Community discussions

Search found 77 matches

by mag2020
Fri Feb 16, 2018 10:54 am
Forum: Beginner Basics
Topic: Block websites http and https without Web Proxy / 100% works.
Replies: 17
Views: 13765

Re: Block websites http and https without Web Proxy / 100% works.

Today i am sharing my little experience with beginner like me, you can understand my post from title so no other words and lets start. This method will not effect any other website, i would like to block Facebook in my example. 1: Add website in Layer7 Protocol. /ip firewall layer7-protocol add nam...
by mag2020
Thu Feb 15, 2018 10:10 am
Forum: Beginner Basics
Topic: How to properly turn off PC with MikroTik?
Replies: 4
Views: 1782

Re: How to properly turn off PC with MikroTik?

How to properly turn off PC with MikroTik? I have: PC, Mikrotik router, power strip 1. Snutdown the PC, then turn off power strip 2. Shutdown MikroTik (shutdown at RouterOS menu), then snutdown the PC, then turn off power strip Usually, I am using the first option of turning off What is this in log...
by mag2020
Mon Feb 12, 2018 6:33 pm
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 290
Views: 41766

Re: wAP 60G experience

I suppose he is reffering to backhaul of traffic from one AP to another AP forming a meshed network. The huge capacity available on the wap60 makes it a candidate for traffic backhauling.
by mag2020
Mon Feb 12, 2018 6:32 pm
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 290
Views: 41766

Re: wAP 60G experience

I suppose he is reffering to backhaul of traffic from one AP to another AP forming a meshed network. The huge capacity available on the wap60 makes it a candidate for traffic backhauling.
by mag2020
Thu Feb 01, 2018 9:54 pm
Forum: General
Topic: Block/limit youtube
Replies: 13
Views: 7768

Re: Block/limit youtube

TLS Host does not work in RouterOS 6.41. Use last RouterOS 6.42rc15 (Release candidate). I can confirm, working in rc15 You are right. The Feb2018 Newsletter however mentioned that this feature is available from ROS v6.41 but that may not be totally correct. The option was available but it was not ...
by mag2020
Sun Jan 21, 2018 6:06 pm
Forum: Beginner Basics
Topic: PP2P interface to bypass governments censorship
Replies: 3
Views: 389

Re: PP2P interface to bypass governments censorship

Hay Guys! I'm trying to use MikroTik hap lite to bypass our governments' censorship. I used this article to config my router: https://wiki.mikrotik.com/wiki/Policy_Base_Routing Everything is OK but nothing is :-). When I try to visit http://www.google.com, I can see that it's under United Kingdom r...
by mag2020
Sun Jan 21, 2018 5:37 pm
Forum: Beginner Basics
Topic: PP2P interface to bypass governments censorship
Replies: 3
Views: 389

Re: PP2P interface to bypass governments censorship

Hay Guys! I'm trying to use MikroTik hap lite to bypass our governments' censorship. I used this article to config my router: https://wiki.mikrotik.com/wiki/Policy_Base_Routing Everything is OK but nothing is :-). When I try to visit http://www.google.com, I can see that it's under United Kingdom r...
by mag2020
Sun Jan 21, 2018 4:44 pm
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 290
Views: 41766

Re: wAP 60G experience

Yes, testing model: https://trzepak.pl/viewtopic.php?p=480703#p480703 Final product will be with 8 year guarantee for protection without rust and some modifications. Nice work if you can achieve 1km. But, what are your antenna parameters like? What beam width do you achieve on the horizontal axis?
by mag2020
Wed Jan 17, 2018 12:00 am
Forum: General
Topic: Dual VPN / same provider
Replies: 15
Views: 1423

Re: Dual VPN / same provider


The OP has clarified that he has two different remote servers so the NAT device would have to be quite stupid to have a problem in this case.
I did n't get this part from his earlier post. In that case its not the issue.
by mag2020
Tue Jan 16, 2018 9:43 pm
Forum: General
Topic: Dual VPN / same provider
Replies: 15
Views: 1423

