Community discussions

MikroTik App

Search found 89 matches

by tr00g33k
Tue Apr 18, 2023 3:11 pm
Forum: Forwarding Protocols
Topic: ROS 7.1 BGP max-prefix-limit missing
Replies: 54
Views: 13101

Re: ROS 7.1 BGP max-prefix-limit missing

I cant find option max-prefix-limit ir RoS v7.7, please any tip ?
by tr00g33k
Thu Aug 12, 2021 12:54 am
Forum: Forwarding Protocols
Topic: BGP Set In Nexthop and Set Check Gateway PING
Replies: 0
Views: 2788

BGP Set In Nexthop and Set Check Gateway PING

Hi, I have some specific configuration on IX. We have peering with IX but no direct peering with other through IX. We have a problem when one of the IX member (lets say AS6500) have two peers one is on the other side of the country (assume ip 10.10.10.101) and one realy close to us (10.10.10.100). R...
by tr00g33k
Wed Aug 19, 2020 3:31 pm
Forum: General
Topic: CRS354-48G+4S+2Q 802.3ad between switch and debian didn't works
Replies: 4
Views: 2800

Re: CRS354-48G+4S+2Q 802.3ad between switch and debian didn't works

Was this solved in 6.47.2, we have problems when we connect HP or netgear 802.3ad to CRS-354, in hp case there is traffic disruption all over the network, in netgear there is nothing going through. With other devices LACP works ok, if we connect only one cable from MikroTik to HP, no traffic goes th...
by tr00g33k
Sun May 24, 2020 1:44 pm
Forum: Forwarding Protocols
Topic: BGP Filtering routes from IXP internet exchange point
Replies: 0
Views: 1284

BGP Filtering routes from IXP internet exchange point

Hi, Bellow Iam attaching the network diagram on which Iam in position os ISP1 (AS65537), we are connected with one router to one of the internet exchange points with two route servers (AS65536). On the other side there is ISP2 (AS65538) connected to the IXP with two routers, one router is 192.168.10...
by tr00g33k
Thu Feb 06, 2020 9:34 am
Forum: General
Topic: MikroTik Q-in-Q the same as nexus/cisco 3750 etc
Replies: 0
Views: 1503

MikroTik Q-in-Q the same as nexus/cisco 3750 etc

Hi, i would like to achive the following configuration that works on Cisco Nexus, on MikroTik HEX s models. CISCO-NX-ISP-SW01 & CISCO-NX-ISP-SW02: Eth1/1: Switchport access vlan 1500 switchport mode dot1q-tunnel Eth1/2 sw mod tr sw tr all vl 1500 C2960-ISP-SW01 & C2960-ISP-SW02: Fa0/1 & ...
by tr00g33k
Tue Jun 04, 2019 11:06 pm
Forum: Virtualization
Topic: MikroTik CHR 6.44.3 high latency on ESXi, 6.5.0.20000 vs 6.0 [SOLVED]
Replies: 2
Views: 15620

Re: MikroTik CHR 6.44.3 high latency on ESXi, 6.5.0.20000 vs 6.0 [SOLVED]

Exactly :) If i would see a post earlier would sure saved me an hour or two of trubleshooting configuration of two data-centers that we dont have any problems with, only CHR have strange problems (or admin didnt get enough of sleep for few days) :) The strangest problems, are most of the time stupid...
by tr00g33k
Thu May 30, 2019 12:07 pm
Forum: Virtualization
Topic: MikroTik CHR 6.44.3 high latency on ESXi, 6.5.0.20000 vs 6.0 [SOLVED]
Replies: 2
Views: 15620

MikroTik CHR 6.44.3 high latency on ESXi, 6.5.0.20000 vs 6.0 [SOLVED]

Hi, Installation and configuration: -Imported vmdk 6.44.3 to datastore -Converted vmdk -Created new virtual machine with 2 cpu, 4 gbram, 512mb disk as it is on MikroTik site -Connected disk to ide0 -Network cards vmxnet3 We installed MikroTik CHR 6.44.3 on vmware ESXi 6.5.0.2000 and we have problem ...
by tr00g33k
Wed Jan 16, 2019 12:19 pm
Forum: General
Topic: SMS without data subscription
Replies: 3
Views: 1269

Re: SMS without data subscription

Where you able to solve this ? I have the same problem,...
by tr00g33k
Mon Sep 03, 2018 3:12 pm
Forum: Beginner Basics
Topic: Max MTU through PPPoE smaller than through PPPoE/OpenVPN
Replies: 3
Views: 1767

Re: Max MTU through PPPoE smaller than through PPPoE/OpenVPN

That is exactly what i figured out. It didnt go out of my head, so i used good old wireshark to check what is going on R1 and R2. The packet are fragmented but if you are PC1 you dont know about it, because they are fragmented through PPPoE and on the link to the R2. And on the other side of OpeVPN ...
by tr00g33k
Mon Sep 03, 2018 12:13 am
Forum: Beginner Basics
Topic: Max MTU through PPPoE smaller than through PPPoE/OpenVPN
Replies: 3
Views: 1767

