Community discussions

MikroTik App

Search found 1896 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 7
by msatter
Tue Oct 20, 2020 12:18 am
Forum: General
Topic: [feature request] Blocking a special kind of DDoS
Replies: 17
Views: 4312

Re: [feature request] Blocking a special kind of DDoS

Hello Could you please share the updated script for ddos and TCP syn flood protection for mikrotik This script is made for a special kind of DDOS and is optimized as much as I am possible to do. In many cases psd is your friend when TCP is used to avoid loading connection up. UDP or other protocols...
by msatter
Mon Oct 19, 2020 5:00 pm
Forum: Scripting
Topic: Example: Showing help, on parameters used in a function
Replies: 0
Views: 58

Example: Showing help, on parameters used in a function

This is a part of bigger script and I share this as a building block to provide help on parameters in a simple way, for a function. It can display the whole help text if you only enter $myFunc -help and if only a specific help on a parameter is needed then $myFunc 1parameter -help. Providing help on...
by msatter
Sat Oct 17, 2020 1:10 am
Forum: Forwarding Protocols
Topic: NTH load balancing
Replies: 63
Views: 1565

Re: NTH load balancing

@DarkNate try Nth 3-1 2-1 - which is the same as 3-1 3-2 3-3 and I think, less processor intensive. Nth 3,1 - 2,1 is likely not the same as Nth 3,1 - 3,2 - 3,3 and if I remember correctly from some MikroTik presentation files, it has to be in that order for either PCC/Nth where 2 means two WAN, 3 m...
by msatter
Fri Oct 16, 2020 10:34 pm
Forum: Forwarding Protocols
Topic: NTH load balancing
Replies: 63
Views: 1565

Re: NTH load balancing

Then, you don't know up-front how much traffic will go over a marked connection. I could look in NAT which connection, had not much traffic yet and then prefer that link. In real time, that is only possible if Mikrotik implement a distribution by clean switching of the source port. Maybe that is alr...
by msatter
Fri Oct 16, 2020 2:43 pm
Forum: General
Topic: How can I make Mikrotik help pages more readable?
Replies: 1
Views: 188

How can I make Mikrotik help pages more readable?

Mikrotik is switching from the Wiki to the Help pages and I can't read it good brcause the rext area is very narrow. Examples and tables have to be scrolled horizontal all the time. I have to tap the two vertical bars in the left column and directly after that the book icon that is then displayed. O...
by msatter
Thu Oct 15, 2020 11:22 pm
Forum: General
Topic: Dynamic firewall filter rule added when IPsec peer is down to avoid unencrypted LAN leaking.
Replies: 5
Views: 203

Re: Dynamic firewall filter rule added when IPsec peer is down to avoid unencrypted LAN leaking.

Even stronger. Most user don't know that their IKEv2 is leaking during the connection is coming up. I use marking all IKEv2 traffic with a routing mark which in NAT is redirected to nothing. This in NAT is not static nor are the connection marking in Mangle. It is a complex script handeling that for...
by msatter
Wed Oct 14, 2020 9:40 pm
Forum: Forwarding Protocols
Topic: NTH load balancing
Replies: 63
Views: 1565

Re: NTH load balancing

When we mark-connection using Nth, it marks the connection based on the Nth classier which is more random (more deeper) as it's per packet (of that particular unmarked connection), hence increasing the chances that the connection to passthrough to the next mangle rule. A connection is a connection ...
by msatter
Wed Oct 14, 2020 6:34 pm
Forum: Forwarding Protocols
Topic: NTH load balancing
Replies: 63
Views: 1565

Re: NTH load balancing

Dude, in the real world connection tracking ( or connection NTH ) is the best way for browsing the internet. NTH is predictable and a listener knows which connection is used next to sent the packet. I am using this for my web browser and a new connection, even to same site, uses a 'unpredictable' pa...
by msatter
Wed Oct 14, 2020 2:49 pm
Forum: Scripting
Topic: Script to save file to disk1 [SOLVED]
Replies: 2
Views: 199

Re: Script to save file to disk1 [SOLVED]

="disk1/$backupfile"
by msatter
Sun Oct 11, 2020 10:59 pm
Forum: General
Topic: Safety Fallback for Script Error
Replies: 2
Views: 199

Re: Safety Fallback for Script Error

You can activate safe mode before starting the script and at the end of the script you deactivate the safe mode and so making the changes permanent. In environment you can see if that script is still running. You can check if the with a schedule if the script/special user is taking to long and the r...
by msatter
Sun Oct 11, 2020 3:41 pm
Forum: RouterBOARD hardware
Topic: Hex gr3 suddenly lost power
Replies: 5
Views: 268

Re: Hex gr3 suddenly lost power

There are two diodes D1 and D3 close to the power connector.

You can also try PPoE in if you have the cable for that.
by msatter
Sun Oct 11, 2020 3:26 pm
Forum: Scripting
Topic: Combine two IP4 address lists to create a /24 list
Replies: 4
Views: 223

Re: Combine two IP4 address lists to create a /24 list

:local AgregateMask 24 :local AgregatedList :local i :local j :local net :local ReversMask (32-$AgregateMask) :foreach i in=$list1 do={ :foreach j in=$list2 do={ :put "$i and $j" :set net (($i>>$ReversMask)<<$ReversMask) :set net ($net . "/$AgregateMask") :if ($j in $net) do={ :put "$j in $net" :if...
by msatter
Sun Oct 11, 2020 1:11 am
Forum: RouterOS v7 BETA
Topic: v7.2 beta & mt7621
Replies: 2
Views: 411

Re: v7.2 beta & mt7621

Those devices are released to be used with new bridge setup, that replaced the Master-Slave default, in RouterOS 6.xx and higher. Hardware switching (HW) is only active on the first bridge in ROS 6.xx+
by msatter
Sat Oct 10, 2020 8:37 pm
Forum: Forwarding Protocols
Topic: NTH load balancing
Replies: 63
Views: 1565

Re: NTH load balancing

A while ago I created a write-up about NTH;
viewtopic.php?f=2&t=159174&p=781975
by msatter
Sat Oct 10, 2020 5:48 pm
Forum: Scripting
Topic: Importing IP List from file
Replies: 5
Views: 284

Re: Importing IP List from file

Reading pure IP adresses is possible up to 64KB large files.

viewtopic.php?f=9&t=152632

I am on the moment busy to create backup/restore for adresslists present in the router and it will export a .RSC file that smaller than the normal export.
by msatter
Thu Oct 08, 2020 1:51 pm
Forum: General
Topic: Why I can't download latest version RouterOS from mikrotik.com/download?
Replies: 8
Views: 282

Re: Why I can't download latest version RouterOS from mikrotik.com/download?

I see nothing wrong and the Common Name is mikrotik.com and that is also present in the SAN:

DNS Name: *.mikrotik.com
DNS Name: mikrotik.com
by msatter
Tue Oct 06, 2020 11:43 pm
Forum: RouterBOARD hardware
Topic: Are the antennas on the RB4011 detachable?
Replies: 4
Views: 245

Re: Are the antennas on the RB4011 detachable?

Sounds right.

Image

Image
by msatter
Tue Oct 06, 2020 9:28 pm
Forum: RouterBOARD hardware
Topic: Are the antennas on the RB4011 detachable?
Replies: 4
Views: 245

Re: Are the antennas on the RB4011 detachable?

No, or you have to make your own cables.
Image
by msatter
Fri Oct 02, 2020 11:13 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 156
Views: 31188

Re: RB4011 and RB1100 AHx4 "bricks" randomly

Ask before you buy if you will receive revision 2 of the device.

viewtopic.php?f=2&t=149062&p=820138#p817223
by msatter
Wed Sep 30, 2020 1:52 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 267
Views: 68776

Re: v7.1beta2 [development] is released!

Friday is not a good day being the start of the Mikrotik weekend.

Sorry, couldn't resist.
by msatter
Sat Sep 26, 2020 2:55 am
Forum: Scripting
Topic: send script output to a file
Replies: 13
Views: 3808

Re: send script output to a file

Many many many thanks! I was looking for a way to write LARGE files for a long long time. This also works in the 6.4X version of ROS. You can test your code easier in the Terminal and here I save a very lean import file for an address list: :execute {:put "script - function - comment"; /ip firewall ...
by msatter
Sat Sep 26, 2020 12:31 am
Forum: Beginner Basics
Topic: Command aliases
Replies: 7
Views: 446

Re: Command aliases

:global domail do={/system script run wrme} on-error={log warning "Mail could not be send"};

$domail;

https://wiki.mikrotik.com/wiki/Manual:S ... #Functions
by msatter
Mon Sep 21, 2020 3:26 pm
Forum: General
Topic: How to obtain inventory/usage of SFP modules?
Replies: 2
Views: 716

Re: How to obtain inventory/usage of SFP modules?

Showing only the interfaces where the default names contain "sfp": :foreach i in=([/interface ethernet find default-name~"sfp" ]) do={ :local iterfacename [/interface ethernet get $i default-name ] :/interface ethernet monitor $iterfacename once without-paging } And a bit shorter by skipping the usa...
by msatter
Mon Sep 21, 2020 12:50 am
Forum: General
Topic: hAP ac2 over heated vent holes mod
Replies: 16
Views: 938

Re: hAP ac2 over heated vent holes mod

I think MK should offer mesh cages for extra cooling. Normis could do it with a 3D printer while he is sleeping!!
Clinging it? ;-)
by msatter
Thu Sep 17, 2020 6:20 pm
Forum: General
Topic: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)
Replies: 30
Views: 1525

Re: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)

No when I look at the subject of this thread. There is a workaround wich can be used till the fix by Mikrotik trickels down to the other versions.

