Community discussions

Search found 74 matches

  • 1
  • 2
by steinbergs
Thu Apr 25, 2019 11:51 am
Forum: Beginner Basics
Topic: OpenVPN cert migration to another MikroTik
Replies: 0
Views: 182

OpenVPN cert migration to another MikroTik

Hi. I'm running two CCR1016-12S with identical config (one primary, the other one as a backup). The primary CCR is a OpenVPN server with self signed certs. If the primary fails, the backup MT should take over the OpenVPN server role as well. I, exported all the certificates from primary CCR with pri...
by steinbergs
Fri Mar 22, 2019 4:57 pm
Forum: Beginner Basics
Topic: OpenVPN + iOS
Replies: 0
Views: 242

OpenVPN + iOS

I'm running OVPN on my CCR, Linux, Android and Windows clients can connect to it, but iOS gets error CORE_ERROR mbed TLS: error parsing config private key : PKCS5 - Requested encryption or digest alg not available [ERR] On google the only solution I found was to export the private certificate withou...
by steinbergs
Fri Dec 21, 2018 12:47 pm
Forum: General
Topic: Migrating self signed CA
Replies: 7
Views: 954

Re: Migrating self signed CA

Yes, I tried to restart everything but I get the same error.
I also tried to create new certificates on CCR2 using the CA from CCR1, but no success.
by steinbergs
Fri Dec 21, 2018 12:12 pm
Forum: General
Topic: Migrating self signed CA
Replies: 7
Views: 954

Migrating self signed CA

Hi. I have one CCR1016-12S-1S+ as the primary device and a second CCR1016-12S-1S+ as backup. The primary CCR is also a OVPN server. I want to configure the second CCR to run the backup OVPN server but so that user can authenticate with the self signed certificates I generated on the primary CCR. I c...
by steinbergs
Thu Nov 22, 2018 7:58 pm
Forum: Beginner Basics
Topic: SSL Certificates Date/time Issues
Replies: 1
Views: 441

Re: SSL Certificates Date/time Issues

Hey. I have the same problem. Did You figure it out?
by steinbergs
Thu Nov 22, 2018 3:00 pm
Forum: Beginner Basics
Topic: Mikrotik + OpenSSL CA and CRL
Replies: 0
Views: 407

Mikrotik + OpenSSL CA and CRL

Hi! I generated some certificates in OpenSSL and included the CRL link in them. I used OpenSSL not the Mikrotik self signed, so that I can import the same CA and server cert to multiple mikrotik devices. The certificate works fine, but I cant get CRL to work. The CRL shows up as dinamic / invalid, l...
by steinbergs
Wed Sep 19, 2018 6:50 pm
Forum: Beginner Basics
Topic: CCR stuck on "starting kernel" [SOLVED]
Replies: 7
Views: 1287

Re: CCR stuck on "starting kernel" [SOLVED]

Did you try ether12 for netinstall? And is there any special routerboot setting that would prevent the netinstall? Well, you solved it using serial... at least that is an option on that device. I tried every ether interface. None of them responded to Netinstall. Maybe the Mikrotik Woobm dongle coul...
by steinbergs
Wed Aug 22, 2018 4:03 pm
Forum: Beginner Basics
Topic: CRL for OpenVPN
Replies: 0
Views: 344

CRL for OpenVPN

Hello. I generated OpenSSL CA and user certificates using this tutorial: https://wiki.mikrotik.com/wiki/Manual:Create_Certificates#Generate_certificates_with_OpenSSL Imported them to Mikrotik and configured OpenVPN. Everything works fine except of CRL. I revoked 2 certificates and added the CRL to M...
by steinbergs
Mon Aug 13, 2018 4:30 pm
Forum: Beginner Basics
Topic: CCR Cluster
Replies: 1
Views: 281

