Community discussions

Search found 204 matches

by JohnTRIVOLTA
Thu Oct 17, 2019 6:04 am
Forum: General
Topic: Block all wesites except one
Replies: 8
Views: 403

Re: Block all wesites except one

Or just do source nat for specific destination address only ! Example? Disable or delete the gobal nat rule first, after that you can add: /ip firewall nat add chain=srcnat dst-address=AAA:BBB:CCC:DDD action=masquerade out-interface=WAN\ AAA:BBB:CCC:DDD - replace with CHMS(Cloud Hospital Management...
by JohnTRIVOLTA
Wed Oct 16, 2019 10:03 pm
Forum: General
Topic: Block all wesites except one
Replies: 8
Views: 403

Re: Block all wesites except one

Or just do source nat for specific destination address only !
by JohnTRIVOLTA
Sun Sep 29, 2019 10:10 am
Forum: General
Topic: BCP and VLANs
Replies: 5
Views: 538

Re: BCP and VLANs

which one is better BCP or EOIP? i run layer 2 network BCP with some PPP Multilink Protocol is better choice for me .I choose L3 reconstruction against L4 re/segmenting. Pros = bigger MTU, smaller CPU usage, no issues due to MSS for some services , one ppp tunnel for transport many EoIPs respective...
by JohnTRIVOLTA
Fri Sep 27, 2019 9:36 pm
Forum: Beginner Basics
Topic: VPN between two routers
Replies: 8
Views: 716

Re: VPN between two routers

I dont need connect to router, i can do it. I need connect to last router LAN.
I need two VPN connections on one IP, but for two devices.

First vpn is working fine, it is my management vpn. But i need another connection directly to last routers lan.
Try to allow gre on 941 input chain too !
by JohnTRIVOLTA
Thu Sep 26, 2019 8:16 am
Forum: General
Topic: L2TP iPSEC Mikrotik to Mikrotik Problem with web UI
Replies: 10
Views: 849

Re: L2TP iPSEC Mikrotik to Mikrotik Problem with web UI

maybe TCP MTU/MSS issue check this https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Mangle#Change_MSS I'm stuck almost for months now looking for the solution but still no luck. Just set L2TP MRRU=1580 on both sites and reconnect the tunnel ! I've tried it all but still no luck. And now what is th...
by JohnTRIVOLTA
Wed Sep 25, 2019 11:04 pm
Forum: Beginner Basics
Topic: VPN between two routers
Replies: 8
Views: 716

Re: VPN between two routers

Set RoMON on all devices for example .
by JohnTRIVOLTA
Wed Sep 25, 2019 6:07 pm
Forum: General
Topic: L2TP iPSEC Mikrotik to Mikrotik Problem with web UI
Replies: 10
Views: 849

Re: L2TP iPSEC Mikrotik to Mikrotik Problem with web UI

I'm stuck almost for months now looking for the solution but still no luck.
Just set L2TP MRRU=1580 on both sites and reconnect the tunnel !
by JohnTRIVOLTA
Mon Sep 16, 2019 10:12 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke
Replies: 35
Views: 4186

Re: hAP AC2+cAP AC Roaming is a joke

I hope in new ROSv7 have a lot of improvements, optimization and other protocol aviability in wireless part ! The Roaming works well, but only for reconnecting to device with strongest signal like 802.11k !
by JohnTRIVOLTA
Mon Sep 16, 2019 7:30 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke
Replies: 35
Views: 4186

Re: hAP AC2+cAP AC Roaming is a joke

Do you want to let us know with this post that you have found the right brand of wireless networking devices for you? This is CapsMan with а few of cAP ac with connected and powered by them mAP Lites. Same SSID, roaming, shaper with QOS etc...no packet loss , just no problems !!! https://i.postimg.c...
by JohnTRIVOLTA
Sun Sep 15, 2019 10:07 pm
Forum: Beginner Basics
Topic: Not working. What am i missing!?
Replies: 7
Views: 961

Re: Not working. What am i missing!?

Thanks for your suggestion, but sadly it did not help.
No firwall /filter, nat, etc/ = no internet !
by JohnTRIVOLTA
Sun Sep 15, 2019 9:23 pm
Forum: RouterBOARD hardware
Topic: Audience
Replies: 34
Views: 6684

Re: Audience

Can anyone post a single export file of basic configuration when Audience connecting to the other audience device with mesh setup? I have to know out exactly what is configured in ROS !
by JohnTRIVOLTA
Thu Sep 12, 2019 6:05 pm
Forum: Wireless Networking
Topic: what is the optimum wireless configuration?
Replies: 8
Views: 1264

Re: what is the optimum wireless configuration?

What speeds do you expect to reach ? For me, you need to fix - channel-width=20/40mhz-Ce frequency-mode=superchannel installation=indoor !
After all, it all depends on whether there is radio interference and how strong it is!
by JohnTRIVOLTA
Mon Sep 09, 2019 7:02 pm
Forum: General
Topic: RBM33G can`t connect winbox neither by IP
Replies: 9
Views: 604

Re: RBM33G can`t connect winbox neither by IP

Hmmm, try to use RS232 serial port !
by JohnTRIVOLTA
Mon Sep 09, 2019 4:11 pm
Forum: General
Topic: RBM33G can`t connect winbox neither by IP
Replies: 9
Views: 604

Re: RBM33G can`t connect winbox neither by IP

Is there plugged any additional peripheral devices - wifi, Lte pci-e card or usb etc...If answer is Yes, remove them and try again .
by JohnTRIVOLTA
Fri Sep 06, 2019 10:23 am
Forum: General
Topic: RBM33G can`t connect winbox neither by IP
Replies: 9
Views: 604

Re: RBM33G can`t connect winbox neither by IP

Reset the router and try again !
by JohnTRIVOLTA
Thu Sep 05, 2019 11:47 am
Forum: Beginner Basics
Topic: Dual dynamic ISP WAN, dual LAN setup
Replies: 13
Views: 1228

Re: Dual dynamic ISP WAN, dual LAN setup

Yes for all questions !
by JohnTRIVOLTA
Thu Sep 05, 2019 9:00 am
Forum: Beginner Basics
Topic: Dual dynamic ISP WAN, dual LAN setup
Replies: 13
Views: 1228

Re: Dual dynamic ISP WAN, dual LAN setup

I created some config - test it ! /ip dhcp-client add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=ether1 use-peer-dns=no use-peer-ntp=no add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=ether11 use-peer-dns=no use-peer-ntp=no /ip address add...
by JohnTRIVOLTA
Wed Sep 04, 2019 1:53 pm
Forum: Beginner Basics
Topic: How I can block VPN progrmas
Replies: 6
Views: 729

Re: How I can block VPN progrmas

The correct method is to allow the necessary services and then block all other traffic on forward chain!
by JohnTRIVOLTA
Wed Sep 04, 2019 1:06 pm
Forum: General
Topic: How Block DHCP in Bridge betwen two interfaces [SOLVED]
Replies: 6
Views: 620

Re: How Block DHCP in Bridge betwen two interfaces [SOLVED]

/interface bridge filter add action=drop chain=forward dst-mac-address=FF:FF:FF:FF:FF:FF/FF:FF:FF:FF:FF:FF dst-port=67 ip-protocol=udp mac-protocol=ip out-interface=ether2 add action=drop chain=forward dst-mac-address=FF:FF:FF:FF:FF:FF/FF:FF:FF:FF:FF:FF dst-port=67 ip-protocol=udp mac-protocol=ip o...
by JohnTRIVOLTA
Wed Sep 04, 2019 11:31 am
Forum: General
Topic: How Block DHCP in Bridge betwen two interfaces [SOLVED]
Replies: 6
Views: 620

Re: How Block DHCP in Bridge betwen two interfaces [SOLVED]

/interface bridge filter add action=drop chain=forward dst-mac-address=FF:FF:FF:FF:FF:FF/FF:FF:FF:FF:FF:FF dst-port=67 ip-protocol=udp mac-protocol=ip out-interface=ether2 add action=drop chain=forward dst-mac-address=FF:FF:FF:FF:FF:FF/FF:FF:FF:FF:FF:FF dst-port=67 ip-protocol=udp mac-protocol=ip ou...
by JohnTRIVOLTA
Tue Sep 03, 2019 9:43 pm
Forum: Beginner Basics
Topic: Forwarding traffic
Replies: 4
Views: 608

Re: Forwarding traffic

I use a similar configuration for L2 transparent connectivity. I use L2TP IPsec with BCP on bridges to the both sides. I usе DHCP on main office with address XX.XX.XX.1/24/respectively gateway for network/ with dhcp-pool from 2-99, and on remote office with address XX.XX.XX.254/24 /respectively gate...
by JohnTRIVOLTA
Tue Aug 13, 2019 4:18 pm
Forum: Beginner Basics
Topic: Automatic Failover
Replies: 2
Views: 619

Re: Automatic Failover

by JohnTRIVOLTA
Tue Jul 23, 2019 8:37 pm
Forum: RouterBOARD hardware
Topic: My Groove AC is dead
Replies: 13
Views: 1238

Re: My Groove AC is dead

I think the board is the same like nonAC Groove with different cpu and ethernet port !
by JohnTRIVOLTA
Tue Jul 23, 2019 6:58 pm
Forum: RouterBOARD hardware
Topic: My Groove AC is dead
Replies: 13
Views: 1238

Re: My Groove AC is dead

Try to hard reset the device by shorting special hole of board . After that try netinstall or try after few of days.
I have several boards / mipsbe based / groove, 951 series with same issue... for me this issue comming from bad flash memory and only full format/netinstall/ may solve the problem .
by JohnTRIVOLTA
Thu Jul 18, 2019 9:48 pm
Forum: Wireless Networking
Topic: Wireless AC performence issue
Replies: 3
Views: 682

Re: Wireless AC performence issue

This seems to be a common pattern, looks like it's pretty much impossible to achieve more than 250-300 Mbit/s real world single client throughput with Mikrotik ac WiFi.
In case you ever manage to break this limit please let me know how you did it :)
For exemple this test
.
by JohnTRIVOLTA
Thu Jul 18, 2019 2:33 pm
Forum: Wireless Networking
Topic: Wireless AC performence issue
Replies: 3
Views: 682

Wireless AC performence issue

Hi friends, I have a router RBM33G with two full-size mpci-e cards / AR9380 for 2.4GHz and AR9880-WLE900VX for 5GHz /. All works just fine. My laptop have Intel AC7260. The connectivity is perfect at 5GHz ~ 40dBm, but I only achieve about max 300Mb/ps - average 250Mb/ps. I expected some speeds in th...
by JohnTRIVOLTA
Sun Jul 14, 2019 10:15 pm
Forum: Wireless Networking
Topic: Wifi range is really bad for a reason
Replies: 17
Views: 1441

Re: Wifi range is really bad for a reason

Fix the channel and change with no EU country for example Canada !
by JohnTRIVOLTA
Mon Jun 17, 2019 12:05 pm
Forum: Wireless Networking
Topic: wAP ac / cAP ac: no 2 streams with 80MHz?
Replies: 4
Views: 982

Re: wAP ac / cAP ac: no 2 streams with 80MHz?

