

If you need telnet - putty
if you need MAC telnet for Windows - Winbox :)
2018-05-21 19_43_09-Screenshot (31).png ‎- Photos.png
by yancho
Mon May 21, 2018 6:26 pm
Forum: General
Topic: mac-telnet client for Windows [SOLVED]
Replies: 20
Views: 12517

Re: mac-telnet client for Windows [SOLVED]

Winbox :?:
by yancho
Tue Apr 18, 2017 12:58 pm
Forum: General
Topic: MGMT port
Replies: 3
Views: 1985

Re: MGMT port

If you have the same subnet on two ports how does the router know where to send traffic?
Why you can't use different subnet for the management port?
by yancho
Mon Jan 02, 2017 10:11 pm
Forum: Wireless Networking
Topic: NV2 Best practices for PTMP setups
Replies: 14
Views: 7240

Re: NV2 Best practices for PTMP setups

20mhz only-N nv2 11 clients 30-40Mbps :)
by yancho
Mon Aug 29, 2016 11:15 pm
Forum: Beginner Basics
Topic: Outbound Traffic Concern
Replies: 3
Views: 1349

Re: Outbound Traffic Concern

Your router acts as open DNS https://support.aa.net.uk/Category:Open_DNS_Resolvers
Drop incoming DNS traffic on WAN interface
/ip firewall filter
add chain=input in-interface=ether1-WAN protocol=udp dst-port=53 action=drop
add chain=input in-interface=ether1-WAN protocol=tcp dst-port=53 action=drop
by yancho
Wed Jul 20, 2016 2:52 pm
Forum: General
Topic: Can't connect to mikrotik
Replies: 2
Views: 882

Re: Can't connect to mikrotik

Try Winbox neighbor discovery http://wiki.mikrotik.com/wiki/Manual:Winbox
by yancho
Tue Feb 09, 2016 4:56 pm
Forum: Beginner Basics
Topic: Zero mac in ARP list ?
Replies: 1
Views: 1733

Re: Zero mac in ARP list ?

by yancho
Sat Dec 26, 2015 1:02 pm
Forum: Wireless Networking
Topic: 2 km point to point HELP !
Replies: 9
Views: 4355

Re: 2 km point to point HELP !

Also set band to 5Ghz-only-N frequency mode to "regulatory domain" and channel-width to 20mhz
Then do frequency scan to find free frequency.
by yancho
Thu Dec 10, 2015 10:19 pm
Forum: Beginner Basics
Topic: Outlook not working after EOIP
Replies: 5
Views: 1588

Re: Outlook not working after EOIP

Might be an MTU problem.
by yancho
Sat Dec 05, 2015 7:04 pm
Forum: General
Topic: igmp-proxy no more available?
Replies: 1
Views: 1222

Re: igmp-proxy no more available?

You should install additional multicast package!
by yancho
Mon Oct 26, 2015 2:16 pm
Forum: General
Topic: RouterOS has always some traffic on internet
Replies: 1
Views: 599

Re: RouterOS has always some traffic on internet

Try Tools -> Torch. Torch this is real time traffic monitoring tool
by yancho
Sun Oct 25, 2015 10:47 am
Forum: Beginner Basics
Topic: Protect rule
Replies: 8
Views: 1814

Re: Protect rule

Router = server? :)
If so Wiki have some examples http://wiki.mikrotik.com/wiki/Firewall
If server is server behind router and providing some services to outside then we need more information.
by yancho
Tue Oct 20, 2015 5:17 pm
Forum: Forwarding Protocols
Topic: Eoip link 40% lower throughoutput than link without EOIP, in TCP
Replies: 7
Views: 2674

Re: Eoip link 40% lower throughoutput than link without EOIP, in TCP

IPANetEngineer seriously? 10 Gbps over wireless? :D
by yancho
Thu Oct 15, 2015 8:45 pm
Forum: Forwarding Protocols
Topic: Eoip link 40% lower throughoutput than link without EOIP, in TCP
Replies: 7
Views: 2674

Re: Eoip link 40% lower throughoutput than link without EOIP, in TCP

Use VPLS less overhead and not CPU intensive
by yancho
Tue Aug 11, 2015 2:04 pm
Forum: General
Topic: Routerboard bandwidth limits destroy performance
Replies: 1
Views: 743

Re: Routerboard bandwidth limits destroy performance

Try simple queues. I never used those interface bandwidth limits also after quick search found similar topic http://forum.mikrotik.com/viewtopic.php?t=79908#p461150
by yancho
Sun Feb 15, 2015 11:07 am
Forum: Beginner Basics
Topic: Am I going nuts?
Replies: 8
Views: 2571

Re: Am I going nuts?

Advice! Start with a very basic configuration like IP, routes, DNS, DHCP, NAT. Disable everything in /firewall filter . When all is working fine, keep this configuration, maybe make backup or create export files and then start securing network using firewall.
by yancho
Sun Feb 15, 2015 10:45 am
Forum: Wireless Networking
Topic: Multiple Signals?
Replies: 5
Views: 3034

Re: Multiple Signals?

This is signal strength level at different rates together with time how long were these rates used. Nothing to do with MIMO.
by yancho
Fri Feb 13, 2015 11:53 am
Forum: General
Topic: individually rate limit every IP in a network
Replies: 6
Views: 2817

Re: individually rate limit every IP in a network

You should adjust pcq parameters: pcq-rate: maximal available data rate of client or stream based on pcq-classfier pcq-burst-rate: maximal data rate which can be reached while the burst for is allowed pcq-burst-threshold: this is value of burst on/off switch pcq-burst-time: period of time, in second...
by yancho
Thu Feb 12, 2015 5:32 pm
Forum: General
Topic: individually rate limit every IP in a network
Replies: 6
Views: 2817

Re: individually rate limit every IP in a network

coylh example missing very important detail
pcq-classifier=dst-address or src-address
And yes RTM ;) http://wiki.mikrotik.com/wiki/Manual:Qu ... Q_Examples
by yancho
Thu Feb 12, 2015 1:17 pm
Forum: General
Topic: Block all websites except ones specified
Replies: 1
Views: 928

Re: Block all websites except ones specified

First of all - enable safe mode before playing with configuration :) Second, configure transparent proxy (link to wiki http://wiki.mikrotik.com/wiki/Manual:IP/Proxy ), set max-cache-size to none (you don't need cache anything) Third, create proxy access list - first rules allow "good" webp...
by yancho
Tue Feb 10, 2015 12:42 pm
Forum: Beginner Basics
Topic: Interface connection with speed limit
Replies: 5
Views: 1926

Re: Interface connection with speed limit

Yes that is global setting
by yancho
Tue Feb 10, 2015 11:58 am
Forum: Beginner Basics
Topic: how to block traffic
Replies: 8
Views: 2330

Re: how to block traffic

I bet on wrong chain. You should use forward input - used to process packets entering the router through one of the interfaces with the destination IP address which is one of the router's addresses. Packets passing through the router are not processed against the rules of the input chain forward - u...
by yancho
Sat Feb 07, 2015 9:55 pm
Forum: Beginner Basics
Topic: Interface connection with speed limit
Replies: 5
Views: 1926