The topic linked to is tackling a different problem of ROS not able return a icmp 3-4 to the correct client when using IKEv2.
by msatter
Thu Sep 17, 2020 12:48 pm
Forum: Scripting
Topic: Built in function library
Replies: 82
Views: 32594

Re: Built in function library

This I am using to read up to 64KB from a file. Sadly always the first up to 64KB from a file. :local result [/tool fetch url=$url as-value output=user]; :if ($result->"downloaded" < 64) do={ :local data ($result->"data") If a file is bigger then that, then the result is not transferred to the array...
by msatter
Thu Sep 17, 2020 12:03 pm
Forum: Scripting
Topic: Built in function library
Replies: 82
Views: 32594

Re: Built in function library

What if you use multiple array's in the foreach? Till now I read/stores up to 64KB files using one array.
When one array is full then switch to the next one.
by msatter
Wed Sep 16, 2020 3:31 pm
Forum: General
Topic: Can't login here with my password from 12 September 2020
Replies: 4
Views: 331

Re: Can't login here with my password from 12 September 2020

False statement there about what passwords were "declared invalid". 1. My password had lower case and upper case characters + numbers and I also had to reset it. 2. I doubt that any forum stores passwords the way you think that are stored, it should be (almost) impossible to recover the plaintext p...
by msatter
Wed Sep 16, 2020 2:45 pm
Forum: RouterOS v7 BETA
Topic: Scripted firewall rule ordering fails
Replies: 7
Views: 315

Re: Scripted firewall rule ordering fails

It is not possible to use ordering sequence numbers in a script! These are only valid in terminal sessions, and only after a print command. When you do a print on the terminal, it shows you the lines with the numbers and at the same time builds a table of numbers and the corresponding line. Then yo...
by msatter
Wed Sep 16, 2020 2:33 pm
Forum: RouterOS v7 BETA
Topic: Scripted firewall rule ordering fails
Replies: 7
Views: 315

Re: Scripted firewall rule ordering fails

The "print without-paging" (runs in script) and comment tagging I have used in the past, however I am doing it differently by using "find dynamic" rule as list generator and it works as dream. I think it will also work when no dynamic rules are present and then it would be 0+2=2 add place-before=("$...
by msatter
Wed Sep 16, 2020 1:21 pm
Forum: General
Topic: Scripting/Testing workflow
Replies: 1
Views: 130

Re: Scripting/Testing workflow

If you use the search function you will find several topics about this. You can even scroll throught the script after it displays where the syntax is incorrect and correct it. Past in tertminal after pressing F5 (clearing window). Put your code between { and } and it will be not executed so you can ...
by msatter
Wed Sep 16, 2020 11:19 am
Forum: RouterOS v7 BETA
Topic: Scripted firewall rule ordering fails
Replies: 7
Views: 315

Re: Scripted firewall rule ordering fails

When I look at your result, the order is the same as you pushed it in, so try it in reverse order and see what the result is then.
by msatter
Wed Sep 16, 2020 12:03 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 156
Views: 31188

Re: RB4011 and RB1100 AHx4 "bricks" randomly

The build-time refects the build-time of the software and not the hardware.
by msatter
Tue Sep 15, 2020 9:41 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 156
Views: 31188

Re: RB4011 and RB1100 AHx4 "bricks" randomly

If there is no specific mention of the revision then you can assume that you have the first revision. Look also at the factory firmware number can be an indication but then you have to know the version that was shipped with the second revision.
by msatter
Tue Sep 15, 2020 10:21 am
Forum: Announcements
Topic: Expected down time for this forum SEPT 11
Replies: 42
Views: 4139

Re: Expected down time for this forum SEPT 11

Please stop implementing/releasing things at the end of the week or in the weekend because we have to wait then till the next week starts before Mikrotik can start fixing things!
by msatter
Mon Sep 14, 2020 12:07 pm
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 38
Views: 8329

Re: v6.46.7 [long-term] is released!

Shouldn't we be seeing the changelog from 6.45.9 to 6.46.7 not from 6.46.6 ? Going up a major version in a long-term release should be looked over a bit more carefully before we take the plunge. Yes, that would be logical. Mikrotik fought the Logic and Mikrotik won. Flawless victory. Lost buyers of...
by msatter
Mon Sep 14, 2020 12:04 pm
Forum: RouterBOARD hardware
Topic: hEX RB750Gr3 micro SD not recognized
Replies: 8
Views: 464

Re: hEX RB750Gr3 micro SD not recognized

And it sticks out so you can grab it, to take it out again.
by msatter
Mon Sep 14, 2020 11:50 am
Forum: General
Topic: CVE-2020-11881 PATCH [SOLVED]
Replies: 16
Views: 943

Re: CVE-2020-11881 PATCH [SOLVED]

Communication could use improvements on the side of Mikrotik. It is not lying but just not telling. - the fixed version was ready last week but that was not communicated with the CVE publishers. - in this thread Mikrotik should have written, "it was fixed last week and fix was released today". It is...
by msatter
Mon Sep 14, 2020 10:40 am
Forum: Scripting
Topic: help to solve issue in script " dns to address lists scripts " [SOLVED]
Replies: 8
Views: 467

Re: help to solve issue in script " dns to address lists scripts " [SOLVED]

You can optimize it a bit if you leave out the check and logging and then I can compress the write to one line: :foreach i in=[/ip dns cache find name~"(facebook|youtube)" ] do={ :do {/ip firewall address-list add address=[/ip dns cache get $i data] list=restricted comment=[/ip dns cache get $i name...
by msatter
Mon Sep 14, 2020 10:23 am
Forum: General
Topic: Blocking Facebook, Tiktok and other websites
Replies: 7
Views: 355

Re: Blocking Facebook, Tiktok and other websites

That was in 2012 and now 'they' use HTTPS instead of HTTP.
by msatter
Sat Sep 12, 2020 8:41 pm
Forum: Scripting
Topic: save export to variable
Replies: 16
Views: 15560

Re: save export to variable

Files up to 64KB can read into an array.

viewtopic.php?f=9&t=152632&p=759468&hilit=cidr#p759468
by msatter
Sat Sep 12, 2020 8:33 pm
Forum: General
Topic: A place for poetry
Replies: 46
Views: 182658

Re: A place for poetry

Poultry hope to find
Llama found
glasses needed
by msatter
Sat Sep 12, 2020 6:13 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 571

Re: Routing mark bug?

I have looked at your other thread. You stated that you created a interface vpn with address 10.121.241.126. You need to use NAT then to set she source address because otherwise the packet can't find the way back to your VPN starting point. By directly routing you also set a route back. This not my ...
by msatter
Sat Sep 12, 2020 4:00 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

ehmmmm I did not see that earlier. You are a gmail user (port 587, normal 25) so you should use inbound The only secure documented method of sending mail via Googles SMTP servers for non-GSuite users is via smtp.gmail.con:587 with TLS I can't get anything on port 587 for gmail.com https://network-t...
by msatter
Sat Sep 12, 2020 3:55 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

Else go the SMTP/25 way.
Plain text / no encryption?
I think that it is only the checking on Mikrotiks side that is disabled. Used it before on IKEv2 connections of which I had no certificates installed.
by msatter
Sat Sep 12, 2020 3:42 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

ehmmmm I did not see that earlier. You are a gmail user (port 587, normal 25) so you should use inbound....if I am correct.

Use this server: aspmx.l.google.com and if not works try it with TLS off.

Else go the SMTP/25 way.
by msatter
Sat Sep 12, 2020 3:36 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

CRL seems only be possible for certificates you generate on your Router.

This what I remembered reading your posting: viewtopic.php?f=21&t=163482&p=805719&hilit=crl#p805719
by msatter
Sat Sep 12, 2020 3:22 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 571

Re: Routing mark bug?

I have tested it and I can use ping from the tools menu and I put in the routing mark and source addres and I can block traffic by blackholing it. Setting: distance=1 dst-address=0.0.0.0/0 routing-mark=test gateway=pppoe-out Export: /ip route add distance=1 routing-mark=test gateway=pppoe-out type=b...
by msatter
Sat Sep 12, 2020 2:56 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

I have gone to my computer and looked up the used certificate, both are using the same root cert depth=2 OU = GlobalSign Root CA - R2, O = GlobalSign, CN = GlobalSign . The root cert is on the first line. I am not a expert on this and Mikrotik checking a cert is a also a PITA. openssl s_client -conn...
by msatter
Sat Sep 12, 2020 2:16 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

Delivering a e-mail to them is a PITA and the best chance is using the relay.

In the middle of the linked page is a PEM file and have a look at that.

I can't test anything being on my tablet.
by msatter
Sat Sep 12, 2020 1:40 pm
Forum: Scripting
Topic: Googlevideo DNS to Address-list
Replies: 8
Views: 540

Re: Googlevideo DNS to Address-list

The number of IP addresses are limited but the names are "endless".

https://discourse.pi-hole.net/t/how-do- ... be/253/145
by msatter
Sat Sep 12, 2020 1:34 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

Have you tried: smtp-relay.gmail.com
by msatter
Sat Sep 12, 2020 1:20 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 571

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

There are no certificates present by default in Mikrotik routers so you have to install them to use TLS.

https://support.google.com/a/answer/6180220?hl=en
by msatter
Sat Sep 12, 2020 12:55 pm
Forum: General
Topic: Can't login here with my password from 12 September 2020
Replies: 4
Views: 331

Can't login here with my password from 12 September 2020

The forum was moved and the day after that the 'forum' cache was cleared by Mikrotik and so all older passwords not containing a capital and number were declared invalid. https://forum.mikrotik.com/viewtopic.php?f=21&t=166059 You have to reset your now invalid password and create a new one with the ...
by msatter
Sat Sep 12, 2020 12:29 pm
Forum: Announcements
Topic: Expected down time for this forum SEPT 11
Replies: 42
Views: 4139

Re: Expected down time for this forum SEPT 11

Darn I had to change my password because it needs now a capital and a number in it after the cleaning of the PHP/forum cache, I assume. Before that I could login. If you have a problem during login you can contact the board administrator....yeah works great. The board administrator contact page has ...
by msatter
Sat Sep 12, 2020 1:52 am
Forum: RouterBOARD hardware
Topic: hEX RB750Gr3 micro SD not recognized
Replies: 8
Views: 464

Re: hEX RB750Gr3 micro SD not recognized

Ehmmm I recovered my card by formatting it in a photo camera. Then could use it again.

Found my posting about that: viewtopic.php?f=2&t=149609&p=736646&hilit=card#p736646
by msatter
Fri Sep 11, 2020 11:14 pm
Forum: Beginner Basics
Topic: How can block all except Address list?
Replies: 11
Views: 400

Re: How can block all except Address list?

Assertive?
by msatter
Fri Sep 11, 2020 11:08 pm
Forum: Announcements
Topic: Expected down time for this forum SEPT 11
Replies: 42
Views: 4139

Re: Expected down time for this forum SEPT 11

So, are we having a Mikrotik weekend?
by msatter
Fri Sep 11, 2020 10:28 pm
Forum: Beginner Basics
Topic: How can block all except Address list?
Replies: 11
Views: 400

Re: How can block all except Address list?

I was talking source address-list. ;-)

Input would "lock" you out of the router. Forward would lock you out from the world outside the router.

BTW your avatar is donkey and not a llama who have no upper theeth. Llama was expected.
by msatter
Fri Sep 11, 2020 9:12 pm
Forum: Beginner Basics
Topic: How can block all except Address list?
Replies: 11
Views: 400

Re: How can block all except Address list?