CCR Cluster

HI! I recently had problems with my main CCR and after recovering all config I wonder if there is a possibility to run 2 CCR's in a cluster and automagicly sync all config from a master CCR to a slave CCR? Googling got me this: https://mum.mikrotik.com/presentations/AE12/lorenzo.pdf but it isn't qui...
by steinbergs
Fri Aug 10, 2018 5:22 pm
Forum: Beginner Basics
Topic: CCR stuck on "starting kernel" [SOLVED]
Replies: 7
Views: 1287

Re: CCR stuck on "starting kernel" [SOLVED]

The solution was to connect via serial port and upload a new firmware. Connect using ExtraPuTTy. Boudrate:115200 Data bit: 8 Stop bit: 1 Parity: 0 Flow control: RTS/CTS And ExtraPutty has the XModem data transfer option. XModem takes longer than ethernet, but if you have no other option it will do t...
by steinbergs
Thu Aug 09, 2018 6:52 pm
Forum: Beginner Basics
Topic: Storing certificates
Replies: 0
Views: 231

Storing certificates

Hi.
Today my router broke and I had to restore from backup to a different Mikrotik hardware.
Everything works except of the certificates that I generated for OVPN.
How do I properly export and store certificates, so that I can import them to a different router?
by steinbergs
Thu Aug 09, 2018 5:10 pm
Forum: Beginner Basics
Topic: CCR stuck on "starting kernel" [SOLVED]
Replies: 7
Views: 1287

Re: CCR stuck on "starting kernel" [SOLVED]

No, I did not check the serial.
Does it boot on eth1 on an other interface?
by steinbergs
Thu Aug 09, 2018 4:49 pm
Forum: Beginner Basics
Topic: CCR stuck on "starting kernel" [SOLVED]
Replies: 7
Views: 1287

CCR stuck on "starting kernel" [SOLVED]

Hi! After upgrading my CCR-1016-12s-1s+ RM to version 6.42.6 it is stuck on "starting kernel". Net install is not working. Tried the net install setup with a different router, and it works. But this particular router is not showing up in the Netinstall router list. What are the options for me? Is it...
by steinbergs
Fri Jul 27, 2018 10:42 am
Forum: Beginner Basics
Topic: hAP ac^2 no internet while WAN IP is responding to ping
Replies: 0
Views: 243

hAP ac^2 no internet while WAN IP is responding to ping

Hi, I'm having some trouble with my hAP ac^2 RBD52G-5HacD2HnD running RouterOS v6.42.6. From time to time I lose internet connectivity and OpenVPN goes down. When this problem occurs I tried to ping the ISP gateway and my WAN IP from a 4G mobile network and it is responding. LAN connections from my ...
by steinbergs
Fri Jun 08, 2018 8:58 am
Forum: Beginner Basics
Topic: slaveless router
Replies: 3
Views: 598

Re: slaveless router

Your LAN IP is configured on ether2. While port 3-5 are slaves they share ether2's LAN IP. When you remove the slave option ports 3-5 are on their own and do not have a LAN IP.
by steinbergs
Mon Jun 04, 2018 3:58 pm
Forum: Beginner Basics
Topic: Cannot Access VPN from Outside
Replies: 2
Views: 314

Re: Cannot Access VPN from Outside

Can you ping the DNS you try to connect to? If not, check the routers DNS server.
Also are there any firewall rules, that block PPTP input on the HQ Mikrotik?
Is there any firewall on modem 192.168.2.1?
by steinbergs
Wed Apr 25, 2018 10:09 am
Forum: Beginner Basics
Topic: Slow connectivity on OVPN [SOLVED]
Replies: 1
Views: 639

Slow connectivity on OVPN [SOLVED]

Hi. I have a some VPN related problems, maybe someone had something similar. The router is a CCR1016-12s-1s+ running RouterOS v6.41.2. Road warriors are using a OpenVPN connection to the main office. Some apps, that connect to local servers, on the remote PC's are working wary slow and sometimes eve...
by steinbergs
Thu Mar 22, 2018 8:33 am
Forum: Beginner Basics
Topic: IPv6 from LMT.lv
Replies: 6
Views: 634

