Community discussions

Search found 110 matches

by sam1275
Fri Apr 07, 2017 8:11 pm
Forum: General
Topic: Suggestion - Increase Bugfix releases life cycle
Replies: 0
Views: 220

Suggestion - Increase Bugfix releases life cycle

Hello.
I think the bugfix releases have too short life cycles, they do last longer than "current" ones, but it's not long enough as a professional level platform like Mikrotik.
Thanks.
by sam1275
Wed Feb 08, 2017 5:16 am
Forum: General
Topic: Disable management login on wireless?
Replies: 3
Views: 646

Re: Disable management login on wireless?

Use a firewall rule with the in interface match.
Thanks, but can the firewall only block certain user account?
by sam1275
Tue Feb 07, 2017 8:36 pm
Forum: General
Topic: Disable management login on wireless?
Replies: 3
Views: 646

Disable management login on wireless?

Hello. How can I prevent a system user from login by wireless(from winbox/ssh/anything)? I want the admin account can only be accessed by wired connection. I just thought a solution, I can assign different ip range to wired and wireless, and restrict the user group's ip address. Is there any problem...
by sam1275
Sun Feb 05, 2017 8:04 pm
Forum: General
Topic: WinBox security?
Replies: 13
Views: 9308

Re: WinBox security?

I just tried winbox on a rb2011 without security package installed, Winbox connects and shows the lock icon, what's happening?
This is a 8.5 years thread, Mikrotik, please do something to protect your customers, thanks.
by sam1275
Sun Feb 05, 2017 7:21 am
Forum: General
Topic: Mikrotik resource verify (Solved)
Replies: 8
Views: 891

Re: Mikrotik resource verify (Solved)

Security is essential, it have to be considered prior to any other functions. No exceptions, no excuse.
People here seems not care much about that, however that's not my business, I care, so I fight for it.
One don't even need to be here if he have as little brain as Jajeblonsky do.
by sam1275
Sat Feb 04, 2017 7:29 pm
Forum: General
Topic: Mikrotik resource verify (Solved)
Replies: 8
Views: 891

Re: Mikrotik resource verify (Solved)

I do this in hoping routeros getting better, a hardened security is not only for me, but for every true genius loving Routeros.
If you don't understand, you can keep silent; but if you insult me, I will not respect you any more.
by sam1275
Sat Feb 04, 2017 7:24 pm
Forum: General
Topic: Mikrotik resource verify (Solved)
Replies: 8
Views: 891

Re: Mikrotik resource verify (Solved)

Those hours would be better spent working on RouterOS and Winbox.
Damn paranoic morons :-E
Of course encryption and security is not for everyone, especially not for a stupid asshole like you.
by sam1275
Sat Feb 04, 2017 6:32 am
Forum: General
Topic: How can I distinguish different certificate in Winbox?
Replies: 0
Views: 258

How can I distinguish different certificate in Winbox?

Hello. There's a secure mode in Winbox, but how can I make sure the machine I'm connecting is not a hacker's setup? Think about SSH, we can check the certificate fingerprint to make sure the target is legit, but Winbox seems not care it, so if a hacker have ANY routerOS certificate(which should not ...
by sam1275
Fri Feb 03, 2017 3:39 pm
Forum: General
Topic: Mikrotik resource verify (Solved)
Replies: 8
Views: 891

Re: Mikrotik resource verify (Solved)

Update: Now the download site is all https supported, thank you mikrotik!
by sam1275
Wed Feb 01, 2017 10:11 pm
Forum: General
Topic: Mikrotik resource verify (Solved)
Replies: 8
Views: 891

Re: Mikrotik resource verify

Here's the update. I emailed to mikrotik support about this issue because it's a pretty important one that affect security, one of the support man kindly enabled https for the download page (I'm not publishing his name in regards of privacy). However the actual download link is still http only and ...
by sam1275
Wed Feb 01, 2017 5:31 pm
Forum: General
Topic: Mikrotik resource verify (Solved)
Replies: 8
Views: 891

Re: Mikrotik resource verify

Here's the update. I emailed to mikrotik support about this issue because it's a pretty important one that affect security, one of the support man kindly enabled https for the download page (I'm not publishing his name in regards of privacy). However the actual download link is still http only and t...
by sam1275
Fri Jan 27, 2017 9:58 pm
Forum: General
Topic: Cannot open some sites
Replies: 4
Views: 701

Re: Cannot open some sites

Did you try clearing DNS cache?
by sam1275
Fri Jan 27, 2017 8:35 pm
Forum: General
Topic: Mikrotik resource verify (Solved)
Replies: 8
Views: 891

Mikrotik resource verify (Solved)

Hello.
i just realized the Mikrotik download site "http://www.mikrotik.com/download" is http only, and I can't find anywhere to verify the hash/signature securely, so how can I make sure the resources I downloaded are legit?
Thanks.
by sam1275
Thu Jan 26, 2017 7:18 am
Forum: General
Topic: How to access internal files of RouterOS?
Replies: 5
Views: 1207

Re: How to access internal files of RouterOS?

It's not meant to be possible from withing RouterOS itself, unless you "hack" you router in some way.
What do you need this for?
Thank you. I think if I can access those files, then I can change some settings not available without it.
by sam1275
Wed Jan 25, 2017 8:41 pm
Forum: General
Topic: How to access internal files of RouterOS?
Replies: 5
Views: 1207

How to access internal files of RouterOS?

