Community discussions

Search found 263 matches

by mixig
Sun Jun 16, 2019 3:36 pm
Forum: General
Topic: CRS317 dead?
Replies: 1
Views: 228

Re: CRS317 dead?

Try netinstall...
by mixig
Fri Jun 07, 2019 7:05 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 82
Views: 17664

Re: Using RouterOS to VLAN your network

This is great but I have one question regarding this topic (exapmle is from wiki): Add the bridge ports and specify PVID for each access port: /interface bridge port add bridge=bridge1 interface=ether1 add bridge=bridge1 interface=ether2 pvid=20 add bridge=bridge1 interface=ether3 pvid=30 Icon-note....
by mixig
Thu May 09, 2019 8:10 pm
Forum: Beginner Basics
Topic: cant view graphing
Replies: 6
Views: 433

Re: cant view graphing

Just for test disable your firewall rules (input chain)
by mixig
Tue Feb 12, 2019 6:00 pm
Forum: General
Topic: Time Limit
Replies: 1
Views: 267

Re: Time Limit

by mixig
Tue Feb 05, 2019 5:55 pm
Forum: Beginner Basics
Topic: MAIL server behind 2 wan ips
Replies: 1
Views: 220

Re: MAIL server behind 2 wan ips

IP firewall mangle, do mark routing, check the wiki for more info
by mixig
Fri Jan 11, 2019 3:52 pm
Forum: Beginner Basics
Topic: Configure VPN (PPTP) connection
Replies: 3
Views: 783

Re: Configure VPN (PPTP) connection

You must allow GRE protocol and port 1723 from WAN (input chain in ip firewall filter)
by mixig
Tue Dec 11, 2018 10:04 pm
Forum: General
Topic: Brigde VLAN again [SOLVED]
Replies: 13
Views: 857

Brigde VLAN again [SOLVED]

Hi, I have setup like this (CCR1016) One bridge with port members sfp1-sfp6 3 VLANs, 111,199,200 sfp1 is trunk port with tagged vlans 111,199 sfp6 is trunk port with tagged vlans 111,200 Ports sfp2-sfp5 must be in access vlan 111 I used new way of bridging vlans, router os 6.42.x, it seems to me tha...
by mixig
Tue Nov 06, 2018 9:29 pm
Forum: Beginner Basics
Topic: Using RouterOS to prioritize (Qos) traffic for a Class C net
Replies: 111
Views: 182803

Re: Using RouterOS to prioritize (Qos) traffic for a Class C

I'm a little curious why you have some rules twice /ip firewall mangle add chain=forward action=mark-connection protocol=udp   src-address=192.168.100.5 connection-state=new new-connection-mark="VOIP" comment="IP-PBX" add chain=forward action=mark-packet     passthrough=no connection-mark="VOIP"   ...
by mixig
Wed Oct 31, 2018 7:22 am
Forum: General
Topic: QoS Internet
Replies: 1
Views: 338

QoS Internet

Hi, can someone check this part of my configuration, there are 3 netoworks (3 VLAN) and all of them are going to Internet via fiber optic 50/50Mbps, I need to share bandwidth 2x15Mbps and 1x20, If there is no congestion on wan then they can use all available bandwidth. Packet are matching in mangle ...
by mixig
Mon Oct 29, 2018 7:18 pm
Forum: Beginner Basics
Topic: Mikrotik 3011 VLAN setup voice + data
Replies: 60
Views: 5020

Re: Mikrotik 3011 VLAN setup voice + data

Try with this: /interface bridge add name=bridge vlan-filtering=no /interface vlan add interface=bridge name=vlan_170 vlan-id=170 add interface=bridge name=vlan_171 vlan-id=171 add interface=bridge name=vlan_172 vlan-id=172 add interface=bridge name=vlan_173 vlan-id=173 /interface bridge vlan add br...
by mixig
Fri Oct 26, 2018 5:13 pm
Forum: General
Topic: How recovery hacked RB2011 via JTAG ?
Replies: 3
Views: 560

Re: How recovery hacked RB2011 via JTAG ?

