Community discussions

Search found 257 matches

by RackKing
Wed Aug 07, 2019 4:24 pm
Forum: RouterBOARD hardware
Topic: WAN to LAN performance clarity sought...
Replies: 1
Views: 352

WAN to LAN performance clarity sought...

Hi, I just want to make sure I am interpreting this correctly. Here is some basic info copied in from the Tik Site for 512 bytes hAP AC^2 - Routing 25 ip filter rules 986.3 RB3011 - Routing 25 ip filter rules 836.0 RB4011 - Routing 25 ip filter rules 2,560.8 I am looking at these devices for routing...
by RackKing
Thu Jul 25, 2019 5:33 pm
Forum: General
Topic: Firewall filter when port forwarded
Replies: 4
Views: 557

Re: Firewall filter when port forwarded

Hi anav - On this - add chain=forward action=accept in-interface=WAN \ connection-state=new nat-connection-state=dst nat Does/should the connection state need to be new? Or does it matter? Thanks ... Okay your individual rules need to be in NAT, only one general firewall filter rule (forward chain) ...
by RackKing
Wed Jul 24, 2019 3:29 pm
Forum: Beginner Basics
Topic: Virtual AP Mac address... use same ones?
Replies: 1
Views: 214

Virtual AP Mac address... use same ones?

Hi, I have a script for hAP ac2 that has wifi settings. I notice that when I create a virtual AP it creates a random (I think) MAC address for it. I realize this a requirement. When I export that config and want to use it in another hAP - can I use the same MAC the original one generated? It has the...
by RackKing
Wed Jun 19, 2019 3:33 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

I have done some more testing on various versions of this script and typical failures that in my mind simulate a malicious attack.. Here are my findings. The script will work properly if the log messages is in this exact format: x.x.x.x phase 1 negotiation failed I believe this is when the VPN serve...
by RackKing
Tue Jun 18, 2019 3:21 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

7d does not work, max 24h, since field is just hour. Did you try then end of line $ ? :local loglist [:toarray [/log find message~"negotiation failed.\$"]] Ah - thank you for the clarification on the 24h part. The first time I ran that as I indicated in #22 I go nothing. How when I run it I do get ...
by RackKing
Tue Jun 18, 2019 2:46 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

I also went back to post #6 and re ran those scripts thinking that since we had different "negotation failed" messages these may work. But I did not receive out put from either. I did adjust the time back far enough to grab them. Below is the second one. :put [:toarray [/log find time>([/system cloc...
by RackKing
Tue Jun 18, 2019 2:38 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

I was working with the script again in an effort to get it going - here is where I at. This: [ :local loglist [:toarray [/log find (message~"negotiation failed" || message~"src_ip")]] :foreach i in=$loglist do={ :local logMessage [/log get $i message] :local ip [:pick $logMessage 0 [:find $logMessag...
by RackKing
Mon Jun 17, 2019 1:33 am
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

Again - thank you for your help. I really appreciate your help like to get his working. Here is the output from the first version https://i.imgur.com/zbjNFkZ.jpg Or this may do, make sure negotiation filed. is at the end of the line The second version did not pull anything. So the first version appe...
by RackKing
Sun Jun 16, 2019 4:41 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

Here is one where id work the IP and message = is the IP address

Image
by RackKing
Sun Jun 16, 2019 4:36 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

Thank you for your continued help in this.

This is a sample of what I get.... it is about 20-30 lines longer.

Image
by RackKing
Sun Jun 16, 2019 2:29 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

For clarity - when I use what I believe is the "within last 24 hour" part of the original script I get no output. [ :local loglist [:toarray [/log find time>([/system clock get time] -24h) message~"negotiation failed"]] :foreach i in=$loglist do={ :local logMessage [/log get $i message] :local ip [:...
by RackKing
Sun Jun 16, 2019 2:11 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

For anyone who may see this - here is some code I have cobbled together to produce the following output. To be clear - this was code that Jotone wrote and is his credit. I am simply trying to find why it does not work for me. [ :local loglist [:toarray [/log find message~"negotiation failed"]] :fore...
by RackKing
Sun Jun 16, 2019 12:47 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

Ok Jotne - Thank you for the links. I assume the script you posted works on your MTs? I would have thought that I could copy a working script and duplicate the results. I will struggle with it some more, but probably do not have the programming skills to work through it. Thanks again for your efforts.
by RackKing
Sun Jun 16, 2019 3:57 am
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

[ :local list [:toarray [/log find message~"negotiation failed"]] :put "ID-List" :put $list :put "" :put "Log lines" :foreach i in=$list do={ :put [/log print as-value where .id=$i]} ] So I ran that - and the log started filling up with lots of lines... I had to interrupt it :-) so that worked Then...
by RackKing
Sun Jun 16, 2019 3:19 am
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

When I copy that in CLI I get the following - ID-List Log lines That is it - with two blanks between. The log is filled with at least 10 "negotiation failed" lines in the last 24 hours. Could the clock be causing a problem? The log is stored in memory - I assume that is ok as default? update - I typ...
by RackKing
Sat Jun 15, 2019 2:50 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

Hi - Here is what happens with the first part - 1. dynamically created a FW address-list rule named IPSEC with and address of phase1. Timeout is correct. 2. Terminal L1: script=IPSEC_failed src_ip=phase1 3. Terminal L2: failure: already have such entry note: I deleted the previous phase1 entries for...
by RackKing
Sat Jun 15, 2019 3:25 am
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

Thanks Jotne - I will try it later and report back.
by RackKing
Fri Jun 14, 2019 4:00 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

I was trying to copy your original post in to the script windows and not CLI. Adding it Via CLI worked better. It ran and gave me a FW entry this time, but it does not pull the IP from the log entry. Here is the log add from the script: script=IPSEC_failed src_ip=phase1 That is the beginning of the ...
by RackKing
Fri Jun 14, 2019 2:31 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

When I add the all the script code via copy/paste it fails. So this must be some CR issue on my end.

I will try and sort it later.

Thanks for your help
by RackKing
Thu Jun 13, 2019 4:16 pm
Forum: General
Topic: L2TP/IPSec more than one shared secret? [SOLVED]
Replies: 8
Views: 638

Re: L2TP/IPSec more than one shared secret? [SOLVED]

Got it - I understand and appreciate your comments.

Your concise explanations are great.
by RackKing
Thu Jun 13, 2019 2:33 pm
Forum: Scripting
Topic: Script to add IP of failed IPSEC login to block list
Replies: 28
Views: 1985

Re: Script to add IP of failed IPSEC login to block list

Thank you for this!
by RackKing
Thu Jun 13, 2019 1:32 pm
Forum: RouterBOARD hardware
Topic: Mikrotik SFP / Cisco
Replies: 3
Views: 728

Re: Mikrotik SFP / Cisco

Probably not massively helpful for you but I successfully use the Cisco GLC-SX-MM SFP's in all of my MT devices. Dirt cheap on the second hand market as well.
Thanks for the tip - very helpful
by RackKing
Thu Jun 13, 2019 12:38 pm
Forum: General
Topic: L2TP/IPSec more than one shared secret? [SOLVED]
Replies: 8
Views: 638

Re: L2TP/IPSec more than one shared secret? [SOLVED]

Thank you. For a road warrior scenario - is there an approach that will work? Alternative VPN or otherwise? As for firewall handling of the contractor, there is plenty of possibilities: you can set a specific remote-address in the contractor's /ppp secret item, or you can make that item refer to a d...
by RackKing
Thu Jun 13, 2019 4:35 am
Forum: General
Topic: L2TP/IPSec more than one shared secret? [SOLVED]
Replies: 8
Views: 638

Re: L2TP/IPSec more than one shared secret? [SOLVED]

Thanks sindy - Can the address be the address assigned to the them in the /ppp /secrets local-address? So when those credentials are used they always get the same IP that I can use in FW filter rules? I am assuming that "Incoming connection requests from the IP address" refers to the contractors WAN...
by RackKing
Thu Jun 13, 2019 1:44 am
Forum: General
Topic: L2TP/IPSec more than one shared secret? [SOLVED]
Replies: 8
Views: 638

Re: L2TP/IPSec more than one shared secret? [SOLVED]

Looks like there has to be a peer and an identity. Did not get it working.

It looks the the key in peer1 is taken from the L2TP server settings.
by RackKing
Wed Jun 12, 2019 2:16 pm
Forum: General
Topic: L2TP/IPSec more than one shared secret? [SOLVED]
Replies: 8
Views: 638

L2TP/IPSec more than one shared secret? [SOLVED]

I have an L2TP/IPSec VPN server up and running on our Mikrotik. I would like to add a VPN user who is outside our organization (i.e. not our employee) in order gain access to certain assets for support. I know I can specify a remote address and use firewall filter rules with that address to limit ac...
by RackKing
Tue Jun 11, 2019 11:07 am
Forum: General
Topic: LT2P/IPSec VPN working no internet access [SOLVED]
Replies: 6
Views: 717

Re: LT2P/IPSec VPN working no internet access [SOLVED]

Thank you again.
by RackKing
Mon Jun 10, 2019 2:43 pm
Forum: General
Topic: LT2P/IPSec VPN working no internet access [SOLVED]
Replies: 6
Views: 717

Re: LT2P/IPSec VPN working no internet access [SOLVED]

"So either add an interface-list=LAN item to the /ppp profile" This looks like a cleaner way to do it. Should I add the interface-list=LAN to both the default and default-encryption profile? To test, I added it to the default-encryption profile and it worked. I did not realize you could dynamically ...
by RackKing
Mon Jun 10, 2019 2:10 am
Forum: General
Topic: LT2P/IPSec VPN working no internet access [SOLVED]
Replies: 6
Views: 717

Re: LT2P/IPSec VPN working no internet access [SOLVED]

Ok - good idea # jun/09/2019 17:49:01 by RouterOS 6.44.3 /interface vlan add interface=main_bridge name=main-v10 vlan-id=10 /interface list add name=WAN add name=LAN /ip pool add name=main ranges=192.168.254.50-192.168.254.199 add name=vpn ranges=192.168.50.50-192.168.50.80 /ip dhcp-server add addre...
by RackKing
Sun Jun 09, 2019 8:52 pm
Forum: General
Topic: LT2P/IPSec VPN working no internet access [SOLVED]
Replies: 6
Views: 717

LT2P/IPSec VPN working no internet access [SOLVED]

Hi - I have an L2TP / IPSec VPN server configured and working (except for internet access) as per these instructions - https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP The VPN tunnel works and I can see the assets on the remote networks - as the firewall allows. The VPN network has a nat Masq ru...
by RackKing
Sun Jun 09, 2019 6:01 pm
Forum: General
Topic: Please check my FW rules for Unifi controller? [SOLVED]
Replies: 2
Views: 271

Re: Please check my FW rules for Unifi controller? [SOLVED]

You've mixed things together in the filter rules. As you've combined the conditions which "new" packets must meet in order to be accepted with a condition saying they must not be "new" in a single rule, no "new" packet will ever go through, so no connection will ever be initiated. You are a scholar...
by RackKing
Sun Jun 09, 2019 5:16 pm
Forum: General
Topic: Please check my FW rules for Unifi controller? [SOLVED]
Replies: 2
Views: 271

Please check my FW rules for Unifi controller? [SOLVED]

Hi, I have a Unifi controller behind a Mikrotik 3011 that works for my local gear. I want to add another site with APs that are at a friends house. I got the port list from https://help.ubnt.com/hc/en-us/articles/218506997-UniFi-Ports-Used that need to be open. Can someone confirm my firewall rules ...
by RackKing
Sat Jun 08, 2019 5:56 pm
Forum: General
Topic: L2TP idle-timeout?
Replies: 0
Views: 177

L2TP idle-timeout?

