Community discussions

MikroTik App

Search found 108 matches

by janus20
Fri Mar 17, 2017 9:07 pm
Forum: Beginner Basics
Topic: Default Mikrotik Firewall config (RouterOS 6.38.5)
Replies: 6
Views: 8861

Re: Default Mikrotik Firewall config (RouterOS 6.38.5)

Hi,

Could you post your config? Please post content of output command;
/export hide-sensitive
kind regards,
by janus20
Fri Mar 17, 2017 8:45 pm
Forum: General
Topic: alarm port with Mikrotik
Replies: 12
Views: 3741

Re: alarm port with Mikrotik

hi, Sorry, i forgot to mention that you should move my suggested rules near top after first drop rule.. Please, move rules #13 and #14 after rule #2 ( add action=drop chain=input connection-state=invalid ) and try again. P.S. Also your 2nd rule add chain=input connection-state=established,related wa...
by janus20
Fri Mar 17, 2017 6:40 pm
Forum: General
Topic: alarm port with Mikrotik
Replies: 12
Views: 3741

Re: alarm port with Mikrotik

Hi, Maybe copy&paste mistake... try again, please: /ip firewall filter add action=accept chain=input comment="Accept external port to be forwarded #tcp" dst-address=192.168.1.2 dst-port=33000 in-interface=eth5-WAN log=yes log-prefix=fwd-acc-tcp protocol=tcp add action=accept chain=inpu...
by janus20
Fri Mar 17, 2017 6:28 pm
Forum: General
Topic: alarm port with Mikrotik
Replies: 12
Views: 3741

Re: alarm port with Mikrotik

Hi, Try first to accept incoming connections on 33000 port since you have a rule that drops in input on your WAN interface. /ip firewall filter add action=accept chain=input comment="Accept external port to be forwarded #tcp " \ dst-address=192.168.1.2 dst-port=33000 in-interface=eth5-WAN ...
by janus20
Thu Mar 16, 2017 5:28 pm
Forum: Beginner Basics
Topic: PPP PROFILE RATE LIMIT
Replies: 7
Views: 5084

Re: PPP PROFILE RATE LIMIT

Hi,
Please send a private message to me -- it is for something else. I do not need any technical help. Thanks!
Just tried but it does not works. On your profile contact link is disabled maybe from your profile is disabled to allow to be contacted, perhaps.

kind regards,
by janus20
Thu Mar 16, 2017 12:42 pm
Forum: General
Topic: Problem with Port Forwarding in Dual Wan Scenario
Replies: 11
Views: 3276

Re: Problem with Port Forwarding in Dual Wan Scenario

Hi,

Please, show us your config in order to get a better idea. Copy&paste here content of command:
/export hide-sensitive
kind regards,
by janus20
Wed Mar 15, 2017 11:48 pm
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi, I guess that means that the bridge isn't set up properly? Setting the VPN pool in the same subnet as the DHCP pool surely means that there's a problem connecting them up? I am not so sure about that. Maybe we have missed some forwarding rules into firewall or alike. I have noticed some weird rul...
by janus20
Wed Mar 15, 2017 11:21 pm
Forum: General
Topic: No DHCP Network settings applied to client leases
Replies: 11
Views: 3164

Re: No DHCP Network settings applied to client leases

Hi, I read some people noting that in 6.38 they were having some DHCP Server issues, but I was also having the problem with 6.35 (what i had before on this router). So I dont think my problem is related. I manage few RB models, rb750gr3, RB2011UiAS, RB3011Uias, rb951 on 6.38.5 and had no issue with ...
by janus20
Wed Mar 15, 2017 10:06 pm
Forum: General
Topic: No DHCP Network settings applied to client leases
Replies: 11
Views: 3164

Re: No DHCP Network settings applied to client leases

Hi, Quick response: add bridge=Lan disabled=yes interface=ether2 a. Seems that you have disabled ether2 port in bridge. Go to Bridge -> Ports -> select ether2 and click enable. b. if you do not want ether2 to be part of bridge then go to interfaces list, double-click on ether2 and from master port d...
by janus20
Wed Mar 15, 2017 8:40 pm
Forum: Beginner Basics
Topic: Reroute traffic
Replies: 5
Views: 1604

Re: Reroute traffic

Hi, From your schema which device is your gateway for your PC ( pc address 172.30.84.13) ? router 10.0.0.254 ? Switches 10.1.0.100 and 10.1.0.102 are configured with Vlans ? or are just "transparent bridge" like ordinary "dumb" switches ? Stupid question: Have you tried on PC put...
by janus20
Wed Mar 15, 2017 7:57 pm
Forum: Beginner Basics
Topic: PPP PROFILE RATE LIMIT
Replies: 7
Views: 5084

Re: PPP PROFILE RATE LIMIT

Hi, Glad it works. I do not know that because i have never done it before. I am at the beginning into Mikrotik world myself. Let me few days to document myself and to try to test your case and i will be back with an answer. If you are in a hurry i hope someone else more experienced than me could hel...
by janus20
Wed Mar 15, 2017 3:18 pm
Forum: Beginner Basics
Topic: Problem with firewall rules
Replies: 10
Views: 2685

Re: Problem with firewall rules

Hi, Quick answer: by using nslookup, ping or resolve. a. From a windows machine on command terminal type: nslookup -type=A webpage_address Into non-authorative section under addresses you should see the ip(s). or just ping webpage_address it should return ip address after "reply from..." b...
by janus20
Wed Mar 15, 2017 11:05 am
Forum: General
Topic: mikrotik viewing visited sites
Replies: 5
Views: 4645

Re: mikrotik viewing visited sites

Hi,

For transparent webproxy you can find a tutorial here:
https://wiki.mikrotik.com/wiki/Proxy_on ... rnal_drive

Hope it helps.

