Community discussions

MikroTik App

Search found 103 matches

by MTNick
Mon Oct 07, 2024 6:52 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

I have made an other update to the import now being aware of any static entries added by user to the active list. Those will be saved and a count of them being displayed on import. Greetings msatter & optio. Is there a chance that the script can be updated to pull data from a JSON file? Spamhau...
by MTNick
Fri Oct 04, 2024 3:19 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

Unable to repeat the issue, sorted filter rules by interface, went to NAT, went back to filter, rules still sorted by interface. Maybe something specific in your case, email some screenshots to support please Greetings normis. I was referring to the firewall filter address-lists, not the rules. Sor...
by MTNick
Fri Oct 04, 2024 4:38 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

Greetings normis. Updated to beta9 on MacOS 15.0.1. The firewall address list. If sorting the list, and you go to another tab, the list defaults to alphabetical order. The sorting isn't being saved. I don't believe it was doing this prior to beta8, but noticed it in beta8 & is the same in beta9....
by MTNick
Sat Sep 28, 2024 3:46 pm
Forum: Beginner Basics
Topic: DNS provider with malicious blocking
Replies: 3
Views: 508

Re: DNS provider with malicious blocking

ControlD has been solid for me. You can choose what you want to block (malware, spam, adult, social, ads, etc) or keep wide open unfiltered. They support standard DNS, DoH & DoT.

https://controld.com/free-dns
by MTNick
Sat Sep 28, 2024 3:30 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

Must've just been a fluke one off, that severely angered me. Back to using Winbox4 beta... FWIW, if that's in some scheduled script, I'd add some "... print" before remove - just possibly prevent stale/in-flight config/realtime data from being used (i.e. kinda like F5 in winbox gets a ref...
by MTNick
Sat Sep 28, 2024 2:13 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

This means that beta releases of Winbox should not be used to manage remote devices/systems. Hold on. If you enter a command into the Terminal, it's the CLI that deleted those things, not poor WinBox! WinBox4 is just running a terminal session for you. It's the find command that not doing what you ...
by MTNick
Fri Sep 27, 2024 3:15 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

Abandoning Winbox 4 for now until a stable is released. I issued a command to delete an address list, that is dynamic, but instead it deleted almost every single address, including statics, in the address-list. Not just the specific "z-blocklist_FireHOL_L1" list, but all of them, even nam...
by MTNick
Thu Sep 26, 2024 8:17 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

Abandoning Winbox 4 for now until a stable is released. I issued a command to delete an address list, that is dynamic, but instead it deleted almost every single address, including statics, in the address-list. Not just the specific "z-blocklist_FireHOL_L1" list, but all of them, even name...
by MTNick
Thu Sep 26, 2024 3:47 pm
Forum: Beginner Basics
Topic: Beginner fail to port forwarding [SOLVED]
Replies: 10
Views: 1218

Re: Beginner fail to port forwarding [SOLVED]

Why are you only allowing ICMP from LAN. If you block ICMP from WAN you break Path MTU Discovery. ICMP should not be blocked for a properly functioning network. If you want to block ping, then only block ICMP echo request. Oof. Good catch CGGXANNX. Didn't notice that. I took the ops rules & edi...
by MTNick
Wed Sep 25, 2024 9:09 pm
Forum: Beginner Basics
Topic: Beginner fail to port forwarding [SOLVED]
Replies: 10
Views: 1218

Re: Beginner fail to port forwarding [SOLVED]

After a few weeks doing something else, thank you so very much @MTNick it works :)
Very much appreciated !

No problem. Glad to help & know it resolved your issue. Can you mark this thread as "solved" to help others out please.
by MTNick
Thu Sep 19, 2024 3:53 am
Forum: Scripting
Topic: Find External IP ? [SOLVED]
Replies: 29
Views: 96032

Re: Find External IP ? [SOLVED]

Jotne, I want to put the dynamic wanip in a dstnat rule. Note the comment for identification/location purposes. /ip firewall nat chain=dstnat dst-address-type=local in-interface=WAN2 protocol=udp dst-port=wg-port action=dst-nat to-addresses=dynamic-ip comment= "wireguard-workaround' The only s...
by MTNick
Fri Sep 13, 2024 6:01 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

@normis & mikrotik dev team

Short & simple, the improvements in this update are outstanding & implemented very well. Thank you for listening to the users. Keep up the good work
by MTNick
Fri Sep 13, 2024 4:32 am
Forum: Beginner Basics
Topic: DNS Issue
Replies: 8
Views: 926

Re: DNS Issue

Greetings. That's no where close to the config requested. If your goal is to have the Mikrotik handle the DNS requests, below is a firewall config that'll work. And it'll redirect any requests back to the Mikrotik. Also a better implementation to block any unauthorized DNS requests coming in on port...
by MTNick
Wed Sep 11, 2024 5:24 pm
Forum: Beginner Basics
Topic: Beginner fail to port forwarding [SOLVED]
Replies: 10
Views: 1218

Re: Beginner fail to port forwarding [SOLVED]

Greetings. Below are cleaned up firewall rules for input & forward chains. I also added a Hairpin NAT rule just in case you're trying to use a web address vs an IP address within your network. Start with editing your firewall rules with the below. Also, like MKX mentioned, the ISP may be blockin...
by MTNick
Wed Sep 11, 2024 4:26 pm
Forum: Beginner Basics
Topic: DNS Issue
Replies: 8
Views: 926

Re: DNS Issue

Greetings. Do you have allow remote requests enabled?

