Community discussions

MikroTik App

Search found 275 matches

by mixig
Sun Aug 30, 2020 10:16 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 669

Re: 16 port short depth PoE switch

+1!
by mixig
Sat Aug 01, 2020 7:14 pm
Forum: RouterBOARD hardware
Topic: HEX POE problem
Replies: 8
Views: 1722

Re: HEX POE problem

mAp need 802.3 af to be powered up, so with that you need 48V adapter on hex side.
Ltap as mentioned in post reply, need 12-30V and can be powered with default hex adapter which is 24V oassive PoE.

So no RMA, you need to change adapter on hex side
by mixig
Fri Jun 19, 2020 4:26 pm
Forum: General
Topic: RB4011 powered via POE
Replies: 10
Views: 1735

Re: RB4011 powered via POE

Only if that linksys switch supports 24V passive poe, 4011 cant be powered with 802.3af/at
by mixig
Fri Jun 05, 2020 1:50 am
Forum: Beginner Basics
Topic: Web and Content Filtering
Replies: 3
Views: 778

Re: Web and Content Filtering

By buying UTM/NGFW product
by mixig
Sun May 31, 2020 2:27 pm
Forum: RouterBOARD hardware
Topic: 48 sfp port switch
Replies: 1
Views: 568

48 sfp port switch

Are there any indications for a 48 sfp port switch in the near future?
by mixig
Wed Apr 29, 2020 7:38 pm
Forum: RouterBOARD hardware
Topic: hardware idea for a multiport switch
Replies: 64
Views: 31797

Re: hardware idea for a multiport switch

Almost year and a half from the first post in this topic... Is there any news about multiport switch, maybe something like old Cisco 6500? With modular slots? 😁
by mixig
Thu Apr 09, 2020 9:30 pm
Forum: RouterBOARD hardware
Topic: Cable suggestions
Replies: 2
Views: 1740

Re: Cable suggestions

We are using only UBNT Tough Cable TC-Pro Level 1 FTP Cat5e outdoor.
Sea, solt, wind, it simply lasts...
by mixig
Mon Mar 23, 2020 11:39 pm
Forum: RouterBOARD hardware
Topic: Request for compact cooper 3xx series switch
Replies: 4
Views: 2666

Re: Request for compact cooper 3xx series switch

+1
++1 for PoE version
by mixig
Thu Feb 20, 2020 10:16 pm
Forum: RouterBOARD hardware
Topic: interface warning fcs error on link
Replies: 1
Views: 2415

Re: interface warning fcs error on link

Replace sfp modules on both sides
by mixig
Thu Jan 30, 2020 8:16 pm
Forum: RouterOS v7 BETA
Topic: new feature request MLAG!!!
Replies: 19
Views: 6445

Re: new feature request MLAG!!!

+ 1
by mixig
Wed Dec 11, 2019 6:17 pm
Forum: Beginner Basics
Topic: CRS326 InterVLAN Routing by Bridge
Replies: 9
Views: 1828

Re: CRS326 InterVLAN Routing by Bridge

Do you have any firewall rules? When pinging DEVICE from CRS it's output chain, when pinging DEVICE from PC it's forward chain.
Also can you ping from PC ip address of CRS from vlan 10, 192.168.10.1 (input chain).
by mixig
Sat Oct 19, 2019 3:37 pm
Forum: Forwarding Protocols
Topic: VOIP Fritzbox -> Mikrotik does not work, NAT and Firwall rules
Replies: 2
Views: 1951

Re: VOIP Fritzbox -> Mikrotik does not work, NAT and Firwall rules

Can fritzbox do a routing, if yes then there is no need to use NAT. Also if you test with wireshark on MKT side (where phone is pluged) I believe you would see in SIP mesages that IP for sending RTP is wrong (signaling is passing fine but NAT breaks/change attributes in SIP signaling messages).
by mixig
Sun Jun 16, 2019 3:36 pm
Forum: General
Topic: CRS317 dead?
Replies: 1
Views: 487

Re: CRS317 dead?

Try netinstall...
by mixig
Fri Jun 07, 2019 7:05 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 78221

Re: Using RouterOS to VLAN your network

This is great but I have one question regarding this topic (exapmle is from wiki): Add the bridge ports and specify PVID for each access port: /interface bridge port add bridge=bridge1 interface=ether1 add bridge=bridge1 interface=ether2 pvid=20 add bridge=bridge1 interface=ether3 pvid=30 Icon-note....
by mixig
Thu May 09, 2019 8:10 pm
Forum: Beginner Basics
Topic: cant view graphing
Replies: 6
Views: 1174

Re: cant view graphing

Just for test disable your firewall rules (input chain)
by mixig
Tue Feb 12, 2019 6:00 pm
Forum: General
Topic: Time Limit
Replies: 1
Views: 494

Re: Time Limit

by mixig
Tue Feb 05, 2019 5:55 pm
Forum: Beginner Basics
Topic: MAIL server behind 2 wan ips
Replies: 1
Views: 456

Re: MAIL server behind 2 wan ips

IP firewall mangle, do mark routing, check the wiki for more info
by mixig
Fri Jan 11, 2019 3:52 pm
Forum: Beginner Basics
Topic: Configure VPN (PPTP) connection
Replies: 3
Views: 2264

Re: Configure VPN (PPTP) connection

You must allow GRE protocol and port 1723 from WAN (input chain in ip firewall filter)
by mixig
Tue Dec 11, 2018 10:04 pm
Forum: General
Topic: Brigde VLAN again [SOLVED]
Replies: 13
Views: 1368

Brigde VLAN again [SOLVED]

Hi, I have setup like this (CCR1016) One bridge with port members sfp1-sfp6 3 VLANs, 111,199,200 sfp1 is trunk port with tagged vlans 111,199 sfp6 is trunk port with tagged vlans 111,200 Ports sfp2-sfp5 must be in access vlan 111 I used new way of bridging vlans, router os 6.42.x, it seems to me tha...
by mixig
Tue Nov 06, 2018 9:29 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 254328

Re: Using RouterOS to prioritize (Qos) traffic for a Class C

I'm a little curious why you have some rules twice /ip firewall mangle add chain=forward action=mark-connection protocol=udp   src-address=192.168.100.5 connection-state=new new-connection-mark="VOIP" comment="IP-PBX" add chain=forward action=mark-packet     passthrough=no connection-mark="VOIP"   ...
by mixig
Wed Oct 31, 2018 7:22 am
Forum: General
Topic: QoS Internet
Replies: 1
Views: 573

QoS Internet

Hi, can someone check this part of my configuration, there are 3 netoworks (3 VLAN) and all of them are going to Internet via fiber optic 50/50Mbps, I need to share bandwidth 2x15Mbps and 1x20, If there is no congestion on wan then they can use all available bandwidth. Packet are matching in mangle ...
by mixig
Mon Oct 29, 2018 7:18 pm
Forum: Beginner Basics
Topic: Mikrotik 3011 VLAN setup voice + data
Replies: 60
Views: 8566

Re: Mikrotik 3011 VLAN setup voice + data

Try with this: /interface bridge add name=bridge vlan-filtering=no /interface vlan add interface=bridge name=vlan_170 vlan-id=170 add interface=bridge name=vlan_171 vlan-id=171 add interface=bridge name=vlan_172 vlan-id=172 add interface=bridge name=vlan_173 vlan-id=173 /interface bridge vlan add br...
by mixig
Fri Oct 26, 2018 5:13 pm
Forum: General
Topic: How recovery hacked RB2011 via JTAG ?
Replies: 3
Views: 1180

Re: How recovery hacked RB2011 via JTAG ?

Factory reset and then restore backup then change the password?
by mixig
Mon Oct 08, 2018 12:11 pm
Forum: General
Topic: Multiple requests from same port.
Replies: 1
Views: 601

Re: Multiple requests from same port.

Try to use SIP TCP instead UDP
by mixig
Mon Oct 08, 2018 12:09 pm
Forum: General
Topic: RouterOS do not upgrade from 6.34.4
Replies: 7
Views: 1337

Re: RouterOS do not upgrade from 6.34.4

Hello, I got a CRS125-24G-1S in control with 6.34.4. I absolutely cant upgrade or change a routerOS at the board. I tried several versions (include a try to downgrade). I put a package file into the router and reboot. And nothing change. Package still on the disk and i have not any records at log, ...
by mixig
Mon Oct 08, 2018 12:05 pm
Forum: Beginner Basics
Topic: Not allowing one certain IP address to see the rest of the network
Replies: 14
Views: 1443

Re: Not allowing one certain IP address to see the rest of the network

Hey. Just set src-address as your laptop and set dst-address as a prohibited network. or you can set firewall rule like this: /ip firewall filter add action= accept chain=forward dst-address= !192.168.0.0/24 src-address=192.168.0.22 P.S.: don't forget to lift this rule up above common forward rule....
by mixig
Mon Oct 08, 2018 11:59 am
Forum: Beginner Basics
Topic: Problem with DHCP server and virtual AP
Replies: 6
Views: 1808

Re: Problem with DHCP server and virtual AP

Please export the full configuration of your router so that we can see all your settings
by mixig
Thu Oct 04, 2018 7:43 pm
Forum: General
Topic: Mikrotik Router SIP Connection Blocked.
Replies: 78
Views: 44737

Re: Mikrotik Router SIP Connection Blocked.

I can confirm that from version 4.x till now 6.4x same thing if PPP interface is in use so I use this one as a script and no more reports from customer:
/ip firewall connection remove [/ip firewall connection find where connection-type=sip and assured=no]
by mixig
Fri Jan 19, 2018 10:07 pm
Forum: General
Topic: winbox for ubuntu
Replies: 37
Views: 43991

Re: winbox for ubuntu

Any update regarding this topic?