Max MTU through PPPoE smaller than through PPPoE/OpenVPN

Hello, I have been playing around a bit with max MTU path discovery, and I came across something strange. My setup is following: http://shrani.si/f/2F/9E/4aIU5CyA/2018-09-02-225848-drawin.png I have OpenVPN tunnel established beetwen R1 and R2 (MikroTiks), R1 access internet through PPPoE, R2 have I...
by tr00g33k
Tue Jul 24, 2018 1:56 pm
Forum: Announcements
Topic: v6.42.6 [current]
Replies: 102
Views: 64370

Re: v6.42.6 [current]

Updated CRS326-24G-2S+ from firmware v6.42.3 to 6.42.6 update went fine but after the update process ether24 en ether23 aren't working anymore. They give link negotiate speed ect. but no mac address what so ever. Both port where trunk ports one has a WAP AC on it and the other a Cisco Switch. Movin...
by tr00g33k
Sat Mar 31, 2018 6:08 pm
Forum: General
Topic: VRF overlaping networks, default route in main routing table
Replies: 0
Views: 1088

VRF overlaping networks, default route in main routing table

Hello, I`am testing MikroTik`s VRF functionality, to see where it can came to good use. I`am trying to achieve following: -4 VRFs: red, blue, green, black -red and black VRF with overlaping networks -All VRFs should access internet through main routing table, at gateway 192.168.24.1 (wlan1 interface...
by tr00g33k
Mon Jul 17, 2017 12:30 pm
Forum: General
Topic: VRRP on VLAN - TRUNK between two Mikrotik
Replies: 7
Views: 6928

Re: VRRP on VLAN - TRUNK between two Mikrotik

I had the same problem two mikrotiks (Rb3011, for redundant links), trunk beetwen them and vlans. VRRP V3 protocol:IPv4 on VLAN interface. On ipv4 protocol vrrp is not working I installed ipv6 package and set VRRP V3 protocol to ipv6, not it works. MikroTik Engineers can you give any info why V3 pro...
by tr00g33k
Tue Jul 11, 2017 8:55 pm
Forum: General
Topic: Site to Site IPSec VPN stops passing traffic
Replies: 3
Views: 2460

Re: Site to Site IPSec VPN stops passing traffic

If you have PFS (perfect forward secrecy) enabled, try disable-ing it. Check all the timers lifetime for phase1 & phase2. Another thing to try is to ping every 1-3 seconds through tunnel, from one side and from another, and see if the tunnel goes down, even if constantly passing traffic through ...
by tr00g33k
Mon Jul 10, 2017 10:58 pm
Forum: General
Topic: Mark packets on one router so another one can use the marks?
Replies: 7
Views: 3491

Re: Mark packets on one router so another one can use the marks?

Simple solution: on router 1 you create two nat rules one is dst-nat and second is src-nat, you NAT src-address to your router LAN IP, so it hides the public IP of the packet. Example: on router one you create two rules: DST-NAT: /ip fire nat add chain=dstnat dst-address=1.1.1.1 protocol=tcp dst-por...
by tr00g33k
Mon Jul 10, 2017 4:47 pm
Forum: Beginner Basics
Topic: 443 outbount not working
Replies: 1
Views: 675

Re: 443 outbount not working

Add in-interface=WAN or dst-address=WAN-IP to your nat configuration, and everything should work fine.
by tr00g33k
Sun Mar 19, 2017 3:26 pm
Forum: Beginner Basics
Topic: Default Mikrotik Firewall config (RouterOS 6.38.5)
Replies: 6
Views: 8861

Re: Default Mikrotik Firewall config (RouterOS 6.38.5)

Are you doing scan from inside the network to your WAN IP? From routers LAN? If this is the case this is normal.

Checked your config once more you have any TCP port NATed to internal 192.168.88.101 32400
by tr00g33k
Thu Mar 09, 2017 7:33 pm
Forum: Beginner Basics
Topic: Problem with firewall rules
Replies: 10
Views: 2685

Re: Problem with firewall rules

You are missing established, related firewall rule on forward chain Your config: ip firewall filter add chain=forward action=accept protocol=udp dst-port=53 comment="Accept DNS" add chain=forward action=accept src-address=172.16.31.101/32 dst-address=190.96.78.8/32 add chain=forward action...
by tr00g33k
Thu Mar 09, 2017 7:30 pm
Forum: General
Topic: Blocking facebook
Replies: 14
Views: 37089

Re: Blocking facebook

I do this whit quit good results, like this: /ip fire address-list add list=Facebook address=facebook.com /ip fire address-list add list=Facebook address=facebook.de and .ru => or whatever country you live in .ru => russia .de => germany etc and after that: /ip firewall filter add chain=forward src-...
by tr00g33k
Wed Mar 08, 2017 8:49 pm
Forum: Beginner Basics
Topic: Begginer - Internet for 1500 houses (Gated community)
Replies: 14
Views: 3034

Re: Begginer - Internet for 1500 houses (Gated community)

Do you have any scheme for the begining ? Ok you are beginner with MikroTik. Tell us how you would accomplish this with other vendor network equipment, and we can try to help you with MikroTik. First you need some design How many network nodes ? Will you provide VoIP for customers? Providing TV? Do ...
by tr00g33k
Sat Mar 04, 2017 12:11 pm
Forum: General
Topic: VLAN weird behavior
Replies: 4
Views: 1119

Re: VLAN weird behavior

It is very hard to guess what is the problem if you dons post cnfiguration. My first guess would be that you briged everything on mikrotik, and connect it to pfsence. Than pfsence gave out DHCP based on dhcp binding that already have. And every device recived correct IP. Communiaction worked because...
by tr00g33k
Thu Mar 02, 2017 10:14 pm
Forum: Beginner Basics
Topic: It does not work TRUNK connection between the CISCO 2950 and CCR1009
Replies: 4
Views: 1490

Re: It does not work TRUNK connection between the CISCO 2950 and CCR1009

Did you try to tag native vlan ? Do you have the vlans created on switch ? does the port goes up ? Do you see MikroTik in
show cdp neig fa x/y det
?


