Community discussions

MikroTik App

Search found 90 matches

by martinclaro
Sat Feb 24, 2024 12:49 am
Forum: Scripting
Topic: sxt lte failover
Replies: 3
Views: 403

Re: sxt lte failover

Here is a good reference for dual sim scripts: https://wiki.mikrotik.com/wiki/Dual_SIM_Application
by martinclaro
Thu Dec 07, 2023 1:23 am
Forum: Beginner Basics
Topic: Turned off NAT, now can't get into WebFig
Replies: 13
Views: 2010

Re: Turned off NAT, now can't get into WebFig

I've not tried that yet, but can see I'd need to install Wine for WinBox to run on my Mac or borrow a PC with it. If I do either of these, can you explain how I would physically go about discovering devices in the network? I.e. would I need to plug the dish's CAT6 cable into the laptop again and th...
by martinclaro
Wed Dec 06, 2023 1:57 pm
Forum: Beginner Basics
Topic: Turned off NAT, now can't get into WebFig
Replies: 13
Views: 2010

Re: Turned off NAT, now can't get into WebFig

Are you able to use WinBox and discover devices in the network? Maybe you can still connect by using MAC address instead of IP address.
by martinclaro
Mon Oct 23, 2023 1:44 am
Forum: General
Topic: Downgrading existing EAP config with VLANs to WPA2 PSK
Replies: 5
Views: 1242

Re: Downgrading existing EAP config with VLANs to WPA2 PSK

Under /caps-man datapath

There are some examples in the official docs: https://wiki.mikrotik.com/wiki/Manual:C ... with_VLANs
by martinclaro
Sun Sep 17, 2023 4:17 pm
Forum: Beginner Basics
Topic: Dhcp Mikrotik \ Dns server windows
Replies: 2
Views: 860

Re: Dhcp Mikrotik \ Dns server windows

It’s not the MikroTik router the one sending the DNS update, but the windows machine instead.

(It’s a Microsoft thing AFAIK)
by martinclaro
Fri Sep 08, 2023 2:44 pm
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 72
Views: 15301

Re: Newsletter #114 | September 2023

I would love to see a PoE+ version of the CRS310-8G+2S+IN =)
by martinclaro
Thu Aug 17, 2023 6:05 am
Forum: General
Topic: How to see what is transmitting high Tx
Replies: 6
Views: 997

Re: How to see what is transmitting high Tx

Hi, please share the output of a “/export hide-sensitive” (if ROS 6.x) ot “/export” (if ROS 7.x) command so we can have a better understanding of what could be happening.

My guess: missing/wrong firewall rules and dns open to public or proxy enabled and open to public.
by martinclaro
Tue Jul 25, 2023 6:12 am
Forum: Announcements
Topic: v6.49.8 [long-term] is released!
Replies: 49
Views: 69205

Re: v6.49.8 [long-term] is released!

I made a backup script using shell script in a Linux machine. So Mikrotik devices act as SSH servers and a Linux machine as the SSH client. CCR1072, CCR1009, RB4011, and hEX S. My case is similar to yours (using a RSA priv/pub key pair) and works perfectly after upgrade, at least on RB4011 and hEX ...
by martinclaro
Sun Jul 23, 2023 11:39 pm
Forum: RouterBOARD hardware
Topic: Port Forwarding / Reverse Proxy / Multiple LANs
Replies: 2
Views: 4299

Re: Port Forwarding / Reverse Proxy / Multiple LANs

Another way (simplier to me) is to allow dnatted traffic in the forward chain by accepting connection-nat-state=dstnat
by martinclaro
Sun Jul 23, 2023 11:19 pm
Forum: Announcements
Topic: v6.49.8 [long-term] is released!
Replies: 49
Views: 69205

Re: v6.49.8 [long-term] is released!

Upgraded many RB760iGS, cAP-ac, RB4011, and CHR and everything looks good.

@davidalain do you mean using ROS as SSH client to connect to other devices?
by martinclaro
Thu Jul 06, 2023 8:45 pm
Forum: General
Topic: gateway spoof
Replies: 12
Views: 1449

Re: gateway spoof

Hi @asdgmae2, the solution would depend on how your network architecture is (other routers, switches, etc). Generally speaking, it could be tackled by enabling dhcp-snooping, trusted ports and denying arp-learning on switch ports what are untrusted. Additionally, in your case, in RouterOS set the `a...
by martinclaro
Sat Jul 01, 2023 4:40 am
Forum: General
Topic: Help needed with routing
Replies: 15
Views: 1789

Re: Help needed with routing

What chain are these rules?
Should be “prerouting”
by martinclaro
Wed Jun 28, 2023 3:14 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37237

Re: Forum moderation volunteers

Thanks for giving me the opportunity to contribute @Normis!
by martinclaro
Tue Jun 27, 2023 12:18 am
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 37237

Re: Forum moderation volunteers

I can help with this responsibility as well. IDK if a minimal amount of post is required for such task =)
by martinclaro
Sun May 14, 2023 6:25 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55070

Re: v7.9 [stable] is released!