BR,
Mixig
by mixig
Sun Feb 16, 2014 3:50 pm
Forum: Beginner Basics
Topic: QOS Verify setup
Replies: 3
Views: 1647

Re: QOS Verify setup

Your mikrotik routers prioritise nothing with the current configuration
by mixig
Mon Dec 09, 2013 3:53 pm
Forum: General
Topic: option 66 ROS 6.7
Replies: 3
Views: 945

Re: option 66 ROS 6.7

works as expected: http://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Server#DHCP_Options you have to set 'random text' (note the quotes) if you want to send a string over as an option value. when everything is set up you can check actual raw value what is going to be sent over. Hi, i put the qoutes and ...
by mixig
Mon Dec 09, 2013 3:32 pm
Forum: General
Topic: option 66 ROS 6.7
Replies: 3
Views: 945

option 66 ROS 6.7

Hi,

i have option 66 for my phones:

http://192.168.10.1:5000/provisioning

on 5.26 it works, on 6.7 i get error (attach)... to resolve my problems I need to downgrade all my router boards??
by mixig
Sun Dec 01, 2013 4:24 pm
Forum: Beginner Basics
Topic: Forward Mail Traffic
Replies: 2
Views: 933

Re: Forward Mail Traffic

Cab you share with us your Firewall (Filter/NAT) config?
by mixig
Wed Nov 20, 2013 10:27 pm
Forum: Beginner Basics
Topic: IPSEC tunnel between RB912 and Sonicwall UP but no packets
Replies: 7
Views: 4073

Re: IPSEC tunnel between RB912 and Sonicwall UP but no packe

Hi, this is from your MKT: [admin@MikroTik] /ip ipsec policy> 0 src-address=1.254.0.0/24 src-port=any dst-address=172.16.0.0/24 dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes sa-src-address=213.27.221.220 sa-dst-address=95.126.72.72 proposal=default priority=0 ...
by mixig
Wed Nov 06, 2013 10:38 pm
Forum: General
Topic: Simple queue comparation
Replies: 1
Views: 465

Simple queue comparation

Hi,
can someone check my two config examples and explain me is there any difference between this two setups? (Priorities are different for each client)

Thanks
by mixig
Thu Aug 22, 2013 7:32 pm
Forum: General
Topic: Winbox search option
Replies: 3
Views: 1507

Winbox search option

Hi,

it would be nice in Winbox to have some search field (which will look for ip address or note value) so that we dont need to scroll through the list (each day i need to connect to some of mkt and each time i must spend some time to find it on the list

Thanks
by mixig
Fri Aug 16, 2013 4:46 pm
Forum: General
Topic: PCC vs ECMP load balancing
Replies: 1
Views: 1688

Re: PCC vs ECMP load balancing

From wiki for ECMP: Known Issues DNS issues ISP specific DNS servers might have custom configuration that treats specific requests from ISP's network differently than requests from other network. So in case connection is made via other gateway those sites will not be accessible. To avoid that we sug...
by mixig
Fri Aug 16, 2013 4:42 pm
Forum: General
Topic: simple firewall question
Replies: 2
Views: 721

Re: simple firewall question

no, because last rule is general, so invalid connections will also be in that rule
by mixig
Mon Jul 15, 2013 6:41 pm
Forum: Scripting
Topic: check port status on another machine
Replies: 0
Views: 715

check port status on another machine

Hi, is there any way how I can check is other machine is listening od specific port? If yes do nothing, if not send an email. WIth netwatch I am monitoring the all machinem but i need to monitor specific services: e.g. with telnet command? step 1 -> system telnet 10.160.250.130 1234 (if port is ok m...
by mixig
Tue Jul 09, 2013 6:45 pm
Forum: General
Topic: RB 1200 temperature
Replies: 0
Views: 439

RB 1200 temperature

Any experience for how long can it works with this temperature? :D
by mixig
Thu Jul 04, 2013 10:24 pm
Forum: General
Topic: ping problem
Replies: 10
Views: 1999

Re: ping problem

First solved issues with ip addressing....
by mixig
Sun Jun 30, 2013 5:50 pm
Forum: General
Topic: Firewall filter content
Replies: 9
Views: 7337

Re: Firewall filter content

I added addresses list "Facebokk" and block everything with destination address list, every month or two i go and check is there any new subnet : http://bgp.he.net/search?search[search]=facebook&commit=Search /ip firewall address-list add address=74.119.76.0/22 disabled=no list=Facebook add address=...
by mixig
Fri Jun 28, 2013 9:42 am
Forum: General
Topic: Accessing internal IPs after connecting via VPN
Replies: 2
Views: 762

Re: Accessing internal IPs after connecting via VPN

Go to your LAN interface (192.168.88.0/24) and search ARP then select proxy-arp
by mixig
Wed Jun 19, 2013 12:27 pm
Forum: General
Topic: dst-nat change source ip address
Replies: 1
Views: 3165

dst-nat change source ip address

Hi, is it posssible to to dst nat from outisde to some local ip but with changing public ip address to local, so that device on lan see that packet as not public ip? with classic port forward i must NAT public ip which came to mikrotik to private ip and send to local machine I found that possibilty ...
by mixig
Mon Jun 17, 2013 7:20 pm
Forum: General
Topic: Route all traffic via VPN
Replies: 10
Views: 50314

Re: Route all traffic via VPN

Step one, if you want push public traffic through VPN create three address list (private ip addresses): /ip firewall address-list add address=10.0.0.0/8 disabled=no list="Local subnet" add address=172.16.0.0/12 disabled=no list="Local subnet" add address=192.168.0.0/16 disabled=no list="Local subnet...
by mixig
Fri May 31, 2013 1:10 pm
Forum: General
Topic: How to by pass 1 user or IP in web proxy - RB2011UAS
Replies: 4
Views: 2539

Re: How to by pass 1 user or IP in web proxy - RB2011UAS

do that in ip firewall nat instead ip firewall mangle
by mixig
Fri May 31, 2013 1:09 pm
Forum: General
Topic: How to by pass 1 user or IP in web proxy - RB2011UAS
Replies: 4
Views: 2539

Re: How to by pass 1 user or IP in web proxy - RB2011UAS

example:

/ip firewall mangle
add action=accept chain=prerouting disabled=no in-interface=ether1-LAN src-address=192.168.0.100

change in-interface=your lan interface
change ip address

put that rule at athe top of the mangle
by mixig
Thu May 16, 2013 4:45 pm
Forum: Beginner Basics
Topic: 2 WAN interfaces
Replies: 2
Views: 950

Re: 2 WAN interfaces

by mixig
Tue Apr 30, 2013 7:35 pm
Forum: General
Topic: need helpe
Replies: 3
Views: 613

Re: need helpe

by mixig
Tue Apr 30, 2013 7:30 pm
Forum: General
Topic: IPsec site-to-site VPN
Replies: 1
Views: 660

Re: IPsec site-to-site VPN

Try with this link:

http://gregsowell.com/?p=1290
by mixig
Wed Apr 17, 2013 9:09 pm
Forum: Beginner Basics
Topic: Redirect HTTP traffic
Replies: 3
Views: 1025

Re: Redirect HTTP traffic

Does traffic is passing through that rule (look at the counter on the right side od the rule) Also does you Mikrotik know how to get to proxy cache? Do you see any traffic on your proxy?
by mixig
Thu Apr 11, 2013 11:42 pm
Forum: General
Topic: WAN with multiple static address; force LAN SUBNET traffic
Replies: 2
Views: 902

Re: WAN with multiple static address; force LAN SUBNET traff

try this:
add action=src-nat chain=srcnat comment="" disabled=no out-interface=WAN_INTERFACE src-address=YOUR_LAN_SUBNET to-addresses=YOUR PUBLIC_IP
by mixig
Thu Apr 11, 2013 9:50 pm
Forum: General
Topic: RB2011UAS
Replies: 5
Views: 996

Re: RB2011UAS

by mixig
Wed Apr 03, 2013 12:10 pm
Forum: General
Topic: Multiple L2TP IPsec Users
Replies: 1
Views: 1190

Re: Multiple L2TP IPsec Users

From presentatio: http://mum.mikrotik.com/presentations/HR13/kirnak.pdf

You can not have more then one 0.0.0.0/0 peer. If you configure multiple, only one will work.
–Use certificates to solve problems with one PSK for all peers.
by mixig
Wed Apr 03, 2013 11:28 am
Forum: General
Topic: IPSEC / Nat issue
Replies: 3
Views: 2403

Re: IPSEC / Nat issue

IPSec traffic must be excluded from NAT (masquerade), can you please also put ipsec configuration here?
by mixig
Mon Apr 01, 2013 7:56 pm
Forum: Beginner Basics
Topic: RB2011L level 4 - blocking the connections between networks
Replies: 1
Views: 1084

Re: RB2011L level 4 - blocking the connections between netwo

check this settings, if that option is not enabled you firewall rules will not work for bridged traffic
by mixig
Mon Apr 01, 2013 7:49 pm
Forum: Beginner Basics
Topic: VPN Problem
Replies: 8
Views: 3187

Re: VPN Problem

Maybe firewall issue?
by mixig
Thu Mar 28, 2013 4:54 pm
Forum: Beginner Basics
Topic: Newbie questions
Replies: 1
Views: 636

Re: Newbie questions

by mixig
Thu Mar 28, 2013 4:53 pm
Forum: Beginner Basics
Topic: Newbie Questions
Replies: 4
Views: 1039

Re: Newbie Questions

All routerboards have the same RouterOS so they all have the same features, you can take 750/751/951/450, they all have 5 eth ports + wlan interface (except 450 which doesnt have WLAN)...
by mixig
Thu Mar 28, 2013 4:44 pm
Forum: Beginner Basics
Topic: RB450 DHCP + AP = only one wireless client.
Replies: 2
Views: 720

Re: RB450 DHCP + AP = only one wireless client.