If you are on source addresses then don't forget to include yoursef or you will have to use MAC communication to the router to control it.
by msatter
Thu Sep 10, 2020 9:24 pm
Forum: Announcements
Topic: Expected down time for this forum SEPT 11
Replies: 42
Views: 4139

Re: Expected down time for this forum SEPT 11

So, on 9-11 we are going to update the forum. Great timing.

I remember it as yesterday that we sat in front a small TV in the firm with the staff looking, with disbelieve what was happening in New York.
by msatter
Thu Sep 10, 2020 1:45 pm
Forum: Announcements
Topic: Expected down time for this forum SEPT 11
Replies: 42
Views: 4139

Re: Expected down time for this forum SEPT 11

It will bit earlier when you are on CET at 11:00 or GMT 10:00 (both still on summertime)

Advantage it will also be ready on a earlier time. ;-)
by msatter
Mon Sep 07, 2020 5:08 pm
Forum: Announcements
Topic: WinBox v3.27 released!
Replies: 70
Views: 8691

Re: WinBox v3.27 released!

I see it again on on my other router.

Half hidden bottom line when the counter in the bottom bar is a even number, when the counter is a uneven number window will scroll up making all lines visible again.
by msatter
Sun Sep 06, 2020 6:50 pm
Forum: General
Topic: 2nd DNS is not working in CRS125-24G-1S-2HnD
Replies: 1
Views: 166

Re: 2nd DNS is not working in CRS125-24G-1S-2HnD

Only when the first one does not answers several times (about 15 times) then the second DNS is used till that one does not answers.

Each client uses it's own counter. If your Mikrotik is the sole DNS for the clients then you have one counter.
by msatter
Sun Sep 06, 2020 3:19 pm
Forum: General
Topic: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)
Replies: 30
Views: 1525

Re: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)

The titile stated that the connection are killed because of the short TTL of the DNS resolve. You have problem that your VPN connection is slowing down and that is a different problem.
by msatter
Sun Sep 06, 2020 12:03 pm
Forum: General
Topic: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)
Replies: 30
Views: 1525

Re: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)

i have same problem with surfshark ikev2 , every few second killing ikev.. the getting new 1

hope mikrotik fix it.
Did you read the thread?
by msatter
Sat Sep 05, 2020 9:50 am
Forum: Scripting
Topic: scripting with for each loop
Replies: 10
Views: 2763

Re: scripting with for each loop

{ :local fileName :foreach fileCounter in=[/file find name~"routeros-mipsbe"] do={ :set $fileName [/file get $fileCounter name] :do { /tool fetch mode=ftp upload=no address=x.x.x.x port=x user="x" password="x" src-path="/$fileName" dst-path="/$fileName" keep-result=yes :log info "Copied file: $file...
by msatter
Fri Sep 04, 2020 10:48 pm
Forum: Scripting
Topic: scripting with for each loop
Replies: 10
Views: 2763

Re: scripting with for each loop

My adaptation needs a extra "}" in the last line.

You have to check what value is in $fileName:
:set $fileName [/file get $fileCounter name]; :put $fileName;
So you can check if yuo have to also a "/" in front of the src-path

src-path="/$fileName"
by msatter
Fri Sep 04, 2020 8:05 pm
Forum: Scripting
Topic: scripting with for each loop
Replies: 10
Views: 2763

Re: scripting with for each loop

{ :local fileName; :foreach fileCounter in=[/file find where name~"routeros-mipsbe"] do={ :set $fileName [/file get $fileCounter name]; /tool fetch mode=ftp upload=no address=x.x.x.x port=x user="x" password="x" src-path=$fileName dst-path=$fileName keep-result=yes } I can't test it and it is way o...
by msatter
Fri Sep 04, 2020 7:56 pm
Forum: Scripting
Topic: scripting with for each loop
Replies: 10
Views: 2763

Re: scripting with for each loop

I only brought forward a logical error.

The next error you make is using foreach and it's counter is changed in the loop to an other value.

Thirdly, you can't use variable names that are already used by RouterOS.

You should check you code better and make you variable names unique.
by msatter
Fri Sep 04, 2020 3:04 pm
Forum: Scripting
Topic: scripting with for each loop
Replies: 10
Views: 2763

Re: scripting with for each loop

Hello, Could you please provide me your script, as Im working on my own with no success, below my script: :local filename; :foreach filename in=[/file find where name~"routeros-mipsbe"] do={ :set $filename [/file get $file name]; /tool fetch mode=ftp upload=no address=x.x.x.x port=x user="x" passwo...
by msatter
Fri Sep 04, 2020 2:55 pm
Forum: Announcements
Topic: WinBox v3.27 released!
Replies: 70
Views: 8691

Re: WinBox v3.27 released!

Another issue that I see now I use 3.27 for a while (but I think it has been introduced in 3.22 or later): When the log window is displayed, and the number of lines in the window is not a whole number, new log lines at the bottom are not readable. They become readable when the window is scrolled do...
by msatter
Fri Sep 04, 2020 12:29 pm
Forum: General
Topic: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)
Replies: 30
Views: 1525

Re: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)

Fixing MSS for forward packages /ip firewall mangle add action=change-mss chain=forward new-mss=1360 protocol=tcp tcp-flags=syn tcp-mss=1453-65535 There is a better way than this just limiting to a MTU of 1360 There is a problem of RouterOS not sending the ICMP 3-4 to the client using a IKEv2 conne...
by msatter
Thu Sep 03, 2020 6:58 pm
Forum: Announcements
Topic: v6.47.3 [stable] is released!
Replies: 50
Views: 9871

Re: v6.47.3 [stable] is released!

Of course, tried it with two different Mikoritik product and different fw version, everywhere do the same. In other branded network device (like TPlink, Dahua) works well but no more in Mikrotik. Three pieces of SFPs was in the device while firware upgrade was running, all of these do the same. Did...
by msatter
Thu Sep 03, 2020 4:17 pm
Forum: Announcements
Topic: v6.47.3 [stable] is released!
Replies: 50
Views: 9871

Re: v6.47.3 [stable] is released!

Did you tried that SFP in a other device? It could be read error.

Or did you downgraded to the previous version to see if the SFP worked again?
by msatter
Thu Sep 03, 2020 1:13 am
Forum: Scripting
Topic: How to add color to output
Replies: 2
Views: 197

Re: How to add color to output

by msatter
Wed Sep 02, 2020 9:53 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 23792

Re: WireGuard Released !

If Mikrotik had made a short manual then that could have avoided some irritations. I would love to see that Mikrotik would update their opening post with information that came forward in posting in that thread. And not have the users find out on their selves where that additional information can be ...
by msatter
Wed Sep 02, 2020 4:02 pm
Forum: Beginner Basics
Topic: HEX Poe Block Diagram
Replies: 2
Views: 212

Re: HEX Poe Block Diagram

All the traffic, that is not local (switched), on eth1-eth5 share a 1Gb/s line. The SFP has its on dedicated 1Gb/s line. I think bonding won't help you and as I wrote, local traffic is switched and does not need to go through the CPU unless is routed or exits through the SFP and vise versa. Exit poi...
by msatter
Tue Sep 01, 2020 8:45 pm
Forum: Announcements
Topic: WinBox v3.25 released!
Replies: 68
Views: 5934

Re: WinBox v3.25 released!

I faced the same problem. When I downgraded to 3.34 everything works fine... When I update to Winbox v3.25, on the Hotspot>Active tab, everything is ok, the connection is ok. But in the event when turn to Hotspot>Host tab, everything is gone wrong, everybody in the hotspot has been disconnected, th...
by msatter
Tue Sep 01, 2020 7:39 pm
Forum: General
Topic: IPSec IKEv2 to NordVPN - can't go higher than 42/5 Mbps on powerful hardware, despite a WAN capable of much more
Replies: 2
Views: 267

Re: IPSec IKEv2 to NordVPN - can't go higher than 42/5 Mbps on powerful hardware, despite a WAN capable of much more

I run close to 500 down and 600+ on the up on my 4011. So the 4011 is not the problem. There could be a bottleneck from you ISP to the VPN server you use from NordVPN. MTU can be a problem and you can test that by pressing the preview button when you are creating a posting here. Slow or no preview t...
by msatter
Tue Sep 01, 2020 12:10 pm
Forum: Announcements
Topic: v6.47.2 [stable] is released!
Replies: 90
Views: 16334

Re: v6.47.2 [stable] is released!

Hmmmm Winbox traffic makes more sence to me than Winbox network traffic . The Wiki label indeed shows that the green box is only shows traffic between the addressed router/device and Winbox. However it can be mistaken as CPU , not in any way accurate, because that also increases to generate the traf...
by msatter
Mon Aug 31, 2020 6:54 pm
Forum: Announcements
Topic: v6.47.2 [stable] is released!
Replies: 90
Views: 16334

Re: v6.47.2 [stable] is released!

It's still not about CPU: https://forum.mikrotik.com/viewtopic.php?f=2&t=27814&p=134483#p134483 That was more than a decade ago and that it is a long time. I can reproduce every time at any time so Mikrotik must be playing a cruel trick on me. The with multiple core processors a little total load o...
by msatter
Mon Aug 31, 2020 2:42 pm
Forum: Announcements
Topic: v6.47.2 [stable] is released!
Replies: 90
Views: 16334

Re: v6.47.2 [stable] is released!

Do anyone experience opening the address-list in Winbox causes the cpu to get loaded? I mean the green graph keeps spiking per second and the cpu stucks at 1%-2% without throughput load. Even turning off all entries in address-list it still happens also turning off all my firewall and mangle rules....
by msatter
Mon Aug 31, 2020 10:52 am
Forum: Scripting
Topic: help to solve issue in script " dns to address lists scripts " [SOLVED]
Replies: 8
Views: 467

Re: help to solve issue in script " dns to address lists scripts " [SOLVED]

An example and it contains the assumption that the IP address is labeled address but it data in real: :foreach i in=[/ip dns cache all find where name~"tiktok" && static=no] do={ :local tmpIP [/ip dns cache get $i data] if ([:len [/ip firewall address-list find where address=$tmpIP list=tiktok-hosts...
by msatter
Mon Aug 31, 2020 10:21 am
Forum: Announcements
Topic: WinBox v3.25 released!
Replies: 68
Views: 5934

Re: WinBox v3.25 released!

A it's the other - and + keys that we normally use. Never thought of that being different but clearly it is here.

It now works even on a keyboard with a numeric keypad using the other keys. While holding the CTRL key you tend to use the outer - and + keys on the keyboard.
by msatter
Mon Aug 31, 2020 10:10 am
Forum: General
Topic: Forum redirect to https://forum.mikrotik.com:80/
Replies: 7
Views: 463

Re: Forum redirect to https://forum.mikrotik.com:80/

Testing testing testing if the weekend is over.

