Community discussions

MikroTik App

Search found 39 matches

by jantypas
Fri Apr 26, 2024 11:14 am
Forum: General
Topic: This very simple firewall ruleset SHOULD work-- but.....
Replies: 4
Views: 657

Re: This very simple firewall ruleset SHOULD work-- but.....

I don't quite understand why -- but dst-address-list, even if it has the same IP in it, is not dst-address. That works. Thanks ofr the help.
by jantypas
Fri Apr 26, 2024 11:04 am
Forum: General
Topic: This very simple firewall ruleset SHOULD work-- but.....
Replies: 4
Views: 657

Re: This very simple firewall ruleset SHOULD work-- but.....

OK -- for my education at least :-) Why does yours work and mine doesn't -- what is different? I see the order of the rules are different but they should say the same thing.
by jantypas
Fri Apr 26, 2024 10:34 am
Forum: General
Topic: This very simple firewall ruleset SHOULD work-- but.....
Replies: 4
Views: 750

This very simple firewall ruleset SHOULD work-- but.....

I've reduced everything down to the basics but it doesn't seem to help.... The hardware is an RB5009 that simply has two interfaces (an OUT (FRC) and an IN (LAN). (There are firewalls upstrea.) The goal of the firewall ruleset at this point is: Allow everything out Allow return traffic in Allow SSH ...
by jantypas
Fri Apr 26, 2024 10:34 am
Forum: General
Topic: This very simple firewall ruleset SHOULD work-- but.....
Replies: 4
Views: 657

This very simple firewall ruleset SHOULD work-- but.....

I've reduced everything down to the basics but it doesn't seem to help.... The hardware is an RB5009 that simply has two interfaces (an OUT (FRC) and an IN (LAN). (There are firewalls upstrea.) The goal of the firewall ruleset at this point is: Allow everything out Allow return traffic in Allow SSH ...
by jantypas
Mon Sep 11, 2023 7:14 pm
Forum: General
Topic: Mikrotik (7.11.2) and Comcast Business IPv6 (DUID issues?)
Replies: 0
Views: 1104

Mikrotik (7.11.2) and Comcast Business IPv6 (DUID issues?)

The subject (almost) says it all :-) I've got an RB5009 attached to a business Comcast line with a /28 IPv6 static block and (supposedly) static IPv6 prefix. That's the problem -- the last part -- the prefix is "almost" static (which doesn't count....) I get 2603:3024:11bd:11xx::/56, but i...
by jantypas
Thu Mar 23, 2023 2:38 pm
Forum: General
Topic: Why do I get esetablished IPv6 packets dropped in 7.8
Replies: 1
Views: 352

Why do I get esetablished IPv6 packets dropped in 7.8

Here are the firewall rules: /ipv6 address add from-pool=ComcastV6 interface=ether1-COMCAST add address=2603:3024:11bd:c1a1::1 interface=ether2-LAN /ipv6 dhcp-client add add-default-route=yes interface=ether1-COMCAST pool-name=ComcastV6 \ pool-prefix-length=56 rapid-commit=no request=prefix use-peer...
by jantypas
Sat Jan 14, 2023 11:19 am
Forum: General
Topic: DNAT NAT should work, but appears blocked
Replies: 2
Views: 689

DNAT NAT should work, but appears blocked

This probably should go in the beginners section since I would think I'd figured this out by now -- but apparently not -- it's been some time since I've had to do this.... The following *should* be a very basic firewall that blocks all unsolicited inbound traffic, masquerades outbound traffic and ha...
by jantypas
Sun Mar 06, 2022 8:14 pm
Forum: General
Topic: GRE performance problems
Replies: 5
Views: 1621

Re: GRE performance problems

I did do that -- wireshark shoes a lot of retransmits and sequence events -- but I'm sure what I can do about it. The MTU is 1280, not 14xx, TCP MSG is set, what else is there to do?
by jantypas
Sun Mar 06, 2022 1:39 pm
Forum: General
Topic: GRE performance problems
Replies: 5
Views: 1621

Re: GRE performance problems

CPUs never go above 35% on the speedtests.... To be more specific: The CHR on the Internet edge is sending IN 199.181.204.0/24 from our BGP edge router. The far branch end will consume a slice of that (199.181.204.128/26). On the wireguard tunnel, I've allocated two IP addresses (192.168.88.1/30 and...
by jantypas
Sun Mar 06, 2022 3:04 am
Forum: General
Topic: GRE performance problems
Replies: 5
Views: 1621

