Community discussions

MikroTik App

Search found 108 matches

by slimprize
Mon May 29, 2023 4:39 pm
Forum: Beginner Basics
Topic: Wi-FI not visible
Replies: 7
Views: 2885

Re: Wi-FI not visible

Hi, I have reset the configuration. I need to setup the router as a wireless access point. I have done this using the following set of commands. /system reset-configuration no-defaults=yes Create the bridge /interface bridge add name=bridge-lan Add all the interfaces to the bridge /interface bridge ...
by slimprize
Mon May 29, 2023 2:41 pm
Forum: Beginner Basics
Topic: Wi-FI not visible
Replies: 7
Views: 2885

Re: Wi-FI not visible

Hi,

ok, I'll do that and update this thread.

Pranav
by slimprize
Mon May 29, 2023 3:07 am
Forum: Beginner Basics
Topic: Wi-FI not visible
Replies: 7
Views: 2885

Re: Wi-FI not visible

Hi all, Thanks for your comments. So, can I reset just the wifi wave 2 configuration and start a fresh? I prefer using the commandline. I ran the reset command like reset wifi1 and then reset wifi2 [admin@MikroTik] /interface/wifiwave2> export # may/29/2023 05:34:57 by RouterOS 7.9.1 # software id =...
by slimprize
Sun May 28, 2023 6:13 pm
Forum: Beginner Basics
Topic: Wi-FI not visible
Replies: 7
Views: 2885

Wi-FI not visible

Hi all, I am unable to see the wi-fi ssid on any device which I try to connect with my router. If I connect a LAN cable to the router, it can access the internet without any problems. The router is connected to another router which is the gateway to the internet. Why is the wi-fi ssid not visible? H...
by slimprize
Sat Aug 13, 2022 4:14 pm
Forum: Wireless Networking
Topic: Using the wps button to connect a device
Replies: 2
Views: 6255

Re: Using the wps button to connect a device

Hi holvoetn,
Many thanks. I did search but I apparently used the wrong keywords because I did not find this reference.
I'll try the wps once my device gets here.
by slimprize
Sat Aug 13, 2022 5:23 am
Forum: Wireless Networking
Topic: Using the wps button to connect a device
Replies: 2
Views: 6255

Using the wps button to connect a device

Hi all, I have a hap ac^2 RBD52G-5HacD2HnD router running ROS 7.4.1. I need to use wps to connect a device to it. The device is proprietary and only supports connecting via the wps mechanism. I am using the commandline therefore how went to /interface wireless I see an option called wps-push-button....
by slimprize
Sun Jan 30, 2022 12:10 pm
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Re: Unable to ssh to my server when I use a static ip address

Hi,

The gateways are defined correctly. However, so far, I have not removed any ports from the bridge.

Pranav
by slimprize
Sat Jan 29, 2022 2:08 am
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Re: Unable to ssh to my server when I use a static ip address

Hi all, I do not have any vlan aware switches hence have not set them up. As for other devices on the network, let me describe the setup. 1. There is a DSL modem router which is operating in bridge mode. This is a device given to me by my internet service provider. It has a fiber cable coming in. Th...
by slimprize
Fri Jan 28, 2022 1:04 pm
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Re: Unable to ssh to my server when I use a static ip address

Hi,
<snip /ip address set [ find address="192.168.3.1/24" ] interface=bridge

Or you already did it but you still have problem described in your initial
PL] I did this so the segment 192.168.3.1/24 is now on the bridge interface. However, the problem is the same.

Pranav
by slimprize
Fri Jan 28, 2022 1:58 am
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Re: Unable to ssh to my server when I use a static ip address

Hi all, Many thanks for your suggestions and comments. 1. I am going to retain the camera segment. The problem there is that the ports are mixed with other stuff. However, I am happy to remove that port from the bridge and get routing rules in place. 2. I'll put the server and NAS on static DHCP lea...
by slimprize
Thu Jan 27, 2022 6:51 pm
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Re: Unable to ssh to my server when I use a static ip address

Hi all, Thanks for your comments and questions. In terms of the purpose of my setup: 1. I have a general lan at 192.168.88.1/24 which has devices like my desktop, my mobile phone, an amazon fire stick etc. 2. I have some IP cameras in the house. I have given them their own network segment at 192.168...
by slimprize
Thu Jan 27, 2022 3:13 pm
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Re: Unable to ssh to my server when I use a static ip address

Hi, <snip /ip firewall nat add chain="chain=dstnat action=redirect to-ports=53 protocol=udp dst-port=53 to-address=192.168.881 comment=Make Mikrotik preferred dns server" PL] No copy paste, that was exactly how the rule was. I am surprised the router accepted it. I have fixed that rule now...
by slimprize
Thu Jan 27, 2022 8:48 am
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Re: Unable to ssh to my server when I use a static ip address

Hi, I am using the windows 11 open ssh client. I have also tried putty with the same results. See the attachment for the configuration. If it does not come through this time, I'll post the configuration in my message. The windows client is in the 192.168.88.1/24 range and the linux server is in the ...
by slimprize
Thu Jan 27, 2022 6:03 am
Forum: Beginner Basics
Topic: Unable to ssh to my server when I use a static ip address
Replies: 27
Views: 4520

Unable to ssh to my server when I use a static ip address

Hi all, I am running the following router. routerboard: yes board-name: hAP ac^2 model: RBD52G-5HacD2HnD firmware-type: ipq4000L factory-firmware: 6.44 current-firmware: 7.1.1 upgrade-firmware: 7.1.1 I have the router configured to serve addresses via dhcp. I have a linux server which when given an ...
by slimprize
Sat Oct 09, 2021 12:48 pm
Forum: Beginner Basics
Topic: How do I configure a HAP ac as a wireless access point
Replies: 8
Views: 4327

Re: How do I configure a HAP ac as a wireless access point

Hi,

Many thanks for the configuration. I found the problem. I had not assigned a dhcp client to the bridge.

