Community discussions

MikroTik App

Search found 98 matches

by NetWorker
Tue Jul 04, 2023 7:15 pm
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 3187

Re: Output route selection - Wireguard

That'll take a lot more redacting including e-mail addresses in scripts and whatnot. I don't think I'll have the time for it this week. I'll see what I can do.
by NetWorker
Tue Jul 04, 2023 6:26 pm
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 3187

Re: Output route selection - Wireguard

Quick and dirty: [admin@rb3011.mainoffice] > ip fire mang print Flags: X - disabled, I - invalid; D - dynamic 0 ;;; local traffic chain=prerouting action=accept dst-address=10.0.0.0/8 log=no log-prefix="" 1 ;;; local traffic chain=prerouting action=accept dst-address=172.20.0.0/24 log=no l...
by NetWorker
Tue Jul 04, 2023 4:20 pm
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 3187

Re: Output route selection - Wireguard

Update: instead of questioning everything I know about mangle, connection tagging and whatnot, I think I'm gonna go with Wireguard implementation as an explanation for this one. If I mark connection as mentioned above, the reply comes out in a new connection with no mark. If I mark that new connecti...
by NetWorker
Tue Jul 04, 2023 3:57 pm
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 3187

Re: Output route selection - Wireguard

add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=ether2 \ passthrough=yes new-connection-mark=viaWAN2 add action=mark-routing chain=output connection-mark=viaWAN2 passthrough=no \ new-routing-mark=preferWAN2 Hi anav! Thanks for the quick reply. Yeah, that's the way I...
by NetWorker
Tue Jul 04, 2023 3:13 pm
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 3187

Output route selection - Wireguard

Hey everyone! So I have the following issue. I recently upgraded a client's VPN from IPsec to Wireguard and seen major improvements. Main office is on two internet connections, one with a static, one with a dynamic IP. Branch offices are on dynamic IPs. Main office: ISP1 - Dynamic 100/30 mbs ISP2 - ...
by NetWorker
Fri Jan 20, 2023 6:17 pm
Forum: General
Topic: Nth vs PCC
Replies: 7
Views: 3681

Re: Nth vs PCC

Hey everyone and sorry of reviving an old thread. I had a couple of glitches with different clients related to load balancing in the past few months. The short term solutions for those glitches was to work around them, assigning a particular WAN to certain traffic that was misbehaving. But since the...
by NetWorker
Fri Jul 29, 2022 5:48 pm
Forum: Forwarding Protocols
Topic: OSPF Routes not Joining Main Route Table
Replies: 10
Views: 11665

Re: OSPF Routes not Joining Main Route Table

Check Network Type between routers, because depending on the type of network they exchange LSA but do not set up a route table. I just updated one of our remote offices from 6.48 to 7.4 and I had some adjustments to do. No surprise there, I already had to do them on some of our other routers after ...
by NetWorker
Tue May 03, 2022 4:34 pm
Forum: General
Topic: Slow VPN speed with single TCP stream in one direction
Replies: 13
Views: 5015

Re: Slow VPN speed with single TCP stream in one direction

Hey y'all!! Yesterday we went online with a new ISP over a symmetric GPON line at our main office (finally catching up to 2015 era tech rofl). Anyway, our VPN issues are now solved. Our DSL line ISP was the culprit. I still can't pinpoint the problem but issues with their pppoe server or router comi...
by NetWorker
Sat Aug 28, 2021 11:51 pm
Forum: General
Topic: Slow VPN speed with single TCP stream in one direction
Replies: 13
Views: 5015

Re: Slow VPN speed with single TCP stream in one direction

Hey, mikegleasonjr! No, I haven't found a solution to it. I managed to reduce full backup size so that they take about 30 hours. Given that I only do full backups every other week, daily backups are incrementals taking short of an hour to upload and that I've already sunk several workdays into this,...
by NetWorker
Fri Apr 23, 2021 6:30 pm
Forum: General
Topic: Slow VPN speed with single TCP stream in one direction
Replies: 13
Views: 5015

Re: Slow VPN speed with single TCP stream in one direction

Well, this week I disabled the IPSec and L2TP tunnel. I didn't suspect it to be the culprit but just to rule it out. So I went with an IPIP tunnel with no encryption (MSS clamp to PTMU=yes) and had the same results. UDP 10 mbps, multistream TCP 10 mbps, single stream TCP 2.4 mbps, single stream TCP ...
by NetWorker
Sun Apr 18, 2021 5:17 pm
Forum: General
Topic: Load Balance Multiple ISP connection
Replies: 3
Views: 1359

Re: Load Balance Multiple ISP connection

It depends on which load balancing scheme and firewall rules you intend to implement. But if I read this right you want to load balance and route 2 gbps+ simultaneously. You'll need to get at least an RB4011, probably a CCR if you don't want to bottleneck your line speeds. It also comes down to you ...
by NetWorker
Wed Apr 14, 2021 8:57 pm
Forum: General
Topic: Slow VPN speed with single TCP stream in one direction
Replies: 13
Views: 5015