kind regards,
by janus20
Wed Mar 15, 2017 9:53 am
Forum: Beginner Basics
Topic: RB450G Performance Issues
Replies: 5
Views: 1269

Re: RB450G Performance Issues

Hi,

Would help if you just could provide:

1. a network schema where your rb is part of
2. your rb config as well; please post output of:
/export hide-sensitive
kind regards,
by janus20
Tue Mar 14, 2017 9:52 am
Forum: Beginner Basics
Topic: PPP PROFILE RATE LIMIT
Replies: 7
Views: 5084

Re: PPP PROFILE RATE LIMIT

Hi, Do you have fasttrack enabled ? If so, you should see "dummy" rules both into filter and mangle tables and also fasttrack rules into filter table: /ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related comment="defconf: fasttrack&quo...
by janus20
Tue Mar 14, 2017 9:43 am
Forum: Beginner Basics
Topic: PPTP vpn to Windows server inside my network
Replies: 7
Views: 8451

Re: PPTP vpn to Windows server inside my network

Hi, OK, I get it now. So need to put it in console: /ip firewall nat add chain=dstnat protocol=tcp port=1723 in-interface=ether1 action=dst-nat to-addresses=x.x.0.20 to-ports=1723 ... and depending on his firewall filter rule might add this as well: /ip firewall filter add action=accept chain=input ...
by janus20
Tue Mar 14, 2017 1:31 am
Forum: General
Topic: No DHCP Network settings applied to client leases
Replies: 11
Views: 3164

Re: No DHCP Network settings applied to client leases

Hi,

Please copy&paste output of command:
/export hide-sensitive
kind regards,
by janus20
Mon Mar 13, 2017 9:50 pm
Forum: General
Topic: No DHCP Network settings applied to client leases
Replies: 11
Views: 3164

Re: No DHCP Network settings applied to client leases

hi, Can you confirm that you have done the following ... a. ip address of ether2 interface /ip address add address=192.168.0.70/24 interface=ether2 network=192.168.0.0 b. dhcp server and pool settings for ether2 /ip pool add name=dhcp_pool8 ranges=192.168.0.80-192.168.0.90 /ip dhcp-server add addres...
by janus20
Mon Mar 13, 2017 3:04 pm
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi, What do you mean by ? If I put all the traffic through the router the static address addition of \\server.local works but \\server doesn't (I realise this probably shouldn't work) but that Windows address resolves on the network. The 10.160.100.x range can be reached. Well, i am not sure why is ...
by janus20
Mon Mar 13, 2017 2:15 pm
Forum: Beginner Basics
Topic: Hotspot help please
Replies: 4
Views: 993

Re: Hotspot help please

Hi, I am not an experienced hotspot admin, in fact never configured it before, but i think that If you are kind enough to post your configuration here maybe it would be more useful for others to understand and help you out with your situation. Please, copy&paste here content of the command: /exp...
by janus20
Mon Mar 13, 2017 1:22 pm
Forum: Beginner Basics
Topic: basic configuration
Replies: 12
Views: 3616

Re: basic configuration

Hi, You may find useful informations regarding your request here: https://wiki.mikrotik.com/wiki/Manual:Configuration_Management Also, if you are looking for a script to do it automatically you can find examples here, under "System Maintenance": https://wiki.mikrotik.com/wiki/Scripts Hope ...
by janus20
Sun Mar 12, 2017 11:03 pm
Forum: Beginner Basics
Topic: Change WAN port in RB2011UiAS-2HnD-IN from ether1 to ether10
Replies: 32
Views: 17662

Re: Change WAN port in RB2011UiAS-2HnD-IN from ether1 to ether10

Hi, @Sebus, calm down man, andriys , macsrwe and jarda have explained very well purpose of Quick Set. As an adition would like to point out hardware schema for your RB: https://i.mt.lv/routerboard/files/Block-RB2011UAS-2HnD.pdf I do not want to continue that discution about Quick Set but i suggest t...
by janus20
Sun Mar 12, 2017 7:27 pm
Forum: Beginner Basics
Topic: Setting up as home router with pppoe
Replies: 6
Views: 4262

Re: Setting up as home router with pppoe

Hi, NAT rule should be applied to pppoe-out and not to ether1 . When you connect via PPPOE to your ISP, pppoe-out is now your WAN interface not ether1 anymore. So that, any firewall rule you may write from now regarding wan interface should use pppoe-out and not ether1. Into IP -> Firewall -> NAT ta...
by janus20
Fri Mar 10, 2017 6:15 pm
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

hi, what do you mean by ? If I put all the traffic through the router a. do not see any "local-arp" on defined bridge1 /interface bridge add arp=proxy-arp name=bridge1 still no ping ? b. try to put ip 192.168.89.1 not on ether2-master but on bridge1 from your config : /ip address add addre...
by janus20
Fri Mar 10, 2017 5:25 pm
Forum: Beginner Basics
Topic: Set Up AP (Rb Groove A-52Hpn) using QUICKSET
Replies: 2
Views: 1951

Re: Set Up AP (Rb Groove A-52Hpn) using QUICKSET

Hi, Is your network schema like : ISP -> RB 2011 -> RB Groove A-52 ( connected via UTP cable into one of the rb2011 lan ports, ex. port 2-10 ) ? I understood so far : - on your main router, rb2011, you have internet connection and if you connect wireless on rb2011 ESSID you have internet connection ...
by janus20
Fri Mar 10, 2017 1:00 pm
Forum: Beginner Basics
Topic: VPN connection over LTE1
Replies: 2
Views: 687

Re: VPN connection over LTE1

Hi,

Would be very useful if you could post your config here ( copy&paste /export hide-sensitive and mask your public ips or user/passwd's ).

kind regards,
by janus20
Fri Mar 10, 2017 12:53 pm
Forum: Beginner Basics
Topic: How to create basic routing?
Replies: 1
Views: 640

Re: How to create basic routing?