Check is the mode on wireless interface set to "ap-bridge"
by mixig
Thu Mar 28, 2013 9:50 am
Forum: Beginner Basics
Topic: Cannot Ping outside of LAN
Replies: 10
Views: 6444

Re: Cannot Ping outside of LAN

go to IP-Routes:

0.0.0.0/0
select your g1 interface to be gateway
by mixig
Wed Mar 27, 2013 11:20 pm
Forum: Beginner Basics
Topic: No access to LAN over PPTP VPN
Replies: 5
Views: 14980

Re: No access to LAN over PPTP VPN

could you post your firewall configuration?
by mixig
Wed Mar 27, 2013 10:11 pm
Forum: Beginner Basics
Topic: Dual Wan IP Addressess
Replies: 2
Views: 1133

Re: Dual Wan IP Addressess

if you have more than one ip address on port you may have trouble with traffic from outside because of the preferred source.. you will need to do some mangling

http://forum.mikrotik.com/viewtopic.php?f=2&t=71173
by mixig
Wed Mar 27, 2013 10:06 pm
Forum: Beginner Basics
Topic: Cannot Ping outside of LAN
Replies: 10
Views: 6444

Re: Cannot Ping outside of LAN

do you have default route in your routing table??? is your gateway to outside g1 interface?
by mixig
Wed Mar 27, 2013 9:53 pm
Forum: General
Topic: Block PC to access another device in LAN
Replies: 4
Views: 8102

Re: Block PC to access another device in LAN

Hi, if you are using bridge there are 2 ways, on bridge port you can enable IP firewall so with that you can block traffic between that two devices (forward chain), or you can use horizon under the ports which are in the bridge (devices which are on the ports with the same horizon number CAN NOT com...
by mixig
Wed Mar 27, 2013 7:51 pm
Forum: Beginner Basics
Topic: Triple Wan - Dual DHCP, default routes
Replies: 2
Views: 1102

Re: Triple Wan - Dual DHCP, default routes

for 3G modem in firewall nat section you can put source nat only for DHCP1 LAN, so DHCP2 address will not get to the internet (it will but the internt would not work), or you can block them in firewall (better solution), src add=LAN_DHCP2 out. interface = 3g modem and also src add=LAN_DHCP2 out. int...
by mixig
Wed Mar 27, 2013 3:42 pm
Forum: General
Topic: Images not showing when using webproxy
Replies: 1
Views: 632

Re: Images not showing when using webproxy

Do you have some rules like this in web proxy:

/ip proxy access
add path=*.jpg action=deny
add path=*.jpeg action=deny
add path=*.png action=deny
add path=*.gif action=deny
?
by mixig
Mon Mar 25, 2013 1:50 pm
Forum: General
Topic: IPSec VPN Tunnel between RG750G and ASA5520
Replies: 3
Views: 1367

Re: IPSec VPN Tunnel between RG750G and ASA5520

Maybe this video will help:

http://gregsowell.com/?p=1290
by mixig
Mon Mar 25, 2013 9:54 am
Forum: General
Topic: VRRP with VLANs
Replies: 4
Views: 1317

Re: VRRP with VLANs

Just to confirm... working very nice :)
by mixig
Mon Mar 25, 2013 9:44 am
Forum: General
Topic: Block PC to access another device in LAN
Replies: 4
Views: 8102

Re: Block PC to access another device in LAN

They are in the same subnet so traffic between is not passing through the Mikrotik, you can configure bridge on Mikrotik, with that you can accomplish your task
by mixig
Sun Mar 24, 2013 8:15 pm
Forum: Beginner Basics
Topic: Mikrotik RB750 can't access Internet
Replies: 5
Views: 1455

Re: Mikrotik RB750 can't access Internet

in winbox: new terminal-> ip route export

paste routing table here...
by mixig
Sun Mar 24, 2013 9:04 am
Forum: Beginner Basics
Topic: Mikrotik RB750 can't access Internet
Replies: 5
Views: 1455

Re: Mikrotik RB750 can't access Internet

Do you have default route in your routing table?
by mixig
Sat Mar 23, 2013 10:00 pm
Forum: Beginner Basics
Topic: RB2011L-IN - Dual WAN Connections?
Replies: 1
Views: 881

Re: RB2011L-IN - Dual WAN Connections?

All ports are just a regular ports.. there is no WAN or LAN ports, you can use any port for LAN or WAN
by mixig
Thu Mar 21, 2013 11:00 pm
Forum: Beginner Basics
Topic: WLAN problem on RB751U-2HnD
Replies: 3
Views: 701

Re: WLAN problem on RB751U-2HnD

you can post firewall settings from mikrotik here... but did you try turning off thr firewall on that devices (windows OS ?)
by mixig
Thu Mar 21, 2013 8:59 pm
Forum: Beginner Basics
Topic: Port forwarding on Load balancing
Replies: 3
Views: 836

Re: Port forwarding on Load balancing

Hi, you can do routing mark for that server (marking by local ip address of that server), and create default route for that marked traffic to go outside through one of your links, and create destination nat -> evertything which came on that particular link from outisde by port "xy" forward that traf...
by mixig
Thu Mar 21, 2013 8:44 pm
Forum: General
Topic: CCR rc10 pptp
Replies: 2
Views: 1232

Re: CCR rc10 pptp

by mixig
Tue Mar 19, 2013 11:09 pm
Forum: General
Topic: UTM
Replies: 1
Views: 1965

Re: UTM

IMO it will never happen...
by mixig
Mon Mar 18, 2013 3:18 pm
Forum: General
Topic: How to winbox more than one router over the internet?
Replies: 3
Views: 735

Re: How to winbox more than one router over the internet?

Thanks for your reply. How do I go about setting up a VPN connection for this?
Mikrotik has few solutions for VPN, take a look on http://wiki.mikrotik.com/wiki/Manual:TOC (L2tp/ispec, pptp, sstp, open VPN)...
by mixig
Sun Mar 17, 2013 8:29 pm
Forum: General
Topic: How to enable wireless on RB951-2n
Replies: 3
Views: 2683

Re: How to enable wireless on RB951-2n

I've never needed to use the wireless feature on the RB951-2N router board i purchased. but now my dLink will be going offline and so i want to use the wireless feature for a couple of days. when i activate the wireless, it bradcasts the SSID alright but i can't get any machine to connect to it sin...
by mixig
Sun Mar 17, 2013 8:23 pm
Forum: General
Topic: VRRP with VLANs
Replies: 4
Views: 1317

Re: VRRP with VLANs

VRRP and Vlans work perfectly.
Just don't forget to put an ip address on the VRRP interface and on the physical interfaces (vlan xx) as well.

Thanks...
by mixig
Sun Mar 17, 2013 12:09 pm
Forum: General
Topic: VRRP with VLANs
Replies: 4
Views: 1317

VRRP with VLANs

Hi,

i read old topics and documentation which said taht vrrp doesnt work with vlan interfaces (v2.9/3.0). Is this fixed in version 5.x/6.x?

I will have trunk between mikrotik and cisco switch...

Thanks
by mixig
Tue Mar 05, 2013 8:35 pm
Forum: General
Topic: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)
Replies: 10
Views: 4841

Re: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)

you also have ip address on eth2 and wlan?????? they are in bridge, try remove that ip addresses... your nar rule says masquarade src address 172.20.0./24 and you have 172.18/172.19 on eth2 and wlan
by mixig
Tue Mar 05, 2013 8:32 pm
Forum: General
Topic: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)
Replies: 10
Views: 4841

Re: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)

from your computer try ping: www.google.com and 4.2.2.2 also from mikrotik too
by mixig
Tue Mar 05, 2013 6:37 pm
Forum: General
Topic: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)
Replies: 10
Views: 4841

Re: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)

you can try ping your default gateway (ISP side) from mikrotik
by mixig
Tue Mar 05, 2013 4:08 pm
Forum: General
Topic: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)
Replies: 10
Views: 4841

Re: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)

Do you have default route on mikrotik which is pointing to your ISP?
by mixig
Tue Mar 05, 2013 12:50 pm
Forum: General
Topic: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)
Replies: 10
Views: 4841

Re: 1 wan 2 LAN (wan dhcp ip assigned to LAN devices)

Do not bridge WAN and LAN ports together, your WAN interface is dhcp client and it gets public ip from your ISP. After that you create bridge interface and put eth2, eth3 and wlan to that bridge interface, put the ip addres to BRIDGE interface from subnet 172.20.0.0/24, enable dhcp server for BRIDGE...
by mixig
Mon Mar 04, 2013 2:23 pm
Forum: General
Topic: IPSec Tunnel not working
Replies: 7
Views: 2079

Re: IPSec Tunnel not working

Also alow UDP 500 on your firewall (input chain), be sure that your nat rule for local networks are above the masquerade rule in ip firewall nat
by mixig
Sat Feb 23, 2013 12:26 am
Forum: Beginner Basics
Topic: vpn not seeing other computers
Replies: 6
Views: 1428

Re: vpn not seeing other computers

L2TP does not require IPSec, IPSec is used to encrypt the traffic
by mixig
Sat Feb 16, 2013 9:15 am
Forum: General
Topic: Which model to select?
Replies: 2
Views: 627

Re: Which model to select?

For central site I'll suggest 1100AHx2: 50$ difference is not so much if you have 70 remote locations. will be pratical not in used... on remote locations will be 1-2 phones.. I don't understand well... you mean there will be little traffic? Sure I'ts true, but don't forget to prioritize it. yes, t...
by mixig
Fri Feb 15, 2013 10:12 pm
Forum: General
Topic: Which model to select?
Replies: 2
Views: 627

Which model to select?

Hi, 1 central location + 60-70 remote locations... all remote locations will have 2 PPTP tunnels to the central MKT (arround 120-140 PPTP tunnels on central MKT), half of that tunnels are for voip and there will be pratical not in used... on remote locations will be 1-2 phones.. other half of the tu...
by mixig
Thu Jan 31, 2013 7:45 pm
Forum: Beginner Basics
Topic: how to set QOS on RB750
Replies: 1
Views: 784

Re: how to set QOS on RB750

Router OS is the same for all models, each of them have ability for QoS, check the official mikrotik wiki
by mixig
Wed Jan 30, 2013 11:27 pm
Forum: Beginner Basics
Topic: how to redirect http traffic to another gateway on Mikrotik
Replies: 10
Views: 8749

Re: how to redirect http traffic to another gateway on Mikro

ok, first thing, your wan2 has wrong gateway, it`s not in the same network as your wan2 interface...
by mixig
Tue Jan 29, 2013 3:02 pm
Forum: Beginner Basics
Topic: how to redirect http traffic to another gateway on Mikrotik
Replies: 10
Views: 8749

Re: how to redirect http traffic to another gateway on Mikro

ip firewall mangle export

ip route export

copy/pase the config
by mixig
Mon Jan 28, 2013 10:31 pm
Forum: Beginner Basics
Topic: Firewall configuring
Replies: 2
Views: 739

Re: Firewall configuring

The best way is prevent duplicate mac address at the start-> managed switches with port security is the best option
by mixig
Mon Jan 28, 2013 10:18 pm
Forum: General
Topic: marking connections and packets
Replies: 2
Views: 493

Re: marking connections and packets

A connection mark is a mark that is automatically applied to all packets of a connection. You mark the connection on one packet, and all other packets in the same connection will have the same mark. Packet marks only are applied to one packet, and do not propagate to other packets in the same connec...
by mixig
Mon Jan 28, 2013 10:14 pm
Forum: General
Topic: PCC - Src-Address method.
Replies: 2
Views: 2396

Re: PCC - Src-Address method.