Re: Interface connection with speed limit

When bridging set
/interface bridge settings set use-ip-firewall=yes
by yancho
Tue Jan 13, 2015 9:10 pm
Forum: RouterBOARD hardware
Topic: Palīdzība
Replies: 2
Views: 1366

Re: Palīdzība

54Mbps ir savienojuma ātrums, teorētiski iespējamais ātrums būs 2x mazāks, reālais ātrums dzīvē vēl mazāks... Skaists kopsavalikums par ātrumiem - sākot ar 7lpp http://mum.mikrotik.com/presentations/AU11/au-savage.pdf 2.4Ghz un vēl jo vairāk 5Ghz tiešā redzamība ir ļoti vēlama, ja grib nodrošināt st...
by yancho
Sat Aug 16, 2014 2:33 pm
Forum: General
Topic: Mark packet
Replies: 3
Views: 1516

Re: Mark packet

1. mark connection 2. mark packets 3. use this packet mark in simple queue Like this: / ip firewall mangle add chain=prerouting protocol=tcp dst-port=5000 dst-address=100.100.100.100 action=mark-connection \ new-connection-mark=5000_connection passthrough=yes add chain=prerouting connection-mark=500...
by yancho
Wed Jun 04, 2014 3:19 pm
Forum: General
Topic: Packet Sniffer
Replies: 1
Views: 897

Re: Packet Sniffer

Use torch http://wiki.mikrotik.com/wiki/Manual:Tr ... l_torch.29 to monitor traffic
or add some firewall rules that match and drop/log those computers http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter and lots of examples in WIKI
by yancho
Mon Jan 02, 2012 10:05 am
Forum: General
Topic: masq with a /32 address?
Replies: 5
Views: 1790

Re: masq with a /32 address?

Use src/dst nat instead.
by yancho
Tue Jun 01, 2010 9:13 am
Forum: Wireless Networking
Topic: frustration all around
Replies: 31
Views: 5155

Re: frustration all around

Is "antenna mode" set to "antenna b" for a reason?
by yancho
Sat May 08, 2010 9:24 am
Forum: General
Topic: QOS and Packet Marking
Replies: 8
Views: 3778

Re: QOS and Packet Marking

Does counters in the queues statistics shows any traffic?
by yancho
Fri May 07, 2010 12:19 pm
Forum: Forwarding Protocols
Topic: block p2p, bittorent,
Replies: 1
Views: 2018

Re: block p2p, bittorent,

This question is a very popular try search forums
like: http://forum.mikrotik.com/viewtopic.php?f=2&t=21178
by yancho
Thu May 06, 2010 10:36 pm
Forum: General
Topic: Massive Upgrade of RouterOS
Replies: 2
Views: 1610

Re: Massive Upgrade of RouterOS

First there is "auto upgrade" under system (never tried this feature).
Second - you can upgrade using Dude http://wiki.mikrotik.com/wiki/Upgrading ... _with_Dude
by yancho
Thu May 06, 2010 10:22 pm
Forum: General
Topic: QOS and Packet Marking
Replies: 8
Views: 3778

Re: QOS and Packet Marking

Open terminal then type
/queue export
and paste output there.
by yancho
Sat Mar 20, 2010 9:17 pm
Forum: Beginner Basics
Topic: How to set up a RB493 as home wireless router
Replies: 2
Views: 1313

Re: How to set up a RB493 as home wireless router

Create bridge and add both interfaces to it.
/interface bridge add
/interface bridge port add bridge=bridge1 interface=ether1
/interface bridge port add bridge=bridge1 interface=wlan1
Now add ip address to the bridge1 and that's it.
by yancho
Sat Mar 20, 2010 1:59 pm
Forum: General
Topic: how to monitor the user connection
Replies: 1
Views: 1810

Re: how to monitor the user connection

Maybe http://wiki.mikrotik.com/wiki/CALEA is what you looking for.
by yancho
Sun Mar 14, 2010 12:40 pm
Forum: General
Topic: Simple QueueNot Working until disable/enable
Replies: 3
Views: 1203

Re: Simple QueueNot Working until disable/enable

Think it should work right? remember, no IP specified in the queue rule.
Specify all wireless subnet not a single ip like 192.168.1.0/24
by yancho
Sat Mar 13, 2010 9:15 am
Forum: Beginner Basics
Topic: basic configration
Replies: 2
Views: 1129

Re: basic configration

Add ip, gateway, dns to the external - internet interface(ip->address/routes/dns). Check connectivity to internet from router using ping or tracert(tools). If you want dynamic ip's to clients use dhcp server setup(ip->dhcp server) if there is dhcp, then go to system->packages enable dhcp and reboot ...
by yancho
Sat Mar 13, 2010 8:59 am
Forum: General
Topic: cpu 70-80%, network 80mbps (100mb card)
Replies: 10
Views: 2259

Re: cpu 70-80%, network 80mbps (100mb card)

Give more information about what your router configuration, maybe you have many simple queues and filter rules?
We have similar setup - pushing 100down/50up and CPU goes up to 20%
by yancho
Sat Mar 13, 2010 8:47 am
Forum: General
Topic: QoS: queues limits
Replies: 5
Views: 1774

Re: QoS: queues limits

First limit and prioritize upload (http,voip,p2p) there are many topics(forum and wiki) about how to do that. And yes for download try pcq.
by yancho
Wed Mar 10, 2010 2:32 pm
Forum: General
Topic: I am not able to set up a queue correctly.
Replies: 4
Views: 1157

Re: I am not able to set up a queue correctly.

If you have one queue per client then not a big difference, anything except "default-small" - check out manual http://wiki.mikrotik.com/wiki/Queue#Queue_Types for more details. Also consider moving to queue trees & PCQ http://wiki.mikrotik.com/wiki/Bandwidth_Managment_and_Queues basic ...
by yancho
Wed Mar 10, 2010 11:41 am
Forum: General
Topic: I am not able to set up a queue correctly.
Replies: 4
Views: 1157

Re: I am not able to set up a queue correctly.

Change queue type - "default-small" not working :)
by yancho
Sun Mar 07, 2010 12:37 pm
Forum: General
Topic: mikrotik issues same ip to two different clients
Replies: 12
Views: 2917

Re: mikrotik issues same ip to two different clients

When it happens again make supout files, describe problem, include forum threads, and send it to support@mikrotik.com
by yancho
Sun Mar 07, 2010 11:11 am
Forum: General
Topic: mikrotik issues same ip to two different clients
Replies: 12
Views: 2917

Re: mikrotik issues same ip to two different clients

Never seen such a problem. Anyway post router configuration and share ROS version. Without any additional information its impossible to check anything.
by yancho
Sun Mar 07, 2010 11:07 am
Forum: Beginner Basics
Topic: Set AP routing, addressing
Replies: 1
Views: 740

Re: Set AP routing, addressing

Can you give more details about network topology? Like: how AP's are connected to each other, where is the internet connected to?
by yancho
Wed Mar 03, 2010 11:00 pm
Forum: Wireless Networking
Topic: What does the '-SP' mean?
Replies: 1
Views: 919

Re: What does the '-SP' mean?

by yancho
Mon Mar 01, 2010 5:37 pm
Forum: General
Topic: limit upload and download
Replies: 2
Views: 1645

Re: limit upload and download

Mangle+address lists+queue tree
http://wiki.mikrotik.com/wiki/Bandwidth ... and_Queues there are nice examples
"QoS Best Practice @ MUM Czech Republic 2009" is really the best :)
by yancho
Fri Feb 26, 2010 10:52 am
Forum: General
Topic: Cannot NAT incoming ports - Kindof Dual Wan setup
Replies: 15
Views: 5991

Re: Cannot NAT incoming ports - Kindof Dual Wan setup

Can you post
/ip firewall nat print 
and
/ip firewall filter print
by yancho
Fri Feb 26, 2010 10:14 am
Forum: Beginner Basics
Topic: Different DNSs for different subnets?
Replies: 3
Views: 1146

Re: Different DNSs for different subnets?

