Community discussions

MikroTik App

Search found 250 matches

by onlineuser
Mon Feb 26, 2024 2:02 pm
Forum: General
Topic: migration from RB2011UiAS-2HnD to L009UiGS-2HaxD-IN
Replies: 7
Views: 1247

Re: migration from RB2011UiAS-2HnD to L009UiGS-2HaxD-IN

If you would like more assistance with piece by pice migration, post the old config and we can try to help Why is there no tool available for migrating configuration from older to newer Mikrotik devices? I had a lot of firewall rules inside my configuration. I solved it by replacing the right inter...
by onlineuser
Sun Jan 28, 2024 12:56 pm
Forum: General
Topic: migration from RB2011UiAS-2HnD to L009UiGS-2HaxD-IN
Replies: 7
Views: 1247

migration from RB2011UiAS-2HnD to L009UiGS-2HaxD-IN

Hello,

is it possible to migrate all the settings 1:1 from a RB2011UiAS-2HnD to a L009UiGS-2HaxD-IN?

Thanks.
by onlineuser
Wed Jan 24, 2024 7:29 pm
Forum: General
Topic: OVPN reconnect delay
Replies: 3
Views: 892

Re: OVPN reconnect delay

*push*
by onlineuser
Wed Jan 24, 2024 7:27 pm
Forum: General
Topic: socks5 proxy dns problem - ROS 7.7
Replies: 9
Views: 2089

Re: socks5 proxy dns problem - ROS 7.7

Any updates for this issue?

I tried it on ROS 7.13.2 - same problem. :-(
by onlineuser
Mon Jan 16, 2023 7:04 pm
Forum: General
Topic: socks5 proxy dns problem - ROS 7.7
Replies: 9
Views: 2089

Re: socks5 proxy dns problem - ROS 7.7

Ok, but this could be filtered with a regex.
Other socks proxies also do this.

The nslookup command also does this - nslookup google.de delivers the IP address, nslookup 127.127.127.127 delivers the hostname.
by onlineuser
Mon Jan 16, 2023 12:44 pm
Forum: General
Topic: socks5 proxy dns problem - ROS 7.7
Replies: 9
Views: 2089

Re: socks5 proxy dns problem - ROS 7.7

Ok yes, I could resolve it by resolving the hostnames locally or with other tools but RFC shows that remote resolving through the proxy also should work.

With the socks proxy "srelay" for example it works fine.
by onlineuser
Sun Jan 15, 2023 11:22 pm
Forum: General
Topic: socks5 proxy dns problem - ROS 7.7
Replies: 9
Views: 2089

Re: socks5 proxy dns problem - ROS 7.7

What do you want to say with this? Locally resolving of domains with third party tool? This is not necessary. Other socks proxies do the same like mikrotik socks - remote resolving works fine for vaid domains (for example google.com). If I want to open an webserver on for example 123.123.123.123, no...
by onlineuser
Sun Jan 15, 2023 10:29 am
Forum: General
Topic: socks5 proxy dns problem - ROS 7.7
Replies: 9
Views: 2089

socks5 proxy dns problem - ROS 7.7

Hi, I use the socks5 proxy on mikrotik with remote dns resolving. This works fine for resolving hostnames (google.de for example) but for inputs like 123.123.123.123 it does not work. Normally for such URL the socks5 proxy needs not to resolv the IP address but it looks like that this will be tried....
by onlineuser
Wed Jan 11, 2023 4:38 pm
Forum: General
Topic: OVPN between 7.6 and 6.48.6
Replies: 0
Views: 282

OVPN between 7.6 and 6.48.6

Hello, I let to connect some clients (6.48.6) to my OVPN server (also running on 6.48.6). Now I added a hAP ac3 with ROS 7.6. On this device it only works when I deactivate the "Verify Server Certificate". If this is also activated on ROS 7.6, I get an TLS error while establishing the OVPN...
by onlineuser
Tue Nov 22, 2022 8:59 am
Forum: General
Topic: OVPN reconnect delay
Replies: 3
Views: 892

Re: OVPN reconnect delay

noone?
by onlineuser
Tue Nov 01, 2022 10:49 am
Forum: General
Topic: OVPN reconnect delay
Replies: 3
Views: 892

OVPN reconnect delay

Hi,

sometimes, when my OVPN connection breaks or has an timeout I need to delay the reconnect.
So I tried to add :delay 10s to the PPP profile of my OVPN connection ("On Down").

But it seemsthat this does not work.
I use the latest ROS release of version 6.

Thanks.
by onlineuser
Wed Jan 05, 2022 2:44 pm
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 46
Views: 18709

Re: feature request ADVANCED DNS Server

Also no dns-server feature in RouterOS7? :-(

The fastest an easiest way would be to adapt maradns to RouterOS. ;-)
by onlineuser
Wed Jan 05, 2022 2:41 pm
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

Re: socks proxy with remote dns

SOCKS proxy with remote dns resolving and a upstream proxy for the SOCKS proxy itself.
by onlineuser
Wed Jan 05, 2022 12:47 pm
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

Re: socks proxy with remote dns

Any news about this feature?
by onlineuser
Sun Jul 11, 2021 12:53 am
Forum: Beginner Basics
Topic: Mikrotik 951G-2HnD and Samsung TV problem
Replies: 43
Views: 40329

Re: Mikrotik 951G-2HnD and Samsung TV problem

A picture is worth a thousand words... Bug.png When I connect my RB2011 (tested with ROS 6.40.1 and ROS 6.47.10) to the white UPC (Magenta) Connect box (I use port 6 - 100 Mbit/sec) the RB2011 only connects with the speed of 10 Mbit/sec. If I force 100 Mbit/sec no link will be established (the cable...
by onlineuser
Tue Mar 02, 2021 10:25 pm
Forum: General
Topic: RB2011 - disable blue SFP LED
Replies: 6
Views: 3239

Re: RB2011 - disable blue SFP LED

Ok, I did. :-)
by onlineuser
Tue Mar 02, 2021 10:24 pm
Forum: General
Topic: OVPN RB750 latest release
Replies: 1
Views: 722

OVPN RB750 latest release

Hi, I use some ovpn connections (4096 bit) on my RB750 (mipsbe). Sometimes it takes very long that the tunnel is established. The CPU load goes while connecting on 100%. OVPN: initializing OVPN: connecting [i]sometimes up to 30 seconds later...[/i] OVPN: terminating - could not negotiate TLS in time...
by onlineuser
Wed Feb 17, 2021 4:30 pm
Forum: General
Topic: RB2011 - disable blue SFP LED
Replies: 6
Views: 3239

Re: RB2011 - disable blue SFP LED

@Mikrotik: A software solution for this "issue" would be fine.
by onlineuser
Wed Feb 17, 2021 4:28 pm
Forum: Wireless Networking
Topic: PEAP mschapv2 auth in station mode?
Replies: 21
Views: 11298

Re: PEAP mschapv2 auth in station mode?

It works fine with UPC-WiFree - but UPC disconnects the signal every hour. Then I loose some seconds until my ovpn connection to this gateway is established again. :-)
by onlineuser
Wed Feb 17, 2021 4:25 pm
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

Re: socks proxy with remote dns

We are working on SOCK5 improvements, please be patient. :)
Any news about this feature?
by onlineuser
Sun Oct 11, 2020 10:55 am
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

Re: socks proxy with remote dns

Are there any news about the new feature?
by onlineuser
Tue Oct 06, 2020 5:55 pm
Forum: Scripting
Topic: notification on incoming and established vpn connection
Replies: 2
Views: 817

Re: notification on incoming and established vpn connection

great, this is implemented :-)
by onlineuser
Mon Oct 05, 2020 10:10 pm
Forum: Scripting
Topic: notification on incoming and established vpn connection
Replies: 2
Views: 817

notification on incoming and established vpn connection

Hello, is it possible to get a notification (call via /tool fetch url="https://...) when a vpn connection from outside to the OpenVPN server will be established? Sure, I could make a script which parses the syslog logfile for such incoming connections but maybe this would be possible directly b...
by onlineuser
Tue Mar 10, 2020 11:04 pm
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 46
Views: 18709

Re: feature request ADVANCED DNS Server

I wish most features from maradns.
maradns is open source - and offers simple configuration as an authoritatived dns server.
It also can be used for internal dns server (non-authoritatived).

dnssec extension would be fine for feature but it is not very important at moment.
by onlineuser
Wed Feb 19, 2020 12:03 pm
Forum: General
Topic: ovpn - bridge-mode
Replies: 0
Views: 1664

ovpn - bridge-mode

Hello, my ovpn connection works fine with ip-mode. I try to set up a UniFi access point through an ovpn tunnel, but the access point cannot be detected by the UniFi controller software. In the local network it works but not through the Mikrotik ovpn tunnel in bridge-mode. Are there any changes on th...
by onlineuser
Thu Feb 13, 2020 4:49 pm
Forum: General
Topic: OpenVPN (dh params and crl file)
Replies: 2
Views: 1444

Re: OpenVPN (dh params and crl file)

Ok, thanks for explanation.
by onlineuser
Thu Feb 13, 2020 4:49 pm
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

Re: socks proxy with remote dns

Sorry, I read it inaccurately.

Good news. :-)
by onlineuser
Thu Feb 13, 2020 12:37 pm
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

Re: socks proxy with remote dns

It's sad. On OpenWrt based devices it's no problem to compile any package you need. Mikrotik should begin to integrate some additional packages which the community want to use. They offer some packages like ntpd, hotspot, ups, advanced-tool and etc. but I miss socks proxy (srelay) or an authoritativ...
by onlineuser
Thu Feb 13, 2020 12:27 pm
Forum: General
Topic: OpenVPN (dh params and crl file)
Replies: 2
Views: 1444

OpenVPN (dh params and crl file)

Hello, on "real" OpenVPN server it is possible to consider the dh params file (dh.pem) and the file with revoked certificates (crl.pem). The DH params are not security sensitive and are only used by an "real" OpenVPN server. On Mikrotik server this seems not to be possible. Why i...
by onlineuser
Tue Feb 11, 2020 9:45 pm
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

Re: socks proxy with remote dns

Thanks.

It would be nice if ROS would get any "real" SOCKS proxy implementation (srelay would be a open source socks proxy).
by onlineuser
Tue Feb 11, 2020 7:43 pm
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 46
Views: 18709

Re: feature request ADVANCED DNS Server

Any news about this feature? maradns or powerdns (both open source) would be perfect for ROS. It's sad. On OpenWrt based devices it's no problem to compile any package you need. Mikrotik should begin to integrate some additional packages which the community want to use. They offer some packages like...
by onlineuser
Tue Feb 11, 2020 7:32 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 67
Views: 48358

Re: OpenVPN SHA256 + UDP

stable UDP and SHA512

Btw I now noticed that ovpn in ROS only supports md5 and sha1 (sha256, sha224, sha384, sha512). SHA512 would be fine!
by onlineuser
Tue Feb 11, 2020 7:30 pm
Forum: General
Topic: certificates - validity - wrong values
Replies: 2
Views: 1536

Re: certificates - validity - wrong values

Thanks.

