Community discussions

MikroTik App

Search found 257 matches

by Nollitik
Thu Jan 20, 2022 6:30 am
Forum: General
Topic: Adding Comment to DHCP Lease [SOLVED]
Replies: 8
Views: 3927

Re: Adding Comment to DHCP Lease [SOLVED]

There is nothing to figure out - the DHCP hostname is an optional parameter that can be passed to a DHCP server within a DHCP request to provide additional information about the client. If the Apple device chooses not to send its name in the DHCP request there is nothing you can do on the Mikrotik ...
by Nollitik
Tue Jan 18, 2022 9:59 pm
Forum: General
Topic: Firewall Rule
Replies: 10
Views: 2300

Re: Firewall Rule

How does IDS and IPS work is it applied to traffic flowing out originating on the LAN out to the internet OR to Traffic originated from external sources heading to the LAN OR Return external to lan traffic Yes, I agree...that's why I have Suricata on WAN (inline mode) for traffic that didn't origin...
by Nollitik
Tue Jan 18, 2022 6:52 am
Forum: General
Topic: Adding Comment to DHCP Lease [SOLVED]
Replies: 8
Views: 3927

Re: Adding Comment to DHCP Lease [SOLVED]

There is nothing to figure out - the DHCP hostname is an optional parameter that can be passed to a DHCP server within a DHCP request to provide additional information about the client. If the Apple device chooses not to send its name in the DHCP request there is nothing you can do on the Mikrotik ...
by Nollitik
Tue Jan 18, 2022 6:17 am
Forum: General
Topic: Firewall Rule
Replies: 10
Views: 2300

Re: Firewall Rule

Yes, ids/ips is not an MT thing..... You must be protecting the king of some nation with all that security, what are you hiding LOL My privacy...LOL. Real answer is I got into networking when I purchased my RB450G and was fascinated with Mikrotik...that was fourteen years ago. Then, discovered pfSe...
by Nollitik
Mon Jan 17, 2022 11:41 pm
Forum: General
Topic: Firewall Rule
Replies: 10
Views: 2300

Re: Firewall Rule

Why do you need the pfsense box? Mikrotik can do it all.
It is much easier to run IPS/IDS on pfSense than Mikrotik, that's why! On pfSense, I have Suricata on WAN as well as Snort on LAN.
Another great package is pfBlpckerNG. So, why cannot I like both platforms? Mikrotik is my LAN's gatekeeper.
by Nollitik
Mon Jan 17, 2022 11:31 pm
Forum: General
Topic: Firewall Rule
Replies: 10
Views: 2300

Re: Firewall Rule

Hi, I would say (but of course lots of details are missing), this is what you miss: remove nat from the Mikrotik box and check routing on the pfsense box, to have a static route for your 10.0.8.0/24 Network to the Mikrotik box IP. Of course give the Mikrotik a static IP from 192.168.1.x. Don´t forg...
by Nollitik
Mon Jan 17, 2022 7:57 pm
Forum: General
Topic: Firewall Rule
Replies: 10
Views: 2300

Firewall Rule

Here is a diagram of my setup below: Screen Shot 2022-01-17 at 11.44.12 AM.png Is this forward rule (12) I have added correct? When I ping the DMZ I get timeout. [admin@NolliTik] > /ip/firewall export # jan/17/2022 11:50:26 by RouterOS 7.1 # software id = 33B2-XGBT # # model = RB450Gx4 # serial numb...
by Nollitik
Mon Jan 17, 2022 7:14 pm
Forum: General
Topic: Adding Comment to DHCP Lease [SOLVED]
Replies: 8
Views: 3927

Re: Adding Comment to DHCP Lease [SOLVED]

What's the real issue you're having? You can add a static lease for any device and then you can add a comment to that lease via terminal / Winbox (and probably WebFig as well). I quickly checked and on one of my routers I have 30+ iOS devices and all of them send hostnames properly. The only catch ...
by Nollitik
Sun Jan 16, 2022 5:22 am
Forum: General
Topic: Adding Comment to DHCP Lease [SOLVED]
Replies: 8
Views: 3927

Re: Adding Comment to DHCP Lease [SOLVED]

How does one add a comment to DHCP lease that didn't receive hostname from device? I cannot do so using Winbox for MacOS. Well, I discovered one can add comment via the webconfig on some things but nothing for my iPhones...thanks Apple for privacy on my own money well-spent private network...my Mik...
by Nollitik
Sat Jan 15, 2022 7:27 pm
Forum: General
Topic: Adding Comment to DHCP Lease [SOLVED]
Replies: 8
Views: 3927

Adding Comment to DHCP Lease [SOLVED]

How does one add a comment to DHCP lease that didn't receive hostname from device?
I cannot do so using Winbox for MacOS.
by Nollitik
Sat Jan 08, 2022 6:26 am
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

It's all working now after figuring out my login/password problem for the second user. I had been creating the password, reconfirmed it, then clicked apply, then, clicked okay. Well doing so killed the newly created password when I clicked okay. One had only one choice, one either click apply or cli...
by Nollitik
Sat Jan 08, 2022 4:03 am
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

NO its not a bug, its a user who has made mistakes in configuring the device. I LOL reading this and seeing some of my mistakes... add name=nolliLAN ranges=10.0.8.2-10.0.8.4, 10.0.8.20-10.0.8.251 WHY??? in any case not wrong just weird from my perspective. I have cameras, servers, and a switch that...
by Nollitik
Fri Jan 07, 2022 8:22 pm
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

Interface menu selection is where you find to add a new LIST, its tricky to find I thing its a square box vice a pulldown.............. There is no way...you'll just be creating another LAN that would have the same exact network. I even tried creating a firewall input rule and that didn't work. The...
by Nollitik
Thu Jan 06, 2022 7:12 pm
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

Yes, looks good, Why not just put the opendns servers right in the MT, dont need pfsense for that?? /ip dns set allow-remote-requests=yes servers=208.67.222.222,208.67.220.220 The reason is I am using pfBlockerNG package on pfSense so all DNS request resolve there. I am still having login issue fro...
by Nollitik
Thu Jan 06, 2022 7:20 am
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

Looking at the config, so far so good! - See three subnets one for the bridge and two for specific ports. Not really wrong but not userful are these settings. /ip dns set allow-remote-requests=yes servers=192.168.1.1,10.0.8.1,172.17.9.1 ( the router already knows these are the servers for the netwo...
by Nollitik
Thu Jan 06, 2022 12:13 am
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

Just realize I could use the browser and copy from Terminal that way...so, here it is... [nolli@MikroTik] > /export # jan/05/2022 16:08:27 by RouterOS 7.1 # software id = 33B2-XGBT # # model = RB450Gx4 # serial number = ADBA0ACE537B /interface bridge add admin-mac=74:4D:28:21:60:52 auto-mac=no comme...
by Nollitik
Wed Jan 05, 2022 11:55 pm
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

Post your lastest config for assistance.
I am using Mac so cannot copy from Mikrotik terminal so I hope a pic will help. I didn't see any list called deconfig...
Screen Shot 2022-01-05 at 2.34.09 PM.png
Screen Shot 2022-01-05 at 2.39.11 PM.png
by Nollitik
Wed Jan 05, 2022 6:16 pm
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

Pictures are nice but need to see the config /export hide-sensitive file=anynameyou wish. I should add that my advice was NOT to create a separate network but to create a separate access to the router for config purposes. For a completely different subnet, besides IP address you need IP pool, dhcp ...
by Nollitik
Tue Jan 04, 2022 8:18 pm
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

You add the WLAN interface to the list NOT the port........ but much thanks it was not clear on my article and have just made some modifications. See if it reads better for you now!! add interface=WLAN name list=manage I am not using Wlan...this is what I have setup...see images and it seems that I...
by Nollitik
Tue Jan 04, 2022 5:45 am
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Re: Proper Way to Create Separate Network Not Bridged [SOLVED]

To make changes so you dont get locked out. create one port off the bridge like this and do all your config from there...... https://forum.mikrotik.com/viewtopic.php?t=181718 Okay I used port three to reconfigure the router; however, the step I am having issue with is where do I add say ether 2 to ...
by Nollitik
Tue Jan 04, 2022 3:04 am
Forum: General
Topic: Proper Way to Create Separate Network Not Bridged [SOLVED]
Replies: 19
Views: 3617

Proper Way to Create Separate Network Not Bridged [SOLVED]

What is the proper way to create separate network that are not bridged? I have the new RB450x4 and I would like to separate my LAN from my guest network, but would like to keep default firewall Screen Shot 2022-01-03 at 6.31.31 PM.png I can easily take port five (5) off the bridge but if I try port ...
by Nollitik
Sat Aug 08, 2020 1:42 am
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections (Solved)

Hello Just mentioning, in case it helps you, that I managed to get ntopng working with the MikroTik Traffic Flow (NetFlowv9) This is including the internal client -> external server usage (after nat) in ntopng The NAT information required to do so is in the exported flows and the solution uses a mo...
by Nollitik
Wed Jun 24, 2020 12:27 am
Forum: General
Topic: Connecting Network on Different Ether [SOLVED]
Replies: 7
Views: 2738

Re: Connecting Network on Different Ether [SOLVED]

Just wanted to report that I can access without any problem ...thanks all helpers!
by Nollitik
Tue Jun 23, 2020 9:45 pm
Forum: General
Topic: Connecting Network on Different Ether [SOLVED]
Replies: 7
Views: 2738

Re: Connecting Network on Different Ether [SOLVED]

Well I think mkx was basically stating, devices (besides MT) have their own sets of behaviours in the software on them, example PCs have sometimes 1 or more software firewalls running
Okay, let me try first and see what happens.
by Nollitik
Tue Jun 23, 2020 6:23 pm
Forum: General
Topic: Connecting Network on Different Ether [SOLVED]
Replies: 7
Views: 2738

Re: Connecting Network on Different Ether [SOLVED]

Also make sure firewalls on LAN devices allow connections from different IP subnet, default windows firewall settings don't allow that.
Interesting ... I have the default firewall as below image ... wouldn't that get covered under ICMP?
Screen Shot 2020-06-23 at 10.18.58 AM.png
by Nollitik
Tue Jun 23, 2020 6:14 pm
Forum: General
Topic: Connecting Network on Different Ether [SOLVED]
Replies: 7
Views: 2738

Re: Connecting Network on Different Ether [SOLVED]

Yes, the router will route between them at L3, unless you have a blocking fw rule.
Cool ... that's what I thought ... thank you!
by Nollitik
Tue Jun 23, 2020 5:39 pm
Forum: General
Topic: Connecting Network on Different Ether [SOLVED]
Replies: 7
Views: 2738

Connecting Network on Different Ether [SOLVED]

I have my main network interface on Ether 2 - (10.0.8.0/24) and I have created a separate network on Ether 4 - (10.8.27.0/24)
I would like to be able to access via the browser servers on Ether 4 from my Ether 2 network ... would I be able to access since
My connection is within LAN?
by Nollitik
Tue Jun 23, 2020 4:06 pm
Forum: General
Topic: How to Remove Slave from Interface [SOLVED]
Replies: 2
Views: 7223

Re: How to Remove Slave from Interface [SOLVED]

If "now" means "after upgrading from pre-6.41" where you could declare one Ethernet interface to be a master one, and indicate other Ethernet interfaces as its slaves, this method of configuration has been replaced by the "new bridge setup" where the same effect is pro...
by Nollitik
Tue Jun 23, 2020 7:37 am
Forum: General
Topic: How to Remove Slave from Interface [SOLVED]
Replies: 2
Views: 7223

How to Remove Slave from Interface [SOLVED]

