Community discussions

Search found 158 matches

by dasiu
Thu Oct 19, 2017 12:31 pm
Forum: Announcements
Topic: RouterOS (v6.39.3, v6.40.4, v6.41rc) NOT affected by WPA2 vulnerabilities
Replies: 58
Views: 83324

Re: RouterOS (v6.39.3, v6.40.4, v6.41rc) NOT affected by WPA2 vulnerabilities

MikroTik Team, short question: If I have a wireless link on 802.11 protocol using Management Protection - can it be vulnerable to the attacks (before the upgrade)? Or does Management Protection already solve the problem (by not allowing the client, if Management Protection is "required", to connect ...
by dasiu
Fri Mar 28, 2014 12:20 pm
Forum: General
Topic: warning DHCP offering lease without success
Replies: 1
Views: 4269

Re: warning DHCP offering lease without success

Maybe the second one is connected via a wireless "station-pseudobridge" link, which means the NAT for MAC addresses?
by dasiu
Sat Mar 22, 2014 11:10 am
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 27
Views: 3591

Re: vLAN with Switch chips _ scenario-based solutions

Dasiu, now between "I understood" and "I'm able to apply it", there's a world :-) In your presentation you mention only one master port for a chip. How if I want to have two but only one with switch chip used for vlans? I currently have a RB450G (planning to switch for a 2011UiAS), can you tell me ...
by dasiu
Fri Mar 21, 2014 1:09 pm
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 27
Views: 3591

Re: vLAN with Switch chips _ scenario-based solutions

You can check my MUM presentation about the switch chip: http://mum.mikrotik.com/presentations/IT14/starnowski.pdf I read, re-read and re-re-read until I (think I) understood everything. Based on your presentation, I now assume that VLAN interface(s) aren't required at all to manage VLANs if switch...
by dasiu
Wed Mar 05, 2014 3:25 pm
Forum: General
Topic: MikroTik Training events and institutions around the world
Replies: 2
Views: 466

Re: MikroTik Training events and institutions around the wor

The trainings are organised by MikroTik certified Trainers. Each trainer can schedule a training in the system using his account - and it is automatically shown on the public schedule. So what you see - is the list of trainings that are scheduled by trainers - exactly they were "clicked in the syste...
by dasiu
Mon Mar 03, 2014 5:26 pm
Forum: General
Topic: how to set maximum clients per wifi interface
Replies: 1
Views: 369

Re: how to set maximum clients per wifi interface

/interface wireless set wlan1 max-station-count=10
by dasiu
Sat Mar 01, 2014 1:59 pm
Forum: General
Topic: Default setting of some routerboard series ackward
Replies: 8
Views: 1140

Re: Default setting of some routerboard series ackward

Usually the antenna is the gateway and that has to be connected in this default setup to ether1. But we actually want to use a PoE-out port. So we have to connect the antenna to ether5. But this is just a slave port in the LAN network. If not aware, problems all over.... I have access to about 5 di...
by dasiu
Fri Feb 28, 2014 11:45 am
Forum: General
Topic: vLAN with Switch chips _ scenario-based solutions
Replies: 27
Views: 3591

Re: vLAN with Switch chips _ scenario-based solutions

What do you mean by port1 = cpu port ?? If ether2 is the master port, then the cpu port of the switch chip is ether2 of router's CPU. I think that you're a bit confused with the terminology :). You can check my MUM presentation about the switch chip: http://mum.mikrotik.com/presentations/IT14/starno...
by dasiu
Sun Feb 23, 2014 2:26 pm
Forum: General
Topic: Mikrotik BGP Protocol configuration
Replies: 2
Views: 533

Re: Mikrotik BGP Protocol configuration

HI, I have an issue with mikrotik Rb-750 gigabyte, 5.11 v router board BGP configuration. My router using my both ISP connection for download and upload bandwidth while i monitor in interface but i want to use my 1st connection as primary cnnection and secondary mean 2nd isp connection as backup co...
by dasiu
Tue Feb 18, 2014 12:49 pm
Forum: General
Topic: AR8327
Replies: 8
Views: 5200

Re: AR8327

Any progress?
I will have a presentation on the next MUM (in 2 days), showing how easy it is :).
by dasiu
Sun Feb 16, 2014 1:26 am
Forum: RouterBOARD hardware
Topic: Making LCD useful.
Replies: 19
Views: 4303

Re: Making LCD useful.

