Community discussions

Search found 109 matches

by NetVicious
Mon Oct 14, 2019 9:51 pm
Forum: Scripting
Topic: RB3011 Can I monitorize voltage from DC and from POE IN?
Replies: 13
Views: 1104

Re: RB3011 Can I monitorize voltage from DC and from POE IN?

Yes. I understand how it works. But IMHO if the system not:s getting power from a POE IN port it should show it too as it does with PSUs.

In that way we can check if all it's ok.
by NetVicious
Mon Oct 14, 2019 5:46 pm
Forum: Scripting
Topic: RB3011 Can I monitorize voltage from DC and from POE IN?
Replies: 13
Views: 1104

Re: RB3011 Can I monitorize voltage from DC and from POE IN?

Hi! I did the test with a HeX and it works as eworm said. I only shows one voltage. Here's the test. 24V it's what it gets directly from the DC adapter, and 23.9V it's the voltage it gets from the POE IN port. [admin@MikroTik] > system health print voltage: 24V temperature: 42C [admin@MikroTik] > sy...
by NetVicious
Fri Oct 11, 2019 6:47 pm
Forum: Scripting
Topic: RB3011 Can I monitorize voltage from DC and from POE IN?
Replies: 13
Views: 1104

Re: RB3011 Can I monitorize voltage from DC and from POE IN?

I don't bought yet the rb3011. I was only asking if RouterOS publishes both voltages or something we can check to discover if POE In or DC In power supply failed. I see someone was writing about RB100 with has 2 AC or DC In. Someone with a device powered at the same time with DC/AC in and POE In can...
by NetVicious
Fri Oct 11, 2019 1:41 pm
Forum: Scripting
Topic: RB3011 Can I monitorize voltage from DC and from POE IN?
Replies: 13
Views: 1104

RB3011 Can I monitorize voltage from DC and from POE IN?

Hi!

I read RB3011 can be powered at the same time within the DC port and the eth1 POE IN port.
I want to know if both voltages can be monitorized within a script to check if one of the power adapters died.

Regards,
by NetVicious
Sat Oct 05, 2019 12:35 pm
Forum: Scripting
Topic: HTTP put backup
Replies: 7
Views: 1628

Re: HTTP put backup

I'm talking about embedding all in one application. I know I can use one external SFTP/SSH server, but If you want to release one application with all inside that external SSH server it's an extra. I don't know how why it's so difficult to add http/https upload when they have the http/https protocol...
by NetVicious
Fri Oct 04, 2019 11:15 am
Forum: Scripting
Topic: HTTP put backup
Replies: 7
Views: 1628

Re: HTTP put backup

Yes I know, but it will be easier to use TFTP-upload or HTTP(s)-upload because there are lots of free components outside. For SFTP it's a bit difficult and expensive to add it to one self-made application
by NetVicious
Wed Oct 02, 2019 7:26 pm
Forum: General
Topic: multiple ssid & vlan bridge filtering
Replies: 1
Views: 339

Re: multiple ssid & vlan bridge filtering

Paste your config here.
by NetVicious
Wed Sep 25, 2019 3:26 pm
Forum: Scripting
Topic: HTTP put backup
Replies: 7
Views: 1628

Re: HTTP put backup

After some test, I've discovered that the problem is that you can't get file contents greater than 4KBytes. Then I have other problem: I don't know how to use a file as palyload for /tool fetch http-method=put The file command it's which has the problem with files greater than 4KBytes. I tried it f...
by NetVicious
Wed Sep 25, 2019 1:55 pm
Forum: Scripting
Topic: Upload file with fetch on mode http
Replies: 7
Views: 2701

Re: Upload file with fetch on mode http

http-data parameter of /tool fetch it's only used to set which string will be sent to the server when doing one upload. It doesn't work (at this moment with RouterOS 6.45.6) in the way you're trying to do writing the name of the file you want to upload on the http-data parameter. You should use the ...
by NetVicious
Wed Sep 25, 2019 11:53 am
Forum: Announcements
Topic: Newsletter 91
Replies: 12
Views: 8589

Re: Newsletter 91

Nice one. What about one MQS with one ethernet port for POE IN and another ethernet port for POE OUT. The new ethernet port will be only used to get power from the current wire, and also can be good for do not have the device down so much time while configuring it. It will be easier to disconect the...
by NetVicious
Fri Sep 13, 2019 2:08 pm
Forum: General
Topic: Mikrotik AP with some SSIDs VLANed to a pfSense router
Replies: 0
Views: 223

Mikrotik AP with some SSIDs VLANed to a pfSense router

Hi! I'm having problems creating a scenario like this image: https://i.postimg.cc/vZf8MDQt/unnamed0.png I was struggling me with one bridge for each VLAN (wrong), assigning the IP address to the bridges instead to the VLAN interfaces, .... But now I think I'm doing it correctly but it doesn' works. ...
by NetVicious
Fri Aug 30, 2019 10:50 am
Forum: General
Topic: Check-for-updates cache
Replies: 0
Views: 236

Check-for-updates cache

Hi! I'm trying to install in some devices the last RouterOS update and I'm getting the "already up to date" message in some devices. As I see on the website, and in other devices I manage, the last one it's the 6.45.5 Obviously it should be a cache related question. That device has the web-proxy dis...
by NetVicious
Mon Jul 22, 2019 9:50 am
Forum: Scripting
Topic: How to read file content using API?
Replies: 7
Views: 1400

Re: How to read file content using API?

More than one year later and the bug it's there yet.