How do one remove slave from an interface now?
Screen Shot 2020-06-22 at 11.17.44 PM.png
by Nollitik
Sat Mar 07, 2020 6:23 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections (Solved)

The solution turned out to be simple however involved third party application. By using the Packet Sniffer tool and Wireshark, I could achieve my goal without, as appeared, taxing the router. Thank you Sob and others for responding.
Screen Shot 2020-03-07 at 10.26.18 AM.png
by Nollitik
Mon Mar 02, 2020 7:53 pm
Forum: General
Topic: Kansas City MUM USA
Replies: 20
Views: 6103

Re: Kansas City MUM USA

Since OP is on limited budget, don't hesitate to use AirB&B...it could surprise you!
by Nollitik
Mon Mar 02, 2020 4:25 am
Forum: The Dude
Topic: Using Dude to Capture Firewall - Connections
Replies: 1
Views: 3892

Re: Using Dude to Capture Firewall - Connections

Is it possible to use the Dude to capture all connections in Firewall > Connections? I have looked at the manual, and it has a syslog; however, the manual seems to lack meaningful or significant instructions. I have installed the server on my RB450Gx4 and the Mac version client so far. Well, the Ma...
by Nollitik
Sat Feb 22, 2020 8:32 pm
Forum: The Dude
Topic: Using Dude to Capture Firewall - Connections
Replies: 1
Views: 3892

Using Dude to Capture Firewall - Connections

Is it possible to use the Dude to capture all connections in Firewall > Connections? I have looked at the manual, and it has a syslog; however, the manual seems to lack meaningful or significant instructions. I have installed the server on my RB450Gx4 and the Mac version client so far.
by Nollitik
Tue Dec 17, 2019 11:30 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

I never found RouterOS scripting intuitive, so personally I wouldn't go there. The only scripting I'd do would be making unique file names, so that multiple files could be saved. Then I'd download them and do needed processing elsewhere using other means. That's if I'd choose this way with snapshot...
by Nollitik
Tue Dec 17, 2019 11:01 pm
Forum: General
Topic: MacOS Catalina, iOS, Catalyst, SwiftUI & Wine
Replies: 186
Views: 97289

Re: MacOS Catalina, iOS, Catalyst, SwiftUI & Wine

It would really be cool to have Winbox or Macbox for the MacOS...never understood why Mikrotik hasn't made the leap. I have been using Winbox4Mac for years now...even preferring it over webConfig but that's not the point. Having the app available through the AppStore could bring many more home netwo...
by Nollitik
Tue Dec 17, 2019 9:35 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

You can do: /ip firewall connection print file=connections.txt And if you wrap it in a script run from scheduler that would generate unique file names like connections-2019-12-11-18-23-00.txt, you could use it to keep history. But working with all those files will be probably nightmare. Okay Sob yo...
by Nollitik
Thu Dec 12, 2019 6:59 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

You can do: /ip firewall connection print file=connections.txt And if you wrap it in a script run from scheduler that would generate unique file names like connections-2019-12-11-18-23-00.txt, you could use it to keep history. But working with all those files will be probably nightmare. Okay Sob, t...
by Nollitik
Wed Dec 11, 2019 7:14 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

The action=fasttrack-connection rule makes the connections which match it (which usually means all connections) to be handled the fasttrack way, which effectively means that it prevents most packets from ever reaching any further rules in its chain (forward). Including your rule 9. More than that, ...
by Nollitik
Tue Dec 10, 2019 5:47 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

Okay Sindy, I read the link you provided and tried again with connection-bytes set at 500, still nothing logged to memory for testing when opened new connection. That link doesn't deal with the fasttracking rule which changes a lot, basically it prevents most packets belonging to established connec...
by Nollitik
Mon Dec 09, 2019 11:30 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

The first step is to understand how the firewall rule chains and connection-state attributes work. This post might be helpful. Knowing this, you cannot be surprised that your rule shows only the first packet of each new connection. You can use attributes like connection-bytes to log first few packe...
by Nollitik
Sat Dec 07, 2019 9:33 pm
Forum: Beginner Basics
Topic: Fallen at the first hurdle!
Replies: 9
Views: 2385

Re: Fallen at the first hurdle!

Ok I gave up trying to reconfigure it in the end. I have updated to the latest stable release but not really bothered trying again. Thanks The attitude to success is never given up...so, when you were setting up, did you create a user and password? Are you sure it not your browser preventing you? D...
by Nollitik
Sat Dec 07, 2019 9:11 pm
Forum: Beginner Basics
Topic: Basic IPV6 set up help [SOLVED]
Replies: 26
Views: 8803

Re: Basic IPV6 set up help [SOLVED]

It totally confused me as well; however, may I suggest to always make your router do DNS resolving first then Google such as 192.168.88.1, 8.8.8.8.
by Nollitik
Sat Dec 07, 2019 9:00 pm
Forum: Beginner Basics
Topic: RouterOS suddenly blocked at least one website
Replies: 13
Views: 2595

Re: RouterOS suddenly blocked at least one website

It's great to see another with pfSense and Mikrotik combo network. Usually, a firewall never suddenly blocks websites though.
by Nollitik
Sat Dec 07, 2019 6:49 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

Hmm... no. Quick test says that it's about state of DHCP client (when it starts, stops, requests address, gets it, ...) and similar changes in state of routing protocols like BGP. If you want to log when connections are established, you can add logging for "firewall" topic, choose some pr...
by Nollitik
Fri Dec 06, 2019 10:52 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

I think you should first of all describe the task more precisely. "logging all connections" may mean to just log each connection initiation attempt which is relatively easy, or to log each connection's resulting data volume as it ends, which is much more complex, or to record all connecti...
by Nollitik
Fri Dec 06, 2019 6:20 am
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

According to manual page you linked, "state" means "DHCP Client and routing state messages". Yes that's what I saw and interpreted that to mean client IP:port and destination:port as displayed in IP>Firewall>Connections...am I correct? Would it be better to set up a firewall rul...
by Nollitik
Fri Dec 06, 2019 4:43 am
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

Well I tested by creating a log rule of State and write to memory...nothing happened!
Screen Shot 2019-12-05 at 8.38.26 PM.png
by Nollitik
Fri Dec 06, 2019 3:52 am
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Re: Logging Connections - IP/Firewall/Connections

Well, I was reading here https://wiki.mikrotik.com/wiki/Manual:System/Log and https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Connection_tracking It seems that logging state to disk should achieve what I want, record of all source and destination without all the DNS chatter. Wondered whether prefi...
by Nollitik
Thu Dec 05, 2019 5:56 pm
Forum: General
Topic: Logging Connections - IP/Firewall/Connections (Solved)
Replies: 23
Views: 18543

Logging Connections - IP/Firewall/Connections (Solved)

How to go about logging all connections except the actual DNS request to the Mikrotik...is that possible?
My Mikrotik is the RB450x4 and I added a 32GB SD card.
by Nollitik
Wed Oct 09, 2019 9:23 pm
Forum: General
Topic: Winbox 64bit Version
Replies: 79
Views: 38167

Re: Winbox 64bit Version

Another +1 for a MacBox version of Winbox!
by Nollitik
Wed Oct 09, 2019 6:46 am
Forum: General
Topic: Router's default Address after Custom Configured [SOLVED]
Replies: 2
Views: 1739

Re: Router's default Address after Custom Configured [SOLVED]

Hey. It's DNS flood from outside, perhaps from your ISP. So just disable your DNS "allow-remote-requests" option. If it's already disabled, then relax. Every router in the world drops so many trash you can't imagine. Yes, I know it's harmless traffic; however, I have an edge pfSense box t...
by Nollitik
Sun Oct 06, 2019 9:59 pm
Forum: General
Topic: Router's default Address after Custom Configured [SOLVED]
Replies: 2
Views: 1739

Router's default Address after Custom Configured [SOLVED]

So, the other day my Internet was down and a public IP address was not available from my ISP. The next day the Internet was still down; however, I noticed that I received a private IP address from my ISP that raised a red flag. My configured router's address is 10.0.8.1, yet my ISP was attempting to...
by Nollitik
Sun Sep 01, 2019 6:07 pm
Forum: General
Topic: Can not log into RB750 with WinBox
Replies: 3
Views: 1228

Re: Can not log into RB750 with WinBox

It seems that a firewall rule on the router might be blocking you since you're not connecting from LAN. The solution is to give the change instructions to the customer for them to do it while you watch via teamview.
by Nollitik
Sat Aug 31, 2019 10:17 pm
Forum: General
Topic: Quick Set
Replies: 6
Views: 1962

Re: Quick Set

Please read his reply again. After you have changed something using another menu item (like you did), do NOT look at Quick Set again. Forget that it exists. Quick Set does NOT work correctly anymore after you have made another change. We have asked MikroTIk many times to remove Quick Set after anot...
by Nollitik
Sat Aug 31, 2019 7:18 pm
Forum: General
Topic: Quick Set
Replies: 6
Views: 1962

Re: Quick Set

The secret of Quick Set (well, it's not really a secret) is that you either use it exclusively and forget that anything outside of it exists, or you use it once to create initial config and then forget that Quick Set exists. Seeing wrong addresses in Quick Set is a sign that you made some changes o...
by Nollitik
Sat Aug 31, 2019 7:27 am
Forum: General
Topic: Quick Set
Replies: 6
Views: 1962

Quick Set

Trying to understand why quick set has my guest IP as my local address instead of my personal network 10.0.8.1. Is it because ether5, which is where my guest resides, is the only ether port that's not a slave? Even if I disable ether5, quick set still shows my guest IP address as local network. If I...
by Nollitik
Wed Aug 28, 2019 4:20 am
Forum: General
Topic: Double VPN
Replies: 7
Views: 2905

Re: Double VPN

I think you need to set the IP address that the VPN client comes in as. Then firewall rules will dictate what clients can then reach the next subnet. If I understood the diagram... its not VPN from one site to another... but a wired connection. If that is the case... you have one feed from the firs...
by Nollitik
Tue Aug 27, 2019 7:30 pm
Forum: General
Topic: Double VPN
Replies: 7
Views: 2905

Re: Double VPN

Whenever I see oVPN in a Mikrotik thread... I stop reading. OpenVPN has been crippled in Mikrotik for like 10 years now. Thanks Gotsprings...maybe that why I intuitively wanted to use L3TP/IPsec at the Mikrotik. That's where I am struggling to visualize when the VPN client reaches the Mikrotik, how...
by Nollitik
Mon Aug 26, 2019 6:41 pm
Forum: General
Topic: Double VPN
Replies: 7
Views: 2905

Re: Double VPN

I got the inspiration from guys such as this: https://www.technadu.com/double-vpn/45274/ However, in their case, it's to hide the IP address from one's ISP. Whereas, in my case, it's just because it seems doable and kind of a "James Bond" approach/novelty. Also, in my case, the WAN is a pf...
by Nollitik
Mon Aug 26, 2019 5:27 am
Forum: General
Topic: Double VPN
Replies: 7
Views: 2905

Re: Double VPN

A company's office doesn't have a public IP address. My office does. I have the Far office calling my Office over L2TP. The route between them is 2 points. On each router... I have a route that points to the l2tp route. Encryption engine grabs the traffic before it goes over the tunnel. I vpn to my...
by Nollitik
Sun Aug 25, 2019 11:45 pm
Forum: General
Topic: Double VPN
Replies: 7
Views: 2905

Double VPN

Has anyone used a double VPN? What I mean is there is an edge router and a LAN router. So, road warrior client would VPN to the edge router from the Internet and would traverse to the LAN router where the client would present a key to get to the back office. It's like entering the building (edge rou...
by Nollitik
Fri Aug 23, 2019 7:13 pm
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 2977

