Community discussions

Search found 105 matches

by Rivera
Fri Aug 26, 2016 1:32 am
Forum: General
Topic: Tunnel - block subnet access from one side
Replies: 4
Views: 556

Re: Tunnel - block subnet access from one side

Your one-rule solution is ok too. It's just that I'm used to whitelist approach, block everything by default and only add allowed exceptions. It's a little safer, because when there's a mistake, things don't work and it gets noticed immediately. With blacklist approach (allow everything by default ...
by Rivera
Thu Aug 25, 2016 9:56 pm
Forum: General
Topic: Tunnel - block subnet access from one side
Replies: 4
Views: 556

Re: Tunnel - block subnet access from one side

Sure you can. Basic idea: #1 accept established and related connections #2 accept connections originating from A to B #3 block the rest Rule #1 will allow reply packets for #2 connections that would be otherwise blocked by #3. And of course you must make it work with current setup, so unless you'd ...
by Rivera
Thu Aug 25, 2016 7:29 pm
Forum: General
Topic: Tunnel - block subnet access from one side
Replies: 4
Views: 556

Tunnel - block subnet access from one side

(i'm not even sure this can be done) I have GRE tunnel between two mikrotiks. Everything is configured and running stable, i can access both subnets. Point A subnet - 192.168.1.0/24 Point B subnet - 192.168.2.0/24 Now, what i'm trying to do is prevent point B from accessing Point A network devices, ...
by Rivera
Sun Aug 21, 2016 10:01 pm
Forum: General
Topic: EOIP + PIM, forwarding broadcasts/multicasts?
Replies: 2
Views: 708

Re: EOIP + PIM, forwarding broadcasts/multicasts?

It seems like VRRP interface itself doesn't receive broadcast/multicast traffic. Correct me if i'm wrong, but after i switched "upstream" port (the one with both PIM and IGMP) to "master" port of VRRP interface (vlan interface in my case), i stopped receiving "upstream neighbor for source X and grou...
by Rivera
Sun Aug 21, 2016 7:01 pm
Forum: General
Topic: EOIP + PIM, forwarding broadcasts/multicasts?
Replies: 2
Views: 708

Re: 2 routers 1 broadcast network

After tinkering with PIM for some time i can't get it to work. I used EoIP tunnel (192.168.44.1/24 "transport" network, site A is 192.168.44.10, site B is 192.168.44.11). Added route for both networks on routers. I can access this networks from both sides without issues. Speed is a bit slow (30-40 m...
by Rivera
Sun Aug 21, 2016 3:56 am
Forum: Scripting
Topic: Webfig with HTTPS support?
Replies: 22
Views: 16290

Re: Webfig with HTTPS support?

I stumbled upon same problem and turns out you need to import certificate twice (i had both key and cert in same file) First pass imports cert only, second import private keys. Again, only if you have cert & key in same file. You should see "KT" status near certificate after that, where K means that...
by Rivera
Sun Aug 21, 2016 3:47 am
Forum: General
Topic: EOIP + PIM, forwarding broadcasts/multicasts?
Replies: 2
Views: 708

EOIP + PIM, forwarding broadcasts/multicasts?

Hello! Need help with something i never touched before. What i'm trying to achieve: Bridge two networks for flawless access between them. No issue here, just add EoIP or IPIP and setup one route - it just works. Additional thanks to MT team for adding "use IPSec" flag in some interfaces types, it he...
by Rivera
Wed May 27, 2015 9:59 pm
Forum: General
Topic: Possible bug: IPv6 addresses invalid
Replies: 5
Views: 2082

Re: Possible bug: IPv6 addresses invalid

Same problem here. Any info? Btw, address is not marked as "invalid" in winbox (only G flag appears), but "IG" is seen in cli interface.
by Rivera
Tue May 19, 2015 6:35 pm
Forum: General
Topic: IPSec bruteforce / strange errors in logs
Replies: 1
Views: 1116

Re: IPSec bruteforce / strange errors in logs

So yeah, that was a bruteforcer from deutsche telekom... Answering my own question, yeah, it's possible to prevent bruteforce pretty much like how it's done in SSH anti-bruteforce, swapping proto and ports to IPSec ones, so now my filter looks like /ip firewall filter add action=drop chain=input com...
by Rivera
Fri May 15, 2015 7:29 pm
Forum: General
Topic: Mikrotik SSTP + Softether
Replies: 9
Views: 5282

Re: Mikrotik SSTP + Softether

I can say for sure that this issue is not present on windows built-in SSTP client
by Rivera
Fri May 15, 2015 6:12 pm
Forum: General
Topic: ROS SSTP Client to SoftEther SSTP Server
Replies: 4
Views: 3043

Re: ROS SSTP Client to SoftEther SSTP Server

I have a ticket running with MT support. They're investigating my configuration. SSTP SoftEther<---->Mikrotik will drop connections right now at random. Have not tried ovpn... In the meantime, you can use L2TP/IPSec, it's pretty solid and stable... Configuration on SE Server is pretty straightforwar...
by Rivera
Fri May 15, 2015 5:57 pm
Forum: General
Topic: IPSec bruteforce / strange errors in logs
Replies: 1
Views: 1116

IPSec bruteforce / strange errors in logs

Since i enabled IPSec / L2TP on my home router for personal usage, i constantly see this messages in log: http://i.imgur.com/T330aDb.png Any idea what happening or how to enable more verbose logging for IPSec? I'm not sure if IPSec bruteforce is even a thing (i constantly have bunch of chinese IPs b...
by Rivera
Thu May 07, 2015 9:04 pm
Forum: General
Topic: Mikrotik SSTP + Softether
Replies: 9
Views: 5282

Re: Mikrotik SSTP + Softether

I have same issue... made a ticket #2015050766000783
Seems to be some issue with MT SSTP client - this does not happen with windows client.
by Rivera
Thu Apr 17, 2014 9:04 pm
Forum: General
Topic: Please fix VPN.
Replies: 1
Views: 883

Please fix VPN.

