Community discussions

Search found 48 matches

by apteixeira
Tue Sep 11, 2018 3:18 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 148
Views: 28953

Re: v6.43 [current] is released!

Hello,

We just upgrade two CHR on AWS to last version of RouterOS and now we are not able to login.
Winbox: wrong username or password
SSH: Access denied

Any advice?

Regards.
by apteixeira
Sat Jun 09, 2018 7:01 pm
Forum: General
Topic: progaram get any mikrotik system usernam and passowrd in 3 second
Replies: 35
Views: 6456

Re: progaram get any mikrotik system usernam and passowrd in 3 second

Hello,

Just for testing purpose I just created a VM with IP 201.217.241.120
Try getting password. Clue: password starts with "test" word.
Port: winbox 8291

Regards.
by apteixeira
Sat Nov 26, 2016 6:37 pm
Forum: Announcements
Topic: v6.37.2 [current] is released!
Replies: 50
Views: 13698

Re: v6.37.2 [current] is released!

Hello, I am getting several times "kernel failure in previous boot" or "router was rebooted without proper shutdown, probably kernel failure" using CCR1072 using "/ip firewall raw limit" and "/ip firewall raw dst-limit" We are testing CCR1072 against DDoS heavy attacks: 400.000 to 1.000.000 packet p...
by apteixeira
Tue Jul 19, 2016 3:51 pm
Forum: General
Topic: dst-limit possible problem
Replies: 4
Views: 891

Re: dst-limit possible problem

Hello macgaiver,

Those IP are not real. They are just for LAB test and routed internally.

Regards.
by apteixeira
Mon Jul 18, 2016 8:10 pm
Forum: General
Topic: dst-limit possible problem
Replies: 4
Views: 891

dst-limit possible problem

Hello, I have being developing an advance firewall for an ISP in order to mitigate as much as possible DoS and DDoS attacks. The problem started when I was testing the property dst-limit with value src-and-dst-addresses in firewall filter. Example: to simulate attack and firewall rule behavior I use...
by apteixeira
Mon May 23, 2016 5:11 am
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello, Here is an OVA optimized for VMware vSphere with SCSI hard disk and SCSI controller (paravirtualization). The hard drive has 1GB. Version: 6.35.2 OVA: https://dl.dropboxusercontent.com/u/3817372/share-public/CHR-OVA/CHR-6.35.2-SCSI_vSphere6.zip It can be used on VMware Workstation as well. En...
by apteixeira
Wed Apr 06, 2016 2:46 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello, There is an issue with the ethernet interface order on CHR using VMware (tested on EXSi and Workstation). When you add several interfaces to the CHR then the interfaces appear in different order as created . This means they cannot be matched easily when connecting to other VMs. You have to c...
by apteixeira
Fri Apr 01, 2016 2:38 am
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello, There is an issue with the ethernet interface order on CHR using VMware (tested on EXSi and Workstation). When you add several interfaces to the CHR then the interfaces appear in different order as created . This means they cannot be matched easily when connecting to other VMs. You have to ch...
by apteixeira
Wed Feb 24, 2016 5:17 am
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

* POST UPDATED: 24-02-2016 @ 09:12AM How to run CHR on AWS (Amazon Web Services) VPC (Virtual Private Cloud) as the default firewall / router gateway Many people have been asking me how to use the CHR as the default firewall / router of your VMs behind a VPC in AWS. Here is a guide that will guide ...
by apteixeira
Mon Jan 18, 2016 5:42 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Anyone have performance metrics related to AWS instance size? I'm looking at using the CHR as a VPN/Router for a corporate cloud infrastructure, and want to be able to price out the instance sizes in terms of routing performance within the VPC as well as number of concurrent users I can support via...
by apteixeira
Tue Jan 05, 2016 3:37 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hey Guys, I am using CHR on AWS using the AMI you provided, and upgraded it to the latest RC30. Everytime the router is restarted, the hostname changes to the reverse-dns. Is there a way of blocking this from happening ? Thanks, Matthew. Hello dirtonth, You can try disabling the DHCP client options...
by apteixeira
Thu Dec 31, 2015 7:04 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello,

CHR license is working on AWS since version 6.34rc30. It is confirmed.