Update: it's over and it works again. :-) or :-( depending on your view.
by msatter
Sun Aug 30, 2020 5:25 pm
Forum: Scripting
Topic: help to solve issue in script " dns to address lists scripts " [SOLVED]
Replies: 8
Views: 467

Re: help to solve issue in script " dns to address lists scripts " [SOLVED]

Try this:
:foreach i in=[/ip dns cache find name~("facebook"|"youtube") type="A"] 
by msatter
Sun Aug 30, 2020 1:26 pm
Forum: General
Topic: TLS problem with this forum since a few hours.
Replies: 14
Views: 691

Re: TLS problem with this forum since a few hours.

I believe that I can speak for many wishing you a fasttrack recovery.
by msatter
Sun Aug 30, 2020 10:48 am
Forum: General
Topic: TLS problem with this forum since a few hours.
Replies: 14
Views: 691

Re: TLS problem with this forum since a few hours.

You misunderstood my question. It was aimed towards administrators, it was meant like who of the admins does care... I wrote in a other thread that it was a typical "Mikrotik weekend" just like when I am ill...always in the weekend....and not from intoxication as one of your smart-asses is going to...
by msatter
Sat Aug 29, 2020 10:06 pm
Forum: Beginner Basics
Topic: Version mismatch
Replies: 4
Views: 150

Re: Version mismatch

You could. Atleast if you get to terms with the different function op a Operating system and Firmware. OS is ROS snd version 46.7.1 Firmware is used to start the router and ROS is running on top off that. Those two can have different versions like a older BIOS in your PC and running the latest Windo...
by msatter
Sat Aug 29, 2020 1:07 pm
Forum: General
Topic: Again surfshark and vpn connecting problems/performance
Replies: 8
Views: 496

Re: Again surfshark and vpn connecting problems/performance

Hello, setting a local dns name with the static ip of the manually found ip adress of the surfshark.vpn-server is working... but i didnt find any information how to setup the scheduled script to renew this static dns by RB start and when dropping the line f.ex.... any idea ? shogunx can you maybe c...
by msatter
Sat Aug 29, 2020 10:42 am
Forum: General
Topic: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)
Replies: 30
Views: 1525

Re: IKEv2 SA killed after 5 seconds due to short DNS TTL

I have opened a support ticket with Surfshark, they are slow but the do respond. So far they have not been very helpful though, just asking me to try different DNS servers and send them screenshots of ipleak.net. funnily enough, I worked out a similar work around as msatter suggested regarding the ...
by msatter
Sat Aug 29, 2020 1:34 am
Forum: RouterOS v7 BETA
Topic: Not a fan of the new (/) slash notation.
Replies: 16
Views: 887

Re: Not a fan of the new (/) slash notation.

That, if I understand correctly what you mean, would have to search through all available locations in config three, and I'm not sure if they are unique enough for this to work well. If nothing else, you have same subgroups in /ip and /ipv6. Pressing TAB will show you then /ipv6 firewall nat. Only ...
by msatter
Fri Aug 28, 2020 10:18 pm
Forum: RouterOS v7 BETA
Topic: Not a fan of the new (/) slash notation.
Replies: 16
Views: 887

Re: Not a fan of the new (/) slash notation.

Slash at the beginning works in older versions too. Question is about slashes in between, instead of original spaces. To be clear, I don't have anything against them, I'm used to spaces, but I can get used to slashes too, it's no big deal. I'm just wondering why are slashes better (I guess MikroTik...
by msatter
Fri Aug 28, 2020 9:02 pm
Forum: General
Topic: TLS problem with this forum since a few hours.
Replies: 14
Views: 691

TLS problem with this forum since a few hours.

When submitting a posting or change then I get a redirect to forum.mikrotik.com:80 and the posting/change is made but I don't get returned to the expected page anymore. When I remove ":80" in the URL then I get an page that I expected. An error occurred during a connection to forum.mikrotik.com:80. ...
by msatter
Fri Aug 28, 2020 8:50 pm
Forum: RouterOS v7 BETA
Topic: Not a fan of the new (/) slash notation.
Replies: 16
Views: 887

Re: Not a fan of the new (/) slash notation.

/I Do Like This - so I get to the correct place without bothering what place I am right now.
by msatter
Fri Aug 28, 2020 8:47 pm
Forum: Announcements
Topic: WinBox v3.25 released!
Replies: 68
Views: 5934

Re: WinBox v3.25 released!

What is the advantage (uses of), "* added support for DNS names in address type fields;" ? It is a very nice addition and makes it easier to use external IP addresses in rules/line without first to have resolve it manually. It is a one-time-resolve and if you have to use dynamic then a addresslist ...
by msatter
Fri Aug 28, 2020 7:44 pm
Forum: Announcements
Topic: WinBox v3.25 released!
Replies: 68
Views: 5934

Re: WinBox v3.25 released!

It seems then that we have to wait till after this weekend before we know what Mikrotik means with that.

I noticed that the CTRL+ or CTRL- did not work with me.
by msatter
Fri Aug 28, 2020 6:16 pm
Forum: Announcements
Topic: WinBox v3.25 released!
Replies: 68
Views: 5934

Re: WinBox v3.25 released!

What is the advantage (uses of), "* added support for DNS names in address type fields;" ? It is a very nice addition and makes it easier to use external IP addresses in rules/line without first to have resolve it manually. It is a one-time-resolve and if you have to use dynamic then a addresslist ...
by msatter
Fri Aug 28, 2020 3:46 pm
Forum: General
Topic: IKEv2 SA killed after 5 seconds due to short DNS TTL (Surfshark)
Replies: 30
Views: 1525

Re: IKEv2 SA killed after 5 seconds due to short DNS TTL

Cname can only point to an other entry in the static DNS of your router. External gives that error "failure: dns name exists, but no appropriate record". I am a long time requester for having a minimal TTL in the options of the DNS but it was a long an fruitless quest. In the meantime I have a own D...
by msatter
Fri Aug 28, 2020 3:31 pm
Forum: Announcements
Topic: WinBox v3.25 released!
Replies: 68
Views: 5934

Re: WinBox v3.25 released!

What is the advantage (uses of), "* added support for DNS names in address type fields;" ? It is a very nice addition and makes it easier to use external IP addresses in rules/line without first to have resolve it manually. It is a one-time-resolve and if you have to use dynamic then a addresslist ...
by msatter
Wed Aug 26, 2020 3:00 pm
Forum: Scripting
Topic: Check if list is empty
Replies: 2
Views: 205

Re: Check if list is empty

Inside the on-error you can use :if-do-else so check if the description is presentin the current country-list and if not adapt your message.
by msatter
Tue Aug 25, 2020 5:35 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 267
Views: 68776

Re: v7.1beta2 [development] is released!

Upgraded my RB3011 this morning to 7.1beta 2. I reset the router before upgrading and only configured it with a WAN connection to upgrade to Beta2. Upgrade seemed to go okay so I set about configuring it correctly. First issue was renaming an interface (ether1 renamed to WAN) would result in a rebo...
by msatter
Tue Aug 25, 2020 12:43 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 267
Views: 68776

Re: v7.1beta2 [development] is released!

ROS: 7.1beta2

2) Unable to set peer Endpoint port in winbox. CLI works

4) IPv4 routes are deleted immediately after disabling (winbox)
Number two was already mentioned in this thread. Number four is cosmetic and on re-entering the route window they are displayed as disabled.
by msatter
Mon Aug 24, 2020 1:51 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 23792

Re: WireGuard Released !

I just noticed the the manual by Rick Frey also states the 51820 UDP port and maybe he tried already.

Update: it appears that UDP/51820 is the default server port for Wireguard.
by msatter
Sun Aug 23, 2020 10:52 pm
Forum: RouterOS v7 BETA
Topic: v7
Replies: 2
Views: 610

Re: v7

Thank you for letting us know. There is by the way a thread where you can more specific:

viewtopic.php?f=1&t=165248
by msatter
Sun Aug 23, 2020 10:50 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 267
Views: 68776

Re: v7.1beta2 [development] is released!

Request: make it possible to ignore the provided dynamic DNS by the VPN providers, also for WireGuard?
by msatter
Sun Aug 23, 2020 10:49 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 23792

Re: WireGuard Released !

I can't test it myself on the moment. I have installed the NordVPN client to see which port NordLynx (Wireguard version by NordVPN) and I got destination port UDP/51820 each time.

Could someone having a NordVPN account test if the 7.1beta2 can connect to NordVPN?
by msatter
Sat Aug 22, 2020 9:54 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 23792

Re: WireGuard Released !

smatter...I had to look that one up ;-)
by msatter
Sat Aug 22, 2020 7:20 pm
Forum: General
Topic: WireGuard Released !
Replies: 41
Views: 23792

Re: WireGuard Released !

Mikrotik did not put out any kind of documentation on Wireguard except it was now in 7.1beta2.

Any documentation, even in a general topic, over Wireguard on a Miktotik is welcome.
by msatter
Fri Aug 21, 2020 9:31 pm
Forum: Beginner Basics
Topic: Command aliases
Replies: 7
Views: 446

Re: Command aliases

That easy ;-) I was expecting some kind of DateAdd kind of function.. Thx! It was not that easy for me because the .id appeared not correct so I had a search and a peek at a other script: https://forum.mikrotik.com/viewtopic.php?f=9&t=151953&p=804911&hilit=%2Flog+get#p804911 My version now is compa...
by msatter
Fri Aug 21, 2020 5:48 pm
Forum: Beginner Basics
Topic: Command aliases
Replies: 7
Views: 446

Re: Command aliases

:put [/log find time>([/system clock get time]-15m)];
This will show you the .id of the log-lines in the last 15 minutes but I am out on the moment to have the lines printed. Maybe someone else can do that or I will do that a later moment.
by msatter
Fri Aug 21, 2020 3:55 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 267
Views: 68776

Re: v7.1beta2 [development] is released!