Re: IPv6 from LMT.lv

pe1chl , if I do not get a IPv6 prefix but only a address from SLAAC, than the one device that gets the address has connectivity but since there is no NAT in IPv6 I can not handle out IP's to my LAN. So if I get a 4G stick and put the SIM card in the 4G stick, connect it to my laptops USB, then the...
by steinbergs
Wed Mar 21, 2018 8:37 pm
Forum: Beginner Basics
Topic: IPv6 from LMT.lv
Replies: 6
Views: 634

Re: IPv6 from LMT.lv

Does it mean that Mikrotik gets the address from SLAAC and does not get a IPv6 prefix to delegate to hosts?
by steinbergs
Wed Mar 21, 2018 8:02 pm
Forum: Beginner Basics
Topic: IPv6 from LMT.lv
Replies: 6
Views: 634

IPv6 from LMT.lv

HI! I got a Mikrotik STX LTE and a SIM card from a local ISP in Latvia. The idea is to test IPv6. I never had any experience with ipv6. The mikrotik device has IPv6 enabled, in the IPv6 ND menu I get a 2003:xxxxxxxxxx::/64 prefix showing up, in IPv6 address lists I see a 2003:xxxxxxxxxxxxxx::/64 pre...
by steinbergs
Mon Mar 19, 2018 2:02 pm
Forum: Beginner Basics
Topic: OVPN v6
Replies: 1
Views: 285

OVPN v6

Hi. I have a OpenVPN server configured on CCR1016-12S-1S+ using IPv4. Some clients can not connect to the OVPN server because they have a IPv6 address. I understand that IPv6 is not backwards compatible and I con not easily access IPv4 OVPN server from a IPv6 network. What would be the best practice...
by steinbergs
Mon Mar 12, 2018 9:32 pm
Forum: Beginner Basics
Topic: 6to4 [SOLVED]
Replies: 1
Views: 702

6to4 [SOLVED]

HI! I have a Mikrotik with a public ipv4 address and a OpenVPN server running in my office. One of the workers who connects to the OpenVPN server has a IPv6 address. I have IPv6 packages enabled, and I followed this guide: https://wiki.mikrotik.com/wiki/Setting_up_an_IPv6_tunnel_via_6to4 I can not c...
by steinbergs
Wed Nov 01, 2017 7:17 pm
Forum: Beginner Basics
Topic: Two WAN
Replies: 5
Views: 534

Re: Two WAN

A simple example:
add action=mark-routing chain=prerouting new-routing-mark=wan2 passthrough=yes src-address=192.168.88.14
add dst-address=0.0.0.0/0 distance=1 gateway=123.123.123.123 routing-mark=wan2
add dst-address=0.0.0.0/0 distance=1 gateway=234.234.234.234
by steinbergs
Fri Oct 20, 2017 9:55 am
Forum: Beginner Basics
Topic: Websites not being blocked/logged?
Replies: 6
Views: 651

Re: Websites not being blocked/logged?

You have to force the proxy on your users browser manualy or with GPO.
Transparent proxy does not work on HTTPS!
by steinbergs
Tue Oct 17, 2017 2:26 pm
Forum: Virtualization
Topic: Which virtualization used instead of VMware Workstation?
Replies: 19
Views: 6559

Re: Which virtualization used instead of VMware Workstation?

I'm using Quemu on my Ubuntu machine to virtualize Mikrotiks for GNS3.
by steinbergs
Wed Sep 13, 2017 8:39 am
Forum: Beginner Basics
Topic: Some ethernet devices won't lease from DHCP ?
Replies: 6
Views: 739

Re: Some ethernet devices won't lease from DHCP ?

