Community discussions

Search found 966 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 20
by Rudios
Thu Mar 02, 2017 1:49 pm
Forum: Beginner Basics
Topic: Export Neighbour list
Replies: 3
Views: 831

Re: Export Neighbour list

just do a
/ip neighbor print file=<name>
If you need detailed information, add the 'detail' parameter.
by Rudios
Thu Mar 02, 2017 1:30 pm
Forum: General
Topic: Prevent connecting unauthorized devices
Replies: 1
Views: 343

Re: Prevent connecting unauthorized devices

Aren't the LLDP packets based on the neighour discovery?
Disable this.
by Rudios
Fri Feb 24, 2017 4:15 pm
Forum: Forwarding Protocols
Topic: OSPF setup
Replies: 34
Views: 4642

Re: OSPF setup

You need to supply more information, like IP assignments etc.
by Rudios
Fri Feb 24, 2017 3:45 pm
Forum: Beginner Basics
Topic: Route traffic between two interfaces
Replies: 9
Views: 2031

Re: Route traffic between two interfaces

I guess both servers are using their default gateway (192.168.1.1) and therefore their ether2 connected slave.
I would create a dedicated route on both servers, that if the other server is the destination, forward the packet to the 10.15.x.1 gateway.
by Rudios
Sat Feb 04, 2017 4:22 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 1266

Re: Hairpin won't work, but why?

I would put the dst-address of your hairpin nat rule being the server only
dst-address=192.168.1.252
Also I don't know what the parameter out-interface-list=all does
Last but not least, leave out the protocol parameter
by Rudios
Sat Feb 04, 2017 4:13 pm
Forum: General
Topic: bridge only for wireless
Replies: 14
Views: 2011

Re: bridge only for wireless

Regarding wiki I need to bridge wireless interfaces and switch master port. In this configuration, when I'm running speedtest wired, I see up to 60% CPU usage. When I removed bridge, created new one only with wireless interfaces, running dhcp on it. On master switch port second dhcp server. Then wh...
by Rudios
Sat Feb 04, 2017 11:20 am
Forum: General
Topic: PS4 and mikrotik
Replies: 17
Views: 7566

Re: PS4 and mikrotik

I don't see any reason to use IP 10.10.10.10 on your DNS.
Try again after removing it, or do you have good reason to use it?
by Rudios
Fri Feb 03, 2017 4:57 pm
Forum: General
Topic: bridge only for wireless
Replies: 14
Views: 2011

Re: bridge only for wireless

So how to achieve this? ether1 - wan ether25 - lan wlan12 - wifi. Create bridge between ether1 & wlan12 (without lan access?), leave ether25 in normal switch mode without bridging? I tried to remove ether25 from bridge and leave there ether1 and wlan12 but it didn't works. Any help please. TIA. Don...
by Rudios
Thu Feb 02, 2017 11:28 am
Forum: Beginner Basics
Topic: RB450 RS232
Replies: 4
Views: 650

Re: RB450 RS232

I don't think this is going to work.
The RS232 connection on the RB only gives you serial connection to the management interface of RouterOS.
I don't think you would be able to read/write any tcp/ip data to/from the PLC
by Rudios
Thu Feb 02, 2017 9:57 am
Forum: Beginner Basics
Topic: Beginner firewall rule question
Replies: 3
Views: 452

Re: Beginner firewall rule question

Another option would be to allow dns requests to the router on UDP/TCP port 53 and block the rest.
I have to add that I follow this generic rule: Allow specific desired connection and drop everything else.
by Rudios
Wed Feb 01, 2017 11:38 am
Forum: Beginner Basics
Topic: port forwarding mistake
Replies: 2
Views: 399

Re: port forwarding mistake

You should be able to reach the router by winbox
On the other hand, you configured the rule on ether3, what if you connect your cable to a different port
by Rudios
Sat Jan 14, 2017 8:56 am
Forum: RouterOS v6 RC and v7 BETA
Topic: mikrotik hacked
Replies: 5
Views: 3171

Re: mikrotik hacked

I vote for unknown port forward!
by Rudios
Thu Jan 12, 2017 10:03 pm
Forum: RouterBOARD hardware
Topic: Faulty RB2011UiAS-RM
Replies: 7
Views: 1257

Re: Faulty RB2011UiAS-RM

I have two RB2011's just like this currently. Ports 1-5 work perfectly as a dumb switch, but there does not seem to be a way to communicate with the internals. The LCD screen is white as well. I've tried Winbox, NetInstall, serial console, ssh, telnet, mac telnet, reset button, and spanning the har...
by Rudios
Thu Jan 12, 2017 12:59 pm
Forum: Beginner Basics
Topic: Port forwarding in local network
Replies: 11
Views: 3677