Re: New RB450G☓4 Breaks Google and its Services

You need to fix the mask, because it explains your problem, quite a few of Google's networks are in 172.0.0.0/8.
Oh, now wonder...thank you for sharing!
by Nollitik
Fri Aug 23, 2019 7:09 pm
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 2977

Re: New RB450G☓4 Breaks Google and its Services

Okay, I fixed it...all is well!
Screen Shot 2019-08-23 at 11.05.58 AM.png
by Nollitik
Fri Aug 23, 2019 6:51 pm
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 2977

Re: New RB450G☓4 Breaks Google and its Services

Your IP addresses are both assigned to ether2 which is part of the bridge, you probably meant to assign them to bride and ether5, like your dhcp servers. Edit: 172.0.0.0/8 is not a private ip range!!! Don't use it on your LAN. Your configured netmask fucks up routing to any public 172.x.y.z IP. Yes...
by Nollitik
Fri Aug 23, 2019 6:15 pm
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 2977

Re: New RB450G☓4 Breaks Google and its Services

Or just /export hide-sensitive Copy/Past result here. Last night, I switched router back to the old and was able to visit google.com as well as gmail just to confirm. Here is the result from the new RB450x4 [Nolli@MikroTik] > /export hide-sensitive # aug/23/2019 10:09:03 by RouterOS 6.45.3 # softwa...
by Nollitik
Fri Aug 23, 2019 6:19 am
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 2977

Re: New RB450G☓4 Breaks Google and its Services

Try to stretch "breaks" a little, into few sentences maybe... There's lot of ways how something can break, it would be good to understand what exactly is happening here. Try to describe it in a way that someone who doesn't see it can understand. What I am saying is the original RB450G wit...
by Nollitik
Fri Aug 23, 2019 6:06 am
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 2977

Re: New RB450G☓4 Breaks Google and its Services

Posting part of settings is not all that helpful.
/export config hide-sensitive file=yourconfigaug22
What am I doing wrong...see image below!
Screen Shot 2019-08-22 at 10.02.49 PM.png
by Nollitik
Wed Aug 21, 2019 11:25 pm
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 2977

New RB450G☓4 Breaks Google and its Services (Solved)

So, my new RB450Gx4 went into production last night/early this morning and now Google, Google Play, and Gmail breaks...not understanding what's happening. My IP > Settings are the same and exact as the original RB450G that the new router replaced...see the image below. Firewall is default just as th...
by Nollitik
Wed Aug 21, 2019 8:32 am
Forum: General
Topic: RB450G to RB450G☓4 How to Transfer State
Replies: 10
Views: 2437

Re: RB450G to RB450G☓4 How to Transfer State

I can't really say that I understand your disappointment. There's nothing special about cached DNS records, router will get new and fresh ones from upstream resolvers. It does that all the time anyway, when old ones time out. I realized that I shouldn't be disappointed because cache is short-term m...
by Nollitik
Wed Aug 21, 2019 3:54 am
Forum: General
Topic: RB450G to RB450G☓4 How to Transfer State
Replies: 10
Views: 2437

Re: RB450G to RB450G☓4 How to Transfer State

Not really. DNS cache does hold records requested by clients, but how long depends on their TTL. So some will be there for hours or even days, but others only for seconds. Oh and reboot also clears it. Sob, I discovered such a short list it's disappointing...see image below! So, I might as well put...
by Nollitik
Wed Aug 21, 2019 3:05 am
Forum: General
Topic: RB450G to RB450G☓4 How to Transfer State
Replies: 10
Views: 2437

Re: RB450G to RB450G☓4 How to Transfer State

If you're not sure what you're looking for, then just export everything ("/export file=myconfig"), then open resulting file in some text editor and you'll see if what you want is there. Sob, I like this above. I had thought that DNS cache would keep track of the website visited and would ...
by Nollitik
Tue Aug 20, 2019 9:59 pm
Forum: General
Topic: Different IP addresses for Port 2 and Port 5
Replies: 2
Views: 2557

Re: Different IP addresses for Port 2 and Port 5

By doing it the way you did, you orphaned the DHCP server so your laptop did not get an address when you woke it up. You could still have accessed the router by setting a fixed IP inside one of those networks on your laptop. Next time, do not disable the bridge but remove port 5 from it and set you...
by Nollitik
Tue Aug 20, 2019 8:49 pm
Forum: General
Topic: Different IP addresses for Port 2 and Port 5
Replies: 2
Views: 2557

Different IP addresses for Port 2 and Port 5

I would like to have a different IP address on Ethernet 2 from Ethernet 5...so, I disabled the bridge interface and set Ethernet 2 to 10.0.8.0 and Ethernet 5 to 172.17.9.0 then put the laptop to sleep before going to bed. This morning I could not access the router...even resetting by depressing the ...
by Nollitik
Tue Aug 20, 2019 8:04 pm
Forum: General
Topic: RB450G to RB450G☓4 How to Transfer State
Replies: 10
Views: 2437

Re: RB450G to RB450G☓4 How to Transfer State

Maybe you use wrong description? Original post sounded like you want to transfer running state of router. I guess you probably don't want that, it's hard to believe that you kept the original running without reboot for ten years. If what you actually want to transfer is config, e.g. address list, j...
by Nollitik
Tue Aug 20, 2019 5:03 pm
Forum: General
Topic: RB450G to RB450G☓4 How to Transfer State
Replies: 10
Views: 2437

Re: RB450G to RB450G☓4 How to Transfer State

... would like to transfer my DNS cache of my establish, related IP state to the new router. The old router I had kept the default IP address (192.168.88.1); however, on the new router, the address and range is 10.0.8.2-10.0.8.254 with router on 10.0.8.1. You can't. Connection tracking states are m...
by Nollitik
Tue Aug 20, 2019 6:07 am
Forum: General
Topic: RB450G to RB450G☓4 How to Transfer State
Replies: 10
Views: 2437

RB450G to RB450G☓4 How to Transfer State

Well, I am a proud owner of a new RB450G☓4 (arrived today) and would like to transfer my DNS cache of my establish, related IP state to the new router. The old router I had kept the default IP address (192.168.88.1); however, on the new router, the address and range is 10.0.8.2-10.0.8.254 with route...
by Nollitik
Mon Apr 23, 2018 4:07 am
Forum: General
Topic: address-list-timeout=2w...What's the 2w?
Replies: 21
Views: 3771

Re: address-list-timeout=2w...What's the 2w?

Sindy, this is what you really wanted...had to use web browser instead of Winbox. However, I just saw that the thread is turning into awesome...have to read all new responses. /ip firewall filter add action=add-src-to-address-list address-list="Port Scanners" address-list-timeout=none-stat...
by Nollitik
Sat Apr 21, 2018 9:55 pm
Forum: General
Topic: address-list-timeout=2w...What's the 2w?
Replies: 21
Views: 3771

Re: address-list-timeout=2w...What's the 2w?

Here's the screen shot you requested. I didn't :-D What I actually wanted was a copy-paste of the text output (select the text, right-click on it, left-click on "copy" in the drop-down menu, then Ctrl-V here), not a picture. You cannot use Ctrl-F for strings in a picture, you cannot rearr...
by Nollitik
Fri Apr 20, 2018 6:18 am
Forum: General
Topic: address-list-timeout=2w...What's the 2w?
Replies: 21
Views: 3771

Re: address-list-timeout=2w...What's the 2w?

I am dropping traffic, yet nothing is been added to the address list...see screen shot, what's up? Your picture shows you are adding only source addresses of TCP packets to the list, but dropping everything. So other than TCP packets are just dropped, their addresses are not added to the list. Pres...
by Nollitik
Thu Apr 19, 2018 5:25 am
Forum: General
Topic: address-list-timeout=2w...What's the 2w?
Replies: 21
Views: 3771

Re: address-list-timeout=2w...What's the 2w?

I am dropping traffic, yet nothing is been added to the address list...see screen shot, what's up?
by Nollitik
Thu Apr 19, 2018 1:47 am
Forum: General
Topic: address-list-timeout=2w...What's the 2w?
Replies: 21
Views: 3771

Re: address-list-timeout=2w...What's the 2w?

2w = two weeks
Thanks Pe1ch1...wasn't expecting such a long time...I now take that to mean the time the source list shall exist. So, does dynamic therefore means that the list would roll over to the next two weeks period?
by Nollitik
Thu Apr 19, 2018 12:13 am
Forum: General
Topic: address-list-timeout=2w...What's the 2w?
Replies: 21
Views: 3771

address-list-timeout=2w...What's the 2w?

I am creating a drop port scanners per https://wiki.mikrotik.com/wiki/Drop_port_scanners and wanted to find out what the 2w means in address-list-timeout=2w. The only option offered is none dynamic or none static...see screen shot.
by Nollitik
Wed Apr 18, 2018 11:04 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082243

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

This is awesome...if only I could get this on a RB450G...is there? Should work fine with RB450G. Just need to stream the packet sniffer to the suricata box and follow the installation instructions. So, are you saying one has to have a separate Suricata box for this to work? The RB450G only has 512M...
by Nollitik
Tue Apr 17, 2018 6:57 am
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082243

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

This is awesome...if only I could get this on a RB450G...is there?
by Nollitik
Mon Apr 16, 2018 10:09 pm
Forum: General
Topic: DHCP Server: Assign - Deassign
Replies: 10
Views: 3918

Re: DHCP Server: Assign - Deassign

Found it...it was on the general tab, and I was trying to edit the lease time on the active tab.
by Nollitik
Sun Apr 15, 2018 5:25 am
Forum: General
Topic: DHCP Server: Assign - Deassign
Replies: 10
Views: 3918

Re: DHCP Server: Assign - Deassign

I have been watching the server and discovered it's setting short leases of approximately 7mins. That seems like a bug. How to set leases to a greater period like 7days? The only other choice is to make static. Looking at the screen shot I realize that particular device was sleeping, while DHCP cont...
by Nollitik
Sun Apr 15, 2018 4:44 am
Forum: General
Topic: DHCP Server: Assign - Deassign
Replies: 10
Views: 3918

Re: DHCP Server: Assign - Deassign

Best will be to sniff the network and analyse the packets with something like wireshark to see what is happening, problem might be caused by client side
Not sure I am following...is not the client side I believe...I want to say a bug! I have wireshark installed...will try having a look.
by Nollitik
Sun Apr 15, 2018 2:52 am
Forum: General
Topic: DHCP Server: Assign - Deassign
Replies: 10
Views: 3918

DHCP Server: Assign - Deassign

Curious as to why DHCP server seems to assign then, moments later deassign...see screen shot.
by Nollitik
Mon Aug 10, 2015 11:39 pm
Forum: General
Topic: Static DHCP for Hikvision IP Cameras
Replies: 6
Views: 3978

Re: Static DHCP for Hikvision IP Cameras

Where are you entering the address...it can only be on the camera and can't be DHCP server! I used the same setup...RB450G that connects Hikvisions IP box cameras with static IP address of my network 10.0.8.0 and a camera has 10.0.8.171. This is what I ended up doing. I've never had a problem assig...
by Nollitik
Sat Aug 08, 2015 10:09 pm
Forum: General
Topic: how to set total amount of data per mac address
Replies: 3
Views: 1190

Re: how to set total amount of data per mac address

Not really sure what you're asking...why limit data? Does he has broadband issues...if so get a bigger Internet package from his ISP like 100Mb per second or more! The kid will, eventually, figured out how to change the Mac address too thanks to Google.
by Nollitik
Sat Aug 08, 2015 9:50 pm
Forum: General
Topic: Static DHCP for Hikvision IP Cameras
Replies: 6
Views: 3978

Re: Static DHCP for Hikvision IP Cameras

Where are you entering the address...it can only be on the camera and can't be DHCP server! I used the same setup...RB450G that connects Hikvisions IP box cameras with static IP address of my network 10.0.8.0 and a camera has 10.0.8.171.
by Nollitik
Tue Aug 04, 2015 10:09 pm
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

Okay, that makes more sense now. Two things though.. 1) Netinstall uses Ethernet, not serial. 2) Netinstall doesn't like virtual machines. I've never had any luck with getting it working in VMware Fusion either. I ended up keeping an old macbook running Windows XP for these type of situations. I tr...
by Nollitik
Mon Aug 03, 2015 8:44 pm
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

Thanks for responding, IntrusDave. To be clear this was not my first time configuring my RB450G with no default configuration...I have had the router over six years; however, it my first time needing to reformat the nand disk. When I say Mikrotik should make available a RS-232 driver, I mean have a ...
by Nollitik
Mon Aug 03, 2015 6:08 am
Forum: General
Topic: MIKROTIK RB450G only one beep.
Replies: 2
Views: 2761

Re: MIKROTIK RB450G only one beep.

