Community discussions

MikroTik App

Search found 1754 matches

by BartoszP
Tue Jun 02, 2020 3:35 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 5
Views: 806

Re: v6.47 [stable] is released!

The proper word coming to my mind is: IMPRESSIVE :) list of changes.
by BartoszP
Fri May 29, 2020 4:38 pm
Forum: General
Topic: DNS Failover
Replies: 16
Views: 5153

Re: DNS Failover

Could you please use "Post replay" instead of quoting hole previous posts.

We are able to follow the thread ... no need to quote it all the time.
by BartoszP
Thu May 28, 2020 8:21 am
Forum: Beginner Basics
Topic: Backup/Restore to Different Hardware
Replies: 3
Views: 368

Re: Backup/Restore to Different Hardware

Export configuration to a file and then import to the new device.
You have to tailor configuration according to interface names, MAC's etc.
Search the forum for "restore configuration"
by BartoszP
Thu May 28, 2020 7:40 am
Forum: General
Topic: Bloqueo de conexiones persistentes
Replies: 3
Views: 533

Re: Bloqueo de conexiones persistentes

Anav:

Rules should be obeyed.

Do you volunteer to translate posts instead of all lazy OP?
by BartoszP
Wed May 20, 2020 5:54 pm
Forum: Forwarding Protocols
Topic: ISP default route and internal network OSPF
Replies: 2
Views: 394

Re: ISP default route and internal network OSPF

IMHO you should set "distance" for ISP interfaces in your local routing tables to number higher than expected "distance" of default router received from OSPF.
With no OSPF information the only one route will be ISP interface and when OSPF is connected the default route will be switched to the new one.
by BartoszP
Wed May 20, 2020 5:33 pm
Forum: Beginner Basics
Topic: Vendor question
Replies: 8
Views: 1002

Re: Vendor question

Upgrade, reset to the default configuration and then compare.
Or reset to "no-default-configuration" and start configuring from scratch.
by BartoszP
Tue May 12, 2020 4:23 am
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23796

Re: Just going to leave this here...

I think more people would want a couple 40G ports at home than 12x 10G.
vortex ... please do not treat us as fools and please do not lie ... once more i see such a comment and you will be banned
by BartoszP
Tue May 12, 2020 3:37 am
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23796

Re: Just going to leave this here...

vortex.

Last call ... PLEASE DO STOP throwing everywhere comments that 10+ Gb ports are a common need at homes ....
by BartoszP
Tue May 12, 2020 3:33 am
Forum: RouterBOARD hardware
Topic: 10 GIG version of HEX
Replies: 7
Views: 1190

Re: 10 GIG version of HEX

Please DO STOP.

CRS305 IS an ALMOST perfect fit for OP needs ... so once more PLEASE DO STOP throwing your comments about "a must have device" for all.
by BartoszP
Tue May 12, 2020 12:16 am
Forum: RouterBOARD hardware
Topic: 10 GIG version of HEX
Replies: 7
Views: 1190

Re: 10 GIG version of HEX

@vortex

PLEASE STOP sharing your thoughts what people need or what you think people dream of.

The OP asked a question about simple device with small amount of fast ports to use them as converters. Nothing more.
by BartoszP
Tue May 05, 2020 5:33 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23796

Re: Just going to leave this here...

CCR2004-1G-12S+2XS is our router with the most powerful single-core performance so far. It provides incredible results in single tunnel (up to 3.4 Gbps) and BGP feed processing.
Maybe it is the answer.
by BartoszP
Sun Apr 26, 2020 10:35 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23796

Re: Just going to leave this here...

And what is the implication of that? What does it mean for Mac's networking?
by BartoszP
Sun Apr 26, 2020 10:25 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23796

Re: Just going to leave this here...

40G is the new 10G. When I was asking for home routers capable of 10G switching some years ago, it was professional level. Now not only is 10G cheap, some people even have 10G WAN at home. Why would you buy a couple of 25G cards when they are not much cheaper than 40G? Workstations and NAS that can...
by BartoszP
Sun Apr 26, 2020 9:58 am
Forum: Beginner Basics
Topic: Winbox connecting with different mac address!
Replies: 3
Views: 769

Re: Winbox connecting with different mac address!

A. Use "Post reply" instead of quoting whole previous post. No need to cite it. B. If an interface is part of any bridge then it "losts" it's MAC. It becomes "dumb" connector of a bridge and a bridge takes over its MAC and presents itself with the lowest MAC of all interfaces it consists of. If inte...
by BartoszP
Sun Apr 26, 2020 9:41 am
Forum: Beginner Basics
Topic: Winbox connecting with different mac address!
Replies: 3
Views: 769

Re: Winbox connecting with different mac address!

Printed MAC is the MAC of interface usually described as Internet and the second MAC is the lowest MAC of interfaces designated to be LAN interfaces. If you configure bridge for a group of interfaces then it receives administrative MAC as the lowest MAC of all included interfaces until you set it ma...
by BartoszP
Sat Apr 25, 2020 9:50 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23796

Re: Just going to leave this here...

@Mikhalich

Could you use "Post reply" button instead of quotting previous posts all the time? Most readers are able to read them if they need it and there is no need to quote.
by BartoszP
Thu Apr 23, 2020 4:40 pm
Forum: General
Topic: How to debug Netflix error with multi-WAN setup.
Replies: 4
Views: 1242

Re: How to debug Netflix error with multi-WAN setup.

You start traffic via WAN2, receive answer and then rest of connection goes via WAN1.
Result: Netflix see traffic from different addresses and "complains".
by BartoszP
Thu Apr 23, 2020 2:39 pm
Forum: Beginner Basics
Topic: Should I go for Router OS ?
Replies: 6
Views: 1389

Re: Should I go for Router OS ?

Quoting news: "Juniper Networks warned customers Thursday of a high-risk vulnerability in the GD graphics library that could allow a remote attacker to take control of systems running certain versions of the Junos OS." "The denial of service vulnerability, CVE-2020-3120, affects separate implementat...
by BartoszP
Tue Apr 21, 2020 4:46 pm
Forum: General
Topic: What is my IP address on my MikroTik router?
Replies: 3
Views: 897

Re: What is my IP address on my MikroTik router?

Inside? Just kidding ... :D
What address are you asking about? Are you connected to your router via WWW or Winbox?
by BartoszP
Tue Apr 21, 2020 8:45 am
Forum: RouterOS v7 BETA
Topic: Mysterious 564/tcp open port 7.0beta5
Replies: 38
Views: 6222

Re: Mysterious 564/tcp open port 7.0beta5

"9pfs is a network filesystem protocol developed for Plan 9"

Is HA coming with shared resources?
by BartoszP
Tue Apr 14, 2020 12:48 pm
Forum: RouterBOARD hardware
Topic: Need new hardware switch (based on RB260GS but do not need SFP/PoE)
Replies: 34
Views: 4553

Re: Need new hardware switch (based on RB260GS but do not need SFP/PoE)

I'm not Mikrotik's empleyee so do not ask me questions what is "ordinary and affordable" and if Mikrotik is "hopeless". Mikrotik does not manufacture "DUMB" switches. DUMB and CHEAP. Maybe their not so cheap devices have their flaws but it's a different story. If you want really "cheap and affordabl...
by BartoszP
Mon Apr 13, 2020 11:26 am
Forum: RouterBOARD hardware
Topic: Need new hardware switch (based on RB260GS but do not need SFP/PoE)
Replies: 34
Views: 4553

Re: Need new hardware switch (based on RB260GS but do not need SFP/PoE)

Once more. What is the sense of doing less usable device_ You have to prepare casting molds for cases. design PCB or redesign current one to be able not to mount some parts. YOU HAVE TO CERTIFY such device for CE/FCC etc. It's not free. You have to have a stock of it, you have to service it. Do you ...
by BartoszP
Sun Apr 12, 2020 6:33 pm
Forum: RouterBOARD hardware
Topic: Need new hardware switch (based on RB260GS but do not need SFP/PoE)
Replies: 34
Views: 4553

Re: Need new hardware switch (based on GPeR)

And what's the point of buying a switch with an SFP port that will never be used What is the sense of removing connectors which make cost of a device a little higher and let serve more users? Are you still joking? You consider providing cable to each desk if only a ceiling would be placed lower. Wh...
by BartoszP
Sun Apr 12, 2020 9:34 am
Forum: RouterBOARD hardware
Topic: Need new hardware switch (based on RB260GS but do not need SFP/PoE)
Replies: 34
Views: 4553

Re: Need new hardware switch (based on GPeR)

Are you joking? Designing new device just beacuse your client cannot afford 10$ difference on a switch with additional USB and SD ports? If look and feel is the most important factor then price shouldn't be a problem. BTW: hide device of any size behind the first desk and there should be no visual/e...
by BartoszP
Wed Apr 08, 2020 12:14 am
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 60623

Re: v6.45.8 [long-term] is released!

