Community discussions

MikroTik App

Search found 291 matches

by huntah
Wed Dec 13, 2023 9:34 pm
Forum: General
Topic: ROS 7.12.1 - enable-ssl-certificate with UserManager
Replies: 1
Views: 2119

ROS 7.12.1 - enable-ssl-certificate with UserManager

Hi, I am trying to renew LE cert with enable-ssl-certificate but I get the following error. /certificate/enable-ssl-certificate dns-name=somegw.of.mine.com progress: [error] http challenge validation failed, please make sure www service is enabled and your device is accessible by letsencrypt.org ser...
by huntah
Sun Nov 12, 2023 3:21 pm
Forum: General
Topic: Win L2TP/IPSEC transfers VPN user over to the SMB Share [SOLVED]
Replies: 1
Views: 1359

Re: Win L2TP/IPSEC transfers VPN user over to the SMB Share [SOLVED]

I have found a sollution. You have to edit the Windows .pbk file! On the user's computer, go to to C:\Users\[username]\AppData\Roaming\Microsoft\Network\Connections\Pbk. Open the rasphone.pbk file with a text editor. In the section for the relevant VPN connection, find userascredentials=1 and change...
by huntah
Fri Oct 06, 2023 3:48 pm
Forum: General
Topic: Win L2TP/IPSEC transfers VPN user over to the SMB Share [SOLVED]
Replies: 1
Views: 1359

Win L2TP/IPSEC transfers VPN user over to the SMB Share [SOLVED]

Hi, I have a problem with Windows L2TP/IPSEC clients (also IKEv2/UserManager). We have a domain controler and shared network drives. User takes the notebook home connects to VPN without a problem and then when trying to connect to network drives it fails. But if I go to credential manager on the cli...
by huntah
Thu Oct 05, 2023 5:56 pm
Forum: Scripting
Topic: ROS 7.x - Get address not working [SOLVED]
Replies: 4
Views: 2508

Re: ROS 7.x - Get address not working [SOLVED]

Just a guess... Possibly you have several ip addresses on that interface now? Try that for the first address: :global ddnsip [ /ip/address/get ([ /ip/address/find where interface="ether1" ]->0) address ]; ... or add more properties to your filter. Yes.. exactly I have more addresses! If I...
by huntah
Wed Oct 04, 2023 9:03 pm
Forum: Scripting
Topic: ROS 7.x - Get address not working [SOLVED]
Replies: 4
Views: 2508

ROS 7.x - Get address not working [SOLVED]

Hi, can any tell me if this scipt is working on ROS 7.x global ddnsip [ /ip address get [/ip address find interface="ether1" ] address ] Error: invalid internal item number It was working perfectly on 6.x .. If I put in a corresponding number of the interface it works.. Something must've c...
by huntah
Thu Jul 27, 2023 9:36 pm
Forum: Announcements
Topic: WinBox v3.39 released!
Replies: 96
Views: 59895

Re: WinBox v3.39 released!

QR Code is very useful if it would be implemented in UserManager-Users. There is a field OTP Secret. It works which GoogleAuth! I use this QR Generator: https://jwessel.github.io/totp-gauth-token/QR_generator.html But if Mikrotik would implement this in Winbox or even better WebPortal. We could have...
by huntah
Fri Nov 11, 2022 8:03 pm
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 142933

Re: v7.6 [stable] is released!

Seems like ! is not working in fasttrack and queues I am trying to disable fastrack for GuestNetwork (Capsman and one Vlan interface) so I can enabel queues /ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related h...
by huntah
Fri Jan 14, 2022 10:32 am
Forum: General
Topic: L2TP/IPsec Issues with Windows 11 update - kb5009566
Replies: 29
Views: 23073

Re: L2TP/IPsec Issues with Windows 11 update - kb5009566

MS posted a workaround:
Workaround: To mitigate the issue for some VPNs, you can disable Vendor ID within the server-side settings. Note: Not all VPN servers have the option to disable Vendor ID from being used.
But I don't think we can do that in RouterOS..
by huntah
Fri Jan 14, 2022 10:25 am
Forum: Forwarding Protocols
Topic: Is RouterOS L2TP + IPsec affected by new microsoft bug?
Replies: 4
Views: 3987

Re: Is RouterOS L2TP + IPsec affected by new microsoft bug?

Sadly yes.

MS is talking about removing VendorID from IPSEC but I do not see the option to remove this.
Maybe someone else have found a workaround other than remove the January Patch from MS.
by huntah
Thu Apr 29, 2021 8:07 pm
Forum: Announcements
Topic: SwOS version 2.13 released!
Replies: 63
Views: 295084

Re: SwOS version 2.13 released!

*) CSS106: make RSTP work with vlanMode=enabled or vlanMode=strict; CSS106 - RSTP issue is resolved SwOS 2.11 and 2.13 - RSTP finds the correct Root Bridge Did have a problem with RSTP root bridge pointed at it itself when I had UPLINK port (SFP) set to TAGGED ONLY! Do not forget to set VLAN Reciev...
by huntah
Sun Jan 03, 2021 1:27 am
Forum: General
Topic: RSTP not selecting the right Root Bridge (hAP-lite, ROS 6.48 and ROS 6.46.8)
Replies: 1
Views: 1151

RSTP not selecting the right Root Bridge (hAP-lite, ROS 6.48 and ROS 6.46.8)

It seems there is a problem with determining the right Bridge Root in RSTP. Here is my scenario: 1. HP v1910-48G - STP enabled. Mode RSTP. Bridge Priority 4096 (0x100 hex in Mikrotik) 2. hAP-Lite with Switch chip defined VLANs and a Bridge with all ports and WLAN1 adapter. (I also disabled Switch As...
by huntah
Sun Jan 03, 2021 1:13 am
Forum: Announcements
Topic: SwOS version 2.12 released!
Replies: 90
Views: 87684

Re: SwOS version 2.12 released!

I can confirm that RSTP on CSS106 is broken.. If I enable it it does not compute the right Root Bridge. Root Bridge is always the CSS106 itself. Regardless of Bridge Priority. Directly attached CRS212 port is in Learning and discarding state... It only helps to disable RSTP on CRS212 and than disabl...
by huntah
Thu Oct 29, 2020 10:15 pm
Forum: Wireless Networking
Topic: iOS Devices Connecting but no internet
Replies: 12
Views: 4034

Re: iOS Devices Connecting but no internet

You have set the IP Address on interface instead of bridge /ip address add address=192.168.2.1/24 comment=defconf interface=ether2 network=\ 192.168.2.0 You should change that to Bridge and everthing should work... /ip address add address=192.168.2.1/24 comment=defconf interface=bridge network=192.1...
by huntah
Thu Aug 27, 2020 7:12 pm
Forum: Announcements
Topic: v6.45.9 [long-term] is released!
Replies: 82
Views: 93818

Re: v6.45.9 [long-term] is released!

Try upgrading winbox to the latest version..
by huntah
Tue Jun 23, 2020 9:04 pm
Forum: General
Topic: IKEv2 Enabling_dynamic_source_NAT_rule_generation [SOLVED]
Replies: 1
Views: 2048

Re: IKEv2 Enabling_dynamic_source_NAT_rule_generation [SOLVED]

Ok,

Connection Mark works perfect for this:
/ip firewall mangle
add action=mark-connection chain=prerouting dst-address=LOCALSUBNET new-connection-mark=VIAIPSECTUNEL passthrough=yes src-address=REMOTESUBNET
by huntah
Tue Jun 23, 2020 8:54 pm
Forum: General
Topic: IKEv2 Enabling_dynamic_source_NAT_rule_generation [SOLVED]
Replies: 1
Views: 2048

IKEv2 Enabling_dynamic_source_NAT_rule_generation [SOLVED]

Hi, I have setup RoadWarrior remote office behind NAT. I use IKEv2 with mode-conf. I have found that I can route all traffice from remote office over the tunnel via dynamic NAT rule generation. https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Enabling_dynamic_source_NAT_rule_generation Which is fine b...
by huntah
Wed May 27, 2020 3:14 pm
Forum: General
Topic: IKEv2 IOS - Cannot Connect [SOLVED]
Replies: 22
Views: 12433

Re: IKEv2 IOS - Cannot Connect [SOLVED]

This is real bummer. It was working last year (at least until Aug .. when people were on vacation and needed VPN). This year I gues I have to make a new CA and recreate all the certficates and redeploy them.. Is there any way to renew CA certificate in Mikrotik? Also what exactly is the drawback of ...
by huntah
Wed May 27, 2020 12:39 am
Forum: General
Topic: IKEv2 IOS - Cannot Connect [SOLVED]
Replies: 22
Views: 12433

Re: IKEv2 IOS - Cannot Connect [SOLVED]

The only difference is My CA is set for 10 years.. If the CA is the culprit then I have to recreate the whole VPN system (CA and all 30 certificates). And redeploy them do clients.. If this is some kind of a Apple bug (valid less than 850 days should not be enforced for CA..). I can understand the l...
by huntah
Wed May 27, 2020 12:34 am
Forum: General
Topic: IKEv2 IOS - Cannot Connect [SOLVED]
Replies: 22
Views: 12433

Re: IKEv2 IOS - Cannot Connect [SOLVED]

@anav: I think your config only works with one certificate?! Judging from this: 17) IDENTITIES Is the biggie, I am not sure if order is important but in any case I have mine first (before any default). Word of caution if you make changes to certificates this will change on you and thus have to reset...
by huntah
Wed Apr 29, 2020 8:49 pm
Forum: RouterOS beta
Topic: VLANs on switch chip
Replies: 2
Views: 2400

Re: VLANs on switch chip

Code: /interface ethernet switch port set 5 vlan-header=add-if-missing vlan-mode=check # or secure This is switch1-cpu .. I always set this like this: /interface ethernet switch port set 5 vlan-header=leave-as-is vlan-mode=secure Try it.. if it works like this.. Or dou you think this not correct fo...
by huntah
Sat Feb 01, 2020 1:52 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 86
Views: 91884

Re: v6.45.8 [long-term] is released!

CCR1009-7G-1C-1S+ 6.44.6 -> 6.45.8 ip ipsec policy peers where is state unknown.. IPSEC tunnels -- some were working some not.. Manualy specified correct peers sand flushinng SAs solved the problem without reboot. Everything else seems to be working after upgrade.. . Kudos for : /ip ipsec active-pee...
by huntah
Sun Dec 29, 2019 4:33 pm
Forum: General
Topic: Mixed VLANs in switch
Replies: 7
Views: 2608

Re: Mixed VLANs in switch

@mkx: I agree that you can set native vlan as you like (your case 42) but I had had always problem when using VLAN1.. MT devices would only work as they should when untagged VLAN1 through (Cisco, Procurve switches) if they had VLAN0 set.. I do not know if it is a bug or not but it works. This is why...
by huntah
Sun Dec 29, 2019 2:14 pm
Forum: General
Topic: Mixed VLANs in switch
Replies: 7
Views: 2608

Re: Mixed VLANs in switch

I Tried this config on hAP-Lite and it works. I removed for test switch1-cpu from all VLANs (it will lock you out of management! So do have wlan1 enabled or you will need to reset via button). It works as it should! For hybrid ports you need to leave it as is .. Tried and please post back.. The big ...
by huntah
Sun Dec 29, 2019 12:19 pm
Forum: General
Topic: Mixed VLANs in switch
Replies: 7
Views: 2608

Re: Mixed VLANs in switch

hmm... I think this should work.. It works at least for me.. Correct me if i Am wrong: ether1-uplnik -> tagged 15,21 in untagged 0 (Native VLAN - for HP Procurve it translates to VLAN1 unttager --- hybrid port) ether2-Management -> unttaged 15 - access port ether3-PC+Voip -> unttaged 0 (PC) + tagged...
by huntah
Wed Oct 09, 2019 1:36 pm
Forum: RouterBOARD hardware
Topic: hAP-aC2 with SFP port
Replies: 13
Views: 5938

Re: hAP-aC2 with SFP port

The point was: 1. HEX price 45 EUR + VAT 2. HEXS price 55 EUR + VAT 3. hAP-AC2 price 55 EUR + VAT 4. And I see here hAP-AC2+SFP for 65 EUR + VAT (my estimate...no such product) Why... I have many custumers where we come to them with Optics and they want just one single affordable device with WiFi.. ...
by huntah
Mon Oct 07, 2019 10:11 pm
Forum: RouterBOARD hardware
Topic: hAP-aC2 with SFP port
Replies: 13
Views: 5938

hAP-aC2 with SFP port

It would be extremly nice to have hAP-AC2 with SFP port.
Something like Hex and HexS but with HW VLAN support...

What do you think @Forum and @MikroTik
by huntah
Wed Oct 02, 2019 3:59 pm
Forum: General
Topic: hAP-AC2 -> Filter mikrotik in:(unknown 1) out:(unknown 0) to TCP to port 80 [SOLVED]
Replies: 1
Views: 2165

Re: hAP-AC2 -> Filter mikrotik in:(unknown 1) out:(unknown 0) to TCP to port 80 [SOLVED]

After step-by-step config redo I have found out it is the System-Certificate CRL as suspected.. @Mikrotik or someonelse: How exactly does this CRL work I have specified my Public IP address...Should allow HTTP from MyPubIP to MyPubIP port 80 ? What happens if webfig is also on port 80...what happens...
by huntah
Mon Sep 30, 2019 11:01 pm
Forum: General
Topic: hAP-AC2 -> Filter mikrotik in:(unknown 1) out:(unknown 0) to TCP to port 80 [SOLVED]
Replies: 1
Views: 2165

hAP-AC2 -> Filter mikrotik in:(unknown 1) out:(unknown 0) to TCP to port 80 [SOLVED]

Hi, I have a strange problem... In Firewall filter I am dropping everything not comming from LAN as a las rule in Input chain. Now I get multiple times a minute this log: Filter:input:in:(unknown 1) out:(unknown 0) , proto TCP (SYN), MyPublicIP:43242-> MyPublicIP:80, len 60 I have IP - Service - www...
by huntah
Thu Jun 13, 2019 9:24 am
Forum: SwOS
Topic: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]
Replies: 3
Views: 12431

Re: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]

Hi all, support got back to me! And kudos to mr. Edwards for writing the updated easy to understand Wiki for SwOS! https://wiki.mikrotik.com/wiki/SwOS/CSS106-VLAN-Example Please disregard wiki link in previous post because it is outdated! Always use the one provided above this line! For Hybrid port ...
by huntah
Wed Jun 12, 2019 1:58 pm
Forum: General
Topic: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED]
Replies: 7
Views: 10435

Re: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED] [SOLVED]

What was the error?
You need PowerShell and not CMD.
It wont work if you have the same CA. I havent tried to specify which cert to use with the same CA (Certificate Authority).

