Community discussions

MikroTik App

Search found 67 matches

by servaris
Tue Jan 31, 2023 2:39 pm
Forum: General
Topic: How to use IP Pools for RoadWarrior IKEv2 connections?
Replies: 3
Views: 570

Re: How to use IP Pools for RoadWarrior IKEv2 connections?

Hi, With IKEv2 connection the IP address one has from their router or ISP is NOT masqueraded like it is with L2TP/IPsec. Even though I am given an IP address from the attribute | ip-pool name, entering 'my ip' into search engine produces the IP address given by the local ISP which to me is absolutel...
by servaris
Sun Jan 29, 2023 5:58 pm
Forum: General
Topic: How to use IP Pools for RoadWarrior IKEv2 connections?
Replies: 3
Views: 570

How to use IP Pools for RoadWarrior IKEv2 connections?

Hi, Have working RoadWarrior IKEv2 configuration. Only one issue, how to get IP Pool IP addresses used like the clients received for L2TP/IPSec VPN? There are 3 groups, each group has their own IP Pool. What has to be changed/added so when a client connects to the Mikrotik router with IKEv2 they get...
by servaris
Fri Sep 16, 2022 4:16 pm
Forum: General
Topic: Speed is very slow
Replies: 2
Views: 1106

Speed is very slow

We have one CCR1009-8G-1S-1S+ and one RB760iGS (hEXS) in two data centers in the same city. There are no queues on both routers. There is 1GB ethernet connection on each router. A new 1GB connection was added today to the CCR1009. It did not help at all. The tests were made very early in the AM when...
by servaris
Wed Jan 19, 2022 10:47 am
Forum: General
Topic: L2TP/IPsec Issues with Windows 11 update - kb5009566
Replies: 29
Views: 23150

Re: L2TP/IPsec Issues with Windows 11 update - kb5009566

You will need to tell windows to NOT run updates or that bug laden update will be reinstalled and you'll have the same problem. On windows10 settings => windows update settings => pause it for as long as possible.
by servaris
Thu Sep 02, 2021 9:23 am
Forum: General
Topic: CCR1009 L2TP/IPsec VPN not masquerading location error or bug
Replies: 0
Views: 622

CCR1009 L2TP/IPsec VPN not masquerading location error or bug

Have a CCR1009 in our DC in Canada . It is configured for L2TP/IPsec VPN connections for some users. Some users are in North America and some are in Israel. The problem is when a user is connected to the CCR1009 VPN from Canada or the USA and opens chrome or firefox and goes to google.com, the resul...
by servaris
Thu Aug 26, 2021 6:55 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

Tried your suggestion of settings => privacy => Permissions => Location to block new requests for location. Cleared cache, closed and then reopened firefox. Open google.com and it shows the location of the computer. Location permissions is not the issue. google-from-ccr1009.png Disconnected from CCR...
by servaris
Thu Aug 26, 2021 3:35 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

I'm using firefox not chrome.
This computer location is set to Canada. So are the clients that need to connect to the CCR1009 as I have asked them.

Thanks.
by servaris
Thu Aug 26, 2021 3:27 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

Connected now to hEX S L2TP/IPsec vpn, IP address is right but same issue it seems with browser geolocation. The google ad at the bottom though is not in foreign language. hexs_ip_address.png hexs_browser_geolocation.png google-from-hexs.png But when going to google.com it sees me in Canada with hEX...
by servaris
Thu Aug 26, 2021 3:14 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

The browser geolocation is actually correct, but that's not the desired result. It should show the country where the IP address is. In this case the IP address is located in Canada. The map image above is not Canada.