You can also export your config so it can be looked at, delete or mask any important info from it:
/export file=anyname
/ip dns
set allow-remote-requests=yes servers=76.76.2.2,76.76.10.2,1.1.1.2,1.1.1.1
by MTNick
Mon Sep 02, 2024 4:00 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

Hi Normis. It's the comments, especially when a rule is disabled. Zoom set to 84%. You're right though, screenshot doesn't capture real world scenario but, the grey text in comments is hard to read. The main black text is clear & visible. No issue there.

Screenshot 2024-09-02 at 8.50.59 AM.png
by MTNick
Mon Sep 02, 2024 3:26 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

********** STATUS UPDATE *************** Known issues to be addressed: Improve contrast in both light and dark modes for old displays with low contrast ratio Same as nz_monkey. My devices are not old. The text is too light MacBook Air M3 w/16gig ram (2024) Screen: 15.3" Mac Mini M2 Desktop w/8...
by MTNick
Sun Sep 01, 2024 3:59 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1308
Views: 249058

Re: 📣 WinBox 4 is here 📣

MacBook Air M3 w/16gig ram Screen: 15.3" macOS Sonoma 14.6.1 Mac Mini M3 Desktop w/8gig ram Screens: 27" & 2 x 24" macOS Sonoma 14.6.1 Devices: RB5009, hEX & hEX-S All on ROS 7.15.2 First, a big Thank You to Mikrotik. I didn't like the app at first (love the classic v3). But a...
by MTNick
Mon Aug 12, 2024 3:56 pm
Forum: Beginner Basics
Topic: Port Fowarding on Internal Network
Replies: 8
Views: 1015

Re: Port Fowarding on Internal Network

Greetings. You can give the below a try. BTW, the proper way to reach an address with a specific port in browser is http://10.0.0.100:8888 /ip firewall nat add action=redirect chain=dstnat comment="Redirect port 8888_to_80" dst-port=8888 in-interface-list=LAN protocol=tcp to-ports=80 src-a...
by MTNick
Sun Jul 14, 2024 7:01 am
Forum: Beginner Basics
Topic: Wireguard no handshake on iOS
Replies: 4
Views: 1039

Re: Wireguard no handshake on iOS

Greetings. You're missing the wireguard interface from the interface member list. Missing the biggest part, the firewall rule in the input chain. Wireguard peers might need to be adjusted. Start with the first 2. Lastly, if you can't connect, adjust peers. Hope this helps /interface list member add ...
by MTNick
Thu Jun 13, 2024 1:35 am
Forum: Beginner Basics
Topic: ISP Bridge Mode cause issue on RB5009 [SOLVED]
Replies: 21
Views: 3093

Re: ISP Bridge Mode cause issue on RB5009 [SOLVED]

Assigning the DNS IP in DHCP-Server Network, all devices attached, either by wireless or wired, will adhere to the set DNS server. Assuming the RB5009’s IP address is 10.0.0.1 /ip dhcp-client add interface="sfp-sfpplus1[WAN]" use-peer-dns=no use-peer-ntp=no add-default-route=yes default-ro...
by MTNick
Wed Jun 12, 2024 8:13 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 655
Views: 257161

Re: v7.15.1 [stable] is released!

RB5009, hex & hex-s upgrade went well & working as intended. System seems more responsive, especially on both hex’s
by MTNick
Wed Jun 12, 2024 8:03 pm
Forum: Beginner Basics
Topic: ISP Bridge Mode cause issue on RB5009 [SOLVED]
Replies: 21
Views: 3093

Re: ISP Bridge Mode cause issue on RB5009 [SOLVED]

Just to test, eliminate the RB5009 DNS server. 1. Enable peer dns (check mark) in DHCP-Client for WAN. Check ping to 8.8.8.8 again. If you can ping after eliminating the RB5009 DNS server, turn the DHCP-Client peer DNS off (no check mark) in DHCP-Client. Then try: 1. Your DHCP-Server DNS is set wron...
by MTNick
Tue May 28, 2024 2:40 am
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 84937