But btw I now noticed that ovpn in ROS only supports md5 and sha1 (sha256, sha224, sha384, sha512). In beta UDP and sha256 are implemented but nowadays sha512 would be fine.
by onlineuser
Tue Feb 11, 2020 4:41 pm
Forum: General
Topic: certificates - validity - wrong values
Replies: 2
Views: 1536

certificates - validity - wrong values

Hello,

I created a certificate for 36500 days (100 years).

openssl outputs the right validity of dates but in Winbox I only can see that it is valid for 6526 days (up to 01/01/2038).

Is this a problem in ROS with any old openssl release which cannot interpret the right validity?

Thanks.
by onlineuser
Wed Jul 17, 2019 10:17 pm
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 46
Views: 18709

Re: feature request ADVANCED DNS Server

Dear Mikrotik developer

are there any news about this feature?
by onlineuser
Wed Jul 17, 2019 10:16 pm
Forum: General
Topic: socks proxy with remote dns
Replies: 13
Views: 5225

socks proxy with remote dns

Hello,

is it possible to use the socks proxy server on a mikrotik router with remote dns?

I tried to set up but it was not possible that the router opened an outgoing connection to the target server.
by onlineuser
Sun Mar 24, 2019 8:41 am
Forum: General
Topic: Impossible to block DHCP Server. By design, or bug???
Replies: 36
Views: 16515

Re: Impossible to block DHCP Server. By design, or bug???

There is another discussion on the topic: viewtopic.php?f=2&t=140569&p=722876
by onlineuser
Sun Mar 24, 2019 8:40 am
Forum: General
Topic: firewall rules for WAN interface - DHCP firewall rules without effect
Replies: 10
Views: 6190

Re: firewall rules for WAN interface - DHCP firewall rules without effect

Up to 6.40.1 it worked to filter DHCP requests on the WAN port. On later releases I tried to enable the "use-ip-firewall" feature and added a rouge DHCP rule. /interface bridge settings set use-ip-firewall yes/no [admin@Client] > /interface bridge settings print use-ip-firewall: yes use-ip...
by onlineuser
Mon Jan 21, 2019 11:04 am
Forum: General
Topic: Hotspot login page not loading automatically on some devices
Replies: 6
Views: 3173

Re: Hotspot login page not loading automatically on some devices

http websites can be accessed without problems - also https after the client has authenticated on the hotspot website.

Yes, please share - a solution for the Mikrotik device would be fine because it would not be possible to fix every client device.
by onlineuser
Wed Jan 16, 2019 12:31 pm
Forum: General
Topic: Hotspot login page not loading automatically on some devices
Replies: 6
Views: 3173

Hotspot login page not loading automatically on some devices

Hello, I setup a hotspot. On most devices it works fine that the welcome (login) page will be loaded. But on some Huawei and Samsung devices I noticed that the redirect to the login page does not work. When I enter the hostname manually the login page will be loaded. Does anyone know this issue? Is ...
by onlineuser
Thu Oct 18, 2018 3:20 pm
Forum: General
Topic: firewall rules for WAN interface - DHCP firewall rules without effect
Replies: 10
Views: 6190

firewall rules for WAN interface - DHCP firewall rules without effect

Hello, in supplement to this thread (still unsolved) - https://forum.mikrotik.com/viewtopic.php?f=2&t=101896 - I want to ask the same question again. When my firewall rules on my testing router with ROS 6.40 dropped the whole WAN traffic, it was not possible that the WAN port got an IP address f...
by onlineuser
Thu Sep 27, 2018 4:45 pm
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 46
Views: 18709

Re: feature request ADVANCED DNS Server

Are there any news about this feature request?
by onlineuser
Thu May 24, 2018 7:37 pm
Forum: General
Topic: firewall rules for bridge for ovpn interfaces
Replies: 2
Views: 1477

Re: firewall rules for bridge for ovpn interfaces

Thanks, it works. :-)
by onlineuser
Tue May 22, 2018 10:48 pm
Forum: General
Topic: firewall rules for bridge for ovpn interfaces
Replies: 2
Views: 1477

firewall rules for bridge for ovpn interfaces

Hello, I created a bridge called "ovpn" which includes the ovpn interfaces "ovpn-in1" to "ovpn-in4" (my ovpn server on the RB offers up to 4 clients a connections to the RB). Because it is not possible to add dynamic interfaces (which are not running all the time) to fi...
by onlineuser
Fri May 04, 2018 6:34 pm
Forum: General
Topic: more public IP addresses
Replies: 5
Views: 1193

Re: more public IP addresses

1.1.1.1 ist in the subnet /28
2.2.2.2 is in the subnet 29

Requests to the 1.1.1.1 or 2.2.2.2-2.2.2.4 will be routed from the provider to my WAN port.
by onlineuser
Fri May 04, 2018 5:31 pm
Forum: General
Topic: more public IP addresses
Replies: 5
Views: 1193

more public IP addresses

Hello, I have one WAN port with one WAN IP (transport IP for outgoing traffic [also ingoing traffic] - 1.1.1.1) and four static IP adresses(2.2.2.2-2.2.2.5). Now, the WAN IP packets and all the static IP adresses packets comes up to the Mikrotik RB. How can I configure it that the all packets to the...
by onlineuser
Wed Apr 18, 2018 1:12 pm
Forum: General
Topic: /system tool fetch via proxy?
Replies: 0
Views: 981

/system tool fetch via proxy?

Hello,

Is it possible that fetch supports proxy support?

@ Mikrotik: If no, please add the feature that the fetch command is able to work via http/https/socks proxy.

Thanks.
by onlineuser
Mon Apr 02, 2018 11:21 am
Forum: General
Topic: memory usage
Replies: 3
Views: 2850

Re: memory usage

19 connections on the ~100MB memory used router and 10 connections on the ~55MB memory used router Normally the router with the usage of 55MB has more traffic than the other one. On the router which uses more memory I just have more entries in the address list. The partition size has 128MB on both d...
by onlineuser
Sun Apr 01, 2018 11:53 am
Forum: General
Topic: memory usage
Replies: 3
Views: 2850

memory usage

Hello,

I noticed on an RB2011 that the memory usage is the half one than on any other RB2011.
Although on the router with less memory usage there I installed the ntp server package, the other router has default packages and just a little bite more firewall rules.

Where does this come from?
by onlineuser
Mon Mar 26, 2018 8:24 pm
Forum: Beginner Basics
Topic: ssh settings
Replies: 3
Views: 1714

Re: ssh settings

I have tested it on a RB2011 with license level 5 and on a RB70 with license level 4. On both devices the WinBox entry is missing (bug in WinBox because on the item list in the documentation it is listed). Trough terminal I can set the flags. Ok, AES-256 instead of AES-128. :-) And it is also strang...
by onlineuser
Mon Mar 26, 2018 7:15 pm
Forum: Beginner Basics
Topic: ssh settings
Replies: 3
Views: 1714

ssh settings

Hello, where do I find the ssh settings in WinBox? /ip ssh set strong-crypto=yes In WinBox 3.12 I can not find it. The option "/ip ssh set strong-crypto=yes" does not change the key-size (no difference between no and yes). The keysize can be changed with "/ip ssh set host-key-size=......
by onlineuser
Thu Mar 15, 2018 4:42 pm
Forum: General
Topic: Supout.rif reader available
Replies: 34
Views: 39377

Re: Supout.rif reader available

Nice, but an offline viewer would be better. :shock: Is there something in planning? The architecture of filesystem seems to be public or where did this guy got the source for his viewer ( did not try it with my supout files)? http://k3dt.eu/supout-reader/ (not serious to upload the supout file on a...
by onlineuser
Thu Mar 08, 2018 8:11 pm
Forum: General
Topic: RB2011 - disable blue SFP LED
Replies: 6
Views: 3239

RB2011 - disable blue SFP LED

Hi,

last time I has configured a RB2011 (6.41.2). When I disabled the SFP interface the blue LED switched off.
Today I configured any older RB2011 (6.40.1) and there I was not able to switch off the SFP LED.

Both RB2011 has no SFP adapter in the slot.
by onlineuser
Fri Mar 02, 2018 5:13 pm
Forum: Beginner Basics
Topic: guaranteed bandwidth for a brigde
Replies: 1
Views: 742

guaranteed bandwidth for a brigde

Hi, how is it possible to set a guaranteed bandwidth for a bridge or one ethernet port. I want that the bandwidht on one port / bridge always offers 100kbps upload and 200kpbs download. In worst case the bandwidth for the other bridges must be reduced. The problem is that the WAN connection also doe...
by onlineuser
Fri Mar 02, 2018 5:11 pm
Forum: Beginner Basics
Topic: wireless clients overview
Replies: 0
Views: 612

wireless clients overview

Hi, when I click in WinBox to "Quick Set" I see on the left side all the wireless clients with the signal strength (graphic). Is the same graphical overview also in other menu available? Because the quick set window is for changing the config and not just for getting information about all ...
by onlineuser
Fri Mar 02, 2018 11:37 am
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 46
Views: 18709

Re: feature request ADVANCED DNS Server

Such of these features would make Mikrotik more popular and additional hardware would not be necessary. All of us trust on RB software although we do not know anything about the source code and possible backholes. Here the OpenWrt was the better solution but the UI is clearer and easier (faster) to ...
by onlineuser
Fri Mar 02, 2018 11:31 am
Forum: General
Topic: Feature Request - Proxy Support for WinBox
Replies: 3
Views: 1472

Re: Feature Request - Proxy Support for WinBox

Tunneling WinBox through Permeo or SocksCap works, but an integrated proxy feature would be better!
by onlineuser
Thu Mar 01, 2018 6:22 pm
Forum: General
Topic: feature request ADVANCED DNS Server
Replies: 46
Views: 18709

Re: feature request ADVANCED DNS Server

A lightweight DNS server like "maradns" would be fine for Mikrotik devices.
The configuration could be done through text files like on any OpenWRT device.