Re: Dual VPN / same provider

Trying to set up failover of VPN tunnels, however, coming across a few issues. I'm using the same Service Provider and mirror all L2TP/IPSEC option for the primary tunnel, however the second tunnel is not coming online. Questions: Is it possible that the conflict arises as I'm using same IPSEC conf...
by mag2020
Mon Jan 15, 2018 1:16 pm
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 290
Views: 41766

Re: wAP 60G experience

I suggest that SFP port be added to this device in future models. That will make it even more superb. My concern is that the board may not have enough space for this.
With SFP included, it will be easy to use the wap g60 to bridge gaps on a fiber transmission path.
by mag2020
Wed Dec 20, 2017 11:13 am
Forum: RouterBOARD hardware
Topic: RB3011 no more POE on port eth10
Replies: 25
Views: 5509

Re: RB3011 no more POE on port eth10

I have solved issue by replacing the SXT unit powered by 3011 Note that "suspected faulty" SXT is OK with its own injector, and powers up OK with few 3011 but KO with other 3011 units. It seems an edge situation where , anyway, 3011 PoE capability is at its limit. Unfortunately I can try no more th...
by mag2020
Wed Dec 20, 2017 10:54 am
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 290
Views: 41766

Re: wAP 60G experience

Hello, what are test results of this equipment? Our experience is quite surprising, keep on mind this is WiFi Renesans.. There are very few technical information in menu. No Signal strength information, just quality and MCS modulation method. On RF spectral analyser we saw something like 2GHz chann...
by mag2020
Mon Dec 18, 2017 11:45 pm
Forum: Beginner Basics
Topic: Port forwarding help
Replies: 10
Views: 720

Re: Port forwarding help

i don't know how to send results. i will put my print screen's how i made it https://prnt.sc/hp92kd http://prntscr.com/hp93lc btw i red somewhere about interface and ethernet1 maybe i should choose In.Interface as well as ethernet1 ?? totally don't know what does it mean... You may have to add the ...
by mag2020
Mon Dec 18, 2017 10:50 pm
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 290
Views: 41766

Re: wAP 60G experience

200m is over the physical limit quality 30-40 points, which is almost no L2 link.. capacity is below 30mbit
Did you say below 30Mbps? At what distance do you get the full rated capacity from your test?
by mag2020
Mon Dec 18, 2017 10:13 pm
Forum: Wireless Networking
Topic: wAP 60G experience
Replies: 290
Views: 41766

Re: wAP 60G experience

Hello, what are test results of this equipment? Our experience is quite surprising, keep on mind this is WiFi Renesans.. There are very few technical information in menu. No Signal strength information, just quality and MCS modulation method. On RF spectral analyser we saw something like 2GHz chann...
by mag2020
Mon Dec 18, 2017 7:55 pm
Forum: Beginner Basics
Topic: Port forwarding help
Replies: 10
Views: 720

Re: Port forwarding help

thanks for you answer. as i see it's not that difficult and i hope i will manage it somehow. start->cmd->ipconfig and then which is " your provider IP " and which is " your LAN IP of your PC " ? yes i do have Mikrotik router and i created already 23428 rules trying to open that port but probably i ...
by mag2020
Mon Dec 18, 2017 7:24 pm
Forum: RouterBOARD hardware
Topic: RB3011 no more POE on port eth10
Replies: 25
Views: 5509

Re: RB3011 no more POE on port eth10

Same issue again here. RB3011 straight out of the box, will not power anything with POE port 10. Tried forced on and nothing works. Can you try powering the RB3011 with a 24VDC 2A PSU instead. My feeling is that the power supplied by the 24VDC 1.2A PSU is not enough to power the RB3011 itself and t...
by mag2020
Sun Apr 23, 2017 9:51 pm
Forum: General
Topic: HBO GO on Samsung Smart TV doesn't work on RB2011 WiFi BUT works on WIRED connection
Replies: 8
Views: 1944

Re: HBO GO on Samsung Smart TV doesn't work on RB2011 WiFi BUT works on WIRED connection

