Community discussions

MikroTik App

Search found 98 matches

by che
Tue Sep 15, 2020 3:39 pm
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 27
Views: 3640

Re: v6.46.7 [long-term] is released!

You seem to be correct, although it doesn't completely explain why only ~200 entries remained out of 50k (all are/were static). I have many small address lists and a huge one with over 50k entries. There is only 2.1MB free space on hAP ac^2 nand chip, and these are the sizes of a couple of latest ba...
by che
Tue Sep 15, 2020 10:33 am
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 27
Views: 3640

Re: v6.46.7 [long-term] is released!

Upgraded my home hAP ac^2 and I had a problem that I saw for the first time. It seems like router only preserved 200-something address list entries, and many were gone completely or only partially preserved, breaking access to the router itself and internet access (because I use those as NAT out add...
by che
Wed Aug 26, 2020 1:28 am
Forum: General
Topic: Mikrotik or NOT!!! Industry standarts say no!! Why? [SOLVED]
Replies: 88
Views: 4147

Re: Mikrotik or NOT!!! Industry standarts say no!! Why? [SOLVED]

You are free to disagree with me or discard my opinion anytime, but I think you can not say that having ssh and telnet on by default on Cisco devices is the same as having ssh, telnet, Winbox and other MikroTik proprietary protocols on by default. I would even extend that to - having any proprietary...
by che
Wed Aug 26, 2020 1:03 am
Forum: General
Topic: Mikrotik or NOT!!! Industry standarts say no!! Why? [SOLVED]
Replies: 88
Views: 4147

Re: Mikrotik or NOT!!! Industry standarts say no!! Why? [SOLVED]

Since we run the largest MikroTik consulting firm in the world, I have some thoughts on this :) If MikroTik officially kept close business relationship with integrators like yours in providing a responsive support for paying business customers, that would finally begin to look like Cisco's way of c...
by che
Mon Oct 21, 2019 3:33 pm
Forum: Beginner Basics
Topic: Load Balancing 3 ISP
Replies: 8
Views: 1798

Re: Load Balancing 3 ISP

If you are using DHCP, you could call a simple "cleanup" script with each client lease change. Add similar script either to DHCP client section, or call it from there after adding it to the /system scripts section: :global fwIP :local dhcpIP :local readIP [/ip address get value-name=address [/ip add...
by che
Thu Mar 21, 2019 10:41 am
Forum: General
Topic: VoIP issues Mikrotik SIP ALG and Grandstream
Replies: 2
Views: 1287

Re: VoIP issues Mikrotik SIP ALG and Grandstream

Indeed, you could have a multitude of problems in your scenario, but let's get back to the beginning: did you try disabling only "SIP Direct Media" option before completely disabling SIP helper?
by che
Tue Sep 11, 2018 5:34 pm
Forum: Scripting
Topic: remote ssh via script
Replies: 52
Views: 36864

Re: remote ssh via script

While I agree that using key pairs is the best practice from security standpoint, my script was not aiming at that particular scenario. My network had few hundreds of MikroTik boxes that needed to be changed quickly and zero key pairs setup beforehand. I was sitting on Windows desktop machine and ca...
by che
Tue Sep 11, 2018 4:15 pm
Forum: Scripting
Topic: remote ssh via script
Replies: 52
Views: 36864

Re: remote ssh via script

Hello, is it possible to change your script to join with RSA key connection with a password + specific username? Thank you Could you clarify the question a bit? As I understood, you want the script to know which hosts use which usernames, passwords and keys, with same host having multitude of those?
by che
Mon Jul 30, 2018 7:16 pm
Forum: RouterBOARD hardware
Topic: how to upgrade the software of the RB532
Replies: 10
Views: 2972

Re: how to upgrade the software of the RB532

Alright, try couple of steps then.

First go for version 5.26
Then 6.27

Then the one linked previously.

If you can not install 5.26 this way, then I'm guessing you will have to learn how to use Netinstall application (another way of installing MikroTik software). :)
by che
Mon Jul 30, 2018 6:48 pm
Forum: RouterBOARD hardware
Topic: how to upgrade the software of the RB532
Replies: 10
Views: 2972

Re: how to upgrade the software of the RB532

I was a long time ago, but one thing I remember is I bricked the device by installing newer version than supported. That's how I found out about this EoL situation. Since you can not use auto-update feature, you have to manually upload software packet to your RB532. 1. Download software package from...
by che
Mon Jul 30, 2018 6:32 pm
Forum: RouterBOARD hardware
Topic: how to upgrade the software of the RB532
Replies: 10
Views: 2972

Re: how to upgrade the software of the RB532

Suport for MIPSLE architecture was dropped 2 years ago. What's new in 6.34 (2016-Jan-29 10:25): *) mipsle - architecture support dropped (last fully supported version 6.32.x); I am running 6.32.4 on couple of my old 532A boards. You can download old version from the archive: https://mikrotik.com/dow...
by che
Wed Jul 25, 2018 3:43 am
Forum: General
Topic: Modify Raw Rule 'add src to address list' [SOLVED]
Replies: 17
Views: 2768

