Community discussions

Search found 25 matches

by cgood
Fri Mar 29, 2019 6:08 pm
Forum: Wireless Networking
Topic: Home glamourous Mesh Wi-Fi?
Replies: 2
Views: 531

Re: Home glamourous Mesh Wi-Fi?

Omg! Thanks You
by cgood
Thu Mar 28, 2019 5:57 pm
Forum: Wireless Networking
Topic: Home glamourous Mesh Wi-Fi?
Replies: 2
Views: 531

Home glamourous Mesh Wi-Fi?

Do you plan to release a product like an Amplifi/Deco/Multi/Orbi etc?
by cgood
Fri Mar 15, 2019 12:05 pm
Forum: Forwarding Protocols
Topic: ip route cache BUG
Replies: 34
Views: 10794

Re: ip route cache BUG

Currently it is known that OVPN interface reconnects are responsible for route cache leaks.
Hello, how to fix this issue?
Mikrotik CHR -> ip route cache full 512k .. OVPN/L2TP server
by cgood
Sat Jan 26, 2019 12:28 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 152353

Re: RouterOS v7.0 beta1 - when?

unsubscribe ...
by cgood
Fri Jan 18, 2019 9:50 pm
Forum: General
Topic: Wiki Firewall spelling error
Replies: 0
Views: 272

Wiki Firewall spelling error

Снимок экрана 2019-01-18 в 22.48.46.png
https://wiki.mikrotik.com/wiki/Manual:I ... Properties PSD section ...
by cgood
Thu Jan 17, 2019 3:26 pm
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 153
Views: 43930

Re: Feature request - DNSCrypt support...

At home i'm mangling DNS fwd+out connections and redirect to EU OVPN (CHR VPS), but DoH = peer-to-peer encryption & we all need it (=
by cgood
Thu Jan 17, 2019 3:20 pm
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 153
Views: 43930

Re: Feature request - DNSCrypt support...

Huh? Since DNS over HTTPS uses port 443 and there is no visual difference in traffic type, admin can't intercept or block this traffic (except by destination address).
When will the DoH appear 😚? Когда же?
by cgood
Mon Jan 14, 2019 9:39 pm
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 153
Views: 43930

Re: Feature request - DNSCrypt support...

Topic started at 30 Jan 2012 09:55 ... we wait for a miracle No. It just proves how futile is the idea of implementing nonstandard or nonstable technologies - they are gone withing few years. Where is DNScrypt today? Is it massively accepted? No. If mikrotik implemented it back then, it would be en...
by cgood
Mon Jan 14, 2019 12:04 pm
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 153
Views: 43930

Re: Feature request - DNSCrypt support...

+1
interesting, how many people still have to write "+1" that this gave the result? :-?
Topic started at 30 Jan 2012 09:55 ... we wait for a miracle
by cgood
Wed Aug 15, 2018 12:32 pm
Forum: Wireless Networking
Topic: caps-man manager interface all forbid=yes && caps-man-addresses=127.0.0.1
Replies: 3
Views: 1114

Re: caps-man manager interface all forbid=yes && caps-man-addresses=127.0.0.1

And with interface-list it'll be nice to configuring ..
by cgood
Sat Apr 28, 2018 11:03 pm
Forum: Scripting
Topic: Convert Address-List Name to Firewall Rules on-up PPP
Replies: 0
Views: 333

Convert Address-List Name to Firewall Rules on-up PPP

Hello guys! My trivial question is how to parse address-list name and convert to block of three Variables? address-list=tcp-8080-80 address=a.b.c.d => [tcp, 8080, 80] => /ip firewall nat add chain=dst-nat action=dst-nat dst-address=<WAN_IP_ADDRESS> proto=<TCP - first VAR> dst-port=<Second Var> to-po...
by cgood
Sat Apr 21, 2018 12:11 am
Forum: Wireless Networking
Topic: caps-man manager interface all forbid=yes && caps-man-addresses=127.0.0.1
Replies: 3
Views: 1114

caps-man manager interface all forbid=yes && caps-man-addresses=127.0.0.1

Hi pipl! i've next config & my caps-man wlan interfaces can't find capsman ... # apr/21/2018 00:03:35 by RouterOS 6.42 # model = RouterBOARD 952Ui-5ac2nD /caps-man manager set enabled=yes upgrade-policy=suggest-same-version /caps-man manager interface set [ find default=yes ] forbid=yes add disabled...
by cgood
Sat Mar 17, 2018 10:47 am
Forum: General
Topic: igmp-proxy vs ip firewall filter forward connection-nat-state=!dstnat
Replies: 1
Views: 349

igmp-proxy vs ip firewall filter forward connection-nat-state=!dstnat

Hi all, defconf ip firewall filter rule drop multicast flow, how to fix it? Which Rule need to add before? # mar/17/2018 11:40:27 by RouterOS 6.41.3 /ip firewall filter add action=accept chain=input connection-state=established,related,untracked add action=drop chain=input connection-state=invalid a...
by cgood
Wed Feb 07, 2018 10:06 pm
Forum: General
Topic: OpenSSL and OpenVPN
Replies: 6
Views: 1205

