Community discussions

Search found 155 matches

by kamillo
Thu Sep 26, 2019 5:29 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 194
Views: 35708

Re: RouterOS v7.0beta1 (ARM)

looks like beta2 is out: https://forum.mikrotik.com/viewtopic.php?f=1&t=152003#p752103 Changes in v7beta2 capsman - improved compatibility between v6 and v7 versions; tr069-client - address support of server CA certificates; winbox - re-added OSPF menu; ppp - fixed "add-default-route" parameter for ...
by kamillo
Thu Jul 18, 2019 12:32 pm
Forum: General
Topic: Mikortik DHCP Option 43
Replies: 10
Views: 993

Re: Mikortik DHCP Option 43

by kamillo
Thu Jul 04, 2019 10:46 am
Forum: General
Topic: Marketing Banana award (by Packetpusher) to MicroTik’s Cloud Router Switch
Replies: 0
Views: 235

Marketing Banana award (by Packetpusher) to MicroTik’s Cloud Router Switch

Greg Ferro of Packetpusher awarded Marketing Banana award to MicroTik’s Cloud Router Switch https://content.blubrry.com/packetpushers/NB_241_Extreme_Buys_Aerohive_Sloppy_BGP_Plumbing_Causes_Route_Leak.mp3 listen from 32:23 https://packetpushers.net/podcast/network-break-241-extreme-buys-aerohive-slo...
by kamillo
Wed Jun 19, 2019 7:59 pm
Forum: Announcements
Topic: MikroTik News June 2019 (Issue #89)
Replies: 38
Views: 10400

Re: MikroTik News June 2019 (Issue #89)

Not a first mistake like this, you should claim your free MUM ticket.
viewtopic.php?f=21&t=135236&p=666260&hi ... et#p666260
by kamillo
Mon May 20, 2019 3:22 pm
Forum: General
Topic: How to log everything and send to remote syslog server?
Replies: 1
Views: 228

Re: How to log everything and send to remote syslog server?

Hi, 1. You could potentially use log action in firewall rules. I would be interested to hear other options/ ideas 2. I personally use Graylog https://www.graylog.org/ , it is free as opposed to Splunk. Can scale (Elasticsearch as search engine), probably you will need to write log parser for easier ...
by kamillo
Sat May 18, 2019 2:37 pm
Forum: General
Topic: IPv6 Address Assignment Hint
Replies: 4
Views: 2136

Re: IPv6 Address Assignment Hint

Sorry to bump the old thread, has this been implemented?
by kamillo
Wed May 15, 2019 11:20 am
Forum: General
Topic: Elasticsearch, Logtash and Kibana Setup Mikrotik ELK Stak
Replies: 3
Views: 517

Re: Elasticsearch, Logtash and Kibana Setup Mikrotik ELK Stak

Hi, I don't think anyone will be able to "just help" you with ELK. This is huge topic. Do you have specific problem or just hoping for "how to- step by step" instruction. There is a topic about Splunk and Mikrotik, you may want to check it if looking for inspiration: https://forum.mikrotik.com/viewt...
by kamillo
Wed Apr 03, 2019 4:52 pm
Forum: Wireless Networking
Topic: Single SSID multiple passwords
Replies: 8
Views: 775

Re: Single SSID multiple passwords

I understand that I will need a guest VLAN, but how can I have two passwords for the same SSID, where each password determines which VLAN the client connects to?
//Nizar
I think this can be achieved with RADIUS authentication.
https://wiki.mikrotik.com/wiki/Manual:RADIUS_Client
by kamillo
Tue Apr 02, 2019 4:18 pm
Forum: General
Topic: Trunk Port on MT4011 (RTL8367)
Replies: 7
Views: 551

Re: Trunk Port on MT4011 (RTL8367)

From the document you posted: Warning: Not all devices with a switch chip are capable of VLAN switching on a hardware level, check the supported features for each switch chip, the compatibility table can be found Here. When you follow the "here" link: You will see that RB4011 doesn't support VLAN ta...
by kamillo
Fri Feb 08, 2019 3:47 pm
Forum: Announcements
Topic: v6.43.11 [stable] is released!
Replies: 79
Views: 11837

Re: v6.43.11 [stable] is released!

Hi 2 all! If I'll upgrade mikrotik from 6.42.1 to 6.43.11 with a lot firewall rules, caps-man and vlan created I will get problem that something will not work ?
No one can possibly answer that question. Start with checking changelogs: https://mikrotik.com/download/changelogs
by kamillo
Tue Feb 05, 2019 9:49 am
Forum: Beginner Basics
Topic: RB4011
Replies: 3
Views: 374

Re: RB4011

Here you will find more some documentation and examples: https://wiki.mikrotik.com/wiki/Manual:TOC
by kamillo
Mon Nov 26, 2018 4:50 pm
Forum: General
Topic: Windows update + Proxy
Replies: 5
Views: 673

Re: Windows update + Proxy

Depending on version and edition of Windows they use, you could look into: Delivery optimization https://docs.microsoft.com/en-gb/windows/deployment/update/waas-delivery-optimization There is also something called BranchCache https://docs.microsoft.com/en-gb/windows/deployment/update/waas-branchcach...
by kamillo
Thu Nov 15, 2018 9:44 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 70404

Re: RB4011

https://linitx.com/search.php?keywords=rb4011 says:
Stock expected 7-Dec-2018
by kamillo
Thu Nov 01, 2018 5:26 pm
Forum: General
Topic: Urgent help for configure
Replies: 2
Views: 396

Re: Urgent help for configure

You don't give too much details to go by...
maybe you should hire consultant: https://mikrotik.com/consultants
by kamillo
Tue Oct 23, 2018 10:39 am
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 24435

Re: v6 RC and v7 BETA

2 years ago the ROS 7.0 was on alpha 134:

Image
https://mobile.twitter.com/mikrotik_com ... 4195920896
by kamillo
Thu Sep 27, 2018 6:21 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 70404

Re: RB4011

cdr.pl initial claimed arrival at the mid September then changed that to "Beginning of October". https://linitx.com has date of 16th of October
by kamillo
Thu Jun 07, 2018 10:16 am
Forum: Beginner Basics
Topic: RB750Gr3 as basic switch
Replies: 12
Views: 1513

Re: RB750Gr3 as basic switch

Be aware of the max speeds you can get. Check the below link

https://mikrotik.com/product/RB750Gr3#fndtn-testresults
by kamillo
Wed Apr 11, 2018 1:15 pm
Forum: Wireless Networking
Topic: wAP AC vs cAP AC
Replies: 8
Views: 3825

Re: wAP AC vs cAP AC

To my understanding it means that traffic will be capped at that speed only if it will have to go through all 25 rules before it is matched. Usually, as the first rule, you would have something to allow all established and related connections. Therefore most of the traffic would be matched by the fi...
by kamillo
Mon Apr 09, 2018 5:44 pm
Forum: Wireless Networking
Topic: wAP AC vs cAP AC
Replies: 8
Views: 3825

Re: wAP AC vs cAP AC

Check https://mikrotik.com/product/RB3011UiAS ... estresults you will see that RB3011 can do 1Gbps but of course it will depend how you use it.
by kamillo
Thu Feb 08, 2018 10:17 am
Forum: General
Topic: Possible to set DHCPv6 option 16?
Replies: 1
Views: 329

Re: Possible to set DHCPv6 option 16?