I have a large network deployed with lots of hAP AC2 with CAPsMAN and I have no such problems!
https://i.postimg.cc/3RF708fz/ccr-7.png

P.S.
You ask for AC models only - my mistake! But with old version of ROS about 6.42/3.XX stable , there is no such problem i mean ?!
by JohnTRIVOLTA
Fri Jun 07, 2019 11:50 pm
Forum: General
Topic: PPTP in IPsec Tunnel
Replies: 1
Views: 158

Re: PPTP in IPsec Tunnel

Maybe the opposite may happen site to site ipsec over ppp connection !
I have already configured such a set up / site to site ipsec over sstp connection with BCP / and a double aes 256 encoding is obtained - the safest tunnel you can set :D
by JohnTRIVOLTA
Fri Jun 07, 2019 8:31 am
Forum: General
Topic: Time Based firewaal rules
Replies: 12
Views: 687

Re: Time Based firewaal rules

Synchronize time on routerboard with ntp client or manually ?
With ntp client!!!
NTP . In ROS this is System-SNTP client .
by JohnTRIVOLTA
Thu Jun 06, 2019 2:26 pm
Forum: General
Topic: Time Based firewaal rules
Replies: 12
Views: 687

Re: Time Based firewaal rules

Synchronize time on routerboard with ntp client or manually ?
by JohnTRIVOLTA
Wed Jun 05, 2019 7:45 pm
Forum: General
Topic: Traffic routing between isolated bridges/subnets
Replies: 3
Views: 275

Re: Traffic routing between isolated bridges/subnets

Check Interface List ... add other bridges in list LAN ?!
by JohnTRIVOLTA
Wed May 29, 2019 9:08 am
Forum: General
Topic: Simple config but Internet not working.
Replies: 8
Views: 475

Re: Simple config but Internet not working.

Change this rule:
/ip firewall nat add action=masquerade chain=srcnat
with
/ip firewall nat add action=masquerade chain=srcnat out-interface=ether13WAN
by JohnTRIVOLTA
Sun May 19, 2019 6:41 pm
Forum: Forwarding Protocols
Topic: L2TP+ipsec speeds
Replies: 7
Views: 1037

Re: L2TP+ipsec speeds

Can you test L2TP ipsec with Multilink Protocol activated - MRRU=1600 on both sides ? Don't use tcp mss clamping - ppp profile set=no on both sites too ! Unsure how to use that setting properly, however with MTU=1420 and MRRU=1600, no clamp in FW nor PPP, I got about 5% less than with MTU=1460. Ser...
by JohnTRIVOLTA
Sun May 19, 2019 5:15 pm
Forum: Forwarding Protocols
Topic: L2TP+ipsec speeds
Replies: 7
Views: 1037

Re: L2TP+ipsec speeds

After lowering the MTU/MRU to 1420 for L2TP+ipsec to avoid fragmentation, I have some expected results: L2TP+IPSec 280 280 120/120 208 200 80/80 Can you test L2TP ipsec with Multilink Protocol activated - MRRU=1600 on both sides ? Don't use tcp mss clamping - ppp profile set=no on both sites too !
by JohnTRIVOLTA
Sat May 18, 2019 11:26 pm
Forum: General
Topic: Block public proxy servers - HOW [SOLVED]
Replies: 12
Views: 635

Re: Block public proxy servers - HOW [SOLVED]

Blocking access to proxies doesn't sound like something that would help much. Unless you have some very strict filtering of all outgoing traffic, any worm will just use either custom ports, or if you block those, then regular https. And you pretty much have to allow that, if those 150 clients shoul...
by JohnTRIVOLTA
Sat May 18, 2019 11:09 pm
Forum: General
Topic: Block public proxy servers - HOW [SOLVED]
Replies: 12
Views: 635

Re: Block public proxy servers - HOW [SOLVED]

It really depends on what exactly you need it for and how persistent users you have. Maybe if you block the most obvious servers, they will give up. The major thing against you is that all they need is just one working server. Behind a ccr I have a very sensitive network with about 150 clients. The...
by JohnTRIVOLTA
Sat May 18, 2019 8:24 pm
Forum: General
Topic: Block public proxy servers - HOW [SOLVED]
Replies: 12
Views: 635

Re: Block public proxy servers - HOW [SOLVED]

I don't follow what happens in public proxy world, but what I got from Google was all without https, just http. But if you have different sources with https, then it's bad for you, because you can't see what's inside https connection, it's the whole point of https. And collecting address, good luck...
by JohnTRIVOLTA
Sat May 18, 2019 7:24 pm
Forum: General
Topic: Block public proxy servers - HOW [SOLVED]
Replies: 12
Views: 635

Re: Block public proxy servers - HOW [SOLVED]

For now, this stops traffic to proxies that do not use https / SSL /. Unfortunately, most of the public are over https ! Тhe only solution for now is that I have to collect their ip addresses in lists .
by JohnTRIVOLTA
Sat May 18, 2019 4:32 pm
Forum: General
Topic: Block public proxy servers - HOW [SOLVED]
Replies: 12
Views: 635

Re: Block public proxy servers - HOW [SOLVED]

I don't think you can. You can block some with L7 like this:
/ip firewall layer7-protocol
add name=proxy regexp="^(CONNECT\\ .*|GET\\ https\?:\\/\\/.*)\\ HTTP\\/1\\."
But it's far from perfect.
Тhank you very much Sob !
I will try it ... I hope I will not block with it another traffic? :D
by JohnTRIVOLTA
Fri May 17, 2019 9:34 pm
Forum: General
Topic: Block public proxy servers - HOW [SOLVED]
Replies: 12
Views: 635

Block public proxy servers - HOW [SOLVED]

Hi guys, I have not found a way to effectively block traffic to public proxies so as not to bypass the rules in the firewall ! If anyone has such a solution, please share their experience ! P.S. I want to ask, if i can add a firewall rule in filter section on forward chain with conten=https and one ...
by JohnTRIVOLTA
Thu May 16, 2019 12:10 pm
Forum: Wireless Networking
Topic: 40MHz channel on hAP Mini
Replies: 4
Views: 399

Re: 40MHz channel on hAP Mini

Your client wireless card may not be configured correctly to use 40MHz channel ?! Sometimes signal noise is the cause of the inability to use a wider frequency length !
by JohnTRIVOLTA
Mon May 06, 2019 9:06 pm
Forum: General
Topic: Port forwarding not working or something interfering possibly? 12 hrs later.. still don't know.
Replies: 7
Views: 444

Re: Port forwarding not working or something interfering possibly? 12 hrs later.. still don't know.

Have you forgotten to put a gateway address on the computer to which we forward(dst-nat) the port ?
by JohnTRIVOLTA
Mon Apr 22, 2019 11:37 am
Forum: General
Topic: How dynamic tunnels can be created?
Replies: 3
Views: 258

Re: How dynamic tunnels can be created?

Thanks JohnTrivolta for replying. I tried that but, I'm running a dhcp server and clients under the bridged interface can't obtain an ip from server. Played around with mtu's but can't get it working. If you have properly configured your BCP, you must successfully expand transparently /L2/ the hots...
by JohnTRIVOLTA
Sun Apr 21, 2019 3:16 pm
Forum: General
Topic: Trying to Understand MSS Clamping - Not Working? [SOLVED]
Replies: 9
Views: 673

Re: Trying to Understand MSS Clamping - Not Working? [SOLVED]

When i need some ppp based VPN i use multilink feature instead clamp mss ! You must set the MRRU = 1600 for example on both sides - try it !
by JohnTRIVOLTA
Sun Apr 21, 2019 8:42 am
Forum: General
Topic: How dynamic tunnels can be created?
Replies: 3
Views: 258

Re: How dynamic tunnels can be created?

Just use L2TP client with BCP on every clients router!
by JohnTRIVOLTA
Thu Apr 18, 2019 9:18 pm
Forum: Wireless Networking
Topic: CAP AC Vs HAP AC2
Replies: 5
Views: 1147

Re: CAP AC Vs HAP AC2

An important difference - cAP AC has separate antennas for each chain /4/ and better wireless performance for that! hAP AC2 has 2 combined antennas for both frequencies!
by JohnTRIVOLTA
Mon Apr 15, 2019 12:50 pm
Forum: Beginner Basics
Topic: HAP mini IPSEC+EoIP performance?
Replies: 4
Views: 461

Re: HAP mini IPSEC+EoIP performance?

I think the hAP ac2 / RBD52G-5HacD2HnD-TC / is the right choice !
by JohnTRIVOLTA
Sun Apr 14, 2019 6:34 pm
Forum: Beginner Basics
Topic: HAP mini IPSEC+EoIP performance?
Replies: 4
Views: 461

Re: HAP mini IPSEC+EoIP performance?

Don't expect more than 10 mb/ps with AES 128 CBC , the eoip tunnel use lot of cpu resources too!
by JohnTRIVOLTA
Sun Mar 24, 2019 10:17 pm
Forum: General
Topic: ROS 6.44 - VPN L2TP not working
Replies: 23
Views: 5666

Re: ROS 6.44 - VPN L2TP not working

Since I upgraded to 6.44.*, I currently have patch 6.44.1 and device CCR1036-12G-4S, can not connect Windows 10 clients with IPSEC, get error when trying to connect and I have not changed at all the configuration in the clients or router I have the same problem. I reverted it with version 6.43.13 L...
by JohnTRIVOLTA
Sat Mar 23, 2019 6:02 am
Forum: General
Topic: PPPOE over PPTP or PPPOE over L2TP ?
Replies: 8
Views: 3227

Re: PPPOE over PPTP or PPPOE over L2TP ?

Does nobody have any Idea ;(
Just set MRRU=1610 on ppp connection on both sides !On the ppp profile dont use Change TCP MSS - put NO .
by JohnTRIVOLTA
Thu Mar 14, 2019 7:09 am
Forum: Beginner Basics
Topic: Simplest Route Rule Possible.
Replies: 13
Views: 640

Re: Simplest Route Rule Possible.

Sorry this discussion is NOT to include mangling LOL.
Ooo sorry .... by the way, all is clear and there is nothing to discuss, but I will follow the topic .
by JohnTRIVOLTA
Wed Mar 13, 2019 10:49 pm
Forum: Beginner Basics
Topic: Simplest Route Rule Possible.
Replies: 13
Views: 640

Re: Simplest Route Rule Possible.