GRE performance problems

Actually, it's an everything performance problem -- a problem that's all over the net, but no answers..... forgive the length of this -- there's a lot here, but I want to make sure I covered everything in this case.... I have a CHR Router under VMWare (7.1.3), attached to gigabit fiber. Plenty of RA...
by jantypas
Fri Feb 11, 2022 6:40 am
Forum: General
Topic: Router OS 7.1.1 and router rules
Replies: 0
Views: 383

Router OS 7.1.1 and router rules

Hello all -- I'm trying to get router rules to work on CHR 7.1.1. In 6.x, at least for V4, I could make it work. What I'm trying to do: I have two ISPs using BGP[/list I want to set up a source-based routing rule that either says "if the incoming interface is ether3, or the source address is 19...
by jantypas
Wed Jun 24, 2020 7:36 pm
Forum: General
Topic: PCC routing or routing rules?
Replies: 2
Views: 1101

Re: PCC routing or routing rules?

OK great -- I'll remove the mangle rules and stick with the routing rules. V6 is also from the same provider albeit over a sit tunnel. like HE would do. So there, it's just one set, and it's easy -- I'll let radv do its magic. For those outside of this detail, this was created because the local &quo...
by jantypas
Wed Jun 24, 2020 5:58 pm
Forum: General
Topic: PCC routing or routing rules?
Replies: 2
Views: 1101

PCC routing or routing rules?

Hello all, I've just been assigned my ARIN IP space so I'm trying to figure out which way to go..... THe ISP is tunneling my IPv4 space over a local provider (IPIP tunnel). So let's say ARIN assigned me public space 100.200.100.x/24 (V6 as well, but we'll get to that) I still need the local ISP defa...
by jantypas
Wed May 13, 2020 5:57 pm
Forum: RouterOS beta
Topic: Feature Request - Wireguard Protocol
Replies: 167
Views: 94521

Re: Feature Request - Wireguard Protocol

I also finally realized I can't type today :-)
by jantypas
Wed May 13, 2020 5:56 pm
Forum: RouterOS beta
Topic: Feature Request - Wireguard Protocol
Replies: 167
Views: 94521

Re: Feature Request - Wireguard Protocol

Not complaining here, but I'm beginning to wonder if we've got things all wrong. I, too, wanted the Uber Mikrotik box with everything on it, but Mikrotik hasn't even got OpenVPN with UDP, and I don't see it coming any time soon, even in RouterOS 7. But when I look at it, nearly everything we're aski...
by jantypas
Thu Apr 16, 2020 6:05 pm
Forum: General
Topic: Public IP space tunneling -- I *think* this is right?
Replies: 4
Views: 1977

Re: Public IP space tunneling -- I *think* this is right?

My bad -- I think in MT world, we call it a sit interface -- typically one uses it for things like Hurricane Electric Ipv6 in V4 tunnels.
It may just be easier to have a single "virtual" router rather than the pair where I'd have to run BGP for no real reason.
by jantypas
Thu Apr 16, 2020 4:49 pm
Forum: General
Topic: Public IP space tunneling -- I *think* this is right?
Replies: 4
Views: 1977

Re: Public IP space tunneling -- I *think* this is right?

So I've almost got it. Let's assume I have a physical tunnel endpoint on my end of 12.13.14.1 and the ISP has 11.12.13.1. The GRE tunnel is 11.12.13.1 <-> 12.13.14.1. My gateway rule for 191.192.193.0/24 is: 191.192.193.0/24 via gw 12.13.14.1. Probe 11.12.13.1 to make sure that gateway is up. At tha...
by jantypas
Thu Apr 16, 2020 5:27 am
Forum: General
Topic: Public IP space tunneling -- I *think* this is right?
Replies: 4
Views: 1977

Public IP space tunneling -- I *think* this is right?

But then again, I think a lot of things, and most people think I need medication.... so who knows. It's been so long since I've had routed public IP space, I don't remember.... I am fortunate enough to still have an Internic assigned IP block. It's small so most ISPs won't route it, but I found one ...
by jantypas
Fri Nov 15, 2019 2:07 pm
Forum: General
Topic: Feature Request: zerotier vpn
Replies: 32
Views: 18442

Re: Feature Request: zerotier vpn

Since Mikrotik appears not to be pursuing other concepts such as Wireguard and ZeroTier, and we're still waiting for OpenVPN with UDP, I finally gave up waiting and just bought a Protecteli box. The atom powered unit can easily run a small Linux distro (Ubutnu 19 in my case), and it handles all of t...
by jantypas
Sun Feb 10, 2019 8:01 pm
Forum: General
Topic: RouterOS side-carring traffic
Replies: 0
Views: 1273

