Community discussions

Search found 505 matches

  • 1
  • 2
by Van9018
Tue Apr 16, 2019 9:29 pm
Forum: Beginner Basics
Topic: check and protect smb from outside
Replies: 2
Views: 343

Re: check and protect smb from outside

SMB from the outside is firewalled by default (out-of-box config). There should be a default deny rule in your firewall. With out-of-box config, your LAN ports would be in a bridge and there would be no firewall, so SMB within the LAN should be ok. I like to firewall outbound SMB though, disallow SM...
by Van9018
Fri Apr 12, 2019 5:51 am
Forum: Beginner Basics
Topic: routers sends back local IP instead of external
Replies: 4
Views: 373

Re: routers sends back local IP instead of external

For the sake of understanding of what you saw at first... when I use filezilla, it does work, but when I use windows explorer.... When your filezilla server uses the private IP of the machine, the remote filezilla-client will probably work because the filezilla client has a feature where it determin...
by Van9018
Sat Apr 06, 2019 10:54 pm
Forum: General
Topic: SIP port(s)
Replies: 6
Views: 447

Re: SIP port(s)

by Van9018
Thu Mar 28, 2019 9:52 pm
Forum: General
Topic: Port forwarding to two pcs for RDP
Replies: 12
Views: 853

Re: Port forwarding to two pcs for RDP

- Can you RDP to the 2nd machine from inside the LAN? If not, then check Windows firewall. If you can, check if firewall is limited to LAN only or something like that. - Use Torch on wan interface. You should see your RDP packets coming in the wan interface, then torch again on the lan and you shoul...
by Van9018
Wed Mar 27, 2019 2:57 am
Forum: Beginner Basics
Topic: Connecting SSTP Client and SSTP Server on MT
Replies: 6
Views: 472

Re: Connecting SSTP Client and SSTP Server on MT

Your MT-DEVICE with IP of 172.17.1.x doesn't know where the 172.16.0.0/16 network is. The MT-DEVICES need a route that says to forward 172.16.0.0/24 to <SSTP-CLIENT-NAME> Your SE-DEVICE with IP of 172.16.1.1 doesn't know where the 172.17.0.0/16 is. The SE-DEVICE needs a route to send 172.17 packets ...
by Van9018
Fri Mar 22, 2019 5:03 am
Forum: Scripting
Topic: macros bug [SOLVED]
Replies: 14
Views: 1801

Re: macros bug [SOLVED]

This page: https://wiki.mikrotik.com/wiki/Manual:S ... _statement
says the syntax of the if statement should be prefixed with a colon

{
:local myBool true;
:if ($myBool = false) do={ :put "value is false" } else={ :put "value is true" }
}
by Van9018
Fri Mar 22, 2019 4:51 am
Forum: General
Topic: How to route (assign) two Public IP's on same segment /29 and keep connectivity
Replies: 18
Views: 1057

Re: How to route (assign) two Public IP's on same segment /29 and keep connectivity

IP > Address, just add the second IP to the same interface. You may need a src-nat rule in IP > Firewall > NAT.
I don't understand your requirements though. Is Public IP #1 meant for guests, and Public IP #2 is meant for the corporate LAN?
by Van9018
Fri Mar 22, 2019 4:15 am
Forum: General
Topic: IPSEC ike2 tunnel drops [SOLVED]
Replies: 4
Views: 646

Re: IPSEC ike2 tunnel drops [SOLVED]

I don't have much input.. sorry! I checked my IPSec configs, and I found that a second set of SA's get created, both sets exist for maybe 30 seconds and then the first set a is removed. My soft lifetime is 30 minutes, hard lifetime is 1d. The status of the SAs say 24/30 for "add lifetime". It's afte...
by Van9018
Fri Mar 22, 2019 2:28 am
Forum: General
Topic: Static DNS for Local network
Replies: 18
Views: 989

Re: Static DNS for Local network

But I would refrain from using Layer 7 protocol expressions. Why refrain from this? I do as Sob suggested. At my office, my Mikrotik maintains a VPN to my clients. Using L7, I intercept DNS packets and redirect them to the client's internal DNS server. Now, any PC from my office can remote into any...
by Van9018
Fri Mar 22, 2019 1:46 am
Forum: Beginner Basics
Topic: Is it OK for all leds to run at once like this ?
Replies: 2
Views: 276

Re: Is it OK for all leds to run at once like this ?

On a LAN, routers often try and be proactive in resolving IPs to Max (Arp Request). An ARP request is a broadcast packet. Your router will query each IP on the LAN for it's mac address. Devices will also do ARP requests. Windows will try and discover new equipment like TVs and Printers on the networ...
by Van9018
Fri Mar 22, 2019 1:37 am
Forum: General
Topic: Attempt of attacks through Remote Desktop [SOLVED]
Replies: 6
Views: 529

Re: Attempt of attacks through Remote Desktop [SOLVED]

First ensure you have the latest updates to Win 7 or Win 10. Don't use older Operating Systems. Microsoft dropped the ball 3 times already where a hacker could send a specially crafted packet that would contain a command that would be executed under the System user. So without logging in, a hacker c...
by Van9018
Fri Mar 22, 2019 1:23 am
Forum: General
Topic: SMB Server question (RB3011)
Replies: 2
Views: 286

Re: SMB Server question (RB3011)

Might be related to line endings. The working PDF has CRLF as line ending whereas corrupted file has LF. This was a problem for iOS mail for a short time a few years ago. Use a hex editor on a corrupted PDF and locate an LF character (ascii=10). There must be a preceding CR character (ascii=13). If ...
by Van9018
Fri Mar 22, 2019 1:07 am
Forum: General
Topic: VoIP issues Mikrotik SIP ALG and Grandstream
Replies: 2
Views: 578

Re: VoIP issues Mikrotik SIP ALG and Grandstream

I don't quite understand your setup. On my Grandstream + Mikrotik setups I leave SIP ALG on, turn sip-direct-media off and set the two ports on the UCM to switch/bridge mode so neither port is a WAN port. It's then like a 2 port switch. I don't use any NAT whatsoever because that's what the SIP ALG ...
by Van9018
Wed Mar 20, 2019 1:09 am
Forum: General
Topic: faile to obtain ip address error
Replies: 4
Views: 289

Re: faile to obtain ip address error

When lease shows mac as 00:00:00:00:00 then a device already has that IP. Some Ideas: - Turn on logging for the DHCP topic. - If log says Offering Lease without Success, check out this thread: https://forum.mikrotik.com/viewtopic.php?f=2&t=130176&p=719332&hilit=apple+dhcp#p719332 - Possibly another ...
by Van9018
Wed Mar 20, 2019 12:59 am
Forum: General
Topic: Static IP not showing at DHCP server.
Replies: 8
Views: 3460

Re: Static IP not showing at DHCP server.

because some pc i set as static at DHCP there and i saw it at lease there.
If your PC started off as DHCP and then you set it to a static IP, the old lease will still be shown until it expires.
by Van9018
Wed Mar 20, 2019 12:14 am
Forum: Beginner Basics
Topic: Any way to scan for *anything* on the LAN? [SOLVED]
Replies: 4
Views: 414

Re: Any way to scan for *anything* on the LAN? [SOLVED]

The link local status will tell you if something is physically connected. If that device tries to communicate, it must have atleast a MAC address and the Mikrotik will record that mac in it's arp tables. You can look up this table in Switch > FDB I think. Entries in arp-tables last for about 10 minu...
by Van9018
Sat Mar 16, 2019 10:23 pm
Forum: Beginner Basics
Topic: ARP issue
Replies: 2
Views: 265

Re: ARP issue

Is this your setup ?
First Router, ether1--> Modem/internet.
2nd Router, ether1 --> First Router's ether2
by Van9018
Tue Mar 12, 2019 2:15 am
Forum: General
Topic: route ip to specific gateway
Replies: 6
Views: 328

Re: route ip to specific gateway

Yes its one less rule but is it more efficient?? I doubt it. If ISP2 is exclusive to the webserver, I'd think of this as a one-to-one NAT where all but HTTP is firewalled. If thinking of this as a one-to-one nat, it feels a bit more semantic to not have connection-marking rules. If familiarizing my...
by Van9018
Tue Mar 12, 2019 1:30 am
Forum: Beginner Basics
Topic: Mikrotik as HUB (configuration)
Replies: 17
Views: 1258

Re: Mikrotik as HUB (configuration)

IP > DHCP Server, delete the dhcp server for bridge1 IP > Addresses, delete the ip address of bridge1 At this point, Ports 2-5 and wifi are considered a switch. ether1 remains the gateway. If you want to use ether1 as another port in the switch... IP > DHCP Client, delete DHCP Client for ether1 Brid...
by Van9018
Tue Mar 12, 2019 1:05 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1369

Re: Harpin NAT between two VLANs

Overriding www.yoursite.com would be less complicated. Do it in pi-hole if possible. If not, you can catch DNS requests in the Mikrotik, repoint the domains to your Mikrotik's DNS and override there.. You'd have to override yoursite.com and www.yoursite.com. You will need to allow port 80/443 to you...
by Van9018
Mon Mar 11, 2019 11:53 pm
Forum: General
Topic: How to reach RouterOs (web or Winbox) via my static ip address from outside network
Replies: 24
Views: 1192

Re: How to reach RouterOs (web or Winbox) via my static ip address from outside network

i see the source IP address if i run torch on the on my WAN IP but no connection is established Next would be to Torch bridge1, youd should see packets forwarding to your webserver. If not, check your NAT (Port forwarding) rules. On the same Torch, you should see packets coming from your webserver....
by Van9018
Mon Mar 11, 2019 11:46 pm
Forum: General
Topic: How to reach RouterOs (web or Winbox) via my static ip address from outside network
Replies: 24
Views: 1192

Re: How to reach RouterOs (web or Winbox) via my static ip address from outside network

Otunmusa, by default the Mikrotik won't remember which ISP your outside request came in on. So you connect to the IP of ISP2, and your port forwarding rules forward to your web server. Then your webserver replies, but the Mikrotik will send the packets out on ISP1. This is a broken connection. You h...
by Van9018
Mon Mar 11, 2019 11:21 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1369

Re: Harpin NAT between two VLANs

You need 4 rules per hairpin. This tutorial worked for me: https://wiki.mikrotik.com/wiki/Hairpin_NAT

Or you can override DNS in the Mikrotik to repoint your website url to the LAN IP of your webserver.
by Van9018
Mon Mar 11, 2019 11:11 pm
Forum: General
Topic: route ip to specific gateway
Replies: 6
Views: 328

Re: route ip to specific gateway

If it's specifically 1 LAN IP that gets to use ISP2 exclusively, then you could skip the connection-marking and just apply routing marks.
by Van9018
Mon Mar 11, 2019 10:59 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 495

Re: Firewall rules

Or use a VPN, then configure your viewer to connect to the local IPs of the cameras. This could be more secure than exposing your Camera's communication protocols to the internet.
by Van9018
Mon Mar 11, 2019 10:32 pm
Forum: General
Topic: Viewing network traffic question
Replies: 7
Views: 552

Re: Viewing network traffic question

I just need a simple "traffic from this IP can go through" rule. To do this, you can create a NAT rule. In Winbox, it's under IP > Firewall, click the NAT tab. Create Rule: chain=dst-nat, src-ip=<Scanner IP>, in-interface=ether1, action=dst-nat, to-address=<IP of internal PC> You can create a 2nd r...
by Van9018
Fri Mar 08, 2019 9:29 am
Forum: General
Topic: Please help SSL Notworking
Replies: 2
Views: 208

Re: Please help SSL Notworking

Port conflict or no certificate. Certificate needs a private key too.
by Van9018
Fri Mar 08, 2019 9:23 am
Forum: General
Topic: Viewing network traffic question
Replies: 7
Views: 552

Re: Viewing network traffic question

I thought the purpose of the PCI Compliance scan was to check for open ports and predictive PAT. They'll check for things such downgrade attacks on servers you may have exposed to the internet. Some routers will have security where it detects and blocks port scanners. They want you to disable that t...
by Van9018
Fri Mar 08, 2019 8:13 am
Forum: General
Topic: SSTP Server, does it REALLY work for anyone??
Replies: 7
Views: 522

Re: SSTP Server, does it REALLY work for anyone??

You don't need to make a certificate chain, but I'd consider it good practice. You'd install 1 self-signed certificate that's marked as a Certificate Authority (CA) on your windows computers then you can create more certificates and sign them with your CA certificate and the computers will trust the...
by Van9018
Fri Mar 08, 2019 7:38 am
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 853

Re: ARP/DHCP issue [SOLVED]

- When a host wants to send a packet to an internet address, it will send the packet directly to the gateway. It will NOT do an arp lookup for that internet address. - You shouldn't see two DHCP discovers and two requests during a DHCP transaction, but not a big deal. Discover, Offer, Request, Ack. ...
by Van9018
Thu Mar 07, 2019 4:44 am
Forum: General
Topic: How to get on mikrotik list of arp records at port.
Replies: 3
Views: 255

Re: How to get on mikrotik list of arp records at port.

