Community discussions

MikroTik App

Search found 52 matches

by abubin
Fri Sep 24, 2021 6:14 am
Forum: General
Topic: dst-nat and src-nat on same connection
Replies: 9
Views: 3432

Re: dst-nat and src-nat on same connection

There are no other NAT rules and firewall rules (besides the fasttrack dummy rules that I can't remove) in there. Did packet sniffing from the mikrotik. I do see the dst-nat doing it's work changing the dst IP&port. However, I do not see src-nat matching packets. Sorry I didn't get a chance to s...
by abubin
Thu Sep 23, 2021 5:53 pm
Forum: General
Topic: dst-nat and src-nat on same connection
Replies: 9
Views: 3432

Re: dst-nat and src-nat on same connection

To better understand what @tdw wrote, have a look at packet flow description . And: all properties of SRC-NAT and DST-NAT conmmands, except to-addresses and to-ports, are "matching" properties. Which means that they are used to selectively pick packets which will get changed. The two ment...
by abubin
Thu Sep 23, 2021 5:29 pm
Forum: Beginner Basics
Topic: Blocking incoming DNS
Replies: 4
Views: 1438

Blocking incoming DNS

I did a torch on the public interface of the mikrotik router and is seeing lots of DNS requests incoming from the internet. I already tried adding the firewall rules to block port 53 (tcp and udp) to no avail. Also disabled the "allow remote requests" in DNS settings. Even removed DNS serv...
by abubin
Thu Sep 23, 2021 1:07 pm
Forum: General
Topic: dst-nat and src-nat on same connection
Replies: 9
Views: 3432

Re: dst-nat and src-nat on same connection

To sum it up;

user 1.2.3.4 5678 ---> our network (src 10.1.1.2 5678) ---> leasedline ---> customer 172.1.1.1 8888

Apologize if my posting is not clear enough. Please do not hesitate to ask any questions. Appreciate any input no matter helpful or not.
by abubin
Thu Sep 23, 2021 12:58 pm
Forum: General
Topic: dst-nat and src-nat on same connection
Replies: 9
Views: 3432

dst-nat and src-nat on same connection

I have a connection coming from outside (WAN) that I need to route it into another network that is connected internally. user (30.1.1.1) ----> mikrotik master (WAN 1.2.3.4 LAN 192.168.1.1) --> mikrotik second (LAN 192.168.1.2 LAN2 10.1.1.2) --> 3com router (10.1.1.1) --> leasedline --> customer (172...
by abubin
Fri Sep 17, 2021 9:31 am
Forum: General
Topic: MikroTik CHR on AWS with IPSec [SOLVED]
Replies: 16
Views: 6868

Re: MikroTik CHR on AWS with IPSec [SOLVED]

Can I know why use Mikrotik CHR instead of AWS VPN service? Some feature that AWS VPN does not support? Cause I am trying to connect Mkrotik in my DC to AWS VPN and is facing issues getting it setup properly. My lack of skill with mikrotik is getting the better of me. And the project is due yesterda...
by abubin
Wed Sep 15, 2021 11:31 am
Forum: General
Topic: Need help with VPN setup
Replies: 6
Views: 741

Re: Need help with VPN setup

aws-mikrotikvpn05.jpg I am wondering if line number 4 is needed with firmware 6.48.4. Anyway, I tried with and without that line and still doesn't work. update: something to do with the BGP setting? And the internal IP used? (169.254.30.76/30). I am not sure what these IPs are called. They seems to...
by abubin
Wed Sep 15, 2021 11:09 am
Forum: General
Topic: Need help with VPN setup
Replies: 6
Views: 741

Re: Need help with VPN setup

What you show does indeed indicate phase 1 success. And yes, 6.36.whatever is very old and a device running that version must not be exposed to internet - if it was connected to internet without tight enough firewall rules, netinstall it again (not just upgrade) to a current long-term version (6.47...
by abubin
Wed Sep 15, 2021 11:08 am
Forum: General
Topic: Need help with VPN setup
Replies: 6
Views: 741

Re: Need help with VPN setup

So I upgraded to latest firmware 6.48.4. Did a change on the IPsec policy. PH2 State: established. aws-mikrotikvpn04.jpg However, still unable to communicate between the 2 sides. Probably routing and firewall issue...again, do I have to do anything at the Mikrotik firewall side? Maybe AWS is trying ...
by abubin
Wed Sep 15, 2021 10:35 am
Forum: General
Topic: Need help with VPN setup
Replies: 6
Views: 741

Re: Need help with VPN setup

Manage to get something showing...but AWS there still showings connection down.

