Community discussions

MikroTik App

Search found 56 matches

by manojlovicl
Wed Aug 09, 2023 6:09 pm
Forum: Announcements
Topic: v7.11rc is released!
Replies: 195
Views: 49294

Re: v7.11rc is released!

Hi!

Something changed from beta firmware(s) (at least 7.11beta2) to RC in relation to OpenVPN - RC version has problems with more than 170 OVPN connections ...
I reverted to 7.11beta2 and everything works great.

Luka
by manojlovicl
Wed Jul 05, 2023 3:07 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

add action=dst-nat chain=dstnat dst-address=PUBLICIPOVERVPN dst-port=443 \
protocol=udp to-addresses=PRIVATEIPININTERNALNETWORK
by manojlovicl
Wed Jul 05, 2023 1:47 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

Hi!

It is a simple DST-NAT where DST address is my public IP that I am receiving over VPN (udp on port 443) that is DST NATed to IP I am receinving in "hosting network".

Luka
by manojlovicl
Sat Jul 01, 2023 11:31 am
Forum: Announcements
Topic: v7.11beta [testing] is released!
Replies: 373
Views: 107128

Re: v7.11beta [testing] is released!

OVPN works much better!!
I can confirm it too... Waiting so long for this fix! Thank you MikroTik!

Luka
by manojlovicl
Sat May 06, 2023 9:45 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 55129

Re: v7.9 [stable] is released!

I have CHR with 10 CPU cores and 4GB memory on Hyper-V and 190 OVPN connections and 190 EoIP tunnels with 10 Bridges - the OVPN is really unstable - sessions get duplicated and in couple of hours router is stuck (unresponsive - in console there was an message about bug, cpu... (I was unable to creat...
by manojlovicl
Thu Mar 09, 2023 10:32 am
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

I would like to thank Anav who helped me solving it out. Long story short - Wireguard (service) that runs on MikroTik prefer main routing table and binds to IP address that is in the same subnet as gateway in main routing table, even if you try to use mangle rule to make it go via other routing tabl...
by manojlovicl
Wed Mar 08, 2023 12:10 am
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

Old school tools still can do wonders.

Pen and paper.
Make a drawing.
by manojlovicl
Tue Mar 07, 2023 11:55 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

A diagram would have made this much clearer. :-( For example, is the SSTP VPN a connection to the MT device/router? or to the Router in front of the MT and then the VPN connection is fed to the MT as a WAN port with an IP address and gateway?? This router is a standalone router connected with 1 cab...
by manojlovicl
Tue Mar 07, 2023 11:38 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

I will provide one last opportunity. Diagram and more importantly FULL CONFIG. Including firewall rules!! etc.... /export file=anynameyouwish (minus router serial number and any public WANIP information, keys etc.) THIS DOES NOT MEAN cover up every private IP, just the info the ISP provides that is...
by manojlovicl
Tue Mar 07, 2023 10:56 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

Since you have multiple wan, mangle might be needed. Read this thread from anav. Section 9 B https://forum.mikrotik.com/viewtopic.php?t=182340 Do you think - as there is UDP that I will need a combination of packet mark + routing mark? I already have a "general" output routing mark mangle...
by manojlovicl
Tue Mar 07, 2023 10:46 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

Wireguard shouldn't need mangle. I also thought it will be simple... But look - this is output filter rule for logging only: output: in:(unknown 0) out:br-lan, connection-state:new proto UDP, 10.x.y.z:443->PUBLICIPOFMYPHONECLIENT:7736, len 120 Instead of private IP there should be public IP as a so...
by manojlovicl
Tue Mar 07, 2023 10:34 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

Why this ? /ip address add address=10.xxx.xxx.1/24 interface=br-lan network=10.xxx.xxx.0 add address=PUBLICIP interface=sstp-kate-wing network=PUBLICIPNetwork add address=10.xxx.xxx.1/24 interface=br-lan network=10.xxx.xxx.0 add address=10.xxx.xxx.1/24 interface=wireguard1 network=10.xxx.xxx.0 Ever...
by manojlovicl
Tue Mar 07, 2023 10:26 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