Hi,

I am trying to terminate L2TP/IPSec VPN connections after 15 mins of inactivity.

I tired using PPP/Profile/Limits/Idle Timeout to make this happen it does not seem to work.

Any advice?
by RackKing
Fri Jun 07, 2019 10:45 am
Forum: Beginner Basics
Topic: DHCP reservation in or out of Pool/Scope?
Replies: 7
Views: 521

Re: DHCP reservation in or out of Pool/Scope?

Thanks guys - that was what I was looking for.
by RackKing
Fri Jun 07, 2019 1:30 am
Forum: Beginner Basics
Topic: DHCP reservation in or out of Pool/Scope?
Replies: 7
Views: 521

Re: DHCP reservation in or out of Pool/Scope?

Any ideas?
by RackKing
Fri Jun 07, 2019 1:29 am
Forum: General
Topic: Filter or NAT rule for ports Unifi?
Replies: 2
Views: 262

Re: Filter or NAT rule for ports Unifi?

anyone?
by RackKing
Thu Jun 06, 2019 3:31 pm
Forum: General
Topic: Filter or NAT rule for ports Unifi?
Replies: 2
Views: 262

Filter or NAT rule for ports Unifi?

What is the right way to do this - There is an main on premise Unifi server/controller running at 192.168.99.10. I need to allow remote owner Unifi gear in to see the controller for normal operation. Here are the ports Unifi has identified as required. - that all makes sense. https://help.ubnt.com/h...
by RackKing
Thu Jun 06, 2019 2:54 pm
Forum: Beginner Basics
Topic: DHCP reservation in or out of Pool/Scope?
Replies: 7
Views: 521

DHCP reservation in or out of Pool/Scope?

This is more of a subjective questions, but... I want comment out some the DHCP leases the router is giving out. Most of the time this is done in conjunction with assigning a specific IP address outside of the pool/scope. I am not as concerned with what the IP address is - simply who/what the host i...
by RackKing
Thu May 23, 2019 3:01 pm
Forum: General
Topic: Mikrotik router with Windows Server DHCP Server?
Replies: 2
Views: 389

Mikrotik router with Windows Server DHCP Server?

Hi, Question - I have a Tik router connected behind a sonicwall router running a 192.168.33.1/24 network. There is a Windows server running DHCP on that network at 192.168.33.6. I want to get clients connected to my Tik to pick up and address from that HDCP server at 192.168.33.6 - ISP >> Sonicwall ...
by RackKing
Thu May 16, 2019 2:17 pm
Forum: The Dude
Topic: The Dude IS Dead, really, isn't it?
Replies: 30
Views: 5537

Re: The Dude IS Dead, really, isn't it?

An update for anyone interested. I've just spent the last few weeks testing several different NMS packages. From licensed to free. Zabbix was a close contender, Solarwinds was simply outside of our price range. We've decided on NetXMS. NetXMS has ticked serveral major boxes for us. It may of easily...
by RackKing
Mon Jan 28, 2019 10:55 pm
Forum: General
Topic: DHCP philosophy - where/what is it best served by?
Replies: 9
Views: 653

Re: DHCP philosophy - where/what is it best served by?

Not just for outlook clients, if your DNS is not good in AD setup, it will brake replication, etc. In an AD environment, use Windows for DHCP and DNS, they integrate with each other and serve a much bigger picture than just IP Addressing and Name resolution to browse the web, etc Thanks CZfan. I he...
by RackKing
Mon Jan 28, 2019 10:44 pm
Forum: General
Topic: DHCP philosophy - where/what is it best served by?
Replies: 9
Views: 653

Re: DHCP philosophy - where/what is it best served by?

I manage all aspects of a network. Routers, switches, servers, video, VoIP, and pretty much anything else that gets an IP address. If there is a real server (or servers) on the network, one or more will be handling DNS, DHCP, and pretty much any other client/server type of service. Routers are quit...
by RackKing
Mon Jan 28, 2019 3:35 pm
Forum: General
Topic: DHCP philosophy - where/what is it best served by?
Replies: 9
Views: 653

Re: DHCP philosophy - where/what is it best served by?

My view: DHCP server and DNS server are L3. If I'm in charge of L3 part of network infrastructure (i.e. address space allocation, perhaps some LAN DNS services[*]), then I'll request to deal with those services exclusively (doesn't matter if it's service running on top of some core router or dedica...
by RackKing
Mon Jan 28, 2019 2:59 pm
Forum: General
Topic: DHCP philosophy - where/what is it best served by?
Replies: 9
Views: 653

DHCP philosophy - where/what is it best served by?

Hi, This is more of a general networking questions than a Tik questions for sure. I am curious to know what others are seeing currently and what the trend it. I suspect the answer moves depending on the market we are talking about. I currently deploy Mikrotik in to a wide range of scenarios from res...
by RackKing
Thu Dec 20, 2018 2:53 am
Forum: General
Topic: Chromecast across VLANs?
Replies: 4
Views: 660

Re: Chromecast across VLANs?

Thanks for this. I am trying to get a PC to cast a chrome tab. I think the guest features only works with cast enabled apps from ios/android.

I wonder if Avahi works for this. I have never used it....
by RackKing
Wed Dec 19, 2018 4:11 pm
Forum: General
Topic: Chromecast across VLANs?
Replies: 4
Views: 660

Re: Chromecast across VLANs?

Anyone?
by RackKing
Tue Dec 18, 2018 10:42 pm
Forum: General
Topic: Chromecast across VLANs?
Replies: 4
Views: 660

Chromecast across VLANs?

How can I do this in ROS?
by RackKing
Tue Dec 11, 2018 6:06 pm
Forum: General
Topic: ISP modem reset causes MT dhcp client to get stuck at NAK
Replies: 0
Views: 257

ISP modem reset causes MT dhcp client to get stuck at NAK

This has become more of a problem recently, particularly when an ISP cable modem and Mikrotik router reset occurs due to power failure. The issue occurs when router's DHCP client makes a request prior to the modem being online and gets a private dhcp IP address from the ISP cable modem. When the lea...
by RackKing
Tue Dec 11, 2018 2:14 am
Forum: General
Topic: DHCP client script execution
Replies: 6
Views: 1344

Re: DHCP client script execution

I'll report what Wiki says: Script that will be executed after lease is assigned or de-assigned. Internal "global" variables that can be used in the script: leaseBound - set to "1" if bound, otherwise set to "0" leaseServerName - dhcp server name leaseActMAC - active mac address leaseActIP - active...
by RackKing
Mon Dec 10, 2018 10:43 pm
Forum: General
Topic: DHCP client script execution
Replies: 6
Views: 1344

Re: DHCP client script execution

I'll report what Wiki says: Script that will be executed after lease is assigned or de-assigned. Internal "global" variables that can be used in the script: leaseBound - set to "1" if bound, otherwise set to "0" leaseServerName - dhcp server name leaseActMAC - active mac address leaseActIP - active...
by RackKing
Mon Dec 10, 2018 5:50 pm
Forum: General
Topic: DHCP client script execution
Replies: 6
Views: 1344

DHCP client script execution

I see the DHCP client can execute a script. I cannot seem to make the script execute - under what circumstances should this trigger? I assumed a manual release would trigger the script. Or any change in the DHCP client status - any thoughts? Thanks.
by RackKing
Fri Dec 07, 2018 10:10 pm
Forum: General
Topic: Raw drop rule of a list... clarification needed.
Replies: 1
Views: 211

Raw drop rule of a list... clarification needed.

I have read this but want to make sure I understand correctly. If I have a "blacklist" created that is dropped bay a rule in raw - there is no need to drop it anywhere else? To put another way - anything in raw that gets dropped will never be seen by the input and forward chains in the filter? So do...
by RackKing
Fri Dec 07, 2018 5:51 pm
Forum: General
Topic: Log prefix length limit from a FW rule?
Replies: 0
Views: 224

Log prefix length limit from a FW rule?

It appears there is a limit to log prefix from a FW rule. Is there a way to increase this? They seem to get cutoff with a ":"
by RackKing
Fri Dec 07, 2018 2:42 pm
Forum: General
Topic: NAT masq rule per src-address-list or one rule for everything? [SOLVED]
Replies: 4
Views: 460

Re: NAT masq rule per src-address-list or one rule for everything? [SOLVED]

@ mkx

"Order matters only within same chain. src-nat and dst-nat are different chains."

That makes perfect sense - thank you
by RackKing
Fri Dec 07, 2018 7:42 am
Forum: General
Topic: NAT masq rule per src-address-list or one rule for everything? [SOLVED]
Replies: 4
Views: 460

Re: NAT masq rule per src-address-list or one rule for everything? [SOLVED]

I have multiple masquerade rules but they are for each WANIP in a failover setup so its pretty clear cut. All LAN users are affected. However if I want to have specific users have their private IPs translated by a specific WANIP, then using source address list in the equation OR source interface li...
by RackKing
Fri Dec 07, 2018 3:23 am
Forum: General
Topic: NAT masq rule per src-address-list or one rule for everything? [SOLVED]
Replies: 4
Views: 460

NAT masq rule per src-address-list or one rule for everything? [SOLVED]

Hi - this is probably a silly question, but... I know the default NAT masq rule is: /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" \ ipsec-policy=out,none out-interface-list=WAN Is the this single rule the defector standard? I have read/seen where this has been don...
by RackKing
Thu Dec 06, 2018 6:38 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 856

Re: Interface-list VS firewall address-list best practices and approach?

I use a mixture of both. As you mentioned, Interface List is like "Zone" based, "trusted", "untrusted", etc. but sometimes need to be more granular, then I use Address Lists, etc Thanks CZFan - the granular part makes good sense. Never thought of it like that. I am still getting my head wrapped aro...
by RackKing
Thu Dec 06, 2018 6:34 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 856

Re: Interface-list VS firewall address-list best practices and approach?

I too do similar with my setup. Interface list as an example "WANs" for my 2 WAN interfaces which is good for firewall & NAT rules and make use of address lists in multiple ways. I think of it more as interface-list for hardware interfaces and address-lists for IP related. Sometimes both will suit ...
by RackKing
Thu Dec 06, 2018 2:40 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 856

Interface-list VS firewall address-list best practices and approach?

I was thinking about how to use these more effectively and efficiently. I typically use an interface-list for WAN and MGMT but use firewall address-list for LAN segregation. Most of the time ether1 is the only interface in the WAN list so I am not sure what I am really saving. I suppose it is easier...
by RackKing
Wed Dec 05, 2018 8:16 pm
Forum: Wireless Networking
Topic: DPSK Dynamic WPA2 PSK support [SOLVED]
Replies: 6
Views: 1124

Re: DPSK Dynamic WPA2 PSK support [SOLVED]

Furthermore, you can associate a RADIUS to manage the mac-address/password association. There are few presentations that covered this topic. MikroTik was there for ages, too bad they didn't use it as a good advertisement. Do you have a link to the presentations? I assume you mean youtube, but I can...
by RackKing
Tue Dec 04, 2018 2:57 pm
Forum: General
Topic: Sonos across VLANs?
Replies: 15
Views: 4964

Re: Sonos across VLANs?

Are you saying that the smart phone and the SONOS will have to be on the same VLAN in the house?? Yes. Unless you implement either of the two solutions above (properly configured igmp-proxy or PIM) thus allowing you to connect controllers PCs, iPhone app, etc... with Sonos equipment Connects, Amps,...
by RackKing
Tue Dec 04, 2018 2:23 pm
Forum: General
Topic: Feature request for v7.x
Replies: 269
Views: 63659

Re: Feature request for v7.x

mDNS server for Chromecast/Bonjour/ZeroConfig across VLANs.

