Community discussions

MikroTik App

Search found 121 matches

by vasilaos
Thu Apr 27, 2023 1:20 pm
Forum: General
Topic: MYNETNAME.NET is down. IP Cloud DDNS not working.
Replies: 15
Views: 2761

Re: MYNETNAME.NET is down. IP Cloud DDNS not working.

yes, back up now. Lasted about 1 hour.
yes it was back up and its down again now
by vasilaos
Thu Apr 27, 2023 1:07 pm
Forum: General
Topic: MYNETNAME.NET is down. IP Cloud DDNS not working.
Replies: 15
Views: 2761

Re: MYNETNAME.NET is down. IP Cloud DDNS not working.

same problem here
by vasilaos
Tue Mar 15, 2022 3:09 pm
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14179

Re: Where is UPS?

I tried in 7.2rc3 and was not fixed yet but in 7.2rc4 it is working. Port is showing correctly after connected to usb on first try and ups is connected.
by vasilaos
Wed Jan 12, 2022 9:15 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 226106

Re: v7.1.1 is released!

I bought a RB5009 and I have to address some problems with RouterOS 7 1. There is no routin-table parameter in the ping option (scripts for monitoring wan's depend on that in order to monitor same host's with different routing mark and in order to make a nice working script) 2. Packet marks in mangl...
by vasilaos
Tue Jan 11, 2022 2:26 pm
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14179

Re: Where is UPS?

I have redeployed the old device since ros 7 is still far from being stable. Ups package was not the only problem. It would have been perfect if was able to downgrade to ros 6 at this moment but for now RB5009 is waiting into the shelves.
by vasilaos
Thu Dec 30, 2021 10:51 am
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14179

Re: Where is UPS?

It is wise to make a backup before the upgrade
by vasilaos
Fri Dec 24, 2021 11:10 pm
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14179

Re: Where is UPS?

I need ups package also. I got a new RB5009 today that can't be downgraded. I avoided getting RB4011 for this case because didn't have usb interface. After getting RB5009 i noticed that the new stable version of ros 7.1.1 didn't have ups package at all in extra packages.
by vasilaos
Sun Jul 26, 2020 2:08 am
Forum: General
Topic: Pi-hole DNS setup with Mikrotik Hex
Replies: 5
Views: 4195

Re: Pi-hole DNS setup with Mikrotik Hex

If you configure something in the dns entry on the dhcp network settings then will force clients to get those dns servers No, clients will get what configured in dhcp network. Router can have any other dns server configured for it self queries and also the option allow incoming requests its not nec...
by vasilaos
Thu Jul 16, 2020 5:13 am
Forum: General
Topic: Pi-hole DNS setup with Mikrotik Hex
Replies: 5
Views: 4195

Re: Pi-hole DNS setup with Mikrotik Hex

Yes in firewall a rule in input chain from WAN interfaces to drop everything on port 53 TCP/UDP is necessary if a general default rules are removed. If default rules are present no additional rules are necessary because those that are not accepted by an accept rule are droped by default. To force tr...
by vasilaos
Thu Jul 16, 2020 4:47 am
Forum: General
Topic: L2TP on CCR1036 with 1Gbps internet
Replies: 4
Views: 1636

Re: L2TP on CCR1036 with 1Gbps internet

I am using multiple site-to-site and road warrior setup with x-auth on the same. Since some sites are over dynamic ip or behind nat i have configured a main branch site with real ip address in passive mode. Sites aren't connected only to the main branch but also with other sites when possible in a m...
by vasilaos
Thu Jul 16, 2020 4:11 am
Forum: General
Topic: Pi-hole DNS setup with Mikrotik Hex
Replies: 5
Views: 4195

Re: Pi-hole DNS setup with Mikrotik Hex

Setting your dns servers in the dns settings will tell RouterOS to resolve anything that it needs to those servers. If no entry configured in dhcp network settings the dhcp client will get the router ip as dns server if allow incoming requests is enabled or will get the dns server adresses you confi...
by vasilaos
Thu Jul 16, 2020 3:20 am
Forum: General
Topic: Moving up from an RB750UP - some questions
Replies: 2
Views: 1185

Re: Moving up from an RB750UP - some questions

I would suggest RB4011iGS+RM for long term solution. Compared to hex poe i think hex S is a better option but have to consider that will have 5MB of free space with clear configuration out of the box. Definitively space is an issue on these devices. You could load images and other large files or scr...
by vasilaos
Thu Jul 16, 2020 2:33 am
Forum: Beginner Basics
Topic: Secondary routes
Replies: 3
Views: 1658

Re: Secondary routes

In the case of IKE2 tunnels no routes are generated and no nat rules are necessary. Instead traffic directed to the remote network follows the default route or 0.0.0.0/0 with the default gateway. Ipsec policy tells to ecrypt the data and send it over the tunnel. When you configure a static route to ...
by vasilaos
Thu Jul 16, 2020 2:18 am
Forum: General
Topic: L2TP on CCR1036 with 1Gbps internet
Replies: 4
Views: 1636

Re: L2TP on CCR1036 with 1Gbps internet

I cant tell for sure about L2TP/IPsec but i have achieved 600-800Mbps over IPsec IKE2 tunnels with cheaper router capable of hardware encryption. Is your bandwidth up/down symmetric or you have slower upload? Check your cores utilization while doing bandwidth tests. Is one core going at 100% ?
by vasilaos
Tue Jun 09, 2020 3:34 am
Forum: General
Topic: PPP DHCP Hotspot rate to Queue Tree
Replies: 1
Views: 942

Re: PPP DHCP Hotspot rate to Queue Tree

You can't. Queue tree isn't meant to put each target ip separately as a child in a queue tree. You could rather put a queue tree child for an ip range with a limited pcq-rate and put clients on separate ranges manually or by radius authentication.
by vasilaos
Tue Jun 09, 2020 2:11 am
Forum: Beginner Basics
Topic: Need Help
Replies: 1
Views: 950