RouterOS side-carring traffic

Here's a wierd one for the day folks.... I've got a couple of MT machiens -- one is the trusty RB1100AH that needs to be replaced soon. (That's going to a young person who wants to learn this stuff...) The other is a VM isntance of a CHR. I've even convinced a hard-core ASAer to look at Mikrotik. (C...
by jantypas
Sun Jan 13, 2019 12:31 am
Forum: General
Topic: Feature Request: zerotier vpn
Replies: 32
Views: 18442

Re: Feature Request: zerotier vpn

I, too, am a ZeroTier user. For those who wonder why we should put it in Microtik, especially if it can appear as a layer-2 interface: ZeroTier is great for doing OSPF across WANs -- yes, I know that's what BGP is for, but there are times we need a "broadcast" interface across a WAN ZeroTi...
by jantypas
Fri Jan 19, 2018 9:11 pm
Forum: General
Topic: Comcast Business service and DHCPv6 from a Mikrotik device
Replies: 0
Views: 605

Comcast Business service and DHCPv6 from a Mikrotik device

OK, it's my fault, I told everyone I had it working, and it did work, until Comcast upgraded my modem.... Old setup: ----> Comcast Netgear Gateway --- Mikrotik 1100AH --- LAN Mikrotik would do a DHCPv6 request of the gateway with a prefix of /60 and a prefix hint of /60. I'd get it, and everything w...
by jantypas
Mon Jan 15, 2018 12:58 am
Forum: General
Topic: Looking for a successor to the RB110AH
Replies: 4
Views: 1545

Re: Looking for a successor to the RB110AH

Very nice choices -- maybe the CCR9 will replace this unit and I can gift this unit to someone who's learning about Mikrotik while coming from an old ASA. He was a bit put off by the Mikrotik CLI but, he's learning you can get a lot of power for a fraction of the Cisco price. While I would love ever...
by jantypas
Mon Jan 15, 2018 12:55 am
Forum: General
Topic: Looking for a successor to the RB110AH
Replies: 4
Views: 1545

Re: Looking for a successor to the RB110AH

Very nice choices -- maybe the CCR9 will replace this unit and I can gift this unit to someone who's learning about Mikrotik while coming from an old ASA. He was a bit put off by the Mikrotik CLI but, he's learning you can get a lot of power for a fraction of the Cisco price. While I would love ever...
by jantypas
Sun Jan 14, 2018 6:38 pm
Forum: General
Topic: Looking for a successor to the RB110AH
Replies: 4
Views: 1545

Looking for a successor to the RB110AH

The subject says it all -- I've got a nice, solid RB1100AH. It's currently an edge router, with a 250Mb/40Mb connection to it. It serves as the edge fireall, IPv6 firewall etc. I let a PFsense box do the IPSEC and OpenVPN work because that's easier for others to handle when compared to the Mikrotik ...
by jantypas
Mon Sep 04, 2017 5:22 am
Forum: General
Topic: Time for VLAN confessions!
Replies: 6
Views: 1942

Re: Time for VLAN confessions!

I shall -- what's special about it? However, I took a shot in the dark and just added the VLANs to the bridges. It works.
So most important, thanks to both of you for the help.
by jantypas
Sun Sep 03, 2017 5:54 am
Forum: General
Topic: Time for VLAN confessions!
Replies: 6
Views: 1942

Re: Time for VLAN confessions!

Since the previous ASCII art attempt was bad, I have a visio image I can send if it helps....... First, we have a pfSense router with two interfaces -- one is for untagged traffic to keep things simple. The other interface is for tagged traffic (Vlans 100, 101, 102). The pFSense box sends out untagg...
by jantypas
Sun Sep 03, 2017 5:38 am
Forum: General
Topic: Time for VLAN confessions!
Replies: 6
Views: 1942

Re: Time for VLAN confessions!

OK -- so here's what I have pFsense -----------------------------------------------------CRS Trunk Switch (100, 101, 102) | | | (All are hybrid ports) S1 S2 S3 | | | | UP 100 UP UP 101 102 | UniFIs Where UP = untagged ports and the numbers are VLANs. The pFSense box sends out untagged traffic to the...
by jantypas
Sat Sep 02, 2017 5:53 pm
Forum: General
Topic: Time for VLAN confessions!
Replies: 6
Views: 1942

Time for VLAN confessions!