Do you see any errors in:
sh int status fa x/y
We have many mikrotik => cisco trunks with no problem.
by tr00g33k
Thu Mar 02, 2017 8:12 pm
Forum: Beginner Basics
Topic: It does not work TRUNK connection between the CISCO 2950 and CCR1009
Replies: 4
Views: 1490

Re: It does not work TRUNK connection between the CISCO 2950 and CCR1009

Two things to try on trunk port on cisco:
switchport trunk encapsulation dot1q
or
global config: vlan dot1q tag nativ 
by tr00g33k
Wed Feb 22, 2017 7:07 pm
Forum: Beginner Basics
Topic: MikroTik, Cisco and QinQ
Replies: 3
Views: 4385

Re: MikroTik, Cisco and QinQ

Thank you for giving me back hope :) I tried one more time the same configuration diffrent cisco switch, works perfect, exactly the same configuration. I was testing this on some old Cisco switch. Than i put the same configuration on production networks, works like it was intended to work.
by tr00g33k
Sat Feb 18, 2017 12:11 pm
Forum: Beginner Basics
Topic: MikroTik, Cisco and QinQ
Replies: 3
Views: 4385

MikroTik, Cisco and QinQ

Hello, i would like to achieve something like this if i even imagine this correctly. I have some network with mostly C2960 switches, that does not support 802.1QinQ. And have some MikroTiks on the edges where i could configure this. But i still have to get vlans through 2960`s without 802.1QinQ supp...
by tr00g33k
Fri Feb 03, 2017 2:10 pm
Forum: Beginner Basics
Topic: Connectivity 2 IP different range
Replies: 8
Views: 5193

Re: Connectivity 2 IP different range

You can assingn IP on port 2: 192.168.100.1/24 assing IP on port 5: 192.168.1.1/24 ip address add interface=Eth2 address=192.168.100.1/24 ip address add interface=Eth5 address=192.168.1.1/24 Than create firewall rules: ip fire fil add chain=forward src-address=192.168.1.0/24 dst-address=192.168.100....
by tr00g33k
Wed Feb 01, 2017 3:23 pm
Forum: General
Topic: Routing between 3 networks
Replies: 5
Views: 2061

Re: Routing between 3 networks

That is the easiest solution if the network 192.168.1.0/24 does not need to access back to 172.100.100.0/24.
This is the worst, if you have to make some VPN tunnels and you dont have access to other side, or un-cooperative network admin on the other side.

Glad that this solved your issue
by tr00g33k
Tue Jan 31, 2017 8:49 pm
Forum: General
Topic: Routing between 3 networks
Replies: 5
Views: 2061

Re: Routing between 3 networks

From 172.10.10.0/24 you can access 192.168.1.0/24?
If this is true what if you try a trick NAT 172.100.100.0/24 through one of the IPs 172.10.10.0/24 to 192.168.1.0/24, so you will see where to look for the miskate, on your side or other side.
by tr00g33k
Mon Jan 30, 2017 9:39 pm
Forum: General
Topic: Routing between 3 networks
Replies: 5
Views: 2061

Re: Routing between 3 networks

On RB201: You have to have route for 192.168.1.0/24 that shows to GW 172.10.1.2 You have to have route for 172.10.10.0/24 that shows to GW 172.10.1.2 On Rb1200: You have to have policy from 172.100.100.0/24 to 192.168.1.0/24 You have to have policy from 172.10.10.0/24 to 192.168.1.0/24 And all prope...
by tr00g33k
Tue Jan 03, 2017 3:53 pm
Forum: Beginner Basics
Topic: Question about multiple VLANs
Replies: 1
Views: 725

Re: Question about multiple VLANs

You create vlan 100 and 101 like this /interface vlan add name=Vlan100-eth10 interface=eth10 vlan-id=100 /interface vlan add name=Vlan100-eth6 interface=eth6 vlan-id=100 /interface vlan add name=Vlan101-eth10 interface=eth10 vlan-id=101 /interface vlan add name=Vlan101-eth6 interface=eth6 vlan-id=10...
by tr00g33k
Sat Dec 17, 2016 4:09 pm
Forum: Beginner Basics
Topic: Dual wan for two gateway
Replies: 2
Views: 1904