Re: Need Help

Have you done netinstall previously with another device or is the first time? I would suggest to retry netinstall with each step carefully https://wiki.mikrotik.com/wiki/Manual:Netinstall Deactivate any windows firewall and directly attach an ethernet cable from ethernet 1 to your pc instead of 30-3...
by vasilaos
Mon Jun 08, 2020 1:55 pm
Forum: General
Topic: No pppoe passthrough bridge
Replies: 1
Views: 1020

Re: No pppoe passthrough bridge

You should select station-bridge on the cpe and enable bridge mode on the ap if not enabled. If you want to use station mode you have to set an eoip tunnel from the cpe to the concentrator, leave wireless interface out of the bridge with client ip on wireless interface in order to establish the tunn...
by vasilaos
Mon Jun 08, 2020 1:35 pm
Forum: Wireless Networking
Topic: Non-Mikrotik Wireless Extender MAC show in hotspot while device MAC only show in DHCP Lease
Replies: 6
Views: 2524

Re: Non-Mikrotik Wireless Extender MAC show in hotspot while device MAC only show in DHCP Lease

Agree totally with @bpwl and also add the only method to bridge transparently is with wds that is compatible with different vebndors if the device supports it. Other methods usually fall into compatibility issues. These devices will use the same chip to recieve and transmit data to the client and wi...
by vasilaos
Sat Jun 06, 2020 9:45 pm
Forum: Beginner Basics
Topic: What am I doing wrong for remote login?
Replies: 6
Views: 1521

Re: What am I doing wrong for remote login?

The router should aquire real ip address in order to be reachable from the internet. Ip cloud net name will translate to public ip address
by vasilaos
Sat Jun 06, 2020 9:40 pm
Forum: General
Topic: Issue with IPSec/IKEv2 tunnel disconnecting and not reconnecting
Replies: 12
Views: 4589

Re: Issue with IPSec/IKEv2 tunnel disconnecting and not reconnecting

A workaround that you can do is to kick automatically active peers that have responder status by script to avoid manually until you find the root of the problem
by vasilaos
Fri Jun 05, 2020 7:03 pm
Forum: Beginner Basics
Topic: Local Port definition and Port Forwarding
Replies: 47
Views: 9263

Re: Local Port definition and Port Forwarding

Apart from the initial dhcp negotiation the router will not involve in the internal communication of the hosts that are directly connected with each other if you use local ip address. If you use domain name that is translated to some ip address public or local then there may be something related to ...
by vasilaos
Fri Jun 05, 2020 6:08 pm
Forum: Beginner Basics
Topic: Local Port definition and Port Forwarding
Replies: 47
Views: 9263

Re: Local Port definition and Port Forwarding

If you try to reach the rdp server by local ip and still experience latency it is not something related to the above configuration. Since the client and server pc are on the same broadcast domain /24 their ip are directly connected and the router is not involved in the communication. I notice that y...
by vasilaos
Fri Jun 05, 2020 4:04 pm
Forum: Beginner Basics
Topic: Local Port definition and Port Forwarding
Replies: 47
Views: 9263

Re: Local Port definition and Port Forwarding

If you rdp with the local address rather than the domain name do you experience latency?
by vasilaos
Fri Jun 05, 2020 3:23 pm
Forum: Beginner Basics
Topic: Local Port definition and Port Forwarding
Replies: 47
Views: 9263

Re: Local Port definition and Port Forwarding

yes since you don't specify an in-interface or dst-address or some other specifier it should kick from outside networks also
by vasilaos
Fri Jun 05, 2020 3:16 pm
Forum: General
Topic: Issue with IPSec/IKEv2 tunnel disconnecting and not reconnecting
Replies: 12
Views: 4589

Re: Issue with IPSec/IKEv2 tunnel disconnecting and not reconnecting

I am not very sure but i have noticed mikrotik will respond anyway if the other peer will try to reestablish the connection so the setting should be set on the remote peer to as Passive only maybe. Why do You have to delete the entry after connection is reestablished? You shouldn't loose connectivit...
by vasilaos
Fri Jun 05, 2020 2:48 pm
Forum: General
Topic: two pppoe connections, question?
Replies: 7
Views: 2353

Re: two pppoe connections, question?

L2 bridge is difficult to accomplish since it needs interoperability form the provider and must be the same provider. PPC is the best and obvious way to go and RB4011 is good choice. It doesn't matter in this case if interfaces are pppoe clients or ethernet interfaces. Usually you should group wan a...
by vasilaos
Fri Jun 05, 2020 3:57 am
Forum: General
Topic: PPPoE server maximum performance.
Replies: 5
Views: 2740

Re: PPPoE server maximum performance.

There may be various reasons behind this. You can start to look wich services eat more resources. It can be masquerade or mangling or something other. Hopefully you can find clues in this video wich is one of my prefered ones https://youtu.be/3LmQYIQ5RoA?t=13m53s
by vasilaos
Fri Jun 05, 2020 3:23 am
Forum: General
Topic: routing mark, such as about routing end devices
Replies: 2
Views: 970

Re: routing mark, such as about routing end devices

You could exclude some destinations from the mangle rule with address lists
by vasilaos
Fri Jun 05, 2020 3:19 am
Forum: Beginner Basics
Topic: can't connect to new cAP ac (((
Replies: 8
Views: 10175

Re: can't connect to new cAP ac (((

I don't remember exactly default configuration on cAP ac but ether1 may be filtered by the default rules in firewall because it may be considered as external interface. Usually that is the default configuration on devices with more than one ethernet port, try connecting with ethernet port 2 temporal...
by vasilaos
Fri Jun 05, 2020 3:06 am
Forum: General
Topic: Load Balancer with NAT rules
Replies: 11
Views: 3562