Is it possible to access the system files on routeros? The "file" function don't show them.
by sam1275
Fri Jan 20, 2017 9:17 am
Forum: General
Topic: New routerboot ot fix the slow LED on RB2011
Replies: 0
Views: 520

New routerboot ot fix the slow LED on RB2011

Hello.
I have a RB2011UiAS which LED flashes very slow, and there's no difference between 1kbps or 1gbps, it just flash the same speed and slowly.
Also there's no new routerboot for a long time, when will the next version release?
Thanks.
by sam1275
Thu Jan 19, 2017 3:25 pm
Forum: General
Topic: Winbox terminal use telnet?
Replies: 4
Views: 1837

Re: Winbox terminal use telnet?

Thank you Normis and everyone!
by sam1275
Wed Jan 18, 2017 11:51 pm
Forum: General
Topic: Winbox terminal use telnet?
Replies: 4
Views: 1837

Winbox terminal use telnet?

Hello.
When I open a terminal in Winbox, the "active user" will show I opened another login through telnet. So does that mean it opened a unencrypted connection even if I checked "secure mode"?
I saw this long time ago but didn't think much until today, can any one explain?
Thanks.
by sam1275
Mon Jan 16, 2017 3:31 pm
Forum: General
Topic: Security vulnerability with mAP Lite
Replies: 5
Views: 870

Re: Security vulnerability with mAP Lite

I'm glad my mikrotik comes with Wlan disabled by default. OP is right, default wireless enabled with management access is dangerous, no matter how small the window is, the racing condition is a vulnerability. I always hate consumer routers and some 3rd party firmware have no or simple password with ...
by sam1275
Mon Jan 16, 2017 3:00 pm
Forum: General
Topic: Loopguard
Replies: 35
Views: 26232

Re: Loopguard

This is already implied in 6.37.3
by sam1275
Mon Jan 16, 2017 5:05 am
Forum: General
Topic: How to remove all UPNP NAT rule using script?
Replies: 2
Views: 646

Re: How to remove all UPNP NAT rule using script?

Put this in your schedule: /ip firewall nat remove [find dynamic] Thank you very much, It works! But there's another problem, even if I removed the NAT rules, those UPNP rules still shows in a UPNP client such as portmapper, and I cannot find anywhere to view/delete it by winbox or terminal, I can ...
by sam1275
Sun Jan 15, 2017 6:24 pm
Forum: General
Topic: How to remove all UPNP NAT rule using script?
Replies: 2
Views: 646

How to remove all UPNP NAT rule using script?

Hello. I reported the issues about UPNP: http://forum.mikrotik.com/viewtopic.php?f=1&t=116854&p=577648 I cannot expect Mikrotik to fix them any soon, so I want to manually solve the second problem. It seems to be difficult to delete a rule based on creation time, but at least I want to delete all ru...
by sam1275
Sat Jan 14, 2017 5:41 am
Forum: General
Topic: Feature/Bugfix required: UPNP
Replies: 1
Views: 767

Feature/Bugfix required: UPNP

Hello, there's a few problems with Mikrotik UPNP: 1. The UPNP rules not working after WAN IP changed: http://forum.mikrotik.com/viewtopic.php?f=2&t=110359&p=555301 The UPNP rules are bounds to WAN IP only by default, not the WAN interface. I found a solution in the post, but that need manual setup, ...
by sam1275
Mon Jan 02, 2017 3:35 am
Forum: General
Topic: How to export without line breaker?
Replies: 1
Views: 355

How to export without line breaker?

Hello, I noticed in the export file there are many "\" symbols which seems doing nothing, just break the long line to multiple short ones. But I don't want it, is it possible to force export without "\" ? Thank you.
by sam1275
Mon Jan 02, 2017 3:29 am
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (Solved thanks) Mikrotik's DNS not working with DNScrypt

After assign multiple IP to my server and not using the NAT method anymore, it's fully working now. The router also can resolve DNS.
by sam1275
Sun Jan 01, 2017 11:21 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

Thank you so much Sob.
It confused the hell out of me when I see 17 while only 2 listing....
I think I may not use this NAT method and just assign several IPs to the DNS server, that will solve the problem.
by sam1275
Sun Jan 01, 2017 10:40 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

Can you ping the dns servers?

Sent from my Nexus 5 using Tapatalk
Of course not, they are fake addresses.
However if you mean the real address 192.168.88.5, yes I can.
by sam1275
Sun Jan 01, 2017 9:18 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

Could anyone explain this picture in my previous post?
Image
It shows 17 caches in use but only 2 in the list, I just checked and it's still like that right now... Why?
by sam1275
Sun Jan 01, 2017 9:15 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

I tried ping from ssh, yes you guys are right, it not work now...
Image
by sam1275
Thu Dec 29, 2016 6:18 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

Yes, itself can resolve any host, ... But how? Your previous thread was about making fake addresses and redirecting DNS traffic going to them to another host and non-standard ports. It can work fine when other devices try to access those fake addresses. But when you give same fake DNS resolvers to ...
by sam1275
Wed Dec 28, 2016 8:19 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

Try to use src-nat with dst-nat to guarantee DNS answer passed through the router and then de-nated rightly.
Could you give me a sample script please? Thank you.
by sam1275
Wed Dec 28, 2016 8:18 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

