Community discussions

MikroTik App

Search found 1626 matches

by msatter
Thu May 28, 2020 6:20 pm
Forum: General
Topic: Script environment suspicious !
Replies: 7
Views: 1026

Re: Script environment suspicious !

Jotne created a loop in the thread by linking back to the same thread.
by msatter
Thu May 28, 2020 6:18 pm
Forum: General
Topic: Script environment suspicious !
Replies: 7
Views: 1026

Re: Script environment suspicious !

by msatter
Thu May 28, 2020 1:08 pm
Forum: General
Topic: Upgrade to HexS (RB760iGS) cannot get ultra fibre speed.
Replies: 18
Views: 1869

Re: Upgrade to HexS (RB760iGS) cannot get ultra fibre speed.

I found that diagram always a bit strange. It states "integrated switch chip" integrated in the CPU? The the diagram is then not logical. That is why I prefer the other diagrams. If you reach 500Mbit/s then fasttracking is working or you would be around 250Mbit/s. Look for way to optimize your rules...
by msatter
Thu May 28, 2020 11:39 am
Forum: General
Topic: Upgrade to HexS (RB760iGS) cannot get ultra fibre speed.
Replies: 18
Views: 1869

Re: Upgrade to HexS (RB760iGS) cannot get ultra fibre speed.

I don't put the port used as WAN in the bridge. PPPoE plus VLAN around 900 Mbit/s on upload speedtest.net. Port 1, 3, 5 sits on one lane and 2, 4 on the other. https://i.mt.lv/cdn/rb_files/RB760iGS-dsw-180517144423.png The little one hEX https://i.mt.lv/cdn/rb_files/RB750Gr3-dsw-161125140316.png
by msatter
Wed May 27, 2020 5:32 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

Pleased to see how it works and I see that routing is used to project the public IP, on the port of the Mikrotik. The Moviestar is 'switch' removed, so that one is out of the picture. This is used where you can't put the router in bridge mode. Going to test it for myself and can used it in those sit...
by msatter
Wed May 27, 2020 5:03 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

Nostromog put in and the VLAN seems already to be removed by the Teldat so the the Internet + VOIP is terminated there. All behind that is then local. I only see this now and so a PPPoE on you Mikrotik is futile unless the Teldat is bridged. I don't even know what the Teldat is but I could be someth...
by msatter
Wed May 27, 2020 4:43 pm
Forum: Scripting
Topic: Colon or not to Colon
Replies: 5
Views: 827

Re: Colon or not to Colon

I found some interesting behavior that could explain the use of the ":". { :delay 4s /interface :if (([pppoe-client monitor pppoe-ikev2 as-value once]->"mtu") < 1500) do={ disable sfp-sfpplus1 :delay 50ms enable sfp-sfpplus1 :log warning "PPPoE MTU lower than 1500, so the SFP port is restarted"} } O...
by msatter
Wed May 27, 2020 4:31 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

When I plug in a laptop directly to the Movistar' Switch I get the address 192.168.1.X, so it must be in router mode. Your subnet is then 192.168.1.0/24 and your Mikrotik has to use the same subnet to communicate with the Moviestar 'switch". When you changed to the new settings then the DHCP also c...
by msatter
Wed May 27, 2020 2:28 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

And which subnet are you using. Old 192.168.100.x and new 192.168.1.x so you are on the wrong track in the new config when using 192.168.100.10/24
by msatter
Wed May 27, 2020 12:48 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

I give up. The solution is so simple but no one wants to see it.
by msatter
Wed May 27, 2020 12:38 pm
Forum: Beginner Basics
Topic: Redirect outgoing DNS requets to internal DNS server
Replies: 3
Views: 372

Re: Redirect outgoing DNS requets to internal DNS server

Make that src-nat redirecting tcp/udp 53 to the Pi-hole.

dst-nat is traffic coming in and src-nat is going out. Have also look at hairpin in the wiki for traffic returning from the Pi-hole. And that is dst-nat traffic.
by msatter
Wed May 27, 2020 12:31 pm
Forum: General
Topic: turn off LEDs on RB4011iGS+RM
Replies: 1
Views: 154

Re: turn off LEDs on RB4011iGS+RM

Nope.

Piece of tape will do wonders.
by msatter
Wed May 27, 2020 12:19 pm
Forum: General
Topic: Strange file have in mikrotik
Replies: 2
Views: 288

Re: Strange file have in mikrotik

They are not proud of this but it does exists at least:

https://blog.mikrotik.com/security/

This is the last one who's router was hacked:
viewtopic.php?f=2&t=161521
by msatter
Wed May 27, 2020 12:15 pm
Forum: General
Topic: Upgrade to HexS (RB760iGS) cannot get ultra fibre speed.
Replies: 18
Views: 1869

Re: Upgrade to HexS (RB760iGS) cannot get antra fibre speed.

Using the SFP, cripples the hEX S and it will get a dedicated lane to CPU. The other 5 ports have to share the other lane. I rather had seen that that ether1 would be disabled when the SFP is used and that both lanes are used by more ports. I have bought a 4011 for more encrypting speed and a dedica...
by msatter
Wed May 27, 2020 12:03 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

To me the old config is over a bridge. add address=192.168.100.10/24 interface=ether1-gateway Is that IP matching the new configuration? Try 192.168.1.10 if it is free and also change the VLAN 6 to 20 and 3 to21. No, that IP is the MikroTik's WAN and I must change it to 217.X.X.X in the new configu...
by msatter
Wed May 27, 2020 1:29 am
Forum: Beginner Basics
Topic: Blocking input and forward traffic from IP
Replies: 4
Views: 765

Re: Blocking input and forward traffic from IP

And that is not how this forum or any other medium works to post IP addresses in public (personal data).

And for kids there is a special kid control unit available under /ip. ;-)
by msatter
Tue May 26, 2020 11:27 pm
Forum: Wireless Networking
Topic: 4011 vs CCR1009
Replies: 3
Views: 815

Re: 4011 vs CCR1009

The FiberStore sells active DAC cables beginning at 36 Pound for a 1 meter cable up to 67 Pound for a 10 meter cable.

If you are also getting Fibre then you could better look at a router with two SFP+ cases like the CCR1009-7G-1C-1S+
by msatter
Tue May 26, 2020 10:55 pm
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

No worries. I am running 6.47RC and nothing has changed there. The Dynamic are still grouped under their own specific template.
by msatter
Tue May 26, 2020 10:52 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

With arrival of 6.47RC it works after a few hick-ups and if it stable on a reboot I won't going to try out yet now it is working.
by msatter
Tue May 26, 2020 9:13 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

@Nostromog look at my posting for the new situation. The router should be in bridge or the device before it. The pppoe + vlan only have to find gateway.
by msatter
Tue May 26, 2020 8:04 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

To me the old config is over a bridge.
add address=192.168.100.10/24 interface=ether1-gateway
Is that IP matching the new configuration?

Try 192.168.1.10 if it is free and also change the VLAN 6 to 20 and 3 to21.
by msatter
Tue May 26, 2020 1:33 pm
Forum: Announcements
Topic: v6.47rc [testing] is released!
Replies: 48
Views: 7990

Re: v6.47rc [testing] is released!

I can now connect over SFP and get a link up of 1Gbit/s. However like with 6.46.x the PPPoE connection drops back to a MTU of 1480 instead of the usual MTU of 1500 after short time. Back to using the media converter connected to a ether-port. Hoping this can be solve this before release of 6.47 Addi...
by msatter
Mon May 25, 2020 10:19 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 93
Views: 17986

Re: RB4011 and RB1100 AHx4 "bricks" randomly

If you look in the status tab you will see that 1000 half is not advertised by the 4011. However it is a test worth to see if also disabling in the settings brings a improvement or a solution.
by msatter
Mon May 25, 2020 9:09 pm
Forum: Scripting
Topic: New to scripting, need help
Replies: 15
Views: 1673

Re: New to scripting, need help

The on-error needs to be indeed on that line like it is necessary with else in a if..do..else To check the syntax you can put the code between { } : { :do { :local checkdns [:resolve "my.domain" server=1.2.3.100] /ip dhcp-server network set 0 dns-server=1.2.3.100 } on-error={ /ip dhcp-server network...
by msatter
Mon May 25, 2020 4:56 pm
Forum: Scripting
Topic: New to scripting, need help
Replies: 15
Views: 1673

Re: New to scripting, need help

test is a local variable that just is used as a dummy. It could be clearer to use dummy but you are asking to test something so test was clearer here.

The lines are in fact one long line and the work in one go.
by msatter
Sun May 24, 2020 10:05 pm
Forum: Scripting
Topic: New to scripting, need help
Replies: 15
Views: 1673

Re: New to scripting, need help

Thwt is not the simplest thing to start with.

Look for on-error and might be the way to archive that.
by msatter
Sat May 23, 2020 2:11 pm
Forum: General
Topic: Mikrotik + Movistar Fusión Empresas
Replies: 37
Views: 3942

Re: Mikrotik + Movistar Fusión Empresas

You should have put VLAN 20 at the ethernet port connected to the switch and the PPPoE connects to VLAN 20. Is the Teldat/switch in bridge mode then you can use PPPoE and if not you let the stuff from Moviestar do the work.

I assume that VOIP is handled by the Teldat/Moviestar switch itself.
by msatter
Sat May 23, 2020 1:55 pm
Forum: Wireless Networking
Topic: Adding a DNS CNAME for internal IP address?
Replies: 2
Views: 279

Re: Adding a DNS CNAME for internal IP address?

Beta 6.47beta60 has this and it will trickle down most likely also in the non-beta versions in time. I am eagerly awaiting the next beta but the current hick-ups take longer to solve than expected so before moving to beta look if you can solve that differently. In the beta you can use the CLI to set...
by msatter
Sat May 23, 2020 11:39 am
Forum: General
Topic: ECMP LoadBalancing
Replies: 15
Views: 1926

Re: ECMP LoadBalancing

@sindy Only the routing-mark differs and the destination address is in all four lines the same. Which is not present if run directly from the router as you wrote.
by msatter
Sat May 23, 2020 10:59 am
Forum: General
Topic: ECMP LoadBalancing
Replies: 15
Views: 1926

Re: ECMP LoadBalancing

I am not a routing specialist but with distance and specific WAN you create a problem. The connection with the shortest distance gets priority to transport traffic but then only for WAN3 traffic leaving WAN2+3 to be catched by the last routing rule. Why not only use the routing-mark and set the dist...
by msatter
Sat May 23, 2020 2:21 am
Forum: General
Topic: ECMP LoadBalancing
Replies: 15
Views: 1926

Re: ECMP LoadBalancing

If you want an exact distribution then the use of PCC is not the best. Also think about when you spread traffic, don't define the last line and just mark what is left over. You create then also a catch-all in case one of you earlier lines are not working. I have spent an posting on this and have a l...
by msatter
Fri May 22, 2020 9:22 pm
Forum: General
Topic: Flooding UDP port 1194
Replies: 14
Views: 2143

Re: Flooding UDP port 1194

They are sending it now as a stream so it seems not to be closed. Try this in RAW and see if that stops the attacks: psd (integer,time,integer,integer; Default: ) Attempts to detect TCP and UDP scans. Parameters are in following format WeightThreshold, DelayThreshold, LowPortWeight, HighPortWeight W...
by msatter
Fri May 22, 2020 4:53 pm
Forum: Beginner Basics
Topic: Replace Vodafone router
Replies: 3
Views: 684

Re: Replace Vodafone router

You will have to set the Vodafone router to bridge if that is posdible. Miktotik does not support ADSL/VDSL in any way on it's own.
by msatter
Tue May 19, 2020 1:32 pm
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 28
Views: 8119

Re: Winbox v3.24 released!

