Community discussions

MikroTik App

Search found 251 matches

by marklodge
Sun Aug 30, 2020 3:49 pm
Forum: General
Topic: SRC NAT to WAN IP without the IP existing on any interface?
Replies: 4
Views: 195

Re: SRC NAT to WAN IP without the IP existing on any interface?

OK, thank you once again for the excellent and 'to-the-point' advice.
I have added the IP addresses to the vlan70 interface (the same interface that the other WAN IP is on) just to mitigate any future issues that you have mentioned
by marklodge
Sun Aug 30, 2020 1:20 am
Forum: General
Topic: SRC NAT to WAN IP without the IP existing on any interface?
Replies: 4
Views: 195

Re: SRC NAT to WAN IP without the IP existing on any interface?

Thank you so much for the reply. You are a legend for public IP routing. So now my config looks like this: /ip route add distance=1 dst-address=45.85.224.224/27 type=unreachable /ip route print 1229 A SU 45.85.224.224/27 1 Adding all of the Public IP addresses to the vlan70Fiber interface is fine to...
by marklodge
Sun Aug 30, 2020 1:12 am
Forum: General
Topic: TLS problem with this forum since a few hours.
Replies: 14
Views: 699

Re: TLS problem with this forum since a few hours.

Me too. From South Africa.
Was just going to post this... Thought it was my routing (as I was adding new public IPs) Wrong timing..
by marklodge
Sun Aug 30, 2020 12:41 am
Forum: General
Topic: SRC NAT to WAN IP without the IP existing on any interface?
Replies: 4
Views: 195

SRC NAT to WAN IP without the IP existing on any interface?

Does WAN/Public IP addresses have to be assigned to any interface of the core or edge router? Here is my topology example.PNG And here is my config: [User@Gateway-CCR1009] > ip firewall nat export /ip firewall nat add action=src-nat chain=srcnat out-interface=vlan70Fiber src-address=10.11.1.4 to-add...
by marklodge
Sat Aug 22, 2020 3:38 am
Forum: General
Topic: RB2011UAS Duplicate Packets
Replies: 3
Views: 508

Re: RB2011UAS Duplicate Packets

vlan issue
by marklodge
Tue Aug 18, 2020 11:57 pm
Forum: General
Topic: Duplicate PPOE sessions with '1>' at end - Yet One session per host is allowed only
Replies: 6
Views: 1003

Re: Duplicate PPOE sessions with '1>' at end - Yet One session per host is allowed only

Okay, thanks. I found that option. It was disabled. So now in Splynx, both POD + clean and COA & POD is enabled. Should be fine right?
coa.PNG
by marklodge
Fri Aug 14, 2020 9:09 pm
Forum: Beginner Basics
Topic: Very Odd Throughput Issue
Replies: 2
Views: 819

Re: Very Odd Throughput Issue

do a speedtest from the mikrotik to a public btest server
by marklodge
Fri Aug 14, 2020 12:00 pm
Forum: General
Topic: Duplicate PPOE sessions with '1>' at end - Yet One session per host is allowed only
Replies: 6
Views: 1003

Re: Duplicate PPOE sessions with '1>' at end - Yet One session per host is allowed only

Any ideas? Also, just FYI - only-one=yes only takes effect when you are not using a RADIUS server. Thank you for this info. Yes, the radius server is doing something called POD+Clean according to the settings in Splynx. Is this sufficient and correct? (screenshot below) So, me seeing both sessions ...
by marklodge
Fri Aug 14, 2020 11:49 am
Forum: General
Topic: Has anyone seen this too: Youtube : An error occurred. Please try again later. (Playback ID: 3b_5eLEgWkNm33GA) [SOLVED]
Replies: 9
Views: 1863

Re: Has anyone seen this too: Youtube : An error occurred. Please try again later. (Playback ID: 3b_5eLEgWkNm33GA) [SOLVED]

If you want an adblocker for YouTube, use uBlock Origin. Works perfect.

Regards.
Excellent, thank you very much for being so helpful!
by marklodge
Fri Aug 14, 2020 2:30 am
Forum: General
Topic: Has anyone seen this too: Youtube : An error occurred. Please try again later. (Playback ID: 3b_5eLEgWkNm33GA) [SOLVED]
Replies: 9
Views: 1863

Re: Has anyone seen this too: Youtube : An error occurred. Please try again later. (Playback ID: 3b_5eLEgWkNm33GA) [SOLVED]

No the issue is with the person who controls the computer, they need a spanking!
seriously, whats bitten you??
by marklodge
Thu Aug 13, 2020 11:35 pm
Forum: General
Topic: Duplicate PPOE sessions with '1>' at end - Yet One session per host is allowed only
Replies: 6
Views: 1003

Duplicate PPOE sessions with '1>' at end - Yet One session per host is allowed only

Router: CCR1016. VER 6.47.1 PPPOE SERVER enabled on a 5 interfaces Config: name="PPPoE-Profile" local-address=10.2.2.1 use-mpls=default use-compression=default use-encryption=default [b]only-one=yes[/b] change-tcp-mss=yes use-upnp=default address-list="" dns-server=10.31.31.105,8.8.4.4 on-up="" on-d...
by marklodge
Thu Aug 13, 2020 11:18 pm
Forum: RouterOS v7 BETA
Topic: SSH connection issues with "fasttrack" switched off. [SOLVED]
Replies: 19
Views: 2817

Re: SSH connection issues with "fasttrack" switched off. [SOLVED]

post and
 /export hide-sensitive
here
by marklodge
Fri Aug 07, 2020 11:36 pm
Forum: General
Topic: Has anyone seen this too: Youtube : An error occurred. Please try again later. (Playback ID: 3b_5eLEgWkNm33GA) [SOLVED]
Replies: 9
Views: 1863

Has anyone seen this too: Youtube : An error occurred. Please try again later. (Playback ID: 3b_5eLEgWkNm33GA) [SOLVED]

Recently I am getting this when i try to open a youtube video. But after a couple of seconds it does actually play the video. And sometimes it does not.

An error occurred. Please try again later. (Playback ID: 3b_5eLEgWkNm33GA)
Learn More
snio.PNG
by marklodge
Wed Aug 05, 2020 1:34 am
Forum: RouterOS v7 BETA
Topic: SSH connection issues with "fasttrack" switched off. [SOLVED]
Replies: 19
Views: 2817

Re: SSH connection issues with "fasttrack" switched off. [SOLVED]

what happens if you disable all firewall rules?
does it work?
by marklodge
Sun Aug 02, 2020 10:55 pm
Forum: General
Topic: Backup Link
Replies: 2
Views: 796

Re: Backup Link

For no packet loss, reliability, and failover do not use a flat bridged network. Use dynamic routing
by marklodge
Sun Aug 02, 2020 10:53 pm
Forum: General
Topic: need help With Firewall RUles
Replies: 2
Views: 794

Re: need help With Firewall RUles

are these accept rules above all others?
by marklodge
Sun Aug 02, 2020 10:52 pm
Forum: General
Topic: Day Night Bandwidht Management
Replies: 1
Views: 545

Re: Day Night Bandwidht Management

use simple queues with scripts
by marklodge
Sun Aug 02, 2020 10:48 pm
Forum: General
Topic: mikrotik and telegram connection
Replies: 1
Views: 437

Re: mikrotik and telegram connection

This is a working export of the telegram api
/tool fetch url=\"https://api.telegram.org/bot812342342:AAGPKJHKJgjjfhfSWEWEV1qvxAKOIk/sendMessage\\\?chat_id=-YOUR-CHAT-ID&text=Test
by marklodge
Sun Aug 02, 2020 10:45 pm
Forum: Wireless Networking
Topic: WW 60Ghz Link - Routing breaks
Replies: 1
Views: 983

Re: WW 60Ghz Link - Routing breaks

An update on this.
Downgrading firmware to 6.44 fixes it and routing no longer breaks.
by marklodge
Sun Aug 02, 2020 10:37 pm
Forum: General
Topic: 4 isp Load balance NTH
Replies: 1
Views: 580

Re: 4 isp Load balance NTH

please post a diagram of the current setup and how you would like it changed
by marklodge
Sun Aug 02, 2020 10:35 pm
Forum: RouterOS v7 BETA
Topic: SSH connection issues with "fasttrack" switched off. [SOLVED]
Replies: 19
Views: 2817

Re: SSH connection issues with "fasttrack" switched off. [SOLVED]

Chateau C12 LTE, ROS v7.1beta1, LTE modem firmware EG12EAPAR01A06M4G . I have switched off default fasttrack for FORWARD chain in order to use QoS and prioritizing traffic. In default setup, I can connect to my SSH servers. If I switch off fasttrack , I will get an error after timeout: packet_write...
by marklodge
Fri Jul 31, 2020 6:08 pm
Forum: General
Topic: Masquerade rule on dynamic interface? [SOLVED]
Replies: 2
Views: 721

Re: Masquerade rule on dynamic interface? [SOLVED]

if the user can't connect more than once at a time, then you can simply create static "L2TP server binding" which will create your interface permanently. Alternative, possibly better way (no matter how many connections are we talking about) is to add profile, with selected "interface list". That is...
by marklodge
Fri Jul 31, 2020 5:49 am
Forum: General
Topic: Masquerade rule on dynamic interface? [SOLVED]
Replies: 2
Views: 721

Masquerade rule on dynamic interface? [SOLVED]

I want to Masquerade traffic out to a l2tp client. When the client is connected, it works. But when the client disconnects then the Masquerade NAT rule shows NO INTERFACE. I need the Masquerade rule to be active as soon as the l2tp client connects. How can I solve this? Please refer to screenshots m...
by marklodge
Mon Jul 27, 2020 12:28 am
Forum: General
Topic: Winbox 3.24 - bug on Open in New window
Replies: 3
Views: 1112

Re: Winbox 3.24 - bug on Open in New window

Report them to Anav?
Yes I see he picked it up. Good for you guys
by marklodge
Fri Jul 24, 2020 5:29 pm
Forum: Wireless Networking
Topic: WW 60Ghz Link - Routing breaks
Replies: 1
Views: 983

WW 60Ghz Link - Routing breaks

This may seem strange, but its true. The Mikrotik 60ghz WW link is breaking OSPF routing. Its a 200m link and signal is good. But it has happened 4 or five times now already. The routing breaks to all the routers connected via the 60ghz link. Then when I reboot the 60ghz link all if fine again. The ...
by marklodge
Sun Jul 19, 2020 3:21 am
Forum: General
Topic: Winbox 3.24 - bug on Open in New window
Replies: 3
Views: 1112

Winbox 3.24 - bug on Open in New window

Latest ver of winbox
Connect to romon,
tick Open in new window
connect to any router, it will disconnect and show another window, then it will connect once you press it again
by marklodge
Tue Jul 14, 2020 4:52 am
Forum: Forwarding Protocols
Topic: PPPoE + OSPF = Discarding packet: locally originated
Replies: 4
Views: 2196

Re: PPPoE + OSPF = Discarding packet: locally originated

We've found the cause of the OSPF errors (ms-configured switch) but the PPPoE drop outs still remain
i had the exact same issue
please tell me what was mis configured
by marklodge
Sun Jul 12, 2020 3:59 pm
Forum: Forwarding Protocols
Topic: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"
Replies: 6
Views: 2815

Re: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"

Run OSPF only on one subet connecting both routers. Check whether RouterIDs are unique.
Correct. I had this issue and solved it this way.
So, two routers connecting to each other had the range 10.2.0.0/22 area=external added.
On one router i changed the area to area14 and the errors disappeared
by marklodge
Tue Jun 30, 2020 5:01 pm
Forum: General
Topic: Doubt about PPPoE Local Address
Replies: 16
Views: 3743

Re: Doubt about PPPoE Local Address

.. So my question is, must the local address be attached to a physical / virtual interface? ... Sorry, don't think I was clear in my question, what I meant to ask was: So my question is, must the local address be " static " configured to a physical / virtual interface? This is my question too.
by marklodge
Tue Jun 23, 2020 5:44 am
Forum: Forwarding Protocols
Topic: A strange routing issue, works if OSPF is disabled
Replies: 6
Views: 2284

Re: A strange routing issue, works if OSPF is disabled

I have already told you the most straightforward way to pursue this issue. Let me know when you have performed it. Thank you very much, you helped me by pointing out the torch function. The issue was a firewall rule that was dropping invalid connections (default mikrotik firewall) Once that was dis...
by marklodge
Tue Jun 23, 2020 5:19 am
Forum: General
Topic: Doubt about PPPoE Local Address
Replies: 16
Views: 3743

Re: Doubt about PPPoE Local Address

1. Could you please give me some reasons or standard/"good" practices to use when setting the Local IP address of the PPPOE profile. I have 8 routers in an ospf ring. 1 core at the main tower and the others are on towers working as edge routers, with pppoe termination of clients happening on each r...
by marklodge
Sun Jun 21, 2020 1:05 am
Forum: General
Topic: Doubt about PPPoE Local Address
Replies: 16
Views: 3743

Re: Doubt about PPPoE Local Address

Unless you are going to use RFC1918 space for the local address, it's probably recommended that you don't use a pool. 1. Could you please give me some reasons or standard/"good" practices to use when setting the Local IP address of the PPPOE profile. I have 8 routers in an ospf ring. 1 core at the ...
by marklodge
Mon May 04, 2020 12:13 am
Forum: The Dude
Topic: How to show Interfaces on network map
Replies: 1
Views: 1006

How to show Interfaces on network map

So I have 10 mikrotik routers on different towers, each has around 15 interfaces connected to Ubiquiti radios (sectors) Is it possible to show the Interfaces as Devices on the network map? So, instead of adding each device, I would like to add the 10 mikrotik routers and have an exploded view of eac...
by marklodge
Tue Apr 14, 2020 4:12 am
Forum: General
Topic: RB4011 Visio Stencil
Replies: 0
Views: 1518

