Community discussions

MUM Europe 2020

Search found 57 matches

by jackman
Thu Apr 19, 2012 12:41 pm
Forum: Beginner Basics
Topic: Selective access to websites
Replies: 5
Views: 962

Re: Selective access to websites

i dont think you will need the rule number 6. from the LAN site your traffic will not pass the forward chain, since it already routed to input chain by dst-nat.

About the MSN what kind protocol does MSN use? does it use http?
by jackman
Wed Apr 11, 2012 11:38 am
Forum: Wireless Networking
Topic: Wireless mesh with ethernet interfaces
Replies: 24
Views: 11799

Re: Wireless mesh with ethernet interfaces

i haven't done it yet, maybe you could create wds like network and put the ether interface connected to the switch to those bridge.
by jackman
Wed Apr 11, 2012 11:19 am
Forum: Beginner Basics
Topic: global-in / global-out - mangle
Replies: 5
Views: 12358

Re: global-in / global-out - mangle

As long as you marking the packet based on the interface all is fine. I think you don't even need to mark the packet.
by jackman
Mon Apr 09, 2012 2:44 pm
Forum: General
Topic: Is it possible to dstnat on OUTGOING traffic???
Replies: 2
Views: 697

Re: Is it possible to dstnat on OUTGOING traffic???

it seem imposible, since the dst-nat located on prerouting. But, if this could be done, it would be usefull. in example i would like to make several pptp connection to the same server with difference out interface.
by jackman
Mon Apr 09, 2012 2:29 pm
Forum: General
Topic: is it possible to do bounding with 2 modems?
Replies: 9
Views: 1214

Re: is it possible to do bounding with 2 modems?

Are you talking about remote IP and local IP? it has nothing todo with ip assigning to this interface. This both ip are the ip of the local router and remote router. For example you have 2 router with wan interface and ip as follow : R1) 100.200.250.1 R2) 100.200.251.1 on R1) you should set the loca...
by jackman
Thu Apr 05, 2012 1:23 pm
Forum: General
Topic: Prerouting Connections cannot be shaped
Replies: 11
Views: 1575

Re: Prerouting Connections cannot be shaped

it seems beyond my exprties, but i'll give it a try. thanks a lot.
anytime
by jackman
Thu Apr 05, 2012 1:15 pm
Forum: General
Topic: PCC + pppoe clients + routing trouble
Replies: 7
Views: 1890

Re: PCC + pppoe clients + routing trouble

Could you attach the ip firewall mangle screen shot?
by jackman
Fri Mar 30, 2012 2:19 pm
Forum: General
Topic: Prerouting Connections cannot be shaped
Replies: 11
Views: 1575

Re: Prerouting Connections cannot be shaped

I have not tried it before, it will be complicated. but it could be done with some tricks. 1) you have to group the ip address of the same user in subnet. It could be done with dhcp static ip 2a) create pcc type of queue name it download and set the classify base on dst-address aslo the src-address ...
by jackman
Thu Mar 29, 2012 1:29 pm
Forum: General
Topic: PCC + pppoe clients + routing trouble
Replies: 7
Views: 1890

Re: PCC + pppoe clients + routing trouble

/interface pppoe-client add ac-name="" add-default-route=no allow=pap,chap,mschap1,mschap2 comment=\ "" dial-on-demand=no disabled=no interface=ether9 \ max-mru=1480 max-mtu=1480 mrru=disabled name=pppoe-out1 password=xxxxxx \ profile=default service-name="" use-peer-dns=no user=\ xxxxxxxxxxx add a...
by jackman
Thu Mar 29, 2012 12:35 pm
Forum: General
Topic: Prerouting Connections cannot be shaped
Replies: 11
Views: 1575

Re: Prerouting Connections cannot be shaped

Output chain is working fine with dst-address-list only for download traffic. But i wanted to do like what it says here http://wiki.mikrotik.com/wiki/TransparentTrafficShaper Looks very simple. I did not bridge thou. Your scenario and on wiki scenario have following differences 1) on WIKI, it is si...
by jackman
Thu Mar 29, 2012 12:16 pm
Forum: General
Topic: Prerouting Connections cannot be shaped
Replies: 11
Views: 1575

Re: Prerouting Connections cannot be shaped

In my basic understanding of simple queue. 1) you could make a traffic shaping based on target address 2) you could also use the packet mark Next take a look on your traffic. With an assumption you have transparent proxy for http traffic (destination port 80). I will simplify the packet stream into ...
by jackman
Wed Mar 28, 2012 12:47 pm
Forum: Wireless Networking
Topic: Wifi Covering 1square km
Replies: 3
Views: 910