I understand and have always known this, however, it has always worked normally. I use this RB4011 like this for more than 3 years, even with v7.8 everything was normal. I had used the passive DACs from MikroTik on my RB4011iGS+ without any issue on 6.x. Didn’t use any of those with 7.x, however, I...
by martinclaro
Wed May 03, 2023 6:48 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55070

Re: v7.9 [stable] is released!

Not so smooth on my RB4011iGS+ with ZeroTier package installed before upgrading: - Upgraded ROS from 7.8 to 7.9 [OK] - Upgraded RouterBoot from 7.8 to 7.9 [OK] - Reboot after "system,info,critical Firmware upgraded successfully, please reboot for changes to take effect!" message [Locked du...
by martinclaro
Tue May 02, 2023 2:58 pm
Forum: General
Topic: re-designing home network, how to replace the unifi switch [SOLVED]
Replies: 8
Views: 968

Re: re-designing home network, how to replace the unifi switch [SOLVED]

For the record I did try to power 3 APS (2 nano HD, 1 WALL HD) and 2 camera + Controlleur + PI via POE adapter (home assistant) and it was working well, the budget power is very low for them. Now the main issue is the number of ports... Also would be better to have more sfp+ ports. That’s interesti...
by martinclaro
Sun Apr 30, 2023 11:39 pm
Forum: General
Topic: re-designing home network, how to replace the unifi switch [SOLVED]
Replies: 8
Views: 968

Re: re-designing home network, how to replace the unifi switch [SOLVED]

The RB5009UPr+S+IN won’t provide enough voltage (PoE+) for the Access-Points and the rest of the UniFi products.

Maybe having a spare CRS328 identically-configured but still having to reconnect everything in case the PSU is gone (additionally, the CRS328 PSU is not hot-swappable)
by martinclaro
Fri Mar 10, 2023 3:16 am
Forum: Beginner Basics
Topic: Software VPN Client
Replies: 1
Views: 363

Re: Software VPN Client

Hi, it would depend on which VPN type you want to setup, but Draytek worked fine for me on some clients: https://www.draytek.com/products/smart-vpn-client/
by martinclaro
Tue Jan 18, 2022 3:25 pm
Forum: Beginner Basics
Topic: Send Magic packet to Mikrotik router remotely via VPN
Replies: 5
Views: 2884

Re: Send Magic packet to Mikrotik router remotely via VPN

Ok I will try that. But I also need to undertand. The route of the Magic Packet is something like this?: Magic Packet from WAN --> Modem/router --> Modem/router sends it to all connected devices because it's a broadcast packet --> So it reaches Mikrotik also --> Mikrotik's NAT translate the address...
by martinclaro
Tue Jan 18, 2022 4:09 am
Forum: Beginner Basics
Topic: Send Magic packet to Mikrotik router remotely via VPN
Replies: 5
Views: 2884

Re: Send Magic packet to Mikrotik router remotely via VPN

There is a trick to make WoL work trough NAT. You have to add a static arp entry under IP > ARP (/ip arp) for the host you want to wake-up. /ip firewall nat add action=dst-nat chain=dstnat comment="DNAT: WOL Host XXXX" dst-port=<wan-port> protocol=udp to-addresses=<lan-host-ipaddr> to-port...
by martinclaro
Sun Dec 05, 2021 4:04 pm
Forum: General
Topic: Truely fanless 10Gb switch with routerOS + hardware accceleration [Fixed]
Replies: 32
Views: 9255

Re: Truely fanless 10Gb switch with routerOS + hardware accceleration [Fixed]

CRS309 + CRS326 (-PC) here. Both fanless and you have 10Gb SFP+ interfaces… you can do LACP also.
by martinclaro
Wed Nov 24, 2021 4:35 am
Forum: General
Topic: Route loses its gateway everytime it disconnects - v6.49
Replies: 3
Views: 1616

Re: Route loses its gateway everytime it disconnects - v6.49

You need to add the route in /ppp secrets under routes parameter, for the route to the client network to be installed upon connection.