Re: Dual wan for two gateway

Hi, i have this situation: Port 1 - working ppoe-out1 connection (wan1) Port 2 - working ppoe-out2 connection (wan2) Port 5 - LAN I have 192.168.1.0/24 and 192.168.2.0/24 ip on port5 LAN. I want set gateway of 192.168.1.0/24 to ppoe-out1 and gateway of 192.168.2.0/24 to ppoe-out2. I tried this /ip ...
by tr00g33k
Sat Dec 17, 2016 4:02 pm
Forum: Beginner Basics
Topic: Link public ip to local ones
Replies: 1
Views: 910

Re: Link public ip to local ones

Hi all, I have been trying for several days to get my block of public IPs to work with no luck... I got this mail from my ISP, they said that "We have now routed 62.XX.X.1/29 as second subnet (gw 62.XX.X.1) and we have 1:1 nat your ip 172.16.XX.2 to 62.XX.X.3 and routed the subnet 62.XX.X.64/2...
by tr00g33k
Sat Dec 17, 2016 3:49 pm
Forum: Beginner Basics
Topic: VoIP Problem!!
Replies: 1
Views: 840

Re: VoIP Problem!!

The QoS have to be implemented all the way, from your customer to last router
by tr00g33k
Thu Dec 15, 2016 10:01 pm
Forum: Beginner Basics
Topic: Can't reach google
Replies: 8
Views: 3274

Re: Can't reach google

The only time that this happens is to google? Do you maybe have some firewall rule related to google`s IP, some L7 google firewall rule? Address list? From what i see i wouldnt say it is a ISP problem it looks like the packet doesnt go out from router, could you paste whole config, to see what could...
by tr00g33k
Thu Dec 15, 2016 9:18 pm
Forum: Beginner Basics
Topic: Route between 2 interfaces with 2 subnets (without a bridge)
Replies: 12
Views: 7299

Re: Route between 2 interfaces with 2 subnets (without a bridge)

Please post whole configuration so we can see what could the problem be.
by tr00g33k
Thu Dec 15, 2016 9:15 pm
Forum: Beginner Basics
Topic: Can't reach google
Replies: 8
Views: 3274

Re: Can't reach google

Please poste your routing table, routing rules and magle rules, it looks like routing loop. but this is only to google ? Try to make traceroute to see where the packet start to bounce between two hosts, at least it looks like that.
by tr00g33k
Wed Dec 14, 2016 7:36 am
Forum: General
Topic: Can i set switches of RB2011 function independently?
Replies: 3
Views: 1283

Re: Can i set switches of RB2011 function independently?

If I understand correctly what you want to achieve: http://shrani.si/f/E/HZ/P1GcVcG/netscheme.png Yes you can create this, be careful you have to create two separate NAT masquerade rules. And you have to create "policy based routing" with mangle rules, so you have to mark routing from &quo...
by tr00g33k
Wed Dec 14, 2016 7:24 am
Forum: Beginner Basics
Topic: Router down alert
Replies: 2
Views: 2198

Re: Router down alert

Simple and easy way that i use, create a "netwatch host", than under 1.) UP EVENT: /file print file=XY_Router_UP tool e-mail send server=xx.xx.xx.xx port=25 user=xx@xx.com to=xy@xx.com from=xx@xx.com subject="XY Router UP" body="XY Router UP" 2.) DOWN EVENT: /file print...
by tr00g33k
Tue Dec 13, 2016 10:19 pm
Forum: Beginner Basics
Topic: Problem whit POP3 mail Server / Load Balance whit recursive GW
Replies: 2
Views: 995

Re: Problem whit POP3 mail Server / Load Balance whit recursive GW

Two ideas, do you maybe have fast path enabled ? Common error when dealing with mangle rules.

Other try with packet marking.

And if still you cannot solve this, try to post the whole configuration so we can see the whole picture
by tr00g33k
Tue Dec 13, 2016 10:13 pm
Forum: Beginner Basics
Topic: Port VLAN assignment and routing
Replies: 2
Views: 1046

Re: Port VLAN assignment and routing

If i understand correctly you recive tagged vlan 8 on port 1 interface vlan add vlan-id=8 interface=ether1 name=VoIP-Vlan8 and then you want to create access port on ether4 and ether5. For that you create additional bridge interface bridge add name=AccessBridgeVlan8 and add ports to that bridge inte...
by tr00g33k
Mon Dec 12, 2016 7:49 pm
Forum: Beginner Basics
Topic: rb2011uias-2hnd-in in/out-interface matcher switch error
Replies: 6
Views: 14436

Re: rb2011uias-2hnd-in in/out-interface matcher switch error

You have ether1 in bridge, on firewall rules use bridge as in/out interface, or remove ether1 from bridge.
by tr00g33k
Wed Nov 30, 2016 10:20 am
Forum: General
Topic: Ping Wan2 on Dual Wan
Replies: 4
Views: 2999

Re: Ping Wan2 on Dual Wan

I do it with mangle rules.