Put some screwdriver (or anything metal) into the hole, apply power and wait until it boots. You will need to open the router...see video.
https://www.youtube.com/watch?v=G-iIxxXcYq0
by Nollitik
Mon Aug 03, 2015 5:50 am
Forum: General
Topic: Mikrotik Firewall/Routing Issues with a somewhat complex setup
Replies: 4
Views: 1718

Re: Mikrotik Firewall/Routing Issues with a somewhat complex setup

Thanks for sharing those firewall rules...not sure I understand them though. I made note of them. Firewall rule (e) chain: input > action: drop...that's normal...you should get lots of "hits." Do you have the Asus in bridge mode? I had a setup where a Mikrotik RB450G is my master router to...
by Nollitik
Sun Aug 02, 2015 7:01 pm
Forum: General
Topic: Please gie advice (network configuration for vpn)
Replies: 4
Views: 1274

Re: Please gie advice (network configuration for vpn)

Hi,
thanks, but i don't see how this is a solution to my situation.
Follow the site to site instructions here: http://wiki.mikrotik.com/wiki/Manual:IP/IPsec
Except for the IP address, this picture seems to be what you described!
Screen Shot 2015-08-02 at 10.58.16 AM.png
by Nollitik
Sun Aug 02, 2015 7:16 am
Forum: General
Topic: Net install in a windows Virtual machine
Replies: 5
Views: 2475

Re: Net install in a windows Virtual machine

Did you used a USB-Serial adapter and if so, what, where did you get the drivers?
by Nollitik
Sun Aug 02, 2015 1:39 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

Having to reformat the router turned out to be a waste of valuable time...the amount of hours (if calculated at minimum U.S. wage) I have put into diagnosis and attempting to reformat, I could have bought another router. Of course, if it weren't for the sake of learning, I wouldn't have tried. The g...
by Nollitik
Sun Aug 02, 2015 12:14 am
Forum: General
Topic: Mikrotik Firewall/Routing Issues with a somewhat complex setup
Replies: 4
Views: 1718

Re: Mikrotik Firewall/Routing Issues with a somewhat complex setup

The more complex a configuration and the longer one had that configuration with periodic upgrades is the more chances that a mishap can lead to having to reformat the router. I am dealing with that right now, and the amount of hours at minimum wage I have put into diagnosis I could have bought anoth...
by Nollitik
Wed Jul 29, 2015 3:58 pm
Forum: General
Topic: L2TP/IPSEC on android and ios.
Replies: 4
Views: 2400

Re: L2TP/IPSEC on android and ios.

Hi! Im having issues connecting to L2TP/IPSEC server hosted on rb750gl ROS version .. i tried 6.0. Rc14/ 6.24 and 6.30.2. I can connect to it fine with windows PC, but when i try to connect from android or ios device ... no connection is happening. MT router is behind WatchGuard and it have public ...
by Nollitik
Wed Jul 29, 2015 4:49 am
Forum: General
Topic: Net install in a windows Virtual machine
Replies: 5
Views: 2475

Re: Net install in a windows Virtual machine

So, did you get it to work? I am a Mac user and am in a situation where I'll need to do a clean install of RouterOS...I didn't plan on using Windows 7 on my Mac via Parallels because of the virtual environment is unreliable. I had that same issue - I was able to trace it back to unreliable unzip me...
by Nollitik
Tue Jul 28, 2015 5:05 pm
Forum: General
Topic: Sorry for my off topic!
Replies: 1
Views: 645

Re: Sorry for my off topic!

Don't crawl...dash swiftly to Facebook...hurry...run!
by Nollitik
Tue Jul 28, 2015 4:58 pm
Forum: General
Topic: Net install in a windows Virtual machine
Replies: 5
Views: 2475

Re: Net install in a windows Virtual machine

So, did you get it to work? I am a Mac user and am in a situation where I'll need to do a clean install of RouterOS...I didn't plan on using Windows 7 on my Mac via Parallels because of the virtual environment is unreliable.
by Nollitik
Tue Jul 28, 2015 6:53 am
Forum: General
Topic: ONVIF Camera behind MKT, Can't make the NAT work...
Replies: 6
Views: 4255

Re: ONVIF Camera behind MKT, Can't make the NAT work...

Glad you found a "pretty easy solution" eventually you'll find VPN a pretty easy solution as well.
by Nollitik
Tue Jul 28, 2015 5:58 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

Hi, did you already try to netinstall your device? The file system may be corrupted. If this strange behavior continues after netinstall, I would say the device is a candidate for RMA. Ape Thank you, Ape for responding. No, I haven't yet...I am waiting on support finding after they examine the supo...
by Nollitik
Tue Jul 28, 2015 5:45 am
Forum: General
Topic: Syslog Server
Replies: 3
Views: 1569

Re: Syslog Server

A linux system.
If it should be low energy and low cost, a raspberry pi can do the job.

Ape
+1...here's a link with how to instruction: http://resources.intenseschool.com/rasp ... og-server/
by Nollitik
Mon Jul 27, 2015 6:08 pm
Forum: General
Topic: ONVIF Camera behind MKT, Can't make the NAT work...
Replies: 6
Views: 4255

Re: ONVIF Camera behind MKT, Can't make the NAT work...

I have HD IP cameras (Hikvision) behind a Mikrotik 450G natted. I can attest to the best solution is VPN. Yes, it's a steep learning curve...why not though...afraid of learning? No worrying about your Internet upload speed or bandwidth to stream HD videos, you'll have. I had no foundation in network...
by Nollitik
Mon Jul 27, 2015 4:57 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

The router is behaving strangle and really weird. Instead of resetting the router with no default configuration, I decided to keep the default config so I would have three separate networks. The default works without a hitch; however, as soon as I add my former networks, identity, and a user with pa...
by Nollitik
Sun Jul 26, 2015 6:06 am
Forum: General
Topic: IPsec VPN - Road Warrior setup with Mode Conf
Replies: 2
Views: 2416

Re: IPsec VPN - Road Warrior setup with Mode Conf

I noticed you didn't allow IPsec in firewall: /ip firewall filter add chain=input comment=established,related connection-state=\ established,related in-interface=WAN add chain=input comment=ESP disabled=yes in-interface=WAN protocol=ipsec-esp add chain=input comment="UDP 500,4500" disabled...
by Nollitik
Sat Jul 25, 2015 6:10 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

So, here the weird part...I reset the router under 6.30.2 and got the default setting (192.168.88.1) then exhausted from monkeying with the router, I decided to watch a movie. I connected my Apple Extreme to which all Apple devices connect including the AppleTV to it's usual Ether2 port on the Mikro...
by Nollitik
Sat Jul 25, 2015 4:49 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

Well, I figured out if I get kicked out of Winbox after resetting with no default configuration I need to restart the computer...very awkward indeed. As soon as I connect to the router using the Mac address then go to input setting, I am kicked out, and when I launch Winbox (winbox4mac) again, I ge...
by Nollitik
Sat Jul 25, 2015 3:29 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

Well, I figured out if I get kicked out of Winbox after resetting with no default configuration I need to restart the computer...very awkward indeed.
by Nollitik
Fri Jul 24, 2015 11:13 pm
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

So, I enabled the Winbox interface in Mac Server for ether1, removed default configuration, and got out my USB serial cable...it's a male. :shock: It's the first time I ever used it...had the wildest laugh. Found the right cable, found out that the Mac Server is only to connect two Mikrotik routers.
by Nollitik
Fri Jul 24, 2015 9:25 pm
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

So, I enabled the Winbox interface in Mac Server for ether1, removed default configuration, and got out my USB serial cable...it's a male. :shock:
It's the first time I ever used it...had the wildest laugh.
by Nollitik
Fri Jul 24, 2015 8:23 pm
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

This is becoming a nightmare...when I reset the router, connect and delete default configuration, I am unable to get back into router. I keep getting error connecting to Mac address. Winbox seems unresponsive...I am using Winbox4mac. I really would like to restore from my backup; however, after com...
by Nollitik
Fri Jul 24, 2015 6:57 pm
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

This is becoming a nightmare...when I reset the router, connect and delete default configuration, I am unable to get back into router. I keep getting error connecting to Mac address. Winbox seems unresponsive...I am using Winbox4mac. I really would like to restore from my backup; however, after comp...
by Nollitik
Fri Jul 24, 2015 7:23 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

it may be better to connect to the WAN port, that way you are not modifying the ports that you are working with.
Good idea...if I have no default configuration, there is no firewall on ether1. I will try that in the morning...thanks for sharing.
by Nollitik
Fri Jul 24, 2015 7:04 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Re: Connecting to Router with No Default Configuration

Click on the "Neighbors" tab, next to the "Managed". It will scan for Mikrotik devices. Thanks IntrusDave for responding. Yes, I did that and logged in with the Mac address; however, as soon as I make a change, such as assigning ether2 as master port, I am automatically shut out...
by Nollitik
Fri Jul 24, 2015 6:12 am
Forum: General
Topic: Connecting to Router with No Default Configuration
Replies: 23
Views: 9429

Connecting to Router with No Default Configuration

How to connect to the router if one issue a reset with no default configuration? Winbox 3 rc12 doesn't have the scan button for the Mac address anymore. Using neighbors, I can see the Mac address...wondering whether that will enable access.
by Nollitik
Wed Jul 22, 2015 6:48 am
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 12086

Re: Creating a Single Blacklist of Multiple IP

I m interested by your automatic blacklist script, would you mind sharing ? What kind of mikrotik do you have to handle that much firewall entry? Thanks a lot My blacklists are currently private, but I have been working on a system to allow them to be downloaded by others. I'll see if I can finish ...
by Nollitik
Tue Jul 21, 2015 7:10 pm
Forum: General
Topic: Need help with router selection
Replies: 4
Views: 924

Re: Need help with router selection

Yes, Mikrotik RB951G-2HnD should work with two gigabit switch each having twenty-four ports; however, I would go with a RB450G (256 vs 128 RAM and has a microSD slot) with the above switches and a wireless access point (my setup for a home office...older RB450G with no microSD). Still, as Jarda said...
by Nollitik
Tue Jul 21, 2015 6:48 pm
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 12086

Re: Creating a Single Blacklist of Multiple IP

karlisi is correct. In the IP->Firewall->Address Lists, you have a single entry per line. I have over 6000 entries in my address lists. I have a server that generates a blacklist every night, and each morning all of the Mikrotik routers that I manage download that list. Wow! Do you add addresses fr...
by Nollitik
Tue Jul 21, 2015 6:43 pm
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 12086

Re: Creating a Single Blacklist of Multiple IP

AFAIK this is not possible, address lists are made from separate entries for each address. This form is more manageable as one entry with multiple values.
Okay, thanks!
by Nollitik
Tue Jul 21, 2015 7:12 am
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 12086