Ok, this will thread of butthurt and suffering. However, i will try to operate facts. And sorry for my bad english. Today i decided to start listening to pandora again. Since it's not available in my country, i used VPN for accessing it. Well, it was working after some 6.x patch. When i configured i...
by Rivera
Mon Feb 03, 2014 2:20 pm
Forum: General
Topic: 6.9 released!
Replies: 223
Views: 80038

Re: 6.9 released!

>OpenVPN server doesn't work! Clients log off immediately after connection establishing. Downgrade to 6.7.

Can confirm. Same goes for PPTP.
by Rivera
Mon Nov 04, 2013 4:06 am
Forum: General
Topic: Changelog RouterOS 6.6
Replies: 33
Views: 14976

Re: Changelog RouterOS 6.6

Still no TLS update :(
by Rivera
Fri Sep 27, 2013 11:52 am
Forum: General
Topic: Mikrotik SSTP does not work with public VPN providers
Replies: 4
Views: 2270

Re: Mikrotik SSTP does not work with public VPN providers

MT Reply:
Hello,

It looks like problems with TLS incompability. We are still using TLS 1.0. We will
update TLS version in future
.
by Rivera
Tue Sep 24, 2013 6:13 pm
Forum: General
Topic: OpenVPN + two CAs in crt
Replies: 0
Views: 617

OpenVPN + two CAs in crt

My VPN provider supplied me with certificate which contains two CAs certificates - one for top-level (globalsign), second for alphassl. On normal openvpn client with that config it works: Tue Sep 24 19:08:23 2013 VERIFY OK: depth=2, C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA Tue Sep...
by Rivera
Tue Sep 24, 2013 5:50 pm
Forum: General
Topic: Mikrotik SSTP does not work with public VPN providers
Replies: 4
Views: 2270

Mikrotik SSTP does not work with public VPN providers

Hello.
I tried several VPN providers like earthvpn, none of them works with mikrotik SSTP implementation.
AFAIK some of them use softether vpn (softether.org).
I tried setting up softether for testing, unable to connect too.
SSTP in MT dies with "tls shutdown" in logs.
by Rivera
Fri Sep 06, 2013 1:31 pm
Forum: General
Topic: [BUG?] 6.3 dropping connections?
Replies: 2
Views: 742

Re: [BUG?] 6.3 dropping connections?

UPD: same happens for winbox connections. SSH and VPN (OpenVPN) is not affected as i can see.
by Rivera
Fri Sep 06, 2013 1:23 pm
Forum: General
Topic: PPTP Mikrotik and MacOS X 10.8.4
Replies: 9
Views: 3918

Re: PPTP Mikrotik and MacOS X 10.8.4

Del
by Rivera
Fri Sep 06, 2013 1:22 pm
Forum: General
Topic: [BUG] ESXi USB bypass leads to kernel panic
Replies: 3
Views: 1045

Re: [BUG] ESXi USB bypass leads to kernel panic

About VMWare, i have some linux/windows VMs with bypassed USB devices, ROS is only one which crashes on bypass, so it may be bug in kernel drivers.
by Rivera
Fri Sep 06, 2013 1:20 pm
Forum: General
Topic: [BUG] ESXi USB bypass leads to kernel panic
Replies: 3
Views: 1045

Re: [BUG] ESXi USB bypass leads to kernel panic

I will verify that when i get home.
But i can confirm that this modem was working on 6.x beta (RC) on hardware (RB493G) router.
by Rivera
Fri Sep 06, 2013 1:03 pm
Forum: General
Topic: [BUG] ESXi USB bypass leads to kernel panic
Replies: 3
Views: 1045

[BUG] ESXi USB bypass leads to kernel panic

I have my primary home router sitting in virtual machine inside VMWare ESXi 5.1u1. Backup router is RB493G, VRRP failover. I also have LTE modem (yota. Something called LU100, but i should verify it) I decided to "bypass" LTE modem to VM with RouterOS (was 6.2 in moment of test) Added USB controller...
by Rivera
Fri Sep 06, 2013 12:58 pm
Forum: General
Topic: [BUG?] 6.3 dropping connections?
Replies: 2
Views: 742

[BUG?] 6.3 dropping connections?

