Community discussions

MikroTik App

Search found 8 matches

by basd
Fri Jul 08, 2022 11:05 am
Forum: General
Topic: OVPN UDP time-out after 1 hour
Replies: 10
Views: 2548

Re: OVPN UDP time-out after 1 hour

Connected at 16:21:29 Disconnected at 17:22:14. Just over an hour again. Server logs show: 17:22:13 ovpn,info ovpn-client: terminating... - peer disconnected 17:22:13 ovpn,info ovpn-client: terminating... - peer disconnected 17:22:14 ovpn,info,account client logged out, 3663 150404 11810 1270 184 f...
by basd
Sun May 29, 2022 2:32 pm
Forum: RouterBOARD hardware
Topic: rb 3011 UiAS-RM dead after upgrade to 6.48.6
Replies: 1
Views: 513

rb 3011 UiAS-RM dead after upgrade to 6.48.6

I upgraded to 6.48.6 on my rb 3011 UiAS-RM. The router didn't come back up, the lcd screen is all white I attached a (cisco) console cable to console port on the back tried with 9600 baud 192.200 baud no luck no output. I tried the reset procedure power cable out, press reset button for 30 seconds, ...
by basd
Sun May 01, 2016 2:18 pm
Forum: Announcements
Topic: v6.35.1 [current] is released!
Replies: 84
Views: 36209

Re: v6.35.1 [current] is released!

After the upgrade, i lost my vrrp interfaces ...
But this is fix in the next RC.

But i have problem with my site tot site now , they don't pass ant TCP trafic. UDP and ICMP are working fine.
But TCP not
by basd
Tue Apr 26, 2016 12:44 pm
Forum: General
Topic: Filter DNS any request to our Nameservers
Replies: 7
Views: 2216

Re: Filter DNS any request to our Nameservers

Correct we are running authoritative DNS servers. Your are correct but how to find the source The correct solution in Linux is to set bind to only allow recursive queries from your approved networks: He probably has an authoritative DNS server for a domain running behind a MikroTik router. So it sho...
by basd
Mon Apr 25, 2016 10:26 pm
Forum: General
Topic: Filter DNS any request to our Nameservers
Replies: 7
Views: 2216

Re:

This no solution this way you block all trafic en not only the ANY request .
/ip firewall filter
add action=drop chain=input connection-state=new dst-port=53 in-interface=ether1 protocol=udp
add action=drop chain=input connection-state=new dst-port=53 in-interface=ether1 protocol=tcp
by basd
Mon Apr 25, 2016 9:35 pm
Forum: General
Topic: Filter DNS any request to our Nameservers
Replies: 7
Views: 2216

Filter DNS any request to our Nameservers

I am currently experiancing DDos attacks to our name server. They are using DNS amplifaction attacks to Request any record from our DNS server. On the linux name server's i can filter it like this : $IPTABLES -A INPUT -p udp --dport 53 -m string --hex-string "|00ff|" --algo bm --from 40 -j...
by basd
Wed Dec 02, 2015 2:09 pm
Forum: Announcements
Topic: 6.33.2 version is released!
Replies: 41
Views: 19076

Re: 6.33.2 version is released!

After the upgrade my site to site tunnels stoped working.

I can ping but but thats all.
Can't make http or ssh sesion over the tunnel any more whats wrong ?
by basd
Mon Sep 14, 2015 11:46 am
Forum: Beginner Basics
Topic: Ipv6 firewall
Replies: 0
Views: 839

Ipv6 firewall

Hi all i am newbe here, I have problem getting my IPv6 firewall to work correctly. Wat i want to allow some port inbound for specifik ip addresses, but not else. And i want to grant all inside ipv6 trafic to go out but it doesn't seem to work, THis is my ipv6 firewall config can anyone help ? /ipv6 ...