No sorry....it is every 2nd time you connect connect rb4011 .... changelog OK ... closing winbox .... connect rb4011 .... changelog NOT OK .... closing winbox .... connect rb4011 .... changelog OK .... and so on What if you enforce it to use only one of the two servers under the domain dowload.mikr...
by msatter
Tue May 19, 2020 12:43 pm
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 28
Views: 8119

Re: Winbox v3.24 released!

New Winbox shows strange changelog in "system -> packages" for stable tree ??!?!?!? The error comes after "clear cache" only on the first device you connect after downloading descriptors. On other devices the changelog is OK. It stays strange only on the first connected device after performing a "c...
by msatter
Mon May 18, 2020 5:33 pm
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 28
Views: 8119

Re: Winbox v3.24 released!

Looks good and no more resizing of the windows on it's own is a big relieve. Running it on a Windows 10 system.
by msatter
Mon May 18, 2020 3:34 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 54
Views: 11571

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

According to the following Manual:Scripting-examples -- file size limitation has been removed Read and write large files Many users requested ability to work with files. Now you can do it without limitations Create and write to file: :global newContent "new file content\r\nanother line\r\n"; [/lua ...
by msatter
Mon May 18, 2020 11:24 am
Forum: General
Topic: Release Notes Bug/Error
Replies: 2
Views: 395

Re: Release Notes Bug/Error

That is known and lets hope Mikrotik can complete the work they are doing on it today.

viewtopic.php?f=21&t=154662#p793522
by msatter
Mon May 18, 2020 1:57 am
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

Thanks eworm for the explanation and I have added the :global gArr; line and this can be used directly in a script: :if ([/system script environment find name="gArr"]) do={} else={:global gArr [:toarray ""]; :set ($gArr->"key1") "val2";}; :global gArr; :put $gArr; On a first run it will create the v...
by msatter
Sun May 17, 2020 11:37 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

As soon the interpreter is hitting the "}", $f is forgotten.

But then I have already put up a version that does not need a helping variable.
by msatter
Sun May 17, 2020 11:27 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

@msatter, stop please. Your code can't be correct as you use $f in the initialization... My code is correct, as it runs in RouterOS. $f is local . You don't have always to go through the process of defining it. It not Cobol. ;-) This is a working and also the shortest version: { :if ([/system scrip...
by msatter
Sun May 17, 2020 11:12 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

It is a global variable: { {... :set $f [:len $gArr] {... :if ($f = "true") do={:set $f true} else={:set $f false}; {... :if ($f) do={} else={ {{... :global gArr [:toarray ""] {{... :set ($gArr->"key1") "val1" {{... } {... {... :put [:pick $gArr 0] {... {... } val1 And via de CLI: :put [:pick $gArr ...
by msatter
Sun May 17, 2020 11:03 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

I am not a programmer but this is my solution: { :set $f [:len $gArr] :if ($f = "true") do={:set $f true} else={:set $f false}; :if ($f) do={} else={ :global gArr [:toarray ""] :set ($gArr->"key1") "val1" } :put [:pick $gArr 0] } Nothing is being printed but the value is there "key1=val1".
by msatter
Sun May 17, 2020 10:42 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

You are barking up the wrong tree here.

I had this exact same problem a few weeks ago and I worked around it going with returned string value.
by msatter
Sun May 17, 2020 10:37 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

What's new in 6.46beta44 (2019-Sep-19 05:54):

Changes in this release:

*) capsman - fixed channel auto reselection;
*) chr - added support for Azure guest agent;
*) console - fixed "tobool" conversion;
As you noticed, it is not.
by msatter
Sun May 17, 2020 10:33 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

Most of the time but as soon you enter /system script environment and want see the values then you use print. It is a mix and one part of you line you are in printing area and to print the variable outside that, put is used.

If you can't print by using put try print, is one thing to remind.
by msatter
Sun May 17, 2020 10:25 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

The print is a official command like put is. Print can do other stuff then put and they are used to their specific purpose. Print is print and put is printing using put. Some things are just not straight forward. The variable is returned as a string and tobool will not convert it. You could just com...
by msatter
Sun May 17, 2020 10:17 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

I gave two answers to two questions.

In environment all globals live. If not there then it is not a global.

Why do you need print while you have put and set?

For your script it is known that tobool is broken since a long time.
by msatter
Sun May 17, 2020 10:12 pm
Forum: Scripting
Topic: How to auto-start a script at interface link up / down ? [SOLVED]
Replies: 30
Views: 3764

Re: How to auto-start a script at interface link up / down ? [SOLVED]

You can print in /system script environment.

If :global is not found set it with a value:

$shortname contains the variable name used in environment.
:if ([/system script environment find name=$shortName]) do={} else={[:parse "global $shortName 99"];};
by msatter
Sun May 17, 2020 6:23 pm
Forum: Scripting
Topic: Do LED flashes
Replies: 5
Views: 570

Re: Do LED flashes

I made a string of a boolean so change it to:
:local a "true"; --> :local a true;
by msatter
Sun May 17, 2020 4:46 pm
Forum: Scripting
Topic: Do LED flashes
Replies: 5
Views: 570

Re: Do LED flashes

On down: /system leds; :local a "true"; :do {set 0 type=off; :delay 2s; set 1 type=on;} while ($a); On up: /system leds set 0 type=on; I have not tested it. and $a is always true and on up the led setting is overwritten. If the blinking does not stop then go to /system scripts environment jobs and k...
by msatter
Sun May 17, 2020 12:57 pm
Forum: Scripting
Topic: Do LED flashes
Replies: 5
Views: 570

Re: Do LED flashes

There is no specific command for flashing. You have to write your own script to do this.
by msatter
Sun May 17, 2020 11:20 am
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 54
Views: 11571

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

The problem is thst first have to read whole list before you can start reducing.

If Miktotik implement resume download then we could chop up the file in little parts.
by msatter
Sat May 16, 2020 5:49 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

Look at the postings above the earlier by me: https://forum.mikrotik.com/viewtopic.php?f=21&t=154662#p793526 The were busy with the server and restored backups or used previous versions and are now at a point it works again. Sadly the Beta60 is not listed but the are on the server. To get the Beta60...
by msatter
Sat May 16, 2020 1:00 pm
Forum: General
Topic: use static DNs in home network [SOLVED]
Replies: 10
Views: 1131

Re: use static DNs in home network [SOLVED]

URL: http://connect.com
Domain: connect.com

Enter only domains in the Domain Name Server (DNS)
www is a sub-domain of www.connect.com and normally the WWW server does this for you.

I hope I did not spoil your day with this. ;-)
by msatter
Sat May 16, 2020 11:07 am
Forum: General
Topic: Using CGNAT (NAT444) to contain an flooding attack
Replies: 1
Views: 340

Using CGNAT (NAT444) to contain an flooding attack

I was reading in the Wiki about setting up a CGNAT and thought this could also be used to limit traffic hitting Connection tracking in the routers. When you look at traffic going from clients to the outside you see that that traffic get random high port-numbers and on return that port number and IP ...
by msatter
Fri May 15, 2020 5:48 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

Hoping that this did not slowed down the release of a new 6.47Beta.
by msatter
Wed May 13, 2020 5:31 pm
Forum: Scripting
Topic: Get last entry from RoS
Replies: 2
Views: 396

Re: Get last entry from RoS

:foreach ID in=[/ip fire nat find comment="NAT 2"] do={:set $lastLine $ID}; print where .id=$lastLine;
by msatter
Wed May 13, 2020 10:41 am
Forum: Scripting
Topic: Colon or not to Colon
Replies: 5
Views: 827

Re: Colon or not to Colon

From the WiKi: Every global command should start with ":" token, otherwise it will be treated as variable. How is that working in the new API (ROS-7) and maybe we are in a transfer to that and the Colon is not handled that strict anymore. I also noted that having to usde define :global to have acces...
by msatter
Wed May 13, 2020 1:46 am
Forum: General
Topic: Firewall Rule against Botnet Attacks?
Replies: 6
Views: 1077

Re: Firewall Rule against Botnet Attacks?

Looking at the log I notice that the destination port targeted by different adresses and the only thing you should look at ate the ports. Using IP adresses in any form is futile. If they use 53 and 389 and you have different requests from different IP drop that destination port for a short time. No ...
by msatter
Tue May 12, 2020 5:36 pm
Forum: Scripting
Topic: Find item by ID
Replies: 3
Views: 440

Re: Find item by ID

In signature you see a link and that topic also contains a script to restart a peer if it went down. It only restarts peers that are enabled and you can rewrite that to enable disabled peers. A meaningful name for the peer is essential or you have to use the comment field as already suggested. This ...
by msatter
Tue May 12, 2020 2:24 pm
Forum: General
Topic: RB4011 random reboots
Replies: 23
Views: 2087

Re: RB4011 random reboots

I have autosupout.rif in the files of my 4011RM and I think is also generated if you reset the router by holding the reset button to reset.

I don't remember what happened then and just received the 4011 and I used once a hard reset.
by msatter
Tue May 12, 2020 2:19 pm
Forum: General
Topic: ISP SFP GPON in HEX S
Replies: 14
Views: 1861

Re: ISP SFP GPON in HEX S

Maybe it would good to put a link to your posting in the ip-phone-forum and back so it will be found easier for others in the future.
by msatter
Tue May 12, 2020 12:22 pm
Forum: General
Topic: ISP SFP GPON in HEX S
Replies: 14
Views: 1861

Re: ISP SFP GPON in HEX S

Really great that you managed it and you had the right tools to archive this. You made great use of it and please put this also on the IP-Phone-forum so that more can follow you way.

