Community discussions

Search found 1082 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 22
by msatter
Fri Jun 14, 2019 11:43 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

Does anyone knows where to find this setting? I am looking for it for years now. *) winbox - do not allow setting "dns-lookup-interval" to "0"; Many support mails about addresslists and DNS timings but this was never mentioned to me. I have now a limiter only for DNS so that when there is no upstrea...
by msatter
Thu Jun 13, 2019 11:05 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 190
Views: 20024

Re: Blacklist Filter (Development Topic)

The ADD in the rules is there to add the line to the RAW section in the firewall. After thst it not used anymore.

Dropping unwanted traffic is most efficient in RAW and so it won't reach connection tracking.
by msatter
Thu Jun 13, 2019 1:41 am
Forum: General
Topic: Annoyed with Mikrotik 'Support'
Replies: 8
Views: 407

Re: Annoyed with Mikrotik 'Support'

Duh. 60 Degrees is the angle and if you look at hardware section you see also a X3 (new) version that has an angle of 180 degrees. The width is limited by the distance. I won't reach the planet Mars despite it could be well in the 60 degrees angle. From the Mikrotik wiki and if you look at the LHG v...
by msatter
Wed Jun 12, 2019 11:42 pm
Forum: General
Topic: Annoyed with Mikrotik 'Support'
Replies: 8
Views: 407

Re: Annoyed with Mikrotik 'Support'

Mikrotik creates a number for each support question and it seems that only one question is accepted. Try next time first the suggestion mentioned earlier and search a bit. If no find put the questions in separate e-mails if the differ much.

The forum is often faster than support.
by msatter
Wed Jun 12, 2019 2:53 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

It is now quiet around the beta and using now the new IKEv2 EAP possibilities for a time, I want to made a suggestion how to direct traffic using policy routing. I am now using a second router to take care of PPPoE and IKEv2 as those two are bound together more or less. I set in the 'inside' router ...
by msatter
Sat Jun 08, 2019 1:41 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 190
Views: 20024

Re: Blacklist Filter (Development Topic)

I helped with an earlier version and it is should be incremental and your get the changes you missed since the last sucessful update you had. The sheer number of routers connecting still can give a heavy bandwith usage. Dave is doing a great job despite his personal set backs. https://forum.mikrotik...
by msatter
Tue Jun 04, 2019 1:48 pm
Forum: RouterBOARD hardware
Topic: Cheapest router for home use with 1Gb
Replies: 5
Views: 444

Re: Cheapest router for home use with 1Gb

I would also go for the 4011. The hAP ac^2 is good but you need to go to fasttracking to reach real high speeds. The encypting power is 4 times higher with the 4011.
by msatter
Tue Jun 04, 2019 12:52 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature request: full crypto speedup for MT7621 chipset (e.g. hEX S)
Replies: 9
Views: 637

Re: Feature request: full crypto speedup for MT7621 chipset (e.g. hEX S)

Hey mada3k, I totally agree with you, but Mikrotik states only that there is IPSec encryption accelleration (compared to the datasheet of hEX S), so I assume that there is no OpenSSL hardware encryption engine support :-( Look at this page and you see that ECB in worse than CBC: https://datalocker....
by msatter
Tue Jun 04, 2019 12:40 am
Forum: Scripting
Topic: Script doesn't continue after a statement [SOLVED]
Replies: 6
Views: 267

Re: Script doesn't continue after a statement

Maybe, use :log info " " instead of /log info " " You confused the actual logging and the log menu itself at this line: /log info "test this" Good that you managed to solve it yourself. I tested /log info "test" and it worked. I never use that and use :log because you can call it wherever you are i...
by msatter
Mon Jun 03, 2019 10:17 pm
Forum: Scripting
Topic: Script doesn't continue after a statement [SOLVED]
Replies: 6
Views: 267

Re: Script doesn't continue after a statement

Maybe, use :log info " " instead of /log info " "

You confused the actual logging and the log menu itself at this line:
/log info "test this"
by msatter
Sun Jun 02, 2019 6:42 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

I am now using IKEv2 peer to connect to a VPN provider. I have the problem that the connection is rebuild and that old connection stays in the connection table. I am using a ping to test it and I get a timeout till I remove that connection out of the connection table. I thought that dead-peer-detect...
by msatter
Sat Jun 01, 2019 3:39 am
Forum: Beginner Basics
Topic: Confused with PASSTHROUGH YES/NO in Mangle
Replies: 7
Views: 415