About dynamic IP, you could create script, that would check let sat every 30 seconds (with scheduler) for IP on your dynamic IP wan port. And updated mangle rule with IP that is currently on wan2 port.
by tr00g33k
Tue Nov 29, 2016 7:33 pm
Forum: General
Topic: Ping Wan2 on Dual Wan
Replies: 4
Views: 2999

Re: Ping Wan2 on Dual Wan

Yes because when you define source and you point it to 8.8.8.8 mikrotik looks at the routing table and takes the default route with better distance. And he tries to go out with wan2 IP on wan1 interface, and gets denied from ISP on WAN1, because ISP doesnt know for this segment. You can solve this w...
by tr00g33k
Tue Nov 29, 2016 6:16 pm
Forum: Beginner Basics
Topic: CCR 1036 routing performance between local 10. and 192. subnet
Replies: 4
Views: 1363

Re: CCR 1036 routing performance between local 10. and 192. subnet

So you unpluged one of the cables and did what ? Plug it into another switch ? Please draw as what setup you have right now.
by tr00g33k
Tue Nov 29, 2016 6:12 pm
Forum: Beginner Basics
Topic: EIOP or VPN?
Replies: 2
Views: 1138

Re: EIOP or VPN?

If you cant get this working you can try with SSTP site to site only port 443 required, if you dont need EOIP because you would need the same L2 broadcast domain over VPN. On one site you setup SSTP server, NAT 443 on DD-WRT, on other side you create SSTP client, and connect to SSTP server.
by tr00g33k
Tue Nov 29, 2016 6:06 pm
Forum: General
Topic: Connect Two RB2011 via VPN tunnel. L2TP/IPSEC or SSTP?
Replies: 4
Views: 1825

Re: Connect Two RB2011 via VPN tunnel. L2TP/IPSEC or SSTP?

One more vote for pure IPsec, at most clients we are running pure IPsec site-to-site MikroTIk->MikroTik and MikroTik->Many other vendors, no problem at all. L2TP and other protocols would be useful if you would run some dynamic routing protocols over site-to-site.
by tr00g33k
Tue Nov 29, 2016 10:28 am
Forum: Beginner Basics
Topic: ether link down in Hap AC
Replies: 2
Views: 1105

Re: ether link down in Hap AC

I had the same problems with hAP lite rb941. Example port 3 only for one laptop did not work, all other ports ok, and port 3 for other computers ok, even two same 8440p elitebooks one worked on ether 3 other not, and the same laptop that did not work on rb941 worked on any other equipment, when repl...
by tr00g33k
Tue Nov 29, 2016 10:23 am
Forum: General
Topic: SSTP vpn & PPP authentication via radius
Replies: 4
Views: 4650

Re: SSTP vpn & PPP authentication via radius

I have working RADIUS for SSTP and PPtP authentication on windows server 2012.

Make sure to tick the radius authentication
Image

Image

Image
by tr00g33k
Mon Nov 28, 2016 7:05 pm
Forum: General
Topic: High upload - security breach?
Replies: 3
Views: 1794

Re: High upload - security breach?

On which port do they connect if it is UDP 53, be sure to block remote DNS requests under IP->DNS->Allow remote request untick the box or with firewall /ip fire filter chain=input in-interface=WAN protocol=UDP dst-port=53 action=drop Otherwise make a torch on LAN interface and see the connections
by tr00g33k
Mon Nov 28, 2016 4:33 pm
Forum: General
Topic: routing-mark sends connections out, but nothing comes back
Replies: 13
Views: 3783

Re: routing-mark sends connections out, but nothing comes back

I suggest that you read: http://mum.mikrotik.com/presentations/UA15/presentation_3077_1449654925.pdf And the new way of fast-path diagram is that than and there one of the packets go the slow path so that it checks if others packets are ok to go fast-path, quickly explained. I never have fast-path e...
by tr00g33k
Sun Nov 27, 2016 8:43 pm
Forum: General
Topic: routing-mark sends connections out, but nothing comes back
Replies: 13
Views: 3783

Re: routing-mark sends connections out, but nothing comes back

Because some packets went the slow path and went through mangle rules as they should and applied correct routing decision. Other packets went through fast-path, and only routing decision was made based on the routing table no mangle rule applied to the packets.

Do you understand the explanation?
by tr00g33k
Sun Nov 27, 2016 8:08 pm
Forum: General
Topic: routing-mark sends connections out, but nothing comes back
Replies: 13
Views: 3783

Re: routing-mark sends connections out, but nothing comes back

Do you maybe have FastPath enabled? If so, disable and try again.
Maybe you could post your whole config so it is easier to see, it there some little thing that needs to be changed.
by tr00g33k
Sun Nov 27, 2016 6:34 pm
Forum: General
Topic: routing-mark sends connections out, but nothing comes back
Replies: 13
Views: 3783

Re: routing-mark sends connections out, but nothing comes back

Try this for test: /ip route rule add src-address=10.0.32.1 dst-address=0.0.0.0/0 routing-mark=direct action=lookup and then try delete all other mangling rules and only add this one: /ip firewall mangle add src-address=10.0.32.1 dst-address=0.0.0.0/0 action=mark-routing new-routing-mark=direct pas...
by tr00g33k
Sun Nov 27, 2016 6:09 pm
Forum: General
Topic: routing-mark sends connections out, but nothing comes back
Replies: 13
Views: 3783

Re: routing-mark sends connections out, but nothing comes back

If there is some traffic in both direction maybe try adjusting tcp-mss, you have L2TP/IPsec site-to-site that goes through PPPoE, if i understood your setting correctly. You have some additional overhead because of this protocols, try adjusting TCP-MSS to about 1352, or even lower if that doesnt work.
by tr00g33k
Sun Aug 14, 2016 11:43 pm
Forum: Beginner Basics
Topic: MikroTik "masquerade" public IP to LAN IP of router
Replies: 4
Views: 3238