DNS cache will hapily cache DNS cahce replies, but you have to allow larger packets (I think that default was already changed to 4096 packet size) That usually fixes dnsec issues.
Thanks, but it still not work when it is 4096.
by sam1275
Wed Dec 28, 2016 8:17 pm
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

If it's the same router that does dstnat for those fake addresses, then it can't work with them, because output packets from router won't go to dstnat chain. I'm wondering where it got address for "mikrotik.com" from... I just tried "check update" in packages and it says "cannot resolve host", so i...
by sam1275
Wed Dec 28, 2016 6:10 am
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

Re: (New problem) Mikrotik's DNS not working with DNScrypt

If it's the same router that does dstnat for those fake addresses, then it can't work with them, because output packets from router won't go to dstnat chain. I'm wondering where it got address for "mikrotik.com" from... Thank you, so there's no workaround available? Yes, itself can resolve any host...
by sam1275
Wed Dec 28, 2016 4:01 am
Forum: General
Topic: (Solved thanks) Mikrotik's DNS not working with DNScrypt
Replies: 19
Views: 3489

(Solved thanks) Mikrotik's DNS not working with DNScrypt

Hello people. Days ago I setup a DNScrypt server in my network: http://forum.mikrotik.com/viewtopic.php?f=2&t=115965 It works, but the router's built-in DNS service refuse to work with it, please see pictures: https://s29.postimg.org/uezi5k3yv/image.png https://s29.postimg.org/u3i1ssniv/image.png ht...
by sam1275
Thu Dec 22, 2016 10:15 am
Forum: General
Topic: (Solved)Use Mikrotik with a DNSCrypt server in LAN problems
Replies: 7
Views: 3527

Re: Use Mikrotik with a DNSCrypt server in LAN problems

Okay I test it my self, very successful, appreciate your help!
by sam1275
Thu Dec 22, 2016 9:16 am
Forum: General
Topic: (Solved)Use Mikrotik with a DNSCrypt server in LAN problems
Replies: 7
Views: 3527

Re: Use Mikrotik with a DNSCrypt server in LAN problems

So the final script will be this: /ip firewall nat add chain=dstnat dst-address=192.168.10.50 protocol=udp dst-port=53 action=dst-nat to-address=192.168.88.5 to-ports=49100 add chain=dstnat dst-address=192.168.10.51 protocol=udp dst-port=53 action=dst-nat to-address=192.168.88.5 to-ports=49101 add c...
by sam1275
Thu Dec 22, 2016 8:50 am
Forum: General
Topic: (Solved)Use Mikrotik with a DNSCrypt server in LAN problems
Replies: 7
Views: 3527

Re: Use Mikrotik with a DNSCrypt server in LAN problems

If you want method #1, this should do the trick: /ip firewall nat add chain=dstnat dst-address=192.168.10.50 protocol=udp dst-port=53 action=dst-nat \ to-address=192.168.88.5 to-ports=49100 add chain=dstnat dst-address=192.168.10.51 protocol=udp dst-port=53 action=dst-nat \ to-address=192.168.88.5 ...
by sam1275
Wed Dec 21, 2016 7:41 pm
Forum: General
Topic: (Solved)Use Mikrotik with a DNSCrypt server in LAN problems
Replies: 7
Views: 3527

Re: Use Mikrotik with a DNSCrypt server in LAN problems

I'm probably missing something, but instead of all this, don't you want to just give 192.168.88.5 (DNSCrypt server) as the only DNS resolver to clients? Thank you, problem is the I have many DNScrypt resolver in use for fail over, and in the current version of DNScrypt proxy software, each resolver...
by sam1275
Wed Dec 21, 2016 4:42 pm
Forum: General
Topic: (Solved)Use Mikrotik with a DNSCrypt server in LAN problems
Replies: 7
Views: 3527

Re: Use Mikrotik with a DNSCrypt server in LAN problems

I just tried Hairpin NAT: http://wiki.mikrotik.com/wiki/Hairpin_NAT /ip firewall nat add chain=dstnat dst-address=192.168.10.50 protocol=udp dst-port=53 \ action=dst-nat to-address=192.168.88.5 add chain=srcnat out-interface=ether8-gateway action=masquerade /ip firewall nat add chain=srcnat src-addr...
by sam1275
Wed Dec 21, 2016 4:05 pm
Forum: General
Topic: (Solved)Use Mikrotik with a DNSCrypt server in LAN problems
Replies: 7
Views: 3527

(Solved)Use Mikrotik with a DNSCrypt server in LAN problems

Hello. Since Mikrotik have no plan to add a DNScrypt function, I just setup one myself, now the DNS proxy server run several instance at the same IP same time, but on different port, but here's some problems: 1. Neither Mikrotik nor Windows support DNS not on port 53. 2. So I try a workaround: set t...
by sam1275
Fri Dec 02, 2016 9:33 pm
Forum: General
Topic: Questions about Routerboot
Replies: 0
Views: 279

Questions about Routerboot

Hello. My router is RB2011UiAS, so no serial port available. 1. How can I know which bootloader is currently in use(main or backup)? 2. Can I downgrade the bootloader, or overwrite it with the same version? 3. If I'm currently using the backup bootloader, and I issue a upgrade command, will the upgr...
by sam1275
Wed Nov 09, 2016 11:36 am
Forum: General
Topic: Is the auto-update in RouterOS encrypted?
Replies: 2
Views: 365

Re: Is the aoto-update in RouterOS encrypted?