@allencesar and @bda

Is it a problem for you to press "Post replay" instead of quoting quotes of quotes ? Do you think it makes reading your discussion more readable?
by BartoszP
Wed Mar 25, 2020 11:24 am
Forum: RouterBOARD hardware
Topic: RouterBoard choice to handle 500Mbps bandwidth
Replies: 9
Views: 3973

Re: RouterBoard choice to handle 500Mbps bandwidth

I use hAP ac2 to do PPPoE connection to ISP on 600/60 line and this router serves/shares pool of public IPs to "second level" routers at my place.
No problem with CPU and traffic. I installed it in the place of my 1100AHx2 which had decided to end it's life :-(
by BartoszP
Thu Mar 19, 2020 5:35 pm
Forum: Wireless Networking
Topic: 6.45.8
Replies: 2
Views: 1426

Re: 6.45.8

More details please. What is your big problem?

Your report is like: I'm ill. What can I do to cure myself.
by BartoszP
Mon Mar 09, 2020 5:28 pm
Forum: General
Topic: How can I change the internet gateway metric? [SOLVED]
Replies: 11
Views: 3139

Re: How can I change the internet gateway metric? [SOLVED]

Make a drawing and post it. One picture tells sometime more than thousends of words.
by BartoszP
Fri Mar 06, 2020 4:51 pm
Forum: RouterBOARD hardware
Topic: What hardware requirement is needed for my Mikrotic router?
Replies: 8
Views: 3592

Re: What hardware requirement is needed for my Mikrotic router?

Buy two hAP ac2 listed @ 65$

Such device behaves quite well for me serving 600/60 line so think that it will be enough for you and you will have two routers.
by BartoszP
Fri Mar 06, 2020 2:46 pm
Forum: Beginner Basics
Topic: SSTP Can-t ping local devices [SOLVED]
Replies: 4
Views: 2568

Re: SSTP Can-t ping local devices [SOLVED]

Make src masquarade changing src ip to router's ip for all connected via VPN.
by BartoszP
Thu Mar 05, 2020 3:36 pm
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 42
Views: 10924

Re: feature request ADVANCED DNS Server

@vortex

Once again:
Could you be so kind and stop filling forum with such consecutive selfanswering "comments".
You just make huge amount of "posts" with no clearly visible sense.
by BartoszP
Sun Mar 01, 2020 12:51 am
Forum: General
Topic: Kansas City MUM USA
Replies: 20
Views: 4006

Re: Kansas City MUM USA

vortex:

Please DO STOP answering yourself and sending post under post ... this is my last "suggestion"
by BartoszP
Thu Feb 27, 2020 9:18 am
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

vortex:

Please DO STOP. It is not funny.
by BartoszP
Wed Feb 26, 2020 12:02 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

B. Moderator's duties. It's not your duty to police a thread that needs none, he isn't posting spam or any such thing. You simply don't like it and that's not enough. *edit* It's not my job to defend so I will just stay out of it. I'm a moderator of a large forum and an admin for another and we fol...
by BartoszP
Tue Feb 25, 2020 10:44 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

Why do you care? He started this thread.
A. I just care. Why not?
B. Moderator's duties.
by BartoszP
Tue Feb 25, 2020 8:43 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

vortex,

IIMHO i's time to stop increasing your post counter. You ask questions, answer them and comment own answers at once. Maybe you should set up your own blog?
by BartoszP
Sun Feb 23, 2020 9:19 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

Too many quotes and post to justify that 10Gb router + 40Gb switching is a "must have" for home users.
by BartoszP
Sun Feb 23, 2020 2:16 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

I did not ask for 10Gbps routing. Some people will eventually need 10Gbps routing. Really? English is not my native language but I try to understand what I read and answer to I am not saying 10G routing is budget. 10G switching is. But when you see the 4011 would be capable of asymmetric 6Gbps it i...
by BartoszP
Sun Feb 23, 2020 1:20 am
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

You freely mix differents things. You ask for 10Gb switching, for 40Gb switching to connect "proper" 40Gb NAS, for 6 or 10GB router based on 4011,.... Adding 10Gb switch just for pure switching with no rules/filtering at bridge level is not even close to providing enough resources to do 10Gb routing.
by BartoszP
Fri Feb 21, 2020 1:46 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

Did I ?

Just saying that there is no sense to push the limits just for show off.
It is like buying the Bugatti Veyron just for it's 1300 Hp and then cruising your urban area @ 30Mph.
by BartoszP
Fri Feb 21, 2020 10:34 am
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

The assumption of your disccusion is that faster is better than stable.
by BartoszP
Tue Feb 18, 2020 6:19 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

10G would be a budget router. A proper home NAS should be 40G now. It depends who you are. Most people could live with 100mb just for Netlix, YouTube or Spotify. If you are a gamer ar IT nerd then yes ... more than 1Gb could fit your needs but is not a "must have". Your theory is that each should b...
by BartoszP
Sun Feb 16, 2020 8:02 pm
Forum: General
Topic: No more than 160 Mbps in a 600 Mbps with RouterBOARD 2011UiAS-2HnD
Replies: 6
Views: 1731

Re: No more than 160 Mbps in a 600 Mbps with RouterBOARD 2011UiAS-2HnD

A. Edit the first post end delete this 2 meters long quote :-)

B. You need a better router. My 2011 also gives no more than your one with 600 Mb FTTH
by BartoszP
Sun Feb 16, 2020 7:56 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

@vortex:

Never ending story .... why do you quote the WHOLE previous post? What for? Deas it emphasise your answer more?
Do you know what "post reply" button is for?
Seems that most of us could follow the discussion flow without such quotes. We are able to read provious posts.
by BartoszP
Sun Feb 16, 2020 9:13 am
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

@rooted:

Never ending story .... why do you quote the WHOLE previous post? What for? Deas it emphasise your answer more?
Do you know what "post reply" button is for?
by BartoszP
Sat Feb 15, 2020 12:45 pm
Forum: Beginner Basics
Topic: RB1100Hx2 basic setup
Replies: 9
Views: 2566

Re: RB1100Hx2 basic setup

@PTPStudio:
Why do you quote whole previous post? Does it makes your answer more valuable? Do you see "Post replay" button?
by BartoszP
Tue Feb 11, 2020 11:46 pm
Forum: RouterBOARD hardware
Topic: multigigabit desktop router
Replies: 113
Views: 16586

Re: multigigabit desktop router

.... Not when you are downloading 50GB games. A. Are you sure that source is able to deliver data with 10Gbs? B. ISPs always oversell bandwith so I'm not shure if they are able to deliver constant multi 10GB traffic to users. Edge routers will limit their throughput. C. 5 sec vs 50 sec for 50GB dow...
by BartoszP
Mon Feb 10, 2020 6:26 pm
Forum: Announcements
Topic: Winbox v3.21 released!
Replies: 55
Views: 14612

Re: Winbox v3.21 released!

@Sib:

"It allows ..." does not mean that it should be full ASCII editor.
Is it possible now to make such a piece of art? Yes or no?
As I wrote ... use any editor to prepare your logo and just paste it into a note.
by BartoszP
Sun Feb 09, 2020 7:20 pm
Forum: General
Topic: Question before purchasing RouterOS [SOLVED]
Replies: 3
Views: 1222

Re: Question before purchasing RouterOS [SOLVED]

3,4) RouterOS is known to not support everything. If you want to be sure, download CD image and try to install it. It will run without any limits for 24 hours. Or there's free L1 license, it works forever, but has some stuff limited.
Just test CHR https://wiki.mikrotik.com/wiki/Manual:CHR
by BartoszP
Fri Feb 07, 2020 9:45 pm
Forum: Announcements
Topic: Winbox v3.21 released!
Replies: 55
Views: 14612

Re: Winbox v3.21 released!

What about designing your logo in notepad or any other text editor and copy+paste into Note?
No one except admin is able to contemplate this logo as a Note :-)
by BartoszP
Wed Feb 05, 2020 11:12 pm
Forum: General
Topic: CVE-2019-3981
Replies: 8
Views: 1183

Re: CVE-2019-3981

@Bartoz - Why would you infer that the issue only refers to 6.43 unless you can prove that the issue raised in the CVE was covered in the firmware upgrade notes of subsequent Versions. In other words, you know it has been and thus a link or quote or post referring to that would be helpful. Or, you ...
by BartoszP
Wed Feb 05, 2020 10:12 am
Forum: General
Topic: CVE-2019-3981
Replies: 8
Views: 1183

Re: CVE-2019-3981

What are the current versions of ROS?
This CPE is about versions 6.42 which are obsolete since 2018 ...
by BartoszP
Fri Jan 24, 2020 5:30 pm
Forum: General
Topic: What is the solution of whole update Mikrotik without Not enough disk space?
Replies: 35
Views: 3490

Re: What is the solution of whole update Mikrotik without Not enough disk space?

....
And of course you must be able to reach internet from the device. So in Tools->Ping try to ping 8.8.8.8. That must work. When not, fix it first.
(check IP->Routes etc)
It is much better to check ping mikrotik.com as it checks not only Internet access but also a DNS resolver.
by BartoszP
Wed Jan 22, 2020 6:25 pm
Forum: General
Topic: My public IP is getting raped by port scanners - is that normal?
Replies: 24
Views: 3590

Re: My public IP is getting raped by port scanners - is that normal?

