Community discussions

MikroTik App

Search found 348 matches

  • 1
  • 2
by loveman
Sun Sep 06, 2020 6:42 pm
Forum: Virtualization
Topic: Vmware can't reach to userman
Replies: 1
Views: 5478

Vmware can't reach to userman

Hello everyone, I need to setup and enable usermanager with hotspot by GNS3 Vmware with CHR so my lab simple with Router one and before that I am setup file of usermanager with the same version all its fine and setup hotspot, My problem i can't access to userman by browser and my ip of that "1...
by loveman
Tue Jun 02, 2020 12:02 am
Forum: Virtualization
Topic: VPN problem in gns3 ipsec?
Replies: 0
Views: 3072

VPN problem in gns3 ipsec?

Hello everyone, My case i used chr 6.46.6 in gns3 2.2.8 and the same version of gns3 2.2.8 in VMware workstation. In this lab i will show you in picture below: Lab.jpg I need to connect vpn ipsec between R1 and R2 through R Internet, Applied to configure ipsec in R1 and R2 all configure of Routers s...
by loveman
Sat May 30, 2020 1:44 pm
Forum: General
Topic: [SOLVED] Hotspot with SSL: Private Key and Certificate fail
Replies: 18
Views: 28712

Re: [SOLVED] Hotspot with SSL: Private Key and Certificate fail

I dont have linux to doing the certificate, Can anyone advice me how to doing in windows?
Because i need to connection secure for my hotspot login webpage https certificate !!
by loveman
Wed May 13, 2020 11:18 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

You don't need to put anything in there, the max allowed is used by default. Which one you mean that? My tested putting the TX power in channel of capsman server = 20 its good one the signal strength best of when using -10 for example! TX power is normally given in positive numbers, but you know th...
by loveman
Wed May 13, 2020 10:59 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

Set control channel width to 20Mhz and extention channel either disabled, in case you only want to use 20Mhz as channel width, or Ce, eC, XX in case you want to support 40 Mhz channel width as well... Thank you, After tested when i selected the 40 Mhz and tried Ce, eC, XX but in log show failed to ...
by loveman
Sun May 10, 2020 12:30 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

In my cause my country Not Found with list, So i selected the Installation "indoor" Those two (country and installation type) are complementary, meaning that installation type does not work at all without country being specified. I guess when running your AP without CAPsMAN your obvious c...
by loveman
Sun May 10, 2020 12:26 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

Set control channel width to 20Mhz and extention channel either disabled, in case you only want to use 20Mhz as channel width, or Ce, eC, XX in case you want to support 40 Mhz channel width as well... Thank you, After tested when i selected the 40 Mhz and tried Ce, eC, XX but in log show failed to ...
by loveman
Sat May 09, 2020 2:36 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

Your question is already answered... If you leave the Tx Power empty, the MAX allowed by interface is used...! However, you must use the Tx Power allowed in your Country ... That is why we select the Country... Therefore, I did not know what is the correct value chosen because my country is not in ...
by loveman
Sat May 09, 2020 1:01 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

If under Capsman -> Configurations -> Wireless you did set your Country (as you should) then the Tx Power will be the maximum allowed for you Country... Only in case you want to lower the Tx Power you do use the Tx Power paramater field... In my cause my country Not Found with list, So i selected t...
by loveman
Sat May 09, 2020 12:45 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

You don't need to put anything in there, the max allowed is used by default.
Which one you mean that?
My tested putting the TX power in channel of capsman server = 20 its good one the signal strength best of when using -10 for example!
by loveman
Sat May 09, 2020 12:33 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

The signal strength will be the same as long as your configuration is correct....
I am need to active capsman inside of building so whats the TX power should i set in capsman"channels configuration" because the signal strength depend on TX power?
Captureq1.jpg
by loveman
Sat May 09, 2020 10:55 am
Forum: Wireless Networking
Topic: Help in Configuration of CAPsMAN
Replies: 3
Views: 1607

Re: Help in Configuration of CAPsMAN

Local forwarding will take a large load off your network. 5Ghz doesn't through objects very well. I saw the problem when tested the signal i believe caps signal maybe the weakest signal in a broadcast "cap" when compared to the usual wireless from the same device "cap" so I used...
by loveman
Sat May 09, 2020 10:49 am
Forum: General
Topic: Firewall Rules openVPN Server
Replies: 4
Views: 3070

Re: Firewall Rules openVPN Server

hi loveman, now I spent some additional days - tried to get the openvpn server running again but without any success... I am not able to connect anymore... I startet the whole configuration from begin with following commands: #create ca# /certificate add name=ca-template common-name=myCa key-usage=...
by loveman
Tue May 05, 2020 9:58 am
Forum: Wireless Networking
Topic: Help in Configuration of CAPsMAN
Replies: 3
Views: 1607

Re: Help in Configuration of CAPsMAN

In your question: d) I have significant loss in signal strength after about 6 meters with some wardrobe and one drywall between. Is this normal for 5GHz or do I have to define the bands and bandwith in detail? I have the same problem, I saw the wireless interface of the same device "cap" w...
by loveman
Tue May 05, 2020 9:29 am
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 5658

CapsMan with mikrotik Vs Wireless mikrotik only?

Hello everyone, I am tested my project to building capsman server with caps so after finished all config and caps worked as well and lock capsman key with caps and its all worked as good, I saw the problem when tested the signal i believe caps signal maybe the weakest signal in a broadcast "cap...
by loveman
Wed Apr 08, 2020 10:04 am
Forum: General
Topic: Firewall Rules openVPN Server
Replies: 4
Views: 3070

Re: Firewall Rules openVPN Server

I think the problem in openvpn software you should edit again to set all information of your vpn
by loveman
Tue Mar 10, 2020 7:59 am
Forum: General
Topic: How to stop sharing internet connection with "baidu"
Replies: 8
Views: 4190

Re: How to stop sharing internet connection with "baidu"

Options: a. Provide separate internet access - because there seems to be a requirement or need for this, and for it not to interrupt or be mixed up with WORK internet/network. b. IF another internet access is not possible (i) Provide a warning that use of illegal internet/wifi on business network i...
by loveman
Tue Mar 10, 2020 7:47 am
Forum: General
Topic: How to stop sharing internet connection with "baidu"
Replies: 8
Views: 4190

Re: How to stop sharing internet connection with "baidu"

This kind of policy control cannot be handled at network layer anymore. As I see it , you will never be able to tell who coming in through "Baidu" "wireless AP" app and who is a regular wireless/wired user on you network. You will have to think about some PROXY system granting a...
by loveman
Mon Mar 09, 2020 1:16 pm
Forum: General
Topic: How to stop sharing internet connection with "baidu"
Replies: 8
Views: 4190

Re: How to stop sharing internet connection with "baidu"

Will be difficult, if not impossible. 1) As this is an application, you should talk to the system guys. It is not the "task" of the network-guy to plug the holes caused by mis-managed desktop systems! Being able to install this software so your PC performs ICS (Internet Sharing Connection...
by loveman
Sun Mar 08, 2020 6:11 pm
Forum: General
Topic: How to stop sharing internet connection with "baidu"
Replies: 8
Views: 4190

Re: How to stop sharing internet connection with "baidu"

Will be difficult, if not impossible. 1) As this is an application, you should talk to the system guys. It is not the "task" of the network-guy to plug the holes caused by mis-managed desktop systems! Being able to install this software so your PC performs ICS (Internet Sharing Connection...
by loveman
Sun Mar 08, 2020 8:52 am
Forum: General
Topic: How to stop sharing internet connection with "baidu"
Replies: 8
Views: 4190

How to stop sharing internet connection with "baidu"

Hello everyone, I need to block program that working with windows 7, 8 The program name "baidu wifi hotspot" how can block by mikrotik I used method to change the TTL to 1 but program can working without any block and since that my mikrotik version 6.45.1, Used PPP, PPPOE Server in my netw...
by loveman
Tue Nov 12, 2019 4:53 pm
Forum: General
Topic: Problem with user access !
Replies: 3
Views: 1292

Re: Problem with user access !

Any help?
by loveman
Tue Nov 12, 2019 6:13 am
Forum: General
Topic: Problem with user access !
Replies: 3
Views: 1292

Re: Problem with user access !

No valid profile found means that the profile has been either expired because of reached uptime limit or because profile validity has ended. So what are the limitations you ve added in the specific user profile? The user have profile limitation "12hour" mean uptime 12hour The user used on...
by loveman
Mon Nov 11, 2019 11:14 am
Forum: General
Topic: Problem with user access !
Replies: 3
Views: 1292

Problem with user access !

Hello everyone In this time i have problem with hotspot and usermanger server, In usermanger server created before long time users like 100 user for example so when i connected to hotspot and write username and password like "netc3r and password 4rx" the user can login direct without any p...
by loveman
Sat Aug 31, 2019 12:17 pm
Forum: The User Manager
Topic: [SHARE] Mikrotik Userman Voucher with QR Code
Replies: 2
Views: 17571

Re: [SHARE] Mikrotik Userman Voucher with QR Code

Did you check out what he had from attack or hack codes! in all codes voucher, which be safe or not! ?
by loveman
Fri Aug 30, 2019 11:42 pm
Forum: General
Topic: Anyone can check the login webpage hotspot from attack codes!
Replies: 10
Views: 3161

Re: Anyone can check the login webpage hotspot from attack codes!

loveman, I guess while this forum would not be the best place to ask for penetration testing for your hotspot app, I do think I have a solution. Some websites offer for you to post a job and let people bid on what they will do for you. Maybe "Fivrr" is the best site for your post. Hope th...
by loveman
Fri Aug 30, 2019 8:39 am
Forum: General
Topic: Anyone can check the login webpage hotspot from attack codes!
Replies: 10
Views: 3161

Re: Anyone can check the login webpage hotspot from attack codes!

I don't think this forum has a lot of professional web developers But it is impossible for users or designers Hotspot service does not know in the topics of page security! This is a forum for routers. Why are you even asking for html configuration help here? Take this to a forum for web designers. ...
by loveman
Fri Aug 30, 2019 8:37 am
Forum: General
Topic: Anyone can check the login webpage hotspot from attack codes!
Replies: 10
Views: 3161

Re: Anyone can check the login webpage hotspot from attack codes!