Thanks.
by servaris
Thu Aug 26, 2021 3:11 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

The connection to the CCR1009 is direct. Have client configured for each separate VPN.
Thanks.
by servaris
Thu Aug 26, 2021 3:10 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

Using https://mylocation.org/ Shows the correct IP address but the browser geolocation shows the country where the computer is located. browser_geolocation.png The google ads all display based on the country the computer is located in rather than the location of IP address. This really screws up cli...
by servaris
Thu Aug 26, 2021 2:21 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

vpntesting.com Ran the test while connected to CCR1009 L2TP/IPsec vpn IPv4 xx.193.49.109 (this is correct IP address handed out by dhcp server in CCR1009) The IP address you use for IPv4 connections. IPv6 N/A The IP you use for IPv6 connections. Connection IPv4 The connection protocol you use now (I...
by servaris
Thu Aug 26, 2021 1:55 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

The only thing I've checked is simple search in search engine. 'My IP' and 'My Location'. My IP results are always correct regardless of which Router I am connected to. When opening browser and connected to say google.com the result (no search yet just opened google.com) page is in foreign language ...
by servaris
Thu Aug 26, 2021 1:50 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

IP routes for the hEX S: Canyon] > /ip route print Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibit # DST-ADDRESS PREF-SRC GATEWAY DISTANCE 0 A S 0.0.0.0/0 l2tp-out1 1 1 ADS 0.0.0.0/0 pppoe-bell 1...
by servaris
Thu Aug 26, 2021 1:35 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

Perhaps you can tell me exactly which config you want to see?
Thanks.
by servaris
Thu Aug 26, 2021 1:21 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

The CCR1009 dhcp server hands out routable (non rfc1918) ip addresses. The hEX S only has 1 public IP address as its just a home office. The CCR1009 has /24 and some of the IP addresses are in pools. The VPN clients get the right IP addresses. There is no problem there.
by servaris
Thu Aug 26, 2021 1:18 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

The search results for anything when connected to the CCR1009 show the results based on one remote country where there are only 3 or 4 client computers. Other VPN clients that are in the same country as the CCR1009 also show search results for the one remote country . These other VPN clients are act...
by servaris
Thu Aug 26, 2021 12:44 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

Have changed the CCR1009 PPP settings to be exactly same as the hEX S. No change. 'my location' search still shows the remote country I am currently in. hEX S shows the location country where the hEX S is. Search 'my ip', the result is the same using either router. Shows the public IP of the hEX S a...
by servaris
Wed Aug 25, 2021 7:03 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

Both VPN client (hEX S and CCR1009) connection settings have 'Use default gateway on remote network' checked.
Thanks.
by servaris
Wed Aug 25, 2021 6:57 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

Re: L2TP/IPsec web browser location result issue

Used a windows 7 notebook to connect to both routers. I connected to the hEX S, location shows up as physical location of the hEX S whereas when I connect to the CCR1009 and location search displays the location of the notebook. I figure it might be a misconfiguration somewhere. The other problem is...
by servaris
Wed Aug 25, 2021 6:34 pm
Forum: General
Topic: L2TP/IPsec web browser location result issue
Replies: 24
Views: 2987

L2TP/IPsec web browser location result issue

Hi, have 2 Mikrotik routers, hEX S and CCR1009 both running L2TP server with IPsec. The issue is when connected to the CCR1009 L2TP/IPsec vpn, the remotely connected computer doing a search for 'my location' will display the country the computer is physically in (not desired). When connected to the ...
by servaris
Wed Jan 17, 2018 9:47 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213936

[SOLVED] Re: Blacklist Filter update script

Thanks to mducharme for pointing out the fix to the failed updates.

Go to system -> scripts
Click on Environment

Negatively increment your blSerial by 1. To be clear, the blSerial WAS 1516197642 and now its 1516197641 as shown below.
script-environment.png
by servaris
Wed Jan 17, 2018 5:53 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213936

Re: Blacklist Filter update script

The script seems to not be working. Ran blacklistUpdate script in terminal. Log displays: 10:46:56 script,warning Checking server for current blacklist serial number. 10:46:56 script,warning Blacklist is already up to date. Nothing to do. 10:46:56 system,info log rule changed by admin 10:46:57 scrip...
by servaris
Sun Nov 12, 2017 4:42 pm
Forum: General
Topic: Large D/L Bandwidth loss with VPN
Replies: 1
Views: 669

Large D/L Bandwidth loss with VPN

Hi, running bandwidth tests with and without connecting to remote AHx2 from local RB2011-UiAS-2Hnd No VPN : speedtest-no-vpn.png /tools => bandwidth test running from the Local RB2011UiAS-2Hnd : bandwidth-test-from-rb2011.png PPTP VPN : speedtest-via-vpn.png /tools => bandwidth test running from the...
by servaris
Mon Oct 30, 2017 5:15 am
Forum: General
Topic: Network issues for L2tp/ipsec with CCR 1009
Replies: 3
Views: 1221