I'm tryting to get the result of the /export command and it seems it's affected by the same limitation of the API.
by NetVicious
Thu Jul 18, 2019 11:59 am
Forum: Scripting
Topic: MtkManager (Remote upgrade tool for RouterOS)
Replies: 13
Views: 1734

Re: MtkManager (Remote upgrade tool for RouterOS)

Currently the application doesn't has any measure you wrote. I will add for sure the option to use non-standard ports. The port knocking seems to be easy to add, but I should need a testing setup to test it. I know what's a DSA key pair, but I don't know now how it applies to one RouterOS API port c...
by NetVicious
Thu Jul 18, 2019 10:52 am
Forum: Scripting
Topic: MtkManager (Remote upgrade tool for RouterOS)
Replies: 13
Views: 1734

Re: MtkManager (Remote upgrade tool for RouterOS)

Hi dakota! Here I think it will be better if we write in English. If you want to talk with me in spanish I don't have any problem to do it on private. My application will work perfectly if you have TCP/IP connection with the RouterOS devices. They can be on an internal network, connected within VPNs...
by NetVicious
Wed Jul 17, 2019 10:03 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69919

Re: v6.45.1 [stable] is released!

Old, good RB450G. Just upgraded to 6.45.1 from something like 6.40 and now can't connect through any port. 4 ports switched and one with DHCP client. Winbox says nothing (even after updating it and clearing cache). The only solution seems to be a rs232 (not tried yet). Any thoughts on that? Try con...
by NetVicious
Fri Jul 05, 2019 7:28 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69919

Re: v6.45.1 [stable] is released!

Yes, because of script. I did not run the script on first day, it was yesterday, and till then nobody complained the issue. Yesterday evening when i got to know the issue from several clients one by one etc then I took the notice. because other than hAP lite router, no one else complained till now ...
by NetVicious
Fri Jul 05, 2019 11:26 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69919

Re: v6.45.1 [stable] is released!

As I posted before I had (as others) problems with GRE with this new version of RouterOS. In my case I'm using pptp VPN tunnels. I have a master router acting as pptp Server and some other devices acting as pptp client. 2 of that clients had problems trying to connect to the pptp server after the 6....
by NetVicious
Wed Jul 03, 2019 12:11 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69919

Re: v6.45.1 [stable] is released!

@andriys. Sorry but I don't saw the official strods post answering a lot of posts of this threads with the info about GRE. I said temporary fix because I have some RB450G with 6.45.1 running perfectly against a RB850Gx2 with 6.45.1 without any new firewall rule about GRE . That's why I though it's a...
by NetVicious
Wed Jul 03, 2019 11:30 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69919

Re: v6.45.1 [stable] is released!

As I read before on this thread It seems 6.45.1 has some problem with GRE. When you do make the effort of reading the topic first and seeing others with the same problem, why don't you go that tiny step further and read the replies that they got (also from MikroTik) about the cause of this "problem...
by NetVicious
Wed Jul 03, 2019 10:39 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69919

Re: v6.45.1 [stable] is released!

Hi! As I read before on this thread It seems 6.45.1 has some problem with GRE. I have some Mikrotik RB450G (call they A, B, C, .....) connected to one RB850Gxx2 (call him as master). "Master" has one PPTP Server binding for each other (A, B, C). After upgrading all the devices to 6.45.1, A and C can...
by NetVicious
Tue Jul 02, 2019 5:53 pm
Forum: Scripting
Topic: MtkManager (Remote upgrade tool for RouterOS)
Replies: 13
Views: 1734

Re: MtkManager (Remote upgrade tool for RouterOS)

My little tool it's near the public release.
I added threads to do the actions in less time.
Check the video on the first post to see what it can do.
by NetVicious
Tue Jun 25, 2019 10:58 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 131
Views: 45938

Re: Another RouterOS API Delphi Client

I see. I'm trying to create a converter of the "export commands" to the "API commands". I don't like to leave so much ports opened on my devices.
Thanks for the info. If I cannot translate all the commands to the API style I will use the ssh mode.
by NetVicious
Tue Jun 25, 2019 5:10 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 131
Views: 45938

Re: Another RouterOS API Delphi Client

Hi!
It's there a way to run commands exported directly from a Mikrotik without modifying the way we need to send the parameters within the API?

I want to add one option to my application to send raw commands as we paste they on the Terminal.

Regards,
by NetVicious
Mon May 27, 2019 11:05 am
Forum: Scripting
Topic: MtkManager (Remote upgrade tool for RouterOS)
Replies: 13
Views: 1734

Re: MtkManager (Remote upgrade tool for RouterOS)

Read the previous message of your post ;-)
by NetVicious
Fri May 24, 2019 7:50 pm
Forum: Scripting
Topic: MtkManager (Remote upgrade tool for RouterOS)
Replies: 13
Views: 1734

Re: MtkManager (Remote upgrade tool for RouterOS)

Hi! The application it's ready for the first betatesters. Please send me one email to "my nick + gmail" I will send you one link to the application. At this moment the application can check each device added, getting info about: serial number model RouterOs version Firmware version If the date+time ...
by NetVicious
Thu May 09, 2019 4:32 pm
Forum: Scripting
Topic: MtkManager (Remote upgrade tool for RouterOS)
Replies: 13
Views: 1734

MtkManager (Remote upgrade tool for RouterOS)

Hi! First of all I need to send thanks to Chupaka for it's Delphi API library. Here I'm introducing my MtkManager, a tool which will help us to upgrade RouterOS and firmware in several RouterOS devices with a few clicks. I don't know if there it's published a similar tool. I know there it's the Dude...
by NetVicious
Tue Apr 30, 2019 6:36 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 131
Views: 45938

Re: Another RouterOS API Delphi Client

Connection error: No SSL/TLS support compiled
Probably you need libeay32.dll and ssleay32.dll
Perfect. That worked for the API Test application.

