Community discussions

MikroTik App

Search found 33 matches

by morituruz
Fri Sep 29, 2017 1:59 pm
Forum: Beginner Basics
Topic: Divide users on 2 WAN from same LAN
Replies: 4
Views: 686

Re: Divide users on 2 WAN from same LAN

Hello.
1. In mangle mark outgoing traffic from these users with some routing mark
2. In routes set bigger distance in existing "0.0.0.0/0" routes
3. add route with routing mark from 1. to wan1
by morituruz
Thu Sep 28, 2017 2:12 pm
Forum: Beginner Basics
Topic: Telnet - Two dsl link
Replies: 1
Views: 348

Re: Telnet - Two dsl link

I do not quite understand what you want but if you want to use port forwarding with two wan interfaces you should try this:
https://wiki.mikrotik.com/wiki/Manual:PCC
by morituruz
Thu Sep 28, 2017 2:05 pm
Forum: Beginner Basics
Topic: Multiple DNS server issues
Replies: 9
Views: 2682

Re: Multiple DNS server issues

Check DNS settings in your DHCP server (in mikrotik: /ip dhcp network)
by morituruz
Thu Sep 28, 2017 2:00 pm
Forum: Beginner Basics
Topic: 2 isps 2 lans and dst-nat
Replies: 4
Views: 601

Re: 2 isps 2 lans and dst-nat

by morituruz
Thu Sep 28, 2017 1:44 pm
Forum: Beginner Basics
Topic: Setting up a network with Mikrotik
Replies: 8
Views: 1360

Re: Setting up a network with Mikrotik

I see no load balancing in your configuration so i can't tell whats wrong :)
Easiest way to archieve balancing is to specify multiple gateways in default route
Something like that:
/ ip route
add dst-address=0.0.0.0/0 gateway=10.111.0.1,10.112.0.1 check-gateway=ping
by morituruz
Sun Sep 24, 2017 8:19 pm
Forum: Beginner Basics
Topic: EoIP + bridge + different subnets = half-broken internet
Replies: 3
Views: 718

Re: EoIP + bridge + different subnets = half-broken internet

MTU of bridge = MTU of bridge port with smallest MTU.
Try to manually set MTU to 1500 in every interface that belongs to bridge.
by morituruz
Fri Sep 22, 2017 12:29 pm
Forum: Beginner Basics
Topic: Help me tu understand some firewall rules
Replies: 10
Views: 1234

Re: Help me tu understand some firewall rules

Also this is a no sense for me
forward is a different chain, look at the diagram:
Image
by morituruz
Fri Sep 22, 2017 8:36 am
Forum: Beginner Basics
Topic: Setting up a network with Mikrotik
Replies: 8
Views: 1360

Re: Setting up a network with Mikrotik

I also tried to follow this Wiki article with no luck.
Post your current config (filter, mangle, routes)
by morituruz
Thu Sep 21, 2017 3:32 pm
Forum: Beginner Basics
Topic: Dual WAN not responding to external telnet/WinBox requests
Replies: 11
Views: 1564

Re: Dual WAN not responding to external telnet/WinBox requests

Actually, prerouting and input are different, and should be used for different purposes.
Marking in prerouting is conveniently because covers both port forwarding (dst-nat) and input staff (ping, winbox). I think that is why it's used in wiki, so this is right approach.
by morituruz
Thu Sep 21, 2017 9:47 am
Forum: Beginner Basics
Topic: Dual WAN not responding to external telnet/WinBox requests
Replies: 11
Views: 1564

Re: Dual WAN not responding to external telnet/WinBox requests

tomaskir is not quite right because it's better to mark connections in prerouting rather then in input. Look at pcc example: https://wiki.mikrotik.com/wiki/Manual:PCC#Application_Example_-_Load_Balancing May be you forgot to add respective routes for that routing marks (like in pcc example). And you...
by morituruz
Wed Sep 20, 2017 12:36 pm
Forum: Beginner Basics
Topic: Packets getting stuck behind NAT
Replies: 1
Views: 395