Just tried this version and had to go back to 6.4x. Bug [SUP-15464] which is partly fixed in 6.4x is still present in 7.1x (retain correct MTU PPPoE through a SFP on a 4011) restarting the SFP does not help. Changing the MTU manually on a interface crashes the router (tested it on a 4011 and 750-Gr2...
by msatter
Thu Aug 20, 2020 12:14 am
Forum: General
Topic: IKEv2 between MikroTiks, sides switching, initiator <> responder
Replies: 13
Views: 1730

Re: IKEv2 between MikroTiks, sides switching, initiator <> responder

So I switched off my DPD on the client-side (I am using VPN a provider) and that worked, the Side is now staying initiator. I saw the renew of the connection and the state column in Active Peers stated something like: message 1 renew and it stayed about 15 seconds that way and then it stated establi...
by msatter
Wed Aug 19, 2020 1:03 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

My Winbox crash on start, is gone with Beta 27. This happened when I added/deleted/changed a column to any viewing box. Many thanks.
by msatter
Tue Aug 18, 2020 10:17 pm
Forum: Scripting
Topic: script to check if dns is running
Replies: 5
Views: 421

Re: script to check if dns is running

You want to switch back your local resolver is active again. I check if the domain "pi.hole" resolves and a external DNS server does know that domain. To avoid the stopping of the script I used also the :do but at the beginning. When the internal DNS does not react or throws a not found then the scr...
by msatter
Tue Aug 18, 2020 10:07 pm
Forum: General
Topic: IKEv2 between MikroTiks, sides switching, initiator <> responder
Replies: 13
Views: 1730

Re: IKEv2 between MikroTiks, sides switching, initiator <> responder

As earlier written by me I have the same behaviour but then after between 15 and 35 minutes.

Like you I made a log but that did not show anything sticking out. It only happens with one VPN provider. It happens on my on my 4011 and hEX-S so platform independable.
by msatter
Mon Aug 17, 2020 8:32 pm
Forum: SwOS
Topic: CRS317-1G-16S+ high temp
Replies: 1
Views: 511

Re: CRS317-1G-16S+ high temp

You are not alone with this: viewtopic.php?f=3&t=132258&p=811167#p727994

I did not know that the fans would ref up to 8500RPM andthat must be a lot of noise.
by msatter
Mon Aug 17, 2020 12:51 pm
Forum: RouterBOARD hardware
Topic: SFP module is extremely hot
Replies: 45
Views: 19146

Re: SFP module is extremely hot

Have look at these: https://www.blacknoise.com/site/en/prod ... m.php#tab1

The 317 hasfour leads and that is to regulate the rotating speed. The I linked to has only three leads.
by msatter
Sun Aug 16, 2020 10:32 pm
Forum: General
Topic: Packets not return from VPN
Replies: 3
Views: 868

Re: Packets not return from VPN

Switch Fasttrack off.
by msatter
Sat Aug 15, 2020 11:01 pm
Forum: RouterBOARD hardware
Topic: SFP module is extremely hot
Replies: 45
Views: 19146

Re: SFP module is extremely hot

That one is totally passive cooled. You see even a sticker on top of the SFP cage that may block one of the venting holes. I used a small 12V fan that is powered by byte tapping in on the 12V poser supply for my 4011...he is on diet you see. I use plugs for putting screws into a wall and this one ar...
by msatter
Sat Aug 15, 2020 11:20 am
Forum: RouterBOARD hardware
Topic: SFP module is extremely hot
Replies: 45
Views: 19146

Re: SFP module is extremely hot

Pictures you can find all over the internet. duck.com or yandex.com and press on the word/button "images" and before you search on the exact product name of you 1009 like: CCR1009-7G-1C-1S+PC The SFP cages have holes in the top that let hot air out and you should not cover all with heatsinks. Also a...
by msatter
Fri Aug 14, 2020 10:56 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

Using a non 6.48 is no problem. It is a problem caused by 6.48beta12 and it does corrupt the saved sessions by Winbox. I use Winbox 3.24 64 bits.
by msatter
Fri Aug 14, 2020 8:16 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

I want to change the shown collumns in Winbox and that it survive than the current session. Not blowing up in my face each time so that I have to restore a back session and start from scratch. My orignal session was destroyed by 6.48 so I had to use one from a different router to have atleast some c...
by msatter
Fri Aug 14, 2020 4:19 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

More than a month without an update of the 6.48 beta. That is a long time.
by msatter
Fri Aug 14, 2020 1:42 pm
Forum: Scripting
Topic: help get wrong result [SOLVED]
Replies: 6
Views: 1016

Re: help get wrong result [SOLVED]

Great news. Really good to see that you solved it on your 'own'. ;-)
by msatter
Thu Aug 13, 2020 11:43 am
Forum: General
Topic: Router "blocks" some SIP INVITES but not all - misconfiguration or bug? [SOLVED]
Replies: 10
Views: 1855

Re: Router "blocks" some SIP INVITES but not all - misconfiguration or bug? [SOLVED]

Do you stll have your modem in bridge mode (modem only)?
by msatter
Wed Aug 12, 2020 11:20 pm
Forum: Scripting
Topic: help get wrong result [SOLVED]
Replies: 6
Views: 1016

Re: help get wrong result [SOLVED]

:local downquotamb [:tonum [:pick $comment 0 3]]
:local downquota ($downquotamb * 1000)
Something like that. I can't test it on the moment but this what the manual stated.

I did not know that I had an other brother. ;-)
by msatter
Wed Aug 12, 2020 9:33 pm
Forum: Scripting
Topic: help get wrong result [SOLVED]
Replies: 6
Views: 1016

Re: help get wrong result [SOLVED]

:tonum and () instead of [] for arithmetic stuff.
by msatter
Wed Aug 12, 2020 7:57 pm
Forum: RouterBOARD hardware
Topic: SFP module is extremely hot
Replies: 45
Views: 19146

Re: SFP module is extremely hot

Kewl, literally, so the fan sucks air from inside the unit to the outside?
How do you power the fan?
There are two fan connectors. I assume the two little fans als suck the air out of the router but a higher sound level.

Image
by msatter
Wed Aug 12, 2020 4:25 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

ROS 6.48Beta23 should bring fix for CRS354 switches. And it is "unpublic" release.... Do you know if there is also a Beta48 fix for the crashing Winbox (64) the next time after you alter any columns in Winbox? Before testing backup your Winbox config files because the one altered has become unusable.
by msatter
Wed Aug 12, 2020 2:05 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

what about 6.48Beta23 ??
Context?
by msatter
Wed Aug 12, 2020 1:57 pm
Forum: Beginner Basics
Topic: SFP overheating
Replies: 2
Views: 513

Re: SFP overheating

Any MikroTik device with active cooling that has SFP+ ports can now be used without installing any optical fiber, just plug the S+RJ10 and your network can be upgraded to 10 Gbps, making it ready for the next generation of RJ45 hardware. From the product page and do you have a active coolded device...
by msatter
Tue Aug 11, 2020 5:51 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta1 [development] is released!
Replies: 103
Views: 41098

Re: v7.1beta1 [development] is released!

RB1100AHx4 does not upgrade.

RB1100AHx4b7.1.PNG
See: viewtopic.php?f=1&t=163957#p808620
by msatter
Tue Aug 11, 2020 1:22 pm
Forum: RouterBOARD hardware
Topic: Usage GPON module SFP in Spain
Replies: 438
Views: 111530

Re: Usage GPON module SFP in Spain

Did you find the temperature of the SFP combined with the RB760igs too high when using it? It felt very hot, unable to touch it
viewtopic.php?f=3&t=132258&p=670687&hil ... nk#p671105
by msatter
Mon Aug 10, 2020 4:15 pm
Forum: Scripting
Topic: If else commands scripting.
Replies: 31
Views: 29530

Re: If else commands scripting.

This rather specific and you better open a separate topic about that. You have tell which way of communication you want to use and which specific information you want to know. With what wrote you can make any selection and if some similar lines have to be treathed differently only marking them in co...
by msatter
Mon Aug 10, 2020 3:06 pm
Forum: Scripting
Topic: If else commands scripting.
Replies: 31
Views: 29530

Re: If else commands scripting.

You removed your previous posting and this will do what you asked for. Replace the lists on lines with only one of them active and and the last code line set all the lines that have no address-list already present. { /ip firewall nat set [find action=masquerade chain=srcnat src-address-list!="" dst-...
by msatter
Mon Aug 10, 2020 2:37 pm
Forum: Scripting
Topic: If else commands scripting.
Replies: 31
Views: 29530

Re: If else commands scripting.

How do you recognize those different NAT lines? You can put several "set" lines in a sequence however that will make things much more tricky. I have added a extra set to my earlier post which only changes lines where there are no src-address-list active on the moment. Tip: you can set a identifier t...
by msatter
Mon Aug 10, 2020 2:07 pm
Forum: Scripting
Topic: If else commands scripting.
Replies: 31
Views: 29530

Re: If else commands scripting.

{ /ip firewall nat set [find action=masquerade chain=srcnat] src-address-list="AllowedSrc" dst-address-list="AllowedDst" } My guess and have RouterOS do the work. If dst/src address already exists then those are overwritten by the new values. If you only want to apply to lines that have no src-addr...
by msatter
Sun Aug 09, 2020 11:33 pm
Forum: General
Topic: change the language [SOLVED]
Replies: 10
Views: 2007

Re: change the language [SOLVED]

Work in progress:
https://help.mikrotik.com/docs/
Still updated but going to be replaced by link above:
https://wiki.mikrotik.com
by msatter
Sat Aug 08, 2020 1:41 pm
Forum: RouterBOARD hardware
Topic: RB4011 ethernet flow control
Replies: 3
Views: 1009

Re: RB4011 ethernet flow control

From the datasheet; 1Mbit SRAM for packet buffer.
by msatter
Fri Aug 07, 2020 11:13 pm
Forum: Scripting
Topic: Get only integers from array of strings
Replies: 3
Views: 807

Re: Get only integers from array of strings

This is the script: { :while ([:len $output]!=0) do={ :if ([:pick $output 0 [:find $output "\n"]]~"^[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}") do={ :do {:put ([:pick $output 0 [:find $output "\n"]].$cidr)} on-error={} } :set $output [:pick $output ([:find $output "\n"]+1) [:len $output]] } ...
by msatter
Fri Aug 07, 2020 7:12 pm
Forum: General
Topic: Suggestion: Address List in Routes
Replies: 1
Views: 461

Re: Suggestion: Address List in Routes

Use mangle to mark routing and then you can route that marked traffic.
by msatter
Fri Aug 07, 2020 7:02 pm
Forum: Scripting
Topic: Get only integers from array of strings
Replies: 3
Views: 807

Re: Get only integers from array of strings

:toip is a better try because you have IP addresses.

This might work to find the IP address and you have to adapt it yourself.
([:pick $data 0 [:find $data "\n"]]~"^[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}")
by msatter
Fri Aug 07, 2020 4:01 pm
Forum: Scripting
Topic: ASK [random wifi password generator]
Replies: 41
Views: 7472

Re: ASK [random wifi password generator]

To avoid the weekly to be the same also add the weeknumber to one of the values.