Pranav
by slimprize
Fri Oct 08, 2021 2:51 am
Forum: Beginner Basics
Topic: How do I configure a HAP ac as a wireless access point
Replies: 8
Views: 4327

Re: How do I configure a HAP ac as a wireless access point

Hi, Sorry about the verbose export and thanks for reminding me about the hide sensitive option. I have 2 IP addresses because the router asked me for a lan side network address. I had to put something in which I did. Otherwise, web fig was not applying the configuration. I am happy to start from scr...
by slimprize
Thu Oct 07, 2021 8:43 pm
Forum: Beginner Basics
Topic: How do I configure a HAP ac as a wireless access point
Replies: 8
Views: 4327

Re: How do I configure a HAP ac as a wireless access point

Hi, Many thanks for your lucid instructions. I however am making a mistake somewhere. See the below verbose export. When I take the router to the location where it needs to be, I do not get any wireless signals from the router. I did try plugging in the LAN cable without successs. I can however acce...
by slimprize
Thu Oct 07, 2021 4:27 am
Forum: Beginner Basics
Topic: How do I configure a HAP ac as a wireless access point
Replies: 8
Views: 4327

How do I configure a HAP ac as a wireless access point

Hi all, I have a spare RouterBOARD 962UiGS-5HacT2HnT router. I want to configure it as a wireless access point. What do I need to do? Could you please give me instructions from the terminal? I am blind so prefer using the commanddline because of accessibility challenges with the web fig interface an...
by slimprize
Wed Oct 06, 2021 8:04 pm
Forum: Beginner Basics
Topic: hAP AC Lite Setup as Access Point Only
Replies: 4
Views: 3990

Re: hAP AC Lite Setup as Access Point Only

Hi all,

I have exactly the same requirement as the originater of this thread. I set the router to bridge mode however. Is that something I was supposed to do? Should I keep the mode at router?

Pranav
by slimprize
Thu Jul 08, 2021 3:13 am
Forum: Beginner Basics
Topic: Disabling2.4GHZ wifi
Replies: 3
Views: 1263

Re: Disabling2.4GHZ wifi

Hi, Many thanks. The /interface wireless disable [find where band~"2"] did the trick. Pranav [pranav@ConShield] /interface> print Flags: D - dynamic, X - disabled, R - running, S - slave # NAME TYPE ACTUAL-MTU L2MTU 0 R ether1 ether 1500 1598 1 RS ether2 ether 1500 1598 2 RS ether3 ether 1...
by slimprize
Wed Jul 07, 2021 6:05 pm
Forum: Beginner Basics
Topic: Disabling2.4GHZ wifi
Replies: 3
Views: 1263

Disabling2.4GHZ wifi

Hi all,

Is it possible to disable the 2.4GHZ wifi from the commandline?

I have upgraded all my home devices to 5GHZ wireless so want to turn off the 2.4GHZ wireless.
Pranav
by slimprize
Thu Jun 17, 2021 1:47 pm
Forum: Beginner Basics
Topic: Coping with slow download speeds on my home LAN
Replies: 8
Views: 2152

Re: Coping with slow download speeds on my home LAN

Hi rextended, I should have seen that coming. <smile I am confused by the mikrotik website. May be it is just me but it is hard to determine which of their devices are routers and which are access points. Could you perhaps share a link to one access point? I am hoping for something that can support ...
by slimprize
Thu Jun 17, 2021 11:42 am
Forum: Beginner Basics
Topic: Coping with slow download speeds on my home LAN
Replies: 8
Views: 2152

Re: Coping with slow download speeds on my home LAN

Hi Metod, Yes, I tried with the pc connected directly to the mikrotik and get about 700MBPS as download and 925MBPS as upload which is what I expect. I have tried changing cables without any change. I have tried on wireless and we are getting 500MBPS download and a similar number as upload. Could it...
by slimprize
Thu Jun 17, 2021 2:36 am
Forum: Beginner Basics
Topic: Coping with slow download speeds on my home LAN
Replies: 8
Views: 2152

Re: Coping with slow download speeds on my home LAN

Hi Metod,
The Netgear access points act as switches. All IP address assignments are done by the mikrotik.
I have now changed the assignments of the sub nets to interface=bridge.
Many thanks for that pointer.

I had connected the pc to the Netgear access point via a LAN cable.
Pranav
by slimprize
Wed Jun 16, 2021 2:29 pm
Forum: Beginner Basics
Topic: Coping with slow download speeds on my home LAN
Replies: 8
Views: 2152

Re: Coping with slow download speeds on my home LAN

Hi @Metod, 1. I want to ensure that all devices use only the router for querying dns hence those rules relating to port 53. 2. The Netgear access point is connected to the Gigabit switch via a cat 6 cable. The switch is then connected to the router. 3. I do nee the sub nets because I have a dedicate...
by slimprize
Wed Jun 16, 2021 12:58 pm
Forum: Beginner Basics
Topic: Coping with slow download speeds on my home LAN
Replies: 8
Views: 2152

Coping with slow download speeds on my home LAN

Hi all, Users on my home LAN if they are connected to one of the access point's are experiencing significantly reduced download speeds. The way my LAN is designed is as follows. 1. There is a Huawei+adsl+modem+hg532d which is ISP supplied. This is set to bridge mode. It has an incoming fibre optic l...
by slimprize
Fri Apr 30, 2021 3:17 am
Forum: General
Topic: Massive slowdown after upgrading to routeros 6.48.2
Replies: 5
Views: 1311

Re: Massive slowdown after upgrading to routeros 6.48.2

Hi all, I have upgraded the router. board-name: hAP ac^2 model: RBD52G-5HacD2HnD serial-number: C6140DDD9D8F firmware-type: ipq4000L factory-firmware: 6.44 current-firmware: 6.48.2 upgrade-firmware: 6.48.2 I am attaching the configuration of the new router. The speed issues persist. Fast track is ac...
by slimprize
Sat Apr 24, 2021 11:53 am
Forum: General
Topic: Massive slowdown after upgrading to routeros 6.48.2
Replies: 5
Views: 1311