Hi,

There is no need for double thread.
Check: viewtopic.php?f=13&t=119412

kind regards,
by janus20
Fri Mar 10, 2017 12:49 pm
Forum: Beginner Basics
Topic: How to add static route
Replies: 8
Views: 48097

Re: How to add static route

Hi, Do you need a static route from lan to wan or do you need masquerade entire lan network to wan interface ? a. static route from lan to wan ( presume you want to route 192.168.0.0/24 to wan interface, ether1 ) 1. new terminal /ip route add dst-address=192.168.0.0/24 gateway=ether1 2. IP left menu...
by janus20
Thu Mar 09, 2017 2:09 pm
Forum: Beginner Basics
Topic: Wireless Bridging
Replies: 14
Views: 5068

Re: Wireless Bridging

Hi,

Could you post a network diagram and also your mikrotik config ( /export hide-sensitive ) ?

kind regards,
by janus20
Thu Mar 09, 2017 1:28 pm
Forum: Beginner Basics
Topic: Vodafone K4201-Z LTE USB Modem Installation
Replies: 5
Views: 2433

Re: Vodafone K4201-Z LTE USB Modem Installation

Hi,

And the solution was/is ? Might help other users in the same situation too :)

kind regards,
by janus20
Thu Mar 09, 2017 11:48 am
Forum: Beginner Basics
Topic: L2TP/IPSec so I can use with Apple sierra and iOS
Replies: 4
Views: 6646

Re: L2TP/IPSec so I can use with Apple sierra and iOS

Hi, You could find a guide here : https://wiki.mikrotik.com/wiki/L2TP_%2B_IPSEC_between_Mikrotik_router_and_a_PC and main page with other examples here: https://wiki.mikrotik.com/wiki/Tunnels If you still have no success please post here your config, by typing into New terminal following command: /e...
by janus20
Wed Mar 08, 2017 12:42 am
Forum: Wireless Networking
Topic: Extend wirelless with one SSID
Replies: 8
Views: 1765

Re: Extend wirelless with one SSID

Hi, Without knowing how building levels are split ( office spaces, living space ) and it's area/footprint i would suggest following scenario: - on each level you could try with ONE basebox 2 with 2 tp-link 2.4Ghz 8dbi omni anntenas Basebox 2: https://routerboard.com/RB912UAG-2HPnD-OUT Tp-link 8dbi a...
by janus20
Wed Mar 08, 2017 12:10 am
Forum: Beginner Basics
Topic: Disable fasttrack
Replies: 7
Views: 51503

Re: Disable fasttrack

Hi, Perhaps you tried to disable rule #1 (dummy) which indeed isn't possible. That's what he did :) Do NOT disable rule #5 (above) since this will block response packets. Just disable the one forward rule with action=fasttrack-connection. He said fasttrack is interfering with his queues. So i presum...
by janus20
Tue Mar 07, 2017 10:42 pm
Forum: Beginner Basics
Topic: Disable fasttrack
Replies: 7
Views: 51503

Re: Disable fasttrack

Hi, Fasttrack enabled by default defined by those two rules: /ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related add chain=forward action=accept connection-state=established,related You could see entire default configuration by running into terminal...
by janus20
Mon Mar 06, 2017 10:54 pm
Forum: Beginner Basics
Topic: backup configs using LCD
Replies: 1
Views: 794

Re: backup configs using LCD

Hi, Don't confirm! Would you like to reset the configuration to default ? Never tried or do not know if it is possible from LCD screen to backup your config but would be better if you do it from webFig or Winbox. You said you connected USB flash drive in it but as i remember, i might be wrong on thi...
by janus20
Mon Mar 06, 2017 10:35 pm
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi Darren, I have made a simple test with VPN PPTP into one of my clients network and from my side it was working ( ping, RDP, access sharing on a workstation running Windows Xp ). It won't resolve your dns names because you have to "suffix" them, at least that's how worked for me. Here is...
by janus20
Mon Mar 06, 2017 6:15 pm
Forum: Beginner Basics
Topic: Bypass VPN for Netflix?
Replies: 16
Views: 14457

Re: Bypass VPN for Netflix?

Hi, I have also an idea. You could separate Roku mediaplayer from your local network and route it directly via your ISP gateway; something like : 1. let suppose you have ether5 port free; remove it from current bridge, if you have one defined, or ether2 (master ) by setting master-port: none 2. assi...
by janus20
Mon Mar 06, 2017 12:09 pm
Forum: Beginner Basics
Topic: Please Help Me: Port Forwarding VIA dynamic ISP?
Replies: 7
Views: 1925

Re: Please Help Me: Port Forwarding VIA dynamic ISP?

Hi, Use some dynamic dns service to register your own domain. ok! so after i register my domain in dynamic dns service, what should i do next? After that you should write a script in order to verify/update your dynamic ip then use a scheduler to run script automatically on a period of X minutes/ Y h...
by janus20
Mon Mar 06, 2017 11:56 am
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi,

Might help you this thread: viewtopic.php?f=13&t=118697
I think Sob has explained very well.

kind regards,
by janus20
Fri Mar 03, 2017 11:31 pm
Forum: Beginner Basics
Topic: Total Rx Bytes from terminal
Replies: 1
Views: 793

Re: Total Rx Bytes from terminal

Hi,

Try with:
/queue simple print stats
or
/queue simple print detail
Hope it helps.

kind regards,
by janus20
Fri Mar 03, 2017 10:48 pm
Forum: Beginner Basics
Topic: Block Websites and Torrents On Mikrotik 951Ui 2HnD
Replies: 9
Views: 10182