Usually it is not the same person who is installing the hotspot router, and also doing the web programming, and also making sure the HTML code is valid and safe against injections.
You should ask in another forum.
Do you have a forum to suggest me, And I'am to ask the question there.
by loveman
Fri Aug 30, 2019 1:18 am
Forum: General
Topic: Anyone can check the login webpage hotspot from attack codes!
Replies: 10
Views: 3161

Re: Anyone can check the login webpage hotspot from attack codes!

I don't think this forum has a lot of professional web developers
But it is impossible for users or designers Hotspot service does not know in the topics of page security!
by loveman
Wed Aug 28, 2019 6:34 pm
Forum: General
Topic: Issue when add the certificate for hotspot "https"
Replies: 3
Views: 2117

Re: Issue when add the certificate for hotspot "https"

It's a little more difficult than this. Regular browser contains built-in list of trusted certificate authorities. If you get certificate from any of them, browser is able to verify that truted CA signed it. Another step is who the certificate is for, the most common is specific hostname. So if you...
by loveman
Wed Aug 28, 2019 10:44 am
Forum: General
Topic: Anyone can check the login webpage hotspot from attack codes!
Replies: 10
Views: 3161

Anyone can check the login webpage hotspot from attack codes!

Hello everyone, I have free login webpage for hotspot "template", What is the correct way to find out if it is harmful or the presence of codes may cause harm to users or may be harmful may cause hacking of users' devices, I searched for a design ready for Hotspot page, but I do not know i...
by loveman
Tue Aug 27, 2019 10:55 pm
Forum: General
Topic: Issue when add the certificate for hotspot "https"
Replies: 3
Views: 2117

Issue when add the certificate for hotspot "https"

Hello everyone! I need to add the certificate for hotspot to be showing in address browser "https" secure website!, But when read by searched and applied all steps but the certificate in browser "connection not secure" cert2.png All the steps can see below: /certificate add name=...
by loveman
Mon Aug 26, 2019 11:46 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Sorry but this is now the wrong forum :) You must google some ways to automate QR code generation for big list of links.
I will check with google, But how i know if the voucher have attack with some code! Because i don't know if any code have attack or anything like this?
by loveman
Wed Aug 21, 2019 4:54 pm
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Now you need to generate a lot of usernames and passwords, and then convert each link into new QR code For example http://172.16.1.1/login?username=love&password=nice http://172.16.1.1/login?username=hate&password=bad http://172.16.1.1/login?username=other&password=password Then use som...
by loveman
Wed Aug 21, 2019 10:18 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Did you use correct URL? You should be logged in automatically with this link: http://172.16.1.1/login?username=love&password=nice Yes dear, Now i checked and changed from server profile to "HTTP PAP", And enter with direct link and can login automatic.. Ok In this how to do and apply...
by loveman
Tue Aug 20, 2019 2:06 pm
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Yoru example doesn't match mine. Examine my example URL more carefully. Also you must enable PAP authentication in hotspot server profile
I checked the authentication and selected only PAP authentication, But the same.
What i see after i check the status of the success URL?
by loveman
Tue Aug 20, 2019 10:50 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

I hope that you have read the previous answer reply in order to get you the idea requested by me to be worked out. After i tested what you want from me the result show below: http://172.16.1.1/login?love&nice for example Ip server: 172.16.1.1 Username: love password: nice When i tried to apply w...
by loveman
Tue Aug 20, 2019 9:39 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

sorry, forum software isn't showing the full link the full link is this: http://10.200.0.1/login?username=alex&password=very-good-password I will test and replay the result here.. But if i need to but all users when connect ssid with hotspot should login like QR code. In this time i applied and...
by loveman
Tue Aug 20, 2019 9:24 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Try to think a little bit. I did not give you exact link. this will depend on your own hotspot installation. Have you installed the hotspot in RouterOS? Have you configured it? Does it work and you can log in? Only then you can start thinking about vouchers and QR codes. In this link: http://10.200...
by loveman
Mon Aug 19, 2019 8:49 pm
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Sorry, I thought you want everyone to use the same QR code. If your vouchers are all generated and unique, simply use this format in Hotspot. You will have to enable HTTP PAP method in the hotspot server profile: http://10.200.0.1/login?username=alex&password=very-good-password I tried to open ...
by loveman
Mon Aug 19, 2019 2:16 pm
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

But this QR card will have the same code for everyone, are you not worried about that? If that's ok, you can achieve that easily What you mean "same code", Like username and password that was created by voucher! If you can help me about the "header, Row, Footer, Break" for QR co...
by loveman
Sun Aug 18, 2019 10:25 am
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

https://support.apple.com/en-jo/HT209144#trusted Price and Trust have nothing to do with each other! E.g. Letsencrypt certificates are free and they are trusted, but paid certificates from some used-to-be-big-names like Symantec are NOT Trusted! If possible, please write down the basic steps in ord...
by loveman
Sun Aug 18, 2019 9:11 am
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

Is the website can buy direct to hotspot server mikrotik?
by loveman
Sun Aug 18, 2019 8:48 am
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

When buying a certificate for your website, buy from "trusted" authority.
Otherwise you might face inconvenient issues when using newer IOS clients.
Can you tell me about trusted website to buy from it.
by loveman
Sun Aug 18, 2019 7:43 am
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

You can get certificates for free. But only for your own site. So you cannot get a certificate for Google.com and so you CANNOT SOLVE the redirection problem. And neither can MikroTik. It is just a case of 'sorry but that is no longer possible, forget about it'. That is why you should focus on gett...
by loveman
Sat Aug 17, 2019 7:57 pm
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

@loveman: I think you don't get it, MikroTik can't solve it. The redirection done by captive portals was always dirty trick, an abuse of technology. That's one reason why https became so popular, because too many people liked to tamper with someone else's unprotected traffic. Https prevents that, s...
by loveman
Sat Aug 17, 2019 6:50 pm
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

As written many times above, that issue cannot be solved ! However, the writers of software like Chrome and Android do know that, and they use requests that you do not enter yourself (some DNS and some HTTP requests) to detect this situation. When they find that they are on a hotspot/portal network...
by loveman
Sat Aug 17, 2019 3:43 pm
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

As written many times above, that issue cannot be solved ! However, the writers of software like Chrome and Android do know that, and they use requests that you do not enter yourself (some DNS and some HTTP requests) to detect this situation. When they find that they are on a hotspot/portal network...
by loveman
Sat Aug 17, 2019 12:52 pm
Forum: General
Topic: Hotspot and HTTPS? What solutions?
Replies: 58
Views: 17754

Re: Hotspot and HTTPS? What solutions?

I have the same issue when i connect with ssid "hotspot services" With computer's, After connect to ssid and i go to broswer like google chroum (If i set before in browser login page like "https://www.google.com", In this case the hotspot login page can't change automatic to hots...
by loveman
Sat Aug 17, 2019 9:37 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Any advice
by loveman
Mon Aug 12, 2019 2:28 pm
Forum: Beginner Basics
Topic: how to send all trafic over l2tp clinet vpn
Replies: 4
Views: 1449

Re: how to send all trafic over l2tp clinet vpn

thnx love man after add this nat , vpn is ok and i have internet over the vpn but when ping 8.8.8.8 result is time out but i have internet when i disable vpn ping is ok and very slow internet over the vpn very very slow Check your dns in vpn, can add the public dns over vpn 8.8.8.8, You know about ...
by loveman
Fri Aug 09, 2019 11:56 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

QR code is just a link to any URL. What URL will you send them to? I know that, But i need to create voucher user name and password by hotspot server in user manger, At result i print all card for services and include the QR In this time any one need internet in cafe i gave him the card, After that...
by loveman
Fri Aug 09, 2019 12:56 am
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

Re: How to active or enable QR code with hotspot

Any advice?
by loveman
Thu Aug 08, 2019 3:52 pm
Forum: Beginner Basics
Topic: how to set time limit to dhcp client
Replies: 3
Views: 3030

Re: how to set time limit to dhcp client

You can using user manger like hotspot server to limit time so when the user finish real time after that the user disconnect or no internet service.
by loveman
Thu Aug 08, 2019 3:45 pm
Forum: Beginner Basics
Topic: how to send all trafic over l2tp clinet vpn
Replies: 4
Views: 1449

Re: how to send all trafic over l2tp clinet vpn

Your ip range of vpn should add rule in firewall, nat
and chain: srcnat
src address: range of vpn ip
action: masquerade
by loveman
Thu Aug 08, 2019 3:40 pm
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

Re: After update to ver. 6.45.2 i have issue with ipsec

All you need on third router are only two addresses and nothing else: /ip address add address=192.168.70.1/30 interface=ether1 add address=192.168.80.1/30 interface=ether2 Then connect R1-ether1 with R3-ether1 and R3-ether2 with R2-ether1. Add default routes on R1 and R2 (same as you tried before)....
by loveman
Wed Aug 07, 2019 11:44 pm
Forum: General
Topic: How to active or enable QR code with hotspot
Replies: 23
Views: 18031

How to active or enable QR code with hotspot

Hello everyone, I want to create QR code in hotspot server by make voucher user name and password, When the users can login by 2 ways (step 1 can login by user name and password by created in user manger, Step 2 the users can login by using QR code by create the voucher so in this step the user can ...
by loveman
Wed Aug 07, 2019 1:08 am
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

Re: After update to ver. 6.45.2 i have issue with ipsec

If you have direct connection between ether1 on first router and ether1 on second, it can't work like this, because there's no routing between them. You added routes, but there's no 192.168.80.1 or 192.168.70.1 anywhere. You need to have same subnet on both ether1s, e.g. 192.168.70.1/30 on one rout...
by loveman
Tue Aug 06, 2019 7:24 pm
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

Re: After update to ver. 6.45.2 i have issue with ipsec

It looks like you may be doing something a little different than I thought. Try to share more info about addresses and subnets, these and any other you have on routers. How exactly is everything connected, on what interface is each address, etc. [admin@Office 1] > ip address print Flags: X - disabl...
by loveman
Tue Aug 06, 2019 7:20 pm
Forum: The User Manager
Topic: How to recharge the uptime in hotspot after finish the user days
Replies: 2
Views: 6393