Enjoy your archivement! :D
by msatter
Sun May 10, 2020 4:01 pm
Forum: Scripting
Topic: Script to control uptime [SOLVED]
Replies: 36
Views: 3700

Re: Script to control uptime [SOLVED]

To retrieve the uptime:
/system resource> :put [get uptime]; 
And in into a variable:
{
:local getUptime [/system resource get uptime]
:put $getUptime
} 
by msatter
Sun May 10, 2020 3:48 pm
Forum: Scripting
Topic: Cleaning characters from string for use in variablename
Replies: 2
Views: 413

Re: Cleaning characters from string for use in variablename

The example functions are :global but it seems that I also can use the :local. { local cleanStringFunc do={ while condition=[find $1 $2] do={ set $1 ("$[pick $1 0 ([find $1 $2]) ]".$3."$[pick $1 ([find $1 $2]+1) ([len $1])]")} return $1 } put [$cleanStringFunc "Can-t-be-used-as-name-for-variable" "-...
by msatter
Sun May 10, 2020 3:12 pm
Forum: Scripting
Topic: Cleaning characters from string for use in variablename
Replies: 2
Views: 413

Re: Cleaning characters from string for use in variablename

And as an function, my first one :-) { global cleanStringFunc do={ while condition=[find $1 $2] do={ set $1 ("$[pick $1 0 ([find $1 $2]) ]"."$[pick $1 ([find $1 $2]+1) ([len $1])]")} return $1 } put [$cleanStringFunc "Can-t-be-used-as-name-for-variable" "-"] } Notice: because of the { at the beginni...
by msatter
Sun May 10, 2020 12:03 pm
Forum: Scripting
Topic: Cleaning characters from string for use in variablename
Replies: 2
Views: 413

Cleaning characters from string for use in variablename

{ local a "Can-t-be-used-as-name-for-variable" local b "-" :while condition=[find $a $b] do={ :set $a ("$[:pick $a 0 ([find $a $b]) ]"."$[:pick $a ([find $a $b]+1) ([:len $a])]")} :put "Result string: $a" } Result string ($a): Cantbeusedasnameforvariable The :local variable $b contains the single u...
by msatter
Sat May 09, 2020 12:31 pm
Forum: General
Topic: Norton Secure VPN and Router OS [SOLVED]
Replies: 7
Views: 1075

Re: Norton Secure VPN and Router OS [SOLVED]

Good that you find the cause of not being able to connect to the VPN. You can mark your own post (above) solved.
by msatter
Sat May 09, 2020 1:14 am
Forum: General
Topic: Norton Secure VPN and Router OS [SOLVED]
Replies: 7
Views: 1075

Re: Norton Secure VPN and Router OS [SOLVED]

Just a quick look by me and you create a list "Port Scanners" and make sure that the source address of Symantec server is not on that list. /ip firewall filter add action=add-src-to-address-list address-list="Port Scanners" address-list-timeout=6h chain=input comment="Port Scanners" in-interface-lis...
by msatter
Fri May 08, 2020 7:16 pm
Forum: Beginner Basics
Topic: nslookup on Mikrotik
Replies: 17
Views: 35223

Re: nslookup on Mikrotik

If you want to use the result in a other script then you should use :global, as ChaOs suggested.
by msatter
Fri May 08, 2020 5:59 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

I got an answer from Mikrotik support that is fixed in a next version(s) of RouterOS. Now I have changed the setup of the different devices so that I don't have to take half of them of the wall to just put an other device on the fiber connector. I had extra fiber cables and adapters for and made the...
by msatter
Fri May 08, 2020 4:43 pm
Forum: Beginner Basics
Topic: nslookup on Mikrotik
Replies: 17
Views: 35223

Re: nslookup on Mikrotik

:set $result [:resolve mt.lv]; :put $result
by msatter
Fri May 08, 2020 1:47 pm
Forum: General
Topic: Norton Secure VPN and Router OS [SOLVED]
Replies: 7
Views: 1075

Re: Norton Secure VPN and Router OS [SOLVED]

From the outside they are closed. That is how a statefull firewall works you can only open a window in the firewall from the inside.

Check if port 500 and 4500 UDP (ipsec) are allowed to open such a window.
by msatter
Fri May 08, 2020 1:39 pm
Forum: General
Topic: How to drop established coonections
Replies: 4
Views: 609

Re: How to drop established coonections

I assume that it are TCP connections that have a time-out of 1 day in the connections table. When you remove the exiting connection there then a new connection has to be made but that will not happen because that is disabled then. Removing is very easy because you know the port. You csn use a schedu...
by msatter
Fri May 08, 2020 1:02 am
Forum: General
Topic: Filter to show
Replies: 10
Views: 1334

Re: Filter to show

I don't assume that many here are willing to help you with this. Spying on your users is not nice to be doing.
by msatter
Thu May 07, 2020 8:25 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS, turn off blue LED, still not possible?
Replies: 2
Views: 687

Re: RB4011iGS, turn off blue LED, still not possible?

I use a small piece of gray tape. No sunglasses needed anymore. ;-)
by msatter
Thu May 07, 2020 6:10 pm
Forum: General
Topic: ISP SFP GPON in HEX S
Replies: 14
Views: 1861

Re: ISP SFP GPON in HEX S

I noticed that you already found the IP-Phone-Forum which is the place to go when having a AVM device.

It look like you have to get a GPON that is changeable without having it to be flashed by a programmer. In the Spain thread a lot is talked about those.
by msatter
Thu May 07, 2020 1:30 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

For all DoT lovers out there, I'm bringing fresh official bad news. Received yesterday, directly from MT support:
Unfortunately, DoT is not planned to be implemented in the near future.
:-(
by msatter
Wed May 06, 2020 11:39 pm
Forum: General
Topic: Redundant uplinks and 2 mikrotik routers
Replies: 3
Views: 764

Re: Redundant uplinks and 2 mikrotik routers

On the moment the VRRP switches you have script on event available. One script for each router and one script for both configs on either router .
by msatter
Wed May 06, 2020 10:55 pm
Forum: General
Topic: Redundant uplinks and 2 mikrotik routers
Replies: 3
Views: 764

Re: Redundant uplinks and 2 mikrotik routers

You can think of a double VRRP. It called load sharing.

https://wiki.mikrotik.com/wiki/Manual:VRRP-examples

The IP becomes active when the other one fails. You have then a virtual between the routers and both have access to the upstream switch.
by msatter
Wed May 06, 2020 9:27 pm
Forum: General
Topic: ISP SFP GPON in HEX S
Replies: 14
Views: 1861

Re: ISP SFP GPON in HEX S

Darn it was in front of me and try ssh to IP: 192.168.47.1 as you found with the help of Wireshark. First do a IP Scan to see if it lives as that IP.
by msatter
Wed May 06, 2020 1:46 pm
Forum: General
Topic: ISP SFP GPON in HEX S
Replies: 14
Views: 1861

Re: ISP SFP GPON in HEX S

Spain: viewtopic.php?f=3&t=116364&p=789506&hilit=spain#p762916

It is not the solution but a start for you.
by msatter
Tue May 05, 2020 9:58 pm
Forum: General
Topic: ipsec ikev2 vpn doesn't do his work [SOLVED]
Replies: 6
Views: 1896

Re: ipsec ikev2 vpn doesn't do his work [SOLVED]

Update: I tested with an eye on the load on the processor and NoTrack is ideal for ipsec (protocol 50) and the tunnel (UDP/4500) can be fastracked and that is the fasted method for that. I can even hide fasttracked untracked traffic but I did not see a advantage in that. I is still strange to me, to...
by msatter
Tue May 05, 2020 11:39 am
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

I have adapted my "way of handling symbols" so you can untwist your eyes again see straight as an arrow. ;-) That the FTTH POP is wideband I expected and the forums never agree on which to use 1490nm or 1550nm, it works both. I have to order the Tx1550/Rx1310nm SFP and some armored cabling so I will...
by msatter
Tue May 05, 2020 10:29 am
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

I have looked up the information on the NTU that is being used and that is a Genexis MC901. It can do both speeds 100Mbit and 1000Mbit fiber. The frequency used is Tx 1310 Rx 1490/1550nm and the dBm is Tx -9 -3 and Rx -3 -23. There are 1G SFP Wideband BiDi LX that have a wider bandwidth 1460-1580nm ...
by msatter
Mon May 04, 2020 6:26 pm
Forum: General
Topic: ISP SFP GPON in HEX S
Replies: 14
Views: 1861

Re: ISP SFP GPON in HEX S

If you search for the word "spain" here you will find a lot postings about gpon andaccess.
by msatter
Mon May 04, 2020 5:56 pm
Forum: Wireless Networking
Topic: DNS Fasttrack and security
Replies: 1
Views: 579

Re: DNS Fasttrack and security

DNS is only tiny bits of information so not much to gain by fasttracking it. Why should it be a DDoS. It are responses to your resolve requests and so statefull. Fasttrack should inspect the first package and time to time also packages in the stream. DNS exists in one or two packets returning so Fas...
by msatter
Mon May 04, 2020 3:56 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

So.......tested it and it is not the SFP but RouterOS. The latest beta does not enforce 1GB if you set it manually instead of Auto-negotiated. I have not tried previous beta's and rather wait till Mikrotik fixed this problem. I tried 6.46.6 and that got a connection but the MTU started at 1500 on th...
by msatter
Sun May 03, 2020 9:12 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

I have my 4011 just 25 hours and is really a fast router but also it's edges. IKEv2 is at 800Mhz just a bit faster then two hEX-S in series. On 1400Mhz I ran out of ISP bandwith, just to browse. ;-) I call the 4011 my 'little stove' because it such a darn hot router...and looks like that also. Got a...
by msatter
Sun May 03, 2020 7:35 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

Oops, did not thought that trough. Next time I order I will also get the other ones.

Thanks for the hint. Saves a bit of work and frustration followed by deep shame. ;-)
by msatter
Sun May 03, 2020 6:34 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

Re: SFP working in hEX-s but not in the 4011

I will check that tomorrow because I have already placed back the NTU on the fiber to have Internet. I also going to try a direct link between the hEX-s and the 4011 to see if that works. Got plenty of modules and a fiber cable for that.
by msatter
Sun May 03, 2020 5:53 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1949

SFP working in hEX-s but not in the 4011

I have a internet fiber connection and am using FS GE-BX (#20140) modules 10 and 20 km. Worked perfectly in the hEX-s but not in the 4011. I get all the normal information in the SFP screen and a link OK. When running Torch I see my PPPoE-discovery being transmitted but there seems to be no answer. ...
by msatter
Sun May 03, 2020 1:08 pm
Forum: Scripting
Topic: delete address list old than 7 days
Replies: 14
Views: 2323

Re: delete address list old than 7 days

Not sure why its not working, but since you already have the ID of the line to delete, just use the ID like this: Very nice. Running this will show the *id of each found entry so you known how it looks. Every line and entry in RouterOS have a unique *id number. You can use that *id directly. { :for...
by msatter
Sun May 03, 2020 12:54 pm
Forum: General
Topic: Limit unknown unicasts, Limit unknown multicasts
Replies: 3
Views: 732

Re: Limit unknown unicasts, Limit unknown multicasts

unknown-multicast-flood (yes | no; Default: yes) When enabled, bridge floods unknown multicast traffic to all bridge egress ports. When disabled, drops unknown multicast traffic on egress ports. Multicast addresses that are in /interface bridge mdb are considered as learned multicasts and therefore ...
by msatter
Sun May 03, 2020 12:04 am
Forum: Beginner Basics
Topic: Nordvpn or surfshark with mikrotik through ikev2
Replies: 3
Views: 921

Re: Nordvpn or surfshark with mikrotik through ikev2

When you want to use Netlfix then you have to connect in a other way. They have dedicated servers for that and the ones used in the Mikrotik is for general use. The best you can ask the helpdesk and in your case Surfshark if it possible do it over IKEv2 and not over OpenVPN? https://support.surfshar...
by msatter
Fri May 01, 2020 10:29 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6178