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Completely lost on this post... Which is the latest script version? msatter provided a script here https://forum.mikrotik.com/viewtopic.php?p=1067023#p1067224 . Works great & has full logging, every step it takes is logged, including the amount of addresses. Backs up current list just in case &...
by MTNick
Thu Apr 11, 2024 1:56 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

You will need to change the Routing Rule on Router B, the action option......... to just lookup /routing rule src-address=LANIP action= lookup table=useWG The current rule will prevent the router from using any other routing. In other words, you DO NOT NEED any script to enable local use of the WAN...
by MTNick
Thu Apr 11, 2024 1:31 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

Greetings. Connectivity is good. The one specific device/IP is using the wireguard tunnel for internet on Router A. Cleaned up the firewall rules & address list. Removed the mangle rules as well. Removed: I added 2 scripts to ping Router A LAN subnet via Router B wireguardB interface. What it'll...
by MTNick
Wed Apr 10, 2024 5:41 pm
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

Sorry, I changed all your wireguard1 entries, on Router B, to wireguardB. Call me anal, but when looking at a config I want to know intuitively which of two or three or more configs I am looking at. Using the same name on both RouterA and RouterB is not clear to me and thus prefer to distinguish. P...
by MTNick
Wed Apr 10, 2024 4:30 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

The big change on Router B seeing as you want internet access but out Router A is changing Allowed IPs........... Many other small changes............... read line by line Simplified firewall rules!!!! For single subnets avoid interface lists............ in general. Thanks anav!! Kinda figured a ro...
by MTNick
Wed Apr 10, 2024 2:37 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

Yee of little faith LOL.

Now the next step is ensuring LAN from Router B, goes out the WAN of ROuter A for internet ( via the wireguard tunnel)??
Yes, that's correct, but only for a single device 192.168.88.5. The rest of Router B devices/subnet to use Router B's internet.
by MTNick
Wed Apr 10, 2024 2:07 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

Understood, but for me adding extra rules like mangling can interfere with testing other things, especially if you have errors in the mangle. (compoundinig), not that there is,, just sayin. Your first attempt at correction isnt right on both accounts......... attention to detail please!!! Greetings...
by MTNick
Wed Apr 10, 2024 12:54 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

Router B. Missing two things: /interface wireguard peers add allowed-address= 192.168.202.0/24 ,192.168.201.0/24 endpoint-address=123.456.789.1 endpoint-port=23231 interface=wireguard1 public-key="***********************************************=" persistent-keep-alive=35 have to move on, ...
by MTNick
Mon Apr 08, 2024 3:37 pm
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

Which WAN, A or B has a public IP, static or dynamic that is reachable. If neither does, does one of them have an upstream ISP router that you can forward a port on? If both have a publicly reachable IP, which one do you want to act as initiation peer ( client for handshake) and which one do you wa...
by MTNick
Mon Apr 08, 2024 3:57 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Re: Redirect Router B to Router A through wireguard [SOLVED]

Anav, adjusted. Hope this clears it up Main Router A: - WAN: 123.456.789.1 (made up WAN IP) -- FW address-list for WAN is "RB5009" on both routers. (there is a firewall address list on both routers, A & B, that has Router A's WAN address, named RB5009) - LAN: 192.168.201.1/24 -- FW add...
by MTNick
Mon Apr 08, 2024 2:15 am
Forum: Beginner Basics
Topic: Redirect Router B to Router A through wireguard [SOLVED]
Replies: 19
Views: 3701

Redirect Router B to Router A through wireguard [SOLVED]

Greetings everyone. Need a little help redirecting a few devices in a firewall address list at a remote router through the main routers WAN using wireguard. The wireguard is configured as site-to-site. LANs are accessible on both sides as intended. Wireguard connectivity is not the issue. Below are ...
by MTNick
Tue Apr 02, 2024 3:31 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greeting msatter. Thank you. I removed all "" from the URL for all of the lists. I had no idea that this caused issues. Happy to report that everything is working great!
by MTNick
Tue Apr 02, 2024 12:57 am
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

@msatter Perfect! The above script is awesome. It's smooth & every step is logged with entry counts as well. Once again, I can't thank you enough. Thank you for this update & cleaning up the dirt I added to your script :D I know nothing about scripting. But, I'll attempt anything with some d...
by MTNick
Mon Apr 01, 2024 7:13 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

@MTNick that is correct, because of the heirule=http. Only importing lines containing "http" in the word(s) after each line. If you want to import all, then omit the heirule. This way you can create different address-lists from the same source file. msatter, Thank you for the explanation ...
by MTNick
Mon Apr 01, 2024 6:25 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greetings msatter. I have tried that delimiter, several of them, including not listing one. Neither work. Below are the spamhaus links: $update url="https://' . "www.spamhaus.org/drop/drop.txt" delimiter=("\_") listname=z-blocklist-SpamHaus timeout=2d $update url="http...
by MTNick
Mon Apr 01, 2024 1:56 am
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Did you check that script is actually working correctly? Try to find all matching lines from downloaded file with regex ^[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}.*http.*$ and you will see that 2935 lines are matching for import and from your log count is 2934, as I analized last matching line...
by MTNick
Mon Apr 01, 2024 1:38 am
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