Update packages are verified by the system for valid signature before installation.
Thank you, What's signature algorithm does it use(MD5/SHA-?)? Also will the routerboard firmware(routerboot) update also verify before install?
by sam1275
Wed Nov 09, 2016 12:23 am
Forum: General
Topic: Is the auto-update in RouterOS encrypted?
Replies: 2
Views: 365

Is the auto-update in RouterOS encrypted?

Hello.
I want to know whether the auto update (OS and Routerboot) are using encrypted connection or not?
My internet environment is not good and the ISP/government are constantly hijacking DNS and websites, so I'm worrying of download malicious codes to my router by update it.
Thanks.
by sam1275
Tue Nov 01, 2016 5:10 pm
Forum: General
Topic: Metarouter RTC question
Replies: 0
Views: 299

Metarouter RTC question

Hello, will the metarouter's RTC auto sync with the host router? Thanks.
by sam1275
Mon Oct 31, 2016 7:11 pm
Forum: General
Topic: DNSsec/DNScrypt plan?
Replies: 5
Views: 2499

Re: DNSsec/DNScrypt plan?

Still no plan at all?
There's many other people/threads also require this feature.
I live in a bad country that the government/ISP always poison the DNS, I have to try other router/firmware to prevent this.
RouterOS is very good, but lack this feature is a big disappointing.
by sam1275
Fri Sep 02, 2016 4:11 pm
Forum: General
Topic: Problem with UPNP/portforwarding
Replies: 5
Views: 920

Re: Problem with UPNP/portforwarding

I find the solution myself! Just create a rule manually, all parameter as the same as the previous UPNP rule, except fill the "dst. address" as "!192.168.0.0/16", instead of the WAN address, it works! This solution is limited to the internal network has only one client device Nope, you define which...
by sam1275
Tue Jul 19, 2016 8:20 pm
Forum: General
Topic: Problem with UPNP/portforwarding
Replies: 5
Views: 920

Re: Problem with UPNP/portforwarding

I find the solution myself!
Just create a rule manually, all parameter as the same as the previous UPNP rule, except fill the "dst. address" as "!192.168.0.0/16", instead of the WAN address, it works!
by sam1275
Tue Jul 19, 2016 7:42 pm
Forum: General
Topic: Problem with UPNP/portforwarding
Replies: 5
Views: 920

Problem with UPNP/portforwarding

Hi everyone. I forwarded some ports through UPNP, and I want to make them not disappear when router reboot, but I find no "make static" button (just like DNS server lease can), then I try to reproduce the same rule manually so it will not mark as dynamic, but then I find a bigger problem: The create...
by sam1275
Wed Mar 30, 2016 1:52 pm
Forum: Announcements
Topic: v6.35rc [release candidate] is released, new wireless package!
Replies: 537
Views: 106690

Re: v6.35rc [release candidate] is released, new wireless package!

When will this version become release?
by sam1275
Thu Mar 24, 2016 10:37 am
Forum: General
Topic: DNSsec/DNScrypt plan?
Replies: 5
Views: 2499

Re: DNSsec/DNScrypt plan?

This is already in the openwrt, ddwrt, cisco IOS, juniper, tomato, pfsense.....and maybe more...
I love routeros very much and I just think this feature should exist, as it is more "basic" than those amazing features in routeros, and it really improve security by prevent many DNS attack.
by sam1275
Thu Mar 24, 2016 2:17 am
Forum: General
Topic: DNSsec/DNScrypt plan?
Replies: 5
Views: 2499

DNSsec/DNScrypt plan?

Hello.
Do anybody know when will DNSsec and/or DNScrypt feature add to RouterOs? Or at least any plan? I really want them!
Thanks.
by sam1275
Tue Jan 12, 2016 3:08 am
Forum: General
Topic: General porpose OS on routerboard?
Replies: 2
Views: 804

Re: General porpose OS on routerboard?

It isn't possible. Maximum you can get is use a capable virtual OS on CCR devices with tileGX architecture, when metaROUTER will be available (possibly in RouterOS v7).
Thank u.
by sam1275
Sun Jan 10, 2016 8:49 pm
Forum: General
Topic: General porpose OS on routerboard?
Replies: 2
Views: 804

General porpose OS on routerboard?

Hi everyone.
I've got a CCR1016 and I want to use it as a general purpose device, I found someone boot into Debian on a routerboard on google, but he's was not CCR, and he uses ethboot, I want to boot from nand, at least usb HDD, is it possible?
Thanks.
by sam1275
Thu Dec 17, 2015 3:40 am
Forum: General
Topic: Continuous traffic even idle?
Replies: 1
Views: 326

Continuous traffic even idle?

Hi. I noticed on the LCD that my router have 2kbps RX and 256-500~bps TX with WAN LED flashing regularly, even no clients are powered on, then I checked: No strange logs except some port flap Only pptp is enabled in firewall/ports No strange connection listed except winbox from my computer to router...
by sam1275
Fri Dec 11, 2015 4:22 pm
Forum: General
Topic: Bug in 6.32.3?
Replies: 0
Views: 487

Bug in 6.32.3?