This feature is now only in RuterOS 6.42 RC
*) dhcpv6-server - added DHCPv4 style user options;
https://mikrotik.com/download/changelog ... lease-tree
by kamillo
Mon Jan 15, 2018 10:58 am
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 77833

Re: v6.41 [current]

You can try Netinstall to reinstall RouterOS:

https://wiki.mikrotik.com/wiki/Manual:Netinstall
by kamillo
Sat Jan 13, 2018 1:36 pm
Forum: Beginner Basics
Topic: CRS125-24G-1S-RM Fios Gigabit WAN
Replies: 2
Views: 331

Re: CRS125-24G-1S-RM Fios Gigabit WAN

Hi, CRS125 has rather weak CPU so it may not handle all the things you want to do. Saying that I'm using CRS125 as my home switch/ router. I have 70Mbps up and 10Mbps Internet connection, whole bunch of firewall rules and for most of the time CPU usage is around 5%. Use switch chip where you can ins...
by kamillo
Thu Jan 04, 2018 11:29 am
Forum: General
Topic: Meltdown and Spectre Security Vulnerabilities on x86
Replies: 13
Views: 2487

Re: Meltdown and Spectre Security Vulnerabilities on x86

I'm not sure about that, according to "The Register" On a shared system, such as a public cloud server, it is possible, depending on the configuration, for software in a guest virtual machine to drill down into the host machine's physical memory and steal data from other customers' virtual machines....
by kamillo
Wed Dec 27, 2017 11:45 am
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 538
Views: 97209

Re: v6.42rc [release candidate] is released!

Admire the spirit, Christmas period and you are releasing new (RC) version. But looking at changes 4 out of 6 are fixes so this sounds more like 6.41.1 not 6.42.
by kamillo
Tue Dec 05, 2017 1:27 pm
Forum: Beginner Basics
Topic: CRS125 and InterVlan-Routing
Replies: 8
Views: 588

Re: CRS125 and InterVlan-Routing

Don't use bridges on CRS125. Bridging is done in software therefore uses CPU which is very weak on CRS125. Use switch vlan. https://wiki.mikrotik.com/wiki/Manual:CRS_examples#VLAN The above comment doesn't apply if you are using 6.41RCxx of the RouterOS, they have change how bridges work but this ve...
by kamillo
Tue Dec 05, 2017 12:52 pm
Forum: Beginner Basics
Topic: CRS125 and InterVlan-Routing
Replies: 8
Views: 588

Re: CRS125 and InterVlan-Routing

Hi,

Can you show your interfaces, bridges and vlans config?
by kamillo
Wed Nov 22, 2017 12:44 pm
Forum: General
Topic: ipv6 - unable to reach beyond mikrotik.
Replies: 25
Views: 1513

Re: ipv6 - unable to reach beyond mikrotik.

This is probably long shot but can you check what you have in your mikrotik device in ipv6 settings.
There is setting called "ip-forward", this should be set to yes.

https://wiki.mikrotik.com/wiki/Manual:IPv6/Settings
by kamillo
Tue Nov 21, 2017 4:48 pm
Forum: General
Topic: ipv6 - unable to reach beyond mikrotik.
Replies: 25
Views: 1513

Re: ipv6 - unable to reach beyond mikrotik.

Do you have any rules in the firewall? Maybe traffic gets blocked there.
by kamillo
Wed Nov 15, 2017 8:58 pm
Forum: RouterBOARD hardware
Topic: Hardware recommendation for SOHO environment
Replies: 9
Views: 1247

Re: Hardware recommendation for SOHO environment

Hi, For APs I would go for wAP AC, they can be powered via PoE and they are good looking. Router wise, if he needs at least 8 ports I would say RB2011 or RB3011, depending on a budget and Internet speed connection. They are 2 issues with above routers, RB3011 has got only one PoE out port so you wil...
by kamillo
Fri Nov 10, 2017 1:06 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 123584

Re: v6.41rc [release candidate] is released! New bridge implementation!

To add to JimmyNyholm's comment: I'm still waiting for LACP hardware support (offload) in CRS125
by kamillo
Tue Oct 31, 2017 3:54 pm
Forum: General
Topic: Mikrotik Cloud Switch
Replies: 1
Views: 795

Re: Mikrotik Cloud Switch

by kamillo
Fri Oct 27, 2017 6:06 pm
Forum: Announcements
Topic: v6.40.4 [current]
Replies: 103
Views: 25690

Re: v6.40.4 [current]

You can try to login to console and see what went wrong....
by kamillo
Thu Oct 26, 2017 3:56 pm
Forum: General
Topic: SFP VDSL2 Modem
Replies: 1
Views: 4575

Re: SFP VDSL2 Modem

There is whole thread RE this: viewtopic.php?f=3&t=104109
by kamillo
Thu Oct 26, 2017 10:29 am
Forum: Beginner Basics
Topic: CRS125 Port Isolation
Replies: 2
Views: 386

Re: CRS125 Port Isolation

Not sure how one would do that but maybe this will help: https://wiki.mikrotik.com/wiki/Manual:C ... #Isolation
by kamillo
Thu Oct 19, 2017 11:03 am
Forum: Announcements
Topic: v6.40.4 [current]
Replies: 103
Views: 25690

Re: v6.40.4 [current]

CPU load on my WAP AC is nearly 0%, also 6.40.4 version (managed by CAPSMAN)
by kamillo
Fri Oct 13, 2017 1:13 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 123584

Re: v6.41rc [release candidate] is released! New bridge implementation!

How to downgrade to an older rc? I cannot find a download-link.
Go to https://mikrotik.com/download

Grab a link to latest RC for your platform and edit url to the version you want.

https://download2.mikrotik.com/routeros/6.41rc38/routeros-mipsbe-6.41rc38.npk
by kamillo
Fri Oct 13, 2017 10:31 am
Forum: General
Topic: Mikrotik IPV6 Network, IPV4 ISP
Replies: 4
Views: 785

Re: Mikrotik IPV6 Network, IPV4 ISP

On your internal network you can have IPv6 regardless of what your ISP is offering, but you will not be able to communicate to the rest of the world over IPv6.

Other solution is to look at IPv6 tunnel, something like this:
https://tunnelbroker.net/
by kamillo
Sat Oct 07, 2017 7:16 pm
Forum: Beginner Basics
Topic: Firewall Rules
Replies: 2
Views: 1062

Re: Firewall Rules

Hi, I would suggest to move your allow, fastrack and related/ established rules to the top of the list, otherwise even already established sessions (trusted) will be checked against bogons lists rules etc. Also consider moving rules which check against bogons list to the raw table more about raw tab...
by kamillo
Thu Oct 05, 2017 10:09 am
Forum: Beginner Basics
Topic: Help to understand log - Possible Attack?
Replies: 5
Views: 669

Re: Help to understand log - Possible Attack?

Yes it is possible, if you do something like that:
filter add chain=input src-address=58.218.198.171/32 in-interface=ether1 action=drop log=yes
RouterOS will drop packets from 58.218.198.171 incoming on interface ether1 and will also log an action (you will see an entry in the logs)
by kamillo
Wed Oct 04, 2017 10:04 am
Forum: Beginner Basics
Topic: Help to understand log - Possible Attack?
Replies: 5
Views: 669

Re: Help to understand log - Possible Attack?

