Community discussions

MikroTik App

Search found 53 matches

by dg3feh
Wed Dec 16, 2020 1:26 pm
Forum: RouterBOARD hardware
Topic: SFP Optical Transceiver from EDGE Technologies
Replies: 0
Views: 224

SFP Optical Transceiver from EDGE Technologies

Hello! Has anyone had any experience with Edge optical transceivers (e.g. https://edgeoptic.com/Pub_downloads/Datasheets/BIDI-1.25G-SFP-21-ADS.pdf) ? They explicitly offer programming for Mikrotik. I had asked about parameter settings as well as diagnostic and status messages that are availible/visi...
by dg3feh
Mon Feb 03, 2020 5:10 pm
Forum: General
Topic: Fritzbox -> Mikrotik VPN
Replies: 15
Views: 5040

Re: Fritzbox -> Mikrotik VPN

Hello!

I am trying the same. Could u please send me a screenshot of the FritzBox Config? That is the strange part for me.

How have u fixed the dynamic ip adress problem?

BR

Holger
by dg3feh
Thu Jul 04, 2019 1:14 pm
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1058

Re: Best way to connect a remote site by some kind of VPN?

is that only done by a passphrase? no keys possible?
by dg3feh
Thu Jul 04, 2019 12:44 pm
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1058

Re: Best way to connect a remote site by some kind of VPN?

The GRE documentation ist not the best one at mikrotik. Do I have to use the static addresses generated by L2TP as local/remote address and afterwards the routing is done in the routing table? Where is the encryption defined at GRE?
by dg3feh
Thu Jul 04, 2019 12:16 pm
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1058

Re: Best way to connect a remote site by some kind of VPN?

IPsec works with policies not with routing and 0.0.0.0 is not accept there......
by dg3feh
Thu Jul 04, 2019 11:54 am
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1058

Best way to connect a remote site by some kind of VPN?

Hello all! I want to connect a remote site (small network with a Mikrotik) behind a natted router with my home site which is also a Mikrotik. I want to have access to my computers on my home site and beside that I want to route all traffic from the remote site to the internet through the tunnel and ...
by dg3feh
Wed Mar 13, 2019 2:48 pm
Forum: General
Topic: IPsec connection between several sites over on concentrator
Replies: 0
Views: 394

IPsec connection between several sites over on concentrator

Hello! I have one site with DDNS running als a concentrator for my network. The concentrators network is 192.168.51.0/24. I connect two satelite sites (192.168.54.0/24 and 192.168.55.0/24) to the concentrator by L2TP/IPsec. That works fine. so I get access from the satelite sites to the concentrator...
by dg3feh
Wed Sep 19, 2018 4:06 pm
Forum: Beginner Basics
Topic: IPsec over L2TP with client-side behind a natted-router
Replies: 2
Views: 655

IPsec over L2TP with client-side behind a natted-router

Hello! I run a L2TP Server on my Mikrotik at home (VDSL connection). The Client side is a Mikrotik connected to some kind of WLAN router running NAT. The configuration export without secrets u find here: Server: server.txt.rsc Client: client.txt.rsc The L2TP connection seems to work (R for running, ...
by dg3feh
Tue Aug 21, 2018 10:39 am
Forum: General
Topic: How to build a simple user interface to choose a WLAN?
Replies: 0
Views: 468

How to build a simple user interface to choose a WLAN?

Hello! I want to set up a mikrotik based on a RB433UL for my parents motor home. The aim is to provide a secure 2GHz WLAN in the RV (R11e-2HPnD). This WLAN connects to the Internet by using a LTE connection (R11e-LTE) or if available a WLAN connection (R52HnD). To set up this within RouterOS is not ...
by dg3feh
Mon Mar 19, 2018 12:15 pm
Forum: Wireless Networking
Topic: Mikrotik as a secure gateway behind public WLAN
Replies: 3
Views: 862