This is useful if you have multiple IKEv2 VPN clients on different locations. And all the servers have different CA.
by huntah
Mon Jun 03, 2019 10:18 pm
Forum: SwOS
Topic: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]
Replies: 3
Views: 12431

CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]

Hi, I thought I have everything figured out.. But again I am buffled :) So I have multiple switches linked together. - port 1 : Uplink to GW (All Tagged) - Port 2 : All Tagged VLANs to hAPAC2 - Port 3: Hybrid Port - Untagged VLAN and Multiple Tagged Ones - Port 4: Hybrid Port - Untagged VLAN and Mul...
by huntah
Thu Apr 04, 2019 9:19 pm
Forum: General
Topic: OTP or 2FA Auth
Replies: 1
Views: 5444

OTP or 2FA Auth

HI, is there any plan to add native support for GoogleAuth or FreeOTP or some other OTP client. It would be great to auth VPN users and/or Router Access (Winbox, WEB etc..) I guess it can be done via external Radius Server.. If someone has done it. Please share it would be helpful to others.. I thin...
by huntah
Sun Nov 25, 2018 4:32 pm
Forum: Beginner Basics
Topic: IPSEC RoadWarrior tunnel between Mikrotik and Shrewsoft client
Replies: 1
Views: 1198

Re: IPSEC RoadWarrior tunnel between Mikrotik and Shrewsoft client

Hi

You have different settings on client and server..
For example..dh group=2 is modp1024
Also enable..ipsec logging to see what client Sends to MikroTik and vice versa
by huntah
Thu Nov 22, 2018 1:38 pm
Forum: General
Topic: Can't get 1Gbps on CRS125-24G-1S-2HnD
Replies: 7
Views: 1878

Re: Can't get 1Gbps on CRS125-24G-1S-2HnD

set [ find default-name=ether4 ] name=ether4-slave-local speed=100Mbps
I think you Are forcing 100mbs on each interface.....
by huntah
Sat Nov 17, 2018 10:48 am
Forum: Beginner Basics
Topic: PCC Load Balancing 2 WAN on Mikrotik HEX
Replies: 17
Views: 10879

Re: PCC Load Balancing 2 WAN on Mikrotik HEX

Does your PCC work with fasttrack enabled ?!
I could not make that work....also in wiki it is mentioned in a note....
by huntah
Fri Nov 16, 2018 2:18 pm
Forum: Beginner Basics
Topic: Best performance on hAP ac lite
Replies: 6
Views: 2018

Re: Best performance on hAP ac lite

HI, use the default settings (ie Quickset). This should give you internet on ether1 and a Bridge with HWoffload and Wlan together. Since you have 32 users I hope you have a Gigabit 24port Switch or two :) So all your clients are directly attached to GigaSiwtch (or whatever switch you got) and only o...
by huntah
Sun Nov 11, 2018 10:10 pm
Forum: Beginner Basics
Topic: Bridging TWO network but each interface communicate each other
Replies: 16
Views: 8260

Re: Bridging TWO network but each interface communicate each other

with Lan C do routing like that:

router a: ether1 IP: 10.30.1.1/29
/ip route
add distance=1 dst-address=10.30.13.0/24 gateway=10.30.1.2
router b: ether3 IP: 10.30.1.2/29
/ip route
add distance=1 dst-address=10.30.14.0/24 gateway=10.30.1.1
by huntah
Sat Nov 10, 2018 8:28 pm
Forum: General
Topic: secure winbox port access only by wan ip
Replies: 16
Views: 10237

Re: secure winbox port access only by wan ip

You need to allow also in firewall filter
Place it before drop tule
by huntah
Mon Nov 05, 2018 10:29 am
Forum: General
Topic: PCC (Dual WAN) not working on hAPAC2 [SOLVED]
Replies: 8
Views: 3304

Re: PCC (Dual WAN) not working on hAPAC2 [SOLVED]

I have found the problem it was in RP Filter which was enabled on the Live Router! Wiki has a note about that :) I should RTFM more carefully! Note: PCC setups is not designed to work if RP Filter is enabled On another note..If I set it to Loose it works.. Will the default FW rules in forward chain ...
by huntah
Sun Nov 04, 2018 7:08 pm
Forum: General
Topic: PCC (Dual WAN) not working on hAPAC2 [SOLVED]
Replies: 8
Views: 3304

Re: PCC (Dual WAN) not working on hAPAC2 [SOLVED]

I was searcing the forum and came across this:
viewtopic.php?t=110560

I have disabled the fastrack and now it is much better.

Must fasttrack be disabled with PCC? Can someone confirm this..
by huntah
Sun Nov 04, 2018 6:35 pm
Forum: General
Topic: PCC (Dual WAN) not working on hAPAC2 [SOLVED]
Replies: 8
Views: 3304

Re: PCC (Dual WAN) not working on hAPAC2 [SOLVED]

OK now I am totally confused :) It kinda works on both devices in my lab. On both there are problems with some sites loading all the images ...or not loaded entirely. Subjective guess it happens more often on hAP-AC2.. Steps to reprodude: 1. Reset config to default 2. remove ether4 from bridge 3. re...
by huntah
Sun Nov 04, 2018 1:51 pm
Forum: General
Topic: PCC (Dual WAN) not working on hAPAC2 [SOLVED]
Replies: 8
Views: 3304

Re: PCC (Dual WAN) not working on hAPAC2 [SOLVED]

Ah OK.. did not know that in the wiki.. But tried several scripts but none work on live system with hAP-AC2 so passthrough is definitly an oversight on my side... I just dont get it why it does work on hAP-lite even though it was set incorrectly.. I have just got one spare hAP-AC2 and will try the s...
by huntah
Sun Nov 04, 2018 11:09 am
Forum: General
Topic: PCC (Dual WAN) not working on hAPAC2 [SOLVED]
Replies: 8
Views: 3304

Re: PCC (Dual WAN) not working on hAPAC2 [SOLVED]

It does not matter if I set it to passthrough :/
Also in Wiki there are not passthrough enabled..
https://wiki.mikrotik.com/wiki/Manual:PCC
As I said it works on hAP-lite just not hAP-AC2.
Have you tried it on hAP-AC2.. has anyone?
by huntah
Sat Nov 03, 2018 3:41 pm
Forum: General
Topic: PCC (Dual WAN) not working on hAPAC2 [SOLVED]
Replies: 8
Views: 3304

PCC (Dual WAN) not working on hAPAC2 [SOLVED]

Hi, can anyone confirm if PCC (Dual WAN) has problems on hAP-AC2? I have tried ROS6.42.9 and latest currunt 6.43.4. Then I used the same Mangle Rules on Hap-Lite and it worked. Using ROS6.44beta28.. WAN1: DHCP-Client no default route (Cable with static IP assigned) WAN2: DHCP-Client no default route...
by huntah
Tue Oct 30, 2018 7:19 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

HI,
ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
just got word back from support. They have found the problem with split-include and it will be fixes in next beta..
Will test then again and post back the results!
by huntah
Tue Oct 30, 2018 11:24 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

I check exactly like that.. but there arent any routes from split-include.. IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.3.1 192.168.3.122 55 127.0.0.0 255.0.0....
by huntah
Tue Oct 30, 2018 9:46 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

I have default configuration (eth1 -> DHCLient to my private network)
All drop rules disabled
DHCPServer on Bridge (Default with IP pool 192.168.88.0)
VPN Pool is 192.168.222.0/24
I have attached the full config export compact
by huntah
Tue Oct 30, 2018 12:45 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

OK my bad :)

Here is the Wireshark capture from Mikrotik..
There are DHCP Inform messages but I am not able to interpret them :/
by huntah
Mon Oct 29, 2018 11:51 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

I dont get any DHCPInform..
Attached is the wireshark and then connect to VPN..
I cant put DHCP Server on WAN port ...

guess we will wait for Mktik guys to wake up :)
Night all and thnx for tips and help sindy!
by huntah
Mon Oct 29, 2018 11:03 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

I tried with ether1 (my wan on test router) but nothing is catcing in the sniffer when I connect or disconnect. I dont really understand what DNS (udp/53) has to do with DHCP (udp/67-68) If I change it to correct ports I get: 0 14.46 ether1 192.168.222.146:68 (bootpc) 255.255.255.255:67 (bootps) udp...
by huntah
Mon Oct 29, 2018 8:25 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

I just installed beta28 on brand new HapLite (default Settings). added Certificates and ipsec ike2 RSA setup: /certificate add common-name=TESTCA name=TESTCA days-valid=3650 sign TESTCA ca-crl-host=192.168.3.124 add common-name=192.168.3.124 subject-alt-name=DNS:192.168.3.124 key-usage=tls-server na...
by huntah
Mon Oct 29, 2018 4:33 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 169874

Re: v6.44beta [testing] is released!

ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
Any Examples?

If I am not mistanken this means that split tunneling will now work!
by huntah
Sat Aug 25, 2018 12:11 pm
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 67
Views: 43036

Re: Sofware VLAN/Bridge on RuterOS explained.

Very nice post but one thing is missing,
Final configuration export with your last picture..
by huntah
Sat Aug 25, 2018 12:07 pm
Forum: General
Topic: how open port 1194 in mikrotik?
Replies: 10
Views: 20615

Re: how open port 1194 in mikrotik?

you have not specified where is your VPN server? On the router (mikrotik) or do you have to port forward it to internal OpenVPN server.. If you just need the client it should work out of the box because there are no limitation for outbound limits. So if you have openVPN server on your Mikrotik you n...
by huntah
Sat Jul 14, 2018 3:12 pm
Forum: General
Topic: How to prevent communication between two bridges? [SOLVED]
Replies: 7
Views: 3659

Re: How to prevent communication between two bridges? [SOLVED]

use ip firewall filter and chain forward.

Drop subnet a to subnet b and vice vera.

Or use search on forum. It has been asked and answered multiple times :)
by huntah
Sun Jun 24, 2018 9:55 am
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 39574

Re: v6.42.4 [current]

Why it just started to suck... different configurations for different rb models in vlans,... are You kidding? cant't rewrite config in common syntax? The VLAN configuration is the same for all models. MikroTik completely changed (improved) the VLAN configuration in 6.41 for all devices. It is not M...
by huntah
Fri Jun 22, 2018 6:16 pm
Forum: General
Topic: hAP-AC2 6.42.4 - HWOffload [solved]
Replies: 13
Views: 6422

Re: hAP-AC2 6.42.4 - HWOffload

The hAP ac² dose have a switch chip (Atheros 8327) with vlan switching support and is supported in routeros. The RB750Gr3 have also a switch chip (MT7621) with vlan switching support but is on yet implemented in routeros. So on the RB750Gr3 you only can use software switch if you need vlans. See th...
by huntah
Fri Jun 22, 2018 11:40 am
Forum: General
Topic: hAP-AC2 6.42.4 - HWOffload [solved]
Replies: 13
Views: 6422

Re: hAP-AC2 6.42.4 - HWOffload

There is no switch menu Winbox in 6.42.4 :) In CLI i can see it.. # NAME TYPE MIRROR-SOURCE MIRROR-TARGET SWITCH-ALL-PORTS 0 switch1 Atheros-8327 none none Will try later to set it via CLI and test. And yes the speed is terrible 5MB/s the gateway is HEXGr3 and gets 33% CPU load... but in anyway this...
by huntah
Thu Jun 21, 2018 11:31 am
Forum: General
Topic: hAP-AC2 6.42.4 - HWOffload [solved]
Replies: 13
Views: 6422

hAP-AC2 6.42.4 - HWOffload [solved]

Is this only cosmetic bug in Winbox? in terminal I can see HW ofload active but Winbox shows off. If I disable VLAN filtering I can see HW offload in Winbox. Here is the Brige config. It is working.. But I havent tested performace yet... /interface bridge add ageing-time=5m arp=enabled arp-timeout=a...
by huntah
Thu Jun 21, 2018 10:37 am
Forum: General
Topic: New IP cloud is coming.
Replies: 84
Views: 46979

Re: New IP cloud is coming.

The hostnames will be the same for the same router. Do not worry about that. The domain name will always be tied to the serial number of the router. If you are going to change routers - then you better create on your your own DNS server CNAME entry that points to the <SN>.sn.mynetname.net FQDN. It ...
by huntah
Wed Jun 20, 2018 11:26 am
Forum: General
Topic: New IP cloud is coming.
Replies: 84
Views: 46979

Re: New IP cloud is coming.

@janisk: I have multiple Clients with IKEv2 Server with RSA (Certificates). Those Certificates are made with ddns hostname (7dgfdghgssaa1.sn.mynetname.net) from IP Cloud.will the hostname remain the same. If not I have a big problem since I have to reissue all certificates to users on multiple site...
by huntah
Wed Jun 20, 2018 9:39 am
Forum: General
Topic: New IP cloud is coming.
Replies: 84
Views: 46979

Re: New IP cloud is coming.

