Community discussions

MUM Europe 2020

Search found 1796 matches

by sebastia
Fri Jun 21, 2019 4:09 pm
Forum: General
Topic: Open only Mobile versions on websites
Replies: 3
Views: 344

Re: Open only Mobile versions on websites

You would need to use application level firewall / proxy, outside the scope of Mikrotik. There you could rewrite the client agent string for example
by sebastia
Fri Jun 21, 2019 4:06 pm
Forum: General
Topic: Bandwith shaping per ISP gateway
Replies: 7
Views: 498

Re: Bandwith shaping per ISP gateway

Yes and no. Yes = bandwidth has been consumed already, No = for tcp we can trigger "back off" resulting in desired effect (=hack).
As discussed before viewtopic.php?f=13&t=129781&p=640278&hi ... ue#p640278
by sebastia
Fri Jun 21, 2019 3:37 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

Thx for info NAT might be used implicitly where applicable. RAW is applied before connection tracking and so doesn't belong in that list. 2) that use is undocumented. Did you use that method already? /ip firewall connection tracking enabled = "Allows to disable or enable connection tracking. Disabli...
by sebastia
Fri Jun 21, 2019 2:57 pm
Forum: General
Topic: Bandwith shaping per ISP gateway
Replies: 7
Views: 498

Re: Bandwith shaping per ISP gateway

Yep. But I need to limit all traffic, both outgoing and incoming.
if incoming too, then changes the situation a bit. How will you route to these isp's? Based on what logic?
by sebastia
Fri Jun 21, 2019 11:50 am
Forum: General
Topic: Bandwith shaping per ISP gateway
Replies: 7
Views: 498

Re: Bandwith shaping per ISP gateway

Hey Do I understand your problem statement well? * single interface, with 2 ips/gw * need to limit outgoing (internet upload) traffic to one isp so second has sufficient interface bandwidth left Simplest solution (in my opinion) * queue tree on isp connection interface ** parent queue for interface ...
by sebastia
Thu Jun 20, 2019 7:51 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

OT: Alfa has cars for all kinds of paying customers ;-)
by sebastia
Thu Jun 20, 2019 5:38 pm
Forum: General
Topic: Management VLAN on CRS328 (RouterOS)
Replies: 4
Views: 408

Re: Management VLAN on CRS328 (RouterOS)

Good for you. I had a different understanding of your request.
by sebastia
Thu Jun 20, 2019 3:00 pm
Forum: General
Topic: Management VLAN on CRS328 (RouterOS)
Replies: 4
Views: 408

Re: Management VLAN on CRS328 (RouterOS)

Hi

Have you considered dst-nat for the ip in question?

Put ip(s) on the routers interface (so multi-homed, simplest solution here) and dst-nat any traffic to these ip's to new target ip's on vlan99.
by sebastia
Thu Jun 20, 2019 2:05 pm
Forum: General
Topic: Custom Mikotik Device
Replies: 2
Views: 362

Re: Custom Mikotik Device

https://mikrotik.com/aboutus

have you tried sales?
by sebastia
Thu Jun 20, 2019 12:54 pm
Forum: General
Topic: How I can edit dhcp client expire time
Replies: 1
Views: 247

Re: How I can edit dhcp client expire time

You can't. You can control the lease time on dhcp server, but it's up to the client to refresh it's lease.
You can also make the lease static / sticky.
by sebastia
Wed Jun 19, 2019 11:57 pm
Forum: RouterBOARD hardware
Topic: RBSXTR problem with LTE
Replies: 17
Views: 2591

Re: RBSXTR problem with LTE

Must have jinxed it...Just had a major interruption (25+ hours from main ISP) and SXT LTE kit was not a reliable backup. Constantly loosing connection (state11 + plain loss). Me not happy at all... Jun 18 00:23:12 ltegw.home lte,info lte1: not registred, state: 11 Jun 18 01:17:34 ltegw.home lte,info...
by sebastia
Wed Jun 19, 2019 11:44 pm
Forum: Beginner Basics
Topic: PiHole DNS for any subnet
Replies: 2
Views: 1184

Re: PiHole DNS for any subnet

If all those subnets get ip config automatically (through dhcp), then configure in your dhcp network definition the pihole as the dns server. to simplify config, put the pihole on different net than the targeted subnets. and make sure that pihole itself can do dns request, either through Tik or dire...
by sebastia
Wed Jun 19, 2019 11:36 pm
Forum: Virtualization
Topic: ar71xx mikrotik build 18.06.2 ?
Replies: 1
Views: 693

Re: ar71xx mikrotik build 18.06.2 ?