I knew this day would come -- I'm hoping people can soften the blow for I have sinned.... Years ago, when I started with Mikrotik, I bought the RB1100 (how I remember that fan), and as needs came, I started adding CRS switches. We didn't VLANs at the time, so I never bothered. I just kept adding swi...
by jantypas
Tue Aug 02, 2016 8:25 pm
Forum: General
Topic: Comcast IPv6 and Mikrotik
Replies: 1
Views: 1390

Comcast IPv6 and Mikrotik

Hello all--- I know I'm close to an answer, but close enough.... I'm a Comcast static IP business customer. Comcast is now also offering me a ./56 V6 prefix (assigned by DHCPv6). First, since Comcast *truly* does not want to talk about this. I believe the following is true? Assume my prefix is 1111:...
by jantypas
Tue Mar 04, 2014 3:01 am
Forum: Beginner Basics
Topic: New CRS125 -- basic questions about switching vs routing
Replies: 5
Views: 2201

Re: New CRS125 -- basic questions about switching vs routing

Wish I could use VLANs, but not every switch in this environment is really VLAN friendly. I just removed them for the sake of the discussion, so I really have no choice but to double NAT at the moment.....
by jantypas
Tue Mar 04, 2014 2:50 am
Forum: Beginner Basics
Topic: New CRS125 -- basic questions about switching vs routing
Replies: 5
Views: 2201

Re: New CRS125 -- basic questions about switching vs routing

In a perfect world, I want to do this: Inter--- RB1100AH ----- CRS24------ Main Router |||| | switch wlan0 Assume the RB1100 has static WAN addresses and NATs all of its internal LAN ports. The LAN side of the IPs are on the subnet 10.0.0.0/16. I have a series of non-switched interfaces on the 1100....
by jantypas
Tue Mar 04, 2014 1:57 am
Forum: Beginner Basics
Topic: New CRS125 -- basic questions about switching vs routing
Replies: 5
Views: 2201

New CRS125 -- basic questions about switching vs routing

Good evening all.... I just received my new CRS125. I hate to admit it.... I've got my two 1100AHs, and they work great, but this is the first switch/router nit I've had where I need to use the switch and router parts, and I'm stumped. So, some basic questions: Assume the 1100s are doing their routi...
by jantypas
Mon Jun 17, 2013 4:18 pm
Forum: General
Topic: If not the RB1100AH, which one?
Replies: 3
Views: 1133

Re: If not the RB1100AH, which one?

Both are fanless? Remember, this is in a home office.
by jantypas
Mon Jun 17, 2013 4:13 pm
Forum: General
Topic: If not the RB1100AH, which one?
Replies: 3
Views: 1133

If not the RB1100AH, which one?

Well, it seems I can't get the RB1100AH anymore. This is a home office with high-bandwidth links, so the 450G isn't quite enough. I had an RB1100, but that wasn't office friendly with its fans, and I've the RB1100AH, but these are hard to get. What's the successor? We know it isn't the RB1200. It ne...
by jantypas
Tue May 07, 2013 6:23 am
Forum: General
Topic: L2TP/IPSEC and NAT -- but client IP is unknown (0.0.0.0/0)
Replies: 1
Views: 1335

L2TP/IPSEC and NAT -- but client IP is unknown (0.0.0.0/0)

I, like many people are setting up an L2TP/IPSEC VPN. Thus far, I have: - Created the PPP user and address pool - Created the IPSEC policy with generate policy 0.0.0.0/0 - Set up the L2TP server - Added accept rules on the input chain for ports 500,1701 and 4500, as well as protocols 50 and 51. My r...
by jantypas
Sat Feb 05, 2011 10:47 pm
Forum: General
Topic: Anyone have success with IPSEC and NAT-T on 5.0r8
Replies: 1
Views: 1619

Anyone have success with IPSEC and NAT-T on 5.0r8

Hello all, I know it's a beta and, things do change... but has anyone been able to get a road-warrior config with L2TP/IPSEC and Mikrotik. I have already done the following with various degrees of success. On the laptop (a Mac), I'm behind a cellular router which has both dynamic IP to the network a...
by jantypas
Wed Dec 15, 2010 7:26 pm
Forum: General
Topic: Trouble creating certificates for OVPN server via Easy-RSA
Replies: 0
Views: 982

Trouble creating certificates for OVPN server via Easy-RSA

I'm sure this has been asked 10,000 times before, in fact, I know I was one of those 10,000, but I've had 9,999 failures since :-) I'm trying to set up a Routerboard 450G (OS 4.14) to be used as an OVPN server. I've got an OpenVPN server working just fine on a Fedora 14 box with self-signed certs fo...
by jantypas
Mon May 03, 2010 12:06 am
Forum: General
Topic: IP6 6-to-4 tunnels (Hurricane Electric) with Mikrotik
Replies: 0
Views: 925

IP6 6-to-4 tunnels (Hurricane Electric) with Mikrotik

Good morning all --- I'm making the transition from a Linux router to a Mikrotik box. I have the 450G right now while I wait for the 1100. I'm try to do several things.... Some are probably easy, but these are a few that have me stumped... 1. I've set up an OpenVPN server. I see where I put in my ce...