Community discussions

MikroTik App

Search found 45 matches

by Fesiitis
Tue Jan 16, 2024 2:38 pm
Forum: General
Topic: User poll about using Winbox
Replies: 102
Views: 76501

Re: User poll about using Winbox

1. Yes, regularly. I use them to save window and column layouts for different routers. 2. I've always thought of sessions as an opportunity to personalize windows and columns to your liking. 3. If sessions could be managed from the Winbox GUI. If I want to use one session for another router, I copy ...
by Fesiitis
Tue Jun 13, 2023 11:45 pm
Forum: Beginner Basics
Topic: NAT hairpinning
Replies: 7
Views: 2175

Re: NAT hairpinning

Here is a good video from Mikrotik on this topic - https://www.youtube.com/watch?v=1I5FywY6opQ
by Fesiitis
Wed Jun 07, 2023 6:42 pm
Forum: General
Topic: Many "payload missing: SA" & "payload missing: NONCE" on 7.9
Replies: 11
Views: 5399

Re: Many "payload missing: SA" & "payload missing: NONCE" on 7.9

I'm also seeing a bunch of errors like these for the last few days on all routers that have IPsec configured. payloadmissing.PNG I think these are new entries on top of the existing ones ( identity not found for peer: FQDN: *something* and identity not found for peer: RFC822: research-scan@sysnet.uc...
by Fesiitis
Tue Sep 13, 2022 9:08 pm
Forum: General
Topic: IKEV2 - problem to connect - identity not found for peer
Replies: 20
Views: 10125

Re: IKEV2 - problem to connect - identity not found for peer

Maybe the method I use for iOS will be useful for someone. Create certificates: /certificate add common-name=XX.XX.XX.XX name=XX.XX.XX.XX sign "XX.XX.XX.XX" ca-crl-host=<router local IP> add common-name=XX.XX.XX.XX subject-alt-name=IP:XX.XX.XX.XX key-usage=tls-server name="IKE2 RSA se...
by Fesiitis
Fri Aug 26, 2022 6:40 pm
Forum: Wireless Networking
Topic: cAP ac 5 GHz upload speed is much slower than download speed
Replies: 11
Views: 2756

Re: cAP ac 5 GHz upload speed is much slower than download speed

So disabling this, to get full speed upload, even without reboot. ??? Yes, I watched one video about the "FastTrack" rule that also explained the cases when it is better to disable it. So, out of interest, I disabled it and ran a speed test without restarting router. And it looks like thi...
by Fesiitis
Thu Aug 25, 2022 2:10 am
Forum: Wireless Networking
Topic: cAP ac 5 GHz upload speed is much slower than download speed
Replies: 11
Views: 2756

Re: cAP ac 5 GHz upload speed is much slower than download speed

Just to let you know, if anyone else has had a similar situation, I discovered the cause of the problem quite by accident, it's the "fasttrack-connection" firewall rule. After I disabled this rule, the 5GHz upload speed "skyrocketed". Even if I disable the "fasttrack-connect...
by Fesiitis
Sun Aug 14, 2022 5:16 am
Forum: General
Topic: RB760iGS on ROSv7 cannot access IPsec resources from road warrior VPN
Replies: 0
Views: 463

RB760iGS on ROSv7 cannot access IPsec resources from road warrior VPN

Hi, After upgrading hEX S (RB760iGS) to ROSv7, I can no longer access resources behind IPsec tunnels from IKEv2 RSA road warrior VPN. It was possible on ROSv6. I have tried reseting the hEX S router to default settings on ROSv7 and configuring it for my needs from sratch but no change. If I downgrad...
by Fesiitis
Sat May 07, 2022 4:33 pm
Forum: Wireless Networking
Topic: cAP ac 5 GHz upload speed is much slower than download speed
Replies: 11
Views: 2756

Re: cAP ac 5 GHz upload speed is much slower than download speed

Ca6ko, unfortunately does not help, the same results as in the first post.

bpwl, thanks for the detailed explanation. Here is a picture showing the HW Frames and Frames columns, looks like Tx HW Frames and Tx Frames are quite different after three speedtest attempts.
frames.PNG
by Fesiitis
Wed May 04, 2022 3:32 pm
Forum: RouterOS beta
Topic: arp-ping not working on RouterOS v7 [SOLVED]
Replies: 26
Views: 12012

Re: arp-ping not working on RouterOS v7 [SOLVED]

