hey i have an issue when some of my clients start tweaking there routers. i have a few that under protest i gave them access to there router. now on 1 hand they have a right since they own it. and they want to manage it. but having issues when they screw it up and want me to fix it . which is fine. ...
andrew thanks for the info. the reason for multiple ip's was for keeping everything straight . ie nat goes thru 64.x.x.2 vpn goes thru 64.x.x.3 had an issue a couple of months ago with p2p grabbing the 1700-1800 ports on our main 64.x.x.2 ip address . so i figured that it would be better to move the...
sorry about that i wasnt thinking very well last night ok ip address on router are 64.x.x.2/26 64.x.x.3/26 64.x.x.4/26 gateway 64.x.x.1 preffered ip 64.x.x.2 now vpn works most of the time ,but only thru the 64.x.x.2 if i try to use 64.x.x.3 it fails with the 619 error i also need to know if there i...
would you recommend putting ip proxy on a rb board . isnt it going to put the router under more usage . or is this ok . i was told that it was not recommend for a using proxy on ?
-------------------------------------------------------------------------------- I am running a couple of 2.8 firewalls, and I have a client PPTP VPN set up. I am able to connect from the outside via a Windows or OS/X PPTP client and get on the network, as well as inside via my WiFi interface. Howev...
serveral people have wroten about this issue . now i know it most like not MT that is at fault but the other router or pc. -------------------------------------------------------------------------------- kchris wrote: Hi! First, I created PPPoE connection, then after disconnection I tried out the PP...
i am going to change out the linsys router that i am having an issue with and see if this fixes the issue. but is there a work around for this or not ?
i have the same issue on this. it works from most other routers to our MT router. but we have a couple of satelite connections that for the life of me wont connect . they do 1 out of 50 times maybe . tryied changing mtu . no luck . i am also getting the same 619 error.
the easiest way to protect your MT from hacks is to only allow two specific internal ip addresses to connect to the router. you can then setup a VPN to the MT , with a different user name an password then the admin user name and password . better security. and much safer MT router
you know i really dont care as much for even dist. as much as being able
to use both gateways in 2.9 i am confused on routing . it isnt the same as in 2.8 .
hello all ok this is strange. i cannot access the router from its outside ip nor its inside ip or mac cannot telnet either but i can from withing another MT mac-telnet to it works . so i removed all firewall rules still nothing any suggestions. Randy it works fine Nat vpn etc. the only reason i noti...
on one of my test MT rc4 does not seem to work well if i use it to bandwith test now i usally just check to make sure they pass traffic with the server fuction. and i know i you are suppose to check thru the MT not to the MT so again i only do this to test the nics on the server. what it does it con...
i may be going in the wrong direction here but . what if any info does the MT pptp server give you at the instint you try to connect. nothing or connection then kicked out? why dont you just brige your wireless with your ether internal . that would fix the issue . and then just hide your ap and requ...
ok one thing to look at on our xp box and on MT settings MT box are you setting user info to default or default-encryp. ? if you are setting the MT to default . you wont get in because XP defaults to encryp. or discon. so try to look at the one of your xp boxes and see if under security it is set th...
why cannot you just give everbody a 255.255.255.252 subnet , this will work in windows and just add this will give you atleast some control of you network . or you could just splite every 5 users by a 248 subnet. doesnt at one point on the ap tx/rx passes thru on ap or another could you limit thrupu...
for the VPN issue on the pptp server side do you see anything from that ip address come in .? also on the wireless side are you tring to use the MT as a bridge or ap ? can you be a little more exact on what you are trying to do i understand your wanting a vpn connection . but again are you trying to...
amd processors have a greater heat output then intel . plus they can have issues of locking up for no reason other then they just wanted to cause you a headache . i had tested some amd processors they do work but are way hotter then a intel so if your using them on a tower forget it . in a controled...