Requirement: There is only one IP used in vlan55, I want to direct this ip 129.168.55.25 to go out my ether1 cable WANIP. Right now the cable WANIP is my secondary fail over wanip, the primary is fibre bell. For my email on cable I simply create a route rule with the mail server IP as the destinati...
by JohnTRIVOLTA
Wed Mar 13, 2019 10:32 pm
Forum: General
Topic: Restrict vpn user access
Replies: 1
Views: 182

Re: Restrict vpn user access

Hello, I managed to configure ovpn connection to my router. I set remote address of some user on 192.168.88.195. He is able to connect with every device in 192.168.88.0 network. How i can restrain his access and allow him only to connect only with one specific IP ? For instance, the user should be ...
by JohnTRIVOLTA
Mon Mar 04, 2019 5:01 pm
Forum: Beginner Basics
Topic: VPN server on sxt lte setup
Replies: 7
Views: 740

Re: VPN server on sxt lte setup

So if I put a vpn server under a public ip pc or routerboard I could connect the sxt routerboard to that server and example Android phone to same server and then with this" kind of bridge " see sxt contents with Android phone and viceversa ?
Еxactly !
by JohnTRIVOLTA
Mon Mar 04, 2019 4:14 pm
Forum: Beginner Basics
Topic: VPN server on sxt lte setup
Replies: 7
Views: 740

Re: VPN server on sxt lte setup

The ISP say that is possible by vpn. If would not possible to connect outside then why I can access with some proprietary app as synology or xiaomi to my nas or hub.? I think these app create a tunnel similar or equal to a vpn. A vpn tunnel would be as the vpn server goes outside of lan /internet a...
by JohnTRIVOLTA
Wed Feb 27, 2019 7:11 am
Forum: RouterBOARD hardware
Topic: Wireless USB dongle support?
Replies: 2
Views: 628

Re: Wireless USB dongle support?

ROS Version 6.X no longer supports WiFi USB adapters ! You can only use Woobm for management purpose or an older version of ROS !
by JohnTRIVOLTA
Sat Feb 23, 2019 8:38 pm
Forum: General
Topic: Hotspot - do not bypass dns router role how ?
Replies: 5
Views: 429

Re: Hotspot - do not bypass dns router role how ?

Wow, okay that is good to know. I wonder why hotspot functionality bypasses NAT rules??
This is my question too !
by JohnTRIVOLTA
Sat Feb 23, 2019 5:54 pm
Forum: General
Topic: Hotspot - do not bypass dns router role how ?
Replies: 5
Views: 429

Re: Hotspot - do not bypass dns router role how ?

Hello Anav, thanks for the quick answer! I already use these rules and work well, but they do not work on the hotspot network unfortunately. There are clients who put a static DNS address and thus jump my router and resolve to the their DNS. I think there must be some rule/s/ between the dynamic one...
by JohnTRIVOLTA
Sat Feb 23, 2019 3:14 pm
Forum: General
Topic: Hotspot - do not bypass dns router role how ?
Replies: 5
Views: 429

Hotspot - do not bypass dns router role how ?

Hello friends. I have a router that has multiple networks and the router has a roll for dns. I have a problem with the hotspot, and can not intercept and redirect the different dns server addresses manually seted from clients. The standard rule can not intercept addresses from hotspots network only....
by JohnTRIVOLTA
Tue Jan 29, 2019 10:23 pm
Forum: Beginner Basics
Topic: block inter VLAN traffic
Replies: 17
Views: 2007

Re: block inter VLAN traffic

Where is this export of configuration or at least that of the firewall? I did not see it anywhere, so I am confined to what is specifically asked! Everything else bordered on divination skills and I do not have ones!
by JohnTRIVOLTA
Mon Jan 28, 2019 10:54 pm
Forum: Beginner Basics
Topic: block inter VLAN traffic
Replies: 17
Views: 2007

Re: block inter VLAN traffic

That sounds silly JT. What are you trying to accomplish?? VLAN to VLAN traffic is blocked by default at layer 2. VLAN to VLAN traffic is blocked at layer 3 unless you allow it with an allow rule. THe only thing the OP requires is an allow VLAN to WAN rule! Тhis is my answer for pegasus123 - its fir...
by JohnTRIVOLTA
Mon Jan 28, 2019 8:57 pm
Forum: Beginner Basics
Topic: block inter VLAN traffic
Replies: 17
Views: 2007

Re: block inter VLAN traffic

I use only one filter rule . First i add all vlans in interface list - VLANs and then put the one filter rule:
/ip fi fi add action=drop chain=forward in-interface-list=VLANs out-interface-list=VLANs
by JohnTRIVOLTA
Sat Jan 26, 2019 8:32 pm
Forum: Wireless Networking
Topic: Reduce Wi-Fi transmitter power on schedule
Replies: 6
Views: 582

Re: Reduce Wi-Fi transmitter power on schedule

Oh man thank you! I did it wrong first time. Then I tried as you said but I cannot succeed. I made this to show how I did it. but it doesn't change anything .. i think https://ibb.co/RzVRqpW You forgot RUN in schedule : /system script run number=1 But this is not the main setup error. You must chan...
by JohnTRIVOLTA
Sat Jan 26, 2019 3:18 pm
Forum: Wireless Networking
Topic: Reduce Wi-Fi transmitter power on schedule
Replies: 6
Views: 582

Re: Reduce Wi-Fi transmitter power on schedule

Did you do this?
Аdd the script in the system section - scripts with changed values ​​as desired . Then add a schedule in system - schedule to run the script at a certain interval - an example of 15 minutes. That is all !
Image
by JohnTRIVOLTA
Sat Jan 26, 2019 12:54 pm
Forum: Wireless Networking
Topic: Reduce Wi-Fi transmitter power on schedule
Replies: 6
Views: 582

Re: Reduce Wi-Fi transmitter power on schedule

Simply set a minimum value /10dbm/ for the transmitting power of the wireless interface in the tx power section - all rates fixed and the script will work! Change the desired values in the script too !
by JohnTRIVOLTA
Fri Jan 25, 2019 7:10 am
Forum: General
Topic: IKEv2 Site-To-Site VPN
Replies: 4
Views: 734

Re: IKEv2 Site-To-Site VPN

Hello, the things you want can be configured, but you also need to set some settings in location A if you want a L2 level or extend transparently the LAN , if I understood right !
by JohnTRIVOLTA
Tue Jan 22, 2019 7:20 pm
Forum: General
Topic: IKEv2 site to site between 2 Mikrotik
Replies: 10
Views: 1051

Re: IKEv2 site to site between 2 Mikrotik

I think your problem is in the balancing mode used /PCC/. In the second router, you do not use balancing, and there is no problem for initiate the connection. For the test, you can stop the wan ports and leave only the wan for ipsec and try it again.
by JohnTRIVOLTA
Tue Jan 22, 2019 6:57 am
Forum: General
Topic: IKEv2 site to site between 2 Mikrotik
Replies: 10
Views: 1051

Re: IKEv2 site to site between 2 Mikrotik

I'm really sorry. I have only seen the beginning of both configurations without scrolling them!
Now, when I look at the config, I think that the traffic that is between the two networks should be marked to be exactly where / which WAN port / will come out for balancing!
by JohnTRIVOLTA
Mon Jan 21, 2019 6:30 pm
Forum: General
Topic: IKEv2 site to site between 2 Mikrotik
Replies: 10
Views: 1051

Re: IKEv2 site to site between 2 Mikrotik

really hoping someone can point out what I'm doing wrong :(
I cant see any IpSec IKE2 Site to Site configuration ! You may have set up some L2TP with IpSec ppp connection and routing the networks on it - do you have any routes for them in both places ?
by JohnTRIVOLTA
Sun Jan 20, 2019 4:26 pm
Forum: Beginner Basics
Topic: how to do Dynamic nat 100 private ip with /24 public ip
Replies: 10
Views: 871

Re: how to do Dynamic nat 100 private ip with /24 public ip

I think this rules will work : /ip firewall address-list add address=192.168.0.1-192.168.0.100 list=100private_addresses #just add your private ip addresses in address list# /ip firewall nat add action=accept chain=srcnat src-address-list=!100private_addresses add action=netmap chain=srcnat src-addr...
by JohnTRIVOLTA
Sun Jan 20, 2019 12:52 pm
Forum: Beginner Basics
Topic: how to do Dynamic nat 100 private ip with /24 public ip
Replies: 10
Views: 871

Re: how to do Dynamic nat 100 private ip with /24 public ip

Hi
Can you please help me how to do Dynamic nat of apporx 100 private ip with /24 public ip pool . thanks
Use NETMAP for source nat !?
by JohnTRIVOLTA
Sun Jan 20, 2019 10:23 am
Forum: General
Topic: No country [SOLVED]
Replies: 4
Views: 624

Re: No country [SOLVED]

Try Debug and then russia2 for other frequencies .
by JohnTRIVOLTA
Mon Jan 07, 2019 3:51 pm
Forum: Beginner Basics
Topic: SSTP VPN speed is too slow between MT router and client
Replies: 3
Views: 677

Re: SSTP VPN speed is too slow between MT router and client

30/5 Mbps respectively only you have maximum 5 Mbps on client downstream !
by JohnTRIVOLTA
Thu Dec 20, 2018 10:19 pm
Forum: General
Topic: Ipsec Site to Site with certificate
Replies: 5
Views: 715

Re: Ipsec Site to Site with certificate

Hi I try to configure a connection between two ccr1009 and encrypt this with ipsec. If I try to use psk everything works fine. But I wanna use instead certificates. I search for some time but I didn't found any tutorial how to do this. So I wanna ask would this be possible? Thanks Just try , use IK...
by JohnTRIVOLTA
Mon Dec 17, 2018 12:25 am
Forum: Wireless Networking
Topic: wAP ac is slow with manager forwarding and high CPU
Replies: 9
Views: 1078

Re: wAP ac is slow with manager forwarding and high CPU

I have same issue ! With netbox 5 , 1 client /my laptop/ achieved max only 46 mbit/s when i transfer some file/s/ via ftp from my local nas. The laptop wireless adapter AR5BWB222 300/300 connectivity .
Image
by JohnTRIVOLTA
Sun Dec 16, 2018 10:59 pm
Forum: Beginner Basics
Topic: Connect three locations
Replies: 9
Views: 771

Re: Connect three locations

I am not sure what I have to do, but if I understand I have to create two firewall--> nat rules: In one of remote routers: 0 chain=srcnat action=src-nat to-addresses=172.31.32.3 src-address=192.168.10.0/24 dst-address=192.168.11.0/24 log=no log-prefix="" In other remote router: 0 chain=srcnat actio...
by JohnTRIVOLTA
Sun Dec 16, 2018 9:30 pm
Forum: Beginner Basics
Topic: Connect three locations
Replies: 9
Views: 771

Re: Connect three locations

My guess is that on routers 2 and 3 your masquerade rules masquerade too much. Whatever sent from e.g. site 2 towards site 1 and site 3 should probably not be masqueraded ... You could try to rewrite masquerade rules to match outgoing interfaces or something ... + must select outgoing interface in ...
by JohnTRIVOLTA
Sun Dec 16, 2018 8:35 pm
Forum: Beginner Basics
Topic: Connect three locations
Replies: 9
Views: 771

Re: Connect three locations

I do nor heva any limitations in filter
You don't have rules in the routers at all ?
by JohnTRIVOLTA
Sun Dec 16, 2018 8:02 pm
Forum: Beginner Basics
Topic: Connect three locations
Replies: 9
Views: 771

Re: Connect three locations

May be necessary to add accept rules for the three networks in the forward chains on filter section on the three routers
by JohnTRIVOLTA
Sun Dec 16, 2018 9:20 am
Forum: Beginner Basics
Topic: Blocking traffic on the same NAT doesn't work
Replies: 10
Views: 747