RB4011 Visio Stencil

Here is a quick mod which visualizes the RB4011. Everyone is welcome to improve it.
4011.zip
by marklodge
Tue Apr 07, 2020 1:48 am
Forum: Forwarding Protocols
Topic: A strange routing issue, works if OSPF is disabled
Replies: 6
Views: 2284

Re: A strange routing issue, works if OSPF is disabled

Your new figure contains nearly no IP address labels, so I can't follow your explanation. If you have determined that return routing of messages from 10.6.0.4 is failing with OSPF enabled, then run a traceroute from 10.6.0.4 to the original origin of the message, examine the results with OSPF disab...
by marklodge
Tue Apr 07, 2020 12:14 am
Forum: Forwarding Protocols
Topic: A strange routing issue, works if OSPF is disabled
Replies: 6
Views: 2284

Re: A strange routing issue, works if OSPF is disabled

You may be looking for the problem on the wrong unit. OSPF should be constructing reciprocal routes on the other unit, and those may be wrong. Torch the interface at 10.6.0.4 to see if your requests from 10.200.0.4 are arriving and departing. Torch the interface at 10.200.0.1 and I suspect you will...
by marklodge
Fri Apr 03, 2020 10:23 pm
Forum: Forwarding Protocols
Topic: A strange routing issue, works if OSPF is disabled
Replies: 6
Views: 2284

A strange routing issue, works if OSPF is disabled

Here is a diagram of the network, basically its just two routers with a wireless PtP link between them. MAP1.jpg So, the address of this side of the link is: 10.200.0.4/29 and the remote side is: add address=10.200.0.1/29 The issue is that if I disable the following I can access the remote pppoe cli...
by marklodge
Fri Dec 27, 2019 5:06 pm
Forum: Beginner Basics
Topic: Winbox For Mac OS Catalina
Replies: 1
Views: 944

Re: Winbox For Mac OS Catalina

must use wine
by marklodge
Fri Dec 27, 2019 5:01 pm
Forum: General
Topic: webconfig not working
Replies: 1
Views: 550

Re: webconfig not working

reset maybe?
by marklodge
Fri Dec 27, 2019 5:00 pm
Forum: General
Topic: Error FTP connection on 21 port
Replies: 5
Views: 956

Re: Error FTP connection on 21 port

on Port 221?
why
by marklodge
Fri Dec 27, 2019 4:58 pm
Forum: General
Topic: Problem with SFP module (S-85DLC05D) in CRS212-1G-10S-1S+IN
Replies: 1
Views: 562

Re: Problem with SFP module (S-85DLC05D) in CRS212-1G-10S-1S+IN

On the CRS switches I had this issue. Auto Negotiation does not work well. Set it to 10gb or 1gb manually
by marklodge
Fri Dec 27, 2019 4:56 pm
Forum: General
Topic: address list and netmap
Replies: 3
Views: 710

Re: address list and netmap

More info needed
by marklodge
Fri Dec 27, 2019 4:54 pm
Forum: General
Topic: DHCP Lease not showing up in DHCP Leases
Replies: 3
Views: 909

DHCP Lease not showing up in DHCP Leases

A Mikrotik router is the only DHCP server, giving out IPs on the range of 10.33.33.0/24 All working well for many months. Just today I added a new device and noticed that it did get an IP of 10.33.33.115 and no issues. But this DHCP Lease is NOT showing up in the DHCP Leases menu on the Mikrotik. Al...
by marklodge
Tue Nov 26, 2019 11:26 pm
Forum: Forwarding Protocols
Topic: 'Correct' Method of Public IP assignment [SOLVED]
Replies: 10
Views: 5195

Re: 'Correct' Method of Public IP assignment [SOLVED]

That's how it works with public addresses, you don't need any NAT. Nice, isn't it? :) Of course if you'll also connect some private subnets to your routers, you will need NAT for them. But it's important to use it selectively only for those subnets, and don't let it interfere with other public addr...
by marklodge
Tue Nov 26, 2019 1:13 am
Forum: Forwarding Protocols
Topic: 'Correct' Method of Public IP assignment [SOLVED]
Replies: 10
Views: 5195

Re: 'Correct' Method of Public IP assignment [SOLVED]

Default gateway on your CCRs should be 45.45.45.1. And PPPoE client will have whatever is PPPoE server's local address (this part clearly works, if it can access internet). But I'm not sure if I believe you about no NAT rules. Maybe you didn't add no new NAT rules, but what about original masquerad...
by marklodge
Sun Nov 24, 2019 1:50 am
Forum: Forwarding Protocols
Topic: 'Correct' Method of Public IP assignment [SOLVED]
Replies: 10
Views: 5195

Re: 'Correct' Method of Public IP assignment [SOLVED]

1) If you didn't need dstnat with masquerade, you don't need it with srcnat either. Those things are not really related, each one serves different purpose. 2) That's the one. 3) Yes, two subnets on same interface and routing between them is possible, router doesn't mind. Although in your case you m...
by marklodge
Sun Nov 17, 2019 7:00 am
Forum: Forwarding Protocols
Topic: 'Correct' Method of Public IP assignment [SOLVED]
Replies: 10
Views: 5195

Re: 'Correct' Method of Public IP assignment [SOLVED]

The correct (or let's say most usual and compatible) way is to *not* use some of "my" configs. But in a desperate world where IPv4 addresses are scarse, desperate measures are sometimes required. :) Basic scheme is that you have some connecting subnet between you and ISP and another subnet routed t...
by marklodge
Sat Nov 16, 2019 9:28 am
Forum: RouterBOARD hardware
Topic: Does CRS328-24P-4S+RM support 24v passive poe?
Replies: 20
Views: 6115

Re: Does CRS328-24P-4S+RM support 24v passive poe?

Thanks. And special thanks to the kind people who answered my post. I have downloaded the quick guide and here i have copied the relevant info: Power output This device can supply PoE powering to external devices from its Ethernet ports. The output voltage will be selected automatically, depending o...
by marklodge
Fri Nov 15, 2019 12:30 pm
Forum: Forwarding Protocols
Topic: 'Correct' Method of Public IP assignment [SOLVED]
Replies: 10
Views: 5195

'Correct' Method of Public IP assignment [SOLVED]

I have searched through this forum and read the threads regarding public IP assignment, alot of which was replied to by 'Sob' Even though this has given me a an idea about how to go bout doing it, I still want to know the "industry standard" (if there is) or the most common ways this is usually acco...
by marklodge
Sun Nov 10, 2019 6:49 pm
Forum: RouterBOARD hardware
Topic: Does CRS328-24P-4S+RM support 24v passive poe?
Replies: 20
Views: 6115

Re: Does CRS328-24P-4S+RM support 24v passive poe?

Before you ask such questions here, you could simply check device specification section. If you did not find an answer on your question there, please take a look at brochure where you could find more detailed information and device description. https://i.mt.lv/cdn/rb_files/CR328-24P-4SplusRM-180424...
by marklodge
Sun Oct 13, 2019 6:55 pm
Forum: General
Topic: bridge1 dynamically being added as an untagged port.
Replies: 6
Views: 1019

Re: bridge1 dynamically being added as an untagged port.

Does this mean the wiki is incorrect?
Which part of which document do you have in mind?
Please refer to attached pic
by marklodge
Sun Oct 13, 2019 5:19 pm
Forum: General
Topic: bridge1 dynamically being added as an untagged port.
Replies: 6
Views: 1019

Re: bridge1 dynamically being added as an untagged port.

Bridge interface , which gets created implicitly for any bridge bridge , is implicitly created as untagged member of VLAN with VID=1 (which makes using VLAN VID=1 in the rest of config so exciting). You can change that if you set pvid on bridge interface to something else ... but you can not make b...
by marklodge
Sat Oct 12, 2019 2:29 pm
Forum: General
Topic: bridge1 dynamically being added as an untagged port.
Replies: 6
Views: 1019

bridge1 dynamically being added as an untagged port.

I am following this: https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table It states that: Note: When frame-type=admit-only-vlan-tagged is used on a port, then the port is not dynamically added as untagged port for the PVID. But i am still getting it added as an untagged port. What am I missing? F...
by marklodge
Sat Oct 12, 2019 2:08 pm
Forum: General
Topic: RoMON Transcends all types of VLAN filtering
Replies: 0
Views: 530

RoMON Transcends all types of VLAN filtering

I am following this: https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table
But even after deploying the strictest measures, like ingress filtering, admit only tagged and even tag stacking, RoMON is still able to connect to it from another romon enabled router. Is this normal?
by marklodge
Mon Oct 07, 2019 12:19 am
Forum: General
Topic: Link failover without co-location noise
Replies: 2
Views: 1682

Re: Link failover without co-location noise

The above config does not seem to work out, instead I have decided to build a netwatch on the two poe switches only to power up/ power down the links accordingly.
by marklodge
Sun Oct 06, 2019 1:15 pm
Forum: General
Topic: Link failover without co-location noise
Replies: 2
Views: 1682

Link failover without co-location noise

Goal: To have 2 ptp links from and edge tower to the main tower. But only one of them should be powered on at the same time. If one link fails the other link powers up and data is sent over there. Reason: If both links are running all the time, the same frequency cannot be used, increases co locatio...
by marklodge
Sun Sep 29, 2019 1:26 pm
Forum: RouterBOARD hardware
Topic: Does CRS328-24P-4S+RM support 24v passive poe?
Replies: 20
Views: 6115

Does CRS328-24P-4S+RM support 24v passive poe?

Does CRS328-24P-4S+RM support 24v passive poe?

https://mikrotik.com/product/crs328_24p_4s_rm

I need to power around 20 x UBNT Rocket Prisms/air fiber and LHGs.
by marklodge
Fri Aug 16, 2019 9:05 am
Forum: General
Topic: DHCP server assigns .0 IP
Replies: 2
Views: 619

DHCP server assigns .0 IP

I have a dhcp server that assigns IPs from 172.16.1.10-17..16.3.10. Now when it reaches the end of 172.16.0. range, the next IP it assigns is 172.16.1.0 How can I set the DHCP server to not assign the .0 IP of each range

Attached screenshot
by marklodge
Wed Aug 07, 2019 2:04 am
Forum: General
Topic: Mikrotik DNS Cache vs BIND9/Unbound server
Replies: 7
Views: 1714

Re: Mikrotik DNS Cache vs BIND9/Unbound server

I can't tell how much will 4k devices need, it depends on what they do and it can vary greatly. The same goes for concurrency limits. It's not like normal device sends dns queries all the time, so average rate should not be high. You should have some space for spikes, again the same thing. I'm big ...
by marklodge
Wed Aug 07, 2019 12:56 am
Forum: General
Topic: Mikrotik DNS Cache vs BIND9/Unbound server
Replies: 7
Views: 1714

Re: Mikrotik DNS Cache vs BIND9/Unbound server

Your 10GB plan probably won't work, I think it uses only RAM. But it's unlikely that you'd ever need that much anyway, records time out, they don't last forever. But it of course depends on how big network you have. Other than that, all resolvers are same in principle. If you need only bare basics,...
by marklodge
Tue Aug 06, 2019 10:34 pm
Forum: General
Topic: Mikrotik DNS Cache vs BIND9/Unbound server
Replies: 7
Views: 1714

Mikrotik DNS Cache vs BIND9/Unbound server

Purely from a DNS caching only perspective. Is a standalone BIND or Unbound DNS Caching server much different to Mikrotiks DNS cache feature? I have 7 towers, each has a mikrotik router acting as a PPPOE server, so I am thinking that I should just increase the cache size to like 10GB (using SD card ...
by marklodge
Tue Jun 04, 2019 8:29 am
Forum: General
Topic: Is CCR CPUs Physical Cores or threads?
Replies: 4
Views: 987

Re: Is CCR CPUs Physical Cores or threads?

I'm using it for a core router with 1gbps traffic, serving 800 clients, meaning many thousands of packets per second. My current CCR 1016 is showing around 36k p/s on the main WAN interface. And one of the CPU cores are 95% usage all the time, while the others are around 0 to 20% used. When you say ...
by marklodge
Fri May 31, 2019 11:43 pm
Forum: General
Topic: Is CCR CPUs Physical Cores or threads?
Replies: 4
Views: 987

Is CCR CPUs Physical Cores or threads?

I am reading the specs here:
https://mikrotik.com/product/CCR1036-12G-4S-EM
It says 36 cores x 1.2GHz CPU. Is this 36 cores? or 36 threads?