I'm not really sure if it's related, but yesterday I upgraded hEX S from v6.49.6 to v7.2.3 and I was no longer able to connect to IPsec resources from the Road-Warrior VPN. Using IKEv2 with RSA authentication, I can connect to resources on the local network, but not to resources behind other IPsec t...
by Fesiitis
Wed May 04, 2022 3:12 pm
Forum: Wireless Networking
Topic: cAP ac 5 GHz upload speed is much slower than download speed
Replies: 11
Views: 2756

Re: cAP ac 5 GHz upload speed is much slower than download speed

Sorry for the late reply. Here are three results: When downloading whendownloading.PNG When uploading whenuploading.PNG When idle whenidle.PNG At the moment, I don't have a long enough RJ45 cable in my home to connect my router to my desktop so that I can test the speed with a cable. However, the la...
by Fesiitis
Sat Apr 16, 2022 5:38 pm
Forum: Wireless Networking
Topic: cAP ac 5 GHz upload speed is much slower than download speed
Replies: 11
Views: 2756

cAP ac 5 GHz upload speed is much slower than download speed

Hi, I have been using cAP ac for several years now. And since day one I have noticed that the 5 GHz upload speed is much slower than the download speed. I don't use 2.4 GHz at all so I haven't tested the difference between upload and download speeds with 2.4 GHz. And I use cAP ac only as 5 GHz wirel...
by Fesiitis
Wed Mar 30, 2022 1:27 am
Forum: General
Topic: Find out which certificate was used for the new ike2 SA (R)
Replies: 4
Views: 733

Re: Find out which certificate was used for the new ike2 SA (R)

Thanks, sindy! I did a couple of tests on my home router last weekend. I'm not entirely sure if it's really necessary to set crl-download to yes in my case, but after I set crl-use to yes and performed the following configuration, I was able to make the router to recognize if the certificate has rev...
by Fesiitis
Sun Mar 13, 2022 5:51 pm
Forum: General
Topic: Find out which certificate was used for the new ike2 SA (R)
Replies: 4
Views: 733

Re: Find out which certificate was used for the new ike2 SA (R)

By revoked certificates I meant client certificates, because they can't be simply deleted. When the employee leaves the company, they no longer need the VPN. And yes, for all the identities I use match-by=certificate , so I always remove the identities that were associated with revoked certificates....
by Fesiitis
Sat Mar 12, 2022 6:59 pm
Forum: General
Topic: Find out which certificate was used for the new ike2 SA (R)
Replies: 4
Views: 733

Find out which certificate was used for the new ike2 SA (R)

Hi, For a pretty long time our office router has a working IKE2 RSA VPN. No problems so far, but there are currently a few revoked certificates in the router. The identities for these certificates have already been removed. For a couple of days now I see the following entries in the router logs. Is ...
by Fesiitis
Mon Nov 15, 2021 11:59 am
Forum: RouterOS beta
Topic: v7.1rc6 [development] is released!
Replies: 145
Views: 56751

Re: v7.1rc6 [development] is released!

Since v7.1rc5 on RB5009, I experience weird issue where router at some point is unable to access to internet anymore. No error logs, no nothing. I can access to router, but there's nothing I can do there. I have to restart the router to get access to internet again. I thought problem is related to I...
by Fesiitis
Wed Oct 27, 2021 2:07 am
Forum: RouterOS beta
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 49195

Re: v7.1rc5 [development] is released!

Upgraded from v7.1rc4 to rc5 on RB5009, rebooted and I can't connect to VPN based on IKEv2 with RSA authentication anymore. Windows 10 gives an error "The error code returned on failure is 13816". Haven't tried with macOS. If that fails too, looks like I will have to visit a client in offi...
by Fesiitis
Tue Mar 02, 2021 11:22 am
Forum: General
Topic: IPSec Site to Site tunnel after netmap subnet does not work
Replies: 3
Views: 957

Re: IPSec Site to Site tunnel after netmap subnet does not work

I have similar situation between two networks. I have site-to-site VPN between 10.0.0.0/24 and 10.95.0.150. In my case I only need different source address when connecting to destinations 80 and 443 port, so I have created NAT rule that changes source IP to 10.0.25.x when connecting to 10.95.0.150:8...
by Fesiitis
Sat Feb 13, 2021 3:38 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 6
Views: 6149

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

I think Windows 10 built-in VPN client still doesn't understand sha256 when doing phase 2 and modp2048 when doing phase 1. Change or add profiles dh-group to modp1024 and proposals auth-algorithms to sha1. I haven't tested it for myself, but you should try this.
by Fesiitis
Fri Jul 03, 2020 11:25 pm
Forum: General
Topic: Two Audiences as AP bridges and Mesh [SOLVED]
Replies: 1
Views: 2928

