Community discussions

MikroTik App

Search found 22 matches

by zvekyf
Sat Dec 02, 2023 10:26 pm
Forum: General
Topic: mikrotik sip don't forward bye commands
Replies: 8
Views: 2182

Re: mikrotik sip don't forward bye commands

RouterOS : 7.12 I have setup static arp under /IP arp There is no IPSec tunnels on mikrotik. Also no specific routes under /ip route I have setup NAT only for 5060. Do you think I should set dst-nat for port 5062? chain=dstnat action=dst-nat to-addresses=192.168.181.15 protocol=tcp dst-address-list=...
by zvekyf
Sat Dec 02, 2023 5:24 pm
Forum: General
Topic: mikrotik sip don't forward bye commands
Replies: 8
Views: 2182

Re: mikrotik sip don't forward bye commands

yes that is strange why mikrotik don't NAT those messages from provider to client(192.168.181.15) and I can't find why.
Also we can't reproduce problem, it just happens several times a week.
2023-12-02_16-16-13.png
by zvekyf
Sat Dec 02, 2023 8:18 am
Forum: General
Topic: mikrotik sip don't forward bye commands
Replies: 8
Views: 2182

Re: mikrotik sip don't forward bye commands

yes 192.168.181.15 is LAN side of mikrotik.

:put [/ip firewall connection tracking get udp-stream-timeout] = 00:03:00
/ip firewall service-port > sip disabled=yes sip-direct-media=no

one of latest examples
2023-12-02_06-50-14.png
by zvekyf
Wed Nov 15, 2023 7:01 am
Forum: General
Topic: mikrotik sip don't forward bye commands
Replies: 8
Views: 2182

mikrotik sip don't forward bye commands

during day we have that mikrotik don't forward bye commands during call and operator have empty line and call must be manually closed. I have collected log but not sure what is happening. Maybe some UDP timeout and mikrotki loses NAT mappings and don't know where to forward packets. Maybe someone ha...
by zvekyf
Thu Mar 30, 2023 10:04 pm
Forum: General
Topic: New OpenVPN community client (version 2.6) cannot connect to Mikrotik OpenVPN server [SOLVED]
Replies: 10
Views: 8128

Re: New OpenVPN community client (version 2.6) cannot connect to Mikrotik OpenVPN server [SOLVED]

Server: Mikrotik Open VPN server (RouterOS 7.8 ) Clienti: Windows OpenVPN 2.6.2 If I set next it still connect with AES-256-CBC and without auth part I get error [unsupported auth digest] data-ciphers AES-256-GCM:AES-128-GCM:AES-256-CBC data-ciphers-fallback AES-256-CBC auth SHA512 But if I set next...
by zvekyf
Tue Nov 15, 2022 6:22 am
Forum: General
Topic: radius and ppp authentication timeout
Replies: 3
Views: 901

Re: radius and ppp authentication timeout

RASDIUS timeout is already 40 sec. which is I think enough, it can be set to 60 sec. so it is same as DUO but problem is PPP authentication as I understand and this is if we don't do DUO autorization inside 5 sec. connection hangs. I would like to control PPP authentication timeout and for now I hav...
by zvekyf
Mon Nov 14, 2022 4:09 am
Forum: General
Topic: radius and ppp authentication timeout
Replies: 3
Views: 901

radius and ppp authentication timeout

ver. 7.6 I have setup radius login for OpenVPN integrated with DUO 2FA authentication. We have noticed problem if you don't click yes in DUO app in about 5 seconds VPN connection hangs and you must manually kill connection because OpenVPN will never clean it. When connection hangs encoding part is e...
by zvekyf
Thu Nov 03, 2022 10:21 pm
Forum: General
Topic: OpenVPN connection stays dynamic
Replies: 11
Views: 5153

Re: OpenVPN connection stays dynamic

ver 7.6

we alse see same problem.
It would be nice that there is something to check and clear problematic interfaces/active connections.
by zvekyf
Thu Nov 03, 2022 10:19 pm
Forum: RouterOS beta
Topic: [ROS 7b4] OpenVPN UDP leaves dead tunnel
Replies: 3
Views: 6606

Re: [ROS 7b4] OpenVPN UDP leaves dead tunnel

ver 7.6
We also have enabled [only one] on profile.
when we see problem, we kill interface and active connection.
by zvekyf
Wed Nov 02, 2022 5:13 am
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 143313

Re: v7.6 [stable] is released!

we have same issue with OpenVPN UDP connections but because we allow [only one] clients can't connect after that any more and we must manually clear connections. https://cdn.screencast.com/uploads/g000302M5s8dVYia1WADrIY2jvebB/11.02.2022-04.03.png?sv=2021-08-06&st=2022-11-02T03%3A09%3A18Z&se...
by zvekyf
Wed Feb 16, 2022 2:54 am
Forum: General
Topic: password policy
Replies: 2
Views: 1249

password policy

in version 7 I see password policy option
/user settings
minimum-password-length: 0
minimum-categories: 0

What is minimum-categories ?
I couldn't find documentation for that.