hey all on this subject . we need to replace all our karlnet equipment and want to use MT but we have heavy users on system mostly business clients. 2mb plus per user about 20 user per site . karlnet ap1000 work well most of the time. be testing MT for about 4 months and worried about performance an...
you can create a shortcut to winbox and then edit the short cut to run maximized that does work but yes it would be nice to even creat folders for different groups of MT's for management purposes/
can i make or how do i make a script flush all dhcp pools .
every once in a while some of our MT's dont issue a particular mac a ip address . so if i flush clear all dhcp tables then they will be hand a address again.
looks kool . but how do i get multible networks to work.. i setup 1 dude on a xp pr box on my local net . it main MT router i attached to 2 additional networks . which i can get to thru it for my internal internal network 192.168.4.0/24 MT networks 212.212.212.0.24 192.168.10.0/24 dude can ping them...
why cannot i dst-nat . ok i can but for some reason my test router get pissy when i do this so can someone tell how to do it correctly if i am doind something wrong 0 chain=dstnat dst-address=64.1.1.178 protocol=tcp action=dst-nat to-addresses=212.212.212.11 to-ports=21-23 1 chain=dstnat dst-address...
ok i think his question was if we are not using proxy howto stop smtp relay from happening . or do we just use proxy rule even if we are not using proxy
can i limit what clients are allowed to access my local NTP server would this work. ? or is there a better way to limit NTP traffic. just dont want anyone using our main router except our clients. add protocol=udp src-port=123 action=accept src-address=(client ip address) chain=input then drop every...
ok guys been working with mt for awhile . got everything figured out except how to get a bridge to work thru another unit.. let me explain. and maybe i am just doing incorrectly i can get bridging to work just not at same time as nat on another nic MT Main AP bridge 192.168.10.1/24 from here i can p...
ok guys been working with mt for awhile . got everything figured out except how to get a bridge to work thru another unit.. let me explain. and maybe i am just doing incorrectly i can get bridging to work just not at same time as nat on another nic MT Main AP bridge 192.168.10.1/24 from here i can p...
i am having this issue link is -59 -63 nstream but my issue is ping rates very alot from 5ms to 60ms from ap to station. have asked before no one responds.
the easiest way is to boot from the cf Microsoft Windows XP [Version 5.1.2600] (C) Copyright 1985-2001 Microsoft Corp. C:\Documents and Settings\randy>C:\physdiskwrite.exe C:\2.8.23-install-image.img that is the software name and then just load whichever version . you need to load the image file not...
thats what we use to do with all are karlnet radios or should i say they had a limit of 64 client connection . reggie was working on before they were bought out on a 128 client version dont know what ever happened to it we tested it but it was not stable past 90 clients this was with 2.4 silver card...
what antennas are you runnig at 7miles ? randy 5ghz in general is harder to work with better over all performance . but it is a lot more particular in alignment . you can be a couple of deg. off and it wont work at all. . if your using 24dbi gain antenna 7miles should be a problem . but if it is not...
i am doing this but not from 1 location . we sectors and spilt a area up . you could most likely get maybe 50-100 units per radio . the main reason you cannot have so many people or clients on one radio is thru put lets say you have 50 cpe's going to one radio and lets say your customers are all wit...
are you using sdram or ddr. if ddr what version. one other thing are you using bridging ?\ i was told from MT support that if bridging , not run arp=disable on interface and run arp or proxy-arp from brige. this did seem to fix most of my hard crashes on a few of my systems . they were all the same ...
the only way if your server requires smtp auth. is to grant a bypass filter on your server to that particular email address. i have this setup on my server works fine one thing though make your bypass email address something like mtfailed23400133@mailserver.com just so it a little more secure randy
so do add log after drop . will this log the
ip firewall filter add chain=input action=drop comment="Log everything else"
ip firewall filter add chain=input action=log comment="Log everything else"
how is this specificing just action=drop to be loged?