WiFi networks are too big to have all the available devices all bridged to the LAN.

Would be nice to then firewall what devices are discoverable.
m2
by RackKing
Tue Dec 04, 2018 2:05 pm
Forum: General
Topic: Sonos across VLANs?
Replies: 15
Views: 4964

Re: Sonos across VLANs?

Hi anav - Sorry for the late reply. Yes the sonos is very different and relies the controller PC or app to see broadcast/multicast traffic in order to work. Control is all local and the services come through the cloud. They can create there own hidden "sonosnet" wi-fi mesh on 2.4 which can be disast...
by RackKing
Mon Dec 03, 2018 4:28 pm
Forum: Beginner Basics
Topic: Routing between 2 Subnets
Replies: 22
Views: 3121

Re: Routing between 2 Subnets

@RackKing: Yes, My Sonos Speakers are in VLAN30 and the controllers are accross different Subnets.It works for me, but sometimes it takes some time until a controller finds the Sonos players (especially the Android widget). For updates it is recommended to join one controller to VLAN30, otherwise y...
by RackKing
Sun Dec 02, 2018 9:14 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

Re: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?

I guess the reason for things stopping with use-ip-firewall-for-vlan is that you allow DNS requests from interface list LAN, but that one doesn't contain ether ports ... and those are ports seen by firewall when used for vlan filtering.. I gave the above a shot and moved to and scr address list as ...
by RackKing
Sun Dec 02, 2018 9:00 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

Re: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?

Out of curiosity, why do you want to use firewall on traffic between hosts in vlan90 iff they communicate via routerboard? Vlan firewall doesn't add security for devices which are not in same vlan (their traffic will pass the usual IP firewall anyway) and doesn't filter anything if devices can talk...
by RackKing
Sun Dec 02, 2018 8:55 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

Re: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?

Well, when I started writing my response, your configuration export wasn't there yet, and I haven't noticed it to appear while sending my response. The dstnat chain of nat is also part of the "prerouting" path through the IP firewall, so I would suspect that the action=redirect may get confused in ...
by RackKing
Sun Dec 02, 2018 8:06 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

Re: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?

Hi sindy,

The only thing running in the raw on mangle section are the dummy Fasttrack counters. I assume those would not cause any issue?

Anything else I should check?

Thanks.
by RackKing
Sun Dec 02, 2018 7:20 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

Re: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?

Hi sindy - thanks for taking the time to help. Well yes - to put it a different way. The firewall works as I desire, but when I added the NAT redirect rule the clients stop getting DNS resolution from the router. This is with the use-ip-firewall and use-ip-firewall-for-vlan enabled on the bridge. Th...
by RackKing
Sun Dec 02, 2018 5:05 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

Re: DNS stops working with Bridge use IP Firewall & IP VLAN?

Thank you all for your replies. I have narrowed it down some, but must admit I am not sure why it is failing to work. I have a NAT redirect rule for DNS. That is the rule the stops the DNS from resolving with IP firewall and VLAN use turned on. When they are disabled DNS works fine. In torch - the m...
by RackKing
Sat Dec 01, 2018 9:56 pm
Forum: Beginner Basics
Topic: Routing between 2 Subnets
Replies: 22
Views: 3121

Re: Routing between 2 Subnets

@Spartacus I was thinking about your FW - nice. I have some questions to pile on :-). Sonos - do those rules allow another user on one subnet to control and connect via the Sonos ap to the hardware on a different subnet? Seems like a good idea to keep the "noisy" sonos equipment on its own. It looks...
by RackKing
Fri Nov 30, 2018 11:48 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

Re: DSN stops working with use IP Firewall & IP VLAN?

Thank you for your reply. The system is working with this unchecked. I have an input rules working that allows in UDP, TCP requests from the lan port 53 while blocking WAN requests. Name resolution is working properly. When I turn on Bridge / use IP firewall /use VLAN that rule stops running. There ...
by RackKing
Fri Nov 30, 2018 9:59 pm
Forum: General
Topic: DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?
Replies: 13
Views: 1077

DNS stops working with Bridge use IP Firewall & IP VLAN with NAT redirect?

Hi, I have some VLANs running on one main bridge. Everything is working with use IP Firewall turned off, but when I turn it on DNS resolution stops working. I have the appropriate DNS rules to allow input to router from these networks specified with address lists. Vlan filtering is used on the bridg...
by RackKing
Thu Nov 29, 2018 10:44 pm
Forum: General
Topic: Firewall Questions
Replies: 8
Views: 901

Re: Firewall Questions

Good stuff - great read!
by RackKing
Wed Nov 28, 2018 5:45 am
Forum: RouterBOARD hardware
Topic: hAP ac2 slides in the case?
Replies: 1
Views: 442

Re: hAP ac2 slides in the case?

So - I took the case apart and indeed the board was not seated into the slots at the back of the case properly. It also explains why the LEDs were not very bright as well. I gently pried up in the bottom slot by the power input with a thin screwdriver and the front retaining bracket came off. I have...
by RackKing
Wed Nov 28, 2018 5:23 am
Forum: RouterBOARD hardware
Topic: hAP ac2 slides in the case?
Replies: 1
Views: 442

hAP ac2 slides in the case?

I have gotten a couple of these - the board slides about 1/4" with the case front to back. Anybody else see this? So when you plug an cable in the board slides backward and hits the back of the case I presume. Pull the cable and the whole things slides forward and stops. Perhaps I can open the case ...
by RackKing
Sat Nov 24, 2018 2:17 pm
Forum: General
Topic: Logging email action adding firewall prefix to logs that don't have them?
Replies: 1
Views: 216

Logging email action adding firewall prefix to logs that don't have them?

Hi, I have a logging rule designed to send an email if the firewall action log contains a prefix "must match" for example. The firewall rule works correctly and adds the prefix to the log like "must match input: xxxxxx...." The problem is the logging rule seems to attach that prefix to other rules i...
by RackKing
Thu Nov 22, 2018 3:43 pm
Forum: General
Topic: Why blacklist burteforcers VS just dropping the ports/service?
Replies: 7
Views: 625

Re: Why blacklist burteforcers VS just dropping the ports/service?

Pre-empting the worst is probably the best summary.
If they're poking at certain ports when they shouldn't then you probably don't want them poking at anything.
This makes a great deal of sense to me - thanks.

Good discussion - thanks to all who responded.
by RackKing
Wed Nov 21, 2018 4:17 pm
Forum: General
Topic: Why blacklist burteforcers VS just dropping the ports/service?
Replies: 7
Views: 625

Why blacklist burteforcers VS just dropping the ports/service?

If you have drop rules that simply drop packets to ports/services you do not use like ssh, ftp, telnet, winbox, etc... what is the advantage to creating a timed black list and dropping that? Is it to gain the logs and perform further action? If you have the IP/Services turned for all those is there ...
by RackKing
Wed Nov 21, 2018 7:11 am
Forum: General
Topic: Block MNDP with IP Neighbors running? [SOLVED]
Replies: 2
Views: 536

Re: Block MNDP with IP Neighbors running? [SOLVED]

Despite the fact MNDP is located in /ip neighbor menu, it should be considered as L2 protocol because both dst-MAC and dst-IP are broadcasts. Due to that, /ip firewall (both filter and raw) see the packets but can't drop them. (personally I consider that as bug - either it should count matched pack...
by RackKing
Wed Nov 21, 2018 5:09 am
Forum: General
Topic: Block MNDP with IP Neighbors running? [SOLVED]
Replies: 2
Views: 536

Block MNDP with IP Neighbors running? [SOLVED]

Hi, I am trying to allow only admin computers that are on a "Winbox_Admin" firewall address list to see the neighbor discovery results from winbox connections to MNDP UDP on port 5678. I want to leave Neighbors Discover settings on my management interface running but block the "results" to admin IPs...
by RackKing
Sat Nov 17, 2018 11:50 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

Hi,

I have been blocking all udp 5678 packets input and forward chains with no luck. Anyone have some help - please?

Thanks
by RackKing
Fri Nov 16, 2018 4:34 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

Anybody else have a thought on this?
by RackKing
Thu Nov 15, 2018 7:16 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

is chain=input right? input is for traffic going to router itself. chain=forward maybe? Hi and thanks for your response. I have a rule for both chains now - the only one that ever generates any traffic is the input rule. The remote winbox pc is sending the MNDP broadcast to the input of the router ...
by RackKing
Thu Nov 15, 2018 5:53 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

So I made this firewall filter rule and drug it to the top.

chain=input action=drop protocol=udp dst-address=255.255.255.255 dst-port=5678 log=no
log-prefix=""

I still see the connection from the host winbox IP:5678.

Am I missing something?
by RackKing
Thu Nov 15, 2018 4:05 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

Just filter out UDP broadcast packets with destination 255.255.255.255 & port 5678 on the devices you don't want taking part in MNDP.
@icsterm Thank you very much. I will give it a shot!
by RackKing
Wed Nov 14, 2018 12:03 am
Forum: General
Topic: Sonos across VLANs?
Replies: 15
Views: 4964

Re: Sonos across VLANs?

Thank you for.posting this - could you expand a little bit? a sample config would help me get my head wrapped around it. Turning on igmp proxy on the interfaces but I have never use the other features.

Thanks for any help.
by RackKing
Tue Nov 13, 2018 6:33 am
Forum: General
Topic: Netinstall sending offer, but not installing [SOLVED]
Replies: 6
Views: 3123

Re: Netinstall sending offer, but not installing [SOLVED]

So.... thank you everyone for this thread and specifically to @Retral and @pukkita. I worked on this for a couple of hours.... it was maddening. I tried 3 different branded laptops win7 - 10 not luck until I found this thread. I think this thread should get referenced in the Wiki. FYI - I could get ...
by RackKing
Mon Nov 12, 2018 12:05 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

@docmarius That was my understanding thanks for the clarification. Discovery is a nice feature to make some things more convenient but I understand the reason for turning it off. I was contemplating leaving it running on my management interface. My concern is that if somebody gains access to an inte...
by RackKing
Sun Nov 11, 2018 3:45 am
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

If there is a way to limit the discovery from only showing up on specific interfaces let me know. "With a list you can activate a single interface" I am not talking about limiting what port it "discovers on" I want it to only report what it discovers to a single physical interface. Thank you for any...
by RackKing
Fri Nov 09, 2018 6:14 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

Re: IP Neighbor Discovery

As in the firewall address list?
by RackKing
Fri Nov 09, 2018 4:22 pm
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 823

Re: Management Network for router access?

@R1CH - do you leave Neighbors Discover on for your management VLAN?
by RackKing
Fri Nov 09, 2018 4:18 pm
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 823

Re: Management Network for router access?

On one of my bigger networks I have a dedicated management VLAN. RouterOS is firewalled on every interface except this VLAN, so it only performs routing. I have a Linux box on the management network running wireguard that allows me to remote in, I trust wireguard far more than any of the RouterOS V...
by RackKing
Fri Nov 09, 2018 4:12 pm
Forum: General
Topic: IP Neighbor Discovery
Replies: 12
Views: 2254

IP Neighbor Discovery

I understand the Neighbor Discovery Settings can only run on and interface list. So you can create a list <LAN> and Add and interface to it like <LAN-VLAN>. It will then discover devices that VLAN and advertise them to Winbox correct? Can you have the "advertised to only a single interface? My manag...
by RackKing
Fri Nov 09, 2018 3:47 pm
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 823

Re: Management Network for router access?