Re: Confused with PASSTHROUGH YES/NO in Mangle

If a rule/line is matching and the Passthrough is NOT marked for that line then the rest of the lines are skipped in Mangle. If a rule/line is matching and the Passthrough is marked then the next line is processed. If that line or an later line is also matching then the value is overwritten if that ...
by msatter
Fri May 31, 2019 10:37 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fasttrack encypted connections the Piggyback way (test)

So after giving up on running it on router I returned to using two routers to be able to use Mangle + PCC to distribute traffic over several IKEv2 and L2TP/IPSEC connections. Also activated fastracking for the first NAT on the 'inner' router which was a bit of hustle. I had made a jump to two chains...
by msatter
Thu May 30, 2019 11:11 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

I give it a rest for now. I can spend days trying to get it work. Who know Mikrotik will give IKEv2 it's own interface and client settings so can do this without double NAT or IPIP tunnels.

Spend too much time on this running in circles.

Thank to Sindy again for all the help.
by msatter
Wed May 29, 2019 6:50 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

So I have two address-list, one for those sites only liking you coming from one IP and those that do not like VPN connections. Again, mangling cannot coexist with fasttracking. So I'd suggest to use your address lists of source-sensitive sites to choose the proper action=src-nat rule with the prope...
by msatter
Wed May 29, 2019 6:14 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

And it's gone.....
by msatter
Wed May 29, 2019 5:57 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

Thanks I am now adapting my config. I factor is that I don't have one IKEv2 connection but multiple and I want separate traffic to those IKEv2 connections with help of mangle. I had it working with multiple connections but I could not go far enough back to restore that. Update: Basically I want to d...
by msatter
Wed May 29, 2019 4:33 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

This is what I have added. /ip address add address=127.0.1.1 interface=aux-lo network=127.0.1.1 add address=10.0.1.1 interface=ipip-outer network=10.0.1.1 /interface ipip add mtu=1500 name=ipip-inner remote-address=127.0.1.1 add local-address=127.0.1.1 mtu=1500 name=ipip-outer remote-address=127.0.0...
by msatter
Wed May 29, 2019 2:52 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

I tried mangle route to an IP in 10.0.1.0 which is in the outer but no luck. Then I went back to route marking and ping on the router itself works but from a client it doesn't. There really strange things the NAT is not hit. Using route marking I see in connections the client IP - target - target - ...
by msatter
Wed May 29, 2019 11:12 am
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

What I want to archive is that 'basic' client behavior using a IKEv2 connection. It is not that simple now the NAT line is created triggered by the source address and the source address is the one of the clients. I tried double NAT on one box and did not get that working. When I use IPIP I saw the c...
by msatter
Tue May 28, 2019 5:28 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Re: Routing to interface with IPIP-dummy

Solved it by marking routing....I did this hundreds of times but not try it here. I will make a short manual so using the new IKEv2 possibilities easier without an client available in ROS/Winbox. Thanks to Sindy for the IPIP idea. It was working and then it stopped and I have figure out why it does ...
by msatter
Tue May 28, 2019 3:48 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 469

Routing to interface with IPIP-dummy

I am bussy with using the latest implementation of IKv2 with EAP authentication. I have it working but I have to manually change each time the entry address of the IKEv2 connection in Mangle. Using the IPIP is partly working when I test it using the ping tool in Winbox. /ip address add address=172.2...
by msatter
Tue May 28, 2019 12:16 pm
Forum: General
Topic: Bonding using openvpn?
Replies: 6
Views: 290

Re: Bonding using openvpn?

Look in the wiki.mikrotik.com for PCC and there you have the choice on what information you can split up traffic.

The simplest one is uding destination address.
by msatter
Tue May 28, 2019 10:19 am
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

Thanks Sindy and it a pity that it did not work as expected. Did you try using different ports as you control the client and the server? When I use IKEv2 I don't activate notracking for now. Tested it with one active IKEv2 connection active and still one core was loaded up...general observation is t...
by msatter
Mon May 27, 2019 12:43 am
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

Thanks looking forward to it. With IKEv2 I need to know the which IP entry point is given and ROS knows it but having no script on start / change I can't automate it. When using mode config + address list I get a NAT line at the top src-natting the new address of the entry point for encrypting. If n...
by msatter
Sun May 26, 2019 11:19 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