how do i add action log and another function like passthru in 2.8 you would /ip firewall rule input add action=drop log=yes \ comment="Log and drop everything else" in 2.9 you /ip firewall filter add chain=input action=drop comment="Log and drop everything else" but i want to log...
this is usally a issue with allowing more then 1 vpn . try allowing or adding ipsec passthru to that address. one of the MT gurus should know how to do this.. we have had this issue with our main sdsl router . if we dont allow ipsec pass thru it will drop everything after the first connection . or a...
better but why are there so many high pings what else can i do to improve this Randy Pinging 192.168.10.112 with 32 bytes of data: Reply from 192.168.10.112: bytes=32 time=13ms TTL=63 Reply from 192.168.10.112: bytes=32 time=19ms TTL=63 Reply from 192.168.10.112: bytes=32 time=9ms TTL=63 Reply from ...
ok gota another link that is -68 station -69 ap side . when running nstream works great doesnt drop connection . but get very slow ping rates this is without Nstream running Pinging 192.168.10.112 with 32 bytes of data: Reply from 192.168.10.112: bytes=32 time=6ms TTL=63 Reply from 192.168.10.112: b...
will play with that today , see got another bozo trying to access our system jan/06 17:38:04 system,error,critical login failure for user aron from 62.218.119.62 via ssh jan/06 17:38:07 system,error,critical login failure for user alex from 62.218.119.62 via ssh jan/06 17:38:11 system,error,critical...
tried the code still same issue . i will rebuild the proxy today ,got anothere issue with this same router . wont allow me to connect thru it to a vpn on another MT . left a post in beta i think
hey all i got one of my MT routers being accessed alot by unknown users. in the log file i am getting 21:05:04 system,error,critical login failure for user anonymous from 67.180.99.136 via telnet 21:05:06 system,error,critical login failure for user anonymous from 67.180.99.136 via ftp and alot with...
you know that this is a on going issue now MT will say it the radios . which it is most likely but there still needs to be a better solution . i have this similar issue . the only way i have fixed it is to limit the radio to 6mb only on 5ghz
hello all can MT be used as a radius or is it better to us linux for radius server, we already have a radius server ,but it is on it way out hard drive is failing and where where trying to figure out what to replace it with . could MT just as well be use , it does everything else:) . what is everybo...
add dst-port=80 url=":http://www.srsnetworks.com" action=deny comment="" \ disabled=no i have tried this with and without the add dst-port=80 url="http://www.srsnetworks.com" action=deny comment="" \ disabled=no add dst-port=80 url="http://www.srsnetworks...
no i got a wierd one i can connect to one of our MT's from outside the network. but cannot connect thru another ie-1. xp pro - MT - outside network - MT (vpn PPtp server) wont connect i get kicked out as soon as MT shows my ip address tcp 47 then byebye ie-2. xp-pro - dlink router - outside network ...
why does our new test link keep dropping connection . if i turn off nstream wont drop . but as soon as nstream is on it will drop every couple of min. now the thruput is better with nstream on but cannot have the link going up and down. tryied restricting link to 6mb running 5ghz didnt seem to make ...
i figured it our . what i was doing or not doing was telling my MT to send thru a particual server . . i was not specifing server=ip or server. atleast this fixed the issue. i got anoter question . is it possible to send a secure email . our emailservers require authentication . i bypassed it for my...
is this what you wanted ? # may/10/2005 01:48:26 by RouterOS 2.9rc1 # software id = TZ7Z-31N # / ip web-proxy set enabled=yes src-address=0.0.0.0 port=8080 hostname="proxy" \ transparent-proxy=yes parent-proxy=0.0.0.0:0 \ cache-administrator="webmaster@srsnetworks.net" max-object...
web-proxy issue . i am trying to acces one of our shopping cart systems out side our network. http://www.xyx.com/shop/admin/configuration.php? i set proxy not to catch this page 0 ;;; Our customers src-address=192.168.4.0/24 action=allow 1 ;;; Our customers src-address=212.212.212.0/24 action=allow ...
