Community discussions

Search found 158 matches

by kujo
Tue Oct 09, 2018 8:53 am
Forum: General
Topic: SCEP
Replies: 1
Views: 606

Re: SCEP

For SCEP work you must enable WEB service(IP-service-www)
by kujo
Thu Jan 11, 2018 2:19 pm
Forum: General
Topic: IKE2 no policy found/generated
Replies: 1
Views: 1776

Re: IKE2 no policy found/generated

When we init connection, mikrotik select a proper Selector!
ipsec, init tunnel.JPG
by kujo
Thu Dec 28, 2017 11:11 am
Forum: General
Topic: IKE2 no policy found/generated
Replies: 1
Views: 1776

IKE2 no policy found/generated

Hi bro! I have VPN tunnel in IKE2 mode. Mikrotik CCR1009 v6.40.4 as a server and Windows 10 client! If no packets go through tunnel then Mikrotik drop ph2 dynamic policy from ipsec policy. Time to policy drop ~2h On widows builtin vpn client no error, tunnel still active, but no traffic pass from ro...
by kujo
Wed Dec 20, 2017 10:34 pm
Forum: General
Topic: CCR1009 maxes out at 2gbps?
Replies: 22
Views: 2242

Re: CCR1009 maxes out at 2gbps?

Attach output, please:
/tool profile cpu=all


Yours respectfully!
by kujo
Wed Dec 20, 2017 6:49 pm
Forum: General
Topic: Queue Tree and PCQ
Replies: 6
Views: 547

Re: Queue Tree and PCQ

You mean passthrough=no(not processed in mangle, after this rule)? Or you mean about fastpath(not processed in queue, etc..)?


Yours respectfully!
by kujo
Tue Dec 19, 2017 7:01 pm
Forum: General
Topic: multiple SSTP connections
Replies: 6
Views: 729

Re: multiple SSTP connections

Easy! Attach your scheme!


Yours respectfully!
by kujo
Tue Dec 19, 2017 7:01 pm
Forum: General
Topic: multiple SSTP connections
Replies: 6
Views: 729

Re: multiple SSTP connections

Easy! Attach your scheme!


Yours respectfully!
by kujo
Wed Dec 13, 2017 10:33 pm
Forum: General
Topic: Queue Tree and PCQ
Replies: 6
Views: 547

Re: Queue Tree and PCQ

You mark new connection only once when you mark connection , other work do a connection tracker. Packet mark rule do this on each packets! You can look at mangle rule packets count. Connection tracker at /ip firewall connections


Yours respectfully!
by kujo
Wed Dec 13, 2017 10:33 pm
Forum: General
Topic: Queue Tree and PCQ
Replies: 6
Views: 547

Re: Queue Tree and PCQ

You mark new connection only once when you mark connection , other work do a connection tracker. Packet mark rule do this on each packets! You can look at mangle rule packets count. Connection tracker at /ip firewall connections


Yours respectfully!
by kujo
Wed Dec 13, 2017 7:10 am
Forum: General
Topic: Queue Tree and PCQ
Replies: 6
Views: 547

Re: Queue Tree and PCQ

You need to mark connection only once, at forward chain. Then you mark all packets of this named connection in forward chain. This method mark all upload and download stream. Queue try parent must be: for download-lan(downstream to lan) for upload-wan(downstream to wan) don't use global Like this: 1...
by kujo
Tue Dec 12, 2017 4:23 pm
Forum: General
Topic: PPP L2TP Secrets (/ppp l2tp-secret) - what for?
Replies: 2
Views: 2603

Re: PPP L2TP Secrets (/ppp l2tp-secret) - what for?

It's like a password for l2tp protocol! Like a pre-shared key but not a ipsec!
Anybody know were this option set in Windows l2tp client?
by kujo
Sun Dec 10, 2017 9:53 am
Forum: General
Topic: USB relay
Replies: 6
Views: 1138

Re: USB relay

+1. If we can add some input/output board to mikrotik this would be fantastic!