Why not? If you are using static addressing set whatever DNS you prefer on a client PC. Using DHCP? Again not a problem. create 2 different DHCP server setups.
by yancho
Fri Feb 19, 2010 3:11 pm
Forum: Forwarding Protocols
Topic: Port Forwarding to port 3784 for Ventrilo
Replies: 1
Views: 2434

Re: Port Forwarding to port 3784 for Ventrilo

How about other firewall filter and nat rules?
by yancho
Fri Feb 19, 2010 3:06 pm
Forum: Wireless Networking
Topic: After upgrade to 3.30 clients disconnecting
Replies: 1
Views: 930

Re: After upgrade to 3.30 clients disconnecting

Contact support!
Make supout.rif file and send it to support@mikrotik.com along with your problem.
And hope tha MT team could reproduce those problems.
by yancho
Fri Feb 19, 2010 12:55 pm
Forum: General
Topic: Allow FULL access through RouterBOARD
Replies: 3
Views: 14448

Re: Allow FULL access through RouterBOARD

Ok, but how the squid proxy is connected? Your MT config looking good. Maybe squid is between ADSL and MT and transparently filtering your traffic?
by yancho
Thu Feb 18, 2010 9:42 am
Forum: General
Topic: Allow FULL access through RouterBOARD
Replies: 3
Views: 14448

Re: Allow FULL access through RouterBOARD

Can you give more information about your network topology? Looks like you have 3 ethernet & 4 wireless interfaces.
by yancho
Fri Feb 12, 2010 7:10 pm
Forum: Beginner Basics
Topic: How to block Multi mac ?
Replies: 3
Views: 1170

Re: How to block Multi mac ?

wireless or wired network?
by yancho
Thu Nov 26, 2009 11:04 pm
Forum: General
Topic: How can I access my routerOS from another public address
Replies: 14
Views: 2900

Re: How can I access my routerOS from another public address

Winbox connects and starts to download plugins but very very very slow.
by yancho
Thu Nov 26, 2009 4:47 pm
Forum: General
Topic: How can I access my routerOS from another public address
Replies: 14
Views: 2900

Re: How can I access my routerOS from another public address

Now port is open it should work.
by yancho
Fri Nov 20, 2009 11:58 am
Forum: General
Topic: How can I access my routerOS from another public address
Replies: 14
Views: 2900

Re: How can I access my routerOS from another public address

Once again if you want more assistance please tell us more about you network topology! If MT router connected directly to internet and has public IP- then zero configuration! If it is behind some other router/firewall etc - then you should forward winbox ports!
by yancho
Thu Nov 12, 2009 2:36 am
Forum: General
Topic: 3.30 vs 3.20 Queues
Replies: 8
Views: 2089

Re: 3.30 vs 3.20 Queues

Looks like there is some bug or change in 3.30 queues. After executing command /queue tree set queuename max-limit=xM packet mark attribute disappears. /queue tree set queuename max-limit=xM packet-mark=somemark instead works ok. Maybe you have the same problem with simple queues - packet marks are ...
by yancho
Thu Oct 15, 2009 9:08 pm
Forum: General
Topic: VLAN between two mikrotiks
Replies: 8
Views: 2200

Re: VLAN between two mikrotiks

Wrong IP addressing. Ethernet and VLAN cant share same ip subnet (192.168.70.0/24)
by yancho
Wed Oct 14, 2009 11:40 pm
Forum: General
Topic: VLAN between two mikrotiks
Replies: 8
Views: 2200

Re: VLAN between two mikrotiks

No:) Can you post vlan and ip configuration from the both routers!? As I remember in some earlier RouterOS versions you need to change MAC of the VLAN interface. Because default values was the same.
by yancho
Sat Oct 10, 2009 11:10 pm
Forum: General
Topic: Winbox from internet?
Replies: 8
Views: 3198

Re: Winbox from internet?

Can't see any problems in this configuration.
You can try temporally disable all rules in input chain. (Input used to filter traffic entering the router. Forward to filter traffic going through.)
Is there any NAT rules? And SSH, telnet, HTTP to the router works?
by yancho
Fri Oct 09, 2009 11:38 pm
Forum: General
Topic: Winbox from internet?
Replies: 8
Views: 3198

Re: Winbox from internet?

Please post your firewall configuration!
by yancho
Tue Oct 06, 2009 10:45 pm
Forum: General
Topic: L7 - Skype regexp blocking Microsoft Outlook SMTP
Replies: 17
Views: 10603

Re: L7 - Skype regexp blocking Microsoft Outlook SMTP

"Outgoing messages form Microsoft Outlook 2007" are SMTP traffic to port TCP 25 right? Then add one rule that allows (accept) all traffic to tcp:25 or your outgoing mail server IP and that's it.
by yancho
Tue Sep 22, 2009 12:46 pm
Forum: Beginner Basics
Topic: Basic NAT for an application
Replies: 4
Views: 1376

Re: Basic NAT for an application

You can type in terminal
/ip firewall nat print
and
/ip firewall filter print
to show us your firewall configuration.
by yancho
Thu Aug 27, 2009 2:13 am
Forum: The User Manager
Topic: removing 144k logs quicky?
Replies: 10
Views: 2950

Re: removing 144k logs quicky?