How to recharge the uptime in hotspot after finish the user days

Hello everyone I have created the voucher users in user manger (10 users with username and password) and applied uptime when the user login with hotspot server the uptime go to count down, Suppose the uptime =0 in this case how can the username and password who zero uptime can be recharge the same a...
by loveman
Tue Aug 06, 2019 6:34 pm
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

Re: After update to ver. 6.45.2 i have issue with ipsec

If it's local and you know it, it's ok. You get timeout on phase 1, so first thing to check out is connectivity between 192.168.80.2 and 192.168.70.2. Can they reach each other? Doesn't firewall block port 500? Can you ping between those addresses (if you don't block ping with firewall)? I tested t...
by loveman
Tue Aug 06, 2019 1:10 am
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

Re: After update to ver. 6.45.2 i have issue with ipsec

Phase 1 depends on peer config, it's before policies. Is this just a local test? Because private address for remote peer would not be very useful otherwise.
If i need to connect 2 router local without internet
Using IPsec site to site and have devices for test..
Not pass the lab you mean?
by loveman
Mon Aug 05, 2019 10:26 pm
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

Re: After update to ver. 6.45.2 i have issue with ipsec

SA Src/Dst Address was where you put the same addresses as in peer config. Now you select peer on General tab and they are taken from there automatically. After show in log i have the error below Untitled223.jpg What is the problem and how to solve it? since that the ipsec policies "PH2 State&...
by loveman
Mon Aug 05, 2019 12:03 pm
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

Re: After update to ver. 6.45.2 i have issue with ipsec

SA Src/Dst Address was where you put the same addresses as in peer config. Now you select peer on General tab and they are taken from there automatically.
Thank you for your replay,
I will try soon and replay you here.
Thank you
by loveman
Mon Aug 05, 2019 12:00 pm
Forum: The User Manager
Topic: Mikrotik user-manager voucher printing
Replies: 21
Views: 40057

Re: Mikrotik user-manager voucher printing

Hello, I found this incredible app for android is called MikroTicket https://fhx47.app.goo.gl/mikroticket generates tickets or vouchers for access by hotspot mikrotik and you can configure access times, bandwidth, time runs and makes automatic removal of the vouchers, I use it in my business. https...
by loveman
Mon Aug 05, 2019 12:53 am
Forum: General
Topic: After update to ver. 6.45.2 i have issue with ipsec
Replies: 14
Views: 4391

After update to ver. 6.45.2 i have issue with ipsec

Hello everyone, I have 2 router and need to join by IPSEC between them, So when i need to finish all step before the last one i cant see : SA Src. Address SA Dst. Address In ip>ipsec>policies>Action And you can see the result in photos below: Untitled1.jpg But in ver. 6.37.2 : SA Src. Address SA Dst...
by loveman
Sat Mar 23, 2019 8:00 am
Forum: General
Topic: Question about SSL certificate
Replies: 3
Views: 1397

Re: Question about SSL certificate

Can I know how much the price of the certificate?
by loveman
Sat Mar 23, 2019 7:54 am
Forum: Wireless Networking
Topic: How to calculate the APS for distribution of network to building roaming wireless
Replies: 1
Views: 843

How to calculate the APS for distribution of network to building roaming wireless

Hello everyone,
How can build roaming wireless to benefit that all wifi who connected in network wireless can gets a strong signal all areas of the building and without any disconnect or reconnect, And how can distribute the APS devices in floors?
Any advice
by loveman
Fri Mar 22, 2019 9:41 pm
Forum: General
Topic: Help to config roming wireless
Replies: 4
Views: 1303

Re: Help to config roming wireless

The best thing you can do with Mikrotik is setup all APs with same SSID / authentication, ensure they're all in the same broadcast domain and ensure your DHCP server is very fast at handling requests / renews (eg no pinging for 2 seconds before giving a lease). Unfortunately RouterOS lacks support ...
by loveman
Fri Mar 22, 2019 4:52 pm
Forum: General
Topic: Help to config roming wireless
Replies: 4
Views: 1303

Re: Help to config roming wireless

You can't. At least not with Mikrotik. Every WiFi access point has its own MAC address (which is base for communication between AP and its clients) and even if all APs are using same frequency client still has to disassociate from the old AP (its MAC actually) and associate to the new AP (its MAC)....
by loveman
Fri Mar 22, 2019 9:27 am
Forum: General
Topic: Help to config roming wireless
Replies: 4
Views: 1303

Help to config roming wireless

Hello everyone, I have a building consisting of 5 floors .. I need the work of the wireless network operating system roming so that the phone of (persons) roaming the whole building in all floors is the signal wireless cover and there is no separation of the phone and re-connect the network of new c...
by loveman
Mon Feb 11, 2019 7:35 pm
Forum: General
Topic: problem to block Pubg Game
Replies: 6
Views: 8796

Re: problem to block Pubg Game

Here are the IP ranges used by PUBG. I would not recommend blocking it. http://ec2-reachability.amazonaws.com/ Why? if some employee playing PUBG among the time working how can i block this game? Most business have employees sign an internet use form. a. though shalt not store or view porn on pc (m...
by loveman
Sun Feb 10, 2019 6:59 pm
Forum: General
Topic: problem to block Pubg Game
Replies: 6
Views: 8796

Re: problem to block Pubg Game

Here are the IP ranges used by PUBG. I would not recommend blocking it.

http://ec2-reachability.amazonaws.com/
Why? if some employee playing PUBG among the time working how can i block this game?
by loveman
Sun Feb 10, 2019 3:11 pm
Forum: General
Topic: problem to block Pubg Game
Replies: 6
Views: 8796

Re: problem to block Pubg Game

Blocking stuff is a complicated thing. You can block DNS used by program, but this can be passed by changing DNS server. Even a forced DNS may be passed by adding DNS to host file. Blocking IP used by the game may block other needed stuff on the same server. VPN can be used to bypass various blocki...
by loveman
Sat Feb 09, 2019 11:04 pm
Forum: General
Topic: problem to block Pubg Game
Replies: 6
Views: 8796

problem to block Pubg Game

Hi,
Any one advice me to how can i block pubg game on mobile with mikrotik?
All of internet method i tried but not working.
Please help me
Thanks
by loveman
Fri Mar 30, 2018 12:42 am
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 142895

Re: Urgent security advisory

1/If i change winbox port from 8291 to others port number? Am on safe or no?
2/My version 6.40.x? Should upgrade?
by loveman
Sun Feb 25, 2018 11:26 pm
Forum: The Dude
Topic: how to block application 'connectify' in mikrotik hotspot
Replies: 10
Views: 7808

Re: how to block application 'connectify' in mikrotik hotspot

Thank all of yours for wonderful comments,
Any one have idea how to block program "Baidu WiFi Hotspot"?
by loveman
Thu Feb 15, 2018 12:40 am
Forum: General
Topic: Help to block program
Replies: 0
Views: 694

Help to block program

Hi everyone
Please help me to block program that working on computer "windows" the program name:
(baidu hotspot wifi), used by users because sharing internet connection.
Anyone have rule to drop it?
Regards
by loveman
Sun Aug 13, 2017 9:37 pm
Forum: General
Topic: Question about poe
Replies: 5
Views: 2276

Re: Question about poe

That will not work! MikroTik (and Ubiquiti) use a nonstandard form of PoE on their (older) products that is not compatible with the 802.11AF/AT standard used by Cisco and other phone manufacturers, and output by mainstream PoE switches. You can use the PoE output of MikroTik routers only to power a...
by loveman
Sat Aug 12, 2017 8:06 pm
Forum: General
Topic: Question about poe
Replies: 5
Views: 2276

Re: Question about poe

Both RB2011 and RB951 will output 12 watts when the input power is 24 volts, such as when using the included power supply. Both these devices output 24v passive. It won't power any device that is expecting 48 volts 802.3af/at. Thank you for your comment If i need to connect ip phone 7962g cisco wit...
by loveman
Fri Aug 11, 2017 12:29 am
Forum: General
Topic: Question about poe
Replies: 5
Views: 2276

Question about poe

Dear members
I need to know what's the output of poe routerboard in watt? or which class poe of routerboard output?
information of routerboard
1-Routerboard 2011 wireless.
2-Routerborad 951 series with bulid in wireless.
Regards
by loveman
Fri Jul 07, 2017 11:51 pm
Forum: Scripting
Topic: help with auto shutdown
Replies: 10
Views: 8585

Re: help with auto shutdown

if i used the script to auto shutdown the routerboard not shutdown? I think the shutdown command will cause the Mikrotik to unmount resources so it's in a safe state to unplug the power. You could buy an electrical timer. Shutdown at 2:45, timer cuts power at 2:46, then the timer turns power back o...
by loveman
Fri Jul 07, 2017 10:38 am
Forum: General
Topic: DUAL WAN setup?
Replies: 13
Views: 47617

Re: DUAL WAN setup?