Upgraded to 6.3 today, noticed that i can't download mac update due to lost connection. As simple test i downloaded several 1GB "test" files, results looks like: http://pastebin.com/1yfPkV6J (I tested around 6 1GB files, results looks same on all of them) I can't remember such bug on 6.2 and i haven...
by Rivera
Fri Sep 06, 2013 12:45 pm
Forum: General
Topic: 6.3 Released
Replies: 95
Views: 20416

Re: 6.3 Released

> Ubuntu/Mint
NM in ubuntu lacks L2TP/IPsec support.
by Rivera
Fri Sep 06, 2013 12:12 pm
Forum: General
Topic: 6.3 Released
Replies: 95
Views: 20416

Re: 6.3 Released

If you so strong against OpenVPN, please provide me with protocol that will be: 1) Secure. Not PPTP 2) Cross-platform. Not SSTP. Btw yours SSTP implementation can connect only to Win and mikrotik based VPN servers, not to SoftEther) 3) Portable, by portable i mean it can be used on both 3G/4G networ...
by Rivera
Fri Sep 06, 2013 11:36 am
Forum: General
Topic: 6.3 Released
Replies: 95
Views: 20416

Re: 6.3 Released

Viscosity on Mac and Windows can simply import config with one click. Same for "free" Mac OpenVPN client - Tunnelblick.
Same applies for Ubuntu with NetworkManager.
Not sure about "OpenVPN GUI" for windows.
So yeah, not a problem at all.
by Rivera
Fri Sep 06, 2013 11:02 am
Forum: General
Topic: 6.3 Released
Replies: 95
Views: 20416

Re: 6.3 Released

*) pptp, l2tp, sstp - allow to specify server via dns name;
Please add OpenVPN to that list. Seriously, that's just unfair for users.
pptp - insecure.
sstp - supported only in windows.
l2tp - requires ipsec+l2tp combo, hard to configure by user.
by Rivera
Thu Aug 08, 2013 9:50 am
Forum: General
Topic: Strange traffic on WAN interfaces
Replies: 3
Views: 1161

Re: Strange traffic on WAN interfaces

On second screenshot, DST set as 0.0.0.0 and there is no SRC. Or is that normal for pppoe? In my setup i can see connection list and not that 0.0.0.0 connection.
by Rivera
Thu Aug 08, 2013 12:59 am
Forum: General
Topic: Strange traffic on WAN interfaces
Replies: 3
Views: 1161

Re: Strange traffic on WAN interfaces

(small upd: wan interface is not bridged, it does not have any DHCP on it, only pppoe client)
by Rivera
Thu Aug 08, 2013 12:12 am
Forum: General
Topic: Strange traffic on WAN interfaces
Replies: 3
Views: 1161

Strange traffic on WAN interfaces

Hello. Friend of mine asked me what is that traffic on WAN interfaces.
We have similar providers but i can't reproduce that on my router.
Image
Image
Any ideas what it can be?
by Rivera
Tue Jul 23, 2013 12:41 am
Forum: RouterBOARD hardware
Topic: Hardware AES + OpenVPN on RBs?
Replies: 3
Views: 2253

Re: Hardware AES + OpenVPN on RBs?

Bump
by Rivera
Mon Jul 22, 2013 10:31 pm
Forum: General
Topic: x86 v6.0 Mikrotik problem
Replies: 12
Views: 3211

Re: x86 v6.0 Mikrotik problem

(And i can confirm that there was no problem with 5.22. Shame on me, it was cracked, but it worked. Now i have legal version and it does not work. Lol)
I emulate intel e1000 on that VM.
by Rivera
Mon Jul 22, 2013 9:42 pm
Forum: General
Topic: x86 v6.0 Mikrotik problem
Replies: 12
Views: 3211

Re: x86 v6.0 Mikrotik problem

Not sure if this is related but... Today my RB493G died, but luckily i have VRRP (fallback router is sitting inside ESXi VM. Also supermicro mobo (X9SCL+-F) with Xeon E3-1230v2) and puchased license just couple of days ago... Well this is all offtopic. VRRP took master role to that VM box. I noticed...
by Rivera
Mon Jul 08, 2013 7:23 pm
Forum: RouterBOARD hardware
Topic: Hardware AES + OpenVPN on RBs?
Replies: 3
Views: 2253

Hardware AES + OpenVPN on RBs?

Hello. My current home RB493G is dying from load (not being able to handle even 10mbps ovpn flow) and i'm looking for replacement. ATM friend suggested me AH1100x2, but i'm not sure if it have hardware encryption for openvpn... Also there is small price difference between AH1100x2 and basic CCR, sho...
by Rivera
Sat Mar 23, 2013 1:15 am
Forum: General
Topic: 6.0rc11 on Fit-PC2 - no Hard Disk
Replies: 4
Views: 1708

Re: 6.0rc11 on Fit-PC2 - no Hard Disk

And about wireless, check This page.
Using USB WiFi adapters is not common practice here, so it may be pretty problematic. Although i had some usb atheros working with my RB.
by Rivera
Sat Mar 23, 2013 1:11 am
Forum: General
Topic: 6.0rc11 on Fit-PC2 - no Hard Disk
Replies: 4
Views: 1708

Re: 6.0rc11 on Fit-PC2 - no Hard Disk

>IDE
this is somewhat strange. Fit-PC have SATA connectors. Maybe you have IDE emulation enabled? If yes, can you try switching SATA mode in BIOS (if it's possible) to AHCI / SATA instead of IDE?
by Rivera
Sat Mar 23, 2013 1:07 am
Forum: General
Topic: Begin RouterOS v6rc12 proposal
Replies: 5
Views: 3365

Re: Begin RouterOS v6rc12 proposal

Another proposal thread? OpenVPN UDP!
by Rivera
Sat Mar 23, 2013 12:49 am
Forum: Scripting
Topic: Script to set gw for bunch of IPs?
Replies: 1
Views: 1363

Script to set gw for bunch of IPs?