For some weird reason, enabling IP-->DNS-->Allow Remote Request, makes HBO GO works again on WiFi . After disabling it, HBO GO stops working. I don't know how to explain this, on wired connection HBO GO works as normal. Now, I need to check if DNS will be abused because of remote requests. Any thou...
by mag2020
Fri Mar 03, 2017 6:04 am
Forum: General
Topic: Cisco replacement
Replies: 6
Views: 788

Re: Cisco replacement

Hi all, Many years ago, I installed a Cisco 1800 series router for a client for them to connect to their ISP and route a /27 public range to their network. They want to increase their bandwidth well above the 100Mb interfaces that the 1800 has so it needs to be replaced. A new Cisco box could be $4...
by mag2020
Fri Mar 03, 2017 6:01 am
Forum: General
Topic: Giving Public IP trough PPPoE
Replies: 15
Views: 9522

Re: Giving Public IP trough PPPoE

mag2020,
You were correct. Its now fixed.

Thanks.
Good to hear that its now fixed!
by mag2020
Mon Feb 13, 2017 9:46 pm
Forum: General
Topic: Giving Public IP trough PPPoE
Replies: 15
Views: 9522

Re: Giving Public IP trough PPPoE

Hello Every One,
I have a similar problem.. In my case the user has been assigned the public IP everything works fine however when he checks on checkmyip.com he gets the WAN IP.

Please help.

Thank you
Check if you have any NAT rule masquerading your client's public IP behind your WAN IP.
by mag2020
Mon Feb 13, 2017 9:19 pm
Forum: Beginner Basics
Topic: One SSID with WPA2 and one SSID with portal login
Replies: 1
Views: 374

Re: One SSID with WPA2 and one SSID with portal login

Hi, I'm quite new into the Mikrotik world and have a few RB952Ui-5ac2nD up and running at our organisation's locations. We use the routers for wireless access via a 4G USB dongle and have two different login needs for different groups of users. 1. Group "Staff" needs a simple login to a combined SS...
by mag2020
Mon Feb 13, 2017 8:04 pm
Forum: The Dude
Topic: Introduction to the dude?
Replies: 3
Views: 941

Re: Introduction to the dude?

Just as you rightly said, most people are able to use dude but we have few experts in it. I suppose that if you have all your devices within networks that are reachable from your dude server, the dude should be able to discover all of them after the scan and not just a few as you stated. Normally I ...
by mag2020
Mon Feb 13, 2017 7:40 pm
Forum: The Dude
Topic: Dude don't generate PDF from history graph
Replies: 2
Views: 625

Re: Dude don't generate PDF from history graph

On my system, I was able to export pdf. Very clean output.
by mag2020
Mon Dec 19, 2016 1:53 am
Forum: Beginner Basics
Topic: SFP port Latency
Replies: 4
Views: 609

Re: SFP port Latency

What is the model of your hardware and which SwOS version is it running currently?
by mag2020
Sun Dec 18, 2016 2:34 pm
Forum: Wireless Networking
Topic: IP camera and two lan. what I need ??
Replies: 15
Views: 1327

Re: IP camera and two lan. what I need ??

If in lan1 and lan2 is present a same ip address can born a conflict? You can use, say 192.168.0.1/30 on the IP camera, and 192.168.0.2/30 on the ether1 interface of the AP. Then on your Lan1 & Lan2, 192.168.1.0/24 and 192.168.2.0/24 respectively. Do a static route from Lan1&Lan2 routers to 192.168...
by mag2020
Fri Dec 16, 2016 2:48 am
Forum: General
Topic: Can't use PPTP and L2TP at same time?
Replies: 1
Views: 489

Re: Can't use PPTP and L2TP at same time?

I'm not sure if this is a bug, but i've noticed on our CCR1009 (6.36) that it isn't possible to have both PPTP and L2TP working at the same time I can turn both on and there appears to be no errors, but only 1 of them actually works - whichever was turned on first If I turn PPTP server on, then tur...
by mag2020
Fri Dec 16, 2016 2:42 am
Forum: General
Topic: How to dynamically bind PPTP connection's uplink?
Replies: 2
Views: 417

Re: How to dynamically bind PPTP connection's uplink?