Re: Massive slowdown after upgrading to routeros 6.48.2

Hi, The second reboot may well have solved the wireless issue. The slowdown however has an interesting solution. The problem was with my desktop from where I was conducting the speed test. Its LAN interface was flaky. The router's reboot was fixing the problem because the desktop would reconnect to ...
by slimprize
Sat Apr 24, 2021 6:01 am
Forum: General
Topic: Massive slowdown after upgrading to routeros 6.48.2
Replies: 5
Views: 1311

Re: Massive slowdown after upgrading to routeros 6.48.2

Hi, I went to /interface ethernet I have a pppoe interface and the ISP's DSL modem router which is running in bridge mode is connected to ether1. I ran the monitor and get the following output. [pranav1@ConShield] /interface ethernet> monitor ether1 name: ether1 status: link-ok auto-negotiation: don...
by slimprize
Fri Apr 23, 2021 3:03 am
Forum: General
Topic: Massive slowdown after upgrading to routeros 6.48.2
Replies: 5
Views: 1311

Massive slowdown after upgrading to routeros 6.48.2

Hi all, When I upgraded to routeros 6.48.2, I began experiencing massive slowdowns. I initially thought the problem was only with the wireless connection of the router but the entire router was impacted. I have a 1GBPS connection from my ISP and was getting only 90MBPS. This was with a desktop conne...
by slimprize
Thu Apr 22, 2021 5:23 pm
Forum: Wireless Networking
Topic: Wireless disconnection after updating to routeros 6.48.2
Replies: 4
Views: 1187

Re: Wireless disconnection after updating to routeros 6.48.2

Hi,

The plot thickens. I did set my country which helped a little bit. I however then saw that my LAN speed was also really slow.

I downgradedd to 6.48.2 and everything is working the way it was.

What is going on with this update?
by slimprize
Thu Apr 22, 2021 10:18 am
Forum: Wireless Networking
Topic: Wireless disconnection after updating to routeros 6.48.2
Replies: 4
Views: 1187

Re: Wireless disconnection after updating to routeros 6.48.2

Hi,
I am attaching the configuration file to this message.

I will upgrade the firmware, I thought a single reboot was sufficient after the upgrade. I cannot reboot immediately (home office running) but will do so in about an hour or so.
by slimprize
Thu Apr 22, 2021 9:51 am
Forum: Wireless Networking
Topic: Wireless disconnection after updating to routeros 6.48.2
Replies: 4
Views: 1187

Wireless disconnection after updating to routeros 6.48.2

Hi all, I have the following router. 962UiGS-5HacT2HnT See below for more details. routerboard: yes board-name: hAP ac model: RouterBOARD 962UiGS-5HacT2HnT firmware-type: qca9550L factory-firmware: 3.41 current-firmware: 6.48.1 upgrade-firmware: 6.48.2 I have upgraded to routeros 6.48.2 today. Since...
by slimprize
Thu Jun 18, 2020 4:40 am
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121334

Re: DNS over HTTPS

@Sob,
Many many thanks. I have DNS over https working. Website lookups are slow so I am not sure if I will keep this configuration. I want to though so lets see.

Pranav
by slimprize
Wed Jun 17, 2020 4:13 pm
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121334

Re: DNS over HTTPS

Hi all,

Has anyone gotten opendns's doh server to work?

As I said above I tried but was getting resolution errors despite importing the certificate.
by slimprize
Sun Jun 14, 2020 5:20 pm
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121334

Re: DNS over HTTPS

slimprize. that's what I do . in the PEM download section. Schermata del 2020-06-14 08.31.14.png PL] frank333, your screen shot is not clear. Could you please describe the procedure from the commandline interface? Do all certificates need to be in pem format? I seemed to have imported the one corre...
by slimprize
Sun Jun 14, 2020 8:40 am
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121334

Re: DNS over HTTPS

Hi all,
Does anyone know the URL to download the certificate for opendns? I am getting dns resolution errors.
I tried
https://support.opendns.com/hc/en-us/ar ... evelopers-
No go though the certificate was imported successfully.
by slimprize
Fri Jun 05, 2020 2:07 pm
Forum: Beginner Basics
Topic: Signaling other computers when a specific amount of runtime is left in a connected UPS
Replies: 2
Views: 1040

Re: Signaling other computers when a specific amount of runtime is left in a connected UPS

Hi,
The UPS does not have a LAN card hence I am planning to connect it to the router. As of now, I do not have snmp but let me see if I can enable it in the router and manage my devices.
by slimprize
Thu Jun 04, 2020 8:43 pm
Forum: Beginner Basics
Topic: Signaling other computers when a specific amount of runtime is left in a connected UPS
Replies: 2
Views: 1040

Signaling other computers when a specific amount of runtime is left in a connected UPS

Hi all,

Is it possible to signal other computers on my LAN when a UPS connected to the router has 10 minutes of runtime remaining? This way, they can begin shutting down gracefully.
I have an APC SUA1000UXI ups. The router is a Mikrotik 962UiGS-5HacT2HnT on ros 6.7.

Pranav
by slimprize
Mon Jun 01, 2020 5:07 am
Forum: General
Topic: Router stopped working suddenly: powering off and on does not help
Replies: 10
Views: 5264

Re: Router stopped working suddenly: powering off and on does not help

Hi @Metog,
<snip Make text export of config ... binary backup is only usable (with ceveat) on same model of routers.
PL] Excellent advice. I did make a text export as you had suggested and was unable to import it. I however manually referenced the file and got things to work.
by slimprize
Sun May 31, 2020 5:29 am
Forum: Beginner Basics
Topic: Unable to get expected speed with router
Replies: 2
Views: 1065

Re: Unable to get expected speed with router

Hi,
Many thanks. I am tempted to grab the rb4011 with wifi at some future point. The CCR range seems to be a tad overkill for my small setup but I am glad its there and I'll factor it in into my next upgrade.

