Community discussions

Search found 749 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 15
by msatter
Mon Jun 18, 2018 7:48 pm
Forum: Wireless Networking
Topic: hacking-router
Replies: 2
Views: 130

Re: hacking-router

Also have a look at this thread.

viewtopic.php?f=2&t=135774
by msatter
Wed Jun 13, 2018 12:05 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

Bug in 6.43rc23: Upgrade from previous version to 6.43rc23 when you have /ip ipsec peer proposal with hash-algorithm=sha512 Open this proposal in Winbox. You will see that in Winbox it have checked md5 and sha1, but in the export it have sha512 Set hash algorithm to sha512 through Winbox, now autos...
by msatter
Tue Jun 12, 2018 2:38 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: v6.43rc23 IPSec bug
Replies: 4
Views: 389

Re: v6.43rc23 IPSec bug

Please report your findings this to Mikrotik support: support@mikrotik.com and state your router os version and win box version also. Please include the link to this topic.
by msatter
Tue Jun 12, 2018 11:25 am
Forum: General
Topic: LCD Display causing packet loss... what???
Replies: 10
Views: 680

Re: LCD Display causing packet loss... what???

I have been tracking down a few reports within our network due to 1-2% packet loss. Isolated the issue to only RB3011UiAS devices. After finding this thread, I disabled the LCD on one unit, and it immediately resolved the packet loss issue. Disabled LCD on 15 or so other units, also resolved the is...
by msatter
Thu Jun 07, 2018 12:17 pm
Forum: Announcements
Topic: Tik App, MikroTik android utility ALPHA test
Replies: 318
Views: 98870

Re: Tik App, MikroTik android utility ALPHA test

Thanks for the update to 0.68 and the TikAPP does now work again with the secure login.
by msatter
Wed Jun 06, 2018 12:22 pm
Forum: General
Topic: Does this void the warranty?
Replies: 2
Views: 249

Re: Does this void the warranty?

Hahaha, you're crazy.

Did you think about the metal dust that came free during sawing and can cause shortages inside?
by msatter
Tue Jun 05, 2018 8:06 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

I am impressed. Thanks for listening to us all.
by msatter
Mon Jun 04, 2018 11:59 am
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

My tire won't survive a caltrop, sometimes a IED is needed if you are have a more secure tire.
by msatter
Sun Jun 03, 2018 8:01 pm
Forum: Beginner Basics
Topic: NTH Truth or Dare
Replies: 3
Views: 197

Re: NTH Truth or Dare

That packets are marked to go trough a specific gateway. Is the gateway death the your packets will be lost.

If you put a HA in there the it has to be after the NTH. If the target gateway is death then the traffic has be rewritten to go through the other gateway(s).
by msatter
Sun Jun 03, 2018 5:32 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

I really like the fact that the wheels stay on the car when drive on the highway. Without security being as good as possible someone else than you can use your router to do harm and thanks to you at a higher speed. ;-)
by msatter
Sun Jun 03, 2018 12:34 pm
Forum: Beginner Basics
Topic: NTH Truth or Dare
Replies: 3
Views: 197

Re: NTH Truth or Dare

5:1 go to ISP1 passthrough =no
5:2 go to ISP1 passthrough =no
5:3 go to ISP1 passthrough =no
To ISP2 passthrough =no

Or

5:4 go to ISP2 passthrough =no
5:5 go to ISP2 passthrough =no
To ISP1 passthrough =no
by msatter
Sat Jun 02, 2018 10:28 pm
Forum: General
Topic: Blocking Virus from Mikrotik
Replies: 9
Views: 408

Re: Blocking Virus from Mikrotik

When I search for sohu.com I find this:

viewtopic.php?f=2&t=68290&hilit=Sohu.com
by msatter
Wed May 30, 2018 2:44 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> none dynamic/static timeout

I just a confirmation that Mikrotik is going to consider to enable none-dynamic also, when adding addresses directly to the adress-list in /IP Firewall address-list

Let's hope the best.
by msatter
Tue May 29, 2018 6:00 pm
Forum: General
Topic: anyone facing DNS ip change to another ip, which is not set by network admin?
Replies: 2
Views: 100

Re: anyone facing DNS ip change to another ip, which is not set by network admin?