Re: Two Audiences as AP bridges and Mesh [SOLVED]

I figured out by myself. After configuring second Audience as repeater, I had to manually change some settings for wlan3. Then repeater successfully connected to main Audience. Firstly I configured both Audiences almost identically, only frequency differed - /interface bridge add name=bridge1 /inter...
by Fesiitis
Fri Jul 03, 2020 12:56 am
Forum: General
Topic: Two Audiences as AP bridges and Mesh [SOLVED]
Replies: 1
Views: 2928

Two Audiences as AP bridges and Mesh [SOLVED]

Hi! I bought two Audiences to replace my old wi-fi setup. The main idea is to configure both Audiences as AP bridges. One of them will be connected to router. Also I want configure both Audiences for mesh networking. It should look like this - https://i.imgur.com/42l4JQJ.png As I have never configur...
by Fesiitis
Thu Jul 02, 2020 12:27 pm
Forum: General
Topic: Audience default config
Replies: 1
Views: 1657

Audience default config

I just bought one and decided to share default config for everyone interested in it. # jan/02/1970 00:01:55 by RouterOS 6.45.4 # software id = XXXX-XXXX # # model = RBD25G-5HPacQD2HPnD # serial number = XXXXXXXXXXXX /caps-man configuration add channel.band=2ghz-b/g/n channel.control-channel-width=20...
by Fesiitis
Tue Apr 14, 2020 6:42 pm
Forum: RouterBOARD hardware
Topic: PoE Injectors
Replies: 5
Views: 3018

Re: PoE Injectors

@Paternot, I got your idea, but I don't have any plans for using second ethernet port, maybe in future. Currently I'm using only wi-fi.
 
The point is U-POE-AF from Ubiquiti would fit perfectly in my current situation. So I would be happy to see similar PoE devices from Mikrotik as well.
by Fesiitis
Tue Apr 14, 2020 6:03 pm
Forum: RouterBOARD hardware
Topic: PoE Injectors
Replies: 5
Views: 3018

Re: PoE Injectors

This is my situation. There is no way RBGPOE can help without any switch or something between incoming LAN cable from ISP and my router. https://i.imgur.com/3DItBBC.jpg I'm planning to replace my current wAP with new cAP ac, and I have to figure out how to power it.   Why don’t you add a female-to-f...
by Fesiitis
Tue Apr 14, 2020 4:03 pm
Forum: RouterBOARD hardware
Topic: PoE Injectors
Replies: 5
Views: 3018

PoE Injectors

Hi, Does Mikrotik has any plans in future for PoE Injectors similar like Ubiquiti has? For example this one - https://store.ui.com/collections/operator-accessories/products/u-poe-af RBGPOE does not fit my needs, because in my apartment the ISP has only provided incoming LAN cable without any switche...
by Fesiitis
Wed Nov 27, 2019 1:26 pm
Forum: General
Topic: Azure VPN [SOLVED]
Replies: 12
Views: 63240

Re: Azure VPN [SOLVED]

You can follow this guide how to create a Site-to-Site connection in the Azure portal - https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-site-to-site-resource-manager-portal And there is my Mikrotik configuration, including full firewall configuration. Just replace your public IP...
by Fesiitis
Fri Nov 22, 2019 3:45 pm
Forum: General
Topic: Can't access router after establishing IPsec tunnel to it
Replies: 11
Views: 3778

Re: Can't access router after establishing IPsec tunnel to it

You have to add additional input rule on both sides -
add action=accept chain=input comment="IPsec allow access to router" \
    dst-address=<site1-router-ip> in-interface-list=WAN ipsec-policy=in,ipsec \
    src-address=<site2-subnet>
by Fesiitis
Wed Nov 13, 2019 10:26 am
Forum: General
Topic: IPsec IKE2 can find valid sertificate [SOLVED]
Replies: 13
Views: 9733

Re: IPsec IKE2 can find valid sertificate [SOLVED]

These are steps I did - 1. Create CA /certificate add common-name=XX.XX.XX.XX name=XX.XX.XX.XX sign "XX.XX.XX.XX" ca-crl-host=XX.XX.XX.XX 2. Create server certificate add common-name=XX.XX.XX.XX subject-alt-name=IP:XX.XX.XX.XX key-usage=tls-server name="IKE2 RSA server" sign &quo...
by Fesiitis
Mon Nov 11, 2019 9:41 pm
Forum: General
Topic: IKE2 RSA Road Warrior connected, but can't access to LAN [SOLVED]
Replies: 2
Views: 2681