A custom text field, that could be generated by a script - would be perfect :).
by dasiu
Tue Feb 04, 2014 9:31 am
Forum: General
Topic: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfomance
Replies: 10
Views: 3474

Re: CCR1036 PPPoE 1000+ clients 400+ Mbit/s degraded perfoma

CPU load does not exceed 20-30% but the CCR cannot go beyond 400-500 mbit/s. How did you check the CPU load? Is it the average load (from /system resource), or max load per core (from /system resource cpu)? When the avg load is 30% - all cores can have 30%, but it's also possible that 20 cores have...
by dasiu
Mon Feb 03, 2014 12:30 pm
Forum: General
Topic: is there anyway to know password mistake?
Replies: 20
Views: 2617

Re: is there anyway to know password mistake?

You can: 1. Do a port redirection - dst-nat for ssh port to a server on a separate linux machine you have in your network for sniffing passwords (ex. a Raspberry Pi machine) for connections coming from an address list (and you just add the "suspicious" IP to the list - to be redirected to the fake s...
by dasiu
Tue Jan 28, 2014 8:54 pm
Forum: General
Topic: Quick hotspot question
Replies: 3
Views: 298

Re: Quick hotspot question

No... Slave interfaces shouldn't have IP addresses, any DHCP/hotspot servers, etc. You should set them on the bridge interface (master).
by dasiu
Mon Jan 27, 2014 9:47 am
Forum: General
Topic: exclude IP from webproxy rule
Replies: 2
Views: 1471

Re: exclude IP from webproxy rule

The "dstnat" chain is TOTALLY SEPARATE from "srcnat". It means, that it doesn't matter, if you place it before or after the srcnat rules. When the packet enters the router, all dstnat rules (in proper order) are applied, and later - before it leaves - the srcnat rules. If you don't want the packets ...
by dasiu
Sun Jan 26, 2014 12:04 pm
Forum: General
Topic: Trunk port on a CCR1036 router
Replies: 11
Views: 4727

Re: Trunk port on a CCR1036 router

So if I got you correct, the configuration should look like this: /interface bridge add name=br-vlan10 /interface bridge add name=br-vlan20 /interface bridge add name=br-vlan30 /interface vlan add interface=ether4 name=vlan10 vlan-id=10 add interface=ether4 name=vlan20 vlan-id=20 add interface=ethe...
by dasiu
Sun Jan 26, 2014 3:52 am
Forum: General
Topic: IPsec with no encryption ... why is the firewall involved?
Replies: 2
Views: 549

Re: IPsec with no encryption ... why is the firewall involve

1. Your /ip firewall nat - is empty right now?
2. Do you use l2tp? It creates dynamic change-mss rules in /ip firewall mangle.
3. What if you disable connection tracking?
4. Check "print dynamic" in /ip firewall filter, nat and mangle - everything empty?
by dasiu
Wed Jan 22, 2014 5:56 pm
Forum: General
Topic: SNMP oids
Replies: 2
Views: 853

Re: SNMP oids

Am i doing something wrong? I am able to fetch other (uptime, memory, cpu) resources, just not the wireless ones. Yes... RTFM - as some people say ;). The snmpwalk command performs a sequence of chained GETNEXT requests automatically. It is a work saving command. Rather than having to issue a serie...
by dasiu
Mon Jan 20, 2014 2:01 am
Forum: General
Topic: Monitor Traffic/Resolve IP Address to Hostnames
Replies: 2
Views: 1350

Re: Monitor Traffic/Resolve IP Address to Hostnames

1. Enable webproxy (/ip proxy set enabled=yes) 2. Let all HTTP traffic go through the webproxy (/ip firewall nat add chain=dstnat action=redirect dst-port=80 protocol=tcp to-port=8080) 3. Just log the "webproxy,!debug" - /system logging add topics=web-proxy,!debug action=... (disk, probably) - that'...
by dasiu
Sun Jan 19, 2014 1:08 am
Forum: General
Topic: Creating Route for Vlan to switch
Replies: 3
Views: 893