Change lines to 0 at system->logging->actions
by yancho
Wed Mar 25, 2009 12:02 am
Forum: Beginner Basics
Topic: The problem we are faced
Replies: 2
Views: 967

Re: The problem we are faced

Routerboard or PC ? If RB then read http://wiki.mikrotik.com/wiki/MikroTik_ ... d_Recovery
by yancho
Mon Mar 23, 2009 7:49 pm
Forum: Beginner Basics
Topic: External To Internal
Replies: 4
Views: 1031

Re: External To Internal

Are you testing from same subnet 192.168.202.0/24? If yes you should add another nat rule for internal traffic!
by yancho
Mon Mar 23, 2009 6:03 pm
Forum: RouterBOARD hardware
Topic: queue tree selector
Replies: 16
Views: 3151

Re: queue tree selector

Not sure, but maybe simple queues without mangling works better?
Anyhow you can use torch tool for realtime traffic monitoring, or you are using queues to collect SNMP data? If yes there is other ways to monitor/collect/count per user bandwidth usage.
by yancho
Mon Mar 23, 2009 12:22 am
Forum: RouterBOARD hardware
Topic: queue tree selector
Replies: 16
Views: 3151

Re: queue tree selector

Wow 600 mangle and 300 queues :shock: What a hell you are trying to limit? Its possible to share bandwidth equally even between 1000 users with few mangle rules and using few PCQ queues! Take a look http://wiki.mikrotik.com/wiki/Bandwidth ... and_Queues
by yancho
Tue Mar 17, 2009 12:55 am
Forum: Wireless Networking
Topic: block by MAC address
Replies: 1
Views: 2615

Re: block by MAC address

Block this MAC in firewall input chain
/ip firewall filter add action=drop chain=input  src-mac-address=AA:AA:AA:AA:AA:AA
by yancho
Tue Mar 17, 2009 12:10 am
Forum: Beginner Basics
Topic: AP basic config
Replies: 1
Views: 867

Re: AP basic config

Did you tried to create bridgeusing this example with ethernet and wireless interfaces?
by yancho
Mon Mar 16, 2009 11:55 pm
Forum: Beginner Basics
Topic: can't ping from RouterOS to PC
Replies: 11
Views: 2086

Re: can't ping from RouterOS to PC

Upload picture using attachment not as hotlink to your computer ;)
No you don't need use RIP for p2p link.
by yancho
Fri Feb 20, 2009 7:20 pm
Forum: Beginner Basics
Topic: I'm Noob :( Help Me )
Replies: 6
Views: 1544

Re: I'm Noob :( Help Me )

Ask wiki ;) -> http://wiki.mikrotik.com/ This is a good starting for beginner: http://wiki.mikrotik.com/wiki/Internet_Sharing
by yancho
Thu Dec 25, 2008 5:29 pm
Forum: General
Topic: Winbox 2.2.14
Replies: 1
Views: 3250

Re: Winbox 2.2.14

by yancho
Sat Aug 09, 2008 1:42 pm
Forum: General
Topic: Can't upgrade from v2.9.46 to v2.9.51
Replies: 4
Views: 1230

Re: Can't upgrade from v2.9.46 to v2.9.51

Use FTP to transfer package.
by yancho
Thu May 08, 2008 12:04 pm
Forum: Beginner Basics
Topic: NAT n00b
Replies: 3
Views: 1496

Re: NAT n00b

If you have masquarde rule check is there out interface set to public interface or source ip's is set to your private network.
by yancho
Tue May 06, 2008 9:32 pm
Forum: General
Topic: Prefered source changed in 3.x ?
Replies: 3
Views: 1181

Re: Prefered source changed in 3.x ?

Thx JJCinAZ.
by yancho
Tue May 06, 2008 2:27 pm
Forum: General
Topic: Prefered source changed in 3.x ?
Replies: 3
Views: 1181

Prefered source changed in 3.x ?

We have following config: Two different subnets: /ip address address=10.0.0.3/24 interface=wlan1 address=192.168.1.3/27 interface=wlan1 Default gateway is from subnet 10.0/24 preferred source from other subnet 192.168.1.0/27: /ip route dst-address=0.0.0.0/0 gateway=10.0.0.1 pref-src=192.168.1.3 This...
by yancho
Wed Apr 16, 2008 11:11 pm
Forum: RouterBOARD hardware
Topic: LINK P-P 12Km. NLOS with 133c
Replies: 48
Views: 11441

Re: LINK P-P 12Km. NLOS with 133c

In the mikrotik I set the TX in BRIDGE mode with 5ghz - 5180mhz antenna gain 19dbi and manual tx power to 11dbm RX in WDSSLAVE mode with 5ghz - 5180mhz antenna gain 19dbi and manual tx power to 11dbm Brr, Why you start with so complicated config? Reset all and start from scratch. Change only necess...
by yancho
Fri Mar 28, 2008 1:54 pm
Forum: The Dude
Topic: How to mark a switch?
Replies: 3
Views: 1639

Re: How to mark a switch?

You may use fake ip like 0.0
by yancho
Wed Mar 26, 2008 1:31 pm
Forum: General
Topic: How many clients (RB153 3xR52H)
Replies: 12
Views: 2791

Re: How many clients (RB153 3xR52H)

routerboard 153, current-firmware: 2.12, RouterOS: 3.6
I noticed that rb 153 works better with 2.9.x
We had one AP - 2 sectors about 20 clients per sector, after update to 3.x - traffic rates was ok, but it was almost impossible to winbox or telnet/ssh to this board. CPU load constantly was 100%.
by yancho
Sat Mar 22, 2008 11:25 pm
Forum: General
Topic: Open ports for clients
Replies: 3
Views: 1312

Re: Open ports for clients

Did you forward both protocols tcp and udp? Maybe first try to forwad all ports(0-65535) and see what happens.Also you could try UPnP (check manual for more information).
by yancho
Sat Mar 22, 2008 5:50 pm
Forum: General
Topic: Open ports for clients
Replies: 3
Views: 1312

Re: Open ports for clients

/ip firewall nat add chain=dstnat dst-address=192.168.2.1 protocol=tcp dst-port=34000 action=dst-nat to-addresses=10.34.100.3 to-ports=34000
should work much better ;)
by yancho
Sat Mar 22, 2008 5:40 pm
Forum: General
Topic: Nat-Sessions
Replies: 8
Views: 3396

Re: Nat-Sessions

We had similar issue when cpu usage constantly hit 100%. Looked like router stopped reply dns requests directed to internal dns cache.
by yancho
Sun Mar 16, 2008 1:37 pm
Forum: General
Topic: there is must be a solution (arp spoofers)
Replies: 14
Views: 4210

Re: there is must be a solution (arp spoofers)

In Ethernet network (wired network using switches) all users are in the same physical layer and using Media Access Control is is hard (almost impossible) to make hierarchy - who is main router and who client. There is no security. As normis mentioned before way to disable forwarding between Ethernet...
by yancho
Mon Jan 14, 2008 3:00 pm
Forum: General
Topic: Ip Firewall
Replies: 8
Views: 1966

Re: Ip Firewall

Someting like
add chain=srcnat action=src-nat  src-address=172.16.100.0/24 dst-address=172.16.100.202  protocol=tcp to-addresses=gateway.ip to-ports=0-65535
should help.
by yancho
Tue Jan 01, 2008 8:56 pm
Forum: General
Topic: Block Skype
Replies: 10
Views: 8335

Re: Block Skype

it's possible with layer 7 filtering avaible in router os version 3.x
by yancho
Wed Nov 14, 2007 1:54 pm
Forum: Scripting
Topic: DoS attack or DDos attack Routeros How to do ?
Replies: 17
Views: 27890

Re: DoS attack or DDos attack Routeros How to do ?