I am using PCC with source address method (about 100 users), it`s not the best method but it works, before that i used src and dst address but there were problems with https/internet banking... with src method more then a year everything is working normally, not 50:50 ratio but ok for me (I enabled ...
by mixig
Mon Jan 28, 2013 9:57 pm
Forum: Beginner Basics
Topic: how to redirect http traffic to another gateway on Mikrotik
Replies: 10
Views: 8749

Re: how to redirect http traffic to another gateway on Mikro

you can see in torch, or you can open the browser and go to www.whatismyip.com

if your address is ip address from WAN2 then it works
by mixig
Sun Jan 27, 2013 11:42 am
Forum: Beginner Basics
Topic: how to redirect http traffic to another gateway on Mikrotik
Replies: 10
Views: 8749

Re: how to redirect http traffic to another gateway on Mikro

Hi, if I understood you have two wan ports on MKT (WAN1, WAN2), WAN1 is default route in our scenario, WAN2 will be used for HTTP traffic which will be coming from local computers. 1) we must mark web traffic which is coming to mikrotik (ip firewall mangle)- put that rule on the top of the mangle (c...
by mixig
Wed Jan 23, 2013 9:11 pm
Forum: General
Topic: DHCP Options
Replies: 1
Views: 470

Re: DHCP Options

My example:

/ip dhcp-server option
add code=66 name=option66 value=http://192.168.0.56/


/ip dhcp-server network
add address=192.168.1.0/24 comment="" dhcp-option=option66 dns-server=4.2.2.2,8.8.8.8 gateway=192.168.1.1
by mixig
Mon Jan 21, 2013 3:49 pm
Forum: Beginner Basics
Topic: VoIP problems
Replies: 4
Views: 1613

Re: VoIP problems

Usual problem when we are having SIP/RTP and NAT in the same story. I will start the packet sniffer on mikrotik: Packet sniffer settings->select proper interface, Streaming: ip of local computer which has Wireshark. Then start the wireshark (select proper interface), then start packet sniffer Now wh...
by mixig
Mon Jan 21, 2013 2:42 pm
Forum: General
Topic: CPU load
Replies: 2
Views: 591

Re: CPU load

by mixig
Mon Jan 21, 2013 9:49 am
Forum: Beginner Basics
Topic: Creating groups of address lists
Replies: 4
Views: 3756

Re: Creating groups of address lists

Hi,

after you create address list you can configure only one rule for those servers
by mixig
Sun Jan 20, 2013 1:13 pm
Forum: General
Topic: Mark traffic on wan interface
Replies: 8
Views: 1601

Re: Mark traffic on wan interface

What i ask post above is, when local traffic is going through the internet (there isnt any marking, not using PCC), traffic will go through WAN3 (pppoe-defulat route), but one of the server is mail server and it must be use WAN2 as his default gateway. Mark routing in mangle will do the trick? mangl...
by mixig
Sun Jan 20, 2013 12:37 pm
Forum: General
Topic: Mark traffic on wan interface
Replies: 8
Views: 1601

Re: Mark traffic on wan interface

Hi, i follow the example and it seems that everything is working fine now, thanks :) Just one thing, i will have mail server in LAN at it must be bind with WAN2 ip address (because mx record, srv record), it will be enough to put one rule on the top of the mangle? src-address=ip_of_mail_server src-p...
by mixig
Sun Jan 20, 2013 3:18 am
Forum: General
Topic: cant get dual WAN to work with proxy
Replies: 6
Views: 2225

Re: cant get dual WAN to work with proxy

On further playing around it looks like the Web Proxy strips the routing mark. If I add an additional gateway that does not have a routing mark, browsing then works again through that gateway. Is there a way I can force traffic from the proxy to another gateway, while not forcing the rest of the tr...
by mixig
Sun Jan 20, 2013 3:14 am
Forum: General
Topic: Transparent proxy with Squid.
Replies: 5
Views: 1566

Re: Transparent proxy with Squid.

in your rule you have disabled=yes mistake?
by mixig
Sat Jan 19, 2013 5:28 pm
Forum: General
Topic: Mark traffic on wan interface
Replies: 8
Views: 1601

Re: Mark traffic on wan interface

picture in the attach
by mixig
Sat Jan 19, 2013 5:13 pm
Forum: General
Topic: Mark traffic on wan interface
Replies: 8
Views: 1601

Re: Mark traffic on wan interface

Hi, thanks for the reply i already take a look your link, i see that that example is using PCC for marking local trafiic, which will load balancing local traffic through two links. in my situation i need that all local traffic is go outisde through WAN3 (pppoe), no need for PCC (i think), only traff...
by mixig
Sat Jan 19, 2013 11:07 am
Forum: General
Topic: Mark traffic on wan interface
Replies: 8
Views: 1601

Re: Mark traffic on wan interface

I alos try this

http://home.swkls.org/mikrotik-dual-wan ... cket-flow/

but device which i want reach (dst-nat) doesnt work, its working only if traffic is for mikrotik, not some forward to local device behind it
by mixig
Sat Jan 19, 2013 10:48 am
Forum: General
Topic: Mark traffic on wan interface
Replies: 8
Views: 1601

Mark traffic on wan interface

Hi, i have wan links on mirkotik, two links with static ip, and the third is pppoe (dynamic ip), default route is over pppoe. what i want is when something came to mirkotik on WAN1 or WAN2 i want that that traffic is going back the same side its came. i did some mangle and routing mark, nad when i c...
by mixig
Tue Jan 15, 2013 3:54 pm
Forum: Beginner Basics
Topic: Port forwarding not working for me on RB411 / 6.0
Replies: 6
Views: 1172

Re: Port forwarding not working for me on RB411 / 6.0

When you are trying 3389 from outside to your routerboard, in firewall/nat on mikrotik do you see on your dst rule for 3389 that the counter is growing? if not traffic is not coming to your mikrotik (also you said that in torch there is no that traffic)
by mixig
Mon Jan 14, 2013 4:47 pm
Forum: General
Topic: how to block certain sites
Replies: 6
Views: 903

Re: how to block certain sites

by mixig
Fri Jan 11, 2013 2:13 pm
Forum: SwOS
Topic: Swos download section
Replies: 0
Views: 2028

Swos download section

There is a wrong date...
by mixig
Tue Jan 08, 2013 10:17 pm
Forum: General
Topic: Block IP Range (facebook)
Replies: 13
Views: 19023

Re: Block IP Range (facebook)

Hi Guys, until yesterday this rules were working for me: > add action = accept chain = forward src-address-List = Facebook_allow dst-address = 66.220.1.0/20 > add action = accept chain = forward src-address = Facebook_allow dst-address = 69.63.176.0/20 > add action = accept chain = forward src-addr...
by mixig
Tue Jan 08, 2013 9:57 pm
Forum: General
Topic: Port forwarding not working, please help
Replies: 8
Views: 5806

Re: Port forwarding not working, please help

Does your PC 192.168.88.237 have access to the Internet? Can you for this rule:

chain=dstnat action=dst-nat to-addresses=192.168.88.237 to-ports=3000 protocol=tcp dst-port=3000

add "in-interface = pppoe-out1" and try again
by mixig
Tue Jan 08, 2013 5:01 pm
Forum: General
Topic: Port forwarding not working, please help
Replies: 8
Views: 5806

Re: Port forwarding not working, please help

Counters on that dst-rule in firewall/NAT rule (look the attach, on right side), clear the counters then try telnet from outside and see is your traffic hits that rule, if does that traffic is forwarded to you local ip. Default gateway on that local computer is mikrotik?
by mixig
Tue Jan 08, 2013 2:16 pm
Forum: General
Topic: Port forwarding not working, please help
Replies: 8
Views: 5806

Re: Port forwarding not working, please help

Does the counter on your firewall rule for dst-nat is growing?
by mixig
Tue Jan 08, 2013 9:25 am
Forum: Beginner Basics
Topic: Help with Site to Site VPN
Replies: 9
Views: 6483

Re: Help with Site to Site VPN

What excatly is not working? Did you allow UDP 500 and esp protocol on both side on mkt firewall (input chain)? What the log says (you can turn on ipsec log, System-Logging section)?
by mixig
Mon Jan 07, 2013 8:05 pm
Forum: Beginner Basics
Topic: Two Gateways failover
Replies: 3
Views: 1963

Re: Two Gateways failover

if your traffic is marked with routing mark e.g. WAN 1 (subnets 192.168.1.0/24, 192.168.2.0/24), and you have default route which has routing mark WAN1 which has exit over pppoe1 and WAN1 is down, your marked traffic will go outiside automatically through some other default route. Rule says if there...
by mixig
Mon Jan 07, 2013 6:03 pm
Forum: General
Topic: Bandwidth management help
Replies: 3
Views: 675

Re: Bandwidth management help

Well, you can accomplished that with two method, as example is showing, step 1 and step 2 if you are using step 2 you can skip step 1. Why? Because in step one we are marking out interesting traffic. How? By selecting the Interface where we want to do "action". In this case this is LAN interaface, o...
by mixig
Mon Jan 07, 2013 12:25 pm
Forum: General
Topic: Bandwidth management help
Replies: 3
Views: 675

Re: Bandwidth management help

Read this first:
http://wiki.mikrotik.com/wiki/Manual:Queues_-_PCQ

and after that try with this setup (change the subnet when configuring target addresses):
http://wiki.mikrotik.com/wiki/Manual:Qu ... Q_Examples
by mixig
Mon Jan 07, 2013 12:21 pm
Forum: Beginner Basics
Topic: Cant connect to internet with pppoe client
Replies: 15
Views: 8012

Re: Cant connect to internet with pppoe client

Make sure that your masquerad rule is on the top, that firewall is not blocking the traffic (you can export firewall and mangle rules here), try to ping some internet ip address but with src address of the mikrotik lan ip address
by mixig
Mon Jan 07, 2013 11:22 am
Forum: Beginner Basics
Topic: Two Gateways failover
Replies: 3
Views: 1963

Re: Two Gateways failover

In firewall mangle you can marking your voip traffic based on src address or port number , DSCP value, what ever and to that traffic give a routing mark, e.g. routing mark=VOIP. Then in ip->routes create defult route 0.0.0.0/0, routing mark=VOIP. p.s. when creating mangle be sure that rule which is ...
by mixig
Sun Jan 06, 2013 8:29 pm
Forum: Beginner Basics
Topic: mangle rule to bypass load balancing with address list
Replies: 1
Views: 1643