Re: Wifi Covering 1square km

Hi, I would like to build a hotspot network in remote are using mikrotik. The are consists of 500 x 500 meter. Concurrent users will be 500. There are porta cabin homes are there. Planning to put 20db 120degree sector antenna in the height of 6 meter (all the porta cabins are at the height of 3M) w...
by jackman
Wed Mar 28, 2012 12:26 pm
Forum: General
Topic: Prerouting Connections cannot be shaped
Replies: 11
Views: 1575

Re: Prerouting Connections cannot be shaped

No other rule for 512k list. But i'm using web proxy and caching.
1) Just make another packet-mark on chain output and name it "packet-from-proxy" with dst-address-list=512k
2) make another simple queue entry with packet mark= packet-from-proxy

3) let me know if that work
by jackman
Wed Mar 28, 2012 12:00 pm
Forum: General
Topic: cache hit from squid as well as webproxy
Replies: 1
Views: 1625

Re: cache hit from squid as well as webproxy

chain=output action=mark-packet new-packet-mark=cache-hit0 passthrough=no dscp=4 On those code you have marked the packet hit on your Mikrotik define by dscp=4. You need to define or find out the tos/dscp of your hit packet came from pfsense. I hear about zph option but never use it before. The poi...
by jackman
Wed Mar 28, 2012 5:43 am
Forum: General
Topic: Prerouting Connections cannot be shaped
Replies: 11
Views: 1575

Re: Prerouting Connections cannot be shaped

Do you have another mangle related to list=512k on another chain? I just tried your code and it work perfect. Or could you attach the output of
/ip fi ma export

so we could have better overview of your system
by jackman
Sun Mar 25, 2012 7:11 pm
Forum: Beginner Basics
Topic: ADSL Connection...
Replies: 3
Views: 754

Re: ADSL Connection...

Using mikrotik as pppoe client and it goes really bad... extremely slow... Worst then a cheap router... Sent from my HTC Desire using Tapatalk i dont have this issue on my RB. I have RB750G running pppoe-client RB750 running 3 pppoe-client with pcc RouterOS on x86 PC running 2 pppoe-client on all t...
by jackman
Thu Mar 22, 2012 10:53 am
Forum: Beginner Basics
Topic: Selective access to websites
Replies: 5
Views: 962

Re: Selective access to websites

but it does not allow for group access (or I don't have an idea how to do group filtering) . why don't you combine the proxy with a firewall rules. For example: 1) create address list of granted access person to access web on ip firewall address list ie weblist 2) create destination nat to redirect...
by jackman
Thu Mar 22, 2012 10:27 am
Forum: Beginner Basics
Topic: bridged network with public and private access
Replies: 3
Views: 708

Re: bridged network with public and private access

First nice diagram, We have to breakdown this configuration into several step as follow : 1) Interfaces, as shown on your diagram you could arrange the interface physically connected to each routerboard and assign ip address on each. Just skip it if you done already 2) Setup dhcp server for both pub...
by jackman
Thu Mar 22, 2012 4:41 am
Forum: General
Topic: is it possible to do bounding with 2 modems?
Replies: 9
Views: 1214

Re: is it possible to do bounding with 2 modems?

In the first Router I have 10.251.3.1 and 10.251.3.2 and the IP of the bonding is 10.0.0.1 In the second Router I have 10.251.3.3. and 10.251.4.5 and the IP of the bonding is 10.0.0.4 as cybercoder mentioned that you will need the 2 EoIP connection on between both router. And then you could bond th...
by jackman
Mon Mar 19, 2012 9:13 am
Forum: Beginner Basics
Topic: bridged network with public and private access
Replies: 3
Views: 708

Re: bridged network with public and private access

Could you provide a diagram with the interface name as well the ip address?
by jackman
Mon Mar 19, 2012 9:08 am
Forum: RouterBOARD hardware
Topic: Need help Configuring BR450 (Load Balance with Auto Faailove
Replies: 11
Views: 1804

Re: Need help Configuring BR450 (Load Balance with Auto Faai

Dear, You are absolutely right. My LAN and Wireless link has the same network as it is a data link network for communication with two branch office. My suggestion you should not bridge directly your wireless interface with your LAN interface. Instead you could make the ospf setup for both connectio...
by jackman
Fri Mar 16, 2012 6:20 am
Forum: Beginner Basics
Topic: Failover on RB433
Replies: 2
Views: 474

Re: Failover on RB433

Does your pc get ip from the Wlan interface via DHCP? or it's a static IP? I did't see any network entry on the /ip dhcp-server network.

could you attach the print out of following code
/ip dhcp-server network print
or check on you pc the output of
route print
by jackman
Thu Mar 15, 2012 7:38 pm
Forum: General
Topic: is it possible to do bounding with 2 modems?
Replies: 9
Views: 1214

Re: is it possible to do bounding with 2 modems?