Any idea what to check?
aws-mikrotikvpn03.jpg
by abubin
Wed Sep 15, 2021 9:41 am
Forum: General
Topic: Need help with VPN setup
Replies: 6
Views: 741

Re: Need help with VPN setup

Does this means phase1 is success?

How to check phase2 successful or not? I still can't ping any IPs in AWS side. Can't even ping the localhost ip 169.254.30.77 of AWS.

BTW, I have downgraded the firmware to 6.36.3 using netinstall. I am thinking maybe should upgrade to latest firmware version.
by abubin
Wed Sep 15, 2021 6:45 am
Forum: General
Topic: Need help with VPN setup
Replies: 6
Views: 741

Need help with VPN setup

Please bear with me, I am very noob at this. I am trying to connect mikrotik to AWS on VPN. The guide I found are a bit old for firmware 6.36. Trying to connect from behind NAT. There is one guide found which have newer guide but it is slightly different from what I am doing. So far, I am unable to ...
by abubin
Thu Oct 08, 2020 5:55 am
Forum: Forwarding Protocols
Topic: IPSEC is getting random encryption issue
Replies: 0
Views: 1009

IPSEC is getting random encryption issue

We have deploy a mikrotik CHR in a cloud environment and manage to establish connection to our client backend that is using Fortigate. However, since the deployment 2 months ago we have been getting random "disconnection" issue. The so called disconnection is not really a disconnection bec...
by abubin
Tue Aug 18, 2020 6:24 am
Forum: General
Topic: Dual connection for dr and test ipsec vpn possible?
Replies: 9
Views: 2410

Re: Dual connection for dr and test ipsec vpn possible?

The bug happened again yesterday. It is causing problems on our side as we have data transactions by the seconds. Anyone can help shed some light into how to resolve this issue? I have already emailed Mikrotik support but they responded with some setting for us to try which does not work. No respons...
by abubin
Thu Aug 13, 2020 5:56 am
Forum: General
Topic: Dual connection for dr and test ipsec vpn possible?
Replies: 9
Views: 2410

Re: Dual connection for dr and test ipsec vpn possible?

I am using Mikrotik CHR RouterOS 6.45.9.
by abubin
Wed Aug 12, 2020 1:52 pm
Forum: General
Topic: Dual connection for dr and test ipsec vpn possible?
Replies: 9
Views: 2410

Re: Dual connection for dr and test ipsec vpn possible?

Thank you for the reply. Appreciate your sharing of knowledge. I have encountered another issue on this VPN. Just this morning connection to the other side suddenly failed. Upon checking, I can see the IPsec connection still showing "established". So I tried a quick telnet (from the mikrot...
by abubin
Wed Jul 29, 2020 9:28 am
Forum: Forwarding Protocols
Topic: loadbalancing ipsec vpn
Replies: 2
Views: 1811

loadbalancing ipsec vpn

I have setup mikrotik with 2 ipsec vpn connection to primary and secondary site. Can I know how I can load balance traffic between them? It can be active-active or active-passive. Preferably active-active. server ----> mikrotik ------> vpn1 ------> primary (192.168.1.1) ------> vpn2 ------> secondar...
by abubin
Tue Jul 28, 2020 10:33 am
Forum: General
Topic: Dual connection for dr and test ipsec vpn possible?
Replies: 9
Views: 2410

Re: Dual connection for dr and test ipsec vpn possible?

Is that something to worry about? Cause telnet works but right now I am facing some issues communicating with the other side. Maybe it is not related to this error but it is concerning to have this showing in the logs.
by abubin
Fri Jul 24, 2020 4:52 am
Forum: General
Topic: Dual connection for dr and test ipsec vpn possible?
Replies: 9
Views: 2410

Re: Dual connection for dr and test ipsec vpn possible?

I am facing another problem now. Even though I manage to have 2 of that VPN connection established, I cannot get the routing to work. It is the problem with the routing. /ip route print lags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - bla...
by abubin
Thu Jul 23, 2020 6:36 am
Forum: General
Topic: Dual connection for dr and test ipsec vpn possible?
Replies: 9
Views: 2410

Re: Dual connection for dr and test ipsec vpn possible?

Hah...got it working. Here is what I changed, [abubin@uatmtik] > /ip ipsec policy print Flags: T - template, X - disabled, D - dynamic, I - invalid, A - active, * - default # P TUN SRC-ADDRESS 0 T * ::/0 1 A o yes 192.168.11.34/32 2 A o yes 192.168.11.33/32
by abubin
Thu Jul 23, 2020 6:32 am
Forum: General
Topic: Dual connection for dr and test ipsec vpn possible?
Replies: 9
Views: 2410

Dual connection for dr and test ipsec vpn possible?