Please confirm

And what would be the x86 comparision to this?
Would a 4 core Dell poweredge server perform better than this CCR for routing/firewall etc?
by marklodge
Wed Apr 24, 2019 5:51 pm
Forum: General
Topic: Devices in VLAN in Management Bridge unreachable
Replies: 10
Views: 1304

Re: Devices in VLAN in Management Bridge unreachable

Why not just cut and paste and use the code block in the FONT line a the top of the EDIT block.
My firewall/AV setup
    blocks pastebin LOL.
    Because it was rather large, but I've did as you said.
    by marklodge
    Wed Apr 24, 2019 5:26 pm
    Forum: General
    Topic: Devices in VLAN in Management Bridge unreachable
    Replies: 10
    Views: 1304

    Re: Devices in VLAN in Management Bridge unreachable

    i dont play whackamole with attempting to solve config issues. Just remove any sensitive bits (dont need to see any vpn stuff, dhcp leases, any firewall address lists, etc............. as a minimum interface ethernet ip addresses vlan config bridge config bridge port config birdge vlan config dhcp-...
    by marklodge
    Wed Apr 24, 2019 3:51 pm
    Forum: General
    Topic: Devices in VLAN in Management Bridge unreachable
    Replies: 10
    Views: 1304

    Re: Devices in VLAN in Management Bridge unreachable

    post your config
    /export hide-sensitive file=yourconfig
    Well, the original post is a very simplified version of my config. My actual config is more complex. Could I PM you my output?
    by marklodge
    Wed Apr 24, 2019 3:45 pm
    Forum: General
    Topic: Devices in VLAN in Management Bridge unreachable
    Replies: 10
    Views: 1304

    Devices in VLAN in Management Bridge unreachable

    I have 4 devices, each of them has management vlan enabled as VLAN 10. 2 devices are connected to ether2 and the other 2 devices are connected to ether3 So, I create a VLAN with ID 10 on ether2 and another VLAN 10 on ether3. Then I create a Bridge called Management Bridge and give it an IP of 172.16...
    by marklodge
    Tue Mar 05, 2019 4:52 pm
    Forum: Forwarding Protocols
    Topic: How do I route a WAN IP to a PPPOE Client connected to an Edge router?
    Replies: 2
    Views: 1793

    Re: How do I route a WAN IP to a PPPOE Client connected to an Edge router?

    From my understanding you should just have to use a NAT rule to forward all traffic for the WAN to the IP of the pppoe client then a NAT rule to translate all traffic from pppoe client to the specific WAN IP. /ip firewall nat add chain=dstnat dst-address=45.45.45.2 action=dst-nat to-addresses=10.2....
    by marklodge
    Fri Mar 01, 2019 7:25 pm
    Forum: Forwarding Protocols
    Topic: How do I route a WAN IP to a PPPOE Client connected to an Edge router?
    Replies: 2
    Views: 1793

    How do I route a WAN IP to a PPPOE Client connected to an Edge router?

    How do I route a WAN IP to a PPPOE Client connected to an Edge router?
    Here is a diagram that explains it all
    wan-topppoe-edge.png
    by marklodge
    Fri Mar 01, 2019 6:53 pm
    Forum: Forwarding Protocols
    Topic: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"
    Replies: 6
    Views: 2815

    Re: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"

    RouterIDs are unique
    If I run the subnet on one router only it does not propagate the clients on the router that the subnet is not running on.
    by marklodge
    Wed Feb 27, 2019 4:56 pm
    Forum: Forwarding Protocols
    Topic: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"
    Replies: 6
    Views: 2815

    Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"

    I want to be able to reach my clients CPE.

    This is my setup: and I'm getting the error mentioned
    The small circles represent pppoe-clients IP
    11.png
    by marklodge
    Sun Feb 24, 2019 9:42 am
    Forum: General
    Topic: How do I enable my network for IPv6
    Replies: 5
    Views: 775

    Re: How do I enable my network for IPv6

    Thank you for the reply.
    Would I need to change my network topology for ipv6 to work?
    Will it work over the current pppoe setup?

    Could you link me to some good resources to understand this better?
    by marklodge
    Sat Feb 23, 2019 10:37 am
    Forum: General
    Topic: How do I enable my network for IPv6
    Replies: 5
    Views: 775

    How do I enable my network for IPv6

    I have a WISP setup. Simple PTMP and CPEs in router mode connecting via PPPOE How do I enable IPv6 for clients? I have the Mikrotik IPv6 package installed and enabled My WAN interface shows an IPv6 address SLAAC is enabled on CPE But my computer connected to the CPE does not receive an IPv6 address,...
    by marklodge
    Tue Feb 05, 2019 2:52 am
    Forum: General
    Topic: How can I add all of urlhaus's list of malware urls to a block list?
    Replies: 1
    Views: 484

    How can I add all of urlhaus's list of malware urls to a block list?

    How can I add all of urlhaus's list of malware urls to a block list?
    https://urlhaus.abuse.ch/api/#retrieve
    by marklodge
    Sun Dec 30, 2018 4:38 am
    Forum: Forwarding Protocols
    Topic: MPLS LDP Neighbor Addresses Blank
    Replies: 6
    Views: 2643

    Re: MPLS LDP Neighbor Addresses Blank

    Should the MTU be set on the VPLS tunnels or on the ether interfaces, or both?
    by marklodge
    Mon Dec 03, 2018 2:14 pm
    Forum: General
    Topic: LInk broken
    Replies: 0
    Views: 397

    LInk broken

    by marklodge
    Wed Oct 03, 2018 10:26 pm
    Forum: General
    Topic: Specific WAN IP per user group
    Replies: 2
    Views: 475

    Re: Specific WAN IP per user group

    /ip firewall nat add chain=srcnat out-interface-list=WAN src-address-list=group1 action=srcnat to-address=45.45.45.2 add chain=srcnat out-interface-list=WAN src-address-list=group2 action=srcnat to-address=45.45.45.3 And then disable/remove default masquerade rule. Thank you for this, I will try im...
    by marklodge
    Wed Oct 03, 2018 2:19 pm
    Forum: General
    Topic: Specific WAN IP per user group
    Replies: 2
    Views: 475

    Specific WAN IP per user group

    I have 500 pppoe clients and I have 5 WAN IPs from my provider
    How do I set a different WAN IP for each 100 users?

    Example:
    4mb User group will use: 45.45.45.2
    2mb User group will use: 45.45.45.3
    etc
    by marklodge
    Tue Oct 02, 2018 11:18 am
    Forum: General
    Topic: Help with Google Unusual Traffic issue
    Replies: 3
    Views: 1370

    Re: Help with Google Unusual Traffic issue

    Are all your 500 clients sharing the same address? Then this issue really cannot be avoided, because there will always be bad guys in there. However, you should still make sure your router and any client routers that you manage are properly configured and not part of the botnet. Yes, all are sharin...
    by marklodge
    Tue Oct 02, 2018 11:02 am
    Forum: General
    Topic: Help with Google Unusual Traffic issue
    Replies: 3
    Views: 1370

    Help with Google Unusual Traffic issue

    Environment: MikroTik CCR1016 as Core router Static IP 500 PPPoE connected clients Recently we've been getting the Unusual Traffic warning when doing a Google Search.Copied below: About this page Our systems have detected unusual traffic from your computer network. This page checks to see if it's r...
    by marklodge
    Fri Sep 28, 2018 10:37 am
    Forum: Wireless Networking
    Topic: Can I run separate Hotspot servers per VLAN?
    Replies: 8
    Views: 1355

    Re: Can I run separate Hotspot servers per VLAN?

    As I recall, the NanoStation will happily pass VLAN traffic and is VLAN aware for the management interface, but I'm not aware of the ability to specify which VLAN to use for locally connected stations. Note that I am using them for a point to point link with a managed switch (CSS326-24G-2S) on each...
    by marklodge
    Fri Sep 28, 2018 9:52 am
    Forum: Wireless Networking
    Topic: Can I run separate Hotspot servers per VLAN?
    Replies: 8
    Views: 1355

    Re: Can I run separate Hotspot servers per VLAN?

    Also models with QCA8337, Atheros8327, Atheros8316 switch chips seem to be able to use the same method as for CRS3xx, but their rule tables are smaller.
    This is inaccurate, I tested the CRS3xx method on the Atheros8327 chip, but New VLAN ID is not supported
    by marklodge
    Wed Sep 26, 2018 4:03 pm
    Forum: General
    Topic: RB CCR1016 specs question
    Replies: 0
    Views: 368

    RB CCR1016 specs question

    While reading the datasheet here, these specs confused me:

    • Up to 1.5 mpps throughput in regular mode
    • Up to 17.8 mpps throughput in fastpath mode (wire speed)
    • Up to 12 Gbps throughput with RouterOS queue/firewall configuration



    What does Up to 1.5 mpps throughput in regular mode mean?
    by marklodge
    Fri Aug 31, 2018 5:07 pm
    Forum: Scripting
    Topic: Retrieve list of PPP Active and compare with ppp secrets
    Replies: 8
    Views: 3442

    Re: Retrieve list of PPP Active and compare with ppp secrets

    You will then get usage data per customer that let you create simple bandwidth usage graphs, Thank you, I understand all that you have said, I will now setup a freeradius server and check it out. So, instead of sending the ppp secrets I will just be sending the same details to the Radius MySQL data...
    by marklodge
    Wed Aug 29, 2018 12:06 am
    Forum: Scripting
    Topic: Get traffic usage via PEAR2 API
    Replies: 2
    Views: 1309

    Re: Get traffic usage via PEAR2 API

    Using a specialized tool that analyzes SNMP and/or Netflow to generate a graph would be most efficient for the router indeed. If you're OK with sacrificing some of that efficiency for the purposes of customizable implementation, the other way would be to detect a new PPPoE interface appearing (see ...
    by marklodge
    Tue Aug 28, 2018 11:58 pm
    Forum: Scripting
    Topic: Retrieve list of PPP Active and compare with ppp secrets
    Replies: 8
    Views: 3442

    Re: Retrieve list of PPP Active and compare with ppp secrets

    If you have shell access to your web server, you can run a PHP from the command line. You can also add it as a startup script if you want it to also restart with a server restart. Or use cron if you want to run it at regular intervals rather than continuously. If you run it continuously, you can us...
    by marklodge
    Tue Aug 28, 2018 11:56 pm
    Forum: Scripting
    Topic: Retrieve list of PPP Active and compare with ppp secrets
    Replies: 8
    Views: 3442

    Re: Retrieve list of PPP Active and compare with ppp secrets

    I have a MySQL db of all ppp secrets, these get sent to the mikrotik via the PEAR2 API. I need to see how many of the ppp clients are active and then mark them as active on the local mysql db. Is there a reason you aren't just using RADIUS (ex. FreeRADIUS), which does all this for you (and more)? 1...
    by marklodge
    Tue Aug 28, 2018 11:47 pm
    Forum: General
    Topic: Priority on Simple Queue Parents
    Replies: 1
    Views: 555

    Priority on Simple Queue Parents

    I read here https://wiki.mikrotik.com/wiki/Manual:Queue that Priority Does not work on parent queue But I wish to confirm, as I have seen that dynamically created parent queues by some ISP Framework software has priorities set If I have the following parents and children: 2mbps-Home-Priority=5/5 -fr...
    by marklodge
    Fri Aug 24, 2018 1:10 am
    Forum: General
    Topic: Tag MAC address with VLAN ID
    Replies: 5
    Views: 1694

    Re: Tag MAC address with VLAN ID

    I would like to know the same:
    is there a way to tag packets from a specific MAC address(es) with a VLAN id?
    by marklodge
    Fri Aug 24, 2018 1:00 am
    Forum: Wireless Networking
    Topic: Can I run separate Hotspot servers per VLAN?
    Replies: 8
    Views: 1355

    Re: Can I run separate Hotspot servers per VLAN?

    Yes, you can. All you need do is select the vlan interface while creating the hotspot for that vlan. You can check out my post on hotspot here. https://www.timigate.com/2017/11/how-to-solve-all-your-mikrotik-hotspot.html I have checked your post. I do understand that I can run a hotspot server on a...
    by marklodge
    Fri Aug 17, 2018 3:34 pm
    Forum: Scripting
    Topic: Get traffic usage via PEAR2 API
    Replies: 2
    Views: 1309

    Get traffic usage via PEAR2 API

    I wish to see how much bandwidth was used per PPP connection, how would I do this via API, I understand that the options are probably Graphing, SNMP or Netflow.
    I just need the simplest way for now. I need to get the usage and create monthly, weekly graphs.
    by marklodge
    Fri Aug 17, 2018 1:44 am
    Forum: Wireless Networking
    Topic: Can I run separate Hotspot servers per VLAN?
    Replies: 8
    Views: 1355

    Re: Can I run separate Hotspot servers per VLAN?

    This can be accomplished using MAC Based VLANs, correct?
    by marklodge
    Fri Aug 17, 2018 1:27 am
    Forum: Scripting
    Topic: Retrieve list of PPP Active and compare with ppp secrets
    Replies: 8
    Views: 3442

    Retrieve list of PPP Active and compare with ppp secrets

    I have read this: https://forum.mikrotik.com/viewtopic.php?t=78145 But it is not working for me My application: I have a MySQL db of all ppp secrets, these get sent to the mikrotik via the PEAR2 API. I need to see how many of the ppp clients are active and then mark them as active on the local mysql...
    by marklodge
    Mon Aug 13, 2018 12:09 am
    Forum: Scripting
    Topic: Scripting and [] commands in PEAR2_Net_RouterOS [SOLVED]
    Replies: 2
    Views: 912

    Scripting and [] commands in PEAR2_Net_RouterOS [SOLVED]

    Using PEAR2_Net_RouterOS-1.0.0b6 The following works fine the in the Mikrotik Terminal. But I cant get it to work via the API. How would I do the following: :foreach user in=[/ip firewall address-list find find address=10.2.2.2] do={ /ip firewall address-list disable $user } Or ip firewall address-l...
    by marklodge
    Sat Aug 11, 2018 11:27 am
    Forum: Scripting
    Topic: Class 'Phar' not found in /home/sharedhost/mysite/PEAR2_Net_RouterOS-1.0.0b6.phar on line 18
    Replies: 2
    Views: 1144

    Re: Class 'Phar' not found in /home/sharedhost/mysite/PEAR2_Net_RouterOS-1.0.0b6.phar on line 18

    For some reason your shared host doesn't have the Phar extension, which is required to open PHAR files. It may be using PHP 5.2 or earlier, where Phar was not enabled by default, or it may be disabled by the host for some reason. If the problem is 5.2, there's no workaround - find a different host ...
    by marklodge
    Fri Aug 10, 2018 10:10 pm
    Forum: Scripting
    Topic: Class 'Phar' not found in /home/sharedhost/mysite/PEAR2_Net_RouterOS-1.0.0b6.phar on line 18
    Replies: 2
    Views: 1144

    Class 'Phar' not found in /home/sharedhost/mysite/PEAR2_Net_RouterOS-1.0.0b6.phar on line 18

    Hi
    I have everything working fine on my local xampp install. I uploaded it to my shared hosting package and I get the following error:
     PHP Fatal error:  Class 'Phar' not found in /home/sharedhost/mysite/PEAR2_Net_RouterOS-1.0.0b6.phar on line 18
    by marklodge
    Tue Aug 07, 2018 10:21 am
    Forum: General
    Topic: [REPOST TO CORRECT SECTION]
    Replies: 0
    Views: 404

    [REPOST TO CORRECT SECTION]

    I think that I posted in the wrong section, should I copy it here or just link it:

    This is the post:
    viewtopic.php?f=7&t=137675
    by marklodge
    Sun Aug 05, 2018 12:33 pm
    Forum: Wireless Networking
    Topic: Can I run separate Hotspot servers per VLAN?
    Replies: 8
    Views: 1355

    Can I run separate Hotspot servers per VLAN?