The route format is: "dst-address gateway metric" (for example, "10.1.0.0/24 10.0.0.1 1"). Several routes may be specified separated with commas
by martinclaro
Tue Aug 24, 2021 2:28 pm
Forum: General
Topic: Windows 7/10 & L2TP connection issue
Replies: 12
Views: 4708

Re: Windows 7/10 & L2TP connection issue

You are right @sindy. I didn’t verify the OP link. The issue is related only to windows. Both MikroTik, Linux and macOS (and iOS) don’t have this issue. Would this dirty trick affect connections from OS’s other than Windows 7/10? on the other hand I agree that if it’s causing SSH issues is because a...
by martinclaro
Tue Aug 24, 2021 6:06 am
Forum: General
Topic: Windows 7/10 & L2TP connection issue
Replies: 12
Views: 4708

Re: Windows 7/10 & L2TP connection issue

I’ve found the following solution for the L2TP/IPSec server behind NAT:
http://woshub.com/l2tp-ipsec-vpn-server-behind/
by martinclaro
Fri Jun 04, 2021 7:45 am
Forum: General
Topic: Is there a problem with IP Cloud? [SOLVED]
Replies: 70
Views: 23460

Re: Is there a problem with IP Cloud? [SOLVED]

Same here with 6.47.10 long-term
by martinclaro
Tue Mar 02, 2021 4:19 am
Forum: Scripting
Topic: Excluding dynamic entries from [ find ]
Replies: 3
Views: 1727

Re: Excluding dynamic entries from [ find ]

remove [find where !dynamic]
by martinclaro
Tue Dec 29, 2020 7:07 pm
Forum: General
Topic: Hairpin NAT no longer working after setting up VLANS [SOLVED]
Replies: 9
Views: 2259

Re: Hairpin NAT no longer working after setting up VLANS [SOLVED]

The following rule at filter table is not allowing your hairpinned-nat traffic:
add action=accept chain=forward connection-nat-state=dstnat in-interface=ether1
You may need to unset the in-interface parameter.

EDIT: mkx had the same observation :D (too fast :)
by martinclaro
Wed Nov 04, 2020 12:46 am
Forum: General
Topic: Framed Route - Two IP addresses from my ISP [SOLVED]
Replies: 12
Views: 3444

Re: Framed Route - Two IP addresses from my ISP [SOLVED]

Hi, this other topic may be helpful: viewtopic.php?t=131363
by martinclaro
Fri Oct 09, 2020 2:26 am
Forum: Beginner Basics
Topic: SSTP and HTTPS WebUI - interference?
Replies: 2
Views: 693

Re: SSTP and HTTPS WebUI - interference?

For most simple setups You must use separate ports for HTTPS Web UI and SSTP Server (I.e. 443 and 8443). SSTP client is not affected. I think you can do some NAT to redirect traffic coming to 443 port and redirect to internal ports if you want to expose same tcp ports in different addresses (I.e. wa...
by martinclaro
Sat Aug 08, 2020 8:05 pm
Forum: General
Topic: LTAP Mini LTE kit - LTE interface dissapears after reboot
Replies: 15
Views: 6420

Re: LTAP Mini LTE kit - LTE interface dissapears after reboot

Mine was R2. I already RMA-ed the device due to lack of response from official MikroTik support (SUP-23837). The new one (also R2) has modem firmware MikroTik_CP_2.160.000_v012 and works fine. I won't upgrade to MikroTik_CP_2.160.000_v017 until I get some kind of response from official support. Also...
by martinclaro
Sat Aug 08, 2020 5:10 am
Forum: General
Topic: Broadcast Traffic Firewall Filter
Replies: 3
Views: 1729

Re: Broadcast Traffic Firewall Filter

IPv6 does not implement broadcast addressing. Broadcast's traditional role is subsumed by multicast addressing to the all-nodes link-local multicast group. You may need to check the following link to know which all-nodes well known addresses you need to filter: https://www.iana.org/assignments/ipv6-...
by martinclaro
Fri Aug 07, 2020 10:43 pm
Forum: General
Topic: l2tp VPN routing issue
Replies: 2
Views: 1222

Re: l2tp VPN routing issue

Probably you may need to NAT the traffic going through VPN if you don’t have the appropriate static routes on each side or dynamic routing properly set.
by martinclaro
Mon Aug 03, 2020 5:41 pm
Forum: General
Topic: LTAP Mini LTE kit - LTE interface dissapears after reboot
Replies: 15
Views: 6420

Re: LTAP Mini LTE kit - LTE interface dissapears after reboot

Contact to Mikrotik support.

