Community discussions

MikroTik App

Search found 38 matches

by Gotmoh
Tue Jun 20, 2006 8:27 pm
Forum: General
Topic: external proxy without parent proxy on my MT. How to do?
Replies: 1
Views: 1097

external proxy without parent proxy on my MT. How to do?

Hi all. Becouse my users are generating too big processor load on main mt server i decided to use squid on debian linux machine. Small problem. It seems work ok with parent proxy enabled on mt. I was try use dst-nat forwarding all tcp 80port request to tcp port on squid proxy. One problem. Squid rec...
by Gotmoh
Sat Jun 17, 2006 8:47 am
Forum: General
Topic: v2.9.26 released..
Replies: 25
Views: 6441

I did upgrades on two routers. Some away from me and some high ;-) . Previous both was 2.9.24. No problems with both routers.
by Gotmoh
Thu Jun 15, 2006 10:04 am
Forum: General
Topic: Who no Pay don´t Surf !
Replies: 11
Views: 3261

one small think. What if your customer change his ip? He will see web page with "pay your bill!", looks into his ip configuration and try add some numbers to his ip to continue surfing without pays bill. I mean then you must controll all ip in your network. Permitt "legal" ip and...
by Gotmoh
Thu Jun 15, 2006 9:53 am
Forum: General
Topic: Problems with queue
Replies: 13
Views: 3199

Two thinks : 1. Maybe not all of your users using the same communication methods (as flashget download, p2p programs, p2m etc.) and it looks as queues works for almos all except few peoples. 2. Change one bad working queue and watch what will be isnt not much work i think so. (about changing lot of ...
by Gotmoh
Wed Jun 14, 2006 11:41 pm
Forum: General
Topic: Problems with queue
Replies: 13
Views: 3199

Im not sure. Im using, and discovering MT from 1,5 year. Using simple queues as you saw my example almost from begin (burst limit = max limit) Its working. Maybe burst limits are not required. I dont want try change this. Too many users in my network (about 600) and it will be too risky. Hope someon...
by Gotmoh
Wed Jun 14, 2006 11:34 pm
Forum: General
Topic: Problems with queue
Replies: 13
Views: 3199

As you wish. I dont see anything wrong with burst limits. My users never goes more than max queue limits ;)
by Gotmoh
Wed Jun 14, 2006 11:24 pm
Forum: General
Topic: Problems with queue
Replies: 13
Views: 3199

too little information. Im using connection limit, p2p blocking and queue tree with services packet marking. All working fine. Im remember some problem with overloaded simple queues with old 2.8.26? mt version... Mabe its problem with lack of parameters in your queues? Did you try use burst limit pa...
by Gotmoh
Wed Jun 14, 2006 11:13 pm
Forum: General
Topic: Problems with queue
Replies: 13
Views: 3199

All my simple queues are as default type; pfifo at 10 packets. Its working from old 2.8.x Mt version up to today (2.9.24).
by Gotmoh
Wed Jun 14, 2006 11:02 pm
Forum: General
Topic: Problems with queue
Replies: 13
Views: 3199

Hi This is one from my simple queues : add name="User 257" target-addresses=192.168.4.209/32 \ dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8 \ queue=default/default limit-at=32000/128000 max-limit=256000/512000 \ burst-limit=256000/768000 burst-threshold=128000/...
by Gotmoh
Wed Jun 14, 2006 11:41 am
Forum: General
Topic: Total connections limit?
Replies: 12
Views: 5487

i have 10 hours now but Normis shows whats up with connections. Track shows more than 5000 conn and second value 2mil it may be max counted connections for me. command ip fire conn print wit shows only first 2049 connections i think so...
by Gotmoh
Wed Jun 14, 2006 11:20 am
Forum: General
Topic: Total connections limit?
Replies: 12
Views: 5487

heh. i give up :/ enabled: yes tcp-syn-sent-timeout: 2m tcp-syn-received-timeout: 1m tcp-established-timeout: 10h tcp-fin-wait-timeout: 2m tcp-close-wait-timeout: 1m tcp-last-ack-timeout: 30s tcp-time-wait-timeout: 2m tcp-close-timeout: 10s udp-timeout: 30s udp-stream-timeout: 3m icmp-timeout: 30s g...
by Gotmoh
Wed Jun 14, 2006 10:54 am
Forum: General
Topic: Total connections limit?
Replies: 12
Views: 5487

sure: last few lines after command ip firewall connections print without-paging : 2041 SA udp 192.168.0.60:4672 66.180.205.52:4672 2m36s 2042 SA udp 192.168.0.60:4672 207.212.26.208:4672 2m58s 2043 SA tcp 192.168.9.56:4763 84.6.195.66:8757 established 9h12m20s 2044 SA tcp 192.168.9.5:1059 82.103.215...
by Gotmoh
Wed Jun 14, 2006 10:48 am
Forum: General
Topic: Total connections limit?
Replies: 12
Views: 5487