Hi, The connections are coming on port ether1 18:30:45 firewall,info input: in:ether1 out:(none), src-mac 58:f3:9c:3d:bb:1a, proto TCP (SYN), 58.218.198.171:60001->myWAN:22, len 60 therefore correct firewall rule should be: filter add chain=input src-address=58.218.198.171/32 in-interface=ether1 act...
by kamillo
Mon Sep 25, 2017 10:38 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 15
Views: 7106

Re: Feature request: OpenVPN compression LZO and UDP

According to Normis UDP support is coming in v7:
teaser:

Code: Select all

What's new in 7.0 alpha
*) added support for UDP OpenVPN;
viewtopic.php?f=1&t=26499&hilit=Teaser& ... 00#p617477
by kamillo
Wed Sep 06, 2017 4:50 pm
Forum: General
Topic: IPv6 support
Replies: 5
Views: 962

Re: IPv6 support

Start with this: https://wiki.mikrotik.com/wiki/Manual:IPv6

You will need to enable IPv6 package first.
by kamillo
Fri Aug 25, 2017 11:32 am
Forum: General
Topic: IPv6 and DHCP and DNS
Replies: 65
Views: 11211

Re: IPv6 and DHCP and DNS

The RFC (4941) part you are referring to uses world SHOULD so it is not compulsory to have that. Additionally the same RFC says (note world MUST): Devices implementing this specification MUST provide a way for the end user to explicitly enable or disable the use of temporary addresses. So event if t...
by kamillo
Fri Aug 25, 2017 10:44 am
Forum: General
Topic: IPv6 and DHCP and DNS
Replies: 65
Views: 11211

Re: IPv6 and DHCP and DNS

"Privacy extension" looks like invention for consumer end of the market not enterprise. In enterprise environment you can control your devices and disable "privacy extension".
But I agree with above comments. Proper DHCPv6 server implementation would be very welcome addition to RouterOS
by kamillo
Fri Aug 04, 2017 1:39 pm
Forum: Beginner Basics
Topic: ipV6 dhcp
Replies: 7
Views: 778

Re: ipV6 dhcp

If you need IPv6 only for internal use set pool to something like: name: "pool name" prefix: fd00:9324:28ac::/64 prefix length: 64 next in IPv6 address list add address ::/64 from pool: "pool name" interface: <your internal network interface> tick: advertise this is quick why to configure internal I...
by kamillo
Fri Aug 04, 2017 12:02 pm
Forum: Beginner Basics
Topic: ipV6 dhcp
Replies: 7
Views: 778

Re: ipV6 dhcp

If your ISP does not provide IPv6, you can not access Internet over IPv6. IPv4 and IPv6 are different protocols. If you want to use IPv6 to access the Internet you can use IPv6 tunnel. Do some reading to understand IPv6 better, you can start here: https://wiki.mikrotik.com/wiki/Manual:IPv6/Address h...
by kamillo
Fri Aug 04, 2017 10:34 am
Forum: Beginner Basics
Topic: ipV6 dhcp
Replies: 7
Views: 778

Re: ipV6 dhcp

You prefix in the pool is empty you need an address like 2001:abcd::/64 to give it to your clients.

I'm assuming you are aware that if your ISP doesn't support IPv6 you will not be able to brake to the Internet unless you have an IPv6 tunnel like HE (https://tunnelbroker.net/).
by kamillo
Wed Jul 12, 2017 12:55 pm
Forum: General
Topic: My IPv6 Triage List for ROS
Replies: 48
Views: 5481

Re: My IPv6 Triage List for ROS

Ability to specify which interfaces get which subnets assigned to them from a pool of IPv6 space I have not found a way to do this - e.g. if I were to receive a /56 from dhcpv6-pd, it would be nice to say: "MyPool:ff::1/64 -> GuestBridge" If this is doable, I'd love to know how. This is possible on...
by kamillo
Fri Jul 07, 2017 10:30 am
Forum: RouterBOARD hardware
Topic: mikrotik CRS and switch based LACP
Replies: 2
Views: 826

Re: mikrotik CRS and switch based LACP

As far as I know there is no support for switch based LACP on CRS125, there may be on CSS326 & CRS317 but only on SwitchOS

What's new in v2.1:

*) added support for LACP in CSS326 & CRS317;
But I'm not sure if this is switch based LACP support.
by kamillo
Wed Jul 05, 2017 12:45 pm
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 893

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

Setting egress is not enough. When you switch to "vlan" tab (the first to the left of "eg. vlan tag"- as on the last image you send), what can you see there?
by kamillo
Wed Jul 05, 2017 12:09 pm
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 893

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

You need to configure a port you plugged your AP to as a trunk port for vlan 10, 30 and 40 (I'm assuming this will be a port on one of your 14 switches). Since your vlans are working OK with a cable connection I'm assuming your uplink switch and RB and configured correctly.
by kamillo
Wed Jul 05, 2017 10:48 am
Forum: Beginner Basics
Topic: OVPN ip vs ethernet
Replies: 15
Views: 2765

Re: OVPN ip vs ethernet

Hi,

If you get IP of 172.16.10.70 (linux box?) and trying to ping 192.168.0.200 (on of the servers behind vpn?). This sounds like routing/ firewall issue.
by kamillo
Wed Jul 05, 2017 10:42 am
Forum: General
Topic: VLAN Trunk issue with CRS-125 and RB100AHx2
Replies: 9
Views: 893

Re: VLAN Trunk issue with CRS-125 and RB100AHx2

Hi,
The access point is plugged in to a port on one of the 14 switches, and I have also set the egress VLAN ID's on that port too. (Image 2).
Did you add eth9-meraki... port to relevant VLANs (Vlan tab on your Image 2)?
by kamillo
Wed Jun 07, 2017 11:18 am
Forum: Wireless Networking
Topic: RouterOS 6.39.1 24h Trial Mode no Virtual-AP allowed?
Replies: 10
Views: 1778

Re: RouterOS 6.39.1 24h Trial Mode no Virtual-AP allowed?

According to https://forum.mikrotik.com/viewtopic.php?f=21&t=121198&start=100 Version 6.40rc18 has been released. Before an upgrade: 1) Remember to make backup/export files before an upgrade and save them on another storage device; 2) Make sure the device will not lose power during upgrade process; ...
by kamillo
Tue May 30, 2017 5:49 pm
Forum: General
Topic: Analyze traffic router Mikrotik
Replies: 8
Views: 1607

Re: Analyze traffic router Mikrotik

This may be overkill for what you are trying to do but you could setup something like Graylog with NetFlow plugin

https://graylog.org/
https://marketplace.graylog.org/addons/ ... a8e2657c34
by kamillo
Thu May 25, 2017 4:00 pm
Forum: The Dude
Topic: DENVER MUM
Replies: 5
Views: 775

Re: DENVER MUM

Is there going to be live stream from the MUM?
by kamillo
Thu May 25, 2017 3:14 pm
Forum: Beginner Basics
Topic: CRS125-24G-1S open ports trouble Newbie asks 4 help.
Replies: 3
Views: 408

Re: CRS125-24G-1S open ports trouble Newbie asks 4 help.