Re: Creating a Single Blacklist of Multiple IP

Still face the same issue...in the sense that it's transferred to the Firewall > address list instead. What I want to do is this: /IP firewall address list add address xxx.xxx.xx1, xx.x.xxx.x2, xx.xx.x.xx3, etc., list = Blacklist, so that one has one entry rather than a new entry for each single IP ...
by Nollitik
Mon Jul 20, 2015 6:34 pm
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 12086

Re: Creating a Single Blacklist of Multiple IP

Your firewall rule uses address-list, there is no need for more rules. In Blacklist address list you will put all addresses to be blocked by this rule. Like this /ip firewall filter add action=drop chain=input comment="drop blacklisted addresses" \ src-address-list=Blacklist disabled=no /...
by Nollitik
Sun Jul 19, 2015 1:03 am
Forum: General
Topic: Creating a Single Blacklist of Multiple IP
Replies: 19
Views: 12086

Creating a Single Blacklist of Multiple IP

I want to create an address-list named Blacklist of IP address that made an attempt to access router from WAN. So, it would like this: Input chain > In interface: Ether1 > Scr. address-list: Blacklist > Action:reject The problem is I would actually like to add a list of IP addresses to this address-...
by Nollitik
Tue Jul 14, 2015 6:22 pm
Forum: General
Topic: 6.30 ipsec-policy matcher question
Replies: 12
Views: 3079

Re: 6.30 ipsec-policy matcher question

I could also do with some extra assistance / documentation on using this feature, it looks useful! I agree and would like further explanation...for instance, advantage of ipsec-policy >in/none VS ipsec-policy >in/ipsec although, intuitively, ipsec-policy >in/none seems to have an edge since it chec...
by Nollitik
Mon Jul 13, 2015 4:32 am
Forum: General
Topic: My Mikrotik RB450 Can't Manage PPPoE User's Bandwidth. Can Anyone Solve The Issue?
Replies: 3
Views: 1296

Re: My Mikrotik RB450 Can't Manage PPPoE User's Bandwidth. Can Anyone Solve The Issue?

Just a suggestion to not display confidential info (IP address) next time.
by Nollitik
Sat Jul 11, 2015 8:27 pm
Forum: General
Topic: 6.30 ipsec-policy matcher question
Replies: 12
Views: 3079

Re: 6.30 ipsec-policy matcher question

I also would like to be sure I understand IPsec-policy match...so if I have a firewall rule as: input chain > advanced >IPsec-policy: in/none >Protocol: 50 (ipsec-ESP) >Action: Accept Then that would place restrictions and add security enhancement through policy matching? I want to learn as much as...
by Nollitik
Sat Jul 11, 2015 4:53 am
Forum: General
Topic: 6.30 ipsec-policy matcher question
Replies: 12
Views: 3079

Re: 6.30 ipsec-policy matcher question

I also would like to be sure I understand IPsec-policy match...so if I have a firewall rule as: input chain > advanced >IPsec-policy: in/none >Protocol: 50 (ipsec-ESP) >Action: Accept Then that would place restrictions and add security enhancement through policy matching? I want to learn as much as ...
by Nollitik
Thu Jul 09, 2015 9:32 pm
Forum: General
Topic: winbox change font/text size?
Replies: 2
Views: 2188

Re: winbox change font/text size?

Is there a way to change either the font or text size used by winbox?

Thanks.

Colin
+1
by Nollitik
Thu Jul 09, 2015 7:22 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

under IPSEC peer 0.0.0.0/0 try changing under generate policy to "port override" as this has resolved issues for me in the past. Actually, Fallenwrx, that's exactly what worked with passive unchecked...thanks for sharing. Maybe Mikrotik should allow the option to select generate IPsec-pee...
by Nollitik
Thu Jul 09, 2015 6:09 am
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!

Thanks to Mikrotik support for resolving my VPN issue. It turned out to be the dynamic generated peer where the problem resided. So, if I reboot the router, I would need to delete the dynamic generated peer for the manually created peer to take effect. My hope is that Mikrotik gives one the option i...
by Nollitik
Sun Jul 05, 2015 10:33 pm
Forum: General
Topic: Please gie advice (network configuration for vpn)
Replies: 4
Views: 1274

Re: Please gie advice (network configuration for vpn)

Hi! Please give advice to me how is the best to setup this vpn. I have two offices (LAN: 10.1.0.0/24 and 10.8.0.0/24) both with mikrotik router to Internet, and one Mikrotik router with static IP address (name it VPN server). The offices connects with L2TP VPN to the VPN Server. What i need to conf...
by Nollitik
Sat Jul 04, 2015 11:12 pm
Forum: General
Topic: PPTP Not authenticating from some MS Windows clients
Replies: 1
Views: 727

Re: PPTP Not authenticating from some MS Windows clients

Hi, First post :) I am having problems on some workstations connecting to a CCR1016-12G running OS version v6.29.1. When I debug, it is stopping on the auth of the user and keeps repeating in the log below until a timeout : <81>: LCP Timer <81>: sent LCP ConfReq id=0x5 <mru 1460> <magic 0x4a49c93b>...
by Nollitik
Tue Jun 30, 2015 5:02 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: [Solved] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!

I would never have guess that having special characters in password would jam up my VPN...wow...thanks Mikrotik support and a special thank you to MrZ.
Sorry that was a false alarm...problem still has not resolved. :(
by Nollitik
Mon Jun 29, 2015 3:40 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: [Solved] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!

I would never have guess that having special characters in password would jam up my VPN...wow...thanks Mikrotik support and a special thank you to MrZ.
by Nollitik
Fri Jun 19, 2015 7:34 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

Doing some research today seems to leading me to a conclusion that my robust firewall might be having issues with L2TP and port 500. It seems that a common problem and thus the main weakness of L2TP. Since IPsec establishes successfully and L2TP establishes both send as well as receive communicatio...
by Nollitik
Fri Jun 19, 2015 4:30 am
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

I had/have similar issue, described here . Only workaround I find is that you need to add always manually the outgoing policy. (which is very inconvenient in case of roadwarriors) I was also in contact with Mikrotik support (ticket number is Ticket#2015061266000262), where they stated in case both ...
by Nollitik
Fri Jun 19, 2015 4:24 am
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

Per Mikrotik support, I disabled all drop rules and that doesn't resolve the L2TP authentication process thus making connection possible, despite IPsec successfully connects. Sent another supout file.
by Nollitik
Wed Jun 17, 2015 11:19 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

Doing some research today seems to leading me to a conclusion that my robust firewall might be having issues with L2TP and port 500. It seems that a common problem and thus the main weakness of L2TP. Since IPsec establishes successfully and L2TP establishes both send as well as receive communication...
by Nollitik
Wed Jun 17, 2015 10:28 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

What ticket number?
[Ticket#2015061066000766] VPN Analysis and Recommendation
by Nollitik
Wed Jun 17, 2015 10:13 pm
Forum: General
Topic: L2TP working in LAN not working from Office
Replies: 1
Views: 837

Re: L2TP working in LAN not working from Office

Hello together, since a few days I own a static public IP-Address and so I tried to configure a VPN with my RouterBoard RB2011UiAS-2HnD. I've watched several youtube videos but I can't get the l2tp/IPSec VPN to work from external. My RB ist natted. Firewall Rules (Input, Accept - UDP dst-port 500, ...
by Nollitik
Wed Jun 17, 2015 9:52 pm
Forum: General
Topic: every ether port than none
Replies: 1
Views: 749

Re: every ether port than none

Hallo.
I have Mikrotik RB751. I have to configuration router, every ether port in mikrotik has to than master port: none. How do I configuration address and route table ?
Not sure what you want to do however I think this video might help you...good luck!
https://www.youtube.com/watch?v=ulDefmf1ces
by Nollitik
Wed Jun 17, 2015 6:49 am
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

under IPSEC peer 0.0.0.0/0 try changing under generate policy to "port override" as this has resolved issues for me in the past. Thanks Fallenwrx for responding. I am using RouterOS 6.29 and when one selects IPsec in the L2TP server, it auto generates an IPsec Peer with a policy to "...
by Nollitik
Wed Jun 17, 2015 6:41 am
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

Enable ipsec debug logs in /system logging menu. Try to connect and post the log output here. Thanks for responding and awaiting my follow MrZ. My log is very long (both L2TP and IPsec)...would take too much time to redact confidential info. Could I just send the supout file to Mikrotik support...I...
by Nollitik
Mon Jun 15, 2015 6:05 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

Since I can connect to my VPN from my guess network at home...connection from the coffee failed, to trouble shoot most would say check firewall. However, from the coffee shop, L2TP is sending and receiving control messages with the client...therefore that would imply going through the firewall, does...
by Nollitik
Sat Jun 13, 2015 8:08 pm
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

Re: Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream?

Can you please confirm that this is using mobile networks eg 3G/4G as i know in NZ we have to change our APN settings on mobile devices to allow VPN traffic through.
No, the client is using either iOS devices or Android devices over WIFI.
by Nollitik
Sat Jun 13, 2015 7:55 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

So, I am still having policy issue with my VPN and reading this doesn't seem to be CLEAR: http://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Policy...talk about frustrating..."Mode Conf, policy group and policy templates will allow us to overcome these problems." However, there is no clear cut...
by Nollitik
Sat Jun 13, 2015 4:59 am
Forum: General
Topic: [Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!
Replies: 21
Views: 9047

[Solved...finally] Is Mikrotik's Road Warrior L2TP/IPsec a Pipe Dream? No!

This road warrior L2TP/IPsec is so, so FRUSTRATING, it seems that it could make one jump over the cliff. No matter how much improvements, it just seem to follow a golden rule: the more things change, the more they remain the same. The problem I have is the L2TP server never gets to the authenticatio...
by Nollitik
Fri Jun 12, 2015 6:30 am
Forum: General
Topic: IPSec
Replies: 11
Views: 3786

Re: IPSec

Please look at the site to site section here: http://wiki.mikrotik.com/wiki/Manual:IP/IPsec

[admin@MikroTik] /ip ipsec proposal> print
Flags: X - disabled
0 name="default" auth-algorithms=sha1 enc-algorithms=3des lifetime=30m pfs-group=modp1024
by Nollitik
Thu Jun 11, 2015 9:05 pm
Forum: General
Topic: IPSec
Replies: 11
Views: 3786

Re: IPSec

Looks like you're having problems completing IPsec phase 1 so it can't go on to phase 2. I take it you're doing a site to site.
by Nollitik
Wed Jun 10, 2015 11:03 pm
Forum: General
Topic: L2TP/IPSec VPN access for Mac OS X 10.5 client
Replies: 8
Views: 22129

Re: L2TP/IPSec VPN access for Mac OS X 10.5 client

Bump :D - Any ideas on either setting up the VPN or why I cannot get any debug-level logging to try and troubleshoot myself? I'd just like to get some visibility as to what's going on and why it's failing. Thanks! If you go to System >Logging, then add to memory L2TP and IPsec...please see screen s...
by Nollitik
Wed Jun 10, 2015 10:41 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

So, I am still having policy issue with my VPN and reading this doesn't seem to be CLEAR: http://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Policy...talk about frustrating..."Mode Conf, policy group and policy templates will allow us to overcome these problems." However, there is no clear cut...
by Nollitik
Wed Jun 10, 2015 10:32 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

So, I am still having policy issue with my VPN ..... If you consider using OpenVPN using MikroTik as server instead, I can offer you a detailed step-by-step instruction. Note that Microsoft, a member of the consortium behind the development of PPTP, specifically recommends against its use. As for L...
by Nollitik
Tue Jun 09, 2015 5:48 pm
Forum: General
Topic: after upgrading RB450G 5.25 to 6.29
Replies: 1
Views: 1706