Sindy suggested to use IPIP to see if can run it on one router but I have see how that is going to be setup. Well, that suggestion was relevant in the context of one CPU thread being loaded at 100 % and the others idling as you've stated here, not the whole machine running at 100 % as you've stated...
by msatter
Sun May 26, 2019 5:31 pm
Forum: General
Topic: DNS ghost traffic
Replies: 4
Views: 275

Re: DNS ghost traffic

The usrrs are free to use a different DNS and Android and APP want to use the DNS of Google itself. You can stop that by blocking that traffic to what I call Rouge DNS servers by putting them in a addresslist and drop that traffic. You can choose to put a NAT enforcer to lesd that trafgic to your ow...
by msatter
Sun May 26, 2019 3:12 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

I had not yet used Fasttracking and the next two are 'profiles'fastracked using outer (GW) and inner (filter/nat/mangle/raw). Inner fasttracked: no picture present And for comparison non encrypting: no picture present] And as second comparison non encrypting on a standalone router with PPPoE: no pic...
by msatter
Sun May 26, 2019 11:40 am
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

I have made 'profile' screenshots when the router(s) are loaded and doing encrypting: no picture present IKEv2 in cascade setup of a box doing the PPPoE and IKEv2. There i NAT running on the box for the IKEv2. no picture present At the same time the other router doing filtering/nat/mangle/raw no pic...
by msatter
Sat May 25, 2019 9:47 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

hmmm reading it I going to put it in a third blank. RB750Gr2 to see how it works and my live boxes are to complicated now to fit in in one time. During testing IPIP I noticed that in connections only one line appeared of the four expected that stated the searched dynamic IP of the IKEv2 connection w...
by msatter
Sat May 25, 2019 8:48 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

I tried to build IPIP on the single router but I did not manage to get it working. The example in the wiki seems to not do what I see on my router.Thanks for the link and I will see if that is working. I already overheated my brain serveral time in the past week. If I can get it to work then Mikroti...
by msatter
Sat May 25, 2019 11:07 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

Update: I have it now working and writing this with a IKEv2 connection through PureVPN. I have still to adapt the manually generated Ipsec Policy and it a PITA to do because sometimes a 0.0.0.0/ is expected but then I receive the TS_UNEXPECTED error. After several time going round and round the Src...
by msatter
Fri May 24, 2019 2:12 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Android client for MikroTik VPN
Replies: 5
Views: 336

Re: Android client for MikroTik VPN

As client I use OpenVPN and for IKEv2 StrongSwan. A good solution is if you own the router that is able to provide VPN connections to isu that. This to have VPN for all devices connected to that router. OpenVPN is a bit of a Unicorn with Mikrotik however IKEv2 is in Beta supported. Works well and I ...
by msatter
Thu May 23, 2019 11:52 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

If your IKEv2 client is running on the PC, the UDP transport of the encrypted data becomes a plaintext transit traffic for the router connecting that PC to the rest of the world, so fasttracking that traffic makes sense if the router doesn't have enough CPU to handle the forwarding and firewalling....
by msatter
Wed May 22, 2019 11:14 pm
Forum: RouterBOARD hardware
Topic: BiDi SFP on CRS326-24G-2S+: light but no link
Replies: 3
Views: 223

Re: BiDi SFP on CRS326-24G-2S+: light but no link

I solved my problem by turning auto negotiation off, and setting the link capacity to 1G fixed. As always. Maybe Mikrotik will implement a extra button in ROS in that screen with the text "Does not work" and pressing it will disable auto negotiation for you. Or make the default negotiation state be...
by msatter
Wed May 22, 2019 8:24 pm
Forum: General
Topic: Help with IKEv2/IPsec client configuration
Replies: 26
Views: 8277

Re: Help with IKEv2/IPsec client configuration

You can route and filter all you want before redirecting it to the entry point of the tunnel. For this you use NAT and in Mangle route marking. If have still to manually create a split horizon and I am now setting two routers in serie (cascade) to see if can then use the option mentioned underneath....
by msatter
Mon May 20, 2019 10:31 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

I have tried now with addresslist and I can make a split horizon. The TS_I is given by PureVPN (10.4.48.178) for that fixed IP server. The only address in the addresslist (Marker) is not to be seen the log. The ST_R is 0.0.0.0/0. The NAT is generated and then I have change my original source address...
by msatter
Mon May 20, 2019 10:22 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