What's new in 6.34rc30 (2015-Dec-30 13:57):
*) chr - license fix for AWS and similar solutions;


Best regards
by apteixeira
Sat Dec 26, 2015 1:59 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Im using router CHR on an esx with a vm with 8 cores . I'm being attack with a simple udp flood and its eating a lot of cpu. I droped the attack on the firewall but still the resource usage is too much http://puu.sh/m8n6s/7327dfed8e.png http://puu.sh/m8mWN/77add21c6a.png http://puu.sh/m8pPU/8e1fbdf...
by apteixeira
Sat Dec 26, 2015 1:58 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

we are working to fix the license. And there will be updated AMIs with latest RouterOS release available. Hello janisk, Is there any soon update that fix AWS CHR AMI license . I am using CHR on production environment in AWS for a new VPC but it is limited to 1 Mbps. Please fix it. It would be great...
by apteixeira
Wed Dec 16, 2015 4:32 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

on eu-west-1 you can look for this ami: ami-fce6448f

if this works that way.
Hello,

It works fine but the license upgrade does not work yet.

Here is the public AMI in us-east-1 (Virginia, EEUU): ami-c6287dac

Best regards.
by apteixeira
Wed Dec 16, 2015 2:29 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Known bug with AWS, are working on it!
Thanks. I just wrote the process to import the image to AWS so anyone can test it.

Best regards.
by apteixeira
Wed Dec 16, 2015 2:24 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

*** Please give karma *** Hello, Here are the steps to upload the CHR to AWS (Amazon Web Services) : Install http://qemu.weilnetz.de/w64/qemu-w64-setup-20151208.exe [/b]Download Cloud Hosted Router Raw Disk Image (lastest) http://download2.mikrotik.com/routeros/6.34rc19/chr-6.34rc19.img.zip Rename ...
by apteixeira
Wed Dec 16, 2015 2:00 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello, I just upgrade the CHR to the latest RouterOS version (v6.34rc21) but I got the same problem trying to upgrade the free license to any trial version . It still says free but in the MikroTik account appears correctly. Any news about it? Best regards. Hello, I have tested several times and the...
by apteixeira
Mon Dec 14, 2015 1:37 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Please send supout file to MikroTik support. Hello, I just successfully upload the MikroTik CHR image to Amazon Web Services (AWS) and it works perfectly as router/firewall for the Amazon VPC. The only problem is that I tried to apply the free trial P-Unlimited license but it did not work. It keeps...
by apteixeira
Thu Dec 10, 2015 1:55 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Please send supout file to MikroTik support. Hello, I just successfully upload the MikroTik CHR image to Amazon Web Services (AWS) and it works perfectly as router/firewall for the Amazon VPC. The only problem is that I tried to apply the free trial P-Unlimited license but it did not work. It keeps...
by apteixeira
Wed Dec 09, 2015 4:21 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello, I just successfully upload the MikroTik CHR image to Amazon Web Services (AWS) and it works perfectly as router/firewall for the Amazon VPC. The only problem is that I tried to apply the free trial P-Unlimited license but it did not work. It keeps saying free license and 1 Mbps Rx/Tx. Is the ...
by apteixeira
Sat Aug 15, 2015 4:09 am
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello,

Where can I find the last CHR vmdk disk?. Do I need to convert the img file to a vmdk?

Regards
by apteixeira
Fri Jul 31, 2015 4:29 am
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Very nice! Problems I've met are unsupported virtio (disk and network both) and cloud-init to be possible to load on AWS, Openstack, etc.. :) I use Virtio network interfaces with RouterOS, virtualise inside Linux KVM. I've not tried Virtio storage, but I suspect it will work. http://i.imgur.com/1sg...
by apteixeira
Thu Jul 30, 2015 2:20 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Will there be optional CHR-only packages available for this flavor of RouterOS? For example, you've mentioned driver support for different virtualisation systems interfaces will be added, but would it be worthwhile that these be additional packages to be installed only as needed, as well as things ...
by apteixeira
Wed Jul 29, 2015 2:52 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

