Community discussions

Search found 20 matches

by deem
Thu Jul 11, 2019 2:58 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 100
Views: 39549

Re: v6.44.5 [long-term] is released!

Isn't EoIP using GRE? *) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160); So make sure you're allowing GRE before dropping invalid connections. You are right, the problem is in GRE state matching, but why EoIP tunnels is in invalid connection state now? EoIP is based...
by deem
Tue Jul 09, 2019 1:46 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 100
Views: 39549

Re: v6.44.5 [long-term] is released!

Isn't EoIP using GRE?
*) conntrack - fixed GRE protocol packet connection-state matching (CVE-2014-8160);
So make sure you're allowing GRE before dropping invalid connections.
You are right, the problem is in GRE state matching, but why EoIP tunnels is in invalid connection state now?
by deem
Tue Jul 09, 2019 1:23 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 100
Views: 39549

Re: v6.44.5 [long-term] is released!

There is critical issue for me, firewall input chain with drop action on invalid connection state now drops incoming EoIP packets with no reason.
by deem
Sun Jan 27, 2019 4:15 pm
Forum: RouterBOARD hardware
Topic: No Current Tx Power for hAP ac^2 and cAP ac
Replies: 5
Views: 1733

Re: No Current Tx Power for hAP ac^2 and cAP ac

No tx power inforamtion. @ 2G show zeros, @ 5G nothing at all.

6.42.11
by deem
Sat Aug 26, 2017 1:46 am
Forum: Virtualization
Topic: CHR suggestions for new functionality
Replies: 157
Views: 32854

Re: CHR suggestions for new functionality

CHR should run containers, docker or whatever. clarify please. why and how? In every single setup i put a Mikrotik device on a border, this is followed by various services, often requiring few resources, web frontend TLS, some PHP scripts, some databases and so on. If i could run these on Mikrotik ...
by deem
Thu Aug 24, 2017 5:01 pm
Forum: Virtualization
Topic: CHR suggestions for new functionality
Replies: 157
Views: 32854

Re: CHR suggestions for new functionality

CHR should run containers, docker or whatever.
by deem
Mon Jul 27, 2015 4:50 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 189862

Re: Cloud Hosted Router

Can't connect with winbox. http://deem.ru/temp/2015-07-27%2015-16-59_RouterOS_WinBox_Error.png That is most likely a VM software config issue. Depends on how you set up your virtual NIC and how it is connected to the host PC. VirtualBox has NAT by default, configure it to use Bridge or reconfigure ...
by deem
Mon Jul 27, 2015 3:23 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 189862

Re: Cloud Hosted Router

Can't connect with winbox.

Image
by deem
Mon Apr 13, 2015 7:17 pm
Forum: General
Topic: Mikrotik does not open some sites
Replies: 4
Views: 1508

Re: Mikrotik does not open some sites

Sometimes sites are really unavailable, an ISP have problems with its channels or you are simply banned etc.

From your screenshot it seems the default config works pretty well.

You have to isolate your problem, noone can help you with such poor info.

And check your ISP btw (http://deem.ru/ip/).
by deem
Thu Apr 02, 2015 3:39 pm
Forum: General
Topic: Mikrotik does not open some sites
Replies: 4
Views: 1508

Re: Mikrotik does not open some sites

1) Check "Change TCP MSS" at your PPP profile (should be "yes") 2) Then check it is correctly applied at IP > Firewall > Mangle after PPP call http://deem.ru/images/mikrotik/2015-04-02_15-31-03_PPP_Profile_TCP_MSS_yes.png http://deem.ru/images/mikrotik/2015-04-02_15-32-43_Mangle_Dynamic_all_ppp.png
by deem
Fri Oct 24, 2014 2:33 pm
Forum: General
Topic: Multiple WAN links with NAT/masquerade for private subnets
Replies: 2
Views: 1761

Re: Multiple WAN links with NAT/masquerade for private subne

You MUST help your router with a routing decision, he should be confused with 5 equal default routes.

