Community discussions

MikroTik App

Search found 24 matches

by hippo
Mon Jun 29, 2009 8:44 pm
Forum: General
Topic: problems with ping and src-address
Replies: 4
Views: 8606

Re: problems with ping and src-address

Thanks for quick answer! Confirmed it, did a packet dump on the 10.0.0.2 device and noticed ICMP packages for 192.168.255.5 comming with src addr 10.0.0.1. Don't have any nat configured on the device, only some IPSEC config (that's why I noticed it since it wouldn't match the policy and therefor not...
by hippo
Mon Jun 29, 2009 8:26 pm
Forum: General
Topic: problems with ping and src-address
Replies: 4
Views: 8606

problems with ping and src-address

Hi, If someone could verify this problem or tell me what I'm doing wrong it would be great :) addresses: 0 10.0.0.1/24 10.0.0.0 10.0.0.255 ether1 1 192.168.0.1/24 192.168.0.0 192.168.0.255 ether2 routing table: 0 A S 0.0.0.0/0 reachable 10.0.0.2 1 ether1 1 ADC 10.0.0.0/24 10.0.0.1 0 ether1 2 ADC 192...
by hippo
Wed Jun 17, 2009 12:00 pm
Forum: Forwarding Protocols
Topic: OSPF internal router
Replies: 1
Views: 1479

OSPF internal router

Hi, I was wondering if it's possible to configure a routeros device as a internal router (only one area) for a area that's not area0? If this is not possible that would indicate that all routeros devices would have to function as ABR (since they would be in both the desired area and area0), somethin...
by hippo
Mon Oct 13, 2008 6:04 pm
Forum: General
Topic: Policy Routing + main routing table
Replies: 6
Views: 3359

Re: Policy Routing + main routing table

Mplsguy, Hmm, I think I misread you then. However if I don't really understand why you want to traverse the routing table twice. I can understand it in those cases where you don't have a src-address for the package (since then it would pick src-address which is the closest interface to the destinati...
by hippo
Mon Oct 13, 2008 3:30 pm
Forum: General
Topic: Policy Routing + main routing table
Replies: 6
Views: 3359

Re: Policy Routing + main routing table

Hi Mplsguy Well, just a typo. I changed the ipaddresses from the real experiement I made. However I think you are wrong, because the marking is working. In the example I gave below it does not use the default gateway it uses the gateway given by the vrf according to the marking. And if you check the...
by hippo
Fri Oct 10, 2008 7:11 pm
Forum: General
Topic: Policy Routing + main routing table
Replies: 6
Views: 3359

Policy Routing + main routing table

Hi everyone It seems both the policy-routing and using VRF (routing-test package) don't work when there isn't no routing in the main routing table. See the following example on what happens: First set some ips: /ip address add address=192.168.0.1/24 broadcast=192.168.0.255 comment="" disab...
by hippo
Fri May 30, 2008 4:08 pm
Forum: General
Topic: Need assistance in bug testing
Replies: 2
Views: 1098

Re: Need assistance in bug testing

Hi Chupaka

Tried this with a rb600 with a clean config (only configured default gw and ip on one interface) and running 3.10

I had no problems.

br
Hippo
by hippo
Tue May 20, 2008 4:40 pm
Forum: General
Topic: v4.0 Feature Request(s)
Replies: 139
Views: 49645

Re: v4.0 Feature Request(s)

Actually most of the functionality for virtual routers are already in the routeros in the form of routing-tables. What needs to be added is some form of front end so that you are able to place interfaces in certain virtual-routers and make sure that traffic only hits the corresponding routing table....
by hippo
Tue May 20, 2008 11:35 am
Forum: General
Topic: v4.0 Feature Request(s)
Replies: 139
Views: 49645

Re: v4.0 Feature Request(s)

I second the request for tunnel based route based vpn:s (see nz_monkeys post).

I would also like to see support for virtual routers (vrouters,vrf...)
by hippo
Mon May 19, 2008 11:35 am
Forum: General
Topic: IPSec Mikrotik --> Netscreen/Juniper SSG using Tunnel Int
Replies: 9
Views: 10467

Re: IPSec Mikrotik --> Netscreen/Juniper SSG using Tunnel Int

Hmm, that looks interesting. What is the mode of the ipsec, tunnel or transport?

And, would you mind posting the configuration for the netscreen side as well?

br
Hippo
by hippo
Thu May 15, 2008 5:12 pm
Forum: General
Topic: IPSec Mikrotik --> Netscreen/Juniper SSG using Tunnel Int
Replies: 9
Views: 10467

Re: IPSec Mikrotik --> Netscreen/Juniper SSG using Tunnel Int

nz_monkey: I was under the impression that you couldn't use route based vpn's with Cisco. I thought you could only either use access-list based vpns with Cisco or somesort of IPSEC-transport + ipip. If you have the time, could you please show me or give me a link on how to configure Cisco with a rou...
by hippo
Wed May 14, 2008 1:40 pm
Forum: General
Topic: IPSec Mikrotik --> Netscreen/Juniper SSG using Tunnel Int
Replies: 9
Views: 10467