Hi. I'm using 6.32.3 budfix, and I find something wrong: even if I set never store DHCP lease on disk, it seems still do, because all leases still exist after a reboot, and the timeout is continue the same before reboot. I'm sure some of the clients is not online so they are not new leases, and if I...
by sam1275
Fri Dec 11, 2015 12:47 pm
Forum: General
Topic: Memory showing in routerOS, question
Replies: 0
Views: 369

Memory showing in routerOS, question

Hi everyone.
I just want to know is the cached and buffered RAM calculated as used or free RAM in router OS?
OPENWRT have a dedicated text to show these memory, and tomato can be choose for how to show them, but what about ROS?
Thank you!
by sam1275
Mon Nov 23, 2015 11:22 am
Forum: RouterBOARD hardware
Topic: Routerboard Hardware wish list
Replies: 61
Views: 13057

Re: Routerboard Hardware wish list

Removable main storage would be great, at least should be added to CCR series, in fact I don't know why high-end CCRs have removable RAM, but fixed flashes, it is extremely difficult to replace them when fails, and flash do have a life limit.
by sam1275
Fri Nov 06, 2015 10:05 pm
Forum: RouterBOARD hardware
Topic: CCR have thermal protection or not?
Replies: 2
Views: 495

Re: CCR have thermal protection or not?

Thank you.
by sam1275
Fri Nov 06, 2015 11:33 am
Forum: RouterBOARD hardware
Topic: CCR have thermal protection or not?
Replies: 2
Views: 495

CCR have thermal protection or not?

Hello. I want to know what will happen if fans inside CCR fails, do those CPU have thermal protection to throttle or hang the system to prevent burn up?
by sam1275
Wed Oct 28, 2015 10:05 pm
Forum: General
Topic: Is it possible for ISP to access my MikroTik?
Replies: 8
Views: 1374

Re: Is it possible for ISP to access my MikroTik?

Hello. 1. You can look at the log to see if there really anyone got into your router. 2. If yes, you can also check history to see what he did to your router, it will be easier than check the log. ---If yes 3. Restore settings if you have backup. 4. Reset to default if you're really hacked, and don'...
by sam1275
Wed Oct 21, 2015 5:55 pm
Forum: General
Topic: Little update broke the OS
Replies: 4
Views: 513

Re: Little update broke the OS

Yes you can use that USB adapter to reinstall the DOM. Download netinstall http://download2.mikrotik.com/routeros/6.30.4/netinstall-6.30.4.zip to a windows PC or VBOX image. Do the same with ROS 6.30.4 x86 ( http://download2.mikrotik.com/routeros/6.30.4/routeros-x86-6.30.4.npk Start netinstall, loo...
by sam1275
Wed Oct 21, 2015 5:07 pm
Forum: General
Topic: Little update broke the OS
Replies: 4
Views: 513

Re: Little update broke the OS

You can try netinstalling it if it has removable storage. I'd stay on bugfix version, 6.30.4 Cannot you get to its BIOS via its console? If its storage isn't removable you could try netinstalling it (bootp)... Hi. Yes it have a removable DOM with 44pin IDE, I installed the OS by connect it to a USB...
by sam1275
Wed Oct 21, 2015 4:50 pm
Forum: General
Topic: Little update broke the OS
Replies: 4
Views: 513

Little update broke the OS

Ok it's a sad story. I got a Firebox II because I like trying old hardwares, it will not work well even on m0n0wall, but when I try routerOS it really make me shock, high throughput and tons of features with little hardware use. So I buy a L4 license just an hour ago, even the timer seems stuck at 1...
by sam1275
Wed Oct 21, 2015 4:36 pm
Forum: General
Topic: DNScrypt / DNSsec
Replies: 2
Views: 1981

DNScrypt / DNSsec

Hope one of these features add in v7, to improve DNS security.
by sam1275
Mon Aug 10, 2015 8:33 pm
Forum: General
Topic: Tilera vs. intel vs. mips-be
Replies: 10
Views: 3467

Re: Tilera vs. intel vs. mips-be

Hi, both intel and AMD are x86 constructions, but they still have different IPC, now you want to compare different constructions? They of course have diff in speed - not only IPC, but they also run different instructions set. Tilera is ARM based, in my mind, x86 > PPC > ARM > MIPS, but I'm not sure ...
by sam1275
Mon Aug 03, 2015 6:36 pm
Forum: RouterBOARD hardware
Topic: Old RB532 repair attempt, need help.
Replies: 0
Views: 338

Old RB532 repair attempt, need help.

Hi everyone, I bought a RB532 from ebay(I like old hardware and I like Mikrotik, so I buy this basically to try and have fun).Seller says it's brand new. When I got it and power it on, I found it seems doesn't boot, the 2 LED (blue and orange) on the bottom of the six lit all the time, the WAN port ...
by sam1275
Sun Aug 02, 2015 2:38 pm
Forum: General
Topic: PPPoE Bug?-"terminating" Forever
Replies: 2
Views: 1298

Re: PPPoE Bug?-"terminating" Forever

Turning off 'Dial on demand' will cause it to always dial, but I don't think it gets around this issue? Wonder if this is the root cause of my issue with MLPPP not recovering from any of the lines going down.. I am using the same model, and I believe the same firmware version. I'm using my router w...
by sam1275
Mon Jul 20, 2015 9:32 am
Forum: Wireless Networking
Topic: 802.11b client cannot connect to RB1011UiAS
Replies: 0
Views: 326

802.11b client cannot connect to RB1011UiAS

Hi everyone. My router is RB1011UiAS-2HnD-IN, but I found I have problems connect to the wireless with 11b devices, my HTC XV6700 can see the AP but cannot connect anyway, even if I allow the TKIP as someone said in another forum; my Palm TX cannot even see my hot spot... How can I solve this proble...
by sam1275
Sat Jul 18, 2015 6:47 pm
Forum: General
Topic: Use Mikrotik as VPN relay?
Replies: 0
Views: 334

Use Mikrotik as VPN relay?