I explain little : Isnt only my single fact. 12/12 mbit link is my main gate, also I have secondary gate in my network. Normaly used for crazy p2p users (its DSL 512/2048). How many connections show ip fire conn print ? 2048. My friend using DSL on his network (DSL 640/8192) and told the same. 2048 ...
by Gotmoh
Wed Jun 14, 2006 10:34 am
Forum: General
Topic: Total connections limit?
Replies: 12
Views: 5487

hmmm. Isnt simple problem. I have 12/12 mbit internet connection. Even without all limitations (queues, connections) my link not go more then 6/6 mbit. Dont know how to do. Cut off link and save some money or looking how to change this conn limit (i think users cant use full internet link speed beco...
by Gotmoh
Wed Jun 14, 2006 10:23 am
Forum: General
Topic: Total connections limit?
Replies: 12
Views: 5487

Total connections limit?

Hi

I found something strange. I have wifi network with about 600 customers. Mikrotik (now 2.9.24) shows maximum 2049 total connections (for all clients). One time saw 2051. Not more. I was try disable all limits on my mt (conn limits, queues, proxy, p2p etc). Still max 2049 connections. How is it?
by Gotmoh
Wed May 10, 2006 9:46 pm
Forum: General
Topic: Can I use results of ping in an script to reset interface?
Replies: 1
Views: 856

Can I use results of ping in an script to reset interface?

Hi all.

Is that posible? How to read ping results to an ip address and using "if" command reset interface. I mean scenario when mikrotik ping IP address to remote location and when have no responce reseting interface connected to those location.
by Gotmoh
Wed Apr 26, 2006 3:41 pm
Forum: General
Topic: Windows Sharing & Network Printing
Replies: 1
Views: 996

How about your wireless customers? They are using access points to connect to your MT server? Most of AP by default blocking netbios and then you cant see shared microsoft resources, use remote desktop protocol etc.
by Gotmoh
Sat Apr 22, 2006 10:56 am
Forum: General
Topic: How to drop an IP address
Replies: 6
Views: 1999

Friend, you should read the manual first before asking here. But, you can try using mac address protection: /ip firewall filter add src-mac-address=[client mac address] src-address=![client correct ip address] action=drop Isnt your rule will drops every ip except one pair MAC+IP ? I mean it will wo...
by Gotmoh
Sat Apr 22, 2006 9:21 am
Forum: General
Topic: FTP multiple logins
Replies: 7
Views: 1991

Realy? It enables internal ftp server on MikroTik IMHO. You dont need this to use ftp inside your LAN.

Gotmoh, you're confusing this with /ip service, which
indeed controls services on the router itself.


--Tom
Me confusing? Or Mapik? :twisted:
by Gotmoh
Fri Apr 21, 2006 2:45 pm
Forum: General
Topic: FTP multiple logins
Replies: 7
Views: 1991

I think this may help

/ip firewall service-port enable ftp
Realy? It enables internal ftp server on MikroTik IMHO. You dont need this to use ftp inside your LAN.
by Gotmoh
Thu Apr 20, 2006 3:17 pm
Forum: General
Topic: Firewall build on ports to give a specific service
Replies: 7
Views: 1586

Email sent to you Ramona.
by Gotmoh
Thu Apr 20, 2006 11:58 am
Forum: General
Topic: Firewall build on ports to give a specific service
Replies: 7
Views: 1586

hi there. Im not sure. Youre wanna permitt only for those ports and drop everything other? Whase problem? I have similary configuration at my company. Users can only using on selected ports and all other are dropped. I using rules in firewall forward. Have few rules. Just all packets from specific v...
by Gotmoh
Wed Apr 19, 2006 10:33 pm
Forum: General
Topic: Memory leak with webproxy
Replies: 1
Views: 949

Hi.