Check if the new DNS IP are the same as the ones provided by your ISP.
by msatter
Tue May 29, 2018 2:14 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

I find it confusing that any thread about software coming from Miktotik uses the word released in the subject and lets save that word solely for the RC. Legacy = no further developed Bug fixed = only security and bug fixes applied Current = bleeding edge and not always stable Release Candidate = can...
by msatter
Tue May 29, 2018 1:52 pm
Forum: General
Topic: mUPS maximum battery voltage?
Replies: 5
Views: 232

Re: mUPS maximum battery voltage?

You can go 3SXP and X can be replaced by 2 or a higher number. You can look at a Godox PB960 and only use the battery pack of it. Use the charger plug on the side and it also supply power back from the cells.

Voltage is between 11,1Volt and 12,6Volt using 3S2P and a capacity of 4300mAh
by msatter
Tue May 29, 2018 12:10 am
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

I think there is only one list internal and it is bloody fast so no complaints from me on that part. My observation is that adding is done in two steps. First the add with check if address already exists in the same list, on completion the obsolete entries are removed. The memory usage increases aft...
by msatter
Mon May 28, 2018 10:56 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

If I get it right, you had to deal with several issues: you don't fetch just a list of CIDR addresses which you would then process by a local script, but you fetch complete rsc, so you have to substitute compression (which would anyway save only bandwidth in transfer but not RAM space when interpret...
by msatter
Mon May 28, 2018 10:34 am
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

Chupaka made it possible that we can import extreme long list fast and without long waits to download the list from an external source. Remember the lists can't be unzipped in RouterOS. Extreme long lists, think about more than 200.000 addresses (size +40MB). Then multiply the huge size of those lis...
by msatter
Sun May 27, 2018 11:43 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

Darn I can't switch easily from one screen to an other on my tablet and search so I got person wrong setting us on the right track with reducing the size of the address lists. It was Chupaka and we own him still a lot of thanks for that eye opener. Link: https://forum.mikrotik.com/viewtopic.php?f=9&...
by msatter
Sun May 27, 2018 11:34 pm
Forum: General
Topic: PCC upload speed issue
Replies: 10
Views: 324

Re: PCC upload speed issue

I am looking at NAT part because there was no selection on what traffic goes to what line. To me it seems that one connection is sent out on all lines. ??? RouterOS is not forking packets unless you specially ask it to do so. What did you actually have in mind? !!! I never understood why I should h...
by msatter
Sun May 27, 2018 9:07 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

If you knew how long several people have been torturing their brain to reduce size size of the files till Chupaka make us sit next to our chairs from astonishment. This all because compression is not available in RouterOS. Using find is the same as shooting yourself with a gun in the face when using...
by msatter
Sun May 27, 2018 8:37 pm
Forum: General
Topic: PCC upload speed issue
Replies: 10
Views: 324

Re: PCC upload speed issue

I use PCC and don't have any problem with speedtest. I am looking at NAT part because there was no selection on what traffic goes to what line. To me it seems that one connection is sent out on all lines. Using source port for PCC is the best when just accessing the internet. Connection tracking wil...
by msatter
Sun May 27, 2018 8:14 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

Having more than 35000 addresses, is that not going to take a while to put them in the addres-list by help of rules?