@janisk: I have multiple Clients with IKEv2 Server with RSA (Certificates). Those Certificates are made with ddns hostname (7dgfdghgssaa1.sn.mynetname.net) from IP Cloud.will the hostname remain the same. If not I have a big problem since I have to reissue all certificates to users on multiple sites.
by huntah
Mon Jun 18, 2018 3:34 pm
Forum: General
Topic: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)
Replies: 15
Views: 6825

Re: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)

Actualy yes and no :) Windows Server VPN (RRAS) uses DHCP to assign IP addresses to VPN Clients. Mikrotik uses only a IP Pool. But that is OK it works. I am trying to put into motion (if you can) a "Feature" in addition to classic routes being sent to the client Another push of DHCP option...
by huntah
Mon Jun 18, 2018 2:56 pm
Forum: General
Topic: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)
Replies: 15
Views: 6825

Re: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)

@mrz IKEv2 client gets an IP from IP-Pool (IKE-Pool). I have one or more DHCP Servers on the LAN side (Depending on VLANs..). But for example sake lets just say I have one on Bridge-Local. Bridge-local: 192.168.1.0/24 IKE-Pool: 192.168.200.0/24 Where do I set DHCP option 121 (on bridge-local DHCP se...
by huntah
Mon Jun 18, 2018 11:57 am
Forum: General
Topic: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)
Replies: 15
Views: 6825

Re: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)

Hi is there any solution for this problem on Windows10. other than: Add-VpnConnectionRoute -ConnectionName "My VPN" -DestinationPrefix 192.168.0.0/16 -PassThru @Mikrotik or someone else: Is there any way to send DHCP option 121 (Static Routes) when WIn10 connect for split tunneling. I thin...
by huntah
Fri Jun 15, 2018 9:00 pm
Forum: General
Topic: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED]
Replies: 7
Views: 10435

Re: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED] [SOLVED]

Hi, I have found the solution if someone should came accros the same problem. So the solution is to use powerShell and specify the CA to use: here is the example. Set-VpnConnection -Name "My VPN Connection" -MachineCertificateIssuerFilter 'C:\mycerts\cert_export_MikrotikIKEv2-CA.crt' Now I...
by huntah
Wed Jun 13, 2018 4:18 pm
Forum: General
Topic: IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED]
Replies: 7
Views: 10435

IKEv2 - Win10 Select Certificate Multiple VPN tunels [SOLVED]

Hi, I have IKEv2 with cert up and running. Everrthig is working as it should but I have a problem on Win10 1803 machines (maybe also other Win versions). The config is based on: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_using_IKEv2_with_RSA_authentication I manage multiple cl...
by huntah
Mon May 21, 2018 4:52 pm
Forum: Beginner Basics
Topic: CHR - Access Internet via external Proxy
Replies: 3
Views: 1568

Re: CHR - Access Internet via external Proxy

Hi CZFan, first sorry for late reply. I think you have just pasted the same answer which I already tried and found on forum. And It is missing a chain. But it does not work (it does not count the packets). So here is the complete ip firewall export: /ip firewall address-list add address=download.mik...
by huntah
Fri May 18, 2018 4:34 pm
Forum: Beginner Basics
Topic: CHR - Access Internet via external Proxy
Replies: 3
Views: 1568

CHR - Access Internet via external Proxy

Hi, I have a Dude Server installed on a CHR (Hyper-V) which is working. ROS 6.42.2. There is only one ether interface name=ether1. IP and Default GW, DNS is configured and I can ping and traceroute everthing as I should. But the Main Firewall is blocking internet acess directly and I have to use Pro...
by huntah
Wed May 16, 2018 7:55 pm
Forum: General
Topic: VPN IKEv2 RW withRSA - Check Logons
Replies: 0
Views: 713

VPN IKEv2 RW withRSA - Check Logons

Hi,

I have IKEv2 with certificates up and running. My only question is there a way to see which users have connected and when. (Without Radius and EAP).
Something similar as LT2P - Secrets - Last logon.

Thanks for answers or advise.
by huntah
Sat May 05, 2018 10:31 am
Forum: General
Topic: Linux<->Mikrotik Site-to-Site OpenVPN issue [UPD]
Replies: 24
Views: 7202

Re: Linux<->Mikrotik Site-to-Site OpenVPN issue [UPD]

How about NAT (Masquerade). Did you disable it on both sides for the tunel IPs?
by huntah
Wed Apr 25, 2018 12:11 am
Forum: The Dude
Topic: How to add Device on map (Device added in Winbox)
Replies: 0
Views: 1158

How to add Device on map (Device added in Winbox)

Hi,

I have added some devices (Switches) in Dude / Device.
Now they are not show on default (only) map.

I cannot find the field or setting to specify to show them on the map.
Any help would be appriciated.

Using ROS 6.42

Regards,
Huntah
by huntah
Wed Mar 21, 2018 12:56 am
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 537
Views: 190713

Re: v6.42rc [release candidate] is released!

Seems like my hap ac2 has 233 MB RAM . at least on ROS 6.40.5 Using it as Cap for testing. So did not jump tu 6.42rc yet.. uptime: 1d7h32m31s version: 6.40.5 (stable) build-time: Oct/31/2017 13:05:15 factory-software: 6.40.5 free-memory: 208.7MiB total-memory: 233.4MiB cpu: ARMv7 cpu-count: 4 cpu-fr...
by huntah
Fri Jan 26, 2018 6:36 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 537
Views: 190713

Re: v6.42rc [release candidate] is released!

*) sfp - improved SFP module compatibility;
That this means thaht the following SFP modules are working:
viewtopic.php?f=17&t=120190&p=591082&hi ... 02#p591082

If yes will there be an update for SwOS also?
by huntah
Thu Jan 25, 2018 12:26 am
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 537
Views: 190713

Re: v6.42rc [release candidate] is released!

I am very glad Mikrotk is working on Certificates. I dont use SCEP but rather more and more popular LetsEncypt (hotstpot, SSTP and IKEv2 VPN !). I would be great if Mikrotik could implement something like acme.sh . I have used this guide https://www.ollegustafsson.com/en/letsencrypt-routeros/ to aut...
by huntah
Fri Dec 01, 2017 4:42 pm
Forum: General
Topic: VLANs not working on 6.40.5
Replies: 4
Views: 1720

Re: VLANs not working on 6.40.5

If you are not using SFP module then you do not need a bridge. So you can remove it as you described All other Interfaces are in the same switch group and thus you can use hw switching. I would do it like this: /interface ethernet set [ find default-name=ether2 ] name=ether2-master set [ find defaul...
by huntah
Fri Dec 01, 2017 1:13 am
Forum: General
Topic: WAN IP's in DHCP
Replies: 1
Views: 854

Re: WAN IP's in DHCP

I suspect you have a DHCP assigned IP address and then the the ISP is Routing a block of IPs to your DHCP assigned IP. You can make a local PPPoE Server and distribute the adresses or simply make a Pool With Public IPs and a DHCP Server on the internal bridge(or interface) on which your clients conn...
by huntah
Fri Dec 01, 2017 12:39 am
Forum: General
Topic: VLANs not working on 6.40.5
Replies: 4
Views: 1720

Re: VLANs not working on 6.40.5

HI, Put VLAN9 interface on top of your master interface (ether2-master) /interface vlan add interface=ether2-master name=vlan9 vlan-id=9 And if you do not use SFP1 than you do not need a bridge. If you want to use HW Switching you must not use Bridge (except in new Bridge implementation 6.41RC) But ...
by huntah
Mon Nov 27, 2017 9:18 pm
Forum: General
Topic: Need to pass VLAN from WAN to LAN [SOLVED]
Replies: 4
Views: 5759

Re: Need to pass VLAN from WAN to LAN [SOLVED]

Yes exactly like that..
by huntah
Sun Nov 26, 2017 8:26 pm
Forum: General
Topic: Need to pass VLAN from WAN to LAN [SOLVED]
Replies: 4
Views: 5759

Re: Need to pass VLAN from WAN to LAN [SOLVED]

Quite a bit wrong in your config :). First If you make a bridge and put interfaces in bridge than add IP on bridge not interface ether2. /ip address add address=10.9.8.1/24 interface=bridge1 network=10.9.8.0 You wont be able to do what you want using Switch chip.. Well maybe you could (WAN-VLAN10, M...
by huntah
Sun Nov 19, 2017 12:05 pm
Forum: Beginner Basics
Topic: IKEv2 with Letsencrypt
Replies: 2
Views: 2730

Re: IKEv2 with Letsencrypt

Did you manage to get this working?
It would be great.. No need to install cert on user device.. There is also a way to auto renew and import le certs to mikrotik...
by huntah
Wed Oct 11, 2017 12:37 am
Forum: General
Topic: Feature Req: IKEv2 server and client [SOLVED]
Replies: 291
Views: 170787

Re: Feature Req: IKEv2 server and client [SOLVED]

Yes it was a masquerade problem!
I have to masquerade traffic to my other VPN endpoints therefore I have to masquerade on all interfaces not just internet one.

Once again thank you ihave!
by huntah
Wed Oct 11, 2017 12:30 am
Forum: General
Topic: Feature Req: IKEv2 server and client [SOLVED]
Replies: 291
Views: 170787

Re: Feature Req: IKEv2 server and client [SOLVED]

Thank you ihave! I was missing the forward firewall rule! Now the internet is working but I have another problem. From my router where IKEv2 Server is I have several VPN tunels (ovpn, L2TP Client to another branch etc).. If I use L2TP/IPSEC Server instead of IKEv2 I can reach all the remote (VPN) lo...
by huntah
Sun Oct 08, 2017 8:02 pm
Forum: General
Topic: Feature Req: IKEv2 server and client [SOLVED]
Replies: 291
Views: 170787

Re: Feature Req: IKEv2 server and client [SOLVED]

Hi all, i have a working Roadwarrior setup IKEv2 but I would like to route all traffic accross the VPN not just SPLIT-Tunnel. I cannot seem to make it work. I get the default route (StrongSwan, even on Win10 with option to use remote default gateway) but it does not seem to work. I think it is a pro...
by huntah
Sun Sep 17, 2017 8:47 pm
Forum: General
Topic: High latency and 100% CPU on load
Replies: 7
Views: 7671

Re: High latency and 100% CPU on load

You are useing software (ROS) based VLAN routing and handling. Because you have followed the wrong example in Wiki. If I understand U are using a CRS switch (CRS210) so the correct way is using Switch menu and utilise hardware VLAN capatibilities. https://wiki.mikrotik.com/wiki/Manual:CRS_examples#P...
by huntah
Sun Jul 16, 2017 10:11 pm
Forum: RouterBOARD hardware
Topic: Why CRS326-24G-2S+RM doesn't show in https://mikrotik.com/products/?
Replies: 8
Views: 2307

Re: Why CRS326-24G-2S+RM doesn't show in https://mikrotik.com/products/?

Anyone knows on which CPU architecture running RouterOS in CRS326-24G-2S+RM? ARM, MIPSBE or SMIPS? How it compares with CPU performance of CRS125 or CRS226?
I would also like to know if it is comparable to CRS125..
How is IPSEC throughput?
by huntah
Mon Jul 10, 2017 11:27 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released! (New bridge implementation delayed till 6.41rc)
Replies: 207
Views: 65770

Re: v6.40rc [release candidate] is released! (New bridge implementation)

I think there is another mistake in VLAN Example #2 (Trunk and Hybrid Ports): https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#VLAN_Example_.232_.28Trunk_and_Hybrid_Ports.29 /interface bridge vlan add bridge=bridge1 tagged=ether2,ether7,ether8 untagged=ether6 vlan-ids=200 add bridge=bridge1 ta...
by huntah
Mon May 01, 2017 2:06 am
Forum: Beginner Basics
Topic: VPN IPSec IKEv2 with Windows 10, Clients behind router not pingable
Replies: 1
Views: 4380

Re: VPN IPSec IKEv2 with Windows 10, Clients behind router not pingable

If you have the same subnet for VPN clients as your internal LAN subnet. Then you have to enable Proxy-arp on the interface facing the local subnet
by huntah
Sat Apr 29, 2017 11:59 am
Forum: General
Topic: rogue DHCP servers destroy the whole network ( mikrotik )
Replies: 13
Views: 3588

Re: rogue DHCP servers destroy the whole network ( mikrotik )

yes it does. but you could also buy a new Mikrotik CRS router for roughly the same amount. But Cisco is a better switch evethough it is used. Or If you have Mikrotik on the edge ports (where APs are connected) you could use this thread and it could help you solve your problems: https://forum.mikroti...
by huntah
Wed Apr 19, 2017 9:51 pm
Forum: General
Topic: Mikrotik Ipsec VPN tunnel problem
Replies: 15
Views: 11493

Re: Mikrotik Ipsec VPN tunnel problem

Do you have fasttrack enabled?
If so disable it for IPSEC traffic.
by huntah
Thu Apr 13, 2017 3:38 pm
Forum: General
Topic: L2TP/IPSec + iOS Error :(
Replies: 1
Views: 1376

Re: L2TP/IPSec + iOS Error :(

At first glance. You are mixing IKEv1 (IPSEC) and L2TP/IPSEC.
Specified ppp users have only L2TP allow.
If you want mode-config then you specify users in IP - IPSEC - USERS

But first choose L2TP or IPSEC with mode conf.
If you go L2TP then Iphone should also be set to L2TP (not IPSEC)
by huntah
Mon Apr 10, 2017 8:15 pm
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 390
Views: 139411

Re: v6.39rc [release candidate] is released

Does the black list function in the discover info window of the dude client for windows work right in this build? In 6.38.3, and previous versions I don't see the . or ... buttons shown in the manual here. http://wiki.mikrotik.com/wiki/Manual:The_Dude/Device_discovery There is a related bug where d...
by huntah
Sat Apr 08, 2017 11:10 am
Forum: Beginner Basics
Topic: Site-to-site IPsec: connection established, but traffic doesn't flow properly
Replies: 9
Views: 7901