Re: mangle rule to bypass load balancing with address list

Create address list with your local ip addresses that you want exclude from load balancing, then in mangle in prerouting chani put that address list in src address list and put the routing mark, passthrough set to "NO". Also important is that you must put that rule on the top in mangle. Then create ...
by mixig
Sat Jan 05, 2013 11:56 pm
Forum: Beginner Basics
Topic: Very Simple,Functional QoS Setup For Begginers
Replies: 5
Views: 8050

Re: Very Simple,Functional QoS Setup For Begginers

go to tiktube and take a look videos from janis megis from 2009 and 2011 and Valens Riyadi 2009 (HTB, QoS)
by mixig
Sat Jan 05, 2013 11:29 pm
Forum: Beginner Basics
Topic: Very Simple,Functional QoS Setup For Begginers
Replies: 5
Views: 8050

Re: Very Simple,Functional QoS Setup For Begginers

Prioritization without set limits not doing absolutely nothing exept the counter is growing...

so, all that for nothing...
by mixig
Mon Dec 31, 2012 11:57 am
Forum: Beginner Basics
Topic: Reaching only one PC in other subnet
Replies: 15
Views: 3487

Re: Reaching only one PC in other subnet

lan1 and lan2 dont have communication between each other (i assume firewall is blocking that traffic), add this rules before that rule which is blocking LAN1 and LAN2: /ip firewall filter add action=accept chain=forward comment="" disabled=no dst-address=10.10.10.5 src-address=192.168.149.112 add ac...
by mixig
Sun Dec 30, 2012 1:08 pm
Forum: General
Topic: What is the best Load Balancing in my case
Replies: 3
Views: 948

Re: What is the best Load Balancing in my case

i think it will be better if not using NAT on mikrotik and put the 192.168.1.0/24 is coming to upstream router, you can get better load balancing. Right now you are doing LB whit which parameters, dst address, port numbers? i am using src address for LB, it is not pure and equal but with another par...
by mixig
Sun Dec 30, 2012 11:48 am
Forum: Beginner Basics
Topic: Mikrotik L2TP IPSEC Client
Replies: 3
Views: 15763

Re: Mikrotik L2TP IPSEC Client

is there any example / tutorial for /ip Ipsec setting?
is it possible to connect mikrotik client to windows server (ipsec configured on win server).?
tnx for reply
L2TP/IPSec
http://gregsowell.com/?p=4389

IPSec
http://gregsowell.com/?p=1290
by mixig
Fri Dec 28, 2012 11:01 am
Forum: Beginner Basics
Topic: about subnet and range
Replies: 6
Views: 2119

Re: about subnet and range

hello :- ihave proplem in subnet (/?) i try more and more but i can`t understand as example ihave range x.x.x.5-x.x.x.10 what subnet i must put and why ? anyone have topic or something give me it i search about it but didn`t found this thing I assume that x.x.x.5-x.x.x10 are usable ip addresses, wi...
by mixig
Wed Dec 26, 2012 11:12 am
Forum: Beginner Basics
Topic: SXT CPE 169.254.x.x
Replies: 2
Views: 983

Re: SXT CPE 169.254.x.x

Hi,
if you put ip address manually? Is there connectivity then?

169.254.x.x is APIPA, dhcp server works?
by mixig
Sat Dec 22, 2012 11:39 am
Forum: Beginner Basics
Topic: PPTP Client not pingable
Replies: 1
Views: 544

Re: PPTP Client not pingable

Maybe your ISP is blocking ICMP traffic, if not check your firewall on 2011 (input chain)
by mixig
Thu Dec 20, 2012 11:49 am
Forum: Beginner Basics
Topic: Dual WAN - DNS not resolve
Replies: 10
Views: 4928

Re: Dual WAN - DNS not resolve

Hi, in your routing table you have two default routes, each route is default route for packets that has routing mark (my, and small), wehn your are pinging from mikrotik that ping packet doesnt have routing mark because it is not defined in the mangle (mikrotik address is not in you src address list...
by mixig
Wed Dec 19, 2012 3:11 pm
Forum: Beginner Basics
Topic: Dual WAN - DNS not resolve
Replies: 10
Views: 4928

Re: Dual WAN - DNS not resolve

Just for test, in firewall put the output and input chain allow
by mixig
Tue Dec 18, 2012 9:18 pm
Forum: Beginner Basics
Topic: Dual WAN - DNS not resolve
Replies: 10
Views: 4928

Re: Dual WAN - DNS not resolve

put the some public dns servers on mikrotik and/or on your PC˙s
by mixig
Thu Dec 13, 2012 3:57 pm
Forum: Beginner Basics
Topic: users cant get internet easy
Replies: 1
Views: 531

Re: users cant get internet easy

you have installed router os on pc? what is the CPU usage? what is your link bandwith? Is your link out of free bandwith?
by mixig
Mon Dec 10, 2012 11:35 pm
Forum: Beginner Basics
Topic: Copy Address Entrys to Second Router
Replies: 7
Views: 2725

Re: Copy Address Entrys to Second Router

i am not familiar with scripting can anyone help me out.
Try to ask here:
http://forum.mikrotik.com/viewforum.php?f=9
by mixig
Wed Dec 05, 2012 10:35 pm
Forum: Beginner Basics
Topic: Connect two Subnets / two internet providers, one fileserver
Replies: 3
Views: 861

Re: Connect two Subnets / two internet providers, one filese

your cisco and mikrotik are connected through switch, there is no layer 3 connectivity, cisco is on one subnet and mikrotik on another subnet but they need to be connected somehow...
by mixig
Wed Dec 05, 2012 10:32 pm
Forum: General
Topic: SIP protocol: I am not able to let it work.
Replies: 9
Views: 2864

Re: SIP protocol: I am not able to let it work.

Could you try with this command:

ip firewall service-port set sip ports=5060,5061 disabled=yes
by mixig
Wed Dec 05, 2012 4:01 pm
Forum: Beginner Basics
Topic: Connect two Subnets / two internet providers, one fileserver
Replies: 3
Views: 861

Re: Connect two Subnets / two internet providers, one filese

It seems that your link is broken
by mixig
Sun Dec 02, 2012 10:45 pm
Forum: Beginner Basics
Topic: firewal mark packet to simple queue
Replies: 3
Views: 2088

Re: firewal mark packet to simple queue

Hi All, I am new to RouterOS, actually just got RB2011 (5.21) as my SOHO gateway. I was experimenting with marking packets by firewall: [admin@Border1] > /ip firewall mangle print Flags: X - disabled, I - invalid, D - dynamic 0 chain=prerouting action=mark-packet new-packet-mark=voip-sip passthroug...
by mixig
Sun Dec 02, 2012 9:33 pm
Forum: General
Topic: Link aggregation of ports to increase bandwidth
Replies: 2
Views: 1897

Re: Link aggregation of ports to increase bandwidth

I have a managed L2 switch, and currently running a 802.1Q trunk (with about 6 VLANs on this) between the switch and Mikrotik's port number 10. I would like to increase bandwidth between the switch and Mikrotik, but still have VLANs. Any advice on how can I do this please? Create bonding interface ...
by mixig
Thu Nov 29, 2012 9:26 pm
Forum: General
Topic: Mikrotik Graphs
Replies: 1
Views: 656

Re: Mikrotik Graphs

only security what i know is to setup ip address or subnet which will be allowed to access to web server/graphs
by mixig
Sun Nov 25, 2012 11:23 pm
Forum: General
Topic: Panasonic SIP working with Mikrotik VPN
Replies: 3
Views: 1681

Re: Panasonic SIP working with Mikrotik VPN

it is works without any problem, on the remote side try to install some softphone on PC on the subnet where is panasonic phone right now (but reading the post once again pc and phone are on the same subnet?) and start the wireshark.. you will see what is happeing with SIP REGISTAR mesage.. also on s...
by mixig
Sun Nov 25, 2012 10:34 pm
Forum: General
Topic: 2 LAN and 2 WAN
Replies: 4
Views: 2647

Re: 2 LAN and 2 WAN

your LAN subnets will be marked in mangle with wan1 and wan2 because you are mangleing only by source address, so when mirkotik need to decide where to route the traffic it will look into the routnig table and search the right routing mark, and it will pass to wan1 or wan2... you must exclude traffi...
by mixig
Sun Nov 25, 2012 10:24 pm
Forum: General
Topic: SIP protocol: I am not able to let it work.
Replies: 9
Views: 2864

Re: SIP protocol: I am not able to let it work.

i would try to figure out where is a problem with wireshark, first yu can install softphone on PC behind 2011 MKT and see what is happening, after that run packet sniffer on mkt which will sent you a copy of traffic to your PC which has wireshark... After that try to see where is the problem
by mixig
Sun Nov 25, 2012 10:19 pm
Forum: Beginner Basics
Topic: Route specific IP address ranges through either WAN1 or 2
Replies: 8
Views: 4004

Re: Route specific IP address ranges through either WAN1 or

no i am just guessing, so traffic is passing through that rule, passthrough is set to no, so traffic is not moving through the manlge, it get to the routing decision... you get timeout... i would say dns is the problem (second provider is using another dns then first provider) but i see that you are...
by mixig
Sun Nov 25, 2012 3:22 pm
Forum: Beginner Basics
Topic: Route specific IP address ranges through either WAN1 or 2
Replies: 8
Views: 4004

Re: Route specific IP address ranges through either WAN1 or

add action=mark-routing chain=prerouting comment="Forced Test Route To WAN2" disabled=no dst-address-list=TEST \
    new-routing-mark=SMALLNETBLDER passthrough=no src-address=192.168.68.0/24
Does this rule has matching traffic, does the counter is growing?
by mixig
Sat Nov 24, 2012 2:45 pm
Forum: General
Topic: Timed Proxy Server
Replies: 2
Views: 824

Re: Timed Proxy Server

Hi, ip firewall nat rule where you redirecting web traffic to web proxy under the Extra tab you can put time when this rule be active, you can put in your case 8-5pm monday-friday, so the rule will be always in your config but it will be active only for the time you specified, when it is inactive yo...
by mixig
Sat Nov 24, 2012 1:24 pm
Forum: Beginner Basics
Topic: Route traffic to one IP through specific gateway
Replies: 6
Views: 17364