@MTNick from the spamhaus topic you need the delimiter=("\_") If you have the link for me then I could have a look at it? Greetings msatter. I have tried that delimiter, several of them, including not listing one. Neither work. Below are the spamhaus links: $update url="https://' . &...
by MTNick
Sun Mar 31, 2024 10:26 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greetings optio. I added the code you provided to the "delete addresses" & "importing addresses. Works great. Very happy here. Thank you so much for helping me out! @msatter. No need to apologize. It's my fault for not looking through the script thoroughly. What you & rextende...
by MTNick
Sun Mar 31, 2024 7:01 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greetings optio. The only thing the logging is missing is the total count of the imported IP addresses per list. How can I add the total count imported? The script will have more lists. I have quite a few lists actually, totaling around 80k addresses
by MTNick
Sun Mar 31, 2024 5:40 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greetings optio. I changed the line as you suggested. It downloaded it once, as you indicated it will do & avoid another download for file size. But logging, is non existent. Only tell me that download is finished. It also seems to keep the file on the router. It doesn't delete it. Is that inten...
by MTNick
Sun Mar 31, 2024 5:24 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greeting optio. Yep, that's what it was. Caught it after I posted. Stupid me didn't notice it until a second look lol. Thank you for the quick catch & help
by MTNick
Sun Mar 31, 2024 5:22 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greetings msatter. It works now. The issue was a source address in the script. Removed it. But logging only logs the download a s finished, nothing else. See screenshot below. RB5009 ROS 7.14.2 Removed src-address from script. Now works :local filesize ([/tool fetch url=$url src-address=10.10.10.10 ...
by MTNick
Sun Mar 31, 2024 5:15 pm
Forum: Scripting
Topic: Is 8MB in a variable from a txt file is possible?
Replies: 57
Views: 5971

Re: Is 8MB in a variable from a txt file is possible?

Greetings msatter. I tried the script above but it fails & returns the error below: Download from view.sentinel.turris.cz FAILED: could not bind: Address not available Same with testing spamhaus: Download from www.spamhaus.org FAILED: could not bind: Address not available Address resolves & ...
by MTNick
Sat Mar 30, 2024 2:06 am
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 84937

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Good call. No I didn't. But, I just did lol. I seem to believe another poster in here had same issue way above ( https://forum.mikrotik.com/viewtopic.php?p=1066787#p1051112 in this thread as I do below. Same script as well Starting import of address-list: spamhaus Conditional deleting all entries in...
by MTNick
Sat Mar 30, 2024 1:54 am
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 84937

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Greetings kevinds. Unfortunately I've tried that. It starts the download, then script just stops. I'm testing it on its own, the only one in the script & fails. Every other link works. Not sure what's up with it. No reason in the log, script just stops { /ip firewall address-list :local update d...
by MTNick
Thu Mar 28, 2024 11:56 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 295
Views: 84937

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

Due to problem with "\n" have to be set manually I have adapted the script to do this for your this when no delimiter has been found: { /ip firewall address-list :local update do={ :put "Starting import of address-list: $listname" :if ($nolog = null) do={:log warning "Start...
by MTNick
Sun Feb 25, 2024 12:27 am
Forum: Beginner Basics
Topic: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP
Replies: 39
Views: 2646

Re: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP

You're right, the Hairpin NAT has 0 traffic in the counters. So, it's not needed. Tested, proved lol If access using LAN is working, I'd say the OP is wrapped up. OP stated external access is good. Now internal access is as well. The NAT rule is needed if not keeping DNS static. Seems you should acc...
by MTNick
Sun Feb 25, 2024 12:16 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Thanks Mesquite. Appreciate the kind words. Went ahead & configured the main router with the final version. Thanks for the heads up to look at pcc setting if any web activity that isn't working as it should. Time will tell To summarize what this thread accomplished: 1. 3 ISP (dynamic) w/Load bal...
by MTNick
Sat Feb 24, 2024 7:53 pm
Forum: Beginner Basics
Topic: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP
Replies: 39
Views: 2646

Re: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP

@MTNick I can confirm that adding a static DNS rule: /ip/dns/static add name=mydomain.com match-subdomain=yes address=192.168.88.5 allows me to disable the WANIP from the AddressList and everything is still working. Which configuration is more beneficial? That I'm not sure of. Mesquite may be able ...
by MTNick
Sat Feb 24, 2024 5:26 pm
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Hello Mesquite. Happy to report that this is working beautifully. I've been testing it before reporting back. Server is not behind it, just some local resources mainly streaming YouTubeTV. I took your advise on changing the route comments & the dhcp-client script to only include 1 command to upd...
by MTNick
Sat Feb 24, 2024 4:34 pm
Forum: Beginner Basics
Topic: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP
Replies: 39
Views: 2646