I am trying to setup 2 ipsec vpn connection to a destination that accept both the connection. I think they are using fortigate at their end. I am using Mikrotik CHR running on a cloud instance. Anyway, we have 2 ipsec connection to setup, DR and testing. I have done the configuration as below: [abub...
by abubin
Thu May 23, 2019 1:27 pm
Forum: General
Topic: same MAC address in two mikrotik
Replies: 6
Views: 3603

Re: same MAC address in two mikrotik

To minimize the outage I'd recommed to change all interfaces in a single step; to do that, you need to add [find] to the end of the command instead of interface name. Can I know what is the exact command I should use with [find] command? Sorry, I can't find any reference for this on changing MAC ad...
by abubin
Wed May 15, 2019 5:17 am
Forum: General
Topic: same MAC address in two mikrotik
Replies: 6
Views: 3603

Re: same MAC address in two mikrotik

So does that means I have to run that command locally? I was thinking of changing the MAC remotely because the router is located in DC. Also, please let me know if any of the mikrotik settings will be reset when I change the MAC addresses. Another question is, should I change the MAC addresses one b...
by abubin
Tue May 14, 2019 12:56 pm
Forum: General
Topic: same MAC address in two mikrotik
Replies: 6
Views: 3603

same MAC address in two mikrotik

I just found out that there are 2 mikrotik sharing same MAC address. Probably from some cloning process that was done previously. My question is, both the devices are running live right now. Does running "reset-mac-address" command cause configurations rules to be reset as well? Will the w...
by abubin
Tue Jan 15, 2019 4:16 am
Forum: General
Topic: Need idea on setting up dual WAN connection
Replies: 6
Views: 1905

Re: Need idea on setting up dual WAN connection

Did some tests on VRRP. Here is what I am at: Site B1 (192.168.10.3) ----||---> [ (192.168.10.1) Mikrotik A1 (172.16.10.1) ---->] ---- backend switch [ ] VRRP (dual M/S)(192.168.10.254)<--[ ]---> VRRP (dual M/S)(172.16.10.254) [ ] Site B2 (192.168.10.4) ----||---> [ (192.168.10.2) Mikrotik A2 (172.1...
by abubin
Mon Jan 07, 2019 3:53 am
Forum: General
Topic: Need idea on setting up dual WAN connection
Replies: 6
Views: 1905

Re: Need idea on setting up dual WAN connection

Looks like VRRP is the way to go with above. Any comments?
by abubin
Fri Jan 04, 2019 4:05 am
Forum: General
Topic: Need idea on setting up dual WAN connection
Replies: 6
Views: 1905

Re: Need idea on setting up dual WAN connection

After some tests and learning experience, I think I got it. I just need to bridge the 2 connections and route the traffic accordingly. The above picture works and I do not need to implement any complicated load balancing setup.....yet. So with the basics out of the way, I would like to take this one...
by abubin
Fri Dec 28, 2018 5:57 am
Forum: General
Topic: Need idea on setting up dual WAN connection
Replies: 6
Views: 1905

Re: Need idea on setting up dual WAN connection

Assuming Site B will handle the load balancing (using ECMP). If I setup each line in Site B with different IP then I do not really need to configure load balancing in Site A, right? Site B1 (192.168.10.1) --------------| |----------> Mikrotik (SFP1 192.168.10.2), (SFP2 192.168.20.2) -----> Backend s...
by abubin
Fri Dec 28, 2018 4:22 am
Forum: General
Topic: Need idea on setting up dual WAN connection
Replies: 6
Views: 1905

Need idea on setting up dual WAN connection

I am trying to connect between 2 networks using mikrotik. Let's call it Site A and Site B. Connection between the 2 sites will be using SFP. Site A belongs to us and we got a mikrotik CCR1036-12G-4S. There will be 2 lines coming from Site B. So we can setup the two line as either Active-Passive or A...
by abubin
Mon Nov 14, 2016 8:05 am
Forum: Scripting
Topic: simple script that does not work in scheduler
Replies: 3
Views: 1363

Re: simple script that does not work in scheduler

anyone have any other ideas? I really need to get this working...
by abubin
Fri Nov 04, 2016 5:17 am
Forum: Scripting
Topic: simple script that does not work in scheduler
Replies: 3
Views: 1363