Re: Network issues for L2tp/ipsec with CCR 1009

If you have subnet overlap you need to enable Proxy ARP on the overlapping non VPN subnet, ether2 in your case. Originally, the VPN windows 'connect to' was set for the 104.19x.x.1 which is on Eth2 . Looking at what you said above makes sense because I believe connecting to the .1 IP on Eth2 is ove...
by servaris
Mon Oct 30, 2017 4:54 am
Forum: General
Topic: Network issues for L2tp/ipsec with CCR 1009
Replies: 3
Views: 1221

Re: Network issues for L2tp/ipsec with CCR 1009

The IPs you're using are public IPs you know that right? Yes the IP's subnets are public with exception of 192.168.1.0/24 obviously. There are no overlapping subnets. But when and in this case there is, 192.158.x.x on eth1 (wan) and there is 104.19x.x.x on eth2 AND there is a src nat rule, anything ...
by servaris
Sun Oct 29, 2017 2:49 pm
Forum: General
Topic: Network issues for L2tp/ipsec with CCR 1009
Replies: 3
Views: 1221

Network issues for L2tp/ipsec with CCR 1009

Hi, trying to get an L2TP/IPsec VPN working so it can be used to go out on the net and to devices behind the CCR1009 as one of the IP's in the 104.19x.x.x subnet . When remotely connected to the VPN and search 'my ip' with a search engine, it does report the IP as 104.19x.x.x. The problem is trying ...
by servaris
Tue Jul 18, 2017 4:08 pm
Forum: General
Topic: ipip tunnel with security both routers use ip cloud
Replies: 0
Views: 885

ipip tunnel with security both routers use ip cloud

Hi, Office A and Office B both have MT routers and are remote to each other. Would like to have ipip tunnel with security between them. Both Routers use /ip cloud for dynamic dns. Both routers are behind cable modem. Modem is set to bridge mode in both offices. Both Routers have dhcp enabled routeab...
by servaris
Mon Mar 27, 2017 4:41 pm
Forum: General
Topic: 50% bandwidth loss RB2011UiAS
Replies: 18
Views: 4552

Re: 50% bandwidth loss RB2011UiAS

tx-stats.png
traffic.png
rx-stats.png
by servaris
Mon Mar 27, 2017 4:39 pm
Forum: General
Topic: 50% bandwidth loss RB2011UiAS
Replies: 18
Views: 4552

Re: 50% bandwidth loss RB2011UiAS

This site only allows 3 images!
ethernet.png
loop-protect.png
general.png
by servaris
Mon Mar 27, 2017 4:34 pm
Forum: General
Topic: 50% bandwidth loss RB2011UiAS
Replies: 18
Views: 4552

Re: 50% bandwidth loss RB2011UiAS

Hi Pukkita,

Below are images af all
status.png
rx-stats.png
overall-stats.png
by servaris
Mon Mar 27, 2017 3:58 pm
Forum: General
Topic: 50% bandwidth loss RB2011UiAS
Replies: 18
Views: 4552

Re: 50% bandwidth loss RB2011UiAS

Fastrack and Fastpath
Search for this in wiki
Thanks for the suggestion Mistry7

New firewall rules added for Fasttrack
firewall.png
by servaris
Mon Mar 27, 2017 3:54 pm
Forum: General
Topic: 50% bandwidth loss RB2011UiAS
Replies: 18
Views: 4552

Re: 50% bandwidth loss RB2011UiAS

Hi Pukkita, Bandwidth test TCP > 10 minutes bandwith-tcp-both-10min.png Eth1 Overall stats > 10 minutes ether1-stats.png Received email from support suggesting to run bandwidth test using UDP, Bandwidth test UDP > 10 minutes . UDP bandwidth looks great but aren't most things TCP? bandwith-udp-both-1...
by servaris
Sun Mar 26, 2017 5:24 am
Forum: General
Topic: 50% bandwidth loss RB2011UiAS
Replies: 18
Views: 4552