Or change the runtime of the script by adding the weeknumber to the seconds of the interval time at the end of the script.
:local $weeknumber=(calculate weeknumber[1-52]);
set scriptname interval=(7d - $weeknumber)
by msatter
Fri Aug 07, 2020 10:51 am
Forum: Scripting
Topic: script address list timeout get value
Replies: 2
Views: 630

Re: script address list timeout get value

Adapt this: https://forum.mikrotik.com/viewtopic.php?f=2&t=161384&p=797016&hilit=value#p797016 And have a look at the wiki linked to. update, adapted it for you: :put ([:pick [/ip firewall address-list print as-value where list=Facebook address=31.13.67.20] 0]->"timeout") :pick start his search for ...
by msatter
Tue Aug 04, 2020 7:11 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 43
Views: 10777

Re: ProtonVPN on Mikrotik

That suggesting was made to detect an error easier by having only one point of failure. Then you posted your config where looked for connection-marking in Mangle and found none.

The Wiki page linked to by Kams19 explains it in detail.
by msatter
Tue Aug 04, 2020 2:35 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 43
Views: 10777

Re: ProtonVPN on Mikrotik

If using connection-mark then you still have to mark traffic in Mangle.
by msatter
Tue Aug 04, 2020 12:33 pm
Forum: General
Topic: IKEv2 between MikroTiks, sides switching, initiator <> responder
Replies: 13
Views: 1730

Re: IKEv2 between MikroTiks, sides switching, initiator <> responder

I have the same behavior of changing from initator to responder but then with a VPN provider. Itis only happening with Pure-VPN and not with other providers. It is happening between 15 and 35 minutes after connect. The only thing that is different is that the Source Address is public instead of priv...
by msatter
Sun Jul 26, 2020 2:32 pm
Forum: Scripting
Topic: add minutes in time variable
Replies: 3
Views: 881

Re: add minutes in time variable

( ) use these two to be able to add.

So, like this:
:local currenttime ([/system clock get time]+110s)
thanks a lot.
it just works )
It has all to do with the ( ) ;-)
by msatter
Sun Jul 26, 2020 1:17 pm
Forum: Scripting
Topic: add minutes in time variable
Replies: 3
Views: 881

Re: add minutes in time variable

( ) use these two to be able to add.

So, like this:
:local currenttime ([/system clock get time]+110s)
by msatter
Sat Jul 25, 2020 11:59 pm
Forum: Scripting
Topic: Auto Delete User Script
Replies: 7
Views: 1642

Re: Auto Delete User Script

What was the question again?
by msatter
Fri Jul 24, 2020 11:11 am
Forum: Scripting
Topic: Auto Delete User Script
Replies: 7
Views: 1642

Re: Auto Delete User Script

You could create a global variable linked to the $user with the creation date.

A two field array would do.
by msatter
Thu Jul 23, 2020 12:36 pm
Forum: Beginner Basics
Topic: SCRIPT TO RESET-COUNTERS OF SPECIFIC USERS
Replies: 1
Views: 382

Re: SCRIPT TO RESET-COUNTERS OF SPECIFIC USERS

It is good that you lowered your voice at the end.
by msatter
Tue Jul 21, 2020 12:42 am
Forum: Beginner Basics
Topic: Webfig login hack
Replies: 14
Views: 3745

Re: Webfig login hack

Is it wrong that I'm highly amused by this?
That depends on your perspective.
by msatter
Tue Jul 21, 2020 12:39 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 156
Views: 31188

Re: RB4011 and RB1100 AHx4 "bricks" randomly

Any thoughts on this question?

viewtopic.php?f=3&t=151046#p806892
by msatter
Tue Jul 21, 2020 12:21 am
Forum: General
Topic: PMTU blues: The trap of Movistar's PPPOE endpoint of 192.168.144.1 + RouterOS default max-mtu and max-mru of 1480...
Replies: 1
Views: 462

Re: PMTU blues: The trap of Movistar's PPPOE endpoint of 192.168.144.1 + RouterOS default max-mtu and max-mru of 1480..

I was looking at that just yesterday. During PPPoE connecting the mrru is send to RouterOS and in my case that is 1596. Then RouteOS send a few times a packet of 1480 to the next hop (ISP). Router OS leaves it there and use the 1480 mtu. Only after I disable and enable the fiber connection the 1500 ...
by msatter
Tue Jul 21, 2020 12:06 am
Forum: Beginner Basics
Topic: Webfig login hack
Replies: 14
Views: 3745

Re: Webfig login hack

To be fair, he did include "please" this time.
No shit!


@Sob....spank me.
by msatter
Sun Jul 19, 2020 12:36 pm
Forum: Beginner Basics
Topic: Webfig login hack
Replies: 14
Views: 3745

Re: Webfig login hack

Maybe it eats pieces of shit. Trolls may like that to eat.

ps. only real, shit should be fed.
by msatter
Thu Jul 16, 2020 2:40 pm
Forum: RouterOS v7 BETA
Topic: Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]
Replies: 4
Views: 1204

Re: Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]

I made a adapted version to read an address list that was exported and contains disabled entries. As you can see you only need to leave the "yes" and remove the labels put in in an export. The file size goes from exported plus 1MB to under 500KB. Update: adapting to if a comment is provided (Now tes...
by msatter
Wed Jul 15, 2020 9:17 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

msatter I also lost direct Winbox access to my 4011RM which is behind the the hEX-S and now only able to connect through Romon. The configuration did not change and Winbox just flashes by on my screen. For the safety I revered to 6.47 on my hEX-S. Update. The TikAPP can access the 4011 directly wit...
by msatter
Wed Jul 15, 2020 5:05 pm
Forum: Beginner Basics
Topic: Mikrotik Hex S (RB760iGS) - GPON SFP support module.
Replies: 16
Views: 3560

Re: Mikrotik Hex S (RB760iGS) - GPON SFP support module.

My bad, I though the HEX could make use of its lower speeds, If not then use this one which does up to 1.25 https://mikrotik.com/product/S-RJ01 The hEX-S has special design that cut one of the two lanes to the CPU as soon as you insert a SFP module. The 5 ports get one lane and the SFP the other la...
by msatter
Wed Jul 15, 2020 4:38 pm
Forum: Beginner Basics
Topic: Mikrotik Hex S (RB760iGS) - GPON SFP support module.
Replies: 16
Views: 3560

Re: Mikrotik Hex S (RB760iGS) - GPON SFP support module.

Another very outside possibility is this device....... Its an RJ45 cage that can accept up to 10gig over Cat 7 for short distances. Thus you could potentially get your internet connection at speed - assumes you have an SFP+ port on your router, and that the ont/modem has ethernet jacks capable of s...
by msatter
Wed Jul 15, 2020 4:06 pm
Forum: Beginner Basics
Topic: Mikrotik Hex S (RB760iGS) - GPON SFP support module.
Replies: 16
Views: 3560

Re: Mikrotik Hex S (RB760iGS) - GPON SFP support module.

GPON is a minefield and even Mikrotik quit on this.

Contact CarlitoxxPro if he can be help you. This is for Spain but made to work in Mikrotik and configured.

viewtopic.php?f=3&t=116364&p=805558#p805558
by msatter
Sat Jul 11, 2020 10:18 pm
Forum: General
Topic: [Solved] Can't remove addresslist in one go if domains are used
Replies: 6
Views: 1537

Re: [Solved] Can't remove addresslist in one go if domains are used

This is the script (.rsc) I use: :global listname "RougeDNSname" :local i do={:global listname; :do {/ip firewall address-list add list=$listname timeout=35w3d13h13m56s address=$1} on-error={:log warning "$listname addresslist, domain already exists: $1"} } :do {/ip firewall address-list remove [fin...
by msatter
Sat Jul 11, 2020 8:13 pm
Forum: General
Topic: [Solved] Can't remove addresslist in one go if domains are used
Replies: 6
Views: 1537

Re: [Solved] Can't remove addresslist in one go if domains are used

Thanks Sindy, saddly it is not that simple with scripts. I can't add static entries using a script, least as far I know. These entries have max. timeout and Mikrotik disabled a time ago that then the became static. The dynamic allows to mix static and dynamic in one list. The only the non static ent...
by msatter
Sat Jul 11, 2020 7:08 pm
Forum: General
Topic: [Solved] Can't remove addresslist in one go if domains are used
Replies: 6
Views: 1537

Re: Can't remove addresslist in one go if domains are used

I solved the puzzle and two entries seems to be some how sticky. When successful removing sometimes two entries remains. This will remove the domains in one go. I have to exclude the resolved IP addresses on removal: :local listname "mikrotik-test" :do {/ip firewall address-list disable [find where ...
by msatter
Sat Jul 11, 2020 6:11 pm
Forum: General
Topic: [Solved] Can't remove addresslist in one go if domains are used
Replies: 6
Views: 1537

Re: Can't remove addresslist in one go if domains are used

I had an other try and first I disabled the resolved IP addresses and then remove. That worked. [user@MikroTik] /ip firewall address-list> :put [find list=mikrotik-test] *37f091f;*37f0921;*37f0922;*37f0925 These are the dynamic domain entries and the resolved IP addresses. After disabling the entrie...
by msatter
Sat Jul 11, 2020 5:58 pm
Forum: General
Topic: [Solved] Can't remove addresslist in one go if domains are used
Replies: 6
Views: 1537

[Solved] Can't remove addresslist in one go if domains are used

When I add more than one domain to a addresslist then I can only remove one at a time and then it states no such item (4) . Using remove then it will only remove the last added item to the addresslist . [user@MikroTik] /ip firewall address-list> add list=mikrotik-test address=mt.lv [user@MikroTik] /...
by msatter
Sat Jul 11, 2020 12:12 pm
Forum: Scripting
Topic: VK Basic Monitoring
Replies: 3
Views: 737

Re: VK Basic Monitoring

by msatter
Fri Jul 10, 2020 11:44 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58279

Re: v6.47.1 [stable] is released!

Nobody cares about the "reduced resell value" because of the sector writes count. Who advertises de sector writes count when selling their hardware? Is that a thing? realy? Selling a cheap MikroTik, cheaper? how much "resell value" loss are we talking about? If you decided to ditch that device you ...
by msatter
Fri Jul 10, 2020 8:35 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58279

Re: v6.47.1 [stable] is released!

Good that the false reporting of sector writes is finally fixed. This did reduce the resell value of the Mikrotik device you own greatly.
Really? Nobody ever asked me for this...
You poor thing. Do you feel left out now?
by msatter
Fri Jul 10, 2020 5:11 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58279

Re: v6.47.1 [stable] is released!