Re: simple script that does not work in scheduler

thanks for the quick reply. i tried removing the script and re-adding but still does not run from run-script or from scheduler. Directly running it or using "/system script run script-b" works
by abubin
Thu Nov 03, 2016 7:06 am
Forum: Scripting
Topic: simple script that does not work in scheduler
Replies: 3
Views: 1363

simple script that does not work in scheduler

I have a 2 scripts which have almost same line. Both run fine if I execute them manually. But when I run them from script or scheduler, it won't work. This is really strange and frustrating. The script is as below: script-a /interface ethernet switch ingress-port-policer disable number=0 script-b /i...
by abubin
Tue May 12, 2015 11:58 am
Forum: General
Topic: bridge mode and rate limit not working
Replies: 8
Views: 2843

Re: bridge mode and rate limit not working


That method works, did you tick in Bridge > Settings button "use ip firewall"??
Yes I did but still doeesn't work...
by abubin
Mon May 11, 2015 11:29 am
Forum: General
Topic: bridge mode and rate limit not working
Replies: 8
Views: 2843

Re: bridge mode and rate limit not working

tried and it doesn't work. few questions: - why do you use tree queue instead of simple queue? - there is packet-mark being used. It this needed? Did you mark the packet in firewall mangle? - queue being used is "pcq-download-default". But for all ports, default is "only-hardware-queu...
by abubin
Tue May 05, 2015 10:09 am
Forum: Beginner Basics
Topic: bridge mode with vpn
Replies: 4
Views: 1991

Re: bridge mode with vpn

after doing a little bit more googling, I think I have the idea on how to do this. So basically I will need to group the ports up. Probably create another group called group-lan which is port 17-24. This group will be used for internal IP and VPN. Then I assign locate IP address into this group? Is ...
by abubin
Tue May 05, 2015 9:52 am
Forum: Beginner Basics
Topic: bridge mode with vpn
Replies: 4
Views: 1991

Re: bridge mode with vpn

wow..good to know it can be done with mikrotik.

Can you provide some guide on how to do this? Perhaps some available tutorial or some sort simple instructions?

Thanks.
by abubin
Sat May 02, 2015 5:21 pm
Forum: Beginner Basics
Topic: bridge mode with vpn
Replies: 4
Views: 1991

bridge mode with vpn

i am new to mikrotik. I would like to know is it possible to have the mikrotik cloud switches set as bridge mode and at the same time configure VPN on it? What I would like to do is have some servers behind the mikrotik using LAN IP. In order to connect to these server, I would need to use VPN. Mayb...
by abubin
Tue Apr 28, 2015 10:42 am
Forum: General
Topic: CRS documentation
Replies: 79
Views: 38065

Re: CRS documentation

would it be possible to separate the documentation into v5 and v6? There are a lot of command differences between them and mixing them into same docs is confusing. On top of that all the examples given are for v5 which make it harder for v6 users to get familiar with CRS. I have been trying to weeks...
by abubin
Mon Apr 27, 2015 11:21 am
Forum: General
Topic: bridge mode and rate limit not working
Replies: 8
Views: 2843

Re: bridge mode and rate limit not working

hmm..no one can help?
by abubin
Thu Apr 23, 2015 12:37 pm
Forum: General
Topic: bridge mode and rate limit not working
Replies: 8
Views: 2843

Re: bridge mode and rate limit not working

ok, the method found is simple and nice. But it controls the whole port speed.

Can someone help with getting the queue method working? This method is preferred as it is more granular for controlling traffic rate limit.

Thanks.
by abubin
Thu Apr 23, 2015 9:34 am
Forum: General
Topic: bridge mode and rate limit not working
Replies: 8
Views: 2843

Re: bridge mode and rate limit not working

found the easier solution: http://wiki.mikrotik.com/wiki/Manual:CRS_features Bandwidth Limiting Both Ingress Port policer and Shaper provide bandwidth limiting features for CRS switches. Ingress Port Policer sets RX limit on port: /interface ethernet switch ingress-port-policer add port=ether5 meter...
by abubin
Wed Apr 22, 2015 7:05 am
Forum: General
Topic: bridge mode and rate limit not working
Replies: 8
Views: 2843

bridge mode and rate limit not working

I just got a CRS125-24G-1S-RM.

We wanted to run it in bridge mode (transparent) and with rate limit.