Diagram of network and full config
/export file=anynameyouwish ( minus router serial # and any public WANIP information keys etc. )

With this info should be quick to fix.
by manojlovicl
Tue Mar 07, 2023 10:13 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Re: Wireguard - "asymmetric routing"

It is a router (A) currently located as guest in a NAT-ed network. It has (private) IP in that network. From here I do a VPN to another router (at our ISP) where I have the option to route public IP to the router (A) - this part works. I can access router (A) via Winbox by using public IP so output ...
by manojlovicl
Tue Mar 07, 2023 9:40 pm
Forum: General
Topic: Wireguard - "asymmetric routing"
Replies: 30
Views: 2372

Wireguard - "asymmetric routing"

Hi! I have a case, that router routes some traffic over VPN (over which I get public IP address) - I want to use this public IP as Wireguard endpoint. The problem is that clients try to connect to IP (I can see packets) but responses from MT Wireguard service are going back by using default routing ...
by manojlovicl
Thu Mar 02, 2023 10:36 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140298

Re: v7.8 [stable] is released!

- CHR freezes after 2 hours with 180+ OVPN connections - unresponsive also in console - OVPN connections are duplicating (it happened before but now it happens sooner) - OVPN server and client change cipher from null to aes 128 gcm - it somehow changed the path for my container from disk2 to slot1-p...
by manojlovicl
Tue Jan 03, 2023 12:11 am
Forum: General
Topic: Let's Encrypt and dynamic Address List firewall rules
Replies: 0
Views: 1617

Let's Encrypt and dynamic Address List firewall rules

Hi! In this great video (https://www.youtube.com/watch?v=T1Dyg4_caa4), colleague Druvis Timma explains how to configure Let's Encrypt on MikroTik and also touches the problem about renewal and opening of the router's port 80 for Let's Encrypt verification. After following the instructions I found ou...
by manojlovicl
Mon Dec 19, 2022 12:48 pm
Forum: General
Topic: Recover router configuration by using SNMP?
Replies: 11
Views: 888

Re: Recover router configuration by using SNMP?

No, it is completely fine - I also think that revealing such information could lead to bigger problems. Do not worry, my first thought was that maybe anyone knows if I do not know maybe by going through SNMP with DUDE can give any better results... All good! Thank you! Tutto bene! :)

Luka
by manojlovicl
Mon Dec 19, 2022 12:39 pm
Forum: General
Topic: Recover router configuration by using SNMP?
Replies: 11
Views: 888

Re: Recover router configuration by using SNMP?

Well, it can be even more complicated - that you need to help a company where someone left and there is no documentation but yes, I understand what you intended to say. It is quite a basic thing so I think I will be able to resolve most of the things by snmp walk output. Thank you colleagues for you...
by manojlovicl
Mon Dec 19, 2022 12:31 pm
Forum: General
Topic: Recover router configuration by using SNMP?
Replies: 11
Views: 888

Re: Recover router configuration by using SNMP?

[…] is possible to recover router configuration if you […]you do have SNMP read-only password and router access ? […] If for "and router access" you mean that you can query by SNMP the device, simply, not. So you think that I need to find things out by checking the output of snmp walk and...
by manojlovicl
Sun Dec 18, 2022 10:13 pm
Forum: General
Topic: Recover router configuration by using SNMP?
Replies: 11
Views: 888

Re: Recover router configuration by using SNMP?

SNMP walk is what I did but I am not completely sure there is everything - I was thinking if there is any other way to somehow use this SNMP read-only community string to get to full config... Thank you for your answer!
by manojlovicl
Sat Dec 17, 2022 12:43 am
Forum: General
Topic: Recover router configuration by using SNMP?
Replies: 11
Views: 888

Recover router configuration by using SNMP?

Hi!

I would like to know if anyone can tell me if it is possible to recover router configuration if you do not have (winbox, ssh...) password but you do have SNMP read-only password and router access?