Regards.
Sure, I'm getting all the required information to send them a full report.
by martinclaro
Mon Aug 03, 2020 5:32 am
Forum: General
Topic: LTAP Mini LTE kit - LTE interface dissapears after reboot
Replies: 15
Views: 6420

Re: LTAP Mini LTE kit - LTE interface dissapears after reboot

Forget my previous post... after one day, LTE interface is gone after reboot.
by martinclaro
Sun Aug 02, 2020 8:13 am
Forum: General
Topic: LTAP Mini LTE kit - LTE interface dissapears after reboot
Replies: 15
Views: 6420

Re: LTAP Mini LTE kit - LTE interface dissapears after reboot

Latest stable (6.47.1) with modem firmware MikroTik_CP_2.160.000_v017 work well after reboots.
by martinclaro
Sun Aug 02, 2020 5:23 am
Forum: General
Topic: LTAP Mini LTE kit - LTE interface dissapears after reboot
Replies: 15
Views: 6420

Re: LTAP Mini LTE kit - LTE interface dissapears after reboot

Has anybody found a solution for this problem? Having same issue. use latest ROS and latest modem firmware and you will be good. Give us logs if you have a problem. Latest long-term with latest modem firmware has the same issue. No LTE interface after reboot. Everything gets back to normal after po...
by martinclaro
Fri Jul 31, 2020 4:55 am
Forum: General
Topic: DNS resolution vulnerability
Replies: 14
Views: 4108

Re: DNS resolution vulnerability

Can you share an export of firewall settings (both filter and nat rules)? Maybe you are dst-nating dns queries from the wan side at nat rules, and allowing dstnated packets on the filter rules.

Is your wan interface added to the WAN interface-list?
by martinclaro
Fri Jul 17, 2020 5:38 am
Forum: Useful user articles
Topic: [Request] Mikrotik Online Training during Pandamic
Replies: 5
Views: 8512

Re: [Request] Mikrotik Online Training during Pandamic

I totally agree with this request! Can’t wait to get more certifications.

Online MUM would be awesome too!
by martinclaro
Sat Jun 20, 2020 6:27 am
Forum: General
Topic: Block pornographic pages
Replies: 5
Views: 2588

Re: Block pornographic pages

You can try using the CloudFlare DNS for Families to block both malware and adult sites. More info here: https://developers.cloudflare.com/1.1.1 ... -families/

You may also want to enforce DNS by redirecting all DNS queries to your router or specific destination.
by martinclaro
Wed Jun 17, 2020 4:46 am
Forum: Beginner Basics
Topic: IP-Cloud Dynamic IP WAN Behind Nat
Replies: 6
Views: 13889

Re: IP-Cloud Dynamic IP WAN Behind Nat

I usually prefer SSTP Tunnel to a public VPN concentrator (i.e. CHR on AWS) so you can access the entire network through a VPN.

Of course , there are many other options to achieve similar results.
by martinclaro
Wed Jun 10, 2020 4:43 am
Forum: General
Topic: How to setup WiFi calling (aka VoWIFI) on mikrotik
Replies: 20
Views: 10618

Re: How to setup WiFi calling (aka VoWIFI) on mikrotik

I agree with @sindy. Many other factors could contribute to the observed issue.

Please tell us more about your deployment (WiFi AP or other details). And don’t forget:
 /export hide-sensitive
by martinclaro
Tue Jun 09, 2020 5:34 am
Forum: General
Topic: How to setup WiFi calling (aka VoWIFI) on mikrotik
Replies: 20
Views: 10618

Re: How to setup WiFi calling (aka VoWIFI) on mikrotik

Make sure you are not blocking IPSec traffic (protocols or ports) in the forward table coming from your LAN side. Also, check your DNS cache to see if the devices are resolving 3gpp FQDN pointing to the telco core network for VoWiFi (you can also setup QoS for that traffic): /ip dns cache print wher...
by martinclaro
Sun May 31, 2020 4:31 pm
Forum: General
Topic: not work bonding mod 802.3ad mikrotik
Replies: 2
Views: 797

Re: not work bonding mod 802.3ad mikrotik

/interface bonding
add mode=802.3ad name=bond01 slaves=ether1,ether2 transmit-hash-policy=layer-2-and-3
by martinclaro
Tue Apr 14, 2020 10:38 pm
Forum: Beginner Basics
Topic: to instal backup to another router
Replies: 12
Views: 3769