Using one of this method
1.NTH
2.PCC
by loveman
Tue Jul 04, 2017 8:33 pm
Forum: Scripting
Topic: help with auto shutdown
Replies: 10
Views: 8585

Re: help with auto shutdown

Use configurable power outlet that will cut the power off. Shutting router down will not switch it off.
if i used the script to auto shutdown the routerboard not shutdown?
by loveman
Tue Jul 04, 2017 8:31 pm
Forum: Scripting
Topic: help with auto shutdown
Replies: 10
Views: 8585

Re: help with auto shutdown

Since you want it to shutdown, use the first script and you can just switch power off/on the next day. However, if there is a power failure it will restart when the power is back on. If you are in an area that has lots of power failures, you may want to turn the power off before you leave. I am won...
by loveman
Sat Jul 01, 2017 4:43 pm
Forum: General
Topic: problem with Playstation and cctv
Replies: 2
Views: 954

problem with Playstation and cctv

Hello everyone
Whats the true rules should I applied to active the store and playing ONLINE with Playstation 4, I used routerboard 2011 wireless.
Regards
by loveman
Sat Jul 01, 2017 4:36 pm
Forum: Scripting
Topic: help with auto shutdown
Replies: 10
Views: 8585

Re: help with auto shutdown

/system scheduler add interval=1d name=shutdown on-event="/system shutdown" start-time=14:45:00 Shutdown requires a power cycle (removing power) to reboot. Did you mean to RESTART? /system scheduler add interval=1d name=restart on-event="/system restart" start-time=14:45:00 This...
by loveman
Sat Jul 01, 2017 1:08 pm
Forum: Scripting
Topic: help with auto shutdown
Replies: 10
Views: 8585

help with auto shutdown

Hello everyone
i need help with how to auto shutdown the routerboard at every day,, the routerboard shutdown at 2:45 pm?
how can do that?
Thank you
by loveman
Sat Jul 01, 2017 2:07 am
Forum: Beginner Basics
Topic: Firewall Drop IP
Replies: 3
Views: 1594

Re: Firewall Drop IP

you can change dhcp, to static dhcp
that makes any one you need add manual you can add with Mac address
else any one can't connect
by loveman
Sat Jul 01, 2017 2:01 am
Forum: Beginner Basics
Topic: Port forwarding to web server in LAN
Replies: 1
Views: 877

Re: Port forwarding to web server in LAN

if you need in hotspot server..
you can add who user logging without login..
you can add in bypass
by loveman
Sat Jul 01, 2017 1:58 am
Forum: Beginner Basics
Topic: DHCP sever wokred but no internet access
Replies: 3
Views: 901

Re: DHCP sever wokred but no internet access

I think you forgot add nat
by loveman
Tue May 09, 2017 10:44 pm
Forum: General
Topic: PPTP connection status showing as " Link established"
Replies: 12
Views: 18650

Re: PPTP connection status showing as " Link established"

im also getting this with v6.38.1 you disable and enable it and works for a while (sometimes more time than other) but after that while it still shows as connected and uptime but it cant ping anymore to the other side what could this problem be? masquarade is ok Using static route to make sure your...
by loveman
Tue Jan 10, 2017 10:26 pm
Forum: The User Manager
Topic: Mikrotik user-manager voucher printing
Replies: 21
Views: 40057

Re: Mikrotik user-manager voucher printing

If i need using only ready voucher with hotspot server how can that ?
What is the number of users can create in ready voucher
by loveman
Sun Nov 06, 2016 11:53 am
Forum: General
Topic: Test for MTCWE
Replies: 4
Views: 4978

Re: Test for MTCWE

Hello,

you won't get them.
This is closed source kept and maintained by Mikrotik guys.

greets
I'd think by mikrotik There is a simple test to a simple test before entering the exam
Thank you
by loveman
Sun Nov 06, 2016 12:18 am
Forum: General
Topic: Test for MTCWE
Replies: 4
Views: 4978

Test for MTCWE

Hello
How can i get test questions for MTCWE exam before test online exam ?
Thank you
by loveman
Sun Nov 06, 2016 12:16 am
Forum: Beginner Basics
Topic: Block Telegram APP
Replies: 1
Views: 3501

Re: Block Telegram APP

Port of program or can block by torch ip
by loveman
Sun Nov 06, 2016 12:09 am
Forum: General
Topic: Mikrotik Certification test
Replies: 89
Views: 52291

Re: Mikrotik Certification test

How can i get the test exam for MTCWE before going to online exam?
by loveman
Sat Nov 05, 2016 11:55 pm
Forum: Beginner Basics
Topic: Block Whatsapp
Replies: 60
Views: 71816

Re: Block Whatsapp

Hi, you only need to make a address-list containing the folowing addresses: (taken from http://www.whatsapp.com/cidr.txt) 31.13.69.240/32 31.13.70.49/32 31.13.71.49/32 31.13.73.49/32 31.13.74.49/32 31.13.76.81/32 31.13.77.49/32 50.22.75.192/27 50.22.93.192/27 50.22.198.204/30 50.22.210.32/30 50.22....
by loveman
Mon Oct 17, 2016 9:06 pm
Forum: General
Topic: How can doing disappear showing login page
Replies: 1
Views: 799

Re: How can doing disappear showing login page

Any help
by loveman
Sun Oct 16, 2016 1:13 am
Forum: General
Topic: How can doing disappear showing login page
Replies: 1
Views: 799

How can doing disappear showing login page

Hi I have some idea to run the project I applied all of the hotspot server, but i need to not showing up login page of hotspot in browser (only when i write gateway "ip address" of hotspot server in browser) the login page will show in browser,and last can write username and password to op...
by loveman
Tue Oct 11, 2016 11:32 pm
Forum: General
Topic: Static pptp server binding problem.
Replies: 3
Views: 1860

Re: Static pptp server binding problem.

Hello, i have same issue but only sometimes - it happends randomly. I use Mikrotik-Mikrotik enviroment. When I manualy do disable/enabla client or remove dynamic connection it reconnect corectly.
Thank you
I tried more than one but the same problem
by loveman
Sun Oct 09, 2016 11:11 am
Forum: General
Topic: Help: DHCP Server - Strange Message
Replies: 5
Views: 8119

Re: Help: DHCP Server - Strange Message

I have the same message in log
Any one know what meaning
by loveman
Fri Sep 23, 2016 9:45 am
Forum: General
Topic: Advice static route "problem"
Replies: 1
Views: 847

Re: Advice static route "problem"

No answer
by loveman
Thu Sep 22, 2016 1:54 pm
Forum: General
Topic: Advice static route "problem"
Replies: 1
Views: 847

Advice static route "problem"

Hello everyone I have a some problem with "static route" My project to connect pptp server between server and client . Now i applied all configuration from server like pool&pptp server&profile ppp& ....etc all are good In client routerboard applied pptp client with all config. ...
by loveman
Wed Sep 14, 2016 12:30 pm
Forum: Beginner Basics
Topic: Program to use call between server and client
Replies: 4
Views: 1187

Re: Program to use call between server and client

I found program using in vpn like "Hamachi"
It is the perfect program?
by loveman
Tue Sep 13, 2016 9:47 pm
Forum: Beginner Basics
Topic: Program to use call between server and client
Replies: 4
Views: 1187

Program to use call between server and client

Hello everyone
I have vpn server between two point and i need to setup program's chatting voice between server and client to use voice between vpn point
What is the best program, free call.
Regards
by loveman
Fri Sep 09, 2016 11:55 am
Forum: Beginner Basics
Topic: Wireless printer does not work
Replies: 2
Views: 2025

Re: Wireless printer does not work

I think the time of lease dhcp change between some time that mean the ip address of printer change.
You can increase the time or applying static dhcp printer
by loveman
Sat Sep 03, 2016 3:52 pm
Forum: Beginner Basics
Topic: Mikrotik Queue Coloring does not work?
Replies: 2
Views: 1162

Re: Mikrotik Queue Coloring does not work?

Upload photos for queue
by loveman
Wed Aug 31, 2016 6:01 pm
Forum: General
Topic: Static pptp server binding problem.
Replies: 3
Views: 1860

Re: Static pptp server binding problem.

Upload some pictures for pptp server configuration
by loveman
Tue Aug 30, 2016 5:10 pm
Forum: General
Topic: MikroTik router to connect remotely
Replies: 4
Views: 1175

Re: MikroTik router to connect remotely

Have public ip address
by loveman
Mon Aug 29, 2016 11:41 pm
Forum: Beginner Basics
Topic: block torrent in a bridge
Replies: 9
Views: 1795

Re: block turrent in a bridge

What have you learned from other threads with the same topic?
i know how block it via firewall
But, I don't know how block it via bridge firewall filter
What is the problem if you block from firewall?
If you can upload the method for how to block torrent via firewall
by loveman
Mon Aug 29, 2016 11:36 pm
Forum: Beginner Basics
Topic: remote access to mikrotic with grey IP
Replies: 3
Views: 1243

Re: remote access to mikrotic with grey IP

How much your public ip address?
If you have one should the public ip address in a orginal branch
by loveman
Sun Aug 28, 2016 11:20 pm
Forum: General
Topic: Block Quic Protocol
Replies: 6
Views: 4303

Re: Block Quic Protocol

You need to control youtube bandwidth from any direction? Like speed or block website
by loveman
Sat Aug 27, 2016 1:37 pm
Forum: Beginner Basics
Topic: Problem in static dns
Replies: 3
Views: 1288

Re: Problem in static dns

Maybe you're redirecting your own DNS queries back to you? Try specifying src-adress= customers blocked from facebook and dst-address != Your_DNS_Server_ip in the dstnat redirection rule. Thank you for replying In dst-address! =have two dns like 8.8.8.8 And dns for isp I try to putting two dns? All...
by loveman
Sat Aug 27, 2016 12:25 pm
Forum: Beginner Basics
Topic: Problem in static dns
Replies: 3
Views: 1288

Problem in static dns

Hello everyone I have problem when i tried to apply static dns My step Ip, dns, static, add For example block website Name :*facebook.com Address:127.0.0.1 Timeout :1d 00:00:00 Apply ok Going to Nat Add chain dstnat, protocol 17udp,dst port 53 Action redirect When i test if website of Facebook was b...
by loveman
Thu Aug 25, 2016 3:53 pm
Forum: General
Topic: TeamViewer not working
Replies: 3
Views: 1635

Re: TeamViewer not working

Any think used to drop any website or application from firewall?
by loveman
Wed Aug 24, 2016 8:20 pm
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

Re: How can stop and drop Auto update

- make sure you run version 6.36.2 - add all those names to an address list named kaspersky (use those URL without the http:// ) - block traffic to that address list on your network - hope for the best When i added in address list Going to filter Add Chain forward Advanced Dst-address-list,,,, here...
by loveman
Wed Aug 24, 2016 6:42 pm
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

Re: How can stop and drop Auto update

I found all server update of Kaspersky antivirus Whats the best way to drop it? Below is the list of Kaspersky Lab servers used for downloading antivirus database updates, new application modules, and patches: http://dnl-01.geo.kaspersky.com http://dnl-02.geo.kaspersky.com http://dnl-03.geo.kaspersk...
by loveman
Wed Aug 24, 2016 8:41 am
Forum: General
Topic: VOIP QOS
Replies: 18
Views: 4918

Re: VOIP QOS

You can use mangle and simple queue and you can take priority packet
by loveman
Wed Aug 24, 2016 1:42 am
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