Re: Slow VPN speed with single TCP stream in one direction

Ok, so I'm back. First of all, I thought to set MSS to a fixed value to be a big no-no. That one should set MTU and MRU to fixed values so as not to fragment and leave MSS be. Further I didn't quite grasp what you meant by terminating the tcp session at the endpoints. We're talking traffic generated...
by NetWorker
Wed Apr 07, 2021 3:37 am
Forum: General
Topic: Slow VPN speed with single TCP stream in one direction
Replies: 13
Views: 5015

Re: Slow VPN speed with single TCP stream in one direction

Thanks for replying bpwl! I've been reading up on TCP congestion control. Cool stuff! Never occured to me the amount of engineering that goes into a protocol we take for granted. I do have a couple of remarks and a couple of questions though. - The issue persists when only two devices are involved: ...
by NetWorker
Sat Apr 03, 2021 8:10 pm
Forum: General
Topic: PPTP S2S bridge - Wrong output IP [SOLVED]
Replies: 8
Views: 1500

Re: PPTP S2S bridge - Wrong output IP [SOLVED]

I recall something about all "services" like pptp in routeros always use the main table, regardless what the "source ip" is set to. So you have to route in the main table and can't use mangle rules.
by NetWorker
Sat Apr 03, 2021 7:53 pm
Forum: General
Topic: PPPoE Server over multpile Switches
Replies: 2
Views: 657

Re: PPPoE Server over multpile Switches

Quick and dirty solution that I'd expect to work would be to mirror the physical ports on the second switch. Though loloski's solution should work too and is much cleaner. =)
by NetWorker
Sat Apr 03, 2021 7:36 pm
Forum: General
Topic: PPTP S2S bridge - Wrong output IP [SOLVED]
Replies: 8
Views: 1500

Re: PPTP S2S bridge - Wrong output IP [SOLVED]

My first tip is for you to ditch PPTP. Use SSTP, OVPN or L2TP over IPSec.

As to the issue at hand, you'll need to post your routing and mangle rules. Though it'll essentially boil down to one of your routing rules not being applied and therefore your traffic being routed to the default gateway.
by NetWorker
Sat Apr 03, 2021 7:23 pm
Forum: General
Topic: Port Forwarding in a Force route with Dual WAN
Replies: 4
Views: 1374

Re: Port Forwarding in a Force route with Dual WAN

I agree with anav that what you're asking isn't abundantly clear. But I understood is as follows. You have an internal subnet and you want to route to and from that network to ISP2. If that's the case, I think you're way overthinking this. Just add mangle rules before those that do your load balanci...
by NetWorker
Sat Apr 03, 2021 7:13 pm
Forum: General
Topic: IPSec Multipoint Config [SOLVED]
Replies: 3
Views: 1262

Re: IPSec Multipoint Config [SOLVED]

I had this requierement too and solved it as follows: I used L2TP on top of IPSec so as to have interfaces, not just policies. This in turn allowed me to use OSPF. But you can also do this with static routes. Else you can use GRE or IPIP if all your public addresses are static. Just add a route to e...
by NetWorker
Sat Apr 03, 2021 2:49 am
Forum: General
Topic: Slow VPN speed with single TCP stream in one direction
Replies: 13
Views: 5015

Slow VPN speed with single TCP stream in one direction

Hey everyone, I’ve got a VPN issue that I can’t figure out. You can skip the background description if you wish. Background: - Main office: Mikrotik RB3011, 30/10 mbps (down/up) on VDSL, Win2008r2 filserver - Remote office: Mikrotik RB2011uias, 10/10 mbps on 3 hop wireless uplink to fiber, Win2016 f...
by NetWorker
Fri Jan 24, 2020 2:15 am
Forum: Scripting
Topic: Routing rules for dynamic IP addresses
Replies: 0
Views: 2572

Routing rules for dynamic IP addresses

Hi all, I came across a situation where I needed to add a routing rule for a domain name that's bound to a dynamic IP address. So I wrote a very short, easy script and thought I'd share. Hope this saves you time/work if you're in the need for something similar. # Routing rules for dynamic IP address...
by NetWorker
Thu Jan 23, 2020 1:21 am
Forum: General
Topic: Double IPsec connection - failing [SOLVED]
Replies: 8
Views: 3343

Re: Double IPsec connection - failing [SOLVED]

Right on, thanks again!
by NetWorker
Tue Jan 21, 2020 5:27 pm
Forum: General
Topic: Double IPsec connection - failing [SOLVED]
Replies: 8
Views: 3343

Re: Double IPsec connection - failing [SOLVED]

If you want to test and fallback to the previous config you can always use safe mode. Safe mode was hit and miss for a long time. I think it's fixed now but a safe mode that isn't safe is not something I'm willing to trust. I therefore never make changes that might lock me out unless I have a way t...
by NetWorker
Mon Jan 20, 2020 8:20 pm
Forum: General
Topic: Double IPsec connection - failing [SOLVED]
Replies: 8
Views: 3343

Re: Double IPsec connection - failing [SOLVED]

Alright, so I had a couple of hours to kill yesterday and decided to look into this. First of all, I got it working! Read on to find out how. After your comment emils I set "send initial contact" to no on both client and server (not sure if you meant client and server or both peers in the ...
by NetWorker
Sat Jan 18, 2020 5:29 pm
Forum: General
Topic: Double IPsec connection - failing [SOLVED]
Replies: 8
Views: 3343

Re: Double IPsec connection - failing [SOLVED]

Thanks for replying emils. I'll try setting initial contact to no. Also, I generally use mangle for everything but I tried to simplify the setup on this one by setting the "local address" for each peer. This way each connection was going out over the correct interface. Or at least that's w...
by NetWorker
Thu Jan 16, 2020 2:34 am
Forum: General
Topic: Double IPsec connection - failing [SOLVED]
Replies: 8
Views: 3343

Re: Double IPsec connection - failing [SOLVED]

Anyone?