6.30.x is older than 6.31 6.30.x only includes fixes, not new features, such as this Hello Normis, You are right. I choose current version from the upgrade menu. However, if you try to upgrade to the release candidate, then the actual license won’t let you. https://dl.dropboxusercontent.com/u/38173...
by apteixeira
Wed Jul 29, 2015 12:59 am
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 188263

Re: Cloud Hosted Router

Hello, This is great! Nice idea! When I try to upgrade to most recent version (6.30.2) it resets the free license to a 24 hours license. Here are some screenshots. Are we going to be able to upgrade this RouterOS VMs? Before: https://dl.dropboxusercontent.com/u/3817372/share2/28-07-2015%2018-24-06.p...
by apteixeira
Thu May 21, 2015 3:02 am
Forum: General
Topic: v6.29 will be released this week!
Replies: 65
Views: 13457

Re: v6.29 will be released this week!

Hello,

There is a bug on BGP VPLS tunnel. I made a post here:
http://forum.mikrotik.com/viewtopic.php ... 05#p482914

Best regards.
by apteixeira
Thu May 21, 2015 2:59 am
Forum: Forwarding Protocols
Topic: v6.28 OSPF/BGP/MPLS Bug
Replies: 5
Views: 2094

Re: v6.28 OSPF/BGP/MPLS Bug

Hello, Something similar happed to me with version 6.28 and 6.29RC22. Here is a video: https://www.youtube.com/watch?v=ayO32xlww7U Here are the configuration files: https://www.dropbox.com/sh/145kbzpw27tsu7a/AABvjN_86CjosnbsIcMfhLQAa?dl=1 The problem with the tunnel happens only when you set to dyna...
by apteixeira
Thu Nov 13, 2014 2:57 am
Forum: General
Topic: 6.22 released!
Replies: 151
Views: 54852

Re: 6.22 released!

Hello,

Can't RESET HTML from hotspot.

Image

Best regards.
by apteixeira
Fri Oct 31, 2014 3:20 pm
Forum: General
Topic: v6.21 released!
Replies: 25
Views: 6586

Re: RouterOS v6.21

Hello, CRL error persists: "OpenVPN Server error: TLS failed". Previous post: http://forum.mikrotik.com/viewtopic.php?f=2&t=88372 I tested with several certificates: issued by GoDaddy, CACert and using OpenSSL. If you create then without CRL the connection established correctly. Here are some images...
by apteixeira
Wed Oct 29, 2014 6:12 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Is using OpenSSL I can remove the password from the certificate and upload them again?
The files are you using are ok for the server.

Yes you can decrypt the rsa private key using openssl. Here is an example: https://support.citrix.com/article/CTX122930/

Best regards.
by apteixeira
Wed Oct 29, 2014 5:18 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Hello 0chi0, The possible reason for "do not have a flag KR, only KT" may be because you are not importing the key of the certificate. On the server you need to install de complete chain and the server key. To avoid "enter the password for the certificate" you have to decrypt the rsa private key. To...
by apteixeira
Tue Oct 28, 2014 10:08 pm
Forum: General
Topic: v6.20 released!
Replies: 146
Views: 58820

Re: v6.20 released!

We have upgraded several RB951 series routers in a class situation. 2 or 3 of these have all exhibited odd firewall behavior when rules are disabled. It shows a rule disabled in Winbox yet the rule continues to work, e.g a rule that logs traffic keeps logging even when disabled. We did not test thi...
by apteixeira
Thu Oct 23, 2014 5:43 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

add openvpn client ip -> internal server ip to forward chain - works fine!
thanks for your attention to my problem, apteixeira! )
I'm glad I could help
by apteixeira
Tue Oct 21, 2014 2:51 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Here is my OVPN Client configuration for Windows: remote xxx.xxx.xxx.xxx 443 proto tcp-client #client tls-client #ns-cert-type server #remote-cert-tls server ca cert_export_myCa.crt cert cert_export_client1.crt key cert_export_client1.key cipher AES-256-CBC auth SHA1 dev tap resolv-retry infinite no...
by apteixeira
Mon Oct 20, 2014 2:22 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