Pranav
by slimprize
Sat May 30, 2020 9:40 pm
Forum: Beginner Basics
Topic: Unable to get expected speed with router
Replies: 2
Views: 1065

Unable to get expected speed with router

Hi all, I have a RouterBOARD 962UiGS-5HacT2HnT It is connected to my ISP supplied OLT. The advertised speed of the connection is 1GBPS and that is what ether1 shows when it is connected to the ISP's modem which is running in bridge mode. My ISP uses pppoe. I am not getting the advertised speed of 1G...
by slimprize
Sat May 30, 2020 4:25 am
Forum: Beginner Basics
Topic: Cannot get a PPPoE connection to work with BT (UK)
Replies: 3
Views: 1674

Re: Cannot get a PPPoE connection to work with BT (UK)

I have just have had to setup my DSL modem router so here goes. 1. Is the draytech in bridge mode or are you using a double nat setup? 2. I think you are complicating the setup. For pppoe, /interface pppoe-client add name="BT" user=login password=pwd add-default-route=yes enable 0 assuming...
by slimprize
Sat May 30, 2020 4:01 am
Forum: Beginner Basics
Topic: What do I ask my isp to determine fiber and or spf compatibility
Replies: 3
Views: 1313

Re: What do I ask my isp to determine fiber and or spf compatibility

Hi all, I have done more research. The ISP is ok with me using my own. I was looking at the following fiber module. https://store.ui.com/collections/operator-ufiber/products/uf-instant The ISP uses a GPON network. Would Mikrotik support this module? I am visualizing that I would plugin the fiber cab...
by slimprize
Wed May 20, 2020 5:21 am
Forum: Beginner Basics
Topic: What do I ask my isp to determine fiber and or spf compatibility
Replies: 3
Views: 1313

What do I ask my isp to determine fiber and or spf compatibility

Hi all, I have a Mikrotik RB962UiGS-5HacT2HnT router. It has a fiber port. I understand that all internet service providers are not compatible with this fiber. What should I ask my isp to check fiber compatibility and what spf module should I get for a small office / home usage? My ISP connection's ...
by slimprize
Fri May 15, 2020 7:22 pm
Forum: General
Topic: Router stopped working suddenly: powering off and on does not help
Replies: 10
Views: 5264

Re: Router stopped working suddenly: powering off and on does not help

Hi all, Many thanks for the reset procedure. The router is indeed on a UPS which is an APC SUA1000UXI UPS. The UPS does work. I have tested it. I did check the health of the router and the health command does not give any output except a blank line. I checked the router board section and the storage...
by slimprize
Fri May 15, 2020 5:37 am
Forum: General
Topic: Router stopped working suddenly: powering off and on does not help
Replies: 10
Views: 5264

Re: Router stopped working suddenly: powering off and on does not help

Hi all, The mystery deepens. I tested the router this morning and it is back online. I have checked its logs and the last thing I see is a reference to an improper shutdown. There does not appear to be anything else in the logs. I did do a reset but that did not work because all my settings are inta...
by slimprize
Thu May 14, 2020 8:29 pm
Forum: General
Topic: Router stopped working suddenly: powering off and on does not help
Replies: 10
Views: 5264

Re: Router stopped working suddenly: powering off and on does not help

Hi,

Many thanks. I did try winbox but nothing shows up in the neighbors tab.
by slimprize
Thu May 14, 2020 7:13 pm
Forum: General
Topic: Router stopped working suddenly: powering off and on does not help
Replies: 10
Views: 5264

Re: Router stopped working suddenly: powering off and on does not help

Hi, I tried a reset using the reset button. I held down the reset button until the light began flashing. Well, no go. I still cannot get to the router. I have tried manually setting the IP address and gateway on my local desktop and have tried connecting to the router. It does not return any respons...
by slimprize
Thu May 14, 2020 5:34 pm
Forum: General
Topic: Router stopped working suddenly: powering off and on does not help
Replies: 10
Views: 5264

Router stopped working suddenly: powering off and on does not help

Hi all, I have a Mikrotik RB751g-2hnd router. It has been working flawlessly for the past 8 years. I suddenly lost connectivity. The router's lights are glowing but it is not doing anything. I have tried entering the router via winbox but the router does not show up. How do I do a hardware reset of ...
by slimprize
Thu Dec 19, 2019 7:35 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi Tom, I suspect the problem was that I was using the pppoe interface. https://groups.google.com/forum/#!topic/security-onion/XUUNgIGqsv4 gave me a clue; I have run the test script mentioned at the above URL and am getting alerts ever since I set the sniffer interface to ether1 on the Mikrotik. Man...
by slimprize
Wed Dec 18, 2019 4:41 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi Tom, Your sniffer streaming from the mikrotik is set up and you are seeing data? PL] Yes. Your streaming server is your suricata host? PL] Yes. The interface is the port connected to your ISP? PL] Ahem, I have a pppoe connection so that is the interface I have defined for sniffing. Should I defin...
by slimprize
Tue Dec 17, 2019 5:28 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi Tom, Many thanks. I tried reading the output of tzsp2pcap from the command line and suricata launched without a problem How have you defined your network? I went to /interface on my mikrotik, and specified the different address ranges I have. Something like 192.168.88.0/24, 192.168.3.0/24 I ask b...
by slimprize
Mon Dec 16, 2019 6:29 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi Tom, https://bløgg.no/2015/03/ids-with-mikrotik-and-snort/ did the trick in terms of getting packets. I believe my streaming is working but now, do I use snort and then send to suricata? Sorry, I remain puzzled about the pipeline here. I plan to implement the IPS functionality but will use IDS an...
by slimprize
Mon Dec 16, 2019 11:49 am
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi Tom,
Thanks for confirming the use of tzsp2pcap. Is there any documentation on how to get it going? I have cloned its source and see the make file but I suspect I need to install headers etc., to build the program.
by slimprize
Sun Dec 15, 2019 5:50 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi,
I am sending the stream from the sniffer tool directly to a Linux box on which I have installed suricata. Do I need an intermediate tool?