Re: after upgrading RB450G 5.25 to 6.29

after upgrading to 6.29 while formatting 16g sd card ex3 at 45% card disappear. now no sd card in in disk . and also winbox not loading previous session e.g after close winbox all open windows closed in next winbox login. routerboard: yes model: 450G serial-number: 279601723555 current-firmware: 3....
by Nollitik
Tue Jun 09, 2015 1:07 am
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

So, I am still having policy issue with my VPN and reading this doesn't seem to be CLEAR: http://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Policy...talk about frustrating..."Mode Conf, policy group and policy templates will allow us to overcome these problems." However, there is no clear cut ...
by Nollitik
Fri Jun 05, 2015 3:42 am
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

What I need is a clear, no nonsense instruction on setting up a VPN for folks who have an office at home and that wants to connect from anywhere in the world where the IP address is unknown. I have been wanting to have this done two years now and have been grossly disappointed with Mikrotik support...
by Nollitik
Wed Jun 03, 2015 6:03 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

What I need is a clear, no nonsense instruction on setting up a VPN for folks who have an office at home and that wants to connect from anywhere in the world where the IP address is unknown. I have been wanting to have this done two years now and have been grossly disappointed with Mikrotik support...
by Nollitik
Wed Jun 03, 2015 5:45 pm
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

What I need is a clear, no nonsense instruction on setting up a VPN for folks who have an office at home and that wants to connect from anywhere in the world where the IP address is unknown. Hello I followed this You tube guide - https://www.youtube.com/watch?v=cgfXs6ZJrgs Additions and Blog on my ...
by Nollitik
Tue Jun 02, 2015 4:08 am
Forum: General
Topic: Apple Tv problem!
Replies: 27
Views: 10502

Re: Apple Tv problem!

If understand correctly, you're trying to stream via airplay from an IOS device to your AppleTV...namely YouTube content...is there any reason you can't get the YouTube content directly from your AppleTV? No, I am trying to stream m4v file via iTunes HomeSharing using Gigabit LAN. And it freezing. ...
by Nollitik
Tue Jun 02, 2015 3:47 am
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

What I need is a clear, no nonsense instruction on setting up a VPN for folks who have an office at home and that wants to connect from anywhere in the world where the IP address is unknown. I have been wanting to have this done two years now and have been grossly disappointed with Mikrotik support....
by Nollitik
Mon Jun 01, 2015 8:07 am
Forum: General
Topic: Need new app for Apple Tiktool is gone and crashes!
Replies: 4
Views: 1742

Re: Need new app for Apple Tiktool is gone and crashes!

I have made a request to have the final version of Winbox available in the app store...lets make more quality noise so it can happen.
by Nollitik
Mon Jun 01, 2015 1:36 am
Forum: General
Topic: Apple Tv problem!
Replies: 27
Views: 10502

Re: Apple Tv problem!

If understand correctly, you're trying to stream via airplay from an IOS device to your AppleTV...namely YouTube content...is there any reason you can't get the YouTube content directly from your AppleTV?
by Nollitik
Fri May 29, 2015 8:15 am
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

For VPN, there is no explanation of what policy override and policy strict means... From the manual: no - do not generate policies port-override -- generate policies and force policy to use any port (old behavior) port-strict -- use ports from peer's proposal, which should match peer's policy Okay,...
by Nollitik
Fri May 29, 2015 7:39 am
Forum: Announcements
Topic: v6.29 released
Replies: 191
Views: 76711

Re: v6.29 released

Upgraded today on 450G...all is good so far!
by Nollitik
Fri May 29, 2015 7:12 am
Forum: General
Topic: Winbox 3 RC
Replies: 636
Views: 208495

Re: Winbox 3 RC

Make the log a rich text file that can be easily exported for further analysis if one needs.
by Nollitik
Thu May 28, 2015 11:13 am
Forum: Announcements
Topic: Manual Improvements
Replies: 94
Views: 31611

Re: Manual Improvements

The twenty-first century calls for graphic illustration of how to. For VPN, there is no explanation of what policy override and policy strict means...no wonder folks have difficulty setting up VPN. Don't kill an excellent router useability by providing inadequate graphic depiction of how to use.
by Nollitik
Thu May 28, 2015 11:01 am
Forum: General
Topic: Mangle - how to do right?
Replies: 52
Views: 21833

Re: Mangle - how to do right?

Awesome discussion...thanks for sharing
by Nollitik
Tue May 19, 2015 12:03 am
Forum: General
Topic: Apple Tv problem!
Replies: 27
Views: 10502

Re: Apple Tv problem!

Not sure what problems folks are having. I have the RB450G that connects two Apple TV's...Apple TV1 and Apple TV3 via a gigabit switch and cat7 Ethernet cables for two years...streaming Netflix, never a problem.
by Nollitik
Sun Feb 22, 2015 2:50 pm
Forum: General
Topic: Block Pinging from outside - ICMP Rule
Replies: 5
Views: 12810

Re: Block Pinging from outside - ICMP Rule

Boen_robot, I was really wondering with my connection state how could some unauthorized party gain entry twice at least. Their algorithm didn't match and hence timed out. That's why I had concluded pinging and port sniffing. It really disturbed me so much that I just turned off rule 3 & 4 (VPN)....
by Nollitik
Sat Feb 21, 2015 8:00 pm
Forum: General
Topic: Block Pinging from outside - ICMP Rule
Replies: 5
Views: 12810

Re: Block Pinging from outside - ICMP Rule

Thank you Boen_robot for responding. Here are my rules (see screen shot)...would you suggest putting your first one at zero? Also, I use interface 5 as my guess network that is separate from my home network. I also use the guess network to test VPN on my network...would your second rule interferes? ...
by Nollitik
Sat Feb 21, 2015 4:22 pm
Forum: General
Topic: Block Pinging from outside - ICMP Rule
Replies: 5
Views: 12810

Block Pinging from outside - ICMP Rule

Well, since me setup VPN (still not working) I discovered non-authorized parties have been trying to access the open port. I would like to setup an ICMP rule however, reading the manual just seems confusing. I figured, if I am correct, that it would be on the input chain, and the connection state wo...
by Nollitik
Sun Jan 04, 2015 2:39 am
Forum: General
Topic: An Official Winbox for Macs
Replies: 3
Views: 2572

Re: An Official Winbox for Macs

I would like to see an official Winbox available via Apple's App Store...that way I don't need to run Apps that the developer has not registered or identified with Apple. Will the official release accomplish this? Wishful Thinking.. :) You are preaching to the crowd... I guess at this point, a beta...
by Nollitik
Sat Jan 03, 2015 4:05 pm
Forum: General
Topic: VPN - L2TP/IPSEC
Replies: 5
Views: 2069

Re: VPN - L2TP/IPSEC

My Droid connects using the standard settings. The only problem I have is that I need to add an input rule to the firewall to allow the IP address I get from my carrier since my last input rule is block anything not specified to pass. I don't know a way around this. Wondered if a rule that accepts ...
by Nollitik
Sat Jan 03, 2015 3:48 pm
Forum: General
Topic: An Official Winbox for Macs
Replies: 3
Views: 2572

An Official Winbox for Macs

I would like to see an official Winbox available via Apple's App Store...that way I don't need to run Apps that the developer has not registered or identified with Apple. Will the official release accomplish this?
by Nollitik
Sat Jan 03, 2015 3:34 am
Forum: General
Topic: VPN - L2TP/IPSEC
Replies: 5
Views: 2069

Re: VPN - L2TP/IPSEC

http://mikrotik.patokatech.com Thank you...I will try your setup later. Also, wondered if you had Android, IOS as well as Mac's as client...those are the devices I mostly use. It's just sad that Mikrotik won't have proper instructions with modern day menu driven that folks with home offices can use...
by Nollitik
Sun Dec 28, 2014 2:46 am
Forum: General
Topic: VPN - L2TP/IPSEC
Replies: 5
Views: 2069

VPN - L2TP/IPSEC

Has anyone got VPN - L2TP/IPSEC to work in RouterOS 6.16 and above could share their setup? I have been unable to get this working now for quite awhile and I am now on Router OS 6.22. I would like to see screen shots with private info blotted out of course. Ever since Mikrotik changed generate polic...
by Nollitik
Thu Oct 02, 2014 10:05 pm
Forum: General
Topic: What's Wrong Why VPN Won't Work?
Replies: 1
Views: 938

Re: What's Wrong Why VPN Won't Work?

1.png
2.png
by Nollitik
Thu Oct 02, 2014 9:57 pm
Forum: General
Topic: What's Wrong Why VPN Won't Work?
Replies: 1
Views: 938

What's Wrong Why VPN Won't Work?

I have been trying to get VPN to work and accessed by multiplatform, such as MacOS, IOS, Android, and Windows 7. I followed the tutorial Mikrotik gave here: http://wiki.mikrotik.com/wiki/Manual:IP/IPsec I have also had my Supout.rif file read. I'll start by posting screen shots of the log I got when...
by Nollitik
Wed Sep 10, 2014 7:56 pm
Forum: General
Topic: Readable Support.rif File to Upload for Analysis, How TO?
Replies: 8
Views: 3242

Re: Readable Support.rif File to Upload for Analysis, How TO

I emailed to support...lets hope someone responds.
by Nollitik
Wed Sep 10, 2014 7:13 pm
Forum: General
Topic: Readable Support.rif File to Upload for Analysis, How TO?
Replies: 8
Views: 3242

Re: Readable Support.rif File to Upload for Analysis, How TO

Better to write such requests directly to mikrotik support by email.
Is it support at mikrotik dot com?
by Nollitik
Tue Sep 09, 2014 11:33 pm
Forum: General
Topic: Readable Support.rif File to Upload for Analysis, How TO?
Replies: 8
Views: 3242

Re: Readable Support.rif File to Upload for Analysis, How TO

you must have received a confirmation email. if not, tell me the login you used. Please refresh my account (Nollitik) at Mikrotik.com Support so I can use the supout.rif reader. I can't login because the account was never properly activated. Please, please, please...this VPN has been dragging out t...
by Nollitik
Sat Aug 02, 2014 2:29 am
Forum: General
Topic: Readable Support.rif File to Upload for Analysis, How TO?
Replies: 8
Views: 3242

Re: Readable Support.rif File to Upload for Analysis, How TO

you must have received a confirmation email. if not, tell me the login you used.
Yes, I did however, I might have had a typo and for my protection wouldn't accept the correct one later. My login is the same as here...Nollitik. Thank you!
by Nollitik
Wed Jul 30, 2014 10:02 pm
Forum: General
Topic: Readable Support.rif File to Upload for Analysis, How TO?
Replies: 8
Views: 3242

Re: Readable Support.rif File to Upload for Analysis, How TO

you can read these files in your mikrotik.com account, look for supout.rif viewer. you will see that it's not a simple document You make it sound so easy; however, I am just in a loop. I set up a Mikrotik.com account and can't log in. The password gave was no good. Requested change password...chang...
by Nollitik
Wed Jul 30, 2014 2:54 pm
Forum: General
Topic: Readable Support.rif File to Upload for Analysis, How TO?
Replies: 8
Views: 3242

Readable Support.rif File to Upload for Analysis, How TO?