50% bandwidth loss RB2011UiAS

Hi, Getting loss of more than 50% DL speed when behind the RB2011UiAS. There is an issue with upload speed ISP said will be fixed. Tests below were performed from wired Desktop Behind RB2011UiAS bandwidth-test-rb2011.png Directly connected to Cable Modem bandwidth-test-cablemodem.png Running the Ban...
by servaris
Mon Nov 28, 2016 8:24 pm
Forum: Wireless Networking
Topic: Clients keep getting disconnected from hot-spot and staff
Replies: 0
Views: 757

Clients keep getting disconnected from hot-spot and staff

Hi, Have an RB1100AHx2 with 3 Groove devices attached to provide wireless for staff and guest hot-spot. Both types are being kicked off for the past few weeks and there has not been any changes made to grooves or RB100AHx2. Log shows entries like: hotspot,info,debug guest (192.168.120.214): logged o...
by servaris
Tue Aug 02, 2016 10:30 pm
Forum: General
Topic: RB2011UiAS-2HnD constantly drops Winbox connection
Replies: 5
Views: 2209

RB2011UiAS-2HnD constantly drops Winbox connection

Hi, Since upgrading to 6.36 yesterday, when using Winbox to connect to the RB2011UiAS-2HnD it is constantly disconnecting Winbox for some strange reason. Popup dialogue box displays: Could not connect to 192.168.1.1 (port 8291) - other end is not responding. A second dialogue box pops up displaying:...
by servaris
Mon Aug 01, 2016 7:58 am
Forum: General
Topic: Cannot Upgrade RB2011UiAS-2hnd - missing wireless-6.36-mipsbe.npk
Replies: 3
Views: 1749

Cannot Upgrade RB2011UiAS-2hnd - missing wireless-6.36-mipsbe.npk

Hi,
Trying to upgrade an RB2011 currently at 6.28 and it fails with
 missing wireless-6.36-mipsbe.npk
How to upgrade when the Router is remote?

Thanks.
by servaris
Sat May 28, 2016 2:50 am
Forum: General
Topic: RB2011UiAS VoIP QoS
Replies: 1
Views: 1023

Re: RB2011UiAS VoIP QoS

Hi, Since writing the first post, took a shot at configuring the mangle rules and queue tree from the wiki page but using parent=GLOBAL . Made some calls from both desktop phone and smart phone and both showup in queue: Current Settings: /ip firewall mangle add action=mark-packet chain=prerouting co...
by servaris
Sat May 28, 2016 1:14 am
Forum: General
Topic: RB2011UiAS VoIP QoS
Replies: 1
Views: 1023

RB2011UiAS VoIP QoS

Hi, My RB2011UiAS version=6.35.2 Found a page that shows a setup for QoS And VoIP at http://wiki.mikrotik.com/wiki/Voip The code on that page shows things like parent=global-in and parent=global-out but there is only global in the Parent drop down list. The code on that wiki page is: /queue tree add...
by servaris
Thu Dec 10, 2015 7:05 pm
Forum: General
Topic: Cannot login to webfig from LAN due to password
Replies: 0
Views: 1057

Cannot login to webfig from LAN due to password

Hi,
Webfig is failing login using 'admin' without password. Tried my username/passwd for ppp and webfig does same..

webfig.png
Tried removing any IP address in /ip service www-ssl and it did not change anything. The user 'admin' doesn't have a password.

Thanks for your help.
by servaris
Tue Apr 28, 2015 3:33 pm
Forum: General
Topic: NEED HELP WITH Inbound QUEUE for HTTP not working
Replies: 2
Views: 1078

Re: NEED HELP WITH Inbound QUEUE for HTTP not working

Hi thebracket, Thanks for replying. Trying to monitor and control inbound packets to this office. Especially so to make sure there is always enough bandwidth available for SIP/RTP (VoIP). Tried changing both mangle rules to use forward but it did not show any usage in the queue tree. After removing ...
by servaris
Fri Apr 24, 2015 3:59 pm
Forum: General
Topic: NEED HELP WITH Inbound QUEUE for HTTP not working
Replies: 2
Views: 1078