As long you can the comunication could be made on each other you could do eoip. Another question which IP belong to which rb?
by jackman
Thu Mar 15, 2012 7:33 pm
Forum: General
Topic: Weird DHCP client address
Replies: 2
Views: 594

Re: Weird DHCP client address

So far that i know, using interface as gateway will only work with on point to point interface such as pppoe, pptp
by jackman
Thu Mar 15, 2012 3:07 pm
Forum: General
Topic: port detection outside gw
Replies: 3
Views: 554

Re: port detection outside gw

I never play with log yet :D , may be somebody else could help you in this issue
by jackman
Thu Mar 15, 2012 11:38 am
Forum: General
Topic: is it possible to do bounding with 2 modems?
Replies: 9
Views: 1214

Re: is it possible to do bounding with 2 modems?

Bonding and eoip could be done, if both of your site using RouterOS. Otherwise you could only load balance the traffic using both of your modem with PCC as example.
by jackman
Thu Mar 15, 2012 11:03 am
Forum: Beginner Basics
Topic: SMTP NAT rule not working
Replies: 1
Views: 466

Re: SMTP NAT rule not working

please attach your
/ip firewall export
by jackman
Thu Mar 15, 2012 10:53 am
Forum: Beginner Basics
Topic: Redirecting IP Address
Replies: 6
Views: 6189

Re: Redirecting IP Address

As TheWiFiGuy, already mentioned. If this possible for you to set static dns entry on your RouterOS? And let the Client use RouterOS dns server?

In this case you could set static dns entry on winbox :
ip/dns

or look at

http://wiki.mikrotik.com/wiki/Manual:IP/DNS
by jackman
Thu Mar 15, 2012 10:22 am
Forum: General
Topic: port detection outside gw
Replies: 3
Views: 554

Re: port detection outside gw

on those wiki site the mangle work on chain input. If you want to use this mangle for the client on LAN interface, you should try to change the chain to "forward" instead "input" and use in-interface (interface conneceted to your client) or src-address. Run the port scanner tool and look on the fire...
by jackman
Thu Mar 15, 2012 9:57 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

If you have already established vpn connection ie pptp and go to interface on winbox root, you will see new connection name pptp-xxxxx with status DR. Right click on that interface and select torch. Just start the torch you will see the all connection on this interface. Which firewall? on router or ...
by jackman
Thu Mar 15, 2012 8:26 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

base on your information, you only have 512Kbps link for both side. It is the Uplink on both side. I don't know how many traffic (bandwidth) do you really need for SQL Query. But you could monitor the traffic with help of torch. Just Try to torch connection came from win7. Make sure there are no oth...
by jackman
Thu Mar 15, 2012 7:08 am
Forum: General
Topic: Dual Wan with Dymanic WAN IP
Replies: 1
Views: 2342

Re: Dual Wan with Dymanic WAN IP

I have not tried the configuration with dhcp ip, may be i could help to analyze the code. add address=[color=#FF0000]192.168.1.2/24[/color] network=[color=#FF0000]192.168.1.0[/color] broadcast=[color=#FF0000]192.168.1.255[/color] interface=WAN1 add address=[color=#FF0000]192.168.2.2/24[/color] netwo...
by jackman
Thu Mar 15, 2012 5:36 am
Forum: Beginner Basics
Topic: Mikrotik RB711U, ROS-5.14 NAT issues for SIP to VoIP carrier
Replies: 10
Views: 6649

Re: Mikrotik RB711U, ROS-5.14 NAT issues for SIP to VoIP car

i have similar issue in the pass, if i have for example ITSP ---- Internet----Router---PABX(Asterisk)---SIP-DEVICE The call was initiated by SIP Device via asterisk and routed to ITSP for example. On the ITSP side, the user could receive my audio, but not the opposite. It's more the SIP issue, that ...
by jackman
Thu Mar 15, 2012 5:01 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