Re: OpenSSL and OpenVPN

ROS 6.41.1

*) ovpn - fixed resource leak on systems with high CPU usage;
by cgood
Thu Feb 01, 2018 11:39 pm
Forum: General
Topic: [Feature Request] hotspot walled-garden on SNI hostname / tls-host
Replies: 1
Views: 395

Re: [Feature Request] hotspot walled-garden on SNI hostname / tls-host

+1! So, we have a tls-host and we need TLS-HOST-LIST too. Next step HOTSPOT+WEB PROXY with fully HTTPS ready functionality :D :) :( :o :shock: !!!
by cgood
Thu Feb 01, 2018 10:48 pm
Forum: General
Topic: tls-host no document [SOLVED]
Replies: 18
Views: 5631

Re: tls-host no document [SOLVED]

Doesn't work for me either. Neither by full name, nor wildcard. P.S. Also, why is this matcher added to NAT rules? There's no info about TLS hostname in TCP SYN packets :) TLS Host does not work in RouterOS 6.41. Use last RouterOS 6.42rc15 (Release candidate). work! https://t.me/cgood/208
by cgood
Wed Jan 10, 2018 4:56 pm
Forum: General
Topic: OpenVPN and subnet for Windows Client
Replies: 4
Views: 2052

Re: OpenVPN and subnet for Windows Client

/interface ovpn-server server> print enabled: yes port: 1194 mode: ip netmask: 32 check your netmask in server config, for mzfk windows it must overlapping server IP and your host IP. So, linux based connect is OK: 2018-01-10 17:45:00 /sbin/ifconfig utun1 172.16.0.63 172.16.0.1 mtu 1500 netmask 255...
by cgood
Fri Dec 08, 2017 12:59 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 152353

Re: RouterOS v7.0 beta1 - when?

Just for an example. Less about OpenVPN TCP. We have more than 100 connected clients (ROS/Linux devices) to CHR (1G RAM P1 lic) - all use TCP. Speed-test between two VPS connected to CHR via ovpn-client: - - - - - - - - - - - - - - - - - - - - - - - - - [ ID] Interval Transfer Bandwidth Retr [ 4] 0....
by cgood
Mon Dec 04, 2017 10:58 pm
Forum: General
Topic: Feature request - DNSCrypt support...
Replies: 153
Views: 43930

Re: Feature request - DNSCrypt support...

+1 DNSCRYPT-PROXY support! Thank you!
by cgood
Sun Nov 19, 2017 8:36 pm
Forum: The Dude
Topic: x86 ROS Device SSL process spikes router CPU to 100%
Replies: 14
Views: 3483

Re: x86 ROS Device SSL process spikes router CPU to 100%

Aruba CHR OVPN server: /interface ovpn-server server> /system resource monitor cpu-used: 100% cpu-used-per-cpu: 100% free-memory: 885812KiB /system resource print uptime: 1w3d3h13m44s version: 6.40.5 (stable) build-time: Oct/31/2017 13:05:15 free-memory: 864.9MiB total-memory: 972.9MiB cpu: Intel(R)...
by cgood
Fri Nov 17, 2017 10:01 pm
Forum: General
Topic: OpenSSL and OpenVPN
Replies: 6
Views: 1205

Re: OpenSSL and OpenVPN

That is NOT true. Here is the manual:
https://wiki.mikrotik.com/wiki/OpenVPN
Sorry :( , i mean UDP support. I forget some users can connect your vpn using OpenVPN over TCP.
Yes
> interface ovpn-server print count-only
113
by cgood
Fri Nov 17, 2017 8:21 pm
Forum: General
Topic: Limit WiFi client internet access by limited time per day
Replies: 9
Views: 11101

Re: Limit WiFi client internet access by limited time per da

Спасибо, работает, избавился от мозго*** с Hotspot+HTTPS /interface bridge add arp=reply-only comment=hotspot name=br1 # # /ip address add address=10.1.30.1/24 comment=hotspot interface=br1 network=10.1.30.0 # # /ip pool add name=dhcp_pool2 ranges=10.1.30.2-10.1.30.254 # /ip dhcp-server add add-arp=...
by cgood
Thu Apr 13, 2017 3:16 pm
Forum: RouterBOARD hardware
Topic: cAP Lite died
Replies: 5
Views: 1237

cAP Lite died

Hi guys. We just bought 8 points, one point died right after inclusion and dumping into the cap mode - at inclusion all indicators burn and ethernet isn't connected. Two points were adjusted at office but also didn't earn on an object. Connection was made from the Ubiquiti EdgeMAX ES-24-150W switchb...