cannot seem to get this script to work wont run . what is wrong with it ( what did i do incorrectly) :global tmp :global tx :global rx :foreach i in [/interface find] do={/interface monitor-traffic $i once do={:set tx ($sent-bits-per-second/1048576):set rx ($received-bits-per-second/1048576):if ([/s...
my bad wrong script try this one system backup save name=email /tool e-mail send to="valid@email.com" from="valid@email.com" server="64.xx.xxx.x" subject=([/system identity get name] . " " . [/system clock get time] . " " . [/system clock get date] ....
your problem is you need to tell MT what server you want to send your email thru. this is the reason for the error this is your script that i modified :if ([/ping 192.168.0.252 count=5] = 0) do={/tool e-mail send to="MT@somwhere.net" subject="Can't ping 192.168.0.252" server=&quo...
Posted: Fri May 06, 2005 9:37 pm Post subject: email error -------------------------------------------------------------------------------- cannot send email , i keep getting system error error sending email . error connectiing to server what does this mean and how do i correct the issue. the script...
got a stupid question my mail server requires SMTP authentication . how do i send it to the server when i am tring to send a email from MT to my email acount.
we dont use poe for our base units direct dc-dc convertors are used . i figure a 150watts is what we need for a consistant draw. so what is the draw of the 400mw cards ? and what type of cooling system should we use . mild temps. we have had issues with keeping units koolin a 4r case. Cisp was talki...
this is how i have it set and works ip web-proxy> print enabled: yes src-address: 0.0.0.0 port: 8080 hostname: proxy transparent-proxy: yes parent-proxy: 0.0.0.0:0 cache-administrator: webmaster@srsnetworks.net max-object-size: 32000 kB cache-drive: secondary-master max-cache-size: unlimited status:...
hello all ok i have proxy up and working well but . i have a ip address is 64.3.3.x http://www.xyz.com/shop/admin page that from out side my network works fine but from within doesnt work i get Error: Access is Denied this server is outside of my MT network not inside i have tried adding the web to ...
your right however i have over 15 non wireless MT systems running no problem. i have tried everything i can think of . these are all new boards. and new chips . new radios have been dealing with Karlnet for many years . and wanted to move away from them have been testing many different motherboards ...
btw the only reason i posted a q&a about trango is i have serval links that work and am having issues with MT ( again it not there fault as much as it is the CM9 cards fault . i have 5 old pcmcia silver cards running on a couple of links and they work fine . just want to move most of our old Kar...
it is most likely the cards not MT that is causing the issue. MT really needs to find a better wireless solution for there product line. MT works well but for some reason the 5200 series cards are kinda flaky or work well one time and not the next. and again this being your business looks bad on you...
hello this is a on going issue i keep asking about but . why with the cm9 card running in 5ghz does it lock up my system using a dfi-socket 370 mottherboard 1.3ghz chip 128 ram sd cf 128 now this is the funky part if i change the card to run on 2.4ghz i dont seem to have any issues , but as soon as ...
btw the only reason i posted a q&a about trango is i have serval links that work and am having issues with MT ( again it not there fault as much as it is the CM9 cards fault . i have 5 old pcmcia silver cards running on a couple of links and they work fine . just want to move most of our old Kar...
i wish MT would give more detail on updates . and why is it MT does not see that there is a issue with the wireless cards t they are using. i got several trango and airaya radio systems that work great at 5-15 miles but we are having a devel of a time getting solid ping rates from links with MT . i ...
not my money . i have learned alot from this forum and just reading other peoples q&a issues. just sometimes there are questions that i or some people in general .get stuck on and would be nice to help out.
hey all . since alot of q&a goes without a response . is MT better at email support on there service contract. want answers like yesterday on somethings . not that the forum is bad it does answers some selective q&a but allot of the nebee's seem to be ignored . i know alot more now but it wa...