Re: How can stop and drop Auto update

the ability to resolve DNS to IP address. However, in testing, it looks like it will only resolve a single address. realistically, you are going to have to look up and manually add all of the IP's yourself. Before i posted here I tested by write link of server update from ip dns static End apply th...
by loveman
Wed Aug 24, 2016 1:35 am
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

Re: How can stop and drop Auto update

If i write in "address" and apply the show error expect?
you need RouterOS 6.36
What is the new in version 6.36 in address list?
by loveman
Wed Aug 24, 2016 1:31 am
Forum: Beginner Basics
Topic: Site to site IPSEC and access to a specific host on the Net
Replies: 3
Views: 1098

Re: Site to site IPSEC and access to a specific host on the Net

Should add ip route from office 1 and office 2
In ip route of office 1 add dst:private network of office 2 and gateway:write gateway of office 1
And the same in office 2 add ip route and write dst:private network of office 1 and gateway:write gateway of office 2
by loveman
Wed Aug 24, 2016 1:25 am
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

Re: How can stop and drop Auto update

create a drop rule in the forward chain that drops an address list. Then put all of the hostname of the update servers into the address list. In address list contains Name Address Timeout If i need to add link for update server for example Kaspersky : Where i add this link? Inside address list If i...
by loveman
Wed Aug 24, 2016 12:40 am
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

Re: How can stop and drop Auto update

Hello everyone
In my network i need to drop and stop all update of Anti virus like Kaspersky, Norton, Node 32 etc
How can that?
Regards
uninstall it?

or block the update servers in the filter
How can drop by filter rule? Like Kaspersky and Norton
by loveman
Tue Aug 23, 2016 10:16 pm
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

Re: How can stop and drop Auto update

Any help
by loveman
Tue Aug 23, 2016 7:22 pm
Forum: General
Topic: How can stop and drop Auto update
Replies: 17
Views: 4336

How can stop and drop Auto update

Hello everyone
In my network i need to drop and stop all update of Anti virus like Kaspersky, Norton, Node 32 etc
How can that?
Regards
by loveman
Thu Aug 11, 2016 9:20 am
Forum: General
Topic: DHCP -> offering lease without success
Replies: 10
Views: 46546

Re: DHCP -> offering lease without success

I have same problem with Ap cisco and mikrotik showing in dhcp server offered
by loveman
Sun Aug 07, 2016 11:09 pm
Forum: General
Topic: Freedom Software
Replies: 14
Views: 8576

Re: Freedom Software

to block the freedom : /ip firewall layer7-protocol add name=freedom regexp="^.+(2yf.de|1yf.de)" /ip firewall filter add action=drop comment="block-freedom-maxupgrade" chain=pre-hs-input layer7-protocol=freedom To know who use your freedom brogram : /ip firewall mangle add actio...
by loveman
Sun Aug 07, 2016 1:19 am
Forum: General
Topic: VPN Mac computer problem.
Replies: 3
Views: 1012

Re: VPN Mac computer problem.

If you not have reply for ping, i think the firewall of windows , can't reply ping,try to off firewall and try to ping.
Regards
by loveman
Sun Aug 07, 2016 12:30 am
Forum: General
Topic: PPTP Dynamic IP Pool round robin way.
Replies: 1
Views: 842

Re: PPTP Dynamic IP Pool round robin way.

Going in ppp, secret
You see username and password for PPTP server
Open this username and you see ip address in (Remote address), this ip the same you seen on remote pptp client.
Clear or remove the ip address from secret in remote address.
Now you try connect pptp client.
Regards
by loveman
Fri Aug 05, 2016 2:43 pm
Forum: General
Topic: Freedom Software
Replies: 14
Views: 8576

Re: Freedom Software

to block the freedom : /ip firewall layer7-protocol add name=freedom regexp="^.+(2yf.de|1yf.de)" /ip firewall filter add action=drop comment="block-freedom-maxupgrade" chain=pre-hs-input layer7-protocol=freedom To know who use your freedom brogram : /ip firewall mangle add actio...
by loveman
Tue Aug 02, 2016 1:12 pm
Forum: Beginner Basics
Topic: How enable DDNS in firewall rules
Replies: 6
Views: 6366

Re: How enable DDNS in firewall rules

I think active DDNS from Ip, Cloud And select true on DDNS after some time you see code that meaning DDNS. Hi. I don't undestand. I can enable DDNS in IP -> Cloud.  But I have problems with firewall rules. With current config I can't use DDNS and I don't want to disable ''Drop'' rule since its risk...
by loveman
Mon Aug 01, 2016 2:23 pm
Forum: General
Topic: How to allow a website in RB750
Replies: 24
Views: 5452

Re: How to allow a website in RB750

Write in run
cmd and press Enter
You look dos screen.
Write
nslookup www.google.com
Press Enter
You look ip's for google website.
In this tutorial you can apply to your website.
nslookup www.jma.go.jp
by loveman
Mon Aug 01, 2016 2:14 pm
Forum: General
Topic: How to allow a website in RB750
Replies: 24
Views: 5452

Re: How to allow a website in RB750

 it is true but in new version of routeros you can import domain name in firewall rule
You meaning in advanced "content" or what the new
by loveman
Mon Aug 01, 2016 1:31 am
Forum: Beginner Basics
Topic: How enable DDNS in firewall rules
Replies: 6
Views: 6366

Re: How enable DDNS in firewall rules

I think active DDNS from Ip, Cloud And select true on DDNS after some time you see code that meaning DDNS. Hi. I don't undestand. I can enable DDNS in IP -> Cloud.  But I have problems with firewall rules. With current config I can't use DDNS and I don't want to disable ''Drop'' rule since its risk...
by loveman
Sat Jul 30, 2016 1:29 pm
Forum: General
Topic: Problem in change rule
Replies: 2
Views: 956

Re: Problem in change rule

hello
i think you should reset configuration and then re-config your router
The problem was solved
by loveman
Sat Jul 30, 2016 8:45 am
Forum: Beginner Basics
Topic: How enable DDNS in firewall rules
Replies: 6
Views: 6366

Re: How enable DDNS in firewall rules

I think active DDNS from Ip, Cloud
And select true on DDNS after some time you see code that meaning DDNS.
by loveman
Wed Jul 27, 2016 1:07 am
Forum: General
Topic: Web access from external
Replies: 13
Views: 5693

Re: Web access from external

Change from
Ip service, in www
Change to 8080 apply ok
Now open browser
Write your public ip address with :8080 like
X. X. X. X:8080
Thanks!
It works too.
Best regards.
You welcome my friend
Regards
by loveman
Tue Jul 26, 2016 12:36 am
Forum: General
Topic: Layer 7 Firewall issues
Replies: 4
Views: 1319

Re: Layer 7 Firewall issues

What is your method to block website? Layer 7 or rule only?
by loveman
Sat Jul 23, 2016 11:16 pm
Forum: General
Topic: Web access from external
Replies: 13
Views: 5693

Re: Web access from external

Change from
Ip service, in www
Change to 8080 apply ok
Now open browser
Write your public ip address with :8080 like
X. X. X. X:8080
by loveman
Sat Jul 23, 2016 11:08 pm
Forum: General
Topic: Block Teamspeak with layer 7
Replies: 14
Views: 3329

Re: Block Teamspeak with layer 7

I think I got it working, and so simple. if there is a better way, please share it or correct me.  I captured some traffic when connecting to different Teamspeak servers, it seems all first packets have the same phrase inside of them. So I used that as my regex. It seems to kill all connection atte...
by loveman
Sat Jul 23, 2016 11:43 am
Forum: General
Topic: Block Teamspeak with layer 7
Replies: 14
Views: 3329

Re: Block Teamspeak with layer 7

You have idea or rule to block psiphon vpn? I need to block psiphon vpn. When will you stop whining about that? Psiphon VPN is designed in such a way that it cannot easily be blocked. Live with it. Furthermore, if you would succeed in blocking it (e.g. by finding all IP addresses of their servers a...
by loveman
Sat Jul 23, 2016 11:40 am
Forum: General
Topic: Block Teamspeak with layer 7
Replies: 14
Views: 3329

Re: Block Teamspeak with layer 7

What is the benefit if it is blocked ,, without block program vpn like "psiphon vpn" buz user can install psiphon vpn to connect with outside server can open all block program. It would be fine if the user would connect trough a VPN, this would prevent other people to see our IP. You have...
by loveman
Sat Jul 23, 2016 10:57 am
Forum: General
Topic: Block Teamspeak with layer 7
Replies: 14
Views: 3329

Re: Block Teamspeak with layer 7

What is the benefit if it is blocked ,, without block program vpn like "psiphon vpn" buz user can install psiphon vpn to connect with outside server can open all block program. It would be fine if the user would connect trough a VPN, this would prevent other people to see our IP. You have...
by loveman
Sat Jul 23, 2016 9:37 am
Forum: Beginner Basics
Topic: First Time setup of RB493G
Replies: 2
Views: 876

Re: First Time setup of RB493G

The same model
by loveman
Sat Jul 23, 2016 9:33 am
Forum: General
Topic: Block Teamspeak with layer 7
Replies: 14
Views: 3329

Re: Block Teamspeak with layer 7

What is the benefit if it is blocked ,, without block program vpn like "psiphon vpn" buz user can install psiphon vpn to connect with outside server can open all block program.
by loveman
Fri Jul 22, 2016 5:28 pm
Forum: Beginner Basics
Topic: disable users by scripting
Replies: 6
Views: 11886

Re: disable users by scripting

how can i disable some of my hotspot users from 06:00 till 23:00 and enable them from 23:00 till 06:00??? You have to create two scripts , one for disabling users at 06:00, and second for enabling them at 23:00 hrs, and schedule them as per required timings. DISABLE Script name: disable-users # Set...
by loveman
Fri Jul 22, 2016 12:12 pm
Forum: Beginner Basics
Topic: Bandwidth limiting Facebook, YouTube, etc. by AS and CIDR IP Address
Replies: 2
Views: 10164