Good that the false reporting of sector writes is finally fixed. This did reduce the resell value of the Mikrotik device you own greatly. Do You think it was "false reporting" ? Maybe it was "true reporting", but now (and before) something is hidden... Mikrotik states increased "sector writes" repo...
by msatter
Fri Jul 10, 2020 11:13 am
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 147
Views: 58279

Re: v6.47.1 [stable] is released!

Good that the false reporting of sector writes is finally fixed. This did reduce the resell value of the Mikrotik device you own greatly.
by msatter
Fri Jul 10, 2020 12:00 am
Forum: RouterOS v7 BETA
Topic: Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]
Replies: 4
Views: 1204

Re: Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]

You are welcome and I is not only my work but work of many others to distill this to the most lean solution. Mikrotik could take this and make it possible to enter the name of the list, the timeout and if you want to clean the old list first so that you can add a list to a already existing list. To ...
by msatter
Thu Jul 09, 2020 11:30 pm
Forum: RouterOS v7 BETA
Topic: Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]
Replies: 4
Views: 1204

Re: Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]

:do {...} on-error={}; # The local variable "i" is a function and is called by $i. $1 inside the function contains the IP-address from that line. :local i do={ :do {/ip firewall address-list add list=Probe-China timeout=35w3d13:13:56 address=$1} on-error={:log warning "IP already exists: $1"} } # Fi...
by msatter
Wed Jul 08, 2020 11:26 am
Forum: General
Topic: BUG: DNS USE ONLY DOH
Replies: 8
Views: 1764

Re: BUG: DNS USE ONLY DOH

I addressed that in the first two sentences. When using DoH you loose the 'backup' server option.
by msatter
Wed Jul 08, 2020 10:08 am
Forum: General
Topic: BUG: DNS USE ONLY DOH
Replies: 8
Views: 1764

Re: BUG: DNS USE ONLY DOH

DoH is a one horse only with Mikrotik. So DoH or normal DNS.

My advise is to use DoH in the webbrowser or in countries or with ISP providers that repressive. This in non-repressive countries/ISP you are only feeding the big firms with our private data.
by msatter
Wed Jul 08, 2020 1:46 am
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

@msatter What feature sets are you using in the versions with the flash write counter issue that are preventing you from just rolling back to a version without this issue?
I am sorry, but I won't go for that.
by msatter
Tue Jul 07, 2020 10:31 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

There seems to be testing but internal. We start 6.48 at version beta twelve. The flash write counter is a big problem despite it not be actual writes. It will decrease the resell value of your router because the write counter is extremely high due to this bug. This bug alone should have been tackle...
by msatter
Tue Jul 07, 2020 3:33 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

See:
I had that same message on my hEX-S, so I manually uploaded the firmware file.

@nkourtzis: It happened even before any reports were made so not likely that the files have been removed.
by msatter
Tue Jul 07, 2020 2:45 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

msatter Do you have custom set of packages installed and wireless package is not installed? 648beta12-pack.JPG I also lost direct Winbox access to my 4011RM which is behind the the hEX-S and now only able to connect through Romon. The configuration did not change and Winbox just flashes by on my sc...
by msatter
Tue Jul 07, 2020 2:15 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49994

Re: v6.48beta [testing] is released!

Can you please send the supout.rif file from your device to support@mikrotik.com? And on the 4011RM and the hEX-S the same error message: 648beta12-error.JPG 13:04:38 system,error,critical error while running customized default configuration script: expected end of command (line 1310 column 53) 13:...
by msatter
Sun Jul 05, 2020 3:35 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

This is a bit quick and dirty but it shows the the servers supporting Wireguard: { :local update do={ :global dataNordVPN :local data $dataNordVPN :do { :put "Reading and displaying from the JSON file, the values for the $valname field:" :while ([:len $data]!=0) do={ :set $fieldname ($valname."\":\"...
by msatter
Sun Jul 05, 2020 3:03 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

If I may... the $update url= beginning of the last three lines is there twice (copy-paste went wrong?), but more important, there is a risk that the response will be different each time you read it. So as you read it into a variable anyway, you can just parse the data from the same response for eac...
by msatter
Sun Jul 05, 2020 1:53 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

You're welcome. It more a bit of playtime for me doing this. And at the same time improve my scripting. There can be a difference in matching the data due to time. My next step would be to loop through different requested fields. This will limits the returned values to only strings or numbers. Putti...
by msatter
Sun Jul 05, 2020 11:56 am
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

This version reads the file multiple times but can now be instructed to treat the wanted field, being a string or a number. { :local update do={ :do { :local result [/tool fetch url=$url as-value output=user]; :if ($result->"downloaded" != "63") do={ :local data ($result->"data") :put "Reading and d...
by msatter
Sat Jul 04, 2020 3:14 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

And then you can extract extra information as IP address and the current load on the server. Notice that the "load" is not a string and then a comma is the end of the field. { :local recordname "hostname" :local valname1 "ip" :local valname2 "load" :local data ([ / tool fetch url="https://api.nordvp...
by msatter
Sat Jul 04, 2020 10:43 am
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

And I have shorted it and made it more flexible. You can now state the name of the field you want to be returned and it adapt the the length of that field. It is still basic but a good start to read from JSON files. # Written by Shumkov # Adapted by blacklister # rewritten to list VPN servers # 2020...
by msatter
Sat Jul 04, 2020 9:10 am
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

Having thought more about it, it looks that there could be two approaches to this in reading a JSON file like this. Your could go for only one value or just convert the JSON file up to 64KB in size to a array containing the values that is direct accessible by RouterOS. The last one is think the best...
by msatter
Sat Jul 04, 2020 2:55 am
Forum: General
Topic: Where can I get v6.44.6?
Replies: 3
Views: 1175

Re: Where can I get v6.44.6?

The download archive had a problem and it seems to be solved now.
by msatter
Sat Jul 04, 2020 1:40 am
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

This will return the first active domain in the list: :local data ([ / tool fetch url="https://api.nordvpn.com/v1/servers/recommendations\?limit=1" output=user as-value ]->"data"); :local position [:find $data nordvpn.com]; put [:pick $data ($position-6) ($position+11)]; And a working script writing...
by msatter
Fri Jul 03, 2020 8:47 pm
Forum: General
Topic: [Feature request] Wireguard
Replies: 142
Views: 46749

Re: [Feature request] Wireguard

+1 for this feature. Mikrotik uses the Linux Kernel if I remember. Wireguard is fast, modern and uses the Linux kernel directly. Also it's very easy to set up in comparison to the nightmare of OpenVPN.
Mikrotik just changed to a kernel version for Beta 7, supporting Wireguard.
by msatter
Thu Jul 02, 2020 4:02 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

hmmm This might filter out the needed domains and this a part of the script that could do that. :while ([:len $data]!=0) do={ :if ([:pick $data 0 [:find $data "\n"]]~"^nl[0-9]{1,3}\\.nordvpn\\.com") do={ :do {add list=$blacklist address=([:pick $data 0 [:find $data $delimiter]].$cidr) timeout=35w3d1...
by msatter
Thu Jul 02, 2020 2:47 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Re: Strange Cert. error with some NordVPN connections

I've seen this myself... Just switched to another server that is currently recommended.
Thanks and was already testing that and I have now chosen a new range. You can see the current servers and load of those servers on this JSON page.

nordvpn.com/api/server/stats
by msatter
Thu Jul 02, 2020 1:31 pm
Forum: General
Topic: Strange Cert. error with some NordVPN connections
Replies: 15
Views: 2074

Strange Cert. error with some NordVPN connections

I have a multiple connections with NordVPN and just saw that I had errors in the log about the certificate. NordVPN-failCert.JPG The certificate is running till 1 January 2036 so that could not be the problem. Other connections to NordVPN are working fine and reconnect. The only thing I can think of...
by msatter
Mon Jun 29, 2020 2:42 am
Forum: General
Topic: VPN provider recommendations
Replies: 17
Views: 10668

Re: VPN provider recommendations

Awesome news! Finally! NordVPN now officially supports Mikrotik with ROS firmware version v6.45++ https://support.nordvpn.com/Connectivity/Router/1360295132/Mikrotik-IKEv2-setup-with-NordVPN.htm Under which stone did you stay for almost a year? Look at the date under this page: https://wiki.mikroti...
by msatter
Mon Jun 29, 2020 2:38 am
Forum: RouterOS v7 BETA
Topic: RB411 7.0 Beta 8 does not boot.
Replies: 2
Views: 767

Re: RB411 7.0 Beta 8 does not boot.

Read this posting in the RouterOs 7.0beta8 thread.

viewtopic.php?f=1&t=161980#p799785
by msatter
Sat Jun 27, 2020 11:59 am
Forum: General
Topic: Hacked MTiks, any examples?
Replies: 9
Views: 1999

Re: Hacked MTiks, any examples?

Sorry, removed.
by msatter
Fri Jun 26, 2020 7:04 pm
Forum: General
Topic: Proscend 180-T VDSL2 SFP Modem - Sync Speed and state
Replies: 2
Views: 753

Re: Proscend 180-T VDSL2 SFP Modem - Sync Speed and state

You are welcome.

viewtopic.php?f=3&t=104109

And here how to call the internal webserver/console:

viewtopic.php?f=2&t=160674
by msatter
Fri Jun 26, 2020 3:20 pm
Forum: RouterBOARD hardware
Topic: HEX S RB760iGS → console mode...?
Replies: 18
Views: 4095

Re: HEX S RB760iGS → console mode...?

#Woobm-USB [https://mikrotik.com/product/woobm] just got it delivered, plugged into the USB got the WoobmAP on, connected to it (hEX S - 6.47 stable) Got assigned IP address 192.168.4.1, opened web browser and there was the console. Logged in, and disabled offending firewall rule and all is working...
by msatter
Fri Jun 26, 2020 11:39 am
Forum: RouterBOARD hardware
Topic: HEX S RB760iGS → console mode...?
Replies: 18
Views: 4095

Re: HEX S RB760iGS → console mode...?

I can't say that and better contact support on support@mikrotik.com this is free and give them a few days time to reply. Should have look, hate sending this kind of stuff over the e-mail. There is a Support Portal to be found here: [https://help.mikrotik.com/servicedesk/] :) I prefer e-mail and tra...
by msatter
Thu Jun 25, 2020 9:25 pm
Forum: RouterBOARD hardware
Topic: HEX S RB760iGS → console mode...?
Replies: 18
Views: 4095

Re: HEX S RB760iGS → console mode...?