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

Thanks mkx and I also gained some new insights. Looking in the wiki I found this in the bridge page: /interface bridge port set [f] horizon=1 And first thought the "f" stood for false but doing a bit of scripting in RouterOS saw that that it standing for find. It would be so nice that the manual wou...
by msatter
Thu Apr 30, 2020 12:56 am
Forum: General
Topic: Work not evenly distributed among the multiple CPU cores
Replies: 7
Views: 1436

Re: Work not evenly distributed among the multiple CPU cores

Unclassified is on my MMIPS very quit and almost always zero. The ARM processor devices show often unclassified being maxed out when they reboot/crash.
by msatter
Wed Apr 29, 2020 2:35 pm
Forum: General
Topic: High number of established connections for one address
Replies: 25
Views: 3185

Re: High number of established connections for one address

Hello, i would like to extend this topic further, i have similar situation where lots of connections are established toward my client with 0/0 orig rate and bytes. I see that these connections are established backward only when client established connection to some https server. How i can filter su...
by msatter
Wed Apr 29, 2020 2:43 am
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

You are not in the same situation because this topic goes about not being to see the preview in this forum due to problems of ICMP 3/4 packets not being return to the client by the router. Please open a own topic on this. Update: I had quick look and is your DNS resolving? You can test that quickly ...
by msatter
Wed Apr 29, 2020 12:45 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 93
Views: 17986

Re: RB4011 and RB1100 AHx4 "bricks" randomly

Looking for a long time at the 4011 and I afraid that it will stay with looking at and not buying.
by msatter
Wed Apr 29, 2020 12:08 am
Forum: Beginner Basics
Topic: Fasttrack wiki page lacks real world example with filter and/or mangle rules
Replies: 14
Views: 2007

Re: Fasttrack wiki page lacks real world example with filter and/or mangle rules

I think the following wiki page needs an update as well: https://wiki.mikrotik.com/wiki/Manual:Packet_Flow#Configurable_Facilities The said raw table from https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Raw is missing there in the list under "Configurable Facilities". The Wiki is not a full manua...
by msatter
Tue Apr 28, 2020 11:56 pm
Forum: Beginner Basics
Topic: Fasttrack wiki page lacks real world example with filter and/or mangle rules
Replies: 14
Views: 2007

Re: Fasttrack wiki page lacks real world example with filter and/or mangle rules

Untrack gives about a 30% increase in speed and is used for example in IPSEC that does not need connection tracking to function. With the introduction (rules before connection tracking) this became posible. I do most of my filtering in RAW but it has it limation because it has not trigger on invalid...
by msatter
Tue Apr 28, 2020 9:04 pm
Forum: Beginner Basics
Topic: Fasttrack wiki page lacks real world example with filter and/or mangle rules
Replies: 14
Views: 2007

Re: Fasttrack wiki page lacks real world example with filter and/or mangle rules

Fasttrack could have some more love and attention in the Wiki. The example shown are showing the dummy rules counting the fasttracked traffic. Showing you if you fastrack rule is working. Fasttrack forwarded traffic should be done before accept rule or you won't the dummy counters increase. If you o...
by msatter
Tue Apr 28, 2020 2:16 pm
Forum: General
Topic: [Solved] Accelerate forward IP-SEC...should be in a tunnel [SOLVED]
Replies: 6
Views: 1153

Re: Accelerate forward IP-SEC [SOLVED]

Thanks again Sindy. :D I found now the perpetrator and as it was indeed because of doing double NAT. When having to use double NAT I have to enable Nat traversal in IPSEC Profiles. This not being enabled, I got two separate streams on the GW from coming the inner. I was already asking myself why the...
by msatter
Tue Apr 28, 2020 1:22 pm
Forum: General
Topic: [Solved] Accelerate forward IP-SEC...should be in a tunnel [SOLVED]
Replies: 6
Views: 1153

Re: Accelerate forward IP-SEC [SOLVED]

It does not need a public address as the GW is providing that. It enters the GW router and looks for the address of the VPN provider not finding it there. Then it takes the door out and the internal source addres is replaced by the GW public address in NAT......darn then it could be is double natted...
by msatter
Tue Apr 28, 2020 1:09 pm
Forum: General
Topic: [Solved] Accelerate forward IP-SEC...should be in a tunnel [SOLVED]
Replies: 6
Views: 1153

Re: Accelerate forward IP-SEC [SOLVED]

Both router are doing IKEv2 on it's own. On the inner router traffic is divided by PCC and connection-marked to the inner IKEv2 or to the GW router. In NAT the traffic marked, for the GW is source natted to to the GW router. There it is handled by the GW IKEv2 en/de-crypter. Two streams are present ...
by msatter
Tue Apr 28, 2020 11:39 am
Forum: General
Topic: [Solved] Accelerate forward IP-SEC...should be in a tunnel [SOLVED]
Replies: 6
Views: 1153

[Solved] Accelerate forward IP-SEC...should be in a tunnel [SOLVED]

I am using two routers in series and IPSEC traffic going through the second router which generated by the first router. That traffic puts a high load on the second router (GW). It won't be accelerated and I can put plus 500 M/bit/s through it and it will hardly break out a sweat (fastrack) but 170 M...
by msatter
Tue Apr 28, 2020 12:55 am
Forum: General
Topic: TCP Flags with inverse
Replies: 3
Views: 1333

Re: TCP Flags with inverse

Test it and this seems to be the same:
TCPflags.JPG
by msatter
Mon Apr 27, 2020 8:57 pm
Forum: General
Topic: Failover not working [SOLVED]
Replies: 19
Views: 3086

Re: Failover not working [SOLVED]

Here is also a manual/topic about this:

viewtopic.php?f=23&t=157048
by msatter
Mon Apr 27, 2020 6:34 pm
Forum: Beginner Basics
Topic: How to send PM to other user (ie. privately contacting a user)? [SOLVED]
Replies: 13
Views: 1785

Re: How to send PM to other user (ie. privately contacting a user)? [SOLVED]

OK, have fun. It's enabled.
Having fun here. Never seen PM enabled.

It makes life a lot easier and spam....lets see if we can handle that.

THANKS!!!
by msatter
Sun Apr 26, 2020 6:32 pm
Forum: Announcements
Topic: Winbox v3.23 released!
Replies: 60
Views: 25840

Re: Winbox v3.23 released!

I keep resizing the windows in Winbox 3.23 64 on Windows 10 64. More than half of the time I am resizing windows to a smaller size instead of working in Winbox on the settings. It really a PITA this way. Update: I was working on three routers using the same profile and I am now trying to have for ea...
by msatter
Sat Apr 25, 2020 10:22 am
Forum: General
Topic: ipsec ikev2 vpn doesn't do his work [SOLVED]
Replies: 6
Views: 1896

Re: ipsec ikev2 vpn doesn't do his work [SOLVED]

I am hiding the tunnels (UDP 4500) created by the IKEv2 and the ESP (protocol 50) this way in connections. In the upstream router I can't hide those anymore because there is no IPSEC handling active for those connections. On the upstream I do the the same for the IKEv2 connections that are handled b...
by msatter
Sat Apr 25, 2020 1:30 am
Forum: General
Topic: ipsec ikev2 vpn doesn't do his work [SOLVED]
Replies: 6
Views: 1896

Re: ipsec ikev2 vpn doesn't do his work [SOLVED]

It works for me and the difference is that I use for the second line output and not prerouting and I put those in manually. 1 ;;; IKEv2 from GW-router in and out. Make them invisible in connections and using so less processor time. chain=prerouting action=notrack src-address-list=NoTrackIKEV 2 chain...
by msatter
Fri Apr 24, 2020 6:04 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

Yes! Mikrotik, you made my day! One thing, though: Looks like DNS forwarding does not work if DoH configuration is active. I think the forwarding should have priority over DoH. That is a chicken and egg problem. Lets say you need to resolve the DoH for google. add name=dns.google ns=8.8.8.8 type=NS...
by msatter
Fri Apr 24, 2020 5:31 pm
Forum: General
Topic: blackhole/unreachable with IPSec policies [SOLVED]
Replies: 29
Views: 4579

Re: blackhole/unreachable with IPSec policies [SOLVED]

Thanks Sindy and I have tried it but not traffic was seen on that GRE interface. Despite the traffic is routing marked it, it did not appear. The only way is to use dst-nat and then the traffic is seen with torch and then I can blacklist it in route then. Works great. This is ideal when the IKEv2 is...
by msatter
Fri Apr 24, 2020 3:34 pm
Forum: Beginner Basics
Topic: IKEV2/1 certificate problem with routeros and NordVON and Surfshark
Replies: 11
Views: 1602

Re: IKEV2/1 certificate problem with routeros and NordVON and Surfshark

Here I got a fact: the mikrotik tutoril for surfshark states peer-->address-->exchange-mode=main, in the tutorial you gae the link it's exchange-mode=ike2 The rest is exaktly the same. So I changed in exchange-mode=ike2 and ... it accepted the identity setting!!! Can it have been the problem? I che...
by msatter
Thu Apr 23, 2020 1:06 pm
Forum: Scripting
Topic: delete address list old than 7 days
Replies: 14
Views: 2323

Re: delete address list old than 7 days

creation-time~"apr"
change it to
creation-time~"mar"
by msatter
Wed Apr 22, 2020 5:44 pm
Forum: Beginner Basics
Topic: IKEV2/1 certificate problem with routeros and NordVON and Surfshark
Replies: 11
Views: 1602

Re: IKEV2/1 certificate problem with routeros and NordVON and Surfshark

Bo I don't understand what do you mean in creating a new identity? I used also this certificate but nothing changes. It is that RouterOs doesn stuck with eap - CHAPv2 ... So nobody has a VPN from surfshark or NordVPN runnig? I am stuck when creating a new identity. You however create a new connecti...
by msatter
Wed Apr 22, 2020 3:27 pm
Forum: Beginner Basics
Topic: IKEV2/1 certificate problem with routeros and NordVON and Surfshark
Replies: 11
Views: 1602

Re: IKEV2/1 certificate problem with routeros and NordVON and Surfshark

I can't help you on this because I am death in the water when adding a indentity here. Wrong mode-config..did I chose a wrong mode config or the mode config is wrong. God only knows why. So the certificate is a Sectigo one according to crt.sh: 2337282437 2020-01-15 2020-01-15 2021-01-14 *.prod.surfs...
by msatter
Wed Apr 22, 2020 1:57 pm
Forum: General
Topic: DNS over HTTPS
Replies: 23
Views: 3411

Re: DNS over HTTPS

Uh, google does a redirect there... So use this: /ip dns static add address=8.8.8.8 name=dns.google /ip dns static add address=8.8.4.4 name=dns.google /ip dns set use-doh-server=https://dns.google/dns-query verify-doh-cert=yes Maybe this can be combined to a bootstrap IP. Also adding the direct IP ...
by msatter
Wed Apr 22, 2020 1:13 pm
Forum: Beginner Basics
Topic: Portforward Client IPs show up as the router? [SOLVED]
Replies: 4
Views: 1142

Re: Portforward Client IPs show up as the router? [SOLVED]