Re: Block Websites and Torrents On Mikrotik 951Ui 2HnD

Hi, Any one with the correct way to block torrent downloads on my mikrotik? Here is a config that is working for me, tested on rb750gr3, rb3011UiAS, rb951g-2hnd. I can not remember from where i have implemented it, most likely from this forum or an outside link from a post. It stops .torrent file do...
by janus20
Wed Mar 01, 2017 12:51 pm
Forum: Beginner Basics
Topic: Access Winbox with starting configuration
Replies: 8
Views: 1495

Re: Access Winbox with starting configuration

Hi,

No problem. Anytime :)

kind regards,
by janus20
Wed Mar 01, 2017 12:45 pm
Forum: Beginner Basics
Topic: Access Winbox with starting configuration
Replies: 8
Views: 1495

Re: Access Winbox with starting configuration

Hi,
Port number is 8291..
Sharp eyes... i did not notice it :)
/ip firewall filter
add action=accept chain=input comment="Winbox from Internet" dst-port=8291 protocol=tcp in-interface=ether1
kind regards,
by janus20
Wed Mar 01, 2017 12:29 pm
Forum: Beginner Basics
Topic: Access Winbox with starting configuration
Replies: 8
Views: 1495

Re: Access Winbox with starting configuration

Hi, Just a guess: a. put your input before any drop rule /ip firewall filter add action=accept chain=input comment="Winbox from Internet" dst-port=8921 protocol=tcp in-interface=ether1 b. disable rule add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed"...
by janus20
Sat Feb 25, 2017 12:37 am
Forum: Beginner Basics
Topic: I can't access my DRV by the external link
Replies: 4
Views: 1012

Re: I can't access my DRV by the external link

Hi, a. have you done any update on DVR firmware or microtik ROS ? b. have you tried to connect externaly using other pc/laptop ? c. have you checked if your 6000 port is open from outside ? P.S. I am just curious about error you have received after filled in username/password ( on changed dst-nat po...
by janus20
Sat Feb 25, 2017 12:23 am
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi, As i can see your configuration is as follow: ether1 - WAN ether2-5 - LAN with ether2 as master port Your LAN address range is 10.160.100.0/24 - DHCP server pool: 10.160.100.2-120 - ether2 ip address is 10.160.100.1 - you have pptp-server/l2tp-server both enabled I skip over filter rules ( which...
by janus20
Thu Feb 23, 2017 11:40 pm
Forum: Beginner Basics
Topic: HELP - Share With Hostname
Replies: 8
Views: 2562

Re: HELP - Share With Hostname

Hi,

Are all pc/laptop from 1st-4rd floor into the same WORKGROUP/DOMAIN ?

kind regards,
by janus20
Thu Feb 23, 2017 11:36 pm
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi,

Sorry for delay i was away with job. One more question: is there any port ( ether2-ether5 ) unused ( meaning you do not have any device plugged in it) ?

kind regards,
by janus20
Wed Feb 22, 2017 6:40 pm
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi, After you connected via Webfig, from left menu click on "New terminal" option. It will open a new window ( terminal window ). In that windows please type the following command: /export hide-sensitive ( meaning "showing" current config ) Copy & paste here in order to have ...
by janus20
Wed Feb 22, 2017 6:06 pm
Forum: Beginner Basics
Topic: Quickset VPN - no LAN Access
Replies: 22
Views: 10337

Re: Quickset VPN - no LAN Access

Hi, After you connected via WebFig, on the left menu click on the " bridge " option. Then in the right you should see your current bridge name. Click on bridge name, then also into the right side of the screen, you should see bridge settings. Check for ARP , is right almost the top of the ...
by janus20
Tue Feb 21, 2017 9:59 pm
Forum: Beginner Basics
Topic: VPN Connect but can't ping LAN devices
Replies: 3
Views: 13715

Re: VPN Connect but can't ping LAN devices

Hi, Just a few questions and an idea. a. did you try with those ICMP rules from firewall disabled ( since you said that there are some replys from management lan device) ? b . in /ppp profile you defined local-address as "192.168.150.1" but which interface/bridge does have this address def...
by janus20
Tue Feb 21, 2017 8:59 pm
Forum: Beginner Basics
Topic: port forwarding issue
Replies: 4
Views: 1177

Re: port forwarding issue

Hi,

Regarding DDNS on router with no-ip you can find tutorial below. I have used for myself and confirm that it is working:
http://wiki.mikrotik.com/wiki/Dynamic_D ... _No-IP_DNS

kind regards,
by janus20
Mon Feb 20, 2017 11:03 pm
Forum: Wireless Networking
Topic: Mikrotik 6Km PTP radio link in a eolic tower
Replies: 6
Views: 1700

Re: Mikrotik 6Km PTP radio link in a eolic tower

Hi, I have a PTP link using QRT 5ac for same distance, 6km over a plain field. Both QRT are mounted on 20m height on water tower and 25m on a granary ( grain elevator) since december 2015. It has been pass throught 2 winters and enought heavy rains and are still online. In fact, link never went down...
by janus20
Sun Feb 19, 2017 10:42 pm
Forum: Beginner Basics
Topic: How to do port forwarding for online game
Replies: 12
Views: 15161

Re: How to do port forwarding for online game

Hi, Sorry i was not pay attention too. Both commands have a typo meaning is mising "add" in front of them. Corrent syntax: /ip firewall nat add chain=dstnat action=dst-nat in-interface=ether1 dst-port=10501-10502 to-addresses=192.168.1.100 to-ports=10501-10502 protocol=tcp and /ip firewall...
by janus20
Sun Feb 19, 2017 7:33 pm
Forum: Beginner Basics
Topic: How to do port forwarding for online game
Replies: 12
Views: 15161