Re: Site-to-site IPsec: connection established, but traffic doesn't flow properly

Hi,

I dont know why it isnt woriking for you..
But check this site with detailed info:
https://schemen.me/mikrotik-fast-track- ... des-ipsec/

Also check the comments.. maybe you need to add those two rules also..
I did not have to add them.
by huntah
Thu Apr 06, 2017 11:51 pm
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 390
Views: 139411

Re: v6.39rc [release candidate] is released

Does the black list function in the discover info window of the dude client for windows work right in this build? In 6.38.3, and previous versions I don't see the . or ... buttons shown in the manual here. http://wiki.mikrotik.com/wiki/Manual:The_Dude/Device_discovery There is a related bug where d...
by huntah
Thu Apr 06, 2017 11:17 pm
Forum: Beginner Basics
Topic: Site-to-site IPsec: connection established, but traffic doesn't flow properly
Replies: 9
Views: 7901

Re: Site-to-site IPsec: connection established, but traffic doesn't flow properly

You have to disable fastrack for IPSEC traffic. It is also documented in Wiki: https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack I have found that this works like a charm: /ip firewall mangle add action=mark-connection chain=forward comment="Mark IPsec" ipsec-policy=out,ipsec new-connecti...
by huntah
Tue Mar 28, 2017 11:54 pm
Forum: General
Topic: [Solved] IKEv1 ModeConf Static DNS not working
Replies: 0
Views: 914

[Solved] IKEv1 ModeConf Static DNS not working

Hi, I am using ROS 6.38.5 and have a working RoadWarrior IPSEC with ModeConf. https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_with_Mode_Conf Do not forget to BYPASS FASTTRACK and ajust the Phase1 and Phase2 settings in ShrewClient to match your config! It is also working with my Wi...
by huntah
Fri Mar 10, 2017 7:49 pm
Forum: Beginner Basics
Topic: DHCP-Server - Leases Sorting - Dynamic on top
Replies: 0
Views: 732

DHCP-Server - Leases Sorting - Dynamic on top

Hi, somewhere between ROS 6.32 and lastest 6.37.4 the sorting in DHCP-Server lease changed. I have quite a few reservation (80plus) and was very happy that Dynamicly assigned leases were on top. Now there are inbetween the staticly assigned leases and it is very annoying. Is there any change to get ...
by huntah
Tue Feb 14, 2017 1:01 am
Forum: General
Topic: IPsec VPN with multiple subnets in "cryptomap"
Replies: 9
Views: 7592

Re: IPsec VPN with multiple subnets in "cryptomap"

After several hours and configuraction changes I searched the forum and I can confirm that MRZ answer is correct and working.

Thanks MRZ!
by huntah
Fri Feb 10, 2017 1:09 pm
Forum: General
Topic: Native vlan 1 + vlans connected to Cisco switch
Replies: 4
Views: 5883

Re: Native vlan 1 + vlans connected to Cisco switch

If it is Tagged VLAN1 then you need to set VLAN1 in mikrotik (interface vlan). If it is Untagged (as in natvice VLAN) then mikrotik needs to be set at VLAN0. Check this post: http://forum.mikrotik.com/viewtopic.php?f=2&t=115115&p=571100&hilit=procurve+vlan HP Procurve should be same as C...
by huntah
Fri Feb 10, 2017 11:53 am
Forum: General
Topic: Native vlan 1 + vlans connected to Cisco switch
Replies: 4
Views: 5883

Re: Native vlan 1 + vlans connected to Cisco switch

Native VLAN (Cisco VLAN1) is translated to Mikrotik VLAN ID 0 /interface ethernet switch vlan add ports=ether1,ether2,ether3,ether4,ether5,switch1-cpu switch=switch1 vlan-id=0 add ports=ether1,ether2,ether3,ether4,ether5 switch=switch1 vlan-id=12 /interface ethernet switch port set switch1-cpu vlan-...
by huntah
Sat Jan 21, 2017 9:25 pm
Forum: General
Topic: ROS6.38 IKEv2+LocalAuth VPN
Replies: 13
Views: 12438

Re: ROS6.38 IKEv2+LocalAuth VPN

Did some more tests and it seems that Windows10 client add route to the public IP od VPN server Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.23.1 192.168.23.101 50 1.2.3.4 255.255.255.255 192.168.23.1 192.168.23.101 51 192.168.77.0 255.255.255.0 On-link 192.168.77.251...
by huntah
Sat Jan 21, 2017 2:19 am
Forum: General
Topic: ROS6.38 IKEv2+LocalAuth VPN
Replies: 13
Views: 12438

Re: ROS6.38.1 IKEv2+LocalAuth VPN

Ok Progress on IkeV2-RSA with certificates! Following manual http://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_Ikev2_RSA_auth Someone needs to update the Wiki page (ip peer missing exchange-mode=Ike2)! And a few changes I managed to: 1. get connected Windows 10 but no routes are added...
by huntah
Fri Jan 20, 2017 9:44 pm
Forum: General
Topic: ROS6.38 IKEv2+LocalAuth VPN
Replies: 13
Views: 12438

Re: ROS6.38 IKEv2+LocalAuth VPN

auth-method=pre-shared-key But than this is not Xauth (mode Confg) ...or am I wrong? I did some tests on windows10 and Ipad (Ios 10.x) and IkeV2 proposal are: Windows10: IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:3DES_CBC/HMAC_SHA2_2...
by huntah
Thu Jan 19, 2017 8:50 pm
Forum: General
Topic: ROS6.38 IKEv2+LocalAuth VPN
Replies: 13
Views: 12438

Re: ROS6.38 IKEv2+LocalAuth VPN

I can't get it to work IPSec+xauth
Can you post your working /IPSec export
How did you setup client on iPad..
Thanx in advance
by huntah
Sun Jan 15, 2017 8:35 pm
Forum: General
Topic: ROS6.38 IKEv2+LocalAuth VPN
Replies: 13
Views: 12438

Re: ROS6.38 IKEv2+LocalAuth VPN

It seems that r3.39rc12 introduces this feature:
*) ike2 - xauth like auth method with user support;

Has anyone tried it yet?
Or can Mikrotik guys give as a working config export.

Thanks
by huntah
Sat Jan 14, 2017 1:34 pm
Forum: General
Topic: ROS6.38 IKEv2+LocalAuth VPN
Replies: 13
Views: 12438

ROS6.38 IKEv2+LocalAuth VPN

Hi, is it possible to make IKEv2 VPN with local Auth. Something like on PfSense 2.3.2 https://doc.pfsense.org/index.php/IKEv2_with_EAP-MSCHAPv2#Set_up_Mobile_IPsec_for_IKEv2.2BEAP-MSCHAPv2 This setup is working for me on Windows10 and I only need a Server Cert (created on PfSense) and then I can spe...
by huntah
Thu Jan 12, 2017 1:13 am
Forum: General
Topic: ipsec can't configure because : is interpreted as ip6 address
Replies: 6
Views: 1291

Re: ipsec can't configure because : is interpreted as ip6 address

Hi,

you can ping from MT to MT over IPSEC. YOu just need to spcify internal interface
ping interface=bridge-local 172.16.1.10
where bridge-local is my internal interface and 172.16.1.10 is server on the internal remote IPSEC site.
by huntah
Thu Jan 05, 2017 1:08 am
Forum: Beginner Basics
Topic: Self signed certificates and CRL
Replies: 2
Views: 6861

Re: Self signed certificates and CRL

Hi did you find a way to use a public WWW server for your CA-CRL-HOST. And how does the update process work. If I create Self Signed CA on Mikrotik who must check CRL. VPN Server on Mikrotik (SSTP, IKEv2, OpenVPN) or clients? If only Mikrotik Server then I only have to open WWW service for localhost...
by huntah
Mon Jan 02, 2017 11:31 pm
Forum: General
Topic: Routing between VLANs
Replies: 11
Views: 24663

Re: Routing between VLANs

I know that ROS is working as it should. Because I use it on over 100 system (different setups, WiSP, MultiHome, Multiple VLANs, routing, switching etc). I "decrypted" from your answer you are using NAT. I guess you mean Masquerade if yes disable it for your VLAN segments. Since you cant/ ...
by huntah
Mon Jan 02, 2017 8:51 pm
Forum: General
Topic: RB2011 chip switch - Trunk and Hybrid ports
Replies: 7
Views: 4151

Re: RB2011 chip switch - Trunk and Hybrid ports

Yes it is possible to have multiple VLANs on the same interface in the same switchgroup (switch1 or switch2) and also unttaged VLAN (Hybrid port) /interface ethernet switch port set 0 default-vlan-id=10 vlan-header=add-if-missing vlan-mode=secure set 1 default-vlan-id=30 vlan-header=always-strip vla...
by huntah
Mon Jan 02, 2017 8:27 pm
Forum: General
Topic: Routing between VLANs
Replies: 11
Views: 24663

Re: Routing between VLANs

If it is aCHR then you dont have a Switch menu. You configure your interfaces in your CHR HOST (ESXi, Hyper-Z etc). I always configure network interface in the host (tagged) and then use appropriate ether interface in CHR. So now it makes sense what you have wirten ether3-VLAN3 and ether4-vlan4. Aga...
by huntah
Mon Jan 02, 2017 6:53 pm
Forum: General
Topic: Routing between VLANs
Replies: 11
Views: 24663

Re: Routing between VLANs

Your Router has both address 3.1 and 4.1 .. so in traceroute you get in vlan3 to 3.1 address and router knows where to go for vlan4.. There is not and additional hop between 3.1 and 4.1 because it is the same device.. post your config.. Or follow the advice from th0massin0 and follow the wiki. The r...
by huntah
Mon Jan 02, 2017 6:26 pm
Forum: General
Topic: VLAN and IP Management
Replies: 9
Views: 2076

Re: VLAN and IP Management

Quick look into your configuration and i can see you did not set Admin MAC for bridge. Please set admin MAC to bridge infterface on both switches. But I dont know why you even created a software bridge as you only added ether1-master interface in this bridge? I would remove bridge and add VLAN50 int...
by huntah
Sat Dec 17, 2016 2:24 pm
Forum: General
Topic: Multi DHCP clients on same WAN port
Replies: 16
Views: 9273

Re: Multi DHCP clients on same WAN port

I think this type of adding IPs by the ISP is wrong. In my cases (different ISPs) I use one DHCP Client address or PPPoE Client for WAN and the the ISP Route all other IPs to my DHCP/PPPoE Assigned IP. Then I can manualy add IPs to ip addresses or route designated (from ISP) addresses to my clients....
by huntah
Mon Dec 12, 2016 11:01 pm
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

As I said before HP VLAN1 is native VLAN and if you set PVID 1 (or untagged VLAN1) on trunk port of HP it translates to Mikrotik native VLAN 0. Ergo then set up ip directly on interface.. No need for aditional VLAN interface.
Anyhow this is how I do it because it is simpler..
by huntah
Mon Dec 12, 2016 5:35 pm
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

The reason for setting my management IP on a vlan interface on the trunk port is that this trunk port is always up an running, thus I can connect to my switch. If I use an untagged port for that which is not always up and running I cannot connect to my device. I must say I dont understand exactly w...
by huntah
Sun Dec 11, 2016 8:34 pm
Forum: Beginner Basics
Topic: LAN Bug on 6.37.3?
Replies: 7
Views: 1838

Re: LAN Bug on 6.37.3?

from this export everthing seems to be OK. Do the host on ether2-4 have DHCP-Client enabled? What are those hosts? Can you check IPs on these hosts? Maybe you have another DHCP server on the same network. Are there any other switches on those ports? From Mikrotik point of view everything should be OK.
by huntah
Sun Dec 11, 2016 4:22 pm
Forum: Beginner Basics
Topic: LAN Bug on 6.37.3?
Replies: 7
Views: 1838

Re: LAN Bug on 6.37.3?

post export.. difficult to say.. as this should work normal..
by huntah
Sun Dec 11, 2016 9:46 am
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

You said I should not add the address to this interface? What is the reason for that? If I add it to trunk port (ether1) itself how can I be sure that it is only visible in VLAN 1? Native VLAN (VLAN0) is ony visible in this VLAN as any other VLAN. It is the same with HP and VLAN1 which is only visi...
by huntah
Fri Dec 09, 2016 12:14 am
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

- All MAC addresses in the Host tab are shown with VLAN ID 0. How is that possible? If you mean when you double click on specific host and see status window I also have all hosts in VLANID 0- . maybe you found a bug (write to support@mikrotik.com). Or if someone else knows why is this feel free to ...
by huntah
Thu Dec 08, 2016 11:42 pm
Forum: General
Topic: Disable DHCP requests
Replies: 2
Views: 1436

Re: Disable DHCP requests

It think it would be better to solve this in switch chip.. but then you must have ether1 and ether2 in same switch group (master and slave interfaces..)

See this post.
http://forum.mikrotik.com/viewtopic.php ... 28#p505473
by huntah
Wed Dec 07, 2016 1:41 am
Forum: Announcements
Topic: v6.37.3 [current] is released!
Replies: 58
Views: 32414

Re: v6.37.3 [current] is released!