Re: Port forwarding in local network

You have to make a Hairpin NAT Rule,
http://wiki.mikrotik.com/wiki/Hairpin_NAT
by Rudios
Wed Jan 11, 2017 6:33 pm
Forum: RouterBOARD hardware
Topic: Faulty RB2011UiAS-RM
Replies: 7
Views: 1257

Re: Faulty RB2011UiAS-RM

The device has a serial port, try to connect to it in order to see if it reacts.
by Rudios
Wed Jan 11, 2017 6:31 pm
Forum: General
Topic: tag and and untagged on same port
Replies: 11
Views: 2798

Re: tag and and untagged on same port

I think you have to clarify a little.
If you want untagged traffic only, just use the normal interface.
Or are you looking for something that drops all packets that DO have vlan tag?
by Rudios
Wed Jan 11, 2017 1:39 pm
Forum: Beginner Basics
Topic: Multiple VLAN's using 1 internet connection
Replies: 9
Views: 3655

Re: Multiple VLAN's using 1 internet connection

Disable the master port assignment for port 5.
by Rudios
Tue Jan 10, 2017 8:33 am
Forum: General
Topic: subnets connection problem
Replies: 6
Views: 742

Re: subnets connection problem

In order to know your firewall rules are blocking the traffic in the right way,
Just ping from a PC in one subnet to a connected client on the other subnet (No the router itself)
by Rudios
Mon Jan 09, 2017 4:42 pm
Forum: Beginner Basics
Topic: Connect 2 networks with separate internet connections
Replies: 16
Views: 2463

Re: Connect 2 networks with separate internet connections

If you configure it as in the image, you need to create static routes in Fritzbox and Zyxel. RB750 should have similar IP: - 192.168.1.X (ideal static IP, excluded from DHCP) on the interface connected to Fritzbox, eg 192.168.1.2 - 192.168.100.X (ideal static IP, excluded from DHCP) on the interfac...
by Rudios
Mon Jan 09, 2017 4:33 pm
Forum: Beginner Basics
Topic: Multiple VLAN's using 1 internet connection
Replies: 9
Views: 3655

Re: Multiple VLAN's using 1 internet connection

Create the needed VLANs on Eth5 and give each VLAN interface a dedicated address (use separate subnets). Build firewall rules in such a way that the traffic can only go outside /ip firewall filter add chain=forward in-interface=vlan-x out-interface=ether1 action=allow add chain=forward in-interface=...
by Rudios
Mon Jan 09, 2017 4:26 pm
Forum: General
Topic: subnets connection problem
Replies: 6
Views: 742

Re: subnets connection problem

You probably mean you type ping!
And what device is holding the IP 10.20.0.254.
If it is the router (interface connected to the 10.20.0.0/24 subnet) it makes sense, because connections to the router itself are handled in the input chain.
by Rudios
Mon Jan 09, 2017 2:09 pm
Forum: General
Topic: subnets connection problem
Replies: 6
Views: 742

Re: subnets connection problem

What do you mean by "ipconfig to the other subnet"?
Maybe draw us a picture and share some more detailed information about your configuration(s)
by Rudios
Mon Jan 09, 2017 8:24 am
Forum: General
Topic: Forward packet for public IP to local IP
Replies: 3
Views: 657

Re: Forward packet for public IP to local IP

You have to use dst-nat for this.
create something like
/ip firewall nat
add chain=dstnat action=dst-nat src-address=192.168.88.10 protocol=udp dst-address=88.88.88.88 dst-port=xxx to-address=192.168.88.11
by Rudios
Tue Dec 20, 2016 8:12 am
Forum: Beginner Basics
Topic: Firewall rules
Replies: 41
Views: 83745

Re: Firewall rules

That is because the dst-nat rule is carried out before the filter rule is applied, and after the dst-nat rule is applied your dst-address is not your public IP anymore but the 10.x.y.z. address. Also you have to handle the filter rules on your forward chain instead of your input because of this dst-...
by Rudios
Tue Dec 06, 2016 8:09 am
Forum: RouterBOARD hardware
Topic: RB433ah problem booting :( :(
Replies: 10
Views: 2162

Re: RB433ah problem booting :( :(

For sure that your firewall could have some negative impact on your tries.
Just temporarily disable your firewall completely on your PC.
by Rudios
Thu Dec 01, 2016 1:42 pm
Forum: General
Topic: what is the lates version for mAP 2n?
Replies: 5
Views: 725

Re: what is the lates version for mAP 2n?