Re: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP

Good morning Mesquite. You're absolutely right. I either missed that part or forgot about while going over the config. Conclusion: beer, configs & forum don't mix. Apologies! From the config, I'm the same, it should be working. 3. If the MYIP list only contains 192.168.100.100 a. external users ...
by MTNick
Sat Feb 24, 2024 5:32 am
Forum: Beginner Basics
Topic: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP
Replies: 39
Views: 2646

Re: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP

I think I found the problem. In the NAT rule for the server, the "dst-address=" should be your ISP address, not the local LAN IP. add action=dst-nat chain=dstnat dst-address-list=MyIP dst-port=80 protocol=tcp to-addresses=192.168.88.5 to-ports=81 Should be: add action=dst-nat chain=dstnat ...
by MTNick
Sat Feb 24, 2024 4:25 am
Forum: Beginner Basics
Topic: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP
Replies: 39
Views: 2646

Re: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP

Hi Mesquite. Stop yelling at me lmao (1) The hairpin nat rule is port/protocol agnostic. Not required. He has the correct rule. ----- Didn't know this. But still, this rule works haha. (2) The dstnat (port forwarding rules) can very much so have a different dst port, the one hitting the router, and ...
by MTNick
Sat Feb 24, 2024 3:46 am
Forum: Beginner Basics
Topic: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP
Replies: 39
Views: 2646

Re: Problem with port forwarding on L009UiGS, double NAT, dynamic WANIP

Hello atais & Mesquite. Hoping I can help out on this one. Looking at the Hairpin NAT rule. It's missing the protocol & you might as well add the out-interface-list=LAN. I've got the same scenario that's been working well for a long time. I can access my server behind my LAN via external web...
by MTNick
Fri Feb 23, 2024 6:34 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Thanks! Appreciate the confidence booster. You explain things very well & in detail. It's been a task to take these last few days lol. But like you said, we'll get there. Does this revision (fingers crossed) get the Mesquite stamp of approval?? /routing table add fib name=to_ISP1 add fib name=to...
by MTNick
Fri Feb 23, 2024 5:00 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

I over think things. That's for sure. I make one change & think it'll need changed in some way lol. Case in point the previous config I posted & then mucked it up. Over thinking it
by MTNick
Fri Feb 23, 2024 4:48 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Ahhhh got ya now. Apologies. Once again, I misunderstood. Updating...

Updated the config in the above post
by MTNick
Fri Feb 23, 2024 4:39 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Scratch the last post. I misunderstood your direction. Don't know what I was thinking lol. Config is updated below... /routing table add fib name=to_ISP1 add fib name=to_ISP2 add fib name=to_ISP3 add fib name=1then2 add fib name=1then3 add fib name=2then1 add fib name=2then3 add fib name=3then1 add ...
by MTNick
Fri Feb 23, 2024 3:42 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Are you sure about this? 6/0 --> AthenB traffic to WAN1 ( 1/6 ) 6/1 --> Bthen A traffic to WAN2 ( 1/6 ) 6/2 --> Cthen A traffic to WAN3 ( 1/6 ) 6/3 --> Athen traffic to WAN1 ( 1/6 ) <--- Missing letter 6/4 --> BthenC traffic to WAN2 ( 1/6 ) 6/5 --> CthenB traffic to WAN3 ( 1/6 )
by MTNick
Fri Feb 23, 2024 3:30 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Why did you remove the SPECIFIC Table routes?
The clue is if you kept them in the tables listing created, you should be using them!
Remember this is for server traffic so you should use them............

Yup, I'm reverting. Standby
by MTNick
Fri Feb 23, 2024 3:21 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Lol. You posted right after I updated. Look again lol. I may have mucked it up

Update. On second thought. Don't look yet. Let me make the changes to the incoming mangle rules & change what I updated lol...
by MTNick
Fri Feb 23, 2024 1:22 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Ok, here's what I got. I haven't configured yet, just "made" the config for verification prior to executing. With creating the new routes that check-gateway=ping, would that affect the recursive GW's? I changed the tables for AthenB to 1then2 and so on. Just to keep it uniform with the num...
by MTNick
Thu Feb 22, 2024 5:35 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Apparently so lmao. Putting more work on me eyyyyyy. Alright, I'm up for it. Will let you know how it goes tomorrow
by MTNick
Thu Feb 22, 2024 4:33 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

That's great news! Thanks for your stamp of approval! Now off to update the config on the active router. It never ends haha
by MTNick
Thu Feb 22, 2024 1:12 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Hello Mesquite

I went ahead & implemented the recursive as well. Hopefully it's correct if I understood your directions. I also changed the dhcp-client script to update ISPx-Recursive instead of ISPx-MainTable.