Re: to instal backup to another router

to: ingdaka. thx for your answer
If I understand well I start New terminal from menu and after that I write instruction: "export". Is it the correct way?
Just run the following command and download the file from the Files section:
/export file=backup-export.rsc
by martinclaro
Sun Apr 12, 2020 5:30 am
Forum: RouterBOARD hardware
Topic: Need new hardware switch (based on RB260GS but do not need SFP/PoE)
Replies: 34
Views: 9103

Re: Need new hardware switch (based on hEX)

hEX is a router! I do not need to make a switch from the router! I need gigabit switch (as Gigabit Ethernet Repeater "GPeR" but on 5 ports) - without PoE - without USB - without microSD - without CPU MT7621A (enough QCA8511) Its price should be much less! What is the point of buying an hE...
by martinclaro
Sat Apr 11, 2020 5:46 pm
Forum: RouterBOARD hardware
Topic: Need new hardware switch (based on RB260GS but do not need SFP/PoE)
Replies: 34
Views: 9103

Re: Need new hardware switch (based on hEX)

Is the hEX too expensive to work as a switch? I don’t know what your topology looks like but it could help you to implement OSPF and avoid bridging. Anyways, it can work as a switch too.
by martinclaro
Sun Mar 15, 2020 11:28 pm
Forum: Scripting
Topic: tool fetch and new line break
Replies: 2
Views: 3759

Re: tool fetch and new line break

You can use %0A to send url-encoded line breaks.
by martinclaro
Thu Mar 12, 2020 10:35 pm
Forum: General
Topic: CRS354-48G-4S+2Q+ unable to switch to switchos
Replies: 5
Views: 3462

Re: CRS354-48G-4S+2Q+ unable to switch to switchos

Did you try with the following command?
  /system routerboard settings set boot-os=swos
by martinclaro
Sun Mar 08, 2020 6:01 pm
Forum: General
Topic: Unifi AP and VLANs
Replies: 2
Views: 3369

Re: Unifi AP and VLANs

AFAIK UniFi controller doesn’t have management VLAN settings. They all expect to be untagged, so you can set PVID on all access ports and use trunk ports for UniFi AP and controller.
by martinclaro
Wed Feb 26, 2020 1:17 pm
Forum: Beginner Basics
Topic: FTTH very slow download speed (upload ok)
Replies: 15
Views: 9874

Re: FTTH very slow download speed (upload ok)

Is this setting really necessary?.
/interface bridge settings
set use-ip-firewall=yes use-ip-firewall-for-pppoe=yes
I think no. Try disabling both and check the speed
by martinclaro
Sun Feb 02, 2020 3:35 pm
Forum: Wireless Networking
Topic: Wireless Wire wAP60G
Replies: 6
Views: 3413

Re: Wireless Wire wAP60G

I forgot to mention that you could also use the following command to get more stats on both ends (master and slave-side):
/interface w60g print stats interval=1
by martinclaro
Sun Feb 02, 2020 5:13 am
Forum: General
Topic: Connection problems with iPhone when using fixed DHCP lease
Replies: 2
Views: 1637

Re: Connection problems with iPhone when using fixed DHCP lease

Network tab is there to set DHCP some of the values sent by DHCP server inside DHCP offer/ack packets.

To set a static IP address, you need to go to DHCP Server > Leases tab.

Also, the network address has the wrong mask in your screenshot.
by martinclaro
Sun Feb 02, 2020 1:07 am
Forum: Wireless Networking
Topic: Wireless Wire wAP60G
Replies: 6
Views: 3413

Re: Wireless Wire wAP60G

You can monitor the error rate and MCS on the client-side (station) of the link by running the following command: /interface w60g monitor 0 connected: yes frequency: 58320 remote-address: 30:07:4D:XX:XX:XX tx-mcs: 8 tx-phy-rate: 2.3Gbps signal: 95 rssi: -50 tx-sector: 36 tx-sector-info: center dista...
by martinclaro
Thu Jan 30, 2020 1:51 pm
Forum: General
Topic: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquiti Unifi Network Switch
Replies: 31
Views: 8501

Re: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquite Unifi Network Switch

Hi, did you see this one?

https://mikrotik.com/product/CRS326-24G-2SplusRM

Completely silent, external power supply (very little one) and PoE-In support. Also bigger than the ones you found (is that an issue?).
by martinclaro
Thu Jan 23, 2020 4:56 pm
Forum: Beginner Basics
Topic: Wireless Wire Connectivity issues from device itself
Replies: 5
Views: 3376

Re: Wireless Wire Connectivity issues from device itself

Hi, I have a similar setup but it works great. Maybe you can post the output of the following command between [ CODE ] [ /CODE ] tags.
 /export hide-sensitive
by martinclaro
Thu Jan 23, 2020 3:11 am
Forum: General
Topic: My public IP is getting raped by port scanners - is that normal?
Replies: 24
Views: 6181

Re: My public IP is getting raped by port scanners - is that normal?