Edit: update, SAs remain intalled on the central office router (3011) until they time out; in fact several of them for the same IP pair (right now three for one IP pair and two for the other). On the remote router they are removed as soon as one connection replaces the other as stated above.
by NetWorker
Thu Jan 09, 2020 12:10 am
Forum: General
Topic: Double IPsec connection - failing [SOLVED]
Replies: 8
Views: 3343

Double IPsec connection - failing [SOLVED]

So we have a central 3011 with a couple of remote offices with 2011s connecting to it via L2TP over IPsec. At one of the remote offices we have two natted conections. We also have two connections at the main office. The idea is to have the remote router establish two connections with different metri...
by NetWorker
Thu Oct 10, 2019 7:43 pm
Forum: General
Topic: Slow connection via mikrotik
Replies: 18
Views: 8493

Re: Slow connection via mikrotik

Are you sure it's not a DNS issue? Did you try setting DNS manually on the PC to see if that makes a difference? From your route trace it apperas the connection is fine as you can ping your modem from behind the mikrotik without issues. Ping times to your ISPs router to the pipe are rather high but ...
by NetWorker
Thu Oct 10, 2019 7:28 pm
Forum: General
Topic: TLS 1.3 + dual WAN session drops
Replies: 7
Views: 3099

Re: TLS 1.3 + dual WAN session drops

Lol, right.

I disabled my old rules yesterday and asked everyone that reported issues with encrypted websites to check those they usually work with and so far so good.
by NetWorker
Wed Oct 09, 2019 11:34 pm
Forum: General
Topic: Is MikrotikOS good enough to support two networks independent of each other? (one needs PPPoE)
Replies: 41
Views: 9519

Re: Is MikrotikOS good enough to support two networks independent of each other? (one needs PPPoE)

Yes, it is possible. RouterOS is not going to be a limitation and CPU power in a Hex is plenty for distributing those 8 mbps.

Just use queues and separate the interfaces from the switch chip.
by NetWorker
Wed Oct 09, 2019 11:24 pm
Forum: General
Topic: Slow connection via mikrotik
Replies: 18
Views: 8493

Re: Slow connection via mikrotik

Check your DNS setup. Make sure /ip dns is setup correctly and that /ip dhcp-server is passing on the correct addresses for dns to clients.
by NetWorker
Wed Oct 09, 2019 10:51 pm
Forum: General
Topic: TLS 1.3 + dual WAN session drops
Replies: 7
Views: 3099

Re: TLS 1.3 + dual WAN session drops

Update: here's what I ended up with. ;;; mark https ISP1 chain=prerouting action=mark-connection new-connection-mark=ISP1 passthrough=yes connection-state=new protocol=tcp connection-mark=no-mark dst-port=443 per-connection-classifier=both-addresses:3/0 log=no log-prefix="" ;;; mark https ...
by NetWorker
Wed Oct 09, 2019 4:40 pm
Forum: General
Topic: TLS 1.3 + dual WAN session drops
Replies: 7
Views: 3099

Re: TLS 1.3 + dual WAN session drops

Gotcha. Never realized it works exactly the same as nth only with the added benefit of the PCC field. I'll set it up and see if the screams coming out of the accounting the department get any louder lol.
by NetWorker
Wed Oct 09, 2019 5:12 am
Forum: General
Topic: TLS 1.3 + dual WAN session drops
Replies: 7
Views: 3099

Re: TLS 1.3 + dual WAN session drops

Hey Sob, thanks for replying. The one sentence that put me off from using PCC in the first place was that at the very beginning it reads "PCC matcher will allow you to divide traffic into equal streams". Since there's nothing symmetric about our links (different bandwidth) or traffic (requ...
by NetWorker
Tue Oct 08, 2019 6:13 pm
Forum: General
Topic: TLS 1.3 + dual WAN session drops
Replies: 7
Views: 3099

TLS 1.3 + dual WAN session drops

Hi all, we've been using mangle and nth (connection marks+routing marks) with great success over the years. This makes perfect use of our two ISP lines (cable+DSL) and assymetrically distributes the traffic (3 to 1) as they're of different bandwidth. Now TLS 1.3 comes along and many TLS hosts check ...
by NetWorker
Wed Sep 11, 2019 5:33 pm
Forum: General
Topic: How to display Mikrotik's SSH keys fingerprint.
Replies: 4
Views: 3346

Re: How to display Mikrotik's SSH keys fingerprint.