In Winbox, Switch > FDB
Untitled.png
by Van9018
Wed Mar 06, 2019 8:03 am
Forum: Wireless Networking
Topic: Block PC to access local LAN on Mikrotik
Replies: 3
Views: 373

Re: Block PC to access local LAN on Mikrotik

If PC is trusted and you want the firewall for good measure, then maybe iptables in ubuntu?
If PC is untrusted, then anav's suggestion is the only way. Also consider firewall input rules to protect router service ports from the untrusted computer.
by Van9018
Wed Mar 06, 2019 4:29 am
Forum: Beginner Basics
Topic: Dropping from non-DHCP clients
Replies: 1
Views: 133

Re: Dropping from non-DHCP clients

In the interface settings, set ARP to enabled (or arp-proxy if your Mikrotik is a VPN Server). You probably have arp set to reply only. Reply Only is a feature that prevents devices with statically set IPs from communicating on the network. For a statically set IP, you'd have to then manually the ma...
by Van9018
Wed Mar 06, 2019 4:25 am
Forum: RouterBOARD hardware
Topic: Problem to choose the right hardware
Replies: 5
Views: 716

Re: Problem to choose the right hardware

Your RB450Gx4 has enough performance and AES hardware acceleration for all 3 situations.l I used a Hex Lite, a very cheap Mikrotik router, for 80 PCs and one IPSec tunnel for site-to-site. The Hex Lite does not have AES hardware acceleration so I had to slow Microsoft DFS to 3 mbit/s otherwise the C...
by Van9018
Wed Mar 06, 2019 4:13 am
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 853

Re: ARP/DHCP issue [SOLVED]

If the Alarm system has an IP statically set and it's not on the same subnet as statically set in the alarm system, then the alarm system will do ARP requests for the gateway that's statically set in the Alarm system. Since no device on your network will have that IP, you will only see ARP requests ...
by Van9018
Wed Mar 06, 2019 4:00 am
Forum: General
Topic: ARP/DHCP issue [SOLVED]
Replies: 9
Views: 853

Re: ARP/DHCP issue [SOLVED]

You're a bit off on ARP. On an Ethernet network, every device has a mac address. When packets get sent out over Ethernet, they are actually routed only by their mac address. Not IP address. Since your PC will connect to remote devices by IP, then it needs to find out who on the network has an IP ass...
by Van9018
Wed Mar 06, 2019 3:08 am
Forum: Beginner Basics
Topic: port forwarding - can't figure it out
Replies: 2
Views: 184

Re: port forwarding - can't figure it out

Issue 1 & 2: You are looking at the firewall rules. You need to go to IP > Firewall and then click the NAT tab. Then when you create a rule you'll see chain=dst-nat and action=dst-nat

Issue 3: Your action should be dst-nat, not dns-nat
by Van9018
Thu Jan 10, 2019 3:01 am
Forum: Beginner Basics
Topic: Cannot access RouterOS using WebFig
Replies: 8
Views: 832

Re: Cannot access RouterOS using WebFig

You can reset the device configuration back to default to make it back into a managed switch. Or if you want to do it manually anyway: - Remove your bridge - Set master-port to ther1 for ports 2-24. - Remove all port forwarding from firewall > NAT, also remove any mangle rules. Delete firewall rules...
by Van9018
Thu Jan 10, 2019 2:48 am
Forum: General
Topic: Apple devices flooding DHCP server
Replies: 7
Views: 1107

Re: Apple devices flooding DHCP server

Have you tried using a different Mikrotik to rule out the Mikrotik as the problem? Disable the DHCP Service, try obtaining an IP. Is there another DHCP service on the network? In Winbox, capture packets with Tools > Packet Sniffer. Save packets to a file. Let the problem happen for a minute. Stop th...
by Van9018
Fri Nov 09, 2018 6:08 am
Forum: General
Topic: DHCP issue
Replies: 4
Views: 630

Re: DHCP issue

The default config of an 951G-2HnD is: Port 1 = WAN Port 2-5 & WIFI = LAN So to accomplish what you're doing, you should plug cables in like this.. R1 Port 1 -> Internet R1 Port 2 -> Client 1 LAN R1 Port 3 -> R2 Port 1 (You probably have this going to a different port?) R2 Port 2 -> Client 2 LAN The...
by Van9018
Wed Oct 10, 2018 1:25 am
Forum: General
Topic: Two of Three Mikrotik router became unreachable after few days
Replies: 1
Views: 299

Re: Two of Three Mikrotik router became unreachable after few days

Try using winbox and connect via MAC address (have to be on the same LAN) I had this issue. Router worked fine but couldn't connect via Winbox to it's IP. But connecting via MAC address worked. I never could get Winbox working again over IP. I replaced it, I have not yet done a factory reset to see ...
by Van9018
Thu Sep 13, 2018 1:01 am
Forum: Beginner Basics
Topic: Got hacked, think I need help with configuring routerOS
Replies: 17
Views: 2746

Re: Got hacked, think I need help with configuring routerOS

For the mikrotik.php virus, Winbox may still work if you connect via mac address. Check IP > Web Proxy, disable it. Go to IP > Firewall, NAT. Delete redirect rule. Go to System > Scripts, delete the bad scripts. Check System > Scheduler too. Even after you secure your router with firewall, upgrade t...
by Van9018
Tue Sep 11, 2018 1:50 am
Forum: General
Topic: Unable to connect to VPN from outside the internal network
Replies: 2
Views: 446

Re: Unable to connect to VPN from outside the internal network

Your firewall rules (500, 4500, 1701) only apply when the routing-mark = DellDsl. Ether4 has a WAN IP. The src-address of packets coming in ether4 would then be a WAN IP. Your mangle rules apply to packets coming in with a private IP - these rules probably don't get triggered.
by Van9018
Tue Sep 11, 2018 1:34 am
Forum: General
Topic: How to block Windows Update on RB2011
Replies: 3
Views: 1701

Re: How to block Windows Update on RB2011

On windows computers you can set the update server. Point it to a non-existent server. You can do that in Group Policy. Then the computers won't get any updates. For the Mikrotik, I think you'd have to resolve all those hostnames to the various IPs in which they may resolve. Then add those IPs to an...
by Van9018
Tue Sep 11, 2018 1:27 am
Forum: Beginner Basics
Topic: DNS for PPTP clients
Replies: 9
Views: 4850

Re: DNS for PPTP clients

If you're trying to resolve hostname only, then your computer goes through various steps to resolve it. 1. It checks the hosts file, this returns immediately. 2. It checks DNS, if any of your adapters has a dns suffix then it'll try and resolve that way. If any DNS servers are slow to respond, this ...
by Van9018
Fri Sep 07, 2018 2:04 am
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1070

Re: Bruteforce prevention Issue

How about a Mikrotik as a VPN server. Techs VPN into that router. Then all client routers allow winbox, RDP, etc from the VPN Servers IP. It also gives the ability to cancel the tech's access to all client sites by deleting his login on the VPN server. iPhone, Android, Windows and Mac all support L2...
by Van9018
Fri Sep 07, 2018 1:11 am
Forum: General
Topic: Windows 2016 DC requesting lots of IPs from DHCP?
Replies: 6
Views: 512

Re: Windows 2016 DC requesting lots of IPs from DHCP?

Why wouldn't you let your DCs be the DHCP server rather than the router? You have redundancy with 2 DCs. If an IP in the DHCP range is in-use but the DHCP server has no lease for it, Mikrotik will mark it as in-use and try the next IP. Microsoft will give out the in-use IP. Example: Client buys a p...
by Van9018
Thu Sep 06, 2018 9:37 am
Forum: General
Topic: Feature Request: IP source guard / arp inspection
Replies: 6
Views: 1396

Re: Feature Request: IP source guard / arp inspection

This exists I believe. For your LAN interface, set arp mode to read-only.
If you want a statically set IP for a client, you'd first have to add his mac to the arp table with desired IP.
Everyone else must use their dynamic IP given by DHCP.
by Van9018
Thu Sep 06, 2018 9:13 am
Forum: General
Topic: Windows 2016 DC requesting lots of IPs from DHCP?
Replies: 6
Views: 512

Re: Windows 2016 DC requesting lots of IPs from DHCP?

Probably Windows Server thing. RAAS will hold a bunch of IPs like this.
by Van9018
Sat Aug 04, 2018 4:49 am
Forum: Beginner Basics
Topic: Nat not working
Replies: 4
Views: 647

Re: Nat not working

I find Torch a useful tool to track where packets are being lost. Torch on the WAN to determine if packets are actually hitting your wan, if they are, check dst-nat rule - is the 'packets' field incrementing? Then torch on the LAN side, see if packets are leaving your Mikrotik with the new dest ip (...
by Van9018
Sat Aug 04, 2018 4:40 am
Forum: Beginner Basics
Topic: dhcp lease table
Replies: 5
Views: 588

Re: dhcp lease table

Another cool feature...
Before Mikrotik gives out the next IP, it'll check to see if that IP is being used on the network. If so, a lease is created where the mac is 00:00:00:00:00 and Mikrotik moves onto the next IP to give out.
by Van9018
Sat Aug 04, 2018 4:31 am
Forum: General
Topic: IP Addresses list that access to google
Replies: 4
Views: 727

Re: IP Addresses list that access to google

Google will use encryption, so you can't check the HTTP header. If your DNS is external, or the Mikrotik is your DNS, then maybe you can create a firewall rule to log packets coming in the LAN interface of the Mikrotik. Using a Layer7 rule you should be able to log google. Your browser and OS may ca...
by Van9018
Wed Jul 25, 2018 2:07 am
Forum: General
Topic: Hacked-Rogue DNS?
Replies: 12
Views: 2096

Re: Hacked-Rogue DNS?

- Use aggressive firewall. Ban all IPs that try to connect to ports with no services listening. How do you do this? Do you have a script? Will this add much CPU load? Rule 1: Chain=Input, in-interface=ether1, src-add-list=BANNED, action=drop Rule 2: Chain=Input, in-interface=ether1, proto=tcp, dst-...
by Van9018
Tue Jul 24, 2018 10:41 pm
Forum: General
Topic: OPENVPN creating certificate
Replies: 1
Views: 260

Re: OPENVPN creating certificate

You can create a self-signed certificate.

With a self-signed certificate, you can enter whatever values you want.
by Van9018
Tue Jul 24, 2018 10:37 pm
Forum: General
Topic: Can't get Port Forwarding of 1812 and 16384 to work
Replies: 3
Views: 533

Re: Can't get Port Forwarding of 1812 and 16384 to work

Try using Tools > Torch in Winbox. Then try and connect remotely. You'll be able to see if packets are being received by the router, and forwarded to the smoker. And that the smoker replies correctly. No gateway in the smoker can cause this. Or firewall rules in the smoker. Torch is a good place to ...
by Van9018
Tue Jul 24, 2018 10:22 pm
Forum: General
Topic: Hacked-Rogue DNS?
Replies: 12
Views: 2096

Re: Hacked-Rogue DNS?

More options: - Use Port Knocking for administrative ports - Use L2TP/IPSec and not expose administrative ports - Use aggressive firewall. Ban all IPs that try to connect to ports with no services listening. For the last one, it seems hackers are using distributed port scans. For my routers, about 1...
by Van9018
Wed Jun 13, 2018 4:08 am
Forum: Beginner Basics
Topic: hEX - IPsec Tunnel slow
Replies: 31
Views: 5574

Re: hEX - IPsec Tunnel slow

Nothing more to do on the router if FTP maxes out your connection.

SMB is a chatty protocol, latency is a killer. You'll have to look more into SMB to see if it can be tuned for better throughput on high latency networks.
by Van9018
Wed Jun 13, 2018 3:31 am
Forum: General
Topic: PPTP client and/or server on alternate ports
Replies: 1
Views: 747

Re: PPTP client and/or server on alternate ports

I doubt a windows client has the option to change from TCP port 1723. If your ISP is blocking 1723, then it's most likely blocking GRE as well. GRE doesn't use ports, so that'll be the show stopper for you. The SSTP VPN can be configured to listen on alternative ports, and in clients you can specify...
by Van9018
Tue Jun 12, 2018 11:12 pm
Forum: General
Topic: IPSec/L2TP and Network Resources [SOLVED]
Replies: 28
Views: 2788

Re: IPSec/L2TP and Network Resources [SOLVED]

I thought there was a trick for this.

If server IP of L2TP/IPSec is the IP of your ether2 ip, and ether2 arp mode is proxy-arp, then it would work? I haven't tested this myself.

if broadcasts won't work, then SMB will still work if you use IP or WINS or DNS.
by Van9018
Mon Jun 11, 2018 10:29 am
Forum: General
Topic: SOME DOUBTS AROUND BYPASS USING WINBOX
Replies: 1
Views: 234

Re: SOME DOUBTS AROUND BYPASS USING WINBOX

You could create a mac based vlan and assign a DHCP Server to that VLAN.
by Van9018
Mon Jun 11, 2018 9:59 am
Forum: Beginner Basics
Topic: L2TP/IPSec Client
Replies: 3
Views: 546

Re: L2TP/IPSec Client

In Windows, iOS, Android and Mac - they automatically forward all traffic over the VPN. The Mikrotik does not. Edit your L2TP client interface in the Mikrotik, and under the Dial Out tab, check "Add Default Route". I'm not sure - but you may have to also set the distance of your existing default rou...
by Van9018
Sat Jun 09, 2018 3:44 am
Forum: General
Topic: Mikrotik detecting all traffic to Synology as invalid connections
Replies: 7
Views: 1172

Re: Mikrotik detecting all traffic to Synology as invalid connections

Any updates or solutions? I'm having the same problem. Mikrotik's invalid rule is dropping some of my synology packets. Are you using a VLAN too? If Synology is on the same lan, then packets don't go through the firewall. Could it be that packets to the synology go through the LAN and the packets f...
by Van9018
Fri Jun 08, 2018 11:20 pm
Forum: Beginner Basics
Topic: L2TP & IPSEC with Windows 10
Replies: 12
Views: 3474

Re: L2TP & IPSEC with Windows 10

Anybody want to run a packet capture on the Mikrotik? On the Wan interface. Post the results in this thread.