Factory reset and then restore backup then change the password?
by mixig
Mon Oct 08, 2018 12:11 pm
Forum: General
Topic: Multiple requests from same port.
Replies: 1
Views: 416

Re: Multiple requests from same port.

Try to use SIP TCP instead UDP
by mixig
Mon Oct 08, 2018 12:09 pm
Forum: General
Topic: RouterOS do not upgrade from 6.34.4
Replies: 7
Views: 836

Re: RouterOS do not upgrade from 6.34.4

Hello, I got a CRS125-24G-1S in control with 6.34.4. I absolutely cant upgrade or change a routerOS at the board. I tried several versions (include a try to downgrade). I put a package file into the router and reboot. And nothing change. Package still on the disk and i have not any records at log, ...
by mixig
Mon Oct 08, 2018 12:05 pm
Forum: Beginner Basics
Topic: Not allowing one certain IP address to see the rest of the network
Replies: 14
Views: 843

Re: Not allowing one certain IP address to see the rest of the network

Hey. Just set src-address as your laptop and set dst-address as a prohibited network. or you can set firewall rule like this: /ip firewall filter add action= accept chain=forward dst-address= !192.168.0.0/24 src-address=192.168.0.22 P.S.: don't forget to lift this rule up above common forward rule....
by mixig
Mon Oct 08, 2018 11:59 am
Forum: Beginner Basics
Topic: Problem with DHCP server and virtual AP
Replies: 6
Views: 702

Re: Problem with DHCP server and virtual AP

Please export the full configuration of your router so that we can see all your settings
by mixig
Thu Oct 04, 2018 7:43 pm
Forum: General
Topic: Mikrotik Router SIP Connection Blocked.
Replies: 76
Views: 36948

Re: Mikrotik Router SIP Connection Blocked.

I can confirm that from version 4.x till now 6.4x same thing if PPP interface is in use so I use this one as a script and no more reports from customer:
/ip firewall connection remove [/ip firewall connection find where connection-type=sip and assured=no]
by mixig
Fri Jan 19, 2018 10:07 pm
Forum: General
Topic: winbox for ubuntu
Replies: 37
Views: 34234

Re: winbox for ubuntu

Any update regarding this topic?

BR,
Mixig
by mixig
Sun Feb 16, 2014 3:50 pm
Forum: Beginner Basics
Topic: QOS Verify setup
Replies: 3
Views: 1481

Re: QOS Verify setup

Your mikrotik routers prioritise nothing with the current configuration
by mixig
Mon Dec 09, 2013 3:53 pm
Forum: General
Topic: option 66 ROS 6.7
Replies: 3
Views: 740

Re: option 66 ROS 6.7

works as expected: http://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Server#DHCP_Options you have to set 'random text' (note the quotes) if you want to send a string over as an option value. when everything is set up you can check actual raw value what is going to be sent over. Hi, i put the qoutes and ...
by mixig
Mon Dec 09, 2013 3:32 pm
Forum: General
Topic: option 66 ROS 6.7
Replies: 3
Views: 740

option 66 ROS 6.7

Hi,

i have option 66 for my phones:

http://192.168.10.1:5000/provisioning

on 5.26 it works, on 6.7 i get error (attach)... to resolve my problems I need to downgrade all my router boards??
by mixig
Sun Dec 01, 2013 4:24 pm
Forum: Beginner Basics
Topic: Forward Mail Traffic
Replies: 2
Views: 790

Re: Forward Mail Traffic

Cab you share with us your Firewall (Filter/NAT) config?
by mixig
Wed Nov 20, 2013 10:27 pm
Forum: Beginner Basics
Topic: IPSEC tunnel between RB912 and Sonicwall UP but no packets
Replies: 7
Views: 3720