I will try another time to use openssl on my code, thanks.
by NetVicious
Tue Apr 30, 2019 12:44 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 131
Views: 45938

Re: Another RouterOS API Delphi Client

Did you try API Test program? It works for me with SSL. If you're refering to the APITest-1.3.exe executable, when I run it and I check the TLS checkbox I got this error when trying to connect: --------------------------- RouterOS API Demo --------------------------- Connection error: No SSL/TLS su...
by NetVicious
Wed Apr 10, 2019 6:59 pm
Forum: Scripting
Topic: Another RouterOS API Delphi Client
Replies: 131
Views: 45938

Re: Another RouterOS API Delphi Client

Hi! The Chupaka library works perfectly on non-SSL protocol, but I want to use it using the API-SSL port. I tried several synapse library versions, criptlib or openssl and I got one " Received TLS alert message: Handshake failure " error when trying to use ssl_cryptlib and a " Network Subsystem it's...
by NetVicious
Thu Jul 12, 2018 9:07 am
Forum: General
Topic: Auto lock nuts for fixing antennas
Replies: 8
Views: 671

Re: Auto lock nuts for fixing antennas

It was a typo sorry. Half = have ;-) I changed it.
by NetVicious
Wed Jul 11, 2018 6:39 pm
Forum: General
Topic: Auto lock nuts for fixing antennas
Replies: 8
Views: 671

Re: Auto lock nuts for fixing antennas

mmm, I'm thinking we need some power to fully tight they so they should have self-locking ring too.
by NetVicious
Wed Jul 11, 2018 5:36 pm
Forum: General
Topic: Auto lock nuts for fixing antennas
Replies: 8
Views: 671

Re: Auto lock nuts for fixing antennas

The kit doesn't includes auto lock nuts, that was my question for getting it more secured.
You can see it on the point 3 of the mounting guide PDF
https://i.mt.lv/routerboard/files/Ilust ... 095554.pdf

The nuts are directly fitted on the mouting kit.
by NetVicious
Wed Jul 11, 2018 3:08 pm
Forum: General
Topic: Auto lock nuts for fixing antennas
Replies: 8
Views: 671

Re: Auto lock nuts for fixing antennas

I understand your answer perfectly, but what about the nuts which link the dish and the mounting kit?
by NetVicious
Tue Jul 10, 2018 6:47 pm
Forum: General
Topic: Auto lock nuts for fixing antennas
Replies: 8
Views: 671

Auto lock nuts for fixing antennas

Hi!
I bought a pair of Wireless Wire Dish (aka LHGG-60ad) and I want to ask why they don't include auto lock nuts instead of the usual nuts.
Any problem to use this kind of nuts on exteriors?
Regards,
by NetVicious
Mon Jul 02, 2018 3:59 pm
Forum: The Dude
Topic: Remote Auto-upgrade RouterOS
Replies: 1
Views: 696

Remote Auto-upgrade RouterOS

I know Dude has one option to mass upgrade RouterOS version, but this upgrade it's done uploading the npk files from the Dude Box to each RouterOS device. Why not add one option to use remotely the auto-upgrade option RouterOS has? This it's done in System/Packages/Check for Updates or in the Quick ...
by NetVicious
Thu May 31, 2018 2:28 pm
Forum: Wireless Networking
Topic: RBM33G + two Wireless mpci-e cards ?
Replies: 3
Views: 696

Re: RBM33G + two Wireless mpci-e cards ?

Nice info! You tested it with lots of traffic in both network cards?
by NetVicious
Thu May 31, 2018 10:47 am
Forum: Wireless Networking
Topic: RBM33G + two Wireless mpci-e cards ?
Replies: 3
Views: 696

Re: RBM33G + two Wireless mpci-e cards ?

I was looking a solution with two wireless cards too, and when I saw the price of the RBM33G I thought something was wrong. Obviously this it's the limitation the routerboard has, and that's why it's more cheaper than the other RB43X models
by NetVicious
Thu Oct 19, 2017 11:37 am
Forum: Wireless Networking
Topic: External antenna connectors of WAP LTE Kit
Replies: 2
Views: 1206

Re: External antenna connectors of WAP LTE Kit

Thanks uldis, I searched on the quickstart guide for external antenna without reading the full document.

I discovered it myself and I was preparing this image ;-)
wap_lte_opened.jpg
Thx for the info. Regards,
by NetVicious
Thu Oct 19, 2017 11:15 am
Forum: Wireless Networking
Topic: External antenna connectors of WAP LTE Kit
Replies: 2
Views: 1206

External antenna connectors of WAP LTE Kit

Hi! I bought two units and all works flawlessly as usual, but I don't see where are the external antenna connectors of the LTE modem. I think I should open the case (not the screw protected bottom part) and change the internal wires to the internal antennas to my external antennas within a little pi...
by NetVicious
Tue May 30, 2017 2:36 pm
Forum: Announcements
Topic: FastTrack - New feature in 6.29
Replies: 237
Views: 140087

Re: FastTrack - New feature in 6.29

Hi!

I read RB4xx don't supports FastTrack. But why Winbox it showing this option on the Firewall action ?

IMHO, Winbox should detect this and the fastrack option should not appear.

Regards,
by NetVicious
Tue May 16, 2017 2:43 pm
Forum: RouterBOARD hardware
Topic: Bruteforce login prevention
Replies: 11
Views: 33990

Re: Bruteforce login prevention

Hi! IMHO the RouterOS should have a bruteforce protection system for it's services. If you want to protect a service which Mikrotik forwards+NAT you should use Mikrotirk filters or another solution on the destination box. That should include the Mikrotik services SSH, Winbox, VPNs (L2TP, PPTP, IPSec...
by NetVicious
Tue Apr 25, 2017 5:47 pm
Forum: The User Manager
Topic: Active USers Vs Active Session
Replies: 7
Views: 9325

Re: Active USers Vs Active Session

I see.