Re: Packets getting stuck behind NAT

You need to specify the in-interface. Try that:
 ip firewall nat add chain=dstnat in-interface=ether1 protocol=tcp port=80,443 to-addresses=10.254.254.3
by morituruz
Tue Sep 19, 2017 6:32 pm
Forum: Beginner Basics
Topic: New router. Cannot access certain websites? [SOLVED]
Replies: 2
Views: 963

Re: New router. Cannot access certain websites? [SOLVED]

in-interface=ether1
It's enough
by morituruz
Tue Sep 19, 2017 8:22 am
Forum: Beginner Basics
Topic: Firewall Filter Rules
Replies: 1
Views: 558

Re: Firewall Filter Rules

Make address-list with all domains from that page (check out all links in page code) and drop everything else expect this list (tcp & udp 80, 443 port).
by morituruz
Tue Sep 19, 2017 8:06 am
Forum: Beginner Basics
Topic: FTP server behind multiwan with load balance
Replies: 3
Views: 661

Re: FTP server behind multiwan with load balance

I can mark port 21 but, how do mark the data coming from an unknown data port?
Make all traffic from this pc go through only one wan by src-address so no load balancing for this pc
by morituruz
Mon Sep 18, 2017 11:06 pm
Forum: Beginner Basics
Topic: Access to my LAN from external network.
Replies: 18
Views: 2727

Re: Access to my LAN from external network.

и как на нем исключить мою внутреннюю сеть я хз.
May be you actually dont need that setting in TP-Link. Just try to add routes as i said.
by morituruz
Mon Sep 18, 2017 10:59 pm
Forum: Beginner Basics
Topic: FTP server behind multiwan with load balance
Replies: 3
Views: 661

Re: FTP server behind multiwan with load balance

Read wikipedia about FTP. It has more than one connection by design so related connection (data connection) probably just goes through another WAN.
You can try to switch passive/active mode in FTP settings.
More robust design is to mark ftp server traffic in mangle and bind it to single WAN.
by morituruz
Mon Sep 18, 2017 8:01 pm
Forum: Beginner Basics
Topic: Access to my LAN from external network.
Replies: 18
Views: 2727

Re: Access to my LAN from external network.

Если вы с соседом действительно в одной сети, то nat в принципе не нужен. Нужно на обоих маршрутизаторах исключить внутреннюю сеть из src-nat правила для интернета (если есть) и прописать маршруты на внутренние подсети за маршрутизаторами (ваша это 10.1.0.1/24) с gateway=ip_противоположного_маршрути...
by morituruz
Mon Sep 18, 2017 12:32 pm
Forum: Beginner Basics
Topic: Access to my LAN from external network.
Replies: 18
Views: 2727

Re: Access to my LAN from external network.

Danila, do you speak russian? Can you ping ip address of your neighbor?
by morituruz
Mon Sep 18, 2017 12:21 pm
Forum: Beginner Basics
Topic: Web proxy over nat
Replies: 3
Views: 569

Re: Web proxy over nat

it says Connection Refused.
Looks like web server won't accept that connection. Check out his logs. May be there is some restrictions in server settings
by morituruz
Mon Sep 18, 2017 11:08 am
Forum: Beginner Basics
Topic: EoIP + bridge + different subnets = half-broken internet
Replies: 3
Views: 718

Re: EoIP + bridge + different subnets = half-broken internet

It's MTU-related problem. It should be 1500 in all interfaces (EoIP and probably in bridge too).
by morituruz
Sun Sep 17, 2017 2:33 pm
Forum: Beginner Basics
Topic: Web proxy over nat
Replies: 3
Views: 569

Re: Web proxy over nat

For routeros internal proxy you need action=redirect to 8080, not dst-nat.
by morituruz
Sun Sep 17, 2017 12:23 pm
Forum: Beginner Basics
Topic: Remove Comment with Wildcard
Replies: 2
Views: 626