Re: Mikrotik as a secure gateway behind public WLAN

Yes, B is mandatory, because in this network are several clients with internal traffic which should have no connection to the outside. I found the problem. operating with a wan-bridge for wlan and ether1 as out-interface doesn't work. the routing here was not clear. using the wlan-to-wan and the eth...
by dg3feh
Sun Mar 18, 2018 1:13 am
Forum: Wireless Networking
Topic: Mikrotik as a secure gateway behind public WLAN
Replies: 3
Views: 862

Mikrotik as a secure gateway behind public WLAN

Hello! I wanna try the following. A) I want to act a MT as a station connected to a (pubilc) wlan. That works fine, I get an IP, DNS, NTP, default route by the WLANs DHCP. B) I want to provide a local WPA2-WLAN for my clients using the network 192.168.54.0/24. That works also fine. C) I want to rout...
by dg3feh
Sat Mar 17, 2018 6:06 pm
Forum: Wireless Networking
Topic: CAPsMAN and AMSDU together with iOS
Replies: 1
Views: 684

CAPsMAN and AMSDU together with iOS

Hello!

I have the problem, that all apple devices loose their WiFi connection, if they are not used. I read in several other threads, that reducing the AMSDU values to 4096 solved the problem. How do I change that value if I use CAPsMAN?

BR Holger
by dg3feh
Thu Mar 15, 2018 8:23 pm
Forum: Forwarding Protocols
Topic: Webserver NAT/Hairpin behind PPPoE
Replies: 4
Views: 1534

Re: Webserver NAT/Hairpin behind PPPoE

Strange, but it doesn't work with an explicit destination IP. I have now an additional problem. I want to route http://<external-ip>:8100 to another webserver 192.168.51.231. add action=accept chain=forward comment=Heatermeter disabled=yes dst-port=8100 log=yes log-prefix=HM-forward: protocol=tcp ad...
by dg3feh
Thu Mar 15, 2018 5:03 pm
Forum: Forwarding Protocols
Topic: Webserver NAT/Hairpin behind PPPoE
Replies: 4
Views: 1534

Re: Webserver NAT/Hairpin behind PPPoE

Hello! Thanks for ur help! I changed the dst-nat to add action=dst-nat chain=dstnat comment="Port-forwarding HTTPS zum Server" dst-address=!192.168.51.254 dst-address-type=local dst-port=443 log-prefix="APACHE443: " \ protocol=tcp to-addresses=192.168.51.230 to-ports=443 add acti...
by dg3feh
Thu Mar 15, 2018 12:40 pm
Forum: Forwarding Protocols
Topic: Webserver NAT/Hairpin behind PPPoE
Replies: 4
Views: 1534

Webserver NAT/Hairpin behind PPPoE

Hello! I am geting a bit nut with my firewall rules. My WAN connection is a PPPoE connection with a dynamic IP, the DynDNS works fine. The local networks I use: 192.168.50.0/24 - only modem in 192.168.51.0/24 - main LAN - Mikrotik Router 192.168.51.254 - Web-Server 192.168.51.230 192.168.53.0/24 - g...
by dg3feh
Thu Dec 07, 2017 12:04 am
Forum: Beginner Basics
Topic: FireTV Stick and wAP G-5HacT2HnD
Replies: 0
Views: 348

FireTV Stick and wAP G-5HacT2HnD

Hello!

I run an AP wAP G-5HacT2HnD and it works fine for all Device (Win7/Win10, Linux, iOS, Android, etc.) Since one week I own a FireTV Stick (the new one with Alexa) and it does not connect to the Mikrotik. I run WPA2 PSK with aes ccm. Does anyone have a hint?

BR Holger
by dg3feh
Wed Jul 26, 2017 9:27 am
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

In /ip firewall service-port there is the possibility to reduce the TTL for SIP connections: SIP helper. Additional options: sip-direct-media allows redirect the RTP media stream to go directly from the caller to the callee. Default value is yes. sip-timeout allows adjust TTL of SIP UDP connections....
by dg3feh
Tue Jul 25, 2017 1:54 pm
Forum: Beginner Basics
Topic: Writing output to usb-stick
Replies: 0
Views: 530

Writing output to usb-stick

Hello! I tried to write the sniffer log to a Memorystick, without success. [admin@Router-HH] /disk> print # NAME LABEL TYPE DISK FREE SIZE 0 disk1 1GB-MEMSTIC fat32 PDU01_1G 71G2.0 968.6MiB 984.0MiB ...that seems ok for me. I found the disk1 in the files: [admin@Router-HH] /file> print # NAME TYPE S...
by dg3feh
Thu Jul 20, 2017 9:14 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

"use peer DNS" results in a "push". These DNS are dynamical set by the ISP.