Telnet uses TCP where SNMP on port 161 is UDP. You will not be able to telnet to 161.

use something like snmpwalk to test SNMP
by kamillo
Tue May 23, 2017 10:45 am
Forum: Beginner Basics
Topic: Port trunking witj vlan tagged.
Replies: 15
Views: 1453

Re: Port trunking witj vlan tagged.

Thanks, for sharing. Good to know
by kamillo
Mon May 22, 2017 4:54 pm
Forum: Beginner Basics
Topic: Port trunking witj vlan tagged.
Replies: 15
Views: 1453

Re: Port trunking witj vlan tagged.

From what I remember both methods will work. If you have interfaces without vlan in a trunk and you will configure the trunk with vlans, config will be propagated to individual interfaces. The same goes other way around if you have vlans on individual interfaces and you added them to a trunk, trunk ...
by kamillo
Mon May 22, 2017 1:16 pm
Forum: Beginner Basics
Topic: Port trunking witj vlan tagged.
Replies: 15
Views: 1453

Re: Port trunking witj vlan tagged.

Yes, this is how I understand that. Trunking will have better speed on CRS but no LACP. If you want LACP you need to use bonding but this is only supported in software. As far as I know CRS switch chip is capable of handling LACP but this was never implemented in RouterOS. It looks like LACP is supp...
by kamillo
Mon May 22, 2017 10:22 am
Forum: Beginner Basics
Topic: Port trunking witj vlan tagged.
Replies: 15
Views: 1453

Re: Port trunking witj vlan tagged.

Check mikrotik's wiki pages: https://wiki.mikrotik.com/wiki/Manual:Interface/Bonding https://wiki.mikrotik.com/wiki/Manual:CRS_examples#Trunking https://wiki.mikrotik.com/wiki/Manual:CRS_features#Trunking You can use LACP but this will be without hardware support, only software. I'm not sue if CRS12...
by kamillo
Fri May 19, 2017 11:03 am
Forum: Beginner Basics
Topic: Just switching over from UBNT Edge... Q regarding OVPN setup
Replies: 2
Views: 405

Re: Just switching over from UBNT Edge... Q regarding OVPN setup

Mikrotik's implementation of OVPN doesn't support UDP nor compression.

Here you will find more info: https://wiki.mikrotik.com/wiki/Manual:Interface/OVPN
by kamillo
Thu May 04, 2017 2:59 pm
Forum: General
Topic: RDP Problem behind Mikrotik
Replies: 4
Views: 1680

Re: RDP Problem behind Mikrotik

Check this: https://serverfault.com/questions/12005 ... te-desktop
RDP uses port 3389 so I'm not sure why are you using 4001?
Another thing could be firewall blocking traffic
by kamillo
Wed Apr 26, 2017 4:22 pm
Forum: General
Topic: IPv6 firewall rules with dynamic IPv6 prefix
Replies: 4
Views: 1738

Re: IPv6 firewall rules with dynamic IPv6 prefix

There is "Address list"
https://wiki.mikrotik.com/wiki/Manual:I ... dress_list

You could use that instead static IP, but you would have to find a way to dynamically add your IP to that list. Maybe with a script?
by kamillo
Fri Apr 21, 2017 12:52 am
Forum: Wireless Networking
Topic: wap AC for home usage indoor?
Replies: 7
Views: 1122

Re: wap AC for home usage indoor?

Hi, I use CRS125 as a switch/ router + wAP AC at home and it works for me (ADSL broadband, some firewall rules and no QoS - CPU usage around 5-10%). You need to remember CRS is primary a switch with routing capabilities. You are asking if this will work. It should but depends on your requirements an...
by kamillo
Tue Apr 11, 2017 10:27 am
Forum: Beginner Basics
Topic: VLan Understand
Replies: 1
Views: 297

Re: VLan Understand

Configuration will depend on your hardware. With CRS is better to use switch chip instead bridges

Check:
https://wiki.mikrotik.com/wiki/Manual:Interface/VLAN
https://wiki.mikrotik.com/wiki/Manual:CRS_examples
https://wiki.mikrotik.com/wiki/Manual:CRS_features
by kamillo
Thu Mar 30, 2017 6:44 pm
Forum: Beginner Basics
Topic: CRS Throughput Bottleneck
Replies: 8
Views: 1204

Re: CRS Throughput Bottleneck

The CRS125 is primary a switch. It can server as a router but its CPU is to weak to do any serious work. CRS125-24G-1S-IN AR9344 1G all port test Mode Configuration 1518 byte 512 byte 64 byte kpps Mbps kpps Mbps kpps Mbps Bridging none (fast path) 81.0 983.7 232.0 950.3 269.6 138.0 Bridging 25 bridg...
by kamillo
Fri Mar 17, 2017 3:08 pm
Forum: General
Topic: High latency in VLANs
Replies: 3
Views: 692

Re: High latency in VLANs

Are you sure you don't have something else on the network causing this? Packet storm for example?
by kamillo
Wed Mar 15, 2017 11:43 am
Forum: Announcements
Topic: v6.38.5 [current]
Replies: 66
Views: 25656

Re: v6.38.5 [current]

I have NTP package installed on CRS125 and it is working OK:
          enabled: yes
             mode: unicast
      primary-ntp: 91.189.91.157
    secondary-ntp: 91.189.89.198
  dynamic-servers:
           status: synchronized
by kamillo
Tue Feb 28, 2017 10:19 am
Forum: General
Topic: IPV6 troubles
Replies: 4
Views: 662

Re: IPV6 troubles

Firewall?

Also check if ipv6 -> settings -> forward is set to "yes"

https://wiki.mikrotik.com/wiki/Manual:IPv6/Settings
by kamillo
Mon Feb 13, 2017 10:53 am
Forum: General
Topic: CRS125 vlan config
Replies: 9
Views: 1348

Re: CRS125 vlan config

CRS125 supports vlans on switch-cpu level. Bridges operate on CPUlevel. CPU is rather weak on CRS125 therefore using bridges could harm performance.

Check:
http://wiki.mikrotik.com/wiki/Manual:CRS_features
http://wiki.mikrotik.com/wiki/Manual:CRS_examples

Best,
by kamillo
Mon Jan 30, 2017 10:22 am
Forum: RouterBOARD hardware
Topic: CRS125-24G-1S-RM .. High Time with VLAN
Replies: 3
Views: 655

Re: CRS125-24G-1S-RM .. High Time with VLAN

Hi,

When you say "Inter-vlan" do you mean that you do routing on that box?

What is the CPU usage?
by kamillo
Mon Jan 30, 2017 10:18 am
Forum: Beginner Basics
Topic: Routing VLAN's over a LACP trunk port
Replies: 2
Views: 935

Re: Routing VLAN's over a LACP trunk port

Hi,

CRS125 doesn't have hardware support for LACP, you can set it up but all the traffic will go via switch's CPU. Which is counterproductive as the CPU is rather weak.