But only related to hotspot. VPN connections are not counted in our RB/450

Please tell me if external Radius server logins count as user manager database. And external logins within Facebook, Linkedin, Twitter APIs?
by NetVicious
Tue Apr 25, 2017 3:33 pm
Forum: The User Manager
Topic: Active USers Vs Active Session
Replies: 7
Views: 9325

Re: Active USers Vs Active Session

Looking these wikis [1] and [2] and this post I have the same question yet! [1] https://wiki.mikrotik.com/wiki/User_Manager/Active_users [2] https://wiki.mikrotik.com/wiki/User_Manager/Active_sessions What needs a session or what counts as active user? I understand if someone connects to winbox or t...
by NetVicious
Tue Nov 08, 2016 5:44 pm
Forum: General
Topic: Feature request: VPN push route
Replies: 6
Views: 3325

Re: Feature request: VPN push route

Thanks for the info.

Link for other people looking for the same: http://wiki.mikrotik.com/wiki/Manual:IP ... _Mode_Conf
by NetVicious
Tue Nov 08, 2016 12:56 pm
Forum: General
Topic: Feature request: VPN push route
Replies: 6
Views: 3325

Re: Feature request: VPN push route

I read on the forum using PPP VPN connection it's not possible to push routes to the client.

What about IPSec VPN or OpenVPN ? It's not possible either?
by NetVicious
Wed Mar 23, 2016 3:11 pm
Forum: General
Topic: Send static routes to VPN clients on PPTP/L2TP/OpenVPN
Replies: 2
Views: 592

Send static routes to VPN clients on PPTP/L2TP/OpenVPN

I know this topic it's largely posted on this forum from a lot of time (>6 years) :? It seems the position of Mikrotik it's to not develop nothing outside the RFCs (aka standards) I was solving this problem using scripts on local computers, or modifying the configuration of the OpenVPN client. One s...
by NetVicious
Mon Feb 01, 2016 10:47 am
Forum: Announcements
Topic: Winbox3.1 released!
Replies: 50
Views: 26526

Re: Winbox3.1 released!

Winbox 3.1 doesn't fix the Neighbors problem on the detection of RouterOs in the same network.

I'm connecting with a RB450G using the mac address but the neighbors tab doesn't shows nothing.
by NetVicious
Mon Jan 18, 2016 10:16 am
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47481

Re: RB850Gx2 - Release date?

English translation of DmitryAVET link ;-)
http://www.microsofttranslator.com/bv.a ... k-RB850Gx2
by NetVicious
Tue Dec 15, 2015 10:16 am
Forum: Announcements
Topic: Winbox3.0 released!
Replies: 45
Views: 15672

Re: Winbox3.0 released!

Neighbors works fine. It does exactly the same as the three dots button. What do you have there? Are you using Winbox 3.0 (not beta)? Here it's not working. I don't know If I disabled something but running the old winbox 2 on a computer with a Routerboard as router of the network nothing it's shown...
by NetVicious
Thu Dec 03, 2015 2:18 pm
Forum: Announcements
Topic: Winbox3.0 released!
Replies: 45
Views: 15672

Re: Winbox3.0 released!

Hi! Where's the option to detect the near Mirkotik devices using broadcast ? On the Winbox 2.0 there was a button with 3 dots at the left of the "connect" button. I thought this function was moved to the Neightbors tab on Winbox 3. When it was a beta I thought it won't work due to work in progress, ...
by NetVicious
Tue Sep 15, 2015 2:08 pm
Forum: RouterBOARD hardware
Topic: Angled Antenna with Magnetic base
Replies: 0
Views: 401

Angled Antenna with Magnetic base

Hi! I'm looking for one antenna for the 2.1Ghz band of GRPS. I need one angled antenna with magnetic base like the image below but I need to put it angled because it will be used on the lateral of one big van. http://thumbs3.ebaystatic.com/d/l225/m/mQAza6WG-VFniWDbNNUdOhA.jpg I don't found any magne...
by NetVicious
Wed Aug 12, 2015 2:18 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47481

Re: RB850Gx2 - Release date?

"1" in the end will indicate that it has a wireless slot or card. + each change in product code results in new government certification for us, to import that product, so i'm against changing any names, especially in cases when there are no physical differences between boards. That's a good reason,...
by NetVicious
Wed Aug 12, 2015 11:16 am
Forum: RouterBOARD hardware
Topic: RB850Gx2 - Release date?
Replies: 193
Views: 47481

Re: RB850Gx2 - Release date?