Thank you,
Luka
by manojlovicl
Sun Oct 16, 2022 9:24 am
Forum: General
Topic: Containers (permissions - chown)
Replies: 5
Views: 808

Re: Containers (permissions - chown)

:) I understand that but it would be much nicer to have it "integrated" ...
by manojlovicl
Sun Oct 16, 2022 9:11 am
Forum: General
Topic: Containers (permissions - chown)
Replies: 5
Views: 808

Re: Containers (permissions - chown)

I would like to run it on CHR - the space and ram is not a problem there but do you have any idea how to solve this chown issue?

Thank you!
Luka
by manojlovicl
Sun Oct 16, 2022 12:29 am
Forum: Announcements
Topic: v7.6rc is released!
Replies: 94
Views: 28965

Re: v7.6rc is released!

*) netwatch - fixed string variable values in script;

Colleagues, can you please implement the option to declare host down only after some failed checks? So can Failed tests be used as trigger for Down? That would be great.

Luka
by manojlovicl
Sun Oct 16, 2022 12:25 am
Forum: General
Topic: Containers (permissions - chown)
Replies: 5
Views: 808

Containers (permissions - chown)

Hi! I would like to run UptimeKuma on my MikroTik devices but I have problem as this software has a startup script that wants to change some permissions on app data folder. Is it possible to overcome this problem? https://github.com/louislam/uptime-kuma Problem: https://github.com/louislam/uptime-ku...
by manojlovicl
Sat Feb 26, 2022 10:16 am
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 42581

Re: v7.2rc4 is released!

Hi! *) ppp - improved stability when handling large amount of connections simultaneously; I am still having problems with PPP sessions - CCR that is running as PPP Server (OVPN) suddenly starts to duplicate sessions without eliminating old ones ... I found out that also configuration changes that ar...
by manojlovicl
Sun Jan 05, 2020 10:46 am
Forum: General
Topic: Installing / running dude on internal storage on hAP ac²
Replies: 6
Views: 2327

Re: Installing / running dude on internal storage on hAP ac²

Thank you very much for the answer! I am getting some of those tomorow! :)

Izredno me je razveselilo tole sporočilo! :) Za enkrat vse deluje super tako, da gremo dalje, naj živi in se razvija MikroTik! :)

Pozdrav,
Luka
by manojlovicl
Sat Jan 04, 2020 11:16 am
Forum: General
Topic: Installing / running dude on internal storage on hAP ac²
Replies: 6
Views: 2327

Re: Installing / running dude on internal storage on hAP ac²

Great, thank you for the reply - so you are using USB stick that has metallic enclosure? Like https://www.mimovrste.com/usb-kljuci/ki ... e9g2-32-gb ?

Yes, Nova Gorica! :)

Luka
by manojlovicl
Sat Jan 04, 2020 10:54 am
Forum: General
Topic: Installing / running dude on internal storage on hAP ac²
Replies: 6
Views: 2327

Re: Installing / running dude on internal storage on hAP ac²

Hi! Thank you for explanation - what a pity - I need Dude to do some local SNMP monitoring that will not grow more than 500K the database ... Well I will go for a USB fit stick. Can you suggest any do you have any experience with USB fit sticks and Mikrotik?

Thank you,
Luka
by manojlovicl
Sat Jan 04, 2020 12:59 am
Forum: General
Topic: Installing / running dude on internal storage on hAP ac²
Replies: 6
Views: 2327

Installing / running dude on internal storage on hAP ac²

Hi! I would like kindly ask you if it possible to run / install and use Dude on standalone hAP ac²? I am getting strange results - I setup a device and parameters but after rebooting the route everything is lost and I need to configure it again - so I am asking - am I doing something wrong by leavin...
by manojlovicl
Tue Oct 15, 2019 12:43 pm
Forum: The Dude
Topic: Export data (time interval) to table
Replies: 3
Views: 8964