Yours respectfully!
by kujo
Sun Dec 10, 2017 9:52 am
Forum: General
Topic: USB relay
Replies: 6
Views: 1138

Re: USB relay

+1. If we can add some input/output board to mikrotik this would be fantastic!


Yours respectfully!
by kujo
Sun Dec 10, 2017 9:52 am
Forum: General
Topic: USB relay
Replies: 6
Views: 1138

Re: USB relay

+1. If we can add some input/output board to mikrotik this would be fantastic!


Yours respectfully!
by kujo
Sun Dec 10, 2017 9:51 am
Forum: General
Topic: USB relay
Replies: 6
Views: 1138

Re: USB relay

+1. If we can add some input/output board to mikrotik this would be fantastic!


Yours respectfully!
by kujo
Sat Dec 09, 2017 1:35 pm
Forum: General
Topic: SSTP VPN with Win7 'verify client certificate'
Replies: 11
Views: 5169

Re: SSTP VPN with Win7 'verify client certificate'

Ok! Than only way to use IPsec and eap radius?


Yours respectfully!
by kujo
Sat Dec 09, 2017 8:33 am
Forum: Scripting
Topic: How configure two WANs with same IP
Replies: 2
Views: 941

Re: How configure two WANs with same IP

Try use a bonding method, like LACP or other(need config change for ISP side). Failover from only one ISP its a mistake, maybe. You can add a 3G modem for example for true failover. If you cant do a bonding, you need write a script for interface up/down on some event of connection lost. Yours respec...
by kujo
Fri Dec 08, 2017 2:21 pm
Forum: General
Topic: SSTP VPN with Win7 'verify client certificate'
Replies: 11
Views: 5169

Re: SSTP VPN with Win7 'verify client certificate'

Wrong place to ask.. Contact Microsoft and ask them if such feature will be implemented.
Hi! Can you confirm, that verify-client-certificate is a mikrotik only feature And windows EAP is not a way for make SSTP VPN to mikrotik with cetrificate/tokens?
by kujo
Tue Dec 05, 2017 9:59 pm
Forum: General
Topic: Fasttrack & queue tree non-global queues
Replies: 4
Views: 1580

Fasttrack & queue tree non-global queues

Maybe packets no more mangling? Without packets marks queue don't work? WTF?


Yours respectfully!
by kujo
Sun Dec 03, 2017 5:00 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

I have one sip connection through pppoe and one through ethernet static. NO PROBLEM THERE!


Yours respectfully!
by kujo
Sun Dec 03, 2017 10:46 am
Forum: General
Topic: NAT - Load Balance traffic to be NATed to several destinations
Replies: 3
Views: 335

Re: NAT - Load Balance traffic to be NATed to several destinations

I would do like this: /ip firewall mangle add chain=prerouting action=mark-connection connection-state=new dst-port=80 in-interface-list=WAN\ new-connection-mark=1st_conn_web per-connection-classifier=src-address:3/0 /ip firewall mangle add chain=prerouting action=mark-connection connection-state=ne...
by kujo
Sun Dec 03, 2017 12:27 am
Forum: General
Topic: NAT - Load Balance traffic to be NATed to several destinations
Replies: 3
Views: 335

Re: NAT - Load Balance traffic to be NATed to several destinations

Yes. You can mangle incoming connections in prerouting chain like a PCC style. Than use connection mark in NAT rules for dst-nating to different web servers. Use queue type pcq for limit and balance



Yours respectfully!
by kujo
Thu Nov 30, 2017 10:04 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Turn off connection tracker and check again)


Yours respectfully!
by kujo
Sun Nov 26, 2017 12:56 pm
Forum: Beginner Basics
Topic: Link 2 Mikrotik Routers [SOLVED]
Replies: 8
Views: 659

Re: Link 2 Mikrotik Routers [SOLVED]

Please, add to your schema ip addresses of used nets. Looks like you make a mistake with networks assign!