Re: Load Balancer with NAT rules

There is a script approach of what you describe to want to accomplish: :do { :local dns1 "8.8.8.8"; :local dns2 "8.8.4.4"; :do { [:resolve dns.google server=$dns1]; :if ([/ip dns get server] != $dns1) do={ /ip dns set server=$dns1 } } on-error={ :if ([/ip dns get server] != $dns2...
by vasilaos
Mon Jul 29, 2019 11:45 pm
Forum: Scripting
Topic: PEAR2\Net\RouterOS sync with Sql [SOLVED]
Replies: 3
Views: 5154

Re: PEAR2\Net\RouterOS sync with Sql [SOLVED]

Use crontab
by vasilaos
Mon Jul 29, 2019 11:32 pm
Forum: Beginner Basics
Topic: DHCP Server Text is RED
Replies: 2
Views: 2165

Re: DHCP Server Text is RED

Add an ip address to the bridge interface and use the DHCP setup instead. Probably you are missing some steps while adding the dhcp configuration manually
by vasilaos
Mon Jul 29, 2019 11:27 pm
Forum: General
Topic: PPPoe server and hotspot at the same RB
Replies: 3
Views: 1156

Re: PPPoe server and hotspot at the same RB

There are a some reasons why high load of cpu on pppoe server can happen. Use tool profile to see wich process is eating cpu resources first.
by vasilaos
Sun Jul 14, 2019 2:12 am
Forum: General
Topic: High Ping
Replies: 1
Views: 948

Re: High Ping

There are many things to take in consideration. The info supplied is not enaugh. Take a look at system resources of each device to see if there is high cpu usage for example.
by vasilaos
Mon May 20, 2019 7:04 pm
Forum: General
Topic: Mesh with OmniTIK 5 PoE ac
Replies: 3
Views: 1637

Re: Mesh with OmniTIK 5 PoE ac

This setup and wds might have various problems. One is the network self interference because aps must be in same channel for wds to operate. The other is wds itself having problems. Also sending and receiving from the same wireless interface will drop performace. The other is that bridging the netwo...
by vasilaos
Mon May 20, 2019 6:42 pm
Forum: Beginner Basics
Topic: Multiple ISP usage question
Replies: 3
Views: 1022

Re: Multiple ISP usage question

What I do is set up mangle rules to mark packets and do the routing decision. I use per connection classifier. A script monitors each isp by pinging 3 different hosts on the Internet and if 2 of them fails then disable respective mangle rules. Not real quality test but quite effective. Also traffic ...
by vasilaos
Sun Feb 24, 2019 10:39 am
Forum: Forwarding Protocols
Topic: OSPF Redistribute Problem
Replies: 19
Views: 7992

Re: OSPF Redistribute Problem

The router R1 will distribute all routes learned from routers of the same area by default. That is what OSPF is about. The redistribute-other-ospf=no is if you want to distribute or not routes of other areas. So you have to specify ospf-out filter to discart those routes in R1 in order to not distri...
by vasilaos
Sun Jan 06, 2019 12:29 pm
Forum: RouterBOARD hardware
Topic: SXT SA5 ac - Two devices cannot see each other 400m apart
Replies: 4
Views: 1428

Re: SXT SA5 ac - Two devices cannot see each other 400m apart

Sxt's maybe missconfigured. Post export configuration of both sxt's
by vasilaos
Mon Nov 05, 2018 8:50 pm
Forum: General
Topic: DNS query
Replies: 3
Views: 1651

Re: DNS query

Post result of /ip dns print
by vasilaos
Mon Nov 05, 2018 8:17 pm
Forum: Beginner Basics
Topic: Meraki MX behind Mikrotik
Replies: 2
Views: 2104

Re: Meraki MX behind Mikrotik

Attach Meraki MX to CRS and forward all to incoming traffic from public ip to meraki to save time with confoguration. Or even better get a real ip adress pool from the isp and distribute real ip to each device behind the CRS
by vasilaos
Mon Nov 05, 2018 8:05 pm
Forum: General
Topic: Whats recommended down/up speed for pppoe clients
Replies: 2
Views: 844

Re: Whats recommended down/up speed for pppoe clients

Is your uplink used at 100% at peak hours or at majority part of the time? Is your device cpu high at peak hours? Whats the physical datalink of pppoe clients? How much users are getting served? What is the device that is running the pppoe server? To answer to your question first need to know if you...
by vasilaos
Mon Nov 05, 2018 7:50 pm
Forum: General
Topic: Netwatch and Scripts [SOLVED]
Replies: 3
Views: 9074

Re: Netwatch and Scripts [SOLVED]

I had this problem after i upgraded to some newer version. Netwatch scripts and all subscripts are run from system user and not from admin user. When you run the script manually you create the global variable from the admin user wich is loged in at the moment but the variable is not visible for the ...
by vasilaos
Mon Nov 05, 2018 7:39 pm
Forum: General
Topic: administration of multiple sites (tunneling)
Replies: 2
Views: 1004

Re: administration of multiple sites (tunneling)

I would connect all sites to a central location so there is no need to forward ports for all sites. Usually i do a vpn connection from a remote site to my office that has public ip temporarily or permanently.
by vasilaos
Mon Nov 05, 2018 11:15 am
Forum: Beginner Basics
Topic: how to Config Mikrotik with 1:1 bandwitdh ratio
Replies: 5
Views: 1203

Re: how to Config Mikrotik with 1:1 bandwitdh ratio

There is not an exact definition of leased line in mikrotik. Depend on how you plan to provide leased line. It can be with pppoe also. Most depends on the physical data link that is capable provide bidirectional or symmetric speeds. In case you want to provide static ip entry you need to make a simp...
by vasilaos
Sun Nov 04, 2018 9:53 pm
Forum: Beginner Basics
Topic: how to Config Mikrotik with 1:1 bandwitdh ratio
Replies: 5
Views: 1203