No sure if this will work but you can try and use "Trunking"
http://wiki.mikrotik.com/wiki/Manual:CR ... s#Trunking
by kamillo
Fri Jan 20, 2017 10:17 am
Forum: The Dude
Topic: Mib files
Replies: 4
Views: 9351

Re: Mib files

by kamillo
Wed Dec 21, 2016 10:24 am
Forum: General
Topic: CRS and LACP/802.11AD
Replies: 2
Views: 623

Re: CRS and LACP/802.11AD

I would like to know that too...
by kamillo
Mon Dec 19, 2016 12:14 pm
Forum: Announcements
Topic: MikroTik News December 2016 (Issue #74)
Replies: 94
Views: 22219

Re: MikroTik News December 2016 (Issue #74)

In regards to CRS317, is LACP support going to be implemented on hardware level?
by kamillo
Mon Dec 19, 2016 10:59 am
Forum: Beginner Basics
Topic: Firewall on CRS125 when used as router
Replies: 4
Views: 714

Re: Firewall on CRS125 when used as router

To block traffic to your device you use chain "INPUT" to block traffic passing thorough the device you need use chain "FORWARD" here is a RouterOS wiki page about firewall: http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter and here you will find some examples: http://wiki.mikrotik.com/wiki/Fir...
by kamillo
Thu Dec 15, 2016 10:21 am
Forum: Beginner Basics
Topic: Firewall on CRS125 when used as router
Replies: 4
Views: 714

Re: Firewall on CRS125 when used as router

Without looking at your firewall rules it is hard to tell what is wrong. Did you use "forward" chain to block traffic from one interface to another?
by kamillo
Thu Dec 08, 2016 1:52 pm
Forum: General
Topic: Port 4070 - Block on Mikrotik
Replies: 2
Views: 981

Re: Port 4070 - Block on Mikrotik

I would also check where your rule is in the chain (how far down the list), by default I think the rule will be added to the bottom of the list. So if you have a rule above your rule which allows traffic to spotify. traffic will never touch your rule. Rules are stopped processed as soon as first mat...
by kamillo
Tue Dec 06, 2016 3:02 pm
Forum: General
Topic: What happens with the LHG-5?
Replies: 2
Views: 516

Re: What happens with the LHG-5?

by kamillo
Mon Dec 05, 2016 12:00 pm
Forum: General
Topic: RB3011 + VLAN
Replies: 5
Views: 2337

Re: RB3011 + VLAN

It looks like you are using bridges to do VLANs. This is not as effective as doing VLANs on a switch chip level. Check the link provided by pukkitta: When you add vlans as interfaces you're doing VLAN in software, so this uses the CPU. Is it possible to use hardware VLAN, by using the Switch chip VL...
by kamillo
Fri Dec 02, 2016 11:02 am
Forum: General
Topic: Am i being hacked?
Replies: 8
Views: 1469

Re: Am i being hacked?

From your logs it looks like you are using DynDNS, this is probably why changing public IP doesn't help.

UDP traffic to/from 5678 is used by MT discovery protocol: http://forum.mikrotik.com/viewtopic.php?t=19812
by kamillo
Thu Dec 01, 2016 11:49 am
Forum: General
Topic: A slow CRS109
Replies: 11
Views: 1303

Re: A slow CRS109

Hi,

Have you checked speed/ duplex on interfaces? Do you have any firewall rules? Are you using bridges? Do the 2 ports belong to the same master port?
by kamillo
Wed Nov 30, 2016 2:59 pm
Forum: Wireless Networking
Topic: QRT5ac throughput
Replies: 13
Views: 1602

Re: QRT5ac throughput

Doing tests from/ to CRS125 may not be the best way, CPU is rather weak on these devices, try with PC instead CRS125. Not sure about RB3011
by kamillo
Tue Nov 29, 2016 1:29 pm
Forum: Beginner Basics
Topic: IPV6 firewall rules
Replies: 3
Views: 2196

Re: IPV6 firewall rules

you are applying drop action on the INPUT chain, so traffic going to the router itself and you are allowing all the traffic to go to anything behind the router. Looking at the ports you are scanning they look like services you would run on a server, not on the router. What I'm trying to say is: shou...
by kamillo
Fri Nov 25, 2016 3:00 pm
Forum: Beginner Basics
Topic: N00b help for setup of Mikrotik with UK PlusNet PPPOE
Replies: 12
Views: 1756

Re: N00b help for setup of Mikrotik with UK PlusNet PPPOE

Happy to hear that, Could you share info what did you do?
by kamillo
Fri Nov 25, 2016 12:02 pm
Forum: Beginner Basics
Topic: N00b help for setup of Mikrotik with UK PlusNet PPPOE
Replies: 12
Views: 1756

Re: N00b help for setup of Mikrotik with UK PlusNet PPPOE

Sorry not sure how would you setup this but http://wiki.mikrotik.com/wiki is your friend. There is vlan-priority parameter in bridge interface section http://wiki.mikrotik.com/wiki/Manual:Interface/Bridge and some info about vlans http://wiki.mikrotik.com/wiki/Manual:Interface/VLAN not sure if this ...
by kamillo
Fri Nov 25, 2016 11:22 am
Forum: Beginner Basics
Topic: N00b help for setup of Mikrotik with UK PlusNet PPPOE
Replies: 12
Views: 1756

Re: N00b help for setup of Mikrotik with UK PlusNet PPPOE

To clarify something are Plusnet Hub and VDSL modem two separate devices? You have already VDSL modem you will need to set it into bridge mode, as I mentioned earlier (you may not need to configure PPPoE on the hAP). Mikotik devices are good but you need to be aware of their limitations. As a side n...
by kamillo
Fri Nov 25, 2016 10:58 am
Forum: Beginner Basics
Topic: N00b help for setup of Mikrotik with UK PlusNet PPPOE
Replies: 12
Views: 1756

Re: N00b help for setup of Mikrotik with UK PlusNet PPPOE

If I'm correct FTTC uses VDSL technology therefore you will still need VDSL modem on front of your hAP
by kamillo
Fri Nov 25, 2016 10:39 am
Forum: Beginner Basics
Topic: N00b help for setup of Mikrotik with UK PlusNet PPPOE
Replies: 12
Views: 1756

Re: N00b help for setup of Mikrotik with UK PlusNet PPPOE

Hi, You say that you want to replace your PlusNet hub, do you mean completely? Mikrotik devices don't have ADSL modem built-in so you will have to keep your PlusNet Hub and set it in a "bridge mode". In some cases in "bridge mode" authentication etc will be handled by the ADSL modem/ router, and the...
by kamillo
Fri Nov 18, 2016 10:04 pm
Forum: General
Topic: [SOLVED] Slow speeds with ISP subnet and VLANs on CRS125
Replies: 14
Views: 2160

Re: Slow speeds with VLANs on CRS125

So you want to remove the Cisco router from your network and just use CRS125 instead? If this is the case like Paternot said, don't. CPU is too weak. CRS is a switch with limited routing capabilities (hardware wise) If you need router you will be better of by looking at something like RB2011, RB3011...
by kamillo
Fri Nov 18, 2016 9:09 pm
Forum: General
Topic: [SOLVED] Slow speeds with ISP subnet and VLANs on CRS125
Replies: 14
Views: 2160

Re: Slow speeds with VLANs on CRS125

From the info presented I'm under impression that CRS125 is not involved in routing and only acts as a switch. It looks like (cisco ?) 10.254.43.1 acts as a router. Is that correct?
by kamillo
Fri Nov 18, 2016 12:26 pm
Forum: General
Topic: [SOLVED] Slow speeds with ISP subnet and VLANs on CRS125
Replies: 14
Views: 2160