why in the wireless status does my Last ip change to all sorts of i addresses not even on my wireless router. the routers ip is 192.168.2.3/24 the routers wireless ip 192.168.44.2/24 it goes from either or these to outside ip's to other ip's on my wireless network . am i doing something wrong . is t...
hi all ok here is what i want to do . wireless router to wired network wireless P2P to our office with 6 differ clients hooked up hard wired to MT MT router - clients building wlan1 - p2p to our main wPOP 192.168.33.2/24 ether1 - client 1 internal ip 192.168.1.1/24 outside ip address 64.x.x.3 ether2...
i have tried this and it does work. but there was a doc i had found on MT site that used routing and scripts to do this similar to this but had 4 routing tables for the different ip ranges ie 0.0.0.0 lookup x.x.x.0/24 lookup table x y.y.y.0/24 lookup table y t.t.t.0/24 lookup table other something l...
just a question . why is it that btest server taps the processor to 100% ? i am running a 1.3 p3 system ,128mb ram , 128 cf on a dfi socket 370 board running the test on a wireless link for testing on the bench. i get only about 5.0 mb thruput . but what my issue is the processor being tapped to 100...
what is the best way to run multi gateways . the manual show just running the gateway=x.x.x.2,y.y.y.2 way and this does work but switches to offten to keep connections alive is there a howto on a better way using routing and scripts?
hello all is there a need to shield the cm-9 or any radio for that matter in the box that they are housed in.? if so what is the best shielding material to use. to isolate the radios from each other.. reason i ask is I am doing testing on two radios (cm-9) and i know that is is also true for the old...
first of all. if you dont have a wireless card in the MT it cannot setup AP.. 2nd - what are the specific ip addresses you need on the MT you stated nic 1 and nic 2 main ip address. what is your ISP ip address that you are trying to connect to . this is the reason for the UNKNOW interface you stated...
dont know if this is a beta question but. btest working in udp mode but if i connect using tcp it disconects .. what it does is connect the emidiately disconects..
if i try just rx or tx same thing . just wont connect using tcp . what am i doing wrong,,,,]
hello .. i tried this but it failed . the router said it was installing packages then rebooted now just sits there . tried it on the two routers i was test in beta 14 . talked to MT the wanted to know what type of equipment i was running . DFI motherboard 128 sdram with cf card CN9 radio and on boar...
i agree on the EXIT location (should be space out or move down a little) or better yet . just make winbox ask you if you want to exit , think MT could just as easily do that instead of moving it ?
hey guys is there a better performance 5.8 radio that works with MT than the cm-9 just was asking .. looking for a high end radio or is the cm-9 just fine. want the best performance (thru put and connection link quality) for a multi-point radio system with about 30 heavy users per site... thanks Randy
hey all have the same issue . i can get the 5213's to connect in beta 14 but not in 2.8.23 or .24 . in .23 .24 it shows from the station that it can see the ap but will not connect even if it is 2' away with a -23 signal strength . thought it was just me but i then went to beta 14 and every works fine
hello all i need to find a pro that is able to be contacted for assistance .will pay on a per hour basis . i have contacted mt they dont responsed quick enough. i have also contacted eje from wisp-router.com but never got back to me. i need someone who can atleast help when i am stuck or need help. ...
you are correct on the wind gen but i have a wind gen at 3,000 feet gets extremly windy around 70 mph average is around 50. on a 20foot pole . works great . and they have auto release clutch assem. now on most .they also have heating elements for the icy condition though you statement about the radi...
first thing your going to have to due . is find out how much each radio will draw at peak usage . 100 mw radio x 6 plus the poe and router board . i am guessing but , i would figure 500watts would be your min. amount of solar power, you would need . now if you are only having 5 hours of good sun on ...
if you are using a poe from 12-24 volts no problem. just make sure you use a failover system i have 2 systems that run on solar the one thing you want is a lot of battery . the batts we use are around 120.00 each and you have to use 6 volt type due to the load that they take. with six radios i would...