IMHO the new RB850Gx2 with hardware encryption should have been called RB851Gx2

Now If we want to buy the improved version of RB850Gx2 we need to ask our provider to know it's serial number
by NetVicious
Mon Aug 10, 2015 3:28 pm
Forum: General
Topic: IPSec Tunnel SAs
Replies: 5
Views: 782

Re: IPSec Tunnel SAs

Ok, thanks for the info. I checked that and RouterOs tried to renew phase 2 SAs when the SAs had 24 minutes remaining of lifetime. 30 minutes remaining it's 75% so it seems to be ok. The problem it's the other router (Mcaffe firewall) has the soft rekeying at its 85% of SA timeout, so my rekey at ar...
by NetVicious
Mon Aug 10, 2015 9:32 am
Forum: General
Topic: IPSec Tunnel SAs
Replies: 5
Views: 782

Re: IPSec Tunnel SAs

Thanks mrz. And you could tell me which should be the standard behaviour or these SAs .... If the phase 2 SAs get its configured timeout the RouterOS should re-negotiate another new phase 2 SAs ? Or it don't needs to do that because it will negotiate new phase 2 sas with the phase 1 SA when the tunn...
by NetVicious
Fri Aug 07, 2015 1:59 pm
Forum: General
Topic: IPSec Tunnel SAs
Replies: 5
Views: 782

IPSec Tunnel SAs

Hi! Someone could tell me which type of SAs we see on IP / IPSec / Installed SAs ? As I know there are two different SAs on IPSec (IKE SAs for phase 1, and IPSec SA for phase 2). Looking to the timeouts, it seems the Installed SAs tag shows IP Sec Sas related to phase 2. And in the Remote Peers tabs...
by NetVicious
Fri Jul 31, 2015 6:11 pm
Forum: General
Topic: IPsec RouterOS <-> Juniper. After phase2 timeouts VPN don't works
Replies: 0
Views: 417

IPsec RouterOS <-> Juniper. After phase2 timeouts VPN don't works

Hi! I set one IPSec VPN tunnel within a RB450G and a Juniper. All seems to be configured correctly because when we start the tunnel all goes ok, we can connect to the server in the other part ... But when the phase 2 gets timeout-ed the tunnel seems to be broken. After that moment on the MK there it...
by NetVicious
Wed Jul 22, 2015 3:19 pm
Forum: General
Topic: Ad Blocking hosts file
Replies: 34
Views: 28606

Re: Ad Blocking hosts file

Hi! I got here looking for one configuration for RouterOS to set an external zone to the Routerboard DNS server. I read here something about dnsmasq or creating a new zone. This it's possible using RouterOS? I want to say to the RouterOs DNS if it gets a query asking for domain.com it should ask for...
by NetVicious
Tue Jul 21, 2015 3:28 pm
Forum: General
Topic: ipsec lifetime clarification
Replies: 1
Views: 1486

Re: ipsec lifetime clarification

Proposal it's the phase 2 of IPSec and it's lifetime means when it should renew the SAs used. Peer it's the phase 1 of IPSec and it's lifetime means when it should close the current connection and create a new one. On the IP / IpSec / Peers you could see the phase 1, and if you double-click one you ...
by NetVicious
Thu May 07, 2015 4:51 pm
Forum: General
Topic: IPSEC with main exchange mode in a NAT environment
Replies: 0
Views: 491

IPSEC with main exchange mode in a NAT environment

Hi! Time ago I post a little tutorial [1] for setting a IPSec VPN connection with RouterOS when the Mikrotik it's after a firewall. That tutorial uses the main exchange mode and needs to set in the ID field the external wan IP address of that office. The option to change the ID on main mode was remo...
by NetVicious
Wed Apr 22, 2015 6:01 pm
Forum: RouterBOARD hardware
Topic: RB 450g no beep signals
Replies: 13
Views: 7979

Re: RB 450g no beep signals

I took the routerboard to an electronical technician which changed the electronical capacitor which was a bit blowed up (or inflated) Take an eye on these capacitors: http://www.pcstats.com/articleimages/200302/capblown_3.jpg If your RouterBoard has one in a similar status that should be the problem...
by NetVicious
Wed Feb 25, 2015 5:34 pm
Forum: General
Topic: IPsec encryption
Replies: 2
Views: 712

Re: IPsec encryption

Looking for the same.

The archived RB1100AHx2 it's sure at 100% it has hardware encription for IPSec.

http://i.mt.lv/routerboard/files/RB1100.pdf
by NetVicious
Wed Feb 25, 2015 5:32 pm
Forum: General
Topic: hardware encryption for vpn
Replies: 5
Views: 1767

Re: hardware encryption for vpn

Normis, can you post a list of RouterBoards with hardware encryption ? A new line element on the Product specifications on the website routerboard.com should be added.


And a little wiki with one explanation about whats hardware encryption (IPSec only and so on) would be perfect.
by NetVicious
Fri Feb 13, 2015 2:32 pm
Forum: General
Topic: Winbox 3 RC
Replies: 639
Views: 123935

Re: Winbox 3 RC

Autoupdate says last version it's RC4!

The RC5 it's on website
by NetVicious
Fri Feb 13, 2015 1:40 pm
Forum: General
Topic: Winbox 3 RC
Replies: 639
Views: 123935

Re: Winbox 3 RC

Allow new line characters on the Memo component to see the whatsnew texts smooth ;-)
by NetVicious
Thu Feb 12, 2015 6:14 pm
Forum: RouterBOARD hardware
Topic: RB 450g no beep signals
Replies: 13
Views: 7979

Re: RB 450g no beep signals

Hi! Sorry for revive this old thread, mitay you got any solution ? My RB450G it's a bit death. Blue led it's on and the upper led it's also on. No beep on boot. No activity on ethernet port leds, no link, Only a fast On and Off when I insert the power. None within hyperterminal COM port. The only th...
by NetVicious
Tue Jan 27, 2015 3:31 pm
Forum: General
Topic: Winbox 3 RC
Replies: 639
Views: 123935

Re: Winbox 3 RC

Winbox closes suddenly If I press a menu button after saving session.

RouterOS 6.24, Win XP SP3.

Name of the session doesn't has any strange character, only alphabetical characters.
by NetVicious
Mon Oct 27, 2014 9:57 am
Forum: General
Topic: Vulnerability on NAT-PMP (Cert VU#184540)
Replies: 1
Views: 1049

Vulnerability on NAT-PMP (Cert VU#184540)

Hi!