No hints regarding the file problem? :(
by dg3feh
Thu Jul 20, 2017 2:47 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

Hello all, thanks for u comments. I have a small unix server in my LAN doing mostly nothing ;) (beside family file serving) which is able do act as DNS. Problem is the dynamic push of the ISPs nameserver to the mikrotik. How do I transfer this information to the server? Beside that: Some hints for t...
by dg3feh
Sat Jul 15, 2017 5:02 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

...beside that I tried to write the sniffer log to a Memorystick, without success. [admin@Router-HH] /disk> print # NAME LABEL TYPE DISK FREE SIZE 0 disk1 1GB-MEMSTIC fat32 PDU01_1G 71G2.0 968.6MiB 984.0MiB ...that seems ok for me. I found the disk1 in the files: [admin@Router-HH] /file> print # NAM...
by dg3feh
Sat Jul 15, 2017 4:41 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

In the last 24h I forced a TTL of 1sec to all DNS entries and there where no registration losts on my VoIP. So I am pretty sure that the ISPs DNS SRV Records are corrupt regarding TTL, weight, priority. I am already in discussion with my ISP, but as usual: To get someone on the phone, who is able to...
by dg3feh
Thu Jul 13, 2017 5:14 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

Nope! I know that my VoIP Service is some how currupted by wrong DNS entries, The work around is to ask not the mikrotik DNS cache, but the ISP DNS directly. Thus I want a directive to do that only for the VoIP domains. The rest works fine with the "normal" DNS relay. Only if this is not p...
by dg3feh
Thu Jul 13, 2017 4:51 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

I am talking about the SRV record. If there are two or more entries for a canocial name the descission which is taken is made by pritority and weight. -> https://en.wikipedia.org/wiki/SRV_record
by dg3feh
Thu Jul 13, 2017 2:49 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

Is it possible to see the priority and the weighting of the records?
by dg3feh
Thu Jul 13, 2017 2:42 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Re: Exclude domains from DNS cache!?

Hello!

I know all this. The IPs TTLs and weightings seems to be wrong. I want to send all DNS queries direct to the ISP DNS and all the rest first to the caching name server. The normal TTL is 1h.
Is there no possibility to force this?

BR Holger
by dg3feh
Thu Jul 13, 2017 1:08 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 3923

Exclude domains from DNS cache!?

Hello! I have quite often regsitration losts on my VoIP. I figured out that the provider is changing all the time the IP Address of the VoIP Server. Thus I need to exclude the Provider Domain from the DNS cache. How can I do this? I need to use the mikrotik as DNS server due to the fact, that the DN...
by dg3feh
Wed Apr 05, 2017 12:12 pm
Forum: Beginner Basics
Topic: OpenVPN client-to-client mode
Replies: 1
Views: 1139

OpenVPN client-to-client mode

Hello!

I have learned that the OpenVPN within Mikrotik has some lacks (e.g. push route, etc). Is it possible to activate client-to-client mode and if so, how?

BR Holger
by dg3feh
Mon Feb 13, 2017 3:51 pm
Forum: Beginner Basics
Topic: Guest-WLAN with dedicated AP - how to reach WAN?
Replies: 1
Views: 781

Guest-WLAN with dedicated AP - how to reach WAN?