Vectra is the Polish CableTV operator. From log we can see that something behind this static address tries to connect to address 155.x.y.x port 52676 For me it is not Qnap the source as it is just accessible with the redirection at the same address from the "attack" comes from. I suspect that there ...
by BartoszP
Fri Jan 17, 2020 7:37 pm
Forum: Scripting
Topic: Update after....two days
Replies: 5
Views: 1986

Re: Update after....two days

by BartoszP
Fri Jan 17, 2020 9:41 am
Forum: Scripting
Topic: Update after....two days
Replies: 5
Views: 1986

Re: Update after....two days

Use Scheduler to schedule when your script runs.

https://lmgtfy.com/?q=mikrotik+script+schedule
by BartoszP
Tue Jan 14, 2020 3:18 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 116248

Re: v6.47beta [testing] is released!

@irqhost: why do you quoute whole post? Isn't it enough just to ask a question in this thread?
by BartoszP
Mon Jan 13, 2020 7:53 am
Forum: General
Topic: Locked myself out of WinBox - Help Requested
Replies: 7
Views: 1368

Re: Locked myself out of WinBox - Help Requested

If you disabled port then nothing could help.
If other ports are not disabled then use WinBox in MAC mode and try to access your router.
by BartoszP
Sun Jan 05, 2020 2:23 pm
Forum: General
Topic: Winbox Shortcuts Keys
Replies: 4
Views: 1280

Re: Winbox Shortcuts Keys

by BartoszP
Fri Jan 03, 2020 6:12 pm
Forum: General
Topic: firewall vs nat packet flow
Replies: 8
Views: 1521

Re: firewall vs nat packet flow

A. "RAW" part of firewal inspects packets which enter firewall or leave it but are originated by router: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Raw B. NAT is done before routing and firewal so you have inspect proper addresses in firewall rules e.g if you DST-NATted packet to internal dev...
by BartoszP
Thu Jan 02, 2020 4:41 pm
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 871

Re: ipsec established, but gre tunnel not

I doubt that it is a bug. I use GRE-IPSec and IPIP-IPSec ..
by BartoszP
Thu Jan 02, 2020 4:00 pm
Forum: General
Topic: ipsec established, but gre tunnel not
Replies: 6
Views: 871

Re: ipsec established, but gre tunnel not

Have you specified local and remote addresses of GRE on both routers?
Do you allow proper protocols to pass firewall?
by BartoszP
Mon Dec 30, 2019 4:59 pm
Forum: General
Topic: rb2011uias-rm ram upgrade
Replies: 1
Views: 445

Re: rb2011uias-rm ram upgrade

I doubt.

Look for 3011 or 4011 instead.
by BartoszP
Mon Dec 30, 2019 3:55 pm
Forum: Beginner Basics
Topic: how many client can connect to my router [SOLVED]
Replies: 6
Views: 1638

Re: how many client can connect to my router [SOLVED]

Simply ... you ask a question: Will my planned restaurant 100 sqm size be big enough to serve all clients? No info of of place where this restaurant is planned? What food do you want to sell? When it will be open? How many tables do you plan? How many chairs or benches do you plan? Will you offer ta...
by BartoszP
Mon Dec 30, 2019 10:27 am
Forum: Beginner Basics
Topic: how many client can connect to my router [SOLVED]
Replies: 6
Views: 1638

Re: how many client can connect to my router [SOLVED]

The answer is easy ... as many as you wish if only they do not use functions which are limited by license:
Read this: https://wiki.mikrotik.com/wiki/Manual:License

The question is ... does this router is powerfull enough to serve all connected clients?
by BartoszP
Thu Dec 26, 2019 1:14 pm
Forum: Beginner Basics
Topic: New router config problem - no LAN to WAN trafic
Replies: 7
Views: 1518

Re: New router config problem - no LAN to WAN trafic

Possibly ISP side was not configured properly on time and that's why it works now.
by BartoszP
Tue Dec 17, 2019 4:47 pm
Forum: General
Topic: RB2011UiAS-RM slow throughput
Replies: 2
Views: 801

Re: RB2011UiAS-RM slow throughput

Last week 2011L tested as PPoE client to ISP. 600/60 bandwith.

Maximum throughput received with fasttrack on and one NAT for PPoE was circa 200Mb / 60Mb
by BartoszP
Fri Dec 06, 2019 10:31 am
Forum: Wireless Networking
Topic: Private Area Network for each guest
Replies: 4
Views: 1799

Re: Private Area Network for each guest

VLANS?
by BartoszP
Wed Nov 20, 2019 10:30 pm
Forum: Beginner Basics
Topic: Change the default webfig ip address
Replies: 3
Views: 648

Re: Change the default webfig ip address

Make firewall rule which accepts access to webfig only for particular address.
by BartoszP
Mon Nov 18, 2019 1:24 pm
Forum: General
Topic: Feature request for v7.x
Replies: 273
Views: 70340

Re: Feature request for v7.x

MAC list ...
by BartoszP
Thu Oct 31, 2019 5:19 pm
Forum: RouterOS v7 BETA
Topic: Torrent client
Replies: 40
Views: 13736

Re: Torrent client

Is it a problem for you to download it to your computer or any RPi device ... the cheapest one you can find? Should it be done by a router? Printer Services, SMB, Torrent ... lets add full SMTP server, Backup server, WordPress, Spotify ,Netflix Player ... Do we really need a monster like this? https...
by BartoszP
Thu Oct 24, 2019 5:11 pm
Forum: General
Topic: Conexiones L2TP de clientes
Replies: 1
Views: 397

Re: Conexiones L2TP de clientes

English please. Use any translator you want. It is English based forum.
by BartoszP
Sun Oct 06, 2019 8:36 am
Forum: General
Topic: Is MikrotikOS good enough to support two networks independent of each other? (one needs PPPoE)
Replies: 41
Views: 6549

Re: Is MikrotikOS good enough to support two networks independent of each other? (one needs PPPoE)

The question is if you are able to make PPPoE connection from "internal" router to receive public address if there is no Mikrotik "in the middle"?
What do Mikrotik should do in your opinion?
by BartoszP
Tue Oct 01, 2019 6:59 pm
Forum: General
Topic: ROS updates to be put on homepage?
Replies: 4
Views: 897

Re: ROS updates to be put on homepage?

@upower3

Is it a problem to pin https://mikrotik.com/download url to the tab in your favourite browser and open it with one click?
by BartoszP
Tue Sep 24, 2019 9:00 am
Forum: General
Topic: Audience Tri-band mesh
Replies: 14
Views: 2839

Re: Audience Tri-band mesh

Checito

You should assume that most readers are skilled enough to stick with the flow of consecuitive posts.
If you want to comment something what was mentioned a few posts earlier then quote only the crucial part of that post.
by BartoszP
Mon Sep 23, 2019 10:03 pm
Forum: RouterBOARD hardware
Topic: Recover from "No Default Configuration" System Reset
Replies: 17
Views: 3027

Re: Recover from "No Default Configuration" System Reset

Why not to use Winbox with MAC address?
by BartoszP
Mon Sep 23, 2019 8:58 pm
Forum: General
Topic: Audience Tri-band mesh
Replies: 14
Views: 2839

Re: Audience Tri-band mesh

Chechito,
Could you please do not quote full previous posts in your answers if there is no need for that.
Just use big button "Post replay"
by BartoszP
Mon Sep 23, 2019 1:22 pm
Forum: RouterBOARD hardware
Topic: Recover from "No Default Configuration" System Reset
Replies: 17
Views: 3027

Re: Recover from "No Default Configuration" System Reset

Zacharias,

Could you please do not quote full previous posts in your answers if there is no need for that.
Just use big button "Post replay"
by BartoszP
Fri Sep 20, 2019 6:06 pm
Forum: Announcements
Topic: v6.45.6 [stable] is released!
Replies: 59
Views: 39599

Re: v6.45.6 [stable] is released!

MikroTik
Certified
Network
Anesthesiologist

will bring your router back to life :lol: :lol: :lol: :lol:
by BartoszP
Fri Sep 20, 2019 6:00 pm
Forum: Scripting
Topic: Hello, everyone, my ROS is far away, the power of ROS is cut off by the bad guys. I want to add a script to detect ROS
Replies: 6
Views: 2515

Re: Hello, everyone, my ROS is far away, the power of ROS is cut off by the bad guys. I want to add a script to detect R

Run such script when rebooted # :local loctoemail "destination@address.com" # :local locident [/system identity get name] :local locmachine [/system resource get architecture-name] :local locversion [/system resource get version] :local loctime [/system clock get time] :local locdate [/system clock ...
by BartoszP
Fri Sep 20, 2019 11:58 am
Forum: Announcements
Topic: v6.45.6 [stable] is released!
Replies: 59
Views: 39599

Re: v6.45.6 [stable] is released!

It's more like coma after surgery as router is still alive :-)
by BartoszP
Mon Sep 16, 2019 9:10 am
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 150
Views: 73000

Re: v6.46beta [testing] is released!