What I'm trying to archive is: 1. The ros box has multiple PPPoE uplink interfaces, say one of the uplink interface hold IP 10.9.9.5. Every uplink is isolated from other uplinks. 2. The ros box is also a PPTP server, PPTP server IP is 10.8.8.4, PPTP connection IP at side server is 192.168.111.5 3. ...
by mag2020
Thu Dec 15, 2016 9:52 pm
Forum: Beginner Basics
Topic: Play store to be allowed
Replies: 5
Views: 1053

Re: Play store to be allowed

Hi,

Since i am a beginer, a little detailed help would be more welcome

Thanks
It is better if you set it up, and then where you encounter a challenge you communicate the specific challenge so that you will be guided.
by mag2020
Thu Dec 15, 2016 9:42 pm
Forum: Wireless Networking
Topic: IP camera and two lan. what I need ??
Replies: 15
Views: 1327

Re: IP camera and two lan. what I need ??

Can lan1/lan2 connect by WDS to AP ? (lan1/lan2 have routers connected to internet)
You can try to set the virtual interfaces on the Access Point on AP mode while the one on the lan1/lan2 are set on Station/Station Bridge mode
by mag2020
Thu Dec 15, 2016 9:08 pm
Forum: Wireless Networking
Topic: IP camera and two lan. what I need ??
Replies: 15
Views: 1327

Re: IP camera and two lan. what I need ??

I'm sorry I did not understand, and excuse my confusion on operating mode/wds, ecc... The solution of Asghari is possible with camera connected by cable on AP? Can lan1/lan2 connect by WDS to AP ? (lan1/lan2 have routers connected to internet) p.s. I updated first post with graphical map Hi Kadkam,...
by mag2020
Wed Dec 14, 2016 1:47 pm
Forum: Wireless Networking
Topic: IP camera and two lan. what I need ??
Replies: 15
Views: 1327

Re: IP camera and two lan. what I need ??

good but I'm not sure that I can finding a good reception for the camera (there are some walls to pass)
Is really not possible to use cable for camera?
It depends on your camera. If your camera has physical ports, you can wire it to the Mikrotik device. In this case, no need for an Access point.
by mag2020
Wed Dec 14, 2016 10:31 am
Forum: Wireless Networking
Topic: IP camera and two lan. what I need ??
Replies: 15
Views: 1327

Re: IP camera and two lan. what I need ??

wAP ac is a good solution;
Are we sure that can I attach ipcamera on ethernet port (client mode)?
I expect your IP camera to connect wirelessly to the Access Point.
by mag2020
Wed Dec 14, 2016 1:18 am
Forum: General
Topic: Stop DHCP
Replies: 7
Views: 1348

Re: Stop DHCP

If your main router and the second router are not connected via a layer 2 connection, you should not receive DHCP issued from one router on the other except if one of the interconnecting ports is participating in the DHCP server bridge ports. You should better use static IPs for interconnection of t...
by mag2020
Tue Dec 13, 2016 11:53 pm
Forum: Beginner Basics
Topic: Play store to be allowed
Replies: 5
Views: 1053

Re: Play store to be allowed

You need to use wild cards to allow access to the contents. I do not think that it will work by merely listing those url. For instance, it wont work if you allow abc.com while the content to be downloaded might be at abc.com/contents. In that case, you need to use those wild cards to meet your speci...
by mag2020
Tue Dec 13, 2016 6:31 pm
Forum: Wireless Networking
Topic: IP camera and two lan. what I need ??
Replies: 15
Views: 1327

Re: IP camera and two lan. what I need ??