Disregard... was a config mistake...
by huntah
Tue Dec 06, 2016 9:15 pm
Forum: Beginner Basics
Topic: Source NAT with multiple public IP adresses
Replies: 9
Views: 12805

Re: Source NAT with multiple public IP adresses

Read here and adjust accordingly to your needs

http://wiki.mikrotik.com/wiki/Manual:IP ... ic_address
by huntah
Tue Dec 06, 2016 9:12 pm
Forum: Beginner Basics
Topic: VLAN Setup using hardware features - RB2011UiAS and Cisco SG 200-08
Replies: 9
Views: 2612

Re: VLAN Setup using hardware features - RB2011UiAS and Cisco SG 200-08

Glad to help. I will point out some more things I spotted. Firstly switch1 and switch2 should have secure (not fallback) VLAN Mode set Here are some mistakes that I see comparing diagram and settings from pictures: 1. Ether1 (wan .. i guess it should be unttaged native vlan) set VLAN mode to disable...
by huntah
Mon Dec 05, 2016 2:02 pm
Forum: Beginner Basics
Topic: VLAN Setup using hardware features - RB2011UiAS and Cisco SG 200-08
Replies: 9
Views: 2612

Re: VLAN Setup using hardware features - RB2011UiAS and Cisco SG 200-08

I see you havent assigned Admin MAC to bridge. Please do so and try again. I had bunch of problems without setting Admin MAC on bridges. Of course set each bridge to unique MAC. Try it and post results.. Also if it is not working try firstly without bridges, just interfaces (I know there are two swi...
by huntah
Sun Dec 04, 2016 11:33 am
Forum: General
Topic: Cannot ping VLAN gateway or obtain IP via DHCP
Replies: 3
Views: 1950

Re: Cannot ping VLAN gateway or obtain IP via DHCP

You did not read the whole wiki ;) Firstly you must put ports in one switch group. so set ether1 and every other port to slave as master port set to ether1 Also you have to pot your vlan interface on to of ether1 /interface vlan add interface=ether1 name=vlan10 vlan-id=10 add interface=ether1 name=v...
by huntah
Sat Dec 03, 2016 10:41 pm
Forum: General
Topic: Cannot ping VLAN gateway or obtain IP via DHCP
Replies: 3
Views: 1950

Re: Cannot ping VLAN gateway or obtain IP via DHCP

If this is your complete export you are missing settings for switch chip and VLANs.
for tagged ports:
/interface ethernet switch egress-vlan-tag
for access ports:
/interface ethernet switch ingress-vlan-translation

Look at these examples:
http://wiki.mikrotik.com/wiki/Manual:CRS_examples
by huntah
Sat Dec 03, 2016 1:39 pm
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

OK I did some test with HP Procurve 1920-8g and hAP Lite. So to sum it up: VLAN1 HP as PVID (or Access Point) translates to VLAN ID 0 on Mikrotik If you change PVID on HP to lets say 450 (something you are not using) and make VLAN1 tagged then it translates on Mikrotik as VLAN1 but you need to creat...
by huntah
Thu Dec 01, 2016 12:08 am
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

HI, sadly I did not find time to configure 1920 yet but here is a working setup based on your initial export. I changed and added more VLANs (for test). Every Interfave gets DHCP from VLAN DHCP (on main Mikrotik Router). Also for Access ports you must just set it like default VLANID (ie PVID in HP) ...
by huntah
Tue Nov 29, 2016 12:45 am
Forum: General
Topic: VPN and Dns Suffix
Replies: 2
Views: 5882

Re: VPN and Dns Suffix

It is not supported.. You can add it on client side manualy.
More on this topic:
http://forum.mikrotik.com/viewtopic.php?t=39999
by huntah
Tue Nov 29, 2016 12:36 am
Forum: General
Topic: Why my Mikrotik Router has same MAC ADDRESS
Replies: 3
Views: 3839

Re: Why my Mikrotik Router has same MAC ADDRESS

My guess would be imported config script. You have a Reset MAC address button in interface windows. Click it and it should revert back to original (unimported) MAC. You can check aginst label on Routerboard hardware. It should be the same. Also check Bridges (admin mac). And change it accordingly. S...
by huntah
Tue Nov 29, 2016 12:21 am
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

When I do that the connection to the MikroTik is lost. Thanks to SafeMode I am able to reconnect after a reboot :-) I have assigned the IP 192.168.0.190 to ether1 as I want to connect by winbox with an IP. This did not work until my single switch rule was added. As far as I understand this is neede...
by huntah
Tue Nov 29, 2016 12:09 am
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

I will check your settings against a HP procurve 1920-8g tommorow. Especialy VLAN1 because I am not sure how MK and HP see native VLAN.. But in the mean time you could do following for test purpuse: remove ether2 from switch group - set master port to none. Add an IP to the interface and you connect...
by huntah
Mon Nov 28, 2016 12:18 pm
Forum: Beginner Basics
Topic: VLAN Setup using hardware features - RB2011UiAS and Cisco SG 200-08
Replies: 9
Views: 2612

Re: VLAN Setup using hardware features - RB2011UiAS and Cisco SG 200-08

I think "native" VLAN in mikrotik is VLAN0. . For trunk port to Cisco you should have setting "secure" and "add if missing" (ie Tagged interface) on Mikrotik interface (Cisco is connected to ether1 I presume) and default VLAN ID 0 (for native VLAN). Also re-enabe VLAN 0...
by huntah
Mon Nov 28, 2016 12:05 pm
Forum: Beginner Basics
Topic: Help making HAP AC as Switch + Other info
Replies: 4
Views: 2619

Re: Help making HAP AC as Switch + Other info

mducharme wrote: Yeah, on the hAP AC I used the "Home AP Dual" quickset config for that kind of setup. I would recommend that for your case. You can always start with that (avoiding use of ether1) and then later manually remove the address from ether1 and make it a slave to ether2-master....
by huntah
Sun Nov 27, 2016 8:39 pm
Forum: General
Topic: VLAN trunk port with switch chip
Replies: 18
Views: 11570

Re: VLAN trunk port with switch chip

I think VLAN1 on Procurve is "native" VLAN. native VLAN on RouterOS is VLAN 0. So set it to VLAN0. Also I think you should specify IP of gateway not Interface. I only set Interface when using with PPPoe client and VPN Client interface. For Mirroring ether1 to ether2 you shoukd use this com...
by huntah
Sat Nov 26, 2016 10:33 pm
Forum: Beginner Basics
Topic: Help making HAP AC as Switch + Other info
Replies: 4
Views: 2619

Re: Help making HAP AC as Switch + Other info

If you use Quickset then I think you are better of with Home AP than WISP. If I understood you correctly the hAP is connected via ethernet cable. Also you already have a DHCP server in your network.so untick DHCP Server. Set a local IP inside your private network and WiFi settings. Connect ethernet ...
by huntah
Sat Nov 26, 2016 8:49 pm
Forum: Beginner Basics
Topic: VLAN issue in CRS
Replies: 1
Views: 910

Re: VLAN issue in CRS

/interface ethernet switch
set drop-if-invalid-or-src-port-not-member-of-vlan-on-ports=\
ether2-master-local,ether5-slave-local,ether7-slave-local
I think you should drop invalid vlan on all interfaces..
by huntah
Sat Nov 26, 2016 8:41 pm
Forum: General
Topic: Simple IPsec site-to-site ... not working
Replies: 1
Views: 934

Re: Simple IPsec site-to-site ... not working

skeeming through setup I cannot see that you allow IPSEC-ESP, IPSEC-AH and UDP 500 ip firewal filter input chain. ;;; Allow IKE chain=input action=accept protocol=udp dst-port=500 ;;; Allow IPSec-esp chain=input action=accept protocol=ipsec-esp ;;; Allow IPSec-ah chain=input action=accept protocol=i...
by huntah
Sun Nov 20, 2016 11:38 am
Forum: General
Topic: CCR and CRS VLAN's
Replies: 4
Views: 2441

Re: CCR and CRS VLAN's

add switch1-cpu to vlan and eg.vlan tag on the CRS side if you want to be able to get IP inside ROS
Else it only works on Layer2 (Switching) and you wont be able to manage it via ROS (ie Layer3).
by huntah
Fri Nov 18, 2016 5:48 pm
Forum: General
Topic: [SOLVED] Slow speeds with ISP subnet and VLANs on CRS125
Replies: 14
Views: 5181

Re: Slow speeds with VLANs on CRS125

maybe you are doing NAT on the oposite side 10.254.43.0/24

Check /IP firewall NAT
by huntah
Fri Nov 18, 2016 5:43 pm
Forum: General
Topic: SXT 5 ac usage as bridge for vlans
Replies: 4
Views: 1535

Re: SXT 5 ac usage as bridge for vlans

Yes it is doable no problem..
by huntah
Wed Nov 16, 2016 5:14 pm
Forum: General
Topic: [SOLVED] RB3011UiAS + USB 3.0 thumb drive
Replies: 12
Views: 8646

Re: RB3011UiAS + USB 3.0 thumb drive

I use SanDisk Extreme CZ80 32Gb, RB3011 can detect it and work at 5000Mbps I format ext3, upload via ftp avarage 5MB/s, download 30MB/s (80MB/200MB when plugin to pc). Can you please test SMB transfer from Windows machine? How is the CPU load.. I have a RB2011 and the speed is too low for any kind ...
by huntah
Sat Nov 05, 2016 11:06 am
Forum: Announcements
Topic: v6.38rc [release candidate] is released
Replies: 331
Views: 122969

Re: v6.38rc [release candidate] is released

strods wrote: !) ipsec - added IKEv1 xauth user authentication with RADIUS "/ip ipsec user settings set radius=yes" (cli only); !) ipsec - added IKEv2 experimental support with pre-shared-key and rsa-signature authentication methods (cli only); !) ipsec - added support unique policy gener...
by huntah
Mon Apr 11, 2016 6:49 pm
Forum: Wireless Networking
Topic: Wireless discovery interface in CAP
Replies: 2
Views: 1414

Wireless discovery interface in CAP

Hi,

is it possible to use a CAP in CAPsMAN system without LAN interface.
Something like UniFi where when you set things up you need a wired link and then it can connect to nearby APs via WLAN uplink..
by huntah
Tue Mar 15, 2016 11:30 pm
Forum: Wireless Networking
Topic: BIG problem with roaming and bridges
Replies: 1
Views: 1225

Re: BIG problem with roaming and bridges

Hi, I am expiriencind the same problem. no TX traffic on the new AP.. Did you mange to solve it? I have tried ROS 6.32.4 and 6.34.2 with same result. I started to happen lately (not sure when). Best result is when I disable fastpath.. then is mainly working. If anyone else can confirm this probelm a...
by huntah
Fri Mar 11, 2016 10:42 pm
Forum: Wireless Networking
Topic: Capsman - hotspot - multiple sites
Replies: 0
Views: 1291

Capsman - hotspot - multiple sites

Hi, is it possible to create a central hotspot and capsman server and connect via internet to other locations. So my setup would be: 1x (or 2x) Central hostpot server and Capsman 20 CAPs around the city. Each of them with static public IP and own internet connection. One method is to link them toget...
by huntah
Fri Feb 05, 2016 12:33 pm
Forum: General
Topic: L2TP/IPSEC black list bad IPs
Replies: 3
Views: 2257

Re: L2TP/IPSEC black list bad IPs

Does anyone else have this problem?

How to drop IP connections to L2TP/IPSEC attackers?

For example if the same IP tries more than 5 times then it is blocked for 24h..
by huntah
Sun Nov 22, 2015 12:27 am
Forum: General
Topic: CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)
Replies: 7
Views: 3007

Re: CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)

As it turns out in RB951U it does not work because it uses Atheros 8227 you need at least Atheros8327 chip to use rules. On the other hand if you use RB951G it works because it uses Atheros8327. You can check witch Mikrotik products have which chip on this Wiki Page http://wiki.mikrotik.com/wiki/Man...
by huntah
Tue Nov 10, 2015 1:03 am
Forum: General
Topic: MikroTik RB750r2 vpn
Replies: 2
Views: 1984

Re: MikroTik RB750r2 vpn

Search the form . answered multiple times!
Or just read the Wiki:
http://wiki.mikrotik.com/wiki/Manual:IP/IPsec

Youll probably want: Site to Site IpSec Tunnel section
by huntah
Tue Nov 10, 2015 12:55 am
Forum: General
Topic: Stuck with RB750 Switching VLANs!
Replies: 11
Views: 3943

Re: Stuck with RB750 Switching VLANs!

I tried the above setup (similar) and it works. I tried it with HP Procurve 1920 switches. They all got the Management IPs via VLAN0 and VLAN200 and VLAN300 vas tagged and avaible in Procurve. My setup: Mikrotik eth4 (vlan0, vlan200,vlan300) -> Procurve1 port 24 (PVID 1, tagged 200, tagged 200) Then...
by huntah
Mon Nov 09, 2015 12:44 am
Forum: General
Topic: how to set dhcp network name in mikrotik?
Replies: 4
Views: 7178

Re: how to set dhcp network name in mikrotik?

Did you set default GW in DHCP Server: Microsoft for some reason designed Win7 (and Win8) to impose the restricted Public network profile for any network that could not be identified - which disables network file sharing. The Network Location Awareness (NLA) service will only allow you to set the ne...
by huntah
Sat Nov 07, 2015 3:43 pm
Forum: General
Topic: Hybrid port on RB750????
Replies: 1
Views: 1240

Re: Hybrid port on RB750????

by huntah
Sat Nov 07, 2015 1:00 am
Forum: General
Topic: Stuck with RB750 Switching VLANs!
Replies: 11
Views: 3943

Re: Stuck with RB750 Switching VLANs!