    Attached diagram shows what I wish to accomplish. The idea is just to separate the traffic per AP, so that I can see count of users connected and traffic stats per AP. How can I accomplish this? The APs are Nanostation M2s, they support VLAN per interface [WLAN0.LAN0, or BRIDGE0]. hotspotPerVLAN.png
    by marklodge
    Tue Jul 31, 2018 2:22 pm
    Forum: Forwarding Protocols
    Topic: Why does the VPLS interface need to be added to a bridge?
    Replies: 1
    Views: 629

    Why does the VPLS interface need to be added to a bridge?

    Following this: https://wiki.mikrotik.com/wiki/Transparently_Bridge_two_Networks_using_MPLS I need to know, in a setup where I am using the tunnel as a psuedo wire from the main tower to a sub tower, does the VPLS interface need to be added to a bridge? The tunnel works fine without being added to a...
    by marklodge
    Fri Jul 27, 2018 4:30 pm
    Forum: General
    Topic: Hosting a server [SOLVED]
    Replies: 6
    Views: 1022

    Re: Hosting a server [SOLVED]

    Are you able to not use the Cisco? Does it provide any other purpose? Personally, I'd still not be using it.. Just connecting the fiber directly to the Mikrotik. No, the Cisco is leased to us by the fiber provider, actually we dont have access to it, only physical access of course, so that we can p...
    by marklodge
    Tue Jul 24, 2018 11:10 am
    Forum: General
    Topic: Hosting a server [SOLVED]
    Replies: 6
    Views: 1022

    Re: Hosting a server [SOLVED]

    Sorry guys if I was not clear. 1. No this is not a homework question, this is for a real world deployment. 2. The cisco is leased to us by the fiber supplier, it is the Fiber Termination point. The Mikrotik is our own router, which we use to supply internet to the users. 3. The fiber supplier gives ...
    by marklodge
    Tue Jul 24, 2018 1:08 am
    Forum: General
    Topic: Hosting a server [SOLVED]
    Replies: 6
    Views: 1022

    Hosting a server [SOLVED]

    Attached diagram is my setup

    Should I connect the server to the mikrotik or the cisco ?
    acmetube.png
    by marklodge
    Tue Jul 17, 2018 6:27 pm
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Re: Mikrotik Email Support is Extremely Frustrating!

    Thats exactly it, you said:
    If you add mine before them, it will allow queries for specific hostname
    But it does not do this. [I adjusted it to myisp.com of course]
    by marklodge
    Tue Jul 17, 2018 6:21 pm
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Re: Mikrotik Email Support is Extremely Frustrating!

    I had thought that the solution received from Mikrotik was workable, but it is not, as it drops connections from the router itself too. So now, the router cannot resolve DNS or ping or anything.
    by marklodge
    Tue Jul 17, 2018 3:45 pm
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Re: Mikrotik Email Support is Extremely Frustrating!

    Then allow dns requests for hotspot.com (put the filter rule before the blocking ones): /ip firewall layer7-protocol add name="dns hotspot.com" regexp="\\x07hotspot\\x03com.\\x01" /ip firewall filter add action=accept chain=input dst-port=53 layer7-protocol="dns hotspot.com" protocol=udp Not ideal,...
    by marklodge
    Tue Jul 17, 2018 3:40 pm
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Re: Mikrotik Email Support is Extremely Frustrating!

    Why not drop DNS to everything except where you need it ?
    Thank you to the previous poster for the workaround, since he said it is not ideal. I am eager to know what your solution was. Please post it for our benefit
    by marklodge
    Mon Jul 16, 2018 2:50 pm
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Re: Mikrotik Email Support is Extremely Frustrating!

    You said you received a workable solution, was it something else, if you are asking it again? The solution i received was to drop all DNS traffic, which is workable. But your solution would be better, if I can allow DNS only where I need it that would be great. I need DNS only to resolve the hotspo...
    by marklodge
    Mon Jul 16, 2018 2:35 pm
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Re: Mikrotik Email Support is Extremely Frustrating!

    Sorry, but in my opinion the first response contains everything you need to know, to resolve your issue (if your suspicions are correct, of course). Why not drop DNS to everything except where you need it ? What is unclear in those emails ? Why not drop DNS to everything except where you need it ? ...
    by marklodge
    Mon Jul 16, 2018 2:33 pm
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Re: Mikrotik Email Support is Extremely Frustrating!

    And your opinion, sir, is certainly better than mine. Just an update, fair is fair and all that, 2 minutes after this post I received a reply from mikrotik, with a workable solution. And about 2 hours after this post I received another reply to my second ticket. Amazing
    by marklodge
    Mon Jul 16, 2018 9:45 am
    Forum: General
    Topic: Mikrotik Email Support is Extremely Frustrating!
    Replies: 13
    Views: 1405

    Mikrotik Email Support is Extremely Frustrating!

    Is it just me that finds Mikrotik email support very unhelpful? For example, look at this email exchange: First, I state the issue and ask for soultions: >>>> I have an issue here with users stealing internet via apps like Freedom >>>> and HTTP injectors. >>>> AFAIK they can do this because mikrotik...
    by marklodge
    Sun Jul 15, 2018 5:26 pm
    Forum: Wireless Networking
    Topic: Drop all traffic besides port 80 for unauthorized hotspot users
    Replies: 4
    Views: 974

    Re: Drop all traffic besides port 80 for unauthorized hotspot users

    but how would they log in? [/i] from my op: They should be only allowed access to the hotspot portal, ie: 192.168.88.2 on port 80 only You realize that most devices are going to detect they are on a hotspot/proxied network and send them to the login page? exactly, they will be directed to http://19...
    by marklodge
    Sat Jul 14, 2018 4:50 pm
    Forum: Wireless Networking
    Topic: Drop all traffic besides port 80 for unauthorized hotspot users
    Replies: 4
    Views: 974

    Re: Drop all traffic besides port 80 for unauthorized hotspot users

    Ah, but you have not understood my post.
    I asked:
    How do I drop all traffic coming from unauthorized hotspot users?

    Meaning, once they are authorized they can access any site, any port.
    by marklodge
    Sat Jul 14, 2018 12:55 pm
    Forum: Wireless Networking
    Topic: Drop all traffic besides port 80 for unauthorized hotspot users
    Replies: 4
    Views: 974

    Drop all traffic besides port 80 for unauthorized hotspot users

    I have a simple hotspot running, i dont need dns to resolve to the hotspot portal. My hotspot portal address is 192.168.88.2 How do I drop all traffic coming from unauthorized hotspot users? I want to drop all DNS, ICMP, any and all protocols and ports for unauthorized users. The only thing that the...
    by marklodge
    Tue Jun 26, 2018 6:15 pm
    Forum: Wireless Networking
    Topic: How to block DNS and other protocols for unauthorized hotspot users?
    Replies: 2
    Views: 627

    Re: How to block DNS and other protocols for unauthorized hotspot users?

    My question:
    I have a Hotspot running. If I drop all DNS requests clients will not be able to resolve the hotspot portal address!
    by marklodge
    Tue Jun 26, 2018 6:13 pm
    Forum: Wireless Networking
    Topic: How to block DNS and other protocols for unauthorized hotspot users?
    Replies: 2
    Views: 627

    Re: How to block DNS and other protocols for unauthorized hotspot users?

    This is a reply from mikrotik support
    Hello,

    You can add firewall filter rules that drop DNS requests to your router. You can learn how to configure firewall rules from this wiki page:

    https://wiki.mikrotik.com/wiki/Manual:I ... all/Filter

    Best regards,
    Martins S.
    --
    by marklodge
    Mon Jun 25, 2018 2:10 am
    Forum: Wireless Networking
    Topic: How to block DNS and other protocols for unauthorized hotspot users?
    Replies: 2
    Views: 627

    How to block DNS and other protocols for unauthorized hotspot users?

    I have an issue here with users stealing internet via apps like Freedom and HTTP injectors.
    AFAIK they can do this because mikrotik hotspot allows DNS requests for unauthorized users

    Any solutions?
    by marklodge
    Mon Jun 04, 2018 3:00 pm
    Forum: Scripting
    Topic: Help with PHP API
    Replies: 3
    Views: 2675

    Re: Help with PHP API

    Im getting this error. the protected array. Also the parent is created but why does this happen Fatal error: Uncaught PEAR2\Net\RouterOS\RouterErrorException: Router returned error when adding items in phar://C:/mikrotikweb/PEAR2_Net_RouterOS-1.0.0b6.phar/PEAR2_Net_RouterOS-1.0.0b6/src/PEAR2/Net/Rou...
    by marklodge
    Sun Jun 03, 2018 11:49 am
    Forum: Scripting
    Topic: Help with PHP API
    Replies: 3
    Views: 2675

    Help with PHP API

    I have the following working perfectly in Delphi. But i don't know how to run the same in PHP. How do I do the following using PHP API: Eg: 1 /ppp/secret/remove =numbers=testuser Eg: 2 /ppp/secret/add =name=testuser =password=testpass =remote-address=10.1.1.1 Eg: 3 /ppp/secret/print =count-only Eg: ...
    by marklodge
    Wed Apr 25, 2018 10:05 pm
    Forum: Forwarding Protocols
    Topic: Static routing instead of OSPF
    Replies: 2
    Views: 746

    Static routing instead of OSPF

    I have a ring of 7 routers, running MPLS and VPLS with OSPF routing.
    I am picking up high latency issues between two points, so I suspect looping somewhere along the line.
    I am thinking about cancelling OSPF routing and just creating static routes, what are your thoughts?
    by marklodge
    Tue Apr 24, 2018 2:30 pm
    Forum: Scripting
    Topic: How do I add more than 128 child IP addresses in a parent queue?
    Replies: 0
    Views: 490

    How do I add more than 128 child IP addresses in a parent queue?

    We are developing a Queue Tree contention application, this app connects to the mikrotik routers and does the rate limiting per contention basis. But we cant seem to add more than 128 childrent toa single parent. How do I add more than 128 child IP addresses in a parent queue? I'm using this for con...
    by marklodge
    Sat Apr 07, 2018 1:49 am
    Forum: Wireless Networking
    Topic: LAN IP Telephony on Mikrotik? Voice VLAN?
    Replies: 2
    Views: 1481

    LAN IP Telephony on Mikrotik? Voice VLAN?

    I was watching this tutorial regarding voip and IP telephony on Cisco: https://www.youtube.com/watch?v=QRmHqTLe260 The video demonstrates how an IP phone can be auto configured from the router and then able to call another phone over the lan. How would I do the same with Mikrotik? Or, what is the Mi...
    by marklodge
    Tue Mar 20, 2018 10:57 am
    Forum: Wireless Networking
    Topic: "Best" way to load balance traffic over 2 or more wireless links
    Replies: 4
    Views: 802

    Re: "Best" way to load balance traffic over 2 or more wireless links


    And buying 5x Mikrotik links, then you are Abel tu buy one link who can deliver 500MBit directly
    What type of link will deliver 500mbps? Are you positive that it will be the same price as buying 5 x ptp radios?
    by marklodge
    Mon Mar 19, 2018 3:12 pm
    Forum: Wireless Networking
    Topic: "Best" way to load balance traffic over 2 or more wireless links
    Replies: 4
    Views: 802

    "Best" way to load balance traffic over 2 or more wireless links

    I have two mikrotiks in two different locations. I wish to create an aggregated link of 500mbps speed between the two using 5 x 100mbps speed radios. How could I achieve this? Secondly, what are your thoughts on filtering traffic per link, for example, all torrent downloads use Link1, all http use l...
    by marklodge
    Sun Mar 18, 2018 1:32 pm
    Forum: Wireless Networking
    Topic: Dummy modem page
    Replies: 1
    Views: 396

    Dummy modem page

    I have a mikrotik as a hotspot with modem connected to ether1. My modem IP is 10.0.0.1. Everyone on the hotspot can access the modem admin panel. I can block it via a filter rule, but I wish to instead make a dummy page which logs all access to it and sends me a notification whenever it is accessed....
    by marklodge
    Sun Feb 25, 2018 8:50 pm
    Forum: Beginner Basics
    Topic: rate limit in userman
    Replies: 4
    Views: 763

    Re: rate limit in userman

    are you running a hotspot?
    by marklodge
    Sun Feb 25, 2018 2:52 pm
    Forum: Beginner Basics
    Topic: Two Mikrotiks with two WANs, how to connect
    Replies: 1
    Views: 372

    Two Mikrotiks with two WANs, how to connect

    Picture says [asks] it all
    by marklodge
    Sun Feb 11, 2018 4:44 pm
    Forum: Scripting
    Topic: Coding a RB Simulator
    Replies: 6
    Views: 1393

    Re: Coding a RB Simulator

    Run normal chr instead the simulator. What is normal chr? Cloud Hosted Router . A version of RouterOS for use in Virtual Machines, like VirtualBox, VMWare and the like. You get the real software running on a virtual hardware, and you can have as many of them running at once as the real hardware wil...
    by marklodge
    Sat Feb 03, 2018 6:45 pm
    Forum: Scripting
    Topic: Coding a RB Simulator
    Replies: 6
    Views: 1393

    Re: Coding a RB Simulator

    Run normal chr instead the simulator. What is normal chr? Why to simulate anything that you can have in real? I require advanced logging, for example, if an intruder touches the mikrotik simulation it needs to log everything possible, date, time, username/s,password/s, source etc. As far as I under...
    by marklodge
    Sat Feb 03, 2018 5:03 pm
    Forum: Scripting
    Topic: Coding a RB Simulator
    Replies: 6
    Views: 1393

    Coding a RB Simulator

    I want to code a RouterOS / Routerboard Simulator. My initial test was to create a listener on TCP port 8291, but when I try to connect to my listener IP from winbox I dont get any response. What am I doing wrong? I also need to set up the simulator to show up in MikroTik Neighbor Discovery, any hel...
    by marklodge
    Thu Feb 01, 2018 4:53 pm
    Forum: General
    Topic: Why are mangle rules suggested for a VPN connection?
    Replies: 1
    Views: 618

    Why are mangle rules suggested for a VPN connection?