Re: Blocking traffic on the same NAT doesn't work

But I have a virtually created bridge, and bridge filters work for it. But not for the default bridge. So if it's a software bridge I can use the bridge filters feature and provide some L2 filtering. Remove the hardware offload of the desired bridgeports /ether2 and ether4/ ! https://i.postimg.cc/5...
by JohnTRIVOLTA
Tue Dec 11, 2018 11:22 pm
Forum: General
Topic: 6.43.7 bootloop on hAP AC
Replies: 2
Views: 359

Re: 6.43.7 bootloop on hAP AC

ixirion has the same issue ! After downgrade to 6.43.4 the routerboard works normally again! The reboots were in a different range from 1 minute to 5 .
by JohnTRIVOLTA
Mon Dec 10, 2018 12:07 am
Forum: General
Topic: ikev2 ports [SOLVED]
Replies: 7
Views: 2100

Re: ikev2 ports [SOLVED]

Okay.... never easy with MT. There are two ways of letting ipsec connections through. Allow protocol 50 or connections with in ipsec policy. When I'm trying with the first option, vpn connects but connections somehow do not get through. If i do it with second type rule, then everything is fine... a...
by JohnTRIVOLTA
Sun Dec 09, 2018 12:04 am
Forum: General
Topic: ikev2 ports [SOLVED]
Replies: 7
Views: 2100

Re: ikev2 ports [SOLVED]

Okay, 50% of mystery solved :)
Why is then my connection working even while I'm not allowing ipsec protocol (50) on input chain?
Are you sure ? When you are activated IKE (ISAKMP) these protocols /50 and 51/ are allowed automatically /unless you explicitly disallow them/ !
by JohnTRIVOLTA
Sat Dec 08, 2018 4:47 pm
Forum: General
Topic: ikev2 ports [SOLVED]
Replies: 7
Views: 2100

Re: ikev2 ports [SOLVED]

I have a working ikev2 vpn connection setup on my ros. Every tutorial says i need to allow ports 500, 4500 UDP and IPSec ESP on input chain. Some tutorials even say port 1701 UDP needs to be opened on input chain. Than why is my connection working completely even if I don't allow 1701 nor IPSec esp...
by JohnTRIVOLTA
Wed Nov 21, 2018 11:29 pm
Forum: Beginner Basics
Topic: Bridge Filter works on independent vlan ?
Replies: 5
Views: 379

Re: Bridge Filter works on independent vlan ?

Now everything works after I added in-bridge and out-bridge on bridge filter rule: /interface bridge filter add action=drop chain=forward dst-port=68 in-bridge=bridge1 ip-protocol=udp mac-protocol=ip out-bridge=bridge1 src-address=!172.16.222.254/32 My configuration is less complex. I have one openv...
by JohnTRIVOLTA
Wed Nov 21, 2018 9:46 pm
Forum: Beginner Basics
Topic: Bridge Filter works on independent vlan ?
Replies: 5
Views: 379

Re: Bridge Filter works on independent vlan ?

Oh, I'm sorry, I'm very .... Ethernet1 is part of the bridge1 ! This may be the answer ! /interface bridge add arp=proxy-arp comment="-- LAN --" fast-forward=no name=bridge1 add fast-forward=no name=bridge2 add name=bridge3 add name=bridge4 add igmp-snooping=yes name=bridge5 add fast-forward=no name...
by JohnTRIVOLTA
Wed Nov 21, 2018 7:49 pm
Forum: Beginner Basics
Topic: Bridge Filter works on independent vlan ?
Replies: 5
Views: 379

Bridge Filter works on independent vlan ?

Hi friends, I had to configure a VLAN on my board and put it on virtual wlan interface. I found out that customers do not receive an ip address. Аfter thorough investigation of the problem, I realized that a rule in the bridge for DHCP stops the packages also in the vlan. My question - Why is it so ...
by JohnTRIVOLTA
Wed Jun 13, 2018 11:26 pm
Forum: Beginner Basics
Topic: Confused about L2TP and IPSec VPNs
Replies: 21
Views: 1997

Re: Confused about L2TP and IPSec VPNs

There's: 6 ;;; defconf: accept established,related chain=forward action=accept connection-state=established,related,untracked log=no log-prefix="" So if the previous rules in "/ip firewall raw" are still in place, it's covered. You are right, the rules already exist in RAW section ! p.s. I remember...
by JohnTRIVOLTA
Wed Jun 13, 2018 10:14 pm
Forum: Beginner Basics
Topic: Confused about L2TP and IPSec VPNs
Replies: 21
Views: 1997

Re: Confused about L2TP and IPSec VPNs

I don't see this rules on the top of filter section on both routers too: /ip firewall filter add chain=forward action=accept place-before=1 src-address=192.168.0.0/24 dst-address=192.168.3.0/24 connection-state=established,related,untracked add chain=forward action=accept place-before=1 src-address=...
by JohnTRIVOLTA
Wed Jun 13, 2018 10:12 am
Forum: Beginner Basics
Topic: Confused about L2TP and IPSec VPNs
Replies: 21
Views: 1997

Re: Confused about L2TP and IPSec VPNs

Firewall NAT [...@trk-mtk-04] /ip firewall nat> print Flags: X - disabled, I - invalid, D - dynamic 0 chain=srcnat action=accept src-address=192.168.0.0/24 dst-address=192.168.3.0/24 log=no log-prefix="" 1 ;;; defconf: masquerade chain=srcnat action=masquerade out-interface=ether1 Is not this a NAT...
by JohnTRIVOLTA
Wed Jun 13, 2018 6:26 am
Forum: Beginner Basics
Topic: Confused about L2TP and IPSec VPNs
Replies: 21
Views: 1997

Re: Confused about L2TP and IPSec VPNs

Encrypted traffic between routers goes through a udp 4500 connection, and I do not see it allowed every router in filter rules!
by JohnTRIVOLTA
Tue Jun 12, 2018 6:35 am
Forum: Beginner Basics
Topic: Confused about L2TP and IPSec VPNs
Replies: 21
Views: 1997

Re: Confused about L2TP and IPSec VPNs

If you have public addresses on both sides, except site to site ipsec, you can also set ip ip tunnel , gre tunnel, eoip tunnel with ipsec and route the local networks through them ! Тhe settings of each of them are literally two clicks . See here - http://systemzone.net/mikrotik-site-to-site-eoip-tu...
by JohnTRIVOLTA
Tue Jun 05, 2018 8:59 pm
Forum: Beginner Basics
Topic: Mikrotik hAP lite As Wifi Extender with different SSID and WPA
Replies: 6
Views: 2980

Re: Mikrotik hAP lite As Wifi Extender with different SSID and WPA

whoops. well if you are in a hurry and a bit dumb that's what happens :D . I edited the post. if you can so too. though I 'll change it now. Ok I 'll try what u suggested me and give it a try. i ll come back with the results. thanks for the answer. edit: can you explain me from which menu I can NAT...
by JohnTRIVOLTA
Mon Jun 04, 2018 11:54 am
Forum: General
Topic: Cannot Access VPN from Outside
Replies: 4
Views: 506

Re: Cannot Access VPN from Outside

Cloud features are used when you have a dynamic public address, not a private one . If you do not have a public address, you can not access your router.
by JohnTRIVOLTA
Sat Jun 02, 2018 10:52 am
Forum: General
Topic: The security flaw for Hajime is closed by the firewall
Replies: 37
Views: 17031

Re: The security flaw for Hajime is closed by the firewall

I had such kind of the invasion too. And now i updated routerOS from 6.41 to 6.42.3. I changed all user's passwords and update my router from the backup which i had before the invasion. But i find this string(screenshot) in the terminal window. What is it mean? This note came from a backup when the...
by JohnTRIVOLTA
Thu May 31, 2018 11:39 pm
Forum: Beginner Basics
Topic: Firewall rules: deny any traffic
Replies: 9
Views: 806

Re: Firewall rules: deny any traffic

And as for me chain=prerouting is not better way because "prerouting" after "input" in the packet flow diagram. Only for you ... Raw section is first in the packet flow , next is the filter ! P.S.First is the prerouting chain, after routing decision the next is forward or input and output chains an...
by JohnTRIVOLTA
Thu May 31, 2018 10:49 pm
Forum: Beginner Basics
Topic: Firewall rules: deny any traffic
Replies: 9
Views: 806

Re: Firewall rules: deny any traffic

Hello everyone. Need a help for newbie. Example section in the documentation say's that I can block everything on input chain with the rule: add chain=input action=drop But. Little bit higher on the same page there are parameters description. And there are words saying that parameter "protocol" has...
by JohnTRIVOLTA
Fri May 25, 2018 11:07 pm
Forum: General
Topic: SSTP Server Problem (port used by another service)
Replies: 6
Views: 799

Re: SSTP Server Problem (port used by another service)

> Yes, just change port number with 444 for example on both sides ! Technically this works, but the idea is to offer VPN-Access when traveling: I would like to stick with 443 since this port is open outgoing for clients from just about everywhere. I understand, but I think two services can not use ...
by JohnTRIVOLTA
Fri May 25, 2018 10:28 pm
Forum: General
Topic: SSTP Server Problem (port used by another service)
Replies: 6
Views: 799

Re: SSTP Server Problem (port used by another service)

Hi, I found a few hints in the forum about this, but did not spot a solution - sorry in case I overlooked it... I use a RB1100AHx4 with a public IP address at eth1 and a hotspot at eth2 with a private IP Address range. When activating the SSTP Server port 443, it complains: "Couldn't change SST Ser...
by JohnTRIVOLTA
Fri May 25, 2018 9:46 pm
Forum: General
Topic: Src-nat internal subnets to different public IPs not working - v6.42.2
Replies: 8
Views: 525

Re: Src-nat internal subnets to different public IPs not working - v6.42.2

I have not - so I would go IP -> Addresses, add .5/32 or the matching Subnet .5/28? Any reason why the /28 isn't covering the entire spread? They should be routed, its a Cable Modem Handoff and the Modem only has 1 Port. Otherwise I wouldnt think the connection would come up if the netmask and scop...
by JohnTRIVOLTA
Fri May 18, 2018 7:03 pm
Forum: Wireless Networking
Topic: RBM33G + two Wireless mpci-e cards ?
Replies: 3
Views: 699

RBM33G + two Wireless mpci-e cards ?

Hello friends, is there a possibility to run two radio modules at the same time on the rbm33g ? I want to run a split signal at 2.4 Ghz and 5 Ghz , i have one AR9380 a/n and one AR9381 b/g/n HP triple chain cards. Now i use only the a/n card! P.S. "Insert the miniPCIe and M.2 cards (not included) an...
by JohnTRIVOLTA
Mon May 07, 2018 10:23 pm
Forum: Wireless Networking
Topic: Where to find # of WIFI VLANS [SOLVED]
Replies: 14
Views: 1377

Re: Where to find # of WIFI VLANS [SOLVED]

Anybody else with actual information? Seems like everyone in Bulgaria drinks heavily all day and should not be allowed near a computer. Every child can run google search engine and the first result gives you answer. I just have added the theoretical number of the vlans to my post ... yes, i drink w...
by JohnTRIVOLTA
Mon May 07, 2018 8:53 pm
Forum: Wireless Networking
Topic: Where to find # of WIFI VLANS [SOLVED]
Replies: 14
Views: 1377

Re: Where to find # of WIFI VLANS [SOLVED]

2007 ssids = 2007 vlans
by JohnTRIVOLTA
Thu Apr 26, 2018 9:45 pm
Forum: Wireless Networking
Topic: CPE And AP on Same Router
Replies: 4
Views: 647

Re: CPE And AP on Same Router

by JohnTRIVOLTA
Thu Apr 26, 2018 6:23 pm
Forum: RouterBOARD hardware
Topic: How to add a ethernet port to RBM33G (mpcie)
Replies: 8
Views: 1077

Re: How to add a ethernet port to RBM33G (mpcie)

It's not possible, because I need 3 ethernet port for our project, and a mPCI used for LTE with R11e-LTE.