Pranav
by slimprize
Sat Dec 14, 2019 3:57 pm
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi, I have suricata setup on my Linux machine. I have enabled the Mikrotik to stream like this. [pranav1@ConShield] /tool> sniffer [pranav1@ConShield] /tool sniffer> print only-headers: no memory-limit: 100KiB memory-scroll: yes file-name: file-limit: 1000KiB streaming-enabled: yes streaming-server:...
by slimprize
Fri Dec 13, 2019 3:05 am
Forum: General
Topic: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)
Replies: 216
Views: 1082260

Re: Suricata IDS/IPS integration with Mikrotik (now with OSSEC)

Hi all, Could someone please point me to a resource that shows me how to set up Suricata from scratch? I have a server running Ubuntu 19.10 and a mikrotik RB751g-2hnd router. The router is the gateway to my home network. It handles PPPOE authentication with my ISP. I already have the firewall config...
by slimprize
Sun May 27, 2018 5:20 am
Forum: Beginner Basics
Topic: Can I set static DNS server priority
Replies: 8
Views: 5149

Re: Can I set static DNS server priority

Thanks msatter. These are exactly the instructions I needed.
by slimprize
Sat May 26, 2018 4:35 am
Forum: Beginner Basics
Topic: Can I set static DNS server priority
Replies: 8
Views: 5149

Re: Can I set static DNS server priority

Hi all, Many thanks for your response. The Mikrotik documentation is indeed silent on the order of DMS. I have put the addguard servers first. msatter, can you tell me more about dnsmasq? I had read about piHole and have a spare pi with me. How did you configure it? The router is advertising the DNS...
by slimprize
Fri May 25, 2018 7:38 pm
Forum: Beginner Basics
Topic: Can I set static DNS server priority
Replies: 8
Views: 5149

Can I set static DNS server priority

Hi all, I have a Mikrotik 751G-2HnD router. I am currently using opendns for additional security. However, I want to do add blocking therefore want to put the DNS servers of adguard. I want the DNS look up to happen such that the adguard servers are used first. If they fail, the router should refer ...
by slimprize
Mon May 29, 2017 5:40 pm
Forum: Beginner Basics
Topic: Mobile phones unable to connect after enabling management protection
Replies: 7
Views: 4195

Re: Mobile phones unable to connect after enabling management protection

<snip I am curious, do you have deauth attacks in a your home network?.
PL] Yes. I am happy to decrease the power levels. Where do I do this from if I am using the terminal?
by slimprize
Sun May 28, 2017 5:26 am
Forum: Beginner Basics
Topic: Request for firewall rule verification: using services like ssh and ftp inside my LAN
Replies: 12
Views: 1914

Re: Request for firewall rule verification: using services like ssh and ftp inside my LAN

Hi, <snip The DHCP IP on ether1 is being handed by the ISP modem so that you can manage it. PL] There is no modem. I have an Ethernet cable coming into my house. It goes to a media converter from where the traffic is placed on to a fiber optic cable. The ISP does have a feature where I can use a bro...
by slimprize
Sat May 27, 2017 3:56 pm
Forum: Beginner Basics
Topic: Request for firewall rule verification: using services like ssh and ftp inside my LAN
Replies: 12
Views: 1914

Re: Request for firewall rule verification: using services like ssh and ftp inside my LAN

Hi, <snip Odd... is pppoe-out1 your WAN interface??? PL] How do I confirm this? I ask because my new ISP is doing something strange. It is also giving me an ip address on ether1 but when I go to whatismyip.com, I see the address assigned to pppoe-out1. I have also tried disabling the client on ether...
by slimprize
Sat May 27, 2017 3:16 pm
Forum: Beginner Basics
Topic: Request for firewall rule verification: using services like ssh and ftp inside my LAN
Replies: 12
Views: 1914

Re: Request for firewall rule verification: using services like ssh and ftp inside my LAN

Hi, ok I removed the new portion from connection-state from rule number 7. My revised rules are below. 0 D ;;; special dummy rule to show fasttrack counters chain=forward action=passthrough 1 ;;; defconf: fasttrack chain=forward action=fasttrack-connection connection-state=established,related 2 ;;; ...
by slimprize
Sat May 27, 2017 2:56 pm
Forum: Beginner Basics
Topic: Request for firewall rule verification: using services like ssh and ftp inside my LAN
Replies: 12
Views: 1914

Re: Request for firewall rule verification: using services like ssh and ftp inside my LAN

Hi all, I was wrong about my initial report. I did another port scan and the ports remain open. My updated set of rules is below. I have also checked the default configuration and except a rule for accepting icmp traffic, I have the remaining rules in place or so I think. 0 D ;;; special dummy rule ...
by slimprize
Sat May 27, 2017 10:18 am
Forum: Beginner Basics
Topic: Request for firewall rule verification: using services like ssh and ftp inside my LAN
Replies: 12
Views: 1914

Re: Request for firewall rule verification: using services like ssh and ftp inside my LAN

Hi, add action=drop chain=input comment="defconf: drop all from WAN" in-interface=pppoe-out1 did the trick in terms of when I port scan the router from the outside, all the ports are shown as filtered. However, why do I need this rule if I am already dropping invalid and new packets? What ...
by slimprize
Fri May 26, 2017 6:44 pm
Forum: Beginner Basics
Topic: Request for firewall rule verification: using services like ssh and ftp inside my LAN
Replies: 12
Views: 1914

Request for firewall rule verification: using services like ssh and ftp inside my LAN

Hi all, I changed ISPS and have had to reconfigure my firewall. pppoe-out1 is my WAN interface. This is a home setup. I want to be able to ssh into the router but only from the LAN. The same applies to using FTP and other services of the router. I do not plan to run any servers. I do however use pro...
by slimprize
Fri May 26, 2017 5:13 pm
Forum: Beginner Basics
Topic: Mobile phones unable to connect after enabling management protection
Replies: 7
Views: 4195

Re: Mobile phones unable to connect after enabling management protection

Hi,
This is a home network. I do not run any servers on it. I do have one access point connected to the router via a cable.
by slimprize
Thu May 25, 2017 7:58 pm
Forum: Beginner Basics
Topic: Mobile phones unable to connect after enabling management protection
Replies: 7
Views: 4195

Re: Mobile phones unable to connect after enabling management protection

Hi Gustavo,

Thanks for the clarification. What can I do? I want to prevent deauth attacks but setting management protection is making my wireless network useless. Is there any other way?