Edit: Why my quoting isn't working?
Check your board settings: http://forum.mikrotik.com/ucp.php?i=prefs&mode=post "BBCode" should be enabled, or just uncheck "disable bbcode" before submiting.
by yancho
Tue Oct 09, 2007 11:53 pm
Forum: Wireless Networking
Topic: Adaptive noise immunity?
Replies: 1
Views: 9726

Re: Adaptive noise immunity?

by yancho
Tue Oct 02, 2007 11:35 am
Forum: Beginner Basics
Topic: >54 Mbps
Replies: 1
Views: 1280

Re: >54 Mbps

Practical maximum 802.11 g/a throughput (in ideal conditions) is around 25Mbps. So stop dreaming about 54mbps, it's air rate. You can't get anywhere closer.
by yancho
Thu Sep 27, 2007 12:49 pm
Forum: General
Topic: What is wrong!!!!
Replies: 3
Views: 1087

Re: What is wrong!!!!

I think you mistyped something. It's not possible to have such ip and subnet mask combination like: 10.5.50.200/24. Subnet mask for one host is /32 not /24. And router really have ip 10.5.50.0? So this should work: / ip address add address=169.18.0.x/24 interface=Public add address=169.18.0.y/24 int...
by yancho
Fri Sep 21, 2007 10:54 am
Forum: Beginner Basics
Topic: How to make queues determine Intra and Internet?
Replies: 12
Views: 3883

Re: How to make queues determine Intra and Internet?

Can you give some more details about your network configuration is it nated or routed. If it's natted - then you should also add local address to address list.
by yancho
Thu Sep 20, 2007 2:16 pm
Forum: Beginner Basics
Topic: How to make queues determine Intra and Internet?
Replies: 12
Views: 3883

Re: How to make queues determine Intra and Internet?

Where you lost subnet mask for 200.100.200.0 ?
Also if you have any other rules after packet-mark you should use action accept.
by yancho
Thu Sep 20, 2007 10:31 am
Forum: Beginner Basics
Topic: How to make queues determine Intra and Internet?
Replies: 12
Views: 3883

Re: How to make queues determine Intra and Internet?

1. ROS manual: http://www.mikrotik.com/testdocs/ros/2.9/ :arrow: http://www.mikrotik.com/testdocs/ros/2.9/ip/flow.php about packet flow in router :arrow: http://www.mikrotik.com/testdocs/ros/2.9/ip/mangle.php how to mangle packets :arrow: http://www.mikrotik.com/testdocs/ros/2.9/ip/address_list.php ...
by yancho
Thu Sep 20, 2007 2:01 am
Forum: Beginner Basics
Topic: How to redirect 21 port correctly?
Replies: 5
Views: 2096

Re: How to redirect 21 port correctly?

Your nat rule should work to connections from outside world - you can check it using http://www.net2ftp.com/ or ask someone else to try to connect. But looks like you are trying access FTP from LAN - 192.168.0.x ? If so try: add chain=srcnat action=src-nat to-addresses=(your local gateway ip) to-por...
by yancho
Wed Sep 12, 2007 9:26 am
Forum: General
Topic: Redirect DNS Queries
Replies: 8
Views: 7031

Re: Redirect DNS Queries

DNS mostly is UDP not TCP !!! This works for me like a charm: / ip firewall nat add chain=dstnat protocol=udp dst-port=53 action=redirect to-ports=53 \ comment="" disabled=no add chain=dstnat protocol=tcp dst-port=53 action=redirect to-ports=53 \ comment="" disabled=no / ip dns s...
by yancho
Tue Sep 11, 2007 7:38 pm
Forum: General
Topic: Attack by SSH ..
Replies: 4
Views: 1515

Re: Attack by SSH ..

Or change default ssh port to something else like 222.
by yancho
Sun Aug 05, 2007 5:40 pm
Forum: Wireless Networking
Topic: LAN can ping WAN??
Replies: 4
Views: 1690

Re: LAN can ping WAN??

http://wiki.mikrotik.com/wiki/Firewall there are some nice examples how to secure router.
by yancho
Mon Jun 18, 2007 6:08 pm
Forum: General
Topic: How to block all website except yahoo or something else...
Replies: 4
Views: 5309

Re: How to block all website except yahoo or something else...

Use nslookup :
nslookup www.google.com

Name:    www.l.google.com
Addresses:  209.85.135.99, 209.85.135.103, 209.85.135.104, 209.85.135.147
Aliases:  www.google.com
And allow them all.
by yancho
Mon Jun 18, 2007 12:28 am
Forum: General
Topic: Blocking NATed customers from sending mail
Replies: 3
Views: 1366

Re: Blocking NATed customers from sending mail

You should do this in the forward chain not output! First allow tcp traffic from your clients ips to 111.222.333.3:25 Second drop all tcp traffic to port 25 Something like this: / ip firewall filter add chain=forward src-address=(your private-nated ips) dst-address=111.222.333.3 protocol=tcp dst-por...
by yancho
Mon Jun 04, 2007 11:01 am
Forum: RouterBOARD hardware
Topic: RESET OF USERNAME AND PASSWORD
Replies: 10
Views: 20839

Re: RESET OF USERNAME AND PASSWORD

You can't reset password using jumpers.
http://wiki.mikrotik.com/wiki/MikroTik_ ... d_Recovery
by yancho
Tue Apr 03, 2007 4:50 pm
Forum: Wireless Networking
Topic: Making a better connection for my clients(Mikrotik + AR5212)
Replies: 13
Views: 3614

Then best results you should get setting channels like: http://www.extremetech.com/article2/0,1 ... 281,00.asp
by yancho
Mon Apr 02, 2007 7:53 pm
Forum: Wireless Networking
Topic: Making a better connection for my clients(Mikrotik + AR5212)
Replies: 13
Views: 3614

elj03 and elj04 has the same frequency, try change frequency to 2412, 2432, 2452, 2472
by yancho
Sun Mar 25, 2007 12:26 pm
Forum: RouterBOARD hardware
Topic: Locked out. How to recover
Replies: 4
Views: 2236

Try'd mac-telnet? if you only messed up ip configuration, router still should be accessible via mac-telnet (available via winbox, click three dots near "conncet to")
by yancho
Tue Mar 20, 2007 12:02 am
Forum: General
Topic: How to make TTL=1
Replies: 6
Views: 4314

You can't call this internet. It would be access to next router :lol:
by yancho
Sun Feb 04, 2007 11:56 pm
Forum: General
Topic: Web Proxy Maximum Size Problem..
Replies: 3
Views: 1323

Re: Web Proxy Maximum Size Problem..