You should check on the openwrt forum, this one only relates to Tik software = ROS.
by sebastia
Wed Jun 19, 2019 11:31 pm
Forum: Beginner Basics
Topic: CCR1072 PCC Multi-WAN Performance Stuck
Replies: 2
Views: 503

Re: CCR1072 PCC Multi-WAN Performance Stuck

Hi Some feedback... 1. See https://wiki.mikrotik.com/wiki/Manual:IP/Hotspot. It has quite some limitations / requirements. In high load scenario some can become a bottleneck, ex "users accounting in local database on the router", local storage => SLOW Only use what you really need and optimise where...
by sebastia
Wed Jun 19, 2019 10:56 pm
Forum: Wireless Networking
Topic: LHG LTE kit
Replies: 8
Views: 1447

Re: LHG LTE kit

This one is strange, masq doens't take dst-address as param...recreate without dst-address. add action=masquerade chain=srcnat dst-address=0.0.0.0/0 out-interface=lte1 (ti's just a filter =all => no-op /ip route add distance=1 gateway=lte1 Do you get point-to-point ip onyour lte1? if not this route...
by sebastia
Wed Jun 19, 2019 10:45 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

Hey @krisjanisj 2) as soon as the connection is flagged for fasttrack, conntrack communicates with interface drivers and packets from those connections are fasttracked skipping all the firewall rules ( RAW /mangle/filter) Don't you mean NAT? RAW is pre conntrack... 3) conntrack by default is most ex...
by sebastia
Mon Jun 17, 2019 10:11 pm
Forum: Scripting
Topic: lte interface disabled inconsistency
Replies: 2
Views: 539

Re: lte interface disabled inconsistency

Hey

the command shoul be "/interface lte disable <name>"
by sebastia
Mon Jun 17, 2019 9:55 pm
Forum: General
Topic: LTE modem firmware changelog
Replies: 2
Views: 453

Re: LTE modem firmware changelog

To my knowledge it's not documented.
Just for info, looks like current version is v11.
by sebastia
Mon Jun 17, 2019 9:30 pm
Forum: Beginner Basics
Topic: Redirect Port to specific WAN [SOLVED]
Replies: 7
Views: 941

Re: Redirect Port to specific WAN [SOLVED]

Hi You can to that with mangling. In mangle:prerouting, route-mark all all packets for port SSH (tcp:22) (or any other port you might be using), with some mark. Next step, make sure you have a route over desired isp with that routing-mark. See https://wiki.mikrotik.com/wiki/Policy_Base_Routing, wrt ...
by sebastia
Mon Jun 17, 2019 9:08 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

@Emil66
It's a forum for technical assistance. Don't be offended when you "waltz in" post "some gut feelings and expectations" without any substations, and someone reacts on that...

Your opinions are incorrect.
by sebastia
Sat Jun 15, 2019 10:15 am
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

I asked for factual info & data, not some gut feelings and expectations! ...to pass many rules before they are accepted, the CPU load will be high... Can you prove it? Tik can easily handle hundreds of rules with no / minimal impact (caveat: as long as no heavy matchers are used) This is bad even wi...
by sebastia
Sat Jun 15, 2019 12:28 am
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

I wouldn't advise to use raw-prerouting rule. It might have negative impact on speed of all (including fasttracked) connections. ... it will have more negative, than positive consequences because ... This is based on what factual info / data? It a rule base system like any other table (filter,nat,m...
by sebastia
Fri Jun 14, 2019 10:48 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

right, that's what you get for writing commands from memory...
/ip firewall raw add action=drop src-address=141.98.80.115 chain=prerouting
Thx!
by sebastia
Fri Jun 14, 2019 6:13 pm
Forum: Beginner Basics
Topic: Limit WAN Winbox access to OpenVPN connected user
Replies: 1
Views: 271

Re: Limit WAN Winbox access to OpenVPN connected user

I tried by using src ip range to limit access only to IP range assigned by OpenVPN but apparently firewall checks "real" user's IP (it's dynamic) not IP assigned by OpenVPN that's the way to go. clients need to use the openvpn ip to connect with Winbox. And then their source ip will be automaticall...
by sebastia
Fri Jun 14, 2019 4:40 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 5072

Re: single IP constantly trying to log to my Mikrotik

Add this
/ip firewall raw add action=drop src-address=141.98.80.115
by sebastia
Fri Jun 14, 2019 2:59 pm
Forum: General
Topic: one dhcp server, static leases two diffent gateway addresses
Replies: 4
Views: 478

Re: one dhcp server, static leases two diffent gateway addresses

You can achieve this by defining multiple networks, ex: /ip dhcp-server network add address=192.168.1.0/26 dns-server=192.168.1.1 domain=home gateway=192.168.1.1 netmask=24 ntp-server=192.168.1.1 add address=192.168.1.64/26 dns-server=172.16.1.2 domain=dyn.home gateway=192.168.1.2 netmask=24 ntp-ser...
by sebastia
Fri Jun 14, 2019 2:24 pm
Forum: General
Topic: Static route between 2 routers,2 networks
Replies: 7
Views: 595