1) Use 5 simple masquerades (without src-address)
2) Use 5 "mark routing" in mangle prerouting chain with appropriate src-address > dst-address
3) Use 5 ip routes with appropriate marks from 2)
by deem
Fri Oct 24, 2014 2:21 pm
Forum: General
Topic: Shaping of EoIP bridge with non-IP traffic
Replies: 3
Views: 1134

Re: Shaping of EoIP bridge with non-IP traffic

/queue simple add target="your-EoIP-interface"
by deem
Sun Jul 06, 2014 9:15 am
Forum: General
Topic: Freezing / disconnection of Winbox over PPTP VPN
Replies: 10
Views: 4457

Re: Freezing / disconnection of Winbox over PPTP VPN

try PPTP without encryption then everything will works fine. How can we live without encryption nowadays? I found a better solution — to strip IPv4 options: ip firewall mangle add chain=postrouting protocol=tcp src-port=8291 action=strip-ipv4-options Apply this code on every router with the issue. ...
by deem
Wed Jul 02, 2014 11:08 pm
Forum: General
Topic: Freezing / disconnection of Winbox over PPTP VPN
Replies: 10
Views: 4457

Re: Freezing / disconnection of Winbox over PPTP VPN

Joining this issue.

I tried everything: changing MSS, changing MTU/MRU, checking with sniffers etc...

Winbox keeps disconnecting when running over VPN.

In sniffer i found a TCP packet with wrong CRC, after that one side becoming in strange state.

ROS 6.15 very easy to reproduce.
by deem
Sun Feb 02, 2014 11:07 pm
Forum: General
Topic: Broadcast domain + smart routing possible?
Replies: 0
Views: 469

Broadcast domain + smart routing possible?

Have: 3 networks (or more) (192.168.1.0/24, 192.168.2.0/24, 192.168.3.0/24 = home 1, home 2, home 3) 3 ISPs (on each) 3 DHCP servers (on each) Need: 1 broadcast domain (192.168.0.0/20) Smart routes between physical networks (so they don't go through other link if they have own, but if this link is d...
by deem
Sat Nov 09, 2013 1:00 am
Forum: General
Topic: BUG — "Verify Server Certificate" IP address does not match
Replies: 3
Views: 1211

Re: BUG — "Verify Server Certificate" IP address does not ma

Are you talking about SSTP?
Certificate contains DNS name and you have sstp client with latest routeros version where you specify DNS as connect to address?
1) Yes.
2) Yes.

Certificate "Common Name" = DNS name of a server. Windows clients have no problem with this setup.
by deem
Fri Nov 08, 2013 10:45 am
Forum: General
Topic: BUG — "Verify Server Certificate" IP address does not match
Replies: 3
Views: 1211

BUG — "Verify Server Certificate" IP address does not match

"server's IP address does not match certificate" when "Connect To" is a DNS-address, but, it seems, ROS does IP-address match instead of DNS-address match with certificate.
by deem
Sun Sep 22, 2013 1:53 pm
Forum: General
Topic: Double (triple?) queue on ethernet?
Replies: 1
Views: 610

Re: How to emulate a double (triple?) packet processing?

Did some research, it seems what the question becomes "how to emulate a double (triple?) packet processing on an ethernet interface?"

It is possible with MetaROUTER feature, but is it possible with a single ROS?
by deem
Sun Sep 22, 2013 1:37 pm
Forum: General
Topic: simple queues are very inaccurate
Replies: 7
Views: 2246

Re: simple queues are very inaccurate

Perhaps something is happening in the packet flow and queuing that isn't what you expect
Agreed. Check the statistics of upload/download queues separately. It seems only one is used for all traffic.

Simple queues work fine if you understand what you do.
by deem
Mon Sep 16, 2013 6:51 pm
Forum: General
Topic: Double (triple?) queue on ethernet?
Replies: 1
Views: 610

Double (triple?) queue on ethernet?

I can do a double queue then my ISP is something like PPPoE. But what should i do if i got my ISP directly on an ethernet interface? In this case packets pass a queue just once :( This question can be expanded to triple and so on queues. Is there any way to make it on single ROS? Maybe i should flus...