    I have a hotspot running on a Mikrotik RB. I needed to route all traffic through a VPN connection. I just added a new PPTP Client and checked Add Default route , and everything worked well. For my own study and learning/curiosity I wish to understand why the VPN tutorials for Mikrotik always suggest...
    by marklodge
    Mon Oct 30, 2017 9:17 pm
    Forum: Beginner Basics
    Topic: How to access files on external USB via browser (Hotspot enabled) repost
    Replies: 1
    Views: 606

    Re: How to access files on external USB via browser (Hotspot enabled) repost

    The files that you wish to access has to reside within the Hotspot directory chosen
    by marklodge
    Wed Oct 25, 2017 11:34 pm
    Forum: Wireless Networking
    Topic: Are different IP Pools possible with a Hotspot?
    Replies: 0
    Views: 370

    Are different IP Pools possible with a Hotspot?

    I need to hand out different IPs to specific users. Reason: To allow certain users full access to all websites and to restrict access to only one website for other users I have created another IP pool and applied it to a test account but once the user logs in he has no access to the internet or even...
    by marklodge
    Sun Oct 22, 2017 12:00 am
    Forum: Wireless Networking
    Topic: Local Masquerading ??
    Replies: 7
    Views: 1756

    Re: Local Masquerading ??

    Hi there, the forward chain, sorry for that. thank you, i appreciate your kind assistance I have done as you said but yet am unable to access the AP Here is my config ping 192.168.111.10 SEQ HOST SIZE TTL TIME STATUS 0 192.168.111.10 timeout 1 192.168.111.10 timeout 2 192.168.111.10 timeout 3 192.1...
    by marklodge
    Sat Oct 21, 2017 9:25 pm
    Forum: Wireless Networking
    Topic: Local Masquerading ??
    Replies: 7
    Views: 1756

    Re: Local Masquerading ??

    [quote="MLubbe"]Hi there, /ip firewall nat add action=accept src-address=192.168.111.0/24 dst-address=192.168.111.0/24 [/quote] What chain should the above be in? [code] /ip firewall nat> add action=accept src-address=192.168.111.0/24 dst-address=192.168.111.0/24 chain: failure: no chain specified A...
    by marklodge
    Sat Oct 21, 2017 7:14 pm
    Forum: Wireless Networking
    Topic: Local Masquerading ??
    Replies: 7
    Views: 1756

    Re: Local Masquerading ??

    Hi there, 1) Ensure that there is an 192.168.111.0/24 & a 192.168.88.0/24 address on your bridge interface. 2) Accept LAN to LAN & AP to AP traffic to prevent them from Masquerading behind the routers IP 3) Masquerade traffic out of your bridge interface. Thank you very much. Could you please enlig...
    by marklodge
    Fri Oct 20, 2017 11:35 pm
    Forum: Wireless Networking
    Topic: Local Masquerading ??
    Replies: 7
    Views: 1756

    Local Masquerading ??

    I have an AP connected to ether 2 of my mikrotik Mikrotik is running a hotspot on a bridge interface which includes all lan and wlan ports. I connect with my laptop to ether 3 of the mikrotik. My IP is 192.168.88.10, the AP ip address is 192.168.111.20. What rules do I need to add to facilitate acce...
    by marklodge
    Tue Oct 03, 2017 2:48 am
    Forum: The User Manager
    Topic: Radius Server is not responding message
    Replies: 6
    Views: 20966

    Re: Radius Server is not responding message

    The default Firewall rules drops traffic not coming from LAN, disable this rule and it will work
    by marklodge
    Fri Sep 29, 2017 5:03 pm
    Forum: Beginner Basics
    Topic: How to access files on external USB via browser (Hotspot enabled) repost
    Replies: 1
    Views: 606

    How to access files on external USB via browser (Hotspot enabled) repost

    Repost I have inserted an external USB flash drive into my rb2011, I have formatted it as ext3. It shows up under Files as disk1. All good. Now how do I access files in disk1 folder from my browser? I am running a Hotspot, if I create a folder with files under my Hotspot directory I can access those...
    by marklodge
    Fri Sep 29, 2017 4:06 pm
    Forum: Virtualization
    Topic: Metarouter on microSD, will it be ever supported ?
    Replies: 19
    Views: 11125

    Re: Metarouter on microSD, will it be ever supported ?

    Bump... 7 years later
    by marklodge
    Fri Sep 29, 2017 12:06 am
    Forum: Wireless Networking
    Topic: what is the path to external USB?
    Replies: 0
    Views: 387

    what is the path to external USB?

    I I have inserted an external USB flash drive into my rb2011, I have formatted it as ext3. It shows up under Files as disk1. All good. Now how do I access files in disk1 folder from my browser? I am running a Hotspot, if I create a folder with files under my Hotspot directory I can access those file...
    by marklodge
    Sun Mar 19, 2017 5:24 pm
    Forum: Scripting
    Topic: Mikrotik user manager generate HTML report from terminal
    Replies: 0
    Views: 447

    Mikrotik user manager generate HTML report from terminal

    How do I generate an usermanager HTML usage report daily, via script and schedule?
    by marklodge
    Fri Mar 17, 2017 9:54 pm
    Forum: Wireless Networking
    Topic: Hide certain menus from winbox interface.
    Replies: 3
    Views: 831

    Re: Hide certain menus from winbox interface.

    Thanks, I have heard about the skins feature. But I specifically want it for winbox.
    Could this be a feature request. Or is there another way to do this
    by marklodge
    Fri Mar 17, 2017 9:08 pm
    Forum: Wireless Networking
    Topic: Hide certain menus from winbox interface.
    Replies: 3
    Views: 831

    Hide certain menus from winbox interface.

    My staff needs to login to our mikrotik router via winbox to administer the Hotspot that runs for our place. But I don't want them to be able to do anything else, like editing the firewall rules etc. How do I hide the Firewall menu and other menus from winbox? If I need to do any changes I will do i...
    by marklodge
    Sun May 15, 2016 3:25 pm
    Forum: General
    Topic: Upload / download counter incorrect on hotspot
    Replies: 1
    Views: 594

    Upload / download counter incorrect on hotspot

    Router details:
    Mikrotik RB750 latest Current firmware.
    Supout attached

    Issue

    I am running a very basic hotspot, simply did the hotspot setup and added users and limits.
    But users data upload and download values are not working correctly, user may download 20mb, but it shows only a few kb.
    by marklodge
    Mon Dec 29, 2014 2:32 am
    Forum: Wireless Networking
    Topic: Frequency and its effect on range??
    Replies: 1
    Views: 668

    Frequency and its effect on range??

    *Confused*
    LTE is 2.6ghz and can connect users at 40km.
    Wifi is 2.4ghz and can only connect users at max 1.3km (usually no more than 300 meters)
    AFAIK.... lower frequency = more penetration, further range..right........or am i missing something?
    by marklodge
    Mon Apr 28, 2014 10:14 pm
    Forum: Beginner Basics
    Topic: Export users with Profiles
    Replies: 3
    Views: 1612

    Re: Export users with Profiles

    Hi
    you can backup from old UM and Restore it to new UM
    from maintenance menu in UM
    Thank you for the reply, but please do not raise my hopes of a solution without reading my post till the end.
    I quote:
    And i cant export from the Maintenance Tab in User Manager due to no space.
    by marklodge
    Mon Apr 28, 2014 1:17 pm
    Forum: Beginner Basics
    Topic: Export users with Profiles
    Replies: 3
    Views: 1612

    Export users with Profiles

    I want to transfer all user manager users to another mikrotik board I cant seem to get all the users across WITH their profile info When i do the following: /tool user-manager user export I get the following output: add customer=admin disabled=no ip-address=192.168.10.1 name=cname \ password=pw shar...
    by marklodge
    Sat Apr 19, 2014 6:16 pm
    Forum: Beginner Basics
    Topic: Simple queue: Download speed is affected by Upload limit
    Replies: 3
    Views: 1493

    Re: Simple queue: Download speed is affected by Upload limit

    BitTorrent uses multiple TCP sessions. If the upload becomes saturated due to the BitTorrent client attempting uploads then sessions being used for download may also show reduction in throughput due to their ACKs being delayed/lost.
    I see, thanks for the info. So is there a solution?
    by marklodge
    Fri Apr 18, 2014 1:30 am
    Forum: Beginner Basics
    Topic: Simple queue: Download speed is affected by Upload limit
    Replies: 3
    Views: 1493

    Simple queue: Download speed is affected by Upload limit

    I have set a simple queue for a client. He uses mostly torrents, so its always uploading and downloading and he is complaining about unstable/lower than his line speed. The Upload limit of his queue is set to 512k and download to 4MB I have noticed that when the upload speed hits the limit it brings...
    by marklodge
    Sat Oct 12, 2013 12:55 am
    Forum: Wireless Networking
    Topic: Routing a proxy server connection to match clients routing
    Replies: 1
    Views: 940

    Routing a proxy server connection to match clients routing

    Routing a proxy server connection to match the clients routing mark I have a network that serves internet to 60 clients, all go through a mikrotik rb which routes traffic according to MARK_ROUTING rule in mangle. So, Group1 goes thru WAN1, and Group2 goes thru WAN2 etc. Now i want to setup a squid p...
    by marklodge
    Fri Mar 01, 2013 2:20 pm
    Forum: Wireless Networking
    Topic: Continous Log proto TCP (SYN) ???
    Replies: 3
    Views: 11065

    Continous Log proto TCP (SYN) ???

    Im a little disturbed as i do not understand the following: I followed this http://wiki.mikrotik.com/wiki/Securing_New_RouterOs_Router and after i added the following rule: add chain=input action=log log-prefix="Filter:" comment="" disabled=no add chain=input action=drop comment="drop everything els...
    by marklodge
    Sun Nov 11, 2012 2:05 am
    Forum: General
    Topic: Unanswered - Manually specify gateway for a pptp-client
    Replies: 5
    Views: 1332

    Re: Unanswered - Manually specify gateway for a pptp-client

    Post your firewall and interface config (export)
    by marklodge
    Sun Aug 05, 2012 10:59 am
    Forum: Wireless Networking
    Topic: Mangle breaks voip - SIP registration
    Replies: 2
    Views: 1112

    Re: Mangle breaks voip - SIP registration

    Hi
    are you use UDP Protocol for sip registration or TCP?
    im not really sure buddy, how would i check that? here is a screenshot of my settings on the sip device
    by marklodge
    Sun Aug 05, 2012 8:01 am
    Forum: Wireless Networking
    Topic: Mangle breaks voip - SIP registration
    Replies: 2
    Views: 1112

    Mangle breaks voip - SIP registration

    Im using the gigaset handsets and connecting via SIP function. This is my config, very basic: ip firewall address-list print detail 4 list=Allowed Internet address=192.168.5.0/24 ip firewall nat print detail Flags: X - disabled, I - invalid, D - dynamic 1 chain=srcnat action=masquerade src-address-l...
    by marklodge
    Thu Mar 08, 2012 8:40 pm
    Forum: Forwarding Protocols
    Topic: Route clients to a 5th & 6th DSL line using 2 RB750s?
    Replies: 6
    Views: 2122

    Re: Route clients to a 5th & 6th DSL line using 2 RB750s?

    looking at the pictures it seems you have adsl routers with pppoe clients that forward all traffic to the rb750 and between rb750 and routers you have a switch. If this is right you only need 2 port on rb: 1 for clients and 1 to the switch. I'll setup the routers on the same subnet (ex. 172.16.0.0/...
    by marklodge
    Tue Mar 06, 2012 11:06 pm
    Forum: Forwarding Protocols
    Topic: Route clients to a 5th & 6th DSL line using 2 RB750s?
    Replies: 6
    Views: 2122

    Re: Route clients to a 5th & 6th DSL line using 2 RB750s?