It is why I need to add a port or a way to communicate with the board.

Regards.
Olivier
Communicate with the board wirelessly through the second mPCI-E wifi adapter !?
by JohnTRIVOLTA
Tue Apr 24, 2018 10:04 pm
Forum: Scripting
Topic: Establish a L2L tunnel on wan failover
Replies: 1
Views: 385

Re: Establish a L2L tunnel on wan failover

Add static route to the L2 vpn server ip address through LTE interface.Add l2tp-out /L2TP client/ and use netwatch to check main gateway , when is on down execute /interface ppp-client enable l2tp-out1 or when is on up - interface ppp-client disable l2tp-out1 !
by JohnTRIVOLTA
Tue Apr 24, 2018 7:27 pm
Forum: Beginner Basics
Topic: don't write logs
Replies: 5
Views: 535

Re: don't write logs

maybe... did you try to check how many lines you have setup? /system logging action print look for "memory-lines= ..." Or go to System / Logging / Actions / memory / Lines Thank you, I've solved the problem ... System / Logging / Actions / disk / Lines are only 1, but why i don't know - they was se...
by JohnTRIVOLTA
Tue Apr 24, 2018 6:52 pm
Forum: Beginner Basics
Topic: don't write logs
Replies: 5
Views: 535

Re: don't write logs

I have completly same problem with my RB3011 ! I'm waiting to see at 22 o'clock what log file will send me to the mail automaticly !
by JohnTRIVOLTA
Mon Apr 23, 2018 3:12 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 204
Views: 161611

Re: Advisory: Vulnerability exploiting the Winbox port

But that whats the point of this, i ran it 3 times and got all my ports listed 3 times before mikrotik blocked it, "attacker" already have all it needs.
Scan this 93.155.148.98 - my IP address and tell me the open ports please!
by JohnTRIVOLTA
Mon Apr 23, 2018 2:50 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 204
Views: 161611

Re: Advisory: Vulnerability exploiting the Winbox port

But if i run it from https://mxtoolbox.com/SuperTool.aspx?action=scan, it finishes every time and shows my open ports on router without blocking it.. Try for your self. OK, try this : ip fi fi add action=add-src-to-address-list address-list=Port_Scanner address-list-timeout=1w chain=input comment="...
by JohnTRIVOLTA
Mon Apr 23, 2018 2:12 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 204
Views: 161611

Re: Advisory: Vulnerability exploiting the Winbox port

What do do : 1) Firewall the Winbox port from the public interface, and from untrusted networks. It is best, if you only allow known IP addresses to connect to your router to any services, not just Winbox. We suggest this to become common practice. As an alternative, possibly easier, use the "IP ->...
by JohnTRIVOLTA
Sat Apr 21, 2018 9:54 pm
Forum: General
Topic: winbox vulnerable! Unusual login to routers [SOLVED]
Replies: 44
Views: 10344

Re: winbox vulnerable! Unusual login to routers [SOLVED]

In point 1 you're wrong, just like the password type, I had a password of type "@ _23UbakJav!2947!#6hasd! - +)" and they have entered with a single attempt, it is something more serious that lets you see the key, only way to close all the ports to the computers on the LAN. Where is the Cyrillic alp...
by JohnTRIVOLTA
Sat Apr 21, 2018 7:38 pm
Forum: General
Topic: winbox vulnerable! Unusual login to routers [SOLVED]
Replies: 44
Views: 10344

Re: winbox vulnerable! Unusual login to routers [SOLVED]

1.Set user name and password with combination with cyrillic alphabet after that remoove or disable user - admin ! 2.Change the port numbers for ssh , winbox etc. 3.Set strog crypto for ssh 4.Set ACL 5.Set 3 attempts login to black list and deny attempts with RAW 6,Disable all other non-useable servi...
by JohnTRIVOLTA
Fri Apr 20, 2018 8:33 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 113454

Re: v6.43rc [release candidate] is released!

*) wireless - improved compatibility with BCM chipset devices (this includes phones by Xiaomi, Lenovo, etc); SUPER . I try some test and the 20 mb/ps speed problem and 54mb/ps connectivity with mobile phones is resolved ! Test Xiaomi https://s26.postimg.cc/i3qlimq3d/xiaomi_TEST.png Test Nokia https...
by JohnTRIVOLTA
Wed Apr 18, 2018 7:29 pm
Forum: Announcements
Topic: v6.42 [current]
Replies: 147
Views: 28133

Re: v6.42 [current]

I have hap lite /smips/ with 6.41.2 . With 6.42 in station mode and WEP security /40bit/not work - can not connect. I downgrade to bugfix 6.40.7 and everything is fine - the routrboard is connected !
by JohnTRIVOLTA
Tue Apr 10, 2018 10:56 am
Forum: Forwarding Protocols
Topic: EoIP Tunnel is Running but not passing traffic
Replies: 3
Views: 1788

Re: EoIP Tunnel is Running but not passing traffic

Allow in firewall filter sectionon port udp 500,4500 and GRE /47/ with in-interface WAN and put the rules on top of the section !
by JohnTRIVOLTA
Tue Mar 27, 2018 10:42 pm
Forum: Beginner Basics
Topic: Problem with port forwarding for RemoteDesktop
Replies: 17
Views: 5577

Re: Problem with port forwarding for RemoteDesktop

GENERAL TAB chain:forward protocol:6(tcp) dst.port:3389 ACTION TAB Action:accept And my remote desktop still not works:( thanks in andvance for help. Add same rule with chain INPUT -put this rule to the top on filter section ! You don't need to add input rules for dst nat to work... Why ? If you ha...
by JohnTRIVOLTA
Tue Mar 27, 2018 6:14 am
Forum: Beginner Basics
Topic: Problem with port forwarding for RemoteDesktop
Replies: 17
Views: 5577

Re: Problem with port forwarding for RemoteDesktop

GENERAL TAB
chain:forward
protocol:6(tcp)
dst.port:3389
ACTION TAB
Action:accept
And my remote desktop still not works:( thanks in andvance for help.
Add same rule with chain INPUT -put this rule to the top on filter section !
by JohnTRIVOLTA
Mon Mar 26, 2018 8:00 pm
Forum: Beginner Basics
Topic: ssh settings
Replies: 3
Views: 603

Re: ssh settings

I think strong crypto enforcing ssh connection to use aes 256 algorithm for encryption !
by JohnTRIVOLTA
Tue Mar 13, 2018 6:51 am
Forum: The Dude
Topic: Mac Address Block
Replies: 3
Views: 615

Re: Mac Address Block

I dont want a given Mac Address to get an IP Address from my DHCP pool Use bridge filter - /interface bridge filter add mac-protocol=ip src-address=192.168.88.1/32 dst-port=68 dst-mac-address=XX:XX:XX:XX:XX:XX 192.168.88.1/32 - replace with actual dhcp ip address XX:XX:XX:XX:XX:XX - replace with re...
by JohnTRIVOLTA
Mon Mar 12, 2018 9:32 pm
Forum: The Dude
Topic: Mac Address Block
Replies: 3
Views: 615

Re: Mac Address Block

Hello,

How can I block DHCP lease for specific mac addresses?
Block or not use lease time ? Just make static addresses for this specific mac addresses in leases table in dhcp server menu !
by JohnTRIVOLTA
Mon Mar 12, 2018 2:52 pm
Forum: General
Topic: Tunnel between two routers
Replies: 2
Views: 390

Re: Tunnel between two routers

Hi Boris, in your case you must set some ppp server on the main router with public ip and route over this ppp link the both lans . If you want to extend transparent lan on main router , just use BCP on bridges on both sites ! if you want to explain in detail you can post a theme in kaldata, аt least...
by JohnTRIVOLTA
Mon Mar 05, 2018 3:19 pm
Forum: General
Topic: Bridge - Use local Gateway
Replies: 2
Views: 291

Re: Bridge - Use local Gateway

Hello, i have two offices. The local LAN 192.168.0.0/24 is bridged between both offices. (eoip tunnel + eth ports) Office1 provides the DHCP server and the default gateway. Now i would like clients in Office2 to use the local internet, instead of going through the brigde. It seems an easy task, but...
by JohnTRIVOLTA
Sat Feb 17, 2018 12:35 pm
Forum: Beginner Basics
Topic: Mikrotik RB941-2ND-TC: VPN Throughput
Replies: 7
Views: 2008

Re: Mikrotik RB941-2ND-TC: VPN Throughput

Hey thanks for the reply!
I will need like 30 - 40Mbit/s.
Do you guys think that I will achieve this speeds?

Many thanks to all.
Kind regards
Rather around 20Mbit/s with aes128cbc !
by JohnTRIVOLTA
Sat Feb 10, 2018 9:31 am
Forum: RouterBOARD hardware
Topic: HAP AC2 PERFORMANCE NUMBERS
Replies: 14
Views: 7235

Re: HAP AC2 PERFORMANCE NUMBERS

i dream an rb750GR4 on this chipset
Why, the router has five ports ... rather we are waiting for a flagship with 8+ Geternet ports , SFP+, hdd bay sata3, HighPower radios 802.11ac/ax 8/4-stream Dual-band with combo /5GHz and 2.GHz /
external antennas ... maybe based on Qualcomm IPQ8074 !
by JohnTRIVOLTA
Thu Jan 25, 2018 6:31 am
Forum: Beginner Basics
Topic: Dual WAN Load Balancing with Fail-over
Replies: 7
Views: 13038

Re: Dual WAN Load Balancing with Fail-over

Hi,

Would you mind explaining me a little what these ratio does?
The connections across the router alternate respectively three connections through the first wan and one connection through the second !
by JohnTRIVOLTA
Fri Jan 19, 2018 8:34 pm
Forum: General
Topic: Host to Host Connection not happening via Mikrotik Router
Replies: 19
Views: 1275

Re: Host to Host Connection not happening via Mikrotik Router

You dont need nat or static routes !!! Just add in firewall filter 2 rules:
/ip fi fi
add chain=forward src-address=192.168.12.0/24 dst-address=192.168.110.0/24 action=accept
add chain=forward src-address=192.168.110.0/24 dst-address=192.168.12.0/2 action=accept
by JohnTRIVOLTA
Thu Jan 11, 2018 10:04 pm
Forum: Beginner Basics
Topic: Port forward not working for me [SOLVED]
Replies: 18
Views: 2445