Why such a service will not be offered by Miktrotik? ;-)
by onlineuser
Thu Mar 01, 2018 6:18 pm
Forum: General
Topic: Feature Request - Proxy Support for WinBox
Replies: 3
Views: 1472

Feature Request - Proxy Support for WinBox

Hello,

it would be nice if WinBox would has a proxy support (socks-proxy) to be able to connect to any external RB through a proxy server.
by onlineuser
Thu Feb 08, 2018 7:48 pm
Forum: Announcements
Topic: v6.41.1 [current]
Replies: 104
Views: 32655

Re: v6.41.1 [current]

onlineuser - It might affect your situation, however, we can not give you precise yes or no answer. If the problem that you have is caused by delayed/slow responses to/from OVPN server, then this might help and your problem might go away; It looks good. At the first connection establishment the con...
by onlineuser
Tue Feb 06, 2018 6:46 pm
Forum: Announcements
Topic: v6.41.1 [current]
Replies: 104
Views: 32655

Re: v6.41.1 [current]

*) ovpn - fixed resource leak on systems with high CPU usage;
Does this fix this problem I reported here?
viewtopic.php?f=2&t=129459
by onlineuser
Fri Feb 02, 2018 11:14 am
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

Re: 100% CPU - OVPN Server error: TLS failed

What's new in 6.41.1 (2018-Jan-30 10:26):
*) ovpn - fixed resource leak on systems with high CPU usage;
Does this fix the problem?
by onlineuser
Wed Jan 24, 2018 6:27 pm
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

Re: 100% CPU - OVPN Server error: TLS failed

Yes, I will upgrade to a more powerful device. But a user-defined timeout also would be fine. In my case there are some seconds missing because after several tries it works. If the device never would be able to establish a connection it would be clear. But the problem only occurs with the two outgoi...
by onlineuser
Wed Jan 24, 2018 8:35 am
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

Re: 100% CPU - OVPN Server error: TLS failed

Thanks but why does it work sometimes immediately to establish the connection.
@Mikrotik: Maybe it would be possible to fix this in software for slower devices?
by onlineuser
Tue Jan 23, 2018 4:49 pm
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

Re: 100% CPU - OVPN Server error: TLS failed

With 2048 bits it should be no problem, but it also works with 4096 bits sometimes to establish the tunnel, so I think it is only a timeout problem of RB. If Mikrotik would give the ssl command more cpu time an set a higher timeout it could be solved. I have other RB2011 with 2048 bit certificates a...
by onlineuser
Mon Jan 22, 2018 10:25 pm
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

Re: 100% CPU - OVPN Server error: TLS failed

No, there is no packet loss.
I think because of the the high cpu power the timeout will be reached before the connection is esablished.
I use for all three OVPN configs certificates with 4096 bit.
by onlineuser
Mon Jan 22, 2018 8:04 pm
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

Re: 100% CPU - OVPN Server error: TLS failed

Yes, single core - RB750.

I am running two OVPN clients and one OVPN server on it.

Sometimes, the reconnect takes few seconds, sometimes it takes 30 minutes. :-(
by onlineuser
Mon Jan 22, 2018 6:43 pm
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

Re: 100% CPU - OVPN Server error: TLS failed

Any known bug?

100% CPU while (re)connecting.
by onlineuser
Wed Jan 10, 2018 2:37 pm
Forum: General
Topic: 100% CPU - OVPN Server error: TLS failed
Replies: 13
Views: 4507

100% CPU - OVPN Server error: TLS failed

Hello, sometimes it happens that the VPN tunnel interrupts. Then I get this error message: OpenVPN Server error: TLS failed or terminating... - TLS failed (while reconnecting) Then the RB tries to reconnect to the server (Linux OVPN server, not a other RB). Sometimes it takes more than one retry and...
by onlineuser
Thu Jan 04, 2018 11:44 pm
Forum: Wireless Networking
Topic: PEAP mschapv2 auth in station mode?
Replies: 21
Views: 11298

Re: PEAP mschapv2 auth in station mode?

Good news! Did you try it within the UPC Wi-Free network? Is it possible to use a RB2011 or any other wireless RB as wireless client with WPA2-Enterprise client (WAN) and as accesspoint (LAN) for the home network? In fact I only want to tunnel all internal traffic over the Wi-Free network through an...
by onlineuser
Thu Jan 04, 2018 11:22 pm
Forum: Beginner Basics
Topic: WPA2-Enterprise client and repeater for home network
Replies: 0
Views: 702

WPA2-Enterprise client and repeater for home network

Hello,

did anyone try to use a RB2011 or any other wireless RB as wireless client with WPA2-Enterprise client and as accesspoint for the home network?

Thanks.
by onlineuser
Tue Jan 02, 2018 3:50 pm
Forum: Beginner Basics
Topic: 6.41 new features
Replies: 1
Views: 1203

6.41 new features

Hello, I have three questions about new features in ROS. 1) !) bridge - implemented software based vlan-aware bridges; https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering Were the default settings be changed in 6.4x compared to 6.39? 2) !) switch - "master-port" co...
by onlineuser
Wed Dec 06, 2017 11:33 am
Forum: General
Topic: flapping statistics
Replies: 1
Views: 631

Re: flapping statistics

*push*
by onlineuser
Mon Dec 04, 2017 6:06 pm
Forum: Beginner Basics
Topic: OpenVPN only without static key
Replies: 3
Views: 1772

Re: OpenVPN only without static key

Maybe in one of the next releases. :lol:
by onlineuser
Mon Dec 04, 2017 6:04 pm
Forum: Beginner Basics
Topic: more than one OVPN server on one RB
Replies: 4
Views: 1175

Re: more than one OVPN server on one RB

Thanks
by onlineuser
Mon Dec 04, 2017 5:42 pm
Forum: Beginner Basics
Topic: more than one OVPN server on one RB
Replies: 4
Views: 1175

Re: more than one OVPN server on one RB

Why this? Will this be changed in one of the next releases? What is the difference between the button "OVPN Server" in PPP and the adding of a new interface "OVPN Server Binding"? So it would be possible to create more OVPN server bindings configs but only one server instance. Th...
by onlineuser
Mon Dec 04, 2017 5:39 pm
Forum: General
Topic: safeness of RB settings
Replies: 2
Views: 771

Re: safeness of RB settings

Thanks, very much.
by onlineuser
Mon Dec 04, 2017 5:25 pm
Forum: Beginner Basics
Topic: more than one OVPN server on one RB
Replies: 4
Views: 1175

more than one OVPN server on one RB

Hello,

is it possible to run two ovpn servers on one RB?
Via Winbox it seems not to work.

Thanks.
by onlineuser
Sun Dec 03, 2017 2:14 pm
Forum: General
Topic: safeness of RB settings
Replies: 2
Views: 771

safeness of RB settings

Hello,

is it possible only to reset the password of a RB (with physically access to the hardware) that the intruder gets all the settings?
I want to prevent that anyone gets the settings - if the intruder uses the reset-button, the configuration is gone but he does not get the settings.

Thanks.
by onlineuser
Sat Dec 02, 2017 6:23 pm
Forum: General
Topic: flapping statistics
Replies: 1
Views: 631

flapping statistics

Hello, on my RB2011 I noticed that sometimes the interface-statistics is flapping (except on port 2; the WAN port is on port 6) - see attached screenshot. When the statistics window is opened one second the bandwidh data on all interfaces are quite ok and then one second later all ports shows 0 bps ...
by onlineuser
Fri Dec 01, 2017 7:23 pm
Forum: General
Topic: load balancing / backup
Replies: 2
Views: 1083

Re: load balancing / backup

Is there any example in the documentation?
But changing of the gateway is not enough, the destination IP address also must be changed to reach the proxy server - is this also possible?
by onlineuser
Fri Dec 01, 2017 5:36 pm
Forum: General
Topic: load balancing / backup
Replies: 2
Views: 1083

load balancing / backup

Hello, I have three OVPN connection on my Mikrotik. That my server has access to all three networks and proxy servers I added three srcnat-masquerade rules. This works fine. server----10.10.1.1====10.10.1.2:8080, 1080 server----10.20.2.1====10.10.3.2:8080, 1080 server----10.20.3.3====10.10.3.2:8080,...
by onlineuser
Fri Dec 01, 2017 11:04 am
Forum: Beginner Basics
Topic: more than one ICMP option
Replies: 0
Views: 544

more than one ICMP option

Hello,

is it not possible to set more than one ICMP type option to one rule?

I want to define type 0 (echo reply) and type 8 (echo request) for one ICMP rule.

The same thing is for the ICMP code: a range or more than one code would be fine.

Thanks.
by onlineuser
Fri Nov 24, 2017 3:01 pm
Forum: Beginner Basics
Topic: OPENVPN SERVER - HOW TO PUSH ROUTE TO CLIENTS
Replies: 19
Views: 40137

Re: OPENVPN SERVER - HOW TO PUSH ROUTE TO CLIENTS

Are there any news about pushing a route from the mikrotik server to the openvpn client?
by onlineuser
Fri Aug 04, 2017 9:14 pm
Forum: Beginner Basics
Topic: 6.40 - no OpenVPN
Replies: 12
Views: 4287

Re: 6.40 - no OpenVPN

OpenVPN client works with 6.40.1 again. :-)
by onlineuser
Fri Aug 04, 2017 11:58 am
Forum: Beginner Basics
Topic: 6.40 - no OpenVPN
Replies: 12
Views: 4287

Re: 6.40 - no OpenVPN

Thanks, very much. :-)
by onlineuser
Tue Aug 01, 2017 8:07 pm
Forum: Beginner Basics
Topic: 6.40 - no OpenVPN
Replies: 12
Views: 4287

Re: 6.40 - no OpenVPN

Thanks.
by onlineuser
Tue Aug 01, 2017 8:14 am
Forum: Beginner Basics
Topic: 6.40 - no OpenVPN
Replies: 12
Views: 4287

Re: 6.40 - no OpenVPN

Noone any idea why this behavior was changed?
Or is it an unintentional bug?
by onlineuser
Fri Jul 28, 2017 8:03 pm
Forum: Announcements
Topic: v6.40 [current]
Replies: 102
Views: 41700

Re: v6.40 [current]

OVPN default route behaviour:

Take a look to this post - why did you change the default route behaviour?
viewtopic.php?f=13&t=124005&p=610512#p610512
by onlineuser
Fri Jul 28, 2017 8:01 pm
Forum: Beginner Basics
Topic: 6.40 - no OpenVPN
Replies: 12
Views: 4287

Re: 6.40 - no OpenVPN

The problem is a wrong dynamic route when OVPN connection is established. screenshot: 6.39: the dynamic set route is set correct 6.40: after upgrading with the wo default routes OVPN connection does not work 6.40 fixed: after removing the DS enrty and adding the AS route, the OVPN connectio nworks a...
by onlineuser
Fri Jul 28, 2017 11:50 am
Forum: Beginner Basics
Topic: 6.40 - no OpenVPN
Replies: 12
Views: 4287

Re: 6.40 - no OpenVPN

Thanks!
With 6.39 it works again. :-)

I hope the OVPN interface bug in 6.40 will be fixed soon.
by onlineuser
Fri Jul 28, 2017 8:54 am
Forum: Beginner Basics
Topic: 6.40 - no OpenVPN
Replies: 12
Views: 4287

6.40 - no OpenVPN

Hello, after upgrade from 6.39 to 6.40 the OpenVPN client does not work any longer - the connection will be established but the interface will not be created, so most rules do not work any longer (for example: srcnat to openvpn interface). How can I downgrade to 6.39? Copying the file to the device ...
by onlineuser
Sat Jun 10, 2017 7:41 pm
Forum: Beginner Basics
Topic: little LOG bugfix
Replies: 2
Views: 819

Re: little LOG bugfix

Some comments are longer than 31 characters.
It would be no problem if there will be an user-defined length be implemented. ;-)

Moreover, the ID of the rule in the beginning of each line on LOG which occurs an log entry would be helpful (F13 for filter rule #13, N14 for NAT rule #14 for example).
by onlineuser
Thu Jun 08, 2017 10:06 pm
Forum: Beginner Basics
Topic: little LOG bugfix
Replies: 2
Views: 819

little LOG bugfix

Hello, when the Log-prefix is too long, the prefix-string in the LOG will be shorten. Maybe this limit can be extended - or better, the user should be able to decide the maximum length of the entry which will be shown in LOG. On the attached picture you see that the prefix was cut (instead of "...
by onlineuser
Tue Jan 31, 2017 4:32 pm
Forum: Wireless Networking
Topic: PEAP mschapv2 auth in station mode?
Replies: 21
Views: 11298

Re: PEAP mschapv2 auth in station mode?