Yours respectfully!
by kujo
Sun Nov 26, 2017 12:48 pm
Forum: General
Topic: Need to pass VLAN from WAN to LAN [SOLVED]
Replies: 4
Views: 2360

Re: Need to pass VLAN from WAN to LAN [SOLVED]

You can add second ip address to vlan5 on mikrotik and dstnat to lan switch through this ip


Yours respectfully!
by kujo
Sat Nov 25, 2017 7:14 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Yep, if you need hide your public IP use something like this 1.1.1.1, not private pools! Maybe its asterisk sip.config problem? Do you use provider recommend config? And try install bugfix only image on mikrotik


Yours respectfully!
by kujo
Sat Nov 25, 2017 1:35 am
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

NAT table not cleared correctly [SOLVED]

I hope that adsl mobem in bridge mobe(Disable dhcp client on ether1-wan interface ) Print sip connection at now, please


Yours respectfully!
by kujo
Fri Nov 24, 2017 4:27 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Why in routes no pref.source in pppoe default route?
There must be your ext address.
This route is Dynamic. Remove from profile "add default route". Disable pppoe. Add this route manually with pref.source! Enable pppoe
by kujo
Fri Nov 24, 2017 3:20 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

/ppp profile add dns-server=192.168.111.1 local-address=dhcp_ovpn1 name=ovpn remote-address=dhcp_ovpn1 use-encryption=required add change-tcp-mss=yes name=wan /interface pppoe-client add add-default-route=yes disabled=no interface=ether1_wan name=pppoe-telekom profile=wan use-peer-dns=yes user=user...
by kujo
Fri Nov 24, 2017 12:53 pm
Forum: General
Topic: mikrotik ccr and fortigate firewall policy
Replies: 11
Views: 1087

Re: mikrotik ccr and fortigate firewall policy

If you need put a fortigate to WAN side-create a wan bridge. Its may works. Can you put scheme with traffic directions?


Yours respectfully!
by kujo
Fri Nov 24, 2017 12:52 pm
Forum: General
Topic: mikrotik ccr and fortigate firewall policy
Replies: 11
Views: 1087

Re: mikrotik ccr and fortigate firewall policy

If you need put a fortigate to WAN side-create a wan bridge. Its may works. Can you put scheme with traffic directions?


Yours respectfully!
by kujo
Fri Nov 24, 2017 12:44 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

NAT table not cleared correctly [SOLVED]

You can also export compact, without sensitive info, your config and put here...


Yours respectfully!
by kujo
Fri Nov 24, 2017 12:39 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Packet sniffer on mikrotik can view all packets to the wan interface(before nat and after nat! No packets no SIP service))) Try change mikrotik to the ... dlink, still problem occur?


Yours respectfully!
by kujo
Fri Nov 24, 2017 9:29 am
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

NAT table not cleared correctly [SOLVED]

My friend, i'am work with two SIP provider simultaneously without any problem(one asterisk server with different external IP address nated through mikrotik). If your router don't receive any packets from provider of SIP, where you mean problem occur?


Yours respectfully!
by kujo
Thu Nov 23, 2017 9:45 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Try open a ticket in support system of tour SIP provider. If provider don't send to you SIP responses it means, that problem not at router point view!


Yours respectfully!
by kujo
Thu Nov 23, 2017 9:36 pm
Forum: General
Topic: mikrotik ccr and fortigate firewall policy
Replies: 11
Views: 1087

mikrotik ccr and fortigate firewall policy

Maybe you need create a bridge on ccr, then add a wan port of provider and wan port of fortigate uplink, then you only assign needed external addr to fortigate? But, if you create a bridge, then all ip config need be at bridge interface, not at physical port.