Maybe you can add a tarpit rule before the drop rule to make them busier and see the results.

Tarpit TCP, Drop UDP.
by martinclaro
Sat Nov 16, 2019 7:50 pm
Forum: General
Topic: Tapatalk + Mikrotik forum
Replies: 26
Views: 7623

Re: Tapatalk + Mikrotik forum

So can the trouble description be formulated more precisely as "Tapatalk (regardless whether free or pro) on iPhone does not work specifically with forum.mikrotik.com, while it does work just fine with at least one other forum"?
Precisely.
by martinclaro
Fri Nov 15, 2019 1:40 pm
Forum: General
Topic: Tapatalk + Mikrotik forum
Replies: 26
Views: 7623

Re: Tapatalk + Mikrotik forum

Same here. It doesn’t work on iPhone (since at least 2 years)
by martinclaro
Fri Oct 04, 2019 2:30 pm
Forum: General
Topic: hotspot users blocking a site
Replies: 3
Views: 2171

Re: hotspot users blocking a site

I think you can block the hotspot users to access those sites by adding them to the hotspot filtering rules: https://wiki.mikrotik.com/wiki/Manual:I ... led_Garden

Or you can add the same mangle and filter rules four output chain, so the proxied traffic will also match.
by martinclaro
Mon Sep 23, 2019 10:12 pm
Forum: RouterBOARD hardware
Topic: Recover from "No Default Configuration" System Reset
Replies: 17
Views: 11142

Re: Recover from "No Default Configuration" System Reset

Why not to use Winbox with MAC address?
Because the OP asks about Linux command to connect using mac-telnet. Obviously he can run WinBox in a VirtualBox guest.
by martinclaro
Wed Sep 18, 2019 3:01 pm
Forum: General
Topic: Ruted Network and Sonos Speakers
Replies: 4
Views: 2185

Re: Ruted Network and Sonos Speakers

Most answers for that kind of setup is NO, because most network-connected speakers and media players (Sonos, Apple TV, HomePod, etc.) require the devices to be in the same broadcast domain (same subnet), and won’t work in a routed environment except for one case: using a mDNS/Bonjour proxy. You can ...
by martinclaro
Sun Sep 15, 2019 1:52 pm
Forum: General
Topic: How to block websites? [SOLVED]
Replies: 5
Views: 13451

Re: How to block websites? [SOLVED]

You have to move the tls-host and layer-7 rules before accepting related/established connections.
by martinclaro
Sun Sep 15, 2019 6:11 am
Forum: General
Topic: How to block websites? [SOLVED]
Replies: 5
Views: 13451

Re: How to block websites? [SOLVED]

Could you post the output of the following command so we can figure out what is not working on your setup?
/ip firewall export
by martinclaro
Sat Sep 14, 2019 5:23 pm
Forum: Beginner Basics
Topic: Add Adress List Users to Queue [SOLVED]
Replies: 5
Views: 4891

Re: Add Adress List Users to Queue [SOLVED]

Maybe a better approach is to mark those BitTorrent packets and put them in a queue with less priority (bigger number) so you can prioritize other traffic before BitTorrent. It’s easier and does not rely on a script to be run every minute.
by martinclaro
Sat Sep 14, 2019 4:05 pm
Forum: Beginner Basics
Topic: Add Adress List Users to Queue [SOLVED]
Replies: 5
Views: 4891

Re: Add Adress List Users to Queue [SOLVED]

Not at all... let's say you have an address-list named "acl-limited" with specific addresses (or set dynamically via dhcp-server leases), and your LAN address is 1.2.3.0/24: /ip firewall address-list add list=acl-limited address=1.2.3.4 add list=acl-limited address=1.2.3.5 add list=acl-lim...
by martinclaro
Sat Sep 14, 2019 2:34 pm
Forum: Beginner Basics
Topic: Add Adress List Users to Queue [SOLVED]
Replies: 5
Views: 4891

Re: Add Adress List Users to Queue [SOLVED]

You can add the mangle Rules to match src/dst-address-list and mark those packets.