Re: Modify Raw Rule 'add src to address list' [SOLVED]

My script doesn't deal with deleting entries because I think that is a waste of router's resources. I suggested you set timeout on automatic list, so entries disapear on their own. You are free to see zero value in my approach, I had fun contemplating the solution.
by che
Wed Jul 25, 2018 12:05 am
Forum: General
Topic: Modify Raw Rule 'add src to address list' [SOLVED]
Replies: 17
Views: 2768

Re: Modify Raw Rule 'add src to address list' [SOLVED]

I'm not sure how fast hashing methods in RouterOS are, never benchmarked it. My initial idea is to have less entries in the list and (in theory) faster rule processing, because my assumption is, as you stated: less address list entries > faster firewall. Using this method you will only have a networ...
by che
Tue Jul 24, 2018 12:04 pm
Forum: General
Topic: Modify Raw Rule 'add src to address list' [SOLVED]
Replies: 17
Views: 2768

Re: Modify Raw Rule 'add src to address list' [SOLVED]

I expanded a bit on your idea. - Script takes addresses in your dynamic list - Converts it to clean /24 network address and adds whole statement to new blacklist :foreach addr in=[/ip firewall address-list find list=dynamic_list address~"^[0-9\\.]*\$"] do={ :local ipAddr [/ip firewall address-list g...
by che
Wed Jul 11, 2018 3:34 pm
Forum: General
Topic: VPN attacks? Blocking?
Replies: 8
Views: 5943

Re: VPN attacks? Blocking?

I've created a little facility for my home dial-in VPN system that addresses the issue you stated. 1) When a client successfuly connects to VPN server (meaning it's a valid user), a script is triggered that adds source address to whitelist. PPP/Profiles/ name of L2TP profile you are using /Scripts (...
by che
Wed Mar 14, 2018 5:05 pm
Forum: General
Topic: Comfortable way to block inter-vlan traffic?
Replies: 10
Views: 3899

Re: Comfortable way to block inter-vlan traffic?

The only scalable way is using one firewall rule with either interface list (layer 2) or address list (layer 3). Create interface (or address) list and add firewall rule that states that in (source) interface (address) list can't talk to the same out (destination) interface (address) list. You only ...
by che
Wed Jan 10, 2018 3:44 pm
Forum: Scripting
Topic: remote ssh via script
Replies: 52
Views: 36864

Re: remote ssh via script

I have uploaded to Github my old Python script that does what you need: connects to a number of different Mikrotik routers and then executes some commands. All you need to do is edit username and password in .py file, list of IP addresses and commands. The only requirement is that you have Python in...
by che
Fri Dec 15, 2017 12:52 pm
Forum: General
Topic: Autorun script after reboot
Replies: 4
Views: 2323

Re: Autorun script after reboot

Go to system/scheduler, click plus button and create entry like on the picture.

Image

Second script name is my guess, you edit it to fit the script name.
by che
Fri Dec 15, 2017 10:29 am
Forum: General
Topic: Autorun script after reboot
Replies: 4
Views: 2323

Re: Autorun script after reboot

When you add system/scheduler you have an option to set "Start Time" to "startup". "On Event" field either calls external script (/system script run name-of-the-script) or if it's not a complex task you can enter command(s) directly in this field.
by che
Mon Dec 11, 2017 10:30 am
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 10039

Re: NAT table not cleared correctly [SOLVED]

I've forgot to ask, have you recreated (deleted and then created it again) PPPoE client interface in these situations?
by che
Thu Dec 07, 2017 12:13 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 10039

Re: NAT table not cleared correctly [SOLVED]

In my own experience, the issue persists while NAT is not used.
In that case the conclusion is that PPP tunnel is the problem, not NAT.
by che
Fri Nov 24, 2017 9:35 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 10039

Re: NAT table not cleared correctly [SOLVED]

I highly suggest that you don't use double-NAT in cases of IP telephony. Judging by one of the posted connection details (reply-dst-address=10.0.0.1:5060) you are doing some sort of DMZ on VDSL modem? Put it in bridge mode, or if it is not possible try this after PPPoE disconnects: /ip firewall conn...
by che
Tue Sep 26, 2017 12:00 pm
Forum: General
Topic: VoIP problems and dilemma
Replies: 10
Views: 2249

Re: VoIP problems and dilemma

If ping is 100ms all the time it should not affect IP voice quality, but if it varies a lot (for example 10ms, 30ms, then 100ms) it will be a problem for voice communication. One more thing: since you are using international SIP proxy, I would strongly recommend using encryption (which will increase...
by che
Sun Jul 02, 2017 1:04 am
Forum: General
Topic: how to connect/configure kiwi syslog with mikrotik
Replies: 8
Views: 3935

Re: how to connect/configure kiwi syslog with mikrotik

Yeah, it looks OK.
by che
Sat Jul 01, 2017 9:10 pm
Forum: General
Topic: how to connect/configure kiwi syslog with mikrotik
Replies: 8
Views: 3935

Re: how to connect/configure kiwi syslog with mikrotik

It's pretty straight forward:

Image

Enter MikroTik's address that you connect to from your PC (you have to make it reachable).
by che
Sat Jul 01, 2017 7:52 pm
Forum: General
Topic: how to connect/configure kiwi syslog with mikrotik
Replies: 8
Views: 3935

Re: how to connect/configure kiwi syslog with mikrotik

I also use Kiwi on my desktop machine to collect some logs from my home MikroTik box. I have deafult rules (one is to display in your Kiwi client, another one is "Log to file"), and I've edited "Log to file" to make different files monthly by entering "J:\path\to\folder\%DateY4-%DateM2 NAME FOR YOUR...
by che
Wed Jun 28, 2017 3:29 pm
Forum: General
Topic: Feature suggestion: Check gateway when using DHCP client [SOLVED]
Replies: 3
Views: 3332

Re: Feature suggestion: Check gateway when using DHCP client [SOLVED]

Hello Aleksandar, I've had the same obstacle and here is what I've done in the end. I've created a static route with option check gateway ping and "dhcp gw" comment. Then I've written a short Frankenstein AI that reads DHCP parameters and updates few global variables: :global fwIP :global dynamicIP ...
by che
Mon Jun 26, 2017 8:06 pm
Forum: General
Topic: python telnetlib not working on Mikrotik routerOs
Replies: 7
Views: 2605

Re: python telnetlib not working on Mikrotik routerOs

Agreed with idlemind, avoid telnet like a plague. But in case you are doing it just on a local device, here is something you can tinker with to fix that script assuming login works like you stated: mtcommand = "/interface disable 4" prompt = ">" ... tn.read_until(prompt) time.sleep(4) tn.write(mtcom...
by che
Sat May 20, 2017 11:48 am
Forum: General
Topic: Port 200 TCP etc. open and telnet by default?
Replies: 8
Views: 1852

Re: Port 200 TCP etc. open and telnet by default?

Did you install breaker panel in your aparatment on your own or you called an electrician? Port 200 and few proxy ones in your list are not open by default (probably your port forwarding rule and activation of non-default services), and if you don't know what services are active on the router by def...
by che
Tue Jan 31, 2017 11:50 pm
Forum: General
Topic: Dual Wan Port Fowarding
Replies: 77
Views: 9186

Re: Dual Wan Port Fowarding

/ip firewall nat add action=dst-nat chain=dstnat dst-address=WAN1ADDRESS dst-port=522 protocol=tcp to-addresses=8.8.8.8 to-ports=22 add action=dst-nat chain=dstnat dst-address=WAN2ADDRESS dst-port=522 protocol=tcp to-addresses=8.8.8.8 to-ports=22 Make sure that you are allowing connections to ports...
by che
Tue Jan 31, 2017 8:18 pm
Forum: General
Topic: Dual Wan Port Fowarding
Replies: 77
Views: 9186

Re: Dual Wan Port Fowarding

You literally need only 2 DST-NAT rules (for both WAN links, or only 1 rule if you know how to make address/interface lists), those 3 mangle rules and 1 policy routing rule for DST-NAT to work via both gateways. If you don't see counter going up on any magle rules but 0, you haven't have done proper...
by che
Sun Jan 29, 2017 12:04 am
Forum: General
Topic: Dual Wan Port Fowarding
Replies: 77
Views: 9186

Re: Dual Wan Port Fowarding

In order for you to inderstand this logic I need to state my optimizing argument: since you are doing simple failover WAN, to prevent excess CPU usage I will advise you to mangle only connections that go via secondary gateway, because even without any mangle rules all connections will go through WAN...
by che
Fri Jan 27, 2017 10:15 am
Forum: General
Topic: Dual Wan Port Fowarding
Replies: 77
Views: 9186

Re: Dual Wan Port Fowarding

This is a common mistake with implementing mangle rules, and oddly enough correct solutions are hard to find. In short, you are missing mangle rules in order to make this work properly, but sadly I don't have time to write them now. If noone jumps in I'll post them tonight.
by che
Thu Jan 19, 2017 10:10 pm
Forum: Beginner Basics
Topic: DNS at each site?
Replies: 17
Views: 2488

Re: DNS at each site?

I would not argue if doing this practice is or is not inheritably wrong. I can just add my personal note that no ISP I've worked at in past twelve years has been doing that, but I know of some that are either redirecting or recording DNS traffic, or both. Just don't be so sure that DNS traffic outsi...
by che
Thu Jan 19, 2017 8:06 pm
Forum: Beginner Basics
Topic: DNS at each site?
Replies: 17
Views: 2488

Re: DNS at each site?

Controlled DNS redirection could also be a security upgrade if you set your caching router to use your ISP's and not public DNS servers. I am actually doing this on my home MikroTik for years as one extra security measure.
by che
Tue Dec 20, 2016 2:12 am
Forum: Scripting
Topic: Dual FailOver Script takes too long to switch over!
Replies: 16
Views: 2898

Re: Dual FailOver Script takes too long to switch over!