Any news concerning WPA2-Enterprise (EAP)?
by onlineuser
Mon Jan 30, 2017 7:08 pm
Forum: Beginner Basics
Topic: WPA2-Enterprise - uplink to wifi
Replies: 0
Views: 633

WPA2-Enterprise - uplink to wifi

Hello, I want to use a wifi-connection as WAN-port. SSID: <ssid> Authentication: WPA2-Enterprice (EAP) Encryption: CCMP PSK: EAP method : PEAP Identity: <identity> Password: <password> inner auth: EAP-MSCHAPV2 Is this WPA2-Enterprise configuration possible with Mikrotik for a WAN-port?
by onlineuser
Wed Jan 18, 2017 6:28 pm
Forum: Beginner Basics
Topic: firewall rules...
Replies: 20
Views: 7437

Re: firewall rules...

Thx. :D
by onlineuser
Tue Jan 17, 2017 8:05 pm
Forum: General
Topic: different log levels - feature request
Replies: 0
Views: 840

different log levels - feature request

Hello, I log different rules. A nice feature would be that the LOG-windows can show all log entries / entries with level 1 / entries with level 2 and so on. If logging is activated for a rule beside the level could be entered (number 0-x). Actually the LOG-window only offers to show all entries or t...
by onlineuser
Tue Jan 17, 2017 7:50 pm
Forum: Beginner Basics
Topic: routing problem
Replies: 8
Views: 2158

Re: routing problem

*push*
by onlineuser
Mon Jan 16, 2017 10:38 pm
Forum: Beginner Basics
Topic: OpenVPN only without static key
Replies: 3
Views: 1772

OpenVPN only without static key

Hello,

normally I use for OpenVPN tls-auth a static key.
client: tls-auth static.key 1
server: tls-auth static.key 0


When I use a Mikrotik as client it is not possible to specify a static key.

Is this a security risk when the tls-auth runs without encryption?
by onlineuser
Mon Jan 16, 2017 9:41 pm
Forum: Beginner Basics
Topic: Thinking about buying
Replies: 7
Views: 3514

Re: Thinking about buying

First I used OpenWrt with iptables and my own scripts but Mikrotik is really good.
I think it is simple to configure a Mikrotik and this forum also helps you. :-)
by onlineuser
Mon Jan 16, 2017 7:37 pm
Forum: Beginner Basics
Topic: port configuration
Replies: 10
Views: 2081

Re: port configuration

Webif is also comfortable but in meantime I prefer the CLI. :wink:
by onlineuser
Mon Jan 16, 2017 7:32 pm
Forum: Beginner Basics
Topic: export file - what will be saved
Replies: 4
Views: 1117

Re: export file - what will be saved

Thanks, very much. :D
by onlineuser
Mon Jan 16, 2017 6:51 pm
Forum: Beginner Basics
Topic: export file - what will be saved
Replies: 4
Views: 1117

Re: export file - what will be saved

Thanks.

Will the entries of the address lists also be stored in a binary-backup (the export is without address lists)?
by onlineuser
Mon Jan 16, 2017 6:18 pm
Forum: Beginner Basics
Topic: destination rule - src address list
Replies: 9
Views: 4071

Re: destination rule - src address list

Ok, thanks. I thought when the NAT rule could drop the packet then the firewall rules get a little bit more clearly to read because then there would be less rules in it. ;-)
by onlineuser
Mon Jan 16, 2017 5:25 pm
Forum: Beginner Basics
Topic: destination rule - src address list
Replies: 9
Views: 4071

Re: destination rule - src address list

For NAT rules there is no DROP available.
A RETURN jumps back where the jump came from.
Why there is no DROP for NAT rules available?

Is a return equivalent to a drop?
by onlineuser
Mon Jan 16, 2017 8:32 am
Forum: Beginner Basics
Topic: destination rule - src address list
Replies: 9
Views: 4071

Re: destination rule - src address list

Cool, thanks - why do not use the same schema like on firewall rules - good idea. ;-)
by onlineuser
Sun Jan 15, 2017 9:50 pm
Forum: Beginner Basics
Topic: export file - what will be saved
Replies: 4
Views: 1117

export file - what will be saved

Hello,

when I save my settings will there be saved the whole settings (also VPN certificates and keyfiles)?

After importing the certificate I tried to delete the uploaded files and the VPN tunnel works further.
by onlineuser
Sun Jan 15, 2017 9:42 pm
Forum: Beginner Basics
Topic: destination rule - src address list
Replies: 9
Views: 4071

Re: destination rule - src address list

Yeah, in meantime I solved it in this way - but it would be also nice if a rule (firewall or NAT) could consider more than one address list. ;-)
by onlineuser
Sun Jan 15, 2017 10:48 am
Forum: Beginner Basics
Topic: destination rule - src address list
Replies: 9
Views: 4071

Re: destination rule - src address list

No, it's not possible. example: address list 1: block_scanner address list 2: block_permanent_blacklisted When there are two rules (first one only allows IP addresses which are not in block_scanner , this rule will be taken without checking the second one if the IP is maybe on the block_permanent_bl...
by onlineuser
Sat Jan 14, 2017 9:03 pm
Forum: Beginner Basics
Topic: destination rule - src address list
Replies: 9
Views: 4071

destination rule - src address list

Hello, I have more address lists which should be ignored for my destination NAT rules. It would be fine if there could be specified more than one address list - it also should be possible to negate some of the address lists. Or can I create dynamically a new address list which contains the IP addres...
by onlineuser
Mon Jan 09, 2017 10:41 pm
Forum: Beginner Basics
Topic: routing problem
Replies: 8
Views: 2158

Re: routing problem

noone any idea? :-(
by onlineuser
Sat Jan 07, 2017 5:52 pm
Forum: Beginner Basics
Topic: routing problem
Replies: 8
Views: 2158

Re: routing problem

Everything works fine but I get a lot of TCP Resets on the 33.3 router. The tunnel and bandwidth are stable. On the OpenVPN server there are no suspicious entries. 15:05:04 firewall,info LAST DROP - INPUT input: in:OpenVPN out:(none), proto TCP (RST), 10.1.0.1:8080->10.1.0.6:61832, len 40 15:05:06 f...
by onlineuser
Sat Jan 07, 2017 5:45 pm
Forum: Beginner Basics
Topic: outgoing request to 81.198.87.240:15252 udp
Replies: 3
Views: 4048

Re: outgoing request to 81.198.87.240:15252 udp

Yeah but since I have deactivated the automatic timezone checking there was no outgoing request.
by onlineuser
Thu Jan 05, 2017 7:07 pm
Forum: Beginner Basics
Topic: outgoing request to 81.198.87.240:15252 udp
Replies: 3
Views: 4048

Re: outgoing request to 81.198.87.240:15252 udp

I think it was the TimeZoneAutodetect flag in System/Clock. ;-)

Haha, will the timezone be guessed by my IP address? ;-)
by onlineuser
Thu Jan 05, 2017 6:44 pm
Forum: Beginner Basics
Topic: outgoing request to 81.198.87.240:15252 udp
Replies: 3
Views: 4048

outgoing request to 81.198.87.240:15252 udp

Hello, my RB tries to establish a connection to 81.198.87.240:15252 UDP. IP/Cloud DDNS and NTP are disabled. I also disabled the SNTP client (System/SNTP Client) Where does this come from? I can remember that I had the same problem on other device but I can not remember which settings caused this pr...
by onlineuser
Thu Jan 05, 2017 3:18 pm
Forum: Beginner Basics
Topic: routing problem
Replies: 8
Views: 2158

Re: routing problem

ISP is on 11.0 on another port of R1. Ok, I will try it with static routes. UPDATE_1: On R1 I set following route: 10.1.0.0/29 via 192.168.33.3 (now from 34.0 10.1.0.6 is reachable). But from 34.0 I cannot ping 10.1.0.1 (only 10.1.0.6 is reachable). UPDATE_2: Ok, now it runs, I forgot the two forwar...
by onlineuser
Thu Jan 05, 2017 8:44 am
Forum: Beginner Basics
Topic: routing problem
Replies: 8
Views: 2158

Re: routing problem

Yes, 33.0 and 34.0 are NAT routed to the gateway (33.1) but 33.0 also routed directly to 34.0 without NAT (34.0 can directly communicate with 33.0). Or can I solve it with port forwarding, that 33.1:1080 will be routed to 33.3:1080 and this will be routed through the tunnel to 10.1.0.1:1080? I would...
by onlineuser
Wed Jan 04, 2017 10:13 pm
Forum: Beginner Basics
Topic: routing problem
Replies: 8
Views: 2158

routing problem

Hello,

the VPN tunnel from 33.3 to the external VPN server works - the 10.1.0.0 is from both sites of the tunnel reachable.

Which routes and NAT rules must I set on R1 and R2 that 10.1.0.6/10.1.0.1 are reachable from the 34.0 network through the 33.1 and 33.30?