NEED HELP WITH Inbound QUEUE for HTTP not working

Hi, Have a strange issue. The mangle list shown below clearly shows packets and there are two rules, mark connection and mark packets. The RB2011 queue is not controlling inbound HTTP packets. Other items in the queue list seem to be working. #IP FIREWALL MANGLE 7 ;;; HTTP Down chain=prerouting acti...
by servaris
Thu Apr 23, 2015 2:27 am
Forum: General
Topic: Queue Tree Not displaying live packets for http down
Replies: 0
Views: 619

Queue Tree Not displaying live packets for http down

Hi, Have a strange issue. The mangle list shown below clearly shows packets and there are two rules, mark connection and mark packets #IP FIREWALL MANGLE 7 ;;; HTTP Down chain=prerouting action=mark-connection new-connection-mark=HTTP passthrough=no protocol=tcp in-interface=ether1-gateway src-port=...
by servaris
Wed Jan 28, 2015 3:47 pm
Forum: General
Topic: how block connection of p2p?
Replies: 291
Views: 197308

Re: how block connection of p2p?

Actually was looking for a way to limit P2P (torrents et al) via queue but thought a good test would be to see if it can be blocked period. Chupaka wrote add to firewall rules: 36 chain=forward action=drop p2p=all-p2p log=no log-prefix="" Then added http://releases.ubuntu.com/14.04.1/ubunt...
by servaris
Thu Nov 20, 2014 7:22 pm
Forum: General
Topic: Guests issue with HotSpot Login.html with Notebooks (solved)
Replies: 2
Views: 1029

Re: Guests issue with HotSpot Login.html with Notebooks (sol

Hi Feklar, Thank you for replying with your comment. I did not put in an FQDN because there is no local dns server. Like I said in the original post, the organization was unwilling to spend money to get a small DNS Server. Since they did not have a dns server, I simply put hotspot1 as the DNS Name. ...
by servaris
Wed Nov 19, 2014 4:50 pm
Forum: General
Topic: Guests issue with HotSpot Login.html with Notebooks (solved)
Replies: 2
Views: 1029

Guests issue with HotSpot Login.html with Notebooks (solved)

Hi, Although I posted this earlier, not one person made any reply which I am really surprised at. The issue was guests running microsoft windows on a notebook could not get to the login.html page. What ever web page they were trying to get to would just show as 'page cannot be displayed'. To be clea...
by servaris
Thu Nov 13, 2014 10:39 pm
Forum: General
Topic: Windows PCs Cannot Access HotSpot login.html
Replies: 0
Views: 823

Windows PCs Cannot Access HotSpot login.html

Hi,
For some reason which is unknown to me, PCs running Windows cannot get to the HotSpot login.html page. PCs running linux and Apple/Mac as well as smart phones can access the login.html and then get internet access.

Any ideas?

Thanks!
by servaris
Wed Nov 12, 2014 2:04 am
Forum: Wireless Networking
Topic: Windows PC's cannot access HotSpot
Replies: 0
Views: 852

Windows PC's cannot access HotSpot

Hi, Using AHx2 with several Groove's in building. People using notebooks with MS Windows cannot get IP address or access the HotSpot login.html page. People with Smart Phones and Apple/Mac notebooks are able to access HotSpot and get IP address without any issues. Wondering if anyone might know what...
by servaris
Wed Oct 15, 2014 6:45 am
Forum: Beginner Basics
Topic: Firewall Mangle rule shows no traffic
Replies: 10
Views: 4229

Re: Firewall Mangle rule shows no traffic

You need to change protocol to tcp. OpenVPN can be either TCP or UDP, in RouterOS only TCP is supported. Hi, I think you are wrong. I write this because of the following from the /log oct/14 23:34:56 firewall,info vpn prerouting: in:ether2 out:(none), src-mac 00:15:65:33:ba:d0, proto UDP, 192 .168....
by servaris
Tue Oct 14, 2014 6:47 am
Forum: Beginner Basics
Topic: Firewall Mangle rule shows no traffic
Replies: 10
Views: 4229

Re: Firewall Mangle rule shows no traffic

Hi,
Where is the connection tracking?
by servaris
Mon Oct 13, 2014 5:57 pm
Forum: Beginner Basics
Topic: Firewall Mangle rule shows no traffic
Replies: 10
Views: 4229