Re: MikroTik "masquerade" public IP to LAN IP of router

Thank you for the TIP i knew that already but i wanted to masqureade only one port. So today i was playing around and i found the way to do this, but i dont know if this is the way it should be done: /ip firewall nat add action=dst-nat chain=dstnat dst-port=3389 in-interface="Eth1 - WAN" p...
by tr00g33k
Sun Aug 14, 2016 12:04 pm
Forum: Beginner Basics
Topic: MikroTik "masquerade" public IP to LAN IP of router
Replies: 4
Views: 3238

MikroTik "masquerade" public IP to LAN IP of router

Hello! I have a question I have two "routers" on network one MikroTik and one L7 firewall for testing purposes. The LAN network have default route (default gateay) set to firewall. But the LAN network can have access through MikroTik to, so the MikroTik and the L7 firewall both have WAN IP...
by tr00g33k
Wed Jul 27, 2016 8:44 pm
Forum: RouterBOARD hardware
Topic: Please help to choose right OEM board for particular task
Replies: 3
Views: 1317

Re: Please help to choose right OEM board for particular task

I can answer on your question about limited editing for cutomer, you can create web skin, and add only the options that you want that the client can configure. Other it is not possible to answer because it depends on a lot of things. You can access into skin designer through web interface, and you c...
by tr00g33k
Mon Jun 06, 2016 12:21 pm
Forum: General
Topic: What is the best way to block P2P traffic
Replies: 10
Views: 3572

Re: What is the best way to block P2P traffic

What kind of VPN connection PPtP, SSTP, vendor specific ? It depends what kind of VPN you whant to block,...
by tr00g33k
Mon Jun 06, 2016 12:15 pm
Forum: Beginner Basics
Topic: Portforwarding based on DNS name
Replies: 9
Views: 7528

Re: Portforwarding based on DNS name

I think this could be possible, with some scripting. If I understand correctly you have 1 static public IP and more dynamic IPs that are connected with some A records ? You could do two nat rules, with diffrent dst-addresses. Than create script that every 10 seconds resolves dns name, and use that I...
by tr00g33k
Thu May 26, 2016 10:20 am
Forum: General
Topic: Mikrotik 2011 on comcast connection
Replies: 3
Views: 1014

Re: Mikrotik 2011 on comcast connection

Try to contact the ISP and ask him what does he recommends for MTU, and set that MTU on WAN interface. Maybe you could give it a shot.
by tr00g33k
Mon May 23, 2016 11:02 am
Forum: General
Topic: PPPoE Failover
Replies: 3
Views: 1389

Re: PPPoE Failover

I would use VRRP and some scripting.
by tr00g33k
Fri Apr 22, 2016 4:56 pm
Forum: Beginner Basics
Topic: Wireless Split traffic Need Help please
Replies: 1
Views: 752

Re: Wireless Split traffic Need Help please

What about if you do dhcp reservations for this 20 clients and create address list for firewall and then allow only this clients to VPN site ?
by tr00g33k
Thu Apr 07, 2016 11:54 am
Forum: Beginner Basics
Topic: Add WLAN to a VLAN trunk
Replies: 12
Views: 3324

Re: Add WLAN to a VLAN trunk

/interface vlan add name=Vlan23 vlan-id=23 interface=ether1 /interface bridge add name="Access_vlan23" /interface bridge port add bridge =Access_vlan23 interface=wlan1 /interface bridge port add bridge=Access_vlan23 interface=Vlan23 This config means that you recive tagged vlan 23 on ethe...
by tr00g33k
Tue Apr 05, 2016 9:08 pm
Forum: General
Topic: MikroTik CCR1016, VLAN, VRRP and reply-only problem
Replies: 2
Views: 1041

Re: MikroTik CCR1016, VLAN, VRRP and reply-only problem

Let me ask a bit diffrent, did anybody ever tried arp: reply-only on VLAN VRRP interface ?
by tr00g33k
Mon Apr 04, 2016 11:29 pm
Forum: General
Topic: MikroTik CCR1016, VLAN, VRRP and reply-only problem
Replies: 2
Views: 1041

MikroTik CCR1016, VLAN, VRRP and reply-only problem

Hello I have configured a VRRP on MikroTik CCR-1016 v6.34.4 in my network and I have some problem. My configuration looks something like this: I have VLAN10 on VLAN10 I have configured VRRP interface. On interface VLAN10 I have set arp to enabled. On VRRP-VLAN10 I have set arp to "reply-only&qu...
by tr00g33k
Thu Mar 24, 2016 10:11 pm
Forum: Beginner Basics
Topic: Traffic analysis
Replies: 1
Views: 889

Re: Traffic analysis

What about using NetFlow software for this?
by tr00g33k
Thu Mar 24, 2016 1:51 pm
Forum: Beginner Basics
Topic: IP and MAC Address Validation before pass through the routeros
Replies: 7
Views: 2495

Re: IP and MAC Address Validation before pass through the routeros

under:

IP/DHCP Server / Networks / You choose network and add netmask.