I have gotten this router to work for the most part I just cannot get a few things to work correctly. this is what I have or should I say what I want to work Outside address ether1 nat address ether2 64.173.180.178/32:20-23 (wan-64.173) should goto 212.212.212.11:20-23 tcp (local) 64.173.180.178/32:...
thanks for the info but i got a really dumb a??? . yes i can but just 1 default gateway but how do i then allow the other ip address to go out. if that makes sense/.? ie i have 2 isp connections isp1 64.x.x.3(router ip)/255.255.255.192 gateway is .2 isp2 67.x.x.2(router ip)/255.255.255.128 gateway i...
hey all problem is i can connect to the winbox remotely (outside network) works for about 10 min. the drops connection. then the ip address i was just using will not ping then if i can locate one of the 4 ip's in add to the MT router i can get back in. i removed all rules and just left the 4 ip addr...
hello all got a wierd problem.(2.8.18 version and i have tried this on 3 different motherboards , with with a 333p2 , p4 2.0 cel and a p4 1mb 2.4,with dlink nics and realtek ,also some other brands . so i have done some home work on this! thought it was all me at first . went thru thinking it was th...
like i said when i add the second gw it does work just doesnt let the other telnet sessions work. i am going to try using a different subnet for the servers and see if this makes a difference.
should start a new post i can get everything to work except i cannot seem to get both server to run telnet sessions which ever one starts first (i mean which ever one is highest on the rules seems to start . ) as soon i add the second gateway they stop working the first on will still work . then if ...
also forgot this on the the other server i added i have src nat also setup
/ip firewall src-nat add src-address=192.x.x.2/32 action=nat to-src-address=64.x.x.20
for the second question i posted . i was refering to (not MT connection) i have a server running telnet on the 64.x.x.12 on the fire wan1 connection. works like a charm with out the second gw when i add the second gw it either stops working or takes for ever to get in . once i am in it is ok but i m...
cmit sorry about that i ment gateway=67.x.x.126,64.x.x.2 i was just stating that the subnets were for the ip range. sorry about that as far as the SRC and DST questions i have 67.x.x.10/32 going to 192.x.x.1/32(server on lan) and 67.x.x.11/32 going to 10.x.x.12/32 (server on wirless) these work but ...
also when i add the second gateway to the MT my network connections seems to lag on the inbond telnet sessions. when i remove the second gateway every is very quick. the telnet session will start just takes it about 20-30 secs to start . without the other gw it take 1-2 seconds. this is on both loca...
hello i have 2 gateways that i can get to work just cannot seem to get the nat to work with both of them. fail over would be nice but at this point i would settle for both just working. if i add to the route add 0 gateway=64.x.x2/25,67.x.x.126/29 it works but only for ping. meaning i can ping the pr...
cmit i have read the manual and yes it is very informitive . however either i am just not getting it or something. just have q&a on particular aspect of the router and if you looked at some of my posts they are fairly detailed on the questions. i also was not directing this post at any one . it ...
Why is it that not all Q&A gets answered in this forum . some of us are new
to the firewall configurations and would like some help . i know i am not the
only one that is going un heard ..
looking for a guiding hand in the world of mikrotik
have two networks on separtate nics that i only want to go to the wan connection and not talk to each other . newbie quation. i think ?? have 192.x.x.0 net 10.x.x.0 net wan is 67.x.x.126 dont want 10.x.x0 network talking to 192 net. right now i can ping either way everything is working but really do...
hello i am a newbie gota a dumb ? would like to load balance and failover 3 wan connections wan1 64.x.x.1/25 384/6mb wan2 67.x.x.126/29 2.3mb sdsl wan3 64.x.x.177/26 2.3mb sdsl local network can i have 3 nated networks . i tried it did not work lan1 192.x.x.1/24 local internal nat lan2 10.10.x.1/24 ...