Version 6.46beta38 has been released.
......
*) console - fixed IP conversation to "num" data type;
....
Shouldn't it be "conversion"?
by BartoszP
Mon Sep 09, 2019 6:45 pm
Forum: Beginner Basics
Topic: Unable to ping/trace from lan
Replies: 7
Views: 1082

Re: Unable to ping/trace from lan

Show configuration of your router.
I suspect that you have assigned 8.8.8.8 address to interface in your router.
by BartoszP
Wed Aug 07, 2019 12:22 am
Forum: Wireless Networking
Topic: 802.11ax [SOLVED]
Replies: 123
Views: 38150

Re: 802.11ax [SOLVED]

How to educate other users if you do not set a good example? Laziness is not a good excuse.
by BartoszP
Wed Aug 07, 2019 12:00 am
Forum: Wireless Networking
Topic: 802.11ax [SOLVED]
Replies: 123
Views: 38150

Re: 802.11ax [SOLVED]

!ste:

Is it necessary to quote FULL previous post?
by BartoszP
Thu Aug 01, 2019 2:35 pm
Forum: Beginner Basics
Topic: Small MikroTik, Big MikroTik
Replies: 2
Views: 652

Re: Small MikroTik, Big MikroTik

Yes,

"Bigger" devices usually have "higher" licenses what is described there: https://wiki.mikrotik.com/wiki/Manual:L ... nse_Levels
by BartoszP
Fri Jul 12, 2019 9:52 pm
Forum: Beginner Basics
Topic: RouterOS v6.41.4 access to admin panel -password problem [SOLVED]
Replies: 9
Views: 1880

Re: RouterOS v6.41.4 access to admin panel -password problem [SOLVED]

Why do you think that Mikrtik's forum is proper place to ask about problems with Tenda router?
by BartoszP
Fri Jul 12, 2019 5:12 pm
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 100
Views: 48606

Re: v6.44.5 [long-term] is released!

Was it "Upgrading on the edge" by Aerosmith? :-)

Jump from 6.40 directly to 6.45 .... you are brave man. Have you read changelogs in the 6.41?
by BartoszP
Sun Jul 07, 2019 11:41 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 2638

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

anav: maybe my toilet paper has just more layers than your? BTW.... If you want to protect computers on one bridge at L3 from another L3 layer then you need to block bridge A pool (name it poolA) from poolB, poolC, poolD ... poolC protect form poolD but not from poolE .... poolF from poolA, poolB bu...
by BartoszP
Sun Jul 07, 2019 5:35 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 2638

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

@anav:

Nets at L2 may be separated but routing at L3 works and OP asks how to prevent IP access.

@OP:
what about using filters at bridge level? Antything what is forwarded to other interface than WAN should be dropped.
by BartoszP
Sun Jul 07, 2019 3:24 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 2638

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

How you add Port1 to four different bridges?
by BartoszP
Tue Jun 11, 2019 7:05 pm
Forum: Beginner Basics
Topic: Block acces to a New router
Replies: 2
Views: 660

Re: Block acces to a New router

Do you connect any interfaces to this bridge?
by BartoszP
Tue Jun 11, 2019 5:54 pm
Forum: General
Topic: Implementing a Blacklist [SOLVED]
Replies: 2
Views: 728

Re: Implementing a Blacklist [SOLVED]

My simple solution: /ip service set winbox port=18291 /interface list add name=WAN_LIST /interface list member add interface=ETH1-WAN list=WAN_LIST /ip firewall raw # # accept packets to nonstandard WinBox port ... could be tailored for access from particular subnets etc. # add action=accept chain=p...
by BartoszP
Mon Jun 03, 2019 8:01 pm
Forum: RouterBOARD hardware
Topic: hAP ac bricked
Replies: 5
Views: 2490

Re: hAP ac bricked

My old 0.02$ to this topic: viewtopic.php?f=1&t=93307&p=490460#p490402
by BartoszP
Wed May 22, 2019 5:26 pm
Forum: RouterBOARD hardware
Topic: RB 450GX4 add a FAN
Replies: 2
Views: 780

Re: RB 450GX4 add a FAN

Directly from power socket if you use 24V PSU?
by BartoszP
Sat May 04, 2019 8:09 pm
Forum: Useful user articles
Topic: How to opitimize list of IP4 addresses
Replies: 7
Views: 4205

Re: How to opitimize list of IP4 addresses

Thank you for the report.
It is example of situation when one subnet is fully included in another. I do not look for such optimization ... yet :)
IMHO it is not "a bug" .. output is fully valid however not optimized to "deep roots".
by BartoszP
Thu May 02, 2019 11:43 pm
Forum: Useful user articles
Topic: How to opitimize list of IP4 addresses
Replies: 7
Views: 4205

How to opitimize list of IP4 addresses

I was thinking how to optimize big IP lists before importing them to Mikrotik. It ended as this program. Feel free to use it. Comments welcome. Written with GNU Linux and gcc. Standard usage ... takes data from stdin and outputs to stdout Program tries to merge consecutive IP addresses or IP ranges....
by BartoszP
Sat Apr 27, 2019 2:45 pm
Forum: RouterBOARD hardware
Topic: Hardware repair RB711-5Hn-MMCX
Replies: 3
Views: 909

Re: Hardware repair RB711-5Hn-MMCX

@tayroborges:

English please !
by BartoszP
Fri Apr 26, 2019 4:25 pm
Forum: General
Topic: RB1100AHx4 Dude Edition insecure by default
Replies: 11
Views: 1465

Re: RB1100AHx4 Dude Edition insecure by default

No device calling itself a router should have this as it's fully patched, default configuration out of the box be this: ...... If you want to make excuses for having crappy default configurations that's fine. Mikrotik is the one that is making the reputation for making devices that are part of botn...
by BartoszP
Mon Apr 22, 2019 9:05 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93383

Re: v6.45beta [testing] is released!

After upgrade of CRS125 it stopped to be visible in a neigherhood and for WinBox.
by BartoszP
Mon Apr 22, 2019 9:02 am
Forum: Beginner Basics
Topic: CHAPTER 2, Basic configuration: username, identity, NTP, Monitoring, Maintenance
Replies: 1
Views: 440

Re: CHAPTER 2, Basic configuration: username, identity, NTP, Monitoring, Maintenance

Tony:

Once more ... please do not start so many threads. Make one and please stick with it.
by BartoszP
Thu Apr 11, 2019 8:32 am
Forum: Beginner Basics
Topic: CHAPTER 2, Basic Configuration, Interface Configuration
Replies: 3
Views: 714

Re: CHAPTER 2, Basic Configuration, Interface Configuration

Isn't it better to make one topic instead of starting several ones?
by BartoszP
Sun Mar 17, 2019 9:38 am
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 25979

Re: v6.44.1 [stable] is released!

After upgrade to 6.44.1 on RB962 GRE+IPSec stopped working when connected to 6.44 on the other side. After downgrade to 6.44 back on-line.
by BartoszP
Sun Mar 17, 2019 12:34 am
Forum: Beginner Basics
Topic: Locked out badly
Replies: 3
Views: 673

Re: Locked out badly

What about logging with WinBox via MACaddress?
by BartoszP
Fri Mar 15, 2019 8:56 pm
Forum: General
Topic: RB4011iGS+ admin password issue
Replies: 3
Views: 609

Re: RB4011iGS+ admin password issue

Resseting configuration should not be allowed without setting password as integral part of this process.
by BartoszP
Fri Mar 15, 2019 3:08 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 54928

Re: Statement on Vault 7 document release

You are using the wrong symbol to explain to IT people, should use "!=" instead, then they will better understand :-)
For some "<>" should be used :)
by BartoszP
Tue Mar 12, 2019 4:25 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 110335

Re: Winbox vulnerability: please upgrade

It is always safer to netinstall as it formats device.
by BartoszP
Mon Mar 11, 2019 11:02 am
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93383

Re: v6.45beta [testing] is released!

*) e-mail - fixed missing "from" address for sent e-mails (introduced in v6.44);
Emils

I'm interested how did it happen? What someone had been messing for with e-mail part of ROS?
by BartoszP
Thu Mar 07, 2019 5:06 pm
Forum: General
Topic: RB4011 real world speed tests
Replies: 12
Views: 3483

Re: RB4011 real world speed tests

"Expected more" means 23+ Gb sustained transmission with 190$ device?
by BartoszP
Wed Mar 06, 2019 12:49 pm
Forum: General
Topic: Radical change coming for home and small business networking
Replies: 53
Views: 7186

Re: Radical change coming for home and small business networking

No. It's not old thinking.

My net is my castle. Period.
by BartoszP
Wed Mar 06, 2019 8:33 am
Forum: General
Topic: Radical change coming for home and small business networking
Replies: 53
Views: 7186

Re: Radical change coming for home and small business networking

Xymox,

Be responsible ISP/IT company and inform your customers that someone tries to take over their security.

Inform them about pros and cons and explain why you prefer not to jump into that train.