Re: IKE2 RSA Road Warrior connected, but can't access to LAN [SOLVED]

Thank you for the detailed explanation! ;) I just changed IP pool to different addresses and it works now. :D Previously I had PPTP enabled with 10.0.0.71-10.0.0.80 in IP pool and proxy-arp was already enabled on bridge interface, so I thought something is wrong with firewall rules. But your post ga...
by Fesiitis
Mon Nov 11, 2019 4:41 pm
Forum: General
Topic: IKE2 RSA Road Warrior connected, but can't access to LAN [SOLVED]
Replies: 2
Views: 2681

IKE2 RSA Road Warrior connected, but can't access to LAN [SOLVED]

Hi! This is first time I have ever configured IKE2 RSA Road Warrior, I followed this tutorial - https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_using_IKEv2_with_RSA_authentication Current DHCP for LAN - 10.0.0.10-10.0.0.70 I have two site-to-site IPsec tunnels configured as well - ...
by Fesiitis
Tue Oct 29, 2019 12:27 pm
Forum: General
Topic: IKE2 EAP as responder
Replies: 1
Views: 1065

IKE2 EAP as responder

Does Mikrotik has any plans for this feature? Support for EAP authentication methods as initiator was added back in 6.45.1 update. I would like to know whether this feature will be added sooner or later or not at all.
by Fesiitis
Thu Oct 03, 2019 5:28 pm
Forum: General
Topic: Azure Site-to-Site VPN using Mikrotik, cant access private IP from. Traffic flows only from Azure to Onprem [SOLVED]
Replies: 8
Views: 7357

Re: Azure Site-to-Site VPN using Mikrotik, cant access private IP from. Traffic flows only from Azure to Onprem [SOLVED]

No, BGP should be configured only if you only really needs it. Also there's no need for additional Routes from Azure side. With default NSG rules, Azure should allow IPsec traffic for both sides.
by Fesiitis
Thu Oct 03, 2019 5:08 pm
Forum: General
Topic: Azure Site-to-Site VPN using Mikrotik, cant access private IP from. Traffic flows only from Azure to Onprem [SOLVED]
Replies: 8
Views: 7357

Re: Azure Site-to-Site VPN using Mikrotik, cant access private IP from. Traffic flows only from Azure to Onprem [SOLVED]

First srcnat rule is not meant to allow Azure to On-Premise traffic, it is for On-Premise to Azure. Basically with that srcnat, mangle rule and these default fw rules you should be able to access Azure from On-Premise and vice versa. I have many IPsec tunnels created from Mikrotik to Azure that way ...
by Fesiitis
Thu Oct 03, 2019 1:10 pm
Forum: General
Topic: Azure Site-to-Site VPN using Mikrotik, cant access private IP from. Traffic flows only from Azure to Onprem [SOLVED]
Replies: 8
Views: 7357

Re: Azure Site-to-Site VPN using Mikrotik, cant access private IP from. Traffic flows only from Azure to Onprem [SOLVED]

You have to add additional NAT rule to access Azure from On-Premise - /ip firewall nat add action=accept chain=srcnat comment="Azure" dst-address=\ azure-subnet/24 src-address=onprem-subnet/24 Also Azure suggests to clamp TCP MSS at 1350, so you should set this value by adding additional M...
by Fesiitis
Thu Sep 26, 2019 12:04 am
Forum: General
Topic: VLANs for wifi and guest on router as AP
Replies: 2
Views: 3233

VLANs for wifi and guest on router as AP

I'm pretty new on VLAN's, never had any needs to configure it before, so basically this is first time I'm doing it. Here you can see how I would like to see network for wifi for employees and guests - https://i.imgur.com/1MukyEr.png On cAP ac has no any specific configuration yet, it's basically fre...
by Fesiitis
Tue Sep 17, 2019 2:32 pm
Forum: General
Topic: Disk space problem [SOLVED]
Replies: 4
Views: 2873

Re: Disk space problem [SOLVED]

This router has only 16 MB of storage size. I have RBwAP2nD and RB760iGS as well. On RBwAP2nD I had upgrade problems just because of storage size. And I solved this by getting rid of unwanted packages. Go to System > Packages and uninstall packages you don't use. Now on both routers I have only thes...
by Fesiitis
Thu Sep 12, 2019 2:08 pm
Forum: General
Topic: L2TP/IPSec VPN can access LAN but not Router [SOLVED]
Replies: 12
Views: 11443

Re: L2TP/IPSec VPN can access LAN but not Router [SOLVED]