Which hardware (low cost) can I use? thanks! You can use wAP Access points. They are low cost and of good performance. https://routerboard.com/RBwAP2nD You can also use the AC variants if you can afford it. https://routerboard.com/RBwAPG-5HacT2HnD Or maybe you can setup Groove with omni. https://ro...
by mag2020
Tue Dec 13, 2016 6:15 pm
Forum: Beginner Basics
Topic: I can`t log in to the Mikrotik
Replies: 4
Views: 6163

Re: I can`t log in to the Mikrotik

Try logging in with mac address instead of IP address using winbox. You may as well try the later versions of winbox.
by mag2020
Tue Dec 13, 2016 5:55 pm
Forum: Beginner Basics
Topic: Play store to be allowed
Replies: 5
Views: 1053

Re: Play store to be allowed

You can try using walled garden with some wild cards to allow access to the play store download url.
by mag2020
Tue Dec 13, 2016 5:21 pm
Forum: Wireless Networking
Topic: Long range AP
Replies: 5
Views: 1704

Re: Long range AP

Something like a Groove would also do, it has a nice 6dBi Omni antenna included in the box: https://routerboard.com/RBGrooveA-52HPn Hi Normis, is there anywhere to find information about the beam pattern(radiation pattern) of these Access Points (antenna)? Are they basically omni in terms of radiat...
by mag2020
Tue Dec 13, 2016 2:10 am
Forum: Wireless Networking
Topic: Long range AP
Replies: 5
Views: 1704

Re: Long range AP

If you do ceiling mount, you should get 25m radius coverage with wAP in an open area. The distance depends on the obstructions available in the area such as walls or other objects.
https://routerboard.com/RBwAP2nD
or https://routerboard.com/RBwAPG-5HacT2HnD
by mag2020
Tue Dec 13, 2016 1:56 am
Forum: Beginner Basics
Topic: SFP port Latency
Replies: 4
Views: 609

Re: SFP port Latency

Is it a constant value of 18ms latency? 18ms is unusual for short cable distances. Why not try uniform hardware types at both ends first, such as Mikrotik to mikrotik instead of Mikrotik to another device(media converter). Can you measure the power output(optical power)?
by mag2020
Wed Nov 30, 2016 12:57 pm
Forum: General
Topic: Access Point and Station in a single unit
Replies: 8
Views: 945

Re: Access Point and Station in a single unit

Thanks..... could you please upload a diagram or details on how to set this up?
I suggest you first send a diagram of what you want to achieve so that we can guide you through on how to achieve it if possible.
by mag2020
Tue Nov 29, 2016 12:23 pm
Forum: Wireless Networking
Topic: Vlan Issue
Replies: 6
Views: 816

Re: Vlan Issue

yes this is why
i want seperate customers
can you please give me links so i can get a clear idea on how can i accomplish this
best regards
Check this page: http://wiki.mikrotik.com/wiki/Vlans_on_ ... nvironment
It will give you a clue on how to go about it.
by mag2020
Tue Nov 29, 2016 12:12 pm
Forum: General
Topic: Access Point and Station in a single unit
Replies: 8
Views: 945

Re: Access Point and Station in a single unit

Is there any other vendor you can recommend? i want to have an alternative.
Mikrotik will not just give you the best performance but also at the best price. What do you want to achieve?
by mag2020
Mon Nov 28, 2016 2:14 pm
Forum: Forwarding Protocols
Topic: L2TP/IPSec: some webpages doesn't load while majority loads fine
Replies: 3
Views: 1017

Re: L2TP/IPSec: some webpages doesn't load while majority loads fine

Thank you for catalyzing the progress. :)
Good to hear that its working fine now. You are welcome!
by mag2020
Mon Nov 28, 2016 4:54 am
Forum: General
Topic: RB750UP PoE not working with IP camera
Replies: 4
Views: 923

Re: RB750UP PoE not working with IP camera

If you chose to extract the DC power from the 'PoE out' of the 750UP device, you will need exactly 12v supply and not 24v since what goes into 750UP is what comes out of the PoE and you have to feed the output directly into your Camera through the 12v input power port of the camera.
by mag2020
Mon Nov 28, 2016 4:28 am
Forum: Forwarding Protocols
Topic: How to NAT the private address to a routed public IP address
Replies: 2
Views: 875

Re: How to NAT the private address to a routed public IP address

I will suggest that you get a separate router for NAT and allow the BGP router to do BGP while the second router does the distribution job and NATing. But if you insist on using the same router, then you have to create a loopback interface (bridge interface with no port attached), Add the public IP ...
by mag2020
Mon Nov 28, 2016 4:14 am
Forum: Forwarding Protocols
Topic: L2TP/IPSec: some webpages doesn't load while majority loads fine
Replies: 3
Views: 1017