Hello. First of all, this is my first script. Second... well, some of you may heard about "russian firewall" which is used by gov to block sites that considered harmful. Main problem is that it blocks sites by IP and not URL, for example we have 2 of 6 IPs of wordpress.com blocked right now. Obvious...
by Rivera
Fri Dec 21, 2012 10:37 am
Forum: General
Topic: v5.22: dhcp-client on VLAN does not work
Replies: 0
Views: 710

v5.22: dhcp-client on VLAN does not work

RB493G. dhcp-client on VLAN interface.
<5.22 - untested, will check a bit later.
=5.22 - no dhcp lease
>=6.0 - got dhcp lease.
by Rivera
Thu Nov 29, 2012 11:24 am
Forum: General
Topic: ESXI+Mikrotik+VLAN
Replies: 6
Views: 4438

Re: ESXI+Mikrotik+VLAN

You can't use VLAN interfaces inside ESX - ESX strips the VLAN IDs. You need to create the VLAN'ed interfaces as physical Ethernet nics connected to the switches inside ESX, and add physical ethernet NICs on the host connected to the virtual switch. False. You can create vSwitch with VLAN#4095, the...
by Rivera
Tue Nov 27, 2012 9:02 pm
Forum: General
Topic: [BUG] impossible to enable dhcp-client from CLI
Replies: 2
Views: 1001

[BUG] impossible to enable dhcp-client from CLI

Steps: /ip dhcp-client add interface=ether1 disabled=no /ip dhcp-client disable ether1 /ip dhcp-client enable ether1 aaaand... "no such item". Affects at least 5.22 on x86 and ppc. Need more replies if anyone can also test it. UPD: also tested on my RB493G 6.0rc4 (build sent by MT support to me toda...
by Rivera
Sun Nov 18, 2012 2:52 pm
Forum: General
Topic: NOT TO DO. Weird instalations?
Replies: 382
Views: 238063

Re: NOT TO DO. Weird instalations?

829430564.jpg
by Rivera
Wed Nov 14, 2012 10:27 pm
Forum: General
Topic: VRRP for home, DHCP, VLAN and etc. Need some help.
Replies: 1
Views: 903

VRRP for home, DHCP, VLAN and etc. Need some help.

Hello there. Due to my RB493G sometimes goes down, and i'm often not at home but still needing access to my homenet (lab, music, etc), i decided to setup fallback router. Now, for technical details. --- provider cable plugged in managed switch (netgear GS110TP), using VLAN 1000 for trunking my provi...
by Rivera
Mon Oct 08, 2012 11:44 am
Forum: General
Topic: DHCPv6, TunnelBroker problems, need help.
Replies: 4
Views: 1392

Re: DHCPv6, TunnelBroker problems, need help.

Any ETA on full implementation? Almost all unix dhcpv6 servers already support PD,TA and IA :)
by Rivera
Mon Oct 08, 2012 12:31 am
Forum: General
Topic: DHCP hostname forwarding
Replies: 0
Views: 323

DHCP hostname forwarding

Is it possible to forward hostnames received with DHCP server to other DNS server, for example ISC BIND?
by Rivera
Mon Oct 08, 2012 12:26 am
Forum: General
Topic: DHCPv6, TunnelBroker problems, need help.
Replies: 4
Views: 1392

Re: DHCPv6, TunnelBroker problems, need help.

So huh, after some digging... is MT's implementation of DHCPv6 includes only DHCPv6-PD and not TP/IA?
by Rivera
Mon Oct 08, 2012 12:23 am
Forum: General
Topic: [Request] Ping via specific gateway in netwatch
Replies: 4
Views: 1562

Re: [Request] Ping via specific gateway in netwatch

I would just create a /32 route for the destination you intend to ping, pointing to your main gateway.
8.8.4.4 would be better for that, since a lot of people may actually use 8.8.8.8 as primary dns.
Thanks, good idea. Gotta find some useless IPs for it. But gw option will be way easier.
by Rivera
Sun Oct 07, 2012 9:33 pm
Forum: General
Topic: DHCPv6, TunnelBroker problems, need help.
Replies: 4
Views: 1392

Re: DHCPv6, TunnelBroker problems, need help.

So i switched to /48 and now what i get: 2012.10.07 22:32:12 Client Info Creating SOLICIT message with 0 IA(s), no TA and 1 PD(s) on eth0/2 interface. 2012.10.07 22:32:13 Client Info Processing msg (SOLICIT,transID=0xa454ee,opts: 1 25 8 6) 2012.10.07 22:32:14 Client Info Processing msg (SOLICIT,tran...
by Rivera
Sun Oct 07, 2012 9:00 pm
Forum: General
Topic: DHCPv6, TunnelBroker problems, need help.
Replies: 4
Views: 1392

DHCPv6, TunnelBroker problems, need help.