Re: Creating Route for Vlan to switch

I have a cisco switch that is connected directly to the mikrotik via ether2. and then it has a SFP port 1/0/25 that connects to a hp switch. [...] interface GigabitEthernet1/0/25 switchport trunk encapsulation dot1q switchport mode trunk What Cisco port is connected to the MikroTik's ether2? And wh...
by dasiu
Sun Jan 19, 2014 12:52 am
Forum: General
Topic: Src & Dst NAT In Same Time
Replies: 1
Views: 390

Re: Src & Dst NAT In Same Time

You simply configure it, it will work in the same time. You configure dst-nat rules in "dstnat" CHAIN, and src-nat rules in the "srcnat" CHAIN. Each IP packet goes through the dstnat chain after getting inside the router (before routing decision), and goes through srcnat chain before leaving the rou...
by dasiu
Wed Jan 30, 2013 1:09 am
Forum: Scripting
Topic: Ip hotspot active user = Ip Bindings
Replies: 4
Views: 5861

Re: Ip hotspot active user = Ip Bindings

:foreach user in=[/ip hotspot active find] do={ :local ip [/ip hotspot active get $user address]; :local mac [/ip hotspot active get $user mac-address]; :local username [/ip hotspot active get $user user]; :foreach binding in=[/ip hotspot ip-binding find address=$ip] do={ /ip hotspot ip-binding rem...
by dasiu
Mon May 07, 2012 3:29 pm
Forum: General
Topic: How to male bandwidth limimitation with miltiple VLAN`s
Replies: 1
Views: 442

Re: How to male bandwidth limimitation with miltiple VLAN`s

How to tag only those packets that come from the Internet to users and exclude inter VLAN traffic? You already did that :). /ip firewall mangle add action=mark-connection chain=forward disabled=no new-connection-mark=\ "vlan7 con-down" passthrough=yes src-address=192.168.7.0/24 add action=mark-pack...
by dasiu
Mon May 07, 2012 2:37 pm
Forum: General
Topic: How to change Graph storage location from disk to Micro SD ?
Replies: 1
Views: 954

Re: How to change Graph storage location from disk to Micro

THERE IS NO SUCH OPTION, YOU CANNOT DO THAT!

And please, don't shout...
by dasiu
Mon May 07, 2012 2:27 pm
Forum: RouterBOARD hardware
Topic: Is RB751G-2HnD performance enough?
Replies: 4
Views: 4730

Re: Is RB751G-2HnD performance enough?

1. Is RB751G-2HnD performance enough? I think it can be too weak for your requirements... see http://routerboard.com/RB751G-2HnD - and remember, that the tests are with simple routing (and conntrack=on), without any queues, tunnels etc. - and they are also CPU consuming. The best way would be to te...
by dasiu
Fri May 04, 2012 2:22 am
Forum: General
Topic: Maybe chewing bit too much
Replies: 4
Views: 538

Re: Maybe chewing bit too much

So it looks quite simple, if you are familiar with policy routing a bit :). I assume, that you have already created the static default route on the wan1 gateway's IP, and that it has greater distance (default=1) than the one from DHCP (default=0). Basically, now everything should go through wan2 (th...
by dasiu
Sat Apr 28, 2012 11:37 am
Forum: Wireless Networking
Topic: 802.11n 3x3 with 3SS
Replies: 7
Views: 2026

Re: 802.11n 3x3 with 3SS

Any plans for a triple polarization antenna? :twisted: In free space, for outdoor links (in Line Of Sight scenario) the spatial streams are different polarizations :). That's the only way to send/receive 2 different signals on the same frequency. And you can have only two orthogonal (totally differe...
by dasiu
Sat Apr 28, 2012 11:13 am
Forum: Beginner Basics
Topic: Managing AP in Hotspot bridge
Replies: 2
Views: 738

Re: Managing AP in Hotspot bridge

Run a PPTP server on the RB1200, connect to it from your computer or router where you actually are, and use the pptp-client interface as your default gateway (check the option when configuring PPTP client). Now you can simply connect to 172.*.*.*. Just remember, that the 172.*.* AP's need to have th...
by dasiu
Sat Apr 28, 2012 11:00 am
Forum: General
Topic: Hotspot and iphone/ipad autofill
Replies: 9
Views: 6809