Hi everyone. I have a VPN account with several servers available, now I want to archive these with my routeros: 1. Let the router connect as a client to one of the VPN server. 2. Router act as a VPN server and relay the VPN service, allow several local clients use the same VPN service at the same ti...
by sam1275
Tue Jun 30, 2015 5:45 pm
Forum: Beginner Basics
Topic: Why Mikrotik needs shut down "properly"?
Replies: 10
Views: 5301

Re: Why Mikrotik needs shut down "properly"?

ROS is Linux. Linux is an operating system. Is "powering-off" standard method for closing OS ? Shutdown is much, much better. I know that ROS mostly runs from memory so "power-off" is not so destructive but sooner or later it could be a disaster. Thank you. In fact I never unplug the power without ...
by sam1275
Tue Jun 30, 2015 1:25 pm
Forum: Beginner Basics
Topic: Why Mikrotik needs shut down "properly"?
Replies: 10
Views: 5301

Re: Why Mikrotik needs shut down "properly"?

Thank you very much everyone!
by sam1275
Mon Jun 29, 2015 9:23 pm
Forum: Beginner Basics
Topic: Why Mikrotik needs shut down "properly"?
Replies: 10
Views: 5301

Why Mikrotik needs shut down "properly"?

Hi everyone. It maybe a stupid question, but I want to know the key reason of why RouterOS needs to shutdown by software first while other routers not, even routers with OPENWRT or other powerful firmware, we just unplug the power if we what to switch them off... So what made RouterOS different at t...
by sam1275
Tue Jun 23, 2015 9:29 am
Forum: Beginner Basics
Topic: Is that possible to use QOS without manual speed?
Replies: 5
Views: 1036

Re: Is that possible to use QOS without manual speed?

I don't need to divide evenly, I just don't want one or more "bad" client to eat up all bandwidth Right. That's why I used the word "fairly" instead of "equally" ;) that router have a auto-QOS which test the upload speed every certain period, and thus don't need to manually set it. Well, you could ...
by sam1275
Sun Jun 21, 2015 8:24 pm
Forum: Beginner Basics
Topic: Is that possible to use QOS without manual speed?
Replies: 5
Views: 1036

Re: Is that possible to use QOS without manual speed?

If you set your parent queue to be use the hardware negotiated rate (100Mbps or 1Gbps) as the max-limit, you're in essence doing exactly that. But if your ISP is not actually able to give those speeds, you're not going to get any good results. It's not theoretically possible for bandwidth to be div...
by sam1275
Sun Jun 21, 2015 5:41 pm
Forum: Beginner Basics
Topic: Is that possible to use QOS without manual speed?
Replies: 5
Views: 1036

Is that possible to use QOS without manual speed?

Hi everyone.
I want to implement QOS function in my router, but all solutions I found need to set a fixed speed in the script, is there any script to archiving QOS without a fixed bandwidth?
Thanks
by sam1275
Sun Jun 21, 2015 2:40 pm
Forum: General
Topic: Active wired clients?
Replies: 9
Views: 999

Re: Active wired clients?

I dont think that last seen is reliable value. At least not for me: lastseen.jpg The 50thousand days is definitely not correct value.... WOW, that's a bug for you.... My last seen time is much more reliable, but it depends on client type, windows 7 clients will renew every several minutes, but XP b...
by sam1275
Sun Jun 21, 2015 10:25 am
Forum: General
Topic: Active wired clients?
Replies: 9
Views: 999

Re:

I have provided many options to you. Try them.
Thank you. I'm using DHCP last seen time to see which client active at what when...
It's not that real-time, but it's the best I can find to run with read a only access.
by sam1275
Sun Jun 21, 2015 8:57 am
Forum: General
Topic: Active wired clients?
Replies: 9
Views: 999

Re: Active wired clients?

what is the problem? you can use the torch to see what traffic goes where... You can also use queues by clients address. Or you can use some NMS, like mikrotik Dude and check the running clients by ping. You can use netwatch to check the clients by ping also. You can shorten the lease time of dhcp ...
by sam1275
Sat Jun 20, 2015 9:57 pm
Forum: General
Topic: Active wired clients?
Replies: 9
Views: 999

Re:

See the torch.
Thank you, but that tool seems more like firewall / connections, not clients, and it need to "run" and admin access.
by sam1275
Sat Jun 20, 2015 8:56 pm
Forum: General
Topic: Active wired clients?
Replies: 9
Views: 999

Active wired clients?

Hello everyone. There are several computers connected to my router by L2 switch, I want to see who is online. I cannot just look at the LED because they will always stay on because the switch is on, and several clients may on the same interface... DHCP server / leases helps a little but it's not rea...
by sam1275
Wed Jun 17, 2015 9:41 am
Forum: General
Topic: Powerful firewall / ADblocker?
Replies: 8
Views: 2159

Re: Powerful firewall / ADblocker?