I see you already have a scheduler that runs a script every second. You can just add those two lines I've posted to your script in places where code is reacting to a dead gateway and when it's comming back to original state (I didn't examine your script).
by che
Tue Dec 20, 2016 12:45 am
Forum: Scripting
Topic: Dual FailOver Script takes too long to switch over!
Replies: 16
Views: 2898

Re: Dual FailOver Script takes too long to switch over!

I had the same question once regarding dual wan L2TP tunnel, and my workaround was adding script routine (netwatch would work as well) to reset the connection tracking table on gateway switch events:
/ip firewall connection tracking set enabled=no
/ip firewall connection tracking set enabled=yes
by che
Sat Nov 26, 2016 11:48 am
Forum: General
Topic: gateway mac 00:00:00:00:00:00 - hEX r3
Replies: 12
Views: 2018

Re: gateway mac 00:00:00:00:00:00 - hEX r3

I was lead to assume your network topology is the one from original post on the topic. I have no idea what switch you are talking about, but if it works it still means physical connection on site 1 is fine. Are there any VLANS configured on any device?
by che
Sat Nov 26, 2016 11:41 am
Forum: Beginner Basics
Topic: Mikrotik + AdBlock Plus
Replies: 20
Views: 28808

Re: Mikrotik + AdBlock Plus

Yes, that is the value you need to alter. The thing that indicates problem is this value: cache-used: 2048KiB - it means your cache is full and not working for additional queries. You can add two zeros and make this value something like this: cache-size: 204800KiB (making it ~200MiB). Monitor "cache...
by che
Sat Nov 26, 2016 10:42 am
Forum: General
Topic: gateway mac 00:00:00:00:00:00 - hEX r3
Replies: 12
Views: 2018

Re: gateway mac 00:00:00:00:00:00 - hEX r3

Alright, before we dive in the digging the layer 2 I need one information: what is the exact address and subnet mask of Cyberoam and hEX? If those are fine, you need to inspect bridge on the site: delete and create bridge again. I've also noticed pptp client on that board, did you try removing it be...
by che
Fri Nov 25, 2016 10:38 am
Forum: General
Topic: gateway mac 00:00:00:00:00:00 - hEX r3
Replies: 12
Views: 2018

Re: gateway mac 00:00:00:00:00:00 - hEX r3

Another way of checking the connection is adding IP address from the same subnet as Cyberoam on each wireless device, and pinging it, it will probably be easier than dealing with layer 2 tables.
by che
Fri Nov 25, 2016 10:32 am
Forum: General
Topic: gateway mac 00:00:00:00:00:00 - hEX r3
Replies: 12
Views: 2018

Re: gateway mac 00:00:00:00:00:00 - hEX r3

You can trace the problem by checking bridge hosts (equivalent of Cisco show mac-address-table) on each wireless device on the path and isolate the faulty connection. You are probably right that cabling on either of 3 places on the path is the problem.
by che
Thu Nov 24, 2016 9:02 pm
Forum: Beginner Basics
Topic: Mikrotik + AdBlock Plus
Replies: 20
Views: 28808

Re: Mikrotik + AdBlock Plus

Did you increase size of DNS cache? Default 2MB is nowhere near enough for what you want to achieve. If you did not do that, most probably you see no hits because your DNS cache is not working at all. If you did increase the cache size, another firewall rule is interfering with your rule - in this c...
by che
Thu Nov 24, 2016 12:44 am
Forum: Beginner Basics
Topic: Mikrotik + AdBlock Plus
Replies: 20
Views: 28808

Re: Mikrotik + AdBlock Plus

You might want to look at the size of your DNS cache. I have not done napkin math to tell you the exact cache size required for almost 150k entries, but I guess you could increase it to 200MB for starters, and if it's still full try increasing it even more. There is enough memory available on the bo...
by che
Fri Nov 11, 2016 10:45 pm
Forum: General
Topic: VPN to 443 port from Android
Replies: 8
Views: 6463

Re: VPN to 443 port from Android

Alright, I am doing this for only one reason: I can not point you to a full tutorial since every single one on this forum or on the internet is incomplete (you would have to tinker a lot on your own, debug imperfections, etc). Also, this is the first time I am about to break my self-inflicted "think...
by che
Thu Nov 10, 2016 10:54 pm
Forum: General
Topic: VPN to 443 port from Android
Replies: 8
Views: 6463

Re: VPN to 443 port from Android

I actually have deployed MikroTik OpenVPN server running on TCP port 443. Works like a charm with "OpenVPN Connect" app for Android.
by che
Thu Nov 10, 2016 12:12 am
Forum: Beginner Basics
Topic: Shaping 300/50 Traffic
Replies: 5
Views: 1030

Re: Shaping 300/50 Traffic

My company currently uses RB3011 devices as BRAS for wireless users and we are happy with it's performance. I've made you one screenshot as an example: box has 100 PPPoE users with simple queue each (speed up to 10Mbps per user), additional QoS atop all those simple queues (less than 10 queue tree r...
by che
Sat Nov 05, 2016 4:56 pm
Forum: Beginner Basics
Topic: Interfaces out of order!
Replies: 5
Views: 874

Re: Interfaces out of order!