Re: Route traffic to one IP through specific gateway

in your mangle put at the top this: add action=accept chain=prerouting disabled=no dst-address=92.11.11.200 With the command above you will exclude traffic designated for that address from the PCC, it will just pass through the mangle without adding and mark... and then put static route for that ip ...
by mixig
Sat Nov 17, 2012 1:25 pm
Forum: Beginner Basics
Topic: Allow some users for complete internet access
Replies: 11
Views: 2226

Re: Allow some users for complete internet access

[admin@MikroTik] > ip proxy access print Flags: X - disabled # DST-PORT DST-HOST PATH METHOD ACTION HITS 0 www.facebook.com, www.yahoo.com deny 0 1 www.youtube.com deny 0 it does`t put any syntax error when putting multiple dst.host, just try and see is it working...
by mixig
Fri Nov 16, 2012 12:37 pm
Forum: Beginner Basics
Topic: IP TUNNEL
Replies: 3
Views: 1237

Re: IP TUNNEL

From wiki: GRE the same as IPIP and EoIP were originally developed as stateless tunnels. Meaning that if remote end of the tunnels goes down all traffic that was routed over the tunnels gets blackholed. To solve this problem RouterOS have added keepalive feature for GRE tunnels. You could try with g...
by mixig
Mon Nov 12, 2012 11:28 am
Forum: Beginner Basics
Topic: pptp source address
Replies: 1
Views: 832

pptp source address

Hi, pptp vpn between two mikrotik. server mirkotik has 172.16.10.1 for pptp interface and pptp client mirkotik has 172.16.10.2. On server side there is a netwrok 192.168.100/24 and on the clinet side is 192.168.200.0/24. Static routes are added to route traffic for remote network through pptp tunnel...
by mixig
Sun Nov 11, 2012 4:37 pm
Forum: Beginner Basics
Topic: Understanding IPSec VPN. Send initial contact or no?
Replies: 22
Views: 7797

Re: Understanding IPSec VPN. Send initial contact or no?

create static route on each mkt for remote network, or put default route (your wan interface), right now your router doesn t know where to send packet for remote network (in routing table you have only directly connected networks)
by mixig
Sat Nov 10, 2012 12:48 pm
Forum: General
Topic: SIP Issue
Replies: 2
Views: 735

Re: SIP Issue

Are you using some PBX behind the NAT? or you are just using some sip account on your pc-softphone or something... if you are using pbx you must do static nat on your router, 5060 (SIP) and udp for RTP. input chain allowed udp what you did it is not needed because voip traffic must pass through the ...
by mixig
Sat Nov 10, 2012 12:38 pm
Forum: Beginner Basics
Topic: Allow some users for complete internet access
Replies: 11
Views: 2226

Re: Allow some users for complete internet access

I cannot see any allow rule in there.

Create the required allow rule and place it ahead of the facebook deny rule.
The image above is just help for Latif123 , it is my web proxy not his :)
by mixig
Sat Nov 10, 2012 9:46 am
Forum: Beginner Basics
Topic: Allow some users for complete internet access
Replies: 11
Views: 2226

Re: Allow some users for complete internet access

Dear ,

I am sorry, I dont understand (/ip proxy access print) command. Could you please guide me in slight simple way ,

I know the /ip proxy access command. but dont now ( print) command.
by mixig
Wed Nov 07, 2012 7:22 pm
Forum: Beginner Basics
Topic: How to insert new line in log files?
Replies: 2
Views: 1048

Re: How to insert new line in log files?

Hi,

can you try to open log file with notepad++. Windows notepad doesn`t display unix newline
by mixig
Mon Nov 05, 2012 9:54 pm
Forum: Beginner Basics
Topic: VPN help
Replies: 5
Views: 1169

Re: VPN help

End of course this video below:

http://gregsowell.com/?p=1290 :D
by mixig
Mon Nov 05, 2012 9:51 pm
Forum: Beginner Basics
Topic: Default Route Interface
Replies: 6
Views: 1236

Re: Default Route Interface

what is on ethernet 1? maybe you get default route from antoher side of eth1, maybe ether 2 is not running yet after reboot... do ip route print and c/p
by mixig
Mon Nov 05, 2012 9:44 pm
Forum: General
Topic: Bandwidth shapping problem
Replies: 1
Views: 484

Re: Bandwidth shapping problem

Does ether 2 has two ip addresses? local and public? can you put some topology?
by mixig
Mon Nov 05, 2012 9:06 pm
Forum: General
Topic: Excluding one IP from PCQ Queues
Replies: 2
Views: 3032

Re: Excluding one IP from PCQ Queues

hi,

you can do two rules in mangle, first for ip that you want exclude (passthrough=no, action accept), then second rule your all subnet, so basically your excluded ip will never reach the second rule if you set passthrough=no on the first rule
by mixig
Thu Nov 01, 2012 1:03 pm
Forum: General
Topic: PPPoE Client problem (some pages are slow)
Replies: 4
Views: 2125

Re: PPPoE Client problem (some pages are slow)

sry, which router do you mean?

the mikrotik or adsl router one?

Connect your PC directly to your adsl router, and than ping the same pages, what are the results?
by mixig
Thu Nov 01, 2012 12:56 pm
Forum: General
Topic: Limiting users download speed after certain cap is reached
Replies: 2
Views: 953

Re: Limiting users download speed after certain cap is reach

http://www.tiktube.com/video/mJeK3iHGhLKLIKImpnCsFrHvnlIomlpG= http://www.tiktube.com/video/JpcD3eCChqGnDlJFJEEsCvExClIoEKDH= http://www.tiktube.com/video/LGcm3foDdlKIoHImKoHwDulxLlColHEJ= and wiki has some material about that, also there are some good examples, note: use official wiki (http://wiki....
by mixig
Thu Nov 01, 2012 12:51 pm
Forum: General
Topic: Multi WAN load balancing. can't login to some website.
Replies: 1
Views: 737

Re: Multi WAN load balancing. can't login to some website.

Hi, for "Per Connection Classifier" in mangle what do you use? Try to use only src-address, so you will always go through the same wan interface, hash algorithm will get always the same result. It is not best option for the load balancing but everything will work http://www.tiktube.com/video/GEfq3hC...
by mixig
Thu Nov 01, 2012 12:42 pm
Forum: Beginner Basics
Topic: RouterBoard 750 GL
Replies: 4
Views: 1682

Re: RouterBoard 750 GL

Best way you can do is load balancing

http://www.tiktube.com/video/GEfq3hCljL ... uIlGopKGp=

and pdf from that video is here http://mum.mikrotik.com/presentations/US12/steve.pdf
by mixig
Tue Oct 30, 2012 6:51 pm
Forum: General
Topic: I lose time, date, and graph data when i reboot RB450G
Replies: 3
Views: 1022

Re: I lose time, date, and graph data when i reboot RB450G

For graphing you can choose to save to disk instead memory so after reboot you will still have your data information
by mixig
Tue Oct 30, 2012 5:10 pm
Forum: General
Topic: IPsec site to site problem
Replies: 4
Views: 1389

Re: IPsec site to site problem

I also have one situation mikrotik-mikrotik, and only one side can trigger ipsec tunnel, i also solved that with ping count=x :)
by mixig
Tue Oct 30, 2012 9:22 am
Forum: General
Topic: IPsec site to site problem
Replies: 4
Views: 1389

Re: IPsec site to site problem

Hi,

didi you allow port 500 udp and esp protocol on both mikrotik (input chain)?
by mixig
Mon Oct 29, 2012 11:06 pm
Forum: General
Topic: IPSec Tunnel Creation
Replies: 8
Views: 45293

Re: IPSec Tunnel Creation

Ah I have not. Can I allow it from only the external interfaces of both sites?
yep

I will try it when I get home and let you know how it goes.
ok
by mixig
Mon Oct 29, 2012 10:46 pm
Forum: SwOS
Topic: Ping time very strange - SOLVED
Replies: 5
Views: 3350

Re: Ping time very strange

It should be 0ms, maybe bad cable? Tried with different computer?
by mixig
Mon Oct 29, 2012 10:43 pm
Forum: Beginner Basics
Topic: Route specific IP address ranges through either WAN1 or 2
Replies: 8
Views: 4004

Re: Route specific IP address ranges through either WAN1 or

can you copy/paste mangle and ip route config?
by mixig
Mon Oct 29, 2012 10:31 pm
Forum: General
Topic: Public ip tunnel
Replies: 3
Views: 708

Re: Public ip tunnel

Why are you using public ip addresses in pptp profile? Also when you have ip address for pptp client which is in the same subnet as some port on pptp server you must put proxy-arp under that interface on pptp server. Also if you want to go to internet over the pptp server you can set that option in ...
by mixig
Mon Oct 29, 2012 8:12 pm
Forum: General
Topic: IPSec Tunnel Creation
Replies: 8
Views: 45293

Re: IPSec Tunnel Creation

Hi,

did you allow port 500 udp and esp on both mikrotiks (input chain)?
by mixig
Mon Oct 29, 2012 12:00 pm
Forum: General
Topic: Public ip tunnel
Replies: 3
Views: 708

Re: Public ip tunnel

What exactly is not working? Did you allow PPTP from outside to the router? if not allow tcp port 1723 to the router (input chain).You can use your home rpouter as a clinet and another one as a server because it ha fixed public IP
by mixig
Mon Oct 29, 2012 11:51 am
Forum: General
Topic: SIP TLS problem
Replies: 0
Views: 734

SIP TLS problem

Hi, I have a strange problem with passing SIP TLS through mikrotik. On mikrotik i have bridge port (eth1 and eth2). On that bridge port I have public ip addresses from my provider (/24). Some of them are on the bridge port some of them are on the comupter. One of the public IP addresses are on the V...
by mixig
Mon Oct 29, 2012 9:49 am
Forum: Beginner Basics
Topic: QOS basics
Replies: 1
Views: 750

Re: QOS basics

QoS is locally significant for that router, waht you can do is marking the traffic and do QoS on each router through the packet will pass
by mixig
Mon Oct 29, 2012 9:47 am
Forum: Beginner Basics
Topic: P2P Backbone on hilly terrain
Replies: 6
Views: 1162

Re: P2P Backbone on hilly terrain

Hi,

I am not wireless expert but SXT will solve your problems, you can build transparent wireless links with them... check on tiktube, there is a workshop for point-to-point wireless links with SXT
by mixig
Mon Oct 29, 2012 9:42 am
Forum: Beginner Basics
Topic: need help in simple portforwarding rules
Replies: 2
Views: 825

Re: need help in simple portforwarding rules

Hi,

when you were configured your port forwarding from outside to inside did you add incoming interface (your public interface) for that rule? If no the rule will be global so every traffic for dst port 3389 will forward back to your inside computer.
by mixig
Thu Oct 25, 2012 11:21 pm
Forum: General
Topic: webfig access via public ip
Replies: 25
Views: 42647

Re: webfig access via public ip

@paka

disable http an d www and https command

ip service disable numbers=2,4


http://wiki.mikrotik.com/wiki/Manual:IP/Services
by mixig
Thu Oct 25, 2012 10:57 pm
Forum: General
Topic: Need secure tunnel on existing bridge
Replies: 2
Views: 643

Re: Need secure tunnel on existing bridge

need secure tunnel on existing bridge......