Re: Bandwidth limiting Facebook, YouTube, etc. by AS and CIDR IP Address

Thanks
If you can drop vpn program like (psiphon vpn) by mikrotik. Please help me
by loveman
Fri Jul 22, 2016 9:31 am
Forum: Beginner Basics
Topic: No Internet Access and cant' PING
Replies: 6
Views: 5772

Re: No Internet Access and cant' PING

Check steps :
1-check if you added gateway ip address from IP ROUTE.
2-check ip dns if you added.
3-check NAT in ip, firewall, nat, add, src address write range ip address, chain Masquerade.
Regards
by loveman
Thu Jul 21, 2016 11:43 pm
Forum: Beginner Basics
Topic: QoS in the office for VoIP and VPN
Replies: 1
Views: 1920

Re: QoS in the office for VoIP and VPN

I have some idea to try it. You can use the mangle and traffic packet to apply the range ip address for example (mark connection, mark packet), and create simple queue In advanced you can select in packets mark(was created in mangle), and you can select priority to voip like equal 1 In the same simp...
by loveman
Thu Jul 21, 2016 11:26 pm
Forum: General
Topic: PPTP VPN Connection cannot be established from another network
Replies: 5
Views: 4053

Re: PPTP VPN Connection cannot be established from another network

I will solution your problem, but first in outside on windows you can upload photo of error you saw it.
by loveman
Wed Jul 20, 2016 8:40 am
Forum: General
Topic: Winbox high on CPU
Replies: 2
Views: 842

Re: Winbox high on CPU

Maybe you added moreover rule on firewall.
by loveman
Tue Jul 19, 2016 11:38 pm
Forum: Beginner Basics
Topic: [How To] NAT on PPTP Server
Replies: 1
Views: 1430

Re: [How To] NAT on PPTP Server

1.you can create ip pool and write range of it. And then in pptp profile you can select pool and continue to create pptp server. Any user connect with vpn server the user have ip from ip pool. Range of ip pool like 192.168.0.2-192.168.0.254 And ip 192.168.0.1 write in pptp profile in local address, ...
by loveman
Mon Jul 18, 2016 12:31 am
Forum: General
Topic: Blocking Pokemon Go
Replies: 29
Views: 9385

Re: Blocking Pokemon Go

Just set DNS for these domains to 127.0.0.1 or to any fake address which will fool te game.
Please explain your method to upload some photos how to do it.
by loveman
Sun Jul 17, 2016 4:28 pm
Forum: Beginner Basics
Topic: connet two mikrotik with different Isp provider
Replies: 5
Views: 1191

Re: connet two mikrotik with different Isp provider

I suggest can connect vpn like pptp server between two mik1 and mik2,
After You can connect computer between them.
by loveman
Sun Jul 17, 2016 9:47 am
Forum: General
Topic: Problem in change rule
Replies: 2
Views: 956

Problem in change rule

Hello everyone
I have problem in firewall that change automatic sequence don't anyone change rules but it is changed automatically, what is the problem and how can i stopped the automatic change.
Note i watch by "log" but not one change it.
Regards
by loveman
Fri Jul 15, 2016 2:56 pm
Forum: General
Topic: mikrotik hotspot
Replies: 2
Views: 888

Re: mikrotik hotspot

In case 2
Try to work dhcp-client and select ether who in case 1
And finally try to access hotspot from case 2
by loveman
Sun Jul 10, 2016 3:13 pm
Forum: Beginner Basics
Topic: How can limit time
Replies: 1
Views: 743

Re: How can limit time

Anyone hava idea
by loveman
Sat Jul 09, 2016 3:11 am
Forum: Beginner Basics
Topic: Cloud Core Reset
Replies: 2
Views: 1273

Re: Cloud Core Reset

Go in new terminal and write
system reset-configuration
Y
The router will rest.
by loveman
Fri Jul 08, 2016 6:26 pm
Forum: Beginner Basics
Topic: How can limit time
Replies: 1
Views: 743

How can limit time

Hello Everyone 1-How can limit time to user with hotspot server When user active in hotspot that limit time to disable automatically for example limit 1 day after time, the user (username and password) will stopped expired. 2-the same method using pppoe server, i read in profile in "session-tim...
by loveman
Fri Jul 08, 2016 8:15 am
Forum: Beginner Basics
Topic: PCQ Not working
Replies: 3
Views: 2416

Re: PCQ Not working

If you need to sharing equal bandwith should put the pcq equal 0 (pcq=0) and in queues limit at general upload and download like 1m/1m, in target put your network like x.x.x.x/24 And in advanced select pcq upolad and pcq download Test your work. In video and pcq=2m that meaning everyone have 2m from...
by loveman
Wed Jul 06, 2016 10:10 pm
Forum: Beginner Basics
Topic: VPN Ping is working only with gateway
Replies: 3
Views: 1628

Re: VPN Ping is working only with gateway

Write ip pool?
And should add your pool in firewall nat and action masquerade.
And in pptp server don't select "chap, pap" select only mschap1 mschap2.
by loveman
Wed Jul 06, 2016 8:10 am
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

Do you really think, that after you block the VPN program the employees will be brave, and honest, and will NEVER EVER use VPN anymore? I can give you 100% guarantee: THEY WILL look for an alternative. Like OpenVPN, which even bypasses the great (fire) wall of China, Bhutan, Oman and other countrie...
by loveman
Wed Jul 06, 2016 8:08 am
Forum: Beginner Basics
Topic: Winbox and Webfig locked out
Replies: 2
Views: 1297

Re: Winbox and Webfig locked out

I think you change some port for winbox and webfig
From ip, services because cant login in mikrotik server.
You can try to input from mac address for mac of interface you can see in neighbors discovery or you can take mac address from behind device.
Regards
by loveman
Wed Jul 06, 2016 8:02 am
Forum: General
Topic: Basic IPSec question
Replies: 6
Views: 1605

Re: Basic IPSec question

1.x the Main ipsec vpn right!
In branch like 2.x,3.x what you added in ip route
How much route added?
Please if you can upload photos for all branch to see where your some wrong.
Regards
by loveman
Tue Jul 05, 2016 6:00 pm
Forum: General
Topic: Help to drop connection vpn
Replies: 8
Views: 3334

Re: Help to drop connection vpn

Are you wanting to block all VPN's from end users, or just specific programs? Depending on what you want to do will determine the path you want to take. Either one will require leg work and testing on your part to make sure it works as you desire and is not preventing traffic that you want to allow...
by loveman
Tue Jul 05, 2016 3:20 pm
Forum: General
Topic: Help to drop connection vpn
Replies: 8
Views: 3334

Re: Help to drop connection vpn

Up up
by loveman
Tue Jul 05, 2016 3:17 pm
Forum: Beginner Basics
Topic: How do I go about blocking a website with RouterOS?
Replies: 6
Views: 1643

Re: How do I go about blocking a website with RouterOS?

You can block website from layer 7 or easy method
In add firewall filter rule
Chain forward, in advanced write in content facebook, action drop, apply
Any one cant access facebook
Regards
by loveman
Tue Jul 05, 2016 3:14 pm
Forum: General
Topic: L2TP with Ipsec cannot connect from outside LAN
Replies: 6
Views: 2351

Re: L2TP with Ipsec cannot connect from outside LAN

Upolad photos for ip firewall
Regardless you upolad external code
by loveman
Tue Jul 05, 2016 3:07 pm
Forum: Beginner Basics
Topic: [RESOLVED] Static Route Between Two ether
Replies: 9
Views: 6042

Re: Static Route Between Two ether

After when you finish apply to added ip route between to routers. And 3.x cant ping in to 2.x
You can try to off "disable" firewall windows in network 2.x then you can try ping finally you see reply ping from network.viceversa.
Regards
by loveman
Mon Jul 04, 2016 4:26 pm
Forum: Beginner Basics
Topic: [RESOLVED] Static Route Between Two ether
Replies: 9
Views: 6042

Re: Static Route Between Two ether

You need to sharing file or connect to computers network from two different ip of ether 1 and ether 2?
by loveman
Mon Jul 04, 2016 12:00 am
Forum: Beginner Basics
Topic: Advice to design login
Replies: 4
Views: 1715

Re: Advice to design login

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html> <head> <title>Broadband Internet (Login)</title> <meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-9"> <meta ht...
by loveman
Sun Jul 03, 2016 3:10 pm
Forum: Beginner Basics
Topic: Usermanager package is not available in RB 3011 Ui AS-RM
Replies: 2
Views: 1520

Re: Usermanager package is not available in RB 3011 Ui AS-RM

Can find from system packages and install
by loveman
Sat Jul 02, 2016 12:13 pm
Forum: General
Topic: L2TP + IpSec problem
Replies: 8
Views: 2819

Re: L2TP + IpSec problem

I know IP Pool for VPN must be in VPN, but still, is not a IP problem, is just is NOT connecting...... Check in L2tp setup of auth. Select only "mschap1" and "mschap2". Your client which are pc computer or routerborad? In case if you are using computer From connection of windows...
by loveman
Sat Jul 02, 2016 9:00 am
Forum: General
Topic: L2TP + IpSec problem
Replies: 8
Views: 2819

Re: L2TP + IpSec problem

Ip pool should put in nat in vpn server
by loveman
Fri Jul 01, 2016 6:52 pm
Forum: Beginner Basics
Topic: Advice to design login
Replies: 4
Views: 1715

Re: Advice to design login

when you open webpage you can not see them :)
No all of word above showing in webpage when i connected with hotspot.
by loveman
Fri Jul 01, 2016 1:20 pm
Forum: Beginner Basics
Topic: Advice to design login
Replies: 4
Views: 1715

Advice to design login

Hi
I tried to design webpage login for hotspot
In finsh i need to hide some word of text which are
"$(if chap-id)"
" $(endif)"
"$(error)"
"$(if error)"
"$(endif)"
"$(username)"
I need to hide all of this word text
How can that
Regards
by loveman
Tue Jun 28, 2016 6:21 pm
Forum: Beginner Basics
Topic: What is the best rule to protection
Replies: 3
Views: 1265

Re: What is the best rule to protection

Thank you all
by loveman
Tue Jun 28, 2016 6:16 pm
Forum: Beginner Basics
Topic: Problem with VPN connection
Replies: 1
Views: 729