Re: how to Config Mikrotik with 1:1 bandwitdh ratio

You can create different ppp profiles with your desidered limitation. When user is loged in a dynamic simple queue is created with the rate set in ppp profiles you have to asociate the ppp secrets with the desidered profile. In case you use radius for authentication you can set limitation on the rad...
by vasilaos
Sun Nov 04, 2018 9:39 pm
Forum: General
Topic: Suddenly some ports are blocked (443, 22 but not 80)
Replies: 3
Views: 929

Re: Suddenly some ports are blocked (443, 22 but not 80)

Ok 1k/1k is too low or equivalent of not having connection at all but that may not be your problem. In case of dsl pppoe connection is encapsulatedand you cant send full size packets without fragmentation. Some dynamic rules in firewall mangle should be created automatically based on the configurati...
by vasilaos
Sun Nov 04, 2018 9:19 pm
Forum: Beginner Basics
Topic: Mangle. Where do you draw the line between connection and packet marks
Replies: 1
Views: 938

Re: Mangle. Where do you draw the line between connection and packet marks

Yes its possible to create 1 connection mark for all connection and then create different packet marks based on destination source address protocol port etc. In fact you can create new packet marks without having connectin marks at all but you have to be careful where using pasthrough and where not ...
by vasilaos
Sun Nov 04, 2018 8:12 pm
Forum: General
Topic: Wireless on CAPsMAN Slower when not using Datapath Local Forwarding
Replies: 5
Views: 1961

Re: Wireless on CAPsMAN Slower when not using Datapath Local Forwarding

Are you using certificate? If so i ncase of non local forward it will encrypt passing data also that will affect performance. With local forward it will encrypt only managment data. Try setting certificate to none and see if that makes a difference
by vasilaos
Sun Nov 04, 2018 6:59 pm
Forum: General
Topic: Multi PPPoE sessions
Replies: 4
Views: 2054

Re: Multi PPPoE sessions

Just an idea because i never tried. Try lowering keep-alive-timeout. If more sessions are created try rising.
by vasilaos
Sun Nov 04, 2018 6:42 pm
Forum: Wireless Networking
Topic: WinBox V3.18 will not log into new BaseBox 5 V6.18
Replies: 2
Views: 1579

Re: WinBox V3.18 will not log into new BaseBox 5 V6.18

Try login in with telnet or ssh or web and first take a look in system resources for high cpu usage. Then upgrade to a newer version of routeros and retry to login with winbox. Sound is not a feature that all routerboards have. Two beeps mean that system has booted. Along with the beeps simultaneous...
by vasilaos
Sun Nov 04, 2018 3:16 pm
Forum: General
Topic: Suddenly some ports are blocked (443, 22 but not 80)
Replies: 3
Views: 929

Re: Suddenly some ports are blocked (443, 22 but not 80)

(I set the max-limit to 1k/1k on a queue that my PC was not in and lost all connectivity
What this mean
by vasilaos
Sun Nov 04, 2018 3:09 pm
Forum: Wireless Networking
Topic: Apparent Selective Wifi Internet
Replies: 2
Views: 901

Re: Apparent Selective Wifi Internet

Reset configuration to default and use ethernet 1 for upstream. If u use ethernet 2 you risk to have 2 dhcp servers in same physical layer. One from the upstream connection and one from the MikroTik hAP lite and devices will get ip from a random one dhcp server. If your device has been compromised y...
by vasilaos
Sun Nov 04, 2018 2:49 pm
Forum: Forwarding Protocols
Topic: VPN connects but no internet
Replies: 2
Views: 6645

Re: VPN connects but no internet

First you have to set different pool for vpn and different local adress. Vpn adresses are virtual and can not be part of the local level 2 broadcast domain. pptp is considered unsecure. I can't see your /ip route configuration also. There maybe other wrongs in your config but that was what i noticed...
by vasilaos
Sun Nov 04, 2018 2:31 pm
Forum: General
Topic: Wireless on CAPsMAN Slower when not using Datapath Local Forwarding
Replies: 5
Views: 1961

Re: Wireless on CAPsMAN Slower when not using Datapath Local Forwarding

Without local forwarding a tunnel between the cap and capsman is created. Maybe there is limmited connectivity between the cap and capsman devices that is causing low speeds. Whats your network topology? Port speeds etc.
by vasilaos
Sun Nov 04, 2018 10:29 am
Forum: Scripting
Topic: Remove unregistered users one by one, not in bulk
Replies: 2
Views: 1141

Re: Remove unregistered users one by one, not in bulk

My radius dosent fail due to many users trying to login at same time. Thats not normal. Authentication should be done without a porblem for more than 1 user at same time and alredy autheticated users shouldnt be affected. Maybe you are kicking autheticated users too at same time. My script looks lik...
by vasilaos
Sat Nov 03, 2018 10:59 am
Forum: General
Topic: Hotspot-MAC blacklist using Wildcard entries?
Replies: 3
Views: 1841

Re: Hotspot-MAC blacklist using Wildcard entries?

You can apply this rule to the hotspot bridge depending on how your network is designed. you may need to apply this rule to any hotspot point or to the core router where all interface are bridged depending on your design. this way the mac adress range will not have not any communication with the rou...
by vasilaos
Sat Nov 03, 2018 12:34 am
Forum: General
Topic: Creating a scheduler from terminal
Replies: 1
Views: 1248

Re: Creating a scheduler from terminal

/system scheduler add name=TelnetON start-time=startup on-event="/ip neighbor discovery-settings set discover-interface-list=all \
    \n\r\
    \n/tool mac-server set allowed-interface-list=none"
by vasilaos
Sat Nov 03, 2018 12:10 am
Forum: The Dude
Topic: Monitor Ethernet port
Replies: 3
Views: 3597

Re: Monitor Ethernet port

Have you thought of using ping to monitor if the device is active or not? Also if the device is directly connected to an interface of mikrotik you can check with a script if the interface on witch the device is attached is running or not with the command: /interface ethernet get "interface_name...
by vasilaos
Fri Nov 02, 2018 11:55 pm
Forum: General
Topic: Hotspot-MAC blacklist using Wildcard entries?
Replies: 3
Views: 1841

Re: Hotspot-MAC blacklist using Wildcard entries?