The problem could be caused by many aspects : - on the pptp-client ->do you use a default route on your pptp-client connection? -> if this windows workstation please print the command route print - on the linksys -> how's the default route for each client on linksys side? -> do you have nat between ...
by jackman
Thu Mar 15, 2012 4:51 am
Forum: RouterBOARD hardware
Topic: Need help Configuring BR450 (Load Balance with Auto Faailove
Replies: 11
Views: 1804

Re: Need help Configuring BR450 (Load Balance with Auto Faai

Dear, I am still facing the same problem. Jackman: I have seen your provided link but there may be a mistake that is /ip address add address=192.168.1.1/30 broadcast=192.168.1.3 comment="" disabled=no \ interface= wlan1 network=192.168.1.0 add address=192.168.1.5/30 broadcast=192.168.1.7 comment=""...
by jackman
Wed Mar 14, 2012 11:51 am
Forum: General
Topic: tunnelled connection between clients
Replies: 1
Views: 335

Re: tunnelled connection between clients

i have found this link http://mum.mikrotik.com/presentations/P ... ademia.pdf , it's mum 2010 presentation. It could help you to see the pros & cons of Both VPN protocol.
by jackman
Wed Mar 14, 2012 9:29 am
Forum: Beginner Basics
Topic: Problem with script for non-payers
Replies: 1
Views: 602

Re: Problem with script for non-payers

add action=src-nat chain=srcnat comment="redirect_all_other_connections" disabled=yes src-address-list=kasa-stalablokada to-addresses=192.168.42.1 This code only replace the all src-address from address list=kasa-stalablokada to 192.168.42.1. for example if you have an ip 192.168.42.10 in the list ...
by jackman
Wed Mar 14, 2012 6:53 am
Forum: Forwarding Protocols
Topic: simple nat setup
Replies: 2
Views: 1106

Re: simple nat setup

Here is what i am trying to do really simple I hope. I have a second IP address from my ISP that I wish to assign to a device behind my mikrotik router. So say my second ISP address is 172.20.5.10 and my lan device is 192.168.1.8. The mikrotik sits on 172.20.5.8. How can I tell the mikrotik router ...
by jackman
Wed Mar 14, 2012 3:34 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

I got fed up and decided to go out for a while, was out for give or take 2 hrs. I hook up my lappy again and to my surprise the internet connection has just worked. :shock: man this is so random. Is this like the usual behavior of this router? no, i never have this issue in my router. Once again if...
by jackman
Tue Mar 13, 2012 6:41 pm
Forum: RouterBOARD hardware
Topic: Need help Configuring BR450 (Load Balance with Auto Faailove
Replies: 11
Views: 1804

Re: Need help Configuring BR450 (Load Balance with Auto Faai

It has basicly difference network, it segmented into /30 network
by jackman
Tue Mar 13, 2012 1:24 pm
Forum: General
Topic: proxy hostname in client browser configuration .How?
Replies: 2
Views: 575

Re: proxy hostname in client browser configuration .How?

Note:I have add proxy for clients because i have complex network why don't you set a transparent proxy with dst-nat? you could redirect all traffic comming to router on port 80 to port 8080 where you have the proxy service running. In this case you don't have to setup anything on your client browser.
by jackman
Tue Mar 13, 2012 1:21 pm
Forum: General
Topic: proxy hostname in client browser configuration .How?
Replies: 2
Views: 575

Re: proxy hostname in client browser configuration .How?

set static dns entry
by jackman
Tue Mar 13, 2012 1:10 pm
Forum: RouterBOARD hardware
Topic: Need help Configuring BR450 (Load Balance with Auto Faailove
Replies: 11
Views: 1804

Re: Need help Configuring BR450 (Load Balance with Auto Faai

Dear, You got it wrong. My fiber does not have any internet it is only the Data Link for Site A to Site B or Site B to Site A communication. You can get a visual on the following link- http://wiki.mikrotik.com/wiki/Manual:BGP_Load_Balancing_with_two_interfaces Ok my bad, in your situation i think t...
by jackman
Tue Mar 13, 2012 1:04 pm
Forum: General
Topic: QOS VOICE VPN
Replies: 2
Views: 1466

Re: QOS VOICE VPN

Anybody??? IMHO to implement QoS as well Bandwidth management on RouterOS we have to know the available bandwidth. Based on those information we could allocate specified amount of bandwidth (limit at) ie: for voip. The priority rank will only work for non-used bandwidth and it will be limited base ...
by jackman
Tue Mar 13, 2012 11:32 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