Easy.
by BartoszP
Mon Mar 04, 2019 12:38 am
Forum: General
Topic: Radical change coming for home and small business networking
Replies: 53
Views: 7186

Re: Radical change coming for home and small buisness networking

Hmmm.... I watched this video and what comes to my eyes is "security manager will configure customers' micornets to be safe/secure etc...." or sth like that ...
Who the ..... is Alice ... opssss ... security manager?
by BartoszP
Wed Feb 27, 2019 5:52 pm
Forum: General
Topic: Hardware Selection
Replies: 14
Views: 1731

Re: Hardware Selection

Keeping up with the Simpsons ... let me decide :-)
by BartoszP
Wed Feb 27, 2019 4:21 pm
Forum: General
Topic: Hardware Selection
Replies: 14
Views: 1731

Re: Hardware Selection

Frankly speaking: Bartosz ... "sz" pronounced as "sh" in "wash" :lol:
by BartoszP
Wed Feb 27, 2019 4:08 pm
Forum: General
Topic: routerOS blocks various surveillance cloud adresses
Replies: 2
Views: 481

Re: routerOS blocks various surveillance cloud adresses

How your PC reaches camera?

WAN -> LAN? Is it OK?
LAN -> LAN? OK or not? Look for Harpin NAT.
LAN -> WAN? OK?
by BartoszP
Wed Feb 27, 2019 2:38 pm
Forum: General
Topic: Hardware Selection
Replies: 14
Views: 1731

Re: Hardware Selection

CRS are switches not routers. Thay can do routing but they are not designed for routing/natting/mangling heavy traffic. You should look for CCR devices if you want to mostly route or start with AH1100x4 ones. I have installation with AH1100x4 for 50+ users, VPN+IPSec used to access main office share...
by BartoszP
Wed Feb 27, 2019 12:44 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 48544

Re: v6.44 [stable] is released!

Strange ... IPSec works for me :-) after upgrade 6.43.12 -> 6.44

IPSeced IPIP and GRE tunnels work smooth after upgrade, self-reconnected without problems. Comments still in place.
by BartoszP
Fri Feb 22, 2019 9:48 pm
Forum: General
Topic: Problem on 6.37.5 version
Replies: 5
Views: 1042

Re: Problem on 6.37.5 version

Do you really use these public IPs in your configuration?
by BartoszP
Mon Feb 18, 2019 5:48 pm
Forum: Beginner Basics
Topic: How do I get a question moderated??
Replies: 2
Views: 539

Re: How do I get a question moderated??

Be patient. Most of moderators are volunteers so it takes some time to be moderated.
by BartoszP
Fri Feb 15, 2019 3:44 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 44
Views: 20290

Re: DHCP Offering Lease Without Success

Suspecting that DHCP server mostly warns

A. when device try to renew address when lease is still valid and full DHCP REQUEST-ACK-CONFIRM process is not done
or
B. ROS sees that device is "vanishing" ... I see it in logs when CAPSMAN moves device from one AP or interface to another.
by BartoszP
Fri Feb 15, 2019 12:59 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 44
Views: 20290

Re: DHCP Offering Lease Without Success

Does not help ... no change .. still receiving warnings
by BartoszP
Thu Feb 14, 2019 2:02 pm
Forum: General
Topic: Guide to (possibly) hack RouterOS ... If yes please protect it
Replies: 10
Views: 2504

Re: Guide to (possibly) hack RouterOS ... If yes please protect it

Most users who start threads "Mikrotik hacked...", "My router is unsecured", "Big hole in security of ..." seems to not check forum for security topics Did you try easiest method to look for security problems: https://forum.mikrotik.com/search.php?keywords=vulnerability https://forum.mikrotik.com/se...
by BartoszP
Wed Feb 13, 2019 5:53 pm
Forum: General
Topic: how to see "(2265 messages not shown)"?
Replies: 2
Views: 676

Re: how to see "(2265 messages not shown)"?

If I recall correctly it means that there is NNNN exactly the same consequent messages in the log.
by BartoszP
Wed Feb 13, 2019 5:48 pm
Forum: General
Topic: Config Review - Security Conscience Home User
Replies: 19
Views: 2081

Re: Config Review - Security Conscience Home User

It is my way of "drop it ASAP" 0. if attacker scans us again (is already on the list) then drop it right now. A. check if unwanted port is checked. B. if yes, add attacker to the ban list C. drop all packets coming from attacker list /ip firewall raw add action=accept chain=prerouting dst-port=porto...
by BartoszP
Wed Feb 13, 2019 4:43 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 262457

Re: Feature requests

It would be convinient to CAPSAM and DHCP to log to log not only MAC address but also HOSTNAME if it is known.
Process of transforming MAC 2 HOST is tedious and if log changes quickly you have no chance to check who is associating/dhcping
by BartoszP
Mon Feb 11, 2019 5:34 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 44
Views: 20290

Re: DHCP Offering Lease Without Success

Uncheck ...
"Always send replies as broadcasts even if destination IP is known. Will add additional load on L2 network."
DHCP broadcast an offer even if device is just deassigned.
by BartoszP
Mon Feb 11, 2019 4:31 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 44
Views: 20290

Re: DHCP Offering Lease Without Success

For me the problem is with static addresses and seems to be connected with this option which sends offer even if there is no demand for it. Converting dynamic address to static makes this option somehow "checked" even DHCP server has it "unchecked" so if you forgot to uncheck then static reservation...
by BartoszP
Thu Jan 31, 2019 2:43 am
Forum: General
Topic: How to migrate RB3011 to CCR1009
Replies: 4
Views: 695

Re: How to migrate RB3011 to CCR1009

Before import rename all interfaces in 1009 to names used in 3011. It will make import much easier.
by BartoszP
Tue Jan 29, 2019 9:30 pm
Forum: Beginner Basics
Topic: DNS server behaviour
Replies: 5
Views: 838

Re: DNS server behaviour

/ip firewall filter
add action=drop chain=input comment=WAN->DNS dst-port=53 in-interface=YOURWAN protocol=udp
by BartoszP
Wed Jan 23, 2019 8:59 pm
Forum: Beginner Basics
Topic: Como usa a RBGrooveA-52HPn simultâneo
Replies: 2
Views: 566

Re: Como usa a RBGrooveA-52HPn simultâneo

Please edit your post and use English
by BartoszP
Tue Jan 22, 2019 5:06 pm
Forum: General
Topic: 6.43.8 vulnerability or hack?
Replies: 31
Views: 9878

Re: 6.43.8 vulnerability or hack?

Anav ... should mrz explain again and again and step by step what to do when you are hacked or could expect that autor is aware of https://blog.mikrotik.com/
by BartoszP
Sun Jan 20, 2019 5:36 pm
Forum: General
Topic: how many users can use different models of routers ?
Replies: 1
Views: 461

Re: how many users can use different models of routers ?

Users of what service?
by BartoszP
Fri Jan 11, 2019 5:17 pm
Forum: General
Topic: Misterious Ethernet problem
Replies: 13
Views: 1709

Re: Misterious Ethernet problem

IMHO it could be problem of STP/RSTP protocol. Switch it off and see what will happen.
by BartoszP
Thu Jan 10, 2019 10:34 am
Forum: General
Topic: Spam filtering - how to improve my antispam system
Replies: 9
Views: 2062

Re: Spam filtering - how to improve my antispam system

I use N++ with it's regular expression search+replace/replace all option.
by BartoszP
Wed Jan 09, 2019 8:14 pm
Forum: General
Topic: Spam filtering - how to improve my antispam system
Replies: 9
Views: 2062

Re: Spam filtering - how to improve my antispam system

@anav: Barracuda ESG does good job .. it filters most of spam from China ... most means 99% ... but I was tired skipping whole pages of "dropped/blocked" entries and decided to not allow such e-mails to reach ESG @Xtreamer: Please check attachment. It is part of a bigger set of rules so you must to ...
by BartoszP
Mon Jan 07, 2019 11:59 pm
Forum: General
Topic: Interface ether accidently removed and I am disconnected.
Replies: 9
Views: 1046

Re: Interface ether accidently removed and I am disconnected.

How did you remove ethernet interface from router? Physically? Then I doubt if you can connect to your router :-)
Do you have more eth interfaces? What router it is? Configuration?
by BartoszP
Mon Jan 07, 2019 10:35 am
Forum: General
Topic: Spam filtering - how to improve my antispam system
Replies: 9
Views: 2062

Re: Spam filtering - how to improve my antispam system

Almost 24 hours later

Edit ... blocked at RAW firewall level
Chiny4.PNG
by BartoszP
Sun Jan 06, 2019 10:40 pm
Forum: General
Topic: Spam filtering - how to improve my antispam system
Replies: 9
Views: 2062

Spam filtering - how to improve my antispam system

Hi, I use Barracuda Spam Filter (Barracude ESG) as my spam-firewall for one of my customers. It does good job but one of their e-mail's was used for communication with China based client. Since then we receive hundreds spam e-mails per day only for this used e-mail. We do not receive e-mails to admi...
by BartoszP
Wed Jan 02, 2019 7:16 pm
Forum: General
Topic: Hacked Board
Replies: 15
Views: 2450

Re: Hacked Board

Do you use same "paranoic" :D rules for LAN as for WAN side?
by BartoszP
Tue Jan 01, 2019 3:45 pm
Forum: Wireless Networking
Topic: Radar detected on XXX
Replies: 31
Views: 5809

Re: Radar detected on XXX

@n21roadie ... could you please stop full quoting all posts you are commenting. Use "Post replay" instead of "quoting" post.
by BartoszP
Mon Dec 31, 2018 3:42 pm
Forum: General
Topic: under attack in port 32231? - help
Replies: 25
Views: 2577

Re: under attack in port 32231? - help

Yes.
You don't need
...dst-port=!8291,22 ...
You accept it earlier so packets to 8291 and 22 do not even reach this drop rule.
I suggest to change 8291 port to other port in you configuration for winbox access.
by BartoszP
Mon Dec 31, 2018 1:37 pm
Forum: General
Topic: under attack in port 32231? - help
Replies: 25
Views: 2577

Re: under attack in port 32231? - help

Yes.