Will this also be password policy when creating other type of users like ppp or radius?
by zvekyf
Sun Sep 12, 2021 2:49 pm
Forum: RouterOS beta
Topic: New User Manager in RouterOS v7
Replies: 211
Views: 81672

Re: New User Manager in RouterOS v7

is there plan to support wireguard authentication?
by zvekyf
Sun Sep 12, 2021 2:46 pm
Forum: RouterOS beta
Topic: Wireguard and radius and connected clients
Replies: 3
Views: 5670

Re: Wireguard and radius and connected clients

it would be nice to be able do authentication by using radius server 👍
by zvekyf
Sat Aug 22, 2020 2:47 am
Forum: General
Topic: openvpn block brutforce
Replies: 0
Views: 1077

openvpn block brutforce

I have read this
https://wiki.mikrotik.com/wiki/Brutefor ... prevention

But I have problem with setup similar blocking for OpenVPN after 3 failed login.

Does anyone have idea how to do this?
by zvekyf
Wed Sep 19, 2018 1:23 am
Forum: General
Topic: 2 IPs and preferred source
Replies: 1
Views: 1684

2 IPs and preferred source

I have 2 IPs on WAN interface let say

1.1.1.1
2.2.2.2

and 1.1.1.1 is set automatically as preferred source but I would like to set 2.2.2.2 as preferred source.
But I can't modify dynamic route(DAC).

What can I do?
by zvekyf
Sun Sep 16, 2018 9:18 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 177603

Re: Winbox vulnerability: please upgrade

is there maybe a plan to add auto update option and set that as default option? There are many routers which will never be updated or until something real bad happens. Also maybe to add option to auto update only security fixes. This way every router will be immediately patched/updated(unmanaged) an...
by zvekyf
Mon Jan 09, 2017 1:11 am
Forum: General
Topic: VPN and NetBIOS broadcast
Replies: 2
Views: 1669

Re: VPN and NetBIOS broadcast

does anyone have any info about NetBIOS broadcast?

Regards,
Darko Bazulj
by zvekyf
Mon Jan 09, 2017 1:08 am
Forum: General
Topic: VPN and Dns Suffix
Replies: 2
Views: 5892

Re: VPN and Dns Suffix

@huntah thank you for the link. I have used rras/isa/tmg and that was never a problem until I switched to mikrotik :( Missing NetBIOS broadcast is another problem. Now I know I can suggest mikrotik only to smaller offices where is feasible to manually setup remote clients. Regards, Darko Bazulj
by zvekyf
Sun Nov 27, 2016 4:40 pm
Forum: General
Topic: VPN and Dns Suffix
Replies: 2
Views: 5892

VPN and Dns Suffix

when client connects to Mikrotik by VPN is there a way to pass [Dns Suffix] property? https://dl.dropboxusercontent.com/u/12735114/mikrotik/dnssuffix1.png Under /ppp profile I see only dns-server option but no domin/dns suffix property . Also I haven't saw option to pass DHCP to VPN clients. I'm men...
by zvekyf
Sun Nov 27, 2016 4:20 pm
Forum: General
Topic: VPN and NetBIOS broadcast
Replies: 2
Views: 1669

VPN and NetBIOS broadcast

we used TMG2010 until now and we have switched to Mikrotik. But now I have problem with VPN clients and machine name resolving/browsing using only machine names. I have read that one solution is to use WINS but for now we don't have WINS. https://dl.dropboxusercontent.com/u/12735114/mikrotik/tmg1-ne...
by zvekyf
Fri Sep 30, 2016 8:42 am
Forum: Beginner Basics
Topic: finde and where examples
Replies: 2
Views: 2643

Re: finde and where examples

@Pietro thank you for help. # find is there a way to test find output on CLI before you start changing something or using in script? Just to check if your query is right. # where and regex I have tried to use regex but it looks id doesn't work or I'm missing something. work /ip route print where com...
by zvekyf
Thu Sep 29, 2016 1:40 am
Forum: Beginner Basics
Topic: finde and where examples
Replies: 2
Views: 2643

finde and where examples

I'm playing with find and where but I'm missing something. #works /ip route print where dst-address="0.0.0.0/0" # don't work /ip route find where dst-address="0.0.0.0/0" /ip route find dst-address="0.0.0.0/0" Aim is to search for comments by using wildcards. Do I miss s...