If you want to go even further you can even set /32 mask for every client.
how u set /32 mask for every client in mt?
by tr00g33k
Thu Mar 24, 2016 1:50 pm
Forum: Beginner Basics
Topic: IP and MAC Address Validation before pass through the routeros
Replies: 7
Views: 2495

Re: IP and MAC Address Validation before pass through the routeros

Maybe I dont understand what exactly you want to achieve, with this config if clients sets up static IP it cannot communicate with router or internet. I have this setup on many networks, and the clients cannot access internet if setup static IP. i am already using the config. u suggest me :) but as ...
by tr00g33k
Thu Mar 24, 2016 7:48 am
Forum: Beginner Basics
Topic: "voided" factory settings
Replies: 2
Views: 882

Re: "voided" factory settings

When you reset router:
/system reset-configuration no-defaults=no
by tr00g33k
Thu Mar 24, 2016 7:41 am
Forum: Beginner Basics
Topic: IP and MAC Address Validation before pass through the routeros
Replies: 7
Views: 2495

Re: IP and MAC Address Validation before pass through the routeros

You setup DHCP server to add arp for leases /ip dhcp-server set "DHCP-Local" add-arp=yes => the router will add ARP lease for every DHCP IP address Than on local bridge you setup arp to reply only /interface bridge set "LAN" arp=reply-only => This means that router will reply onl...
by tr00g33k
Sun Mar 20, 2016 7:23 pm
Forum: Beginner Basics
Topic: Log Screen
Replies: 2
Views: 1223

Re: Log Screen

Looks like somebody is bruteforcing your SSH service. If you dont need it disable it under /ip service disable ssh If you use it, limit the access with firewall rules (example if you need access to ssh only from 192.168.1.10): /ip firewall filter add chain=input src-address=192.168.10.1 protocol=tcp...
by tr00g33k
Sun Mar 20, 2016 7:16 pm
Forum: Beginner Basics
Topic: 4 VPN on one server
Replies: 1
Views: 842

Re: 4 VPN on one server

Do the same for all 4 WAN ports 1.) Enable PPTP server 2.) For each WAN IP create coresponding firewall rules to accept GRE protocol and TCP port 1723 3.)Configure all other PPTP setings to your need (IP pools, users etc.) You should write some more what you dont know how to do, or what you want to ...
by tr00g33k
Sat Mar 12, 2016 10:42 pm
Forum: Beginner Basics
Topic: IPSec site to site - can ping but no other traffic flows
Replies: 2
Views: 1999

Re: IPSec site to site - can ping but no other traffic flows

What if you try Site1: chain=forward action=accept src-address=192.168.253.0/24 dst-address=192.168.88.0/24 log=no log-prefix="" chain=forward action=accept src-address=192.168.88.0/24 dst-address=192.168.253.0/24 log=no log-prefix="" Site2: chain=forward action=accept src-addres...
by tr00g33k
Wed Mar 09, 2016 8:09 pm
Forum: General
Topic: DDoS attack on port 53
Replies: 1
Views: 2438

Re: DDoS attack on port 53

/ip firewall filter

add chain=input protocol=udp dst-port=53 in-interface=internet2 action=drop
And delete all the existing connections to port 53 from internet.
by tr00g33k
Tue Feb 23, 2016 11:51 am
Forum: General
Topic: ask about customers dns attack
Replies: 2
Views: 872

Re: ask about customers dns attack

You have to block DNS request on WAN side. Assume your WAN uplink is ether1
/ip firewall filter

add chain=input protocol=udp dst-port=53 in-interface=ether1 action=drop
by tr00g33k
Sat Feb 13, 2016 7:34 pm
Forum: Beginner Basics
Topic: ICMP QoS
Replies: 1
Views: 1561

ICMP QoS

Hello! I have a question about QoS in MikroTik, just for example I`am trying to do QoS for ICMP. My setup: Lan: 192.168.1.0/24 Host1: 192.168.1.10 Host2: 192.168.1.20 MikroTik config: add chain=prerouting src-address=192.168.1.0/24 protocol=icmp action=mark-connection passthrough=yes new-connection-...
by tr00g33k
Thu Jan 14, 2016 10:15 am
Forum: Beginner Basics
Topic: MikroTik PseudoBridge, BroadCast domain problem
Replies: 12
Views: 3985

Re: MikroTik PseudoBridge, BroadCast domain problem

ZeroByte thank you for all your help and pointing me in the right direction. The problem was that MikroTik really choose diffrent group and unicast cipher. And it was the same with other vendor than UniFi. I set static aes on AP (UniFi or any other vendor) and on MikroTik and now it works as it shou...
by tr00g33k
Tue Jan 12, 2016 10:03 pm
Forum: Beginner Basics
Topic: MikroTik PseudoBridge, BroadCast domain problem
Replies: 12
Views: 3985

Re: MikroTik PseudoBridge, BroadCast domain problem

Yes we tried another router. We started from strach many times. We tried with diffrent vendors than UniFi, it is the same, we tried inbox v60 or something similiar. We tried with about 30 routers hAP Lite, and some RB951 and diffrent OS versions and diffrent firmware versions. Right at the moment I`...
by tr00g33k
Tue Jan 12, 2016 6:41 pm
Forum: Beginner Basics
Topic: MikroTik PseudoBridge, BroadCast domain problem
Replies: 12
Views: 3985