Re: Hotspot and iphone/ipad autofill

Have you tried setting HTTP PAP instead of HTTP CHAP in hotspot server profile? Maybe your Apple devices get lost, when the CHAP is used, and the password sent by the browser is different than written by you (it's MD5 hashed by JavaScript). Maybe iOS refuses to remember the form data, as they were d...
by dasiu
Thu Apr 26, 2012 10:15 am
Forum: General
Topic: can someone please double-check my queues?
Replies: 1
Views: 407

Re: can someone please double-check my queues?

http://forum.mikrotik.com/viewtopic.php?f=2&t=54350&p=276863#p276863 - it is already here :). In a few words - the parents' queue types are IRRELEVANT :). In /queue tree (generally - HTB) only the children do the actual queueing (waiting room for packets), and the parents only count bandwidth for t...
by dasiu
Thu Apr 26, 2012 10:05 am
Forum: Scripting
Topic: Script to Disconnect All Active pppoe Users
Replies: 2
Views: 1607

Re: Script to Disconnect All Active pppoe Users

/ppp active remove [find] or - being strict: /ppp active remove [find service="pppoe"] Will I get carma for this? Or was it too trivial? ;) edit: How is it possible, that I saw the topic as "unreplied" few minutes ago (26 Apr 09:00 CEST) , while a response was "Posted: Wed Apr 25, 2012 5:49 pm"? Is...
by dasiu
Thu Apr 26, 2012 9:09 am
Forum: Beginner Basics
Topic: IP problem rb433l
Replies: 1
Views: 297

Re: IP problem rb433l

The default address 192.168.88.1 is configured only on ether1 ;).
by dasiu
Thu Apr 26, 2012 9:03 am
Forum: The Dude
Topic: The DUDE 100% CPU usage
Replies: 5
Views: 2693

Re: The DUDE 100% CPU usage

I use Dude server on a separate machine with MikroTik RouterOS - it monitors hundreds of machines, and the average cpu-load is always below 10% :).
by dasiu
Mon Apr 23, 2012 11:52 pm
Forum: The Dude
Topic: The DUDE 100% CPU usage
Replies: 5
Views: 2693

Re: The DUDE 100% CPU usage

Pretty obvious recommendation would be to use a newer version of Dude :).
by dasiu
Mon Apr 23, 2012 11:51 pm
Forum: General
Topic: Login by HTTP CHAP ?
Replies: 1
Views: 715

Re: Login by HTTP CHAP ?

Look into the HTML :). I don't have the files accessible now, so I can't check, but I'm pretty sure it's just a MD5 hash. And the idea is that you are not able to decrypt the password :). You can just check, if the hash is made using proper password and challenge string :).
by dasiu
Mon Feb 27, 2012 4:56 pm
Forum: General
Topic: FREE ROUTER!
Replies: 15
Views: 5729

Re: FREE ROUTER!

Is the special offer closed already? Or do you plan to prolong it? ;-)
by dasiu
Thu Feb 23, 2012 11:59 am
Forum: Forwarding Protocols
Topic: Help with OSPF
Replies: 3
Views: 1329

Re: Help with OSPF

Try changing default-distribute on every router to "if-installed-as-type-1" and remove all static routes to 0.0.0.0/0 :). Then check if it works. With "if-installed" router will not advertise a route it doesn't have, and with "type 1" the distance will change with every single hop - so the best path...
by dasiu
Wed Feb 22, 2012 12:02 am
Forum: General
Topic: daily limitation of upload traffic
Replies: 3
Views: 554

Re: daily limitation of upload traffic

http://forum.mikrotik.com/viewtopic.php?f=10&t=59306 - the solution was discussed here a week ago :). In hotspot you can specify uptime and you can specify amount of bytes sent/received/total :). So it's the same case (hotspot, limited user, and script that clears the counters every midnight).
by dasiu
Tue Feb 21, 2012 11:59 pm
Forum: Beginner Basics
Topic: Transparent Bridge with NAT?
Replies: 3
Views: 1973

Re: Transparent Bridge with NAT?

yes :)
by dasiu
Tue Feb 21, 2012 11:20 am
Forum: General
Topic: who can help me to set up something with Mikrotik.
Replies: 1
Views: 261

Re: who can help me to set up something with Mikrotik.