Which version of RouterOS are you using? If you use a version that is lower than 6.47 then the console could work. We are not the support department of Mikrotik and users of Mikrotik products just like you. There must be a reason Mikrotik disabled the console for the hEX-S in 6.47 which not known to...
by msatter
Thu Jun 25, 2020 8:58 pm
Forum: RouterBOARD hardware
Topic: HEX S RB760iGS → console mode...?
Replies: 18
Views: 4095

Re: HEX S RB760iGS → console mode...?

I can't say that and better contact support on support@mikrotik.com this is free and give them a few days time to reply.
by msatter
Thu Jun 25, 2020 5:28 pm
Forum: RouterBOARD hardware
Topic: HEX S RB760iGS → console mode...?
Replies: 18
Views: 4095

Re: HEX S RB760iGS → console mode...?

RouterOS 6.47 release notes: *) port - removed serial console port on hEX S

viewtopic.php?f=21&t=161887
by msatter
Tue Jun 23, 2020 8:45 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 381
Views: 101611

Re: RB4011

At product page only the passive DAC warning remains and it seems that Mikrotik got to grips with the other problems mentioned by you for the 4011. I had some problems with my SPF and that resolved and in the next beta also the last hickup should be tackled. The solution you mention is already known...
by msatter
Sun Jun 21, 2020 11:05 am
Forum: Useful user articles
Topic: Is there a reasone why I cannot send private messages ?
Replies: 4
Views: 780

Re: Is there a reasone why I cannot send private messages ?

Recipient mailbox full?

Do not accept new messages (New messages will be held back until enough space is available)
by msatter
Sat Jun 20, 2020 3:13 am
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

dns64.dns.google can't be resolved to a IP address:
;; AUTHORITY SECTION:
dns.google.             48      IN      SOA     ns1.zdns.google. dns-admin.google.com. 2684358593 21600 3600 1209600 300
by msatter
Sat Jun 20, 2020 3:00 am
Forum: General
Topic: Block gamers UDP traffic
Replies: 14
Views: 2781

Re: Block gamers UDP traffic

I had a glance at Discord and it seems to be above 50000. Address list won't work because the connections are a sort of P2P.
by msatter
Fri Jun 19, 2020 10:24 pm
Forum: General
Topic: Block gamers UDP traffic
Replies: 14
Views: 2781

Re: Block gamers UDP traffic

VOIP UDP sits on port 7000-7100 (STUN) and instead of blocking choose to allow traffic and block the rest of the UDP traffic.
by msatter
Fri Jun 19, 2020 8:08 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

In the Holy book you see, Normis, only Google and Cloudflace is being mentioned.

As I predicted.
by msatter
Fri Jun 19, 2020 3:17 pm
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 106
Views: 57338

Re: Winbox v3.24 released!

If you want to have good visual representation of the contention being lost due to reboot, upgrade or just no connections then Winbox should not be responding to any changes and the screen should be become transparent to white. The box as SiB suggest could then the only part of the Winbox screen tha...
by msatter
Fri Jun 19, 2020 1:48 pm
Forum: General
Topic: DOUBT ABOUT MESHING WITH MK
Replies: 1
Views: 523

Re: DOUBT ABOUT MESHING WITH MK

You are loud enough. Why need WiFi.
by msatter
Fri Jun 19, 2020 10:49 am
Forum: General
Topic: um-beforemigration.tar
Replies: 2
Views: 662

Re: um-beforemigration.tar

I think that has to do with when a router is migrated from Master-slave ports to Bridge and I your router is not restarted for a long time it is still there. https://forum.mikrotik.com/viewtopic.php?p=603014#p602683 Or in this Woke time talk: "We went from Master-Slave to the more inclusive way of b...
by msatter
Fri Jun 19, 2020 10:45 am
Forum: General
Topic: where can I create a script in RouterOS?
Replies: 11
Views: 7840

Re: where can I create a script in RouterOS?

You can create a script in a house,
You can create a script with a mouse
You can create a script with the help of fewi
You can create a script with the webgui
You can create a script with green eggs and ham!!
I don't like the looks of green eggs and if, then I would hide it under the ham.
by msatter
Fri Jun 19, 2020 10:41 am
Forum: RouterBOARD hardware
Topic: HexS / RB760iGS inconsistent PoE output after reboot
Replies: 4
Views: 1193

Re: HexS / RB760iGS inconsistent PoE output after reboot

After contacting support@mikrotik.com or contacting support of your seller.
by msatter
Thu Jun 18, 2020 10:09 pm
Forum: General
Topic: 1Gbps test issues
Replies: 3
Views: 740

Re: 1Gbps test issues

Reading this I think the ISP is throtteling except for the sites where you can test speeds.

Check if fasttrack is enabled for UDP and TCP and used ports.
by msatter
Wed Jun 17, 2020 12:06 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

I just hope you can try and see the other side of the coin. It was discussed enough times above. There are many reasons not to trust the ISP. There are also many reasons to not trust anyone with your private data. That is why I do it myself and ask the authorative directly. The Dutch government doe...
by msatter
Wed Jun 17, 2020 10:51 am
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

And when it comes to it, I would rather Cloudflare have my data than my shitty government/ISP.
Maybe that the people here that do no like DoH DoT are ISP them self ;)
Why should DoT be wrong? As an ISP or as concerned parents of a family you can enforce not using DoT.
by msatter
Tue Jun 16, 2020 1:40 pm
Forum: Scripting
Topic: Script for If enivorment = then do
Replies: 14
Views: 2096

Re: Script for If enivorment = then do

{
:global provisionedstatus false
:if $provisionedstatus do={} else={/tool fetch url= $configserver output=file; :log info "download provision"}
:if $provisionedstatus do={:log info "already provision"}
}
by msatter
Mon Jun 15, 2020 6:21 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

Look at the crazy amount of questions on this forum. DoH is really popular. A lot of regimes nowadays filter content. People started to use 8.8.8.8 as DNS, but that got blocked. So now people ask for DoH. This is what it's for basically. I will not get political. We just make what users ask for (so...
by msatter
Mon Jun 15, 2020 3:23 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

Yes you can, but how many will do that!?
by msatter
Mon Jun 15, 2020 1:56 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

I did not mixed things, I compared to it.

"See it as the Facebook pixel...."
by msatter
Mon Jun 15, 2020 11:47 am
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

Exactly! DoH can be used in countries where governments enforce filtering of news and such. This is why it's popular, I guess. Is Latvia such a country? The popularity is due to indoctrination by the big firms wanting to follow you where ever you go. You always sent your IP address with your reques...
by msatter
Mon Jun 15, 2020 10:25 am
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

Not sure why Mikrotik never implimeneted DoT and went for DoH. Routers are tools to implement and include to network designs. It makes absolutely no sense to pick DoH over DoT in routers. Leave DoH for the browsers :) @BlackFate Leave DoH for the browsers is 100% on the mark ! Not all internet traf...
by msatter
Sun Jun 14, 2020 11:56 am
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 64927

Re: v7.0beta8 [development] is released!

And we got a Linux version that supports Wireguard. So endless whining is avoided.

RouterOS eight would not be there in my lifetime.
by msatter
Sun Jun 14, 2020 11:53 am
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

You click.
by msatter
Sat Jun 13, 2020 8:07 pm
Forum: General
Topic: WEB PROXY CACHE.
Replies: 1
Views: 476

Re: WEB PROXY CACHE.

That could be smaller.
by msatter
Fri Jun 12, 2020 11:20 pm
Forum: General
Topic: torch mikrotik
Replies: 1
Views: 513

Re: torch mikrotik

English is the language used in this forum.
by msatter
Fri Jun 12, 2020 11:17 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

I don't know but have a look at the first posting in this thread.
by msatter
Fri Jun 12, 2020 4:20 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 381
Views: 101611

Re: RB4011

Now the hot days are back I looked for a way to cool the 4011 a bit. It is passive cooled by the housing but it still gets quite warm so looked for a very small fan and a way to attach it to the 4011. I took small plugs used to keep screws into a wall and cut one of the halves of the plug away. then...
by msatter
Wed Jun 10, 2020 8:00 pm
Forum: General
Topic: UPDATE FIRMWARE [SOLVED]
Replies: 3
Views: 977

Re: UPDATE FIRMWARE [SOLVED]

Every time you do an update you won't know what you are updating with. It could be new but it could be also a existing version and only the version number is changed.

Only Mikrotik knows if there are changes.

It very inpolite to SHOUT, do you know that?
by msatter
Wed Jun 10, 2020 1:57 pm
Forum: General
Topic: Feature requests
Replies: 1278
Views: 288985

Re: Feature requests

Those list can be obtained at mikrotikconfig dot com Beside that you need to maintain a seperate list with scanning IP add. that are domestic or listed with the wrong country. I am doing it myself since a few days becsuse I got fed up with maintaining the separate list all the time. Now is because v...
by msatter
Wed Jun 10, 2020 1:32 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 95807

Re: v6.47 [stable] is released!

I also get ip/smb error on 6.47: 192.168.101.46 dialect: NT LM 0.12 192.168.101.46 session setup GSS error: 0x90000 192.168.101.46 dialect: SMB 2.002 192.168.101.46 session setup GSS error: 0x90000 Till this issue, for now I downgraded to 6.46.6 and all work fine. Please fix it in next stable relea...
by msatter
Mon Jun 08, 2020 3:14 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

I have to apologize for calling hamburges with McDonalds unhealty.

Eating one McDonalds hamburger yourself does not mean that all McDonalds hamburger are unhealthy also.



Just trying to be inculsive. ;-)
by msatter
Mon Jun 08, 2020 12:56 am
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

It's a tool like any other. A hammer can be used to hit a nail or someone's head, it's everyone's choice, but you don't blame the hammer. Same with DoH, you can use different public servers or run your own. If you're affraid of Google and friends, you probably shouldn't use their servers. The nail ...
by msatter
Sun Jun 07, 2020 11:10 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

You can argue that are free to choose a more private aware DNS servers but 99% will use Google and Cloudflare in the end....sounds of popping champagne bottles in the background. I was in Turkey last year, and there Wikipedia was blocked used DNS block. DoH agent om my PC solved this fine. Also I d...
by msatter
Sun Jun 07, 2020 10:02 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

I think you meant "Yes, except for FWD". Static entries are still preferred with DoH, except FWDs, those are currently ignored. There are also other differences but they don't affect @sindy's use case. I had this posting in my memory: https://forum.mikrotik.com/viewtopic.php?f=21&t=161583#p795962 A...
by msatter
Sun Jun 07, 2020 6:47 pm
Forum: General
Topic: DNS over HTTPS
Replies: 147
Views: 29604

Re: DNS over HTTPS

No, except for FWD.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 7