Re: IPSec Mikrotik --> Netscreen/Juniper SSG using Tunnel Int

Hi nz_monkey From my understanding it's not possible, which is a shame since that way is very easy to work with. However I don't think the way that netscreen does this is completely RFC compliant. I would also (at the moment) recommend you to stay away from ipsec on router-os since I have experience...
by hippo
Mon Apr 28, 2008 4:58 pm
Forum: General
Topic: BGP Synchronize
Replies: 4
Views: 7495

Re: BGP Synchronize

Short answer, stay away from it. It's evil :)

For a long answer on what syncronization is:
http://www.juniper.net/techpubs/softwar ... fig11.html

(yehe I know it's for juniper, but it applies for anything that talks bgp)
by hippo
Thu Apr 17, 2008 3:20 pm
Forum: General
Topic: How to protection form Layer 2 below ??
Replies: 5
Views: 1836

Re: How to protection form Layer 2 below ??

Hi

That's solved on l2 level and not l3 levels. For example extreme has a concept that's called super-vlan and I think cisco calls it pvlan. So you have to solve it on your switches, not your firewall.
by hippo
Tue Apr 08, 2008 2:32 pm
Forum: General
Topic: BGP + OSPF default routes
Replies: 6
Views: 1866

Re: BGP + OSPF default routes

Hi I would advise that you turn synchronization of in the BGP routers (if you are using IBGP between them which I suspect you are), this could fix your problem. I would also advice that you configure a high static default route out of the network so that even if you experience this problem, you will...
by hippo
Tue Apr 08, 2008 1:26 pm
Forum: General
Topic: Quality of IPSec Implementation
Replies: 7
Views: 2039

Re: Quality of IPSec Implementation

I think what you are experiencing is the same problems as I have been having, see:
http://forum.mikrotik.com/viewtopic.php?f=2&t=22975

For a detailed instruction for how to reproduce the problem
br
Hippo
by hippo
Mon Apr 07, 2008 2:17 am
Forum: General
Topic: Ipsec problem, Bug?
Replies: 1
Views: 1113

Re: Ipsec problem, Bug?

No one is able to replicate this? Have someone tried?

Or do you have any suggestions or tips?
by hippo
Wed Apr 02, 2008 6:02 pm
Forum: General
Topic: ip firewall mangle
Replies: 3
Views: 1268

Re: ip firewall mangle

Hi Gff

I would use /interface print

However I'm sure you could use /interface find type
but I'm unsure about the syntax.

br
by hippo
Wed Apr 02, 2008 3:04 pm
Forum: General
Topic: Ipsec problem, Bug?
Replies: 1
Views: 1113

Ipsec problem, Bug?

I discovered something strange when playing around with ipsec on ROS. I have one ROS device on 1.2.3.236/25 that I have been playing around with. I have a transport ipsec tunnel configured towards 1.2.3.234/25. The gateway on that network is 1.2.3.129. When that tunnel is up and running everything i...
by hippo
Tue Apr 01, 2008 4:18 pm
Forum: General
Topic: Routing-mark on Output chain not working *SOLVED*
Replies: 3
Views: 3603

Re: Routing-mark on Output chain not working *SOLVED*

Hi! Thanks for the help! Allthough there was one more thing missing, you have to have a route for the network in the 192.168.0.0/24 in the main table. That route wasn't used but unless it was there it would not check the alternative routing table for a route for that network. I noticed this I didn't...
by hippo
Mon Mar 31, 2008 11:29 am
Forum: General
Topic: Routing-mark on Output chain not working *SOLVED*
Replies: 3
Views: 3603

Routing-mark on Output chain not working *SOLVED*

Hi I seem to have a problem with route mark on outgoing traffic from the RouterOS device. Version used is ROS 3.6 If I do the following: /ip route> add dst-address=192.168.0.0/24 gateway=10.0.0.1 routing-mark=test /ip route rule> add routing-mark=test action=lookup table=test /ip firewall mangle> ad...
by hippo
Thu Mar 27, 2008 11:34 am
Forum: General
Topic: Problems with multiple routing tables
Replies: 3
Views: 3405

Re: Problems with multiple routing tables

More input, if I connect one client 10.0.1.5 to the mikro234 and one more client 10.0.2.5 to mikro236 they can ping each other without any problems so the problem really seem to be when packages are originating from the routeros device.
by hippo
Thu Mar 27, 2008 10:54 am
Forum: General
Topic: Problems with multiple routing tables
Replies: 3
Views: 3405

Re: Problems with multiple routing tables

Hi 1) Upgraded to 3.6 on both devices and the problem is still occuring. 2) yes, I have a bgp filter in that looks like this: 0 chain=setmarktrust invert-match=no action=passthrough set-routing-mark="trust" that I use to make sure that all routes I get from the bgp are inserted into the co...
by hippo
Wed Mar 26, 2008 2:36 pm
Forum: General
Topic: Problems with multiple routing tables
Replies: 3
Views: 3405

Problems with multiple routing tables

Hi I have some trouble getting secondary routing tables up and running and I would appricate some help. What I'm trying to achive is the following: Two routeros boxes, called mikro234 and mikro236, they each have two interfaces used, one side towards the internet and one side towards the trusted sid...