Well... It seems easy - with HOTSPOT :). I think it's what you are looking for. And also an external server with Radius and PHP and a database :). Each user can have his account, and the Radius server will inform MikroTik about limits for the user. If the limits are over, user will be redirected to ...
by dasiu
Tue Feb 21, 2012 10:43 am
Forum: Forwarding Protocols
Topic: Help with OSPF
Replies: 3
Views: 1329

Re: Help with OSPF

BGP with "redistribute connected"?? wow...

Could you show us the "/routing export" output from the core router? It will cover the BGP, OSPF and filters configuration - and will show us what is the configuration idea and what can be missing :).
by dasiu
Tue Feb 21, 2012 10:22 am
Forum: General
Topic: Hotspot e-mail login.
Replies: 2
Views: 691

Re: Hotspot e-mail login.

No, it's not possible :). But it should be easy with a simple server with RADIUS and PHP.
by dasiu
Wed Feb 15, 2012 2:21 pm
Forum: Beginner Basics
Topic: RB750 is dead after update to 5.13
Replies: 4
Views: 1663

Re: RB750 is dead after update to 5.13

A while ago I had to save my RB750 the same way ;).
Did you upload 5.13, or an older version?
by dasiu
Wed Feb 15, 2012 2:02 am
Forum: General
Topic: DST-NAT Local IP to Local IP
Replies: 8
Views: 3688

Re: DST-NAT Local IP to Local IP

If I understand it correctly, the MailServer is on LAN1, just like the other computers? Then - add another masquarading rule: chain=srcnat action=masquerade src-address=192.168.0.0/24 dst-address=192.168.0.2 Does it work now? :) If it is the case, computer with 192.168.0.1 sends a packet to 192.168....
by dasiu
Wed Feb 15, 2012 1:35 am
Forum: Beginner Basics
Topic: RB750 is dead after update to 5.13
Replies: 4
Views: 1663

Re: RB750 is dead after update to 5.13

Something went wrong... But there is an option! :) See the manual for RB750 about the reset button: "● Hold this button during boot time longer, until LED turns off, then release it to make RB750 look for Netinstall servers." You need to run a Netinstall server on your computer, and connect the rout...
by dasiu
Mon Feb 13, 2012 6:56 pm
Forum: The User Manager
Topic: can I have a user with 2 hour internet for every day
Replies: 4
Views: 1545

Re: can I have a user with 2 hour internet for every day

Yes, you can! :) 1. Create a simple hotspot (using the wizard), you can find many tutorials on this 2. Create the hotspot user and set the time restrictions for him (for example - 2 hours of activity) 3. Create a script, that resets the counters for the user (or for all hotspot users) - with scripti...
by dasiu
Sun Feb 12, 2012 3:05 pm
Forum: Beginner Basics
Topic: Hotspot Documentation
Replies: 2
Views: 386

Re: Hotspot Documentation

Strange... I looked for such article, but I found nothing. That's why I'm doing such presentation for the next MUM in Warsaw ;).
What exactly do would you like to do? What is your plan?
by dasiu
Thu Feb 02, 2012 11:50 pm
Forum: Forwarding Protocols
Topic: BGP Advice
Replies: 4
Views: 899

Re: BGP Advice

Maybe I should be looking at OSPF instead? And how many "real" eBGP sessions (on different routers) do you have there? iBGP's main idea is that the eBGP routers should "discuss" the routes received from their peers and decide, how to route the traffic outside. For routing inside one "real" AS - BGP...
by dasiu
Fri Jan 06, 2012 1:21 pm
Forum: Beginner Basics
Topic: Dropping traffic from ether3 to ether2
Replies: 3
Views: 757

Re: Dropping traffic from ether3 to ether2

I was able to access a wireless AP that was 192.168.1.2, but after changing the order, it is working properly. You can paste your rules here so we can see and think ;). If changing the order helped, it would suggest that there was a problem :). If you have the rules for accepting established, relat...
by dasiu
Fri Jan 06, 2012 4:41 am
Forum: Beginner Basics
Topic: Dropping traffic from ether3 to ether2
Replies: 3
Views: 757

Re: Dropping traffic from ether3 to ether2

/ip firewall filter add chain=forward src-address=10.10.0.0/24 dst-address=192.168.1.0/24 action=drop place-before=0 /ip firewall filter add chain=forward dst-address=10.10.0.0/24 src-address=192.168.1.0/24 action=drop place-before=0 Are you sure that there were no other filter rules before the ones...