Re: Slow speeds with VLANs on CRS125

by looks of it there is no issues with routing, I would check the router for any blocking policies/ speed policies and also check things like speed/ duplex on the interfaces between CRS125 and router
by kamillo
Fri Nov 18, 2016 10:40 am
Forum: General
Topic: CRS212-1G-10S-1S+IN used for routing purposes
Replies: 5
Views: 724

Re: CRS212-1G-10S-1S+IN used for routing purposes

On the bottom of: https://routerboard.com/CRS212-1G-10S-1SplusIN you can find tables with some data what you can expect from the device in terms of throughput.
by kamillo
Fri Nov 18, 2016 10:32 am
Forum: General
Topic: [SOLVED] Slow speeds with ISP subnet and VLANs on CRS125
Replies: 14
Views: 2160

Re: Slow speeds with VLANs on CRS125

Hi, Not sure if I understood your network layout but... Your trace results: The first one, you doing that from 192.168.203.254 to 10.254.43.37, and all is good right? The second, from 10.254.43.37 to 192.168.203.254, which is opposite direction from what you have done in above example, and this is n...
by kamillo
Wed Nov 16, 2016 5:32 pm
Forum: General
Topic: [SOLVED] Slow speeds with ISP subnet and VLANs on CRS125
Replies: 14
Views: 2160

Re: Slow speeds with VLANs on CRS125

Hi, I have CRS125 at home and never had issues like this. I don't remember my config from top of my head but it looks similar to yours. I think the problem is with a test method. You are sending a loads of traffic to the switch itself. CPU on the switch is to weak to process all the traffic this is ...
by kamillo
Tue Nov 15, 2016 5:38 pm
Forum: Beginner Basics
Topic: MikroTik RB951Ui2nD hAP ADSL connection
Replies: 2
Views: 521

Re: MikroTik RB951Ui2nD hAP ADSL connection

Hi,

As far as I remember non of MT product has ADSL modem build in. So yes you need another device to connect to he phone line.
PoE in is a "Power over Ethernet" port. It means you can power device via Ethernet cable. https://en.wikipedia.org/wiki/Power_over_Ethernet

Best,
by kamillo
Tue Nov 15, 2016 1:49 pm
Forum: Beginner Basics
Topic: vlan - via bridge or switch, about differences
Replies: 2
Views: 474

Re: vlan - via bridge or switch, about differences

Hi, You may want to check http://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features as well. Generally if you use switch chip you can get wire speed. If you use bridge your traffic will go via CPU and that will add a load to your CPU, as a result you may not achieve wire speeds In your example RB201...
by kamillo
Mon Oct 31, 2016 10:38 am
Forum: Beginner Basics
Topic: Configure CCR1009 Multi VLANS to CRS125
Replies: 7
Views: 1096

Re: Configure CCR1009 Multi VLANS to CRS125

Hi, Just a side note, don't use bridges on CRS. Traffic in bridges goes via CPU and CRS has got only 1Gbps connection between switch chip and CPU. Better to implement vlans on switch chip level Check this: http://wiki.mikrotik.com/wiki/Manual:CRS_examples http://wiki.mikrotik.com/wiki/Manual:CRS_fea...
by kamillo
Thu Oct 20, 2016 10:47 am
Forum: General
Topic: The problem with addressing Vlan
Replies: 2
Views: 451

Re: The problem with addressing Vlan

Hi,

To little info to tell.

I looks like you may be getting IPs from the TP-link as it is on 192.168.0.x, double check your vlan/ trunk configuration
by kamillo
Thu Oct 13, 2016 10:41 am
Forum: Beginner Basics
Topic: CRS125 VLAN problem
Replies: 6
Views: 868

Re: CRS125 VLAN problem

by kamillo
Thu Oct 13, 2016 10:29 am
Forum: RouterBOARD hardware
Topic: New CRS hardware? Show us some love
Replies: 23
Views: 4268

Re: New CRS hardware? Show us some love

I would like to see hardware level support for LACP as well. PoE support would be nice as well
by kamillo
Fri Sep 30, 2016 1:33 pm
Forum: Announcements
Topic: v6.38rc [release candidate] is released
Replies: 331
Views: 75167

Re: v6.38rc [release candidate] is released

Great news with STP on CRS. What I would like to see is hardware support for LACP on CRS, any chance/ time scale for that?
by kamillo
Thu Sep 15, 2016 10:45 am
Forum: Beginner Basics
Topic: CRS-125 LACP Trunk to CRS-125
Replies: 1
Views: 405

Re: CRS-125 LACP Trunk to CRS-125

Hi, You can have LACP trunk on CRS but I wouldn't do that. The reason for this is LACP tunnel on CRS will use CPU, it is not supported by switch chip.... You can use trunking Check some wiki pages, they should help you: http://wiki.mikrotik.com/wiki/Manual:CRS_examples http://wiki.mikrotik.com/wiki/...
by kamillo
Tue Aug 23, 2016 5:39 pm
Forum: Beginner Basics
Topic: New CRS125-24G-1S, new Mikrotik user, Vlan isolation
Replies: 15
Views: 1653

Re: New CRS125-24G-1S, new Mikrotik user, Vlan isolation

If I'm correct, it works this way: you put all interfaces on master port - this works like normal switch. Do the same but with vlans and you can separate traffic. But put some interfaces on on master and some other to other master and you will end up with 2 independent switches (so it would work lik...
by kamillo
Wed Aug 10, 2016 9:55 am
Forum: General
Topic: IPV6 Tunnel (6in4) not receiving any data - transmit works
Replies: 15
Views: 2377

Re: IPV6 Tunnel (6in4) not receiving any data - transmit works

Since you have dynamic IP address this may be a problem From HE.com web page: https://ipv6.he.net/certification/faq.php My IPv4 endpoint address is dynamic. Can I still create a tunnel? If yes, what do I need to do when my IP address changes? Yes, you can still create a tunnel even if you are using ...
by kamillo
Thu Aug 04, 2016 10:53 am
Forum: General
Topic: IPV6 Tunnel (6in4) not receiving any data - transmit works
Replies: 15
Views: 2377

Re: IPV6 Tunnel (6in4) not receiving any data - transmit works

7 G 2001:470:25:301::2/64 sit1 no 8 G 2001:470:26:301::1/64 VLAN666 yes I don't understand why do you have the same subnet on 2 different interfaces? Your default IPv6 route sends traffic to 2001:470:26:301::1 so it goes via VLAN666
by kamillo
Wed Jul 27, 2016 5:48 pm
Forum: RouterBOARD hardware
Topic: CRS125 - How to BOND slave interfaces?
Replies: 5
Views: 1029

Re: CRS125 - How to BOND slave interfaces?