Pranav
by slimprize
Wed May 24, 2017 7:47 pm
Forum: Beginner Basics
Topic: Unable to login via ssh after enabling strong-crypto
Replies: 0
Views: 958

Unable to login via ssh after enabling strong-crypto

Hi all, I have enabled strong-crypto on my RB751g-2hnd router running router OS 6.39.1. I have tried logging in via putty and tera term without success. I can however login via mac-telnet. See the below log snippet. 22:07:56 system,error,critical login failure for user pranav from 192.168.88.15 via ...
by slimprize
Wed May 24, 2017 7:32 pm
Forum: Beginner Basics
Topic: Mobile phones unable to connect after enabling management protection
Replies: 7
Views: 4195

Mobile phones unable to connect after enabling management protection

Hi all, I have been experiencing wireless deauth attacks. I have a RB751g-2hnd router running router OS 6.39.1. I have a mix of wired and wireless clients. This setup is in a home environment. I enabled management protection and the iPhone can see the SSID but cannot connect. I am pasting the export...
by slimprize
Thu Jan 05, 2017 4:52 pm
Forum: General
Topic: Unable to get bridge mode working on my Mikrotik RB751g-2hnd after the switch to VDSL
Replies: 0
Views: 531

Unable to get bridge mode working on my Mikrotik RB751g-2hnd after the switch to VDSL

Hi all I am unable to get bridge mode configuration working on my VDSL connection. I have a Huawei HG630a DSL modem router. This is connected to my Mikrotik RB751g-2hnd router. It is in a double NAT setup which I want to change to a setup where I set the Huawei HG630a in bridge mode and the Mikrotik...
by slimprize
Mon Nov 14, 2016 4:57 pm
Forum: Beginner Basics
Topic: Urgent: unable to connect via pppoe after upgrade to DSL vector
Replies: 0
Views: 589

Urgent: unable to connect via pppoe after upgrade to DSL vector

Hi all, My ISP has upgraded to DSL vector. I am unable to connect using the mikrotik pppoe client after that upgrade. The client keeps trying to connect but fails. My credentials are correct The ISP has supplied a new modem which is a HUAWEI hg630A. I did set that modem to bridge mode like I had don...
by slimprize
Wed Oct 19, 2016 2:35 am
Forum: Beginner Basics
Topic: Unable to see imported scripts in script repository
Replies: 2
Views: 770

Re: Unable to see imported scripts in script repository

Hi David,

Many thanks for your explanation. I had always wondered about this but finally asked.

Pranav
by slimprize
Tue Oct 18, 2016 8:12 pm
Forum: Beginner Basics
Topic: Unable to see imported scripts in script repository
Replies: 2
Views: 770

Unable to see imported scripts in script repository

Hi all, If I import a script which is saved in the root of my Mikrotik router, I am unable to see it when I do a /system script print The script does run because I can see its output in the router logs. Do I need to import the script every time? I want to import and then schedule the script. router ...
by slimprize
Tue Oct 18, 2016 8:07 pm
Forum: Beginner Basics
Topic: iPhone SE unable to join wireless network
Replies: 4
Views: 3913

Re: iPhone SE unable to join wireless network

Hi Tom and all,

I have finally got my iPhone connected. I did not however create access-lists. See the post at the below link which helped me.
https://www.beardy.se/securing-the-mikr ... re-minimum
by slimprize
Sun Oct 16, 2016 7:57 pm
Forum: Beginner Basics
Topic: iPhone SE unable to join wireless network
Replies: 4
Views: 3913

Re: iPhone SE unable to join wireless network

Hi Tom, I set the preamble to long but no success. [admin@MikroTik] /interface wireless> export # oct/16/2016 22:21:09 by RouterOS 6.37.1 # software id = 7S88-QHXW # /interface wireless set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-Ce \ country=india default-authentication=n...
by slimprize
Sun Oct 16, 2016 6:28 am
Forum: Beginner Basics
Topic: Securing a new installation of RouterOS 6.37.1
Replies: 5
Views: 1484

Re: Securing a new installation of RouterOS 6.37.1

Thanks for your lucid explanation. As of this writing, I will go with blocking from the WAN which I think is already in place (if I understand the rules correctly) that is.
by slimprize
Sun Oct 16, 2016 6:22 am
Forum: Beginner Basics
Topic: iPhone SE unable to join wireless network
Replies: 4
Views: 3913

iPhone SE unable to join wireless network

Hi all, I have had to reset my Mikrotik router model 751G-2HnD . I am unable to connect my iPhone SE running IOS 10.0.2 to the wifi network. I have the same SSID that I had earlier. I did reset the iPhone's network settings but when I enter my wireless key, I am told "unable to join network.&qu...
by slimprize
Sat Oct 15, 2016 8:43 pm
Forum: Beginner Basics
Topic: Securing a new installation of RouterOS 6.37.1
Replies: 5
Views: 1484

Re: Securing a new installation of RouterOS 6.37.1

Hi, Thanks for your message. The rules were created as a part of the default configuration. I get the logic of allowing only what I want to get out but my LAN is trusted. This is my home network which has a couple of desktops, 3 or 4 mobile phones and a couple of iPads. My top priority is to prevent...
by slimprize
Sat Oct 15, 2016 6:46 pm
Forum: Beginner Basics
Topic: Securing a new installation of RouterOS 6.37.1
Replies: 5
Views: 1484

