Zerobyte Not yet. It was really messing up the start of my customers business day so I kept it operational at the 10.0.x.x I will be spending some more time on it this weekend and will give it a shot. I agree the subnet should not matter. Just appeared to in this situation. In fact, I had 2 location...
Performed a router reboot this AM and when it came back up, all the ospf links on 172.16.x.x/30 were stuck on init. About 20 of them. Changed IP subnet to 10.0.x.x/30 and they came back up. Logs did not provide any detail. I updated router to latest OS (just before 6.36 release) and same results. Cu...
Hello Forum
Looking for a method to verify whether a vlan tag is making it to a port or not. Should I just torch a port or is there other methods for identifying this?
Pe1chi Possibly but I now have it working by bypassing the shared switches. Its also a potential issue with the RF link as the same problem occurred on a different network using same radio models and firmware. I had to install them, then remove them when customers called in and unable to move. I hav...
Update on this issue. One oddity I have identified is that I can go to any google site. Youtube, news, Drive, +, etc... I can ping any other site (IP or URL). But not pull them up. All MTU (even EOIP) is set to 1560. :?: Seriously confused :-? Any insight on what I may be running into greatly apprec...
Small update to this. When on the tower site, I can connect to a VPN on another network and successfully gain TCP connectivity. Its just on the native public IP that I lose that capability. Also, as expressed in image attached, I bypassed the two switches to further diagnose the trouble spot. Bringi...
Hello Forum Running OSPF across a single link with an EOIP tunnel connecting the core router to an edge 2011. I tunnel my public subnet through here to make connections work. My latest setup is behaving oddly. I have great latency and can do router to router UDP capacity tests but no TCP tests. Webs...
Still fighting this loop warning. Is there a combination of log settings that may help shed more light on what the Mikrotik is seeing as a loop? To date, I have reviewed the bridge Hosts list where 12 entries relating/connecting to port vpls250 are labeled. Going to each router and interface that at...
The wiki is not providing any insight into this feature.
Bridge-Port has an auto isolate toggle. What does it do that Split horizon or STP/RSTP not do?
Have a router log telling me the following: "vpls250: Bridge port received a packet with own address as source address: probably loop" I torched the interface and awaited the log entry to occur again then scoured it for a src. address that may match one of the many allocated to this unit. ...
Have an interface that I plan on placing multiple public IP's on with the goal of routing them to one each customer whom I connect to a respective port. I want to do NAT an DHCP on each port for the customer with their network resolving to the public IP I assign to them. I have set a basic route and...
Thanks gtj for chiming in.
Selecting info a message window pops up stating "Couldn't start-can't reuse channel while ppp-client running"
No info is displayed in the resulting info window.
I'll hit the boards and see what other sprint users do.
Anyone work with the modem for successful operation? System-Resources-USB can see it but its stuck at PPP status "waiting for packets" Its a plug and chug device on a windows machine with a gui UI but I am not certain which config parameters I can/should modify to apply to the Mikrotik's P...
That line worked! What I am trying to achieve is keeping a call going even if the primary connection fails. Clearing the SIP registration between the phone and server is my plan. I can clear the SIP registration and it pops back up about 5 seconds later on either connection, which is ideal. Any insi...
You may, thanks. Setup a tik for WAN fail over using netwatch. I want to see wan1 fail, bring up wan2, remove the SIP registration to my voip server allowing it to re-initialize via the new route. I can manually remove the connection and see it pop back up under the new route but, that defeats the p...
Bought the switch. Lost the rack mount ears. They are offset with one being several inches longer than the other. Any vendor carry them or can they be purchased direct from TIK?
Have a customer needing facebook messenger blocked. I have a layer7 filter killing the webpages on certain clients but it appears that messenger uses certain ports I need to filter for. Anyone know which ones?
Thanks in advance
Bola
You should post your OSPF settings for review. Our setups are not alike so I cannot provide too much assistance but I would certainly start with the OSPF setup since it is the core of your issues.
Bola You may have the same setup I do but need some clarification. You setup a VLAN from core to your switches then VPLS tunnel to each client? What MTU values are you using? Review your logs on the switches to see what ospf errors are being generated. That has helped me several times. The fact you ...