It's this vulnerability fixed at the 6.20 release ?

http://www.kb.cert.org/vuls/id/184540

If not, there it's any workaround or temp fix?

Regards,
by NetVicious
Wed May 21, 2014 4:23 pm
Forum: General
Topic: IPSec tunnel within Cisco
Replies: 2
Views: 1103

Re: IPSec tunnel within Cisco

Hi! thx for answer. I fixed it yesterday. It seems it was a problem with the IP the Cisco was receiving which was not the IP agreed and set on the Phase 2. I needed to do a real snat on the Mikrotik because I want other networks different than what we define on the MKT phase 2. Check my solution I p...
by NetVicious
Wed May 21, 2014 4:22 pm
Forum: General
Topic: IPSec VPN tunnel within Cisco with lots of inside subnets
Replies: 1
Views: 801

IPSec VPN tunnel within Cisco with lots of inside subnets

IPSec tunnel within a Mikrotik behind a Firewall and a Cisco ASA 5510 NETWORK MAP mkt_natted_to_cisco.png MIKROTIK CONFIG Note: Take attention to your encryption algorithms, lifetimes and other things, because this config should be exactly the same on the Cisco. IP / IPSec / Peer (aka IPSec Phase 1)...
by NetVicious
Mon May 19, 2014 9:55 am
Forum: General
Topic: RB1100AHx2 replacement fans
Replies: 3
Views: 1144

Re: RB1100AHx2 replacement fans

My next step if I was on your position it's: - Ask this ebayer: http://www.ebay.co.uk/usr/sentory-global-trade?_trksid=p2047675.l2559 He has something similar what you're looking for, but I think it's not the exact fan you need. http://www.ebay.ca/itm/1x-D4020V12HB-RD-SYM-BANG-12V-DC-0-16A-Brushless...
by NetVicious
Mon May 19, 2014 9:46 am
Forum: General
Topic: VPN ipsec between AVM FritzBox an Mikrotik
Replies: 15
Views: 9233

Re: VPN ipsec between AVM FritzBox an Mikrotik

I didn't read nothing about AVM FritzBox until I saw it on your post. So I cannot help you.

Try reading tutos of how to config Mikrotik against IPSEC Cisco.

http://gregsowell.com/?p=787
by NetVicious
Fri May 16, 2014 3:24 pm
Forum: General
Topic: IPSec tunnel within Cisco
Replies: 2
Views: 1103

IPSec tunnel within Cisco

Hi! I'm trying to do one IPSec tunnel within one RB450G and a Cisco ASA 5510. I'm doing what this tuto [1] says but I'm stuck on the IPSec phase2 with a message saying: Received a valid R-U-THERE, ACK sent And it loops always with the same codes. No traffic it's going throught the tunnel because the...
by NetVicious
Wed May 14, 2014 7:45 pm
Forum: General
Topic: RB1100AHx2 replacement fans
Replies: 3
Views: 1144

Re: RB1100AHx2 replacement fans

Try asking the manufactured for a local provider near you:
http://www.activa.com.tw/contact?language=en
by NetVicious
Wed May 14, 2014 7:19 pm
Forum: General
Topic: IP SEC UP, NO TRAFFIC
Replies: 1
Views: 505

Re: IP SEC UP, NO TRAFFIC

If you're masquerading, you need to create a NAT rule before all the other NAT rules with the source network and destination netwokt with Action: accept

This it's for disable masquerading
by NetVicious
Wed May 14, 2014 4:10 pm
Forum: General
Topic: VPN ipsec between AVM FritzBox an Mikrotik
Replies: 15
Views: 9233

Re: VPN ipsec between AVM FritzBox an Mikrotik

hansmeier61. Did you enabled the logging for ipsec ?
/system logging add topics=ipsec
by NetVicious
Tue Apr 22, 2014 1:05 pm
Forum: General
Topic: Using IP Pool on Firewall DST Addresses option
Replies: 0
Views: 410

Using IP Pool on Firewall DST Addresses option

Hi!

WinBox allow to set it, but it seems it doesn't works.

I have one IP Pool with 5 separate ip addresses.

I tried to add only one firewall filter instead of creating 5 filters, but it didn't worked.
by NetVicious
Thu Apr 10, 2014 11:25 am
Forum: General
Topic: VPN Dial on Demand in both sides of tunnel
Replies: 2
Views: 1284

VPN Dial on Demand in both sides of tunnel

Hi! Im using PPTP VPNs for trivial tasks. As I know on VPN we have one client and one Server. The client has one option to up the VPN tunnel when it detects traffic that should go throught the tunnel (Dial on Demand option). But what about if a computer on the router set as VPN Server wants to trans...
by NetVicious
Fri Jan 24, 2014 1:42 pm
Forum: The User Manager
Topic: error 734
Replies: 1
Views: 2632

Re: error 734

Check for the IPs/Pool you're assigning to the VPN users.