It depends on the channel you are checking. As of today the most current release is 6.37.3 for the stable channel, for the bug-fix-only channel the latest version is 6.36.4 In order to update you can always download the latest version from the Mikrotik website and upload the package to your routerbo...
by Rudios
Mon Nov 28, 2016 8:14 am
Forum: General
Topic: Forwarding
Replies: 3
Views: 503

Re: Forwarding

The thing is that I do not want to connect ( call ) through my WAN IP and use my internet bandwidth when inside WLAN. I want packet to get forwarded directly to my PBX server so that they are not going through my WAN port whenever Im inside my LAN. I guess it is just a matter of routing, you don't ...
by Rudios
Fri Nov 25, 2016 1:07 pm
Forum: General
Topic: Does the order of the ports knocked matters in Port Knocking?
Replies: 2
Views: 705

Re: Does the order of the ports knocked matters in Port Knocking?

As I see it you either have to first knock 1000 OR 2000 and if you then knock 3000 you will be granded access. If you want a specific order, all three should be assigned a dedicated address-list. so knock 1000, add to list port-knock1 then; knock 2000, when in port-knock1, add to port-knock2 then kn...
by Rudios
Fri Nov 25, 2016 10:50 am
Forum: Beginner Basics
Topic: Dropping Packets between subnets with an exception
Replies: 11
Views: 1015

Re: Dropping Packets between subnets with an exception

I would even go for one allow rule, and then a generic drop.
by Rudios
Fri Nov 25, 2016 10:46 am
Forum: General
Topic: Forwarding
Replies: 3
Views: 503

Re: Forwarding

I assume you have a port forward on our router in order to connect you mobile phone via your external IP.
If that is the case you should configure a HairPin NAT rule in order to be able to connect via your WAN ip when inside your network.
by Rudios
Fri Nov 25, 2016 10:29 am
Forum: RouterBOARD hardware
Topic: I lost the access of my mikrotik router after deleting the default bridge
Replies: 3
Views: 798

Re: I lost the access of my mikrotik router after deleting the default bridge

MikroTik RouterBOARD RB2011UiAS-RM
That model does have a serial console port, so when you have physical access to the device, use this.
by Rudios
Mon Nov 21, 2016 8:20 am
Forum: Virtualization
Topic: Hyper-V 2012 R2 & Mikrotik version 5.2
Replies: 5
Views: 1235

Re: Hyper-V 2012 R2 & Mikrotik version 5.2

Keep in mind to use the Legacy Network adapters on your guest configuration.
When using the Standard adapters, they will appear within RouterOS, but will not passthrough any traffic.
by Rudios
Mon Nov 21, 2016 8:07 am
Forum: Wireless Networking
Topic: Design a network
Replies: 4
Views: 859

Re: Design a network

I also had the first thought to go for simple solution with VLAN's.
@jarda: But how to solve the wireless links in combination with these VLAN's. I have come across some possible solution with WDS, but it is not that stable after-all.
by Rudios
Mon Nov 14, 2016 3:51 pm
Forum: Beginner Basics
Topic: [advice] Configuration RBwAP2nD
Replies: 16
Views: 3844

Re: [advice] Configuration RBwAP2nD

Based on your first screenshot you are not using the IP segment 192.168.88.0 at all on your router. Your local IP address is 192.168.1.1 You have set the subnet mask to /8 (255.0.0.0) I guess you have to revert that back to /24 (255.255.255.0) Also your WAN connection is getting an IP address in ran...
by Rudios
Mon Nov 14, 2016 8:01 am
Forum: Beginner Basics
Topic: how to connect a pc behind a router to nas that is on main cable modem?
Replies: 5
Views: 813

Re: how to connect a pc behind a router to nas that is on main cable modem?

I still would suggest my earlier solution.
Bridge all ports on the MikroTik and let the DCHP on your cable modem assign addresses to your NASs (or put static if needed)
by Rudios
Fri Nov 11, 2016 8:51 am
Forum: Beginner Basics
Topic: Setup mAP as AP
Replies: 3
Views: 1092

Re: Setup mAP as AP

You actually not using the DNS server supplied by your DHCP server (use-peer-dns=no parameter on your dhcp-client)
by Rudios
Fri Nov 11, 2016 8:45 am
Forum: Beginner Basics
Topic: 3 Routers 1 SSID
Replies: 8
Views: 1112

Re: 3 Routers 1 SSID

Please share your configurations, that will make it more easy to help you out.
by Rudios
Thu Nov 10, 2016 9:48 pm
Forum: Scripting
Topic: SD card backup
Replies: 6
Views: 1799

Re: SD card backup

rsc is the result of export
by Rudios
Thu Nov 10, 2016 9:35 pm
Forum: Scripting
Topic: SD card backup
Replies: 6
Views: 1799