Hahaha I wanted to try the TikApp to try the magic number but RC is too advanced for the poor TikApp so back to a bigger computer.
by msatter
Sun May 27, 2018 3:23 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

In the decision table underneath I have changed the interpretation in IP - Firewall - Address Lists on the CLI. ... If timeout = 00:00:00 then it is dynamic without end time (erased on reboot / not in export/backup / Flags: D) --> "none dynamic" in Winbox ... Not sure what version you've used to ve...
by msatter
Sun May 27, 2018 2:46 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

You are correct. I can't see them in the export because they are not exported...I should have known that. So now I tried to add an address from the terminal with an time-out of 00:00:00 and that is interpreted as a static entry and this could be used as a "none dynamic" (no timeout, dynamic). A nega...
by msatter
Sun May 27, 2018 12:55 pm
Forum: Scripting
Topic: l2tp-client per script enable not consistent working
Replies: 6
Views: 220

Re: l2tp-client per script enable not consistent working

hi,

just checked it out. - no its not working.

christian
Thanks for checking out.
by msatter
Sun May 27, 2018 12:52 pm
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

I make regularly a backup and a RSC file from the configuration as it is good practice. So having the lists present in the files takes more place on the backup disk. Some lists have a limited lifetime of a few hours till 7 days before being regenerated externally. These will not be included in the b...
by msatter
Sun May 27, 2018 10:59 am
Forum: Scripting
Topic: l2tp-client per script enable not consistent working
Replies: 6
Views: 220

Re: l2tp-client per script enable not consistent working

hey again,

jfyi:

/interface l2tp-client find name XX
is also working.

greetings

christian
Can you try and see if this also works?

/ip route set [find where comment="floating-hsi"] distance=1
/ip route set [find where comment="floating-mgt"] distance=4
by msatter
Sun May 27, 2018 10:49 am
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Re: Address list --> non dynamic/static timeout

Anyone?
by msatter
Sat May 26, 2018 10:01 am
Forum: Beginner Basics
Topic: Can I set static DNS server priority
Replies: 8
Views: 336

Re: Can I set static DNS server priority

In the Mikrotik you put the DNS address of the PiHole (only one) and that will take care of your DNS. Don't "Allow Remote Request". To install PiHole on your your first setup up your Raspberry with the standard Linux from their site and then go to the PiHole site to copy, past and execute the link: ...
by msatter
Fri May 25, 2018 11:36 pm
Forum: Beginner Basics
Topic: Can I set static DNS server priority
Replies: 8
Views: 336

Re: Can I set static DNS server priority

I don't know adguard but did you have a look at PiHole?

I made myself an ad blocker by using DNSmasq and since a short while I put an other caching DNS in the chain with the name unbound which handle correctly the DNSSEC.

I really love the workings of unbound.
by msatter
Thu May 24, 2018 8:14 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

. . Also for those too lazy to read where to get the new winbox.exe here you go: https://www.mikrotik.com/download/share/winbox.exe that link was not in the update text of the package manager, but was in the post about the latest release. 8) Is now mentioned at the top of the posting. The original ...
by msatter
Thu May 24, 2018 3:54 pm
Forum: General
Topic: [Security] Attackers changed DNS servers
Replies: 8
Views: 2621

Re: [Security] Attackers changed DNS servers

.
.
We are also working on a blog.
That is excellent news and will make information easier accessible and questions/discussion can be done in the forum linked to from the blog.
by msatter
Thu May 24, 2018 10:29 am
Forum: General
Topic: Address list --> none dynamic/static timeout
Replies: 27
Views: 687

Address list --> none dynamic/static timeout

When I add an address to an address list in the rules lines I can set instead of a expiration time for that specific entry. This can be done by setting a time-out time or none dynamic or none static. I wanted to do this also in the terminal but those two options beside the time are not available. I ...
by msatter
Wed May 23, 2018 10:42 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

*) backup - do not encrypt backup file unless password is provided; :D

I will wait till the next release because of the possible pitfalls when having to clear the configuration.
by msatter
Tue May 22, 2018 9:38 pm
Forum: Beginner Basics
Topic: Connection via USB?
Replies: 3
Views: 194

Re: Connection via USB?

by msatter
Thu May 17, 2018 1:07 pm
Forum: RouterBOARD hardware
Topic: New : RB760IGS - HEX-S
Replies: 28
Views: 3582