Re: L2TP/IPSec: some webpages doesn't load while majority loads fine

This sounds more like an MTU problem. If so, one solution is to use IP firewall mangle feature to modify TCP MSS to a lower value(say 1400) so that your packets are fragmented and reconstructed appropriately to enable web servers that(websites) serve large packet sizes (MTU >1400) to be accessible f...
by mag2020
Mon Nov 28, 2016 3:56 am
Forum: The Dude
Topic: Dude Consultants?
Replies: 9
Views: 1932

Re: Dude Consultants?

I suggest you make direct contact with these Consultants listed here. Their emails are there on the webpage. http://www.mikrotik.com/thedude
You might just get help from one of them before you speak to 3 or 4 persons.
by mag2020
Mon Nov 28, 2016 2:54 am
Forum: Wireless Networking
Topic: Vlan Issue
Replies: 6
Views: 816

Re: Vlan Issue

I guess your reason for doing VLAN is to logically separate the traffic to some end users/terminal points. So, at one end you have several VLANs (trunk) and at the terminal points you have the individual VLANs (access). If you tag the interface at one end, the bridge propagates your traffic as tagge...
by mag2020
Mon Nov 28, 2016 12:27 am
Forum: General
Topic: Access Point and Station in a single unit
Replies: 8
Views: 945

Re: Access Point and Station in a single unit

All Mikrotik devices with wireless interfaces running the latest ROS should be able to do this. You only have to create virtual interfaces and place the interfaces on the modes you desire. But note that all the virtual interfaces run on the same Band, Channel width, and Frequency.
by mag2020
Sun Nov 27, 2016 11:53 pm
Forum: Wireless Networking
Topic: Vlan Issue
Replies: 6
Views: 816

Re: Vlan Issue

If all your wireless links are on bridge mode, adding the vlans appriopriately at the end points should work.
by mag2020
Sun Nov 27, 2016 11:40 pm
Forum: General
Topic: RB750UP PoE not working with IP camera
Replies: 4
Views: 923

Re: RB750UP PoE not working with IP camera

If you insist on using the 750UP, then you have to power it through a good PSU, say 12v, 2A spec and extract the power off the ports to feed directly to the 12v port of the Camera.
by mag2020
Sun Nov 27, 2016 11:34 pm
Forum: General
Topic: RB750UP PoE not working with IP camera
Replies: 4
Views: 923

Re: RB750UP PoE not working with IP camera

Your Camera is 802.3af spec and is expecting 48V DC on the PoE port and not 24v DC as you may be feeding it through the Mikrotik switch.The issue is not about the current/power, its about the excitation voltage which must be a minimum of 44v DC.
by mag2020
Sat Oct 29, 2016 11:40 am
Forum: Beginner Basics
Topic: RB2011 Suports IP aliases
Replies: 4
Views: 705

Re: RB2011 Suports IP aliases

Hi, If what you need is to add multiple IPs on a given interface, YES, your RB2011 can support that both on the physical interfaces and on the Bridge interfaces.
by mag2020
Sat Oct 29, 2016 10:38 am
Forum: Beginner Basics
Topic: Help with specific configuration
Replies: 2
Views: 386

Re: Help with specific configuration

I am not sure what you want to achieve, but with your setup the devices cannot see each other because they are not in the same subnet. Even if you place them on the same vlan on the switch.
by mag2020
Wed Oct 26, 2016 7:32 pm
Forum: Forwarding Protocols
Topic: OSPF - loopback interface
Replies: 23
Views: 5658

Re: OSPF - loopback interface

In our network, it is necessary for us to setup loopback interfaces with IPs on them. They are really necessary, not for fancy.
by mag2020
Wed Oct 26, 2016 7:09 pm
Forum: Beginner Basics
Topic: I would like to filter through cameras at the door 2 for mac address
Replies: 2
Views: 403