How about RAM? By default the proxy cache can use as much disk space as there is allocated for it. When the system allocates the space for the proxy cache, 1/7th of the total partition (disk) size is reserved for the system, but not less than 50MB. The rest is left for the proxy cache. The system RA...
by yancho
Tue Jan 09, 2007 3:35 pm
Forum: General
Topic: Blocking client access to router
Replies: 4
Views: 1712

If you have 2.9 version, use the following rule to block the Winbox data, 'ip firewall filter add src-address=client_network_addres dst-port=8291 dst-port=tcp action=drop comment=drop_local_client_Winbox_traffic'. with some corrections ;) / ip firewall filter add chain=input src-address=client_netw...
by yancho
Fri Jan 05, 2007 7:58 pm
Forum: RouterBOARD hardware
Topic: Copy config
Replies: 2
Views: 1909

Yes, you can use export - import command.
by yancho
Fri Jan 05, 2007 12:59 pm
Forum: General
Topic: dst-nat outside dns requests
Replies: 4
Views: 1663

janisk, yep you are right, but mainly it's UDP traffic. The DNS assumes that messages will be transmitted as datagrams or in a byte stream carried by a virtual circuit. While virtual circuits can be used for any DNS activity, datagrams are preferred for queries due to their lower overhead and better...
by yancho
Thu Jan 04, 2007 10:22 pm
Forum: General
Topic: dst-nat outside dns requests
Replies: 4
Views: 1663

Change protocol to UDP ;)
by yancho
Sun Dec 24, 2006 11:36 am
Forum: Wireless Networking
Topic: Routing with no NAT
Replies: 6
Views: 2020

Re: Routing with no NAT

MT1 and PC1 has the same ip !?
PC1: 192.168.10.254 GW: 192.168.10.1

MT1
ether1: 192.168.10.254
But anyway you should use masquarade on MT2, becouse adsl router can deal only with 192.168.123.0/24 subnet.
by yancho
Wed Dec 20, 2006 11:31 pm
Forum: General
Topic: URL based DST NAT?
Replies: 4
Views: 9753

by yancho
Thu Sep 21, 2006 1:31 pm
Forum: General
Topic: QOS for Upload
Replies: 5
Views: 2787

From version 2.8 manual:
Troubleshooting:

The priority setting does not work!

In order to take the priority setting in account, you have to specify limit-at parameter. Otherwise This setting will be ignored or will not work correctly
So try to set limit-at value for all queues.
by yancho
Wed Aug 02, 2006 11:01 pm
Forum: General
Topic: Block websites by IP address?
Replies: 8
Views: 4930

Try to use nslookup to resolve all ip:
nslookup www.uwm.edu
Name:    batch1.csd.uwm.edu
Addresses:  129.89.169.224, 129.89.7.9, 129.89.70.230
Aliases:  www.uwm.edu
by yancho
Thu Jul 20, 2006 9:08 am
Forum: General
Topic: Problems with getting through router to mail server
Replies: 8
Views: 2378

Try to move masquerade rule to the bottom.
by yancho
Mon Jul 03, 2006 10:09 am
Forum: General
Topic: How to Allow SMTP/POP3 only in NAT for some local IP`s
Replies: 5
Views: 4989

/ ip firewall filter add chain=forward src-address-list=all_services action=accept comment="allow 192.168.0.x full access" disabled=no add chain=forward protocol=tcp dst-port=110 src-address-list=mail action=accept comment="allow pop3 to 192.168.0.y" disabled=no add chain=forwar...
by yancho
Sun Jun 04, 2006 11:36 pm
Forum: General
Topic: http traffic priority
Replies: 4
Views: 1725

Maybe first try to enable those rules :roll:
by yancho
Mon May 01, 2006 12:28 am
Forum: General
Topic: TCP SynCookie
Replies: 5
Views: 12105

by yancho
Tue Apr 25, 2006 12:27 am
Forum: General
Topic: Interesting
Replies: 5
Views: 2028

Re: chinese

How about the chinese ?
http://www.google.lv/translate :wink:
by yancho
Tue Apr 18, 2006 10:12 am
Forum: General
Topic: Bittorrent and MT
Replies: 16
Views: 4804

Droping all bittorent:
/ip firewall filter add chain=forward p2p=bit-torrent action=drop
by yancho
Sat Apr 15, 2006 11:56 pm
Forum: General
Topic: ip web proxy
Replies: 4
Views: 1528

Mabye start some other business like sheep breeding :wink: There are no need for queues p2p filtering and so on....
by yancho
Fri Apr 14, 2006 12:22 pm
Forum: General
Topic: MT incorrectly reporting memory?
Replies: 4
Views: 1421

http://www.mikrotik.com/docs/ros/2.9/gu ... #1.1.1.1.2

RAM - minimum 32 MiB, maximum 1 GiB; 64 MiB or more recommended
by yancho
Sun Apr 02, 2006 11:14 am
Forum: General
Topic: transparent traffic shaper
Replies: 35
Views: 12065

1. Create bridge
 /interface bridge add name=bridge
2. Add interfaces to bridge, ether1 and ether2 are interfaces names
/interface bridge port add ether1 bridge=bridge
/interface bridge port add ether2 bridge=bridge
Manual and how-to is outdated :cry:
by yancho
Sat Apr 01, 2006 1:22 am
Forum: General
Topic: How to clone NIC's MAC?
Replies: 2
Views: 1373

interface ethernet set interfacename mac-address=XX:XX:XX:XX:XX:XX
by yancho
Mon Mar 20, 2006 1:29 am
Forum: General
Topic: Port knocking
Replies: 4
Views: 1397

http://forum.mikrotik.com/viewtopic.php?t=7238 there is an example how to use address list for that purpose
by yancho
Thu Mar 16, 2006 1:00 am
Forum: General
Topic: Ban / disable user
Replies: 11
Views: 2616

upz sory little typing error:
ip firewall filter add chain=forward src-address=bad.user.ip action=drop
by yancho
Thu Mar 16, 2006 12:40 am
Forum: General
Topic: Ban / disable user
Replies: 11
Views: 2616

ip firewall filter add chain=forward src-address=bad.user.ip action=drop
by yancho
Wed Mar 15, 2006 4:26 pm
Forum: General
Topic: How to avoid dst-nat masquing origin IP address...
Replies: 5
Views: 1840

Change
chain=srcnat action=masquerade
to
chain=srcnat out-interface=ADSL action=masquerade 
by yancho
Mon Mar 06, 2006 11:43 am
Forum: General
Topic: Need help to create firewall filter rule.
Replies: 4
Views: 1527

add chain=forward in-interface=NIC3 dst-port=21 action=accept
add chain=forward in-interface=NIC3 dst-port=80 action=accept
add chain=forward in-interface=NIC3 dst-port=110 action=accept
add chain=forward in-interface=NIC3 action=drop
by yancho
Mon Feb 27, 2006 6:32 pm
Forum: General
Topic: 2.9.12 software anyone?
Replies: 13
Views: 3194

by yancho
Thu Feb 23, 2006 1:56 am
Forum: General
Topic: 2.9.14
Replies: 10
Views: 2307

Notice the resource counters at the top.. (I have not seen this before..)
Also notice 4 of them are marked CPU ??

Things that make you go " HMMMM...."