Would be helpful to see what Windows is sending.
by Van9018
Fri Jun 08, 2018 11:16 pm
Forum: General
Topic: DNS service on specific Public IP address
Replies: 12
Views: 1080

Re: DNS service on specific Public IP address

action=mark-connection
DNS uses UDP, not TCP. UDP is connectionless so there is no connection to mark.
by Van9018
Fri Jun 08, 2018 8:32 pm
Forum: General
Topic: DNS service on specific Public IP address
Replies: 12
Views: 1080

Re: DNS service on specific Public IP address

out-interface=wan, protocol=udp, DST-port=53 , then action=src-nat, to-address=Desired-IP router Address I think it has to be src-port=53, no? A client will send a dns query with a random src-port and dst-port of 53. When the server replies, it's src-port will be 53 and dst-port will be the src-por...
by Van9018
Thu Jun 07, 2018 1:48 am
Forum: General
Topic: DNS service on specific Public IP address
Replies: 12
Views: 1080

Re: DNS service on specific Public IP address

Try putting src-nat rule at the top.

When out-interface=wan, protocol=udp, src-port=53, then action=src-nat, to-address=Desired-IP
by Van9018
Thu Jun 07, 2018 1:32 am
Forum: General
Topic: Mikrotik Open VPN Server + Windows Client
Replies: 6
Views: 4196

Re: Mikrotik Open VPN Server + Windows Client

Are you using tap(bridge) or Tunnel/IP mode for OVPN?

Use TAP/Bridge for client. I think that creates a layer 2 tunnel so you don't have to worry about routes.
by Van9018
Wed Jun 06, 2018 10:59 pm
Forum: General
Topic: Which mikrotik router for OpenVPN
Replies: 8
Views: 2812

Re: Which mikrotik router for OpenVPN

Since 2010, Mikrotik is no longer developing their OpenVPN implementation. Expect the limitations to be permanent. Use IPSec, or GRE/IPSec if you want an interface to work with (I think Cisco supports GRE/IPSec?)
by Van9018
Wed Jun 06, 2018 10:42 pm
Forum: General
Topic: Mikrotik Open VPN Server + Windows Client
Replies: 6
Views: 4196

Re: Mikrotik Open VPN Server + Windows Client

Yes - you have to create static routes. You'd start off with a basic client-to-gateway setup as described here: http://wiki.mikrotik.com/wiki/OpenVPN Once you get that part working, then you move onto the site-to-site config by adding static routes. Your two Lans will have to be separate subnets. On...
by Van9018
Wed Jun 06, 2018 5:10 am
Forum: Beginner Basics
Topic: Probs connecting to RB2011UiAS-IN
Replies: 2
Views: 336

Re: Probs connecting to RB2011UiAS-IN

Your laptop's weird address starts with 169.254? That's a random IP that Windows will assign itself. In winbox, are you on the Neighbours tab? It should list detectable Mikrotiks on the network. Even if there is incompatible IPs, you should still be able to connect to it via MAC address. Try ether3,...
by Van9018
Wed Jun 06, 2018 4:53 am
Forum: Beginner Basics
Topic: Select public IP compared to the LAN
Replies: 5
Views: 450

Re: Select public IP compared to the LAN

As for dynamic IPs assigned by your DHCP, The config is similar but you have to use scripts to update your src-nat and default routes. First, in the DHCP protocol your DHCP Client defines a client-id. You can set this and have multiple DHCP IPs assigned to one mac. However many DHCP Servers ignore t...
by Van9018
Wed Jun 06, 2018 4:40 am
Forum: Beginner Basics
Topic: Select public IP compared to the LAN
Replies: 5
Views: 450

Re: Select public IP compared to the LAN

You'd still need to add the default route manually, as you'd do if you were only dealing with 1 static IP. In my example I should've used a bigger subnet such as /29 which would yield 6 usable addresses. So for 200.218.100.0/29 .0 = the network, can't use that IP .1 to .6 = IPs that can be used. You...
by Van9018
Wed Jun 06, 2018 3:59 am
Forum: Beginner Basics
Topic: hosted website points to mikrotik webfig
Replies: 2
Views: 360

Re: hosted website points to mikrotik webfig

I imagine your setup works when you connect from outside your home? (if you've done the port forwarding already) You will need a hairpin NAT for internal clients to connect to the internal website. https://wiki.mikrotik.com/wiki/Hairpin_NAT An alternative solution is to override DNS. If your PCs beh...
by Van9018
Wed Jun 06, 2018 2:21 am
Forum: Forwarding Protocols
Topic: sip phone being stopped at wan address
Replies: 7
Views: 907

Re: sip phone being stopped at wan address

If you have: Phones <--> Mikrotik <---> Internet <---> Mikrotik <---> PBX then set up the nat rule as mentioned for the PBX mikrotik. Leave SIP Helpers ON for both Mikrotiks. Or tunnel so NAT and PAT are not in the mix. If you don't have control of the router in front of the phones, then there are t...
by Van9018
Wed Jun 06, 2018 1:44 am
Forum: Beginner Basics
Topic: Select public IP compared to the LAN
Replies: 5
Views: 450

Re: Select public IP compared to the LAN

I'll assume it's a block of static addresses. You assign ether1 the block of public static addresses. ie: 200.218.100.0/30 In IP > Firewall > Nat, add a src-nat rule. When packets come from interface of 2nd LAN, then action=src-nat, to-address = 2nd public IP. Move this rule above the masquerade rul...
by Van9018
Wed Jun 06, 2018 1:23 am
Forum: General
Topic: Mikrotik Open VPN Server + Windows Client
Replies: 6
Views: 4196

Re: Mikrotik Open VPN Server + Windows Client

If bridge mode (tap) then:
If you have a bridge1, edit the interface and set arp mode to proxy.
If you don't have bridge 1, edit ether2 and set arp mode to proxy.

Can you at least ping the Mikrotik address?
by Van9018
Wed Jun 06, 2018 1:14 am
Forum: General
Topic: Troubleshooting performance issues
Replies: 8
Views: 706

Re: Troubleshooting performance issues

I tested the site I'm at. My networking process went to 40% on my RB750 but I got the full 100mbit. And I have a bunch of rules and a queue too with ipsec (speed test didn't go through ipsec). So now I think your cpu usage is normal since mine is the same and I get the expected numbers. You may have...
by Van9018
Wed Jun 06, 2018 1:01 am
Forum: Beginner Basics
Topic: How to choose the right load balacing mode ?
Replies: 7
Views: 641

Re: How to choose the right load balacing mode ?

It sounds like what you really want is Bonding. Ask your ISP if they support it, they may not. With Bonding, your ISP gives you two physical connections and 1 public IP. To reduce technical support, an ISP would likely give you a modem/device that does the bonding so you technically would have only ...
by Van9018
Tue Jun 05, 2018 1:00 pm
Forum: General
Topic: Troubleshooting performance issues
Replies: 8
Views: 706

Re: Troubleshooting performance issues

What process is taking up 30% of CPU? Seems high.

Check the interface stats for CRC errors and dropped packets. Tools > Packet Sniffer, look for tcp retransmissions.
by Van9018
Tue Jun 05, 2018 12:37 pm
Forum: Beginner Basics
Topic: How to choose the right load balacing mode ?
Replies: 7
Views: 641

Re: How to choose the right load balacing mode ?

PCC load balancing is common: https://wiki.mikrotik.com/wiki/Manual:PCC With PCC, if a client behind your router opens multiple connections to the same host, all connections will go out the same WAN. Where as N-th load balancing the multiple connections could be across both WANs. When using a websit...
by Van9018
Tue Jun 05, 2018 12:00 pm
Forum: Beginner Basics
Topic: IPSec tunnel connectivity
Replies: 7
Views: 632

Re: IPSec tunnel connectivity

What about the route table? No routes required. The policy handles this. Packets get routed out the wan with the 0.0.0.0/0 rule, then the policy kicks in and sees the packet matching the ipsec policy. It encrypts the packet and drops it back into the routing logic, where it goes out the wan again b...
by Van9018
Tue Jun 05, 2018 11:31 am
Forum: Beginner Basics
Topic: L2TP & IPSEC with Windows 10
Replies: 12
Views: 3474

Re: L2TP & IPSEC with Windows 10

It's because your L2TP/IPSec server is behind a NAT. DMZ doesn't fix it. Registry key should. Life might be better if you change modem mode back to bridge mode. For Windows Vista, 7, 8, 10, and 2008 Server: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent RegValue: AssumeUDPEncapsula...
by Van9018
Tue Jun 05, 2018 11:07 am
Forum: Beginner Basics
Topic: L2TP IPSec VPN questions
Replies: 1
Views: 401

Re: L2TP IPSec VPN questions

No. Sorry! I wish for this too.

In this thread: viewtopic.php?t=39999
Mikrotik support says this feature is not supported.
by Van9018
Tue Jun 05, 2018 10:59 am
Forum: Beginner Basics
Topic: L2TP/IPSEC server configuration questions
Replies: 6
Views: 813

Re: L2TP/IPSEC server configuration questions

1. Port 4500 is used to detect NAT traversal. If the client has a public IP and not behind a NAT device, then IPSec will happen over the ipsec-esp protocol. This may be a rare occurrence and maybe you'll never see the counts increase. 2. I also never have problems with leaving FastTrack alone. Maybe...
by Van9018
Tue Jun 05, 2018 10:52 am
Forum: General
Topic: Open DNS and Mikrotik
Replies: 1
Views: 1512

Re: Open DNS and Mikrotik

To make all internal computers use OpenDNS you would have to: - Go to IP > DHCP Client, uncheck the checkbox to use peer dns so that Mikrotik doesn't use the DNS servers provided by your ISP - Go to IP > DNS, allow remote requests. By default the firewall should block input requests from the WAN, wh...
by Van9018
Tue Jun 05, 2018 10:15 am
Forum: The User Manager
Topic: DHCP server problem
Replies: 5
Views: 4521

Re: DHCP server problem

I would start with Tools > Packet sniffer. Set it to save to a file and only capture UDP packets. Click Apply, then Start and renew the IP on a client. Wait 10 seconds and stop the packet capture. Copy the file to your computer and open it with Wireshark. In the list of packets, you should see a Dis...
by Van9018
Tue Jun 05, 2018 10:01 am
Forum: General
Topic: slow connection over pptp!
Replies: 1
Views: 444

Re: slow connection over pptp!

Possibly because the encryption process is maxing out the CPU. Go to Tools > Profiler and do the test again. Is the CPU being maxed? If it gets maxed, packets will be dropped. Thus slower and less reliable. As far as I know, only IPSec makes use of the AES hardware acceleration. Other protocols such...
by Van9018
Tue Jun 05, 2018 9:45 am
Forum: Wireless Networking
Topic: dhcp-server lease disable and enable numbers. [SOLVED]
Replies: 2
Views: 1261

Re: dhcp-server lease disable and enable numbers. [SOLVED]

How do you determine if a MAC is wanted? Manually? Something to try is changing arp mode of your ether2 to read-only. This means 2 things: - You must manually add a mac to the arp list for any static IP on your network. - Other clients must use DHCP to get an IP. There is a checkbox in the DHCP Serv...
by Van9018
Tue Jun 05, 2018 9:32 am
Forum: General
Topic: Weird ip problem on torch
Replies: 1
Views: 250

Re: Weird ip problem on torch

What interface are your Torch'ing on? And which way are the bogus packets going?
by Van9018
Fri Feb 23, 2018 2:29 am
Forum: General
Topic: Going to be traveling, need advice on remote/vpn connection [SOLVED]
Replies: 10
Views: 1192

Re: Going to be traveling, need advice on remote/vpn connection [SOLVED]

IPSec may not work everywhere. Hotspots may block it. Hotels will likely allow it. Our international airport blocks all obvious VPNs like IPSec, PPTP https://www.softether.org/ is an "Open-Source Free ​Cross-platform Multi-protocol VPN Program". It can be daunting to learn, but with that on your Mac...
by Van9018
Fri Feb 23, 2018 2:08 am
Forum: General
Topic: No IP is being assigned to my RB951G-2HnD
Replies: 1
Views: 225

Re: No IP is being assigned to my RB951G-2HnD

Can you provide a little detail on how you're using the device? DHCP Client is on the LAN/WAN or bridge interface? Mikrtok's work great in a professional environment. In my opinion, Mikrotik's are better than Cisco due to feature set, flexibility, consistent gui over models and troubleshooting tools...
by Van9018
Tue Aug 15, 2017 11:08 pm
Forum: General
Topic: Are packet marks supposed to stay on in the IPsec layer?
Replies: 4
Views: 852

Re: Are packet marks supposed to stay on in the IPsec layer?