Re: Firewall Mangle rule shows no traffic

Hi, What I did now to retest was the following. On one SIP phone here, changed it to stop using VPN and just use normal insecure communications. Even using the VoIP mangle rule doesn't catch it. The reason seems to be RTP (the actual voice) because 5060 is NOT where voice goes, 5060 is for registrat...
by servaris
Mon Oct 13, 2014 2:19 am
Forum: Beginner Basics
Topic: Firewall Mangle rule shows no traffic
Replies: 10
Views: 4229

Firewall Mangle rule shows no traffic

Hi, I am reasonbly sure the problem is with me. Setup a Firewall Mangle rule to mark connection and mark packet for 'any port' 1194. Make a call, no traffic shows. Tried adding src address and then dest address, still no traffic shows. Tried again and used Packet Sniffer and there of course the traf...
by servaris
Wed Oct 08, 2014 4:26 am
Forum: Beginner Basics
Topic: Configuring for 2 types of users on LAN
Replies: 1
Views: 953

Configuring for 2 types of users on LAN

Hi, On a new RB1100AHx2 what would be suggested to accomplish the following: 1) One group (group1) of users to be able to see/access any device on the LAN (Wired and Wireless) 2) One group (group2) of users to only have internet access and not be able to see/access other devices on the LAN. (Wired a...
by servaris
Wed Oct 08, 2014 2:16 am
Forum: Beginner Basics
Topic: Using backup from one router in another?
Replies: 9
Views: 9451

Re: Using backup from one router in another?

Hi,
Can a /export compact from a 6.15 rb2011uias be transfered into a brand new rb1100ahx2? If it can, should the ahx2 have configuration reset first using the following command?
/system> reset-configuration no-defaults=yes


Thanks.
by servaris
Mon Sep 15, 2014 5:17 am
Forum: General
Topic: RouterOS Not sending DHCP-Server Option 66
Replies: 14
Views: 37097

Re: RouterOS Not sending DHCP-Server Option 66

I suggest to take a look at the new syntax for the dhcp options in the wiki.

http://wiki.mikrotik.com/wiki/Manual:IP ... CP_Options
Hi Patrikg,
My syntax is:

/ip dhcp-server option
add code=150 name=tftp-server value=0x63EE56AE

It works. However, if code=66 it will NOT work.
by servaris
Sun Sep 14, 2014 11:24 pm
Forum: General
Topic: tftp-server-name option in DHCP-SERVER
Replies: 17
Views: 34957

Re: tftp-server-name option in DHCP-SERVER

I think it is worth noting that code cannot be 66

Been playing with this all day and have found when using code 66 the phone does not connect to remote tftp server.
by servaris
Sun Sep 14, 2014 10:01 am
Forum: General
Topic: RouterOS Not sending DHCP-Server Option 66
Replies: 14
Views: 37097

Re: RouterOS Not sending DHCP-Server Option 66

I tried adding it via Mikrotik GUI and do not see the phone able to connect to the tftp server. Turned off the dhcp server on Mikrotik for the wired network and used some windows based dhcp server, used option 66 with the IP and it connected immeditately. /ip dhcp-server network add address=192.168....
by servaris
Fri Jul 04, 2014 4:07 am
Forum: General
Topic: Firewall/QoS rules for small office RB2011 and CRS125
Replies: 9
Views: 3810

Re: Firewall/QoS rules for small office RB2011 and CRS125

But at some point there is a choke point on the Mikrotik where you could sniff traffic correct? I tried the sniff app. I did not see the address. Actually, the phone is setup to use OpenVPN, and it uses a 10.8.0.x IP. The phone says though 192.168.10.11 In the sniff app, for 10.11 IP it did show a ...
by servaris
Fri Jul 04, 2014 4:03 am
Forum: General
Topic: Firewall/QoS rules for small office RB2011 and CRS125
Replies: 9
Views: 3810