/interface ethernet switch port set 0 vlan-mode=fallback set 1 default-vlan-id=200 vlan-header=add-if-missing vlan-mode=secure set 2 default-vlan-id=200 vlan-header=add-if-missing vlan-mode=secure set 3 default-vlan-id=0 vlan-header=always-strip vlan-mode=secure set 4 default-vlan-id=300 vlan-heade...
by huntah
Sat Oct 31, 2015 11:54 pm
Forum: General
Topic: How can I create on Trunk mikrotik with Bridge
Replies: 9
Views: 5620

Re: How can I create on Trunk mikrotik with Bridge

dont use a bridge! Just add vlans to the interface connected to Cisco. Example /interface vlan add interface=eth3 name=vlan15-Management vlan-id=15 add interface=eth3 l2mtu=1594 name=vlan35-private.net vlan-id=35 add interface=eth3 l2mtu=1594 name=vlan36-VoIP-CCTV vlan-id=36 add interface=eth3 l2mt...
by huntah
Sat Oct 31, 2015 1:37 am
Forum: General
Topic: How can I create on Trunk mikrotik with Bridge
Replies: 9
Views: 5620

Re: How can I create on Trunk mikrotik with Bridge

dont use a bridge! Just add vlans to the interface connected to Cisco. Example /interface vlan add interface=eth3 name=vlan15-Management vlan-id=15 add interface=eth3 l2mtu=1594 name=vlan35-private.net vlan-id=35 add interface=eth3 l2mtu=1594 name=vlan36-VoIP-CCTV vlan-id=36 add interface=eth3 l2mtu...
by huntah
Fri Oct 30, 2015 3:06 pm
Forum: General
Topic: CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)
Replies: 7
Views: 3007

Re: CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)

If you use RB951 or similar you can enable DHCP snopping via Switch Rule .. /interface ethernet switch rule add dst-port=68 new-dst-ports="" ports=ether2-master-local,ether3-slave-local,ether4-slave-local switch=switch1 In this example DHCP traffic isnt allowed on ports ether2,3,4 (all por...
by huntah
Fri Oct 30, 2015 8:25 am
Forum: General
Topic: CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)
Replies: 7
Views: 3007

Re: CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)

I need to learn to RTFM :).

The "true" DHCP server must NOT be in the same isolation group..
Now everthing is working as it should and I can enable the filtering rule!

Thanks for your help.
by huntah
Fri Oct 30, 2015 12:32 am
Forum: General
Topic: Trunking Help
Replies: 1
Views: 706

Re: Trunking Help

If you are using CRS use Switch chip VLAN.. It is much faster (wire speed) your configuration is software based Bonding and VLANs.. Use this Wiki: http://wiki.mikrotik.com/wiki/Manual:CRS_examples It is a little tricky at first but when you get a hang of its ok. I would like to see from mikrotik som...
by huntah
Thu Oct 29, 2015 6:36 pm
Forum: General
Topic: Stuck with RB750 Switching VLANs!
Replies: 11
Views: 3943

Re: Stuck with RB750 Switching VLANs!

this should work: /interface ethernet switch port set 0 vlan-mode=fallback set 1 default-vlan-id=200 vlan-header=add-if-missing vlan-mode=secure set 2 default-vlan-id=200 vlan-header=add-if-missing vlan-mode=secure set 3 default-vlan-id=200 vlan-header=always-strip vlan-mode=secure set 4 default-vla...
by huntah
Thu Oct 29, 2015 6:00 pm
Forum: General
Topic: CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)
Replies: 7
Views: 3007

CRS DHCP Snooping (Port Level Isolation) not working (SOLVED)

Hi, I have used the Wiki Example to implement DHCP Snooping (Rouge Server detection). But it isnt working.. I am missing something.. Here is my setup: Clients on ports 1-22 DHCP Server (port 14) Master-port = ether1-master slave ports = port 2-22 master (ether1-master) /interface ethernet switch por...
by huntah
Fri Jul 03, 2015 4:06 pm
Forum: General
Topic: Revoked certificates contunue to work
Replies: 11
Views: 8518

Re: Revoked certificates contunue to work

Can I join and ask what is this host in Wiki (http://wiki.mikrotik.com/wiki/Manual:Create_Certificates): /certificate sign ca-template ca-crl-host=10.5.101.16 name=myCa Is this Router IP (public or internal).. which ports on ip firewall filter must be opened to work? I cannot find anywhere more docu...
by huntah
Fri May 15, 2015 1:20 pm
Forum: General
Topic: L2TP/IPSEC black list bad IPs
Replies: 3
Views: 2257

Re: L2TP/IPSEC black list bad IPs

I am afraid that this kind of filtering would brake legitimate L2TP connections..
But it is worth a try. I will test it in test enviroment in post back the results..

Thanx for the idea!
by huntah
Fri May 15, 2015 1:13 am
Forum: General
Topic: L2TP/IPSEC black list bad IPs
Replies: 3
Views: 2257

L2TP/IPSEC black list bad IPs

Hi, I have successfuly deployed L2TP/IPSEC VPN server. But I have noticed (on multiple routers with l2TP) that some people are trying to hack into VPN. log: ipsec,error failed to pre-process ph1 packet (side: 1, status 1). ipsec,error phase1 negotiation failed. ipsec,error phase1 negotiation failed ...
by huntah
Mon Apr 20, 2015 9:39 pm
Forum: General
Topic: hAP Lite IPSEC Performace
Replies: 2
Views: 3397

Re: hAP Lite IPSEC Performace

Hi Normis,

can you check if your hAP are also using only 60-80% of CPU.. Is this normal?
Why wont they go up to 100% (max out the cpu).. As I recall RB433AH do that..
by huntah
Fri Apr 17, 2015 3:14 pm
Forum: General
Topic: hAP Lite IPSEC Performace
Replies: 2
Views: 3397

hAP Lite IPSEC Performace

Hi, I just got two new hAP Lite Routers. I was wondering how much IPSEC performace is hidden in those tiny boxes :) They can push 14,5-15Mbit/s which is not as bad as I dreaded... Interesting fact is that the CPU is not maxed out but is between 50-80%. Test was done with 2 PC with Win7 and File copy...
by huntah
Mon Feb 16, 2015 12:28 am
Forum: General
Topic: Winbox 3 RC
Replies: 636
Views: 208382

Re: Winbox 3 RC

Anyone else has all the same IPs in Neighbours?
MK-rc5-neighbors.png
by huntah
Thu Feb 12, 2015 11:18 pm
Forum: General
Topic: Setup L2TP\IPsec while IPsec tunnels running
Replies: 4
Views: 1274

Re: Setup L2TP\IPsec while IPsec tunnels running

post your config And I will see what I can do...
Also tell us your network settings (local net, remote GW, remote net etc..)
ip ipsec export
by huntah
Thu Feb 12, 2015 11:16 am
Forum: General
Topic: Setup L2TP\IPsec while IPsec tunnels running
Replies: 4
Views: 1274

Re: Setup L2TP\IPsec while IPsec tunnels running

Hi,

You have to make specific Policies for IPSEC tunels.
L2TP/IPSEC policy has 0.0.0.0/0 (Any).
The specific Policy for IPSEc tunel (example: src 192.168.11.0/24, dst 192.168.12.0/24) will take precedens before the generic 0.0.0.0...

so it should work withut any trouble..
by huntah
Sat Nov 29, 2014 11:43 am
Forum: The Dude
Topic: Define alternative Winbox port
Replies: 10
Views: 9827

Re: Define alternative Winbox port

This is done already..
It is from the dude monitoring software that you cannot set the alterantive port to connect to the device behind NAT (multiple MK behind same NAT)
by huntah
Fri Nov 28, 2014 10:31 am
Forum: General
Topic: Can not Restore a Backup file
Replies: 8
Views: 27806

Re: Can not Restore a Backup file

Try using you login password if you haven't specified anything
by huntah
Mon Nov 03, 2014 10:50 am
Forum: General
Topic: Now it won't route!
Replies: 16
Views: 4457

Re: Now it won't route!

please post you config
export compact
it is difficult to know where the problem lies without a config.
by huntah
Wed Oct 29, 2014 11:03 pm
Forum: Beginner Basics
Topic: CRS VLan for VoIP
Replies: 3
Views: 2274

Re: CRS VLan for VoIP

Thanx I noticed that the next day (fax wasnt working :)) but forgot to update the thread. I also got the official reply from Mikrotik that this is the correct configuration. It would be nice to update the Wiki Examples with something like this (native vlan (untagged, vid=0)) , tagged). It would have...
by huntah
Fri Oct 17, 2014 11:36 pm
Forum: General
Topic: IPSec Site-to-Site VPN Established - No NAT
Replies: 2
Views: 2328

Re: IPSec Site-to-Site VPN Established - No NAT

Have you tried pinging from clients?
On routers you need to specify the local lan interface to test the tunel. Tools - Ping - Interface..

From a quick glance of your setup the IPSECtunel should work..
by huntah
Thu Oct 16, 2014 10:51 pm
Forum: RouterBOARD hardware
Topic: Info trunk + native vlan
Replies: 1
Views: 1654

Re: Info trunk + native vlan

Hi I just had a similiar problem with CRS125. I wanted to set a trunk port on ether1-master (VLAN100 (VoIP), VLAN101 (Guests) + native VLAN (LocalNet)). On CRS I have three DHCP servers (each VLAN + native) Port ether24 is indepedenet (no master) and is used for wan (internet Access). All Wiki CRS E...
by huntah
Wed Oct 15, 2014 1:07 am
Forum: Beginner Basics
Topic: CRS VLan for VoIP
Replies: 3
Views: 2274

Re: CRS VLan for VoIP

I managed to configured it correctly. VLANs have worked as they should but there was no communication with ROS. I was missing switch1-cpu in the VLAN.. /interface ethernet switch vlan add ports=ether1-master-local,ether6-slave-local,ether14-slave-local,ether16-slave-local,switch1-cpu vlan-id=100 /in...
by huntah
Wed Oct 15, 2014 12:31 am
Forum: Beginner Basics
Topic: CRS VLan for VoIP
Replies: 3
Views: 2274

CRS VLan for VoIP

Hello, I have a problem configuring VLANs on CRS (heck Im not the only one :). Somehow the Procurve webinterface is way simpler..). My goal is to use CRS as Router and switch for local network and VoIP. So here is my goal: port 1-8 - local LAN untagged devices port 9-15 - VoIP VLAN 100 (tagged devic...
by huntah
Thu Jul 10, 2014 11:21 pm
Forum: RouterBOARD hardware
Topic: Finally RB953GS-5HnT is available!
Replies: 12
Views: 5731

Re: Finally RB953GS-5HnT is available!

Normis,

please test them all because it is a vital feature for some of us.
It is good to know what speeds can be achieved with different hardware
by huntah
Sun Jun 29, 2014 11:54 pm
Forum: RouterBOARD hardware
Topic: Finally RB953GS-5HnT is available!
Replies: 12
Views: 5731

Re: Finally RB953GS-5HnT is available!

IPSEC performance info would be very nice to know.
3DES-MD5, AES-128-MD5 and SHA1

older (and current on MIPS) models are struggling with SHA1...and IPSEC overall ..
by huntah
Mon Jun 16, 2014 11:57 pm
Forum: General
Topic: ARP and accessibility between subnets
Replies: 3
Views: 1137

Re: ARP and accessibility between subnets

because it is a router :) client in subnet A has a gw pointing to eth1 and router knows where to route the packets in subnet B because it has an address of subnet B on eth2..Also clients in Subnet B must have gw of router IP on eth2.. If you want to prevent trafic between subnets you must use firewa...
by huntah
Sun Apr 20, 2014 11:26 pm
Forum: General
Topic: Monitoring traffic through routers
Replies: 10
Views: 3290

Re: Monitoring traffic through routers

Try Using Torch in bridge to see packets on all routers (bridges)..
Also you could make Ip firewall filter to log all packets traveling through firewall (chai forward )..
by huntah
Wed Apr 16, 2014 7:15 pm
Forum: General
Topic: v6.12 released
Replies: 236
Views: 81771

Re: v6.12 released

DHCP on VLAN was also working on 6.11.. I am using it right now without problems. I reported that back in 6.11 released topic..
by huntah
Tue Apr 15, 2014 10:55 pm
Forum: General
Topic: v6.11 released
Replies: 260
Views: 112702

Re: v6.11 released

[Ticket#2014032566001217] BUG 6.12: Replicable kernel crash when try to discover why winbox not working well from 6.8 over IP obtained from pppoe-client Hi, when I try to replicate this problem: "Winbox connection freeze after some kb received over mppe encrypted connection" RouterOS vers...
by huntah
Thu Apr 03, 2014 4:42 pm
Forum: General
Topic: VPN with L2tp/IPsec Problem
Replies: 8
Views: 7300

Re: VPN with L2tp/IPsec Problem

If I understood you correctly a while ago 3 differrent users could connect to VPN server (L2TP) just not at the same time. And now it is not working at all.. I would try to reboot the VPN router and see if it helps. If you havent changed anything it should work. Once on ROS 6.11 my L2TP/IPSEC server...
by huntah
Tue Apr 01, 2014 10:00 am
Forum: General
Topic: vpn L2TP IPsec
Replies: 8
Views: 4797

Re: vpn L2TP IPsec

have you added routes froms ite b,c,d,e to site a like this:
/ip route add distance=1 dst-address=192.168.20.0/24 gateway=192.168.10.1
You need multiple routes (for each site-> Subnet) all pointing to site A (gateway).
by huntah
Sun Mar 30, 2014 8:51 pm
Forum: General
Topic: Internet not working after hotspot setup
Replies: 22
Views: 11302

Re: Internet not working after hotspot setup

Hi, first change distance in DHCP Client to 1 /ip dhcp-client add default-route-distance=1 disabled=no interface=ether1 Is your RADIUS Server working? Can you Access Userman? Is hotspot login page accesseble (try typing: 192.168.88.1 it should display login page) Try disabling RADIUS and use interna...
by huntah
Sun Mar 30, 2014 12:18 pm
Forum: General
Topic: VPN with L2tp/IPsec Problem
Replies: 8
Views: 7300

Re: VPN with L2tp/IPsec Problem

As rextended said before you can only connect ONE client behind same static IP. So if you have multiple users at a hotel which uses NAT (so all your users are behind NAT with same IP) only 1 will work. This is a limitation of L2TP/IPSEC implementation on Mikrotik. You can try OPVN or PPTP if you nee...
by huntah
Sat Mar 29, 2014 11:03 pm
Forum: General
Topic: L2TP/IPSEC - Ppp Profile Use encryption yes /no
Replies: 3
Views: 3312