Securing a new installation of RouterOS 6.37.1

Hi all, I have done a fresh install of routerOS version v6.37.1 [current] on my Mikrotik model: 751G-2. I currently have the following rules running. I would like to secure the router. 1 ;;; defconf: fasttrack chain=forward action=fasttrack-connection connection-state=established,related 2 ;;; defco...
by slimprize
Thu Feb 11, 2016 6:35 pm
Forum: Beginner Basics
Topic: Logging to disk & log formats
Replies: 6
Views: 3857

Re: Logging to disk & log formats

Many thanks. Time I setup another syslog server.
by slimprize
Thu Feb 11, 2016 1:59 am
Forum: Beginner Basics
Topic: Logging to disk & log formats
Replies: 6
Views: 3857

Re: Logging to disk & log formats

Hi,
Thanks for this idea. I no longer have ossec installed but I may bring it up again. How did you add the prefix to Mikrotik's syslog messages?
by slimprize
Wed Jan 20, 2016 6:53 pm
Forum: Beginner Basics
Topic: Logging to disk & log formats
Replies: 6
Views: 3857

Re: Logging to disk & log formats

Hi, No. I do remember logging to syslog while I had that setup working. My current set of actions is as follows. Flags: X - disabled, I - invalid, * - default # TOPICS ACTION PREFIX 0 * info memory 1 * error memory 2 * warning memory 3 * critical echo 4 critical disk 5 firewall disk 6 firewall memor...
by slimprize
Sat Jan 31, 2015 3:08 pm
Forum: General
Topic: OpenDNS - Catch all DNS traffic
Replies: 11
Views: 16805

Re: OpenDNS - Catch all DNS traffic

Thanks Toni. Your suggestion worked. I have added the drop rules as you suggested and have also incorporated the point about tcp in large dns requests that another poster has mentioned in this thread.
by slimprize
Sat Jan 31, 2015 5:06 am
Forum: General
Topic: OpenDNS - Catch all DNS traffic
Replies: 11
Views: 16805

Re: OpenDNS - Catch all DNS traffic

Hi all, I am trying to add the rule /ip firewall nat add chain=dstnat in-interface=LAN protocol=udp dst-port=53 action=redirect I do not have an interface called lan. Here is my interface list. Do I add the rules for each LAN interface or is there a way to globally address all of them? [admin@conShi...
by slimprize
Mon Oct 21, 2013 6:39 pm
Forum: Beginner Basics
Topic: Logging to disk & log formats
Replies: 6
Views: 3857

Logging to disk & log formats

Hi all, I need to integrate My Mikrotik router with Ossec at http://www.ossec.net. Has anyone already done this? I want to collect all the logs that my router generates. What is the best way to do this? I have a home setup so I was thinking of logging everything to an external drive. I have a Rd 751...
by slimprize
Fri Jan 25, 2013 7:17 pm
Forum: Beginner Basics
Topic: Troubleshooting my inability to connect to facetime
Replies: 3
Views: 2496

Troubleshooting my inability to connect to facetime

Hi all, I am trying to use facetime and iMessage from my iPhone 5 running IOS 6.02 on my wireless network. My Mikrotik router is running RouterOS 5.22. Facetime and iMessage are unable to connect. I suspect my firewall rules are to blame but I can't figure out which rules I need to alter. Please see...
by slimprize
Mon Aug 20, 2012 4:41 pm
Forum: Scripting
Topic: VB .net: communicating via router's ip
Replies: 9
Views: 5267

Re: VB .net: communicating via router's ip

Hello Grzegorz,

Many thanks for the modification. This is exactly what I needed.

Pranav
by slimprize
Mon Aug 20, 2012 3:30 pm
Forum: Scripting
Topic: VB .net: communicating via router's ip
Replies: 9
Views: 5267

Re: VB .net: communicating via router's ip

Hi, I did do a trace. The problem is at tcpCon.Connect(ips.AddressList(0), If(port = -1, 8728, port)) What I cannot fully understand is what the following line does. Dim ips = Net.Dns.GetHostEntry(ipOrDns) As far as I can tell, the above line is asking for a DNS server which I do not have. I just ha...
by slimprize
Sun Aug 19, 2012 2:54 am
Forum: Scripting
Topic: VB .net: communicating via router's ip
Replies: 9
Views: 5267

Re: VB .net: communicating via router's ip

[admin@conShield] /ip service> print Flags: X - disabled, I - invalid # NAME PORT ADDRESS CERTIFICATE 0 telnet 23 1 ftp 21 2 www 80 3 ssh 22 4 X www-ssl 443 none 5 api 8728 6 winbox 8291 I removed the ip address conversionfunction and now, I am getting an index out of range exception. An unhandled e...
by slimprize
Sat Aug 18, 2012 7:57 am
Forum: Beginner Basics
Topic: ADLS configuration and internet in lan
Replies: 3
Views: 2176

Re: ADLS configuration and internet in lan

Hi m1cky64, I was in your position a week ago. Please try the following. 1. Update the firmware to v5.20 or whatever is the latest. 2. Go into the web interface. This is usually http://192.168.88.1. 3. Login. 4. Follow the quick setup screen. If there is a checkbox for nat, please ensure that you ch...
by slimprize
Sat Aug 18, 2012 3:20 am
Forum: Beginner Basics
Topic: USB UPS: will router act as snmp server
Replies: 2
Views: 2158

Re: USB UPS: will router act as snmp server

Hi Kev, The solution I am planning to implement is to have a computer that acts as a UPS server. This computer will have the ups connected directly to it via USB. The computer will run apcupsd from http://www.apcupsd.org. When a shutdown event is detected, I will run a program to shutdown the router...
by slimprize
Sat Aug 18, 2012 3:15 am
Forum: Beginner Basics
Topic: Validating firewall rules
Replies: 6
Views: 2351

Re: Validating firewall rules

Yes you will want the in interface to be the PPoE one in that case. For your rules, they work and they will do what you expect. Just a few comments: 1.) What is the point of blocking port scanners if you are already dropping everything that is coming into your WAN interface that is not from your LA...
by slimprize
Sat Aug 18, 2012 3:08 am
Forum: Scripting
Topic: VB .net: communicating via router's ip
Replies: 9
Views: 5267