So far in the last 10 years using Mikrotiks I've always been positive about which device I was connecting to. Therefore I've never bothered to check the fingerprint. Today for the first time I'm going through another company's network rather than our own and I'm not 100% sure if I'm reaching our dev...
by NetWorker
Thu Aug 22, 2019 4:26 pm
Forum: Announcements
Topic: hAP lite
Replies: 391
Views: 239429

Re: hAP lite

@xbliss, performance varies A LOT with different rules and setups. There used to be no numbers at all since it can vary so much. For example the charts are published for zero or 25 ip filter rules. However the load on the cpu is not linear and you can't really extrapolate and say "ok, so 13 rul...
by NetWorker
Thu Aug 22, 2019 3:59 pm
Forum: General
Topic: Issue with L2TP/IPSec VPN, Clients cant access LAN devices
Replies: 4
Views: 1394

Re: Issue with L2TP/IPSec VPN, Clients cant access LAN devices

As SoB said, it's hard to suggest a solution without knowing how you setup the load balancing. But if you used mangle to mark the nth connections, simply put a rule before that one that either accepts or marks the connections coming from the l2tp interface or it's subnet.
by NetWorker
Thu Aug 22, 2019 3:46 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257376

Re: RouterOS v7.0 beta1 - when?

Thanks, I needed a laugh. If you shilled any harder I would've fell on to the floor laughing. Hey, I'm all for smiles and grins but after looking up shill in the dictionary I can honestly say that that wasn't the intention of my post. Yes, I posted in a "take it or leave it" sorta way but...
by NetWorker
Thu Aug 22, 2019 3:37 am
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257376

Re: RouterOS v7.0 beta1 - when?

I just want to let everyone know, that v7 is progressing pretty good this year, and most core functionality is usable. Some more difficult parts need to be done and we can release a public beta. Koala Pic ROFL Keyko, you made my day. To be honest I too have been waiting on a few v7 features but hav...
by NetWorker
Mon Jun 03, 2019 11:56 pm
Forum: RouterBOARD hardware
Topic: More info about mUPS
Replies: 53
Views: 15226

Re: More info about mUPS

Lol, that makes sense. Thanks again! I'll post back if we decide to give it a shot. Right now we're leaning towards a different setup.
by NetWorker
Mon Jun 03, 2019 8:18 pm
Forum: RouterBOARD hardware
Topic: More info about mUPS
Replies: 53
Views: 15226

Re: More info about mUPS

Brochure says max battery charging current is 1A ... so it'll take ages to charge that "massive" 18Ah battery when fully discharged even if power adapter used is powerful enough. Other than that, 18Ah battery should be fine. Thanks for replying mkx. Actually, I have another question relat...
by NetWorker
Sun Jun 02, 2019 1:48 am
Forum: RouterBOARD hardware
Topic: More info about mUPS
Replies: 53
Views: 15226

Re: More info about mUPS

Sorry for reviving an old thread (though it isn't that old! lol). I've been unable to find any comments on battery size. I know it'll take 7 and 12 Ah batteries. But any thoughts on going to 18 Ah? I realize it's a bit on the high side but we're looking at getting a bit longer run times at a low wat...
by NetWorker
Mon May 20, 2019 4:31 pm
Forum: Scripting
Topic: Backup script
Replies: 5
Views: 9825

Re: Backup script

Agreed. Though it did save me twice on a rb2011 that went into a boot loop. Reinstalling routerOS over serial and then restoring the backup file was easier than having to import all the certificates and a few other things that are not in the compact again. It's not that you can't do it but it does s...
by NetWorker
Mon May 20, 2019 3:24 am
Forum: Scripting
Topic: Backup script
Replies: 5
Views: 9825

Re: Backup script

well what use is the build-in scripting and a linux box that pulls the backup from the router and stores it on a nas.
quick & dirty solution , but this allows me to make a backup for example from a rb2011 and restore it on a hapac2
Exactly!
by NetWorker
Sat May 18, 2019 6:19 am
Forum: General
Topic: routing - 3x GW, failover
Replies: 14
Views: 2894

Re: routing - 3x GW, failover

Glad to help! Didn't read all your code since the Mrs. is nagging to go to bed lol. But I still find you're missing the default gateways? Unless you have something else in mind? Anyway, I posted an interface watchdog script a couple of years ago that would reset an interface since we were having iss...
by NetWorker
Wed May 15, 2019 11:04 pm
Forum: Scripting
Topic: Backup script behaves strange
Replies: 3
Views: 1595

Re: Backup script behaves strange

It does indeed sound like a permissions issue. i don't know what you mean by "everywhere else", I assume you mean "don't-require-permissions"? Check again that it is indeed set to yes. However it's always best to just enable the required permissions. For my backup script I use po...
by NetWorker
Wed May 15, 2019 10:41 pm
Forum: Scripting
Topic: Backup script
Replies: 5
Views: 9825

Re: Backup script

Oh and in case anyone's wondering about all the picks, the system date comes back with / (slashes) which you can't use in a filename so I replace those with . (dots).
by NetWorker
Wed May 15, 2019 10:38 pm
Forum: Scripting
Topic: Backup script
Replies: 5
Views: 9825