Re: How to do port forwarding for online game

Hi, Let's suppose your WAN interface is ether1 and your PC lan ip address is 192.168.1.100. I think that what Revelation wants to say is that you should issue following command into "New Terminal" for 10501-10502 tcp /ip firewall nat chain=dstnat action=dst-nat in-interface=ether1 dst-port...
by janus20
Fri Feb 17, 2017 12:31 pm
Forum: Beginner Basics
Topic: Groove A-52HPn with IP 0.0.0.0
Replies: 3
Views: 1614

Re: Groove A-52HPn with IP 0.0.0.0

Hi, Just an idea: 1. try with Winbox 3.10; 2. if winbox 3.10 still does not work i have a suggestion: connect via winbox on WHITE HOUSE 1 ( 192.168.88.2 ); from it go to ip -> neighbors. If you have interfaces enabled on "discovery interfaces" tab ( on 192.168.88.2 device ) into the NEIGHB...
by janus20
Wed Feb 15, 2017 11:42 pm
Forum: Beginner Basics
Topic: How to do port forwarding for online game
Replies: 12
Views: 15161

Re: How to do port forwarding for online game

Hi, Without any knowledge about your config you could give a try to this: /ip firewall nat add action=src-nat chain=srcnat dst-address={your_wk_lan_ip} dst-port=32303 protocol=udp comment="UDP 32303 theHunter" *dst-address={your_wk_lan_ip} - here put your workstation internal lan ip ( Ex.:...
by janus20
Wed Feb 15, 2017 10:37 pm
Forum: Beginner Basics
Topic: vpn server without local access
Replies: 3
Views: 1892

Re: vpn server without local access

Hi, So if i understood corectlly you want to connect to your gr750 from outside via PPTP and have internet connection from PPTP tunnel but in the same time not to interference with local lan network. Here is an idea: a. you should use one ether especially for this. Remove ether5 from master-bridge e...
by janus20
Mon Jan 30, 2017 10:08 pm
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

[SOLVED] 2 concurent pppoe connections on the same wan interface

hi, I have just solved the problem with help from mikrotik support ( i have just writen them an e-mail). Magic phrase from Mr. Janis M. was : If you still insist on using tunnels, use different IP range and exclude them from policy routing. Best regards, Janis M. So i have decided to leave as is pol...
by janus20
Fri Jan 27, 2017 12:03 pm
Forum: Beginner Basics
Topic: Firewall Filter Restriction
Replies: 15
Views: 3786

Re: Firewall Filter Restriction

Hi,

would you be kind enough to elaborate what do you want to achieve ?

kind regards,
by janus20
Fri Jan 20, 2017 10:20 am
Forum: Beginner Basics
Topic: DHCP Hates Me
Replies: 19
Views: 3371

Re: DHCP Hates Me

Hi, I think there is a typo with your ip address for ether1-LAN; it can not be: 192.168.2.0 ( from /ip route print ) ! Check ip -> addresses see that ether1-LAN have ip address 192.168.2.1/24 , network 192.168.2.0 ( meaning netmask 255.255.255.0 ), interface ether1-LAN . Also noticed: /ip dhcp-serve...
by janus20
Thu Jan 19, 2017 11:33 pm
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi @bajodel,

I see. I will try what you have suggested and come back with results.

Thank you very much.

kind regards,
by janus20
Thu Jan 19, 2017 10:09 am
Forum: Beginner Basics
Topic: problem with passing l2tp port and protocol from mikrotik
Replies: 18
Views: 4483

Re: problem with pass l2tp port and protocol from mikrotik

Hi, Maybe this will help you, presuming your modem is in bridge and your mikrotik will do the rest: http://wiki.mikrotik.com/wiki/MikroTik_RouterOS_and_Windows_XP_IPSec/L2TP Adjust firewall settings Do not forget to allow UDP 500 (Dst.Port), UDP 1701, UDP 4500 (Nat-Traversal) and Protocol 50 (ESP) i...
by janus20
Wed Jan 18, 2017 1:32 pm
Forum: Beginner Basics
Topic: Request for help: Dual Wan Load Balancing with failover to available WAN upon ISP unavailable
Replies: 5
Views: 3023

Re: Request for help: Dual Wan Load Balancing with failover to available WAN upon ISP unavailable

Hi, I have never done a failover scenario but i guess adding parameter "distance" should be enough: /ip route add dst-address=0.0.0.0/0 gateway=ISP_1 distance=1 check-gateway=ping /ip route add dst-address=0.0.0.0/0 gateway=ISP_2 distance=2 Might help you this links too: http://wiki.mikrot...
by janus20
Tue Jan 17, 2017 5:01 pm
Forum: Beginner Basics
Topic: Request for help: Dual Wan Load Balancing with failover to available WAN upon ISP unavailable
Replies: 5
Views: 3023

Re: Request for help: Dual Wan Load Balancing with failover to available WAN upon ISP unavailable

Hi,

as i remember there is an attribute, "check-gateway" to "/ip route" which takes as paramaters "ping" or "arp". An example:
/ip route
add dst-address=0.0.0.0/0 gateway=XXX check-gateway=ping  
kind regards,
by janus20
Sun Jan 15, 2017 9:56 pm
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi @bajodel, First of all thank you very much for your inputs. Second, i have read all your instructions and have implemented. Still does not work after i have sucessfuly connected via PPTP. Here is some logs: I. after add static route ( on route list window it says "unreachable", but in t...
by janus20
Fri Jan 13, 2017 9:38 am
Forum: Beginner Basics
Topic: hEX and creating two (switch or port) groups
Replies: 5
Views: 2695

Re: hEX and creating two (switch or port) groups

Hi, Yes it is possible. - for ether3-5 set master-port to none. - create 2 bridges: bridge1 and bridge2 ( from left menu, hit bridge then in BRIDGE tab click on "+" sign ) - after creating bridges, on bridge windows go to tab PORTS; click on "+" and in general tab into "Inte...
by janus20
Thu Jan 12, 2017 11:01 pm
Forum: Beginner Basics
Topic: DHCP Server does not work
Replies: 10
Views: 29951

Re: DHCP Server does not work

Hi,

would you be kind to post output of
/ip dhcp-server export
kind regards,
by janus20
Thu Jan 12, 2017 7:04 pm
Forum: Beginner Basics
Topic: Route all my traffic through a VPN
Replies: 7
Views: 7669

Re: Route all my traffic through a VPN

Hi,

I think Sob is reffering to openVPN client settings not into Mikrotik RB side. On school on your laptop/pc you have installed a OpenVPN client in order to make VPN connection to your MK at home, right ?

kind regards,
by janus20
Thu Jan 12, 2017 10:51 am
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi @bajodel,

Have you got a little spare time to look over my config ? Is there any info you'd need ?