If you use an other router/modem in front of this router have them route traffic to you and not have them use src-nat of have them use dst-nat.
by msatter
Wed Apr 22, 2020 11:24 am
Forum: General
Topic: DNS over HTTPS
Replies: 23
Views: 3411

Re: DNS over HTTPS

For Google you still a first resolve through a normal DNS or it will not know how to reach the DOH of Google. Cloudflare used a trick to by putting 1.1.1.1 as alternative name in their certificate.
by msatter
Wed Apr 22, 2020 11:10 am
Forum: General
Topic: blackhole/unreachable with IPSec policies [SOLVED]
Replies: 29
Views: 4579

Re: blackhole/unreachable with IPSec policies [SOLVED]

I am revisiting this tread again while busy to create a Kill-Switch for IKEv2. Till now I blackholed traffic by using a src-nat to 127.0.0.1 and noticed a few day ago that the traffic was reaching the next router in my network. I put a rule in that router in RAW to drop any traffic coming from 127.0...
by msatter
Wed Apr 22, 2020 10:37 am
Forum: General
Topic: Simple routing..not so simple for me
Replies: 2
Views: 1045

Simple routing..not so simple for me

I have been trying a few times but I can't get it working. I have a local network in the 192.168.1/0/24 range. I have now two routers behind each other and that works. Now I want to put a third router in between to accelerate IKEv2 as I do with the two routers. Router 1 has the local network attache...
by msatter
Wed Apr 22, 2020 10:12 am
Forum: Beginner Basics
Topic: IKEV2/1 certificate problem with routeros and NordVON and Surfshark
Replies: 11
Views: 1602

Re: IKEV2/1 certificate problem with routeros and NordVON and Surfshark

openssl s_client -connect us-dal.prod.surfshark.com:443 CONNECTED(00000005) depth=2 C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority verify return:1 depth=1 C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo...
by msatter
Wed Apr 22, 2020 9:40 am
Forum: Beginner Basics
Topic: IKEV2/1 certificate problem with routeros and NordVON and Surfshark
Replies: 11
Views: 1602

Re: IKEV2/1 certificate problem with routeros and NordVON and Surfshark

IKEv2cert.JPG
As I wrote the manual by Surfshark is wrong on this. You should make the box empty (click the top triangle) and the certificate they provided should be found then.
by msatter
Wed Apr 22, 2020 9:05 am
Forum: General
Topic: How to remove an unused Routing Mark?
Replies: 1
Views: 630

Re: How to remove an unused Routing Mark?

Routing mark main will always be there because that is the same as not routing marked.

There are parts of the config that are not exported, like users.
by msatter
Tue Apr 21, 2020 8:51 pm
Forum: Beginner Basics
Topic: IKEV2/1 certificate problem with routeros and NordVON and Surfshark
Replies: 11
Views: 1602

Re: IKEV2/1 certificate problem with routeros and NordVON and Surfshark

You don't point to the cetificate. The cerificate should be present in the certificate store on your router to be found. Their manual is wrong on that point.I have not check the rest of their manual. https://support.surfshark.com/hc/article_attachments/360010703300/addidentity17.png https://support....
by msatter
Tue Apr 21, 2020 8:49 pm
Forum: General
Topic: ip neighbours bug
Replies: 2
Views: 883

Re: ip neighbours bug

Send a e-mail to support@mikrotik.com so they can correct it a next release.
by msatter
Tue Apr 21, 2020 2:11 pm
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

I use the provided config by Mikrotik in the Wiki and I use connection-marking to selrct the traffic I want have handled by the VPN. Fasttracking and IPSEC is a no-no. The policy has to be at the top in /ip ipsec policy table and the NordVPN lines underneath. To be sure the order is correct you coul...
by msatter
Sun Apr 19, 2020 7:03 pm
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

When I temember it well you use the DoH client in RouterOS to connect to Cloudflare. This DNS DoH traffic is not passing through the VPN because only your client IP 192.168.0.5 is using only the VPN. The shortest way for now is to use the dynamic DNS server of NordVPN and disable DoH. This if you do...
by msatter
Sun Apr 19, 2020 1:30 pm
Forum: RouterOS v7 BETA
Topic: Mysterious 564/tcp open port 7.0beta5
Replies: 38
Views: 6175

Re: Mysterious 564/tcp open port 7.0beta5

That is what you are told and as all things in life that does not have to reflect reality.
by msatter
Sat Apr 18, 2020 11:20 pm
Forum: Useful user articles
Topic: Turn off LEDs using the MODE button
Replies: 7
Views: 3252

Re: Turn off LEDs using the MODE button

I just noticed the the new docs is not updated on this.

https://help.mikrotik.com/docs/display/ ... ion-Health
by msatter
Sat Apr 18, 2020 1:03 pm
Forum: Useful user articles
Topic: Turn off LEDs using the MODE button
Replies: 7
Views: 3252

Re: Turn off LEDs using the MODE button

By helppage you mean the Manual inside Winbox. That is displaying the Wiki and states:

RB760iGS (hEX S) Turns off Power LED and SFP LED


On the RB760iGS you can only control the Power and SFP LED.
by msatter
Sat Apr 18, 2020 2:41 am
Forum: Useful user articles
Topic: Turn off LEDs using the MODE button
Replies: 7
Views: 3252

Re: Turn off LEDs using the MODE button

The wiki page is correct and Becs corrected it from all to only the Power LED and SFP leds.

https://wiki.mikrotik.com/index.php?tit ... ldid=33661
by msatter
Fri Apr 17, 2020 1:37 pm
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

Then add the ICMP in /ip pisec policy underneath the default *T (template) line and then start your NordVPN connection. Not underneath, above !!! The ICMP packets from Mikrotik itself to the LAN hosts must hit the action=drop policy before hitting the dynamically created one!! I wrote underneath th...
by msatter
Fri Apr 17, 2020 12:35 pm
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

You are using DOH and there also dynamic DNS servers from NordVPN active try it with DOH deactivated. Should not make a difference but better one captain on the ship. Let me know if you find somthing and else just remove the current config and leave the defaults (also active) and do a new IPSEC Nord...
by msatter
Fri Apr 17, 2020 11:54 am
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

Thanks Cindy and I have tried now for each of my VPN provides a dedicated line instead of the one default one. First I see (print detail) the template, then the DA lines and underneath those the T line for ICMP. This after restarting the VPN connections. I don't think a dedicated template is needed ...
by msatter
Fri Apr 17, 2020 11:31 am
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

I have my template on the group=default. To have it positioned then, then the *T on should be on position 0. When adding it should land on the correct spot underneath *T.

Indeed removing the template and in my the posting above I have addressed that.
by msatter
Fri Apr 17, 2020 11:19 am
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

The MTU on the PPPoE is no problem and are you sure the VPN is up again? I see now a set 1 group=NordVPN add group=NordVPN proposal=NordVPN template=yes or set 1 group=NordVPN proposal=NordVPN template=yes Check if your proposal is the same as I wrote or replace it with your own proposal. Update: as...
by msatter
Fri Apr 17, 2020 11:09 am
Forum: Beginner Basics
Topic: Turn off all RB760iGS leds
Replies: 7
Views: 1678

Re: Turn off all RB760iGS leds

Strange that someone "Becs" fixed the documentation yesterday "Latest revision as of 09:24, 16 April 2020 (view source)" and did not comment in this thread. I am sure that documentation was updated due to this thread. It starts to look like Mikrosoft. Instead of fixing the problem, we just change t...
by msatter
Fri Apr 17, 2020 11:03 am
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

It's simple - the policy you've added must be placed before (above) the template from which the IKEv2 connection creates the actual policy for the connection. The order of policies matters the same way like the order of firewall rules does - the packet is matched to all of them starting from the to...
by msatter
Fri Apr 17, 2020 10:54 am
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

I have updated my first response to you. Enable the line with X*T and remove line with T . The one with the * is the default line. ::/0 is the same as 0.0.0.0/0 and covers also IPv6 if that is available. If you do test hit the preview button in this forum when writing a posting and if it is shown th...
by msatter
Fri Apr 17, 2020 10:23 am
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

I have to think about that and my first answer was not correct if you address range is 192.168.0.1-192.168.0.255 Update: I can't place the first line: /ip ipsec policy set 0 disabled=yes My template is also a bit different: /ip ipsec policy add group=NordVPN proposal=NordVPN template=yes On copy-pas...
by msatter
Thu Apr 16, 2020 10:57 pm
Forum: Beginner Basics
Topic: Turn off all RB760iGS leds
Replies: 7
Views: 1678

Re: Turn off all RB760iGS leds

https://wiki.mikrotik.com/index.php?tit ... ldid=33661
 	
    <td ><b>RB760iGS (hEX S)</b></td>
	 	
    <td ><b>RB760iGS (hEX S)</b></td>
−	
    <td >Turns off all LEDs</td>
	+	
    <td >Turns off Power LED and SFP LED</td>
by msatter
Thu Apr 16, 2020 3:12 pm
Forum: General
Topic: vpn attacks and how to block these connections
Replies: 8
Views: 1694

Re: vpn attacks and how to block these connections

Thanks msatter. I read your script. Correct me if im wrong the script reads the connections table and automatically puts the /24 subnet into an address list and then? you manually set a filter rule? I don't use the connections table. Every connection on a specfic port(s) are put on list one with a ...
by msatter
Wed Apr 15, 2020 10:34 pm
Forum: General
Topic: Speedtest.net
Replies: 2
Views: 1214

Re: Speedtest.net

Do both tests fail? Download and then upload. If only upload fails then then it is a problem with packet size.
by msatter
Wed Apr 15, 2020 12:37 pm
Forum: General
Topic: Security Vulnerabilities
Replies: 13
Views: 2403

Re: Security Vulnerabilities

Oof...that saves a lot of responding to support e-mails for Mikrotik. ;-)
by msatter
Wed Apr 15, 2020 12:03 pm
Forum: General
Topic: Security Vulnerabilities
Replies: 13
Views: 2403

Re: Security Vulnerabilities

From what I read this can't be reported through the vulnerability page of Mikrotik because you the user is already logged in.

It should then be reported as a bug to: support@mikrotik.com

Everyone can do that and refer in their support request to the page describing this bug.
by msatter
Wed Apr 15, 2020 11:52 am
Forum: General
Topic: vpn attacks and how to block these connections
Replies: 8
Views: 1694

Re: vpn attacks and how to block these connections

Here you go:

viewtopic.php?f=2&t=152953&p=758068&hilit=%2F24#p758068

Don't reject because the other side is not listening. If you do that in RAW then that gives the least impact on your router.
by msatter
Tue Apr 14, 2020 11:35 pm
Forum: Beginner Basics
Topic: Turn off all RB760iGS leds
Replies: 7
Views: 1678

Re: Turn off all RB760iGS leds

I had also a look and it seems that only the blue, brightest ones, can be switched off.
after-1h  after-1min  immediate  never
[mt@MikroTik] /system leds settings> set all-leds-off=
by msatter
Mon Apr 13, 2020 11:50 am
Forum: General
Topic: DNS question
Replies: 3
Views: 1160

Re: DNS question

When both static and dynamic servers are set, static server entries are more preferred, however it does not indicate that static server will always be used (for example, previously query was received from dynamic server, but static was added later, then dynamic entry will be preferred). It looks li...
by msatter
Fri Apr 10, 2020 10:45 pm
Forum: General
Topic: SIP Through IPSEC VPN Site to Site drops calls randomly
Replies: 30
Views: 4676

Re: SIP Through IPSEC VPN Site to Site drops calls randomly

I was writing that with an eye you not getting SIP logging.