Thanks for responding Van9018
I am planning on assigning 2 publics to the device then routing one to eth2 and the other to the customer on eth3. Any special approach you would take to that setup?
Using a 750up I want to use one connection coming into eth1 to deliver 2 public IP's to separate customers. One will be NAT'd on eth2 while the other gets an IP directly on eth3. Getting the communications between eth1 and eth3 is no sweat with a bridge but how or should I use Bridge NAT for the cus...
I called on some pros to jump in and help out with this task as well. They too have run into issues with it to. Outbound access through the pppoe connection will not flow. I am still seeking an answer on the web but wanted to update and bump this post to hopefully reach someone that has experience w...
I am following this Wiki exactly. http://wiki.mikrotik.com/wiki/Load_Balancing_over_Multiple_Gateways In an attempt to send my voip traffic down one connection (pppoe) and the LAN subnet (cable DHCP) through the other. I am successfully marking the packets and have an active static gateway for the p...
Running 6.18 and referencing this article http://wiki.mikrotik.com/wiki/Voip A customer has these Cisco SPA504G phones that do not have a DSCP field to populate but do have a TOS/COS option. But, I do not see any reference to the TOS/COS tagging in the mangle rule filter. If its not an option anymor...
Thanks for the reply's I've not sat down to fiddle with this for awhile. Here is the filter currently employed: 0 chain=forward action=accept protocol=tcp dst-address=172.16.17.17 in-interface=ether1-gateway dst-port=8081 1 ;;; default configuration chain=input action=accept protocol=icmp 2 ;;; defa...
Okay I set the following filter rule: chain=forward action=accept protocol=tcp dst-address=172.16.17.17 in-interface=ether1-gateway dst-port=8081 Same results. Tried variants on this as well including action=forward, out-interface=vlan1,bridge-local Question, is this a new requirement for V6? I've n...
Thanks for replying back CelticComms I have the standard forwarding rules applied if that is what you are referring to. : 12 ;;; default configuration chain=forward action=accept connection-state=related 13 ;;; default configuration chain=forward action=accept connection-state=established 14 ;;; def...
RB951-2n running 6.15 Trying to simply access a few phones that reside on a VLAN. Same dstnat rules I use on other Mtik devices are in place but unable to get through to the hosts. Following the connection track, the router is sending syn packets but they are either not being received by the hosts o...
Thanks for replying kickoleg No go on adding the dst. address. I used my current IP and 0.0.0.0/0 Ive never had to populate that field before for other accessible LAN devices. I have disabled filter rules to test but no go. I am accessing a group of phones on a VLAN tied to a different subnet. Thing...
I do this all the time. I can access the router via the public IP via either Winbox or GUI. But, reaching a device on a VLAN behind the thing is shrugging me off. chain=dstnat action=dst-nat to-addresses=172.16.16.5 to-ports=1194 protocol=udp dst-port=1194 Standard Filter rules apply but like all pa...
The router on a stick wiki is helpful but I need to modify it slightly and want to make sure I setup the properties accordingly. What I am not grasping is which mode to use and how to treat the header for the setup as follows on a 260GS: Port 1 (trunk) VLAN 1 Port 2 VLAN 101, 198 Port 3 VLAN 101,198...
Have a loop in my OSPF Have an IP 172.16.6.66/26 that is un-reachable and one hop from core. Ping gives result: 10.0.0.34 84 64 11ms redirect host 10.0.0.33 84 64 14ms redirect host 10.0.0.34 84 64 42ms redirect host 10.0.0.33 84 64 58ms redirect host 10.0.0.34 84 64 123ms redirect host 10.0.0.33 84...
To quickly get a tower up-erational, I have setup a poor mans backhaul off a sector. The tower router at the receiving end is pingable but not making a /30 route back to the broadcasting side. It is however showing up as a neighbor with Full state. Just not showing up in the broadcasting side OSPF r...
That is just a typo. It is isp2. As I understand it. It works (how I have it setup) by marking the packets destined to the ISP2 public subnet. The default route is just there as a pointer for where to go once I make a routing rule for whatever LAN subnet or IP I want to send to ISP2. Now, I will cro...