It's a great idea to have a management network if your end devices can be separated like that. Once you are in a SOHO/SMB environment then this becomes almost standard to have multiple LANs (/vlans). The trick is ensuring nobody simply plugs in to your MGMT network to access the devices. Ensuring y...
by RackKing
Thu Nov 08, 2018 3:18 pm
Forum: General
Topic: Ip Servcie/ Winbox/Available From VS Firewall
Replies: 0
Views: 258

Ip Servcie/ Winbox/Available From VS Firewall

How does the IP/Service/Winbox - "Available From" differ from an input rule with address-list in the firewall? Does one have priority over the other?
by RackKing
Thu Nov 08, 2018 4:42 am
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 823

Re: Management Network for router access?

Thank you both for your replies.
by RackKing
Thu Nov 08, 2018 4:07 am
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 823

Re: Management Network for router access?

I would really appreciate any feedback.
by RackKing
Wed Nov 07, 2018 3:39 pm
Forum: The Dude
Topic: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?
Replies: 6
Views: 1206

Re: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?

I don't think they overlap and I would implement Dude, Splunk and, in place of Cacti, Zabbix. Dude for management and very basic monitoring but it can do more. Splunk (I am using it's alternative Graylog) for log collecting, log analyzing and alerting. Zabbix for monitoring, graphing and alerting. ...
by RackKing
Wed Nov 07, 2018 2:14 pm
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 823

Management Network for router access?

This is a SOHO/SMB focused question for the most part. I typically create a management network for devices like managed switches, APs, Power Devices, and other various widgets that are directly related to core network operations. I let them pull DCHP and then set a reservation out of the DHCP scope....
by RackKing
Wed Nov 07, 2018 2:45 am
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 70615

Re: RB4011

Just got my wired 4011 up in the lab.... I will play with it over the next week. Physically a solid device - but what I don't like > - miss the beep (dumb I know) - miss the LCD as it had customer curb appeal even though it was rarely used.... - think it should have USB - storage and WAN - I really ...
by RackKing
Tue Nov 06, 2018 8:02 pm
Forum: The Dude
Topic: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?
Replies: 6
Views: 1206

Re: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?

For monitoring stuff I do recommend Splunk as I have posted here: https://forum.mikrotik.com/viewtopic.php?t=137338 There are other nice program like NEDI that can be used to keep track of all your devices. Thanks for your reply! Do you use The Dude? I am thinking about using Splunk as well but it ...
by RackKing
Tue Nov 06, 2018 7:32 pm
Forum: General
Topic: HW Switch vs Bridge VLANs..... the future?
Replies: 8
Views: 974

Re: HW Switch vs Bridge VLANs..... the future?

Here is a post where I am struggling to understand the VLAN :) https://forum.mikrotik.com/viewtopic.php?t=138232 I have read that thread about 10 times... it is good stuff. I am amazed at your visualizations and drawings - Visio? I could only dream of doing something that well laid out - great work.
by RackKing
Tue Nov 06, 2018 6:39 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 191
Views: 25205

Re: Blacklist Filter (Development Topic)

So maybe a dumb question... I did have a look a the Patreon page. What level would you recommend to an integrator like who would offer this to his customers as part of a annual service offering? I would bill them directly and purchase your service. I suppose I could buy a tier and then upgrade as I ...
by RackKing
Tue Nov 06, 2018 3:54 pm
Forum: General
Topic: HW Switch vs Bridge VLANs..... the future?
Replies: 8
Views: 974

Re: HW Switch vs Bridge VLANs..... the future?

@Jotne thanks very much for your reply. I have not been brave enough to try and combine these approaches yet, but I can see where you can get the best of both worlds by doing so. I guess there is "no one bridge to rule them all"... :-) (sorry). it is curious that newer hardware does not have the swi...
by RackKing
Tue Nov 06, 2018 3:45 pm
Forum: The Dude
Topic: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?
Replies: 6
Views: 1206

Re: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?

Thank you for the reply. So much for a single pain of glass :-)
by RackKing
Tue Nov 06, 2018 4:44 am
Forum: General
Topic: Whitelist VS blacklist , CPU hit, throughput, etc... thoughts?
Replies: 3
Views: 325

Re: Whitelist VS blacklist , CPU hit, throughput, etc... thoughts?

Due to that, you can't consider blacklist as alternative to whitelists (which are useful only for incoming connections). It has different purpose and even with thousands of blocked IP's blacklist will not have significant impact on your CPU.
This was very helpful - and perhaps the end game.
by RackKing
Tue Nov 06, 2018 4:41 am
Forum: General
Topic: Whitelist VS blacklist , CPU hit, throughput, etc... thoughts?
Replies: 3
Views: 325

Re: Whitelist VS blacklist , CPU hit, throughput, etc... thoughts?

@vecernik87

Thank you very much for your thoughtful response. That helps me very much.
by RackKing
Tue Nov 06, 2018 2:46 am
Forum: The Dude
Topic: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?
Replies: 6
Views: 1206

Re: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?

Anyone? I was hoping @jotne would chime in as he is the splunk guy and spread some light on this topic.
by RackKing
Tue Nov 06, 2018 2:34 am
Forum: General
Topic: Whitelist VS blacklist , CPU hit, throughput, etc... thoughts?
Replies: 3
Views: 325

Whitelist VS blacklist , CPU hit, throughput, etc... thoughts?

Hi, I have been reading a great deal about all the various exploits going around and thinking about how to protect my networks better. I also have read about the interesting blacklist update projects that are being developed. One comment got me thinking about whitelisting vs blacklisting - the spiri...
by RackKing
Mon Nov 05, 2018 7:17 pm
Forum: RouterBOARD hardware
Topic: hap ac2 in a StationBox - Anyone? [SOLVED]
Replies: 2
Views: 579

Re: hap ac2 in a StationBox - Anyone? [SOLVED]

um - I feel silly.... That is the ticket.
by RackKing
Mon Nov 05, 2018 6:48 pm
Forum: RouterBOARD hardware
Topic: hap ac2 in a StationBox - Anyone? [SOLVED]
Replies: 2
Views: 579

hap ac2 in a StationBox - Anyone? [SOLVED]

Any feedback or pictures? Or another solution if you wanted to ceiling mount this. Thanks in advance.
by RackKing
Mon Nov 05, 2018 2:44 pm
Forum: The Dude
Topic: The Dude, Cacti, Splunk, NMS - where do the fit/overlap?
Replies: 6
Views: 1206

The Dude, Cacti, Splunk, NMS - where do the fit/overlap?

I am just trying to get his sorted in my mind. I am curious to know how these fit together, or don't. What is the typical use case, or better put how do yo use them. I primarily serve the SMB market. I am not a WISP, although I do a fair amount of PTP and PTMP installations :-). I am to the point wh...
by RackKing
Fri Nov 02, 2018 4:25 am
Forum: General
Topic: HW Switch vs Bridge VLANs..... the future?
Replies: 8
Views: 974

Re: HW Switch vs Bridge VLANs..... the future?

it does even appear on the new RB4011 device. We need a standard layer to work with VLAN and let it sort itself out automatically. Thanks for the response.... wow I had no idea the new 4011 did not allow access to the switch chip config. Poor assumption on my part - thanks for setting me straight. ...
by RackKing
Fri Nov 02, 2018 3:55 am
Forum: General
Topic: HW Switch vs Bridge VLANs..... the future?
Replies: 8
Views: 974

HW Switch vs Bridge VLANs..... the future?

I have spent countless hours reading posts form @sindy, @CZFan, @mkx, @efaden, @ dasiu, @Jonte, and many others who gratefully contributed to this topic on these forums. I cannot express how thankful I am for all your posts on this often confusing and complex topic. Sharing your knowledge and patien...
by RackKing
Wed Oct 31, 2018 1:35 pm
Forum: General
Topic: 6.41 to 6.43 ping across vlan stopped working.
Replies: 0
Views: 282

6.41 to 6.43 ping across vlan stopped working.

Same firewall rules - any idea where to start looking? The gateway for each vlan is responding to ping but the hosts are not.
by RackKing
Mon Oct 29, 2018 5:01 pm
Forum: General
Topic: Advanced IP scanners locks up winbox access?
Replies: 7
Views: 657

Re: Advanced IP scanners locks up winbox access?

Right - no radius here. I have 3.18.

I still have the issue. I am going to do some more testing today,,,
by RackKing
Tue Oct 23, 2018 2:48 pm
Forum: General
Topic: Advanced IP scanners locks up winbox access?
Replies: 7
Views: 657

Re: Advanced IP scanners locks up winbox access?

That is what happens to me as well.

Anyone?
by RackKing
Mon Oct 22, 2018 2:10 pm
Forum: General
Topic: Advanced IP scanners locks up winbox access?
Replies: 7
Views: 657

Advanced IP scanners locks up winbox access?

Hi, I have used Advanced IP scanner for a long time with no issues. I use it to scan the network from a connected PC to get info on devices, IP, etc... it is easy and I like the export function. I know a similar scan can be done in winbox, but not as convenient from a test client without winbox.... ...
by RackKing
Wed Jun 13, 2018 5:03 am
Forum: General
Topic: VLAN, Trunk and access port help requested with 6.41 changes
Replies: 10
Views: 1616

Re: VLAN, Trunk and access port help requested with 6.41 changes

do it the old way... RB3011 connections ether1 - WAN ether2 - Trunk 1 (V100, V200, V300) ether3 - Trunk 2 (V100, V200, V300) ether4 - access port vlan 100 ether5 - access port vlan 200 1. make a bridge. br1 2. add ether2 and 3 to the bridge. 3 make vlan 100 and 200 as port to the bridge. vlan100_br...
by RackKing
Wed Jun 13, 2018 5:02 am
Forum: General
Topic: VLAN, Trunk and access port help requested with 6.41 changes
Replies: 10
Views: 1616

Re: VLAN, Trunk and access port help requested with 6.41 changes

Not sure I understand your last sentence. I am trying have VLAN 100 and 200 present (egress?) on ether2 to and 3 to pass tagged to a downstream switch. The Tags simply aren't there. I can confirm this with a test downstream switch and a Netool.io scan device. When I use your option 1 from the first...
by RackKing
Sat Jun 09, 2018 12:33 am
Forum: General
Topic: VLAN, Trunk and access port help requested with 6.41 changes
Replies: 10
Views: 1616

Re: VLAN, Trunk and access port help requested with 6.41 changes

The only mistake I can spot is that under /interface bridge port , you haven't set the pvid for the access ports ether4 and ether5 . So you have to add the pvid parameter to these lines in accord with the rules under /interface bridge vlan : /interface bridge port set [find interface=ether4] pvid=1...
by RackKing
Fri Jun 08, 2018 11:21 pm
Forum: General
Topic: VLAN, Trunk and access port help requested with 6.41 changes
Replies: 10
Views: 1616

Re: VLAN, Trunk and access port help requested with 6.41 changes

here is the config - note the default was left to keep it simple so I could connect. # jun/08/2018 15:16:55 by RouterOS 6.42.3 # software id = # # model = 2011UiAS /interface bridge add admin-mac=64:D1:54:1E:B4:AE auto-mac=no comment=defconf name=bridge add fast-forward=no name=my-bridge vlan-filter...
by RackKing
Fri Jun 08, 2018 11:07 pm
Forum: General
Topic: VLAN, Trunk and access port help requested with 6.41 changes
Replies: 10
Views: 1616

Re: VLAN, Trunk and access port help requested with 6.41 changes

Thanks for responding. I will have to build it from your option 2 and will post back.
by RackKing
Fri Jun 08, 2018 9:26 pm
Forum: General
Topic: VLAN, Trunk and access port help requested with 6.41 changes
Replies: 10
Views: 1616

VLAN, Trunk and access port help requested with 6.41 changes

Hi, First I would like to say thank you to the following members in no particular order: @sindy @CZFan and @acrul. I have read through your man post and a grateful for what I have gleaned. But - I have been really struggling this week trying to get this sorted. I am hoping someone can set me straigh...
by RackKing
Sun Jun 03, 2018 4:50 pm
Forum: General
Topic: VLANs no switch chip
Replies: 10
Views: 1181

Re: VLANs no switch chip

Thanks, so it appears I'm on the right track then, other than not doing the firewall rules yet. I'll do a few more tweaks and then put this in as active. Just wanted to make sure with the newer changes in 6.4x that I didn't need to reconfigure how I was doing things previously for any reason. Just ...
by RackKing
Sat Jun 02, 2018 4:04 pm
Forum: General
Topic: Create multiple trunk ports?
Replies: 3
Views: 1388

Re: Create multiple trunk ports?