Yours respectfully!
by kujo
Thu Nov 23, 2017 3:32 pm
Forum: General
Topic: mikrotik ccr and fortigate firewall policy
Replies: 11
Views: 1087

Re: mikrotik ccr and fortigate firewall policy

You can mangle new gateway IP


Yours respectfully!
by kujo
Thu Nov 23, 2017 1:35 pm
Forum: General
Topic: mikrotik ccr and fortigate firewall policy
Replies: 11
Views: 1087

Re: mikrotik ccr and fortigate firewall policy

You can move traffic by mangle in any needed gateway. Can you?


Yours respectfully!
by kujo
Thu Nov 23, 2017 12:05 am
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Response packet from SIP provider arrive to Wan interface?
by kujo
Thu Nov 23, 2017 12:01 am
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Response packet arrive to Wan interface?


Yours respectfully!
by kujo
Wed Nov 22, 2017 11:57 pm
Forum: General
Topic: mikrotik ccr and fortigate firewall policy
Replies: 11
Views: 1087

Re: mikrotik ccr and fortigate firewall policy

Hi! Can you attach a scheme of your net and your plan?


Yours respectfully!
by kujo
Wed Nov 22, 2017 5:23 pm
Forum: Forwarding Protocols
Topic: How to redistribute bandwidth to my secondary mikrotik with static route and two bgp dyanamic route route
Replies: 1
Views: 334

Re: How to redistribute bandwidth to my secondary mikrotik with static route and two bgp dyanamic route route

Create vlan4 on main, set address from pool 148.66.66.0/29. Create vlan4 at satellite, assign another addr from pool(66.3). On main mark all connection to this vlan(by mac or ip), then mark packets. Create on main queue for downstream to satellite, set to max 5m. In mangle route this packets to 148....
by kujo
Wed Nov 22, 2017 3:56 pm
Forum: General
Topic: CCR health monitoring
Replies: 1
Views: 346

Re: CCR health monitoring

We have a big trouble when disk space is over! Monitor this parameter!


Yours respectfully!
by kujo
Wed Nov 22, 2017 11:36 am
Forum: Beginner Basics
Topic: Cisco ASA change to CCR1072
Replies: 6
Views: 805

Re: Cisco ASA change to CCR1072

Yep... HA its also bgp, few isp... etc. Any device spend cpu to firewall rule processing! But mikrotik is not a security appliance with antivirus, thread detectors, etc...


Yours respectfully!
by kujo
Wed Nov 22, 2017 11:25 am
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

NAT table not cleared correctly [SOLVED]

Stefan, can you start packet sniffer at mikrotik router? /tool packet sniffer


Yours respectfully!
by kujo
Wed Nov 22, 2017 7:48 am
Forum: Beginner Basics
Topic: Cisco ASA change to CCR1072
Replies: 6
Views: 805

Re: Cisco ASA change to CCR1072

Cisco ASAP is a firewall and ccr is a router. Not the same type of product. ROS does have a firewall and can be used but is not built to be a firewall. I use ROS at home as both firewall and router but would not do so at work. I personally like Pfsense a lot. They also have some great appliances an...
by kujo
Wed Nov 22, 2017 7:28 am
Forum: General
Topic: A summary about performance queue tree in CCR for medium-large cases
Replies: 4
Views: 816

Re: A summary about performance queue tree in CCR for medium-large cases

Any feedback from support?


Yours respectfully!
by kujo
Wed Nov 22, 2017 7:24 am
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

NAT table not cleared correctly [SOLVED]

Ok. There are all good in ip firewall. Try turn on packet sniffer on all interface and udp and port 5060. How the packers arrive? Look at connection tracker when you make outgoing call. Look at asterisk console, 'sip show peers', and calls log. You also can turn on debug on specific sip channel! You...
by kujo
Tue Nov 21, 2017 3:44 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Ok. Can you past /ip firewall nat export compact?


Yours respectfully!
by kujo
Tue Nov 21, 2017 3:44 pm
Forum: General
Topic: NAT table not cleared correctly [SOLVED]
Replies: 77
Views: 6437

Re: NAT table not cleared correctly [SOLVED]

Ok. Can you past /ip firewall nat export compact?


Yours respectfully!