Re: Static route between 2 routers,2 networks

the default gateways are set on both pc's?

try pinging one hop further at a time to discover where "connection breaks", from both ends.
by sebastia
Fri Jun 14, 2019 2:15 pm
Forum: Beginner Basics
Topic: Two WAN, 1 Mikrotik, 2 Networks [SOLVED]
Replies: 1
Views: 378

Re: Two WAN, 1 Mikrotik, 2 Networks [SOLVED]

Sure possible, quite a similar situation here viewtopic.php?f=13&t=149263
by sebastia
Fri Jun 14, 2019 2:10 pm
Forum: General
Topic: SSTP over 1 Gbps link bad performance
Replies: 4
Views: 624

Re: SSTP over 1 Gbps link bad performance

probably related to fragmentation, you'll need to adjust the MTU to max allowed by tunnel.
by sebastia
Fri Jun 14, 2019 12:39 pm
Forum: General
Topic: Static route between 2 routers,2 networks
Replies: 7
Views: 595

Re: Static route between 2 routers,2 networks

Your firewall is allowing all which is not explicitly blocked. So that should be fine. add action=accept chain=forward connection-state=established add action=accept chain=forward connection-state=related add action=drop chain=forward connection-state=invalid Are the firewalls same for both routers?
by sebastia
Fri Jun 14, 2019 11:07 am
Forum: General
Topic: MT setup- FW setup due to GDPR - Hotspot - General Security Issue(s)
Replies: 5
Views: 623

Re: MT setup- FW setup due to GDPR - Hotspot - General Security Issue(s)

GDPR doesn't specify any specific measures: so its up for interpretation.

Personally I would prefer a certificate based VPN above port knocking.
by sebastia
Fri Jun 14, 2019 11:00 am
Forum: Scripting
Topic: switch on and off wifi radio script don't work anymore
Replies: 8
Views: 932

Re: switch on and off wifi radio script don't work anymore

Hence why you need a script that will be triggered often and can determine what to do ...
by sebastia
Fri Jun 14, 2019 10:56 am
Forum: General
Topic: Static route between 2 routers,2 networks
Replies: 7
Views: 595

Re: Static route between 2 routers,2 networks

Hi You have two relevant routes on each router: one without mark and one with mark. So, whether it's marked or not routing should work. Although the whole connection / routing marking for "to_LAN" looks unnecessary to me (in current context) -> one route entry WITHOUT mark should have been enough. Y...
by sebastia
Thu Jun 13, 2019 10:31 pm
Forum: General
Topic: Cablelabs Micronets
Replies: 4
Views: 849

Re: Cablelabs Micronets

Amen to that!
by sebastia
Thu Jun 13, 2019 10:28 pm
Forum: Scripting
Topic: switch on and off wifi radio script don't work anymore
Replies: 8
Views: 932

Re: switch on and off wifi radio script don't work anymore

Looking at other posts, ex https://forum.mikrotik.com/viewtopic.php?t=149298 is a good start :local time [/system clock get time]; :if ($time >= "07:00:00" && $time < "21:59:00") do={ :if (<is_wifi_off>) do={ :log warning "Switching wifi on" # add code here } } else { :if (<is_wifi_on>) do={ :log wa...
by sebastia
Thu Jun 13, 2019 10:02 pm
Forum: Scripting
Topic: switch on and off wifi radio script don't work anymore
Replies: 8
Views: 932

Re: switch on and off wifi radio script don't work anymore

why don't you schedule a repeatable task and put the logic to trigger or not in the script?
by sebastia
Thu Jun 13, 2019 3:40 pm
Forum: Wireless Networking
Topic: Change network
Replies: 5
Views: 648

Re: Change network

I would suggest to add new addresses first, then remove the old ones.
by sebastia
Thu Jun 13, 2019 2:45 pm
Forum: Beginner Basics
Topic: Cannot route over EoIP tunnel on PtP link
Replies: 3
Views: 340

Re: Cannot route over EoIP tunnel on PtP link

default route should look like this:
forward traffic to 0.0.0.0/0 (connection destination) to <ip> (gateway), with ip being a directly connected router

so for
TikA: it needs to forward to ip of your ips appliance
TikB: needs to forward to ip of TikA 10.8.8.1

why do you need a pppoe client?
by sebastia
Thu Jun 13, 2019 2:39 pm
Forum: Beginner Basics
Topic: STATIC ROUTE
Replies: 1
Views: 272