Hi, If you are trying to do 802.3ad, don't. CRS125 doesn't support that in the switch chip, so all the traffic will go via CPU and that will potentially hammer it. Additionally, bond interfaces can't belong to any master ports. Try using trunking instead: http://wiki.mikrotik.com/wiki/Manual:CRS_exa...
by kamillo
Wed Apr 20, 2016 10:48 am
Forum: Beginner Basics
Topic: Vlan Configuration
Replies: 2
Views: 559

Re: Vlan Configuration

Hi,

You didn't post your config...
by kamillo
Mon Apr 18, 2016 11:20 pm
Forum: General
Topic: tcp syn-flood
Replies: 9
Views: 1986

Re: tcp syn-flood

The first rule is disabled
disabled=yes
by kamillo
Tue Apr 12, 2016 3:40 pm
Forum: General
Topic: CRS VLAN
Replies: 3
Views: 548

Re: CRS VLAN

There are 2 ways of setting VLANs on CRS devices. One, by using bridges - you will be able to use STP but whole traffic will go via CPU. So you are limited to what CPU can achieve in terms of bandwidth. The other way is to use switch chip and enjoy wire speed but no STP. Here is instruction how to d...
by kamillo
Wed Mar 23, 2016 1:15 pm
Forum: RouterBOARD hardware
Topic: hAP ac selling like hotcakes ?
Replies: 2
Views: 717

Re: hAP ac selling like hotcakes ?

If you live in the EU you always can try distributor from different country:

https://linitx.com/product/mikrotik-rou ... -psu/14663
http://cdr.pl/p4905,mikrotik-routerboar ... ac2nd.html
by kamillo
Fri Mar 18, 2016 4:10 pm
Forum: General
Topic: Two exchange servers
Replies: 6
Views: 999

Re: Two exchange servers

This is correct behaviour, traffic matches first rule so it is not processed by other rules.

I'm not Exchange expert but this is not the way to achieve your goal. Maybe something like "Network Load Balancing Services"
by kamillo
Fri Mar 18, 2016 2:22 pm
Forum: General
Topic: VLANs without Bridge in CRS125-24G
Replies: 4
Views: 662

Re: VLANs without Bridge in CRS125-24G

happy to hear that. You are probably right regarding switch1-chip. I checked my config and it was there but I'm using routing between VLANs. Anyway it is working, great!
by kamillo
Thu Mar 17, 2016 11:00 am
Forum: General
Topic: VLANs without Bridge in CRS125-24G
Replies: 4
Views: 662

Re: VLANs without Bridge in CRS125-24G

interface ethernet switch egress-vlan-tag should be used only for trunk ports and switch1-cpu should be included

switch1-cpu should also be included: in /interface ethernet switch vlan
by kamillo
Fri Feb 26, 2016 2:37 pm
Forum: Beginner Basics
Topic: CRS and RB2011 vlan configuration
Replies: 10
Views: 1165

Re: CRS and RB2011 vlan configuration

Hi, I have CRS with working vlan config. My trunk ports look like that: <interface ethernet switch egress-vlan-tag> print # VLAN-ID TAGGED-PORTS 0 10 bond0 ether17 ether23 switch1-cpu 1 96 bond0 ether17 ether23 switch1-cpu 2 15 bond0 ether23 switch1-cpu 3 2 ether1 switch1-cpu 4 D 4095 So I'm using e...
by kamillo
Thu Feb 25, 2016 3:40 pm
Forum: RouterBOARD hardware
Topic: Advice needed in choosing the right Mikrotik device
Replies: 33
Views: 4322

Re: Advice needed in choosing the right Mikrotik device

Unoptimized, that is, without fasttrack?
yes, without fasttrack. fasttrack was introduced after I configurer the switch and never bothered to enable it as never had to.
by kamillo
Thu Feb 25, 2016 11:42 am
Forum: RouterBOARD hardware
Topic: Advice needed in choosing the right Mikrotik device
Replies: 33
Views: 4322

Re: Advice needed in choosing the right Mikrotik device

Well, somebody posted once that some CPU resources are used for switching, so it would be good for Mikrotik to comment on this.
Yes if you use bridges, no if you use switch chip
by kamillo
Thu Feb 25, 2016 11:41 am
Forum: RouterBOARD hardware
Topic: Advice needed in choosing the right Mikrotik device
Replies: 33
Views: 4322

Re: Advice needed in choosing the right Mikrotik device

I have CRS125. It is connected to Cisco ADSL router 15Mbps down and 1Mbps up. I have firewall, OpenVPN and routing between 4 VLANs, no bridges. CPU usage average usage is around 6% with picks to 52%. NATing happens on Cisco but the firewall rules and routing happens on CRS125. This is home usage, wi...
by kamillo
Mon Feb 15, 2016 4:55 pm
Forum: General
Topic: OVPN Server can't rdp ssh when connected but can ping.
Replies: 1
Views: 303

Re: OVPN Server can't rdp ssh when connected but can ping.

Hi,

If you can ping the servers over VPN but can't access other resources (ssh/ http etc) there must be some filter somwhere if not on the router itself maybe servers?
by kamillo
Mon Feb 08, 2016 2:06 pm
Forum: RouterBOARD hardware
Topic: HAP AC
Replies: 540
Views: 134317

Re: HAP AC

It looks like HAP AC will be available in UK around 26/02

https://linitx.com/product/mikrotik-rou ... -psu/14663
by kamillo
Mon Feb 01, 2016 8:24 pm
Forum: Beginner Basics
Topic: How to add a 802.3ad LACP bondng on ether16 and ether17 in this config?
Replies: 6
Views: 1145

Re: How to add a 802.3ad LACP bondng on ether16 and ether17 in this config?

Bonding does work in the CRS series if the port is routed or bridged and not switched Not sure about that I have CRS with bonding interface where both Ethernet interfaces are switched, with vlan trunk configured. I'm using xor balance Flags: X - disabled, I - invalid # NAME MEMBER-PORTS 0 bond0 eth...
by kamillo
Sun Jan 31, 2016 9:38 pm
Forum: Announcements
Topic: v6.34 [current] is released!
Replies: 91
Views: 22915

Re: v6.34 [current] is released!

After upgrade on CRS125, vlans trunk disappeared from bonded interface.

Easily fixed by adding vlans to the interface but that should not happened.
by kamillo
Thu Jan 21, 2016 6:43 pm
Forum: General
Topic: Traceroute
Replies: 1
Views: 319

Re: Traceroute

Hi,

Yes you are right, there must be a filter on the 2nd hop. Standard traceroute sends ICMP packets to the destination but it will play around with TTL

more about traceroute on https://en.wikipedia.org/wiki/Traceroute

Rergards,
by kamillo
Fri Jan 15, 2016 10:38 am
Forum: General
Topic: VLAN as Trunk .. Possible??
Replies: 3
Views: 558

Re: VLAN as Trunk .. Possible??

I don't have any experience with this and I'm not sure if it is supported by RouterOS but maybe it will be useful to you:

https://en.wikipedia.org/wiki/Virtual_Extensible_LAN
by kamillo
Sun Jan 10, 2016 11:28 pm
Forum: Beginner Basics
Topic: DHCP - how to block IP offer to the client ?
Replies: 6
Views: 1452

Re: DHCP - how to block IP offer to the client ?

I think easier would be to write some Windows script to check for network status on both nics. If both Ethernet and WiFi are up and belong to the same subnet, disable one or change default GW or do whatever you think is appropriate. You could deploy that with Group Policy.
by kamillo
Wed Dec 30, 2015 10:38 am
Forum: General
Topic: v6.33.3 [current] is released!
Replies: 59
Views: 18812

Re: v6.33.3 [current] is released!