Thank you very much for your time, once again.

kind regards,
by janus20
Wed Jan 11, 2017 5:03 pm
Forum: Beginner Basics
Topic: Renew IP to beginning
Replies: 2
Views: 810

Re: Renew IP to beginning

Hi,

Do you want to reconfigure pool address or clear all dynamic leases already allocated ?

For last might help this: http://forum.mikrotik.com/viewtopic.php?t=70106

Hope it helps.

kind regards,
by janus20
Tue Jan 10, 2017 12:53 am
Forum: Beginner Basics
Topic: mAP as a simpliest AP
Replies: 7
Views: 1460

Re: mAP as a simpliest AP

Hi,

Please use /export file=XXX in order to have a clear view of your configs.

kind regards,
by janus20
Mon Jan 09, 2017 10:14 pm
Forum: Beginner Basics
Topic: Connect 2 networks with separate internet connections
Replies: 16
Views: 6467

Re: Connect 2 networks with separate internet connections

Hi,

ok, no problem :)

regards,
by janus20
Mon Jan 09, 2017 10:03 pm
Forum: Beginner Basics
Topic: Connect 2 networks with separate internet connections
Replies: 16
Views: 6467

Re: Connect 2 networks with separate internet connections

HI, Just curious: 1. from network 1 PC (WLAN) 192.168.1.x -> 192.168.100.1 ( zyxel MuM ) - ??? PC (LAN) 192.168.1.x -> 192.168.100.1 ( zyxel MuM ) - ??? 2. add on RB750 on filter rules before rule 3 ( ;;; defconf: drop all from WAN ): /ip firewall filter add action=accept chain=forward comment=\ &qu...
by janus20
Mon Jan 09, 2017 8:41 pm
Forum: Beginner Basics
Topic: Connect 2 networks with separate internet connections
Replies: 16
Views: 6467

Re: Connect 2 networks with separate internet connections

Hi, Well beside default firewall config which comes on rb750, at first sight from ip address print : 1 192.168.1.2/32 192.168.1.0 ether3 - RoTa 2 192.168.100.2/32 192.168.100.0 ether4 - MuM should be: 1 192.168.1.2/24 192.168.1.0 ether3 - RoTa 2 192.168.100.2/24 192.168.100.0 ether4 - MuM I mean ip ...
by janus20
Mon Jan 09, 2017 8:05 pm
Forum: Beginner Basics
Topic: Connect 2 networks with separate internet connections
Replies: 16
Views: 6467

Re: Connect 2 networks with separate internet connections

Hi,

Please post ( from New Terminal window type commands below ) output of:
/interface export
and
/ip address export

And also, could you tell us in which ports from RB750 did you connect Fritzbox and Zyxel ?

kind regards,
by janus20
Mon Jan 09, 2017 10:31 am
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi @bajodel, Very sorry for delay i was away last 3 days. I was testing inside network like i said in last post but i could not see anything in logs. Maybe because both laptop and workstation were connected into same switch and they have made a direct connection and not through mikrotik or maybe i d...
by janus20
Thu Jan 05, 2017 5:23 pm
Forum: Beginner Basics
Topic: I want a script
Replies: 1
Views: 586

Re: I want a script

Hi,

I am not sure but try changing default "keepalive-timeout" value, from 60 to 120 into pppoe-client ( interfaces -> pppoe-client .... ).

kind regards,
by janus20
Thu Jan 05, 2017 12:46 am
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi, 1. - done ( tested with proxy-arp and also with local-proxy-arp ); 2. - done ( i see bytes and packets moving ), i put it as a 3th rule before even "drop invalid rule"; /ip firewall filter add action=accept chain=forward comment="Explicit forward" dst-address=172.16.21.240/28...
by janus20
Wed Jan 04, 2017 10:42 pm
Forum: Beginner Basics
Topic: Open port (GAMERANGER)
Replies: 16
Views: 8493

Re: Open port (GAMERANGER)

Hi,

Just a guess. On first rule, chain "forward", would not be corect if you specify the interface ?

kind regards,
by janus20
Wed Jan 04, 2017 9:55 am
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi @bajodel. Nope; Code you listed is working fine ( as i have already mentioned above ) but i want to connect via RDP from inside lan after i have been connected over PPTP ( which is always giving me address 172.16.21.252/32 after connected ) and not on direct from outside using port forwarding on ...
by janus20
Tue Jan 03, 2017 5:34 pm
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Thanks @bajodel for your answer. I just did but nothing change: [freya@gw-BFY] > /interface ethernet export # jan/03/2017 01:26:10 by RouterOS 6.37.3 # software id = QEKX-Y5VI # /interface ethernet set [ find default-name=ether1 ] comment="WAN RDS - PPPOE1 + PPPOE2" set [ find default-name...
by janus20
Fri Dec 30, 2016 6:53 pm
Forum: Beginner Basics
Topic: Connecting to home network over PPTP
Replies: 17
Views: 7770