Backup script

Hi everyone, a couple of weeks ago I became aware that years of routerOS backups all nice and tidily organized in one of our backup servers are USESLESS if an older router goes belly up. Read all about it here . Long story short, in case you're blissfully unaware like I was that using the winbox bac...
by NetWorker
Wed May 15, 2019 5:27 pm
Forum: Scripting
Topic: Two questions about DHCP leases script. [SOLVED]
Replies: 10
Views: 12804

Re: Two questions about DHCP leases script. [SOLVED]

Glad you got it working!
by NetWorker
Wed May 15, 2019 5:22 pm
Forum: Scripting
Topic: Set timer or some other way to prevent script from running multiple times in short time [SOLVED]
Replies: 5
Views: 3238

Re: Set timer or some other way to prevent script from running multiple times in short time [SOLVED]

There are two ways to go about doing that. One, you put the scheduled task and enable/disable it as needed. The other, you create and remove it each time. This is the task you need. /system scheduler add name=dwnFlagCleaner start-time=startup interval=60m on-event=dwnFlagCleaner Either add it and di...
by NetWorker
Wed May 15, 2019 6:57 am
Forum: General
Topic: RB750GR3 for a 30 PCs Gaming event?
Replies: 11
Views: 3327

Re: RB750GR3 for a 30 PCs Gaming event?

Lol I haven't played a lot of online games in recent years. Actually I've never played a lot of online games after Team Fortress 2 and the original Counter Strike. Recently became a dad so don't have much time for gaming anymore. =) Anyway, your numbers sound about right. Online gaming has always be...
by NetWorker
Wed May 15, 2019 3:17 am
Forum: General
Topic: RB750GR3 for a 30 PCs Gaming event?
Replies: 11
Views: 3327

Re: RB750GR3 for a 30 PCs Gaming event?

can route 980 Mbps with 25 firewall rules and 512 bytes packet size. 512 bytes are fairly large packets. Most packets are a lot smaller than that. A lot of acks, etc. So the number you should look at is the one on the right, for 64 bytes. Mainly for two reasons, first it kinda provides a worst case...
by NetWorker
Tue May 14, 2019 11:26 pm
Forum: Scripting
Topic: Two questions about DHCP leases script. [SOLVED]
Replies: 10
Views: 12804

Re: Two questions about DHCP leases script. [SOLVED]

Wow, that's news for me. I hadn't read that bit. Cool stuff. Right, so for question number two, did you try using the hostname variable? I know not all devices report host name correctly. Other than that, if you are indeed using static leases you could try to comment each lease and using the MAC, re...
by NetWorker
Tue May 14, 2019 11:16 pm
Forum: General
Topic: routing - 3x GW, failover
Replies: 14
Views: 2894

Re: routing - 3x GW, failover

- by using a ping check of a remote system, you make the usability of the link dependent on the availability of the remote system. when it is down, your ISP link will be declared down even when it really isn't. remember that the remote system may decide that it had enough of the pings and just bloc...
by NetWorker
Tue May 14, 2019 7:59 pm
Forum: Scripting
Topic: Two questions about DHCP leases script. [SOLVED]
Replies: 10
Views: 12804

Re: Two questions about DHCP leases script. [SOLVED]

Lol, right. But what about this:
global telegramMessage "$leaseActMAC connected as guest and received $leaseActIP address."
How are you setting those variables?
by NetWorker
Tue May 14, 2019 7:47 pm
Forum: General
Topic: hotspot + userman : how avoid to reach webfig ?
Replies: 5
Views: 1569

Re: hotspot + userman : how avoid to reach webfig ?

I've never setup a hotspot but have you tried changing the www service port from 80 to whatever? I don't have the hotspot package installed on any of my routers so I can't check but afaik hotspot and webfig are different services so changing the www service port shouldn't affect the hotspot portal?
by NetWorker
Tue May 14, 2019 7:45 pm
Forum: General
Topic: RB750GR3 for a 30 PCs Gaming event?
Replies: 11
Views: 3327

Re: RB750GR3 for a 30 PCs Gaming event?

Balancing close to 30 mbps upload shouldn't be a problem for that router. But if anyone decides to starts to download at anything close to max download speeds you posted, you'll need to move into the CCR range so make sure you cap download speeds. Unless those are indeed mB/s and not mbps in which c...
by NetWorker
Tue May 14, 2019 7:21 pm
Forum: General
Topic: routing - 3x GW, failover
Replies: 14
Views: 2894

Re: routing - 3x GW, failover

Forgot to point out two things. First was already covered by pe1chl. If you only ping the gateway and there's a problem further down the line in the ISP, those routes will stay up but you'll drop all the traffic. I.e. the failover won't happen. More complex checking schemes will require scripts. Sec...
by NetWorker
Tue May 14, 2019 6:46 pm
Forum: General
Topic: routing - 3x GW, failover
Replies: 14
Views: 2894