Hello. I'm trying to make dhcpv6 on my RB493G. IPv6 with RA configuration works, but DHCPv6 looks like a bit tricky to configure. And no, "just use RA is not an answer :) Here is my config: IPv6 addresses (link-local skipped) # ADDRESS FROM-POOL INTERFACE ADVERTISE 1 G 2001:470:71a9::/64 internal-br...
by Rivera
Thu Oct 04, 2012 2:13 pm
Forum: General
Topic: [Request] Ping via specific gateway in netwatch
Replies: 4
Views: 1562

Re: [Request] Ping via specific gateway in netwatch

Should be easy to implement and will be useful, for example enabling ADSL/3G interface and switching routes if 8.8.8.8 is not pingable from main uplink. This is what you seem to be looking for: http://wiki.mikrotik.com/wiki/Advanced_Routing_Failover_without_Scripting Non exactly that. Example: We h...
by Rivera
Thu Oct 04, 2012 1:37 pm
Forum: General
Topic: [Request] Ping via specific gateway in netwatch
Replies: 4
Views: 1562

[Request] Ping via specific gateway in netwatch

Should be easy to implement and will be useful, for example enabling ADSL/3G interface and switching routes if 8.8.8.8 is not pingable from main uplink.
by Rivera
Wed Oct 03, 2012 4:59 pm
Forum: General
Topic: openvpn client connection
Replies: 7
Views: 6154

Re: openvpn client connection

Here is my config, if it helps...

client
remote some.host.name
ca /home/lex/root.crt
auth-user-pass
dev tun
proto tcp
nobind
auth-nocache
script-security 2
persist-key
persist-tun
user openvpn
group openvpn

Simple as that. Working everyday, using this to see my home stuff on work and vice versa.
by Rivera
Wed Oct 03, 2012 4:55 pm
Forum: General
Topic: DNS problem with my mikrotiks
Replies: 3
Views: 580

Re: DNS problem with my mikrotiks

in latest RouterOS DHCP should add dynamic dns entries and does not touch static settings at all.
Huh? Haven't seen that in changelogs.
by Rivera
Wed Oct 03, 2012 4:53 pm
Forum: General
Topic: Is there any chance to set up this OVPN conf in RouterOS?
Replies: 5
Views: 1748

Re: Is there any chance to set up this OVPN conf in RouterOS

>tls-auth ta.key 1
It won't work. MT's implementation of openvpn dies not allow import tls key.
by Rivera
Wed Oct 03, 2012 4:33 pm
Forum: Virtualization
Topic: MetaROUTER stability issues on certain MIPSBE and PPC boards
Replies: 490
Views: 123523

Re: MetaROUTER stability issues on certain MIPSBE and PPC bo

Does this patches (for mipsbe) included in 6.0rc1?
by Rivera
Wed Oct 03, 2012 4:18 pm
Forum: General
Topic: RouteOS 6.0 beta3 Missing SNMP OID
Replies: 9
Views: 4510

Re: RouteOS 6.0 beta3 Missing SNMP OID

Thanks. Currently "fixed" with snmpbulkwalk -Cc, some digits messed up, but at least it shows interfaces usage.
by Rivera
Wed Oct 03, 2012 2:10 pm
Forum: General
Topic: RouteOS 6.0 beta3 Missing SNMP OID
Replies: 9
Views: 4510

Re: RouteOS 6.0 beta3 Missing SNMP OID

Can't grab interfaces on 6.0rc1 lex@exile > snmpwalk -v2c -c lexcomt 192.168.69.1 iso.3.6.1.2.1.1.1.0 = STRING: "RouterOS RB493G" iso.3.6.1.2.1.1.2.0 = OID: iso.3.6.1.4.1.14988.1 iso.3.6.1.2.1.1.3.0 = Timeticks: (24436800) 2 days, 19:52:48.00 iso.3.6.1.2.1.1.4.0 = STRING: "mail here" iso.3.6.1.2.1.1...
by Rivera
Thu Sep 27, 2012 3:02 pm
Forum: General
Topic: Xbox Live on RB433
Replies: 11
Views: 2171

Re: Xbox Live on RB433

I have same problem with CoD:MW3 on PC.
by Rivera
Tue Sep 25, 2012 5:58 pm
Forum: Virtualization
Topic: Wireless in virtualized OpenWRT
Replies: 5
Views: 4292

Re: Wireless in virtualized OpenWRT

it's not possible to bypass wireless interface to openwrt.
by Rivera
Thu Sep 20, 2012 7:42 pm
Forum: General
Topic: Monitor clients traffic
Replies: 1
Views: 762

Monitor clients traffic

Hello, is it possible to monitor how much particular ip/mac address downloaded/uploaded? Or maybe there is some tool to quickly view who downloading/uploading, on what speed and etc?
by Rivera
Tue Sep 18, 2012 2:32 pm
Forum: RouterBOARD hardware
Topic: 12V / 3-5A PSU for RB493G?
Replies: 1
Views: 464

12V / 3-5A PSU for RB493G?