Re: SD card backup

I would go for the export feature! The big downside to making a backup is that it could only be restored on the same type device, with exact same RouterOS version. When creating an export (rsc file) you could alter fhe file if needed and load it on practical any replacement device when needed. [EDIT...
by Rudios
Thu Nov 10, 2016 9:28 pm
Forum: Wireless Networking
Topic: station/AP config issues
Replies: 3
Views: 839

Re: station/AP config issues

I am not sure, but I guess you will need a device that has 2 wirelss interfaces.
For as much as my information goes, any wireless interface can only be running as an AP or station at any given time uniquely, no dual modes together.
by Rudios
Thu Nov 10, 2016 9:21 pm
Forum: Beginner Basics
Topic: No access to LAN over SSTP VPN (can only ping router)
Replies: 13
Views: 3754

Re: No access to LAN over SSTP VPN (can only ping router)

Hi everyone, I found my mistake, actually everything worked well from the start, without having to add route. The packed arrived well in my LAN, but could not return to the VPN, because I marked packets in my LAN to WAN1. I therefore excluded marking packets for the VPN: chain=prerouting action=mar...
by Rudios
Thu Nov 10, 2016 9:19 pm
Forum: Beginner Basics
Topic: No access to LAN over SSTP VPN (can only ping router)
Replies: 13
Views: 3754

Re: No access to LAN over SSTP VPN (can only ping router)

Hi everyone, I found my mistake, actually everything worked well from the start, without having to add route. The packed arrived well in my LAN, but could not return to the VPN, because I marked packets in my LAN to WAN1. I therefore excluded marking packets for the VPN: chain=prerouting action=mar...
by Rudios
Wed Nov 09, 2016 8:21 pm
Forum: Beginner Basics
Topic: access router from internet
Replies: 4
Views: 657

Re: access router from internet

not working, I already tried.

chain=dstnat action=dst-nat to-addresses=192.168.88.1 to-ports=8291 protocol=tcp in-interface=pppoe-out1 dst-port=8291 log=no log-prefix=""

for filter rules, I have default rules.
If you have default rules, you should add one for allowing traffic after dst-nat.
by Rudios
Wed Nov 09, 2016 3:47 pm
Forum: Beginner Basics
Topic: Access IP Address Via Wifi
Replies: 2
Views: 491

Re: Access IP Address Via Wifi

What device is holding your wifi AP?
Where is the device connecting from located? At the same wifi or on the internet somewhere?
by Rudios
Wed Nov 09, 2016 3:45 pm
Forum: Beginner Basics
Topic: access router from internet
Replies: 4
Views: 657

Re: access router from internet

The best way is to port-forward (dst-nat) an explicit outside port to the internal ip address of your routerboard, port 8291 (default winbox).
Additionally you probably need an allow rule in your firewall filter input chain.
by Rudios
Wed Nov 09, 2016 12:47 pm
Forum: Beginner Basics
Topic: No access to LAN over SSTP VPN (can only ping router)
Replies: 13
Views: 3754

Re: No access to LAN over SSTP VPN (can only ping router)

on your RB1100 put the following
/ip route
add dst-address=192.168.0.0/24 gateway=10.10.10.11
by Rudios
Wed Nov 09, 2016 8:04 am
Forum: Beginner Basics
Topic: Mikrotik is lab network connected to corporate domain
Replies: 3
Views: 601

Re: Mikrotik is lab network connected to corporate domain

If you do not have the possibility to alter the corp. network infrastructure, the only thing is left is adding a static route on your corp. domain systems. I don't know what type of systems you are using? As last resort you can also NAT masquerade the traffic from your lab environment towards the co...
by Rudios
Tue Nov 08, 2016 9:10 pm
Forum: Beginner Basics
Topic: No access to LAN over SSTP VPN (can only ping router)
Replies: 13
Views: 3754

Re: No access to LAN over SSTP VPN (can only ping router)

You should add a route to your remote network on your RB1100
by Rudios
Tue Nov 08, 2016 6:02 pm
Forum: Beginner Basics
Topic: No access to LAN over SSTP VPN (can only ping router)
Replies: 13
Views: 3754

Re: No access to LAN over SSTP VPN (can only ping router)

What if you do a trace route towards the server?
by Rudios
Tue Nov 08, 2016 4:43 pm
Forum: Beginner Basics
Topic: how to connect a pc behind a router to nas that is on main cable modem?
Replies: 5
Views: 813

Re: how to connect a pc behind a router to nas that is on main cable modem?

Just disable all DHCP stuff on the routerboard and add all ports to the same bridge.
If bridging all ports, it is just like a switch.
Give the MikroTik an IP address for management only (in the 192.168.0.x segment)
  • 1
  • 2
  • 3
  • 4
  • 5
  • 20