Re: IPSEC tunnel between RB912 and Sonicwall UP but no packe

Hi, this is from your MKT: [admin@MikroTik] /ip ipsec policy> 0 src-address=1.254.0.0/24 src-port=any dst-address=172.16.0.0/24 dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes sa-src-address=213.27.221.220 sa-dst-address=95.126.72.72 proposal=default priority=0 ...
by mixig
Wed Nov 06, 2013 10:38 pm
Forum: General
Topic: Simple queue comparation
Replies: 1
Views: 349

Simple queue comparation

Hi,
can someone check my two config examples and explain me is there any difference between this two setups? (Priorities are different for each client)

Thanks
by mixig
Thu Aug 22, 2013 7:32 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Winbox search option
Replies: 3
Views: 1244

Winbox search option

Hi,

it would be nice in Winbox to have some search field (which will look for ip address or note value) so that we dont need to scroll through the list (each day i need to connect to some of mkt and each time i must spend some time to find it on the list

Thanks
by mixig
Fri Aug 16, 2013 4:46 pm
Forum: General
Topic: PCC vs ECMP load balancing
Replies: 1
Views: 1393

Re: PCC vs ECMP load balancing

From wiki for ECMP: Known Issues DNS issues ISP specific DNS servers might have custom configuration that treats specific requests from ISP's network differently than requests from other network. So in case connection is made via other gateway those sites will not be accessible. To avoid that we sug...
by mixig
Fri Aug 16, 2013 4:42 pm
Forum: General
Topic: simple firewall question
Replies: 2
Views: 463

Re: simple firewall question

no, because last rule is general, so invalid connections will also be in that rule
by mixig
Mon Jul 15, 2013 6:41 pm
Forum: Scripting
Topic: check port status on another machine
Replies: 0
Views: 582

check port status on another machine

Hi, is there any way how I can check is other machine is listening od specific port? If yes do nothing, if not send an email. WIth netwatch I am monitoring the all machinem but i need to monitor specific services: e.g. with telnet command? step 1 -> system telnet 10.160.250.130 1234 (if port is ok m...
by mixig
Tue Jul 09, 2013 6:45 pm
Forum: General
Topic: RB 1200 temperature
Replies: 0
Views: 329

RB 1200 temperature

Any experience for how long can it works with this temperature? :D
by mixig
Thu Jul 04, 2013 10:24 pm
Forum: General
Topic: ping problem
Replies: 10
Views: 1535

Re: ping problem

First solved issues with ip addressing....
by mixig
Sun Jun 30, 2013 5:50 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Firewall filter content
Replies: 9
Views: 6428

Re: Firewall filter content

I added addresses list "Facebokk" and block everything with destination address list, every month or two i go and check is there any new subnet : http://bgp.he.net/search?search[search]=facebook&commit=Search /ip firewall address-list add address=74.119.76.0/22 disabled=no list=Facebook add address=...
by mixig
Fri Jun 28, 2013 9:42 am
Forum: General
Topic: Accessing internal IPs after connecting via VPN
Replies: 2
Views: 590

Re: Accessing internal IPs after connecting via VPN

Go to your LAN interface (192.168.88.0/24) and search ARP then select proxy-arp
by mixig
Wed Jun 19, 2013 12:27 pm
Forum: General
Topic: dst-nat change source ip address
Replies: 1
Views: 2676

dst-nat change source ip address

Hi, is it posssible to to dst nat from outisde to some local ip but with changing public ip address to local, so that device on lan see that packet as not public ip? with classic port forward i must NAT public ip which came to mikrotik to private ip and send to local machine I found that possibilty ...
by mixig
Mon Jun 17, 2013 7:20 pm
Forum: General
Topic: Route all traffic via VPN
Replies: 8
Views: 39749