Hello! I run two mikrotik devices: - Cloudswitch CRS125-24-1S - Access point wAP ac The private (W)LAN is 192.168.51.0/24 and the guest WLAN is 192.168.52.0/24. The private LAN incl. WLAN works fine. I setup the WLANs for guest WLAN as virtual APs, put them in a new bridge interface and defined a ne...
by dg3feh
Wed Feb 08, 2017 12:44 pm
Forum: Beginner Basics
Topic: Passing VLAN tagging to Modem
Replies: 1
Views: 498

Passing VLAN tagging to Modem

Hello! I use a Draytek Vigor 130 as a modem and fire up the WAN connection by PPPoE with the router. Rightnow I am connected to a ADSL2+ line and everything works fine. I will switch over to VDSL2+ in a few weeks and for that I need to pass a VLAN Tag from the mikrotik to the modem, but I haven't fo...
by dg3feh
Sat Feb 04, 2017 11:11 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 2020

Re: Hairpin won't work, but why?

But it works now, thanks for ur help.
by dg3feh
Sat Feb 04, 2017 10:23 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 2020

Re: Hairpin won't work, but why?

Correct me, but I masqueraded the request with the external address, why shouldn't match that with !192.168.1.0/24?
by dg3feh
Sat Feb 04, 2017 9:52 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 2020

Re: Hairpin won't work, but why?

Ok, that's the point. I changed it now to /ip firewall nat add action=dst-nat chain=dstnat comment="Portforwarding HTTP zum Server" dst-port=80 log=yes log-prefix=FW80 protocol=tcp \ src-address=!192.168.1.0/24 to-addresses=192.168.1.252 to-ports=80 So that rule only works, if the source i...
by dg3feh
Sat Feb 04, 2017 9:41 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 2020

Re: Hairpin won't work, but why?

So how this thread differs from your previous one ? Because the first one is more general and now only the hairpin is the problem. Is there any specific reason why you refuse to acknowledge that it can't work with dstnat rules that have in-interface=PPPoE-ALICE? :) I have under stand that, but /ip ...
by dg3feh
Sat Feb 04, 2017 8:23 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 2020

Re: Hairpin won't work, but why?

use code on conclusion page of this presentation https://goo.gl/35GBvK , it's work both single wan and multi-wan

credit : https://www.facebook.com/mikrotiktutori ... 126599365/
I can't see the difference to what I am doing....
by dg3feh
Sat Feb 04, 2017 7:51 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 2020

Re: Hairpin won't work, but why?

Ok, I tried that one: /ip firewall nat add action=masquerade chain=srcnat comment="Maskierung LAN" out-interface=PPPoE-ALICE src-address=192.168.1.0/24 add action=src-nat chain=srcnat comment=NTP protocol=udp src-port=123 to-addresses=192.168.1.254 add action=dst-nat chain=dstnat comment=&...
by dg3feh
Sat Feb 04, 2017 3:00 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 2020

Hairpin won't work, but why?

Hello! I have the following configuration: FullSizeRender.jpg I want to reach with the normal clients the internet and the server from extranal and subnet 192.168.1.0/24 under the external server address. Beside that I want to reach the modem on its internal address for configuration, etc. The addre...
by dg3feh
Fri Feb 03, 2017 9:07 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

That's just a half of it. You still need proper dstnat rules. And your current ones only work for connections coming from internet (via PPPoE-ALICE interface). Hm. As far as I understood: We are coming from the inside (e.g. 192,168.1.100) and want to connect to the WAN addresss. Therefore we catch ...
by dg3feh
Fri Feb 03, 2017 2:29 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

Yep, two hints: 1) tag is very useful thing. what do u mean by that? 2) Read my previous post again and this time pay a little more attention (extra subhint: you did not touch your dstnat rules).[/quote] As fare as I understod, the Hairpin works by masquerading. The internal call from LAN to the ex...
by dg3feh
Fri Feb 03, 2017 1:46 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

Hello! the Hairpin and the forwarding for the Router still does not work. Here the actual export: [admin@Router-HH] > /export # feb/03/2017 00:42:43 by RouterOS 6.38.1 # software id = D5X7-MT4X # /interface ethernet set [ find default-name=ether2 ] master-port=ether1 set [ find default-name=ether3 ]...
by dg3feh
Thu Feb 02, 2017 1:09 pm
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