Re: Export data (time interval) to table

I managed to open DB with DB Browser for SQLLite and I am able to find data but: Does anyone know how to get date/time from sourceIDandTime column? I have value like: 130899289405392 in this column and some value in column value (which is OK). But I would like to know how to "decrypt" sour...
by manojlovicl
Sun Oct 13, 2019 10:53 am
Forum: The Dude
Topic: Export data (time interval) to table
Replies: 3
Views: 8964

Export data (time interval) to table

Hi! I am running DUDE just to make a simple SNMP query to some device by using data source. It works great - I am getting the graph. I would like to ask if it is somehow possible to export the raw data to csv or some other table - for example for some time interval (like between 18:30 and 22:00)? Th...
by manojlovicl
Sat Aug 31, 2019 1:37 am
Forum: Announcements
Topic: v6.45.5 [stable] is released!
Replies: 53
Views: 49892

Re: v6.45.5 [stable] is released!

I have two routers that are doing BGP (they are made redundant by using VRRP ...) Since update on 6.45.5 IPv6 static routes are simply ignored and after BGP becomes stable (after rebooting that was needed for update) I was forced to change gateway to some dummy IP on all static routes in my routing ...
by manojlovicl
Fri Jul 12, 2019 8:07 pm
Forum: General
Topic: SSTP VPN + port forwarding with multiple WAN ipv4 addresses
Replies: 4
Views: 2077

Re: SSTP VPN + port forwarding with multiple WAN ipv4 addresses

Just don't forget you need to use policy routing to properly choose an outgoing route via the corresponding WAN for each of the two server processes (SSTP and HTTPS). /ip route rule is enough, you don't need to fiddle with /IP firewall mangle. What if I have two public IPv4 addresses on same WAN in...
by manojlovicl
Fri Jul 12, 2019 2:03 pm
Forum: General
Topic: SSTP VPN + port forwarding with multiple WAN ipv4 addresses
Replies: 4
Views: 2077

SSTP VPN + port forwarding with multiple WAN ipv4 addresses

Hi! I would like kindly ask if anyone knows if it is possible to run SSTP VPN server on Mikrotik if there are multiple WAN IPv4 addresses (let say 2) but on first I would like to have port forwarding to internal HTTPS server on second I would like MikroTik to terminate SSTP VPN connections. Is it po...
by manojlovicl
Sun Jun 02, 2019 12:10 pm
Forum: Scripting
Topic: Sending SMS using Infobip service and MikroTik tool / fetch feature - http-header-field example
Replies: 2
Views: 2014

Re: Sending SMS using Infobip service and MikroTik tool / fetch feature - http-header-field example

I just recycled the concept that I am using with Powershell scripts - yes as far as I can read in documentation I could user username / password combination as well.

Luka
by manojlovicl
Sat Jun 01, 2019 1:40 pm
Forum: Scripting
Topic: Sending SMS using Infobip service and MikroTik tool / fetch feature - http-header-field example
Replies: 2
Views: 2014

Sending SMS using Infobip service and MikroTik tool / fetch feature - http-header-field example

Hi! I somehow managed to succeed getting SMS sent from my MikroTik device by using tool fetch. /tool fetch http-method=post mode=https http-header-field=”content-type:application/json,Authorization:Basic key23123832″ http-data=”{ \”from\”:\”MyMonitoring\”, \”to\”:[\”386xxyyyzzz\”], \”text\”:\”HOST x...
by manojlovicl
Sat Jun 01, 2019 1:19 pm
Forum: Scripting
Topic: MikroTik – Netwatch enhanced (updated June 2019)
Replies: 0
Views: 1147

MikroTik – Netwatch enhanced (updated June 2019)

Netwatch is a great feature but sometimes there is a need to wait more than just one lost ping to trigger some action ... I managed to solve it by scripting an "extension" to Netwatch - hope it is useful to someone: https://luka.manojlovic.net/2019/06/01/mikrotik-netwatch-enhanced-updated-...
by manojlovicl
Sat Jun 01, 2019 9:52 am
Forum: Scripting
Topic: How to use fetch http-header-field since 6.43.12 [SOLVED]
Replies: 6
Views: 6492