Thanks for reply. This works. Next time I will post configuration as a text, thanks for suggestion. ;)
by Fesiitis
Thu Sep 12, 2019 1:34 pm
Forum: General
Topic: L2TP/IPSec VPN can access LAN but not Router [SOLVED]
Replies: 12
Views: 11443

Re: L2TP/IPSec VPN can access LAN but not Router [SOLVED]

I found this topic, because I have a same issue the OP had. Except I don't have L2TP/IPsec VPN, but IKE2 IPsec configured. And changing from !LAN to WAN does not fix issue, I can't access to router from any device on 10.12.14.0/24 network at all. If I disable that default "not from LAN" ru...
by Fesiitis
Thu Aug 15, 2019 7:24 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639523

Re: Feature requests

I'm waiting for ike2 support for eap as responder. Hope this feature will be added soon, since support for this as initiator was added in v6.45.1 update.
by Fesiitis
Wed Jul 03, 2019 5:12 pm
Forum: General
Topic: L2TP VPN can not connect on Windows 10
Replies: 17
Views: 23105

Re: L2TP VPN can not connect on Windows 10

Does it stuck on "Connecting to **IP address**"? If yes then it's not Mikrotik problem. I have same issue with L2TP. On 1803 I had this issue if I had GeForce Experience installed on Windows 10. After upgrade to 1809 L2TP does not work even without GeForce Experience. Haven't tried with 19...
by Fesiitis
Wed Jul 03, 2019 4:55 pm
Forum: General
Topic: IKEv2 with EAP-MSCHAPv2 mobile VPN [SOLVED]
Replies: 1
Views: 3652

IKEv2 with EAP-MSCHAPv2 mobile VPN [SOLVED]

Hi! I have two different routers. One of them is just a personal computer running OPNsense as OS. Second one is RB850Gx2 (v6.45.1). I want to create VPN server using IKEv2 with EAP-MSCHAPv2 on both of them. I have already created it on OPNsense following this tutorial . Now I want to create somethin...
by Fesiitis
Tue Jun 26, 2018 8:21 pm
Forum: General
Topic: IP NAT only when connecting to specific IP [SOLVED]
Replies: 2
Views: 1533

IP NAT only when connecting to specific IP [SOLVED]

Hi! I have DHCP setup with address pool 10.2.0.0/24. What I want to achieve is that when I connect to 10.50.50.4 with 80 and 443 ports (just example) then outgoing address pool is 10.3.0.0/24. It's should be like - my PC has IP 10.2.0.15 assigned. I'm connecting to 10.50.50.4:80 via web browser. My ...
by Fesiitis
Tue Apr 17, 2018 11:36 am
Forum: General
Topic: Remote logging to Graylog2 [SOLVED]
Replies: 2
Views: 3719

Re: Remote logging to Graylog2 [SOLVED]

Problem solved. Stupid Graylog2 can't reach neither Mikrotik router nor any other server if it's binded to direct IP address. After I set bind address to 0.0.0.0, everything started as it should be.
by Fesiitis
Tue Apr 17, 2018 11:26 am
Forum: General
Topic: Remote logging to Graylog2 [SOLVED]
Replies: 2
Views: 3719

Remote logging to Graylog2 [SOLVED]

I'm trying to configure Mikrotik router to send logs to Graylog2 server, but it looks that I have something missing or wrong because nothing happens..
mikrotik.PNG
graylog.PNG
Is there someone who can help me?
by Fesiitis
Tue Sep 13, 2016 1:57 pm
Forum: Wireless Networking
Topic: 2.4 and 5 GHz best settings
Replies: 5
Views: 26883

Re: 2.4 and 5 GHz best settings

When both chains are in use, my laptop (with Intel Centrino Wireless-N 2230) maximum download/upload speed shows ~25Mbps, but with one chain ~55Mbps. However another laptop (with Intel Centrino Advanced-N 6230), when both chains are in use, maximum speed is ~90Mbps, but with one chain ~45Mbps. That'...
by Fesiitis
Tue Sep 13, 2016 11:18 am
Forum: Wireless Networking
Topic: 2.4 and 5 GHz best settings
Replies: 5
Views: 26883

2.4 and 5 GHz best settings

Hi! One of our clients is using this product . That wireless router is configured as access-point (no DHCP, Ethernet and both Wi-Fi interfaces bridged). Currently settings for both interfaces: https://s12.postimg.io/bsv9tzpx9/image.png https://s12.postimg.io/6vhp8vny5/image.png Problem is that I can...