Screen Shot 2024-02-21 at 6.09.38 PM.png
by MTNick
Wed Feb 21, 2024 11:33 pm
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Awesome, I need we could get there, the journey is the fun part! Hi Mesquite. Indeed it is & was. Thank you for everything & helping me out with this. It's working perfectly. For shits & giggles, I randomly moved the cables around earlier today (ISPs/WANs) between ether1-ether3 & th...
by MTNick
Wed Feb 21, 2024 5:45 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Hello Mesquite Happy to report the dhcp-client script is updating all routes, didn't have to reboot this time. Changed the GW two more times for sake of sanity haha. The pcc load balancing is working perfect. As a matter of fact everything is working perfectly. Thank you so much for your time & ...
by MTNick
Wed Feb 21, 2024 12:30 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Try this iteration......... for the three scripts.......... should work. :if ($bound=1) do={ :local gw $"gateway-address" /ip route set [ find comment="ISP1-MainTable" gateway!=$gw ] gateway=$gw /ip route set [ find comment="ISP1-SpecificTable" gateway!=$gw ] gateway=$...
by MTNick
Tue Feb 20, 2024 11:24 pm
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

standard export is fine.........i use notepad++

Sounds good. I'll reply back in a few hours with the full config. Thank you Mesquite
by MTNick
Tue Feb 20, 2024 11:07 pm
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Correct. I'll put it back to test that way you'll see the full config, along with the IP info. Allow me some time to do this. I'm not in front of it at the moment. I'll provide the full unedited config later tonight. Is there a certain way you want me to export the config? Or is the standard "e...
by MTNick
Tue Feb 20, 2024 9:36 pm
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

I printed the routes. When I export using "export verbose file=" or "export file=", the defaults created by dhcp-client don't show up. Only the manually created routes do. Let me know if there's a way to print it properly. If not, if you'd like, I can create the command similar t...
by MTNick
Tue Feb 20, 2024 8:27 pm
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Hello Mesquite You were right! I put the hex in a live environment & the counters in the first 2 sets of mangle rules are now working. I personally like the differentiation as its really different traffic we are marking, the similarity is we push that traffic to the same routes, via using the sa...
by MTNick
Tue Feb 20, 2024 6:24 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Greeting Mesquite That worked! Changing the chain to prerouting vs forward. I can access via IP. All ISP's have equal amounts of traffic shown in interfaces. But, the counters in the mangles rules are at 0 for the first 2 sets of rules. Everything seems to be working though. Does it matter is the co...
by MTNick
Tue Feb 20, 2024 3:42 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Greetings Mesquite Apologies for the delay in response. I made the changes. I ended up losing access to the hex. I couldn't login using the IP 192.168.88.1. I was able to regain access by using the mac method in the neighbors tab in winbox. I disabled the mangle rules & was able to gain access a...
by MTNick
Mon Feb 19, 2024 1:35 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Thank you Mesquite. I will adjust the config & report back shortly
by MTNick
Mon Feb 19, 2024 12:04 am
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

Re: 3-ISPs Load Balancing - need help [SOLVED]

Can you confirm that ISP1,2,3 are providing static fixed WANIPs, or dynamic WANIps Are they all from the same provider? Do you have any external traffic going to the router itself (aka wireguard handshake for example) Do you have any LAN servers that external traffic expects to hit........... Hello...
by MTNick
Sun Feb 18, 2024 10:55 pm
Forum: Beginner Basics
Topic: 3-ISPs Load Balancing - need help [SOLVED]
Replies: 51
Views: 8333

3-ISPs Load Balancing - need help [SOLVED]

Hello everyone. Need some help on triple ISP config with PCC load balancing. Looking for assistance to please look at the mangle & routing rules. Also the DHCP-client script. Config & concerns are below. HEX on ROS 7.13.4 using winbox ISP1: ether1 (100/100) ISP2: ether2 (100/100) ISP3: ether...
by MTNick
Mon Jan 29, 2024 8:05 pm
Forum: General
Topic: wireguard problem
Replies: 15
Views: 2545

Re: wireguard problem

Hello. Below is an example of what worked for me. Change the dst & src address list to match the subnets you're trying to reach from your own address lists. Place this in the forward chain section. Hope this helps /ip firewall filter add action=accept chain=forward comment="allow multi-subn...
by MTNick
Mon Jan 29, 2024 4:52 am
Forum: General
Topic: Triple WAN PCC Load Balancing validation - debloat
Replies: 0
Views: 674