Think I have it. Looking through this wiki article http://wiki.mikrotik.com/wiki/Testwiki/IP_routing I found the policy routing implementation example which covers my exact situation. I added a routing rule in IP - Routes - Rules /ip route rule add action=lookup disabled=no src-address=10.255.255.0/...
Thanks for replying CelticComms The mangle rule is the only one in the table. As far as the routing table, here is what I have for the two default routes: /ip route add comment="Default route for anything marked as isp2" disabled=no distance=\ 1 dst-address=0.0.0.0/0 gateway=198.x.x.x rout...
Getting some additional capacity for the network and have a second ISP coming into the core router. All is well except for a couple nagging issues that are keeping me from moving traffic to the new services. The main problem is I am unable to perform NAT on a couple of private subnets using the new ...
Put in a new backhaul on ether6 lan 172.16.5.0/24 with 172.16.5.1 on AP, 172.16.5.2 on client and 172.16.5.3 on ether6 interface. Here is the route I use: add comment="Route for VPN to new backhaul" disabled=no distance=1 \ dst-address=172.16.5.0/24 gateway=ether6 pref-src=172.30.74.10 sco...
Came across the following regular expression at this website: http://www.mkyong.com/regular-expressions/domain-name-regular-expression-example/ Expression: ^[A-Za-z0-9-]+(\\.[A-Za-z0-9-]+)*(\\.[A-Za-z]{2,})$ As his post demonstrates, the expression identifies valid domains based on the structure of ...
You should enable the display of the reply-dst and reply-src addresses in the Connections list. That might show you something interesting. trackreply.jpg Source NATing is just not happening correctly. The SIP server does not want to associate with the LAN IP. Now, how to kick it into correctly oper...
Here is an update that may prove useful. The torch image I have posted shows all SIP customers and their related source and destination info. I color coordinated the accounts so you can see how they are connecting. As you can see in blue, two host phones connect while one does not. Same applied to r...
GRE is not GREat right now. Getting a bunch of assured connections that I am trying to control with little success: gre.jpg I have filters in place for the SRC IPs as seen here: 0 chain=input action=drop protocol=gre src-address=70.182.28.60 dst-address=69.71.x.x in-interface=TH connection-type=pptp...
Thanks pcunite for the filter code. Yes, I have the same filters applied. Here is my ROS filter with a few of the IP's I am trying to get rid of: /ip firewall filter add chain=input connection-state=established add chain=input connection-state=related add chain=input connection-state=new add chain=f...
What happens if you add connection-state=new for both the input and forward chains? That is what I'm doing. I too have the SIP helper turned off. No solution with that addition. I turned the NAT helper on again just to check that config option too. Did that addition resolve SIP reg issues for you? ...
Hello Janisk Thanks for responding. Yes, searching the forums on SIP issues I found posts that mentioned turning off the NAT helper SIP function. I have already made that settings adjustment earlier with no discernible change. The random nature of the phone re-regs prompted me to look further into t...
Hello Forum Beginning this past Saturday, 11-16, a few of my SIP customers on my network reported phones that were not working. It would not be the entire group of phones. Just one or two out of say, 4 or 6. Looking at the server details for each customer, I find that random VOIP phones were not reg...
Its a couple of cards I picked up online to bench test with. No USB stick. Only pci-e with sim card. I will locate an 87xx series, perhaps even a usb unit to allow for use in a PC in an effort to identify the correct APN.
Thanks for your assistance. I will update the post as I progress.
Thanks vk7zms I understand and can confirm what you post. The ppp-out1 interface is automatically made and awaiting config. Stepping through the process, I find that the data and info channels will not be set with the suggested numbers. Pop up error indicating no such data or info channel exists. I ...
Have a Sierra Wireless MC5720 PCI-e card (compatible according to the hardware list) I am using in the 411 OS ver 5.6. Looking for an explanation on how to initialize the device. I have reviewed wiki post http://wiki.mikrotik.com/wiki/Manual:Port and identified the location of the driver and port li...