You should still be able to firewall outbound packets, but before their encrypted. Packets destined to the remote network that don't have the packet mark and going out the wan interface could be dropped. As for prioritizing, I don't see how it would work. You could prioritize within the IPSec tunnel...
by Van9018
Sat Aug 12, 2017 11:16 pm
Forum: General
Topic: Question about poe
Replies: 5
Views: 1129

Re: Question about poe

If your only looking to power a single cisco phone, search your local vendors for a 802.3af POE DC Injector. Since your cisco phone is 802.3af then your POE DC Injector must be 802.3af. If specs don't mention if their PoE is 802.3af, then assume it's not and do research. An example of a single DC in...
by Van9018
Sat Aug 12, 2017 3:45 am
Forum: Beginner Basics
Topic: Mikrotik Blocking Inbound VoIP Calls
Replies: 4
Views: 1488

Re: Mikrotik Blocking Inbound VoIP Calls

Are you using load balancing? Are you registering to a company PBX behind a firewall or to a paid service? One way audio problems are often from NAT or PAT. In the SIP protocol, your phone will tell the PBX which port it's listening for inbound audio, and what ports it will be sending audio out, as ...
by Van9018
Sat Aug 12, 2017 3:12 am
Forum: Beginner Basics
Topic: DHCP not send for win7 clients
Replies: 2
Views: 352

Re: DHCP not send for win7 clients

Reboot the router. If problem persists, use Tools > Packet Sniffer to see if Win 7 client DHCP requests are making it to router, and if the router is replying.

Also check windows event log for things like IP conflict.
by Van9018
Sat Aug 12, 2017 3:09 am
Forum: SwOS
Topic: HEX PoE not for SwOS?
Replies: 2
Views: 715

Re: HEX PoE not for SwOS?

Are you trying to make the Hex POE act like a 5 port switch? That can be done through configurations.
by Van9018
Sat Aug 12, 2017 3:05 am
Forum: General
Topic: Honeypot with Mikrotik
Replies: 2
Views: 1801

Re: Honeypot with Mikrotik

A honeypot is just adding remote IPs to an address-list and denying every IP on that list from connecting to your port forwards. The remote IPs must meet some firewall criteria, such as attempting to create too many connections in a short period of time. Some sample firewall rules are: https://wiki....
by Van9018
Sat Aug 12, 2017 2:50 am
Forum: Beginner Basics
Topic: NAT issue : port 80 works, 443 does not
Replies: 7
Views: 4423

Re: NAT issue : port 80 works, 443 does not

Nope, you need to allow them somehow. The best way (in most cases) is the magic rule
Bloody hell, I just checked my rules on several routers. Default config for forward chain was allow established, allow related, drop invalid. Which is why I've never had to add a rule for NAT'd connections.
by Van9018
Sat Aug 12, 2017 1:57 am
Forum: General
Topic: Question about poe
Replies: 5
Views: 1129

Re: Question about poe

Both RB2011 and RB951 will output 12 watts when the input power is 24 volts, such as when using the included power supply.

Both these devices output 24v passive. It won't power any device that is expecting 48 volts 802.3af/at.
by Van9018
Sat Aug 12, 2017 1:32 am
Forum: Beginner Basics
Topic: NAT issue : port 80 works, 443 does not
Replies: 7
Views: 4423

Re: NAT issue : port 80 works, 443 does not

This setup looks correct. You don't need the filter rules to allow ports 80 and 443 as it's implied when you have NAT rules setup. Go to Tools > Torch. Torch will show you what packets are coming and going from what interfaces. In a working scenario, you should see packets destined to port 443 comin...
by Van9018
Sat Aug 12, 2017 1:22 am
Forum: General
Topic: Are packet marks supposed to stay on in the IPsec layer?
Replies: 4
Views: 852

Re: Are packet marks supposed to stay on in the IPsec layer?

I don't know if marks are supposed to stay when encrypted. I can see why not since the ESP packet may be a brand new packet. In this article: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Mangle scroll down to the property ipsec-policy: in | out, ipsec | none This looks interesting, but I don't ...
by Van9018
Sat Aug 12, 2017 12:41 am
Forum: General
Topic: a virus scanner on the router board
Replies: 14
Views: 5562

Re: a virus scanner on the router board

Do you have a Mikrotik firewall script that protects the user from this mallware? There is no router firewall rule that'll protect users from malware. Routers with AV built in often only do a signature based detection which has a low detection rate. Computer malware protection should be down on the...
by Van9018
Fri Aug 11, 2017 9:59 pm
Forum: Beginner Basics
Topic: use two ISP simulatenously
Replies: 10
Views: 4928

Re: use two ISP simulatenously

With PCC, if a client behind your router opens multiple connections to the same host, all connections will go out the same WAN. Where as N-th load balancing the multiple connections could be across both LANs. When using a website, a browser cookie is used to remember the session and thus you can use...
by Van9018
Tue Aug 08, 2017 2:08 am
Forum: Beginner Basics
Topic: use two ISP simulatenously
Replies: 10
Views: 4928

Re: use two ISP simulatenously

PCC load balancing is common: https://wiki.mikrotik.com/wiki/Manual:PCC
by Van9018
Thu Aug 03, 2017 1:05 am
Forum: General
Topic: High CPU on "networking" process
Replies: 6
Views: 2562

Re: High CPU on "networking" process

Tools > Torch may display useful information. A loop in the network can also cause high CPU as it floods the network.
by Van9018
Thu Aug 03, 2017 1:00 am
Forum: Beginner Basics
Topic: Multiple srcnat/static IPs per internal ip
Replies: 3
Views: 416

Re: Multiple srcnat/static IPs per internal ip

In Mikrotik you can mark a connection. Then you can apply a routing-mark to packets who belong to that connection. Then you can route based on routing-marks. These get set up under the mangle rules. Create a rule, when a SYN (new-connection) packet comes in the WAN, action=mark-connection and set co...
by Van9018
Wed Aug 02, 2017 6:49 pm
Forum: Beginner Basics
Topic: What can a mikrotik
Replies: 13
Views: 1504

Re: What can a mikrotik

Wouldn't the bulk of the traffic be going through just your switch, and not the router? So the Hex will be fine as your router, but doesn't help your LAN. If you have slowness when accessing SQL Server, I'd start looking at that server first..
by Van9018
Wed Aug 02, 2017 12:01 am
Forum: General
Topic: Setup Mikrotik as VPN Service to hide Public IP
Replies: 3
Views: 1223

Re: Setup Mikrotik as VPN Service to hide Public IP

It would work. Many VPNs with encryption may use a lot of CPU. Mikrotik supports AES hardware support BUT only for IPSec. SSTP, OpenVPN, etc will not use AES acceleration and will use the CPU. You may want to consider installing RouterOS on a computer/server for better performance and memory. Router...
by Van9018
Tue Aug 01, 2017 11:43 pm
Forum: Beginner Basics
Topic: What can a mikrotik
Replies: 13
Views: 1504

Re: What can a mikrotik

- Complete firewall, better than consumer devices - VPNs, site-to-site if you will connect another lab later - VPN for roadwarriors, support for SSTP and others. - Troubleshooting Tools, go to Tools menu in winbox. These are a huge help when there are anomalies in your network. - Snappy interface (I...
by Van9018
Tue Aug 01, 2017 11:32 pm
Forum: General
Topic: WAN interface usage is higher than LAN interface usage
Replies: 10
Views: 3547

Re: WAN interface usage is higher than LAN interface usage

An inbound queue can cause this. In the case of a single TCP connection, the sender will send packets as fast as it can until it detects packet loss. Then it'll slow it's transmission until the point where packets are not being lost. In the case of many short lived TCP connections, such as many inte...
by Van9018
Tue Aug 01, 2017 6:28 pm
Forum: General
Topic: DHCP and STATIC IP on the same interface
Replies: 5
Views: 1809

Re: DHCP and STATIC IP on the same interface

Ohhh.. Your dynamic IP and Static IP both have the same subnet. You'll have to use a script like ZeroByte says.

See the following link. A script can be called when a lease is added/changed/removed. You need atleast v6.39rc33
https://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Client
by Van9018
Tue Aug 01, 2017 12:28 pm
Forum: General
Topic: DHCP and STATIC IP on the same interface
Replies: 5
Views: 1809

Re: DHCP and STATIC IP on the same interface

Do both your 0.0.0.0/0 routes have the same distance? Set the static route distance to 2, in IP > DHCP Client, set distance to 1.
by Van9018
Tue Aug 01, 2017 2:08 am
Forum: SwOS
Topic: RB260GSP support VOIP
Replies: 3
Views: 1201

Re: RB260GSP support VOIP

The RB260GSP's PoE is 24v, it won't power Cisco phones. They don't support LLDP-MED. They support VoIP (as all switches would?) If DHCP Option 66 is used on data vlan and network is configured so data network devices can access provisioning, then out-of-the-box phones can auto-provision themselves w...
by Van9018
Sun Jul 30, 2017 9:31 pm
Forum: General
Topic: Block IP Ranges in SwitchOS
Replies: 4
Views: 651

Re: Block IP Ranges in SwitchOS

1. Go through all interfaces and set master-port=none 2. Go to Bridge, add bridge1 3. Click the Settings button. Select "Use IP-Firewall" 4. Go to Bridge > Ports, add all interfaces to bridge1 Now you should be able to use the IP > Firewall to filter IP ranges. By putting interfaces into a bridge in...
by Van9018
Wed Jul 26, 2017 4:31 am
Forum: General
Topic: Plz Help me
Replies: 4
Views: 732

Re: Plz Help me

When packets go out ether2, they need to take on ether2's pubic IP. 1. IP > Firewall > NAT, add masquerade rule for packets going out ether2. Same for ether1 (it probably exists already) At this point packets will still go out Ether1. So setup Mangle rules and routing. The mangle rule will mark pack...
by Van9018
Tue Jul 25, 2017 8:13 pm
Forum: General
Topic: Hot to get Multiple Public IP's on 1 interface?
Replies: 8
Views: 2741

Re: Hot to get Multiple Public IP's on 1 interface?

You can try creating multiple DHCP clients with different Client IDs. But the ISP DHCP server may just use MAC anyway and ignore client-id.
by Van9018
Tue Jul 25, 2017 2:08 am
Forum: General
Topic: [Solved] Several internet connections on a mikrotik
Replies: 9
Views: 1147

Re: [Solved] Several internet connections on a mikrotik

Each wan needs masquerade rule. Each wan needs a mangle rule: chain=forward, src-nat=192.168.?.0/24, action=mark-routing, new-routing-mark=WAN1 (or WAN2, etc) Each wan needs a routing rule with routing-mark configured. Solved. I bought another router. Not Mikrotik........ Which router did you go wit...
by Van9018
Tue Jul 25, 2017 1:47 am
Forum: General
Topic: Block Of IP Addresses
Replies: 6
Views: 1117

Re: Block Of IP Addresses

Follow this guide for one-to-one NAT:
https://wiki.mikrotik.com/wiki/How_to_l ... Local_ones
by Van9018
Mon Jul 24, 2017 1:41 am
Forum: Beginner Basics
Topic: New to MT - How to add rule allowing port through via wireless
Replies: 3
Views: 390

Re: New to MT - How to add rule allowing port through via wireless

Sounds like you're using the Mikrotik as just a switch with AP? Ports 2-5 and wifi are already bridged (so it's like a switch already). You wouldn't use ether1 in this case. If you already have a DHCP server on the network, and you forgot to turn off the DHCP server in the Mikrotik, then maybe somet...
by Van9018
Mon Jul 24, 2017 1:31 am
Forum: General
Topic: Minor issue with dual wan failover
Replies: 4
Views: 1007

Re: Minor issue with dual wan failover

When WAN1 goes down, I think the connections associated with WAN1 are reset/dropped, and thus all clients will have to re-establish their connections. When WAN1 comes back online, connections established out WAN2 DON'T get reset because WAN2 is still online. However the routing does in fact send pac...
by Van9018
Mon Jul 24, 2017 12:15 am
Forum: General
Topic: How to combine 3 WAN speed
Replies: 10
Views: 7672

Re: How to combine 3 WAN speed

Load Balancing: https://wiki.mikrotik.com/wiki/Manual:PCC But you can't split a connection like a single download across wans when using load balancing. If three WANs are from same ISP, call the ISP and ask if they support bonding. If you wish to have 16 mbps from one site to another site, and you h...
by Van9018
Wed Jul 19, 2017 12:08 am
Forum: General
Topic: Speed less than 20 Mbps
Replies: 5
Views: 1806

Re: Speed less than 20 Mbps

What are your wireless settings? I tested another cap lite this morning and at best it gave me 17 mbps. I've tried this and that, compared brands, I can't get the cap lites to break 25mbps. I'd love to figure this out!!
by Van9018
Tue Jul 18, 2017 11:49 pm
Forum: General
Topic: can I redirect https to my router?
Replies: 24
Views: 3980

Re: can I redirect https to my router?