Re: L2TP/IPSEC - Ppp Profile Use encryption yes /no

I use ROS 6.11 and I am happy to report is working for me without problems (DHCP on VLAN, L2TP Server and OVPN Client for VoIP). So if I understood you correctly there is no need for use Encryption in ppp profile because the L2TP/IPSEC is already secure from start.. If the Encryption set to yes basi...
by huntah
Sat Mar 29, 2014 12:49 am
Forum: General
Topic: vpn L2TP IPsec
Replies: 8
Views: 4797

Re: vpn L2TP IPsec

You need to enable UDP Ports 500, UDP Port 1701, and UDP Port 4500 (For NAT Traversal)
/ip firewall filter add chain=input comment="L2TP ports" action=accept protocol=udp dst-port=500,1701,4500
by huntah
Sat Mar 29, 2014 12:30 am
Forum: General
Topic: L2TP/IPSEC - Ppp Profile Use encryption yes /no
Replies: 3
Views: 3312

L2TP/IPSEC - Ppp Profile Use encryption yes /no

I have I question about L2TP/IPSEC configuration. If I set ppp Profile Use Encryption to Yes or required I cannot connect with Android Phone but I have no Problem connecting with Win7 client. It says It is using encoding "MPPE128STATELESS" in Active Connections. If I set Use Encryption to ...
by huntah
Sat Mar 22, 2014 12:16 am
Forum: General
Topic: v6.11 released
Replies: 260
Views: 112702

Re: v6.11 released

DHCP on VLAN seems to be working at least for me on RB751-2HND
by huntah
Thu Mar 20, 2014 12:41 am
Forum: General
Topic: VPN for Voice
Replies: 3
Views: 1479

Re: VPN for Voice

I think you masquerade trafiic from phones over PPTP..

add a Firewall NAT rule before masquerade like this:
/ip firewall nat
add chain=srcnat comment="Route Local to Remote VPN" dst-address=\
    192.168.12.0/24 src-address=192.168.10.0/24
Hope this helps.. if not post config export..
by huntah
Sun Mar 16, 2014 9:11 pm
Forum: General
Topic: L2TP/IPSec for Road Warrior
Replies: 93
Views: 50074

Re: L2TP/IPSec for Road Warrior

One more thing I just remembered Mikrotik have enabled IPSEC XAUTH support.. This is on my try list :) See here: http://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_with_Mode_Conf Also no mention of Droid or IOS support.. For Windows you have Shrew VPN Client.. ON PPTP VPN Passthrough I...
by huntah
Sun Mar 16, 2014 8:00 pm
Forum: General
Topic: L2TP/IPSec for Road Warrior
Replies: 93
Views: 50074

Re: L2TP/IPSec for Road Warrior

PPTP works with multiple clients behind same NAT.. If you have multiple static IPs on gateway (L2tp Server) you can make clients connect each to specific static IP.. Yes I know its a stupid work around but it works :) Or you can use OpenVPN via TCP.. it also works for multiple Natted clients.. Since...
by huntah
Sun Mar 16, 2014 1:05 pm
Forum: General
Topic: L2TP/IPSec for Road Warrior
Replies: 93
Views: 50074

Re: L2TP/IPSec for Road Warrior

As far as I know there can be only one L2TP/IPSEC tunnel behind the same NATed internet connection. For example when two of out employies stay at the same hotel with public Wifi only one can work. This is the limitation of Mikrotik implementation of L2TP/IPSEC VPN. Cisco VPN client to Cisco ASA has ...
by huntah
Fri Oct 04, 2013 4:24 pm
Forum: Wireless Networking
Topic: Multiple APs in bridge - connectivity problems
Replies: 2
Views: 2488

Re: Multiple APs in bridge - connectivity problems

I read somewhere that because of roaming clients you need some kind of STP protocol..

SXT are not in WDS mode but in station bridge mode and they connect to the second router on top of the hill. WLAN in in classic AP-bridge mode..
SXT have their interfaces (WLAN1 in Ether1) in bridge called hotspot.
by huntah
Sat Sep 28, 2013 6:41 pm
Forum: Wireless Networking
Topic: Multiple APs in bridge - connectivity problems
Replies: 2
Views: 2488

Multiple APs in bridge - connectivity problems

Hello, I have set up a Wireless network with multiple APs and in full bridge mode. See the attached picture. My scenario is as follows: 1. ADSL on WAN side of Router 1, which has configured DHCP Server for the whole network and hotspot server. The router has two WLAN cards. wlan1 is used for 5GHz Up...
by huntah
Wed Jun 05, 2013 6:16 pm
Forum: Beginner Basics
Topic: 2 VAPs with different subnets and no visibility between them
Replies: 4
Views: 2083

Re: 2 VAPs with different subnets and no visibility between

Hi, firstly you must understand that each VAP (Virtual AP) is a separate interface. So if you use bridge and assign both VAP to same bridge the you cannot have separate DHCP servers... I would do this in the following way: 1. Create a bridge - Bridge-Local 2. Add ports to Bridge Local (LAN interface...
by huntah
Sat May 18, 2013 9:26 pm
Forum: General
Topic: L2TP (add route on Windows L2TP-client)
Replies: 1
Views: 3185

Re: L2TP (add route on Windows L2TP-client)

You can add routes in PPP->Secret and the desired username..
by huntah
Sun Apr 07, 2013 8:34 pm
Forum: General
Topic: [ASK] multipe ip public on 1 mikrotik
Replies: 1
Views: 860

Re: [ASK] multipe ip public on 1 mikrotik

Hi, This is quite simple and if you searched the wiki U could find answers in few minutes.. 1. Add all adresses to your wan interface ( ip addresss add) 2. User port forwarding (ip firewall nat) to forward specific ports to internal server.. use dst-address to specify external IP for specific servic...
by huntah
Fri Mar 01, 2013 10:50 am
Forum: General
Topic: Userman - User limit 4h per day
Replies: 2
Views: 1200

Re: Userman - User limit 4h per day

The trial user does not go through Radius server.. If I have multiple AP through out the city I would like to have centralized management and quasi roaming and restrictions throughout entire network.. Is it possible to generate users on the fly (when they click a button) with lets say MAC address? T...
by huntah
Thu Feb 28, 2013 8:31 pm
Forum: General
Topic: Userman - User limit 4h per day
Replies: 2
Views: 1200

Userman - User limit 4h per day

Hello,

How can I make one universal user for example "free" that is used by unlimited users from diferent hotspots using central Radius Server.
The Rate Limit is great and is functioning great but I also need time (like Hotspot Trial User feature which in this scenario I dont wanna use)
by huntah
Wed Feb 27, 2013 12:21 am
Forum: General
Topic: central Hotspot server for multiple remote APs
Replies: 1
Views: 1432

central Hotspot server for multiple remote APs

Hello, I would like to centralize multiple Mirkotik APs. Each AP has a local hotspot server and internet connection. My goal is to make "roaming" network. Simpler put clients dont need to reauthenticate when they move through town and different APs. WLAN SSID will be same but on different ...
by huntah
Tue Jan 22, 2013 9:04 pm
Forum: General
Topic: SLOW speed over VLAN (CPU 100%)
Replies: 1
Views: 1922

SLOW speed over VLAN (CPU 100%)

Hello, I just noticed strange low speed over VLAN interface... If I copy files (windows SMB) from PC2 (VLAN100) to PC1 (VLAN1) speed is around 26MB/s (CPU 100%) If I copy the same files via Ether4 (VLAN1, or simply no VLAN) the speed is 90MB/s (CPU 93%) This was tested with RB2011-2Hnd ( ROS 5.22) a...
by huntah
Sun Nov 11, 2012 10:41 am
Forum: General
Topic: Central Authentication with mikrotik
Replies: 2
Views: 1396

Re: Central Authentication with mikrotik

Use the mikrotik with Userman and hotspot confugred as central GW for all other Access point.
On other MKs just setup APs (no hotspot!) and route traffic through your main MK which will act as a hotspot.
by huntah
Sun Nov 11, 2012 10:17 am
Forum: General
Topic: Unanswered - Manually specify gateway for a pptp-client
Replies: 5
Views: 1841

Re: Unanswered - Manually specify gateway for a pptp-client

Have you tried to specify the gateway as interface?
It works for me on similar setup (2x DSL in bridge mode.. same ISP provider ie. mostly same gateway to the ISP)
by huntah
Sat Jul 28, 2012 5:40 pm
Forum: General
Topic: Load Balancing multiple connections
Replies: 2
Views: 1344

Re: Load Balancing multiple connections

use Netwatch and ping gateway... if gateway is down then disable interface or route to the failed ISP...

Or use check-gatway in ip/route ..
by huntah
Sat Jul 28, 2012 5:34 pm
Forum: General
Topic: RB1100AHx2 High CPU Usage
Replies: 2
Views: 1707

Re: RB1100AHx2 High CPU Usage

As you can see from Profile it has to do with queues..
Are you doing QoS..
Send as your Queue configuration to see if we can make sense of it..
by huntah
Tue Jul 10, 2012 1:33 pm
Forum: General
Topic: RB750UP only 10Mbit
Replies: 2
Views: 1049

RB750UP only 10Mbit

Hello, I installed a new RB750UP last week and today I have checked the speed on POE ports it negotiates to only 10mbit ?! Before on supplied POE adapters (1x SXT and RB433) it was working 100mbits? If I uncheck auto negotiate and set it to 100Mbits it does not work! Help 10mbit is too slow because ...
by huntah
Tue Jul 10, 2012 1:28 pm
Forum: General
Topic: Limit users via MAC
Replies: 3
Views: 1190

Re: Limit users via MAC

Thanx I will check it!
by huntah
Mon Jul 09, 2012 10:15 pm
Forum: General
Topic: Limit users via MAC
Replies: 3
Views: 1190

Limit users via MAC

Hi, can someone point me in the right direction regarding user/traffic filtering via MAC. I am trying to achive that only a device which is assigned an IP via DHCP can transfer data over internet (throuh Router).. For example: 1x User connects his router or HomePC and ROS assignes an IP with MAC. 1x...
by huntah
Sat Jun 16, 2012 12:03 am
Forum: General
Topic: SXT CPE end user access rights
Replies: 1
Views: 913

Re: SXT CPE end user access rights

I think WEbfig is the way to go.. But i think it is a little buggy. For example When I deselect in menu Interfaces certain "add new interface" types (allow ony PPPoE and VLAN) the skin always shows all types interfaces. I attached the skin.. Which is like half done for what I need.. So If ...
by huntah
Fri Jun 15, 2012 11:16 pm
Forum: General
Topic: SXT CPE end user access rights
Replies: 1
Views: 913

SXT CPE end user access rights

Hi, I was wondering if you can limit certain settings in ROS so the end users (costumers) cannot change them. Essentialy we have one AP which have PPPoE server and several SXT on the end user side. Now we have two options: 1. Leave SXT in Bridge mode and lock it down so the end user dont have access...
by huntah
Sun Jun 03, 2012 12:50 am
Forum: General
Topic: SMB speed and CPU usage
Replies: 0
Views: 1160

SMB speed and CPU usage

Hello, I would like to know If anyone else has done some speed testing with SMB feature? I must sadly say it is pretty much useless at this time for and SOHO NAS/router combination. I have tested with one old USB 1GB stick (transcend) and the speed was horrible (500 KB/s, CPU 100%). Then I thought i...
by huntah
Sat Feb 04, 2012 10:40 am
Forum: General
Topic: Multiple PPPOE clients
Replies: 4
Views: 5457

Re: Multiple PPPOE clients

This topic is coverd very good in foroum.
Just use a search engine...or wiki

You are looking for: PCC (http://wiki.mikrotik.com/wiki/Manual:PCC)
search for: 2wan, multiple wan, multiple ISP
You'll find it with no problem..
by huntah
Fri Feb 03, 2012 8:55 pm
Forum: General
Topic: Cisco lan-to-lan IPSEC tunnel
Replies: 29
Views: 17704

Re: Cisco lan-to-lan IPSEC tunnel

HI, Since I had similar problem I've made a script for workaround.. It is working ok.. Sometimes it doesnt help and in those cases (maybe once per month or two) I have to change excription from MD5 to sha1 on proposal. Then flush all and voila its working :) So if anybody else needs a script here it...
by huntah
Wed Feb 01, 2012 11:06 pm
Forum: General
Topic: Bypassed
Replies: 36
Views: 6777

Re: Bypassed

I dont understand what you are saying.. It seems you still don't get the conpet of SRC and DST address. Also it seems you don't know what is INSIDE your network and what outside... 1. For the THIRD time From inside of the network use 192.168.88.102:8282. Or setup Hairpin NAT.. http://wiki.mikrotik.c...
by huntah
Wed Feb 01, 2012 5:29 pm
Forum: General
Topic: Bypassed
Replies: 36
Views: 6777

Re: Bypassed

Where did you assign that IP (31.209.110.x)? If on the same device as PPPoE Server, then you have to make a port forward on that device/router.. /ip firewall nat add chain=dstnat action=dst-nat to-addresses=192.168.88.102 to-ports=8282 protocol=tcp dst-address=31.209.110.x dst-port=8282 Where X is y...
by huntah
Tue Jan 31, 2012 8:02 pm
Forum: General
Topic: Bypassed
Replies: 36
Views: 6777

Re: Bypassed

It is really hard to understand you, because you dont use punctiations (., .. sentences). I think you lack (are missing) fundamental knowledge of networking here: 1. SRC address is the address that you are trying to connect from. 2. From internal network (anywhere in 192.168.88.x) there is no MASQUE...
by huntah
Mon Jan 30, 2012 9:51 pm
Forum: General
Topic: Bypassed
Replies: 36
Views: 6777

Re: Bypassed

YOu have set up Nanobridge that it forward packet comming from 192.168.88.102 :)