Eoip, gre, ipip totally unsecured.... but gre with ipsec...
by mixig
Thu Oct 25, 2012 10:53 pm
Forum: General
Topic: Move from ECMP to PCC load balancing
Replies: 16
Views: 2925

Re: Move from ECMP to PCC load balancing

yep, need to adjust that passthrough=yes on some places

also check this and you will be ready to go with PCC


http://www.tiktube.com/video/GEfq3hCljL ... uIlGopKGp=

and pdf from that video is here http://mum.mikrotik.com/presentations/US12/steve.pdf
by mixig
Thu Oct 25, 2012 10:49 pm
Forum: General
Topic: Create IPsec VPN secure channel
Replies: 7
Views: 1967

Re: Create IPsec VPN secure channel

in policy you put src-address=152.21.XXX.0/24 and dst-address=152.12.100.1/32 , on the cisco side must be mirror of that... also check proposals again for phase 2 in first post before editing you was talkin about 169.x.x.x networks, in the picture there are 192.168.x.x networks, now in last post ano...
by mixig
Tue Oct 23, 2012 6:14 pm
Forum: General
Topic: VRRP tracking interface
Replies: 4
Views: 3064

Re: VRRP tracking interface

I am on DHCP so i cant ping gateway, script which will be ping outside ip it must always be active and even with that it will not automaticaly low priority (if ping is setup e.g. every 10 sec, and there is an extra overhead on mikrotik) on the master mikrotik. So pppoe status will be good, if it is ...
by mixig
Tue Oct 23, 2012 1:30 pm
Forum: General
Topic: VRRP tracking interface
Replies: 4
Views: 3064

VRRP tracking interface

Hi, two mikrotik routers on the same lan segment, one master, the second one backup, in lan area it`s working how it should be. How to configured mikrotik to low priority if wan interface is done, or if some ip address from the internet is not up (in cisco in hsrp we can do tracking interface using ...
by mixig
Mon Oct 22, 2012 7:07 pm
Forum: General
Topic: Create IPsec VPN secure channel
Replies: 7
Views: 1967

Re: Create IPsec VPN secure channel

Watch this video...

http://gregsowell.com/?p=1290

after that you will know how to setup ipsec :D
by mixig
Mon Oct 22, 2012 7:05 pm
Forum: General
Topic: Deny DHCP to issue the same ip
Replies: 7
Views: 1176

Re: Deny DHCP to issue the same ip

Can you create no-ip or dyndns account and put the script which will update your account with currnet public ip, for that you also need to create schedule. so after that you can you your domain name e.g. xxyyy.no-ip.org and that will be pointing to your public ip, to your mikrotik...
by mixig
Mon Oct 22, 2012 6:58 pm
Forum: Beginner Basics
Topic: RB750G WEBFIG 5.21 need to set STATIC internet connection
Replies: 3
Views: 1126

Re: RB750G WEBFIG 5.21 need to set STATIC internet connectio

Choose one of your lan ports (port 1 e.g.) on mikrotik and put ip address : xx.xx.xx.53, subnet mask is : 255.255.255.248 which is equal /29, so your ip address on mikrotik will be xx.xx.xx.53/29 then go to : IP-Routes add new route and put destination 0.0.0.0/0 , and below put gateway: xx.xx.xx.49 ...
by mixig
Mon Oct 22, 2012 4:38 pm
Forum: General
Topic: Create IPsec VPN secure channel
Replies: 7
Views: 1967

Re: Create IPsec VPN secure channel

Did you allow in input chain protocol 500 and protocol esp on your mikrotik ? your proposal must be mirroring your lan as source another side lan dst address: mkt: src-add 169.24.xxx.0/24 dst-add 169.12.xxx.0/24 also you must exclude that traffic from NAT, put this command on the top of your NAT sec...
by mixig
Fri Oct 19, 2012 2:25 pm
Forum: General
Topic: [SOLVED]PPTP VPN on RB750
Replies: 4
Views: 866

Re: PPTP VPN on RB750

yep, if your lan is on ether3, go to the interface menu and select that interface and change ARP:Enabled to ARP: Proxy-arp
by mixig
Fri Oct 19, 2012 1:46 pm
Forum: General
Topic: [SOLVED]PPTP VPN on RB750
Replies: 4
Views: 866

Re: PPTP VPN on RB750

go to your lan interface and in general tab select ARP: proxy-arp, by default is : Enabled

then try pinging that computer again
by mixig
Thu Oct 18, 2012 11:20 pm
Forum: Beginner Basics
Topic: Remove default bridge so each port is seperate.
Replies: 4
Views: 3924

Re: Remove default bridge so each port is seperate.

ok. Last question. Can you explain to me after i have removed the ports from the bridge and deleted the bridge. How do set up the wireless connection on its own port ? I will be using winbox and i wil be setting up each port so it is independent of the other ports and giving it access thru my modem...
by mixig
Thu Oct 18, 2012 11:15 pm
Forum: General
Topic: access to local mkt when route all traffic to ipsec
Replies: 1
Views: 446

access to local mkt when route all traffic to ipsec

Policy based ipsec, all remote locations are having mkt and they are routing ALL traffic into the ipsec tunnel and traffic is going to the central location. Everything is working but the problem is that i cannot access or ping my mikrotik from local network (remote locations). From central location ...
by mixig
Thu Oct 18, 2012 12:09 pm
Forum: General
Topic: Route based IPSec MKT-Sonicwall
Replies: 3
Views: 1744

Re: Route based IPSec MKT-Sonicwall

I also find this one: Feature/Application: How to Configure a Tunnel Interface VPN (Route-based VPN) between two SonicWALL UTM appliances. Background: The advantages of Tunnel Interface VPN (Route-Based VPN) between two SonicWALL UTM appliances include: 1) the network topology configuration is remov...
by mixig
Thu Oct 18, 2012 12:02 pm
Forum: General
Topic: Route based IPSec MKT-Sonicwall
Replies: 3
Views: 1744

Route based IPSec MKT-Sonicwall

Hi, currently we have policy based ipsec between sonicwall and MKT. Now we want to changed that with route based. Is any of you done this kind of the setup? MKT support gre and ipip and sonicwall in my opinion doesnt support that features, i found only this for sonicwall: Do SonicWALL security appli...
by mixig
Tue Oct 16, 2012 11:52 pm
Forum: General
Topic: All traffic into ipsec
Replies: 0
Views: 356

All traffic into ipsec

Hi, MKT is remote office, the goal is route all users traffic via ipsec to central location. Central location isn`t a MKT and has static public IP. Assume that MKT on remote office has 192.168.10.0/24 network. How does the config is look like for IPsec on that MKT? What would be the src address and ...
by mixig
Mon Oct 15, 2012 11:47 pm
Forum: General
Topic: load balance with 3 different WANs
Replies: 2
Views: 745

Re: load balance with 3 different WANs

yep, you will need to adjust pcc, sent double more traffic via wan1 and wan2 than via wan3 because of the wan bandwith, with that you will create more efficient load balancing here is all that you need http://www.tiktube.com/video/GEfq3hCljLoKpmLEqFGqqsFuIlGopKGp= and pdf from that video is here htt...
by mixig
Sun Oct 14, 2012 6:37 pm
Forum: Beginner Basics
Topic: How to make queues per source/dst ip?
Replies: 3
Views: 1434

Re: How to make queues per source/dst ip?

Hello, We want to use dynamically created(/destroyed) queues per each customer IP for make same bandwith limit for every customer. Unfortunately, such design doesn't work: add limit-at=10M max-limit=50M name=queue-out packet-mark=mark-from-home parent=common-out priority=4 \ queue=queue-type-per-ip...
by mixig
Thu Oct 11, 2012 2:13 pm
Forum: General
Topic: softphone traffic prioritize
Replies: 6
Views: 1440

Re: softphone traffic prioritize

I tried my setup but it seems that it`s not working, please help
by mixig
Thu Oct 11, 2012 12:52 pm
Forum: General
Topic: softphone traffic prioritize
Replies: 6
Views: 1440

Re: softphone traffic prioritize

Hi again, i did something, can someone check my config to see if this is ok? ether1=LAN ether2=WAN x.x.x.x ip address of sip voip provider The goal is to reserve at least 500kbps for voip traffic (for about 5 simultaneous calls) from client to provider and vise versa. Will this code do the trick? If...
by mixig
Wed Oct 10, 2012 2:57 pm
Forum: General
Topic: softphone traffic prioritize
Replies: 6
Views: 1440

Re: softphone traffic prioritize

One more question, if i do mangling, and after queue tree WITHOUT MAX-LIMIT and LIMIT-AT will my mark traffic be prioritize? Janis Megis said in his presentation that if there is no that two thing configured priritize will not work because MKT is not doing prioritize, it must know what is the bandwi...
by mixig
Wed Oct 10, 2012 1:37 pm
Forum: General
Topic: softphone traffic prioritize
Replies: 6
Views: 1440

Re: softphone traffic prioritize

Hi,

can you provide me config of mangle and queue? Instead of DSCP can i prirotize traffic from me to our provider based on dst address? Like for the incoming traffic (src traffic), srd/dst is provider address
by mixig
Wed Oct 10, 2012 1:01 pm
Forum: General
Topic: softphone traffic prioritize
Replies: 6
Views: 1440

softphone traffic prioritize

Hi,

i have few softphones. Each softphone has his own sip account from internet voip provider. we need to prioritize voip traffic in both directions (from softphones to provider sip server and from provider sip server to the softphones). What is the easiest and best way to accomplish this?
by mixig
Fri Sep 28, 2012 11:15 am
Forum: General
Topic: Comment on pppoe interface
Replies: 1
Views: 475

Comment on pppoe interface

Hi,

450G, Router OS 5.11, when i changed comment on pppoe interface my pppoe connection disconnect and after that connect again, why is this happening? Bug?
by mixig
Thu Sep 27, 2012 9:29 pm
Forum: Scripting
Topic: Log pppoe change status
Replies: 1
Views: 3882

Log pppoe change status

Hi,

can someone write down how to monitor status of pppoe interface and log that to a txt file which will be saved on mkt on disk (under the "Files"):

date, time, pppoe-out1 down
date, time, pppoe-out1 up
.
.
.
.