Re: Port forward not working for me [SOLVED]

I'm a bit noob. How do I do that? :shock:
https://wiki.mikrotik.com/wiki/Hairpin_NAT
or
/ip dns static add name=www.xxxxxxxx.duckdns.org address=192.168.10.16
by JohnTRIVOLTA
Thu Jan 11, 2018 7:13 pm
Forum: Beginner Basics
Topic: Port forward not working for me [SOLVED]
Replies: 18
Views: 2445

Re: Port forward not working for me [SOLVED]

If you want to access it/web server/ from the local network , you must set Hairpin NAT , or if the board have DNS role you must add a static entry on DNS section !
by JohnTRIVOLTA
Thu Jan 11, 2018 10:54 am
Forum: Beginner Basics
Topic: Port forward not working for me [SOLVED]
Replies: 18
Views: 2445

Re: Port forward not working for me [SOLVED]

he just has to place up the rules and the last input rule must be - /add action=drop chain=input comment="Drop everything else"
by JohnTRIVOLTA
Thu Jan 11, 2018 10:20 am
Forum: Beginner Basics
Topic: Port forward not working for me [SOLVED]
Replies: 18
Views: 2445

Re: Port forward not working for me [SOLVED]

Just add accept rule for port tcp 8123 in filter section:
/ip fi fi add action=accept chain=input comment="allow WEB" dst-port=8123 protocol=tcp place-before=3
by JohnTRIVOLTA
Sun Jan 07, 2018 3:40 pm
Forum: General
Topic: Problems with proxy-arp after upgrade from 6.39.1 to 6.41
Replies: 6
Views: 1759

Re: Problems with proxy-arp after upgrade from 6.39.1 to 6.41

I have similar issue with proxy-arp . I have build sstp connection with BCP between 2 routerboards. After upgrade ROS to 6.41 i lost the network discovery between bridges!
by JohnTRIVOLTA
Wed Dec 27, 2017 10:35 pm
Forum: Wireless Networking
Topic: wAP AC 5GHz problem
Replies: 4
Views: 562

Re: wAP AC 5GHz problem

First , i thank you for the help !
I understand that the power adapter has been changed inadvertently with less than 0.2A 24v and may be the problem!
I will write by replacing it if everything is all right, at 99% I'm sure this is the solution.
by JohnTRIVOLTA
Tue Dec 26, 2017 8:52 pm
Forum: Wireless Networking
Topic: wAP AC 5GHz problem
Replies: 4
Views: 562

Re: wAP AC 5GHz problem

I have all 3chains enabled and no problems with restart. Maybe you have problem with power?
On Sys/Health i see 23.1v ... this is normal ?
by JohnTRIVOLTA
Tue Dec 26, 2017 7:12 pm
Forum: Wireless Networking
Topic: wAP AC 5GHz problem
Replies: 4
Views: 562

wAP AC 5GHz problem

Hi all, i have a problem with wAP AC 5GHz radio , when I test the speed with the phone the board is always restarted, and when I uncheck one of the chains /second or third/ everything is fine and i get maximum speed ! In conclusion, the board works with only 2 chains regardless of which one we chose...
by JohnTRIVOLTA
Fri Dec 22, 2017 12:09 pm
Forum: General
Topic: Prevent Client comunication - block relay
Replies: 2
Views: 336

Re: Prevent Client comunication - block relay

You talking about wireless isolation ? Do not use a "default forward" on the radio interface settings!
by JohnTRIVOLTA
Sun Dec 10, 2017 9:28 pm
Forum: General
Topic: Mikrotik to Mikrotik VPN - Dynamic IP
Replies: 7
Views: 615

Re: Mikrotik to Mikrotik VPN - Dynamic IP

Hi yeah thanks for pointing that bit out, thats the bit I already know how to do

What main crux of my question was how to do this with a dynamic public IP address at both ends.
Choose the one of routers for vpn server and use cloud /ddns/ for establish the ppp connection !
by JohnTRIVOLTA
Sun Dec 10, 2017 2:50 pm
Forum: General
Topic: Mikrotik to Mikrotik VPN - Dynamic IP
Replies: 7
Views: 615

Re: Mikrotik to Mikrotik VPN - Dynamic IP

Put addresses at both ends of the ppp link /examp. 10.100.0.1/30 and 10.100.0.2/30 /.Route home networks over this addresses / add static route in main routing table for each home network respectively/ and make an exception in filter section on firewall for accepting the traffic between them .
by JohnTRIVOLTA
Wed Nov 29, 2017 11:39 am
Forum: Beginner Basics
Topic: Pro's & Cons GRE-IPIP-EoIP
Replies: 5
Views: 2022

Re: Pro's & Cons GRE-IPIP-EoIP

EoIP can carry L2 frame for transparent bridge purpose, the other two can use for routing purpose !
by JohnTRIVOLTA
Thu Oct 26, 2017 11:57 am
Forum: Beginner Basics
Topic: Adding Facebook Block
Replies: 5
Views: 550

Re: Adding Facebook Block

I have already. I would just like to know if it possible and how to do it. I have managed to do the Facebook block but I need to know if the WhatsApp Desktop Client can be blocked. I tried blocking it through Windows Firewall but I am still able to open WhatsApp, send and receive messages. Try with...
by JohnTRIVOLTA
Tue Oct 24, 2017 11:37 am
Forum: General
Topic: Blocking
Replies: 1
Views: 311

Re: Blocking

Use only your routerboard for clients DNS server, drop udp and tcp 53 in forward chain , finally make static dns enty for facebook with regex ^(.*)(facebook)(.*)$ on address 172.0.0.1 !
Don't remember to flush dns cashe.
by JohnTRIVOLTA
Tue Oct 24, 2017 11:25 am
Forum: General
Topic: Traffic passes firewall rules - what I don't understand? [SOLVED]
Replies: 13
Views: 1664

Re: Traffic passes firewall rules - what I don't understand? [SOLVED]

Remove in-interface on the forward drop rules !
by JohnTRIVOLTA
Mon Oct 23, 2017 10:59 pm
Forum: Beginner Basics
Topic: Router to Router VLAN link over L2TP [SOLVED]
Replies: 5
Views: 1040

Re: Router to Router VLAN link over L2TP [SOLVED]

L2TP is layer 3.
Are you sure ? How then can this tunnel (or all ppp tunnels) carry EoIP or all ppp tunnels with BCP carry L2 traffic?


Тo topic author :
Use bcp on bridges on both sites !
by JohnTRIVOLTA
Wed Oct 18, 2017 7:16 pm
Forum: Beginner Basics
Topic: One way video - PBX [SOLVED]
Replies: 9
Views: 842

Re: One way video - PBX [SOLVED]

just try this :
/ip fi service-port disable sip,h323
by JohnTRIVOLTA
Mon Oct 16, 2017 10:14 am
Forum: Beginner Basics
Topic: Do Nat or routing between private network [SOLVED]
Replies: 14
Views: 1728

Re: Do Nat or routing between private network [SOLVED]

The rules in a filter section are read in sequence for their execution. For that we first allow, and then we drop everything else! the firs allow connection with the router from external host through that ports (22,8291,80,443) - Yes because we have drop on input chain on ether6 on rule 4 ! the seco...
by JohnTRIVOLTA
Sun Oct 15, 2017 9:06 pm
Forum: Announcements
Topic: v6.40.4 [current]
Replies: 103
Views: 25731

Re: v6.40.4 [current]

Problem with SSTP. RB2011 here. I have 22 clients connecting to various services from their homes using SSTP with cert. After upgrading to v6.40.4 I'm able to establish the connection, but for example - I can't RDP to Windows PCs. I can't ping any internal address from my IP pool. After downgrade t...
by JohnTRIVOLTA
Sun Oct 15, 2017 8:39 pm
Forum: Beginner Basics
Topic: Do Nat or routing between private network [SOLVED]
Replies: 14
Views: 1728

Re: Do Nat or routing between private network [SOLVED]

Also, I changed the IP pool to the grade nat 100.64.0.0/24 and it's working. Do you think that I can bring any trouble? because generally it's the opossite. The private ip pool and then the grade nat pool. In this case is grade nat pool and a nat to a private pool. But with this implementation I ca...
by JohnTRIVOLTA
Sun Oct 15, 2017 6:32 pm
Forum: Beginner Basics
Topic: Do Nat or routing between private network [SOLVED]
Replies: 14
Views: 1728

Re: Do Nat or routing between private network [SOLVED]

/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether2

Fix this with ether6 !

P.S. The routes are enough, you do not have to add others!
P.P.S. I want to see too:
/ip dhcp-server network print
and
/ip dhcp-server lease print detail
by JohnTRIVOLTA
Sun Oct 15, 2017 7:04 am
Forum: Beginner Basics
Topic: Do Nat or routing between private network [SOLVED]
Replies: 14
Views: 1728

Re: Do Nat or routing between private network [SOLVED]

if you have ttl=1 the packet will die on the wan interface... some ISP still use this limitation ! ОК now you try to use private network not carrier network for your lan - example: 172.16.0.0/24 Dont use master port for ether 6 remoove my firewall rule and paste this basic rules: /ip firewall add ch...
by JohnTRIVOLTA
Sun Oct 15, 2017 6:39 am
Forum: Beginner Basics
Topic: Do Nat or routing between private network [SOLVED]
Replies: 14
Views: 1728

Re: Do Nat or routing between private network [SOLVED]

Use ping in tool menu in winbox or in gui for ping 8.8.8.8 using interface ether6 and tell me the ttl value !
by JohnTRIVOLTA
Sun Oct 15, 2017 5:50 am
Forum: Beginner Basics
Topic: Do Nat or routing between private network [SOLVED]
Replies: 14
Views: 1728

Re: Do Nat or routing between private network [SOLVED]

When you ping 8.8.8.8 what value is there for ttl ?
by JohnTRIVOLTA
Sun Oct 15, 2017 12:13 am
Forum: Beginner Basics
Topic: Do Nat or routing between private network [SOLVED]
Replies: 14
Views: 1728

Re: Do Nat or routing between private network [SOLVED]

If you have access to Any Router, make routing , just set another nat rule with youre network.If yo have not access, respectivly setup nat on second router !
In this setup just add this rule in firewall and tell us what's happened :
/ip fi fi add chain=forward
use Terminal
by JohnTRIVOLTA
Sat Oct 14, 2017 9:23 pm
Forum: Beginner Basics
Topic: Configured a NAT without know the destination address
Replies: 6
Views: 547

Re: Configured a NAT without know the destination address

Why should I use firewall rules? The only thing I want to do is a nat and the host OS take care of the firewall. Or it's necesary to make a nat? I use rip because the router will learn the network. I can't make an static route because I don't know the public network. do I? First, you will not route...
by JohnTRIVOLTA
Sat Oct 14, 2017 8:07 pm
Forum: Beginner Basics
Topic: Configured a NAT without know the destination address
Replies: 6
Views: 547