Re: Connecting to home network over PPTP

Hi, I guess that as long as it hangs on "Authenticating user..." most likely is on microtik something. You could temporary allow connection from outside on winbox port service, connecting first via winbox then watching log while you are attempting to connect via pptp. I have two rb750gr3 c...
by janus20
Fri Dec 30, 2016 2:26 pm
Forum: Beginner Basics
Topic: Connecting to home network over PPTP
Replies: 17
Views: 7770

Re: Connecting to home network over PPTP

Hi, Have you tried to open "pptp" port ( 1723 ) into your firewall ? When you initiate pptp connection from outside ( presuming from Windows after you have set up a VPN connection ) do you have any error ? ( i mean in connecting window it remains on "opening port...." or shows an...
by janus20
Wed Dec 28, 2016 12:17 am
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi everybody, Great news. I have made it using a hex RB750gr3, firmware 6.37.3 and a few modifications beside original configuration above. Here is a speed test on a workstation connected directly to mikrotik router ( i have choosen Amsterdam server for testing external bandwidth), CPU was about 50-...
by janus20
Sun Dec 11, 2016 8:34 pm
Forum: Beginner Basics
Topic: Need Help with port forwarding
Replies: 6
Views: 1846

Re: Need Help with port forwarding

Hi OceanWW,

Yes, it is normal what you see in "New Terminal"; what JB172 wanted to say is that in "New Terminal" window type export, hit enter and copy&paste results here.

Image

kind regards,
by janus20
Fri Dec 09, 2016 9:12 pm
Forum: General
Topic: Cannot connect from LAN to WAN IP
Replies: 4
Views: 3841

Re: Cannot connect from LAN to WAN IP

Hi, Based on your two rules and the fact that you need Hairpin Nat, try this: /ip firewall nat add action=masquerade chain=srcnat comment="Access WAN from local LAN" dst-address=192.168.1.1 dst-port=80 out-interface=\ bridge-LAN protocol=tcp src-address=192.168.1.0/24 to-addresses=192.168....
by janus20
Wed Dec 07, 2016 11:37 pm
Forum: Beginner Basics
Topic: port forwarding/firewall issue
Replies: 5
Views: 1689

Re: port forwarding/firewall issue

Hi, I think your problem accessing port forwarding services from inside using "public ip" as your point of origin is related to Hairpin NAT. http://wiki.mikrotik.com/wiki/Hairpin_NAT For your rules: 0 chain=dstnat action=dst-nat to-addresses=10.1.0.4 to-ports=5001 protocol=tcp dst-address=...
by janus20
Mon Nov 21, 2016 10:08 pm
Forum: Beginner Basics
Topic: DNS server
Replies: 8
Views: 1905

Re: DNS server

Hi,

One VM with nginx behind rb i think it would be an elegant solution; easy with port forwarding on rb too.

P.S. Goodluck ( "multa bafta" )
by janus20
Tue Nov 15, 2016 1:35 am
Forum: Beginner Basics
Topic: [advice] Configuration RBwAP2nD
Replies: 16
Views: 6874

Re: [advice] Configuration RBwAP2nD

Hi, Nope, i think ap bridge is fine. Maybe frequency but i have noticed that your signal si some kind of low ( -73db if that is your laptop). Could you give a comparation list with other wifi router which you say you have better speed? ( chanel width, frequvency, signal level, download speed, ping -...
by janus20
Tue Nov 15, 2016 12:48 am
Forum: Beginner Basics
Topic: [advice] Configuration RBwAP2nD
Replies: 16
Views: 6874

Re: [advice] Configuration RBwAP2nD

Hi, Well, for a quick view, you could change channel width from "20Mhz" to "20/40Mhz Ce", in the first place. You could do that directly into Quick Set window or accessing, from the left menu, wireless -> interfaces tab -> double click wlan1 interface then into wireless tab selec...
by janus20
Mon Nov 14, 2016 11:20 pm
Forum: Beginner Basics
Topic: [advice] Configuration RBwAP2nD
Replies: 16
Views: 6874

Re: [advice] Configuration RBwAP2nD

Hi, In ip -> routes as you see in quick set you do not have default route to 192.168.1.1 ( AS 0.0.0.0 bridge1 reachable ) that why it is not working. Short way from ip -> routes: a. delete second rule DS 0.0.0.0 192.168.1.1 reachable b. modify first rule AS 0.0.0.0 bridge1 reachable, double click on...
by janus20
Mon Nov 14, 2016 5:35 pm
Forum: Beginner Basics
Topic: [advice] Configuration RBwAP2nD
Replies: 16
Views: 6874

Re: [advice] Configuration RBwAP2nD

Hi, Sure, it is ok but you will need to add default route to proper lan gateway ( modify in step 3. with proper gateway or skip step 3 and may do it from ip -> routes, click '+', in general tab of new route leave Dst. address 0.0.0.0/0 untouched and click in field Gateway: and enter proper gateway i...
by janus20
Mon Nov 14, 2016 5:14 pm
Forum: Beginner Basics
Topic: [advice] Configuration RBwAP2nD
Replies: 16
Views: 6874

Re: [advice] Configuration RBwAP2nD

Hi, If you want that your wAP would act simply as a AP bridge between your current router who is managing dhcp pool and internet connections ( 192.168.1.1 ), login into your wAp on it's MAC address, not 192.168.88.1, and do the following in New Terminal window: 1. putting in bridge mode, alocating e...
by janus20
Mon Nov 14, 2016 10:37 am
Forum: General
Topic: How Can I Show A Custom Message When Blocking Sites Using FireWall?
Replies: 4
Views: 3386

Re: How Can I Show A Custom Message When Blocking Sites Using FireWall?