Fast-track any traffic through a IPSEC/VPN is not wise and instead use no-track.
by msatter
Fri Apr 10, 2020 9:17 pm
Forum: General
Topic: SIP Through IPSEC VPN Site to Site drops calls randomly
Replies: 30
Views: 4676

Re: SIP Through IPSEC VPN Site to Site drops calls randomly

I see that a different port is used and the log could looking for ports 5060 and 5061. In /ip service you can add your port to the SIP line.

https://help.vantact.com/index.php?/Kno ... a-mikrotik
by msatter
Fri Apr 10, 2020 2:38 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

viewtopic.php?f=21&t=154662&p=784984#p780798

Enable logging and look for strange things.
by msatter
Fri Apr 10, 2020 12:56 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

I found a memory leak (or cleaning error) in the DNS (hEX v6.47beta53/54), after flushing the cache it is not reset to aprox. 17KiB, but grows until the device reboots, in this example 358KiB. Accordingly, it does not clean normally during working and only grows. I have not found this and do you us...
by msatter
Fri Apr 10, 2020 12:04 pm
Forum: Scripting
Topic: Script code syntax check [Check Selected]
Replies: 5
Views: 2176

Re: Script code syntax check [Check Selected]

Kingdom for standard "syntax error at line X, column Y"! :) It is displayed if you use { and } to contain the bit of code: { #Loop through names of the peers and see if they need restart :foreach peerName in=[find] do={ :lset $pn [get $peerName name ]; :if (![get $peerName disabled]) do={:if ([/ip ...
by msatter
Wed Apr 08, 2020 8:23 pm
Forum: General
Topic: Keep IKEv2 connections running [ script ]
Replies: 6
Views: 4178

Re: Keep IKEv2 connections running [ script ]

I am currently working a more flexible version with more option. It is going slow because scripting is not always easy and RouterOS is sometimes trowing a Enigma that has to be worked around.
by msatter
Wed Apr 08, 2020 8:20 pm
Forum: RouterOS v7 BETA
Topic: Mysterious 564/tcp open port 7.0beta5
Replies: 38
Views: 6175

Re: Mysterious 564/tcp open port 7.0beta5

Yes you can find that in less than two seconds on the internet.

What is it doing in the next RouterOS? Or is it something else?
by msatter
Tue Apr 07, 2020 8:40 pm
Forum: Scripting
Topic: Script code syntax check [Check Selected]
Replies: 5
Views: 2176

Re: Script code syntax check [Check Selected]

Went back in time and found this: /system script print where name="scriptname" You will get a full page and where the colour-full letters end there is the syntax incorrect. If this can be also reachable as described above one can easily check a part of a code. Second option: You can also use /system...
by msatter
Mon Apr 06, 2020 9:21 pm
Forum: Scripting
Topic: on-event filling and the "
Replies: 0
Views: 1367

on-event filling and the "

I tried, by using a script, to put [:parse "global ".... As soon it sees the " it assumes it ready and executes the rest. Is there a way to tell that the " is not the one to look at. I tried \" but that did not work. I was ending up putting in :local's and puzzle together the correct line. edit: Hol...
by msatter
Sun Apr 05, 2020 12:17 pm
Forum: RouterBOARD hardware
Topic: Mikrotik VDSL / DSL Modem?
Replies: 365
Views: 113467

Re: Mikrotik VDSL / DSL Modem?

In the Netherlands we have now free router/modem choice. The KPN which is the biggest provider on telephone lines, I can't recommend any Mikrotik router to whom is asking me due to no decent VDSL support. Many people are looking now for a better router than the one they are hiring right now from the...
by msatter
Wed Apr 01, 2020 6:08 pm
Forum: General
Topic: mark routing bunch of IP lists and route it through another gateway
Replies: 4
Views: 1263

Re: mark routing bunch of IP lists and route it through another gateway

You set which route is to be used in Mangle and are using a destination address list. Your own external IP is not destination but a source address.

So if destination address is not on the county list then mark for VPN. That would indeed be correct.
by msatter
Wed Apr 01, 2020 5:08 pm
Forum: Scripting
Topic: how clear Mikrotik Log ?
Replies: 20
Views: 14603

Re: how clear Mikrotik Log ?

I tried it and my loglines went down from 1475 to 1100 when I executed: /system logging action set memory memory-lines=100 Hmmm checking that closer..... Tried it now with 99 and the lines went from 1100 to 1099 so 1001 seems to be the minimum achievable. (edit clarification of 1001: 1000 disk lines...
by msatter
Wed Apr 01, 2020 12:38 pm
Forum: General
Topic: mark routing bunch of IP lists and route it through another gateway
Replies: 4
Views: 1263

Re: mark routing bunch of IP lists and route it through another gateway

If you use IKEv2 like NordVPN the you can't route that easy.

If you use OpenVPN or L2TP/IPSEC check if you disabled the default route in their settings.
by msatter
Wed Apr 01, 2020 12:26 pm
Forum: Scripting
Topic: how clear Mikrotik Log ?
Replies: 20
Views: 14603

Re: how clear Mikrotik Log ?

If you look at it which log-lines are important and which not that much the split you log up in memory and file. If router restart your memory log is gone and the file log is still there. If you want to have the opertunity to have a burst of loglines to look at the cause of a problem then use a othe...
by msatter
Tue Mar 31, 2020 11:37 pm
Forum: Scripting
Topic: Days remaining in the month..
Replies: 4
Views: 1422

Re: Days remaining in the month..

Everything is above my pay grade. ;-) You can have a look overhere: https://forum.mikrotik.com/viewtopic.php?f=9&t=150168&p=739572&hilit=date+calculation#p739572 https://github.com/phistrom/datetime-routeros/blob/master/README.md And a scipt from which you can build your own: ### calculate diff betw...
by msatter
Tue Mar 31, 2020 9:19 pm
Forum: Scripting
Topic: Script code syntax check [Check Selected]
Replies: 5
Views: 2176

Re: Script code syntax check [Check Selected]

I have have been a lot of coding in RouterOS lately and have some more insight now how to syntax check can bea lot easier. I first said that combining to one line was good, however there is a better way. If I want to check code now I add an "\" at the end of the list and then select it and past it i...
by msatter
Tue Mar 31, 2020 12:51 am
Forum: General
Topic: Exclude IPs from NAT rules (DNS redirect)
Replies: 4
Views: 1365

Re: Exclude IPs from NAT rules (DNS redirect)

Do the counters increase on those two lines if there is traffic natted?
by msatter
Mon Mar 30, 2020 10:23 pm
Forum: General
Topic: Exclude IPs from NAT rules (DNS redirect)
Replies: 4
Views: 1365

Re: Exclude IPs from NAT rules (DNS redirect)

You are in different subnets and if the clients know the DNS server in a other subnet then I would source nat.

If you want to rewrite the destination address then you need to stay in same subnet 192.168.0.0/16 and not /24 for each subnet. The DNS server can't find the way back to otherwise.
by msatter
Mon Mar 30, 2020 2:47 pm
Forum: General
Topic: Outgoing "Winbox" TCP/IP-Request
Replies: 1
Views: 880

Re: Outgoing "Winbox" TCP/IP-Request

Those are most likely scanners looking for open Mikrotiks. Those can also be good people who check your config and if they get in disable your faulty config and log a warning for you and then close the open door on the way out. Better is to not expose the router controls or services and this you can...
by msatter
Sun Mar 29, 2020 10:59 pm
Forum: General
Topic: hEX PoE Switch Rule for sfp1
Replies: 8
Views: 1630

Re: hEX PoE Switch Rule for sfp1

I assume that you found fasttracking which is not available for IPv6.

or: https://wiki.mikrotik.com/wiki/Manual:I ... st_Forward
by msatter
Sun Mar 29, 2020 3:39 pm
Forum: Beginner Basics
Topic: DNS redirect: action redirect VS dst-nat [SOLVED]
Replies: 8
Views: 2165

Re: DNS redirect: action redirect VS dst-nat [SOLVED]

I think you are incorrect but I can't find any documentation on it right now. Local are the adresses in /ip address. Redirect carry your packets to the local port of the router with that address, and leave it there. If there is no pick-up service than your packets gets lost. Pickup service is gateway.
by msatter
Sun Mar 29, 2020 2:12 pm
Forum: Beginner Basics
Topic: DNS redirect: action redirect VS dst-nat [SOLVED]
Replies: 8
Views: 2165

Re: DNS redirect: action redirect VS dst-nat [SOLVED]

redirect - replaces destination port of an IP packet to one specified by to-ports parameter and destination address to one of the router's local addresses As long you are redirecting to local address you can use redirect and if it outside then you need to use dst-nat. local - if dst-address is assi...
by msatter
Sat Mar 28, 2020 9:45 pm
Forum: Scripting
Topic: fetch - how receive response code
Replies: 3
Views: 1576

Re: fetch - how receive response code

From the Wiki: Return value to a variable Since RouterOS v6.43 it is possible to save the result of fetch command to a variable. For example, it is possible to trigger a certain action based on the result that a HTTP page returns. You can find a very simple example below that disables ether2 wheneve...
by msatter
Sat Mar 28, 2020 9:41 pm
Forum: Scripting
Topic: fetch - how receive response code
Replies: 3
Views: 1576

Re: fetch - how receive response code

Have a look at my script which is uses the result.

viewtopic.php?f=9&t=152632&p=778113&hilit=fetch#p759427
by msatter
Sat Mar 28, 2020 3:59 pm
Forum: General
Topic: Keep IKEv2 connections running [ script ]
Replies: 6
Views: 4178

Re: Keep IKEv2 connections running [ script ]

And I have not included the option to use also a KILL SWITCH in case you IKEv2 connections are not up. You will need to kill it in NAT and this is the script for that: https://forum.mikrotik.com/viewtopic.php?f=2&t=158439&p=782424#p781870 # Free to use. Created by Blacklister 20200328-2.5 # Traffic ...
by msatter
Sat Mar 28, 2020 3:56 pm
Forum: General
Topic: Routing to local web server not working
Replies: 10
Views: 2346

Re: Routing to local web server not working

Search for the word "hairpin"...yes really.


https://wiki.mikrotik.com/wiki/Hairpin_NAT
by msatter
Sat Mar 28, 2020 1:21 am
Forum: General
Topic: IP streser atack prevent
Replies: 13
Views: 2031

Re: IP streser atack prevent

Disabling your destination IP that is new for me. However your ISP is still forwarding to that IP of you so that would create also problems. If it is UDP and you blocked that in RAW as high as possible in your RAW lines (/ip firewall raw) then there nothing more that you can do. Then you have to fin...
by msatter
Fri Mar 27, 2020 6:09 pm
Forum: General
Topic: IP streser atack prevent
Replies: 13
Views: 2031