Re: VB .net: communicating via router's ip

first things first: check if API service port is enabled, it is not blocked by firewall PL] My system firewall is not prompting me. I am on windows and the windows firewall is silant. The service port is enable on the MikroTik. check if address of router is reachable from your PC PL] Yes it. I can ...
by slimprize
Fri Aug 17, 2012 1:09 pm
Forum: Scripting
Topic: VB .net: communicating via router's ip
Replies: 9
Views: 5267

VB .net: communicating via router's ip

Hi all, I am trying to use the example from the wiki in a simple vb .net application. I am unable to communicate with the router. I get a host not found error. My code is below. Module Module1 'function from http://www.planet-source-code.com/vb/scripts/ShowCodeAsText.asp?txtCodeId=5179&lngWId=10...
by slimprize
Thu Aug 16, 2012 3:21 am
Forum: Beginner Basics
Topic: Validating firewall rules
Replies: 6
Views: 2351

Re: Validating firewall rules

Hi Feklar, Many thanks for the rules. I have most of these in place. See my configuration below. I have one question about one of the rules. add action=drop chain=input comment="default configuration" disabled=no \ in-interface=ether1-gateway PL] Since my isp uses pppoe, should the in-inte...
by slimprize
Wed Aug 15, 2012 9:29 am
Forum: Beginner Basics
Topic: USB UPS: will router act as snmp server
Replies: 2
Views: 2158

USB UPS: will router act as snmp server

Hi all,

I have an APC SUA1000UXI ups. I see that I can connect it to my RB751g-2hnd router running router os 5.19.

I am a tad confused about one thing. Will the router act as a snmp server if I connect the ups to it and enable snmp on the router?

Pranav
by slimprize
Tue Aug 14, 2012 5:50 pm
Forum: Beginner Basics
Topic: Validating firewall rules
Replies: 6
Views: 2351

Re: Validating firewall rules

Hi, My bad. My objectives behind the rules are as follows. 1. I need to prevent someone from the internet accessing the router. This could via telnet, ssh, ftp, winbox etc. 2. I want to block or at least slow down port scans. 3. if I have malware on my internal network, then that malware should not ...
by slimprize
Mon Aug 13, 2012 7:53 pm
Forum: Beginner Basics
Topic: Validating firewall rules
Replies: 6
Views: 2351

Validating firewall rules

Hi all,

I have a bunch of firewall rules that I have added over the past week by reading the wiki. <chuckle

Is there a way to validate them? I have exported them. The resulting file is attached.
by slimprize
Mon Aug 13, 2012 7:35 pm
Forum: Beginner Basics
Topic: Handling a situation of two interfaces on the same subnet
Replies: 3
Views: 1673

Re: Handling a situation of two interfaces on the same subne

Hello hassibi,

Thanks for your answer. Ether3 and ether4 are already slaves to ether1 which is on the default bridge. How do I remove them? I am not sure of the commands.
by slimprize
Mon Aug 13, 2012 7:28 pm
Forum: Beginner Basics
Topic: Setting the time zone on RB751g-2hnd running router os 5.19
Replies: 2
Views: 1263

Re: Setting the time zone on RB751g-2hnd running router os 5

Hi C. Brown,
No go. set time-zone-name=india and then double tab does not show me new delhi India. I have tried asia/india without success.
Pranav
by slimprize
Sun Aug 12, 2012 8:06 pm
Forum: Beginner Basics
Topic: Handling a situation of two interfaces on the same subnet
Replies: 3
Views: 1673

Handling a situation of two interfaces on the same subnet

Hi all, I have devices with static ip addresses on two interfaces of my Mikrotik router. These addresses are in the same subnet. See below for details. ether1 links to the wan DSL modem router. Ether 2 is my desktop. Ether 3 has my linux desktop. Ether 4 connects to a switch that has 4 IP cameras an...
by slimprize
Sun Aug 12, 2012 7:58 pm
Forum: Beginner Basics
Topic: Setting the time zone on RB751g-2hnd running router os 5.19
Replies: 2
Views: 1263

Setting the time zone on RB751g-2hnd running router os 5.19

Hi all, How do I set the time zone from the cli on a RB751g-2hnd which is running router os version 5.19? I am following the guide at http://wiki.mikrotik.com/wiki/Securing_New_RouterOs_Router I navigated to /system clock and then ran set time-zone=+5.5 I get an error expected end of command (line 1...
by slimprize
Sun Aug 12, 2012 7:53 pm
Forum: Beginner Basics
Topic: RB751g-2hnd: PPPOE up but unable to get to the internet
Replies: 4
Views: 1951

Re: RB751g-2hnd: PPPOE up but unable to get to the internet

[quote="nickshore"]What do you have in IP -> Routes ? PL] Hi Nick, I have sorted the problem. The problem lay in my initially trying to configure things manually. I had 2 pppoe interfaces configured and the nat was mapped to the wrong one. This occured with version 5.11. I am not sure what...
by slimprize
Fri Aug 10, 2012 1:09 pm
Forum: Beginner Basics
Topic: RB751g-2hnd: PPPOE up but unable to get to the internet
Replies: 4
Views: 1951

Re: RB751g-2hnd: PPPOE up but unable to get to the internet

Hi all, Things have moved on since I posted this message. I have been successful in connecting the router to my setup. The problem was the NAT rule. When I first got the router, I had tried to manually configure things. I then upgraded the firmware and tried a number of things after that. The result...
by slimprize
Thu Aug 09, 2012 3:08 am
Forum: Beginner Basics
Topic: RB751g-2hnd: PPPOE up but unable to get to the internet
Replies: 4
Views: 1951

RB751g-2hnd: PPPOE up but unable to get to the internet

Hi all, I have a MikroTik RB751g-2hnd router. I have upgraded it to version 5.19 of the router OS. I have a DSL modem router in bridge mode which is connected to ether1 on the router. My ISP uses PPPOE so I have configured the PPPOE client. The PPPOE link is up. I have added static leases for the DN...