Thanks
by mixig
Wed Sep 05, 2012 10:19 pm
Forum: Beginner Basics
Topic: NAT bypass
Replies: 2
Views: 1003

Re: NAT bypass

Anybody?

Thanks
by mixig
Tue Sep 04, 2012 10:55 am
Forum: Beginner Basics
Topic: NAT bypass
Replies: 2
Views: 1003

NAT bypass

Hi, i have MKT with multiple public IPs. One of them is on my server. I need to bypass nat in both direction, from server to internet and vice versa. On the server under the network setup i have address 89.x.x.150/28 and def. gateway is 89.x.x.146 (that ip is on mkt). As I mentioned I need bypass th...
by mixig
Tue Sep 04, 2012 9:23 am
Forum: Beginner Basics
Topic: Зort forwarding
Replies: 9
Views: 1548

Re: Зort forwarding

try locally, from cmd prompt: telnet 192.168.30.11 5001 and see is it working
by mixig
Mon Sep 03, 2012 8:44 pm
Forum: Beginner Basics
Topic: Зort forwarding
Replies: 9
Views: 1548

Re: Зort forwarding

Hi,

if you are using this port forward from outside to inside you can put incoming interface so that rule can be more specific... Put rule at the top and see the counter? does packets are passing through that rule? if does, does the local device know how to return traffic back?
by mixig
Sun Sep 02, 2012 2:41 pm
Forum: General
Topic: Simple http server
Replies: 9
Views: 3300

Re: Simple http server

for this job use ftp server.
ftp is insecure
Than you can use sftp
by mixig
Fri Aug 31, 2012 12:02 pm
Forum: Beginner Basics
Topic: dscp prioritize
Replies: 3
Views: 1049

Re: dscp prioritize

Hi again,

thanks fot the config, so basically this will prioritize all traffic with dscp 46 no matter the in/out interface?
by mixig
Fri Aug 31, 2012 11:58 am
Forum: General
Topic: drytek 2850 vpn clirnt to mikrotik
Replies: 4
Views: 1015

Re: drytek 2850 vpn clirnt to mikrotik

you can use PPTP with profile "default-encryption", client is connecting to the server (in your case MKT), other side can be on dynamic ip
by mixig
Thu Aug 30, 2012 9:33 pm
Forum: Beginner Basics
Topic: dscp prioritize
Replies: 3
Views: 1049

dscp prioritize

Hi, two locations, each location one MKT, between is PPTP vpn, each MKT has few IP phones. how to prioritize the RTP traffic (which has DSCP 46) to go first into that PPTP tunel? In mangle I can mark first connection in prerouting (by dscp value) than packet from that connection, and than somehow in...
by mixig
Sun Jul 22, 2012 9:05 pm
Forum: Beginner Basics
Topic: Enable ping on WAN
Replies: 5
Views: 36321

Re: Enable ping on WAN

Maybe provider is blocking the ping?

does your counter for that rule is growing?
by mixig
Sat Jul 21, 2012 12:46 pm
Forum: Beginner Basics
Topic: Mail server behind NAT - forcing perticular outgoing IP addr
Replies: 12
Views: 4955

Re: Mail server behind NAT - forcing perticular outgoing IP

i solve that with this line: add action=src-nat chain=srcnat disabled=no out-interface=wan_port src-address=192.168.x.x to-addresses=89.201.x.x change wan port with your public interface, src-address with local ip, to addresses with your public ip which your smtp will get when go outisde to the inte...
by mixig
Tue Jul 17, 2012 10:32 pm
Forum: Beginner Basics
Topic: Need help WAN Failover between two ISP
Replies: 5
Views: 1860

Re: Need help WAN Failover between two ISP

you can also use public DNS servers
by mixig
Wed Jul 11, 2012 9:16 am
Forum: Wireless Networking
Topic: Hidden WLAN SSID
Replies: 2
Views: 670

Re: Hidden WLAN SSID

ok, thanks
by mixig
Tue Jul 10, 2012 11:21 pm
Forum: Wireless Networking
Topic: Hidden WLAN SSID
Replies: 2
Views: 670

Hidden WLAN SSID

Hi,

when i am using VAP I remove SSID from real wlan card but on my computer i see "other network" (hidden SSID from wlan card). is there any way tu turn that off?? I want that on wifi list on the computer are only SSIDs of VAPs

thanks
by mixig
Mon Jul 09, 2012 11:59 am
Forum: Beginner Basics
Topic: Books?
Replies: 6
Views: 4049

Re: Books?

Hi,

I also would like to buy a book, which is better Learn RouterOS or RouterOS by example?

I have some experience with mikrotik but I want to go more depth specially for Wireless, mangling and QoS.

I cant decide which book to buy...


Thanks
by mixig
Thu May 17, 2012 3:24 pm
Forum: General
Topic: IPSec tunnel up time
Replies: 4
Views: 1972

Re: IPSec tunnel up time

Hi, if I understand the tunnel will be up without any traffic for lifetime period (default 1day)? with that.. i dont need to generate some addititonal traffic for keeping my ipsec tunnel up? (e.g. like netwatch) On cisco routers if there is no interesting traffic tunnel wil be dead after 5 min (no m...
by mixig
Wed May 16, 2012 1:20 pm
Forum: General
Topic: IPSec tunnel up time
Replies: 4
Views: 1972

Re: IPSec tunnel up time

Anybody??
by mixig
Wed May 16, 2012 1:17 pm
Forum: General
Topic: oracle traffic PPTP problem
Replies: 2
Views: 663

Re: oracle traffic PPTP problem

update... i tried to connect my aplication from remote site via Interent (port forward) to central location and it is working, so the problem is in PPTP VPN. I also changed MTU/MRU on mirkotik to 1372, problem still exist, I removed "dynamically change MSS" from mangle (turn off on pptp server)and a...
by mixig
Tue May 15, 2012 6:28 pm
Forum: General
Topic: IPSec tunnel up time
Replies: 4
Views: 1972

IPSec tunnel up time

Hi, I am having central site with PBX and remote offices with IP phones (there are also IP telephony on central site but that is not important for this story :)), i will configured ipsec between remote offices and central location. Remote offices are on dynamic ip addresses while central location is...
by mixig
Mon May 14, 2012 11:15 am
Forum: General
Topic: oracle traffic PPTP problem
Replies: 2
Views: 663

oracle traffic PPTP problem

Hi, we are having problem with some remote computers which are connected via PPTP (both sides are mikrotik), all other traffic is passing through VPN normal, only problem is when remote computer is pulling some information from server which is on central location, tcp 1521 port, it is taking too lon...
by mixig
Sun May 13, 2012 7:33 pm
Forum: Beginner Basics
Topic: user manager
Replies: 1
Views: 505

Re: user manager

I found under the "all packages"...
by mixig
Sun May 13, 2012 4:56 pm
Forum: Beginner Basics
Topic: user manager
Replies: 1
Views: 505

user manager

Where can I find user manage for download?? on mikrotik site there is no nothing under the download section....


Thanks
by mixig
Tue Apr 24, 2012 7:57 pm
Forum: Beginner Basics
Topic: Port forwarding Works for most devices, but not one.
Replies: 17
Views: 5063

Re: Port forwarding Works for most devices, but not one.

I would recommend narrowing it down by either specifying the public IP you want to have forwarded as the dst-address, or the in-interface of the WAN port. That is correct, and also check manual for that camera, i had problems with video for ip cameras, with web port many cameras using RTSP, in my c...
by mixig
Thu Apr 12, 2012 11:37 am
Forum: General
Topic: UDP broadcast over VPN
Replies: 1
Views: 1114

UDP broadcast over VPN

Hi, we have hub and spoke topology, each remote site is connected via VPN pptp to central location, each computer must have list of active computers in network places, right now they can se just local computers because UDP broadcast is not passing through VPN, what is the most easiest way to resolve...
by mixig
Wed Mar 28, 2012 2:32 pm
Forum: Beginner Basics
Topic: restore backup 450G->1100AH
Replies: 5
Views: 1464

Re: restore backup 450G->1100AH

450G have v. 4.17, 1100AH 5.8. so i must upgrade 450G to 5.12 and than make /compact export? and after that copy/paste to 1100AH?
by mixig
Wed Mar 28, 2012 1:44 pm
Forum: Beginner Basics
Topic: restore backup 450G->1100AH
Replies: 5
Views: 1464

restore backup 450G->1100AH

Hi, I have 450G which is in production, now I need to replace that router with 1100AH. What is the simplest way to copy existing configuration from one to antoher (from 450G to 1100AH). Can I use .backup file which is created on 450G? If i use .rsc I will need to modify some things (mac addresses......
by mixig
Mon Mar 12, 2012 8:38 pm
Forum: Beginner Basics
Topic: Allow VPN
Replies: 5
Views: 2458

Re: Allow VPN

with that 2 rules you are allowing PPTP (port 1723) and GRE (47) protocol into the router, additional config must be configure (pptp server or pptp clinet....)
by mixig
Mon Mar 12, 2012 7:09 pm
Forum: General
Topic: QOS VOICE VPN
Replies: 2
Views: 1629

Re: QOS VOICE VPN

Anybody???
by mixig
Sun Mar 11, 2012 3:42 pm
Forum: General
Topic: QOS VOICE VPN
Replies: 2
Views: 1629

QOS VOICE VPN

hi, i am having 3 locations, centralize location with static ip and two remote offices with adsl with dynmaic ip. My goal is to prioritize voice over the lan and over the VPN. Ip phone are marking voice packet with DSCP 46, I also have the same config on the switch, so my voice are coming to the MKT...
by mixig
Wed Feb 22, 2012 1:35 pm
Forum: General
Topic: daily limitation of upload traffic
Replies: 3
Views: 1019

Re: daily limitation of upload traffic

Hi,


i dont use hot spot, do i need some firewall rule to do this.


Best regards.