It is a common "feature", since MikroTik staff stated many times that bakcups are intended for the same boards. What you can do if you want to avoid wiping complete confinguration is reset each interface mac address, then go to Interfaces and open Ethernet tab, sort them by mac address and rename th...
by che
Wed Oct 26, 2016 3:16 pm
Forum: General
Topic: Mikrotik Poor Bandwidth Throughput Problem Help
Replies: 27
Views: 3793

Re: Mikrotik Poor Bandwidth Throughput Problem Help

Change channel width to 40Mhz and band to 5GHz-N (if your card in RB433 supports it). Since you run single polarisation device (Groove) with 5GHz-A and 20MHz channel width you can expect maximum ~35-40Mbps real throughput with your current settings. Also, something else is wrong with your setup, tha...
by che
Tue Oct 11, 2016 4:34 pm
Forum: Scripting
Topic: Please help me
Replies: 2
Views: 665

Re: Please help me

:local getState [/ip route get value-name=active [/ip route find where gateway=8.8.4.4 and static=yes]] :if ($getState = true) do { SCRIPT WHEN ROUTE IS PRESENT AND ACTIVE } :if ($getState = false) do { SCRIPT WHEN ROUTE IS PRESENT BUT NOT ACTIVE } :if ($getState = "nothing") do { SCRIPT WHEN THERE...
by che
Tue Oct 11, 2016 11:04 am
Forum: General
Topic: Connections total-entries
Replies: 13
Views: 1828

Re: Connections total-entries

If you want to read variable from the script, make it global and read it's value from /system script environment. I haven't tried it in your scenario, but it might work since that way variable is always accessible and there is a chance it will have functional OID.
by che
Mon Oct 10, 2016 7:42 pm
Forum: General
Topic: add source IP of VPN client to trusted_ip address list in /ip firewall
Replies: 6
Views: 2393

Re: add source IP of VPN client to trusted_ip address list in /ip firewall

Just upgrade the board to current RouterOS, 6.27 was out in February 2015 and there were a lot of new features and fixes implemented since then. And if you don't want to upgrade, just use my script and schedule it to run on whatever interval you think is fine.
by che
Mon Oct 10, 2016 4:34 pm
Forum: General
Topic: add source IP of VPN client to trusted_ip address list in /ip firewall
Replies: 6
Views: 2393

Re: add source IP of VPN client to trusted_ip address list in /ip firewall

I had similar dilemma, and decided to go with solution where I call a script when any VPN client connects. First I've added event in VPN profile where script runs when any client connects: /ppp profile set vpn on-up="/system script run vpn-on_connect" This is "vpn-on_connect" script that's been call...
by che
Wed Oct 05, 2016 11:19 am
Forum: General
Topic: Networking career
Replies: 6
Views: 901

Re: Networking career

MTCNA does not aim to properly teach you foundation of networking, it's more focused on enabling you to use basic features in RouterOS. It can not even remotely compare to CCNA for example. But if you want to troubleshoot some basic problems in your network, it might be helpful. Focus on one problem...
by che
Fri Sep 30, 2016 8:41 pm
Forum: General
Topic: Routing blackhole
Replies: 13
Views: 10381

Re: Routing blackhole

I think you are trying to secure the routing table? If you do, the method you want to use is route filters (ospf-in and ospf-out). By blackholing whole /16 segment (and announcing it to other routers by enabling redistribute-static?) you did the opposite - you made whole segment always reachable up ...
by che
Thu Sep 29, 2016 8:37 pm
Forum: Scripting
Topic: Add variable to the end of a file
Replies: 1
Views: 663

Re: Add variable to the end of a file

This is a simple method of appending lines to a file in RouterOS: :local content [file get YOUR_FILE contents] :set content ("$content\r\n$YOUR_VARIABLE") /file set YOUR_FILE contents=$content Bear in mind there is 4KB size limitation on read/write of files with this method . If you want to overcome...
by che
Tue Sep 27, 2016 10:35 am
Forum: Beginner Basics
Topic: Dual Wan failover with 1 static and 1 dynamic IP?
Replies: 9
Views: 3343

Re: Dual Wan failover with 1 static and 1 dynamic IP?

Sure it can. You need to find out exact order of DHCP clients. Afaik, you can not do that from Winbox (you can only assume list position, but it's not numbered), so you have to open new terminal either from Winbox or use telnet/ssh, and enter this command: ip dhcp-client print If DHCP client you wan...
by che
Mon Sep 26, 2016 5:21 pm
Forum: RouterBOARD hardware
Topic: CCR1036-8G-2S+ PPP client limitation?
Replies: 6
Views: 1762

Re: CCR1036-8G-2S+ PPP client limitation?

User IPANetEngineer tested CCR1072 with 30k simultaneous PPPoE sessions , so I really doubt there is intentional software limitation to 3041 sessions on CCR1036. What is ROS version you are running? It's not impossible that some bug your configuration is expressing is fixed in newer iteration of the...
by che
Mon Sep 26, 2016 10:41 am
Forum: Beginner Basics
Topic: Dual Wan failover with 1 static and 1 dynamic IP?
Replies: 9
Views: 3343

Re: Dual Wan failover with 1 static and 1 dynamic IP?