I have tried following this guide http://wiki.mikrotik.com/wiki/TransparentTrafficShaper

but it is not working. Anyone can provide some help please?
by abubin
Mon Dec 10, 2012 11:07 am
Forum: RouterBOARD hardware
Topic: RB751U-2Hn frequent (daily) reboots
Replies: 111
Views: 86468

Re: RB751U-2Hn frequent (daily) reboots

is this a joke? the problem was reported on Nov 2011 and now it's already 1 year and still not fixed? How can we (system integrator) rely on this product with such bad support? This is a major issue that is a deal breaker for this router. If support is unable to fix it, the company should have reca...
by abubin
Mon Dec 10, 2012 6:47 am
Forum: RouterBOARD hardware
Topic: RB751U-2HnD
Replies: 4
Views: 2326

Re: RB751U-2HnD

if you want to fix the cpu-load-high-when-turn-on-wifi-reboot-issue then don't waste your time. Look at the other thread where they discuss about this issue. ros6 does not fix this problem. We tested latest 5.22 firmware and it is even worst. No one is connected to the wifi and it still reboots. I a...
by abubin
Mon Dec 10, 2012 6:31 am
Forum: RouterBOARD hardware
Topic: RB751U-2Hn frequent (daily) reboots
Replies: 111
Views: 86468

Re: RB751U-2Hn frequent (daily) reboots

is this a joke? the problem was reported on Nov 2011 and now it's already 1 year and still not fixed? How can we (system integrator) rely on this product with such bad support? This is a major issue that is a deal breaker for this router. If support is unable to fix it, the company should have recal...
by abubin
Fri Sep 14, 2012 11:23 am
Forum: Beginner Basics
Topic: HOTSPOT - issues with secure web pages.
Replies: 22
Views: 15650

Re: HOTSPOT - issues with secure web pages.

I also discovered this problem and apparently there are no REAL solution to it. From my research in this forum, found out that because mikrotik hotspot is unable to redirect https connection to hotspot login page. This is problem with https protocol and proxy. Cause hotspot login redirection is some...
by abubin
Fri Sep 14, 2012 6:12 am
Forum: General
Topic: Android 2.34 and MT hotspot problem
Replies: 6
Views: 3929

Re: Android 2.34 and MT hotspot problem

Hai...I Think your DHCP network netmasik is /32, netmask 32 not work with gingerbird...so back to netmask /24 but dangerous with netcut. or change your android with ice cream sandwich :-). soryy my english Awesome!! This solved the problem!! Apparently Android 2.3.x have problem using other than /2...
by abubin
Thu Sep 13, 2012 12:17 pm
Forum: General
Topic: Android 2.34 and MT hotspot problem
Replies: 6
Views: 3929

Re: Android 2.34 and MT hotspot problem

wow..is surprised that this is a known problem but no solution yet. I am currently met with this problem as well. MT750. Problem only happen when using android 2.3.x. Android honeycomb 3.x and ICS 4.x does not have this problem. Can login fine. Anyone have any solution? This is important because the...
by abubin
Tue Aug 28, 2012 1:32 pm
Forum: Scripting
Topic: reading text file line by line not working correctly in wiki
Replies: 1
Views: 5664

Re: reading text file line by line not working correctly in

I found the solution myself.

Change
:local entry [:pick $line 0 ($lineEnd -1) ]
to
:local entry [:pick $line 0 $lineEnd ]
by abubin
Fri Aug 10, 2012 12:32 pm
Forum: Scripting
Topic: reading text file line by line not working correctly in wiki
Replies: 1
Views: 5664

reading text file line by line not working correctly in wiki

I have some script that I need to implement that read certain text file for the content line by line and output accordingly. This script to read line by line were copied from an example in wiki. Excerpt is as below: if ( [/file get [/file find name=text.txt] size] > 0 ) do={ :global content [/file g...
by abubin
Fri Aug 03, 2012 2:12 pm
Forum: Scripting
Topic: adding walled-garden to hotspot does not work from script
Replies: 1
Views: 2812

Re: adding walled-garden to hotspot does not work from scrip

ok, i found the problem. This is due to the wall.txt file. All the entries in the text file have an empty space at the end of each line. Therefore, mikrotik.com becomes "mikrotik.com ". Note the space after "m". So the mikrotik was unable to resolve the domain names correctly due...
by abubin
Fri Aug 03, 2012 12:56 pm
Forum: Scripting
Topic: adding walled-garden to hotspot does not work from script
Replies: 1
Views: 2812

adding walled-garden to hotspot does not work from script

I have a script that download a text file from remote website. Then it will go through the file line by line to all entry into walled-garden ip list. However, the relevant dynamic entries are not added into walled-garden and firewall filters. I follow example as depicted in this http://wiki.mikrotik...