Re: Configured a NAT without know the destination address

I want to see firewall rules too ! Ping to 8.8.8.8 on lan pc's?
P.S. You can update the routerboard to final bugfix release of ROS after firmware update of course!
P.P.S. Why you use RIP mostly on LAN?
by JohnTRIVOLTA
Sat Oct 14, 2017 6:17 pm
Forum: Beginner Basics
Topic: Configured a NAT without know the destination address
Replies: 6
Views: 547

Re: Configured a NAT without know the destination address

/ ip fi nat add chain=src-nat action=masquerade out-interface=ether6
When we have dhcp client for wan, we must use masquerade action !!!
by JohnTRIVOLTA
Thu Oct 12, 2017 10:19 am
Forum: General
Topic: Site to Site Eoip Tunnel with same ip range [SOLVED]
Replies: 7
Views: 977

Re: Site to Site Eoip Tunnel with same ip range [SOLVED]

hello, John Intranetwork is work fine but there is some issue causes while browsing internet to the client pc is there any rule to be apply. To work both internet and intra-network If you want the "slave" site to use its own Internet instead of using the master router tunnel, do not use the dhcp se...
by JohnTRIVOLTA
Tue Oct 10, 2017 9:03 pm
Forum: General
Topic: Site to Site Eoip Tunnel with same ip range [SOLVED]
Replies: 7
Views: 977

Re: Site to Site Eoip Tunnel with same ip range [SOLVED]

Are you sure the eoip and lan/ether/ are in bridge on both sites ?You can put lan segment addresses on bridges , for example 192.168.2.1/24 and other 192.168.2.2/24 and set dhcp serv on bridge in the main router .Be sure the input rule is at the top in filter section !Are you using IPSEC with eoip?
by JohnTRIVOLTA
Tue Oct 10, 2017 2:33 pm
Forum: General
Topic: Site to Site Eoip Tunnel with same ip range [SOLVED]
Replies: 7
Views: 977

Re: Site to Site Eoip Tunnel with same ip range [SOLVED]

On the two routers in firewall filter you have to allow GRE protocol on input chain !
You do not need to put addresses on EoIP interfaces, only if you have some routing solution!
by JohnTRIVOLTA
Mon Oct 09, 2017 8:03 pm
Forum: Beginner Basics
Topic: Joining 2 subnets??
Replies: 7
Views: 763

Re: Joining 2 subnets??

Just add 2 rules in firewall filter on the top of the forwards rules:
These are completely unnecessary. You should NOT add them because they don't do anything that isn't done already.
Because i don't know full firewall setup ,let try to set them !
by JohnTRIVOLTA
Mon Oct 09, 2017 7:46 pm
Forum: Beginner Basics
Topic: Joining 2 subnets??
Replies: 7
Views: 763

Re: Joining 2 subnets??

Hi people, i´m wondering if i need to set statics routes for comunicate two subnets in the same router RB-951G Here is the thing: Bridge_work=ether 2 and ether 3 / DHCP server=10.2.3.0/24 / Bridge_home=wlan1 / DHCP server=10.2.1.0/24 So, my cuestion is : do i need to set static routes for get a goo...
by JohnTRIVOLTA
Mon Oct 09, 2017 6:30 pm
Forum: Beginner Basics
Topic: how to remove the fasttrack dummy rule ? [SOLVED]
Replies: 2
Views: 3328

Re: how to remove the fasttrack dummy rule ? [SOLVED]

Remove the fasttrack connection rule on firewall filter and reboot the board !
This rule only helps to unload the processor for best performance!
by JohnTRIVOLTA
Mon Oct 09, 2017 5:32 pm
Forum: General
Topic: L2TP/IPSEC client-to-client [SOLVED]
Replies: 8
Views: 1174

Re: L2TP/IPSEC client-to-client [SOLVED]

Pls write it in our forum http://www.mikrotik-bg.net to solve the problem ! P.S. Keep the Bulgarian tradition of putting a minus on a person who wants to help you, I was easier to explain the settings in our native language! Anyway, check the routes and see the firewall of the main router Ванчо ! I...
by JohnTRIVOLTA
Sun Oct 08, 2017 5:42 pm
Forum: General
Topic: L2TP/IPSEC client-to-client [SOLVED]
Replies: 8
Views: 1174

Re: L2TP/IPSEC client-to-client [SOLVED]

Pls write it in our forum http://www.mikrotik-bg.net to solve the problem !

P.S. Keep the Bulgarian tradition of putting a minus on a person who wants to help you, I was easier to explain the settings in our native language! Anyway, check the routes and see the firewall of the main router Ванчо !
by JohnTRIVOLTA
Sun Oct 08, 2017 4:57 pm
Forum: General
Topic: L2TP/IPSEC client-to-client [SOLVED]
Replies: 8
Views: 1174

Re: L2TP/IPSEC client-to-client [SOLVED]

try adding the routes:
for Router 2.2.2.2 - /ip route add dst-address=10.0.3.0/24 gateway=172.16.1.1 ,
for Router 3.3.3.3 - /ip route add dst-address=10.0.2.0/24 gateway=172.16.1.1
by JohnTRIVOLTA
Sat Sep 30, 2017 9:51 am
Forum: Forwarding Protocols
Topic: NetBIOS block ?
Replies: 10
Views: 2811

Re: NetBIOS block ?

This is a right rule for hairpin nat if you use http for access :
/ip firewall nat
add chain=srcnat src-address=192.168.10.0/24 dst-address=192.168.10.40 protocol=tcp dst-port=80 out-interface=LAN action=masquerade
by JohnTRIVOLTA
Fri Sep 29, 2017 11:21 pm
Forum: Forwarding Protocols
Topic: NetBIOS block ?
Replies: 10
Views: 2811

Re: NetBIOS block ?

add action=dst-nat chain=dstnat dst-address=77.162.238.*** to-addresses=\
192.168.10.40

Remove this nat rule , because you are forward all ports to the local address 192.168.10.40 , that is, they become visible to the public !
by JohnTRIVOLTA
Fri Sep 29, 2017 11:09 pm
Forum: General
Topic: RB3011 UNIFY VLAN
Replies: 1
Views: 469

Re: RB3011 UNIFY VLAN

/interface vlan add interface=ether2 name=eth2-vlan10 vlan-id=10 add interface=ether2 name=eth2-vlan20 vlan-id=20 add interface=ether3 name=eth3-vlan10 vlan-id=10 add interface=ether3 name=eth3-vlan20 vlan-id=20 add interface=ether4 name=eth4-vlan10 vlan-id=10 add interface=ether4 name=eth4-vlan20 v...
by JohnTRIVOLTA
Thu Sep 28, 2017 6:11 pm
Forum: General
Topic: Forwarding traffic from Virtual AP to VPN: performance issues
Replies: 6
Views: 845

Re: Forwarding traffic from Virtual AP to VPN: performance issues

Thank you. That improves the performance a little, up to ~3 Mbps, but still nowhere near the bandwidth test results. When I have the Torch tool enabled performance goes up?! Could you post your settings? Which settings you are interested in? I use 5GHz for vAP , because there is much interference a...
by JohnTRIVOLTA
Tue Sep 26, 2017 10:48 pm
Forum: General
Topic: Forwarding traffic from Virtual AP to VPN: performance issues
Replies: 6
Views: 845

Re: Forwarding traffic from Virtual AP to VPN: performance issues

You can try to add new bridge interface and put there VirtualAP ! Put ip and dhcp on this bridge and change in-interface respectively in the mangle rule . I have this setup and works fine !
VPN srcnat is 1st rule in the nat section with defined src addresses/network/ !
by JohnTRIVOLTA
Tue Sep 26, 2017 9:10 pm
Forum: Beginner Basics
Topic: Block DDos Attack and be able to access internet [SOLVED]
Replies: 4
Views: 4803

Re: Block DDos Attack and be able to access internet [SOLVED]

Not that the previous decisions are wrong, but I think this is the right one :
/ip firewall raw
add action=drop chain=prerouting dst-port=53 in-interface=WAN protocol=tcp
add action=drop chain=prerouting dst-port=53 in-interface=WAN protocol=udp
by JohnTRIVOLTA
Mon Sep 11, 2017 11:07 am
Forum: Announcements
Topic: v6.40.3 [current]
Replies: 95
Views: 26238

Re: v6.40.3 [current]

JohnTRIVOLTA - This problem is already fixed in 6.41rc version. However, I recommend to fix the script. E-mail tool does not have a full file name in your script so if there will be two files with similar names, then you will still get an error. For example, now you specify file=test, but actual fi...
by JohnTRIVOLTA
Sun Sep 10, 2017 8:38 pm
Forum: Announcements
Topic: v6.40.3 [current]
Replies: 95
Views: 26238

Re: v6.40.3 [current]

RB3011 stop sending logs to email when upgrade the board to 6.40.3 "error handling file" .After that i revert the board to 6.39.2 and problem is gone !
by JohnTRIVOLTA
Sun Sep 10, 2017 4:33 pm
Forum: General
Topic: Nat rule not working for internal network
Replies: 3
Views: 1666

Re: Nat rule not working for internal network

Do you have a rule in the filter section for accepting traffic over the general drop rule:
/ip fi fi add chain=input in-interface=wan protocol=tcp dst-port=119
by JohnTRIVOLTA
Fri Sep 08, 2017 6:59 pm
Forum: Beginner Basics
Topic: Site to Site VPN (on both sides same ip subnet)
Replies: 17
Views: 6717

Re: Site to Site VPN (on both sides same ip subnet)

Do you have an example of configure a EoIP with IPSEC? example: side A ip wan address - 111.111.111.111 , ip address LAN bridge 192.168.0.1/24 dhcp pool 192.168.0.100-192.168.0.200 side B ip wan address - 222.222.222.222 , ip address LAN bridge 192.168.0.2/24 , without DHCP server Side A: /ip ipsec...
by JohnTRIVOLTA
Fri Sep 08, 2017 1:30 pm
Forum: Beginner Basics
Topic: Site to Site VPN (on both sides same ip subnet)
Replies: 17
Views: 6717

Re: Site to Site VPN (on both sides same ip subnet)

Hi, Thanks for your reply. I have on both sites Static IP addresses. SO is EoIP the best option? Is it easy to configure (and save?) Not only static, but also public addresses ! Yes , its easy to configure EoIP with IPSEC , but you should know that the maximum speed between the sites will be around...
by JohnTRIVOLTA
Fri Sep 08, 2017 9:15 am
Forum: Beginner Basics
Topic: Site to Site VPN (on both sides same ip subnet)
Replies: 17
Views: 6717

Re: Site to Site VPN (on both sides same ip subnet)

Hi, I have a question. Is it possibile to build a Site-to-Site VPN tunnel (secure) with on both sides Mikrotik routers. On both sides we use the same IP range and subnet. You want to create a secure transparent bridge between two sites - there are several ways to make it ! 1.You can use EoIP with I...
by JohnTRIVOLTA
Mon Sep 04, 2017 3:38 pm
Forum: General
Topic: Seriously, what is Mikrotik's problem with Apple Devices?
Replies: 21
Views: 7491

Re: Seriously, what is Mikrotik's problem with Apple Devices?