Re: routing - 3x GW, failover

Not quite. You either do it with mangle or with routing rules as pe1chl suggested. Also, you're missing the default gateways. /ip route #first add the default gateways with distance for failover add dst-address=0.0.0.0/0 gateway=10.0.1.1 distance=1 check-gateway=ping add dst-address=0.0.0.0/0 gatewa...
by NetWorker
Tue May 14, 2019 5:15 pm
Forum: Scripting
Topic: Two questions about DHCP leases script. [SOLVED]
Replies: 10
Views: 12804

Re: Two questions about DHCP leases script. [SOLVED]

Alright, sorry for not getting back to you sooner. First of all, you haven't shown me how you parse the MAC which is what interests me from the other script. I apologize for not making that clear. In any case, I always recommend (and to the best of my knowledge so does Mikrotik) keeping all scripts ...
by NetWorker
Tue May 14, 2019 4:11 pm
Forum: General
Topic: Can't get 10gig speed
Replies: 3
Views: 1024

Re: Can't get 10gig speed

Awesome. Do check your cabling though. This might be the reason why it's not negotiating 10G and why you're not nearer to the actual 10G mark.
by NetWorker
Fri May 10, 2019 6:25 pm
Forum: General
Topic: DSL TLS MTU problem [SOLVED]
Replies: 2
Views: 2034

Re: DSL TLS MTU problem [SOLVED]

Found it! MSS can be changed in the profile. Turns out the option "Change TCP MSS" was set to no. When set to yes TLS started working again. Also, even with MTU at 1492 it works a lot better than before. I'm guessing that's because browsers were doing a lot of path discoveries which oddly ...
by NetWorker
Fri May 10, 2019 5:30 pm
Forum: General
Topic: Can't get 10gig speed
Replies: 3
Views: 1024

Re: Can't get 10gig speed

Have you checked that autonegotiation actually went for 10G? Did you try forcing it to 10G? Have you checked CPU load during your bandwith tests?
by NetWorker
Fri May 10, 2019 5:22 pm
Forum: General
Topic: DSL TLS MTU problem [SOLVED]
Replies: 2
Views: 2034

DSL TLS MTU problem [SOLVED]

Hey everyone! We've recently been having increasing issues with some webpages not being displayed correctly or not loading at all. Long story short, I've tracked it down to being pages that have upgraded to newer versions of TLS. Haven't checked if 1.3 only or also 1.2. And only when going over our ...
by NetWorker
Mon Apr 29, 2019 4:22 pm
Forum: Scripting
Topic: No such item [SOLVED]
Replies: 2
Views: 1982

Re: No such item [SOLVED]

Wouldn't it be more logical to check for number of items?
:log info [:len [/ip ipsec installed-sa find]];
And then compare if it's zero or more.
*Facepalm* :lol: Thanks sob!
by NetWorker
Fri Apr 26, 2019 3:00 am
Forum: Scripting
Topic: Two questions about DHCP leases script. [SOLVED]
Replies: 10
Views: 12804

Re: Two questions about DHCP leases script. [SOLVED]

You didn't mention how you're triggering the lease script so I can't answer your first question. But in case you're triggering from the dhcp-server, you could just check if said mac address is still registered and if it isn't not to run the telegram script. That way it will only notify of the new le...
by NetWorker
Fri Apr 26, 2019 1:28 am
Forum: Scripting
Topic: No such item [SOLVED]
Replies: 2
Views: 1982

No such item [SOLVED]

So I want to wite a script that checks if an item exists and performs an action if it doesn't. Specifically, we want to check if ipsec is connected and if it isn't disable the l2tp interface so it doesn't endlessly pollute the log with reconnection attempts. -----Background info----- We have a 2 rou...
by NetWorker
Fri Apr 26, 2019 12:24 am
Forum: Wireless Networking
Topic: importing and exporting config files
Replies: 24
Views: 219553

Re: importing and exporting config files

Yeah, I realized that from the above. I mean I was a happy camper with my regular backups, all nice and tidy, indexed by date and name, safely stored on the server. So if a router goes up in flames I got exactly squat. Nice.......
by NetWorker
Thu Apr 25, 2019 7:48 pm
Forum: Wireless Networking
Topic: importing and exporting config files
Replies: 24
Views: 219553

Re: importing and exporting config files

Backups are only valid for a given device with a given RouterOS and firmware versions. Backups are not intended for setup replication. I apologize for reviving an old thread and quoting a 4 year old post but like gator, I was just *shocked* by this statement. WHAT??? We have a few routers running i...
by NetWorker
Wed Mar 20, 2019 7:04 pm
Forum: General
Topic: Very slow download speed when USB tethering to 4G phone
Replies: 2
Views: 2170

Re: Very slow download speed when USB tethering to 4G phone

My first guess would be the phone and or cell spectrum/backhaul. Did you check the phone with a PC at the same time you were getting these results? How much throughput did you get with that setup? It's pretty common to see dismal download rates and high upload rates at times in highly congested cell...
by NetWorker
Wed Mar 20, 2019 6:15 pm
Forum: General
Topic: Need help routing public subnet IP to internal server
Replies: 22
Views: 2643

Re: Need help routing public subnet IP to internal server

Dunno if you solved this and I stand to be corrected but here's what I'm thinking: You have 2 interfaces: eth5 and eth9. On eth5 you have 1.1.1.1 and on eth9 a server with 2.2.2.1 (with gateway 1.1.1.1) but no IP on the router ethernet interface. This setup won't work because router has no IP connec...
by NetWorker
Wed Mar 20, 2019 5:37 pm
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 5737