Hello. Can anyone point me to subject? I can't find any solutions except with build-in battery which is not needed for me. I heard somewhere that eeePC 900 have compatible PSU (http://www.amazon.com/1000HE-1002HA-Netbook-Replacement-Adapter/dp/B002CYXKYA), can anyone confirm? P.S. RB493G + 3xR52Hn c...
by Rivera
Tue Sep 18, 2012 2:18 pm
Forum: RouterBOARD hardware
Topic: RB493G intermittent packet loss
Replies: 14
Views: 9103

Re: RB493G intermittent packet loss

Having the same issue. -RB493G properly grounded with original Mikrotik case. -Powered through POE 24V 1A and PowerJack 12V 5A at the same time. -Running 5.20 OS with 2.41 firmware -Previous 1100AH worked flawlessly for 9 months in its place. It is NOT a temp issue, it is NOT a powersupply issue. W...
by Rivera
Thu Sep 13, 2012 5:49 pm
Forum: Virtualization
Topic: MetaROUTER stability issues on certain MIPSBE and PPC boards
Replies: 490
Views: 123523

Re: MetaROUTER stability issues on certain MIPSBE and PPC bo

i can confirm that metarouter works flawlessly with latest build on my RB493G.
However when i try to use nginx to proxy_pass some streaming audio, i experience timeouts. Tried with same config on my home server, looks like it's metarouter problem...
by Rivera
Thu Sep 13, 2012 11:58 am
Forum: Virtualization
Topic: OpenWRT metarouter patch v1.2
Replies: 40
Views: 30555

Re: OpenWRT metarouter patch v1.2

Trying to build latest openwrt with needed packages (8.09 branch), gives me following error: http://pastebin.com/7PeV0jvk
by Rivera
Mon Jul 16, 2012 11:27 pm
Forum: RouterBOARD hardware
Topic: RB493G, faulty ports?
Replies: 0
Views: 456

RB493G, faulty ports?

Hello, i have a problem with my RB493G. I cannot use ports from switch1 group. All ports from switch2 works perfectly (i resetted RB and re-configured everything from start to make sure it's not my mistake - now all ports is just bridged with DHCP server sit on top of bridge). I can see proper port ...
by Rivera
Thu Feb 16, 2012 8:27 pm
Forum: Virtualization
Topic: RB450G and Metarouter OpenWRT
Replies: 8
Views: 3536

Re: RB450G and Metarouter OpenWRT

http://forum.mikrotik.com/viewtopic.php?f=15&t=35800
Looooooong story. Mikrotik devs can't fix it for it seems like years.
by Rivera
Thu Feb 16, 2012 11:39 am
Forum: RouterBOARD hardware
Topic: RB-493G ethernet lockups
Replies: 31
Views: 7760

Re: RB-493G ethernet lockups

went to this forum to ask about similar forum and whoa!
Can confirm. RB493G. Current version 5.13, still problems.
LED blinking, interface is active in panel, but no data and no DHCP lease. Solved only by removing power cord and inserting back (software reboot works from time to time)
by Rivera
Thu Feb 16, 2012 11:33 am
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

Raising that thread. Yes, mangle-way was correct (mark my /24 subnet routes as VPN and add route based on mark), but there is one problem - if VPN connection goes down, all data silently choose main route, which is not prefered to use. P.S. also, AFAIK mark-based routing uses first rule found? So if...
by Rivera
Tue Nov 22, 2011 10:31 am
Forum: General
Topic: NAT-T & IPSec Issues still exist
Replies: 25
Views: 12140

Re: NAT-T & IPSec Issues still exist

i use Lion, maybe that's the problem.
by Rivera
Mon Nov 21, 2011 2:42 pm
Forum: General
Topic: Feature Request - Openvpn improvement.
Replies: 11
Views: 1528

Re: Feature Request - Openvpn improvement.

And? I was able to use L2TP with some vpn provider, but not with mikrotik.
by Rivera
Mon Nov 21, 2011 1:30 pm
Forum: General
Topic: Feature Request - Openvpn improvement.
Replies: 11
Views: 1528

Re: Feature Request - Openvpn improvement.

Recommending SSTP as alternative to openvpn? lol.
MT, this is most requested feature ever. How can you ignore it?
You suggest using L2TP? L2TP does not work in Mac OS X + ROS.
I can implement _proper_ openvpn server in openwrt - but metarouter is broken!
What the hell?
by Rivera
Mon Nov 21, 2011 12:53 pm
Forum: General
Topic: Feature request: support for DNS in packages
Replies: 4
Views: 1402

Re: Feature request: support for DNS in packages

why firewall? I primary ask for VPN support.
by Rivera
Sat Nov 19, 2011 8:35 pm
Forum: General
Topic: NAT-T & IPSec Issues still exist
Replies: 25
Views: 12140

Re: NAT-T & IPSec Issues still exist

Tested windows 7 and windows 8, both with NAT (connecting inside NAT) and from remote.
by Rivera
Sat Nov 19, 2011 8:23 pm
Forum: General
Topic: Feature request: support for DNS in packages
Replies: 4
Views: 1402

Feature request: support for DNS in packages

Really anoying part i that i should put, for example, IP for VPN servers. Many providers have vpn server address as domain name, for example vpn.corbina.net. And they sometimes changing. And more than that - there is servers in rotation, so if one of them will fail, resolver can pick another and con...
by Rivera
Wed Nov 16, 2011 8:53 pm
Forum: General
Topic: Problem with PPPoE connection
Replies: 6
Views: 886