If you want to protect your castle then you build THE WALL which stops all at the gate and then allow to go inside only allowed persons/goods/packets. It is far far easier then allow all to enter and spy them for "bad guys". :D :D :D
by BartoszP
Fri Dec 28, 2018 11:11 am
Forum: The User Manager
Topic: user manager database is corrupted everyday
Replies: 4
Views: 2196

Re: user manager database is corrupted everyday

More details please.
by BartoszP
Fri Dec 28, 2018 8:47 am
Forum: General
Topic: Post Very good ... Thank you for that.
Replies: 3
Views: 664

Re: Post Very good ... Thank you for that.

Done ... just warned as previous posts were quite "normal"
by BartoszP
Thu Dec 27, 2018 11:13 am
Forum: General
Topic: After updating RouterOS to version 6.43.7, part of computers in the LAN can't ping each other.Is there the problem with
Replies: 3
Views: 697

Re: After updating RouterOS to version 6.43.7, part of computers in the LAN can't ping each other.Is there the problem w

General answer is: No.

More details please. Configuration, topology, version upgraded from ... we aren't wizards guessing from tea leaves
by BartoszP
Thu Dec 27, 2018 11:09 am
Forum: General
Topic: RB2011 dont upgrade
Replies: 1
Views: 397

Re: RB2011 dont upgrade

Maybe you are victim of viewtopic.php?f=21&t=140165
by BartoszP
Sun Dec 23, 2018 3:15 pm
Forum: General
Topic: PPPoE client help needed
Replies: 3
Views: 755

Re: PPPoE client help needed

L'italiano è una bella lingua but please use English :D
by BartoszP
Fri Dec 21, 2018 2:23 pm
Forum: General
Topic: securize network
Replies: 1
Views: 379

Re: securize network

Yes.
by BartoszP
Tue Dec 11, 2018 2:36 am
Forum: RouterBOARD hardware
Topic: hardware idea for a multiport switch
Replies: 59
Views: 25023

Re: hardware idea for a multiport switch

I...Maybe make an expander module that can be mounted on the front or back of the rack, via a fiber optic cable and connected power back to the switch. Would make it easy to have a top of rack back and front switch ports....
Just PoE powering. No need for next PSU.
by BartoszP
Mon Dec 10, 2018 6:06 pm
Forum: RouterBOARD hardware
Topic: hardware idea for a multiport switch
Replies: 59
Views: 25023

Re: hardware idea for a multiport switch

Do you imagine this FAT-FAT-FAT cable boundle which you try to move to slide out/in a switch? How to organize them to ease slide device out and not to have big gnarl when slided in? How to protect cables against braking down RJ45 connectors? How many empty Us above device needed to organize cables? ...
by BartoszP
Sun Dec 02, 2018 5:15 pm
Forum: General
Topic: process called system send data to ip pptp server
Replies: 3
Views: 569

Re: process called system send data to ip pptp server

How your ptoblem is connected to Mikrotik?
by BartoszP
Mon Nov 19, 2018 5:02 pm
Forum: Beginner Basics
Topic: plan-B
Replies: 5
Views: 741

Re: plan-B

Safe mode is good solution but having Plan-B is even better if you commit "safe" configuration.
by BartoszP
Wed Nov 14, 2018 1:42 pm
Forum: Beginner Basics
Topic: Am I hacked?
Replies: 2
Views: 978

Re: Am I hacked?

Start with:
/interface list
add name=WAN_LIST
/interface list member
add interface=YouRWANInterface list=WAN_LIST
/ip firewall raw
add action=drop chain=prerouting dst-port=53 in-interface-list=WAN_LIST log-prefix=UDP53ALL protocol=udp
by BartoszP
Thu Nov 08, 2018 1:03 pm
Forum: Forwarding Protocols
Topic: Forward and redirect port [SOLVED]
Replies: 3
Views: 2634

Re: Forward and redirect port [SOLVED]

Read this: viewtopic.php?f=2&t=102483&p=508981&hil ... IC#p508981

Why do you use public IPs in internal network?
by BartoszP
Sun Oct 28, 2018 8:19 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 84
Views: 41432

Re: URGENT security reminder

Why to waste time? Netinstall and import configuration via script if you have one.
by BartoszP
Sun Oct 28, 2018 7:26 pm
Forum: RouterBOARD hardware
Topic: X86 restart.
Replies: 2
Views: 770

Re: X86 restart.

Why do you use x86? Isn't it better to buy Mikrotik device like https://mikrotik.com/product/RB750Gr3
by BartoszP
Sun Oct 28, 2018 11:37 am
Forum: Beginner Basics
Topic: same ip for multi interfaces
Replies: 4
Views: 1089

Re: same ip for multi interfaces

A. Do bridge both interfaces and then filter traffic between interfaces.
or
B. Divide 192.168.2.0/24 subnet to two 192.168.2.0/25 subnets for each interface and then filter traffic
by BartoszP
Thu Oct 25, 2018 6:43 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 90745

Re: VPNfilter official statement

More impressive statisctic for 42 days of up-time.
RAW2 registers IPs which "revisist" router and are still registered with RAW1 rule.
Firewall.PNG
by BartoszP
Wed Oct 24, 2018 4:07 pm
Forum: RouterBOARD hardware
Topic: MUM Europe 2018 - New hardware incoming
Replies: 52
Views: 20297

Re: MUM Europe 2018 - New hardware incoming

Micron Enterprise SSD 9200 MAX 6.4TB NVMe U.2 3 500$ gross
by BartoszP
Wed Oct 24, 2018 3:47 pm
Forum: RouterBOARD hardware
Topic: MUM Europe 2018 - New hardware incoming
Replies: 52
Views: 20297

Re: MUM Europe 2018 - New hardware incoming

Let's check ... the generic example I've found in Poland: SSD Crucial MX500 500GB for 100$ is too expensive?
by BartoszP
Fri Oct 19, 2018 10:22 am
Forum: General
Topic: Mejor opcion de MIKROTIK para 3000 abonados
Replies: 7
Views: 1468

Re: Mejor opcion de MIKROTIK para 3000 abonados

A. What if forum moderators hardly speak Spanish? Should we accept post in eg. Katakana or Hindi or Hebrew alphabets? B. Moderators do "complain" about non English posts. C. If English is not your "best friend" then you can always use translator or write/ask on non English forum. D. This forum has s...
by BartoszP
Thu Oct 18, 2018 6:38 pm
Forum: Beginner Basics
Topic: no internet after IP changed
Replies: 6
Views: 946

Re: no internet after IP changed

What are NAT rules and Firewall?
Connections shows that there is some traffic from LAN to WAN ... do you have DNS properly configured?
by BartoszP
Thu Oct 18, 2018 6:07 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 90745

Re: VPNfilter official statement

It is log for 25 days since reboot so this router drops circa 15k connections per day. Most of them are for 22,23,8291 ports.
MM.PNG
by BartoszP
Thu Oct 18, 2018 3:40 pm
Forum: Beginner Basics
Topic: no internet after IP changed
Replies: 6
Views: 946

Re: no internet after IP changed

Have you looked at firewall settings? Do they use 192.168.1.x instead a.b.88.x?
by BartoszP
Wed Oct 17, 2018 6:32 pm
Forum: RouterBOARD hardware
Topic: Cracked cover on RouterBOARD DISC Lite5
Replies: 59
Views: 10197

Re: Cracked cover on RouterBOARD DISC Lite5

Time for "Best before sticker" :-( I have client which sells car components. We wondered why eg. spark plugs have "Best before date" info and "Production date" as there is nothing what could be expected to detoriate when they are waiting on a shelf packed/sealed/protected by manufacturer. Now I know...
by BartoszP
Tue Oct 16, 2018 4:39 pm
Forum: General
Topic: Optimization for crazy-asymetric DOCSIS connection
Replies: 1
Views: 437

Re: Optimization for crazy-asymetric DOCSIS connection

Try to lower MTU for WAN interface.
by BartoszP
Mon Oct 15, 2018 4:51 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 110335

Re: Winbox vulnerability: please upgrade

Have you netinstalled?
by BartoszP
Fri Oct 12, 2018 6:01 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 84
Views: 41432

Re: URGENT security reminder

It was already discussed. Who do call customers? End users or admins? End users? ... most of them do not even know that they have Mikrotik device installed as gateway to Internet. Forget them. Admins? ... real admins reading Mikrotik's site or forum should be/are aware of these problems but the main...
by BartoszP
Fri Oct 12, 2018 5:52 pm
Forum: Beginner Basics
Topic: Router Attack [SOLVED]
Replies: 6
Views: 1377

Re: Router Attack [SOLVED]

Why do you think that it is router problem?
Do you think that js:Miner-AL[pup] is installed in your router?
Are you shure that your computer or any other local one are not infected with js:Miner-AL[pup]?
by BartoszP
Fri Oct 12, 2018 10:26 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 105527

Re: v6.44beta [testing] is released!