    Buy a RB1100 or RB1200 so you have much interface. I also think that rb750 couldn't run as reliable main router, pppoe concentrator and dsl load balancer ok, i buy rb1100, then what do i do when i need to add a 11th and 12th DSL line? and what if i need to add 20 more dsl lines? how would i join th...
    by marklodge
    Tue Mar 06, 2012 2:52 pm
    Forum: Forwarding Protocols
    Topic: Route clients to a 5th & 6th DSL line using 2 RB750s?
    Replies: 6
    Views: 2122

    Re: Route clients to a 5th & 6th DSL line using 2 RB750s?

    currently i'm doing a pppoe-out to each of the WAN links (my DSL routers) and i'm using the pppoe-out as the gateway. do you have any example config that i would use for NAT-DMZ between the routers and mikrotik? would the routers have to be i Router mode (ISP username nad pw programmed into the rout...
    by marklodge
    Sun Mar 04, 2012 11:03 pm
    Forum: Forwarding Protocols
    Topic: Route clients to a 5th & 6th DSL line using 2 RB750s?
    Replies: 6
    Views: 2122

    Route clients to a 5th & 6th DSL line using 2 RB750s?

    We currently have 4 dsl lines, each line serves 8 clients. we are marking clients per ip, so the mangle rule for client group 1 looks like this : ;;; client group 1 chain=prerouting action=mark-routing new-routing-mark=client-group-1 passthrough=no src-address=192.168.1.0/24 Then we route it out ove...
    by marklodge
    Mon Feb 27, 2012 1:22 am
    Forum: General
    Topic: Possible Bugs in RouterOS v 5.1
    Replies: 0
    Views: 444

    Possible Bugs in RouterOS v 5.1

    Before i report this as a bug i would like to confirm if it really is one. My RB: 600A i just upgraded from 4.16 to latest version 5.14 Bug in Version 5.14 for RB600 series: 1. Clients cannot login via usermanager to view thier usage etc (by going to http://routerip/user ) 2. The front page logo doe...
    by marklodge
    Tue Jan 10, 2012 1:42 pm
    Forum: Wireless Networking
    Topic: Usermanager 5 lacking a feature i need that was in userman 4
    Replies: 1
    Views: 616

    Usermanager 5 lacking a feature i need that was in userman 4

    how do i sort the users by the amount of bandwidth they have used, in usermanager 5?
    i nusermanager 4 i could just click the download arrow to sort the users, (see attached screenshot. but in usreman 5 i cant do it. is there another way of accomplishing this in userman 5?
    by marklodge
    Wed Dec 28, 2011 2:30 am
    Forum: Wireless Networking
    Topic: i need an Updated list of youtube ip addresses
    Replies: 10
    Views: 37679

    Re: i need an Updated list of youtube ip addresses

    OK, well i tried what i wanted but did not get the results expected. Problem is that some youtube videos dont work (error occured) and some dont load, and it takes longer than usual to load. heres my config if anyone wants it /ip firewall address-list add address=208.117.224.0/24 disabled=no list=Yo...
    by marklodge
    Tue Dec 27, 2011 2:59 pm
    Forum: Wireless Networking
    Topic: i need an Updated list of youtube ip addresses
    Replies: 10
    Views: 37679

    Re: i need an Updated list of youtube ip addresses

    ;;; Youtube chain=prerouting action=add-dst-to-address-list protocol=tcp address-list=Youtube address-list-timeout=10m in-interface=!(YOUR PUBLIC IFACE) dst-port=80 content=youtube.com Thanks for that. Does this work and and add all the ips that serve youtube videos to the address-list? Because i s...
    by marklodge
    Tue Dec 27, 2011 2:29 am
    Forum: Wireless Networking
    Topic: i need an Updated list of youtube ip addresses
    Replies: 10
    Views: 37679

    i need an Updated list of youtube ip addresses

    i have 3 wan links to the internet with around 25 clients. i want to route all web video like youtube dailymotion etc to one specific WAN link OR a cahching server. I tried to mark web video like .flv and .mp4 extension using layer7 but that did not work. so i think it is best if i mark all traffic ...
    by marklodge
    Sun Dec 25, 2011 3:15 pm
    Forum: Wireless Networking
    Topic: Using a backhaul and routing thru it.
    Replies: 6
    Views: 1546

    Re: Using a backhaul and routing thru it.

    Don't NAT until you get to the the 750 or use one of the load balancing examples in the wiki. I don't use Rockets, but this is easy enough to do on a routed all MT network. (policy routing) if i dont Masquerade NAT from my RB in rural area i cant reach the RB in business area I tried the NTH and a ...
    by marklodge
    Sat Dec 24, 2011 12:16 am
    Forum: Wireless Networking
    Topic: Using a backhaul and routing thru it.
    Replies: 6
    Views: 1546

    Re: Using a backhaul and routing thru it.

    heres my network layout,
    problem: i cant get the rb750g to load-balance as it cannot see the source ip addresses of clients (192.168.5.x or 192.168.6.x)
    How do i loadbalance in this situation?
    my mikrotik layout.png
    by marklodge
    Wed Nov 30, 2011 2:38 am
    Forum: Wireless Networking
    Topic: routing to specific adsl connecting
    Replies: 5
    Views: 1126

    Re: routing to specific adsl connecting

    Nope. Same principle. The connection the proxy makes has NOTHING to do with the original connection from the user that prompted the proxy to fetch content. You can't make a routing decision based on properties that connection simply doesn't have. The source IP is the router itself. i see, thanks a ...
    by marklodge
    Wed Nov 30, 2011 2:22 am
    Forum: Wireless Networking
    Topic: routing to specific adsl connecting
    Replies: 5
    Views: 1126

    Re: routing to specific adsl connecting

    It won't be possible. Proxies take connections, terminate them on themselves, and then fetch the content for the client. Once they have fetched it they returned it. Therefore a proxy splits what would normally be a client/server connection and makes it two connections. Your WAN routers will only ev...
    by marklodge
    Wed Nov 30, 2011 1:52 am
    Forum: Wireless Networking
    Topic: routing to specific adsl connecting
    Replies: 5
    Views: 1126

    routing to specific adsl connecting

    this is my network layout. (attached picture) Will it be possible to route client group 1 to ADSL 1 and client group 2 to ADSL 2? i need to have all connections go thru a proxy plus have the ability to route specific clients to a specific gateway. does anyone here know whether that will be at all po...
    by marklodge
    Mon Nov 14, 2011 6:59 pm
    Forum: Wireless Networking
    Topic: Breaking my head trying to access yahoo and other https site
    Replies: 6
    Views: 5373

    Re: Breaking my head trying to access yahoo and other https

    i am using ADSL routers in router mode as my gateways. the adsl routers create the pppoe connection to my isp. is this what you mean? Not really, this normally happens with multiple tunnels within. It's always possible that your ISP may be doing something further up the line. In any event the probl...
    by marklodge
    Mon Nov 14, 2011 4:55 pm
    Forum: Wireless Networking
    Topic: Using a backhaul and routing thru it.
    Replies: 6
    Views: 1546

    Re: Using a backhaul and routing thru it.

    Yes. Use the IP firewall mangle section to mark connections, and to mark routing based on connection marks. Then have routes out via specific interfaces for those routing marks. Your post is kind of shy on details, so this is a made up example. Traffic to/from 192.168.1.10/32 will be routed out a c...
    by marklodge
    Mon Nov 14, 2011 12:45 am
    Forum: Wireless Networking
    Topic: Using a backhaul and routing thru it.
    Replies: 6
    Views: 1546

    Using a backhaul and routing thru it.

    i have 2 adsl lines in a business area where there is adsl infrastructure. i want to serve this to a rural area. so i want to use route my clients thru the mikrotik router in the business area. i need to know: 1. is it possible to mark the connections coming from clients (on the router in rural area...
    by marklodge
    Sat Nov 12, 2011 8:33 am
    Forum: Wireless Networking
    Topic: PCC Load balancing - Help Following the Wiki
    Replies: 1
    Views: 998

    PCC Load balancing - Help Following the Wiki

    My System: RB433 v5.8 i am trying to follow this Load Balancing example: http://wiki.mikrotik.com/wiki/Manual:PCC But it just doesnt work. After i do the config i try to access the internet, i cannot, unless i specify a default route (without routing marks) Heres my config [admin@MikroTik] /ip addre...
    by marklodge
    Sat Nov 12, 2011 7:25 am
    Forum: Wireless Networking
    Topic: Clarity on MSS and MRU /MRRU values
    Replies: 1
    Views: 4347

    Clarity on MSS and MRU /MRRU values

    I need calrity on the following please. 1. Under pppoe-servers. Should the MAX MTU be 1500 for all sites to work? - The reason for this is that i have set my MAX MTU to 1480 and set the following mangle rule: / ip firewall mangle add chain=forward protocol=tcp tcp-flags=syn action=change-mss tcp-mss...
    by marklodge
    Thu Nov 10, 2011 6:33 pm
    Forum: Wireless Networking
    Topic: Breaking my head trying to access yahoo and other https site
    Replies: 6
    Views: 5373

    Re: Breaking my head trying to access yahoo and other https

    You are probably accessing the internet through a tunneled connection (e.g. PPtP tunneled over PPPoE to deliver public IP's) and that creates problems with MTU/MSS when using another PPPoE connection inside your network i am using ADSL routers in router mode as my gateways. the adsl routers create ...
    by marklodge
    Thu Nov 10, 2011 8:29 am
    Forum: Wireless Networking
    Topic: Breaking my head trying to access yahoo and other https site
    Replies: 6
    Views: 5373

    Re: Breaking my head trying to access yahoo and other https

    Set your MTU and MSS appropriately for a PPPoE connection. See the FAQ on the wiki for how to. Wow, that worked! but i dont understand how it worked tho. because i just set the MTU and MRU on the pppoe service to: 1500 instead of 1480 isnt it supposed to be less, not more? i am using ubiquiti airma...
    by marklodge
    Thu Nov 10, 2011 1:45 am
    Forum: Wireless Networking
    Topic: Breaking my head trying to access yahoo and other https site
    Replies: 6
    Views: 5373

    Breaking my head trying to access yahoo and other https site

    i have had a problem now for 3 weeks, cant access yahoo mail nor paypal and some other ssl sites. (some ssl https sites do work tho, like hostgator cpanel and gmail ) i have completely RESET my mikrotik rb433 and upgraded it to the latest v5.8 and all i configured was a super basic pppoe server usin...
    by marklodge
    Mon Nov 07, 2011 10:31 pm
    Forum: General
    Topic: HTTPS does not work
    Replies: 2
    Views: 1066

    Re: HTTPS does not work

    It looks like port 80 gets natted and goes through a web proxy, but you forgot about 443 and it doesn't get natted. i forgot to mention that not ALL https does not work. there are 3 that i know dose not work, 1. gumtree.co.za (cannot sign in to : https://secure.gumtree.co.za/capetown-westerncape/s-...
    by marklodge
    Mon Nov 07, 2011 7:37 pm
    Forum: General
    Topic: HTTPS does not work
    Replies: 2
    Views: 1066

    HTTPS does not work

    I cannot access any secure https sites such as: Yahoo Mail It opens up and the following address shows in the address bar and it just hangs. https://login.yahoo.com/config/login_verify2?.intl=us&.src=ym Here are the details that fewi requests. [admin@UBNTMik] > /ip address print detail Flags: X - di...
    by marklodge
    Fri Nov 04, 2011 1:08 am
    Forum: General
    Topic: Persistent user connections With Web Proxy enabled possible?
    Replies: 0
    Views: 536

    Persistent user connections With Web Proxy enabled possible?

    I am load balancing between two adsl lines. I have set equal cost gateways /ip route add dst-address=0.0.0.0/0 gateway=10.0.0.12,10.0.0.13 \ routing-mark=ecmp-http-route then i do as per the instructions on the mikrotik wiki ( http://wiki.mikrotik.com/wiki/ECMP_load_balancing_with_masquerade ) OK th...
    by marklodge
    Sat Oct 15, 2011 11:24 pm
    Forum: General
    Topic: Load balancing between many mikrotik routerboards
    Replies: 0
    Views: 409

    Load balancing between many mikrotik routerboards

    i have three mikrotiks serving three client groups. each mikrotik runs a usermanager and pppoe service on the eth2 port i want to join them all up and load balance between them all. i am looking at this load balancing: http://wiki.mikrotik.com/wiki/NTH_load_balancing_with_masquerade_%28another_appro...
    by marklodge
    Thu Oct 13, 2011 3:24 pm
    Forum: General
    Topic: Mark routing based on file type AND size
    Replies: 2
    Views: 647

    Re: Mark routing based on file type AND size

    ok thanks for the info. i'll be trying to use two proxies now. one for browsing and the othe for downloads. hope it works!
    by marklodge
    Tue Oct 11, 2011 2:18 am
    Forum: General
    Topic: Mark routing based on file type AND size
    Replies: 2
    Views: 647

    Mark routing based on file type AND size

    How would i mark routing for EXE files that are 10MB or more? Possible? So the final result will mark routing only for files that are .exe AND the exe file size is 10MB or more. My intention is to actually block the above 10Mb exe files. But mark routing is better as i can redirect to my webserver f...
    by marklodge
    Thu Sep 15, 2011 11:43 pm
    Forum: General
    Topic: PPPoE and dynamic queue for Internet traffic only
    Replies: 9
    Views: 1873

    Re: PPPoE and dynamic queue for Internet traffic only

    ok thanks for the answers, the reason i did what i did was firstly i just followed the tutorial step by step and it called for the following: /ip firewall mangle add chain=prerouting in-interface=LAN \ dst-address=10.0.0.0/24 action=mark-packet \ new-packet-mark=exempt-up add chain=postrouting out-i...
    by marklodge
    Thu Sep 15, 2011 4:38 pm
    Forum: General
    Topic: PPPoE and dynamic queue for Internet traffic only
    Replies: 9
    Views: 1873