Re: MikroTik PseudoBridge, BroadCast domain problem

I`am sorry for reaction, but we are really working hard on this for a few days, and we are trying to get help from all sides, and I`am writing the same thing over and over again. Offcourse I`am helpful for your help, dont get me wrong. Yes it is set to enabled, I have been doing some sniffing and it...
by tr00g33k
Mon Jan 11, 2016 9:41 pm
Forum: Beginner Basics
Topic: MikroTik PseudoBridge, BroadCast domain problem
Replies: 12
Views: 3985

Re: MikroTik PseudoBridge, BroadCast domain problem

Please read all my posts, the same with Station mode. :?
by tr00g33k
Sat Jan 09, 2016 11:48 am
Forum: Beginner Basics
Topic: MikroTik PseudoBridge, BroadCast domain problem
Replies: 12
Views: 3985

Re: MikroTik PseudoBridge, BroadCast domain problem

I`m the admin of the whole network, its not a problem to buy a one or two new mikrotik`s, but i have 9 UniFi AP`s and 30 hAP lite MikroTiks, that are connect through some cisco`s and CCR MikroTik that is routing all traffic to internet. Its like that because client behing mikrotik can have only ethe...
by tr00g33k
Fri Jan 08, 2016 3:14 pm
Forum: Beginner Basics
Topic: MikroTik PseudoBridge, BroadCast domain problem
Replies: 12
Views: 3985

Re: MikroTik PseudoBridge, BroadCast domain problem

Ok, what else do you suggest that i use, i tried station mode, the same result. This two modes, are the only modes that mikrotik support with other vendors, please any help how to solve this problem ? For now i manage MikroTik`s from other network, but if I`am on site of this network and have access...
by tr00g33k
Fri Jan 08, 2016 8:08 am
Forum: Beginner Basics
Topic: MikroTik PseudoBridge, BroadCast domain problem
Replies: 12
Views: 3985

MikroTik PseudoBridge, BroadCast domain problem

Hello evrybody, I need some help please. I have UniFi with dhcp and connected to my core network, and on this unify i have connected clients, laptops, mikrotiks as pseudobridge. And the problem is that this MikroTik clients are not pingable inside this broadcast domain 192.168.1.0/24 I can ping lapt...
by tr00g33k
Tue Dec 22, 2015 9:29 pm
Forum: Beginner Basics
Topic: MikroTik, two diffrent trunks on RouterOS
Replies: 2
Views: 1810

Re: MikroTik, two diffrent trunks on RouterOS

Thank you very much. It realy is logical, i just couldn figure out how to have two ports with taged vlan, i didnt tought that you "have to create vlan 10 twice". Thank you very much I will try this as soon as possible. I have another question is this possible with switch function on Router...
by tr00g33k
Mon Dec 21, 2015 3:48 pm
Forum: Beginner Basics
Topic: MikroTik, two diffrent trunks on RouterOS
Replies: 2
Views: 1810

MikroTik, two diffrent trunks on RouterOS

Hello evrybody i would need some help please I attach network diagram of what I would like to achive. On ether 1 I would like to bring vlans 30, 40 tagged and VLAN 20 untagged (native vlan) Then I would like to get vlan 20 untagged to ehter port 2, and VLAN 30 tagged And on ether 3 VLAN 40 untagged ...
by tr00g33k
Tue Dec 08, 2015 7:53 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639395

Winbox SSL Certificate

It would be really great if you could add feature, that certificate is needed on client to directly connect to winbox from anywhere. We have a lot of client, and sometimes its realy annoying to always setup vpn, or always have to coonect to office and then to clients. It would be much easies, if i w...
by tr00g33k
Mon Nov 30, 2015 4:23 pm
Forum: General
Topic: Multiple routers same certificate
Replies: 0
Views: 551

Multiple routers same certificate

Hello evryone i would need some help please! Scenario: I have 5 MikroTik routers with 5 diffrent WAN IPs, for Windows clients i would like to create one CA that i would export from one of the mikrotiks and import to client, and with this cert they could connect to evry SSTP MikroTik routers. So my i...
by tr00g33k
Tue May 05, 2015 3:39 pm
Forum: Beginner Basics
Topic: Client isolation CAPsMAN
Replies: 1
Views: 5816

Client isolation CAPsMAN

Hello!

I have a question how to do client isolation in capsman if i have lets say 3 caps with 3 ssids. If there is no capsman you have to untick default forward on wireless interface, but how to solve this with capsman ?

I just cant find how to do it. please help.
by tr00g33k
Sun Mar 29, 2015 4:18 pm
Forum: General
Topic: Please help me configure VLANs on mikrotik
Replies: 0
Views: 690

Please help me configure VLANs on mikrotik

Hello i have a problem with configuring VLANs on mikrotik, I have a WiFi network configured on routerboard 1100AHx2 And 3 APs RouterBoard RB951Ui-2HnD Capsman is connceted to firewall watchguard. And i would like to have configured: On evry AP I have networks: Vlan10 ==> Network 192.168.90.0/24 ==> ...