Re: Route all traffic via VPN

Step one, if you want push public traffic through VPN create three address list (private ip addresses): /ip firewall address-list add address=10.0.0.0/8 disabled=no list="Local subnet" add address=172.16.0.0/12 disabled=no list="Local subnet" add address=192.168.0.0/16 disabled=no list="Local subnet...
by mixig
Fri May 31, 2013 1:10 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: How to by pass 1 user or IP in web proxy - RB2011UAS
Replies: 4
Views: 2248

Re: How to by pass 1 user or IP in web proxy - RB2011UAS

do that in ip firewall nat instead ip firewall mangle
by mixig
Fri May 31, 2013 1:09 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: How to by pass 1 user or IP in web proxy - RB2011UAS
Replies: 4
Views: 2248

Re: How to by pass 1 user or IP in web proxy - RB2011UAS

example:

/ip firewall mangle
add action=accept chain=prerouting disabled=no in-interface=ether1-LAN src-address=192.168.0.100

change in-interface=your lan interface
change ip address

put that rule at athe top of the mangle
by mixig
Thu May 16, 2013 4:45 pm
Forum: Beginner Basics
Topic: 2 WAN interfaces
Replies: 2
Views: 760

Re: 2 WAN interfaces

by mixig
Tue Apr 30, 2013 7:35 pm
Forum: General
Topic: need helpe
Replies: 3
Views: 483

Re: need helpe

by mixig
Tue Apr 30, 2013 7:30 pm
Forum: General
Topic: IPsec site-to-site VPN
Replies: 1
Views: 522

Re: IPsec site-to-site VPN

Try with this link:

http://gregsowell.com/?p=1290
by mixig
Wed Apr 17, 2013 9:09 pm
Forum: Beginner Basics
Topic: Redirect HTTP traffic
Replies: 3
Views: 875

Re: Redirect HTTP traffic

Does traffic is passing through that rule (look at the counter on the right side od the rule) Also does you Mikrotik know how to get to proxy cache? Do you see any traffic on your proxy?
by mixig
Thu Apr 11, 2013 11:42 pm
Forum: General
Topic: WAN with multiple static address; force LAN SUBNET traffic
Replies: 2
Views: 734

Re: WAN with multiple static address; force LAN SUBNET traff

try this:
add action=src-nat chain=srcnat comment="" disabled=no out-interface=WAN_INTERFACE src-address=YOUR_LAN_SUBNET to-addresses=YOUR PUBLIC_IP
by mixig
Thu Apr 11, 2013 9:50 pm
Forum: General
Topic: RB2011UAS
Replies: 5
Views: 721

Re: RB2011UAS

by mixig
Wed Apr 03, 2013 12:10 pm
Forum: General
Topic: Multiple L2TP IPsec Users
Replies: 1
Views: 831

Re: Multiple L2TP IPsec Users

From presentatio: http://mum.mikrotik.com/presentations/HR13/kirnak.pdf

You can not have more then one 0.0.0.0/0 peer. If you configure multiple, only one will work.
–Use certificates to solve problems with one PSK for all peers.
by mixig
Wed Apr 03, 2013 11:28 am
Forum: RouterOS v6 RC and v7 BETA
Topic: IPSEC / Nat issue
Replies: 3
Views: 2084

Re: IPSEC / Nat issue

IPSec traffic must be excluded from NAT (masquerade), can you please also put ipsec configuration here?
by mixig
Mon Apr 01, 2013 7:56 pm
Forum: Beginner Basics
Topic: RB2011L level 4 - blocking the connections between networks
Replies: 1
Views: 956

Re: RB2011L level 4 - blocking the connections between netwo

check this settings, if that option is not enabled you firewall rules will not work for bridged traffic
by mixig
Mon Apr 01, 2013 7:49 pm
Forum: Beginner Basics
Topic: VPN Problem
Replies: 8
Views: 2818

Re: VPN Problem

Maybe firewall issue?
by mixig
Thu Mar 28, 2013 4:54 pm
Forum: Beginner Basics
Topic: Newbie questions
Replies: 1
Views: 465

Re: Newbie questions