Docmarius .. thank you for explanation but what USB U3 has common with ROS? What does he want to beta test with U3?
by BartoszP
Thu Oct 11, 2018 4:25 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 84
Views: 41432

Re: URGENT security reminder

This change makes router more secure as it is not possible to connect to WinBox service with standard port.
by BartoszP
Wed Oct 10, 2018 4:51 pm
Forum: Beginner Basics
Topic: Remote Desktop
Replies: 1
Views: 440

Re: Remote Desktop

You cannot RDP from WAN lan or LOCAL lan?

Read this: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT
by BartoszP
Mon Oct 08, 2018 5:49 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 90745

Re: VPNfilter official statement

Tenable story is different ... they mounted ROS filesystem system to other Linux, made changes to files and then explored RouterOS. You have to have physical access to such system you want to break in. All Linuxes without encrypted filesystem are volunerable ... you can just mount root partition, re...
by BartoszP
Mon Oct 08, 2018 3:28 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 191
Views: 90745

Re: VPNfilter official statement

Congratulations to Tenable !!! They should also send list of affected routers. - it is SARCASM.

IMHO it is totally irresponsible.
by BartoszP
Sun Oct 07, 2018 8:57 am
Forum: General
Topic: My Mikrotik Public IP Has been blacklisted by spamhuas, for the second time!
Replies: 9
Views: 1655

Re: My Mikrotik Public IP Has been blacklisted by spamhuas, for the second time!

You can.

A. You can filter connections for SMTP ports
B. Make Torch buffer time longer than 3 sec.

or

C. Make firewals rules adding src address to SMTPsenders list for PC's starting traffic to any SMTP port
by BartoszP
Sat Oct 06, 2018 7:20 pm
Forum: Beginner Basics
Topic: I broke my network and can't access Webfig. Please help
Replies: 5
Views: 1704

Re: I broke my network and can't access Webfig. Please help

Do not use WebFig ... use Winbox instead. It's proper tool.
by BartoszP
Sat Oct 06, 2018 7:03 pm
Forum: General
Topic: My Mikrotik Public IP Has been blacklisted by spamhuas, for the second time!
Replies: 9
Views: 1655

Re: My Mikrotik Public IP Has been blacklisted by spamhuas, for the second time!

Check computers, servers etc. behind your router if they are sending emails. Just observe connections in the firewall or torch WAN interface.
by BartoszP
Sat Oct 06, 2018 6:39 pm
Forum: General
Topic: My Mikrotik Public IP Has been blacklisted by spamhuas, for the second time!
Replies: 9
Views: 1655

Re: My Mikrotik Public IP Has been blacklisted by spamhuas, for the second time!

disconnect router from Internet
review configuration
export configuration to file
netinstall
set new admin password
add new user with admin privileges
remove admin
import configuration
connect to Internet
by BartoszP
Thu Sep 27, 2018 2:02 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 262457

Re: Feature requests

Please add:

MAC address lists
Port lists in Firewall
by BartoszP
Tue Sep 25, 2018 12:08 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 105527

Re: v6 44beta testing is released

Id like to find out about helping with the Beta test on this...Ive used the big program for many years now, and have been on the Beta list for quite some time. I just started using PE, as Ive changed employers, and my new job wont allow me to install anything on my computer there, but I can use USB...
by BartoszP
Sun Sep 23, 2018 1:50 pm
Forum: General
Topic: I am Not a Robbot
Replies: 17
Views: 1756

Re: I am Not a Robbot

If you configured local LAN as 194.168.1.0/24 instead of 192.168.1.0/24 then DNS name of your gateway is resolved to external name.
You didn't show your configuration so it is just a guess.
by BartoszP
Sun Sep 23, 2018 1:47 pm
Forum: General
Topic: iPhone XS and Mikrotik hAP ac
Replies: 29
Views: 6492

Re: iPhone XS and Mikrotik hAP ac

Try to change channel width.
by BartoszP
Fri Sep 21, 2018 4:48 pm
Forum: RouterBOARD hardware
Topic: RB333
Replies: 3
Views: 886

Re: RB333

The only way is to ask support@mikrotik.com for help.
by BartoszP
Sat Sep 15, 2018 10:14 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 110335

Re: Winbox vulnerability: please upgrade

What do you want to say? Have you example of hacked 6.42.7 or are you just guessing and making noise?
by BartoszP
Fri Sep 14, 2018 5:07 pm
Forum: General
Topic: [ASK] disable PMKID
Replies: 2
Views: 2464

Re: [ASK] disable PMKID

Have you ever tried Serach function ?

search.php?keywords=PMKID+
by BartoszP
Mon Sep 10, 2018 1:13 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 110335

Re: Winbox vulnerability: please upgrade

@msatter: Is it joke or not?
by BartoszP
Fri Sep 07, 2018 2:20 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 88905

Re: RB4011

by BartoszP
Fri Sep 07, 2018 12:18 pm
Forum: Scripting
Topic: wpa to wpa2 clone
Replies: 3
Views: 759

Re: wpa to wpa2 clone

Start from here: https://wiki.mikrotik.com/wiki/Manual:S ... g#Keywords

You need to read WPA2 property with "get". Property is not a traditional variable.
Setting property is also not so simple as you tried .. look here for example viewtopic.php?f=9&t=138893
by BartoszP
Fri Sep 07, 2018 11:45 am
Forum: Beginner Basics
Topic: Winbox keeps disconnecting
Replies: 4
Views: 6315

Re: Winbox keeps disconnecting

Have you tried search function of this forum?

search.php?keywords=Winbox+keeps+disconnecting
by BartoszP
Thu Sep 06, 2018 10:44 pm
Forum: Scripting
Topic: Backup scripts
Replies: 3
Views: 1009

Re: Backup scripts

It seems not to be so hard .... here you are: http://bfy.tw/JlQ6
by BartoszP
Thu Sep 06, 2018 5:32 pm
Forum: General
Topic: License
Replies: 6
Views: 782

Re: License

Do you mean taht you have Mikrotik's ROS x86 installed on this PC? We are not mentalists to know what do you want to say.
by BartoszP
Thu Sep 06, 2018 5:23 pm
Forum: Wireless Networking
Topic: 70 Kms Point 2 Point link
Replies: 18
Views: 3834

Re: 70 Kms Point 2 Point link

IMHO if you do not set then Mikrotik do not know that antenna gains output signal with 24dB and therefore total emitted power of Mikrotik + antenna could not meet regulatory limits.
by BartoszP
Thu Sep 06, 2018 5:18 pm
Forum: Forwarding Protocols
Topic: Ubuntu SSH port forwarding 22
Replies: 3
Views: 919

Re: Ubuntu SSH port forwarding 22

But how your problem is connected with Mikrotik?
by BartoszP
Thu Sep 06, 2018 11:40 am
Forum: General
Topic: Help, Switch over from RB1100AHx2 to RB1100AHx4 not working
Replies: 1
Views: 732

Re: Help, Switch over from RB1100AHx2 to RB1100AHx4 not working

The problem is JUMP form 6.3.1 to 6.42.7

There is FORMIDABLE change in the ROS viewtopic.php?t=128915

Try to downgrade to 6.40.9 bugfix which is the last version which is compatibile with 6.3.x line
by BartoszP
Thu Sep 06, 2018 10:06 am
Forum: General
Topic: Windows 2016 DC requesting lots of IPs from DHCP?
Replies: 6
Views: 900

Re: Windows 2016 DC requesting lots of IPs from DHCP?

Check for loops in your lan ...

EDIT:

... and for proxy-arps which pass packets from one subnet to another and "eat" DHCP IPs.
by BartoszP
Thu Sep 06, 2018 10:01 am
Forum: General
Topic: Capsman download
Replies: 1
Views: 879

Re: Capsman download

CAPSMAN is a fragment of wireless package. Enable this package and you shoul see CAPSMAN menu even if the router has no WiFi interfaces.
by BartoszP
Wed Sep 05, 2018 5:05 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 110335

Re: Winbox vulnerability: please upgrade

... This article respectively the new vulnerability CVE-2018-14847 makes me afraid of using any mikrotik product anymore I have looked here https://tools.cisco.com/security/center/publicationListing.x and I'm wondering who use these products? And you are lucky if you have software upgrade plan acti...
by BartoszP
Tue Sep 04, 2018 7:10 pm
Forum: RouterBOARD hardware
Topic: Need new hardware (8ports and 16ports)
Replies: 29
Views: 2602

Re: Need new hardware (8ports and 16ports)

Have you considered using two HexLites mounted on opposite walls? Just reuse one cable from existing infrastructure and extend it with 3 more cables as needed. OR buy any WHITE & CHEAP 8-port switch, install it and all the logic configure in propper router/switch/device installed outside apartments ...
by BartoszP
Tue Sep 04, 2018 5:46 pm
Forum: RouterBOARD hardware
Topic: Need new hardware (8ports and 16ports)
Replies: 29
Views: 2602

Re: Need new hardware (8ports and 16ports)

Not a problem ... just thinking. A. Why do you need full featured router? B. Isn't switch with 8 ports sufficient ... like this one https://mikrotik.com/product/CRS112-8G-4S-IN C. CRS112 has SFP ports to connect user with FTTH D. Why white is so important? Mayby we need black ones? Nowadays gray is ...
by BartoszP
Tue Sep 04, 2018 4:59 pm
Forum: RouterBOARD hardware
Topic: Need new hardware (8ports and 16ports)
Replies: 29
Views: 2602

Re: Need new hardware (8ports and 16ports)

And one port should be placed on bootom side to be pluggable directly from the wall with 5 cm hidden cable. This port should be PoE In to power device. and ports should be colored to let users easy find one ... I am almost listening to technician saying "look for purple port and connect cable to it ...
by BartoszP
Mon Sep 03, 2018 2:49 pm
Forum: Beginner Basics
Topic: How to hide web interface of router from internet?
Replies: 11
Views: 1181

Re: How to hide web interface of router from internet?