:lol:

Craig
you can add more than one resource counter :wink:
by yancho
Sun Feb 05, 2006 10:59 am
Forum: RouterBOARD hardware
Topic: 2.4 Frequency list
Replies: 8
Views: 3198

Not broken, just hotlinking disabled!
by yancho
Thu Feb 02, 2006 12:08 pm
Forum: The Dude
Topic: Chart
Replies: 1
Views: 1929

Chart

After device reboot or connection timeout link bandwidth charts displays very high values.
by yancho
Wed Feb 01, 2006 10:36 am
Forum: General
Topic: P2P connection limiting
Replies: 4
Views: 1831

Maybe try something like:
chain=forward in-interface=Local protocol=tcp dst-port=1024-65535 connection-limit=20,32 action=drop
by yancho
Tue Jan 17, 2006 11:58 am
Forum: General
Topic: Help with Mangle for QOS
Replies: 11
Views: 4763

add chain=prerouting p2p=all-p2p action=mark-connection new-connection-mark=p2p-con passthrough=yes add chain=prerouting connection-mark=p2p action=mark-packet new-packet-mark=p2p passthrough=no (all p2p) add chain=prerouting protocol=tcp dst-port=53 action=mark-connection new-connection-mark=dns-co...
by yancho
Sun Jan 15, 2006 4:14 pm
Forum: General
Topic: Cannot complete basic MT router setup
Replies: 5
Views: 2184

There is nothing there at the link you gave. What is it supposed to be.
Correct url should bet without dot :) -> http://www.mikrotik.com/docs/ros/2.9/guide/basic
by yancho
Fri Jan 13, 2006 5:16 pm
Forum: General
Topic: P2P detecion
Replies: 19
Views: 5071

Maybe we should start worry:
Core Improved: add protocol header encrypt option
by yancho
Sat Jan 07, 2006 4:54 pm
Forum: General
Topic: Rflow in MK
Replies: 1
Views: 2547

by yancho
Sun Jan 01, 2006 12:04 pm
Forum: RouterBOARD hardware
Topic: Is frequent power cycles a problem
Replies: 7
Views: 2871

or use /system shudown :)
by yancho
Wed Dec 28, 2005 12:32 pm
Forum: General
Topic: Porn blocklist Upload One Time
Replies: 2
Views: 1459

1)upload file to router via ftp
2)use terminal command /import filname
by yancho
Thu Dec 22, 2005 9:51 pm
Forum: General
Topic: Peer2peer makes me want to be near2beer
Replies: 10
Views: 3637

by yancho
Tue Dec 20, 2005 12:24 pm
Forum: The Dude
Topic: IP and gateway change
Replies: 4
Views: 3396

MAC telnet
by yancho
Thu Dec 15, 2005 9:39 pm
Forum: General
Topic: Feature Request: Conformation on disabling interfaces
Replies: 10
Views: 4910

Open winbox, click New terminal, hit [ctrl] + [x] to enter safe mode, leave terminal open and operate in winbox... Thats it. Now you get safe mode in winbox.
by yancho
Fri Dec 09, 2005 11:30 am
Forum: General
Topic: Nat ?
Replies: 6
Views: 1966

I guess yours masquerade rule is little bit wrong:
chain=srcnat action=masquerade 
change to:
chain=srcnat out-interface=Public action=masquerade 
by yancho
Mon Nov 28, 2005 10:50 pm
Forum: Wireless Networking
Topic: 2.9.8 upgrade problem
Replies: 2
Views: 1537

by yancho
Tue Nov 22, 2005 11:40 pm
Forum: The Dude
Topic: Ping without 4 packet count like in last routeros versions..
Replies: 3
Views: 2654

thanks, and the statistics also would be nice...
by yancho
Mon Nov 21, 2005 2:08 pm
Forum: General
Topic: updating from 2.9.1 to 2.9.7
Replies: 4
Views: 1373

I newer had any problems with upgrading from 2.9.x to 2.9.y
Also you can backup configuration using /export or /system bakcup
by yancho
Fri Nov 18, 2005 9:15 pm
Forum: The Dude
Topic: Ping without 4 packet count like in last routeros versions..
Replies: 3
Views: 2654

Ping without 4 packet count like in last routeros versions..

I think it would be nice..
by yancho
Thu Nov 17, 2005 2:50 pm
Forum: General
Topic: Emule upload vs download
Replies: 16
Views: 5196

First half: p2p upload limited to 512kbps pcq
second: without any limits for upload
Image
by yancho
Thu Nov 17, 2005 12:45 am
Forum: The Dude
Topic: Instant Crash V0.1 beta 13
Replies: 5
Views: 3328

The same problem...
Copy data folder to secure place, install beta12 from http://www.mikrotik.com/download/dude-i ... beta12.exe and replace data folder
by yancho
Thu Nov 17, 2005 12:20 am
Forum: General
Topic: Print Configuration
Replies: 1
Views: 22382

to screen/terminal: export
to file: export file=somefilename
by yancho
Wed Nov 16, 2005 7:49 pm
Forum: General
Topic: vajadzig biks palizib...
Replies: 5
Views: 4053

To dariit var ar: 1)ssh 2)telnet 3)winbox 4)webbox Pirmaas divas ir parastam lietotaajam nedraudziigas vides melns fons un balti burti :) lai tiktu caur ssh, vajadzees kaadu ssh klientu, piemeeram putty lai tiktu caur peedeejiem triis veram valjaa kaadu interneta paarluuku, rakstam ruutera adresiiti...
by yancho
Wed Nov 16, 2005 12:28 pm
Forum: General
Topic: firewall problem
Replies: 1
Views: 962

I think you should allow add chain=forward connection-state=related action=accept comment="accept related packets" disabled=no add chain=forward connection-state=established action=accept comment="accept established packets" disabled=no and for droping all trafic beter use add ch...
by yancho
Thu Nov 03, 2005 6:49 pm
Forum: Wireless Networking
Topic: esu cainiks un vajadziga palidziba 532 boarda konfiguresana!
Replies: 21
Views: 6189

The main disscusion was about how to find [enter] on keyboard :)
by yancho
Mon Oct 31, 2005 11:29 am
Forum: General
Topic: demonstration movies
Replies: 2
Views: 1139

Not small, bet very nice "full-length film" about internet http://www.warriorsofthe.net/
by yancho
Thu Oct 27, 2005 1:44 pm
Forum: General
Topic: [req] 2.9.6 spyware n virus ports
Replies: 21
Views: 4989

Your internet is for free? Droping all except standart web port is very cruelly...
You should specify port, like /ip firewall filter add src-address=10.10.0.0/16 dst-port=!80 action=drop chain=forward protocol=tcp
by yancho
Wed Oct 26, 2005 5:46 pm
Forum: General
Topic: Blocking Users using IP addresses
Replies: 9
Views: 2945

First put allow(accept) rules then drop. And subnet mask for one host is /32 like 10.0.0.100/32.
by yancho
Mon Oct 24, 2005 2:34 pm
Forum: The Dude
Topic: Network map don't like nonenglish char...
Replies: 0
Views: 1870

Network map don't like nonenglish char...