Thanks, very much.
by onlineuser
Wed Jan 04, 2017 9:43 am
Forum: Beginner Basics
Topic: RB as OpenVPN client - some questions
Replies: 3
Views: 1806

Re: RB as OpenVPN client - some questions

Thanks for hints. lport parameter will be ignored. :-( @Mikrotik: Please implement this - then the firewall rules can be more restrictive. username and password are for locally certificates (although when they are not password protected it seems to be ignored - I just entered anything). OpenVPN supp...
by onlineuser
Tue Jan 03, 2017 5:38 pm
Forum: Beginner Basics
Topic: RB as OpenVPN client - some questions
Replies: 3
Views: 1806

RB as OpenVPN client - some questions

Hello, I am running a OpenVPN server on any linux machine. Now I want that my RB connects to the OpenVPN server as client. Does this work? Why do the RB needs an user and password for dialout? Where can I put the certificate data [ca, cert, key, tls-auth] (under DD-WRT is was easy to paste the conte...
by onlineuser
Tue Jan 03, 2017 3:57 pm
Forum: General
Topic: feature - separator line
Replies: 2
Views: 1423

Re: feature - separator line

Exactly the same idea. :-)

@Mikrotik: Why do you not want to implement this feature?
It would make the fast reading of a lot of rules quite easier!
by onlineuser
Tue Jan 03, 2017 3:54 pm
Forum: Beginner Basics
Topic: port configuration
Replies: 10
Views: 2081

Re: port configuration

I know - I only did the default config and then I tried to configure it though an other RB. I was too lazy to take the laptop again for Winbox. ;-)
by onlineuser
Tue Jan 03, 2017 2:33 pm
Forum: General
Topic: feature - separator line
Replies: 2
Views: 1423

feature - separator line

Hello, if the list of filter rules becomes longer and longer it is hard to read. There would be a kind of separator line nice - maybe an empty line without line number and with the possiblity to set any comment for this line (comment in different textcolor or italic - maybe also the textcolor for ev...
by onlineuser
Tue Jan 03, 2017 10:26 am
Forum: Beginner Basics
Topic: port configuration
Replies: 10
Views: 2081

Re: port configuration

Thanks, this is I was looking for. Now, it works. :-)

First time I configured a RB via SSH instead of Winbox ;-)
by onlineuser
Mon Jan 02, 2017 7:19 pm
Forum: Beginner Basics
Topic: port configuration
Replies: 10
Views: 2081

Re: port configuration

This I also tried but the RB750 does not answer ping request which comes from 192.168.33.1 (RB2011). On the same network there is an other device (192.168.33.10/27 with gateway 192.168.33.1) and this device is answering the requests which comes through 192.168.33.1. So the RB750 has a wrong configur...
by onlineuser
Mon Jan 02, 2017 6:56 pm
Forum: Beginner Basics
Topic: port configuration
Replies: 10
Views: 2081

Re: port configuration

Ok thanks. I tried "ip routes" and "ip addresses" but both does not work. I want that one port of my RB750 has following configuration. IP: 192.168.33.30 Netmask: 255.255.255.224 Gateway: 192.168.33.1 How can I set this? Why always will be added the default gateway 192.168.33.30 ...
by onlineuser
Mon Jan 02, 2017 11:33 am
Forum: Beginner Basics
Topic: port configuration
Replies: 10
Views: 2081

port configuration

Hello, I tried to set an IP address on a RB750 for one port - 192.168.33.30/27. By default the gateway 192.168.33.30 will be set. Is it not possible that I set as gateway 192.168.33.1? Changing is not possible so I tried ti add a default gateway but it also not helps. Do anyone know any solution? # ...
by onlineuser
Fri Jun 17, 2016 8:32 am
Forum: Beginner Basics
Topic: strange firewall behaviour
Replies: 8
Views: 1950

Re: strange firewall behaviour

Ok thanks, very much.

I will try to do like you suggested. :-)

That the nat rule will be inactive when the limits of this rule are reached and the packets goes to the input chain, is not a good design principle but why does Mikrotik allow limits on nat rules?
by onlineuser
Wed Jun 15, 2016 10:21 pm
Forum: Beginner Basics
Topic: strange firewall behaviour
Replies: 8
Views: 1950

Re: strange firewall behaviour

Ok, I also set the limit and dst-limit on my nat rules for port 80 and 443. I thought that when Mikrotik offers these parameters, I also can use them. But I also not found out how to reproduce this behaviour - so I believed that it is a matter of manipulated or not valid packets. And one more thing ...
by onlineuser
Tue Jun 14, 2016 10:43 pm
Forum: Beginner Basics
Topic: strange firewall behaviour
Replies: 8
Views: 1950

Re: strange firewall behaviour

No, I do not use any proxy service on RB. Ahh, I only forward port 80 and 443 and maybe the incoming http/https requests are not good (clean) enough to be forwarded. And because no forwarding rule will be used on of the last dropping rules drop the invalid packets. So the webserver can't write anyth...
by onlineuser
Tue Jun 14, 2016 6:59 pm
Forum: Beginner Basics
Topic: strange firewall behaviour
Replies: 8
Views: 1950

strange firewall behaviour

Hello, how can this happen? There comes a port 80 request from WAN and it will be routed via the NAT-rule to the DMZ server. But the webserver logfile has no entry that any request on port 80 came in (this sometime happens). And then there came three ICMP requests from the same IP to the WAN port. W...
by onlineuser
Tue May 03, 2016 6:37 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

Thanks, very much. :-)
by onlineuser
Mon May 02, 2016 8:23 pm
Forum: Beginner Basics
Topic: Multiple Src. Address Lists
Replies: 6
Views: 18248

Re: Multiple Src. Address Lists

Hello,

I also have the same problem - I have two adress lists and when I use two rules (for every address list one rule) the traffic can't be filtered well.

How can I create a combined address list that contains all IP addresses of list A and list B which is also always synchronous?
by onlineuser
Mon May 02, 2016 5:42 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

Yes, you are right - but it is funny to play around with such "speacial rules". ;-)

Is it possible to write a script for ROS which sends me every hour a complete list of the address lists via mail or FTP upload (or even shown on the internal website)?
by onlineuser
Sun May 01, 2016 10:21 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

Now it works but when I activate the first drop rule for blacklisted IP addresses the other rules for extend the time to long won't be reached any longer. So it is only possible to extend the blacklist-time when the short time is expired and a new request from the same IP comes in. Why it is not pos...
by onlineuser
Sun May 01, 2016 12:02 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

Thanks, now it's clear. But now I have one last logicaly problem. chain=input action=add-src-to-address-list tcp-flags=syn connection-state=new protocol=tcp address-list=Port_Attack_List address-list-timeout=1d in-interface=WAN dst-port=!80,443 limit=2/1m,2:packet : log=yes log-prefix="PORT-ATT...
by onlineuser
Sat Apr 30, 2016 8:32 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

1) drop src-address-list=blacklist ... (normal set of rules) 2)default drop (with match rate limit, e.g. 5/5) 3)src not in abusers -> add src to blacklist timeout=short 4)src in abusers -> add src to blacklist timeout=long 5)add src to abusers timeout=something like 1 week or 1 month - at least as ...
by onlineuser
Fri Apr 29, 2016 10:12 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

Thanks, very much - I will try it. :-)
by onlineuser
Fri Apr 29, 2016 4:37 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

1st rule, drop address list 2nd rule, match traffic up to some limit, then passthrough 3rd rule add to address list 4th rule drop traffic if ports are not 80 and 443. In this case, traffic would be dropped in both cases ( address list and not on address list sources) but you will be able to add tim...
by onlineuser
Fri Apr 29, 2016 1:43 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

Ok here my rules. The first blocks IPs from blacklist. The second tries to detect TCP requests on WAN port and the thirs should detect UDP requests on WAN port. Your example accepts incoming requests, I drop it because I only want to count such requests so that I can blacklist the IP after 2 or thre...
by onlineuser
Wed Apr 27, 2016 3:53 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

I tried - it only works if I set the inverse flag for limit. If it is not set the IP will be added after first request to blacklist. (Port 80 and 443 incoming are excepted from the blacklisting-rule) Moreover there seems to be another bug. I use the Dst-limit by "addresses and dst port". O...
by onlineuser
Wed Apr 27, 2016 10:14 am
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

Yes I tried 5/5 but per minute. That means that when 6 packets come in per minute the IP should be added to the Port_Attack_List. But when I test it the IP will be added after the first packet. I also tried to set the Dst. Limit (5/5 min, dst. address and port) but it also was unsuccesssfull. BTW, I...
by onlineuser
Tue Apr 26, 2016 8:20 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

I tried following rule. When more that 2 requests/minute comes in (also tried with Dst. Limit for port an adress) the IP should be added to the Port_Attack_List. But when I do not use the inverse feature the IP will be added after first request to the Port_Attack_List - moreover, I only set this rul...
by onlineuser
Mon Apr 25, 2016 7:53 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

Re: how to detect and block access via one port

I tried it with "limit" seen here: http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter I want that IP addresses which sends about 4 requests per minute will added to a blocklist of 1 hour. The next step would be that when one IP address of this blocklist tries again after one hour that...
by onlineuser
Sun Apr 24, 2016 12:05 pm
Forum: Beginner Basics
Topic: how to detect and block access via one port
Replies: 23
Views: 7357

how to detect and block access via one port

Hello, I added port detection rules (TCP and UDP) to my rules - it works fine. But how can I detect such a access trial like this one on the screenshot (when the source IP and port is always the same and there are about 10 requests per second)? And would it be possible that the first block-time take...
by onlineuser
Tue Mar 08, 2016 9:51 pm
Forum: General
Topic: TCP 80 forwarding for webserver (how relevant are TCP flags)
Replies: 9
Views: 2454

Re: TCP 80 forwarding for webserver (how relevant are TCP flags)

Has noone an idea how incoming connections could become more secure by checking the TCP flags? :-(
by onlineuser
Tue Jan 12, 2016 10:59 pm
Forum: Beginner Basics
Topic: webserver http/https
Replies: 1
Views: 984

Re: webserver http/https

This seems to be a configuration issue of your webserver. ;-)
by onlineuser
Tue Jan 12, 2016 11:42 am
Forum: Beginner Basics
Topic: Hairpin-NAT
Replies: 3
Views: 1440

Re: Hairpin-NAT

Interessting question! http://wiki.mikrotik.com/images/2/2e/Hairpin_nat_1.png If any client from the subnet 192.168.1.0/24 tries to open the public IP the NAT-rule works. But what when I want the same thing for the webserver itself (192.168.1.2)? Here the schema: http://www2.pic-upload.de/img/294064...
by onlineuser
Wed Jan 06, 2016 11:58 am
Forum: General
Topic: TCP 80 forwarding for webserver (how relevant are TCP flags)
Replies: 9
Views: 2454

Re: TCP 80 forwarding for webserver (how relevant are TCP flags)

Thanks. Yes, there are some different combinations possible but if I only allow the "good" combinations for port 80 forwarding and drop all the rest it should work. I tried to set at incoming port 80 rule the syn and ack flag to check if the handshake is right but it does not work. Moreove...
by onlineuser
Mon Jan 04, 2016 10:46 pm
Forum: General
Topic: TCP 80 forwarding for webserver (how relevant are TCP flags)
Replies: 9
Views: 2454