Then, use the same mark at the simple queues or queue tree.
by martinclaro
Fri Sep 06, 2019 1:54 am
Forum: Beginner Basics
Topic: How to change source IP to destination network
Replies: 10
Views: 7055

Re: How to change source IP to destination network

---EDITED---
Try to put the srcnat rule before other srcnat/masquerade rules and do a traceroute to see what happens.
by martinclaro
Thu Sep 05, 2019 5:25 pm
Forum: Beginner Basics
Topic: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?
Replies: 18
Views: 6056

Re: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?

Well, that's because you are using a certificate created by yourself, not by a trusted entity. That's not a router issue. Maybe you can deal with the new issue by adding the CA certificate to your windows host. Also the common-name or the alt-name should match the hostname you are using to connect t...
by martinclaro
Thu Sep 05, 2019 4:44 pm
Forum: Beginner Basics
Topic: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?
Replies: 18
Views: 6056

Re: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?

[admin@MikroTik] > /ip service export hide-sensitive # sep/05/2019 16:26:29 by RouterOS 6.45.1 # software id = SEYH-HLMS # # model = RouterBOARD 941-2nD # serial number = 8AFE08FFCDCE [admin@MikroTik] > Ok, so you will need to desable the www-ssl service or change its port: To disable it: /ip servi...
by martinclaro
Thu Sep 05, 2019 3:20 pm
Forum: Beginner Basics
Topic: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?
Replies: 18
Views: 6056

Re: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?

[admin@MikroTik] > /interface sstp-server server export hide-sensitive # sep/05/2019 14:58:00 by RouterOS 6.45.1 # software id = SEYH-HLMS # # model = RouterBOARD 941-2nD # serial number = 8AFE08FFCDCE /interface sstp-server server set authentication=mschap2 certificate=server enabled=yes [admin@Mi...
by martinclaro
Thu Sep 05, 2019 3:15 pm
Forum: Beginner Basics
Topic: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?
Replies: 18
Views: 6056

Re: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?

[admin@MikroTik] > /ip services export hide-sensitive
bad command name services (line 1 column 5
I'm sorry, the command is:
/ip service export hide-sensitive
by martinclaro
Thu Sep 05, 2019 3:13 pm
Forum: Beginner Basics
Topic: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?
Replies: 18
Views: 6056

Re: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?

Start by moving this rule: add action=accept chain=input comment="Permit SSTP" dst-port=443 protocol=tcp before this other rule: add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN That's why the router is dropping the connections fr...
by martinclaro
Thu Sep 05, 2019 2:45 pm
Forum: Beginner Basics
Topic: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?
Replies: 18
Views: 6056

Re: How do i solve Error 0x8007274C in windows 7 when connecting vpn from windows 7 to mirotik hap lite router?

You only need yo allow traffic to port 443 (or the port you set on /interface sstp-server server) in the input chain. Do not add a nat rule for the port. Second, make sure you have disabled the www-ssl service on "/ip service" (or change the port at /ip service) so the port does not confli...
by martinclaro
Thu Sep 05, 2019 2:02 pm
Forum: Beginner Basics
Topic: 1 interface, 2 vlans, prioritize Vlan2 95%
Replies: 8
Views: 2561

Re: 1 interface, 2 vlans, prioritize Vlan2 95%

VLANS are presented as interfaces by themselves, so you need to use the vlan interface name on the queues.

Again, the queues will not balance the traffic, just will limit it.

On simple queues, you can use the “dst” parameter to set the upstream interface (vlan in this case).
by martinclaro
Thu Sep 05, 2019 2:37 am
Forum: Beginner Basics
Topic: Unstopable DSTNAT
Replies: 17
Views: 4884

Re: Unstopable DSTNAT

Good to hear you resolved the issue.

For future reference, the traffic between 2 IP addresses belonging to the same bridge and same subnet does NOT go through the firewall as it is a Layer-3 firewall (unless you have enabled the use-ip-firewall option under /interface bridge settings).
by martinclaro
Thu Sep 05, 2019 2:09 am
Forum: Beginner Basics
Topic: Change DDNS name (Mikrotik cloud)
Replies: 11
Views: 10667

Re: Change DDNS name (Mikrotik cloud)

You can't change the name but, if you have your own domain, you can point a CNAME record in your domain's DNS to point to 529c0491d41c.sn.mynetname.net . ;; ANSWER SECTION: router.yourdomain.com. 179 IN CNAME 529c0491d41c.sn.mynetname.net. 529c0491d41c.sn.mynetname.net. 13 IN A 1.2.3.4
by martinclaro
Thu Sep 05, 2019 1:59 am
Forum: Beginner Basics
Topic: 1 interface, 2 vlans, prioritize Vlan2 95%
Replies: 8
Views: 2561