Using wildcard entries for MAC addresses is not possible. Adding many entries with a script is possible but other problems may happen like blocking wrong mac addresses and it may not be a solution at all because MAC addresses can be spoofed to another range anyway. Explain what the unwanted user is ...
by vasilaos
Fri Nov 02, 2018 11:18 pm
Forum: General
Topic: 2 WAN -> 2 LAN. Need access from VPN to the 2 LAN's but no connection
Replies: 5
Views: 2013

Re: 2 WAN -> 2 LAN. Need access from VPN to the 2 LAN's but no connection

You haven't explained how you are trying to map ports yet. The IP addresses on your wan interfaces are private ip adresses and are not routable throught internet so you must be behind another router. Are you mapping ports on the edge router that has a real ip address reachable from the internet?
by vasilaos
Fri Nov 02, 2018 11:10 pm
Forum: General
Topic: 2 WAN -> 2 LAN. Need access from VPN to the 2 LAN's but no connection
Replies: 5
Views: 2013

Re: 2 WAN -> 2 LAN. Need access from VPN to the 2 LAN's but no connection

Along with TCP port 1723 that allow PPTP tunnel maintenance traffic you also need to o allow PPTP tunneled data to pass through router so you need open Protocol ID 47 (GRE) but consider that PPTP is no longer considered secure
by vasilaos
Thu Nov 01, 2018 10:52 pm
Forum: Scripting
Topic: Running multiple scripts
Replies: 1
Views: 1433

Re: Running multiple scripts

a solution is to run scripts this way
/system script run "script_name1"

/system script run "script_name2"
by vasilaos
Thu Nov 01, 2018 10:32 pm
Forum: Wireless Networking
Topic: Hap AC2 extreme slow wifi
Replies: 16
Views: 8816

Re: Hap AC2 extreme slow wifi

I guess you can't turn off a security profile but you can set mode to none if that is what you mean. Please provide more information on your wireless security profile configuration. Have you selected both wpa psk & wpa2 psk. Have u specified tkip or aes ccm chipers or both or none of them. Try s...
by vasilaos
Fri Oct 12, 2018 12:28 pm
Forum: General
Topic: Connect two networks which are behind different routers with NAT
Replies: 5
Views: 2112

Re: Connect two networks which are behind different routers with NAT

You may not want to masquerade traffic form your connected subnets. In order to do that best approach is to add an accept rule between your connected subnets above the main masquerade rule in firewall nat like: MT1 /ip firewall nat add chain=srcnat src-address=192.168.1.0/24 dst-address=192.168.2.0/...
by vasilaos
Fri Oct 12, 2018 12:02 pm
Forum: Beginner Basics
Topic: [ASK]Can't access some website "this site can't be reached"
Replies: 14
Views: 5765

Re: [ASK]Can't access some website "this site can't be reached"

To me it looks like you are running into mtu issues. Depending on the encapsulation of your internet connection you may add a rule to clamp to pmtu via mangle
by vasilaos
Sun Jun 17, 2018 4:52 pm
Forum: General
Topic: Lost access with Traffic Generator
Replies: 0
Views: 500

Lost access with Traffic Generator

Hello guys. Today i started a traffic generator on a remote location with quick start and i lost connection with the remote location. I can't stop the traffic generator my self now at the moment. I wanted to know if there is any default duration of the test?
by vasilaos
Wed Aug 30, 2017 5:30 pm
Forum: General
Topic: disable running check in latest RouterOS? [SOLVED]
Replies: 3
Views: 4371

Re: disable running check in latest RouterOS? [SOLVED]

i refer to this https://wiki.mikrotik.com/wiki/Manual:Interface/Ethernet disable-running-check (yes | no; Default: yes) Disable running check. If this value is set to 'no', the router automatically detects whether the NIC is connected with a device in the network or not. Default value is 'yes' becau...
by vasilaos
Wed Aug 30, 2017 5:15 pm
Forum: General
Topic: disable running check in latest RouterOS? [SOLVED]
Replies: 3
Views: 4371

disable running check in latest RouterOS? [SOLVED]

Hi guys! where is the disable running check in latest RouterOS?
by vasilaos
Wed Jul 05, 2017 2:29 pm
Forum: Beginner Basics
Topic: How to set facebook speed 5mbps to all clients through pcq simple queues
Replies: 10
Views: 2342

Re: How to set facebook speed 5mbps to all clients through pcq simple queues

i will do this later but i can not guarantee it will work 100% with simple queues since i use queue tree for marked packets and simple queues in a few cases
by vasilaos
Wed Jul 05, 2017 2:06 pm
Forum: Beginner Basics
Topic: How to set facebook speed 5mbps to all clients through pcq simple queues
Replies: 10
Views: 2342

Re: How to set facebook speed 5mbps to all clients through pcq simple queues

yes sorry you have specified in title now that i see. it isn't that easy task you have to be familiar with Layer7 Protocol, Filter rules, Mangle, Queue Types. the right direction to this is to: 1. create a Layer 7 protocol to detect facebook.com traffic regexp: ^.+(facebook.com).*$ 2. create a filte...
by vasilaos
Wed Jul 05, 2017 1:05 pm
Forum: Beginner Basics
Topic: IPTables bash script
Replies: 6
Views: 3418