This error it's due to problems with the assigned IP to the VPN user.
- IP Pool Full
- No IP assigned
- no fixed ip/no pool assigned and DHCP off
- TCP/IP config on user bad configured
- Bad range of IPs being assigned to user
by NetVicious
Fri Jan 24, 2014 11:03 am
Forum: General
Topic: CCR LCD Is it needed member poll
Replies: 3
Views: 892

Re: CCR LCD Is it needed member poll

The price should be a bit lower. I think the LCD component should cost some money.
by NetVicious
Thu Jul 11, 2013 3:01 pm
Forum: General
Topic: PPP Dial on demand
Replies: 0
Views: 1024

PPP Dial on demand

Hi! First of all a diagram to see easily what we're talking about. Office 1 ------- Mikrotik 1 ---- Internet ---- Mikrotik 2 ---- Office 2 192.168.1.x ---- 172.25.0.1 ------------------ 172.25.0.2 ---- 192.168.2.x I have two Mikrotiks connected between one L2TP VPN. On the PPTP Client I have marked ...
by NetVicious
Tue May 15, 2012 10:02 am
Forum: General
Topic: [Feature Request] DNS Slave of a DNS Zone
Replies: 10
Views: 6690

Re: [Feature Request] DNS Slave of a DNS Zone

Thanks for the links. If the feature request it's not approved I will try to use some of the ideas of the links. Here are my comments for the previous links: The first one will involve to make the firewall packet inspector to check all the dns packets. And the second will make the router to check ea...
by NetVicious
Mon Apr 23, 2012 11:07 am
Forum: General
Topic: [Feature Request] DNS Slave of a DNS Zone
Replies: 10
Views: 6690

Re: [Feature Request] DNS Slave of a DNS Zone

Mikrotik team has created a entry in his wiki for new features: http://wiki.mikrotik.com/wiki/MikroTik_RouterOS/Feature_Requests#Not_yet_implemented If you want to vote for some feature request you need to register on the wiki and edit the page adding your nick and time of the vote as other users di...
by NetVicious
Fri Apr 13, 2012 11:51 pm
Forum: General
Topic: [Request] Schedule a system reboot
Replies: 4
Views: 2654

Re: [Request] Schedule a system reboot

The problem with the scheduler it's you need to delete the scheduler item after the restart because if you don't do it the router will be rebooted each day.

One possible solution could be a flag for delete the scheduler item after a correct execution.
by NetVicious
Fri Apr 13, 2012 8:25 pm
Forum: General
Topic: [Feature Request] DNS Slave of a DNS Zone
Replies: 10
Views: 6690

[Feature Request] DNS Slave of a DNS Zone

Now users have the Windows AD Server as DNS Servers. If the server goes down no one could browse the internet until the dns request timeout finishes (a lot of time) and it jumps to the next dns server (secondary AD server) If the RouterOs have one option to do zone transfer to his DNS cache the user...
by NetVicious
Fri Apr 13, 2012 8:22 pm
Forum: General
Topic: [Request] Schedule a system reboot
Replies: 4
Views: 2654

[Request] Schedule a system reboot

For late night reboots for applying new uploaded RouterOS images.
by NetVicious
Wed Dec 07, 2011 9:37 am
Forum: RouterBOARD hardware
Topic: RB1100AH - new product
Replies: 101
Views: 29005

Re: RB1100AH - new product

normis: In the webpage of RB1100AHx2 says zero LAN ports. (copy&paste bug ;-)
by NetVicious
Wed Nov 16, 2011 12:02 pm
Forum: RouterBOARD hardware
Topic: RB1100AH - new product
Replies: 101
Views: 29005

Re: RB1100AH - new product

The new RB1100AH model doesn't haves IPSec hardware acceleration.

Normis said the new model it's faster than the old RB1100AH model.
by NetVicious
Mon Nov 07, 2011 9:40 am
Forum: General
Topic: Sample Installations - Sticky Please
Replies: 230
Views: 136717

Re: Sample Installations - Sticky Please

I think he is refering to use something like this (http://www.i4wifi.eu/8-port-pasiv-poe-i ... d2063.html) instead of 8 separated POE Injectors
by NetVicious
Tue Oct 25, 2011 10:04 am
Forum: RouterBOARD hardware
Topic: RB1100AH - new product
Replies: 101
Views: 29005

Re: RB1100AH - new product

Ok, we need to see if the price has increased too. If it loses one very good feature talking about secured VPNs but it gains a bit more speed I think it should get a bit lower price.

There is a planned release date for the AHx2 ?
by NetVicious
Tue Oct 25, 2011 9:52 am
Forum: RouterBOARD hardware
Topic: RB1100AH - new product
Replies: 101
Views: 29005

Re: RB1100AH - new product

Our future product, the AHx2 will have hardware acceleration
What? If my memory it's not wrong I remember the old RB1100AH had IPSec acceleration isn't it ?
by NetVicious
Tue Sep 20, 2011 10:13 am
Forum: RouterBOARD hardware
Topic: RB1100AH - new product
Replies: 101
Views: 29005

Re: RB1100AH - new product

Also, the AHx2 has the advantage, that it will have two cores
Good information. Any other difference between AH and AHx2 ?
by NetVicious
Wed Sep 14, 2011 2:32 pm
Forum: RouterBOARD hardware
Topic: RB1100AH - new product
Replies: 101
Views: 29005

Re: RB1100AH - new product

we had a problem with part supplier, that's why we made a "new and improved" RB1100AH and RB1100AHx2, which will be coming this autumn. Hi! The "new" product will be named RB1100AH as the older? or the "new" it's the RB1100AHx2 ? Autum starts on 10 days. Do you have some information about the aprox...
by NetVicious
Thu Apr 28, 2011 7:34 pm
Forum: Scripting
Topic: Use a SD card for save temporal files in a script
Replies: 1
Views: 871

Use a SD card for save temporal files in a script

Hi! I'm using in one of our RB450G Mikrotik routers one script for DynDNS taken from this forum (thx to the developer). It saves a temporary file to the memory for use it as it was a html cookie for the IP on dyndns. I see this router has more bad blocks on memory than others (bought at the same tim...
by NetVicious
Sat Mar 12, 2011 8:09 pm
Forum: RouterBOARD hardware
Topic: RB433AH with 3miniPCI - only 200meters maximum throughput
Replies: 2
Views: 819