Re: How to use fetch http-header-field since 6.43.12 [SOLVED]

http-header-field="Header1: Value1,Authorization: Basic dXNlcjpwYXNz" But for basic authentication you can also use: user=user password=pass Hi! I managed to do it: http-header-field="content-type:application/json,Authorization:Basic SomeString1234" and it works! :) Thank you!
by manojlovicl
Sat Jun 01, 2019 1:00 am
Forum: Scripting
Topic: How to use fetch http-header-field since 6.43.12 [SOLVED]
Replies: 6
Views: 6492

Re: How to use fetch http-header-field since 6.43.12 [SOLVED]

you can now specify many headers, separated by comma:

http-header-field=h1:fff,h2:yyy
Hi! Does anyone know how you can add a header that has a space inside? For example: http-header-field=Authorization:Basic test123

Thank you!
by manojlovicl
Sat Feb 02, 2019 5:47 pm
Forum: General
Topic: IPSec "route based" S2S VPN with Azure
Replies: 5
Views: 3741

Re: IPSec "route based" S2S VPN with Azure

Yes, it works like policy based VPN now (even though I am using IKE2). But unfortunately there is no possibility to use ipip or something like that ...
by manojlovicl
Sat Feb 02, 2019 11:48 am
Forum: General
Topic: IPSec "route based" S2S VPN with Azure
Replies: 5
Views: 3741

IPSec "route based" S2S VPN with Azure

Hi! I want to use 2 on-prem MikroTik routers to connect to Azure Virtual network - to do so I need to choose route based VPN (attachment multiple-active-tunnels.png). It uses IKE2 which is good and it works with MikroTik - I am also able to configure BGP so I get routes announced from Azure - and I ...
by manojlovicl
Thu Nov 08, 2018 10:21 am
Forum: General
Topic: SSTP VPN with trusted public certificate
Replies: 3
Views: 1578

Re: SSTP VPN with trusted public certificate

Oh! I did not do that... I will try again. Thank you, thank you!
by manojlovicl
Thu Nov 08, 2018 9:17 am
Forum: General
Topic: SSTP VPN with trusted public certificate
Replies: 3
Views: 1578

SSTP VPN with trusted public certificate

Hi! I would like to know which extensions must a certificate have to work with SSTP VPN. Currently I have created a self-signed cert on Mikrotik and deployed it to my Local Machine certificate store on Windows and it works but I would like to buy a certificate from a trusted public certification aut...
by manojlovicl
Sat Sep 08, 2018 12:03 am
Forum: General
Topic: AutoMasshTik - Mass software update and firmware upgrade tool
Replies: 0
Views: 1744

AutoMasshTik - Mass software update and firmware upgrade tool

Hi! For all those who would like to execute massive software update (/system packages update install) and after that massive firmware upgrade (/system routerboard upgrade (and reboot)) on your MikroTiks, now we have a solid solution. I run a network of free public hot-spots in Slovenia called wlan.n...
by manojlovicl
Tue Feb 21, 2017 10:42 pm
Forum: General
Topic: Netwatch timeout
Replies: 0
Views: 988

Netwatch timeout

Hi!

I was testing netwatch today and I have increased the timeout to 30000 = 30 seconds... But I found out that it only makes a second ping (after first one timeout) after one minute and 30 seconds in stead of 30 seconds only?
Using latest firmware - 6.38.1

Luka
by manojlovicl
Sun Nov 06, 2016 3:48 am
Forum: General
Topic: NIC-Teaming and Bonding
Replies: 2
Views: 3127

Re: NIC-Teaming and Bonding

I would use switch indepedent teaming as MT is not good with LACP/Static teaming. And by the way - you must know that you will not have 2 gigabit per one TCP session. Only multiple sessions will be loadbalanced between cards - by the way I suggest to use load balancing algorithm: dynamic And the sec...
by manojlovicl
Sun Jul 17, 2016 4:48 pm
Forum: Scripting
Topic: Enhanced NetWatch
Replies: 0
Views: 1136