Could you disable the whole accept action first on every chain in your firewall? base on those configuration it should work. Ppl usually tell me to enable NAT masquerade. In this case i don't it, right? because linksys is feeding the internet connection so i guess we dont need to maquerade? In this...
by jackman
Tue Mar 13, 2012 11:29 am
Forum: Beginner Basics
Topic: HTB download queues in VoIP QoS examples
Replies: 1
Views: 870

Re: HTB download queues in VoIP QoS examples

This is only my opinion, correct me if i'm wrong. For VoIP people tend to mangle in prerouting, and create both upload and download queue structure. If you working with voip, especially if your mikrotik is using nat, as you know the SIP protocol for example using several port for media straming, you...
by jackman
Tue Mar 13, 2012 11:07 am
Forum: RouterBOARD hardware
Topic: Need help Configuring BR450 (Load Balance with Auto Faailove
Replies: 11
Views: 1804

Re: Need help Configuring BR450 (Load Balance with Auto Faai

My assumption your Fiber link you to the internet and you could not communicate with each other through the fiber link. In this case you should communicate with your isp to allow ip traffic between those 2 ip's. otherwise you will need 3th node for example on data center of your isp where you could ...
by jackman
Tue Mar 13, 2012 10:48 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

Could you disable the whole accept action first on every chain in your firewall? base on those configuration it should work.
by jackman
Tue Mar 13, 2012 10:30 am
Forum: Beginner Basics
Topic: Passthrough in mangle
Replies: 9
Views: 28925

Re: Passthrough in mangle

do you have any examples? any link? tnx on mikrotik wiki you will find alot of example but i will give you a simple trial : just set following mangle on your router : 1) mark connection on chain prerouting with your pc ip address as src-address and action mark-new-connection with new connection mar...
by jackman
Tue Mar 13, 2012 9:48 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

could you just ping from the linksys to your notebook to find out does the static route work? If you choose the ping with ether5 the traffic will go out the mikrotik from ether5. It will not go back to the router via ether5 and route to ether2, since you already decide to use the ether5 as outgoing ...
by jackman
Tue Mar 13, 2012 9:37 am
Forum: General
Topic: Setup PCQ but not working!
Replies: 3
Views: 833

Re: Setup PCQ but not working!

Hello, 3 Ethernet Interfaces - Public - Local - Public 2 I have Dedicated 4Mbps/12Mbps through Public Interface and I thought of using a contention ration 1:50 using PCQ which means I want to share 12Mbps using 12 GROUPS and each group must have a dedicated 1 Mbps and each 1Mbps would be shared wit...
by jackman
Tue Mar 13, 2012 9:06 am
Forum: Beginner Basics
Topic: Routing Help - RB 750GL - Will pay $
Replies: 5
Views: 918

Re: Routing Help - RB 750GL - Will pay $

have you configured the NAT?
by jackman
Tue Mar 13, 2012 8:57 am
Forum: Beginner Basics
Topic: Passthrough in mangle
Replies: 9
Views: 28925

Re: Passthrough in mangle

As a suggestion, you could use the counter to find out, do your mangle work or not. Basicly the passthrough will be usefull for example you would like to mark connection and base on the marked connection you would like to mark routing or packet. Or you would like to remark the already marked entity ...
by jackman
Tue Mar 13, 2012 8:48 am
Forum: Beginner Basics
Topic: Problem comunicating hosts between network in 2 router
Replies: 26
Views: 2913

Re: Problem comunicating hosts between network in 2 router

This is my ping output from interface ether5 to 10.10.10.252 which is my laptops ip address. ....... If i ping 10.10.10.252 from ether2, it works. hmm...what do i do wrong? If you execute ping with interface parameter ie : ether5, you have already defined this ping came from your ether5 which is, y...
by jackman
Tue Mar 13, 2012 6:53 am
Forum: General
Topic: rb411ar with linux proxy server
Replies: 2
Views: 456

Re: rb411ar with linux proxy server

Could you more specified the question at least with network diagram?
I need to know in which interface your client or proxy server connected to.
by jackman
Tue Mar 13, 2012 5:51 am
Forum: Beginner Basics
Topic: Simple queue for mikrotik
Replies: 6
Views: 1057

Re: Simple queue for mikrotik

oh ok, I have done abit of this. But marking packets that are downloading is harder as the local ip's are not in the packets untill a later stage? how do i sort that out? is there no way to link a pppoe connection to a ip? Therefor you'll need a connection mark as cbrown said. As well you'll need t...