You didn't state what type of WAN connection you have on dynamic gateway, so I'll just assume it's DHCP client. Since you would like to keep the script from wiki, replace current static variable with new one that reads acutal gateway value, and schedule script to run in a reasonable interval (15 min...
by che
Thu Sep 15, 2016 9:39 pm
Forum: Beginner Basics
Topic: Windows 10 updates killing my network
Replies: 6
Views: 7513

Re: Windows 10 updates killing my network

Hello, this same thing was driving me crazy as well, so I gathered all Microsoft's BGP prefixes and created access list in order to block them completely - during hours I don't want them to spend my traffic. Windows update does not work, web access to Bing does not work, no Microsoft telemetry works...
by che
Tue Sep 06, 2016 4:40 pm
Forum: Scripting
Topic: Netwatch...
Replies: 5
Views: 1445

Re: Netwatch...

You could also prevent your router from reaching 8.8.8.8 via WAN2 interface, like this:
/ip firewall filter add action=drop chain=output comment="gateway control" disabled=yes dst-address=8.8.8.8 out-interface=WAN2
Just replace "WAN2" with your actual interface name.
by che
Mon Apr 25, 2016 10:44 pm
Forum: Scripting
Topic: Run a script every 3rd of the month
Replies: 2
Views: 1301

Re: Run a script every 3rd of the month

I would do the same as you suggested: schedule a script to run every day and check the date, and if day of the month is equal to 3 then proceed with whatever you wanted to do. So, you need to declare variable for a day of the month in order to proceed. For example: :local date [/system clock get dat...
by che
Thu Jun 06, 2013 10:17 am
Forum: General
Topic: Exclude specific site from going through proxy
Replies: 1
Views: 648

Re: Exclude specific site from going through proxy

Hello, read info about bypassing URLs here:
http://wiki.mikrotik.com/wiki/Manual:IP ... ect_Access
by che
Sun Mar 24, 2013 12:11 pm
Forum: RouterBOARD hardware
Topic: How to select correct SFP adapter ?
Replies: 12
Views: 2772

Re: How to select correct SFP adapter ?

Unhappy I'm unable to find the info as the ISP will never tell me what equipment is on other end. I have only the reference of the ONT used but I didn't find any details about it on Internet to know what signal is used :( That is strange, usually there is type of fiber connector in specifications t...
by che
Wed Jan 30, 2013 2:27 pm
Forum: General
Topic: How to manage a RB behind a RB from the WAN?
Replies: 29
Views: 3501

Re: How to manage a RB behind a RB from the WAN?

Then you are missing the following rule

ros code

/ip firewall nat
add action=src-nat chain=srcnat disabled=no src-address=10.5.50.0/24 to-addresses=86.86.86.86
by che
Wed Jan 30, 2013 2:14 pm
Forum: General
Topic: How to manage a RB behind a RB from the WAN?
Replies: 29
Views: 3501

Re: How to manage a RB behind a RB from the WAN?

I believe its just a matter of port forwarding but I can't seem to get it to work. Can anyone help me please. /ip firewall nat add chain=dstnat action=dst-nat dst-address=86.86.86.86 dst-port=8292 to-addresses=10.5.50.2 to-ports=8291 protocol=tcp add chain=dstnat action=dst-nat dst-address=86.86.86...
by che
Tue Jan 29, 2013 3:17 am
Forum: Beginner Basics
Topic: Trunking Vlans to VMWare (Block VLAN->VLAN traffic)
Replies: 13
Views: 2207

Re: Trunking Vlans to VMWare (Block VLAN->VLAN traffic)

Hi Guys, I have a bridge for trunking, bri-trunk. I have added 5 vlans to the bridge to trunk to vmware. Have you tried adding VLANs on the bridge interface, not as bridge port, and bridging physical interfaces? That way you will keep VLAN isolation as you intended and their availability on all phy...
by che
Fri Nov 23, 2012 4:42 pm
Forum: Beginner Basics
Topic: IMAP from in and outside
Replies: 5
Views: 1367

Re: IMAP from in and outside

Didn't mean to cause frustration, you gave complete answer regarding the problem.
by che
Fri Nov 23, 2012 12:31 pm
Forum: Beginner Basics
Topic: IMAP from in and outside
Replies: 5
Views: 1367

Re: IMAP from in and outside

Just a side-note, in Cisco teminology this is called "DNS doctoring".
by che
Wed Mar 21, 2012 11:18 am
Forum: General
Topic: Thundercache
Replies: 20
Views: 9432

Re: Thundercache

Usually the videos are shared over facebook or other social networking sites so the chances are high for multiple hits per popular videos. Exactly - I do network design for my own ISP and I'd LOVE a box that could cache just the 10 most viewed videos from youtube somewhere central in our backbone. ...
by che
Wed Mar 07, 2012 7:51 pm
Forum: General
Topic: Best control over CPE devices
Replies: 20
Views: 2967

Re: Best control over CPE devices

Ok, if you want to keep exactly the same billing system you would have to isolate CPE monitoring IPs and client bridge. First thing that comes to mind is creating separate VLANs or EoIP tunnels. I'm guessing VLANs would be easier solution since you wouldn't have to add IP addresses for EoIP terminat...
by che
Wed Mar 07, 2012 5:31 am
Forum: General
Topic: Best control over CPE devices
Replies: 20
Views: 2967

Re: Best control over CPE devices

I want to reconfigure my network so I can access, benchmark and control my CPE's (so that I have full speed access and users just speed I gave to them) but to keep them simple with as low as possible config on them. Any suggestions? Is there any reason why your CPEs are set to bridge besides "simpl...
by che
Thu Jan 12, 2012 4:14 am
Forum: Wireless Networking
Topic: Mikrotik cpe is hacked?
Replies: 3
Views: 1386

Re: Mikrotik cpe is hacked?