I would never, ever accept a third-party root CA from anyone telling me that I had to install it on my computer in order to use their network Neither would I, and as the I.T. of a company I wouldn't ask guests or contractors to do so. But they would be expected to use the guest wifi where there wou...
by Van9018
Tue Jul 18, 2017 9:54 am
Forum: Beginner Basics
Topic: hex rb750 to hap ac lite
Replies: 2
Views: 441

Re: hex rb750 to hap ac lite

Plug Ether2 of the hap into the hex. Turn off DHCP Server on the hap Delete the default 192.168.88.1 IP (under IP > Addresses) add a DHCP Client for interface: bridge-local Now you have 1 LAN. If you plug ether1 of the hap into the hex, you end up with a sub-LAN and certain functions like printer di...
by Van9018
Tue Jul 18, 2017 9:49 am
Forum: General
Topic: Firewall Rule didn't properly work
Replies: 2
Views: 481

Re: Firewall Rule didn't properly work

What ports are you applying this filter on? Facebook and Youtube will both use HTTPS so you can't scan that traffic. At best you can drop DNS queries that contain certain texts. For packets going out the wan where the destination port is 53 and L7 filter applies, then drop the packet. Some clients m...
by Van9018
Tue Jul 18, 2017 9:39 am
Forum: Beginner Basics
Topic: How to add another WAN link
Replies: 2
Views: 370

Re: How to add another WAN link

Maybe these are a good place to start:

Failover WAN
https://wiki.mikrotik.com/wiki/Advanced ... _Scripting

A load balancing WAN:
https://wiki.mikrotik.com/wiki/Manual:PCC
by Van9018
Tue Jul 18, 2017 9:26 am
Forum: General
Topic: Does DHCP server check for address availability?
Replies: 7
Views: 1107

Re: Does DHCP server check for address availability?

Yes it does check! And it'll skip that IP. I tested this last month after I discovered that Microsoft DHCP Server doesn't check. If you suspect clients are giving themselves static IPs, you can look into setting the arp-mode to read-only on your interface. This means the Mikrotik will respond to all...
by Van9018
Tue Jul 18, 2017 2:36 am
Forum: General
Topic: can I redirect https to my router?
Replies: 24
Views: 3980

Re: can I redirect https to my router?

Mikrotik won't be the right choice for web content filtering. Other devices (Sonicwall? Fortigate?) have features where you can upload your own CA certificate, and install that CA cert on the internal computers. Now the router can generate certs on the fly and those certs will be trusted by the inte...
by Van9018
Mon Jul 17, 2017 4:10 am
Forum: Beginner Basics
Topic: My first mikrotik device
Replies: 5
Views: 566

Re: My first mikrotik device

ISPs in my region allow for 1 device to be connected. A second won't obtain an IP, and a new mac won't obtain a new IP until the old lease expires. Try cloning the mac of your Asus to your ether1. In winbox, go to Terminal and paste the following: /interface ethernet set ether1 mac-address=xxx (wher...
by Van9018
Mon Jul 17, 2017 4:03 am
Forum: General
Topic: Anyone else having this VPN issue?
Replies: 17
Views: 1803

Re: Anyone else having this VPN issue?

In IP > IPSec, SA tab, try flushing the SA's? I had an endpoint that was a Cisco. Sometimes Cisco was send a delete message and the Mikrotik would remove the active peer but leave the security associations in place. Then no traffic would happen. Try turning on logging for IPSec to see if the remote ...
by Van9018
Sun Jul 16, 2017 12:58 pm
Forum: General
Topic: Mikrotik x Cisco ASA - VPN IPSEC
Replies: 1
Views: 555

Re: Mikrotik x Cisco ASA - VPN IPSEC

Try turning on logging for ipsec, see if it tells you why it's mismatching.
by Van9018
Sun Jul 16, 2017 12:52 pm
Forum: Wireless Networking
Topic: public or campsite or marina wifi APs or hide many devices behind one MAC
Replies: 5
Views: 591

Re: public or campsite or marina wifi APs or hide many devices behind one MAC

What you say is correct! MACs need only be unique on the Layer 2 network. However as the Mikrotik can support many Layer 2 networks, it's probably computationally easier and faster to have a single ARP table across all Layer 2 networks. Because of the single arp table, you wouldn't be able to have a...
by Van9018
Sun Jul 16, 2017 1:40 am
Forum: General
Topic: NAT rules for local network
Replies: 5
Views: 1352

Re: NAT rules for local network

I don't understand what you mean by this? Using the DNS means that you always have to use the switch part so that they can see each other. When using Hairpin, all traffic for the FTP connection will go through the Mikrotik. In a scenario where the user's network looks like this: Modem ---> Mikrotik ...
by Van9018
Sat Jul 15, 2017 11:11 pm
Forum: General
Topic: NAT rules for local network
Replies: 5
Views: 1352

Re: NAT rules for local network

Or use DNS overrides. In IP > DNS, add a static dns entry to point your ftp url to the private IP of your ftp server.
by Van9018
Fri Jul 14, 2017 12:17 am
Forum: Scripting
Topic: Download IP List
Replies: 2
Views: 769

Re: Download IP List

by Van9018
Thu Jul 13, 2017 10:35 pm
Forum: General
Topic: Speed less than 20 Mbps
Replies: 5
Views: 1806

Re: Speed less than 20 Mbps

I've spent many hours trying to get better wifi speeds out of various Mikrotik products. I've never gotten anything better than 20mbps for 2.4 Ghz. My solution was to go with another brand for wifi, but I still use Mikrotik for Routing, VPNs, etc. Others have posted this same problem. I've followed ...
by Van9018
Thu Jul 13, 2017 10:19 pm
Forum: Beginner Basics
Topic: Allow team viewer only for specific IP
Replies: 6
Views: 6416

Re: Allow team viewer only for specific IP

I think I've got it.... In Team Viewer options, set "Incoming LAN Connections" to "Accept Exclusively". Your ID field now shows your IP instead of an ID. Team Viewer is not supposed to connect to Team Viewer servers now. If you don't trust it, use the L7 to kill *.teamviewer.com dns lookups. Now you...
by Van9018
Thu Jul 13, 2017 3:21 am
Forum: Beginner Basics
Topic: Firewall rules allowing specific ports outbound
Replies: 1
Views: 2500

Re: Firewall rules allowing specific ports outbound

It says "Outbound" firewall. By default Mikrotik doesn't have an outbound firewall. It's not common for a company network to have outbound firewall rules applied. Maybe banks and institutions with full time I.T. departments. You can read the rules under IP > Firewall, click the Filters tab. If one i...
by Van9018
Thu Jul 13, 2017 2:55 am
Forum: Beginner Basics
Topic: VPN is fast, but Internet traffic is slow
Replies: 8
Views: 1912

Re: VPN is fast, but Internet traffic is slow

When traffic is slow, does Tools > Profile show any processes with high CPU?
by Van9018
Thu Jul 13, 2017 2:53 am
Forum: General
Topic: cap Lite locking up? Dead?
Replies: 1
Views: 403

Re: cap Lite locking up? Dead?

There should be a reset button on it that'll reset it to factory default configurations. Then try connection eth2 to your laptop. Does it still lock up at some point? If not, you can do a firmware update. If it still locks up, then maybe a Net install to do a firmware update. After that... I'd deem ...
by Van9018
Thu Jul 13, 2017 2:49 am
Forum: Beginner Basics
Topic: Allow team viewer only for specific IP
Replies: 6
Views: 6416

Re: Allow team viewer only for specific IP

Team Viewer's knowledge base says team viewer has over 200 servers and are expanding. They won't publish a list of IPs so you'll have to update your list via 3rd party sources on a regular basis. TV will prefer port 5938, but fall back on tcp 443 and then tcp 80, so you can't block by port only. You...
by Van9018
Wed Jul 12, 2017 10:05 pm
Forum: Beginner Basics
Topic: DHCP server offering lease without success
Replies: 24
Views: 27544

Re: DHCP server offering lease without success

A duplicate client MAC could cause this. While it's failing, check the arp table on the Mikrotik. It's under Switch > Host, or Switch > FDB. It should show your PC's mac address as being down one of the interfaces. Tools > Packet Sniffer on the Mikrotik will also show if the Mikrotik is in fact actu...
by Van9018
Wed Jul 12, 2017 9:53 pm
Forum: Beginner Basics
Topic: Mikrotik - How to config same gateway wan and local?
Replies: 8
Views: 897

Re: Mikrotik - How to config same gateway wan and local?

Your default route 0.0.0.0 says to use 192.168.2.1 as gateway. I think the "reachable via ether1" means nothing, it's just friendly info for the tech to see. So it'll route to 192.168.2.1, that IP belongs to Local2. Now I think Local2 will put it back in the routing, where it'll get routed back to L...
by Van9018
Wed Jul 12, 2017 9:32 pm
Forum: Beginner Basics
Topic: IP leak from LAN to wan ?
Replies: 10
Views: 2006

Re: IP leak from LAN to wan ?

even creating a separate bridge group with only the wan port in.
Wan port should not be in a bridge, nor a slave to any other port. Goto IP > Firewall, NAT There should be 1 masquerade rule tied to the wan port (usually ether1).
by Van9018
Wed Jul 12, 2017 9:24 pm
Forum: General
Topic: RB1100Ahx2 Offering lease problem, and whiteout success
Replies: 2
Views: 561

Re: RB1100Ahx2 Offering lease problem, and whiteout success

- If you have a bridge, DHCP should be tied to the bridge instead of interface Use Tools > Packet Sniffer on the Mikrotik, and Wireshark on the PC. Do an IP renewal. With this you'll see if DHCP packets are being lost, and you'll see if the client is rejecting the offer. Or maybe you'll find a secon...
by Van9018
Wed Jul 12, 2017 9:18 pm
Forum: Beginner Basics
Topic: Mikrotik - How to config same gateway wan and local?
Replies: 8
Views: 897

Re: Mikrotik - How to config same gateway wan and local?

You can't have the same IP scheme for 2 interfaces. Change Local2 to 192.168.3.0/24 ( or change the WAN IP scheme )
by Van9018
Tue Jul 11, 2017 8:26 pm
Forum: General
Topic: Site to Site IPSec VPN stops passing traffic
Replies: 3
Views: 791

Re: Site to Site IPSec VPN stops passing traffic

It may be something about time outs, or 1 end kills the connection after some idle time. When the connection is dead (but still shows connected on both sides), use packet sniffer to capture IPSec packets. Also turn on logging for IPSec, maybe something useful will show in the logs. I did this with C...
by Van9018
Tue Jul 11, 2017 10:24 am
Forum: General
Topic: IPsec enchansments
Replies: 2
Views: 796

Re: IPsec enchansments

IPSec doesn't use ports like UDP and TCP do. So a connection is only defined by src-ip and dst-ip. The security associations are applied to a connection, which are used to decrypt the payload. This means there is no option for Mikrotik to create a connection identifier. However, if the IPSec connect...
by Van9018
Tue Jul 11, 2017 2:18 am
Forum: General
Topic: PCI Compliane CVE2003-0213 TopPop
Replies: 1
Views: 274

Re: PCI Compliane CVE2003-0213 TopPop

While that particular vulnerability was fixed, PPTP VPNs overall are considered less secure than alternatives. I don't foresee PCI Compliance wanting to make exceptions. Even PopTop's website recommends alternatives: http://poptop.sourceforge.net/dox/protocol-security.phtml IPSec, OpenVPN and SSTP a...
by Van9018
Tue Jul 11, 2017 1:48 am
Forum: General
Topic: install mikrotik as bridge
Replies: 4
Views: 496

Re: install mikrotik as bridge

Yes - in my scenario you'd be moving the Mikrotik from in front of the fortigate to behind the fortigate. If you want to have it in front of the fortigate (Fortigate --> Mikrotik --> Modem) Then look for an option in the fortigate called operation mode. Change it from Gateway/NAT to Router/Transpare...
by Van9018
Tue Jul 11, 2017 1:30 am
Forum: General
Topic: What is Google DNS doing here?
Replies: 9
Views: 1103

Re: What is Google DNS doing here?

Yes - Wireshark can read it.
by Van9018
Mon Jul 10, 2017 9:30 pm
Forum: Beginner Basics
Topic: Site-to-site VPN through NAT and firewall on one side
Replies: 1
Views: 533

Re: Site-to-site VPN through NAT and firewall on one side

I'd use IPSec as underlying tunnel, with NAT-T mode enabled. NAT-T uses UDP port 4500 to encapsulate the IPSec packets making them NAT friendly. The primary side can be the initiator, so you only need to set up port forwarding on the remote site. You can configure the policies so the IPSec tunnel is...
by Van9018
Mon Jul 10, 2017 9:19 pm
Forum: General
Topic: install mikrotik as bridge
Replies: 4
Views: 496

Re: install mikrotik as bridge

Put the Mikrotik bridge on the other side of the Fortigate. Fortigate --> Mikrotik (Port 2), then Mikrotik (Port 3) --> Switch Disable DHCP Server Edit port 3 interface, set master-interface to none Create bridge1 Add port 2 and port 3 to the bridge. Go to Bridge, click the settings button Enable "U...
by Van9018
Mon Jul 10, 2017 9:05 pm
Forum: General
Topic: What is Google DNS doing here?
Replies: 9
Views: 1103

Re: What is Google DNS doing here?

Use Tools > Packet Sniffer to view the content of the DNS queries. Or post the packet capture on this thread.
by Van9018
Mon Jul 10, 2017 8:34 pm
Forum: General
Topic: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON
Replies: 22
Views: 3688

Re: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON

Good to hear it worked!

Setting interfaces to 100 Full can also resolve frequent link up/downs when both endpoints are gigabit running through old Cat 5e cables. This sometimes happens in old buildings with Cat 5 and long cable runs.
by Van9018
Mon Jul 10, 2017 6:02 am
Forum: Beginner Basics
Topic: ISP assigned static IP - changing from DHCP remotely
Replies: 4
Views: 706

Re: ISP assigned static IP - changing from DHCP remotely

I think it has similar concepts to dual wan. To have both IPs work at the same time, the TCP connections coming in on the static IP needs to be marked. Outbound packets for that connection would need to be marked, and then a route added for packets with that route.
by Van9018
Mon Jul 10, 2017 5:52 am
Forum: General
Topic: Mark packets on one router so another one can use the marks?
Replies: 7
Views: 1305

Re: Mark packets on one router so another one can use the marks?