Re: Firewall/QoS rules for small office RB2011 and CRS125

On the Yealink 22P it shows: http://www.servaris.com/images/voip/yl22p-qos.jpg The T22P manual states: Voice QoS In order to make VoIP transmissions intelligible to receivers, voice packets should not be dropped, excessively delayed, or made to suffer varying delay. DiffServ model can guarantee high...
by servaris
Fri Jul 04, 2014 3:46 am
Forum: General
Topic: Firewall/QoS rules for small office RB2011 and CRS125
Replies: 9
Views: 3810

Re: Firewall/QoS rules for small office RB2011 and CRS125

By the way, I don't have a problem with wireshark. The problem is running wireshark on what? The phones here are not connected to computers. They run to switch and its not a Mikrotik switch either. Its an unmanaged 3com.
by servaris
Fri Jul 04, 2014 3:43 am
Forum: General
Topic: Firewall/QoS rules for small office RB2011 and CRS125
Replies: 9
Views: 3810

Re: Firewall/QoS rules for small office RB2011 and CRS125

Hi,
We have Yealink T22P and HT502 ATA for analogue phone and Polycom VVX310

I am extremely new to Mikrotik and no network guru either. I want to setup our RB2011AiUS and have another RB2011AiUS and a CRS125 for client. Basically the same setup.

Thanks JKarras
by servaris
Fri Jul 04, 2014 2:41 am
Forum: General
Topic: Firewall/QoS rules for small office RB2011 and CRS125
Replies: 9
Views: 3810

Re: Firewall/QoS rules for small office RB2011 and CRS125

Do your phones tag the packets with DSCP or COS values? It may be easy to pickup on those values for your QOS.
Hi jkarras,

How can I tell? Since the phones here go through the RB2011 I cannot run a tcpdump. Can this be done on the RB2011?
by servaris
Wed Jul 02, 2014 10:12 pm
Forum: General
Topic: Firewall/QoS rules for small office RB2011 and CRS125
Replies: 9
Views: 3810

Firewall/QoS rules for small office RB2011 and CRS125

Hi, I have searched around for simple firewall rules for small offices which include QoS for SIP. What I have found are very complicated sets and unsure if those are really needed. Below is the network topology: Wireless Internet Access <-> RB2011iUAS <--> CRS125-24G-1S-2H <--> LAN RB2011UiAS Wirele...
by servaris
Mon Jun 02, 2014 3:46 am
Forum: Beginner Basics
Topic: SSH attack
Replies: 7
Views: 6523

Re: SSH attack

I am no Mikrotik guru but I would say it is easier to use a different port for SSH. We use a 5 digit port number (same one of course) on every one of our servers. Never got broken into. We used PF on the Servers (running FreeBSD). IThen you can use the firewall rule the person above said to use for ...
by servaris
Mon May 26, 2014 1:54 am
Forum: Beginner Basics
Topic: How to block many IP subnets
Replies: 1
Views: 800

How to block many IP subnets

Hi, In a previous firewall system we blocked many subnets using a simple text file which has each x.x.x.x/x or /xx per line. We are using the RB2011UiAS now. Example: x.x.x.x/16 x.x.x.x/24 x.x.x.x/12 Is there a way to just import a file like that? If not, how do we add all subnets in order to block ...
by servaris
Wed May 21, 2014 12:13 am
Forum: Beginner Basics
Topic: VoIP, Queue and QoS setup help
Replies: 0
Views: 1183

VoIP, Queue and QoS setup help

Hi, Just received a new RB2011UiAS. Current configuration is the default the RB2011 came with + wireless (using access list), port 2 = 192.168.0.1/24, 192.168.1/24, 192.168.2.0/24 (make it 192.168.0.1/22 ?). Although I tried, perhaps incorrectly, to get dhcp server on the RB2011 working for Wireless...
by servaris
Tue May 20, 2014 5:26 pm
Forum: Beginner Basics
Topic: How to setup QoS and some firewall rules?
Replies: 0
Views: 1263

How to setup QoS and some firewall rules?

Hi, Just received an RB2011UiAS and have it somewhat setup. That is, all LAN clients can access other computers on the LAN and access Internet. We have a few IP phones which use VPN ( OpenVPN setup on REMOTE FreePBX Server ). Local SIP phones show up on remote FreePBX as coming from 10.8.0.6 (FreePB...