ok, I can create certificates with my rb750gl (without any load, espessially torrents, timeout is gone ), but I still got tls error about 60 sec timout - connection failed. crl on my certificate is absent. Are you following the instructions? Are you using your own certificates? Can you post what ar...
by apteixeira
Fri Oct 17, 2014 2:50 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

v6.20, RB750G
but why this info is not in wiki?
that's the third way I try to create certificates - openvpn(easy-rsa), openssl and in RouterOS.
and no one works
Here is a video: http://youtu.be/93__PLZgebE

Best regards.
by apteixeira
Fri Oct 17, 2014 2:26 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

/certificate sign ca-template name=myCa
error: couldn't perfom action - timeout(13)
?
Which version are you using?
I use version 6.20. In version 6.19 is different.

Best regards.
by apteixeira
Tue Oct 14, 2014 2:19 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Hello, Using RouterOS 6.20 you can execute the following commands on the MikroTik server: We will create two client certificates at this time (you can add more lately) /certificate add name=ca-template common-name=myCa key-usage=key-cert-sign,crl-sign add name=server-template common-name=server add ...
by apteixeira
Tue Aug 26, 2014 7:50 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Hello,

Confirmed. The problem happened when you set the CRL on the certificates.

Tested on several RouterBoards and it works without using CRL.

The certificates were generated by: OpenSSL and RouterOS (with bought works)

Best regards.
by apteixeira
Tue Aug 26, 2014 7:16 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Hello,

Found the problem. When set the CRL it does not work. If skip the CRL then it works.

Tested on several RouterBoards and x86.

Best regards.
by apteixeira
Tue Aug 26, 2014 6:46 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Hello, Another problem: after successful implementation generating the certificates on one RouterOS, when I try to use the exported certificates with OVPN (require-client-certificate checked) in another RouterOS (including all the private keys) the error appear again: "TLS FAILED". I follow this lin...
by apteixeira
Tue Aug 26, 2014 5:56 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Hello sanitycheck,

Thank you for your answer.

I just follow this steps and it works: http://wiki.mikrotik.com/wiki/Manual:Cr ... rtificates

There must something with the certificate chain or the CRL.

Best regards.
by apteixeira
Fri Aug 22, 2014 8:35 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

There are just for test. I will generate then again. Thanks you for your suggestion.
by apteixeira
Fri Aug 22, 2014 6:39 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

Re: OpenVPN Server error: TLS failed

Note:

If I uncheck "require-client-certificate" it works.

Best regards.
by apteixeira
Fri Aug 22, 2014 6:31 pm
Forum: General
Topic: OpenVPN Server error: TLS failed
Replies: 43
Views: 77366

OpenVPN Server error: TLS failed

Hello MikroTik, I am pretty sure there is a problem with OpenVPN Server running on RouterOS when you choose "require-client-certificate" . I tested several times using different chain of certificates. The weird thing is that if you try the same configuration and certificates on version 5.26 (OpenVPN...
by apteixeira
Fri Jan 25, 2013 7:42 pm
Forum: General
Topic: v6 rc7 released
Replies: 88
Views: 24098

Re: v6 rc7 released

Hello. I am having problems with v6 rc7. This is the second time that the router lost connectivity. I can only access using MAC from another router with the same version and when I try to ping any ip this is the result: 132 (No buffer space available) Has anyone experienced this issue? Bye. http://d...
by apteixeira
Sun Oct 28, 2012 5:49 pm
Forum: Wireless Networking
Topic: Problems: Wireless USB card with Atheros AR9271 version 5.21
Replies: 1
Views: 1060

Problems: Wireless USB card with Atheros AR9271 version 5.21

Hello Everyone. I have been testing a Wireless USB card with Atheros AR9271 (TP-Link WN722N). It works fine on RB751 with RouterOS version 5.20. When I updated to version 5.21 some problems started. I can’t manage the wireless interface using WinBox. This message always appears: "Couldn’t change int...