Re: TCP 80 forwarding for webserver (how relevant are TCP flags)

Ok, thx very much. All your hints I have already implemented. :-) My RB2011 has a CPU utilization about 3 up to 15 percent (about 30-40 permanent outgoing/incoming connections). So I thought the router could also check the traffic for any anomalies for example: initialitation, three-way handshake, r...
by onlineuser
Mon Jan 04, 2016 6:01 pm
Forum: General
Topic: TCP 80 forwarding for webserver (how relevant are TCP flags)
Replies: 9
Views: 2454

Re: TCP 80 forwarding for webserver (how relevant are TCP flags)

How can I set a fail2ban list for ip-adresses which tries several invalid combinations of tcp-flags?
It it possible to detect and filter manipulated requests?
by onlineuser
Sun Jan 03, 2016 3:53 pm
Forum: Beginner Basics
Topic: RB2011 with 2 WANs
Replies: 2
Views: 1305

Re: RB2011 with 2 WANs

Thanks. :-)
by onlineuser
Fri Dec 11, 2015 9:11 pm
Forum: Beginner Basics
Topic: RB2011 with 2 WANs
Replies: 2
Views: 1305

RB2011 with 2 WANs

Hello, I have two WAN ports on my RB2011. My default masquerade rule says that the traffic goes out via WAN_1. Now I want to set up an Socks Proxy on my DMZ which should route all the traffic via a masquerade rule out on WAN_2. Can I control this via a second masquerade rule where I set the src addr...
by onlineuser
Fri Dec 11, 2015 7:21 pm
Forum: General
Topic: PPPoA feature request
Replies: 2
Views: 1299

Re: PPPoA feature request

Yes, it makes no sense, I thought PPPoA must be used when running a modem in bridge mode. But it seems that a PPTP connection is enough.
by onlineuser
Fri Dec 11, 2015 7:15 pm
Forum: Beginner Basics
Topic: PPPoA with RB2011
Replies: 2
Views: 1467

Re: PPPoA with RB2011

Thx. I also have a modem in single user mode (bridged mode) - the Technicolor TG588. On your link I saw that he just added a PPTP-Client. Ithought in single user mode I also need a PPPoA client on my RB2011. Or is the PPPoA connection only necessary when the modem is still in multi user mode? UPDATE...
by onlineuser
Fri Dec 11, 2015 6:29 pm
Forum: General
Topic: Feature request: OpenVPN compression LZO and UDP
Replies: 200
Views: 125998

Re: Feature request: OpenVPN compression LZO and UDP

+1

Yes, come on, please add UDP and compression!
by onlineuser
Fri Dec 11, 2015 6:28 pm
Forum: General
Topic: PPPoA feature request
Replies: 2
Views: 1299

PPPoA feature request

Hello,

please implement the PPPoA client in one of the next firmware releases.

PPP over ATM (RFC2364)
PPP over Ethernet (RFC2516)
IPoA (RFC1577/2225)

Thanks!
by onlineuser
Fri Dec 11, 2015 6:20 pm
Forum: Beginner Basics
Topic: PPPoA with RB2011
Replies: 2
Views: 1467

PPPoA with RB2011

Hello, I have a modem in single user mode and the RB2011 must create a PPPoA connection to my modem - how can I set it up? ADSL (ITU-T G.992.x) > aINTERNET (PPPoA) VDSL (ITU-T G.993.x) > vINTERNET (PPPoE) PPPoE connectiosn are possible with ROS, but I could not find a PPPoA connection in ROS. :-(
by onlineuser
Fri Dec 04, 2015 5:11 pm
Forum: General
Topic: DHCP - WAN interface without DNS addresses
Replies: 6
Views: 1140

Re: DHCP - WAN interface without DNS addresses

Ok, I will contact the support - but this buggy behavior is simple to reproduce.
by onlineuser
Fri Dec 04, 2015 1:18 pm
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 3774

Re: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

Why can the WAN port get an IP address from the DHCP server if there is no traffic allowed? I tried to drop everything on a WAN port but the router can communicate with the DHCP server. I tried it with my provider DHCP server and with an internal DHCP server. If I compare this behavior with an iptab...
by onlineuser
Fri Dec 04, 2015 1:13 pm
Forum: General
Topic: DHCP - WAN interface without DNS addresses
Replies: 6
Views: 1140

Re: DHCP - WAN interface without DNS addresses

Yes, also with 6.33.3.
by onlineuser
Thu Dec 03, 2015 8:22 pm
Forum: Beginner Basics
Topic: Ethernet port only 10Mbit
Replies: 2
Views: 1045

Re: Ethernet port only 10Mbit

Yes, the same device was recognized on port 4 as gigabit device. The interface settings were the same - I double-checked it. Totally strange - I also tried two other cables - same problem. Now, after some shaking, it works - maybe there was some dirt in the jack!? I am happy that the hardware is not...
by onlineuser
Thu Dec 03, 2015 7:00 pm
Forum: Beginner Basics
Topic: Ethernet port only 10Mbit
Replies: 2
Views: 1045

Ethernet port only 10Mbit

Hello,

today I tried to connect the ether 5 port on my 2011 router.

The status says that there is no link - the cable is ok, because on ether 4 port it works.

When I reduce the speed to 10Mbit the ether 5 port works but on 100 or 1000Mbit it gets no link. :-(

What can I do?
by onlineuser
Fri Nov 20, 2015 2:30 pm
Forum: General
Topic: how to translate these rules
Replies: 3
Views: 1281

Re: how to translate these rules

The first and second rule is a default rule but per default there were set 5 rules. 3 ACCEPT gre -- anywhere anywhere 4 REJECT all -- anywhere anywhere reject-with icmp-port-unreachable 5 REJECT tcp -- anywhere anywhere reject-with tcp-reset 6 TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN TC...
by onlineuser
Fri Nov 20, 2015 2:26 pm
Forum: General
Topic: 6.33 - strange packets outgoing
Replies: 13
Views: 2713

Re: 6.33 - strange packets outgoing

Thx, very much! :-)
by onlineuser
Thu Nov 19, 2015 6:29 pm
Forum: General
Topic: 6.33 - strange packets outgoing
Replies: 13
Views: 2713

Re: 6.33 - strange packets outgoing

On my testing router I upgraded to 6.33.1. licensing - fix unneeded connection attempts to 169.254.x.x must be CHR only (introduced in 6.33); This is now solved. :-) Because it was a licensing bug, will the router send any data to any of your servers for checking the registration? What does CHR mean?
by onlineuser
Thu Nov 19, 2015 8:26 am
Forum: General
Topic: how to translate these rules
Replies: 3
Views: 1281

Re: how to translate these rules

noone? :-(
by onlineuser
Mon Nov 16, 2015 11:50 pm
Forum: General
Topic: how to translate these rules
Replies: 3
Views: 1281

how to translate these rules

Hello, I found on my OpenWrt router some default firewall rules. These rules makes sense and are clear how to realize it on ROS. DROP all -- anywhere anywhere state INVALID ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED But how can these rules be realized in ROS and which sense have these...
by onlineuser
Mon Nov 16, 2015 11:30 pm
Forum: General
Topic: using current wan-IP as source address
Replies: 5
Views: 1679

Re: using current wan-IP as source address

ok, thx. :-)
by onlineuser
Mon Nov 16, 2015 11:29 pm
Forum: General
Topic: DHCP keep alive
Replies: 3
Views: 1416

Re: DHCP keep alive

ok, thx. :-)
by onlineuser
Mon Nov 16, 2015 8:11 pm
Forum: General
Topic: using current wan-IP as source address
Replies: 5
Views: 1679

Re: using current wan-IP as source address

You could write a script that checks the WAN IP and updates any rules or address lists if it changes. If your WAN address (almost) never changes, I'd say it's not worth the work. Ok thanks. I thought there is any variable like $WAN I could use and which always points to the current WAN IP. Did anyo...
by onlineuser
Mon Nov 16, 2015 6:55 pm
Forum: General
Topic: DHCP keep alive
Replies: 3
Views: 1416

Re: DHCP keep alive

noone? :-(
by onlineuser
Mon Nov 16, 2015 6:55 pm
Forum: General
Topic: using current wan-IP as source address
Replies: 5
Views: 1679

Re: using current wan-IP as source address

noone? :-(
by onlineuser
Tue Nov 10, 2015 11:21 am
Forum: General
Topic: 6.33 - strange packets outgoing
Replies: 13
Views: 2713

Re: 6.33 - strange packets outgoing

Yes, yesterday I found the graphics. ;-)

The strategy of the 3 ways is good butthis bug is easy to find / detecting should be found by any tester before publication.
This is a bug which can be found without knowing the source code.
by onlineuser
Tue Nov 10, 2015 10:45 am
Forum: General
Topic: 6.33 - strange packets outgoing
Replies: 13
Views: 2713

Re: 6.33 - strange packets outgoing

Thx. Is there any real stable 6.xx firmware available? I think ROS is good but such bugs should not pass the quality management - how long will new releases be tested by your engineers before publication? ;-) P.S. Here the reference link for the hint before: http://forum.mikrotik.com/viewtopic.php?f...
by onlineuser
Mon Nov 09, 2015 10:01 pm
Forum: General
Topic: 6.33 - strange packets outgoing
Replies: 13
Views: 2713

Re: 6.33 - strange packets outgoing

Yes, it seems to be the same problem. How did you sniff the URL which is always treid to open? x.x.x.x - - [09/Nov/2015:00:12:04 +0100] "GET /latest/meta-data/public-keys/0/openssh-key HTTP/1.1" 200 604 "-" "-" x.x.x.x - - [09/Nov/2015:00:12:05 +0100] "GET /latest/...
by onlineuser
Mon Nov 09, 2015 9:25 pm
Forum: General
Topic: 6.33 - strange packets outgoing
Replies: 13
Views: 2713

Re: 6.33 - strange packets outgoing

Yes, but I did not change anything from the 6.32.3 up to 6.33.