Does the linux device have a static IP from the same subnet as Mikrotik?
I see you have 192.168.5.0/24 subnet in mikrotik and 192.168.1.0/24 in your old tplink.
by steinbergs
Tue Sep 05, 2017 10:41 am
Forum: Beginner Basics
Topic: Can't limit wlan
Replies: 4
Views: 682

Re: Can't limit wlan

Look at the "Traffic" tab. Do you see any traffic on this rule?
by steinbergs
Fri Sep 01, 2017 9:17 am
Forum: Beginner Basics
Topic: in SFP1 out SFP2
Replies: 2
Views: 573

in SFP1 out SFP2

Hi! I have CCR1016-12S-1s+ (tile) v6.39.2 with 2 wan ports sfp1 and sfp2. I noticed that when pinging sfp1 IP from a branch office the packages enter SFP1 and try to leave through SFP2. In result I gen a timeout on the ping. Has anyone any idea what could be wrong? There have been no recent modifica...
by steinbergs
Thu Aug 24, 2017 10:36 am
Forum: Beginner Basics
Topic: Web proxy error
Replies: 1
Views: 661

Re: Web proxy error

I think the error occurs because of the special characters in the link. When opening this link: http://visaszales.lv/Aptiekas/ Mago ņ u_aptieka _SIA_Sentor_Farm/1016 I get the error with a modified link: While trying to retrieve the URL http://visaszales.lv/Aptiekas/ Mago %C5%86 u_aptieka _SIA_Sento...
by steinbergs
Thu Aug 24, 2017 10:19 am
Forum: Beginner Basics
Topic: Web proxy error
Replies: 1
Views: 661

Web proxy error

Hi, I'm having a problem with web proxy and one particular web address that users can't access with proxy enabled. Users are getting error: Address family not supported by protocol When I hit refresh in the browser I get the page working. While trying to retrieve the URL http://visaszales.lv/Z%c4%81...
by steinbergs
Wed Aug 16, 2017 11:29 am
Forum: Beginner Basics
Topic: L2TP/IPSec VPN Remote Worker Access
Replies: 11
Views: 10115

Re: L2TP/IPSec VPN Remote Worker Access

When doing traceroute on any internal ip, do the packages travel through the VPN interface?
by steinbergs
Wed Aug 09, 2017 8:46 am
Forum: Beginner Basics
Topic: Isolating networks
Replies: 4
Views: 523

Re: Isolating networks

You can use firewall filters to drop traffic from one subnet to another: /ip firewall filter add action=drop chain=forward src-address=192.168.10.0/24 dst-address=192.168.20.0/24 Create this rule for each subnet. To allow traffic from some wifi users you should bind the users mac to a ip address and...
by steinbergs
Fri Jul 28, 2017 8:33 am
Forum: Beginner Basics
Topic: vpn with isp ddns help.
Replies: 3
Views: 528

Re: vpn with isp ddns help.

now my vpn and laptop can communicate [by seeing data packet on nat] but it stuck on nat and firewall not connect to PPTP server my vpn site say "The remote connection was not made because the name of the remote access server did not resolve" after login i try many way from google did't work please...
by steinbergs
Thu Jul 27, 2017 12:02 pm
Forum: Beginner Basics
Topic: VLAN setup
Replies: 4
Views: 598

Re: VLAN setup

Add only the VLANs to the bridge, not the physical ports on witch the vlan's are configured or else it will create a loop.
by steinbergs
Wed Jul 26, 2017 4:24 pm
Forum: General
Topic: Hot to get Multiple Public IP's on 1 interface?
Replies: 8
Views: 2618

Re: Hot to get Multiple Public IP's on 1 interface?

Thats the option we'll go for it seems...

What will the second cable to? Theres 4 public addresses, can all those be passed by the second cable?
If all DHCP servers bind to a mac address you need to connect one cable from the sw to mikrotik interfaces for each address.
by steinbergs
Wed Jul 26, 2017 2:31 pm
Forum: General
Topic: Hot to get Multiple Public IP's on 1 interface?
Replies: 8
Views: 2618

Re: Hot to get Multiple Public IP's on 1 interface?