    Re: PPPoE and dynamic queue for Internet traffic only

    Thanks for the help fewi! I did as you said, matched the queue and mangle names, but although i could see traffic flowing over the mangle rules to the queues it did not override the limit. But then i blanked out the in and out interface from the Queue Tree exempt rule and then it worked! Now i need ...
    by marklodge
    Thu Sep 15, 2011 12:13 am
    Forum: General
    Topic: PPPoE and dynamic queue for Internet traffic only
    Replies: 9
    Views: 1873

    Re: PPPoE and dynamic queue for Internet traffic only

    You could go to a PCQ queue tree configuration, but that's not really necessary. If you tried overriding simple queues with queue trees as described in the link I posted and it didn't work then something wasn't implemented right. Post the configuration you tried, together with all the info requeste...
    by marklodge
    Mon Sep 12, 2011 12:13 am
    Forum: General
    Topic: PPPoE and dynamic queue for Internet traffic only
    Replies: 9
    Views: 1873

    Re: PPPoE and dynamic queue for Internet traffic only

    Those rate limits are implemented via simple queues so this link applies: http://wiki.mikrotik.com/wiki/PCQ_and_Hotspots,_and_exempting_upstream_resources_from_rate_limit Currently i have dynamic queues set from the Mikrotik Usermanager. Should i clear all the Rate Limits set in the mikrotik userma...
    by marklodge
    Sun Sep 11, 2011 1:03 pm
    Forum: General
    Topic: PPPoE and dynamic queue for Internet traffic only
    Replies: 9
    Views: 1873

    Re: PPPoE and dynamic queue for Internet traffic only

    This is exactly what i'm trying to achive too.
    Did you find a way to limit internet traffic only?
    by marklodge
    Tue Jul 26, 2011 2:45 pm
    Forum: General
    Topic: simple (very simple) load balancing
    Replies: 4
    Views: 1418

    Re: simple (very simple) load balancing

    wont the first pppoe client who connects use gateway 1 and the second pppoe client who connects use gateway 2?
    by marklodge
    Tue Jul 26, 2011 1:34 am
    Forum: General
    Topic: simple (very simple) load balancing
    Replies: 4
    Views: 1418

    simple (very simple) load balancing

    i once spoke to a MT techie who told me if i have two adsl lines connected i could setup a very simple load balancing by adding the second adsl routers address into IP>Routes list with a distance of 2 (i'm not sure exactly if he said distance of 2 or not)
    anyhow. i want to know if this is workable?
    by marklodge
    Sat Jul 09, 2011 12:31 pm
    Forum: Wireless Networking
    Topic: PPPOE-Out to specific DSL router? specify by ip address?
    Replies: 3
    Views: 855

    Re: PPPOE-Out to specific DSL router? specify by ip address?

    Network diagram will help to understand what is happening. BTW unless DSLs are copper or some other "weird" interface (read not ethernet or WiFi), all can be done by one Mikrotik. Heres my newtork diagram. The reason i have to have both adsl routers connected to each other is because i need to rout...
    by marklodge
    Fri Jul 08, 2011 10:51 pm
    Forum: General
    Topic: Mikrotik setup behind UBNT gear
    Replies: 5
    Views: 1815

    Re: Mikrotik setup behind UBNT gear

    so basically. the Rocket M5's must be connected to ether2 of the mikrotik and the ether1 must be connected to the Internet (dsl router) . Is that correct?

    so it wont work if for eg, ether1 is connected to the same switch that the rorckets and the dsl router is connected to?
    by marklodge
    Fri Jul 08, 2011 10:47 pm
    Forum: Wireless Networking
    Topic: PPPOE-Out to specific DSL router? specify by ip address?
    Replies: 3
    Views: 855

    PPPOE-Out to specific DSL router? specify by ip address?

    I have two adsl routers connected to two mikrotiks. so basically both adsl routers are connected to each other. both routers are currently in Router mode. meaning the adsl routers dial the pppoe connection to my providers. Now for some weird reason, the adsl connection (to my provider) of one router...
    by marklodge
    Thu Jul 07, 2011 5:48 pm
    Forum: General
    Topic: Mikrotik setup behind UBNT gear
    Replies: 5
    Views: 1815

    Re: Mikrotik setup behind UBNT gear

    can i connect all the three rocketM5 sectors to one network switch and then connect the switch to ether1 of the mikrotik? or does each rocket have to be connected to an ether interface ? If you plan to use RB750G as border router, clients are terminating at RB750 and it forwards packets to Internet...
    by marklodge
    Wed Jul 06, 2011 11:35 pm
    Forum: General
    Topic: Mikrotik setup behind UBNT gear
    Replies: 5
    Views: 1815

    Mikrotik setup behind UBNT gear

    Could someone be kind enought to please tell us how to setup a mikrotik rb to (pppoe) authenticate userswhich are connected via airmax sectors. I have followed this guide: http://www.ubnt.com/wiki/Building_a_wisp Fine i understand all of that. But i'm a bit blank as to how i should setup the Mikroti...
    by marklodge
    Sat May 28, 2011 10:59 pm
    Forum: General
    Topic: how to mark SSL with DSCP?
    Replies: 11
    Views: 3307

    Re: how to mark SSL with DSCP?

    btw, how about doing this?:
    add action=set-priority chain=forward comment=dscp_42 disabled=no dst-port=\
        443 new-priority=1 passthrough=yes protocol=tcp
    
    shouldnt that set the ssl to high priority?
    by marklodge
    Sat May 28, 2011 10:56 pm
    Forum: General
    Topic: how to mark SSL with DSCP?
    Replies: 11
    Views: 3307

    Re: how to mark SSL with DSCP?

    i tried this: /ip firewall mangle add action=mark-packet chain=forward comment=dscp_42 disabled=no dst-port=443 \ new-packet-mark=ssl passthrough=no protocol=tcp then it picks up the SSL connections (i can see the stats moving whenever i access a ssl site) BUT, the queue doesnt catch it. i did the q...
    by marklodge
    Fri May 27, 2011 6:50 pm
    Forum: General
    Topic: how to mark SSL with DSCP?
    Replies: 11
    Views: 3307

    Re: how to mark SSL with DSCP?

    can you try to mangle dscp value in the pre-routing chain ?!? i tried this, [below] but it did not work. add action=mark-packet chain=forward comment="" disabled=no dst-port=443 \ new-packet-mark=ssl passthrough=yes protocol=tcp add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at...
    by marklodge
    Fri May 27, 2011 1:01 pm
    Forum: General
    Topic: how to mark SSL with DSCP?
    Replies: 11
    Views: 3307

    Re: how to mark SSL with DSCP?

    Hi, correct me, if i'm wrong, but DSCP is the wrong way, because you don't have any influence on the internet Routers and they will definitely not 'look' at your DSCP Value. What you need to go for is priority Queues. http://wiki.mikrotik.com/wiki/Manual:Queues_-_PCQ_Examples regards hi thanks for ...
    by marklodge
    Fri May 27, 2011 11:33 am
    Forum: General
    Topic: how to mark SSL with DSCP?
    Replies: 11
    Views: 3307

    Re: how to mark SSL with DSCP?

    Hi, correct me, if i'm wrong, but DSCP is the wrong way, because you don't have any influence on the internet Routers and they will definitely not 'look' at your DSCP Value. What you need to go for is priority Queues. http://wiki.mikrotik.com/wiki/Manual:Queues_-_PCQ_Examples regards hi thanks for ...
    by marklodge
    Fri May 27, 2011 8:20 am
    Forum: General
    Topic: how to mark SSL with DSCP?
    Replies: 11
    Views: 3307

    how to mark SSL with DSCP?

    Hi
    what is the DSCP marking for SSL (https)
    i want to prioritise sites like gmail .. https://www.mail.google.com
    by marklodge
    Tue May 03, 2011 11:59 pm
    Forum: Beginner Basics
    Topic: Why Queues rule limits local sharing speed ??
    Replies: 12
    Views: 13457

    Re: Why Queues rule limits local sharing speed ??

    mate, could you post the rules that you created please, i also need to test unlimited bandwidth from my ftp server.
    by marklodge
    Tue Apr 05, 2011 1:37 am
    Forum: General
    Topic: How to give priority to certain sites? like mail.google.com
    Replies: 3
    Views: 2018

    Re: How to give priority to certain sites? like mail.google.

    hi, anyone can give me an eg how to do this please.
    by marklodge
    Tue Mar 29, 2011 8:28 pm
    Forum: General
    Topic: Does Equal Sharing queue affect LOCAL throughput?
    Replies: 0
    Views: 657

    Does Equal Sharing queue affect LOCAL throughput?

    Here is my setup: ------------------------------------------------ High site- RB600 with 5GHz Sector Antenna. RB600 has Equal Sharing Queue set up and it also has userman and routing etc. At the high site there is a linux box that i am using as a file server (like a file repository) ----------------...
    by marklodge
    Thu Mar 24, 2011 4:26 pm
    Forum: RouterBOARD hardware
    Topic: Is it better to use a PC with Mikrotik OS or a Routerboard?
    Replies: 7
    Views: 2205

    Re: Is it better to use a PC with Mikrotik OS or a Routerboa

    RouterBOARD devices will always be fully compatible with RouterOS. It's hard to find completely compatible PC. They are all slightly different, and each has their own ethernet, motherboard etc. ah that is very useful info. i thought just any pc will work with routeros installed. thank you for all t...
    by marklodge
    Mon Mar 14, 2011 1:48 am
    Forum: RouterBOARD hardware
    Topic: Is it better to use a PC with Mikrotik OS or a Routerboard?
    Replies: 7
    Views: 2205

    Is it better to use a PC with Mikrotik OS or a Routerboard?

    I require someone to clear something for me please. Is it better to use a PC with Mikrotik OS installed or a Routerboard for handling Usermanager and Bandwidth Queues etc? The PC would have much more RAM available than most RB's. So will it work faster? Or am i missing something? Secondly, what do y...
    by marklodge
    Wed Jan 05, 2011 4:11 pm
    Forum: General
    Topic: CPE plus Hotspot config wanted
    Replies: 1
    Views: 1267

    CPE plus Hotspot config wanted

    Hi
    I'd like to setup a CPE that includes a 2.4ghz hotspot or just a plain access point. So it should do the following:
    1. Create pppoe connection via 5ghz grid
    2. Create an access point with the 2.4ghz omni

    The cpe will be a rb433 with 2 minipci cards, 1 x 5ghz and 1 x 2.4ghz
    by marklodge
    Mon Jan 03, 2011 10:32 pm
    Forum: General
    Topic: How to setup CPE that includes an Access point
    Replies: 2
    Views: 1343

    Re: How to setup CPE that includes an Access point

    by any change, you have ip addresses set ip and oyu have NAT set up? Do your clients see your AP?
    The client receives an ip from the pool. There is NAT setup on the main AP. Yes, clients see the AP of course.
    by marklodge
    Sat Jan 01, 2011 9:32 pm
    Forum: General
    Topic: How to setup CPE that includes an Access point
    Replies: 2
    Views: 1343

    How to setup CPE that includes an Access point

    Hi I'd like to setup a CPE that includes a 2.4ghz Access point. So it should do the following: 1. Create pppoe connection via 5ghz grid 2. Create an access point with the 2.4ghz omni The cpe will be a rb433 with 2 minipci cards, 1 x 5ghz and 1 x 2.4ghz this is the setup i currently use for the CPE. ...
    by marklodge
    Sun Dec 26, 2010 11:39 pm
    Forum: General
    Topic: How to allow a user access to only 1 ip address and block
    Replies: 7
    Views: 9292

    Re: How to allow a user access to only 1 ip address and bloc

    ok, let me explain exactly what i want to do and about my setup i have a server set up on my high site. i want to make this server accessible to friends to download/upload files from / to this server. this server is a local file repository. I want a username, say for eg: joelocal to have access only...
    by marklodge
    Sun Dec 26, 2010 11:13 pm
    Forum: General
    Topic: How to allow a user access to only 1 ip address and block
    Replies: 7
    Views: 9292

    Re: How to allow a user access to only 1 ip address and bloc

    Write appropriate firewall filter rules to permit traffic to that one server and then drop everything else. What those rules specifically look like is impossible to say given how little details you have given. thanks fewi. i have done what you suggest in your sig, here are the details, could you gi...
    by marklodge
    Sun Dec 26, 2010 2:15 pm
    Forum: General
    Topic: How to allow a user access to only 1 ip address and block
    Replies: 7
    Views: 9292

    Re: How to allow a user access to only 1 ip address and bloc

    you can put another router board like RB/750 or any other Mikrotik routerboard behind the RB/600. then, install hotpspot on the RB/600 and remove its DHCP Server. after that go to RB/750 install DHCP Server in there . the clients will recieve IPs from RB/750 and they will have local network but whe...
    by marklodge
    Sun Dec 26, 2010 12:13 pm
    Forum: General
    Topic: How to allow a user access to only 1 ip address and block
    Replies: 7
    Views: 9292

    How to allow a user access to only 1 ip address and block

    hi i'm running a mikrotik rb 600 with a nanostation on client side. Authentication from client side is done over pppoe. i have a server behind the mikrotik that i want come clients to access, but these clients should not have internet access. in other words i want to restrict certain users from inte...
    by marklodge
    Thu Nov 25, 2010 9:23 pm
    Forum: General
    Topic: How do you set up a miikrotik router as a simple AP?
    Replies: 5
    Views: 1964

    Re: How do you set up a miikrotik router as a simple AP?

