Community discussions

MikroTik App

Search found 24 matches

by himvas
Thu Jan 16, 2020 12:15 am
Forum: General
Topic: IPSEC+tunnel packet flow
Replies: 3
Views: 672

Re: IPSEC+tunnel packet flow

Thanks. Regrading the log message, "in:" denotes ingress interface, not direction. But the direction is still _in_, as all incoming IP packets that were not bridged or MPLS-switched are hitting prerouting chain. But how can router LOCALY originating packet hit prerouting chain? It should hit RAW OUT...
by himvas
Wed Jan 15, 2020 11:55 pm
Forum: General
Topic: ipsec tunnel only works when both sides send data [SOLVED]
Replies: 10
Views: 1493

Re: ipsec tunnel only works when both sides send data [SOLVED]

May be something with firewall, exactly rule "RELATED, ESTABLISHED"?
Both sides send packets and awaiting reply, so incoming packet is treated as reply.
Also, do you try only ping or some other traffic?
by himvas
Wed Jan 15, 2020 11:45 pm
Forum: General
Topic: Routing traffic to different gateway on remote site
Replies: 1
Views: 417

Re: Routing traffic to different gateway on remote site

You can try add additional address to L2TP on site A (and of course corresponding on site B) and NAT client-b to this address. On site B simple route this address to isp-c.
by himvas
Wed Jan 15, 2020 11:39 pm
Forum: General
Topic: GRE tunnel established, ping ok, but no traffic
Replies: 16
Views: 2895

Re: GRE tunnel established, ping ok, but no traffic

Your firewall stops traffic comming from GRE (GRE in WAN list and not NATed).
by himvas
Wed Jan 15, 2020 11:22 pm
Forum: General
Topic: Mikrotik and CVE-2020-0601
Replies: 4
Views: 1072

Re: Mikrotik and CVE-2020-0601

Not only Win10 but all prev WinNT bases Windows (2000, XP, 7, 8).
by himvas
Wed Jan 15, 2020 11:17 pm
Forum: General
Topic: Set Top Box DHCP Options - HELP
Replies: 3
Views: 2510

Re: Set Top Box DHCP Options - HELP

I suppose it must be TFTP.
by himvas
Wed Jan 15, 2020 11:12 pm
Forum: General
Topic: winbox access port 8291 issue
Replies: 1
Views: 438

Re: winbox access port 8291 issue

Are your Mikrotik and management computer in one broadcast network or routed?
by himvas
Wed Jan 15, 2020 11:05 pm
Forum: General
Topic: IPSEC+tunnel packet flow
Replies: 3
Views: 672

IPSEC+tunnel packet flow

Hello. I have such configuration: Two Mikrotik routers (call them "Router1" and "Router2") with white external IP each. There is IPSEC policy in transport port between them and also IPIP tunnel, so I have interface for dynamic routing and etc. Of course tunnel's interface on both routers have IP fro...
by himvas
Wed Jan 08, 2020 1:10 am
Forum: RouterBOARD hardware
Topic: MT7621 switch chip VALN table
Replies: 1
Views: 2546

MT7621 switch chip VALN table

According https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Introduction MT7621 based devices (hEX, hEX S) don't have VLAN table in switch chip, but MT7621 datasheet http://www.trolink.cn/UploadFiles/Product/20160419152925_77763.pdf indicates: "Supports 4K VLAN entries". Also https://wiki.m...
by himvas
Fri Oct 18, 2019 1:48 pm
Forum: Announcements
Topic: Winbox v3.20 released!
Replies: 42
Views: 25100

Re: Winbox v3.20 released!

When start new winbox (either 32bit or 64bit) I get message: "ERROR: Colud not save conffiguration". If I start with administrative privileges - no such error. Also without administrative privileges I can't connect to router. And with administrative privileges - without problem OS - Windows 7 Prof S...
by himvas
Wed May 16, 2018 1:09 pm
Forum: RouterBOARD hardware
Topic: RB3011UiAS-RM
Replies: 102
Views: 56177

Re: RB3011UiAS-RM

IPsec accelerator (HW acceleration) RB3011UiAS-RM ??? Когда, сколько ждать? When, how long to wait? IPsec accelerator support for RB3011 is still being worked on, the HW acceleration is not yet supported for this model. The CPU is much faster than RB2011 even without HW accelerator. But HW accelera...
by himvas
Fri Apr 13, 2018 4:54 pm
Forum: General
Topic: Firewal rules conditions
Replies: 5
Views: 677

Re: Firewal rules conditions

Ok, The source of question is video from last MUM
https://www.youtube.com/watch?v=nJr77a1rWRI
At 10:53 there is slide with two different rules for established and related states.
by himvas
Fri Apr 13, 2018 12:50 pm
Forum: General
Topic: Firewal rules conditions
Replies: 5
Views: 677