Re: I would like to filter through cameras at the door 2 for mac address

You can use bridge filter rules to achieve some level of mac address filtering, but that needs some experience. Take a look at the options and give it a shot.
by mag2020
Wed Oct 26, 2016 6:50 pm
Forum: Beginner Basics
Topic: Capture all dns requests and pass them to my dns
Replies: 4
Views: 835

Re: Capture all dns requests and pass them to my dns

Did you try simple dst-nat ? For example, assuming your clients come from 192.168.0.0/24 /ip firewall nat add action=dst-nat chain=dstnat disabled=yes dst-port=53 protocol=udp src-address=192.168.0.0/24 to-addresses=10.55.22.11 will redirect DNS queries to 10.55.22.11 You can add a second rule same...
by mag2020
Wed Oct 26, 2016 6:41 pm
Forum: General
Topic: Load Balancing and Firewall
Replies: 4
Views: 757

Re: Load Balancing and Firewall

Finished 4Wan Load Balancing. ether 1 to ether 4 are the wans. cant access two local websites(Local Server) after the load balance. this two local connection is coming from ether 4. when i ping to the address it shows (admin prohibited) Please Help me with this situation. You may need to describe y...
by mag2020
Wed Oct 26, 2016 6:23 pm
Forum: General
Topic: mikrotik hacked!?
Replies: 14
Views: 3918

Re: mikrotik hacked!?

i am not blaming anything, but this is not good at all. Here is a firm question then. How can I setup in Mikrotik that one particular host (for eg the NVR) can only reach an IP or a DNS name (IP range) ? This is very easy to setup in Sophos firewall, but I am not familirar much with Mikrotik. So, I...
by mag2020
Tue Oct 25, 2016 2:35 am
Forum: General
Topic: mikrotik hacked!?
Replies: 14
Views: 3918

Re: mikrotik hacked!?

Or it connects to a DNS name that was hijacked and an the exploit downloaded.
You are right. In this circumstance, I think it is most probably the DNS name that was hi-jacked and the hi-jacker would be controlling all the DVR's from that point.
by mag2020
Mon Oct 24, 2016 8:55 pm
Forum: General
Topic: mikrotik hacked!?
Replies: 14
Views: 3918

Re: mikrotik hacked!?

I have a small network behind the NAT-ed internet, ALL ports closed from internet, however my NVR (Network Video Recorder) was hacked last weekend and it was used for the DynDNS attack.: http://thehackernews.com/2016/10/iot-camera-mirai-ddos.html my network is not reachable from external, unless th...
by mag2020
Mon Oct 24, 2016 8:37 pm
Forum: Beginner Basics
Topic: expire date in mikrotik hotspot
Replies: 1
Views: 374

Re: expire date in mikrotik hotspot

hello from greece
i make a hotspot with mikrotik rb951 and i want users to expire in 1 week or to a specify date. how can i do that?
You can do that in usermanager setup where you define the validity for a user while creating the user profile. You can state the validity in hours, days, months etc.
by mag2020
Mon Oct 24, 2016 8:26 pm
Forum: Beginner Basics
Topic: Hotspot Bridge problem
Replies: 1
Views: 462

Re: Hotspot Bridge problem

I swap the ether2 from the WAN bridge to Hotspot, the hotspot and internet access stops working
Hope your WAN IP, the route, etc are defined/setup on the WAN bridge Interface and not the bridge ports.
by mag2020
Mon Oct 24, 2016 7:55 pm
Forum: General
Topic: Hacked DVR's
Replies: 12
Views: 2643

Re: Hacked DVR's

Best I can tell, these are the guys attacking me.
http://www.pcboxargentina.com.ar/productos/?id=82
These guys may not be the ones attacking your system. They, too may just be victims like you. Their hardware are high-jacked by the bad boys.
by mag2020
Tue Oct 11, 2016 2:41 pm
Forum: General
Topic: DHCP Sub-options
Replies: 4
Views: 669

Re: DHCP Sub-options

I'm doing the same next week did you get a work around or a fix????
If you have a similar challenge, you can try the suggestion I made and give us feedback if it works or not.
by mag2020
Tue Oct 11, 2016 2:37 pm
Forum: General
Topic: DHCP Sub-options
Replies: 4
Views: 669