Maybe if Host 1 can have two IPs? Windows and linux both support this I think. Then you can mark packets that come into Router 1 from IP2 of Host 1, you can forward that packet to Router 2.
by Van9018
Mon Jul 10, 2017 5:39 am
Forum: Scripting
Topic: help with auto shutdown
Replies: 10
Views: 1975

Re: help with auto shutdown

Mikrotik devices are safe to loose power in normal operation mode. 3 times in the last 5 years a Mikrotik had issues after power outage for me. First time the static WAN IP was missing. Route was still there. Adding the WAN IP fixed it. Second time I guided a user through restoring the config from ...
by Van9018
Mon Jul 10, 2017 1:29 am
Forum: Scripting
Topic: Really? No No-Ip working script?
Replies: 8
Views: 2363

Re: Really? No No-Ip working script?

That looks like the script from the Mikrotik scripts page. It didn't for me neither, which is why I fell back on the one liner.
by Van9018
Mon Jul 10, 2017 1:25 am
Forum: General
Topic: random speed limitation
Replies: 3
Views: 386

Re: random speed limitation

I use auto-negotiation unless there is a problem. I've found auto-negotiation always works well with two gigabit end points. But if one or both are 100mbit, then it's possible the the auto-negotiation features are implemented slightly differently, and auto-negotiation may fail. With ROS version arou...
by Van9018
Mon Jul 10, 2017 1:18 am
Forum: General
Topic: DNS over VPN
Replies: 7
Views: 4979

Re: DNS over VPN

+1 for
I use that one a lot. Works well for me.
by Van9018
Sat Jul 08, 2017 12:17 am
Forum: Scripting
Topic: Really? No No-Ip working script?
Replies: 8
Views: 2363

Re: Really? No No-Ip working script?

The most basic script is to just send an update every minute. NoIP hasn't blocked me from sending so many updates. The \3F in the script below translates to a question mark. By excluding my IP from the host, NoIp will use the IP that sent the request. /tool fetch url=("http://dynupdate.no-ip.com/nic...
by Van9018
Fri Jul 07, 2017 6:25 am
Forum: Wireless Networking
Topic: Slow WiFi (Mikrotik WAP)
Replies: 31
Views: 18489

Re: Slow WiFi (Mikrotik WAP)

I stopped using Mikrotik for wifi as I've never gotten anything better than 25mbps (3MB/s) on 2.4Ghz. I switched to another brand for wifi APs and performance is better.
Lots of people have this issue and no solutions found yet.
viewtopic.php?f=7&t=122853
by Van9018
Fri Jul 07, 2017 6:04 am
Forum: General
Topic: random speed limitation
Replies: 3
Views: 386

Re: random speed limitation

In each interface you can view the status tab for bad packets and CRC errors. For the RB951-2n specifically, don't use port 5. In the few I implemented, port 5 always had dropped packets due to CRC errors. Check your wan interface to see if it's 100 FULL duplex, and not half duplex. Finally you can ...
by Van9018
Wed Jul 05, 2017 10:35 pm
Forum: Beginner Basics
Topic: How to isolate physical ports
Replies: 5
Views: 1729

Re: How to isolate physical ports

Yeah - Bridge > Ports is where you go.

For ports 3-5, edit the interface and set master-port to none. I'm not sure if it's required or not.
by Van9018
Wed Jul 05, 2017 4:51 am
Forum: Wireless Networking
Topic: Need advice
Replies: 3
Views: 377

Re: Need advice

Wired as much as possible. Fewer issues.
by Van9018
Wed Jul 05, 2017 3:31 am
Forum: Beginner Basics
Topic: Port Forwarding Partially works
Replies: 5
Views: 810

Re: Port Forwarding Partially works

I agree to consider DNS overrides as an alternative to hairpin NAT. I find it simpler.
by Van9018
Wed Jul 05, 2017 3:06 am
Forum: General
Topic: Firewall Connections Listed To Unconfigured IPs
Replies: 5
Views: 554

Re: Firewall Connections Listed To Unconfigured IPs

I don't think it matters what IPs are assigned and which are not. If a packet comes down the cable into your router and there are no firewall rules to stop it, then it'll get NAT'ed (if a rule exists) and routed. Even if a bogus packet with a private IP will get NAT'ed if a NAT rule is matched. Conn...
by Van9018
Wed Jul 05, 2017 2:51 am
Forum: General
Topic: Newly installed RB2011 loses its config
Replies: 6
Views: 765

Re: Newly installed RB2011 loses its config

It's not supposed to. Maybe it's defective? Tried another RB2011?
by Van9018
Wed Jul 05, 2017 2:27 am
Forum: Beginner Basics
Topic: How to isolate physical ports
Replies: 5
Views: 1729

Re: How to isolate physical ports

I found vlans in Mikrotik's to be more complicated than other switches. To wrap my head around it, I think of VLANs on a Mikrotik as just bridges. Think of VLAN interfaces as a device that adds vlan tags on egress and removes tags on ingress. A standard interface (eth1, eth2, etc) are always untagge...
by Van9018
Wed Jul 05, 2017 1:43 am
Forum: Beginner Basics
Topic: How to just open ports
Replies: 23
Views: 102757

Re: How to just open ports

You need to setup hairpin NAT https://wiki.mikrotik.com/wiki/Hairpin_NAT By default, when you are internal, you can't connect to your internal website via your external IP address. This is because when you connect to 31.5.xxx.xxx, the packets are redirected to your webserver without changing (NATing...
by Van9018
Wed Jul 05, 2017 1:26 am
Forum: General
Topic: Certificate renewal
Replies: 4
Views: 1731

Re: Certificate renewal

Don't think you can replace the certificate. But deleting and importing is easy enough? Scriptable too.
by Van9018
Wed Jul 05, 2017 12:30 am
Forum: General
Topic: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON
Replies: 22
Views: 3688

Re: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON

The screen changes when unchecking auto-negotiation. You then select your speed. TX and RX flow control is off. For me this was already set as off.
100full.png
by Van9018
Tue Jul 04, 2017 10:50 pm
Forum: Scripting
Topic: help with auto shutdown
Replies: 10
Views: 1975

Re: help with auto shutdown

if i used the script to auto shutdown the routerboard not shutdown? I think the shutdown command will cause the Mikrotik to unmount resources so it's in a safe state to unplug the power. You could buy an electrical timer. Shutdown at 2:45, timer cuts power at 2:46, then the timer turns power back o...
by Van9018
Tue Jul 04, 2017 10:12 pm
Forum: General
Topic: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON
Replies: 22
Views: 3688

Re: RE: Re: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON

I can't set the ethernet speed on the Huawei, it doesn't have such thing in the menu and I can't even access the menu being set in bridge mode by the ISP. All other devices work just fine, including cheap routers so I really think this is something related strictly to ROS and Mikrotik. I also could...
by Van9018
Sat Jul 01, 2017 12:20 am
Forum: General
Topic: Make an ip act like another
Replies: 2
Views: 330

Re: Make an ip act like another

Phones may require the ability to detect the printer on the network (like air print). In order the search the network, the printer and phone must be on the same broadcast domain (meaning the same LAN). My solution to this problem was to keep the wlan and lan in a bridge with 1 subnet. Then use Bridg...
by Van9018
Sat Jul 01, 2017 12:05 am
Forum: General
Topic: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON
Replies: 22
Views: 3688

Re: Half duplex 100 only and link duplex mismatch on hAP Lite and EPON

The auto-negotiation standard grew to quickly. Vendors may have different interpretations on how 10/100 auto-negotiation should work. These interpretation issues are rare in gigabit links. Without auto-negotiation, link speed can still be determined but duplex cannot. If you set both devices to 100M...
by Van9018
Thu Jun 29, 2017 11:02 pm
Forum: General
Topic: Wixbox.exe error
Replies: 7
Views: 732

Re: Wixbox.exe error

In the problematic windows profile, go to: C:\Users\<USERNAME>\AppData\Roaming\Mikrotik\Winbox Close Winbox if open. Create a folder called Backup, move all the folders in the backup folder. Delete registry key HKCU\Software\Mikrotik Run winbox again, does it work now? If not, use procmon from syste...
by Van9018
Thu Jun 29, 2017 10:53 pm
Forum: General
Topic: How to block Webcam Internet Access by MAC Address
Replies: 2
Views: 512

Re: How to block Webcam Internet Access by MAC Address

I would think using src mac address would work. But instead of specifying the dst-address as not 192.168.2.0/24 I would use out-interface=ether1 Or put the camera on it's own interface and block that interface from the internet. in-interface=ether-x, out-interface=ether-1 You could also deny the web...
by Van9018
Thu Jun 29, 2017 10:29 pm
Forum: General
Topic: Winbox: can log in from one computer but not another
Replies: 3
Views: 371

Re: Winbox: can log in from one computer but not another

username is case sensitive. I spent an hour learning this.
by Van9018
Thu Jun 29, 2017 10:24 pm
Forum: General
Topic: Deauth
Replies: 1
Views: 568

Re: Deauth

A deauth is when the station (the mikrotik) tries to kick a client off the wifi, probably from too much data loss from a weak signal, or noisy frequency. If the client doesn't receive the deauth, it may try to continue communicating. At this point the Mikrotik may see the device as unknown since the...
by Van9018
Thu Jun 29, 2017 10:14 pm
Forum: General
Topic: Router/switch with poe to connect IPcam or AP
Replies: 1
Views: 274

Re: Router/switch with poe to connect IPcam or AP

Your IPCam and AP is probably 802.3af/at (which is a standard). Many Mikrotik products are PoE but only output at 24v, so not 8.2.3af/at. The Hex Poe router supports 802.3af but comes with a 24 volt power supply, so you have to buy the 48POW power supply separately. The RBGPOE is a power injector. I...
by Van9018
Thu Jun 29, 2017 9:56 pm
Forum: General
Topic: Unable to run two site to site GRE Tunnels on Mikrotik RB-750 Board
Replies: 1
Views: 374

Re: Unable to run two site to site GRE Tunnels on Mikrotik RB-750 Board

Your issue could be a routing problem. What are the routes when both GRE tunnels are connected?
And if you disable tunnel A, does tunnel B work as expected? Only when both tunnels are connected?
by Van9018
Wed Jun 28, 2017 12:18 am
Forum: General
Topic: Connection tracking: tcp established timeout [SOLVED]
Replies: 2
Views: 1490

Re: Connection tracking: tcp established timeout [SOLVED]

Changing the TCP connection timeout could have a negative impact on other things. It's really supposed to be the end points that have a keep-alive mechanism. VoIP clients are supposed to register themselves with the server every x minutes. Often it's 2 minutes. I'd look for those settings in the voi...
by Van9018
Tue Jun 27, 2017 11:33 pm
Forum: Wireless Networking
Topic: mAP lite powered by RB960PGS (hEX PoE) - 802.3af?
Replies: 2
Views: 851

Re: mAP lite powered by RB960PGS (hEX PoE) - 802.3af?

I think the mAP can support power in via pins 1,2,3,6 (Mode A) or 4,5,7,8 (Mode B). And I think the hEX can only send power out via pins 4,5,7,8 (Mode B). The description of the hEX PoE says "It can power at/af mode B (4,5+)(7,8-) compatible devices, if 48-57 input voltage is used." It doesn't say a...
by Van9018
Tue Jun 27, 2017 11:52 am
Forum: Wireless Networking
Topic: Failure to subsequently reconnect
Replies: 2
Views: 320

Re: Failure to subsequently reconnect

This happens to me too, but not consistently. Once in awhile a device won't reconnect until I clear that SSID from cache and reconnect. I didn't look into it. Try turning on extra logs for wifi and see what the logs show. I've given up on Mikrotik for office wireless solutions.
by Van9018
Tue Jun 27, 2017 11:48 am
Forum: Beginner Basics
Topic: Blocking Three IP/Mac Addresses
Replies: 2
Views: 430

Re: Blocking Three IP/Mac Addresses

If you're not concerned about security and just want a simple way to block a non-malicious user from eating bandwidth, you can create a DHCP reservation for these 3 MACs and assign them an invalid IP. You can also find the rogue devices by looking at arp tables which will tell you which port the mac...
by Van9018
Tue Jun 27, 2017 11:35 am
Forum: Beginner Basics
Topic: Ping/transmision between networks
Replies: 1
Views: 231

Re: Ping/transmision between networks

Firewall should block by interface, not protocol and port.

When packets come in Ether9 and not going out Ether1, drop the packet Same for Ether10.
When packets come in Bridge1 and not going out Ether1, drop the packet.
by Van9018
Tue Jun 27, 2017 11:29 am
Forum: Beginner Basics
Topic: Nat Rule - FTP Filezilla server
Replies: 5
Views: 5651

Re: Nat Rule - FTP Filezilla server

If you use plain FTP (no encryption) then you only need to port forward tcp 21. The FTP Helper service will dynamically forward inbound ports, and also translate your private IP to public. If you use encrypted FTP, you have to set up port forwarding for the destination ports and also define these po...
by Van9018
Mon Jun 26, 2017 10:04 pm
Forum: General
Topic: Why Mikrotik ???
Replies: 32
Views: 6266

Re: Why Mikrotik ???

