Community discussions

MikroTik App

Search found 44 matches

by brianchrist
Thu Sep 23, 2021 12:27 am
Forum: General
Topic: Filter-Id attribute in RADius Accept-Response cause ppp connection drops [SOLVED]
Replies: 2
Views: 946

Re: Filter-Id attribute in RADius Accept-Response cause ppp connection drops [SOLVED]

I found the problem.

I put the jump action to evaluate the PPP filters in the "input" chain which cause an error when the dynamic rules are created (include in & out interface in the rules)
You have to put it in the forward chain which accepts either in or out interface.
by brianchrist
Wed Sep 22, 2021 12:15 pm
Forum: General
Topic: Nat of indirectly connected network
Replies: 5
Views: 1077

Re: Nat of indirectly connected network

1. make sure you can ping the 192.168.0.1 from client device (172.16.0.2) 2. make sure your traceroute to internet (ex. 8.8.8.8) go through 192.168.0.1 3. add NAT on 192.168.0.1 router /ip firewall nat add action=masquerade chain=srcnat out-interface=<interface with public IP> src-address=172.16.0.0...
by brianchrist
Wed Sep 22, 2021 12:00 pm
Forum: General
Topic: routing between VLANs
Replies: 22
Views: 5318

Re: routing between VLANs

You're marking the packets on the incoming LAN interface with mark-routing, so they will be routed to the ISP interface while Mikrotik evaluates the routing decision.
They will never reach other LAN interfaces.
by brianchrist
Wed Sep 22, 2021 11:41 am
Forum: General
Topic: one cable / 2VLANS
Replies: 4
Views: 476

Re: one cable / 2VLANS

Just connect the Mikrotiks using that single cable and add VLAN interfaces on the ETH interface on both devices.

Something like this:
2021-09-22_153917.jpg
by brianchrist
Wed Sep 22, 2021 11:34 am
Forum: General
Topic: Filter-Id attribute in RADius Accept-Response cause ppp connection drops [SOLVED]
Replies: 2
Views: 946

Filter-Id attribute in RADius Accept-Response cause ppp connection drops [SOLVED]

Hi all, I set up the Mikrotik as a VPN server using L2TP and RADius authentication. When I add the attribute "Filter-Id" to the Accept-Response, the established connection will be dropped. The error message in the log is: could not add filter: outgoing interface matching not possible in in...
by brianchrist
Mon Nov 06, 2017 1:24 pm
Forum: Beginner Basics
Topic: Port Forwarding
Replies: 3
Views: 1548

Re: Port Forwarding

If your internet/uplink plugged to ether1, this should work:

/ip firewall nat add chain=dstnat dst-port=25565 action=dst-nat to-addresses=192.168.88.29 in-interface=ether1

and make sure you have src-nat for internal hosts to access the internet.
by brianchrist
Mon Sep 29, 2014 4:11 am
Forum: General
Topic: OID for dropped packets
Replies: 4
Views: 2029

Re: OID for dropped packets

Please add dropped packet counter for SNMP (OID), this is very important to measure queue effectiveness.
by brianchrist
Thu Oct 28, 2010 1:55 pm
Forum: General
Topic: RouterOS v5 RC2
Replies: 91
Views: 22276

Re: RouterOS v5 RC2

which link is broken? works for everyone else
got it. it's only available on czech and germany site
by brianchrist
Thu Oct 28, 2010 12:39 pm
Forum: General
Topic: RouterOS v5 RC2
Replies: 91
Views: 22276

Re: RouterOS v5 RC2

where i can download it?
the download link at http://www.mikrotik.com/download.html is broken
by brianchrist
Tue Oct 26, 2010 2:27 am
Forum: General
Topic: Mikrotik Performance at Its Best
Replies: 12
Views: 3406

Re: Mikrotik Performance at Its Best

Driver used is realtek. I have couple of intel pro 1000, i tried it before with same result. Irq is balanced to use the two cores. RPS doesn't seem to work yet in v5rc1, enabled but the other two cores are idle while the two cores connected to the NICs are 100%. I really hopes RPS can work to solve ...
by brianchrist
Mon Oct 25, 2010 8:32 pm
Forum: General
Topic: General questions on RouterOS
Replies: 14
Views: 3663

Re: General questions on RouterOS

Just using mikrotik's bandwidth test on 2 PCs and router under test in between.
by brianchrist
Mon Oct 25, 2010 7:55 pm
Forum: General
Topic: Mikrotik Performance at Its Best
Replies: 12
Views: 3406