Re: DHCP Sub-options

When I configure the options they both work separately. When I go to the DHCP Network and assign both DHCP options the log reports that it is only sending the first listed option to the device. How do I get it to send multiple options and let the device choose which one it will receive? Have you tr...
by mag2020
Mon Oct 10, 2016 1:20 pm
Forum: Beginner Basics
Topic: Access devices behind MT router
Replies: 2
Views: 471

Re: Access devices behind MT router

So with you all's help, I've managed to get a couple routers in place on my network and they are working well. My problem now is that I'm not able to access devices behind the routers. I have a router at a WISP site. WAN is eth1, LAN eth2&3. DHCP on LAN to customer routers. AP is ubnt in bridge mod...
by mag2020
Mon Oct 10, 2016 12:54 pm
Forum: RouterBOARD hardware
Topic: Connect CCR-1036-8G-2S+EM to cisco 1G sfp
Replies: 7
Views: 1504

Re: Connect CCR-1036-8G-2S+EM to cisco 1G sfp

i want to connect my router through cisco sfp to a cisco 3750 switch in 1Gbps Mode The Router led port show active but cisco switch do not accept connection and there is a one way traffic that shown on mikrotik statistics can anyone help me What i do most times is to play around with the speed and ...
by mag2020
Mon Oct 10, 2016 12:33 pm
Forum: General
Topic: NTP Server
Replies: 4
Views: 1989

Re: NTP Server

Use same package version for the system package and the optional ntp package. Be sure that the package is successfully installed.
Execute the command >system package print
to be sure the ntp package is listed as installed package therein.
by mag2020
Mon Oct 10, 2016 11:24 am
Forum: General
Topic: Block Internet Access to ip but keep internal access to network.
Replies: 3
Views: 2441

Re: Block Internet Access to ip but keep internal access to network.

I am not sure exactly what your description of problem is, but in situations where you need some devices with certain IPs to only access certain networks at some points, a combination of policy routing and some firewall rules will do the magic.
by mag2020
Wed Jun 08, 2016 6:13 pm
Forum: General
Topic: Loop issue in VLAN trunking between two CCR Routers
Replies: 6
Views: 917

Re: Loop issue in VLAN trunking between two CCR Routers

I think we have allready found a solution for this. it wasn´t a doubled mac address or something. it was a faulty router, since it is disconnected, no log entries anymore. Ok. Good to know. But have you confirmed if it is a faulty router hardware or a configuration on the router. It will be nice to...
by mag2020
Wed Jun 08, 2016 3:40 pm
Forum: General
Topic: Loop issue in VLAN trunking between two CCR Routers
Replies: 6
Views: 917

Re: Loop issue in VLAN trunking between two CCR Routers

We see same Issue between one CCR and a 2011 Board. Both have 6.35.2 Firmware. The CCR is the Bridge between AC and the 2011 is for the wireless costumers and makes the tunnel to the CCR. The Problem is since 2 or 3 days before we had no problems... We changed from Arp to Proxy Arp on the 2011 PPPo...
by mag2020
Wed Jun 08, 2016 3:20 pm
Forum: General
Topic: Loop issue in VLAN trunking between two CCR Routers
Replies: 6
Views: 917

Re: Loop issue in VLAN trunking between two CCR Routers

However, when I changed the MAC address of the bridge interface using admin MAC feature, the log stopped: Any ideas? You already solved it wth changing the MAC address. I guess you did a backup on router 1 and installed this on router 2. backup files contain MAC addresses, this can totlly screw up ...
by mag2020
Wed Jun 08, 2016 2:20 am
Forum: General
Topic: Loop issue in VLAN trunking between two CCR Routers
Replies: 6
Views: 917

Loop issue in VLAN trunking between two CCR Routers

Can anyone explain why I get this log "bridge port received packet with own address as source address, probably loop". I trunk a few VLANs between two CCR. See image: vlans in bridge port.png The SFP1 interface of one CCR router is connected to the SFP1 interface of the second CCR router over about ...