Re: IPTables bash script

i think is up to FWBuilder developers but what is the real advantage of this?
by vasilaos
Thu Jun 15, 2017 9:39 pm
Forum: Scripting
Topic: Mikrotik Log
Replies: 8
Views: 3127

Re: Mikrotik Log

i done same configuration on a mt device to test and the file showed just immediately. idk what you are missing exactly. try a
/system logging print
also and post it here again please.
by vasilaos
Thu Jun 15, 2017 8:55 pm
Forum: General
Topic: Two subnets on different interfaces communication problem
Replies: 12
Views: 2448

Re: Two subnets on different interfaces communication problem

it is the masquerade rule because will masquerade everything from the selected range and the replying machine will reply to your mikrotik address instead of your pc Your out interface of masquerade rule in mt includes your other local subnet because out interface is bridge1. if you want to keep the ...
by vasilaos
Tue Jun 13, 2017 4:12 pm
Forum: Scripting
Topic: Mikrotik Log
Replies: 8
Views: 3127

Re: Mikrotik Log

/file print
or if u use winbox go to files use drag and drop file to desktop
by vasilaos
Mon Jun 12, 2017 1:54 am
Forum: Scripting
Topic: Mikrotik Log
Replies: 8
Views: 3127

Re: Mikrotik Log

file should be created automatically under mikrotik files and you shouldn't see it work on system log. probably log action has not been created successfully and and you are logging to memory instead. see if logging action have been created by print command /system logging action print and if logging...
by vasilaos
Sun Jun 11, 2017 10:47 pm
Forum: Scripting
Topic: Mikrotik Log
Replies: 8
Views: 3127

Re: Mikrotik Log

Yes it is possible. As i understand you want to save connections log to disk file inside your mikrotik device. This is not that much recommended scenario because it may use a lot of memory and processing depending on how many connections there are. there are some limits for the created file like num...
by vasilaos
Sun Jun 11, 2017 9:50 pm
Forum: Beginner Basics
Topic: Mikrotik haplite speed issue
Replies: 7
Views: 2142

Re: Mikrotik haplite speed issue

G/N option is available in newer versions of routeros
by vasilaos
Sun Jun 11, 2017 6:42 pm
Forum: General
Topic: up routing by service ?
Replies: 1
Views: 706

Re: up routing by service ?

Yes you should know the all the dns names or hosts the site uses to connect and upload first. you can not use *.hubic.com. Then with a script resolve dns names to ip addresses and add them to an address list for later use. Also I'd like to upload from multiple PCs so marking/routing tcp/443 connecti...
by vasilaos
Sun Jun 11, 2017 6:15 pm
Forum: General
Topic: CCR1036-12G-4S
Replies: 9
Views: 2315

Re: CCR1036-12G-4S

by vasilaos
Sat Jun 10, 2017 3:20 pm
Forum: General
Topic: How to detect & block proxy & VPN Traffic
Replies: 3
Views: 2002

Re: How to detect & block proxy & VPN Traffic

you can bock something by knowing the protocol or port it uses to connect or you can block everything and allow only some ports like port 80 http or 443 https etc.
by vasilaos
Sat Jun 10, 2017 3:10 pm
Forum: General
Topic: Opening Ports
Replies: 10
Views: 3206

Re: Opening Ports

what u can do is forward ports from public ip to local ip with dst nat
by vasilaos
Fri Jun 09, 2017 9:07 pm
Forum: General
Topic: DNS failure when some of dynamic servers do not answer
Replies: 9
Views: 4019

Re: DNS failure when some of dynamic servers do not answer

But anyway, I suppose mikrotik should anyway rotate the queries to all dns-servers and get the answer from some of them? At least when the query-server-timeout is like 1s and query-total-timeout 10s, it should have time to ask from 10 dns-servers before timeout. There is no timeout but instead an i...
by vasilaos
Fri Jun 09, 2017 8:41 pm
Forum: General
Topic: DNS failure when some of dynamic servers do not answer
Replies: 9
Views: 4019

Re: DNS failure when some of dynamic servers do not answer

mikrotik reach the dns based on routes in routing table. if you have default route active primary isp then will query the dns of the second isp through the active route that might be your primary isp. add routes to the dns ip manually to select proper path. /ip route add dst-address=192.19.223.230 g...
by vasilaos
Wed Jun 07, 2017 6:35 pm
Forum: Beginner Basics
Topic: Few public IP without NAT
Replies: 4
Views: 1892

Re: Few public IP without NAT

So I set the address 217.153.XXX.13 on the computer with the gate 217.153.XXX.12 to move through the microtic.
what subnet have you set for the computer? can u do a tracert from the computer to see if you are being routed from 217.153.XXX.12?
by vasilaos
Wed Jun 07, 2017 3:44 pm
Forum: General
Topic: DNS failure when some of dynamic servers do not answer
Replies: 9
Views: 4019

Re: DNS failure when some of dynamic servers do not answer

if u have dual wan link and one of them fails then you are querying the dns server from the other link. usually isp dns servers are not public. you can query them only from inner network. what is happening in your case is that you can still ping the server from outside isp network so their status is...
by vasilaos
Tue Jun 06, 2017 5:57 pm
Forum: Wireless Networking
Topic: Zero handoff - Wifi roaming possible?
Replies: 8
Views: 4911

Re: Zero handoff - Wifi roaming possible?