I have the same results. AMD 1.8, 1 GB Ram. Memory droping from 720 to 40 mb after 2-3 days. In another location have CELERON 2.6, 1 GB Ram. After 11 days uptime lost only 60 mb ram. Isnt "function" amd processor or motherboards problem?
by Gotmoh
Wed Apr 19, 2006 9:38 pm
Forum: Scripting
Topic: Script to add IP's to firewall blocklist (DROP)
Replies: 4
Views: 2587

Isnt easier to use address list contains only valid-admins ip whos have rights to access to your routerboard?
by Gotmoh
Wed Apr 19, 2006 9:37 pm
Forum: Scripting
Topic: how to make a profile for users that did not pay´d the bill?
Replies: 18
Views: 6189

Hi Im using some different way to resolve this problem. Using two address list. One contains all valid user ip addresses, second exactly the same ips but all by default are disabled. In dst nat have two positions. First using address list with disabled ip redirect http requests to page with "pa...
by Gotmoh
Fri Mar 10, 2006 3:30 pm
Forum: General
Topic: why I can't use winbox remotely?
Replies: 2
Views: 1437

need pass packet on tcp port 8291 on external interface.
by Gotmoh
Fri Mar 10, 2006 3:27 pm
Forum: General
Topic: outlook configuration in MT
Replies: 2
Views: 989

You mean outlook with LDAP protocol to exchange server or Outlook Express with pop3/smtp ?
by Gotmoh
Mon Mar 06, 2006 9:08 pm
Forum: General
Topic: Mikrotik reboot varies times to the day
Replies: 17
Views: 4134

I had broken one memory module at my mikrotik (2x512 MB DIMM). It was reboot few times a week, sometimes two-three times a day.
by Gotmoh
Mon Mar 06, 2006 1:32 pm
Forum: General
Topic: Simple queue with multiple target addresses
Replies: 1
Views: 2100

Simple queue with multiple target addresses

How is it work? If i define simple queue with two or more target addresses it will share queue bandwith with those addresses or just multiple two or more queues for simple targets? example : add name="user1" \ target-addresses=172.16.0.1/32,172.16.0.2/32,172.16.0.3/32 \ dst-address=0.0.0.0...
by Gotmoh
Mon Mar 06, 2006 9:26 am
Forum: General
Topic: error publishing multiple services online!
Replies: 3
Views: 1115

Strange. Im using publish rules for emule high id for my customers. Have about 60 dst-nat rules. All working fine (2.9.14 at this moment).
by Gotmoh
Sun Mar 05, 2006 1:00 pm
Forum: General
Topic: Protect router against attack
Replies: 6
Views: 2355

Just block input icmp packets from sources. You can use address list to pass only from accepted places.
by Gotmoh
Sat Mar 04, 2006 6:25 pm
Forum: General
Topic: simple queue small problem
Replies: 3
Views: 1400

ok. this is it. parent queue : add name="xxxxxxx Rafal 1" target-addresses=192.168.9.154/32 \ dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=8 \ queue=default/default limit-at=1000000/1000000 max-limit=1000000/1000000 \ burst-limit=1356000/1768000 burst-threshold=1...
by Gotmoh
Sat Mar 04, 2006 9:14 am
Forum: General
Topic: simple queue small problem
Replies: 3
Views: 1400

simple queue small problem

Hi all.

I created simple queue for an user. Then created another one as child for previous queue. Now parent and child counters doesnt show any activity (but when using torch I can see packet moves at this queues (both)). Was try use higher priority for child queue but dont work. Any ideas?
by Gotmoh
Sat Dec 17, 2005 2:48 pm
Forum: General
Topic: p2p filtering
Replies: 4
Views: 1857

Try controll connection limits for users. Every p2p program generates 100+ more connections and lot of conn try per minute.
by Gotmoh
Thu Dec 15, 2005 9:56 am
Forum: General
Topic: Stupid question ? ;)
Replies: 0
Views: 685

Stupid question ? ;)

Hi All.

Have one small (maybe silly ;-) ) problem. How to remove empty address list from mt????

D.
by Gotmoh
Fri Sep 02, 2005 9:07 am
Forum: General
Topic: Ares P2P not being blocked in 2.9rc7
Replies: 9
Views: 5642

im using someting like this : add chain=forward in-interface="internal_bridge" protocol=tcp dst-port=0-80 \ tcp-flags=syn,!fin,!rst,!psh,!ack,!urg,!ece,!cwr connection-limit=15,32 \ action=drop comment="Connlimit" disabled=no add chain=forward in-interface="internal_bridge&q...
by Gotmoh
Mon Aug 15, 2005 2:53 pm
Forum: General
Topic: 2.9 Demo router
Replies: 18
Views: 17092

I did remote upgrade to rc10 3 hours ago. Had some affraid (router is about 6 km away from me on roof 10floor bulding) but working fine. Processor have normal load (up to 60%).
by Gotmoh
Sun Aug 14, 2005 4:20 pm
Forum: General
Topic: 2.9 Demo router
Replies: 18
Views: 17092

Hi I have the same problem.Moterboard with AMD processor and 100% utilisation. Few days ago did upgrade from 2.9 rc7 to rc9. Before all works ok, now after few hours always have 100% processor load. Working only telnet-ssh connection. The only way to resolve this problem is reboot router. Its AMD pr...