Re: IP streser atack prevent

Indeed but you first have to be able to know what is real and what is not. If you can afford to drop all UDP traffic in RAW for a while then that is the best way. A time ago I had a slow attack on port 80 (SYNC) and it went on for a long time form server parks. I decided to look at IP addresses and ...
by msatter
Fri Mar 27, 2020 5:41 pm
Forum: General
Topic: IP streser atack prevent
Replies: 13
Views: 2031

Re: IP streser atack prevent

Yes this is an option but as attacked use fake IP addresses that will make you to deny connection so some servers that you really need! When you are using also IKEv2 connection then those can be made notrack in RAW and so are caught by the rule (UDP 4500). To avoid that the box by untracked has to ...
by msatter
Fri Mar 27, 2020 4:11 pm
Forum: General
Topic: Round Robin in RouterOS
Replies: 0
Views: 1307

Round Robin in RouterOS

I have been busy with distribution traffic in the last time and I like to use a simple Round Robin for that and I found the following ways to archive that in RouterOS. Bst known is using Round Robing for DNS resolving and in RouterOS you can use /ip dns static Create the following domain and IP's fo...
by msatter
Fri Mar 27, 2020 3:17 pm
Forum: General
Topic: IP streser atack prevent
Replies: 13
Views: 2031

Re: IP streser atack prevent

thy this add chain=input protocol=udp in-interface=ether1 connection-state=!established,related action=drop To use that then you are using connections which is most expenceive, in processor time. If you put that in filter then use it to add the source IP address to an address list which is used in ...
by msatter
Fri Mar 27, 2020 1:35 pm
Forum: General
Topic: IP streser atack prevent
Replies: 13
Views: 2031

Re: IP streser atack prevent

Are you attacking yourself?! These are UDP snd like Covid-19 you have take drastic measures. Don't look what what you want block. Look what you want to allow and block the rest of the UDP ports in RAW. That is the best you can do. You have normal DNS responses that need and you know which IP should ...
by msatter
Thu Mar 26, 2020 9:28 pm
Forum: General
Topic: IP streser atack prevent
Replies: 13
Views: 2031

Re: IP streser atack prevent

I not expert on this.

Best is blocking in RAW and you need to use filter, new connection to fill the blocking IP address table for usage in RAW.

This way your connection table stays cleaner and stays working.
by msatter
Thu Mar 26, 2020 7:45 pm
Forum: General
Topic: TLS Host glob format?
Replies: 2
Views: 987

Re: TLS Host glob format?

Thanks Sob but that help is really there if you are on one of the "\\" and press tab:
tlshost.JPG
I can enter the characters show by help in terminal (look at the orange $), and it is accepted on enter, but in the Winbox interface shows a blank field.
tlshost1.JPG
by msatter
Thu Mar 26, 2020 5:41 pm
Forum: General
Topic: TLS Host glob format?
Replies: 2
Views: 987

TLS Host glob format?

I was looking at using an expression in TLS Host but I can't get it to work. I press TAB then I get the following possibilities: " $ ? [0-9A-F] \ _ a b f n r t v $ = end of string ? = one or zero characters/signs/figures [0-9A-Z] = in a range \ = escape character _ = used in domain names a = b = f =...
by msatter
Thu Mar 26, 2020 11:42 am
Forum: General
Topic: Finally got it, using NTH for connections
Replies: 0
Views: 1312

Finally got it, using NTH for connections

I am using distribution of connections for my multiple IKEv2 providers and got always got the best spread with Per Connection Classifier (PCC) using the source port. The source port is for each connection out different. A good habit is to have the the last line function as a catch-all by removing PC...
by msatter
Wed Mar 25, 2020 11:27 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

At ROS 6.47beta49 I press Download in "Check For Updates" and in loop see that:
qcRwlwoD1m.gif
To stop this loop I do:
/system package update cancel
This is done on purpose so you don't install it automatically/by accident. To go to 7.x has to be a manual process.
by msatter
Wed Mar 25, 2020 11:05 pm
Forum: General
Topic: FastTrack in Mangle table?
Replies: 3
Views: 1660

Re: FastTrack in Mangle table?

It doesn't make much difference because the the way FastTrack works. After it is activated only sporadic traffic is sent through the normal rules.

Have also a look at notrack in RAW which speeds up traffic by bypassing the connections table.
by msatter
Wed Mar 25, 2020 10:56 pm
Forum: General
Topic: Keep IKEv2 connections running [ script ]
Replies: 6
Views: 4178

Re: Keep IKEv2 connections running [ script ]

When using IKEv2 connection to a VPN provider Mikrotik inserts dynamic src-address lines at the top of the NAT table. If you are directing traffic to it those dynamic lines can still be in the buildup phase and so leak traffic. This added line is insert after the dynamic lines at the top atleast if ...
by msatter
Wed Mar 25, 2020 10:38 pm
Forum: General
Topic: IPsec packets flow
Replies: 2
Views: 820

Re: IPsec packets flow

by msatter
Wed Mar 25, 2020 5:47 pm
Forum: RouterBOARD hardware
Topic: Number of ether interfaces ? [SOLVED]
Replies: 8
Views: 2522

Re: Number of ether interfaces ? [SOLVED]

Have also a look at the RB4011 which has 10 ports with five, each on a 2,5Gbit/s connection. Aggregated 5Gbit/s. The SPF has it's own 10Gbit/s connection.

There is also a Wifi version of that router.

Image
by msatter
Wed Mar 25, 2020 5:38 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

You can make the most secure connections and traffic ever but when it ends up with Google etc. then why bother to secure it. You're the product. SSL was never sold in those day to be a secure connection, it was and still is seen as being a trustworthy site in the general public view. Today we should...
by msatter
Wed Mar 25, 2020 5:24 pm
Forum: RouterBOARD hardware
Topic: Number of ether interfaces ? [SOLVED]
Replies: 8
Views: 2522

Re: Number of ether interfaces ? [SOLVED]

The first two have switch chips so traffic between devices in the network are switched and do not enter the CPU unless it is router traffic to the outside. The hEX S is ............ I have two but never got it switching directly. I happens all in CPU/Bridge and the SPF reduces the overall speed of t...
by msatter
Wed Mar 25, 2020 5:13 pm
Forum: RouterBOARD hardware
Topic: Number of ether interfaces ? [SOLVED]
Replies: 8
Views: 2522

Re: Number of ether interfaces ? [SOLVED]

Image

Image

Image

The Chateau is almost identical to the AC2.
by msatter
Wed Mar 25, 2020 2:46 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

It is a FALSE assumption, that your traffic (metadata) is invisible when using HTTPS or/and DoH. When TLS 1.3 becomes mainstream, it will no longer be an assumption. Right now even using TLS, the ISP can see the domain you are visiting. After TLS 1.3 that will no longer be possible and the L3-L4 "m...
by msatter
Wed Mar 25, 2020 1:46 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

DoH is a nightmare and I don't understand why it is supported by Mikrotik. After HTTS become standard, your ISP did not anymore see what you was surfing on, but up until DoH or other solution are in place, then they can always look at your DNS request on port 53. They will not see what your read, b...
by msatter
Tue Mar 24, 2020 1:58 pm
Forum: Beginner Basics
Topic: Understanding IPSec packet flow
Replies: 11
Views: 1980

Re: Understanding IPSec packet flow

Encrypting/decrypting is only changing the content of the package
by msatter
Sun Mar 22, 2020 7:05 pm
Forum: Scripting
Topic: Enable a rule just for specific time
Replies: 6
Views: 1695

Re: Enable a rule just for specific time

You can do that in scheduler with one activating the rule and a second onedisabling it again.
In a scipt you can also put a :delay 2m between to script lines.
by msatter
Sun Mar 22, 2020 4:39 pm
Forum: General
Topic: MTU troubles using IKEv2 providers like NordVPN [work around]
Replies: 35
Views: 6367

Re: MTU troubles using IKEv2 providers like NordVPN [work around]

Yes you have to adapt to your own address range. I have taken the default range set for Mikrotik routers.
by msatter
Sun Mar 22, 2020 11:43 am
Forum: General
Topic: NordVPN IKEv2 connected but no internet!
Replies: 7
Views: 2449

Re: NordVPN IKEv2 connected but no internet!

It would be nice if Mikrotik would atleast put this on the Wiki page about using NordVPN IKEv2.
by msatter
Sat Mar 21, 2020 9:16 pm
Forum: General
Topic: Keep IKEv2 connections running [ script ]
Replies: 6
Views: 4178

Re: Keep IKEv2 connections running [ script ]

I am even more pleased that I managed to create a script that look at the active IKEv2 connections and create the distribution rules for traffic over those multiple connection. It is adapts when a connection is halted or a connection is added and it evens makes the last one in the lists, a catch-all...
by msatter
Sat Mar 21, 2020 9:01 pm
Forum: Scripting
Topic: Script code syntax check [Check Selected]
Replies: 5
Views: 2176

Re: Script code syntax check [Check Selected]

An Empire. However just putting it just flat on the road is already a BIG step.
by msatter
Sat Mar 21, 2020 4:06 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

How DoH works. Pssssst I like to go to the Pornhub can you give me the IP address. Here you go says Google, of you are. Google making a note the IP xxx.xxx.xxx.xxx went to the pornhub on that day and time and it is already the 6543 time. Lets ask pornhub what is the preference of IP xxx.xxx.xxx.xxx ...
by msatter
Sat Mar 21, 2020 11:17 am
Forum: General
Topic: Obtaining info from other router by script
Replies: 0
Views: 1341

Obtaining info from other router by script

I have a script and that needs information from a directly attache other Mikrotik router and I had a look at RoMon but I found not much info about how it works. Script example running on router 2 and wanting to obtaining info from router 1: :foreach i in=[/ip ipsec policy find tunnel=yes] do={:set $...
by msatter
Sat Mar 21, 2020 9:39 am
Forum: Scripting
Topic: Script code syntax check [Check Selected]
Replies: 5
Views: 2176

Script code syntax check [Check Selected]

Writing scripts code in Winbox is a PITA. I check my syntax by copying it to a terminal and see there are errors in it and test it directly if possible. This manual copy and paste can be much easier if in the boxes where we can input scripts, select the script code and then right-click and choose Ch...
by msatter
Fri Mar 20, 2020 2:22 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

Try setting https://10.5.51.5 as the server.
thanks for reply now it's verified but could not resolve any dns name
How can it verify only by a IP address?
by msatter
Fri Mar 20, 2020 2:21 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

Try setting https://10.5.51.5 as the server.
You can ingnore verify but then how do you know you are talking to the correct DNS server? DoH need TLS and so a verify.