Re: ARP/DHCP issue [SOLVED]

Well folks, I managed to crack it. For whatever reason the "designer" (if we can call the schmuck who designed this marvellous piece of... erm... tech, that) decided that always doing an ARP request, no matter what the destination IP address is, is a good idea. I'm guessing they did this t...
by NetWorker
Fri Mar 08, 2019 4:40 pm
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 5737

Re: ARP/DHCP issue [SOLVED]

There are two kind of routes in the IP protocol: interface routes (or connected routes, that Mikrotik marks with a C when printing) gateway routes (that in classic route command are marked with a G ) The interface routes are where the ARP mechanism is used, to know which L2 host to address with pac...
by NetWorker
Fri Mar 08, 2019 4:34 pm
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 5737

Re: ARP/DHCP issue [SOLVED]

- When a host wants to send a packet to an internet address, it will send the packet directly to the gateway. It will NOT do an arp lookup for that internet address. - You shouldn't see two DHCP discovers and two requests during a DHCP transaction, but not a big deal. Discover, Offer, Request, Ack....
by NetWorker
Thu Mar 07, 2019 7:03 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 13458

Re: load-balancing don't work

I admittedly haven't read through all the code because I don't have a lot of time right now. But load balancing is all about mangle marking. First mark connections that are NOT to be load balanced. You can either do action=accept or use some other mark. For example DNS requests or specific addresses...
by NetWorker
Thu Mar 07, 2019 6:21 pm
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 5737

Re: ARP/DHCP issue [SOLVED]

If the Alarm system has an IP statically set and it's not on the same subnet as statically set in the alarm system, then the alarm system will do ARP requests for the gateway that's statically set in the Alarm system. Since no device on your network will have that IP, you will only see ARP requests...
by NetWorker
Thu Mar 07, 2019 5:57 pm
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 5737

Re: ARP/DHCP issue [SOLVED]

You're a bit off on ARP. On an Ethernet network, every device has a mac address. When packets get sent out over Ethernet, they are actually routed only by their mac address. Not IP address. Since your PC will connect to remote devices by IP, then it needs to find out who on the network has an IP as...
by NetWorker
Wed Mar 06, 2019 3:09 am
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 5737

ARP/DHCP issue [SOLVED]

Hi all, Ihave a question about ARP: ---background---- At one of our remote offices we recently elected to have an alarm system installed. We have an RB2011 with dual wan running there. The alarm, which apparently is one of those Christopher Columbus brought with him back in 1493, is supposed to be i...
by NetWorker
Mon Sep 04, 2017 7:06 pm
Forum: Scripting
Topic: UPS script
Replies: 1
Views: 3154

Re: UPS script

Guys, quick followup. The script won't read the previously run global variables if the policy policy is not set. So as it stands now, you need four of them for the script to behave: read, write, test and policy. I've edited the comment in the script to reflect this: # UPS-Script powerfail # (c) stei...
by NetWorker
Thu Aug 31, 2017 8:14 pm
Forum: Scripting
Topic: UPS script
Replies: 1
Views: 3154

UPS script

Hey yall! The UPS script on the wiki https://wiki.mikrotik.com/wiki/UPS_scripts seems to be a little outdated when it comes to the online/onbattery flag. On our APC SUA1000 attached to a RB750, the flag is called "on-line" instead of "on-battery": https://thumb.ibb.co/mOO245/Capt...
by NetWorker
Sat Jul 22, 2017 12:08 am
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Re: Usb port invalid

Well, we've moved past using 3g modems a couple of years ago. But are considering setting one up again as a backup connection since the site now also runs a server and some more critical traffic. On topic, I wanted to point out that we later moved from the USB dongles to a Sierra Wireless MC 8775 3g...
by NetWorker
Fri Jul 21, 2017 11:55 pm
Forum: Scripting
Topic: Failover
Replies: 6
Views: 2346

Re: Failover

Holy cow, that looks incredibly complex to me. First of all, I'm assuming (you failed to clarify) you have a main connection and a backup and that you run ALL traffic through your main unless it fails. If this is the case: add two default routes 0.0.0.0/0 with distance 1 and 2. Set gateway of your m...
by NetWorker
Thu Jun 22, 2017 6:30 pm
Forum: Scripting
Topic: Interface Watchdog script
Replies: 5
Views: 7833

Re: Interface Watchdog script

Quick update when using multiple reset counters. In the interface reset script I just used the global variable. But if you have multiple global variables, instead of editing the variable name everywhere in all the scripts, you can use a local variable and just change the name of the global at the be...
by NetWorker
Thu Jun 22, 2017 6:18 pm
Forum: Scripting
Topic: Interface Watchdog script
Replies: 5
Views: 7833

Re: Interface Watchdog script

Guys, a word of caution. I've also been running this script for our VPN links now, since they tend to crash along with the pppoe client. That is, our dedicated lines stay up but ovpn connections over the DSL line crash. Anyways, long story short, the ovpn client drops the connection but doesn't try ...
by NetWorker
Fri Jun 16, 2017 2:15 am
Forum: Scripting
Topic: Interface Watchdog script
Replies: 5
Views: 7833