Re: Problem with PPPoE connection

Correct - your primary uplink is pppoe connection. Because you start PPPoE connection on router. Let's say PPPoE is some sort of "tunnel" between you and provider. PPPoE uses PPP protocol, this is different than IP. (DHCP uses TCP/IP, PPP have it's own system for setting IP/gateway/etc). You can "in...
by Rivera
Wed Nov 16, 2011 2:56 pm
Forum: General
Topic: NAT-T & IPSec Issues still exist
Replies: 25
Views: 12140

Re: NAT-T & IPSec Issues still exist

ROS 5.8
IPSec and IPSec/L2TP does not work with Mac OS X. Works fine with windows and linux.
by Rivera
Wed Nov 16, 2011 2:30 pm
Forum: General
Topic: Problem with PPPoE connection
Replies: 6
Views: 886

Re: Problem with PPPoE connection

Masquerade? I dunno if MT have configured NAT out of the box.

Show IP->Firewall->NAT config.
As well as IP->DHCP Client.
by Rivera
Tue Nov 15, 2011 7:10 pm
Forum: General
Topic: OpenVPN - TCP
Replies: 8
Views: 1943

Re: OpenVPN - TCP

Oh, i found it, message by normis (MT employee?):
"OpenVPN is very very buggy and hard to implement. Our developers almost all committed suicide trying to make it work. It's a big mess, so we can't continue to implement it 100%"
proof

So we are out of luck.
by Rivera
Tue Nov 15, 2011 7:07 pm
Forum: General
Topic: OpenVPN - TCP
Replies: 8
Views: 1943

Re: OpenVPN - TCP

I dunno, then.

Btw: http://wiki.mikrotik.com/wiki/MikroTik_ ... e_Requests
Search for "Support for OpenVPN server over UDP" - many people need this feature since start of 2009! (i think wiki was added somewhere around that date?). One of most requested feature of ROS.
by Rivera
Tue Nov 15, 2011 6:21 pm
Forum: General
Topic: DNS-based routing?
Replies: 8
Views: 2267

Re: DNS-based routing?

NetRange: 208.85.40.0 - 208.85.47.255
CIDR: 208.85.40.0/21
OriginAS: AS40428

I know i can do ip routes, my question was about DNS-based routing.
by Rivera
Tue Nov 15, 2011 2:19 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

Tried many ways, and i can't get it working. Sad.
by Rivera
Tue Nov 15, 2011 2:16 pm
Forum: General
Topic: OpenVPN - TCP
Replies: 8
Views: 1943

Re: OpenVPN - TCP

that have been discussed here over 9000 times. I also want to see UDP (as well as LZO) support, but MT support stated: they will not add new ovpn features in ROS :( Reason: "hard to implement"
Correct me if i wrong.
by Rivera
Tue Nov 15, 2011 2:13 pm
Forum: General
Topic: DNS-based routing?
Replies: 8
Views: 2267

DNS-based routing?

Hello. Since some services available only in USA (for example - pandora), i want to use VPN tunnel with USA IP address. The problem is i can't find any way to do DNS-based routing (example - *.pandora.com via ovpn-out-usa). I can setup ip-based routing, but pandora uses many IPs - some for website, ...
by Rivera
Fri Nov 11, 2011 9:47 pm
Forum: Virtualization
Topic: RB450G + openwrt Metarouter strange problem
Replies: 221
Views: 76757

Re: RB450G + openwrt Metarouter strange problem

Some interesting info. I enabled writing debug logs to disk, and tried to catch some messages. Of course i haven't found any useful info, but... There were no virtual machine freezes Instead, router crashes hard. I always saw that first virtual machine freezes, and then router crashes (if you do not...
by Rivera
Fri Nov 11, 2011 8:41 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

Yes, i need PPTP as default route but i need access to ADSL ip from external net.
Sorry if i described something wrong because my english is not really good.

BTW, with config in prev post i'm not able to ping PPTP ip :(
by Rivera
Fri Nov 11, 2011 8:34 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

0 chain=forward action=change-mss new-mss=1360 passthrough=yes tcp-flags=syn protocol=tcp tcp-mss=1453-65535 1 chain=prerouting action=mark-routing new-routing-mark=primary-uplink passthrough=no in-interface=pptp-out-someisp (i tried with both passthrough=yes and no) 0 A S dst-address=0.0.0.0/0 gat...
by Rivera
Fri Nov 11, 2011 8:23 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

Strange... ADSL and PPTP - metric=1. PPTP routing mark - "uplink" (that's in ip -> routes) in mangle - mark all routes with in-interface=pptp-uplink as "uplink" (prerouting) (ip - firewall - mangle) In that case, default gw = ADSL. P.S. i do not use "use as default gw" in PPTP/PPPOE client and write...
by Rivera
Fri Nov 11, 2011 7:45 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

hm. pppoe route - metric 2
pptp route - metric 1 + marked (in mangle i mangle all routes that have in-interface=pptp-interface)

now pppoe route is my default route O_o
by Rivera
Fri Nov 11, 2011 7:07 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

by "metric" you mean "distance" in ip - route?
by Rivera
Fri Nov 11, 2011 3:31 pm
Forum: Virtualization
Topic: RB450G + openwrt Metarouter strange problem
Replies: 221
Views: 76757

Re: RB450G + openwrt Metarouter strange problem

v 5.8, still broken. Also crashes host machine.
by Rivera
Fri Nov 11, 2011 2:28 pm
Forum: Scripting
Topic: Update to "Hurricane Electric IPv6toIPv4 Endpoint updater"
Replies: 6
Views: 3166

Re: Update to "Hurricane Electric IPv6toIPv4 Endpoint update

No problem. And thanks for my first karma + :) Personally i think that whole article should be rewriten. For example: In newer ROS versions you should use IPv6 of gateway, not ::216.7.3.6/etc - it stated in the end of article as "you probably can try..." It also does not cover ND (neigbor discovery)...
by Rivera
Fri Nov 11, 2011 1:24 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

It will not work, because all VPN traffic also will be marked. Basically all traffic will be marked - ADSL is uplink for VPN.