I implemented ur hints, and the Harpin still doesn't work :(

also the redirect of the Router HTTPS Interface doesn't work
by dg3feh
Thu Feb 02, 2017 11:41 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

And what about the Hairpin? I need to get that working to get access to the addressbooks an calendars from smartphones while they are connected to the LAN via WLAN
by dg3feh
Thu Feb 02, 2017 9:55 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

Hello! Thank u for ur answer. The routing from the outside works fine for HTTP, HTTPS and SSH. For the Harpin rule u mean: /ip firewall nat add action=masquerade chain=srcnat comment=Hairpin dst-address=192.168.1.252 dst-port=22,80,443 out-interface-list=ether1 protocol=tcp src-address=192.168.1.0/2...
by dg3feh
Wed Feb 01, 2017 11:47 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

Please show a complete /export of your config so it can be debugged. [admin@Router-HH] > /export # feb/01/2017 10:45:22 by RouterOS 6.38.1 # software id = D5X7-MT4X # /interface ethernet set [ find default-name=ether2 ] master-port=ether1 set [ find default-name=ether3 ] master-port=ether1 set [ fi...
by dg3feh
Wed Feb 01, 2017 8:53 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

LAN means LAN, the internal network where both server and client are connected.
How do I define that? These are all ports accept 23 (where the Modem is connected to)
by dg3feh
Wed Feb 01, 2017 1:54 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

Mistake found. I have to use the PPPoE Interface and not the port! Next problem is the Hairpin NAT http://wiki.mikrotik.com/wiki/Hairpin_NAT /ip firewall nat add chain=srcnat src-address=192.168.1.0/24 \ dst-address=192.168.1.2 protocol=tcp dst-port=80 \ out-interface=LAN action=masquerade what does...
by dg3feh
Wed Feb 01, 2017 1:12 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

So the public IP address is assigned to a PPPoE connection on the Mikrotik? Do you have firewall forward rules to accept the incoming connection? dst-nat only tells the system what you want the packets re-written to, it doesn't give it permission to actually forward the traffic. You likely need to ...
by dg3feh
Wed Feb 01, 2017 12:43 am
Forum: Beginner Basics
Topic: DDNS for different providers
Replies: 0
Views: 436

DDNS for different providers

Hello! I did some changes on the DDNS-script given by the Wiki in order to use different providers and protocols: :global ddnsuser "USERNAME" :global ddnspass "PASSWORD" :global theinterface "INTERFACEtoWAN" :global ddnshost DOMAINNAME :global ddnsserver SERVERNAME :glo...
by dg3feh
Wed Feb 01, 2017 12:26 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Re: Port-forwarding does not work, but why?

The public IP is held by the PPP Interface on ether23-MODEM.

What kind of forward rule? U can see all my rules in the post.
by dg3feh
Tue Jan 31, 2017 11:09 pm
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 4743

Port-forwarding does not work, but why?

Hello! I run my LAN on 192.168.1.0/24 and a xDSL connection via a modem (192.168.0.2) which is connected to ether23-MODEM. The internet connections worksfine. The firewall is like this Flags: X - disabled, I - invalid, D - dynamic 0 ;;; Kaputte Pakete DROP chain=input action=drop connection-state=in...
by dg3feh
Mon Jan 30, 2017 3:40 pm
Forum: Beginner Basics
Topic: Routing two Networks on one CRS125-24G-1S
Replies: 2
Views: 753

Re: Routing two Networks on one CRS125-24G-1S

Thanks!
The defined gateway is not used, if the Vigor130 acts as a modem and not as a router! The route on the modem sloved the problem!

Holger
by dg3feh
Mon Jan 30, 2017 11:11 am
Forum: Beginner Basics
Topic: Routing two Networks on one CRS125-24G-1S
Replies: 2
Views: 753

Routing two Networks on one CRS125-24G-1S

Hello! I am completely new to mikrotik. The first aim is to connect a local network (192.168.1.0/24) via a modem (DratyTek Vigor 130) to the internet. The modem has a maintenance ip inteface. This on should run in a seperate network (192.168.0.0/24). Mikrotiks IP is set to 192.168.1.254 on ether1 an...