Hi, Thanks so much for your reply and sorry to not be very clear. The "piece of cake" I was referring to was creating multiple trunk ports prior to 6.4.1 (I think thats right) when the master port designation was still being used. If my trunk port was configured on ether-2-master for example, I coul...
by RackKing
Thu May 31, 2018 10:20 pm
Forum: General
Topic: Create multiple trunk ports?
Replies: 3
Views: 1388

Create multiple trunk ports?

I have ether 2 setup as a trunk port with several VLANs running on it. IP addresses, DHCP, etc.. are defined on those VLANs. So - in previous versions of ROS you could just select the master port (eth2) and boom you would have another trunk to carry to another switch or whatever. How is this accompl...
by RackKing
Sun Feb 11, 2018 3:15 am
Forum: General
Topic: DMZ firewall setup rule help
Replies: 4
Views: 555

Re: DMZ firewall setup rule help

anyone?
by RackKing
Fri Feb 09, 2018 3:10 pm
Forum: General
Topic: DMZ firewall setup rule help
Replies: 4
Views: 555

DMZ firewall setup rule help

Hi, I have a dev router behind a main production router. I would like the dev router to be in the DMZ for testing purposes. I have the an ether7 setup as the DMZ interface on my 2011 production router with a separate network setup for it. I have a DHCP server running on ether7 it to test DHCP client...
by RackKing
Wed Feb 07, 2018 5:11 pm
Forum: General
Topic: discovery = "no" in 6.41.1 - how?
Replies: 5
Views: 904

Re: discovery = "no" in 6.41.1 - how?

Thanks all
by RackKing
Tue Feb 06, 2018 11:13 pm
Forum: General
Topic: discovery = "no" in 6.41.1 - how?
Replies: 5
Views: 904

Re: discovery = "no" in 6.41.1 - how?

Thanks for your reply - I still get "discover-interface-list: !dynamic"

It should say none, after that command right?
by RackKing
Tue Feb 06, 2018 10:49 pm
Forum: General
Topic: discovery = "no" in 6.41.1 - how?
Replies: 5
Views: 904

discovery = "no" in 6.41.1 - how?

I am somewhat confused as how to use the new list feature. We had our interfaces and vlans set to discovery = no. How do I achieve that with the new ROS version 6.41.1.

thanks in advance
by RackKing
Sat Feb 03, 2018 6:53 pm
Forum: General
Topic: Winbox access from different subnet?
Replies: 4
Views: 478

Re: Winbox access from different subnet?

yes - can you provide some basics of the filter rules?
by RackKing
Sat Feb 03, 2018 3:50 pm
Forum: General
Topic: Winbox access from different subnet?
Replies: 4
Views: 478

Re: Winbox access from different subnet?

The basics are that the router is on the management network (for example) 192.168.1.x and the PC I am trying to access it via winbox is one 192.168.2.X. The firewall is setup to isolate the two networks. The networks are setup on different interfaces with DHCP, DNS, all the normal stuff.
by RackKing
Sat Feb 03, 2018 2:30 pm
Forum: General
Topic: Winbox access from different subnet?
Replies: 4
Views: 478

Winbox access from different subnet?

This should be trivial... but need some help. I have a router on a management network and would like to access it from a specific workstation on a user network. I thought a simple forward rule from the workstation to the router would work, but no. Do I need an input rule from the IP to the TCP port ...
by RackKing
Thu Feb 01, 2018 8:06 pm
Forum: General
Topic: Log help.... 2 Unifi devices crushing port 5050?
Replies: 2
Views: 291

Re: Log help.... 2 Unifi devices crushing port 5050?

I rebooted the Unit and the problem stopped. - solved
by RackKing
Thu Feb 01, 2018 7:55 pm
Forum: General
Topic: Log help.... 2 Unifi devices crushing port 5050?
Replies: 2
Views: 291

Re: Log help.... 2 Unifi devices crushing port 5050?

I turned off SSH and same result.

I noticed discovery and CDP are both enabled. Could these be an issue?
by RackKing
Thu Feb 01, 2018 6:06 pm
Forum: General
Topic: Log help.... 2 Unifi devices crushing port 5050?
Replies: 2
Views: 291

Log help.... 2 Unifi devices crushing port 5050?

I am at a loss on this - not my install on the Unifi equipment and have never seen this before. I am hoping somebody can tell me what this traffic is and how to stop it? Thanks in advance. I have a feeling this is a "Oh duh, I should have known that" type of answer..... 10:04:36 firewall,info Input ...
by RackKing
Thu Mar 23, 2017 3:30 pm
Forum: General
Topic: ROS 6.38 serious DHCP server problem
Replies: 91
Views: 29812

Re: ROS 6.38 serious DHCP server problem

I am now having the same issue after an upgrade - any update?
by RackKing
Wed Sep 21, 2016 5:29 pm
Forum: RouterBOARD hardware
Topic: Update to CRS125-24G-1S-RM anytime soon?
Replies: 6
Views: 974

Re: Update to CRS125-24G-1S-RM anytime soon?

What do you mean by that? In such case it would not be an update but fully different product. Anyway remember the difference between a switch and a router... Hi Jarda - thanks for commenting. In smaller projects I do set these up as a router as well to do basic DHCP, NAT and basic firewall. Perhaps...
by RackKing
Tue Sep 20, 2016 3:44 pm
Forum: RouterBOARD hardware
Topic: Update to CRS125-24G-1S-RM anytime soon?
Replies: 6
Views: 974

Update to CRS125-24G-1S-RM anytime soon?

Hi - wondering if this product will be updated at any time or if it is in the works already I am out of the loop. An ARM aka 3011 version of this would be killer, or even a processor on par with the HEX.

Thanks in advance for any feedback.
by RackKing
Sat Sep 17, 2016 2:33 pm
Forum: General
Topic: VLANs on 750G2 with no bridge help sought
Replies: 3
Views: 516

Re: VLANs on 750G2 with no bridge help sought

Thank you for your reply - but I am not sure I understand. Some questions. 1. If use the management IP as described in the last step, does that mean the only way I will be able to access the router will be on port 2? I will have to provide my PC a static IP in the 192.168.88.1/24 network? 2. DHCP - ...
by RackKing
Fri Sep 16, 2016 5:46 pm
Forum: General
Topic: VLANs on 750G2 with no bridge help sought
Replies: 3
Views: 516

VLANs on 750G2 with no bridge help sought

I am struggling to make this work and wonder if someone can provide some assistance. He is some setup info with RB750: ether 1 = WAN ether 2 = master port - VLAN 10,20,30,40 connect to managed switch ether 3 = Master port 2 ether 4 = Master port 2 ether 5 = Master port 2 All of the VLANs are configu...
by RackKing
Thu May 12, 2016 10:26 pm
Forum: Beginner Basics
Topic: simple firewall question - allow limited ping.
Replies: 8
Views: 1302

Re: simple firewall question - allow limited ping.

I suspect that you have an allow state=established,related rule that comes before your "allow ICMP" rule - so once one ping gets through, all of them will as long as connection tracking considers the connection "active" If your allow ICMP rule has a rate limit, then as long as the threshold isn't c...
by RackKing
Thu May 12, 2016 10:00 pm
Forum: Beginner Basics
Topic: simple firewall question - allow limited ping.
Replies: 8
Views: 1302

Re: simple firewall question - allow limited ping.

A reasonably-sized botnet can scan the entire IPv4 space in pretty short time, so they're not going to waste time trying to ping and then scan - they're just going to scan. I bet that by now they've gotten clever enough to shuffle the target hosts/ports among their entire botnet and slow it down to...
by RackKing
Thu May 12, 2016 3:50 pm
Forum: Beginner Basics
Topic: simple firewall question - allow limited ping.
Replies: 8
Views: 1302

simple firewall question - allow limited ping.

Hi, So I am using the basic two line "allow limited ping" filter rules outlined in the Wiki and other places. The rule works and begins to hit the drop rule when the threshold is met. here for example: http://wiki.mikrotik.com/wiki/Securing_your_router My question is - what should the "pinger" or ge...
by RackKing
Thu May 12, 2016 3:40 pm
Forum: General
Topic: Verizon UML 295 support
Replies: 31
Views: 5218

Re: Verizon UML 295 support

I just got my Pantech UML 295 and followed these directions and was not able to even see the LTE under interfaces but I can see it under resources under system > resources > USB Any recommendations on what I can try? Yes. Install the modem in a Windows machine, with the Verizon software. Use that s...
by RackKing
Sat Apr 30, 2016 3:53 pm
Forum: General
Topic: RB3011 VLAN help - do I need a bridge?
Replies: 5
Views: 1297

Re: RB3011 VLAN help - do I need a bridge?

Yes in that case you can do it with the switch:

/interface ethernet switch port
set 5 default-vlan-id=172 vlan-header=always-strip vlan-mode=secure

This will make port 5 an untagged member of vlan 172.

Thanks so much - I will give this a shot!
by RackKing
Fri Apr 29, 2016 11:40 pm
Forum: General
Topic: RB3011 VLAN help - do I need a bridge?
Replies: 5
Views: 1297

Re: RB3011 VLAN help - do I need a bridge?

So I want Ether5 to be a member of a VLAN currently on Ether2 - and pull from that DHCP, DNS, etc...
by RackKing
Fri Apr 29, 2016 11:32 pm
Forum: General
Topic: RB3011 VLAN help - do I need a bridge?
Replies: 5
Views: 1297

Re: RB3011 VLAN help - do I need a bridge?

thanks for the reply - but do I do it /switch settings?
by RackKing
Fri Apr 29, 2016 10:16 pm
Forum: General
Topic: RB3011 reset button.... how to make it work?
Replies: 5
Views: 2753

Re: RB3011 reset button.... how to make it work?

Thank you this was helpful and allowed me back in.
Which one of the two hints?

console cable - I could never get the reset button to function.
by RackKing
Fri Apr 29, 2016 9:45 pm
Forum: General
Topic: RB3011 VLAN help - do I need a bridge?
Replies: 5
Views: 1297

RB3011 VLAN help - do I need a bridge?

Hi,
I have trunk port on ether2 with several VLANs, address, DHPC, etc... this all works will connected to a manged switch.

I would like to make ether9 on the RB3011 part of an existing VLAN (172). Can I do this in the switch settings or do I need to create a bridge?

Thanks in advance.
by RackKing
Fri Apr 29, 2016 9:38 pm
Forum: General
Topic: RB3011 reset button.... how to make it work?
Replies: 5
Views: 2753

Re: RB3011 reset button.... how to make it work?