Enhanced NetWatch

Hi! Maybe someone Will find this useful: http://luka.manojlovic.net/2016/07/17/mikrotik-netwatch-enhanced/ I have created a script that does some additonal pinging after netwatch UP/DOWN is triggered so you do not change things (change configuration / trigger actions) until you are "sure" ...
by manojlovicl
Mon May 30, 2016 3:47 am
Forum: General
Topic: Hotspot - Login by: MAC
Replies: 1
Views: 1896

Hotspot - Login by: MAC

Hi! I try to setup hotspot to be transparent (only use with advertise feature (hotspot user profile / advertise) so it should not popup login page - I want users to be automaticaly authenticated by using MAC address. So on Server profiles / hsprof1 configuration I selected only Login by: MAC and MAC...
by manojlovicl
Thu Aug 06, 2015 1:50 am
Forum: General
Topic: CRS125-24G-1S in combination with 1100 AH (x2) slow / loss after couple of days?
Replies: 0
Views: 661

CRS125-24G-1S in combination with 1100 AH (x2) slow / loss after couple of days?

Hi! I have a strange situation - my scenario is like this: CCR1036-12G-4S - Cloud core router 1 (vrrp) CCR1036-12G-4S - Cloud core router 2 (vrrp) connected to: CRS125-24G-1S - Cloud core switch (no vlans - access mode) in which I have connected 3 other routers: 1100AHx2 1100AHx2 1100AH after some t...
by manojlovicl
Thu Mar 26, 2015 2:22 pm
Forum: General
Topic: Cloud core switch - example
Replies: 4
Views: 1937

Re: Cloud core switch - example

Ok - how can I restrict vlan 1 not to be on all ports - but only on port 24 (untagged + other tagged vlans) and only on port 4 not on other 3 ports?

Did not I do that with VLAN tab - if you check my config?
by manojlovicl
Thu Mar 26, 2015 2:11 pm
Forum: General
Topic: Cloud core switch - example
Replies: 4
Views: 1937

Re: Cloud core switch - example

Hi! The example is not the same - in this example you have 3 tagged vlans going into - and no default untagged vlan (like in my example - vlan 1). I would like to know how can I be 100% shure that everything is isolated completely - for example I would like to force Access ports to be only for untag...
by manojlovicl
Wed Mar 25, 2015 11:57 pm
Forum: General
Topic: Cloud core switch - example
Replies: 4
Views: 1937

Cloud core switch - example

Hi! Can someone please help me out with an example of vlan config? I would like to make souch setup: Port 24 - untagged vlan 1 + tagged vlan 10 + tagged vlan 11 + tagged vlan 12 Port 1 - untagged vlan 10 Port 2 - untagged vlan 11 Port 3 - untagged vlan 12 Port 4 - untagged vlan 1 I have configured S...
by manojlovicl
Tue Aug 19, 2014 8:34 am
Forum: RouterBOARD hardware
Topic: Info trunk + native vlan
Replies: 1
Views: 1657

Info trunk + native vlan

Hi!

If we take a look at first example @ http://wiki.mikrotik.com/wiki/Manual:CRS_examples

In my scenario I would like to have also native (untagged) vlan (1) passing through ether2 and going to let say ether5

Is it possible to somehow get it trough?
by manojlovicl
Mon Aug 18, 2014 11:53 pm
Forum: RouterBOARD hardware
Topic: Cloud Router Switch 24 port - trunk port + native vlan
Replies: 0
Views: 927

Cloud Router Switch 24 port - trunk port + native vlan

Hi! I would like to kindly ask you if it possible to pass native vlan (1) from Trunk port to an Access port on CRS? So if you take a look at example 1: http://wiki.mikrotik.com/wiki/Manual:CRS_examples In my scenario I have untagged (vlan1) that I would like to pass through port Ether2 (that has onl...