Update: I have it now working and writing this with a IKEv2 connection through PureVPN. I have still to adapt the manually generated Ipsec Policy and it a PITA to do because sometimes a 0.0.0.0/ is expected but then I receive the TS_UNEXPECTED error. After several time going round and round the Src...
by msatter
Sun May 19, 2019 10:41 pm
Forum: General
Topic: Help with IKEv2/IPsec client configuration
Replies: 26
Views: 8277

Re: Help with IKEv2/IPsec client configuration

Hello emils Please, provided the configuration command for use Ikev2 with EAP authentication. I will test the new firmware version, I will configue NordVPN with IKEV2 with EAP authentication. This is the Linux config for NordVPN for exemple: https://nordvpn.com/tutorials/linux/ikev2ipsec/ You can h...
by msatter
Sun May 19, 2019 9:22 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Re: Fastrack encypted connections the Piggyback way (test)

Thanks Sindy and I was this afternoon ofline to test it so I did not see your reply earlier. I had the PPPoE running and changed my settings but I could not get any traffic to the "PPPoE" router so I still know nothing. I had to discover that you have to use a bridge to even have an IP on ether2 vis...
by msatter
Sun May 19, 2019 3:53 pm
Forum: General
Topic: Fasttrack encypted connections the Piggyback way (test)
Replies: 17
Views: 718

Fasttrack encypted connections the Piggyback way (test)

I have been bussy with IKEv2 connections the last few days and now all is working I was disappointed the my RB760iGS only managed to do 70-90 Mbit/s due to networking an firewalling task being taking all the CPU of Core 0 while the others are almost idling. I am thinking and going to setup in a mome...
by msatter
Sat May 18, 2019 10:03 pm
Forum: General
Topic: Help with IKEv2/IPsec client configuration
Replies: 26
Views: 8277

Re: Help with IKEv2/IPsec client configuration

Many thanks and I have working with PureVPN and their support could not help me much. I sm uding now a IP address of one of their XX-ikev.ptoservers so that the internal and network IP (range) is constant. This have a src-nst with a condtant gateway. Thanks to Mikrotik make it possible and also Nord...
by msatter
Fri May 17, 2019 11:11 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

Try setting the remote-id to ignore. I tried that and it still complains that it can't get local certificate from configuration and it not a dealbreaker and it goes on till it processes payloads: NOTIFY and then I get the error that the notify is TS_UNACCEPTABLE and the next line it is a got error:...
by msatter
Wed May 15, 2019 11:26 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

I am a bit further and I needed two certificates to be in the certificates box. https://blogger.davidmanouchehri.com/2017/09/ Now I get twice the error that the [b ]peer's ID does not match certificate [/b] and the line above that reads in the log: unable to get certificate CRL(3) at depth:0 Subject...
by msatter
Wed May 15, 2019 11:20 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

Thanks Emils. It is PureVPN and using PossitiveSSL (pointoserver.com / ptoserver.com) and that is the root certificate of Comodo which I tried. I contacted support and they don't provide a certificate to connect as NordVPN is doing. I will a look at the current certificates in the windows store to s...
by msatter
Tue May 14, 2019 9:37 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released! IKEv2

Now mschapv2 is supported I tried to connect with IKEv2 to a VPN provider. This provider does not supply a certificate so I match on FQDN which is *.pointtoserver.com (the "*." needs to be there) ip ipsec identity add auth-method=eap certificate="" disabled=yes eap-methods=eap-mschapv2 peer=PureIKEv...
by msatter
Mon May 13, 2019 12:29 pm
Forum: General
Topic: [Feature request] Wireguard
Replies: 78
Views: 16388

Re: [Feature request] Wireguard

Wireguard was tested by INRIA Source: https://www.security.nl/posting/608796/Onderzoekers+testen+cryptografische+werking+WireGuard-vpn Abstract : WireGuard is a free and open source Virtual Private Network (VPN) that aims to replace IPsec and OpenVPN. It is based on a new cryptographic protocol deri...
by msatter
Fri May 03, 2019 12:27 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 268
Views: 55020

Re: v6.45beta [testing] is released!

can you add EAP-MSCHAPv2 to the authentication method list?
Yes, it is coming as well.
Does this means that Mikrotik can be removed from the not supported router list at NordVPN and is going to use ike2 to connect?
by msatter
Sun Apr 28, 2019 11:30 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 939

Re: GoogleFiber

Also check if your ethernet interface negotiates to the correct speed and duplex.
Status shows as Unknown.
Then set it manually.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 22