Not quite sure if this is new with 6.33.3 but pretty often the webfig becomes unresponsive and does not react on any clicks anymore. An F5 reload fixes it for a bit until it fails again within a few minutes. I have noticed the same. Before in version 6.32.x I didn't have this issue. I'm using Firef...
by kamillo
Tue Dec 22, 2015 6:58 pm
Forum: General
Topic: Problem with exposing external IP, behind VLAN on CRS
Replies: 4
Views: 894

Re: Problem with exposing external IP, behind VLAN on CRS

Hi, I don't understand what are you trying to achieve. vlan20 (on top bridge1) - 10.1.20.1/24 vlan40 (on top bridge1) ether24 - x.x.x.17,18,19,20/29 If I set address on vlan40 i can ping x.x.x.21, so the VLAN is working. I have no control over x.x.x.21. Setting bridge between vlan40 and ether24 is n...
by kamillo
Wed Nov 25, 2015 10:57 am
Forum: General
Topic: VLANs on bridges, or bridges for VLANs?
Replies: 4
Views: 2235

Re: VLANs on bridges, or bridges for VLANs?

Hi,

Generally I would avoid using bridges as the traffic will pass thorough CPU. I would use switch chip for that (this is how it works on my CRS switch).

Check:
http://wiki.mikrotik.com/wiki/Manual:CRS_examples#VLAN
http://wiki.mikrotik.com/wiki/Manual:Interface/VLAN
by kamillo
Thu Nov 05, 2015 10:38 am
Forum: General
Topic: VPN Routing issue
Replies: 3
Views: 401

Re: VPN Routing issue

If you route whole traffic to VPN tunnel, your tunnel itself will try to follow the path and it will go down therefore you will lose connection. What you need to do is to set the routes the way that the tunnel itself uses DSL and the rest of the traffic will go via tunnel.
by kamillo
Mon Oct 26, 2015 11:06 pm
Forum: General
Topic: openvpn client udp
Replies: 2
Views: 808

Re: openvpn client udp

Hi,

The implementation is different.

MT doesn't support UDP nor compression.

You can read more about that on MT wiki pages and there is a topic on the forum with UDP support request.
by kamillo
Tue Oct 13, 2015 2:11 pm
Forum: Beginner Basics
Topic: OVPN issue (can't reach hosts on the same network)
Replies: 4
Views: 885

Re: OVPN issue (can't reach hosts on the same network)

Above solution is Ok just keep in mind that CRS doesn't have powerful CPU and if you bridge interfaces whole traffic will pass through CPU (traffic from bridged interfaces). So keep an eye on the CPU usage
by kamillo
Tue Oct 13, 2015 10:50 am
Forum: Beginner Basics
Topic: OVPN issue (can't reach hosts on the same network)
Replies: 4
Views: 885

Re: OVPN issue (can't reach hosts on the same network)

The problem is that you have both interfaces (public and private) attached to different master ports. Basically you have isolated the two networks so they are unable to talk to each other despite the fast they use the same ip range. I would suggest assigning different IP range to VPN side and set up...
by kamillo
Thu Oct 08, 2015 6:48 pm
Forum: Forwarding Protocols
Topic: VPN Configure
Replies: 2
Views: 801

Re: VPN Configure

Hi,

I don't understand what do you mean by "my workplace that using PPTP " do you want to configure PPTP VPN or you just telling us that you can connect to your corporate network using PPTP?
by kamillo
Wed Aug 26, 2015 10:49 am
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 93410

Re: Feature request: OpenVPN compression LZO and UDP

I would like to see UDP and compression support as well
by kamillo
Thu Jun 25, 2015 3:52 pm
Forum: Announcements
Topic: Comments about RouterOS release schedule
Replies: 35
Views: 11080

Re: Comments about RouterOS release schedule

I like the idea
by kamillo
Wed Jun 17, 2015 11:11 am
Forum: General
Topic: Configure OpenVPN client
Replies: 8
Views: 47308

Re: Configure OpenVPN client

Hi,

If I remember correctly, MT doesn't support certificate authentication only user/ password

Check: http://wiki.mikrotik.com/wiki/Manual:Interface/OVPN
by kamillo
Fri Jun 12, 2015 4:30 pm
Forum: Beginner Basics
Topic: router itself no internet
Replies: 2
Views: 661

Re: router itself no internet

Do you have firewall configured? Can you ping the same host from any device which is behind the router? Did you try to ping IP or just a hostname?
by kamillo
Mon May 25, 2015 7:04 pm
Forum: General
Topic: Help To Get OpenVPN Server Works in my RouterBoard
Replies: 1
Views: 317

Re: Help To Get OpenVPN Server Works in my RouterBoard

Hi there,

You need to give use little bit more... what is your current configuration? What is your scenario? Where is the problem?
by kamillo
Thu May 14, 2015 4:50 pm
Forum: RouterBOARD hardware
Topic: I can't buy cAP 2n in Poland
Replies: 5
Views: 773

Re: I can't buy cAP 2n in Poland

Hi,

Try other distributor from EU maybe they will be willing to ship it to Poland
One example from UK:
http://linitx.com/product/mikrotik-rout ... -psu/14396

(30 in stock)

Best
by kamillo
Tue May 12, 2015 12:18 pm
Forum: General
Topic: OpenVPN only works within integrated RouterOS client
Replies: 4
Views: 1610

Re: OpenVPN only works within integrated RouterOS client

I have seen connection restarting like that when username or password was incorrect. Remember that username is case sensitive

Could you post your router configuration for OpenVPN?
by kamillo
Mon May 11, 2015 2:14 pm
Forum: General
Topic: OpenVPN only works within integrated RouterOS client
Replies: 4
Views: 1610

Re: OpenVPN only works within integrated RouterOS client

Hi there, From the config file you posted it looks like you are trying to use compression: # Enable compression on the VPN link. # Don't enable this unless it is also # enabled in the server config file. comp-lzo try and comment out the line with comp-lzo. As far as I remember OpenVPN on Mikrotik do...
by kamillo
Tue Apr 21, 2015 6:58 pm
Forum: Beginner Basics
Topic: Firewall rule not stopping tcp port 63000
Replies: 5
Views: 927

Re: Firewall rule not stopping tcp port 63000

Hi,

Picture shows packets with destination x.x.181.1 if this is your router's public IP, you should change chain from forward to input
by kamillo
Mon Jul 28, 2014 12:50 am
Forum: General
Topic: CRS125; packets tagged on access port
Replies: 1
Views: 512

CRS125; packets tagged on access port

Hi all, I hope someone could point me to right direction on how to solve my problem. I have a CRS125-24G-1S, firmware version 3.15, RouterOS 6.17 I wanted to implement InterVLAN routing and I followed http://wiki.mikrotik.com/wiki/Manual:CRS_examples#InterVLAN_Routing The problem is that on access p...
by kamillo
Tue Jul 22, 2014 1:32 am
Forum: General
Topic: CRS documentation
Replies: 79
Views: 30140

Re: CRS documentation

Hi all, I hope someone could point me to right direction on how to solve my problem. I have a CRS125-24G-1S, firmware version 3.12, RouterOS 6.15 I wanted to implement InterVLAN routing and I followed http://wiki.mikrotik.com/wiki/Manual:CRS_examples#InterVLAN_Routing The problem is that on access p...