Well would be even more awesome if a device can send and receive simultaneously to more than 1 physical ap considering it a single ap. something like synced ap placed in different locations working as 1
by vasilaos
Mon Jun 05, 2017 7:34 pm
Forum: Beginner Basics
Topic: Looking for suggestions on using Basebox 5 as mobile 2 Ghz Station and 5 Ghz AP
Replies: 7
Views: 1479

Re: Looking for suggestions on using Basebox 5 as mobile 2 Ghz Station and 5 Ghz AP

lol. Simpler way would be to enter the key into the right field
by vasilaos
Mon Jun 05, 2017 5:17 pm
Forum: Beginner Basics
Topic: Block internet access on specific physical port
Replies: 16
Views: 13364

Re: Block internet access on specific physical port

you can block communication to wan interface for example if your wan inteface is ether1 then: /ip firewall filter add action=drop in-interface=ether4 out-interface=ether1 or you can block traffc other than your lan network for example if your lan network is 192.168.0.0/24 then: /ip firewall filter a...
by vasilaos
Mon Jun 05, 2017 4:31 pm
Forum: Beginner Basics
Topic: Stupid Question how to make Internet connection work for my second special WAN..
Replies: 4
Views: 1190

Re: Stupid Question how to make Internet connection work for my second special WAN..

I am not very familiar with OpenVPN but i think you can make a tunnel directly from your CCR1036. There is another post explaining how to: https://forum.mikrotik.com/viewtopic.php?t=92546 then route traffic with connection mark through the tunnel otherwise you can connect the wan of your R7000 to a ...
by vasilaos
Mon Jun 05, 2017 4:08 pm
Forum: Beginner Basics
Topic: Looking for suggestions on using Basebox 5 as mobile 2 Ghz Station and 5 Ghz AP
Replies: 7
Views: 1479

Re: Looking for suggestions on using Basebox 5 as mobile 2 Ghz Station and 5 Ghz AP

You should be able to connect to any WPA2 secured network by configuring the profile correctly otherwise the UniFi is using some proprietary protocol u cant connect to it. But if you can connect with other devices like smartphone or laptop then you should be able to connect with mikrotik too. First ...
by vasilaos
Sun Jun 04, 2017 10:53 pm
Forum: Beginner Basics
Topic: Looking for suggestions on using Basebox 5 as mobile 2 Ghz Station and 5 Ghz AP
Replies: 7
Views: 1479

Re: Looking for suggestions on using Basebox 5 as mobile 2 Ghz Station and 5 Ghz AP

Hello! Idk if i understand what u want to achieve but first WPA2 is not a connection but an authentication method for secured wireless.

My question is u want to connect to any unsecured 2.4ghz around or to a specific secured network using WPA2. If is the second option then i assume u have the key.
by vasilaos
Sun Jun 04, 2017 1:40 pm
Forum: Beginner Basics
Topic: Stupid Question how to make Internet connection work for my second special WAN..
Replies: 4
Views: 1190

Re: Stupid Question how to make Internet connection work for my second special WAN..

i think your problem is your route for route mark OpenVPN. 0.0.0.0/24 dosent make any sense. should be 0.0.0.0/0 and you need to add 192.168.5.1 gateway for that route with no interface selected for that route. router os will select interface based on gateway. like this: /ip route add dst-address=0....
by vasilaos
Fri Jun 02, 2017 4:10 pm
Forum: Wireless Networking
Topic: nv2 tcp single conncetion problem
Replies: 8
Views: 2464

Re: nv2 tcp single conncetion problem

Thanks Elliot. 1. There are no obstacles but a lot of interference i guess since it is urban area. I think there might be a problem with noise detection on routeros or on wlan chipset itself since noise floor threshold is showing always around -116 and i dont think mine is a perfect environment for ...
by vasilaos
Wed May 31, 2017 1:39 pm
Forum: Wireless Networking
Topic: nv2 tcp single conncetion problem
Replies: 8
Views: 2464

Re: nv2 tcp single conncetion problem

Elliot can i ask you why use nstreme (exact size - 3600+). what is the purpose to it? i was thinking what could fix the disconnecting issue
by vasilaos
Wed May 31, 2017 1:32 pm
Forum: Wireless Networking
Topic: nv2 tcp single conncetion problem
Replies: 8
Views: 2464

Re: nv2 tcp single conncetion problem

I switched already another ap to nstreme with some tweaking and is working a lot better. even though other antennas connected to it disconnect sometimes, throughput is a lot better compared to nv2. nv2 seem to be a disaster on point to multi point maybe in noisy environments.
by vasilaos
Tue May 30, 2017 4:30 pm
Forum: Wireless Networking
Topic: nv2 tcp single conncetion problem
Replies: 8
Views: 2464

Re: nv2 tcp single conncetion problem

Yes i just tried now with station bridge and its the same result.
by vasilaos
Mon May 29, 2017 6:07 pm
Forum: Wireless Networking
Topic: nv2 tcp single conncetion problem
Replies: 8
Views: 2464

nv2 tcp single conncetion problem

I am experiencing low bandwidth test from a single tcp connection over nv2 protocol. This problem is not present over nstream protocol. since nstream has some disconnecting problems i have preferred using nv2. Or should i not use nv2 and nstream at all? i seen many posts in the past about this but n...
by vasilaos
Sat Jan 28, 2017 8:33 pm
Forum: Wireless Networking
Topic: Open Wireless Encryption
Replies: 6
Views: 2354

Re: Open Wireless Encryption

I know how to set up a hotspot. what hotspot configuratin has to do with my question?
by vasilaos
Fri Nov 18, 2016 5:42 pm
Forum: Wireless Networking
Topic: Open Wireless Encryption
Replies: 6
Views: 2354

Re: Open Wireless Encryption

What would you like to achieve by this? Why cannot users put in a one time password?


No, users can not put in a one time password. Actually i don't have to know the costumers. I just want to provide free wireless access on a secured wireless connection.
by vasilaos
Wed Nov 16, 2016 5:56 pm
Forum: Wireless Networking
Topic: Open Wireless Encryption
Replies: 6
Views: 2354

Open Wireless Encryption

Is it possible to set a Wireless Access Point open for anyone to connect without having to input a pass key and at the same time have the wireless connection encrypted over the air?
by vasilaos
Wed Oct 08, 2014 11:52 am
Forum: Scripting
Topic: elif statement
Replies: 12
Views: 12355

elif statement

can i use elif statement in mirkotik scripts?
by vasilaos
Wed Apr 09, 2014 2:13 am
Forum: Wireless Networking
Topic: Nstreme or Nv2. Is Nstreme Obsolete?
Replies: 23
Views: 16488

Re: Nstreme or Nv2. Is Nstreme Obsolete?