- Consistent gui across products. Cisco's gui varies - Winbox is a very snappy and portable exe, quite nice to work with. Some cisco products require java and a clunky software install just to do port forwarding. - Tools: Huge set of tools including pcap capture. I wouldn't bother using Cisco's sad ...
by Van9018
Sun Jun 25, 2017 11:55 pm
Forum: Beginner Basics
Topic: Unresponsive router
Replies: 2
Views: 297

Re: Unresponsive router

by Van9018
Sun Jun 25, 2017 11:50 pm
Forum: General
Topic: Mikrotik is unable to open ports for port forwarding [SOLVED]
Replies: 5
Views: 1900

Re: Mikrotik is unable to open ports for port forwarding [SOLVED]

For UPNP, turn it on under IP > UPNP
Looks like Uber conference uses SIP/VoIP. There is no port forwarding to setup for that.
Uber conference website says to disable SIP ALG. I'd first try it with it enabled... Then try turning it off with UPNP enabled.
by Van9018
Sun Jun 25, 2017 9:36 pm
Forum: General
Topic: nat problem between clients
Replies: 16
Views: 1510

Re: nat problem between clients

It looks like you have 1 WAN and LANs.
There is no NAT required between LANs. No 0.0.0.0/0 routes required to route from 1 lan to the next.

If you only have 1 WAN, then you should only have 1 0.0.0.0/0 route.
by Van9018
Sun Jun 25, 2017 12:46 am
Forum: Beginner Basics
Topic: Vpn server in mikrotic pc
Replies: 3
Views: 461

Re: Vpn server in mikrotic pc

SSTP VPN will likely get around firewalls at airports, etc.
https://wiki.mikrotik.com/wiki/SSTP_step-by-step
And an SSTP client is built into Windows.
by Van9018
Sun Jun 25, 2017 12:44 am
Forum: General
Topic: SSTP between 2 Mikrotik issue with " verify server certificate " at client
Replies: 1
Views: 487

Re: SSTP between 2 Mikrotik issue with " verify server certificate " at client

Use "Verify Server Address from Certificate" instead of "Verify Certificate". Otherwise the Mikrotik will want to check the server's certificate against a certificate revocation list or online service. Both of which you may not have defined in your CA certificate if you're using self signed certific...
by Van9018
Sun Jun 25, 2017 12:25 am
Forum: Wireless Networking
Topic: Wirelles can over 25mb of Download
Replies: 18
Views: 3677

Re: Wirelles can over 25mb of Download

My Config: From the default out-of-box config, I change SSID in wlan1 and in default security profile, I set Auth types to WPA-PSK, WPA2-PSK, aes ccm and I set the pre shared key. Thats all. To troubleshoot the slow performance, I I tried changing band to 2Ghz-n only, freqency and channel width. All...
by Van9018
Fri Jun 23, 2017 10:08 am
Forum: Beginner Basics
Topic: Mikrotik as Trasparent Router
Replies: 2
Views: 407

Re: Mikrotik as Trasparent Router

Sounds like you want a switch. The Mikrotik can be configured as such. IP > Interface, go through ether2 - ether5, set master port to ether1. IP > Bridge > Ports. Remove ether2 and add ether1 to bridge-local IP > DHCP Server, delete the entry IP > Address, delete the default 192.168.88.0 entry IP > ...
by Van9018
Fri Jun 23, 2017 10:02 am
Forum: Wireless Networking
Topic: Wirelles can over 25mb of Download
Replies: 18
Views: 3677

Re: Wirelles can over 25mb of Download

I've sold a lot of hAP lites. None of them get more than 25 mbps. I bought a $250 Mikrotik with 5Ghz AC. It maxes out at 40 mbps. I spent time testing and troubleshooting but was never to make it work faster. Now I buy DLink DIR-822 and am able to max out client's 150 mbps internet connection (using...
by Van9018
Wed Jun 21, 2017 8:42 am
Forum: Beginner Basics
Topic: Allow 2 users from same mac address
Replies: 2
Views: 492

Re: Allow 2 users from same mac address

Duplicate mac addresses are not allowed on the same Layer2 network. One of them will need to change their mac address. If you backup 1 Mikrotik, the mac addresses of the interfaces are backed up too. If you restore that config to a different Mikrotik, the mac addresses are applied to the new device....
by Van9018
Wed Jun 21, 2017 8:26 am
Forum: General
Topic: Scan but no ARP?
Replies: 2
Views: 680

Re: Scan but no ARP?

There are two arp tables. IP > ARP are the arp resolutions that the RouterOS needs to communicate with hosts. Entries get added here when: - A host sends packet outside of the LAN (ie: to the internet) - A device communicates with the Mikrotik (ie: if the Mikrotik is the DNS server on the LAN) - If ...
by Van9018
Wed Jun 21, 2017 8:04 am
Forum: Beginner Basics
Topic: Very weird issue about RouterOS and MS domain, please help
Replies: 14
Views: 1067

Re: Very weird issue about RouterOS and MS domain, please help

The Mikrotik can still be DHCP but would have to give out IP of MS DNS. Your previous router must've had some support for SRV records, whereas Mikrotik offers only basic DNS functionality.

In a Windows Domain network, it's common for the MS Server to be DHCP and DNS.
by Van9018
Tue Jun 20, 2017 8:25 am
Forum: Beginner Basics
Topic: Very weird issue about RouterOS and MS domain, please help
Replies: 14
Views: 1067

Re: Very weird issue about RouterOS and MS domain, please help

These issues happening on the LAN? (AD and workstations on same LAN) If you did not turn off DHCP on the Mikrotik, then your MS DHCP server will disable itself and allow the Mikrotik to give out IPs (and the default DNS). On a workstation you can't join to the domain, go to command prompt. nslookup ...
by Van9018
Tue Jun 20, 2017 8:13 am
Forum: General
Topic: Netbios vs bridge
Replies: 7
Views: 1978

Re: Netbios vs bridge

Are you using NetBios over NBF? Probably not if you have any computers newer than XP. Edit the properties for IPv4, go to Advanced > WINS. Enable NetBios over TCP/IP on both a workstation and server. Does it work then? Use Winbox > Tools > Packet Sniffer, try resolving a hostname and then post the c...
by Van9018
Fri Jun 16, 2017 10:37 pm
Forum: Beginner Basics
Topic: Set up hAP Lite as a switch with wifi
Replies: 5
Views: 2564

Re: Set up hAP Lite as a switch with wifi

VPN is an option for remote management and most will argue a VPN is much more secure for remote management.

I expose Winbox ports to the internet but then always use a firewall so only my office can connect to client Mikrotiks.
by Van9018
Fri Jun 16, 2017 10:17 pm
Forum: Beginner Basics
Topic: Multiple OVPN Server
Replies: 3
Views: 867

Re: Multiple OVPN Server

I don't think there is an option for a 2nd OVPN server instance. But since the address pool gets specified to a profile, and profile to a user, then each user could potentially have it's own address pool. So in that way, you could have two tunnels with two different IP ranges. OVPN SERVER1 ---> User...
by Van9018
Wed Jun 14, 2017 11:11 pm
Forum: Beginner Basics
Topic: Site to Site IpSec Tunnel
Replies: 23
Views: 28419

Re: Site to Site IpSec Tunnel

Policies and encryption options must match. At least one side must be an initiator. Don't forget Firewall rules! For filter rules, add rule in INPUT chain. Allow UDP 500 (for IKEv2). Add another rule, allow ESP. On both sides, you need to use Tunnel mode. Do not use NAT-T if both sides are not behin...
by Van9018
Wed Jun 14, 2017 10:54 pm
Forum: Beginner Basics
Topic: Port forwarding not working
Replies: 4
Views: 1027

Re: Port forwarding not working

In Winbox, check out Tools > Torch

This tool will show if your inbound packets are atleast making it to your wan interface even if the ports are firewalled.
by Van9018
Wed Jun 14, 2017 10:48 pm
Forum: Beginner Basics
Topic: Multiple OVPN Server
Replies: 3
Views: 867

Re: Multiple OVPN Server

You can specify a profile per user. I think this is supposed to override the profile defined in the OVPN Server settings.
by Van9018
Wed Jun 14, 2017 10:35 pm
Forum: Beginner Basics
Topic: Set up hAP Lite as a switch with wifi
Replies: 5
Views: 2564

Re: Set up hAP Lite as a switch with wifi

Sounds close, but only put wlan1 and ether1 in the same bridge. Then set the master port to ether1 for ether2 through ether5. Delete DHCP Server on bridge1. Delete DHCP client on ether1. Delete IP addresses from IP > Addresses. Delete firewall rules, and nat rule (the masquerade rule on ether1). For...
by Van9018
Wed Jun 14, 2017 10:28 pm
Forum: General
Topic: Problem with cable or what?
Replies: 3
Views: 713

Re: Problem with cable or what?

I'd bet on a bad cable. Easy enough to try another cable between the two devices. Or basic cable tester will tell you if wires are mismatched, shorted, broken, etc. The ethernet dialog in winbox will say what speeds and duplexes were advertised. In a working environment, it should show a few entries...
by Van9018
Fri Jun 09, 2017 11:03 pm
Forum: General
Topic: Forwarding source dhcp server through another interface.
Replies: 5
Views: 679

Re: Forwarding source dhcp server through another interface.

The quick way would be to disable the DHCP service on the Mikrotik and plug the lan into ether2, not ether1. That would be enough to do what you want. Or you can go the extra mile and turn the Mikrotik into a switch with an IP. IP > Interface, go through ether2 - ether5, set master port to ether1. I...
by Van9018
Fri Jun 09, 2017 10:49 pm
Forum: Beginner Basics
Topic: Router kill switch - vpn
Replies: 6
Views: 1365

Re: Router kill switch - vpn

I believe that's correct. Test it.. Check whatsmyip.org to see if you have the IP from the VPN provider. Disable vpn client, which will cause traffic to go out WAN. Then enable filter rule. Traffic should stop. Re-enable vpn client and then internet should work again, going through vpn.
by Van9018
Tue May 30, 2017 9:29 am
Forum: Beginner Basics
Topic: LAN to LAN NAtting
Replies: 6
Views: 1122

Re: LAN to LAN NAtting

I can't see how it'll work with a dynamic IP on your end. You may have to use static or DHCP reserved. Here is the packet flow diagram: https://wiki.mikrotik.com/wiki/Manual:Packet_Flow#IPsec_encryption You'll notice packets going out to 192.168.11.242 will actually go out your ether1-gateway interf...
by Van9018
Wed May 24, 2017 6:55 am
Forum: General
Topic: A problem connecting to PPTP VPN
Replies: 2
Views: 416

Re: A problem connecting to PPTP VPN

The PPTP server should have two firewall filter rules. Chain=Input, in-interface=wan1, proto=tcp, port=1723, action=accept Chain=Input, in-interface=wan1, proto=gre, action=accept Since PPTP works with the GRE protocol, it's easy for hotspots like airports to block PPTP connections. Some home based ...
by Van9018
Wed May 24, 2017 6:49 am
Forum: Beginner Basics
Topic: Mikrotik as Hub
Replies: 3
Views: 1268

Re: Mikrotik as Hub

You need a bridge. Add the master ports to the bridge (so likely just ether1 and ether2, ether3 to ether5 are probably a slave to ether2 and thus already switched with them.) Remove DHCP client from any ether port. Remove DHCP Server from any ether port. Remove IP Address from any ether port. Option...
by Van9018
Fri May 19, 2017 1:06 am
Forum: Beginner Basics
Topic: Can't connect to remote SMB v2/v3 server. SMB v1 works.
Replies: 8
Views: 4696

Re: Can't connect to remote SMB v2/v3 server. SMB v1 works.

SMBv1-v3 use the same TCP port 445 I think. If SMBv1 works, then you must have port forwarding set up correctly, and using an IP or FQDN to connect (like \\host.domain.local\share) The Mikrotik router won't be concerned with the content or protocols used. Your issue probably lies elsewhere. On Windo...
by Van9018
Fri May 19, 2017 12:46 am
Forum: General
Topic: Wireless Speed Slow
Replies: 3
Views: 1634

Re: Wireless Speed Slow

I have sold about 30 Mikrotiks (same model as yours) to various clients. All of mine only get 8-20 mbps, even when I was 4 feet under it. Then I purchased a $250 5Ghz Mikrotik with 2 antennas and it only gets 20-40Mbps when I'm 5 feet away from it. I've since been disabling the wifi in the Mikrotiks...
by Van9018
Tue May 02, 2017 5:59 am
Forum: Beginner Basics
Topic: Router kill switch - vpn
Replies: 6
Views: 1365

Re: Router kill switch - vpn

Under IP > Firewall > Filter, add a rule. Chain=Forward. Out Interface=WAN, Action=Drop Then drag and drop the rule to the top of the list. When traffic originates from the router, the firewall rules in the OUTPUT chain are applied. When traffic is destined to the router (meaning it has the WAN inte...
by Van9018
Tue Apr 25, 2017 11:24 pm
Forum: Beginner Basics
Topic: DNS in site to site VPN tunnel
Replies: 1
Views: 871

Re: DNS in site to site VPN tunnel

I don't know why the second DNS doesn't work for you. But an alternate config that I use: - 2nd site uses Mikrotik for DNS - 2nd site Mikrotik has Layer7 firewall rule to redirect DNS queries to 192.168.0.2 when the query ends with .company.local Go to IP > Firewall, Layer7 Protocol. Create an entry...
by Van9018
Tue Apr 25, 2017 10:28 pm
Forum: Beginner Basics
Topic: Router kill switch - vpn
Replies: 6
Views: 1365

Re: Router kill switch - vpn

You can add a firewall rule to block all packets outbound the WAN interface in the FORWARD chain. The FORWARD chain only applies to packets going through the router, not packets that originate from the router which means your VPN Client on the router will still work.