Below is the config for the 750 I am using to accomplish this. Have a working netwatch config setup with two separate internet connections. It functions correctly when link is dropped, disabled or all together disconnected. After about 20 seconds, the backup line comes up and takes over. From a PC, ...
Exported a .rsc file from one 750 I want to transfer to another 750. FTP'ing in to the device, it will not allow me to copy the file over into the second 750 for me to execute an import on the config.
What am I missing to allow it to accept the .rsc into the file vault?
Still working on this. Here is the routing table: # DST-ADDRESS PREF-SRC GATEWAY DISTANCE 0 A S ;;; Route to the world 0.0.0.0/0 10.74.100.5 1 1 A S ;;; VPN route 10.0.2.0/24 pptp-out1 1 2 ADC 10.0.2.1/32 10.0.2.52 pptp-out1 0 3 ADC 10.74.100.4/30 10.74.100.6 TH 0 4 ADC x.x.x.48/28 x.x.x.49 LAN 0 5 ...
Setting up a gateway 1100AH and received a small /28 group of publics from my provider. Eth1 on the 1100 is connected to their 450G and accessing their network with 10.74.100.5/30. I want to route the public /28 group to Eth2 for use on my LAN but coming up short. Using x.x.x.49/28 on the 1100's Eth...
Okay
What I am finding is I need to enable "Use Peer DNS" checkbox and change the firewall NAT to masquerade the pppoe-out1 interface. It does not complete these items automatically.
From a default state, I am using a basic 750 and putting it on an ATT network with the PPPoE credentials. I add the PPPoE client, apply the user and pass and it connects applying a default route and getting an IP. My client machine gets the necessary IP from the default DHCP server (192.168.88.x). B...
Thanks for chiming in bdennie Net traffic is managed on a separate device that ties in to my billing server. Services are setup on the billing server and the bandwidth management device handles the service they are subscribed to. Keep in mind, this is all theory right now. I have the bandwidth manag...
Setting up leased line replacement services via wireless and need to identify a method for limiting the speed limits for traffic between the business locations. I have read up on simple ques where this can be done when you have a mikrotik device at each location however, I am wanting to control this...
Coming up short on googling for routerboard repair services. Does anyone have sources for reputable repair shops?
Have a few 500 series units acting a fool.
Thanks for taking a moment JJOliver. I have attempted to contact 3 separate consultants at his point but no success in getting a response back. If you have a suggested contact or a resource that you can pass on I would appreciate it.
Hello Pre-planning a network I would like to deploy. Looking to the experts on this forum for some pointed direction. Below is the initial design: http://ulinksystems.com/ulinknetwork.jpg Looking for the following hardware input: A cost efficient router for up to 500 subs A cost efficient switch for...
Using a radius server and 750's as NAS devices in various locations for authentication. Having an issue with users that have ipods/ipads or put their PC's to sleep. Anytime they do this they have to login again which becomes annoying. I want to allow a login session to stay active for up to 3 days b...
How can I prevent clients from communicating on the LAN? Prevent users file and printer sharing settings from opening themselves up to other users who may be apt to peak into whats on the network.
Have a PPTP server and client setup with an established tunnel and able to ping the radius server through the tunnel. All seems well. When authenticating a user on the NAS, I see from the radius server logs, that it is seeing the request but ignoring it as its not the correct NAS IP. In this case, i...
Making a login.php file to use in the hotspot but not sure what file needs to be modified to tell the hotspot to redirect to login.php and not login.html.
Looking at redirect.html, its providing a variable link-redirect however, I do not know where to set that variable.
Looks legit and dynamically sets up the firewall rules. I can ping the radius server via its pptp VPN address whilst not logged in. All looks well but consistently getting "radius server is not responding" and auth status failures pile up. Below is the code is necessary. Thanks for any ass...
Well, I just got it working. However, I cannot say for certain what the fix was. I applied the new addresses to the tunnel but that was two days ago. Since then, I have spent 4 hours flipping numerous different switches. Finally, after 5 attempts of "Radius Server Not Responding" I get thr...