IP/Services /WWW ... set available only from LAN subnet.
by BartoszP
Mon Sep 03, 2018 2:43 am
Forum: Beginner Basics
Topic: Locked Out of Mikrotik
Replies: 29
Views: 5105

Re: Locked Out of Mikrotik

Tested on 962 ... I've inserted it directly to 962 and connected via terminal as described in the manual but when you restart/power-on router then Woobm is restarted as USB power is cycling. Try to connect Woobm with USB dock station with external power supply to prevent resseting during router reset.
by BartoszP
Sun Sep 02, 2018 12:04 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 88905

Re: RB4011

.... will force all programmers to finally start thinking multithread from the very beginning....
Most people are single threaded :D
by BartoszP
Thu Aug 30, 2018 8:23 pm
Forum: General
Topic: How to downgrade the ROS below the factory version?
Replies: 5
Views: 1155

Re: How to downgrade the ROS below the factory version?

It has been programmed at factory with 6.40.5 so 6.41 is newer.
by BartoszP
Thu Aug 30, 2018 12:36 pm
Forum: Beginner Basics
Topic: Locked Out of Mikrotik
Replies: 29
Views: 5105

Re: Locked Out of Mikrotik

Do you have MAC address in the field "Connect to:" specified?
by BartoszP
Thu Aug 30, 2018 12:23 pm
Forum: Beginner Basics
Topic: Locked Out of Mikrotik
Replies: 29
Views: 5105

Re: Locked Out of Mikrotik

Winbox via MAC address.
Open Winbox ... click "Neighberhood" ... wait for your router ... click MAC address in the MAC column ... fill user + password ... connect
by BartoszP
Thu Aug 30, 2018 9:06 am
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 37108

Re: v6.42.7 [current] is released!

Have you tried to use WinBox with MAC connection?
by BartoszP
Wed Aug 29, 2018 4:55 pm
Forum: Scripting
Topic: Exit script if...
Replies: 4
Views: 2144

Re: Exit script if...

Maybe this could help:
:if ([:len $net1] > 0) do={
do what I want
}
by BartoszP
Wed Aug 29, 2018 8:10 am
Forum: Beginner Basics
Topic: PS4/Hulu connection issues.
Replies: 6
Views: 1196

Re: PS4/Hulu connection issues.

Read these posts: search.php?keywords=hulu
by BartoszP
Sun Aug 26, 2018 1:08 pm
Forum: General
Topic: Block user with bad intention
Replies: 6
Views: 1118

Re: Block user with bad intention

Your router could always be blocked by DDOS. Yes, one packet seems to be too preventive but most of addresses I am watching are pure port scanning or attacks to SSH, Winbox or SMB. I have showed just a snippet of the first barrier. You can always adjust time used to block particular IP address or ad...
by BartoszP
Fri Aug 24, 2018 11:30 pm
Forum: General
Topic: Block user with bad intention
Replies: 6
Views: 1118

Re: Block user with bad intention

I use as the first barier: /interface list add name=WAN_LIST /ip firewall raw add action=accept chain=prerouting dst-port=65432 protocol=tcp add action=add-src-to-address-list address-list=RAWATTACK2 address-list-timeout=27m chain=prerouting comment=RAW2ADD in-interface-list=WAN_LIST log-prefix="RAW...
by BartoszP
Thu Aug 23, 2018 7:07 pm
Forum: General
Topic: Strange outgoing connection
Replies: 2
Views: 547

Re: Strange outgoing connection

Simple Google search for https://ipinfo.io/216.58.205.99 shows that it is Google IP so I suspect that that it is a connection to Gmail or Google lookup from web browser. You have session timeout set to 24 h. so if browser opens connection to google.com and then you change web page, the connection to...
by BartoszP
Thu Aug 23, 2018 1:04 pm
Forum: Announcements
Topic: v6.40.9 [bugfix] is released!
Replies: 56
Views: 19456

Re: v6.40.9 [bugfix] is released!

5 x 951G-2HnD updated without any problems ... simple sonfiguration.
1 x 1100AHx4 - no problems with update
1 x 1100AHx4 - needed power cycle to start working after "Download&Instal".
by BartoszP
Thu Aug 23, 2018 12:55 pm
Forum: General
Topic: Port forward from within local network?
Replies: 1
Views: 492

Re: Port forward from within local network?

Read this: https://wiki.mikrotik.com/wiki/Hairpin_NAT

SOHO routers do this behind the scenes. In Mikrotik's world ... read non-SOHO routers ... you need to do it yourself. You have full controln on packet routing/forwarding.
by BartoszP
Tue Aug 21, 2018 8:37 am
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 37108

Re: v6.42.7 [current] is released!

Could we expect 6.40.9 ?
by BartoszP
Mon Aug 20, 2018 5:48 pm
Forum: General
Topic: Page can't be displayed due to blocked resources
Replies: 1
Views: 599

Re: Page can't be displayed due to blocked resources

Why do you suspect that Mikrotik is responsible for this? Have you checked this page via different connection?
Picture clearly shows message which looks like valid html page prepared by bank's server. Have you contacted with bank?
by BartoszP
Sun Aug 19, 2018 10:09 am
Forum: General
Topic: Passwords for hundreds/thousdands of devices
Replies: 10
Views: 1629

Re: Passwords for hundreds/thousdands of devices

What do you mean by "manage"?
by BartoszP
Sun Aug 19, 2018 1:28 am
Forum: Wireless Networking
Topic: Sharing Motel WiFi
Replies: 13
Views: 4910

Re: Sharing Motel WiFi

Yes.
Use any dual band device. Use one WiFi interface as WAN and the second connect to LAN bridge.
by BartoszP
Tue Aug 14, 2018 10:16 pm
Forum: Announcements
Topic: Photos of towers and masts
Replies: 71
Views: 27259

Re: Photos of towers and masts

Real world without tie-wraps does not exist :-)
by BartoszP
Tue Aug 14, 2018 9:13 pm
Forum: General
Topic: force push local address to gateway? (to avoid Hairpin NAT)
Replies: 4
Views: 934

Re: force push local address to gateway? (to avoid Hairpin NAT)

What is wrong with Harpin NAT? It is just name of technology which "other" routers do behind the scenes.
One line for NAT. That is all.
by BartoszP
Mon Aug 13, 2018 8:38 am
Forum: General
Topic: Forced routing with UTM connected both ends to Mikrotik
Replies: 7
Views: 1029

Re: Forced routing with UTM connected both ends to Mikrotik

Maybe you should just make bridge for ETH1+ETH2 and the second for ETH3+ETH4 and connect it with this UTM?
by BartoszP
Mon Aug 13, 2018 8:20 am
Forum: Beginner Basics
Topic: One IP Public Multiple Webserver
Replies: 4
Views: 2416

Re: One IP Public Multiple Webserver

It is not problem of Mikrotik configuration.

You should configure virtual hosts on your WWW server to manage different domains.
In Mikrotik device you should pass all HTTP trafic to this server.
by BartoszP
Thu Aug 09, 2018 8:24 am
Forum: General
Topic: New Attack on WPA/WPA2 Discovered, Most Modern Routers Might be at Risk
Replies: 8
Views: 2253

Re: New Attack on WPA/WPA2 Discovered, Most Modern Routers Might be at Risk

Davis,
Is ROS affected? IMHO it is stupid question.
If Mikrotik implements and follow WiFi standard then the standard is affected then this "flow in design" is in current ROS implemented.

What, in yor opinion, should be done? Change to WiFi implementation to not follow standard?
by BartoszP
Wed Aug 08, 2018 11:03 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 120
Views: 46756

Re: Security announcement blog

What is the conclusion?
by BartoszP
Wed Aug 08, 2018 10:32 pm
Forum: General
Topic: Another worrying Wi-Fi exploit could potentially plague your router
Replies: 3
Views: 941

Re: Another worrying Wi-Fi exploit could potentially plague your router

What is connection of cracking WiFi credentials and router?