Hi, To block download of .mp3 files from any browser you could do: /ip firewall filter add action=drop chain=forward comment="block .mp3 download" content=.mp3 log=yes log-prefix=block-dwd-mp3 Regarding blocking HTTPS sites like youtube, facebook... 1. first create a rule on layer7 protoco...
by janus20
Sat Nov 12, 2016 9:12 am
Forum: Beginner Basics
Topic: New PPPoE Connection --> Connected. But Not Working
Replies: 8
Views: 3447

Re: New PPPoE Connection --> Connected. But Not Working

Hi, Supposing your pppoe connection is on ether1 interface, Are you sure ether1 mac address is the same with tp-link wan mac address ? /int ethernet print As i remember from a few tp-link routers when configuring a pppoe connection beside username/passwd, eventually service name and MTU there is not...
by janus20
Wed Nov 09, 2016 11:18 pm
Forum: Beginner Basics
Topic: Setup mAP as AP
Replies: 3
Views: 1926

Re: Setup mAP as AP

Hi, Maybe you forgot to set dns and default route ( rb750 ip ) ? Please define " I can't access RB750..": can not access it on webFig, Winbox or does not respond to ping ? Could you post here results of ( from 'New Terminal' of mAP ) : /ip route print and /ip dns print P.S. May i ask why d...
by janus20
Wed Nov 09, 2016 11:05 pm
Forum: Beginner Basics
Topic: add ip on interface
Replies: 2
Views: 721

Re: add ip on interface

Hi, What do you want to achive ? If a cable from your isp router is connected into ether1 interface and ether1 has been assigned ip address 192.168.0.15 (/24 i suppose), in ether 2 what is connected? is there a cable who is then connected into a switch in which are connected both your servers or you...
by janus20
Wed Nov 09, 2016 10:47 pm
Forum: Beginner Basics
Topic: new NAT does nothing
Replies: 7
Views: 1775

Re: new NAT does nothing

Hi, I think you need 2 rules: first, a dst-nat in nat chain and second a forwarding rule in filter chain. Let's say that for new machine you wish to alocate port 4000, on mikrotik router, and fordwaring the remote desktop to your new machine 192.168.0.10 on which remote desktop is listening on 3389:...
by janus20
Wed Nov 09, 2016 10:21 pm
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi,

Thanks a lot ( multumesc frumos) @docmarius. I will buy the equipment and made some tests with "dial on demand" disabled. Most probable on monday next week i will be back with an input.

Thank you very much once again.

kind reagrds,
by janus20
Wed Nov 09, 2016 10:17 pm
Forum: Beginner Basics
Topic: access router from internet
Replies: 4
Views: 1447

Re: access router from internet

Hi,

If your winbox port is still 8291, try this:
/ip firewall filter
add action=accept chain=forward dst-port=8291 comment="Accept connections from Winbox" in-interface=pppoe-out1 log=yes protocol=tcp
kind regards,
by janus20
Wed Nov 09, 2016 9:48 am
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

Re: 2 concurent pppoe conections on the same wan interface

Hi,

Please, forgive my insistence as well as i do not want to be rude, at least anyone could give me an advice?
Thanks in advance.

kind regards,
by janus20
Tue Nov 08, 2016 11:04 pm
Forum: Beginner Basics
Topic: [SOLVED]Port Forwarding problem.
Replies: 21
Views: 22767

Re: Port Forwarding problem.

Hi, I understood that he wants that anyone who is trying to connect on either 80 or 443 ports on his public ip, which is not fixed, to be forwarded into inside local lan BSD box 9 192.168.0.254) that is running a nginx instance ( probable his website ); that was my rules about. Regarding accesing We...
by janus20
Tue Nov 08, 2016 10:25 pm
Forum: Beginner Basics
Topic: [SOLVED]Port Forwarding problem.
Replies: 21
Views: 22767

Re: Port Forwarding problem.

Hi @lebarondemerde, First of all you should change default WebFig ports ( 80, 443 ) and Winbox port as well; this could be done from menu IP -> Services, either from Winbox or WebFig. Then, supposing that ether1 is your WAN and ports 2-4 are in bridge, or are making part of your internal lan in whic...
by janus20
Mon Nov 07, 2016 6:26 pm
Forum: Beginner Basics
Topic: Port Forwarding Issue
Replies: 19
Views: 4971

Re: Port Forwarding Issue

Hi rudios,

I see, it makes a lot of sense now. Thank you very much for your explications.

kind regards
by janus20
Mon Nov 07, 2016 3:25 pm
Forum: Beginner Basics
Topic: Port Forwarding Issue
Replies: 19
Views: 4971

Re: Port Forwarding Issue

Hi, In his latest post he said: How do I open the port 8150 in the router? Sorry for the many questions. Unfortunately, it still doesn't work. I can see packets. I am a beginner into mikrotik routers myself so that please forgive me but I still think that proper chain commands here would be ( it is ...
by janus20
Mon Nov 07, 2016 2:00 pm
Forum: Beginner Basics
Topic: Port Forwarding Issue
Replies: 19
Views: 4971

Re: Port Forwarding Issue

Hi pcarlo71, In my humble opinion you should put in FILTER rules, before rule nr. 6, a rule to accept connections for port 8150: IP -> FIREWALL -> FILTER 1. In GENERAL Tab, click "+", for add new rule 2. select CHAIN = input 3. select PROTOCOL = (6) tcp 4. select destination port = Dst. Po...
by janus20
Sun Nov 06, 2016 7:02 pm
Forum: Beginner Basics
Topic: [SOLVED] 2 concurent pppoe connections on the same wan interface
Replies: 20
Views: 15657

[SOLVED] 2 concurent pppoe connections on the same wan interface

Hi, I am new here and this is my first post so please be patient with me. I have a situation in whitch my client ISP has alocated him 2 pppoe conections ( 2 different username and passwords) on the single FTP cable. Now it is working as ISP cable is into a 5 port switch from where leave 2 ftp cables...