Well, I have been jacking with the config for 2.5 hours now. I appear no closer although the steps to getting these two to see each other is straight forward. I could use some additional eyes on this setup. Below is my exports: Network is Radius Server-->450G (pptp server)-->DSL<--Interwebs-->DSL-->...
I have setup a remote RadiusManager server and have a 750 as a hotspot making a pptp connection back to NOC 450G. The RadiusManager documentation specifies the use of a ppp interface. Following those instructions is simple however there is no pptp interface available when setting up the pppoe servic...
Spending some time searching, I came across a post from 08 that speaks of this issue. Post link regarding a problem with UPNP and Xbox's was provided. Has their been a fix or work around since then?
Have a xbox problem where users are randomly able to access xbox live. It appears that once one xbox gets online and plays, the second is unable to communicate with xbox live. I have set port triggering in the router and UPNP but this is not working. How should I configure a mikrotik to allow the xb...
Thanks for the in depth details as always Fewi. I like the VLAN idea Roc-Noc. I will need to get a different switch however. Just a basic DLink 24 port. Roc-Noc, I have read the wiki on setting up VLAN's but have yet to practice it. This situation, I believe, would be different from what is covered ...
I have a 750 running 4.11 setup as a basic NAT'd router for a small 22 unit apartment complex. Without running hotspot, what is the best method for preventing any host to host traffic? There are 3 machines however that I do want file sharing capabilities allowed.
How should I proceed?
Thanks.
Believe I got it. Thanks Fewi
0.0.0.0 is a sort of white washing value attributed to all hosts whereas 0.0.0.0/0 is applicable to all routes when used in that context.
What part of the manual would cover this particular subject? There are probably other nuggets I should make myself aware of.
I see that, when using winbox, you cannot setup the passthrough without an IP address. When I used CLI, it automatically entered 0.0.0.0 as an IP.
Still need to check with user to verify if it worked but will the device now receive an IP of 0.0.0.0 or does this tell the router something specific?
Setup a hotspot with manually input usernames and passwords. Would like some devices to simply bypass the HS login requirements.
Is that best done with a firewall filter or in the HS IP Bindings tab?
Well I had not had the chance to get over to the remote site and play with the firewall so I sat around last night just throwing a few things at the issue and found a way in. However, Not sure if its the most secure way of using PPTP. Here is how I went about it. I setup secrets for each location. I...
Its a cisco device that is plopping a bunch of ARP connections on my router. Going to try and block it but curious about what it means. 0 D 10.0.0.157 4E:38:55:84:72:B4 lan 1 D 10.0.0.155 00:15:6D:3A:26:B1 lan 2 D 71.153.40.13 00:00:0C:8D:B2:90 wan 3 D 65.55.158.118 00:00:0C:8D:B2:90 wan 4 D 174.17....
Okay Fewi
Any other encrypted access method you suggest? I have setup an l2tp server and client on this link with the same results. Going to drop firewall and rebuild piece by piece to hopefully identify whats blocking winbox.
Appreciate your input Fewi No, Its the other way around. I am trying to get to the client from any network via the vpn. I can access the Server router (450g) with no troubles with the VPN from anywhere. Its getting to the clients (scenicd) that is not functional. Even from the home LAN where the ser...
Now that Xmas is behind me, I can get back to a solution for this. Setup another 750 with its own acct, scenicd. Configs indicate that it is in session with the server. I am pouring over this detail for oddities. To answer your Q's Fewi, I plan on adding mapping for devices behind the router once I ...
Fewi Thank you for replying. Network layout is as follows: My PC-->450G-->Internet-->cable modem-->750-->remote lan What I am trying to accomplish is vpn access to winbox on the 750 and the network devices behind it. At present, the 750 pptp IP is pingable and registers its VPN connection but stops ...
Have server setup with 3 client (750's) connections. I am assigning IP's to the clients from the existing IP pool I use on my LAN. Each client is responding to pings and keeps the sessions active. I have allowed port 1726 and GRE protocol through client firewalls. What can I be missing? The server i...
Stepping through the wiki on BCP bridging on my 450G. Enabling port LAN2 then setting up the bridge interface kills the hotspot operating on interface 1.