Re: Mikrotik Performance at Its Best

considering the CPU is 100% already, will changing NIC make any difference?
or might the PCI slowness increase the CPU load?
by brianchrist
Mon Oct 25, 2010 7:50 pm
Forum: General
Topic: General questions on RouterOS
Replies: 14
Views: 3663

Re: General questions on RouterOS

great!

i manage to create selector for connection markings (which hits on new connection only) and the packet marking.
on my simulation router the performance is increase 25k to 62.5k pps

it's 250% increase ... yahoooooo
by brianchrist
Mon Oct 25, 2010 6:37 pm
Forum: General
Topic: General questions on RouterOS
Replies: 14
Views: 3663

Re: General questions on RouterOS

Selector is a great idea!

Thanks leonset.
by brianchrist
Mon Oct 25, 2010 6:25 pm
Forum: General
Topic: Mikrotik Performance at Its Best
Replies: 12
Views: 3406

Re: Mikrotik Performance at Its Best

Some disadvantages of using PCQ on dedicated customers: - cannot have more than one IP address. Each IP in PCQ will be treated as one customer, dedicated customer might have up to 32 IPs - cannot have SNMP (OID) for each customer - cannot set custom bandwidth requested by customer (upload, download,...
by brianchrist
Mon Oct 25, 2010 5:54 pm
Forum: General
Topic: Mikrotik Performance at Its Best
Replies: 12
Views: 3406

Re: Mikrotik Performance at Its Best

just limiting bandwidth for each --dedicated-- customer, not broadband, each customer might have different bandwidth limit.
I use PCQ for broadbands.
by brianchrist
Mon Oct 25, 2010 5:38 pm
Forum: General
Topic: Mikrotik Performance at Its Best
Replies: 12
Views: 3406

Mikrotik Performance at Its Best

Getting desperate here ... Mikrotik setup as transparent bandwidth manager only (bridged), 250 customers, 2 mangles for each customer (~500 mangles), 500 queue classes Maximum load only 65k pps, 100% on both CPUs (for each NIC) Tested on ROS v4 and v5, same result. Hardware: Gigabyte Motherboard Int...
by brianchrist
Mon Oct 25, 2010 5:07 pm
Forum: General
Topic: General questions on RouterOS
Replies: 14
Views: 3663

Re: General questions on RouterOS

forget about RB1000-1100 for you network, no more than 150-200MBit whith little firewall. Use Core-i5-i7 based routers or Xeon 54x, 55x, 56x + Intel based ethernet. (Now on Core-i7 have 2 BGB full view uplink, ~ 400 Mbit traffic, heavy mangle chain, little forward chain , little nat chain, CPU load...
by brianchrist
Wed Oct 06, 2010 9:59 am
Forum: RouterBOARD hardware
Topic: RX drops
Replies: 35
Views: 41652

Re: RX drops

After struggling for couple weeks, I found the cause of the drop is the CPU. I use dual 4 core xeon (makes 8 cores) but Mikrotik only use 1 core (because I only use 1 interface) Drops happen when CPU (a core) reach 100%, you can see each core usage in ROSv5, in ROSv4 cannot see each core. In my case...
by brianchrist
Thu Aug 19, 2010 3:12 am
Forum: RouterBOARD hardware
Topic: RX drops
Replies: 35
Views: 41652

Re: RX drops

i have intel here too and one of the ether shows rx drops 5 in 5 minutes exactly. the proc is a dual core. if i set the /system hardware set multi-cpu=no, it can get better? thanks no. keep multi-cpu=yes if your mikrotik detect 2 cpus, just make sure the load is below 50% otherwise it will start dr...
by brianchrist
Fri Jun 25, 2010 11:24 am
Forum: RouterBOARD hardware
Topic: RX drops
Replies: 35
Views: 41652

Re: RX drops

New find out.

Using Intel Core i5 3.33GHz with equal Gygabyte MB is no better than AMD 3.0 GHz

Using Intel shows counting RX Drops.
Using AMD shows NO drop at all.
by brianchrist
Thu Jun 24, 2010 10:55 am
Forum: RouterBOARD hardware
Topic: RX drops
Replies: 35
Views: 41652

Re: RX drops

Hi,

What MoBo and NICs do you use?