Nv2 should give you better speed. Nstreme in some cases could have better latency.
nv2 does not give better speed in my case and nstreme is disconnecting because of pool timeout.
by vasilaos
Sat Apr 05, 2014 12:50 am
Forum: Wireless Networking
Topic: Omnitik issue
Replies: 4
Views: 1746

Re: Omnitik issue

I have set Frequency Mode to manual-txpower not to regulatory domain. on the other side those with the long distance are SEXTANT G 5HPnD. those far away have better throughput with nstreme protocol but when i change the protocol another cpe that is located close keeps disconnecting and associating.
by vasilaos
Fri Apr 04, 2014 11:54 am
Forum: Wireless Networking
Topic: 2011UiAS-2HnD-IN: constant signal drop outs
Replies: 7
Views: 3270

Re: 2011UiAS-2HnD-IN: constant signal drop outs

I have the same problem with 2011UAS-2HnD-IN. i do not buy them anymore
by vasilaos
Fri Apr 04, 2014 5:27 am
Forum: Wireless Networking
Topic: Omnitik issue
Replies: 4
Views: 1746

Omnitik issue

I am having some problems with one of my omnitiks. One of my problems is that working withi higher frequencies i get lower signal. Is this normal? 3 of my client cpe-s that are 5km distance away from the omnitik does not connect because of low signal when i use higher frequencies. Is it possible tha...
by vasilaos
Thu Mar 27, 2014 12:43 pm
Forum: General
Topic: problems with poe-out
Replies: 2
Views: 1745

Re: problems with poe-out

yes its RB951Ui-2HnD sorry routeros is 6.10 firmware is 3.12 what is poe firmware? the power supply is the original supplied with this device. 24v 0.8A regular shaped if i cant power a sxt lite 5 with this port whats the purpose mikrotik made it for? i had to make a jumper to power my sxt in this ca...
by vasilaos
Fri Mar 21, 2014 11:35 am
Forum: General
Topic: problems with poe-out
Replies: 2
Views: 1745

problems with poe-out

I am having problems with poe out feature. i have connected a sxt lite5 to a RB951G-2HnD and it randomly restarts most with traffic. how can i fix this?
by vasilaos
Sun Dec 15, 2013 11:13 pm
Forum: General
Topic: Android USB Tether to RouterBoard
Replies: 11
Views: 10878

Re: Android USB Tether to RouterBoard

can you add some usb ethernet drivers to. I have some USB To LAN i can not connect. Also some cheap usb wifi device would be great. i can use only TP-Link TL-WN722N for the moment but the price is relatively hi compared to some other adapters. i can give more information if you want. i need the othe...
by vasilaos
Wed Apr 03, 2013 12:38 pm
Forum: General
Topic: RouterOS v6rc12
Replies: 78
Views: 30558

Re: RouterOS v6rc12

Hello IP>>HotSpot>>Active Users>> Users Tx Rate , is not active on this Version. It was not active on RC11 also. Any suggestion ? Regards Do you use Bridge ? I had this problem in v6rc11. i was waiting for this fix. It seem has not been fixed http://forum.mikrotik.com/viewtopic.php?f=2&t=70207
by vasilaos
Wed Apr 03, 2013 12:19 pm
Forum: General
Topic: Hotspot tx rate problem
Replies: 10
Views: 4040

Re: Hotspot tx rate problem

did RouterOS v6rc12 resolve this?
by vasilaos
Sun Mar 10, 2013 12:28 am
Forum: General
Topic: Hotspot tx rate problem
Replies: 10
Views: 4040

Re: Hotspot tx rate problem

i downgraded to v6rc9 and works fine now. So it was related to the v6rc11. but now the router restarts randomly and i don't understand why. waiting for v6rc12
by vasilaos
Sun Mar 10, 2013 12:23 am
Forum: RouterBOARD hardware
Topic: OmniTIK and RB711-2n
Replies: 114
Views: 64006

Re: OmniTIK and RB711-2n

Omnitik has a great performance and i like the dual polarization very effective. I like to modify this ap with some diodes to give power to the other ports so i can connect an 2.4 ghz ap and other ptp links. 2.4 ghz variant would be a great solution for me since i am very satisfied with Omnitik 5.8 ...
by vasilaos
Sun Feb 24, 2013 3:53 pm
Forum: General
Topic: Hotspot tx rate problem
Replies: 10
Views: 4040

Hotspot tx rate problem

after updated to RouterOS v6rc9 then to RouterOS v6rc11 i see in the hotspot hosts and active clients that there is no tx traffic and the radius server is not getting information about the tx traffic. http://www.ozoone.net/share/txrate.jpg what is this related to? have i to downgrade to the previous...
by vasilaos
Mon Apr 16, 2012 9:25 pm
Forum: General
Topic: reset counters hotspot
Replies: 4
Views: 11744

reset counters hotspot

hello! i have a simple question. I want to reset the user counters. there is a reset all counters button. even when i open a single hotspot user the button says reset all counters. i have clicked by mistake this button twice loosing all the user counters. i need to know how can i reset a single user...
by vasilaos
Tue Aug 04, 2009 10:24 am
Forum: Wireless Networking
Topic: Problem with WDS on v3.27
Replies: 0
Views: 588

Problem with WDS on v3.27

I have a RB600A with 3 wireless adapters R52H. now i want to replace a the main TrendNet access point with this one and connect to it some TrendNet access points acting as client/repeater. the problem is that wen TrendNet tew-453apb acting as client/repeater try to connect the first time it does not...