But why will the packets out from my public IP to port 169.254.169.254:80?
by onlineuser
Mon Nov 09, 2015 6:19 pm
Forum: General
Topic: 6.33 - strange packets outgoing
Replies: 13
Views: 2713

6.33 - strange packets outgoing

Hello,

since I have upgraded from 6.32.3 to 6.33 the RB wants to send strange packets.
6.33.PNG
Where does this come from?
by onlineuser
Sat Nov 07, 2015 12:40 am
Forum: General
Topic: using current wan-IP as source address
Replies: 5
Views: 1679

using current wan-IP as source address

Hello,

is it possible to set the current wan-IP as source address (or source address list entry) in a firewall rule?
by onlineuser
Fri Nov 06, 2015 10:14 pm
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 3774

Re: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

If everything is blocked an I reboot the router, which requests must go out and which are allowed to come in for getting an IP from the dhcp server? Here is a correct example: http://www.linklogger.com/UDP67_68.htm first dhcp request: UDP 0.0.0.0:68 -> 255.255.255.255:67 UDP dhcp-server:67 -> 255.25...
by onlineuser
Fri Nov 06, 2015 9:03 pm
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 3774

Re: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

It seems that renewing of the IP address (outgoing dhcp request) is allowed when the device had got an IP before. I tried to remove the cable modem and waited 5 minutes - then the RB did not get an IP any longer (I did not change my firewall rules). But it seems that the request to 255.255.255.255 c...
by onlineuser
Fri Nov 06, 2015 3:35 pm
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 3774

Re: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

Yes, I have an outgoing rule with output and drop, so TCP and UDP and all other will be blocked. I have only allowed WinBox port on LAN and on my testing router I have disabled after this rule everything for input, output and forward and the RB2011 gets an IP from the DHCP server. :-( 5 rules: 1) in...
by onlineuser
Thu Nov 05, 2015 5:49 pm
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 3774

Re: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

Yet, I blocked all outgoing traffic, too. I do not understand how the DHCP can be send out, because everything is blocked. :-( I also unchecked the DNS an NTP feature but in the parameter list these two things will be request furthermore. And then the DHCP server also delivers the DNS entries and th...
by onlineuser
Wed Nov 04, 2015 11:12 pm
Forum: General
Topic: no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list
Replies: 7
Views: 3774

no firewall rules for DHCP renewing for WAN interface + DHCP-parameter list

Hello, today I tried to block everything except Winbox port. 1) When I rebooted the RB2011 the WAN port got an IP from the DHCP server. Why is it possible for the WAN port to request an IP (discover to 255.255.255.255) when everything is blocked by firewall rules? The WAN port can enter <requesting>...
by onlineuser
Wed Nov 04, 2015 10:56 am
Forum: General
Topic: established connection but webserver had no entry
Replies: 5
Views: 1601

Re: established connection but webserver had no entry

Yes I also thought to this solution. 1) setting all IP addresses from incoming dst-nat requests to a list 2) set the timout for this list to 60 seconds Is this possible with mikrotik? In dst-nat settings I only can set a limit to max. connections per time but no timeout for this connection. The sett...
by onlineuser
Wed Nov 04, 2015 9:10 am
Forum: Beginner Basics
Topic: RB2011 and USB stick
Replies: 4
Views: 1585

Re: RB2011 and USB stick

You are right - I am also curious for RB3011. :-)
by onlineuser
Tue Nov 03, 2015 6:51 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

thx ;-)
by onlineuser
Tue Nov 03, 2015 6:50 pm
Forum: Beginner Basics
Topic: RB2011 and USB stick
Replies: 4
Views: 1585

Re: RB2011 and USB stick

Ok thx.
The RB3011 will has a USB 3.0 port. The external memory also should be used for the "graphing data".
Webproxy and FTP-server are a nice feature but there are more performance solutions available and should not be integrated on a router. ;-)
by onlineuser
Tue Nov 03, 2015 6:29 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

thx :-(

The saving on external memory would be nice feature!

For what can be the external USB memory used?
by onlineuser
Tue Nov 03, 2015 2:16 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

When I activate the "storing on disk" in Graphing/Interface Rules or Ressource Rules, does the router save the data automatically on the stick instead of the internal memory? I tried to log the interface statistics (without saving to disk). When will the logged data be removed? Although I ...
by onlineuser
Tue Nov 03, 2015 2:13 pm
Forum: Beginner Basics
Topic: RB2011 and USB stick
Replies: 4
Views: 1585

RB2011 and USB stick

Hello, for what could I use a connected USB stick? Which data can be stored on it? When I activate the "storing on disk" in Graphing/Interface Rules or Ressource Rules, does the router save the data automatically on the stick instead of the internal memory? If someone uses the Web Proxy ca...
by onlineuser
Mon Nov 02, 2015 10:34 pm
Forum: General
Topic: established connection but webserver had no entry
Replies: 5
Views: 1601

Re: established connection but webserver had no entry

Today happened the same thing. Request from tor-limits-scanning.cl.cam.ac.uk (128.232.110.28) to port 80 but no data was transferred. The connection stayed established. Would it be possible to put IP addresses from such incoming requests to port 80 to a list which will be automatically removed after...
by onlineuser
Mon Nov 02, 2015 7:23 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

Yeah, these graphs are nice but they need space on the internal file system. When the storing to disk is disabled, will it be saved in memory? graphs.PNG What happens when the memory of my RB2011 gets quite full? When 0.0.0.0/0 has access to the graphs I hope this setting does not override the firew...
by onlineuser
Mon Nov 02, 2015 2:54 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

:-)
by onlineuser
Sun Nov 01, 2015 8:28 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

thx :-)
by onlineuser
Sun Nov 01, 2015 4:44 pm
Forum: General
Topic: established connection but webserver had no entry
Replies: 5
Views: 1601

Re: established connection but webserver had no entry

In Windows the value is dynamic for established conections, though the default for initial connections is 72 seconds. The Registry settings are defined in this article: http://technet.microsoft.com/en-us/library/cc739819(WS.10).aspx HKEY_LOCAL_MACHINE \SYSTEM \CurrentControlSet \Services: \Tcpip \Pa...
by onlineuser
Sun Nov 01, 2015 2:57 pm
Forum: General
Topic: DHCP keep alive
Replies: 3
Views: 1416

DHCP keep alive

Hello, I saw that my provider send me every minute a UDP packet. C | dhcp-server:67 | my_WAN_IP:68 | 17(udp) | 0bps/0bps | 700byte/0byte Does the DHCP server make a lookup if my WAN-port is still alive? Can I affect the time beween two of these packets? The relpying bytes for this incoming connectio...
by onlineuser
Sun Nov 01, 2015 10:41 am
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

I think it takes getting used to. ;-)
by onlineuser
Sun Nov 01, 2015 10:39 am
Forum: General
Topic: Upgrade up to v8
Replies: 4
Views: 1608

Re: Upgrade up to v8

ok, thx. very good! :-)
by onlineuser
Sun Nov 01, 2015 7:48 am
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

Ahhh, it's possible to add the memory, uptime, date, cpu via the WinBox dashboard.

But I am used to have a detailed overview from my DLink DFL firewall. There was one information site on which I could see several relevant data (cpu, connections, bandwidth, and so on).
by onlineuser
Sun Nov 01, 2015 7:44 am
Forum: General
Topic: Upgrade up to v8
Replies: 4
Views: 1608

Re: Upgrade up to v8

Yes, but only up to v8. When v9 will be published we will not get a free upgrade to v9.xx for our devices. On some screenshots I saw the "upgradeable to" field. http://wiki.mikrotik.com/images/thumb/7/7b/2009-05-21_1608.png/703px-2009-05-21_1608.png http://wiki.mikrotik.com/images/7/7c/Lic...
by onlineuser
Sat Oct 31, 2015 9:11 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

Re: utilization of CPU via WinBox

thx :-)

a more detailed profile would be nice ;-)
by onlineuser
Sat Oct 31, 2015 7:51 pm
Forum: General
Topic: Upgrade up to v8
Replies: 4
Views: 1608

Upgrade up to v8

Hello,

I read that Mikrotik routers with license level 5 are upgradeable up to v8 in (near) future.
Is it foreseeable when v8 is reached (beta of v7 seems to be published soon?

It's a shame that we do not get free upgrades for lifetime of the product. :-(
by onlineuser
Fri Oct 30, 2015 7:12 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

Nevertheless a pity that the DFL product line was abandoned. :-(
by onlineuser
Fri Oct 30, 2015 6:38 pm
Forum: General
Topic: utilization of CPU via WinBox
Replies: 18
Views: 3167

utilization of CPU via WinBox

Hello,

is there a way to see the utilization (CPU, memory,...) of my device via WinBox?
by onlineuser
Fri Oct 30, 2015 6:31 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

The DFL products were good products (my DFL-700 ran 11 years).
But the RouterOS has more features and it's better to configure than a OpenWrt based Firewall. ;-)

I only miss the OpenVPN UDP and compression feature in RouterOS. :-(
by onlineuser
Fri Oct 30, 2015 4:44 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

DFL-700 to RB2011UiAS-2HnD-IN

ftp://ftp.dlink.de/@archive/datenblatt/ ... t_engl.pdf

The DFL has problem with Docsis 3.0 cable modem - it only works up to 35Mbps stable - now at 150Mbps downstream I decided to buy a new router. ;-)
by onlineuser
Fri Oct 30, 2015 4:34 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

Yeah, I think the RB2011UiAS-2HnD-IN is a good successor product for the Dlink DFL firewall product.
by onlineuser
Fri Oct 30, 2015 3:31 pm
Forum: General
Topic: established connection but webserver had no entry
Replies: 5
Views: 1601

established connection but webserver had no entry

Hello, today I saw that there was a connection established for about 4 hours but in my webserver-logfile I had no entry from any request from the IP "128.232.110.28". An outgoing connection to this IP is also not allowed - how can it be that this connection was estahblished over such a lon...
by onlineuser
Fri Oct 30, 2015 3:18 pm
Forum: General
Topic: strange file found
Replies: 2
Views: 833

Re: strange file found

Ok, thx.

It seems that when I click to System/License and then to "paste key" (if no key can be pasted because the cache is empty) the file will be created.
by onlineuser
Fri Oct 30, 2015 3:10 pm
Forum: General
Topic: strange file found
Replies: 2
Views: 833

strange file found

Hello,

I found a strange file on my router.

xxxx-xxxx.key with following content:
SoftwareID: KCFM-GF89
-----BEGIN MIKROTIK SOFTWARE KEY------------
...
-----END MIKROTIK SOFTWARE KEY--------------
For what is this file used?