How can I export a readable Support.rif file to a word processor so I can annotate private info before uploading for analysis? I tried both under MacOS Mavericks as well as Windows 7 Ultimate and both are unable to open document...very frustrating indeed. Why don't they have it in rich text file for...
by Nollitik
Tue May 13, 2014 6:14 pm
Forum: Beginner Basics
Topic: Configuring L2TP / IPSec client
Replies: 6
Views: 8050

Re: Configuring L2TP / IPSec client

Your log shows the behavior problem similar to what the server is doing so I mentioned.
by Nollitik
Mon May 12, 2014 5:41 pm
Forum: Beginner Basics
Topic: Configuring L2TP / IPSec client
Replies: 6
Views: 8050

Re: Configuring L2TP / IPSec client

There are bugs associated with RouterOS v6.12 relating to L2TP...see here: http://forum.mikrotik.com/viewtopic.php?f=2&t=78816
by Nollitik
Sun May 11, 2014 5:52 am
Forum: Beginner Basics
Topic: Ready-to-go IPSec+L2TP config?
Replies: 6
Views: 2298

Re: Ready-to-go IPSec+L2TP config?

[/quote] The video and audio is recorded by Mikrotik on the MUMs .[/quote] That's sad...a Mikrotik event and they didn't take the audio directly off the sound board or PA mixer. Maybe someone might read this feedback and begin to do so for future event. Yes, your presentation was about Mikrotik; how...
by Nollitik
Sat May 10, 2014 11:15 am
Forum: Beginner Basics
Topic: Ready-to-go IPSec+L2TP config?
Replies: 6
Views: 2298

Re: Ready-to-go IPSec+L2TP config?

As mentioned previously, see my presentation about L2TP/IPSec setup itself. Video also linked in my sig. It's VERY difficult to follow along with your video as the background noise is more audible and a turn off. May I suggest fine tuning your presentation so your voice clearly heard! Also, today's...
by Nollitik
Sat May 10, 2014 10:44 am
Forum: General
Topic: IPsec appears to select the wrong peer
Replies: 2
Views: 1769

Re: IPsec appears to select the wrong peer

It seems the VPN in Router OS v6.12 has bugs issues...could relate to number 3 in the link below.

http://forum.mikrotik.com/viewtopic.php?f=2&t=78816
by Nollitik
Fri May 09, 2014 5:30 am
Forum: Beginner Basics
Topic: Ready-to-go IPSec+L2TP config?
Replies: 6
Views: 2298

Re: Ready-to-go IPSec+L2TP config?

As an Apple MacOS user myself, you might be the first to provide the ready-to-go L2TP over IPsec...so prepare a great presentation for us all. Having said that, this link might offer you some insight despite the road warrior setup for Windows: http://mum.mikrotik.com/presentations/HR13/kirnak.pdf I ...
by Nollitik
Fri May 02, 2014 3:55 pm
Forum: General
Topic: Help Me Dicipher VPN Issue
Replies: 3
Views: 1325

Re: Help Me Dicipher VPN Issue

Well of course I am extremely not happy learning that after spending so much time trying to resolve VPN issue only to read here: http://forum.mikrotik.com/viewtopic.php?f=2&t=78816 There is an issue with the L2TP server...it has bugs. Three days ago after receiving no response I made a decision ...
by Nollitik
Wed Apr 30, 2014 1:28 am
Forum: General
Topic: Help Me Dicipher VPN Issue
Replies: 3
Views: 1325

Re: Help Me Dicipher VPN Issue

Note: All packets are IPIP encapsulated in tunnel mode, and their new IP header's src-address and dst-address are set to sa-src-address and sa-dst-address values of this policy. If you do not use tunnel mode (id est you use transport mode), then only packets whose source and destination addresses a...
by Nollitik
Tue Apr 29, 2014 11:27 am
Forum: General
Topic: Help Me Dicipher VPN Issue
Replies: 3
Views: 1325

Re: Help Me Dicipher VPN Issue

Okay, after examining the log further, it seems that the issue is with L2TP and IPsec never got a chance to do its thing because the L2TP server closed the connection. I am connecting a tablet with Android 4.2, and it seems to just repeating the process...see screen shot from the log. I double check...
by Nollitik
Sat Apr 26, 2014 4:32 am
Forum: General
Topic: Help Me Dicipher VPN Issue
Replies: 3
Views: 1325

Help Me Dicipher VPN Issue

It seems from the log that the issue surrounds Policy...I selected no policy generated. Please view my log as well as the policy tab screen shot...thank you.
by Nollitik
Fri Apr 18, 2014 10:56 am
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

Okay, the issue seems to be Mavericks which I am very unhappy about having to go through a twelve pages of thread without a clear answer. Just to share it for folks having VPN issues and who's client use Mavericks. https://discussions.apple.com/thread/54 ... 0&tstart=0
by Nollitik
Thu Apr 17, 2014 11:03 pm
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

I keep getting this message in Console on VPN connection using the default configuration to determine which side of the fence having the issue and wanted to see whether someone can help me decipher so I can remedy the situation. I am using Mavericks latest update. The sad part is I was hoping that l...
by Nollitik
Thu Apr 17, 2014 1:34 am
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

Thank you MRZ for responding...I am so frustrated with this VPN over L2TP/IPsec...going to take a nap. I tried a test from home and the log seems to suggest some working action...see screen shot. Screen Shot 2014-04-16 at 5.29.49 PM.png I earlier tried to connect from a coffee shop...after no connec...
by Nollitik
Wed Apr 16, 2014 12:12 pm
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

Okay, upon read the latest modification to IPsec, I see that Port Override is the "old behavior." Does that mean by selecting that would generate policy automatically? I wish there would be an example for VPN over L2TP/IPsec that connects to home from anywhere as more, and more folks seek ...
by Nollitik
Sun Apr 13, 2014 12:16 am
Forum: Wireless Networking
Topic: Apple devices & Mikrotik
Replies: 30
Views: 30611

Re: Apple devices & Mikrotik

FWIW, I never have any issues because I used an Apple Extreme with a Mikrotik RB450G in front of it. So, I get the robustness of the Mikrotik RouterOS and the seamlessness of the Apple devices connectivity with the Apple Extreme either wired or wirelessly. I would recommend the route if it's importa...
by Nollitik
Sat Apr 12, 2014 9:21 pm
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

Okay, I am almost complete the VPN over L3TP/IPsec...just stuck on small detail. I am using OS v6.11 and there isn't the box to check generate policy...instead one has the option to select No, Port Override, or Port Strict. So. that where I am stuck and wondered if I need to to setup policy manually...
by Nollitik
Tue Apr 01, 2014 9:36 pm
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

Thank you Mikrotik Support (MRZ) and Jaytcsd for responding. Of course, I had to look up SSTP and found out it means Secure Socket Tunneling Protocol...so I learned something new today. I also began to understand why my original idea wouldn't work. I also must say that I am impressed with Jaytcsd's ...
by Nollitik
Tue Apr 01, 2014 2:52 am
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

Thanks for the response; however, most responses have nothing to do with answering my question except Jaytcsd's attempt. I am glad for the clarification regarding the amount of client’s ability to connect via L2TP/Ipsec. I really want to use the Mac Address of my laptop in conjunction with the pre-s...
by Nollitik
Sun Mar 30, 2014 11:42 pm
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

Re: VPN over L2TP/IPSEC

Thank you Rextended for responding and for the hint...that would be okay as I am the only person who would be connecting. However, can you comment on the rest of my question...I would really appreciate it...thanks again!
by Nollitik
Sun Mar 30, 2014 6:33 am
Forum: General
Topic: VPN over L2TP/IPSEC
Replies: 23
Views: 6036

VPN over L2TP/IPSEC

I have a Mikrotik Rb450G already setup and now wanting to add VPN service. Do I have to setup PPP/profile/Service - user/password/L2TP or can I just enable L2TP Server then setup under IP/IPSec the service with pre-shared password etc, then under Firewall filter enable input chain>protocol>UDP>DST P...
by Nollitik
Mon Feb 24, 2014 12:53 pm
Forum: General
Topic: DNS Not Resolving
Replies: 1
Views: 1706

DNS Not Resolving

I am using RB450G with OS 6.10, and I can't figure out why the DNS is not resolving. The firewall filter is set up to accept new connections if the request originates from the address list on my LAN. I have an Apple Mac Mini as a server on the same network as the Mikrotik. Ether2 is a master port fo...
by Nollitik
Tue Jan 21, 2014 1:41 pm
Forum: General
Topic: Two Separate Network within RB450G
Replies: 1
Views: 1116

Two Separate Network within RB450G

I am creating two separate network within RB450G where: 1. LAN1 - private home network on Ether 2 with IP 10.0.X.X/24. This port has its own DHCP Server (dhcp1), Ether 3 and Ether 4 are switched to master Ether 2, as well as have a VLAN. 2. LAN2 - private home guess network on Ether 5 with IP 172.18...
by Nollitik
Sun Jan 12, 2014 9:29 pm
Forum: General
Topic: No Router IP address
Replies: 4
Views: 1622

Re: No Router IP address

Okay, I figured it out...I didn't realize that when I did not accept default setting that I would need to set up everything...sorry for posting.
by Nollitik
Sun Jan 12, 2014 8:04 pm
Forum: General
Topic: No Router IP address
Replies: 4
Views: 1622

Re: No Router IP address

Yes, I can connect via Winbox...how do I get the router its IP address?
by Nollitik
Sun Jan 12, 2014 12:57 pm
Forum: General
Topic: No Router IP address
Replies: 4
Views: 1622

No Router IP address

My router...a RB450G, doesn't have its usual default IP address of 192.168.88.1 instead it has 0.0.0.0. So; I am unable to connect to the web. However, in Winbox, I am able to set up DHCP Client, get IP address from ISP, yet the router still has 0.0.0.0. In terminal, I am able to Ping 8.8.8.8 and ww...
by Nollitik
Sat Nov 30, 2013 11:15 pm
Forum: Beginner Basics
Topic: Locked out of mu Mikrotik 450g
Replies: 1
Views: 1699

Locked out of mu Mikrotik 450g

I was doing some firewall set up and accidentally locked myself out. I will reset and upgrade to OS 6.6 again. However, I wanted to know whether it's possible to apply the same firewall rules to two different Ethernet ports if I don't want to use the address list. I had an Apple Extreme on Eth2 for ...
by Nollitik
Tue Sep 10, 2013 1:37 pm
Forum: Beginner Basics
Topic: How to Note IP Address
Replies: 0
Views: 703

How to Note IP Address

Hello, I shall set up say on interface Ether2 a private address example 10.X.X.2/24. However, I would also like to set up on the same 1nterface Ether2 a VLAN and carved out say ten or fifteen addresses out of the above range for this. My problem is I am not sure how to note it...for example, should ...
by Nollitik
Sun Jul 28, 2013 6:00 pm
Forum: Beginner Basics
Topic: Setting Up Secure Private network with RB450G
Replies: 8
Views: 2994

Re: Setting Up Secure Private network with RB450G

No problem. If you run into problems just post and I'll see what I can do. I was pretty sure you didn't want Double NAT... Okay, I know I need to set the Apple Extreme (AE) has to connect using DHCP-NAT for the Back To My Mac feature to work, which I believe uses port 5900...I'll reconfirm. Then, I...
by Nollitik
Sat Jul 27, 2013 10:42 pm
Forum: Beginner Basics
Topic: Setting Up Secure Private network with RB450G
Replies: 8
Views: 2994

Re: Setting Up Secure Private network with RB450G

[/quote]You don't need to have it setup as a double NAT for that. Basically what you can do is utilize the Airport Extreme as a WIFI access point, but use the MikroTik as the Router/DHCP/etc... Thats what I am currently running... Then you just forward whatever ports through that you need for VNC, e...
by Nollitik
Sat Jul 27, 2013 4:11 am
Forum: Beginner Basics
Topic: Setting Up Secure Private network with RB450G
Replies: 8
Views: 2994