How about using a switch?
It could work if you connect a switch to the ISP's cable and link two different cables from sw to mikrotik ports 1 and 2.
by steinbergs
Wed Jul 26, 2017 12:19 pm
Forum: Beginner Basics
Topic: How to block all websites except special website
Replies: 10
Views: 3222

Re: How to block all websites except special website

Thanks normis, what way could I audit SSL traffic? not content of course.
I use GPO to force proxy settings on my users. This way I can use proxy for port 80, 443...
by steinbergs
Wed Jul 26, 2017 7:55 am
Forum: Beginner Basics
Topic: How to block all websites except special website
Replies: 10
Views: 3222

Re: How to block all websites except special website

If you block all except google they can't search anything because you are dropping all searchs.
You could use Web Proxy if it's not HTTPS.
BTW, why can't you block it if to use HTTPS?
I ment: you can't use https on a transparent proxy.
by steinbergs
Wed Jul 26, 2017 7:53 am
Forum: Beginner Basics
Topic: IPs assigned to VPN and LAN IPs cannot see each other
Replies: 4
Views: 493

Re: IPs assigned to VPN and LAN IPs cannot see each other

Do you have any interface related firewall rules?
by steinbergs
Tue Jul 25, 2017 11:28 am
Forum: Beginner Basics
Topic: IPs assigned to VPN and LAN IPs cannot see each other
Replies: 4
Views: 493

Re: IPs assigned to VPN and LAN IPs cannot see each other

Can you ping the router from VPN?
Run traceroute to a LAN ip! Where to the packets go?
by steinbergs
Mon Jul 24, 2017 11:29 am
Forum: Beginner Basics
Topic: How to block all websites except special website
Replies: 10
Views: 3222

Re: How to block all websites except special website

You could use Web Proxy if it's not HTTPS.
by steinbergs
Fri Jul 21, 2017 4:05 pm
Forum: Beginner Basics
Topic: How do I fix this?
Replies: 4
Views: 555

Re: How do I fix this?

I suggest to try to put the backup on a VM and export the configuration to CLI. Then copy it to the newly reset mikrotik bit by bit!
by steinbergs
Fri Jul 21, 2017 2:25 pm
Forum: Beginner Basics
Topic: vlan trunking
Replies: 4
Views: 640

Re: vlan trunking

by steinbergs
Wed Jul 19, 2017 2:01 pm
Forum: Beginner Basics
Topic: Access NATed server from LAN over domainname
Replies: 7
Views: 1869

Re: Access NATed server from LAN over domainname

It does not work for me.
Maybe the problem is, that mikrotik has no public IP. It has only a LAN ip assigned by a 3G gateway!
Port forward is set up on 3G and Mikrotik, still, I cannot access the LAN server from my LAN network through the public IP!
by steinbergs
Tue Jul 18, 2017 8:51 am
Forum: Beginner Basics
Topic: Access NATed server from LAN over domainname
Replies: 7
Views: 1869

Re: Access NATed server from LAN over domainname

Should it work like this?
/ip firewall nat
add chain=src-nat action=src-nat to-address=<your LAN IP, for example 192.168.88.1> src-address=<your lan network, for example 192.168.88.0/24> dst-address=<your WAN IP> out-interface=<your LAN interface, most likely bridge-local>
by steinbergs
Mon Jul 17, 2017 11:11 pm
Forum: Beginner Basics
Topic: Access NATed server from LAN over domainname
Replies: 7
Views: 1869

Access NATed server from LAN over domainname

Hi! I configured dst-nat to my server and I can access it from any network outside my LAN through my domain linked to the public IP. But I can't reach the server from my LAN through domain or WAN IP. I understand the problem is that the server tries to send the package on the shortest path, but the ...
by steinbergs
Mon Jul 17, 2017 4:35 pm
Forum: Beginner Basics
Topic: ICMP Issue
Replies: 5
Views: 516

Re: ICMP Issue

If you want to block incoming ICMP to your MikroTik, than it's a INPUT chain.
Forward chain will block your local servers and desktops from using ICMP.
by steinbergs
Mon Jul 17, 2017 4:00 pm
Forum: Beginner Basics
Topic: Smartphone access?
Replies: 3
Views: 461

Re: Smartphone access?

You can use VPN or buy a static IP from your service provider, in some countries it's possible but expensive.
  • 1
  • 2