UPD: i tried it, but it does not work.
by Rivera
Thu Nov 10, 2011 10:05 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

I already fixed that (see first post) - just need to add second masquerade rule. It will not work without it.

Second problem is how i should configure routing so all packets received by pppoe-adsl should be sent via pppoe-adsl too..
by Rivera
Thu Nov 10, 2011 1:09 pm
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

Re: [Routing] ADSL and PPTP as primary uplink. Custom routin

Network is bridged. All ports in bridge except adsl modem. IP cfg: Flags: X - disabled, I - invalid, D - dynamic 0 address=192.168.69.1/24 network=192.168.69.0 interface=bridge actual-interface=bridge 2 address=192.168.1.10/24 network=192.168.1.0 interface=eth5-mgts-uplink actual-interface=eth5-mgts...
by Rivera
Thu Nov 10, 2011 11:06 am
Forum: General
Topic: [Routing] ADSL and PPTP as primary uplink. Custom routing
Replies: 21
Views: 2437

[Routing] ADSL and PPTP as primary uplink. Custom routing

Hello, i need some help in routing. At home i have RB493G router and i need that scheme of connection: Clients --> Mikrotik (NAT) --> ADSL provider --> VPN connection (external) /ip firewall nat add action=masquerade chain=srcnat disabled=no out-interface=my_vpn_interface src-address=my_lan_range So...
by Rivera
Mon Nov 07, 2011 12:03 pm
Forum: General
Topic: Mikrotik PPTP server with FreeRadius and EAP-TLS
Replies: 1
Views: 1475

Re: Mikrotik PPTP server with FreeRadius and EAP-TLS

I can't find EAP support in routeros pptp.

AFAIK that's not possible - you should use only one - radius or internal auth.
by Rivera
Mon Nov 07, 2011 11:47 am
Forum: Scripting
Topic: Update to "Hurricane Electric IPv6toIPv4 Endpoint updater"
Replies: 6
Views: 3166

Re: Update to "Hurricane Electric IPv6toIPv4 Endpoint update

Just a quick note: you can also use /tool netwatch for it. My setup: /tool netwatch add disabled=no down-script="/system script run he-update" host=2001:47:47:47::1 interval=20s timeout=1s up-script="" Where 2001:47:47:47::1 - IPv6 of your tunnelbroker server. So when the IPv6 is available, there wi...
by Rivera
Tue Nov 01, 2011 4:48 pm
Forum: Virtualization
Topic: RB450G + openwrt Metarouter strange problem
Replies: 221
Views: 76757

Re: RB450G + openwrt Metarouter strange problem

And yes, there is something i discovered in process of testing: 1) netconsole. There is no error logs sent via network - only standart boot data. 2) There is no crashdumps in openwrt machine. Basically everything is okay with openwrt. 3) i tried watching dmesg, and there is no error messages too. 4)...
by Rivera
Tue Nov 01, 2011 4:28 pm
Forum: Virtualization
Topic: RB450G + openwrt Metarouter strange problem
Replies: 221
Views: 76757

Re: RB450G + openwrt Metarouter strange problem

Can anyone run 'while true;do dmesg -c;done' and see what happens? And please leave that command running in openwrt (for example in background)
by Rivera
Fri Jul 22, 2011 10:40 pm
Forum: General
Topic: Metarouter + Openwrt = freezes?
Replies: 1
Views: 584

Re: Metarouter + Openwrt = freezes?

Small update: it works with that script, but cpu load always near 100%.

Also, sometimes when disabling-enabling that virtual machine, router reboots.
by Rivera
Fri Jul 22, 2011 11:25 am
Forum: Wireless Networking
Topic: 802.11n Slow
Replies: 126
Views: 48235

Re: 802.11n Slow

rb493g, 2x52Hn... Same problem, lol.
by Rivera
Fri Jul 22, 2011 11:15 am
Forum: General
Topic: Does RB/493GPI support 3G modem ZTE MF626?
Replies: 8
Views: 1431

Re: Does RB/493GPI support 3G modem ZTE MF626?

USB port on rb493g does not have 5VDC power. You need to use usb power injector.
by Rivera
Thu Jul 21, 2011 7:58 pm
Forum: General
Topic: Metarouter + Openwrt = freezes?
Replies: 1
Views: 584

Metarouter + Openwrt = freezes?

Hello, i recently compiled openwrt image for my RB493G (nothing special, just mail server and radius server) The problem is i have randomly freezes of virtual machine. It just becomes completely stalled - no reply at icmp, no logs, no kernel panics - only reboot can help (thanks to netwatch feature ...