Triple WAN PCC Load Balancing validation - debloat

Hello everyone. I have 3 WAN's that I setup as load balancing pcc. Everything seems to work well but I'd like to know if there is bloat in my config or any cleaner with less mangle rules if possible. I followed the below to configure it: YouTube video: https://www.youtube.com/watch?v=nlb7XAv57tw PCC...
by MTNick
Sat Jan 20, 2024 9:01 pm
Forum: Beginner Basics
Topic: Accessing device across subnets
Replies: 1
Views: 644

Re: Accessing device across subnets

Hi, I used the MikroTik android app wizard with default config to setup my hAP lite. Port 1 is connected to my ISP router. Port 2 is connected to my LG TV running webOS. My PC is connected to my ISP router. Under IP > Address I currently have: 192.168.1.70/24 on ether1 and 192.168.88.1 on bridge. M...
by MTNick
Wed Jan 17, 2024 3:07 am
Forum: Beginner Basics
Topic: doh server connection error network is unreachable over DNS 1.1.1.1
Replies: 54
Views: 11360

Re: doh server connection error network is unreachable over DNS 1.1.1.1

Above, a member wrote about three certificates: Above, one member obscure public availabledata on image, so who trust? Someone who has posted little on the forum, just registered, or someone who has written more and is member from long time? Installing the three certificates in the PEM chain that y...
by MTNick
Sat Jan 13, 2024 12:37 am
Forum: Beginner Basics
Topic: Cloudflare DoH working
Replies: 15
Views: 21792

Re: Cloudflare DoH working

preemptive strike https://www.ssl.com/how-to/install-ssl-com-ca-root-certificates/#ftoc-heading-4 SSL_COM_TLS_ECC SSL.com SSL Intermediate CA ECC R2 SSL.com Root Certification Authority ECC According to Cloudflare community Great find! If you look at this link: https://community.cloudflare.com/t/up...
by MTNick
Fri Jan 12, 2024 8:50 pm
Forum: Beginner Basics
Topic: Cloudflare DoH working
Replies: 15
Views: 21792

Re: Cloudflare DoH working

According to Cloudflare, as long as you have the DigiCert Global Root G2, not the DigiCert Global Root CA, it should update automatically. Go to https://1.1.1.1 , click on the lock icon & export the "DigiCert Global Root G2" certificate. Import to Mikrotik. Per Cloudflare https://commu...
by MTNick
Thu Jan 11, 2024 3:46 pm
Forum: Beginner Basics
Topic: doh server connection error network is unreachable over DNS 1.1.1.1
Replies: 54
Views: 11360

Re: doh server connection error network is unreachable over DNS 1.1.1.1

The situation is simple: Cloudflare updates the https certificate every 2 years (last time done on 30 Dec 2023). This time DigiCert did not sign the certificate with the old key, but with the new one, so the root certificate is no longer valid. So probably every 2 years or less (it can happen at an...
by MTNick
Thu Jan 11, 2024 3:40 pm
Forum: Beginner Basics
Topic: doh server connection error network is unreachable over DNS 1.1.1.1
Replies: 54
Views: 11360

Re: doh server connection error network is unreachable over DNS 1.1.1.1

Pardon me, thisis complicated for me to understand :) So, basically the workaround is to run these commands one by-one from this thread : /ip dns set allow-remote-requests=yes doh-max-concurrent-queries=100 \ doh-max-server-connections=20 doh-timeout=6s servers=1.1.1.1,1.0.0.1 \ use-doh-server=http...
by MTNick
Thu Jan 11, 2024 3:28 pm
Forum: Beginner Basics
Topic: doh server connection error network is unreachable over DNS 1.1.1.1
Replies: 54
Views: 11360

Re: doh server connection error network is unreachable over DNS 1.1.1.1

NEVER get certificates from 3rd parties, downloading stuff like this from anonymous user google drive is very dangerous. Do what the DNS documentation tells you to do. Go to the address you configured as your DoH address and download certificate from your browser, by clicking on the padlock icon ht...
by MTNick
Thu Jan 11, 2024 12:25 am
Forum: Beginner Basics
Topic: doh server connection error network is unreachable over DNS 1.1.1.1
Replies: 54
Views: 11360

Re: doh server connection error network is unreachable over DNS 1.1.1.1

Hello everyone. Here are the certs for Cloudflare obtained today. Unable to attach them, here's a link to g-drive

Link Removed

If you need help/direction setting it up, follow what wfburton said: Cloudflare DoH working viewtopic.php?t=201784
by MTNick
Wed Jan 10, 2024 11:56 pm
Forum: Beginner Basics
Topic: Difficulty Configuring Port Forwarding on RouterOS for Website Hosting
Replies: 2
Views: 794

Re: Difficulty Configuring Port Forwarding on RouterOS for Website Hosting

Greetings Joe, As anyone here will tell you, post you config using the command below. Download it & remove any identifying/important info from it. /export file=whateveryoucallthefile Hopefully you have your interface member list proper as well, indicating the LAN/WAN interfaces like the example ...
by MTNick
Wed Jan 03, 2024 3:52 am
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 33
Views: 25739