You can start by doing port scan targeting customers IP address to see if there are any non standard services up on CPE (unprotected proxy or similar). After that you can check what is going on by starting torch utilitiy at client's CPE (Tools > Torch), select WAN interface and check all boxes. That...
by che
Thu Aug 11, 2011 1:00 am
Forum: The Dude
Topic: User access level
Replies: 5
Views: 1781

Re: User access level

I would also be happy to see these features. Currently I am running 3 Dude servers which all generate their own SNMP traffic and make management procedures more complicated (increase time spent on maintaince and human resources involved). Suggested features would optimize both segments of the proble...
by che
Fri Jun 03, 2011 3:28 pm
Forum: RouterBOARD hardware
Topic: RB751
Replies: 73
Views: 22095

Re: RB751

I'm also curious about official release of this product.
by che
Mon Jun 15, 2009 3:38 pm
Forum: General
Topic: ssh tunnel to internal socks proxy -> crash
Replies: 3
Views: 3321

Re: ssh tunnel to internal socks proxy -> crash

We will have to continue using Linux for this purpose. At least we had some adventurer spirit. :)
tunnel mode will be fully disabled in next version of RouterOS as it should
have been. Try to use other tunnel type is you need secure connection (PPTP
for example)
by che
Tue Jun 09, 2009 3:30 pm
Forum: General
Topic: ssh tunnel to internal socks proxy -> crash
Replies: 3
Views: 3321

Re: ssh tunnel to internal socks proxy -> crash

Same problem here, but different board and newest ROS. Only difference is that router created autosupout file, which I sent to their support. Seems like router processor hangs to 100% after this connection. Will reply here if I get anything worth mentioning from support.
by che
Tue Mar 10, 2009 10:59 am
Forum: RouterBOARD hardware
Topic: bizarre behaviour
Replies: 5
Views: 1071

Re: bizarre behaviour

-mistake-
by che
Mon Sep 22, 2008 12:08 pm
Forum: RouterBOARD hardware
Topic: ros 3.14 torrent is out but no seed since friday :P
Replies: 27
Views: 3343

Re: ros 3.14 torrent is out but no seed since friday :P

Same here, I see bunch of 99,8% peers, and 0 seeders. I used HTTP links for specific architectures to get v3.14.
by che
Thu Aug 14, 2008 10:37 am
Forum: General
Topic: v3.12 crashing on x86
Replies: 42
Views: 11042

Re: v3.12 crashing on x86

It's an alarm sign for me that in the changelog has from 3.x releases, more and more lines appear to be starting with "fixed" than starting with "added". I trust releases with most "fixed" lines in changelog. Currently, latest trusted (so-so:) release for me is 3.10, because I realised there is no ...
by che
Fri Aug 08, 2008 12:37 pm
Forum: RouterBOARD hardware
Topic: rebooting for (cause 1)
Replies: 23
Views: 8183

Re: rebooting for (cause 1)

My router rebooted twice 3 days ago with watchdog timer error (last month it was cause 1 error few times), and it's up since. I'm clueless about that board. I also put script to measure voltage every hour, hoping it will show some irregularity. So far nothing unusual.
by che
Mon Aug 04, 2008 11:00 am
Forum: RouterBOARD hardware
Topic: rebooting for (cause 1)
Replies: 23
Views: 8183

Re: rebooting for (cause 1)

Strange thing in my case. I have RB333 RouterOS v3.10 that was randomly rebooting with that error (+ watchdog timer one) during approx 1 month, and it stopped ~18 days ago. When I log in the ONLY difference I can see is this: system routerboard print routerboard: yes model: "333" serial-number: "XXX...
by che
Wed Jul 30, 2008 10:11 am
Forum: General
Topic: Wiki Broken?
Replies: 9
Views: 1512

Re: Wiki Broken?

Time goes backwards in Australia, huh? :D
by che
Tue Jul 29, 2008 2:54 pm
Forum: Scripting
Topic: Using fetch to retrieve IP lists
Replies: 43
Views: 16024

Re: Using fetch to retrieve IP lists

;)
by che
Fri Jul 25, 2008 12:47 pm
Forum: Scripting
Topic: Using fetch to retrieve IP lists
Replies: 43
Views: 16024

Re: Using fetch to retrieve IP lists

Just minor syntax thing.