    Is it an ADSL router, or modem? Does it already provide NAT? If you're looking to just add wireless to an existing NATed network then you don't need most of that config. If you're looking to terminate the PPPoE session from your ISP directly on your MikroTik then you do require additional configura...
    by marklodge
    Thu Nov 25, 2010 1:47 pm
    Forum: General
    Topic: How do you set up a miikrotik router as a simple AP?
    Replies: 5
    Views: 1964

    Re: How do you set up a miikrotik router as a simple AP?

    /interface wireless set wlan1 mode=ap-bridge ssid="OpenWiFi" frequency=2412 band="2.4ghz-b/g" disabled=no /ip address add interface=wlan1 address=192.168.1.1/24 /ip pool add name=wifi-dhcp ranges=192.168.1.10-192.168.1.254 /ip dhcp-server add name=dhcp1 interface=wlan1 address-pool=wifi-dhcp author...
    by marklodge
    Thu Nov 25, 2010 12:03 pm
    Forum: General
    Topic: How do you set up a miikrotik router as a simple AP?
    Replies: 5
    Views: 1964

    How do you set up a miikrotik router as a simple AP?

    I just want to create a wireless LAN without any security, no firewall, nothing. Just a simple Wireless Access point like the one you buy off the shelf and use in your home. I have checked this Tut: http://wiki.mikrotik.com/wiki/Manual:Making_a_simple_wireless_AP but it still seems that i have to do...
    by marklodge
    Tue Oct 26, 2010 1:27 am
    Forum: General
    Topic: Load balance or push browsing to one adsl router
    Replies: 1
    Views: 550

    Load balance or push browsing to one adsl router

    heres my setup (see pic) 2 x adsl lines, 10.0.0.2 and 10.0.0.3 i want to load balance the load between them .....or even better, send browsing to one router and downloading and other protocols to other router. Is it possible to have http BROWSING only to forward to 10.0.0.2 and DOWNLOADING to 10.0.0...
    by marklodge
    Fri Oct 22, 2010 1:03 pm
    Forum: General
    Topic: How to give priority to certain sites? like mail.google.com
    Replies: 3
    Views: 2018

    Re: How to give priority to certain sites? like mail.google.

    you can't make anything faster, unless you make the other stuff slower :)
    yes, thats what i mean. when one client is accessing gmail and other clients are downloading then for the period it takes to login to gmail everything else gets slower and all speed goes to the one client accessing gmail.
    by marklodge
    Fri Oct 22, 2010 2:32 am
    Forum: General
    Topic: cannot ping internet from my mikrotik rb
    Replies: 4
    Views: 1611

    Re: cannot ping internet from my mikrotik rb

    what does traceroute show at both working/non-working Internet? its currently working now so it shows: > tool traceroute 196.23.168.147 ADDRESS STATUS 1 10.0.0.2 6ms 9ms 3ms 2 41.132.0.1 42ms 15ms 21ms 3 196.22.163.218 47ms 50ms 47ms 4 196.22.189.3 51ms 46ms 96ms 5 196.22.169.241 56ms 54ms 57ms 6 1...
    by marklodge
    Fri Oct 22, 2010 2:24 am
    Forum: General
    Topic: How to give priority to certain sites? like mail.google.com
    Replies: 3
    Views: 2018

    How to give priority to certain sites? like mail.google.com

    Setup: -mikrotik RB (RB600A Level 4) -clients connect via usermanager/pppoe Queues currenty set: -Equal sharing Queue I would like to give High priority (all bandwidth speed) to certain sites. For eg, i want to make Gmail super fast so i give mail.google.com highest priority. is that possible? if so...
    by marklodge
    Fri Oct 22, 2010 12:27 am
    Forum: General
    Topic: cannot ping internet from my mikrotik rb
    Replies: 4
    Views: 1611

    Re: cannot ping internet from my mikrotik rb

    but are you always able to ping from the client computer?
    no, when i try to ping from client it cannot ping unless mikrotik can ping
    by marklodge
    Thu Oct 21, 2010 2:18 am
    Forum: General
    Topic: cannot ping internet from my mikrotik rb
    Replies: 4
    Views: 1611

    cannot ping internet from my mikrotik rb

    my rb is a bit eratic. sometimes it cannot ping internet and sometimes it can. no changes being done to it tho.
    heres my supout attached
    by marklodge
    Mon Oct 04, 2010 11:45 pm
    Forum: Wireless Networking
    Topic: PPPOE connections lose connectivity after enabling Bridge
    Replies: 0
    Views: 520

    PPPOE connections lose connectivity after enabling Bridge

    System setup: RB600A 4.6 4 x sector antennas Radius server to authenticate clients. Clients connect via pppoe connections >> usermanager [usually via Nanostations] i'm trying to create a bridge between two sites using one sector on high site and mikrotik CPE on other end I have followed the followin...
    by marklodge
    Mon Oct 04, 2010 5:46 pm
    Forum: Wireless Networking
    Topic: Setup a Mikrotik CPE so that it acts as a cpe plus a link ?
    Replies: 4
    Views: 1482

    Re: Setup a Mikrotik CPE so that it acts as a cpe plus a lin

    Do I understand correct? You want the CPE to use your network as the primary connection and the ADSL on their premises as the backup/failover. Other customers/CPEs should also use the ADSL at the highsite as the primary link and the one on the left of the image as the failover? Yes, that is exactly...
    by marklodge
    Fri Oct 01, 2010 1:19 pm
    Forum: Wireless Networking
    Topic: Setup a Mikrotik CPE so that it acts as a cpe plus a link ?
    Replies: 4
    Views: 1482

    Setup a Mikrotik CPE so that it acts as a cpe plus a link ?

    I need to know how to do this, would appreciate some help. The setup required is for the Mikrotik CPE that allows another ADSL router (connected via CPE) to be used as a gateway. basically we need to setup the Mikrotik CPE so that it acts as a cpe plus a link for the adsl. so that the adsl can be us...
    by marklodge
    Thu Feb 18, 2010 11:47 am
    Forum: General
    Topic: Allow FULL access through RouterBOARD
    Replies: 3
    Views: 14063

    Re: Allow FULL access through RouterBOARD

    Can you give more information about your network topology? Looks like you have 3 ethernet & 4 wireless interfaces. yes, all routerboards have 3 ethernet ports but i'm using one only, and i have 3 wireless cards that are running sectors at 5ghz (cpe connects to the sectors)and 1 2.4ghz card runnning...
    by marklodge
    Tue Feb 16, 2010 10:39 pm
    Forum: General
    Topic: Allow FULL access through RouterBOARD
    Replies: 3
    Views: 14063

    Allow FULL access through RouterBOARD

    I have a routerboard that has been setup for me by a company, the technical guys that set it up has left the company, now i'm left with a setup that does not allow any connections through besides HTTP, and that too has to go via my Squid proxy server only. How do i open up my MikroTik RouterBoard to...
    by marklodge
    Tue Feb 16, 2010 12:19 am
    Forum: General
    Topic: allowing direct access via mikrotik, repost
    Replies: 4
    Views: 6576

    Re: allowing direct access via mikrotik, repost

    You cant forcibly redirect non http traffic to a proxy. The customers would have to specify the proxy and the application would have to be proxy aware..
    Then maybe all other traffic is blocked? because no other traffic is able to go through, i'm struggling with this for around 6 months now
    by marklodge
    Tue Feb 16, 2010 12:18 am
    Forum: General
    Topic: allowing direct access via mikrotik, repost
    Replies: 4
    Views: 6576

    Re: allowing direct access via mikrotik, repost

    I do not see reason, why POP3 should not go through the router with current configuration.
    thanks for the reply.. but it doesnt go through, i could send you my backup file if you will be willing to check please

    Thanks
    by marklodge
    Fri Feb 12, 2010 11:57 am
    Forum: General
    Topic: allowing direct access via mikrotik, repost
    Replies: 4
    Views: 6576

    allowing direct access via mikrotik, repost

    Hi I have a Mikrotik RB600A that has been setup to force all traffic through my Squid Cache Proxy. The current connection is: CPE--->mikrotik--->>Squid Proxy--->ADSL modem I can browse websites fine, but POP3 or any other protocol like online gaming etc does not go through. How do i allow pop3 and o...
    by marklodge
    Thu Feb 11, 2010 5:53 am
    Forum: Scripting
    Topic: Traffic forced through Proxy, How do i allow others?
    Replies: 5
    Views: 9325

    Re: Traffic forced through Proxy, How do i allow others?

    That would require people to sacrifice a lab unit and load it up with your config. That config could also potentially contain RADIUS shared secrets, IP addresses and other authentication methods you may not want to make public. Post your configuration obtained via the "export" command instead. Sorr...
    by marklodge
    Thu Feb 11, 2010 5:51 am
    Forum: Scripting
    Topic: Traffic forced through Proxy, How do i allow others?
    Replies: 5
    Views: 9325

    Re: Traffic forced through Proxy, How do i allow others?

    Thanks for the reply here is my config # feb/11/2010 05:45:14 by RouterOS 3.24 # software id = K57N-PTT # /interface bridge add admin-mac=00:00:00:00:00:00 ageing-time=5m arp=enabled auto-mac=yes \ comment="PPPoE Peak Time" disabled=no forward-delay=15s max-message-age=\ 20s mtu=1500 name=radius1 pr...
    by marklodge
    Thu Feb 11, 2010 5:30 am
    Forum: Scripting
    Topic: Traffic forced through Proxy, How do i allow others?
    Replies: 5
    Views: 9325

    Re: Traffic forced through Proxy, How do i allow others?

    here is my config attached, (zipped)
    thanks
    by marklodge
    Wed Feb 10, 2010 8:07 pm
    Forum: Scripting
    Topic: Traffic forced through Proxy, How do i allow others?
    Replies: 5
    Views: 9325

    Traffic forced through Proxy, How do i allow others?

    Hi everyone I have a Mikrotik RB600A that has been setup to force all traffic through my Squid Cache Proxy. The current connection is: CPE--->mikrotik--->>Squid Proxy--->ADSL modem I can browse websites fine, but POP3 or any other protocol like online gaming etc does not go through. How do i allow p...
    by marklodge
    Sun Oct 11, 2009 7:18 am
    Forum: General
    Topic: What are the Country limitations set to?
    Replies: 2
    Views: 988

    Re: What are the Country limitations set to?

    can you hear the echo??
    by marklodge
    Sat Oct 10, 2009 11:43 am
    Forum: General
    Topic: What are the Country limitations set to?
    Replies: 2
    Views: 988

    What are the Country limitations set to?

    i'm running mikrotik rb600a with r5h cards (350mW) and 5ghz sectors I set Wireless>>Frequency Mode: to 'manual txpower' then i get a dropdown menu to set the country. Now if i set the country to UK or US does it limit the txpower? if so, where do i get a list of the limitations? I want to push out t...
    by marklodge
    Tue Sep 15, 2009 12:47 am
    Forum: General
    Topic: How to allow POP3 access over mikrotik
    Replies: 1
    Views: 521

    How to allow POP3 access over mikrotik

    What rules do i set to allow POP3 traffic to go through my router board?
    by marklodge
    Tue Sep 15, 2009 12:46 am
    Forum: General
    Topic: Streaming MMS Audio streaming Mikrotik
    Replies: 1
    Views: 627

    Streaming MMS Audio streaming Mikrotik

    Hi
    I have a Mikrotik RB600A board and clients connect via their CPEs.

    The problem is when a client tries to stream audio he is not able to, for eg mms://www.2mfm.org.au/live

    How do I allow MMS streaming?

    I tried adding a forward all port 7000-7070 tcp but that did not work

    Please help
    Thanks
    Mark
    by marklodge
    Mon Jul 06, 2009 5:47 pm
    Forum: Beginner Basics
    Topic: Prioritising AND bandwidh sharing?
    Replies: 0
    Views: 413

    Prioritising AND bandwidh sharing?

    if PCQ is enabled on the routerboard should traffic still be prioritized? if so then how will a request be handled for eg: if priorities are set: 1st priority: Port 80 2nd priority: Port 25 client 1 ----------port 25 traffic-------------| ------------ 4mb line speed client 2 ----------port 80 traffi...
    by marklodge
    Mon Jul 06, 2009 2:13 am
    Forum: Wireless Networking
    Topic: prioritise and bandwidth sharing?
    Replies: 0
    Views: 420

    prioritise and bandwidth sharing?

    if PCQ is enabled on the routerboard should traffic still be prioritized? if so then how will a request be handled for eg: if priorities are set: 1st priority: Port 80 2nd priority: Port 25 client 1 ----------port 25 traffic-------------| ------------ 4mb line speed client 2 ----------port 80 traffi...
    by marklodge
    Mon Jun 22, 2009 1:35 am
    Forum: Wireless Networking
    Topic: Mount HP Omni upside down?
    Replies: 6
    Views: 1410

    Re: Mount HP Omni upside down?

    Check the antennas signal pattern. But in you case I'll mount it lower. It will catch less noise and the chance of signal going over your clients is smaller. For hotspots I usually use a 12 db yagi pointed into the ground. If I was in your case I would use 3 yagis pointed 120deg from each other. as...
    by marklodge
    Mon Jun 22, 2009 12:31 am
    Forum: Wireless Networking
    Topic: Mount HP Omni upside down?
    Replies: 6
    Views: 1410

    Re: Mount HP Omni upside down?

    Should i mount the omni higher or lower? Which will be better?
    by marklodge
    Sun Jun 21, 2009 7:07 pm
    Forum: Wireless Networking
    Topic: Mount HP Omni upside down?
    Replies: 6
    Views: 1410

    Mount HP Omni upside down?

    I want to have 3 5gz sectors and 1 2.4ghz omni at 16m above ground level. The omni is for serving internet to laptops around the high site. Now, if i mount a vp omni at 16m the signal might go over the guys on the ground trying to catch it. Someone mentioned that an HP omni mounted upside down will ...