Now Mikrotik can do DoH what about DoT which is a real advancement.
by msatter
Fri Mar 20, 2020 2:20 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

DoH is a nightmare and I don't understand why it is supported by Mikrotik. Why ? DoH is weapon and not a tool. You should use that in countries that are not respecting freedoms or if ISP that manipulate DNS resolves. I see that it not well implemented because a IP address can be used instead of onl...
by msatter
Fri Mar 20, 2020 12:40 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

DoH is a nightmare and I don't understand why it is supported by Mikrotik.
by msatter
Thu Mar 19, 2020 5:50 pm
Forum: General
Topic: Keep IKEv2 connections running [ script ]
Replies: 6
Views: 4178

Re: Keep IKEv2 connections running [ script ]

Made it more efficient and it will run without having to define the names upfront: #Change to IPsec peer to have that as default location to run commands /ip ipsec peer #Loop through names of the peers and see if they need restart :foreach i in=[find] do={ :local pn "$[get value-name=name $i]"; :if ...
by msatter
Sat Mar 14, 2020 2:26 pm
Forum: General
Topic: New WIKI Confluence
Replies: 3
Views: 1315

Re: New WIKI Confluence

To hide the left column is not that difficult. The right column is first click the book sign till it becomes transparant an then click three dots for menu and close menu amd the third column will be hidden. I prefer the reader mode in the Firefox browser. Screenshot_20200314_131452_net.waterfox.wate...
by msatter
Wed Mar 11, 2020 1:48 pm
Forum: General
Topic: NordVPN-IKEv2 slow NET speed
Replies: 21
Views: 5080

Re: NordVPN-IKEv2 slow NET speed

You can test it by editing your own posting and press onthe Preview button. If nothing is happening or very slow then you need the MTU workaround in IPSEC.

You have to check that you did not enable Fasttracking on traffic going throug the VPN.
by msatter
Tue Mar 10, 2020 1:26 pm
Forum: General
Topic: Keep IKEv2 connections running [ script ]
Replies: 6
Views: 4178

Re: Keep IKEv2 connections running [ script ]

I am now checking if the IKEv2 connection is enabled so that it not restarted if the user disabled it: # Change to IPsec peer, to have that as default location to run commands /ip ipsec peer ## Check NordVPN :local pn NordVPN-1; :if ([ find name="$pn"&&.dead ]!="") do={:if ([/ip ipsec policy find pe...
by msatter
Tue Mar 10, 2020 1:24 pm
Forum: General
Topic: MSS doesn't change when going to IPsec Tunnel
Replies: 3
Views: 1712

Re: MSS doesn't change when going to IPsec Tunnel

I can't help you except for lower the MTU from 1480 to 1280 and try again.
by msatter
Sat Mar 07, 2020 11:29 am
Forum: General
Topic: Keep IKEv2 connections running [ script ]
Replies: 6
Views: 4178

Keep IKEv2 connections running [ script ]

Now we can use IKEv2 (NordVPN etc.) to encrypt our traffic it sometimes occurs that connection are not made/reconnected for any reason. That connection does nor recover and if you have several connections you only will notice that some web pages are not loading or after a delay. I have written a scr...
by msatter
Sat Mar 07, 2020 2:11 am
Forum: General
Topic: MSS doesn't change when going to IPsec Tunnel
Replies: 3
Views: 1712

Re: MSS doesn't change when going to IPsec Tunnel

You don't have change MTU/MSS activly here.

viewtopic.php?f=2&t=154449
by msatter
Tue Mar 03, 2020 9:50 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 54
Views: 11571

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

My version checks for list larger than 63KiB and logs then if the list is loaded or not.

There no way to import a list bigger than that through an array.

Bigger lists can be used but that is an other story.
by msatter
Tue Mar 03, 2020 7:32 pm
Forum: General
Topic: IPsec Nordvpn no more connection
Replies: 5
Views: 1803

Re: IPsec Nordvpn no more connection

No problem it happens to the best. ;-)
by msatter
Tue Mar 03, 2020 5:02 pm
Forum: General
Topic: IPsec Nordvpn no more connection
Replies: 5
Views: 1803

Re: IPsec Nordvpn no more connection

The only think I found to be different is: set [ find default=yes ] enc-algorithms=aes-256-cbc,aes-192-cbc,aes-128-cbc,3des pfs-group=none Mine: add auth-algorithms=sha256,sha1 enc-algorithms=aes-256-cbc name=NordVPN pfs-group=none I enforce sha256 for authorizations and encoding only aes-256-cbc. A...
by msatter
Sat Feb 29, 2020 10:53 pm
Forum: Beginner Basics
Topic: NordVPN IPSEC (IKE2)
Replies: 3
Views: 1751

Re: NordVPN IPSEC (IKE2)

You have to choose one of the options and not both.
by msatter
Sat Feb 29, 2020 1:13 pm
Forum: Beginner Basics
Topic: Mikrotik and pihole as a DNS server
Replies: 10
Views: 4063

Re: Mikrotik and pihole as a DNS server

Does your Pi.hole resolve?

You can test this by going to the CLI on your Pi-hole and rnter:

dig mikrotik.com

If it resolves the you can take the step to point clients to Pi-hole through seting it's in the DHCP of the Mikrotik.

Later you then also point the mikrotik to Pi-hole.
by msatter
Fri Feb 28, 2020 7:56 pm
Forum: Beginner Basics
Topic: Mikrotik and pihole as a DNS server
Replies: 10
Views: 4063

Re: Mikrotik and pihole as a DNS server

There is no such thing as backup DNS server.
by msatter
Wed Feb 26, 2020 12:37 pm
Forum: Beginner Basics
Topic: FTTH very slow download speed (upload ok)
Replies: 15
Views: 3603

Re: FTTH very slow download speed (upload ok)

The 2011 can switch gigabit but not route it, period.
That is why you have Fastpath/Fasttrack made available by Mikrotik.
by msatter
Wed Feb 26, 2020 12:30 pm
Forum: RouterOS v7 BETA
Topic: Cannot set routing-mark or table for routing rule
Replies: 11
Views: 6282

Re: Cannot set routing-mark or table for routing rule

I am affraid more guidance is needed.
by msatter
Mon Feb 24, 2020 11:20 pm
Forum: General
Topic: NordVPN IKEv2 connected but no internet!
Replies: 7
Views: 2449

Re: NordVPN IKEv2 connected but no internet!

In the meantime the real cause was found and I have posted today about it at the end of this thread and follow the link for an explaination and solution. It not where you expected that it would be. It took a good part of a year to find it and Sindy brought the solution. Still waiting for Mikrotik to...
by msatter
Mon Feb 24, 2020 9:19 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

Yes, there is a known issue with latest MikroTik smartphone app on Android. We are working on it.
iOS works fine.
With the new 1.3.11 version in the store, the issue is resolved. Thanks fixing the Android version so it works again with 6.47 Beta.
by msatter
Mon Feb 24, 2020 7:30 pm
Forum: General
Topic: Surfshark IKEv2 VPN
Replies: 9
Views: 3701

Re: Surfshark IKEv2 VPN

It is still a work around and no clamping needed anymore. The packet returning indication that the package size is, to big is pointed the wrong way by RouterOS.

viewtopic.php?f=2&t=154449&p=763404&hil ... v2#p763404
by msatter
Sat Feb 22, 2020 1:15 pm
Forum: General
Topic: NordVPN IKEv2 EAP VPN tunnel: DNS leak
Replies: 7
Views: 2213

Re: NordVPN IKEv2 EAP VPN tunnel: DNS leak

You start reading from this point and this was tackled this week in the Beta:

viewtopic.php?f=21&t=154662#p775493
by msatter
Fri Feb 21, 2020 1:38 pm
Forum: Beginner Basics
Topic: Date format Please Help
Replies: 5
Views: 1448

Re: Date format Please Help

If the output of systemdate has the same format as you have in sheddate then replace systemdate in the example, by sheddate.
:local mydate ([:pick $sheddate 4 6] . "/" . [:pick $sheddate 0 3] . "/" .[:pick $sheddate 7 11]);
by msatter
Fri Feb 21, 2020 11:15 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 77
Views: 20512

Re: Feature Request: IPSEC Improvements

If the certificate database is big, even if it has a selected number of root certificates is it an idea to make the database to be "side-load" as a dedicated file? If it is present the router can use/import the correct certificate and the user does not have track down the right certificate.
by msatter
Thu Feb 20, 2020 7:36 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 12
Views: 1952

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

You have to treath all traffic the same and use the same protection. That traffic is coming through a VPN makes it not more secure. If you use a VPN we do that on connection level and what goes out comes back on the same connection and need not separate rules. Unasked traffic coming in are mostly fr...
by msatter
Thu Feb 20, 2020 5:35 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 12
Views: 1952

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

You use prerouting for that.
by msatter
Thu Feb 20, 2020 11:17 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 77
Views: 20512

Re: Feature Request: IPSEC Improvements

Can we have automatic root certificate check so that public certificates (IKEv2) have not to be manually imported in the store?

cert.JPG
by msatter
Thu Feb 20, 2020 11:13 am
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 12
Views: 1952

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

/ip firewall mangle add chain=prerouting action=mark-routing new-routing-mark=vpn passthrough=no src-address=192.168.x.x/24 comment=xxx connection-state=new add action=fasttrack-connection routing-mark=vpn connection-state=new If you switch to IKEv2 the you double the speed of 70 MBit/s to around 13...
by msatter
Wed Feb 19, 2020 8:25 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 12
Views: 1952

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

I am missing your fasttrack line. Simplified it should read: If not routing-mark=vpn and connection is new then fasttrack. Not is written as ! in ROS. An other option is also. Marking routing not going to the next line by disabling passtrough in the action tab. Then only traffic which is not marked ...
by msatter
Wed Feb 19, 2020 5:41 pm
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 12
Views: 1952

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

This done in Mangle by Mark routing in your case. Then only fasttrack traffic that is not marked to be routed through that VPN connection. Only mark new traffic for fasttracking. BTW they also support IKEv2 which is much better. You can follow the NordVPN instructions. You have to find out which roo...
by msatter
Wed Feb 19, 2020 11:45 am
Forum: General
Topic: Unusable speed Mikrotik-ExpressVPN(L2TP)
Replies: 12
Views: 1952

Re: Unusable speed Mikrotik-ExpressVPN(L2TP)

Traffic going through a VPN can not be fasttracked so please check if your traffic is not fasttracked.
by msatter
Tue Feb 18, 2020 2:40 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

Confirmed theat the Android client is reverting to it's login screen. Clear cache did not change that.
by msatter
Tue Feb 18, 2020 11:28 am
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 115789

Re: v6.47beta [testing] is released!

*) ipsec - added "use-responder-dns" parameter support (CLI only); Thanks for implementing this and it was a looooooong wait before it became reality. Update: I used the example given by eworm and removed the "..." do all configs in one go. The default setting is "exclusively". / ip ipsec mode-confi...
by msatter
Sun Feb 16, 2020 12:09 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - Wireguard Protocol
Replies: 85
Views: 21800

Re: Feature Request - Wireguard Protocol

He was writing OpenVPN UDP support by Mikrotik and not about OpenVPN itself.

A good alternative for now is IKEv2, in the time waiting for Wireguard being implemented by Mikrotik.
by msatter
Sun Feb 16, 2020 12:05 pm
Forum: RouterOS v7 BETA
Topic: need sock5 please update in v7
Replies: 4
Views: 2304

Re: need sock5 please update in v7

To be more precise:

What's new in 6.47beta19 (2020-Jan-09 08:08):
MAJOR CHANGES IN v6.47:
----------------------
!) socks - added support for SOCKS5 (RFC 1928);
----------------------