Re: Setting Up Secure Private network with RB450G

Goal: To be able to access private network anywhere in the world. Tools: Cisco DPQ3212 to Microtik RB450g to Apple Extreme to devices, including a Netgear for private wireless network for my guest. Objective: I would like the Microtik RB450g to be my master gate to the world and the Apple Extreme t...
by Nollitik
Sat Jul 27, 2013 3:16 am
Forum: Beginner Basics
Topic: Setting Up Secure Private network with RB450G
Replies: 8
Views: 2994

Setting Up Secure Private network with RB450G

Goal: To be able to access private network anywhere in the world. Tools: Cisco DPQ3212 to Microtik RB450g to Apple Extreme to devices, including a Netgear for private wireless network for my guest. Objective: I would like the Microtik RB450g to be my master gate to the world and the Apple Extreme to...
by Nollitik
Sun Apr 14, 2013 4:41 pm
Forum: General
Topic: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450
Replies: 8
Views: 4015

Re: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450

you can NOT upload ZIP package. Upgrade this - http://download2.mikrotik.com/routeros/ ... .0rc13.npk

and then reboot
Thank you for responding...That did it.
by Nollitik
Sun Apr 14, 2013 3:45 pm
Forum: General
Topic: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450
Replies: 8
Views: 4015

Re: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450

Here's the other.
by Nollitik
Sun Apr 14, 2013 3:37 pm
Forum: General
Topic: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450
Replies: 8
Views: 4015

Re: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450

What say Log?
by Nollitik
Sun Apr 14, 2013 12:44 pm
Forum: General
Topic: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450
Replies: 8
Views: 4015

Re: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450

Load V6 RC12 into the router (drop the files in) and then see if you can flash the board firmware. That way you can upgrade the board firmware, and then when you restart it should be able to start in RC 12? I'm just guestimating this... I upgraded the routerboard firmware to 2.29 from 2.28; however...
by Nollitik
Sat Apr 13, 2013 9:47 pm
Forum: General
Topic: Could Microtik Killed Dievices Ethernet Ports
Replies: 3
Views: 1355

Re: Could Microtik Killed Dievices Ethernet Ports

The answer is NO, and the problem is resolved...it was the cable modem. Thank you for viewing.
by Nollitik
Sat Apr 13, 2013 3:29 am
Forum: General
Topic: Could Microtik Killed Dievices Ethernet Ports
Replies: 3
Views: 1355

Re: Could Microtik Killed Dievices Ethernet Ports

No one has some answers or an explanation of what could have happened? The router seems to connect to the Internet on the Eth1; however, none of the other ports are connected despite being able to logged-in the RouterOS through Winbox.
by Nollitik
Mon Apr 08, 2013 12:27 pm
Forum: General
Topic: Could Microtik Killed Dievices Ethernet Ports
Replies: 3
Views: 1355

Re: Could Microtik Killed Devices Ethernet Ports

I forgot to mentioned that the sad part is the Apple TV, the Blueray player, and the Emac were powered off. Also, I had tried to upgrade the Microtik RB450g to OS 6.0rc12 and had actually uploaded the file which didn't install when I reboot. The Ethernet ports on the Microtik seem to be dead too.
by Nollitik
Mon Apr 08, 2013 1:37 am
Forum: General
Topic: Could Microtik Killed Dievices Ethernet Ports
Replies: 3
Views: 1355

Could Microtik Killed Dievices Ethernet Ports

As the subject states, i found several devices connected to the Microtik can no longer received Internet signal via the Ethernet port (the Netgear wireless access point, the Apple TV, the Emac, and the Blueray player).

What happen?
by Nollitik
Sun Mar 31, 2013 8:02 pm
Forum: General
Topic: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450
Replies: 8
Views: 4015

Re: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450

ok, I FTP the file (routeros-mipsbe 6.0rc12) to the router; however, the upgrade was not installed upon rebooting.

What went wrong?
by Nollitik
Sun Mar 31, 2013 8:21 am
Forum: General
Topic: Upgrading to V6.0rc12 from V5.5 mipsbe on RB450
Replies: 8
Views: 4015

Upgrading to V6.0rc12 from V5.5 mipsbe on RB450

I drag the file from desktop file in Winbox...it just does nothing. I am using Winbox on Mac.
by Nollitik
Sun Mar 31, 2013 5:29 am
Forum: General
Topic: Monitor Service provider
Replies: 1
Views: 807

Monitor Service provider

Is it possible to monitor Internet service provider speed with my RB450? I will be upgrading to the latest OS (currently running v5) shortly. I am paying for 25 - 30 mbps and wants to ensure I am receiving that 24/7 - 365 at least 90% of the time which I believe to be reasonable. Thanks for respondi...
by Nollitik
Wed Dec 29, 2010 7:13 am
Forum: Beginner Basics
Topic: Upgrading 450G to OS 4.16
Replies: 9
Views: 4360

Re: Upgrading 450G to OS 4.16

Yes, open the folder, select all the files, drag them on the folder inside of winbox. Don't drag the directory the files are in, drag the files themselves. If you drag the folder the files end up in a folder that is in the root, which means that the files aren't in the root themselves. I'm not sure...
by Nollitik
Wed Dec 29, 2010 6:05 am
Forum: Beginner Basics
Topic: Upgrading 450G to OS 4.16
Replies: 9
Views: 4360

Re: Upgrading 450G to OS 4.16

No, you dragged the directory containing the files into the root directory. Select the directory named all-packages in the File view of Winbox and delete it by pressing the minus ("-") icon. Then drag the files over into the root - not the directory. Which packages you need is obviously u...
by Nollitik
Wed Dec 29, 2010 4:36 am
Forum: Beginner Basics
Topic: Upgrading 450G to OS 4.16
Replies: 9
Views: 4360

Re: Upgrading 450G to OS 4.16

You need to put the packages into the root directory. Also, only install packages you actually need. While maybe not as clear as possible, here the manual: http://wiki.mikrotik.com/wiki/Manual:Upgrading_RouterOS Methods You can upgrade RouterOS in the following ways: Winbox – drag and drop files to...
by Nollitik
Wed Dec 29, 2010 3:43 am
Forum: Beginner Basics
Topic: Upgrading 450G to OS 4.16
Replies: 9
Views: 4360

Upgrading 450G to OS 4.16

I followed the upgrade instructions and the router still showing 4.13.What has gone wrong? Please see shots below. Thank you.
1.jpg
1.5.jpg
by Nollitik
Wed Dec 29, 2010 12:56 am
Forum: Wireless Networking
Topic: RB450G - cannot discover from WinBox
Replies: 4
Views: 1604

Re: RB450G - cannot discover from WinBox

If router still has default configuration then, ether1 is configured as WAN port and does not accept any connections to the router. Plug the cable in ether2 to ether5 then you will be able to connect. It's funny seeing this as I learned this the hard way...two days to figured it out. :) The best th...
by Nollitik
Wed Dec 29, 2010 12:29 am
Forum: Beginner Basics
Topic: DNS Changing to the Fastest
Replies: 6
Views: 3552

Re: DNS Changing to the Fastest

Another option is to write a script that will run every few minutes that will try and resolve stuff and depending on the results, modify the NAT rule that handles the redirect. I'm not sure you'll get any real useful information to be able to use it in a script however. I doubt one can write a scri...
by Nollitik
Mon Dec 27, 2010 8:50 pm
Forum: Beginner Basics
Topic: DNS Changing to the Fastest
Replies: 6
Views: 3552

Re: DNS Changing to the Fastest

Even better, tinydns will query multiple DNS servers and forward the quickes reply to the client. tinydns runs on linux, but I think Acrylic DNS does something similar on Windows. Thank you rmichael for responding. I must point out that I am new to the Mikrotik, RouterOS, etc. Is it possible to add...
by Nollitik
Mon Dec 27, 2010 4:12 am
Forum: Beginner Basics
Topic: DNS Changing to the Fastest
Replies: 6
Views: 3552

DNS Changing to the Fastest

Is there a way to set up a client quick response in real time DNS servers where the router verifies, say every 5 or 10 mins. the resolve times of DNS servers and changes the client DNS servers in order of the fastest DNS servers?
by Nollitik
Thu Dec 23, 2010 7:59 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Uhm, that screenshot just shows the lease you received. That will always show the DNS server the DHCP server gave you, since you cannot control what the server includes in the lease. You can only control what you DO with the information you receive. Look at IP > DNS. Does it actually show the serve...
by Nollitik
Thu Dec 23, 2010 5:45 am
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

I don't understand. That screenshot shows "Use peer DNS". Uncheck it, renew the DHCP lease. You might have to delete the dynamic DNS resolver entry if there is one, I don't know if it is removed automatically. It would not be there after a router reboot. 4.jpg 4.5.jpg Well I did what you ...
by Nollitik
Wed Dec 22, 2010 9:40 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Yes, you can use any DNS servers you want.

You're not looking at the right tab. Look at the actual DHCP client configuration (not the status) and uncheck "Use peer DNS".
3.jpg
I uncheck the "use peer DNS but nothing happen! Shot shows the check after I unchecked and nothing happen!
by Nollitik
Wed Dec 22, 2010 9:24 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Yes. Do those items have a D next to them? That means they're being picked up by a DHCP client. Edit the client in IP > DHCP Client and uncheck "Use DHP DNS" 1.jpg Well, my Mikrotik 450G is now online. The above the a shot of my DHCP Client status. It's showing my ISP's DNS server. What d...
by Nollitik
Wed Dec 22, 2010 7:40 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Yes. Do those items have a D next to them? That means they're being picked up by a DHCP client. Edit the client in IP > DHCP Client and uncheck "Use DHP DNS" 1.jpg Well, my Mikrotik 450G is now online. The above the a shot of my DHCP Client status. It's showing my ISP's DNS server. What d...
by Nollitik
Wed Dec 22, 2010 4:38 am
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Okay it appears the router is now working. I will put online in the morning. I wanted to use Google public DNS but the router is also the DNS server. In the IP/DNS, it shows the router in # 0 position and Google in 1 and 2 positions. However, when I click on settings, I get my old Belkin router and ...
by Nollitik
Tue Dec 21, 2010 6:30 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

I notice in the previous post that in the /interface bridge there is no admin MAC address; should that have been the MAC address for my laptop?
by Nollitik
Tue Dec 21, 2010 6:43 am
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

So can you ping 192.168.88.1 when you have .36 configured on your wired interface and plug into ether2? I haven't worked with 450Gs, there appears to be a bridge configured. Can you also post the output of "/interface bridge export"? bridge.jpg I hope this shot is visible. I could ping 19...
by Nollitik
Mon Dec 20, 2010 10:38 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Some weird things I have notice are I am unable to access the Mikrotik without connecting to the network. I can't connect with just an ethernet cable connecting laptop to router. The last two digits of the MAC are 77 on the back of the router but 78 in the Winbox loader window. On the router's back ...
by Nollitik
Mon Dec 20, 2010 8:19 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Here is it with me having a different ip address: Last login: Mon Dec 20 11:17:41 on ttys000 ralston-champagnies-macbook-pro:~ ralston$ ifconfig lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 inet 127.0.0.1 netmask 0xff0000...
by Nollitik
Mon Dec 20, 2010 8:11 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

The only thing I was able is to attached an image of the Winbox screen below:
by Nollitik
Mon Dec 20, 2010 7:57 pm
Forum: Beginner Basics
Topic: Can't Connect to 450g
Replies: 27
Views: 4754

Re: Can't Connect to 450g

Huh. Try screenshots for now. ifconfig is run in the OS X terminal. Last login: Sun Dec 19 22:44:52 on console ralston-champagnies-macbook-pro:~ ralston$ ifconfig lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 inet 127.0.0...