Change path=folder/anotherfolder/ipaddress.txt to src-path=folder/anotherfolder/ipaddress.txt


Thanx for great script, Changeip!
by che
Thu Jul 24, 2008 11:20 am
Forum: General
Topic: Load Balancing Persistent
Replies: 3
Views: 962

Re: Load Balancing Persistent

Greetings,

There is also example for what you need on wiki. It's basically upgrade of script you use now.

http://wiki.mikrotik.com/wiki/Two_gatew ... _balancing
by che
Wed Jul 23, 2008 12:56 pm
Forum: General
Topic: OSPF in 311
Replies: 2
Views: 824

Re: OSPF in 311

I have same behaviour at one site with RB333. I checked routing config, and started troubleshooting the PHY link. It didn't deauth, and main OSPF table refreshes on seemingly random intervals from uplink interface which is CM9 card. Could be 30 seconds, could be 30 mins, and wireless link is working...
by che
Mon Jul 14, 2008 10:55 am
Forum: General
Topic: prism 2511mp plus problems
Replies: 7
Views: 1975

Re: prism 2511mp plus problems

Downgraded to 3.2 all work again :)
Maybe this is the explanation:
*) updated drivers;
by che
Mon Jul 07, 2008 5:32 pm
Forum: General
Topic: Load Average heads towards 100% after about 6 days
Replies: 11
Views: 1369

Re: Load Average heads towards 100% after about 6 days

Did you notice progressive memory consumption during period of uptime, not just CPU usage? In my case, there was less and less available RAM to router, and eventually at ~ 20% available memory he starts slowing so u cant even console log in, for that leak made CPU usage to 100% IMHO. I had that expe...
by che
Sun Jun 29, 2008 1:06 am
Forum: General
Topic: ospf distribut list
Replies: 11
Views: 1567

Re: ospf distribut list

Thank you. :)
by che
Sat Jun 28, 2008 6:46 pm
Forum: General
Topic: ospf distribut list
Replies: 11
Views: 1567

Re: ospf distribut list

I have one question regarding this. Is there a way of blocking large segment of distributed routes instead of filthering exact small segments? For example, I have /30 networks that are distributed and are part of /24 segment, and when I try to use more globar rule it does nothing. I have to have exa...
by che
Mon Jun 23, 2008 11:38 am
Forum: General
Topic: Safe to update RB532A remotely to 3.x?
Replies: 7
Views: 1591

Re: Safe to update RB532A remotely to 3.x?

I'm curious about this topic too. There are few RB532A I would like to move from 2.9.51 to 3.10 and I don't have time to play with my home router to test it.

Ashish, what is 'the latest version'? 3.10?

Anyone else have expirience with this kind of upgrade?
by che
Mon Apr 07, 2008 10:09 pm
Forum: General
Topic: MAC Winbox No Longer Works on New Laptops (Toshiba + Vista)
Replies: 29
Views: 12215

Re: MAC Winbox No Longer Works on New Laptops (Toshiba + Vista)

I see this happen when there are more than 1 network card in the machine. If you're plugged into it, disable the wireless interface.. If you're connecting wirelessly, disable the wired card. I've used mac connections in winbox on vista before, so it's not vista in general. Just to confirm this, I h...
by che
Thu Mar 20, 2008 12:07 pm
Forum: General
Topic: Failed 3.4 to 3.5 upgrade x86
Replies: 20
Views: 4077

Re: Failed 3.4 to 3.5 upgrade

Yesterday I upgraded mine home RB532A with v3.5 from v3.4 and I got surprise: router did not recognize CM9 card at first boot after upgrade. Luckily, I did one more reboot and it worked for me, but ppl who have these in production can be harmed.

I also upgraded bunch of RB333 with no problems.
by che
Sun Feb 03, 2008 4:47 pm
Forum: General
Topic: /ip firewall connection remove broken in 3.0 rc10-14, & v3.1
Replies: 20
Views: 4883

Re: /ip firewall connection remove broken in 3.0 rc10-14, & v3.1

v3.2

Seems to be working. :)
by che
Tue Jan 29, 2008 4:33 pm
Forum: General
Topic: /ip firewall connection remove broken in 3.0 rc10-14, & v3.1
Replies: 20
Views: 4883

Re: /ip firewall connection remove broken in 3.0 rc10 - rc14?

Hi,

Same router as in my previous post - 532A, this time with latest RouterOS v3.1: same problem.
by che
Mon Nov 19, 2007 1:23 am
Forum: General
Topic: /ip firewall connection remove broken in 3.0 rc10-14, & v3.1
Replies: 20
Views: 4883

Re: /ip firewall connection remove broken in 3.0 rc10 ?

I tried that on my home router RB532A RouterOS v3.0rc10, ~500 connections in list.

Terminal hanged for ~30secs and connection was not removed.
by che
Fri Oct 12, 2007 1:33 pm
Forum: RouterBOARD hardware
Topic: RB333 Power
Replies: 4
Views: 1644

Re: RB333 Power

Interesting timing. I've got dozen of RB333 through my hands so far, and that happened to me only once - yesterday. I didn't make big deal of it and sent it in production. If problem occures again with same router I'll post here. So far, 24h uptime with no problems.