Re: RB433AH with 3miniPCI - only 200meters maximum throughpu

Thx for answer. I read something related. So I will have problems of space mounting 3 R52nM cards ??? What do you refer with the interferences ? Related to the antennas or related to the interferences of the cards because the connectors release signal inside the mikrotik case ? It's there some solut...
by NetVicious
Thu Mar 10, 2011 8:16 pm
Forum: RouterBOARD hardware
Topic: RB433AH with 3miniPCI - only 200meters maximum throughput
Replies: 2
Views: 819

RB433AH with 3miniPCI - only 200meters maximum throughput

Hi! I'm looking for a project for join two installations separated only by 200meters, but we need the maximum throutput available. I'm thinking to place in each building one RB433AH with 3 R52nM, and 3 directional MIMO antenas. I read some posts about problems with space trying to put three miniPcis...
by NetVicious
Tue Feb 15, 2011 9:50 am
Forum: General
Topic: Looking for a PPTP VPN Client with route adding
Replies: 2
Views: 600

Re: Looking for a PPTP VPN Client with route adding

Yes, because by default the VPN connection has a checkmark marked called ""Use default gateway on remote network". It's uses the tunnel as the gateway and all the traffic goes to the tunnel. The other day I discovered CMAK from Microsoft [2] It seems to allow us to create an EXE with the VPN connect...
by NetVicious
Sat Feb 12, 2011 9:12 pm
Forum: General
Topic: Looking for a PPTP VPN Client with route adding
Replies: 2
Views: 600

Looking for a PPTP VPN Client with route adding

Hi! I know we cannot distibute routes to VPN clients in PPTP, L2TP protocols and other, so I'm trying to find one software that allows me to set on it the routes on my internal network, because I dont wan't my users use my central connection as gateway so I need to use routes. On Windows I could set...
by NetVicious
Thu Nov 11, 2010 8:54 pm
Forum: General
Topic: VPN Server with Static Routes distribution
Replies: 7
Views: 2247

Re: VPN Server with Static Routes distribution

Thx for the explanation roadracer96. But I want to work only with Mikrotiks. I'm talking of clients pulling static routes from the Mikrotik. When talking about site-to-site vpns I don't have any problem adding them manually to each router or using rip, ospf, .... My problem are clients connecting to...
by NetVicious
Thu Nov 11, 2010 6:09 pm
Forum: General
Topic: VPN Server with Static Routes distribution
Replies: 7
Views: 2247

Re: VPN Server with Static Routes distribution

Ok, thank for the info.

For the people who is reading this looking for the same as me:

OpenVPN allows to add static routes in the client configuration file using this command (you could add more than one if you need):

route 192.168.4.0 255.255.255.0
by NetVicious
Thu Nov 11, 2010 3:08 pm
Forum: General
Topic: VPN Server with Static Routes distribution
Replies: 7
Views: 2247

Re: VPN Server with Static Routes distribution

Ok, good answer.

Any roadmap for add it to openVPN (as example) ?
by NetVicious
Thu Nov 11, 2010 2:47 pm
Forum: General
Topic: VPN Server with Static Routes distribution
Replies: 7
Views: 2247

VPN Server with Static Routes distribution

Hi! I read this on the forum: - We cannot distribute static routes to clients with PPTP on RouterOS. - OpenVPN supports static routes distribution but RouterOS doesn't have this option. - Ciscos could do it, but I don't read nothing if RouterOS could do it with IPSec VPNs. The question is: Is there ...
by NetVicious
Thu Nov 11, 2010 12:41 pm
Forum: General
Topic: Sample Installations - Sticky Please
Replies: 230
Views: 136717

Re: Sample Installations - Sticky Please

Here's Poynting's 23dBi 5GHz integrated enclosure. Only one clamp to the wall ? Take care when you get a lot of wind. The bracket is made from 5mm steel that's galvanised. The pole is 50mm with a 2mm wall thickness. Again galvanised. Now for the magic. The wall plugs are Fischer "UX". They are the ...
by NetVicious
Thu Nov 11, 2010 10:07 am
Forum: General
Topic: Sample Installations - Sticky Please
Replies: 230
Views: 136717

Re: Sample Installations - Sticky Please

Here's Poynting's 23dBi 5GHz integrated enclosure.
Only one clamp to the wall ? Take care when you get a lot of wind.
by NetVicious
Thu Nov 11, 2010 2:30 am
Forum: General
Topic: IP Service Port
Replies: 6
Views: 1819

Re: IP Service Port

You need the 5.0RC1 for vanilla GRE. Keep in mind it's a release candidate.
I have installed minutes ago the 5.0rc3 and I don't see nothing about the gre helper on the mikrotik in one RB450G.

I don't know if the RB450G doesn't gets the same plugins than other better motherboards.
by NetVicious
Wed Sep 29, 2010 6:38 pm
Forum: General
Topic: IP Service Port
Replies: 6
Views: 1819

Re: IP Service Port

I'm trying with IPSec now, but thx for the info.
by NetVicious
Wed Sep 29, 2010 5:23 pm
Forum: General
Topic: IP Service Port
Replies: 6
Views: 1819

Re: IP Service Port

Yes I want. I'm using one RB450G
by NetVicious
Fri Nov 13, 2009 3:43 pm
Forum: General
Topic: Strange problem with ping and Routing
Replies: 0
Views: 343

Strange problem with ping and Routing

Hi! I have a strange problem in one setup. Internet ----- DSL Router ------- Wifi AP with WDS --------- Mikrotik with WDS There is only one network 192.168.2.x Ping to Wifi AP - Ok Ping to DSL Router - Ok Ping to Internet - problems I could browse internet webpages without any problem. We got some p...