Regards, Grzegorz.
Gigabyte GA-MA785GM-US2H
Onboard NIC
AMD Phenom II 3.0 GHz
by brianchrist
Thu Jun 24, 2010 4:47 am
Forum: RouterBOARD hardware
Topic: RX drops
Replies: 35
Views: 41652

Re: RX drops SOLVED!

it's a matter of CPU! Using double xeon (totally 8 cores) 2.26 GHz does not good enough to serve 1200 lines of mangles and 200 queue policies. Mikrotik use one core only for firewall & queue, that's why the cpu resource shows 15% (one core equal to 12.5% for 8 cores cpu) I change the CPU to AMD ...
by brianchrist
Sat Jun 12, 2010 6:29 am
Forum: RouterBOARD hardware
Topic: RX drops
Replies: 35
Views: 41652

Re: RX drops

Onboard NIC (intel) on Intel mainboard has RX drops problem. RB-44GV NIC doesn't have problem with RX drops, but has problem with FCS/CRC error on Cisco switch. (tested with several cards) RB-44G NIC has no problem with FCS/CRC but the RX drops exist. Dlink 538T has problem with RX drops, but it muc...
by brianchrist
Thu Jun 10, 2010 12:38 pm
Forum: RouterBOARD hardware
Topic: RX drops
Replies: 35
Views: 41652

Re: RX drops

Same problem here.
I'm using intel onboard NIC, Intel motherboard.
Traffic is about 100 Mbps, 28k pps.
cpu is 15%

Is the buffer of the onboard NIC to small to handle this traffic?

Tonight I'll try RB-44G NIC
by brianchrist
Wed Apr 28, 2010 7:46 am
Forum: General
Topic: static route to dhcp gateway
Replies: 3
Views: 1324

Re: static route to dhcp gateway

but the xx.xx.xx.xx could be different for each session since the IP is dynamic using DCHP.

the situation:

1. host got ip dynamically (dhcp)
2. host connect to vpn server (using pptp) add default gateway to the link.
3. need static route to a host but NOT via pptp link
by brianchrist
Tue Apr 27, 2010 4:16 pm
Forum: General
Topic: static route to dhcp gateway
Replies: 3
Views: 1324

static route to dhcp gateway

i need to put a static route to a PPTP host on a dynamic ip client (dhcp).
is there any way to do this without script?
using ethernet interface as gateway is not working.

i need this because i have to use the default gateway routed to the pptp interface.
by brianchrist
Wed Apr 14, 2010 5:35 pm
Forum: Forwarding Protocols
Topic: OSPF over PPTP problems
Replies: 2
Views: 7594

Re: OSPF over PPTP problems

mrz is right, i have same situation with cobianet and now i have oveercome the problem by add filters to allow only prefix you need only. my routing filter on pptp server: 0 chain=ospf-in prefix=10.162.0.0/16 prefix-length=0-32 invert-match=no action=accept 1 chain=ospf-in invert-match=no action=dis...
by brianchrist
Thu Mar 25, 2010 8:40 am
Forum: General
Topic: change MAC Address interface vlan
Replies: 20
Views: 14529

Re: change MAC Address interface vlan

I think you should add the physical interface to the bridge.
And looks like this only add a new MAC to the VLAN because the original interface MAC still exist.
by brianchrist
Thu Sep 03, 2009 6:44 pm
Forum: General
Topic: ARP poisoning problem
Replies: 1
Views: 1167

Re: ARP poisoning problem

Let me simplified this.

Hotspot should be reply any arp-request from client computers with hotspot mac-address.
What happen if the real owner of IP address replying also (in case the IP address is used by a computer on the same subnet)?
by brianchrist
Thu Sep 03, 2009 3:48 pm
Forum: General
Topic: ARP poisoning problem
Replies: 1
Views: 1167

ARP poisoning problem

I'm using ROS 3.28 My hotspot clients seem do not have arp-reply from hotspot gateway. Here the case: One of my client (Computer A) using static IP 192.168.1.1 Other client (Computer B) that eventually using static IP with the 192.168.1.1 as gateway, have mac-address of Computer A instead of hotspot...
by brianchrist
Thu May 07, 2009 12:11 pm
Forum: General
Topic: MAC and IP Binding
Replies: 6
Views: 16808

Re: MAC and IP Binding

I tried adding static ARP method before but you have to change the interface ARP setting to reply-only, or a new ARP entry will created as the user using new IP address.
by brianchrist
Thu May 07, 2009 12:02 pm
Forum: General
Topic: Router Freezes on Bridging Interfaces
Replies: 7
Views: 2111

Re: Router Freezes on Bridging Interfaces (Solved)

Looks like i addressed the issue in this mangle rule.. if i enable this, the router crashes after a while and reboots /ip firewall mangle chain=forward action=add-dst-to-address-list src-address-list=IP dst-address-list=!IP address-list="P2P Address" address-list-timeout=5m connection-mar...
by brianchrist
Thu May 07, 2009 11:57 am
Forum: General
Topic: is EoIP using ICMP?
Replies: 1
Views: 791

is EoIP using ICMP?