You should ask the government to also block the ads then ;) But seriously, adblocker list will not work the same way in router as in the browser. If you block these URLs in the router, the browser will try to load these pages, you will have longer waiting time, and a lot of 404 or 403 errors in the...
by sam1275
Wed Jun 17, 2015 8:27 am
Forum: General
Topic: Powerful firewall / ADblocker?
Replies: 8
Views: 2159

Re: Powerful firewall / ADblocker?

So the opendns already blocked the ads? I'm already using it... Thanks. It depends on how you configure it. It will never act as a real adblocker, I think, but at least it can block malicious ads. Thank you, in fact I'm using Adblocker's list in my main computer (by IE's tracking protection), and f...
by sam1275
Tue Jun 16, 2015 2:25 pm
Forum: General
Topic: Powerful firewall / ADblocker?
Replies: 8
Views: 2159

Re: Powerful firewall / ADblocker?

That list looks way too broad, installing that in a webfilter will probably break legitimate sites that happen to have one of those patterns in a URL somewhere. When you want to block at host level instead of URL pattern, I would advise to check filtered DNS services like OpenDNS. You can just set ...
by sam1275
Tue Jun 16, 2015 11:39 am
Forum: General
Topic: Powerful firewall / ADblocker?
Replies: 8
Views: 2159

Re: Powerful firewall / ADblocker?

you could only use this in conjunction with the transparent webproxy functionality, somehow read the list, and update the proxy access list in RouterOS. I don't think this is a good idea, such large list would overload the device, maybe if you have really powerful hardware Thank you, are there any ...
by sam1275
Tue Jun 16, 2015 11:03 am
Forum: General
Topic: Powerful firewall / ADblocker?
Replies: 8
Views: 2159

Powerful firewall / ADblocker?

Hi everyone. I just got my routerboard finally works well, now I want to use it to do more powerful and automated firewall, and even ADs block. I known some common methods to easily do this, such as host file or url blocking, but they are too limited, I mean, they cannot block many ADs and they are ...
by sam1275
Tue Jun 16, 2015 9:04 am
Forum: General
Topic: Auto terminate TCP connections after client disconnects.
Replies: 2
Views: 454

Re: Auto terminate TCP connections after client disconnects.

You can change that under IP>Firewall>Connections Thank you, do you mean shorten the TCP time out? but I don't want them to time out when using, I want the router to delete idle connections, for example, a client disconnected from the router 10 minutes ago, then delete all connection with that clie...
by sam1275
Mon Jun 15, 2015 1:02 pm
Forum: General
Topic: Auto terminate TCP connections after client disconnects.
Replies: 2
Views: 454

Auto terminate TCP connections after client disconnects.

Hi everyone, I found I have over 1000 connections in the firewall connection list, and most of them are generated by clients already disconnected from my router, but they are still waiting the 24h time out.
Is there any way to remove them automatically after clients disconnected?
Thank you.
by sam1275
Fri Jun 12, 2015 1:31 pm
Forum: General
Topic: Known issues and bugs - a list
Replies: 283
Views: 111527

Re: Known issues and bugs - a list

Issue: PPPoE Bug?-"terminating" Forever Description: PPPoE dial-out won't reconnect automatically after failing when "dial on demand" is enabled. Versions affected: Metal 2SHPn with OS 6.28, RB2011UiAS-2HnD-IN with OS 6.29.1 How to reproduce: First factory reset to default, then setup to "Home AP" m...
by sam1275
Fri Jun 12, 2015 1:24 pm
Forum: General
Topic: How to force non compact export .rsc file?
Replies: 2
Views: 382

Re: How to force non compact export .rsc file?

/export verbose 
Thank you very much!
by sam1275
Fri Jun 12, 2015 1:14 pm
Forum: General
Topic: How to force non compact export .rsc file?
Replies: 2
Views: 382

How to force non compact export .rsc file?

Hi everyone.
I just found this: http://forum.mikrotik.com/viewtopic.php ... 49#p417649
Now I want to know how to force export everything, not the new default compact mode?
Thank you.
by sam1275
Fri Jun 12, 2015 12:23 pm
Forum: Beginner Basics
Topic: What's the difference between .backup and .rsc file?
Replies: 3
Views: 4096

Re: What's the difference between .backup and .rsc file?

Thank you everyone, I just read my rsc file and find it doesn't content any user password, but it do show WIFI and PPP passwords, what else I need to configure manually if I recovered by rsc file from default resetting?
by sam1275
Fri Jun 12, 2015 11:04 am
Forum: Beginner Basics
Topic: What's the difference between .backup and .rsc file?
Replies: 3
Views: 4096

What's the difference between .backup and .rsc file?

Hi everyone, there seems 2 different method to backup/restore RouterOS configuration: use "file" to generate a .backup file, or "/export file=12345.rsc" in console to generate a .rsc file. I found .backup file is bigger and contains more information, for example, it will become bigger even if I just...
by sam1275
Thu Jun 11, 2015 3:53 pm
Forum: General
Topic: PPPoE Bug?-"terminating" Forever
Replies: 2
Views: 1298

PPPoE Bug?-"terminating" Forever

Hi all! I found a problem when using routerOS in home environment, here's how to reproduce it: First factory reset to default, then setup to "Home AP" mode in quick setup, choose PPPoE for WAN, then setup a few WLAN and admin password. Now go to the PPP and open your PPPoE interface, in "dial out" t...
by sam1275
Thu Jun 11, 2015 3:30 pm
Forum: General
Topic: Unusable: 6.29.1 has similar memory leak to 6.28
Replies: 5
Views: 2302

Re: Unusable: 6.29.1 has similar memory leak to 6.28

Hi.
I'm using RB2011UiAS-2HnD with 6.29.1, no problem at all...
by sam1275
Wed Jun 10, 2015 5:32 pm
Forum: RouterBOARD hardware
Topic: How to disassemble RB2011UiAS-2HnD-IN?
Replies: 4
Views: 1243

Re: How to disassemble RB2011UiAS-2HnD-IN?