How long was the apple client sleeping, when he got this issue waking up? Try to run packet sniffer before he wakes up, then during the issue. OK , but this is a remote place , for this next week as I go to the site I will generate a file to explore it ! P.S. I have activated the sniffer for this m...
by JohnTRIVOLTA
Mon Sep 04, 2017 2:43 pm
Forum: General
Topic: Seriously, what is Mikrotik's problem with Apple Devices?
Replies: 21
Views: 7491

Re: Seriously, what is Mikrotik's problem with Apple Devices?

Lease time is 1 day . Тhe problem is that the device is trying to get an IP address - then a free one IP from the dhcp pool for 15-20 minutes and finally the device takes one. After an indefinite time, this problem is repeated ! P.S. I hope the problem is in the Apple device, which I say to its owner!
by JohnTRIVOLTA
Mon Sep 04, 2017 2:13 pm
Forum: General
Topic: Seriously, what is Mikrotik's problem with Apple Devices?
Replies: 21
Views: 7491

Re: Seriously, what is Mikrotik's problem with Apple Devices?

I have problem with apple devices too !
Image
My router RB3011- ros 6.39.2 after upgrade to 6.40.3 , the problem is still here . The APs are Linksys, TP-Links ! The problem is only with this Apple device with this mac addr.!
by JohnTRIVOLTA
Fri Sep 01, 2017 12:37 pm
Forum: Beginner Basics
Topic: RB750 And Problem with port forwarding when i use mark routing
Replies: 5
Views: 693

Re: RB750 And Problem with port forwarding when i use mark routing

please help me......
First disable service http /port 80/ on the router , after that add the nat rule:
/ip fi nat
add chain=dstnat dst-address= put wan ip address portocol=tcp port=80 action=dst-nat to-addresses:192.168.10.1 to-ports=80
by JohnTRIVOLTA
Sat Aug 26, 2017 1:51 pm
Forum: Beginner Basics
Topic: RB750 And Problem with port forwarding when i use mark routing
Replies: 5
Views: 693

Re: RB750 And Problem with port forwarding when i use mark routing

see this example: add chain=prerouting in-interface=WAN1 connection-mark=no-mark action=mark-connection new-connection-mark=WAN1_conn add chain=prerouting in-interface=WAN2 connection-mark=no-mark action=mark-connection new-connection-mark=WAN2_conn add chain=prerouting in-interface=VLAN10 connectio...
by JohnTRIVOLTA
Fri Aug 25, 2017 11:04 am
Forum: General
Topic: About RB750Gr3
Replies: 8
Views: 1078

Re: About RB750Gr3

What APs you will use ? Do not use cAP Lite, mAP Lite if more devices / more than 5-6 / will connect to each one ! Why? I've had about 15 devices connected to a mAP-lite. Not using a lot of bandwidth but it worked fine. I use a couple /around 14/ of cAP Lite, mAPs Lite and 2 hAP AC Lite for APs wit...
by JohnTRIVOLTA
Thu Aug 24, 2017 4:33 pm
Forum: General
Topic: About RB750Gr3
Replies: 8
Views: 1078

Re: About RB750Gr3

What APs you will use ? Do not use cAP Lite, mAP Lite if more devices / more than 5-6 / will connect to each one !
by JohnTRIVOLTA
Thu Aug 24, 2017 3:04 pm
Forum: General
Topic: About RB750Gr3
Replies: 8
Views: 1078

Re: About RB750Gr3

Hi, all. I need to know if this routerboard https://mikrotik.com/product/RB750Gr3 can handle 150-200 clients only routing without QoS. This is diagram of network topology https://goo.gl/photos/VZtViMQnFtWRrgrZ8 . This network is in hotel. Best regards https://s26.postimg.org/4a3we306x/caps_Man2.png...
by JohnTRIVOLTA
Mon Aug 14, 2017 11:31 pm
Forum: Beginner Basics
Topic: Connect to mikrotik without ethernet on linux
Replies: 14
Views: 2522

Re: Connect to mikrotik without ethernet on linux

Get another mikrotik with wlan and set it on a bridge! Then connect the laptop with it and you can connect with winbox on the 2 level - mac address ! We are waiting for Woobm "Plug into a device to have a new management AP" !
by JohnTRIVOLTA
Mon Aug 14, 2017 11:12 pm
Forum: Beginner Basics
Topic: OpenVPN can't access lan
Replies: 2
Views: 1309

Re: OpenVPN can't access lan

Hello I'm new at the routerOS and I have same problems. My isp router is 192.168.10.1 Mikrotik router 192.168.10.2 ether1 connects with isp router. Ether2-ether5 is bridge and I have my network 192.168.1.0/24. I tried to setup a ovpn server 10.0.0.1 I make a pool with network 10.0.0.2-20 I connect ...
by JohnTRIVOLTA
Sun Aug 13, 2017 5:59 pm
Forum: Scripting
Topic: how i can disable and then enable pppoe users automatic ?
Replies: 6
Views: 1158

Re: how i can disable and then enable pppoe users automatic ?

Mercy John But I do not have a HotSpot. My users use ppp\secret account and DHCP pool and profile . Thanks for helping me. Sorry, the setting is the same, just replace with " ppp secret disable user1,user2,user3" and t " ppp secret enable user1,user2,user3" scripts .Change the name of the schedule ...
by JohnTRIVOLTA
Sun Aug 13, 2017 1:00 pm
Forum: Scripting
Topic: how i can disable and then enable pppoe users automatic ?
Replies: 6
Views: 1158

Re: how i can disable and then enable pppoe users automatic ?

Please help me . This is my example: /system scheduler add name=EnableHSusers on-event="system script run enableHSusers" policy=\ ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \ start-date=aug/13/2017 start-time=08:00:00 add name=DisableHSusers on-event=" system script run disabl...
by JohnTRIVOLTA
Fri Aug 11, 2017 11:12 pm
Forum: Scripting
Topic: Netwatch logging and send log daily by email
Replies: 9
Views: 2994

Re: Netwatch logging and send log daily by email

I'm a beginner of RouterOS ;) I would like to set up a lan monitoring tool that send me the log daily. Email is already configured. Using netwatch i want log only if a host is down. But how can i write a specific log only dedicated to netwatch and send it only daily by email ? How can i "reset" the...
by JohnTRIVOLTA
Wed Aug 09, 2017 5:53 pm
Forum: General
Topic: Mikrotik won't connect to hidden wi-fi
Replies: 2
Views: 528

Re: Mikrotik won't connect to hidden wi-fi

Add an entry to the "connect list" in wireless tab with the necessary data for the wireless network!
by JohnTRIVOLTA
Sun Aug 06, 2017 3:10 pm
Forum: General
Topic: block arp broadcast sweep in bridge firewall
Replies: 2
Views: 792

Re: block arp broadcast sweep in bridge firewall

this is not working
how to block arp responses (reply) from clients to clients ?
Make static arp list and after that disable arp on the interface if you want !
by JohnTRIVOLTA
Sun Jul 23, 2017 1:16 pm
Forum: Wireless Networking
Topic: Metal 52 ac Speed
Replies: 5
Views: 667

Re: Metal 52 ac Speed

Yes, as it's a 1 chain radio, TCP Mbps will be around 50-70Mbps max. Are you sure, 1 chain OK , but AC ? Yes, I'm talking about TCP Mbps of real traffic, not radio modulation Mbps. I understand , but radio modulation Mbps in best situation 433mb/s and i think real traffic must be around 120-150mb/s...
by JohnTRIVOLTA
Sat Jul 22, 2017 10:39 pm
Forum: Wireless Networking
Topic: Metal 52 ac Speed
Replies: 5
Views: 667

Re: Metal 52 ac Speed

Yes, as it's a 1 chain radio, TCP Mbps will be around 50-70Mbps max.
Are you sure, 1 chain OK , but AC ?
by JohnTRIVOLTA
Thu May 04, 2017 3:22 pm
Forum: Announcements
Topic: v6.39.1 [current]
Replies: 158
Views: 36843

Re: v6.39.1 [current]

Try this :
First put the power, after 2-3 seconds press the reset button and after 5 seconds release it and see if you will initialize the flash!
I use 10.0.0.1/24 for PC lan adapter and 10.0.0.2 for PXE .
I said in my post that my router was running now.
Glad it works
by JohnTRIVOLTA
Thu May 04, 2017 3:14 pm
Forum: Announcements
Topic: v6.39.1 [current]
Replies: 158
Views: 36843

Re: v6.39.1 [current]

Try this :
First put the power, after 2-3 seconds press the reset button and after 5 seconds release it and see if you will initialize the flash!
I use 10.0.0.1/24 for PC lan adapter and 10.0.0.2 for PXE .
by JohnTRIVOLTA
Thu May 04, 2017 2:04 pm
Forum: Announcements
Topic: v6.39.1 [current]
Replies: 158
Views: 36843

Re: v6.39.1 [current]

"RB951G-2Hnd, upgraded from 6.39 to 6.39.1 After updating the router does not work normally. When it turn on, one BEEP is heard. Double BEEP is absent. The router is not detected by the MAC in Winbox Neighbors. Resetting the router does not help, neither through the button nor through the closure of...
by JohnTRIVOLTA
Tue Apr 04, 2017 10:47 pm
Forum: General
Topic: How to build a 2.4+5Ghz home network using hAP AC and wAP?
Replies: 5
Views: 3622

Re: How to build a 2.4+5Ghz home network using hAP AC and wAP?

Use capsman and cap on both devices - hAP AC with capsman of course, to me it works perfectly !
by JohnTRIVOLTA
Sat Mar 11, 2017 8:08 pm
Forum: Announcements
Topic: v6.37.5 [bugfix] is released!
Replies: 35
Views: 13385

Re: v6.37.5 [bugfix] is released!

I have RB3011 with ROS 6.38.1 . In menu "system - packages" i choose v6.37.5 bugfix to try this version but the router continuously restarts after download and reboot !
by JohnTRIVOLTA
Sun Mar 05, 2017 4:15 pm
Forum: General
Topic: Blocking DNS which is better
Replies: 7
Views: 925

Re: Blocking DNS which is better

This is the right way:
/ip firewall raw
add action=drop chain=prerouting dst-port=53 in-interface=ether1 protocol=tcp
add action=drop chain=prerouting dst-port=53 in-interface=ether1 protocol=udp
by JohnTRIVOLTA
Fri Jan 13, 2017 11:55 pm
Forum: Announcements
Topic: v6.38 [current] is released!
Replies: 168
Views: 37199

Re: v6.38 [current] is released!

I upgraded hEX/v3 - mmips/ to 6.38, firmware to 3.35 . This release broke my speed to 250Mbit/s max for tcp or udp per direction/rx or tx/, both speed 130-150 per direction, whats happenеd ?Only now the load of cpu have equal threads load 20-30%, previously only one thread work on 100% load but spee...
by JohnTRIVOLTA
Sun Dec 25, 2016 2:16 pm
Forum: Announcements
Topic: MikroTik News December 2016 (Issue #74)
Replies: 94
Views: 22244

Re: MikroTik News December 2016 (Issue #74)

Merry Christmas to all Mikrotik friends!
I waiting for device like OmnitikAC but with dual HP radio/2.4 and 5GHz/ and 2 variants 2MIMO and 4MIMO and ARM based :)