Network map become incantive after changing device name to nonenglish characters like ā ņ ö and so on.
by yancho
Sat Oct 22, 2005 11:22 pm
Forum: General
Topic: Problem with DNS
Replies: 2
Views: 1313

i think you should add static dns entry with your router ip and some name
by yancho
Wed Oct 19, 2005 9:55 pm
Forum: General
Topic: Policy based routing for p2p
Replies: 1
Views: 1126

Set second route as default and then route rest traffic to first gateway...
by yancho
Wed Oct 19, 2005 3:53 pm
Forum: General
Topic: How to protect DNS server
Replies: 4
Views: 3503

To be sure for 100% yes :)
Typically, UDP is employed as the transport mechanism for DNS queries and responses and TCP for Zone refresh activities.
by yancho
Wed Oct 19, 2005 3:04 pm
Forum: General
Topic: How to protect DNS server
Replies: 4
Views: 3503

/ip firewall filter add chain=input src-address=!10.0.0.0/24 protocol=udp dst-port=53 action=drop
by yancho
Thu Oct 13, 2005 5:08 pm
Forum: General
Topic: How to do client isolation on LAN (ethernet port)
Replies: 13
Views: 17354

It's not possible. Because AP acts like hub or even wire. Communication goes to AP and back to clients but not to switch behind AP! (if clients have same subnet address). Only if client is in different subnet, then traffic goes to router/gateway.
by yancho
Tue Oct 11, 2005 12:20 am
Forum: General
Topic: P2P mangle
Replies: 3
Views: 1576

There are some examples in how to: http://www.mikrotik.com/docs/ros/2.8/howto/howto
by yancho
Mon Oct 10, 2005 10:30 am
Forum: General
Topic: firewall
Replies: 6
Views: 3535

demo2.mt.lv login: demo
by yancho
Tue Oct 04, 2005 11:07 pm
Forum: General
Topic: Mystery log query
Replies: 3
Views: 1314

by yancho
Sun Sep 25, 2005 10:37 am
Forum: Scripting
Topic: TimeZone
Replies: 1
Views: 1565

And the answer is: RouterOS dosn't support daylight saving.
You have to change time zone manualy to +02:00 and change back to +02:00 at end of october and so on... There are some discussions about same problem: http://forum.mikrotik.com/viewtopic.php ... t=daylight
by yancho
Fri Sep 16, 2005 2:34 pm
Forum: General
Topic: IP-MAC records
Replies: 6
Views: 2083

yep it works for ip changes log you can use something like: /ip firewall rule forward add src-address=!x.x.x.x/32 src-mac-address=xx:xx:xx:xx:xx:xx action=drop log=yes but this code don't log mac changes for log mac changes, i guess this should help: /ip firewall rule forward add src-address=x.x.x.x...
by yancho
Wed Sep 14, 2005 9:00 am
Forum: General
Topic: Firewall rules
Replies: 1
Views: 1024

open winbox
open new terminal
type /ip firewall filter export
copy paste
by yancho
Fri Aug 19, 2005 10:21 pm
Forum: General
Topic: Server on local network - how redirect to the world ;-)
Replies: 11
Views: 2853

/ ip firewall dst-nat 
add dst-address=80.55.159.106/32:80 protocol=tcp action=nat to-dst-address=192.168.1.200 to-dst-port=80  disabled=no

/ ip firewall src-nat 
add action=masquerade disabled=no 
add dst-address=192.168.1.200/32:80 protocol=tcp action=nat to-src-address=192.168.1.2  disabled=no
by yancho
Sat Aug 06, 2005 11:30 am
Forum: General
Topic: transparent web proxy not working
Replies: 21
Views: 4430

/ip firewall dst-nat add in-interface=ether1 change to ether2 protocal=tcp dst-address:!:80 action=redirect to-dst-port=8080

the same in : ip firewall dst-nat add in-interface=ether2 protocal=tcp dst-address:!192.168.0.1/24:80 action=redirect to-dst-port=8080
by yancho
Fri Jul 15, 2005 5:46 pm
Forum: General
Topic: Best Web Filtering software with Mikrotik Router OS
Replies: 3
Views: 1761

by yancho
Fri Jul 08, 2005 10:29 am
Forum: General
Topic: how to restart router every day?
Replies: 9
Views: 5991

by yancho
Mon Apr 25, 2005 7:16 pm
Forum: General
Topic: make the MT invisibly??
Replies: 15
Views: 3897

Or change www service port, or add your computer ip in "available from"
by yancho
Mon Apr 18, 2005 9:50 pm
Forum: General
Topic: DNS Cache Issue
Replies: 18
Views: 5398

Try to add static entry with any name and your router ip.
by yancho
Tue Mar 08, 2005 10:30 am
Forum: General
Topic: Domain blocking
Replies: 3
Views: 1215

/ip firewall rule forward dst-address=domain.ip/32 action=drop
by yancho
Sat Jan 29, 2005 10:35 am
Forum: General
Topic: Port priority - not working
Replies: 1
Views: 1100

Try:
/ip firewall mangle add dst-address=10.16.13.0/24 protocol=tcp src-port=80 mark-flow=mark80
by yancho
Sat Jan 15, 2005 3:15 pm
Forum: General
Topic: Transferring Config to New Router
Replies: 7
Views: 2150

by yancho
Thu Jan 13, 2005 7:35 pm
Forum: General
Topic: Virus Problem
Replies: 10
Views: 3615

by yancho
Sun Jan 02, 2005 11:54 am
Forum: General
Topic: Max conncections
Replies: 1
Views: 1159

Yes, there is connection-limit parameter in the firewall:
add action=reject protocol=tcp src-address=10.0.0.188/32 connection-limit=50
This pasthrought 50 connections and rejects all over.
by yancho
Wed Dec 01, 2004 1:08 pm
Forum: General
Topic: give priority to icmp
Replies: 1
Views: 1183

by yancho
Fri Nov 05, 2004 12:54 pm
Forum: General
Topic: Dns cache
Replies: 7
Views: 3637

Why all cache is full with entries from non-existng network? My local network is 10.0.0.0/24, but most part of cached entries are from 10.0.0.0/8 subnet and marked as uknown type! I think it's not normal. Mabye some computer is inficed with virus or ... i don't know...
by yancho
Fri Nov 05, 2004 12:10 am
Forum: General
Topic: Dns cache
Replies: 7
Views: 3637

Dns cache

How to prevent DNS cache to fill up with such mess: 42 N 55.63.26.10.in-addr.arpa 6d18h5m32s 43 N 133.76.169.10.in-addr.arpa 6d18h5m32s 44 N 133.228.18.10.in-addr.arpa 6d18h5m33s ... 2075 N 102.89.109.10.in-addr.arpa 6d20h31m4s 2076 N 253.243.179.10.in-addr.arpa 6d20h31m5s 2077 N 201.64.87.10.in-add...
by yancho
Sat Jun 12, 2004 10:41 pm
Forum: General
Topic: Help: Setting Web Server using NAT
Replies: 4
Views: 3159

Add source - nat rule:
dst-address=192.168.0.5/32:80 protocol=tcp action=nat to-src-address=192.168.0.1/32
by yancho
Sun Jun 06, 2004 7:57 pm
Forum: General
Topic: blocking ping and syn floods..
Replies: 3
Views: 3444

I need help too... :roll: :arrow: jun/06/2004 17:42:47 forward->DROP, in:Local, out:Public2, prot TCP (SYN), 39.120.238.55:1061->152.1.3.33:113, len 40 > jun/06/2004 17:42:47 forward->DROP, in:Local, out:Public2, prot TCP (SYN), 39.120.238.56:1800->152.1.3.33:113, len 40 > jun/06/2004 17:42:47 forwa...