No idea about the reset problem (except: note that the first blinks do not count, first wait 5 seconds THEN wait for it to blink). However, when you only locked yourself out due to the firewall or IP config problem, note that you can still access it via the RS232 port. Use a "Cisco blue cable" or s...
by RackKing
Fri Apr 29, 2016 5:42 am
Forum: General
Topic: Netinstall help...please
Replies: 0
Views: 331

Netinstall help...please

I have a 3011 I am trying to recover. I have followed the instructions on the Wiki closely. I have the console cable and ethernet cabled attached to port 1, etc.... I have selected etherboot in the serial console and all is good. I can see the routerboard 3011 in the list as "ready". I am using 6.35...
by RackKing
Fri Apr 29, 2016 3:07 am
Forum: General
Topic: RB3011 reset button.... how to make it work?
Replies: 5
Views: 2753

RB3011 reset button.... how to make it work?

So - I bricked the config on the 3011 and cannot reconnect. I have tried the reset button several times but must be doing something wrong. I apply power while holding the reset button and wait for the top LED next to the USB port to blink then let go - no work. I can get it to go to ether boot every...
by RackKing
Thu Apr 28, 2016 8:41 pm
Forum: RouterBOARD hardware
Topic: Reset RB3011 - button no work?
Replies: 0
Views: 1309

Reset RB3011 - button no work?

Trying to use the reset button on the back of the RB3011 to reload the default config. I have pressed and held .... and prayed. I cannot get it to reset.

Any advice?
by RackKing
Mon Apr 25, 2016 4:42 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

@RackKing - thank you so much!! I was going mad with the EdgeSwitch. My Problem was that the Trunk Port from my CRS was simply not working at all. I couldn't even manage to connect to the Edgeswitch itself through the Trunk Port. Disabling STP on the Edgeswitch solved the Problem. The Trunk Port us...
by RackKing
Tue Mar 01, 2016 5:08 pm
Forum: RouterBOARD hardware
Topic: RB2011/3011 replacement power supply source?
Replies: 2
Views: 1438

RB2011/3011 replacement power supply source?

We are looking to find replacement power supplies for the DC24V 1.2 amp units that come in the box. We have had a few fail and want to keep some on hand. The model number is FLD301-240120-U for the 2011 I just checked but I am sure they chance. The form factor is perfect for us - so I am looking for...
by RackKing
Wed Feb 17, 2016 10:06 pm
Forum: General
Topic: Block or Allow MAC address on interface?
Replies: 6
Views: 1348

Re: Block or Allow MAC address on interface?

RB2011 with the default local bridge. I am trying to filter ether3 to allow only a specific MAC address to connect. When I run the rule on the bridge it works but obviously block all other traffic. Ether3 is slaved to ether2 as well. I want it on the same network DHCP server as ether2 but want to re...
by RackKing
Wed Feb 17, 2016 7:06 pm
Forum: General
Topic: Block or Allow MAC address on interface?
Replies: 6
Views: 1348

Re: Block or Allow MAC address on interface?

it appears there is no way to do this by interface with a bridge involved
by RackKing
Wed Feb 17, 2016 6:20 pm
Forum: General
Topic: Block or Allow MAC address on interface?
Replies: 6
Views: 1348

Re: Block or Allow MAC address on interface?

This is also a 2011 with a bridge - so I will add that and try
by RackKing
Wed Feb 17, 2016 6:09 pm
Forum: General
Topic: Block or Allow MAC address on interface?
Replies: 6
Views: 1348

Re: Block or Allow MAC address on interface?

Thanks Jarda - I went to bridge / settings and ticked the "use IP Firewall box" on and off with same result. I assume this should be off as it was by default?

Is there a different way to turn the bridged firewall on?
by RackKing
Wed Feb 17, 2016 5:27 pm
Forum: General
Topic: Block or Allow MAC address on interface?
Replies: 6
Views: 1348

Block or Allow MAC address on interface?

This should be an easy one - but I cannot seem to get it to work. I was trying bridge filter > forward in/out interface action drop. This does not seem to work.

Any help.
by RackKing
Sat Dec 12, 2015 3:49 pm
Forum: General
Topic: Dynamic i.e. automatically use address list by VLAN on one network with two DHCP servers?
Replies: 2
Views: 382

Dynamic i.e. automatically use address list by VLAN on one network with two DHCP servers?

That title probably makes little sense.... but here goes I am trying to get clients that connect to a WLAN with a VLAN tag (from Unifi) to pull from an address pool/list this that is forced to use OpenDNS - while being on the same network with an additional HDCP server for "normal" clients that use ...
by RackKing
Thu Dec 10, 2015 5:33 am
Forum: General
Topic: Family network OpenDNS strategy - any ideas?
Replies: 2
Views: 426

Family network OpenDNS strategy - any ideas?

Hi, I have setup some address lists - regular vs family. I have setup rules rules to send family to open dns and regular to google. The issue is I have to manually add "family" users. This is a PITA. I have also setup some a Family wirelss vlan that uses OpenDNS - but the VLAN prohibits other things...
by RackKing
Tue Dec 08, 2015 8:57 pm
Forum: The Dude
Topic: The Dude is back! v6.34rc test build released
Replies: 269
Views: 74329

Re: The Dude is back! v6.34rc test build released

@ krisjanis

Thanks for your reply - now I understand. Is a server package for the RB3011 in the works?

Sorry if this has been covered.
by RackKing
Tue Dec 08, 2015 7:26 pm
Forum: The Dude
Topic: The Dude is back! v6.34rc test build released
Replies: 269
Views: 74329

Re: The Dude is back! v6.34rc test build released

Probably a dumb question - but you are discussing this running on arm - you are talking about the client right? Not the router, i.e. so the dude package will run on the rb3011 right? I am, obviously, new to The Dude. Does anyone recommend a "newbie" guide or getting started post? I will begin here a...
by RackKing
Mon Dec 07, 2015 2:28 pm
Forum: Beginner Basics
Topic: Run Winbox on a Raspberry Pi?
Replies: 21
Views: 8051

Re: Run Winbox on a Raspberry Pi?

Can you detail this statement a little? AFAIK, RP is ARM based and does not support wine... Is there a native linux or a java version available? My mistake then. But the question is not for us, but for Wine developers. MikroTik has never made Winbox for Linux, we do have Webfig that works on all pl...
by RackKing
Mon Dec 07, 2015 4:36 am
Forum: Beginner Basics
Topic: Run Winbox on a Raspberry Pi?
Replies: 21
Views: 8051

Run Winbox on a Raspberry Pi?

Sorry if this is a dumb question... but it would be great to run Winbox from a Pi.

Thanks in advance.
by RackKing
Tue Oct 27, 2015 5:04 pm
Forum: RouterBOARD hardware
Topic: United States 3G/4G USB Modem suppoort
Replies: 2
Views: 980

Re: United States 3G/4G USB Modem suppoort

I am wondering the same - anyone?
by RackKing
Sun Oct 11, 2015 3:00 pm
Forum: General
Topic: Sonos across VLANs?
Replies: 15
Views: 4964

Sonos across VLANs?

Any ideas for getting Sonos to work across VLANs where the speaker is on the main network, but the app is running on a device connected Wi-Fi and is on a different Guest VLAN? Can this be done via firewall rules or something else. I am just not sure what sonos needs. Any help would be appreciated. T...
by RackKing
Fri Oct 09, 2015 6:56 pm
Forum: General
Topic: Guest isolation on Wired Network?
Replies: 0
Views: 615

Guest isolation on Wired Network?

I have a wired guest network - I would like to isolate them from seeing one another.3

I have the guest network setup with a firewall address list - but cant seem to write a filter rule that works. Any advice?
by RackKing
Sun Oct 04, 2015 3:04 am
Forum: General
Topic: Dishnet ISP double NAT - They do provide IPV6, but....
Replies: 4
Views: 733

Re: Dishnet ISP double NAT - They do provide IPV6, but....

So - I am not sure, but will check. I am not sure how that would work? How would you forward from the WAN to the router?

Would the IPV6 hit the router directly? Sorry to be naive just never really dealt with double NAT before.
by RackKing
Sat Oct 03, 2015 11:14 pm
Forum: General
Topic: Dishnet ISP double NAT - They do provide IPV6, but....
Replies: 4
Views: 733

Dishnet ISP double NAT - They do provide IPV6, but....

I am not sure how/if I can make use of it. So, I have DishNet that uses a double NAT and I cannot hit the router as I have no WAN IP. I have no experience with IPV6 and have a question. I am told the with Dishnet the IPV6 WAN address is discrete to the modem. Can I use the IPV6 address to reach the ...
by RackKing
Thu Aug 27, 2015 7:15 pm
Forum: General
Topic: VLAN setup on RB2011 to Engenius EAP-350 - what am I missing?
Replies: 2
Views: 768

Re: VLAN setup on RB2011 to Engenius EAP-350 - what am I missing?

I've run into this before with the EAP350. I think you need to have "Isolation" checked on SSIDs not part of the primary/management VLAN (so enable Isolation on your Guest SSID).
Thank you! Spot on - works now. :D

Cheers
by RackKing
Thu Aug 27, 2015 6:11 pm
Forum: General
Topic: VLAN setup on RB2011 to Engenius EAP-350 - what am I missing?
Replies: 2
Views: 768

VLAN setup on RB2011 to Engenius EAP-350 - what am I missing?

First - on this same rb2011 I have a guest VLAN configured and operating properly with some existing Unifi APs. The Guest SSID is tagging properly and pulling from the correct DCHP server, etc.... they work fine. On the EnGenius setup they have place to enable a VLAN ID. I set this to my guest VLAN ...
by RackKing
Mon Aug 24, 2015 5:39 am
Forum: General
Topic: hEX performance numbers? Some clarification for a newbie...
Replies: 7
Views: 1025

Re:

I am estimating according the last row from the performance table (routing with 25 filter rules) 512B column. This is the most representative value that roughly corresponds to my cases when a device should do the nat. And the values are quite similar in real. Thank you - this is exactly the informa...
by RackKing
Fri Aug 21, 2015 4:53 pm
Forum: General
Topic: hEX performance numbers? Some clarification for a newbie...
Replies: 7
Views: 1025

Re: hEX performance numbers? Some clarification for a newbie...

I am just trying to understand what byte packet size is best used or most representative......
by RackKing
Fri Aug 21, 2015 3:22 pm
Forum: General
Topic: hEX performance numbers? Some clarification for a newbie...
Replies: 7
Views: 1025

Re: hEX performance numbers? Some clarification for a newbie...

Thank you so much for the reply - but in general terms what size should I use to estimate WAN to LAN performance from the data?
by RackKing
Fri Aug 21, 2015 3:14 pm
Forum: General
Topic: hEX performance numbers? Some clarification for a newbie...
Replies: 7
Views: 1025

hEX performance numbers? Some clarification for a newbie...

Hi, So I see the performance numbers have been put out on routerboard.com for the hEX RB750Gr2. http://routerboard.com/RB750Gr2 Based on 25 IP filter rules it looks the throughput for 1518 bytes is 986.1 Mbps. Does 1518 relate to the MTU size, or what number is the most realistic to use for determin...
by RackKing
Wed Aug 19, 2015 6:03 pm
Forum: RouterBOARD hardware
Topic: hEX performance numbers? Some clarification on the numbers please for a layman...
Replies: 2
Views: 1276

hEX performance numbers? Some clarification on the numbers please for a layman...

Hi, So I see the performance numbers have been put out on routerboard.com for the hEX RB750Gr2. http://routerboard.com/RB750Gr2 Based on 25 IP filter rules it looks the throughput for 1518 bytes is 986.1 Mbps. Does 1518 relate to the MTU size, or what number is the most realistic to use for determin...
by RackKing
Sat Aug 15, 2015 4:06 pm
Forum: General
Topic: Xbox Live Open NAT, Filter Rules necessary?
Replies: 6
Views: 1999

Re: Xbox Live Open NAT, Filter Rules necessary?