Re: Problem with VPN connection

Upolad some picture from your vpn to see where the wrong
by loveman
Tue Jun 28, 2016 6:12 pm
Forum: General
Topic: IPSec Issue
Replies: 10
Views: 1958

Re: IPSec Issue

In server check
Ip, ipsec, peer
Check
Generate policy : port overmide
...
And in proposale
Select
3des
Sha1
by loveman
Mon Jun 27, 2016 11:30 pm
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

Please answer me
by loveman
Sun Jun 26, 2016 9:33 pm
Forum: Beginner Basics
Topic: What is the best rule to protection
Replies: 3
Views: 1265

What is the best rule to protection

Hello
We need to discuss about the most important rules used to protect the server from penetration.
Any one have rule please write here and discuss little for rule how to work.
Regards
by loveman
Sat Jun 25, 2016 7:54 am
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

Thank you for your explain I have idea if you agree I add 2 rule in mangle No. 1 Add Chain forward Src address 10.10.10.2-10.10.10.254 that mean range of ip pool Action Mark-connection New mark connection :for example name, white -connection Select true on pass through. Apply ok Step 2 Add Chain for...
by loveman
Wed Jun 22, 2016 10:18 pm
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

If you want to use PCQ then you need to specify a target that covers all hosts who are to share bandwidth fairly. I.e. Target=10.10.16.0/23 When using the global htb, the IPs can live on several interfaces. You could probably insert s few "more-specific-target queues sooner in the list (e.g. T...
by loveman
Wed Jun 22, 2016 12:38 am
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

The target cannot use ranges. It has to use a CIDR block. i.e. 192.168.12.0/24 , or 10.12.0.0/16 or whatever prefix describes the IP range. And yes, your pools should be organized in CIDR blocks like this too - not ranges, because very few things work with ranges. (I've seen lots of networks that a...
by loveman
Tue Jun 21, 2016 8:46 am
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

Try setting the target to be the IP range that your users come from - HTB happens sort of "in between" lots of other steps, so perhaps that's the best way to capture the traffic and police it properly, so that the queueing is done before the time that PPPoE encapsulation takes place / aft...
by loveman
Tue Jun 21, 2016 12:48 am
Forum: General
Topic: MUM 14-june-2016
Replies: 0
Views: 762

MUM 14-june-2016

Hello everyone
I need slides for mum in Lebanon whats the way to i get all presentation of mum.
Because one of the lecture told any one need to slide you can get from Mikrotik.com
Any one help
Regards
by loveman
Mon Jun 20, 2016 10:40 pm
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

What you want is more of a PCQ application than a per-user-queue application, and there's nothing that directly does exactly what you want - that being give users up to full pipe if available, but strictly limit to X whenever there is load. In general, the options for bandwidth management are basic...
by loveman
Mon Jun 20, 2016 12:47 am
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

No- just specify a queue in the pop profile and the router will dynamically add queues whoever users connect. Or specify a RADIUS attribute on their account and that will work too. In your paragraph "just specify a queue in the pop profile and the router will dynamically add queues whoever use...
by loveman
Sat Jun 18, 2016 1:16 pm
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

The queue can't see this traffic because it's looking for IP addresses, but ether2 isn't carrying IP traffic - it's carrying PPPoE traffic. In other words - pppoe is like a tunnel, and the only information available on the "outside" of the tunnel is the src/dst MAC addresses for each sess...
by loveman
Fri Jun 17, 2016 8:21 pm
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Re: Problem in pppoe with Queues

u maked pppoe server with ip pools and profiles ?? or what
Yes
created ip pool
Profile
pppoe server
Secret
What is the problem
by loveman
Thu Jun 16, 2016 11:37 pm
Forum: General
Topic: Problem in pppoe with Queues
Replies: 19
Views: 9380

Problem in pppoe with Queues

Hello everyone I have problem in queues when i create pppoe server in ether 2 then, Created new queue and in target putting interface ether 2 And put upload and download load like 1m/1m Finally apply ok. Suppose all user's active.. I saw the traffic of queue was not working? Where is the error? pppo...
by loveman
Wed Jun 15, 2016 4:51 pm
Forum: General
Topic: Problem with pptp client
Replies: 2
Views: 1227

Re: Problem with pptp client

Does the PPTP server in the Mikrotik have MSCHAP and MSCHAP v2 selected?  

Also check to see what authentication methods are selected on the PPTP client.  

Screenshot_2.pngScreenshot_1.png
Yes was working
But why dont selected chap and pap?

Thank you
by loveman
Tue Jun 14, 2016 6:16 pm
Forum: General
Topic: Problem with pptp client
Replies: 2
Views: 1227

Problem with pptp client

Hello everyone I have pptp server created by routerboard all of the setting was finished. When i testing that pptp client if work or not I test in Windows xp to create new connection of vpn and write username and password and write public ip address.. When to connect the connection i saw error "...
by loveman
Tue Jun 14, 2016 6:05 pm
Forum: General
Topic: PPTP error
Replies: 2
Views: 2782

Re: PPTP error

I have the same problem
With Windows xp
Please help me to upload picture how to solved that problem
by loveman
Wed Jun 08, 2016 9:46 am
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

The less you block, the less headache you will have. You should not BLOCK the services, but make good, reliable, reasonable policies regarding internet usage. Do not let the disability of manager who cannot "control" the productivity of their employees to have you solved by "technica...
by loveman
Tue Jun 07, 2016 3:19 pm
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

The less you block, the less headache you will have. You should not BLOCK the services, but make good, reliable, reasonable policies regarding internet usage. Do not let the disability of manager who cannot "control" the productivity of their employees to have you solved by "technica...
by loveman
Tue Jun 07, 2016 3:15 pm
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

Once you have succeeded in blocking psiphon vpn the people will find another vpn that you have not blocked. The best way to avoid such situations is make them sign a contract that forbids the activities you do not like to see in your company, so you can fire them when they breach it. All technical ...
by loveman
Tue Jun 07, 2016 3:11 pm
Forum: General
Topic: What is the best way to block P2P traffic
Replies: 10
Views: 3564

Re: What is the best way to block P2P traffic

/ip firewall filter add chain=forward protocol=gre action=drop add chain=forward protocol=tcp dst-port=1723 action=drop i hope vpn will be off ... :D What you describe is PPTP which is something different from P2P. Dear friend Any think you have to drop p2p traffic please write here.. Thank you
by loveman
Tue Jun 07, 2016 3:06 pm
Forum: General
Topic: What is the best way to block P2P traffic
Replies: 10
Views: 3564

Re: What is the best way to block P2P traffic

Iam already block Hotspot Shield program.. But i need to block psiphon vpn? Oh man you are so confusing! You ask "What is the best way to block P2P traffic" then you need to block some VPN, and when you get told it is a social/contract problem not a technical problem you just start a new ...
by loveman
Tue Jun 07, 2016 1:39 pm
Forum: General
Topic: What is the best way to block P2P traffic
Replies: 10
Views: 3564

Re: What is the best way to block P2P traffic

This method will be drop Hotspot Shield program. i am not sure 100%, But it will be work for dropping Hotspot Shield. Must you have to use open dns in Mikrotik. /ip firewall address-list add address=157.56.106.0/24 disabled=no list=hotspotshield add address=157.56.144.0/24 disabled=no list=hotspots...
by loveman
Mon Jun 06, 2016 10:09 pm
Forum: General
Topic: What is the best way to block P2P traffic
Replies: 10
Views: 3564

Re: What is the best way to block P2P traffic

/ip firewall filter
add chain=forward protocol=gre action=drop
add chain=forward protocol=tcp dst-port=1723 action=drop

i hope vpn will be off ... :D
My question to you
If you tried your method and that method true active "drop vpn program" or not working
Regards
by loveman
Mon Jun 06, 2016 12:07 am
Forum: General
Topic: What is the best way to block P2P traffic
Replies: 10
Views: 3564

What is the best way to block P2P traffic

Hello every one i tired to drop P2P traffic but can't block that below will show you the way when i tried that /ip firewall filter add action=add-src-to-address-list address-list=P2P address-list-timeout=30m chain=forward comment="Add P2P hosts to address list" out-interface=ether1-gateway...
by loveman
Sun Jun 05, 2016 11:41 pm
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

What you mean "drop from Mikrotik servers"? If you want block some service please block all protocol and port connect to dst-address (phipson servers). I do not understand why you block only one VPN Service. I think it very difficult block because service uses multiple IP-address pool. in...
by loveman
Sun Jun 05, 2016 11:27 pm
Forum: General
Topic: Block Torrents & p2p Traffic 100% working on all versions
Replies: 60
Views: 181142

Re: Block Torrents & p2p Traffic 100% working on all versions

add chain=forward src-address=192.168.1.0/24 p2p=all-p2p action=drop comment=p2p_drop


not working
buz i need to drop "psiphon vpn" from server ,,

how can drop that p2p buz drop vpn?
by loveman
Wed Jun 01, 2016 1:35 am
Forum: Beginner Basics
Topic: VPN - no access to local lan
Replies: 2
Views: 872

Re: VPN - no access to local lan

Why you should be able the Arp is set to proxy-arp
by loveman
Tue May 31, 2016 9:45 am
Forum: General
Topic: Remote vpn
Replies: 1
Views: 705

Remote vpn

Hello
How the best way to create vpn server (L2TP / PPP)
With routerborad
I need to join remote vpn pc's
To connect vpn with the server routerborad.
Any one write example for method and write all steps for that.
Suppose i have 1 public ip address in routerborad server.
Regards
by loveman
Tue May 10, 2016 11:08 pm
Forum: Beginner Basics
Topic: Block Whatsapp
Replies: 60
Views: 71816

Re: Block Whatsapp

yes, interval 2 minutes
Whats difference between interval 2 m
Or change to equal interval 10 m?
by loveman
Tue May 10, 2016 7:35 pm
Forum: General
Topic: Help to drop connection vpn
Replies: 8
Views: 3334

Re: Help to drop connection vpn

No answer
by loveman
Mon May 09, 2016 10:49 pm
Forum: General
Topic: Help to drop connection vpn
Replies: 8
Views: 3334

Help to drop connection vpn

Hello
Any one have idea how can blocking connection vpn like "psiphon" vpn program in mikrotik server .
Regards
by loveman
Sun May 08, 2016 12:19 am
Forum: General
Topic: PPPoE Authentication for Share & Dedicated users on the same Ethernet port.
Replies: 3
Views: 1548

Re: PPPoE Authentication for Share & Dedicated users on the same Ethernet port.