Re: Force Users to Use Specific DNS Server

It is not clear what firewall rule you are talking about??
Greetings Anav,

This one, specifically the udp:
/ip nat
add action=redirect chain=dstnat dst-port=53 in-interface-list=LAN protocol=tcp
add action=redirect chain=dstnat dst-port=53 in-interface-list=LAN protocol=udp
by MTNick
Tue Jan 02, 2024 11:31 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 33
Views: 25739

Re: Force Users to Use Specific DNS Server

You allow access to external server 185.228.168.9 is also okay as it looks to be another DNS service....... Yes just in case Cloudflare is down. So quickly I see nothing untoward........... What happens when a user uses google in a browser search or google mail or something like that, perhaps event...
by MTNick
Tue Jan 02, 2024 10:25 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 33
Views: 25739

Re: Force Users to Use Specific DNS Server

Negative, to ports is implied to be the same as dstports if not entered. To-Ports is this really used when doing port translation. What is important is such sweeping rules in-interface-list=LAN is to ensure you exclude the pI LAN address or any other subnets not being subjegated to PI. /ip nat add ...
by MTNick
Tue Jan 02, 2024 9:26 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 33
Views: 25739

Re: Force Users to Use Specific DNS Server

Crystal clear!! Then the solutions become. A. Force Redirect to OPENDNS (without PI hole) /ip dns set allow-remote-requests=yes servers=208.67.222.222,208.67.220.220 /ip nat add action=redirect chain=dstnat dst-port=53 in-interface-list=LAN protocol=tcp add action=redirect chain=dstnat dst-port=53 ...
by MTNick
Wed Nov 29, 2023 2:59 am
Forum: Beginner Basics
Topic: Can't access or ping devices in a LAN over WireGuard tunnel
Replies: 7
Views: 6020

Re: Can't access or ping devices in a LAN over WireGuard tunnel

I took a look at the link provided by Anav. It's a lot to soak in. Great writeup and worth the read! It works better than what I posted previously. The below allows access to LAN & WAN. A bit of advise, use the Mikrotik WG Peer in Winbox to add the peers. When configuring the peers, leave the Pu...
by MTNick
Tue Nov 28, 2023 10:50 pm
Forum: Beginner Basics
Topic: Cloudflare DoH working
Replies: 15
Views: 21792

Re: Cloudflare DoH working

Thanks! Downloaded. Those match what I have for Cloudflare. What is the Teams certificate? I use Teams daily with no issue without that certificate
by MTNick
Tue Nov 28, 2023 10:38 pm
Forum: Beginner Basics
Topic: Can't access or ping devices in a LAN over WireGuard tunnel
Replies: 7
Views: 6020

Re: Can't access or ping devices in a LAN over WireGuard tunnel

The below will help. I had the same problem. Put this in the input chain section, above "drop all else" in that section, of the firewall filter rules. You may not need the second one. /ip firewall filter add action=accept chain=input comment="Rule: allow WireGuard" dst-port=your ...
by MTNick
Mon Nov 27, 2023 5:43 am
Forum: Beginner Basics
Topic: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing
Replies: 2
Views: 1776

Re: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing

Hello Anav. Fair enough. I went ahead & changed the firewall using the Apprentice setup. Much cleaner. There are typo's in there which failed in the terminal while adding. Below the failed code is the new firewall. Let me know what you think. Thank you for looking/verifying. Appreciate it! Code ...
by MTNick
Sun Nov 26, 2023 9:23 pm
Forum: Beginner Basics
Topic: Cloudflare DoH working
Replies: 15
Views: 21792

Re: Cloudflare DoH working

Hello wfburton. Thanks for the post. My Cloudflare DoH is working, it always has worked. I made a post to let others know that it does work along with the config. Apologies, I assumed that people would already have the security certificates installed. Downloading certificates from other websites isn...
by MTNick
Sun Nov 26, 2023 4:50 pm
Forum: Beginner Basics
Topic: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing
Replies: 2
Views: 1776

Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing

Greetings everyone. I have configured the hEX S for 2 networks, one just for testing. I'm requesting someone to review the configuration to check if I'm missing anything or have too many rules in place (or redundant) & if they're in the proper order. The default config was wiped & started fr...
by MTNick
Fri Nov 24, 2023 6:56 am
Forum: Beginner Basics
Topic: Cloudflare DoH working
Replies: 15
Views: 21792

Cloudflare DoH working

Hello everyone. I noticed some people having problems with DoH. Especially after a reboot. Seems https DNS query isn't working after a reboot until the certificates are updated. Resolved by setting static DNS because it needs set to update the certificates. No issues whatsoever after implementing th...