Can anyone comment on the filter rules?
by RackKing
Fri Aug 14, 2015 5:30 pm
Forum: General
Topic: Xbox Live Open NAT, Filter Rules necessary?
Replies: 6
Views: 1999

Re: Xbox Live Open NAT, Filter Rules necessary?

If it is not listening to connections from the public Internet, how is it a security risk? All it does is let computers on the LAN request ports be open and forwarded to them. That is to say, what is needed to make a game work properly. There's no real rocket science. /did game programming until a ...
by RackKing
Fri Aug 14, 2015 5:07 pm
Forum: General
Topic: Xbox Live Open NAT, Filter Rules necessary?
Replies: 6
Views: 1999

Re: Xbox Live Open NAT, Filter Rules necessary?

I believe another quick and dirty way to get game consoles (xbox, playstation, etc) running properly is to turn UPNP on in the client cpe. We typically leave UPnP disabled on the router as it is a potential significant security risk. If UPnP was running, I assume it would work well but have never t...
by RackKing
Fri Aug 14, 2015 3:17 pm
Forum: General
Topic: Xbox Live Open NAT, Filter Rules necessary?
Replies: 6
Views: 1999

Xbox Live Open NAT, Filter Rules necessary?

Hi, I have used the link below to identify and open the required ports for an Xbox One. http://support.xbox.com/en-US/xbox-one/networking/network-ports-used-xbox-live Here are the rules being used, where xbox ip address = the reserved local IP address of the Xbox /ip firewall filter= add chain=forwa...
by RackKing
Thu Aug 06, 2015 8:40 pm
Forum: RouterBOARD hardware
Topic: HEX VS RB450G?
Replies: 0
Views: 746

HEX VS RB450G?

I am wondering if anyone has an idea of how these two compare simply in WAN to LAN performance? The processor speed is different, but I am unsure how that translates to real world performance. With a normal firewall I wonder how big of an internet connection the HEX could handle - 500Mbps with fastt...
by RackKing
Mon Aug 03, 2015 11:32 pm
Forum: RouterBOARD hardware
Topic: hEX GL?
Replies: 6
Views: 1303

Re: hEX GL?

I checked the usual suspects and found! Thanks for the input. I am pretty excited about this little router!
by RackKing
Mon Aug 03, 2015 11:01 pm
Forum: RouterBOARD hardware
Topic: hEX GL?
Replies: 6
Views: 1303

Re: hEX GL?

really - who? I will check the usual suspects but if you would PM me that would be great.
by RackKing
Mon Aug 03, 2015 6:52 pm
Forum: RouterBOARD hardware
Topic: hEX GL?
Replies: 6
Views: 1303

Re: hEX GL?

great - any idea when this is shipping?
by RackKing
Wed Jul 29, 2015 2:52 pm
Forum: Scripting
Topic: dynDNS Update Script
Replies: 158
Views: 109266

Re: dynDNS Update Script

@gbr - thank you very much for posting this. I kind of works for me.... have a couple of questions. Note: I am a novice at scripting and still learning.

I have the script I provided working successfully on three routers.
Thanks very much GBR for the help and clarification.
by RackKing
Sun Jul 26, 2015 4:22 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 105949

Re: Blacklist Filter update script

Thank you for providing this to the community!
by RackKing
Wed Jul 22, 2015 2:59 pm
Forum: Scripting
Topic: dynDNS Update Script
Replies: 158
Views: 109266

Re: dynDNS Update Script

@gbr - thank you very much for posting this. I kind of works for me.... have a couple of questions. Note: I am a novice at scripting and still learning. So I have poured over this sever times - it has been a great learning opportunity. As I understand it this - # get the current IP address from the ...
by RackKing
Mon Jul 20, 2015 2:29 pm
Forum: Scripting
Topic: dynDNS Update Script
Replies: 158
Views: 109266

Re: dynDNS Update Script

@gbr

did you get it working - can you share?
by RackKing
Wed Jul 15, 2015 6:33 am
Forum: RouterBOARD hardware
Topic: Would a product like the hEX 750Gr2 ever be available board only? Or perhaps a non branded case?
Replies: 0
Views: 521

Would a product like the hEX 750Gr2 ever be available board only? Or perhaps a non branded case?

Also - a data sheet I saw shows a 750 mhz processor. With a normal "soho" firewall and nat rules what do you think the max wan to lan performance would be?

Thanks in advance .
by RackKing
Wed Jul 08, 2015 6:06 am
Forum: RouterBOARD hardware
Topic: RB3011 Block diagram?
Replies: 230
Views: 51024

Re: RB3011 Block diagram?

RB 2011 was the product in 2011 so i might be that RB 3011 will be released in Q2 of 3011?! :lol: no seriously i'm also waiting for that device. but it's also better if it get postponed rather than a not working release. nevertheless MT could give an update on the state.

+1
by RackKing
Sat Jun 20, 2015 2:50 pm
Forum: RouterBOARD hardware
Topic: RB3011 Block diagram?
Replies: 230
Views: 51024

Re: RB3011 Block diagram?

I use the rack mount 2011 versions almost exclusively. So it is simply black with white lettering and matches the rest of the gear it lives with. No red on the rack. I don't think the red looks bad on the desktop models.

my 2
by RackKing
Wed Jun 17, 2015 12:25 pm
Forum: RouterBOARD hardware
Topic: hEX GL?
Replies: 6
Views: 1303

hEX GL?

when we have hEX with gigabit?
by RackKing
Wed Jun 17, 2015 12:18 pm
Forum: RouterBOARD hardware
Topic: RB3011 Block diagram?
Replies: 230
Views: 51024

Re: RB3011 Block diagram?

"ny chance to get the rb3011 rm in the style of the crs series?"

no white please........ for that matter, I wish the CRS stuff was black as well
by RackKing
Sun Jun 14, 2015 5:59 pm
Forum: Scripting
Topic: How to ***really*** block invalid TCP and UDP packet
Replies: 43
Views: 36277

Re: How to ***really*** block invalid TCP and UDP packet

So I understand these rules would be in addition to existing firewall rules - as somewhat of a newbie, in a home environment would I simply add these to the standard Mikrotik home config they recommend? /ip firewall filter add chain=input connection-state=established action=accept add chain=input co...
by RackKing
Sun Jun 07, 2015 4:01 pm
Forum: Beginner Basics
Topic: Firewall Help needed for Unifi
Replies: 1
Views: 620

Firewall Help needed for Unifi

I have some firewall rules that are blocking some of my networks from communicating or seeing one another. This is working fine. I am trying to allow some traffic through and am wondering the best way to accomplish this. I have a UAPs that dropped off the remote server when I put them in place. Also...
by RackKing
Fri Jun 05, 2015 2:14 pm
Forum: General
Topic: Log help - what do these entries mean?
Replies: 6
Views: 600

Re: Log help - what do these entries mean?

Thanks Dave!
by RackKing
Fri Jun 05, 2015 1:40 am
Forum: General
Topic: Log help - what do these entries mean?
Replies: 6
Views: 600

Re: Log help - what do these entries mean?

Ah - that would have been good info - RB2011UiAS ROS - 6.29 Firmware - 3.22 That port is connected to a Charter cable modem. I suppose it could be the modem - I just have never seen it do that kind of thing. As I check the logs it is still going on. I would suspect it is not the cable, and I would t...
by RackKing
Thu Jun 04, 2015 9:46 pm
Forum: General
Topic: Log help - what do these entries mean?
Replies: 6
Views: 600

Re: Log help - what do these entries mean?

thanks for the reply - it seems to happen every 30 mins? Is the interface failing on the router?
by RackKing
Thu Jun 04, 2015 9:41 pm
Forum: General
Topic: Log help - what do these entries mean?
Replies: 6
Views: 600

Log help - what do these entries mean?

this may be a dumb question.... can someone help me understand what is happening? The port is a connected to the modem which is not dropping.

Image

Thanks in advance.
by RackKing
Fri May 29, 2015 12:35 pm
Forum: The Dude
Topic: Dude newbie needs help to monitor remote routers ........please
Replies: 10
Views: 3126

Re: Dude newbie needs help to monitor remote routers ........please

thanks - this worked sort of - I will check the manual to find more information. The wish the manual was setup in more of a "how to" fashion.

Anyway - when I add the WAN IP address or DSN name it finds it, but only ads a DNS service. Do I need to ad the router IP?
by RackKing
Thu May 28, 2015 11:26 pm
Forum: The Dude
Topic: Dude newbie needs help to monitor remote routers ........please
Replies: 10
Views: 3126

Re: Dude newbie needs help to monitor remote routers ........please

Hi jarda - I simply do not understand what you are asking me in regard to tunnels. I am at work behind a router. I have an RB2011 remotely I can access through a wan IP. I can access it through winbox. I have all services on the router off, so SSH, telnet, etc... are all off. My winbox port is the o...
by RackKing
Thu May 28, 2015 2:09 pm
Forum: The Dude
Topic: Dude newbie needs help to monitor remote routers ........please
Replies: 10
Views: 3126

Re: Dude newbie needs help to monitor remote routers ........please

Thanks I appreciate the lesson and information.

Can you tell me how to setup The Dude to monitor other routers on connections to let me know when they go up/down?

Are you saying I do that with a tunnel?
by RackKing
Wed May 27, 2015 9:28 pm
Forum: The Dude
Topic: Dude newbie needs help to monitor remote routers ........please
Replies: 10
Views: 3126

Re: Dude newbie needs help to monitor remote routers ........please

Thanks Jarda -
Have you tried to use tunnels between your devices to have clear access to them?
If you mean can I Winbox into them remotely - yes. Is tunnel something you start on the Dude?

I am just not sure how to get started...
by RackKing
Wed May 27, 2015 2:39 am
Forum: The Dude
Topic: Dude newbie needs help to monitor remote routers ........please
Replies: 10
Views: 3126

Dude newbie needs help to monitor remote routers ........please

So, I would like to know how to use the dude to monitor remote routers, mostly rb2011s. I would like to get an email if a 2011 goes missing. I am using windows and can run on a server. I would maybe grow into other things - but right now I just want to watch remote installations and know if they go ...
by RackKing
Sat Jan 31, 2015 3:34 pm
Forum: Beginner Basics
Topic: Step Up from the RB2011....?
Replies: 22
Views: 4769

Re: Step Up from the RB2011....?

Thanks for all he replies!
by RackKing
Fri Jan 30, 2015 9:54 pm
Forum: General
Topic: Winbox access from WAN i.e. remotely - best practices?
Replies: 5
Views: 1330

Re: Winbox access from WAN i.e. remotely - best practices?

thank you very much - that really helps

Kudos to you,
by RackKing
Fri Jan 30, 2015 5:36 pm
Forum: General
Topic: Winbox access from WAN i.e. remotely - best practices?
Replies: 5
Views: 1330

Re: Winbox access from WAN i.e. remotely - best practices?

hmmmm - never done port knocking I will do a search and see if I figure it out. Or if you have some info please pass it along.

by tunneling do you mean VPN?
by RackKing
Fri Jan 30, 2015 3:47 pm
Forum: General
Topic: Winbox access from WAN i.e. remotely - best practices?
Replies: 5
Views: 1330

Winbox access from WAN i.e. remotely - best practices?