You can using static ip address from pppoe server (secret) put your static ip in remote address inside secret and then apply to all user's you like to be share bandwidth , and also when finish you can going in queues to allow who was static ip in pppoe server ,, to apply queue to them,, regards Tha...
by loveman
Sat May 07, 2016 11:12 am
Forum: Beginner Basics
Topic: Block Whatsapp
Replies: 60
Views: 71816

Re: Block Whatsapp

# Copy and Paste the above to WinBox New Terminal # /system scheduler add comment="Whatsapp Blocker" interval=2m name="Whatsapp Blocker" on-event="#\ \_Use DNS Entrys and add Address to the Firewall Address-list #\r\ \n:foreach i in=[/ip dns cache all find where (name~\&quo...
by loveman
Mon May 02, 2016 11:36 pm
Forum: General
Topic: How can drop netcut
Replies: 4
Views: 2930

Re: How can drop netcut

You cannot simply 'drop' it. Bussiness class ethernet switches support a feature called Dynamic ARP Inspection, but it only works with dynamically assigned IP addresses (DHCP). Mikrotik doesn't offer DAI. But if a direct communication between the clients isn't necessary and all adresses are assigne...
by loveman
Mon May 02, 2016 11:32 pm
Forum: General
Topic: PPPoE Authentication for Share & Dedicated users on the same Ethernet port.
Replies: 3
Views: 1548

Re: PPPoE Authentication for Share & Dedicated users on the same Ethernet port.

You can using static ip address from pppoe server (secret) put your static ip in remote address inside secret
and then apply to all user's you like to be share bandwidth ,
and also when finish you can going in queues to allow who was static ip in pppoe server ,,
to apply queue to them,,
regards
by loveman
Mon May 02, 2016 11:11 am
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

That you mean: https://psiphon.ca/index.html ? I do not know why but you can block with firewall all psiphon IP-address.
yes i meaning that,,
but you can help me to drop it from Mikrotik server
what's protocol and range ip's program use to try drop ?
by loveman
Fri Apr 29, 2016 10:27 pm
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

No answer
No answer
by loveman
Fri Apr 29, 2016 10:27 pm
Forum: General
Topic: How can drop netcut
Replies: 4
Views: 2930

Re: How can drop netcut

No answer
by loveman
Thu Apr 28, 2016 1:31 am
Forum: General
Topic: stop vpn connection
Replies: 18
Views: 16546

Re: stop vpn connection

using opendns

block the Proxy/Anonymizer category and that can help
Please write your method in the post
by loveman
Thu Apr 28, 2016 1:28 am
Forum: General
Topic: How can drop netcut
Replies: 4
Views: 2930

How can drop netcut

Hello
How can drop netcut program
Please anyone know how to block netcut.
Regards
by loveman
Wed Apr 27, 2016 12:41 am
Forum: General
Topic: stop vpn connection
Replies: 18
Views: 16546

Re: stop vpn connection

Any one have ideo to block psiphone vpn program?
by loveman
Thu Apr 21, 2016 12:46 pm
Forum: Scripting
Topic: Equal Bandwidth for a Number of Users not working good
Replies: 7
Views: 5719

Re: Equal Bandwidth for a Number of Users not working good

thank you very much
i get it
I need this to equal bandwidth but i used pppoe server how can distribution all user's in equal bandwidth
by loveman
Thu Apr 21, 2016 12:42 pm
Forum: General
Topic: RESTRICT FACEBOOK AND YOUTUBE STREAMING BASED ON OFFICE HOUR FROM 8:00 - 4:00 (08:00 - 16:00)
Replies: 21
Views: 23227

Re: RESTRICT FACEBOOK AND YOUTUBE STREAMING BASED ON OFFICE HOUR FROM 8:00 - 4:00 (08:00 - 16:00)

if you can using method to block facebook and youtube ? if you need this reply me and i helping you
by loveman
Wed Apr 20, 2016 3:50 pm
Forum: General
Topic: How can share equal bandwith
Replies: 6
Views: 1867

Re: How can share equal bandwith

I don't use it myself so can't help you but there're lotsa tutorials and examples on the internet. Just google "Mikrotik Simple Queue PCQ Examples"

http://bfy.tw/5LEI
Thanks, i now that
by loveman
Wed Apr 20, 2016 3:49 pm
Forum: Scripting
Topic: Help! Script for equal bandwidth
Replies: 1
Views: 1417

Re: Help! Script for equal bandwidth

No answer
by loveman
Tue Apr 19, 2016 4:02 pm
Forum: Scripting
Topic: Help! Script for equal bandwidth
Replies: 1
Views: 1417

Help! Script for equal bandwidth

Hello
Any one have script to do equal sharing bandwidth using queue tree, between user's according to using pppoe server.
Regards
by loveman
Tue Apr 19, 2016 9:42 am
Forum: General
Topic: How can share equal bandwith
Replies: 6
Views: 1867

Re:

Ok. Too lazy to Google? I did it for you :

http://wiki.mikrotik.com/wiki/Manual:Queues_-_PCQ
I know this site, but need an actual application with photo
by loveman
Tue Apr 19, 2016 8:20 am
Forum: General
Topic: How can share equal bandwith
Replies: 6
Views: 1867

Re: How can share equal bandwith

why not using simple queue with pcq?
Ok,, please write method for pcq and explain with photo.
by loveman
Mon Apr 18, 2016 7:51 pm
Forum: General
Topic: How can share equal bandwith
Replies: 6
Views: 1867

How can share equal bandwith

Hello every one
How can share equal bandwith using queue tree
Regards
by loveman
Sun Apr 17, 2016 8:38 am
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

Re: How can block psiphon vpn

No answer
by loveman
Thu Apr 14, 2016 11:28 pm
Forum: Beginner Basics
Topic: How can block psiphon vpn
Replies: 16
Views: 10655

How can block psiphon vpn

Hello
Experience difficulty to how can block " psiphon vpn"
if any one have idea please share it here .

Thank you
regards
by loveman
Thu Apr 14, 2016 11:14 pm
Forum: General
Topic: Layer7 rule to block Psiphon and Opera Turbo
Replies: 6
Views: 4952

Re: Layer7 rule to block Psiphon and Opera Turbo

How can block Psiphon ?
by loveman
Fri Apr 08, 2016 10:56 am
Forum: General
Topic: pppoe server can't connect
Replies: 2
Views: 1390

Re: pppoe server can't connect

No answer
by loveman
Thu Apr 07, 2016 12:29 am
Forum: General
Topic: pppoe server can't connect
Replies: 2
Views: 1390

Re: pppoe server can't connect

No answer
by loveman
Thu Apr 07, 2016 12:29 am
Forum: General
Topic: share file with difference subnet
Replies: 18
Views: 3102

Re: share file with difference subnet

Follow
by loveman
Mon Apr 04, 2016 11:24 pm
Forum: General
Topic: pppoe server can't connect
Replies: 2
Views: 1390

pppoe server can't connect

Hello everyone I have problem with pppoe server when i try to connect with windows 8 . message of problem from windows, "error 720 a connection to the remote computer could not be established you might need to change the network settings for this connection ." I expect that problem in &quo...
by loveman
Wed Feb 17, 2016 8:54 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re: How can Drop - sharing internet program

PPPoE does not use DHCP. PPP assigns the IP addresses of the clients using IPCP, so it can use /32 addresses. Assigning a /32 to clients' ethernet adapters (when they're not using PPPoE) would probably break their connectivity - I haven't tried this in the lab or anything, but I think I'll experime...
by loveman
Thu Feb 11, 2016 11:12 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re: How can Drop - sharing internet program

pppoe eliminates arp poisoning attacks and rogue/malicious dhcp because your router only forward packets in pppoe tunnels. Of course, someone could put a pppoe server on the LAN if they're motivated..... Again... you can put all of the rules you like into your router, but it will not block client-t...
by loveman
Tue Feb 09, 2016 11:19 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re: How can Drop - sharing internet program

Not really.... netcut lets users do things like arp poisoning and such - the router can't stop this kind of traffic because this traffic doesn't even go through the router at all. It's strictly client to client. arp = reply-only coupled with DHCP server creating dynamic ARP table entries is a way t...
by loveman
Tue Feb 09, 2016 6:14 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re: How can Drop - sharing internet program

Dropping things like netcut requires access port security, which Mikrotik doesn't really have. The mainstream net vendors like Cisco, Dell, Juniper, etc have features like DHCPguard, RA guard (if you're doing IPv6), MAC guard, etc - all of these things are required for stopping such things, because...
by loveman
Tue Feb 09, 2016 6:05 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re:

Try to limit connections or packets. For sure you can see a difference between a normal client and those who sharing. This will not stop them to share but for sure will make them problems :) . Some years ago I was changing the TTL to 1 and luckily they did not know to increment it again . Sent from...
by loveman
Tue Feb 09, 2016 6:04 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re: How can Drop - sharing internet program

Changing the TTL is still an option in my router, which is running the bleeding-edge 6.34.1 You could do a sniffer capture on the LAN interface to confirm that the outbound TTL values are indeed being set to 1. If they are being set to 1, then the client's sharing devices are incrementing the TTL a...
by loveman
Thu Feb 04, 2016 10:49 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re: How can Drop - sharing internet program

In a word - you really can't do it. How can you tell by inspecting packets, the difference between packets generated by an application on the "sharing" host, vs packets generated by applications running on devices behind the sharing device? There may be subtle clues in the payload, but th...
by loveman
Thu Feb 04, 2016 10:40 pm
Forum: General
Topic: How can Drop - sharing internet program
Replies: 18
Views: 5077

Re: How can Drop - sharing internet program

Write great method... OK. First of all you need to know how to distinguish their traffic from the rest. Can you? If yes then you can drop it. Unfortunately I haven't noticed any problems caused by these programs in my network so I cannot advice how to distinguish their traffic. I am working in comp...
  • 1
  • 2