Does anyone knows that EoIP use ICMP?

Because when my link provider block the ICMP between the IP tunnel, the packet loss is increase significantly and back to normal when the ICMP filter is disabled.
by brianchrist
Tue Apr 07, 2009 6:29 pm
Forum: The Dude
Topic: The Dude config lost when VM restart
Replies: 0
Views: 770

The Dude config lost when VM restart

I run the dude over mikrotik's xen.
everything run nicely, until the vm restart.
all config lost, just like when you first time login to the dude.

mt v3.22
dude 3.1

any suggestions?
by brianchrist
Fri Feb 13, 2009 6:18 am
Forum: General
Topic: MAC and IP Binding
Replies: 6
Views: 16808

Re: MAC and IP Binding

try this filter to bind IP and MAC:

add action=drop chain=forward src-address=192.168.X.X src-mac-address=!00:0C:42:XX:XX:XX

* there is a "!" in front of MAC address
by brianchrist
Fri Feb 13, 2009 5:26 am
Forum: General
Topic: 2 interfaces in one switch in a local network
Replies: 5
Views: 1410

Re: 2 interfaces in one switch in a local network

two interfaces from the same router connected to a switch can cause loop in the network (the network can be down).
if you want to run 2 PPPoE service with different profile, it can be done on one interface.
by brianchrist
Thu Feb 12, 2009 7:14 pm
Forum: General
Topic: Router Freezes on Bridging Interfaces
Replies: 7
Views: 2111

Re: Router Freezes on Bridging Interfaces

Almost same problem with me and still find the cause. I'm using Intel Quad Core on Asus mobo, RB44G running as bridge, transparent firewall, vlans and queue. System works as expected but not more than 2 days, it just crash and restart. Log only shows "router was rebooted without proper shutdown...
by brianchrist
Wed Oct 22, 2008 7:59 am
Forum: General
Topic: VOIP Mikrotik
Replies: 9
Views: 5158

Re: VOIP Mikrotik

I use EoIP between HQ and branches, the VoIP and data works fine.
I use x86 PCs and different versions of mikrotik
by brianchrist
Wed Oct 22, 2008 6:57 am
Forum: General
Topic: Torch error
Replies: 1
Views: 819

Torch error

v3.14
torch-error.png
the link doesn't work.
never happen before. any clue?
by brianchrist
Mon Oct 13, 2008 4:56 am
Forum: General
Topic: need expert answer: Strange behaviour in bridging
Replies: 3
Views: 1242

Re: need expert answer: Strange behaviour in bridging

New findouts: This morning I did a ping test again, but now I add a firewall filter on each box and the result is: All the packets COUNT and bytes COUNT in each box are exacly the same, means no packet is loss nor bypassed. But the traffic RATE in the middle mikrotik, in torch, is always lower than ...
by brianchrist
Mon Oct 13, 2008 3:37 am
Forum: General
Topic: need expert answer: Strange behaviour in bridging
Replies: 3
Views: 1242

Re: need expert answer: Strange behaviour in bridging

Is connection tracking for bridge on? Why would you want to put Vlan, if you bridge the two routers? Do you mean the one at the /ip firewall connections? yes, it is enabled. and, use-ip-firewall: yes use-ip-firewall-for-vlan: yes Between those two routers, there are some vlans, with different purpo...
by brianchrist
Fri Oct 10, 2008 3:24 pm
Forum: General
Topic: need expert answer: Strange behaviour in bridging
Replies: 3
Views: 1242

need expert answer: Strange behaviour in bridging

Configuration: 1 PC with 2 network cards, bridged Mikrotik version 3.14 Vlan trunk traffics (802.1q) flow through the box without problem. diagram: router1(vlan) --------- Mikrotik (bridge) --------- (trunk)Cisco(vlan) --------- router2 Problem: If you try to torch the traffic on Mikrotik, you'll fi...