Delete the sourceIP/mask field and it should work.
Leave it empty or put in the actual IP you are trying to login...
You can check your src address on the web page www.whatismyip.com
by huntah
Mon Jan 30, 2012 9:22 pm
Forum: General
Topic: VLAN, Inter-VLAN Routing and SRC-NAT
Replies: 3
Views: 2773

Re: VLAN, Inter-VLAN Routing and SRC-NAT

do you use NAT for VLAN subnets? If you masquerade your VLANs then I think this can be your problem.. Disable masquerade rule and try... Or try somthing like that (place it as the first rule): /ip firewall add action=accept chain=forward comment="Accept Everything from VLAN10 - VLAN11" dis...
by huntah
Mon Jan 30, 2012 5:55 pm
Forum: General
Topic: Bypassed
Replies: 36
Views: 6777

Re: Bypassed

Hi, PPPoE Server is better less confusing and simpler for administration. I attached the picture of one of my NanostationM2, which is basicly the same as NanoBridge: 1. Go to Webconfig 2. Under Network youll find Port Forwarding. 3. Enable Port forwarding and clik Configure. Attached is and example ...
by huntah
Sun Jan 29, 2012 9:55 pm
Forum: Beginner Basics
Topic: 3 or more VLANs that connect to 2 servers using L2 switch
Replies: 4
Views: 1641

Re: 3 or more VLANs that connect to 2 servers using L2 switc

Hi did you solve your problem? I had also trouble comunication with Trunk port on Linksys POE SRW208 switch. But if I changed trunk port so it accepts multiple vlans (General Mode with Tagging enabled for VLANs 10,20,30,40.. all of your vlans defined on RB1100) then it would work. Then all you need ...
by huntah
Sun Jan 29, 2012 3:27 pm
Forum: General
Topic: Bypassed
Replies: 36
Views: 6777

Re: Bypassed

From what I can understand (and it is quite difficult from your posts :)) you are trying to access SecurityCAM behind a Router (NanoBridge M5). And in earlier posts you mentioned that you use NanoBridge in Router MODE .. So NAT is enabled on NanoBridge I presume. From Public IP you can get to NanoBr...
by huntah
Fri Jan 27, 2012 11:17 pm
Forum: General
Topic: Redundant link between Mikrotik bridge devices - RSTP?
Replies: 10
Views: 14777

Re: Redundant link between Mikrotik bridge devices - RSTP?

Hi, In Winbox you should go to Bridge 1. Double click on your bridge interface (bridge1 if Im not mistaken) 2. Click the STP tab 3. You'll find Prioty and change it as stated above Root Bridge should have lowest priority.. Or change from terminal: /interface bridge add admin-mac=00:00:00:00:00:00 ag...
by huntah
Thu Jan 12, 2012 1:41 pm
Forum: General
Topic: vlan via transparent bridge (wi-fi)
Replies: 2
Views: 1901

Re: vlan via transparent bridge (wi-fi)

it will be passed to AP2..
I think you do not need Use service tags..

Set IP address on VLan Interface which must be in different subnet as main Bridge (AP).
Then use IP / Firewall to filter Winbox access only to VLAN2
by huntah
Sun Jan 08, 2012 10:56 am
Forum: General
Topic: [SOLVED] VLAN setup
Replies: 2
Views: 1278

Re: VLAN setup

OK I have solved this problem it was quite a stupid one..

1. As stated by dleo (thx for that) the trunk port must be tagged
2. Use service tag must be set to No (Default)..if set to yes it is not working

Thanx for pointers and help
by huntah
Sun Jan 08, 2012 10:39 am
Forum: General
Topic: HELP!! Need seamless IP environment > 2 APs MESH > 4-VoIP
Replies: 5
Views: 3010

Re: HELP!! Need seamless IP environment > 2 APs MESH > 4-VoI

sorry for the late answer I missed your post.. Here is what I would do: 1. Main AP has connection to ISP (wan) and localnet (Multiple APs). 2. If you have backhaul connection between APs (ether, wlan) you must put all interfaces in Bridge (Backhaul, Wlan for AP-customers) on connecting APs. 3. Put I...
by huntah
Sun Jan 08, 2012 10:26 am
Forum: The Dude
Topic: Define alternative Winbox port
Replies: 10
Views: 9827

Re: Define alternative Winbox port

not yet as far as I know.. But this would realy be a great feature since many one us have similar setups and managing them is not as easy (manual Winbox plus port).

Luckily we can add multiple SNMP agents (different ports) so we can se if it is online, traffic and all other SNMP settings
by huntah
Sat Dec 17, 2011 12:33 am
Forum: General
Topic: IPSEC and local gw ping
Replies: 0
Views: 701

IPSEC and local gw ping

Hello, I have a slight problem with IPSEc behavaior. My local network is 192.168.1.x/24 and remote peers are 192.168.0.x/24, 192.168.2.x/24 and 192.168.3.x/24. Main router is cisco ASA with local network 192.168.0.0/24 Branch offices ( 1.x/24, 2.x/24, 3.x/24) have RB433AH (ROS4.17) which has IPSEC c...
by huntah
Fri Dec 16, 2011 11:21 pm
Forum: General
Topic: Forward Public IP with PCC
Replies: 6
Views: 2279

Re: Forward Public IP with PCC

Maybe I missunderstood but I thought clients behind hotspots (on picture) are NAT-ed.. if they are not I would make an PPPoE server on the main router. The client then has an username/Password (PPP-Secrets on main router, there you also specify remote adress = customer PublicIP) and gets the PublicI...
by huntah
Fri Dec 16, 2011 11:04 pm
Forum: General
Topic: Forward Public IP with PCC
Replies: 6
Views: 2279

Re: Forward Public IP with PCC

If you got a block of IPs you could also make a PPPoE server and Public IPs assigned for specific users...

Or change your network to fully routed network ...
by huntah
Fri Dec 16, 2011 9:50 pm
Forum: General
Topic: [SOLVED] VLAN setup
Replies: 2
Views: 1278

[SOLVED] VLAN setup

Hello, I have a problem with VLAN setup. The Attached picture is what I want to do. So let me explain: 1. linksys Managed switch is configured as followed: a) ports 4-8 VLAN100 (untagged, separate network 10.240.240.224/27) b) port 2-3 untagged VLAN1 (default VLAN..meaning no VLAN) c) port 1 Trunk (...
by huntah
Thu Dec 15, 2011 12:58 pm
Forum: General
Topic: L2TP Server with Windows7 Client
Replies: 1
Views: 1118

L2TP Server with Windows7 Client

Hello, I have been browsing the forum and reading the Wiki but I cannot get L2TP server on MK (RB433) work with Windows7 SP1 64 bit built in VPN client. The client is behind a Router (Nat). I tried NAT Traversal, manual generated IPSEC Policy and nothing. I use ROS 5.8. The connetion is not establas...
by huntah
Mon Dec 05, 2011 6:16 pm
Forum: General
Topic: 2 SXT (bridge) but performance problems
Replies: 7
Views: 2105

Re: 2 SXT (bridge) but performance problems

Hi,

check Wireless Interface under HT Tab if you have cheked chain0 and chain1
One SXT is in Station Mode the other is in Bridge
I use NV2 wireless protocol. Standarad is set to 5GHZ-OnlyN

ROS v5.8 and legacy rate control...
by huntah
Mon Dec 05, 2011 10:33 am
Forum: General
Topic: HELP!! Need seamless IP environment > 2 APs MESH > 4-VoIP
Replies: 5
Views: 3010

Re: HELP!! Need seamless IP environment > 2 APs MESH > 4-VoI

Hi, When you change IP you loose connection (aka new device for your VoIP server nad VoIP Client). You have to maintain the same client IP over your entire MESH network. You could try setting up a simpler soulution using WDS (downside is badwidth which is cut in half with each AP, but if you have a ...
by huntah
Fri Dec 02, 2011 12:08 am
Forum: General
Topic: 2 SXT (bridge) but performance problems
Replies: 7
Views: 2105

Re: 2 SXT (bridge) but performance problems

Did you enable both chains in Wireless? Do you have any obstacles between SXTs? I have several similar setups and get around 10MB/s real life performance (copying a file :)) And as you can see this almost the limit of 100 Mbit/s ethernet port. My Wireless connection is 130Mbit/130Mbit and CCQ 100/10...
by huntah
Thu Nov 24, 2011 12:55 am
Forum: General
Topic: CPU usage with ipsec
Replies: 2
Views: 5147

Re: CPU usage with ipsec

Change from SHA1 to MD5 you will get much better performance..
I thnik that SHA1 implementation is bad or way more complex than MD5.

When I changed my IPSEC tunnels to MD5 I got much better performance (from 2Mbit to 10mbit!).
I am using 433AH which runs at 680 MHz..
by huntah
Wed Sep 21, 2011 7:31 pm
Forum: General
Topic: PPTP and Multi WAN
Replies: 13
Views: 6024

Re: PPTP and Multi WAN

Hi, I think it does not matter what type of Connection to ISP you have... Follow this instractions: http://wiki.mikrotik.com/wiki/Manual:PCC Just modify them acording to your PPTP Client interfaces.. Remeber to Mark packets.. I have done such setups on DSL and fiber connections and it works like a c...
by huntah
Fri Aug 05, 2011 12:42 am
Forum: Wireless Networking
Topic: 1km link no Line Of Sight
Replies: 17
Views: 5830

Re: 1km link no Line Of Sight

Ok the attached picture is from Ligo Calc.. I am not excalty sure what RX-Tresholds means.. I put -80 dBm is this OK? Noise floor is over -100 dBm (i think 105).. On the bottom (coast) there is also another Wlan card witch 18dBi Gain Omni antenna Should I use NV2 protocol? Would the results be bette...
by huntah
Wed Aug 03, 2011 12:04 am
Forum: Wireless Networking
Topic: 1km link no Line Of Sight
Replies: 17
Views: 5830

Re: 1km link no Line Of Sight

thanx for your replies, even though it is not what I wanted to hear :) 2x2 mimo --> You mean 2x 19dBi Antena on each side (HT TX in HT RX Chains 0 and 1?) - one for TX and one for RX.. Or do I need special MIMO Antenas? Which yould you suggest. As answered above better results will be with lower fre...
by huntah
Mon Aug 01, 2011 9:00 pm
Forum: Wireless Networking
Topic: 1km link no Line Of Sight
Replies: 17
Views: 5830

1km link no Line Of Sight

Hello, I am atempting to link two sites via Wireless (2x RB433 with R52Hn and 19dBi Cyberbajt Giga Eter antenas). The problem is I do not have clear line of sight (LoS) because of the steep descend in front of me (coastal area). The link is working so/so. I only get -80 to -85 dBm and hence the link...
by huntah
Sat Jul 23, 2011 10:19 pm
Forum: General
Topic: IPSec Tunnel not starting
Replies: 2
Views: 2407

Re: IPSec Tunnel not starting

how did you test the tunel from router (new terminal) or device. try using tool/Ping and set interface to your LAN and then ping the LAN IP of other router.. Or use a client on each side and ping.. log should say somtehing like Phase1 blablabla if you are trying to route traffic over ipsec tunnel Tr...
by huntah
Sat Jul 23, 2011 10:04 pm
Forum: General
Topic: HOTSPOT STOPPED WORKING AFTER CHANGING CARD FROM R52 TO R52H
Replies: 3
Views: 1763

Re: HOTSPOT STOPPED WORKING AFTER CHANGING CARD FROM R52 TO

Check two things:
1. Interface .. Did you configure your new card (AP Bridge, SSID, securtiy...)
2. Bridge Port (add the new card to hotspot bridge)

Most likely is the second thing ..
by huntah
Sat Jul 23, 2011 9:43 pm
Forum: General
Topic: IPSEC performance MD5 vs SHA
Replies: 6
Views: 6641

Re: IPSEC performance MD5 vs SHA

Thanx for clarification..
It would be nice if someone from Mikrotik would respond to this and not just users..

I was reading IPSEC mikrotik wiki and found that only AES is hardware accelerated.
I would like to know the difference between MD5 ans SHA on RB1200..

Need real world numbers..
Anyone..
by huntah
Wed Jul 20, 2011 11:17 pm
Forum: General
Topic: IPSEC performance MD5 vs SHA
Replies: 6
Views: 6641

IPSEC performance MD5 vs SHA

hello, I've done some testing with RB433 and IPSEC performance. I have noticed something strange or maybe normal.. not sure. If I use MD5 in Proposal Auth. Algorithem then I get: 1. AES-128 -> 15 Mbit/s 2. 3DES -> 5,5 Mbit/s But If I use SHA1 in Proposal Auth. Algorithem then I get: 1. AES-128 -> 2 ...
by huntah
Thu Jun 09, 2011 5:15 pm
Forum: The Dude
Topic: Feature request - Winbox Port
Replies: 0
Views: 1082

Feature request - Winbox Port

Hello,

I often have two or more RB behind firewall. I would very much appriciate if I could connect to those RBs via Dude (set Winbox port).
I cna make SNMP agents on different ports but not Winbox..

Any chance of doing this?

Sincerly,
Huntah
by huntah
Fri Apr 22, 2011 11:49 pm
Forum: General
Topic: Do I have this Queue set up correctly
Replies: 4
Views: 1449

Re: Do I have this Queue set up correctly

Or if you can you can make a PPPoE Server and define in ppp-profile Rate-limit (example 2M/1M).

This is much simpler since i beleive you have more than enough bandwidth (62*2M...)

Clients than use and authenticate over PPPoE Clients
by huntah
Tue Feb 15, 2011 11:57 am
Forum: General
Topic: VOIP prioritization
Replies: 2
Views: 950

Re: VOIP prioritization

Use Queues..

Nice Wiki manual on this subject can be found here: http://wiki.mikrotik.com/wiki/Voip

I use it and it works perfectly...