How can I setup the bridge on one interface and still use the Hotspot?
I have PPTP and EOIP setup and operational on the 450g(server) and 750(client) following the Butch Evans tut at http://butchevans.com/readarticle.php?article_id=19 Straight forward. While the PPTP tunnel is pingable from either side, the EOIP link appears to get thwarted by firewalls as identified b...
I have PPTP setup and operational on a 450g (UM Radius host) and 750 (pptp client). I want to setup the 750 to act as a UM Radius client to the host 450g serving UM payment processes and authenticating users. What functions on the 750 should I enable and what functions should I pass to the 450g? Ena...
Found it fellas It was a DNS entry I made on my DHCP server. I removed that and I am in. I recall trying to ping IP addresses to verify that. In any event, I looked at the IP details of my PC and found the odd DNS entry. As far as the 20 dot address, I did not change it in the post. Its the addressi...
Paying too much for a static IP from Centurylink but finally have it issued and setting it up in my RB450G Setting up PPPoE is pretty straight forward. Followed a good forum post and the wiki. Connection to Centurylink is up: [admin@MikroTik] /interface pppoe-client> monitor pppoe-out1 status: "...
Throwing some different ideas to this. Processing another payment to myself, I get the following for tools-user manager-users: 2 I customer=admin name="ulink" password="ulink" registration-date=oct/12/2010 02:09:39 email="service@ulinksystems.com" shared-users=1 last-se...
Received email from paypal recognizing that payment notifications are failing: Please check your server that handles PayPal Instant Payment Notifications (IPN). IPNs sent to the following URL(s) are failing: https://mypublicip/user?serviceId=MWT.Payment&method=2 https://mypublicip/user?serviceId...
Item 2 below is a user I am setting up in testing the paypal payment setup with UM 4.11 Payment processes. Its receiving a registration key as seen below but remains incomplete. One issue I notice the the registration date. It is 5 hours AHEAD of actual time. I believe this is related to a GMT offse...
Using test pack 4.11
Noticing the user signup path is changed from https://um-ip/user?signup=xxxxxxx
to....well....something else.
Can someone kindly share?
Working on getting the paypal system to function. I can create a user and send the payment and see the new user account with transaction key and services purchased. I understand that trans-start and trans-end are date stamps. Currently trans-end=waiting trans-status=0 result-code=0 and result-msg=&q...
Thanks for replying.
Right after running lose key and reboot, I attempted to apply the level 4. It was really only within minutes of applying lose key. However, now its been well over 24.
Reckon I will contact Mikrotik support on this one.
Had a demo key going. Upgrading to level 4 key. Ran system>lose-key. That appeared to work but now RB is not showing up in Winbox.
Besides serial console connection, what other methods are suggested for accessing then applying the new license?
On the UM wiki at the following link http://wiki.mikrotik.com/wiki/User_Manager/4/User_Signup Under Customization Steps is the following bullet point: "Signup page must be accesses at least once, because template files are created on first request. Therefore open signup page in your browser. If...
Thanks for replying Normis I am missing a setting somewhere that allows UM to display the options for a user to sign up a new account or log in with an existing one. If I use any URL to envoke this page like http://router_ip_address/user?subs=publicID (all variables included) I am taken to the main ...
Have 4.11 of UM installed but not seeing several of the features mentioned in 4.x
I am assuming I have the wrong version of rOS installed. What license level should I be using to utilize latest UM features?
Thanks
Hello I am working on this as well. Signup is eluding me. I followed your lead and can get the login page with signup. After accepting the SSL cert, I am directed to https://192.168.1.1/user/signup/mikrotik. Address would seem correct however, it is the standard user manager login page. Not a new us...
Thats something I am working on as well. Bought the gear from Baltic Networks. Site indicated it will be a version 4 license but reviewing the system details I get 3.25 I have emailed them regarding this but no response yet.
Thanks for replying.
Where will it identify itself in ROS? I have plugged it in but no indication of its communication with ROS. Although I have not inserted the antenna.
Bought my first hardware setup.
Besides plugging the R52n into the 411ar pci slot, what steps need to be taken to make it usable/accessible within winbox?