Move that rule to the top.
by Van9018
Wed Apr 19, 2017 3:54 am
Forum: General
Topic: Mikrotik Ipsec VPN tunnel problem
Replies: 15
Views: 6405

Re: Mikrotik Ipsec VPN tunnel problem

Turning on Logging can help. System > Logging, add topics: IPSEC

In IP > IPSec, Installed SAs you should see two lines indicating a tunnel was successful. If there are no lines, then check your config again. Or consult the logs for a helpful message.
by Van9018
Wed Apr 19, 2017 3:51 am
Forum: Beginner Basics
Topic: Please help with port forwarding!
Replies: 21
Views: 3056

Re: Please help with port forwarding!

Has this worked with other routers? ISPs in my region block inbound ports 80 and 22 to protect their residential customers from being hacked. Only way to get these ports unblocked by our ISPs is to subscribe to a business internet plan for an extra 20% per month. Run Tools > Torch It'll show if the ...
by Van9018
Wed Apr 19, 2017 3:02 am
Forum: General
Topic: Site to Site IP Sec VPN allow only http traffic
Replies: 3
Views: 406

Re: Site to Site IP Sec VPN allow only http traffic

IPSec doesn't create an interface. See the "IPSec Encryption" and "IPSec Decryption" packet flow diagrams in this link: https://wiki.mikrotik.com/wiki/Manual:Packet_Flow#IPsec_encryption For inbound packets, I believe you'd set up a forward rule in the filters. The packet diagram shows that an inbou...
by Van9018
Wed Apr 19, 2017 2:42 am
Forum: Beginner Basics
Topic: DNS for PPTP clients
Replies: 9
Views: 4850

Re: DNS for PPTP clients

The DNS part will only work with FQDN. You should be able to use WINS, and set the IP of the WINS server in the DHCP. I think you'd only be able to have 1 WINS server.
by Van9018
Wed Apr 19, 2017 2:38 am
Forum: General
Topic: IPSec
Replies: 5
Views: 930

Re: IPSec


My issue is the VPN works for about 30 minutes then stop transmitting data.
I checked my settings. The lifetime is different on my Sonicwall and Mikrotik. My dead peer detection is disabled on the Mikrotik, and Keep-Alive is disabled on the Sonicwall.
by Van9018
Thu Apr 13, 2017 7:11 pm
Forum: General
Topic: TOOL FETCH question
Replies: 1
Views: 426

Re: TOOL FETCH question

You could use a Layer 7 firewall rule. When you're requesting http://domain.com/otherfile.zip it can mark the packets with a routing mark, then you can route out WAN2
by Van9018
Tue Apr 11, 2017 10:13 pm
Forum: General
Topic: VPN to LAN access
Replies: 1
Views: 321

Re: VPN to LAN access

It's not a bridge you need, but a route on your iPhone to send 192.168.1.0/24 packets over the VPN. However this will also conflict with the local network you iPhone is connected. Options: 1. Change home IP subnet 2. Set iPhone to send ALL traffic over the VPN. Then your iPhone will connect to your ...
by Van9018
Tue Apr 11, 2017 10:02 pm
Forum: General
Topic: Layer7 Protocol filter doesn't work right
Replies: 6
Views: 1899

Re: Layer7 Protocol filter doesn't work right

The layer 7 firewall won't work for encrypted https connections. You may spend a lot of time on this and not get a satisfactory result. Your best bet would be to find a different device that's designed to do content filtering. Fortinet and Sonicwall maybe. With Mikrotik, best you may get is applying...
by Van9018
Tue Apr 11, 2017 9:46 pm
Forum: Beginner Basics
Topic: Winbox connect to MAC
Replies: 14
Views: 5437

Re: Winbox connect to MAC

I've had this issue on one device. IP went to 0.0.0.0, couldn't connect by MAC on lan. Hard reset and reconfigure worked, but later on the same day it went back to 0.0.0.0. I replaced it after the 2nd time. Mine wasn't an LHG5, it was a Hex Lite. I never tried a firmware update, felt like a hardware...
by Van9018
Tue Apr 11, 2017 9:36 pm
Forum: Beginner Basics
Topic: DNS for PPTP clients
Replies: 9
Views: 4850

Re: DNS for PPTP clients

In the DNS static entry, you should specify the FQDN, ie: host.domain.local One the client's PPTP suffix includes your domain name, then it should work. ie: domain.local If it doesn't work, use nslookup on Windows, set server to the IP of your Mikrotik and do a query. If there is no response from th...
by Van9018
Tue Mar 28, 2017 10:56 pm
Forum: Wireless Networking
Topic: I need way to find loop
Replies: 2
Views: 2368

Re: I need way to find loop

Enable Loop Protect, find which interface gets disabled due to loop, follow the cable from that interface.
https://wiki.mikrotik.com/wiki/Manual:Loop_Protect
by Van9018
Tue Mar 28, 2017 10:35 pm
Forum: General
Topic: IPSec
Replies: 5
Views: 930

Re: IPSec

Probably. I've had success with connecting Mikrotik to Cisco and SonicWall. IPSec is a standard so it should work. I found that I had to learn a bunch about IPSec before I was able to get Mikrotik to work with Sonicwall.
by Van9018
Tue Mar 28, 2017 9:37 pm
Forum: General
Topic: PPTP server stops accepting connections after a few days, IPSEC works fine all of the time
Replies: 3
Views: 606

Re: PPTP server stops accepting connections after a few days, IPSEC works fine all of the time

I have 6.37.1 but I use SSTP for site-to-site without any issues. Mikrotik will probably want you to try the latest packages before submitting an issue to their support. Also turn on logging for PPTP, see if it says anything interesting. a convenient work around could be to set the routers to reboot...
by Van9018
Fri Mar 24, 2017 1:06 am
Forum: Beginner Basics
Topic: VPN SITE-TO-SITE WITH 2 LINKS INTERNET
Replies: 1
Views: 359

Re: VPN SITE-TO-SITE WITH 2 LINKS INTERNET

What VPN will you use? IPSec is best choice for site-to-site. Then change your default route to that of the bridge-local IP on the VPN server.
You may have to set up a special route so the actual IPSec packets don't try and go over the VPN..
by Van9018
Fri Mar 24, 2017 1:02 am
Forum: General
Topic: PPTP server stops accepting connections after a few days, IPSEC works fine all of the time
Replies: 3
Views: 606

Re: PPTP server stops accepting connections after a few days, IPSEC works fine all of the time

First upgrade to latest firmware. If problem persists you can use Tools > Torch to confirm your incoming PPTP packets are making it to your WAN. Then file a bug report with support@mikrotik.com (also send rtf support file from your device). - Two clients behind the same public IP can't connect to yo...
by Van9018
Wed Mar 22, 2017 5:32 am
Forum: General
Topic: vpn pptp
Replies: 2
Views: 499

Re: vpn pptp

It'll work with VPN. The VPN needs a different subnet. Then establish a site-to-site VPN connection, but of course nothing will flow over that site-to-site connection because of the LAN subnet conflict. Once you get the site-to-site VPN working, you'll need a route for each specific IP address that ...
by Van9018
Wed Mar 22, 2017 5:12 am
Forum: General
Topic: Can't login via winbox
Replies: 6
Views: 1569

Re: Can't login via winbox

Default firewall config is to deny remote administration. Add an INPUT filter rule in IP > Firewall. Inbound connections on ether1-gateway on port 8291 should be accepted. Place this rule at the top of the list in the firewall rules. For better security, consider using a VPN to administer your devic...
by Van9018
Wed Mar 22, 2017 5:07 am
Forum: General
Topic: Clients IP
Replies: 2
Views: 388

Re: Clients IP

You running Torch on your WAN interface? Mine shows the IP address of the wan public IP. In IP > Firewall > NAT you should have a masquerade rule for your wan interface. This is the out-of-box config and if your internet works, then the masquerade rule must be there. If you're using IPSec, the priva...
by Van9018
Wed Mar 22, 2017 5:02 am
Forum: General
Topic: Mikrotik VPN behind firewall?
Replies: 4
Views: 747

Re: Mikrotik VPN behind firewall?

Pay the $6? It'll be the most reliable way. I can't think of a better way, VPN Services will cost money, probably more than $6/month. The solution you found means you have to trust ngrok as they also have access to your LAN.
by Van9018
Wed Mar 22, 2017 4:22 am
Forum: General
Topic: Best VPN
Replies: 23
Views: 12945

Re: Best VPN

Both IPSec and SSTP do not require both sides to have a static IP. For IPSec you'll have to use the NAT-T option so IPSec packets are wrapped in a UDP packet. In my experiences, IPSec is more tolerant of network issues. I use SSTP for site-to-site as well but then I have to use a script on both rout...
by Van9018
Wed Mar 22, 2017 4:04 am
Forum: Beginner Basics
Topic: DHCP,
Replies: 6
Views: 644

Re: DHCP,

The telnet attacks are from the wan. Check your firewall rules, you should have a default deny rule for inbound connections. Then only open ports as necessary. You do NOT need filter rules to allow incoming connections for ports that are forwarded with dst-nat. The PC obtained an IP not from either ...
by Van9018
Wed Mar 22, 2017 3:57 am
Forum: General
Topic: Possible security breach
Replies: 12
Views: 4931

Re: Possible security breach

Also check firewall, you should have a default deny rule for inbound connections on the WAN. Consider not allowing router admin access from WAN. Don't leave the default admin password as nothing, malware inside the network can log into the router and configure whatever it wants.
by Van9018
Wed Mar 22, 2017 3:47 am
Forum: Wireless Networking
Topic: Sniffing WiFi traffic
Replies: 2
Views: 933

Re: Sniffing WiFi traffic

Tools to trouble shoot are Tools > Torch and Tools > Packet sniffer. Torch temporarily shows what interfaces packets are coming and going. In the wireless interface there is an option called "Default Forward". When this is NOT enabled, wifi devices cannot communicate with each other. Is it checked? ...
by Van9018
Wed Mar 22, 2017 3:37 am
Forum: General
Topic: Internet Dies When Downloading a File
Replies: 2
Views: 360

Re: Internet Dies When Downloading a File

Check Tools > Profile (this shows the cpu usage of various processes). Is the CPU maxed out? Packets get dropped badly if the CPU is maxed out. The encryption/decryption process may be using up the CPU.
by Van9018
Wed Mar 22, 2017 3:35 am
Forum: Beginner Basics
Topic: Strange behaviour on IPSEC connection
Replies: 1
Views: 269

Re: Strange behaviour on IPSEC connection

Track the packets of the RDP connection attempt with Tools > Torch and find out where the packet gets lost.

Check firewall of windows, maybe remote desktop is only allowed for local subnet.
by Van9018
Thu Mar 16, 2017 11:20 pm
Forum: Beginner Basics
Topic: PPTP vpn to Windows server inside my network
Replies: 10
Views: 3968

Re: PPTP vpn to Windows server inside my network

To forward PPTP into a Windows PPTP Server: - Forward TCP port 1723 (dst-nat chain) to server IP - Forward GRE packets to server IP. GRE is an IP Protocol, alternative to TCP. - Input Filters have no effect on packets forwarding through your router. Adding the input filter rule in the firewall is on...
by Van9018
Thu Mar 16, 2017 11:14 pm
Forum: Beginner Basics
Topic: dst-nat in NAT doesn't appear to be working
Replies: 5
Views: 728

Re: dst-nat in NAT doesn't appear to be working

The NAT rule looks fine. Does another interface have the 10.10.1.0/24 network defined so the Mikrotik knows which interface to route the packet? In IP > Route will show. Regular internet browsing works? If you've changed your WAN from eth1 to eth2, there's a few things to configure. If your web brow...
by Van9018
Fri Mar 03, 2017 7:10 pm
Forum: General
Topic: Routerboard
Replies: 2
Views: 345

Re: Routerboard

Change log output to save to disk so it's not cleared after each boot. I had a constant reboot issue with a different model. Log showed kernel failure. Netinstall is usually the first trial. Didn't fix it for me. I exchange the unit for a new one.
by Van9018
Fri Mar 03, 2017 7:02 pm
Forum: General
Topic: Packets loss in local network
Replies: 2
Views: 919

Re: Packets loss in local network

Check CPU usage. Tools > Profile, is it high? Check interface statistics. Interface > double click on interrface > Traffic. Does it show drops? Look for errors in RX stats and TX Stats. Then go to the status tab. Check the speed and duplex is what you'd expect it to be, and check the client as well.
by Van9018
Fri Mar 03, 2017 3:14 am
Forum: Beginner Basics
Topic: access SMTP server using VPN
Replies: 3
Views: 497

Re: access SMTP server using VPN

Does the hairpin nat work... If you're on the same network as smtp server, and you connect to the smtp service via the external IP of your router, does it hairpin back to the smtp server? I avoid hairpin in favour of DNS because of these types of issues. An internal DNS will resolve to internal IP, ...
  • 1
  • 2