Re: 1 interface, 2 vlans, prioritize Vlan2 95%

To do that, you will need to do load-balancing + failover (search for PCC or ECMP). https://wiki.mikrotik.com/wiki/Load_Balancing https://wiki.mikrotik.com/wiki/ECMP_load_balancing_with_masquerade https://wiki.mikrotik.com/wiki/Manual:PCC Queues won't help with traffic distribution, but will put a l...
by martinclaro
Tue Sep 03, 2019 10:33 pm
Forum: Wireless Networking
Topic: Do I have to separate configurations within CAPsMan?
Replies: 4
Views: 1544

Re: Do I have to separate configurations within CAPsMan?

Correct, and the same applies to CAP interfaces.
by martinclaro
Tue Sep 03, 2019 9:27 pm
Forum: Wireless Networking
Topic: Do I have to separate configurations within CAPsMan?
Replies: 4
Views: 1544

Re: Do I have to separate configurations within CAPsMan?

Indeed, you will find useful to configure the specific settings as the work like "profiles" you can override under interface tab. I usually create all the settings separately (channels, datapaths, security, rates, and all together into configuration), then I set the interfaces. If I want t...
by martinclaro
Wed Aug 28, 2019 9:01 pm
Forum: Beginner Basics
Topic: RB4011iGS with more subnets
Replies: 11
Views: 2675

Re: RB4011iGS with more subnets

Ok, can you provide the output of the following commands?
/export hide-sensitive
/ip arp print
/ip address print
/ip route print
Just obfuscate the public IP addresses only.
by martinclaro
Wed Aug 28, 2019 6:13 pm
Forum: Beginner Basics
Topic: RB4011iGS with more subnets
Replies: 11
Views: 2675

Re: RB4011iGS with more subnets

You can start by removing the ether10 port from bridge, or assign the IP address to the bridge.
by martinclaro
Wed Jul 10, 2019 8:58 pm
Forum: Beginner Basics
Topic: mikrotik as router with dhcp doesn't see some devices with static adress manually entered on the device
Replies: 1
Views: 1062

Re: mikrotik as router with dhcp doesn't see some devices with static adress manually entered on the device

Hi, can you post an export so we can help you? Looks like wrong settings for ARP under bridge or interface.
by martinclaro
Tue Feb 26, 2019 2:15 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 96992

Re: v6.44 [stable] is released!

Upgraded a RB851G (both RouterOS and RouterBOOT) from 6.42.12 today. I get errors every time I try to save a backup file (both local and cloud, same error). [admin@xxxx] > /system backup save Saving system configuration Configuration backup saved 08:54:42 echo: backup,critical error creating backup...
by martinclaro
Tue Feb 26, 2019 2:00 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 96992

Re: v6.44 [stable] is released!

Upgraded a RB851G (both RouterOS and RouterBOOT) from 6.42.12 today. I get errors every time I try to save a backup file (both local and cloud, same error). [admin@xxxx] > /system backup save Saving system configuration Configuration backup saved 08:54:42 echo: backup,critical error creating backup ...
by martinclaro
Mon Dec 17, 2018 11:17 pm
Forum: General
Topic: IP CLOUD is down
Replies: 65
Views: 24125

Re: IP CLOUD is down

@martinclaro It takes about 15 minutes for it to start working again once you upgrade @tricksol, as I said before, my routers and CHR were updated before this issue happened. I also rebooted some of my routers and nothing happened. As many other forum members said, it looks like connectivity or res...
by martinclaro
Mon Dec 17, 2018 5:41 pm
Forum: General
Topic: IP CLOUD is down
Replies: 65
Views: 24125

Re: IP CLOUD is down

Upgrading will make it work again + give some new features. Name will stay and nothing else will change. @normis I've been upgrading both RouterOS and Firmware to the latest current-channel version on all my devices and today the service is not working. Is there any process to follow to enable the ...
by martinclaro
Sat Sep 28, 2013 6:18 am
Forum: Beginner Basics
Topic: Layer 7 facebook block
Replies: 29
Views: 166758

Re: Layer 7 facebook block

Also you can update those rules by using whois in a linux/unix/mac box running the following commands: echo "/ip firewall filter" ; whois -h whois.radb.net -- '-i origin AS32934' | grep '^route:' | sort -n | uniq | awk '{print "add action=drop chain=forward comment=Facebook dst-addres...