Re: Interface Watchdog script

intreset #Interface Reset #Feel free to use or modify as needed. #Hope this saves you work, trouble or time. #Regards, Networker. #The following script will reset the defined interface. It also checks the number of #resets performed. Past that number, the script will permanently disable said interf...
by NetWorker
Fri Jun 16, 2017 2:09 am
Forum: Scripting
Topic: Interface Watchdog script
Replies: 5
Views: 7833

Re: Interface Watchdog script

intwatchdog #Interface Watchdog #Feel free to use or modify as needed. #Hope this saves you work, trouble or time. #Regards, Networker. #This script will ping a remote address from a particular interface and its gateway. #This way, we don't bombard the remote host with icmp requests, and make sure ...
by NetWorker
Fri Jun 16, 2017 2:07 am
Forum: Scripting
Topic: Interface Watchdog script
Replies: 5
Views: 7833

Re: Interface Watchdog script

intctrreset #Interface counter reset #Feel free to use or modify as needed. #Hope this saves you work, trouble or time. #Regards, Networker. #This script defines and sets to zero the global variable that we will later use to define when #to disable the interface or reset the router as needed. #Note...
by NetWorker
Fri Jun 16, 2017 2:06 am
Forum: Scripting
Topic: Interface Watchdog script
Replies: 5
Views: 7833

Interface Watchdog script

Time and again has it been brought up that the Netwatch tool should include a interface parameter as the ping tool does. I've been living without this feature but recently we've added a new ISP to our corporate network. We run a load balancing system with ping checking routes. Our dedicated lines ar...
by NetWorker
Thu May 04, 2017 11:43 pm
Forum: General
Topic: Possible SSH bug 6.38.5 [SOLVED]
Replies: 3
Views: 1196

Re: Possible SSH bug 6.38.5 [SOLVED]

Please export ip ssh. I telnetted in, but /ip ssh returned bad command. I thought, that's odd, it should be there even if it was failing, right? Then it hit me, I checked the installed packages and sure enough, the security package wasn't there. Looks like I accidentally didn't select it when uploa...
by NetWorker
Sat Apr 29, 2017 7:46 pm
Forum: General
Topic: Possible SSH bug 6.38.5 [SOLVED]
Replies: 3
Views: 1196

Possible SSH bug 6.38.5 [SOLVED]

Hey all, I've searched around but haven't found anything related to a failing SSH service. I recently upgraded a RB750GL to 6.38.5 (also updated firmware to 3.33) from 6.35.4. I don't know if it was the update per se, all I know is that it was working before and now it isn't. I also applied a few mi...
by NetWorker
Wed Apr 07, 2010 3:31 am
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Re: Usb port invalid

Sorry DogHead, I'm all out of suggestions.

I tried this weekend the 9 second delay (9s being the highest value) with no results.

Also forgot to generate the support file. :(
Will do it next time.
by NetWorker
Wed Mar 17, 2010 7:10 pm
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Re: Usb port invalid

Trying the same settings with a second RB 411U works without any problems! The same settings being the delay? How much did you use? I'd give as much delay as it takes the modem to blink once (you know, when it sees the network it blinks once, else it blinks twice in quick succession) plus 5 or 10 s...
by NetWorker
Sun Mar 14, 2010 10:31 pm
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Re: Usb port invalid

Damn... Was hoping it'd work. I'll give it a try though jcem, to see if we get the same results. But like I said, I don't know when that's going to be. I'm burried with work and college and don't have time to make the trip (200 km). And no, it's not supposed to come back invalid with nothing attache...
by NetWorker
Sat Mar 13, 2010 10:06 pm
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Re: Usb port invalid

Steve0, that's a great idea! I haven't been on site for about a month now, for which reason I haven't followed up on this. I'll give it a shot when I'm there again.
by NetWorker
Wed Feb 03, 2010 9:36 pm
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Re: Usb port invalid

Oh... That's going to be a problem. The board is in a remote location and the only internet access is per GSM. Hence without the modem on the board, I have no way of providing access. I'd had to remove the whole thing from the tower and bring it in to the city... If you guys really need it, then I'l...
by NetWorker
Mon Feb 01, 2010 9:23 pm
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Re: Usb port invalid

Are you using the latest RouterOS version? Thanks for the reply uldis. RouterOS version 4.4 Can you reproduce it almost every reboot? It's basically like this. Every time I shut it down and boot it up again, I have to reboot because the usb port shows invalid in red. After the reboot, everything is...
by NetWorker
Sun Jan 31, 2010 7:09 pm
Forum: RouterBOARD hardware
Topic: Usb port invalid
Replies: 46
Views: 31884

Usb port invalid

Hi all. I'll start off by saying that I'm new to Mikrotik and am already in love with you guys! I've setup my RB 411U with a Huawei E226 (like E220) 3G modem in no time and it works great. Except for one minor detail. Almost every time (I'd say 9 out of 10) I shutdown the router, disconnect the powe...