Success!!!!!
Thank you very much...
by sam1275
Wed Jun 10, 2015 2:07 pm
Forum: RouterBOARD hardware
Topic: How to disassemble RB2011UiAS-2HnD-IN?
Replies: 4
Views: 1243

Re: How to disassemble RB2011UiAS-2HnD-IN?

He just block the Lens for a few seconds, then already opened...
by sam1275
Wed Jun 10, 2015 1:16 pm
Forum: RouterBOARD hardware
Topic: How to disassemble RB2011UiAS-2HnD-IN?
Replies: 4
Views: 1243

How to disassemble RB2011UiAS-2HnD-IN?

I took off 2 screws and cannot go any further... Please help.
by sam1275
Tue Jun 09, 2015 5:07 pm
Forum: Virtualization
Topic: Virtualization for non-routing purpose?
Replies: 5
Views: 1666

Re:

Yes. There are openwrt metarouter packages for example.
Thank you, but Openwrt is also a router system, I want to know is it possible to run a more general-propose OS like debian...
by sam1275
Tue Jun 09, 2015 12:32 pm
Forum: Virtualization
Topic: Virtualization for non-routing purpose?
Replies: 5
Views: 1666

Virtualization for non-routing purpose?

Hi everyone.
Is it possible to virtualize a general-propose OS inside RouterOS? Such as running BOINC...
Thanks.
by sam1275
Thu Jun 04, 2015 6:20 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx2-LM ?
Replies: 2
Views: 586

Re: RB1100AHx2-LM ?

is the only difference is the 512MB ram instead of 2GB? Any other difference?
No.
use "at least DDR2 667" RAM to replace, but the picture showing bootloader shows it can work as high as DDR2 533, why is that?
Who cares? Why use something slower?
Thank you, I'm just curious.
by sam1275
Thu Jun 04, 2015 6:18 pm
Forum: RouterBOARD hardware
Topic: Overheat Protection?
Replies: 0
Views: 407

Overheat Protection?

Hi forum.
Is there a protection if a router board overheat? Will it slow down the CPU or suspend the system, or just continue full speed running? Thanks.
Sam
by sam1275
Wed Jun 03, 2015 10:41 am
Forum: RouterBOARD hardware
Topic: RB1100AHx2-LM ?
Replies: 2
Views: 586

RB1100AHx2-LM ?

Hi everyone, comparing the RB1100AHx2-LM to standard version, is the only difference is the 512MB ram instead of 2GB? Any other difference? Also, in the manual it says one should use "at least DDR2 667" RAM to replace, but the picture showing bootloader shows it can work as high as DDR2 533, why is ...
by sam1275
Fri May 22, 2015 4:09 pm
Forum: Beginner Basics
Topic: Routing through one interface only?
Replies: 7
Views: 637

Re: Routing through one interface only?

Yes, in that case you do this with vlans.
Thank you.
by sam1275
Fri May 22, 2015 4:08 pm
Forum: RouterBOARD hardware
Topic: A few questions about Metal 2SHPn
Replies: 0
Views: 330

A few questions about Metal 2SHPn

Hi everyone, I have a few questions about my Metal 2SHPn. 1. Are there any low gain antenna for it? I want one made by Mikrotik but I cannot find any. 2. I have powered it on a few minutes without an antenna, but it works OK now, I've heard this will damage the RF chip, what's the truth? 3. I want t...
by sam1275
Fri May 22, 2015 12:42 pm
Forum: Beginner Basics
Topic: Routing through one interface only?
Replies: 7
Views: 637

Re: Routing through one interface only?

If I understood correctly you want one wireless interface to be station and AP at the same time? That is not possible. wireless interface can be eiter AP or station but not both. Thank you, but sorry I mean I want one wireless interface to be station and client at the same time, it receives from an...
by sam1275
Thu May 21, 2015 9:25 pm
Forum: Beginner Basics
Topic: Routing through one interface only?
Replies: 7
Views: 637

Re: Routing through one interface only?

I want to dial PPPOE through WLAN1 to internet while use WLAN1 as the router LAN port at the same time.
by sam1275
Thu May 21, 2015 6:10 pm
Forum: Beginner Basics
Topic: Routing through one interface only?
Replies: 7
Views: 637

Re: Routing through one interface only?

What do you want to accomplish exactly? A wireless link between both APs?
Thank you, I want it to dial PPPOE to ISP using WLAN1 instead of ETHER1 while remain the wireless router function on WLAN1.
by sam1275
Thu May 21, 2015 3:19 pm
Forum: Beginner Basics
Topic: Routing through one interface only?
Replies: 7
Views: 637

Routing through one interface only?

Hi everyone. I'm using Metal 2Shpn now, it basically running in home AP mode, so the WAN is ether1 with PPPoE to my ISP, the LAN is wlan1. Now I want to change PPPOE form wired to wireless connection, I'll setup another pure AP with wired to modem, to be more clear: Now: Internet---modem---Mikrotik ...