Re: Remove Comment with Wildcard

«~» mean regular expression:
/ip firewall address-list remove [find comment~"Test Group *"]
by morituruz
Sat Sep 16, 2017 11:05 pm
Forum: Beginner Basics
Topic: ip firewall diagram
Replies: 3
Views: 892

Re: ip firewall diagram

pe1chl, i know about wiki page, but my picture is about /ip firewall only and yes, its intended for beginners
by morituruz
Sat Sep 16, 2017 9:06 pm
Forum: Beginner Basics
Topic: ip firewall diagram
Replies: 3
Views: 892

ip firewall diagram

I think it would be helpful for beginners
routeros_ip_firewall.jpg
by morituruz
Tue May 02, 2017 3:16 pm
Forum: Announcements
Topic: v6.39 [current]
Replies: 89
Views: 39726

Re: v6.39 [current]

https://www.youtube.com/watch?v=diA-5e7TdZM Thanks, i know about layer7 based solutions. Personally I haven't found any 100% reliable method without having to do some settings on each torrent client's PC (read bellow). But I haven't looked into it the last 2-3 years to be honest, so there maybe oth...
by morituruz
Tue May 02, 2017 12:41 pm
Forum: Announcements
Topic: v6.39 [current]
Replies: 89
Views: 39726

Re: v6.39 [current]

It's great that you think it did it's job, but actually it was not doing anything.
It's doing its job pretty well actually.
I just checked it again right now on 6.39rc41.

Rules disabled:
Image


Rules enabled:
Image
by morituruz
Tue May 02, 2017 11:27 am
Forum: Announcements
Topic: v6.39 [current]
Replies: 89
Views: 39726

Re: v6.39 [current]

!) firewall - discontinued support for p2p matcher (old rules will become invalid);
So how we should detect p2p traffic now?
p2p matcher with two-step method (add destination ip to address list and block/prioritize this list) is working very good for me.
by morituruz
Wed Mar 23, 2016 9:35 am
Forum: General
Topic: Feature request: DNS server priority
Replies: 0
Views: 1151

Feature request: DNS server priority

Hello.
I want something like route distance for DNS servers.
Example: in normal situation all DNS requests should go to DNS servers with priority=0, but when they become unreachable by any reason all DNS requests should go to servers with priority=1 and so on.
by morituruz
Fri Mar 04, 2016 1:27 pm
Forum: General
Topic: Anyone have issues with Mikrotik NTP servers not coming up?
Replies: 2
Views: 1133

Re: Anyone have issues with Mikrotik NTP servers not coming up?

I have same problem on every router. Tested it with filter rules in input and output chains. I see that ntp request is coming in input chain but no packets is sent back to answer this requests. In my case disabling-enabling NTP server may fix it but not for long. I even wrote a script for that: # pr...
by morituruz
Sun Jan 31, 2016 8:44 pm
Forum: Scripting
Topic: Command «find» somtimes failed with big address-lists
Replies: 2
Views: 688

Re: Command «find» somtimes failed with big address-lists

How can i protect my scripts from this error? do={} on-error={} does not help.
by morituruz
Fri Jan 22, 2016 1:19 pm
Forum: Scripting
Topic: Command «find» somtimes failed with big address-lists
Replies: 2
Views: 688

Command «find» somtimes failed with big address-lists

I have some thousands of the IP's in ip firewall address-list . Sometimes find command failed with error "no such item (4)" Test script: :local tmpAddress "104.16.109.203"; :local ListName "CENSORED"; :do { :if ([/ip firewall address-list find address="$tmpAddress" list="$ListName"]="") do={ :log in...
by morituruz
Tue Nov 17, 2015 8:39 am
Forum: General
Topic: DHCP networks selection
Replies: 0
Views: 507

DHCP networks selection

Hello.
I can create ip dhcp-server network 192.168.0.0/24 with some properties and i can create network 192.168.0.100/30 with different properties. How DHCP server will decide which settings will be sent to IP that belongs to both networks?