Re: New : RB760IGS - HEX-S

How about RM(rackmount) version of Hex?
You could use a tray and put a few of those little rascals side by side. ;-)
by msatter
Thu May 17, 2018 12:47 pm
Forum: General
Topic: How to block URL-s contains IP address (Proxy)
Replies: 11
Views: 433

Re: How to block URL-s contains IP address (Proxy)

I use the content filter in RAW to drop the direct IP traffic. You have to disable fast tracking for that direction or only engage fast tracking after 1100bytes. It was in a recent MUM presentation if I remember that correctly. This is for a known IP and if you want to filter all direct IP address o...
by msatter
Tue May 15, 2018 11:35 am
Forum: RouterBOARD hardware
Topic: New : RB760IGS - HEX-S
Replies: 28
Views: 3582

Re: New : RB760IGS - HEX-S

PDF about the RB760igs:

https://www.ip-sa.com.pl/doc/datasheet/hEX_S.pdf

Nice replacement for the RB750Gr3 and I could connect the router directly the glass fiber and do away with the NTU.

Power usage went up from 5 watt yo 11 watt and the PoE OUT is a nice bonus.
by msatter
Mon May 14, 2018 12:08 am
Forum: RouterBOARD hardware
Topic: New : RB760IGS - HEX-S
Replies: 28
Views: 3582

Re: New : RB760IGS - HEX-S

by msatter
Sun May 13, 2018 8:13 pm
Forum: General
Topic: filter rule notation
Replies: 5
Views: 165

Re: filter rule notation

When you enter terminal press TAb twice and curse, it is already implemented. I don't like it because I have to close the terminal window and reopen it type the commands in full and press TAB once to complete or some help which options are available.
by msatter
Thu May 10, 2018 4:02 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 341
Views: 40056

Re: v6.43rc [release candidate] is released!

I had good hope my ticket (Ticket#2018042122002234) would be resolved in this version but it is not. Setting Neighbors to !Dynamic still pokes my Dail-on-Demand connection and won't let it go to sleep when the time-out is there. When I look in interfaces - interface lists I don't see any content in ...
by msatter
Wed May 09, 2018 8:57 pm
Forum: Beginner Basics
Topic: Mangle - Jump Question.
Replies: 12
Views: 491

Re: Mangle - Jump Question.

I was wrong on that and I am confused on my thoughts that it was possible. I really remember seeing and even check if i could set connection tracking which was not posible. I have a backup from a config that was no working correct and I went back then several days to restart from base again. As I sh...
by msatter
Wed May 09, 2018 7:55 pm
Forum: Announcements
Topic: Tik App, MikroTik android utility ALPHA test
Replies: 318
Views: 98870

Re: Tik App, MikroTik android utility ALPHA test

Cisco sucks in making tablets. ;-)
by msatter
Wed May 09, 2018 12:43 pm
Forum: RouterBOARD hardware
Topic: What can be improved in hEX (RB750Gr3)?
Replies: 22
Views: 1747

Re: What can be improved in hEX (RB750Gr3)?

Make visible/controllable in RouterOS if the ports are in switch mode or in CPU mode.
by msatter
Sun May 06, 2018 4:03 pm
Forum: General
Topic: Firewall rule : How to drop TCP connection lasting more than 3 hours
Replies: 11
Views: 435

Re: Firewall rule : How to drop TCP connection lasting more than 3 hours

If you add the source then it could be working for several tv/set-topbox/tablet/phone independent but I don't think that will be doable. Using destination you can control access to the destination the IPTV is transmitted from, this if it is one source. Update: have made an first setup and 10.20.20.0...
by msatter
Sun May 06, 2018 2:05 pm
Forum: General
Topic: Firewall rule : How to drop TCP connection lasting more than 3 hours
Replies: 11
Views: 435

Re: Firewall rule : How to drop TCP connection lasting more than 3 hours

If you can identify the traffic by IP or port then you could use two addresslist. The first set the IP to be blocked for 24 hours. The second one allows for three hours. On set: Put IP destination address in three hour list if not in the 24 hour list Put IP destination address in in 24 hour list if ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 15