We have several routers in the filed at this point that we access from our Office. We have 8291 open and can access these no problem. We use a good 8 character password currently. What do you guys to secure this more? Should we use a stronger password? Changing the port? Can I specify specific hosts...
by RackKing
Fri Jan 30, 2015 3:16 pm
Forum: Beginner Basics
Topic: Step Up from the RB2011....?
Replies: 22
Views: 4769

Re: Step Up from the RB2011....?

Thanks very much for the information from each of you. This helps me frame it up. @ Nathan, The 1100 looks like a defiantly step up, but the pricing delta puts it really close to the entry 1009. I have been watching the prices and sometimes they are within about $60. so the 1009 is not that much mor...
by RackKing
Fri Jan 30, 2015 10:42 am
Forum: Beginner Basics
Topic: Step Up from the RB2011....?
Replies: 22
Views: 4769

Re: Step Up from the RB2011....?

I guess I was just asking about "faster" in general terms. We are dealing with 100mbps WAN connections regularly now. I have seen the charts on router board and get that, but I wonder how a few concurrent VPN connections running at the same time affect that performance? One reason for my question is...
by RackKing
Fri Jan 30, 2015 3:36 am
Forum: Beginner Basics
Topic: Step Up from the RB2011....?
Replies: 22
Views: 4769

Re: Step Up from the RB2011....?

Bueller.....
by RackKing
Wed Jan 28, 2015 5:00 pm
Forum: Beginner Basics
Topic: Step Up from the RB2011....?
Replies: 22
Views: 4769

Step Up from the RB2011....?

So - Just to make this clear in my own little mind.... I am interested in WAN to LAN performance primarily, and VPN and routing speed next. Metarouter is not a factor for my thinking. What is the natural progression from the 2011? RB980gx2 CCR1009 seems like a big jump.... also afraid to ask this fo...
by RackKing
Thu Jan 22, 2015 4:35 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

@Nathan

I disabled this on the EdgeSwitch. As I was testing this and trying to figure out where the problem lies, I was pinging the edgeswitch. so RSTP was on for a long long time.....

@43 - yeap the bridges with RTSP did not play nice for sure.

Thanks guys.
by RackKing
Wed Jan 21, 2015 2:20 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

So..... mercifully I have tracked down the problem/issue. A big thanks to 43north for throwing some time at this - he is a great guy. To be clear - at the most basic level - when I had the Edgeswtich connected to a CCR port that was part of a bridge it would instantly become unavailable. As seen by ...
by RackKing
Tue Jan 13, 2015 3:54 pm
Forum: General
Topic: VLAN setup and configuration – please proof my work/process
Replies: 1
Views: 591

VLAN setup and configuration – please proof my work/process

First - I apologize for the minutia in this post. I am still very much a beginner with Router OS. Hi, I am looking for confirmation that I am doing the right things when configuring VLANs. If there are scenarios where this will not work please advise. Specifically I am trying to make sure I have not...
by RackKing
Sat Jan 10, 2015 11:46 am
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

Hi 43 - again thanks for your continued help. I cannot get mine to work. What settings are you using?
by RackKing
Fri Jan 09, 2015 4:23 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

at least I do not feel so crazy...... thanks 43 for your help
by RackKing
Thu Jan 08, 2015 6:17 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

A Nathan & 43 thank you both for the help. @ Nathan you have descried what I am trying to achieve perfectly - but it simply does not work for me. 0/48 uplink trunk has VLANs 10,20,30,40 included and tagged and Default VLAN 1 included and untagged. This should mean the hardware on this is into the ne...
by RackKing
Wed Jan 07, 2015 2:57 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

First thanks 43 for your help - I have followed the instructions exactly - and no necessarily getting an error. I just cannot get an IP address from the router to the wireless client. Here is my setup - perhaps more clear. On the CCR1016 I have 4 VLANs setup with DHCP servers, addresses, bridges, et...
by RackKing
Tue Jan 06, 2015 4:25 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

not really .... if my VLANs are 10,20,30,40 - are you saying the pvid needs to be the same? pvid 10,20,30,40? On the Ubiquiti EdgeSwitch 1) Create VLANs that you wish to pass from your Mikrotik - I did this on the status page = 10,20,30,40 2) On Port Configuration page, include VLANs TAGGED on your ...
by RackKing
Mon Jan 05, 2015 10:42 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

thank you for the clarification on the access points - if the PVID is default at 1 does it need to be changed?
by RackKing
Mon Jan 05, 2015 9:12 pm
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

So - I very much appreciate your efforts - but cannot get his to take.... Any feedback would be appreciated, I am probably missing something simple. This management vlan is confusing to me. Here is my 192.168.x.x setup on my CCR1016 .10 network - VLAN 10 .20 network - VLAN 20 .30 network - VLAN 30 ....
by RackKing
Wed Dec 31, 2014 12:35 am
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 34
Views: 12302

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

I am in same situation with an edge switch - how did you get this working - cant figure out how to create a trunk port. All the VLans are setup in the CCR. I am using UAPs to tag via SSID.

any help appreciated.
by RackKing
Tue Nov 18, 2014 9:07 pm
Forum: General
Topic: Philosophy question..... UTMs?
Replies: 5
Views: 1942

Re: Philosophy question..... UTMs?

I was asking how many people deploy a UTM with a Mikrotik router. Is there a UTM everyone likes or a go to unit for a small business, restaurant, church, large residential, (not enterprise) that we should consider using? I am wondering if this would be a good standard practice to just do? I know the...
by RackKing
Tue Nov 18, 2014 3:09 pm
Forum: General
Topic: Philosophy question..... UTMs?
Replies: 5
Views: 1942

Re: Philosophy question..... UTMs?

Is this a crazy question?
by RackKing
Mon Nov 17, 2014 7:39 pm
Forum: General
Topic: Philosophy question..... UTMs?
Replies: 5
Views: 1942

Philosophy question..... UTMs?

We primarily use RB2011 of various flavors in residential systems and some light commercial projects.

Should we consider a UTM as part of our standard package? Does anyone else out here do this? If so do you have a recommendation?
by RackKing
Thu Oct 09, 2014 5:28 pm
Forum: General
Topic: DNS filtering?
Replies: 3
Views: 978

DNS filtering?

Is there a way to do DNS filtering by mac?

So in a household you want the Kids computer to be using OpenDNS setup up appropriately, but the parents computer to use google DNS.

Can this be done?

Sorry if this is a newbie question.
by RackKing
Fri Sep 05, 2014 3:02 pm
Forum: General
Topic: Email uses? What best practices should I be doing?
Replies: 3
Views: 625

Email uses? What best practices should I be doing?

Again, Sorry for the newbie questions... I have never setup the Mikrotik email feature. I have read some posts about "monitoring? using the email feature. What to you guys use the email function for? Can someone share some scripts/tricks on using the Email feature. Any remote information concerning ...
by RackKing
Thu Aug 28, 2014 1:44 pm
Forum: General
Topic: RB2011 + CyberpowerUPS via USB
Replies: 8
Views: 1832

Re: RB2011 + CyberpowerUPS via USB

RackKing, I use a USB port replicator. This is the only way I can get the RB2011 to talk to my APC-UPS (after a few reboots). http://wiki.mikrotik.com/wiki/Manual:System/UPS From the wiki, it looks like MK only supports APC Smart UPS. Thanks for this - I will try one. So - you have gotten communica...
by RackKing
Wed Aug 27, 2014 2:31 pm
Forum: General
Topic: RB2011 + CyberpowerUPS via USB
Replies: 8
Views: 1832

Re: RB2011 + CyberpowerUPS via USB

Does anyone have any input?
by RackKing
Wed Aug 20, 2014 3:15 pm
Forum: General
Topic: Netinstall RB2011 console or ethernet cable?
Replies: 6
Views: 4323

Re: Netinstall RB2011 console or ethernet cable?

So - I am an idiot I think. The instructions indicated to use ether1.... so I am connected ether1 directly to my laptop. I have also downloaded and installed the correct netinstall version that matches what is currently on the RB2011 V6.7 I hold the reset button down on power up until I see ether bo...
by RackKing
Wed Aug 20, 2014 1:26 pm
Forum: General
Topic: Netinstall RB2011 console or ethernet cable?
Replies: 6
Views: 4323

Re: Netinstall RB2011 console or ethernet cable?

ah - google is my friend. I will make a rolled RJ45 cable and give it a shot. If I am on the wrong track please let me know.
by RackKing
Wed Aug 20, 2014 1:04 pm
Forum: General
Topic: Netinstall RB2011 console or ethernet cable?
Replies: 6
Views: 4323

Netinstall RB2011 console or ethernet cable?

Hi, I have a 2011 that needs the OS to be re-installed via netinstall. I see the 2011 has a console port on the back of the unit. Can I connect via Ethernet to this? I do have a console style serial to Ethernet cable but no serial port on my laptop. Sorry to be a newbie - I have never used a console...
by RackKing
Tue Aug 12, 2014 2:40 pm
Forum: General
Topic: RB2011 + CyberpowerUPS via USB
Replies: 8
Views: 1832

Re: RB2011 + CyberpowerUPS via USB

any help?
by RackKing
Tue Aug 05, 2014 2:08 am
Forum: Beginner Basics
Topic: Frontier PPPoE ADSL setup help needed....
Replies: 1
Views: 867

Frontier PPPoE ADSL setup help needed....

I am trying to setup a RB2011 to a DSL router in bridge mode. I setup the PPPoE to the correct port and configured the dial in with the user name and password, but I cannot get it to connect. Also - I have place the modem (netgear 7550 from frontier) in bridge mode previously. Is there a guide for t...
by RackKing
Tue Aug 05, 2014 1:49 am
Forum: General
Topic: error when copying in scripts.... in 6.18 - any help?
Replies: 5
Views: 2355

Re: error when copying in scripts.... in 6.18 - any help?

I got is sorted - thanks. You gave me the place to look.
by RackKing
Mon Aug 04, 2014 2:54 am
Forum: General
Topic: error when copying in scripts.... in 6.18 - any help?
Replies: 5
Views: 2355

error when copying in scripts.... in 6.18 - any help?

Hi,
I have some scripts I use that when I copy over produce the following error. I think the error has to do with syntax changes - any help?

"input does not match any value of policy"

Thanks in advance.
by RackKing
Sun Aug 03, 2014 2:33 pm
Forum: General
Topic: RB2011 + CyberpowerUPS via USB
Replies: 8
Views: 1832

Re: RB2011 + CyberpowerUPS via USB

Further - when I try to do a = system resources usb> print" the router locks up and reboots....

I do not see an entry into the log either.

ideas?
by RackKing
Sun Aug 03, 2014 2:19 pm
Forum: General
Topic: RB2011 + CyberpowerUPS via USB
Replies: 8
Views: 1832

RB2011 + CyberpowerUPS via USB

So - I have read through some posts and not read any concrete information so I thought I would ask. My ultimate goal is to create a script that sends an email if the UPS goes on batter backup if the site looses power. But first... I have the USB package loaded and the UPS connected - but I cannot se...
by RackKing
Sat Jul 26, 2014 4:01 am
Forum: General
Topic: Remote monitoring.... what are you guys using? please :-)
Replies: 5
Views: 1252

Re: Remote monitoring.... what are you guys using? please :

Thanks guys for all the responses I see I have a lot of work to do
by RackKing
Fri Jul 25, 2014 4:00 pm
Forum: General
Topic: Remote monitoring.... what are you guys using? please :-)
Replies: 5
Views: 1252

Remote monitoring.... what are you guys using? please :-)

We would like to be able to keep better track of the systems we have deployed. What are you guys using for remote monitoring? At the very least we are looking at a system to email alert us if a router has dropped offline. Is there a cloud management app that works well. Nagios and the like sound gre...