Firewal rules conditions

Hello As I understand in IP Firewall and Mangle conditions for rule to work are combined with "AND" operator. But is is still true for "Connection state" options (established, invalid, new ...)? As I see almost everywhere there are such rules "For NEW packet with some conditions action allow" and "F...
by himvas
Tue Dec 19, 2017 10:41 pm
Forum: General
Topic: IPIP tunnel and filter rules
Replies: 6
Views: 2394

Re: IPIP tunnel and filter rules

Yes. There are several tracked connections (IPsec, IPIP and some kind of "usefull" -ICMP, TCP etc). But it's for case when all is good. But I'm talking about broken IPSec router-to-router connection and moment of establishing IPIP tunnel. So for beginning there are no IPSec now and no IPIP. Then "fi...
by himvas
Tue Dec 19, 2017 5:43 pm
Forum: General
Topic: Firewall Priority and blocking rules
Replies: 1
Views: 740

Re: Firewall Priority and blocking rules

You should create address list with allowed IPs from 10.23.40.0/24 subnet. Then you should first allow access to internet fo this address list and second disable access for all 10.23.40.0/24 subnet. To force wireless clients to use another subnet you should primarily assign address from 10.23.50.0/2...
by himvas
Tue Dec 19, 2017 5:27 pm
Forum: General
Topic: IPIP tunnel and filter rules
Replies: 6
Views: 2394

Re: IPIP tunnel and filter rules

Thanks. Using RAW table helps. Another solution is to move IPSec rules above "established, related" rules.
I don't dig IPSec address subst now, but it also can work.

In any case it's oddly that ROS always treats IPIP packets as "established, related" even when creating tunnel.
by himvas
Mon Dec 18, 2017 6:18 pm
Forum: General
Topic: IPIP tunnel and filter rules
Replies: 6
Views: 2394

IPIP tunnel and filter rules

I need securely connect two routing networks, so I decide to use IPIP tunnel over IPSec running in transport mode between gateways. Also it's needed not to run unencrypted traffic between networks. So I configure IPSec and IPIP tunnel. Also on both gateways I make filter rules to prevent not IPSec t...
by himvas
Tue Dec 05, 2017 10:48 am
Forum: General
Topic: IPSec peer options
Replies: 0
Views: 279

IPSec peer options

Good day.

I don't find in wiki descriptions of following parameters seemed in my RB750GR3 (6.40.5):
"firewall" - maybe it replacement for absent "notrack-chain" ?
"compatibility-options" - only find, that is ignored in ikev2 exchange mode.
by himvas
Tue Aug 29, 2017 3:16 pm
Forum: Wireless Networking
Topic: CAPSMAN Rates
Replies: 1
Views: 2459

CAPSMAN Rates

Hello. In CAPSMAN where is tab "Rates" in which we can configure wifi rates. Also where are tabs "Rates" in "Configurations" and in "CAP interfaces" in which I can select from named rateset configured in "Rates" and also manualy set some rates. How do this settings work together? What takes preceden...
by himvas
Wed Aug 23, 2017 2:17 pm
Forum: General
Topic: IPsec peer "Local Address"
Replies: 2
Views: 1788

Re: IPsec peer "Local Address"

Ok. I missed this because this desc in part for established peer connections. So we can use this field for selecting IP address (for example fro multihome interface)?
by himvas
Tue Aug 22, 2017 7:10 pm
Forum: General
Topic: IPsec peer "Local Address"
Replies: 2
Views: 1788

IPsec peer "Local Address"

What does parameter "Local address" in IPsec/Peer configuration?
Where are no info in wiki.
by himvas
Thu Feb 02, 2017 4:01 pm
Forum: General
Topic: Winbox empty (Resolved)
Replies: 4
Views: 2899

Re: Winbox empty

Problem resolved. Source was in network adapter in my computer. All was fine till today morning, when problem began, I don't know what triggered it - there was no changes for some months. But when I turn off all default turned on offloads for TCP/IP in onboard Realtek based network card problem disa...
by himvas
Thu Feb 02, 2017 9:38 am
Forum: General
Topic: Winbox empty (Resolved)
Replies: 4
Views: 2899

Winbox empty (Resolved)

I have RB3011. It's working fine, but when I connect by Winbox it shows all pages empty (no interfaces, no addresses and so on). For SSH connection I can see all. Also I have some wAPs - WInbox connection for them works fine. I connect to IP address, not MAC. WInbox version 3.10. I deleted 'Mikrotik...
by himvas
Tue Jan 24, 2017 4:52 pm
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 391
Views: 97153

Re: v6.39rc [release candidate] is released

About *) wap-ac - fixed performance problems with 2.4GHz wireless (additional reboot after upgrade required); I have same issue with wAP (RBwAP2nD) - in the same place there are D-Link DAP-2310 and just buyed wAP. I connect from the same device and run iperf. D-Link gives about double speed above wA...