Why was it created?
by onlineuser
Fri Oct 30, 2015 2:34 pm
Forum: General
Topic: how secure (trustable) is mikrotik firmware
Replies: 3
Views: 1253

Re: how secure (trustable) is mikrotik firmware

Yes, no device is 100 percent secure but an independent security-test on routerOS would be nice.
by onlineuser
Fri Oct 30, 2015 2:10 pm
Forum: Beginner Basics
Topic: Port Mapping - Virtual Servers
Replies: 2
Views: 4142

Re: Port Mapping - Virtual Servers

thx, it worked. :-)
by onlineuser
Fri Oct 30, 2015 2:09 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

thx, it worked. :-)
by onlineuser
Thu Oct 29, 2015 9:07 pm
Forum: General
Topic: how secure (trustable) is mikrotik firmware
Replies: 3
Views: 1253

how secure (trustable) is mikrotik firmware

Hello, how secure or trustable is the mikrotik firmware? Because we can't look into the source code I have sometimes small concerns that it could be that there are hidden firewall rules implemented. ;-) Are there some evidences available which shows that there are no backdoors in it (after all for e...
by onlineuser
Thu Oct 29, 2015 8:57 pm
Forum: General
Topic: openvpn client udp
Replies: 2
Views: 1413

Re: openvpn client udp

Thx.
Over most tunnels goes TCP packets and TCP over TCP has an overhead from 30 or more percent. :-(
by onlineuser
Thu Oct 29, 2015 8:56 pm
Forum: Beginner Basics
Topic: port-forwarding for port 80
Replies: 2
Views: 1238

Re: port-forwarding for port 80

Thx for the hints. :-)
by onlineuser
Thu Oct 29, 2015 6:15 pm
Forum: Beginner Basics
Topic: detailed information about WAN DHCP data
Replies: 2
Views: 947

Re: detailed information about WAN DHCP data

Thanks. Is it necessary to divulge the hostname and client-id to the wan dhcp server? The client-id is any MAC-address, this I think is necessary. ;-) Is there any RFC about what is really necessary? If I do not want that the dhcp server sets my local dns entries, can I control this behave by settin...
by onlineuser
Wed Oct 28, 2015 10:26 pm
Forum: General
Topic: firewall/connections - what does the first column mean
Replies: 5
Views: 12116

Re: firewall/connections - what does the first column mean

Thanks - I should use the CLI more than the winbox tool ;-)
by onlineuser
Wed Oct 28, 2015 10:25 pm
Forum: Beginner Basics
Topic: port-forwarding for port 80
Replies: 2
Views: 1238

port-forwarding for port 80

Hello, I have made a port forwarding for port 80 (from wan port to dmz). This works fine. But when I try to open the domain from a lan port (with my public IP in browser or the domain which points to my public IP) the destination nat rule doesn work. Is there any workaround possible that I also can ...
by onlineuser
Tue Oct 27, 2015 5:21 pm
Forum: General
Topic: TCP 80 forwarding for webserver (how relevant are TCP flags)
Replies: 9
Views: 2454

Re: TCP 80 forwarding for webserver (how relevant are TCP flags)

Does noone have some hints for me? :-)
by onlineuser
Tue Oct 27, 2015 5:19 pm
Forum: General
Topic: firewall/connections - what does the first column mean
Replies: 5
Views: 12116

firewall/connections - what does the first column mean

Hi,

what does the first column in firewall/connections site mean - SAC, SACs, A, U?
connections.jpg
by onlineuser
Sun Oct 25, 2015 11:06 am
Forum: General
Topic: openvpn client udp
Replies: 2
Views: 1413

openvpn client udp

Is the mikrotik implementation of openvpn different from the original openvpn?

Why there is no udp protocol available? :-(

Is it planned for one of the next releases?

Moreover, I miss the tap feature - I only found the tun feature in the documentation.
by onlineuser
Sun Oct 25, 2015 11:04 am
Forum: Beginner Basics
Topic: how to solve this ruleset
Replies: 1
Views: 873

Re: how to solve this ruleset

Solved?
Maybe one rule before has an enabled connection type or anything like that so that this rule will not be reached.
by onlineuser
Sat Oct 24, 2015 12:20 am
Forum: General
Topic: DHCP - WAN interface without DNS addresses
Replies: 6
Views: 1140

Re: DHCP - WAN interface without DNS addresses

I disabled "use peer DNS" and "use peer NTP" for DHCLP client for wan-interface but the status page shows the primary and secondary DNS server.
by onlineuser
Fri Oct 23, 2015 11:49 pm
Forum: General
Topic: TCP 80 forwarding for webserver (how relevant are TCP flags)
Replies: 9
Views: 2454

TCP 80 forwarding for webserver (how relevant are TCP flags)

I forwarded port 80 to my DMZ. How relevant is it also to set the TCP flags ACK, SYN, PSH, FIN in firewall rules? First the dst-nat rule is needed. And then a rule from wan to dmz and then a second rule from dmz to wan. How must be the TCP flags set for the two firewall rules that the routing is sec...
by onlineuser
Fri Oct 23, 2015 11:27 pm
Forum: General
Topic: DHCP - WAN interface without DNS addresses
Replies: 6
Views: 1140

DHCP - WAN interface without DNS addresses

Is it possible to say which parameters while DHCP-releasing/renewing is allowed?

I do not need DNS addresses given by the DHCP from my ISP.
by onlineuser
Fri Oct 23, 2015 11:24 pm
Forum: General
Topic: mikrotik tries to call "HOME"
Replies: 4
Views: 1842

Re: mikrotik tries to call "HOME"

Cool, you were faster. :-)
by onlineuser
Fri Oct 23, 2015 11:23 pm
Forum: General
Topic: mikrotik tries to call "HOME"
Replies: 4
Views: 1842

Re: mikrotik tries to call "HOME"

It was the Cloud / NTP Service. ;-)
by onlineuser
Fri Oct 23, 2015 11:08 pm
Forum: General
Topic: mikrotik tries to call "HOME"
Replies: 4
Views: 1842

mikrotik tries to call "HOME"

Why my mikrotik router tries to connect to 81.198.87.240:15252 (udp)?

Can I disable it?
by onlineuser
Fri Oct 23, 2015 4:46 pm
Forum: Beginner Basics
Topic: detailed information about WAN DHCP data
Replies: 2
Views: 947

detailed information about WAN DHCP data

How can I findout detailed information about the DHCP release of the WAN adapter (time to next renewing and so on).
by onlineuser
Wed Oct 21, 2015 1:08 pm
Forum: Beginner Basics
Topic: how to configure firewall rule for 2 target-IPs
Replies: 8
Views: 2954

Re: how to configure firewall rule for 2 target-IPs

Thx.

When I close Winbox the settings of additional colums also will be resetted. :-(

It's a little bit awkward that I must add a destination address list instead of entering two or three IP addresses in destionation IP field. ;-) There the user ability could be improved. ;-)
by onlineuser
Wed Oct 21, 2015 10:59 am
Forum: Beginner Basics
Topic: firewall rules...
Replies: 20
Views: 7437

Re: firewall rules...

So you would just make a rule that says in-interface=ether5 protocol=tcp dst-port=80 action=dst-nat to-addresses={web server internal IP} don't worry about the out interface. If the proxy is explicitly configured in the browsers, then you don't need any nat rules. If you're wanting to redirect peop...
by onlineuser
Tue Oct 20, 2015 11:07 pm
Forum: Beginner Basics
Topic: how to configure firewall rule for 2 target-IPs
Replies: 8
Views: 2954

Re: how to configure firewall rule for 2 target-IPs

Ok, I will try. But when the destionation IP stays blank a first look on all firewall rules doesn't show the destionation IPs because the table only shows the entry of General/destionation IP and not the entries from Advanced/destination address list. :-( There the winbox table also should show more...
by onlineuser
Tue Oct 20, 2015 10:53 pm
Forum: Beginner Basics
Topic: how to configure firewall rule for 2 target-IPs
Replies: 8
Views: 2954

Re: how to configure firewall rule for 2 target-IPs

Why do I need the a address list on Firewall/Address Lists? Is it not enough to to it only in the firewall rule on "Advanced" and then I the General destionation IP stays blank? address_list.png UPDATE: In address list it's not possible to set two or more IP addresses. :-( addresslist.png
by onlineuser
Tue Oct 20, 2015 10:48 pm
Forum: Beginner Basics
Topic: Port Mapping - Virtual Servers
Replies: 2
Views: 4142

Port Mapping - Virtual Servers

Hello, how can I realize a firewall rule as we know it from cheap routers - there it is called port mapping or virtual servers. I need it for runing a webserver behind my router. I want that port 80 and 443 will be forwarded from WAN to DMZ port. With which parameters can I raise the protection of t...
by onlineuser
Tue Oct 20, 2015 10:43 pm
Forum: Beginner Basics
Topic: how to configure firewall rule for 2 target-IPs
Replies: 8
Views: 2954

Re: how to configure firewall rule for 2 target-IPs

Do you mean to create the address list under Firewall rule / Advanced / Destination Address List?

And on Firewall Rule / General the destination IP I leave it blank?
by onlineuser
Tue Oct 20, 2015 10:33 pm
Forum: Beginner Basics
Topic: how to configure firewall rule for 2 target-IPs
Replies: 8
Views: 2954

how to configure firewall rule for 2 target-IPs

Hello,

how can I set via Winbox for one firewall rule two destination IP addresses?

It's possible to set an IP range like xxx.yyy.zzz.10/31 for xxx.yyy.zzz.10 and xxx.yyy.zzz.11 but how does it work for xxx.yyy.zzz.2 and xxx.yyy.zzz.5 for example?

Best Regards
by onlineuser
Fri Oct 16, 2015 11:43 pm
Forum: Beginner Basics
Topic: where does this setting come from?
Replies: 2
Views: 979

Re: where does this setting come from?

No, the problem is that the last three tuple appears in Windows when I connect via cable but the showd MAC comes from the wireless NIC from the mikrotik router which is disabled. I tried to connect a "fresh" laptop which never was connected to the router and then Windows detected the route...
by onlineuser
Fri Oct 16, 2015 10:36 pm
Forum: Beginner Basics
Topic: where does this setting come from?
Replies: 2
Views: 979

where does this setting come from?

When I connect a client to the mikrotik RB2011 I see the router-name "Mikrotik-XXYYZZ" in the network interface overview. The last 3 tuples are the last three from the wireless MAC from the mikrotik router. Under system I set the router name to "test". Moreover, the default ssid ...
by onlineuser
Mon Aug 10, 2015 12:32 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

Do you mean this website?
http://wiki.mikrotik.com/wiki/Manual:Interface/Bridge
But there I can't find any examples for my problem. :-(
by onlineuser
Mon Aug 10, 2015 8:05 am
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

*push*
by onlineuser
Thu Aug 06, 2015 7:35 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

Re: router replacement

This sounds perfectly.

I have a RB2011. Where can I find a tutorial for the bridge mode?

Can I set one of the ports to bridge mode and on the second switch (5 gigabit ports) can I configure the DMZ while the rest works over the old DLink router?
by onlineuser
Thu Aug 06, 2015 12:18 pm
Forum: General
Topic: router replacement
Replies: 15
Views: 2597

router replacement

Hello, I want to replace an old DLink business router with a mikrotik router. On the old one there are a lot of rules (LAN, DMZ1, DMZ2). That the work is not interrupted for long time I thought I connect the new one to the modem and then I connect the old DLink router to the mikrotik. Can I set a ru...