Re: STATIC ROUTE

you would want to split the test route and general route:
so have specific route for test server over wan1
and 2nd general route for all destination over wan1

Only the second gets disabled.
by sebastia
Thu Jun 13, 2019 2:36 pm
Forum: General
Topic: Mikrotik mangle for VoIP
Replies: 3
Views: 518

Re: Mikrotik mangle for VoIP

Any will do, but usually forward or postrouting, as then the outgoing interface is known.
by sebastia
Thu Jun 13, 2019 2:09 pm
Forum: Beginner Basics
Topic: Cannot route over EoIP tunnel on PtP link
Replies: 3
Views: 340

Re: Cannot route over EoIP tunnel on PtP link

You need to configure default gateway on both endpionts. -> where to forward non-local traffic

A note/question: why do you need ipip tunnel? You already have dedicated network between the radios: 10.8.8.1 & .2..
by sebastia
Thu Jun 13, 2019 1:02 am
Forum: General
Topic: RouterOS Virtual Labs
Replies: 84
Views: 116116

Re: RouterOS Virtual Labs

Now:
gns3 Version 2.1.20 (current), NPcap v0.995 (with wincap compatible api) and gns3 vm. (=only components installed)
The vm is running on Hyper-V on Win10Pro. The vm was built "manually": minimal install Ubuntu 18.04.2 server + gns3-server packages.
by sebastia
Wed Jun 12, 2019 11:35 pm
Forum: General
Topic: MT setup- FW setup due to GDPR - Hotspot - General Security Issue(s)
Replies: 5
Views: 623

Re: MT setup- FW setup due to GDPR - Hotspot

GDPR is not specific about what measure should be taken, but "appropriate ones" to ensure customers privacy, based on "industry standards". It also expect inherent security within the systems, it's called "security / privacy by default / design" default: safe settings out of the box design: safe sys...
by sebastia
Wed Jun 12, 2019 9:38 pm
Forum: General
Topic: MT setup- FW setup due to GDPR - Hotspot - General Security Issue(s)
Replies: 5
Views: 623

Re: MT setup- FW setup due to GDPR - Hotspot

GDPR is about personal identification. As long as you don't log data which could identify a person, you're fine. So is that applicable in the case you specified?
by sebastia
Wed Jun 12, 2019 5:21 pm
Forum: General
Topic: RouterOS Virtual Labs
Replies: 84
Views: 116116

Re: RouterOS Virtual Labs

Just a heads-up: when running VPCS within the gns3-vm, it fully loads a core of cpu.
Running that same VPCS on the gns3server locally doesn't have this effefct: cpu load is minimal.
by sebastia
Wed Jun 12, 2019 2:55 pm
Forum: General
Topic: Cant connect to winbox after hotspot setup
Replies: 5
Views: 405

Re: Cant connect to winbox after hotspot setup

https://wiki.mikrotik.com/wiki/Manual:IP/Hotspot
The MikroTik HotSpot Gateway provides authentication for clients before access to public networks .
I think you should still have access to routerboard when using MacServer with WinBox -> so connect to "mac of routerboard".
by sebastia
Wed Jun 12, 2019 2:51 pm
Forum: Beginner Basics
Topic: set up second WAN/ISP temporarily
Replies: 8
Views: 715

Re: set up second WAN/ISP temporarily

The above will work for traffic going to router itself only.

For traffic forwarded, "forward chain + input interface condition" for inbound and "prerouting chain + mark condition" for outbound can be used.
by sebastia
Wed Jun 12, 2019 12:53 am
Forum: General
Topic: Cant connect to winbox after hotspot setup
Replies: 5
Views: 405

Re: Cant connect to winbox after hotspot setup

your pcc config looks ok

hotspot will divert traffic to login page, hence you would want to setup hotspot on a guest network only, not your internal network.
by sebastia
Wed Jun 12, 2019 12:08 am
Forum: Beginner Basics
Topic: set up second WAN/ISP temporarily
Replies: 8
Views: 715

Re: set up second WAN/ISP temporarily

You'll need to mark traffic coming from ISP2, so that based on that mark only that traffic will be routed out to internet over isp2.
The other traffic to internet should go over isp1.

Added emphasis
by sebastia
Wed Jun 12, 2019 12:01 am
Forum: RouterBOARD hardware
Topic: RBSXTR problem with LTE
Replies: 17
Views: 2591

Re: RBSXTR problem with LTE

Was quite spotty last year, when isp was upgrading it's fiber network, but now stable again. Most recent event: Mar 24 19:45:28 firewall.home interface,info e5_ext link down I'm using that link for vpn traffic during office hours on occasion, but otherwise just idling (except for link mgmt traffic (...
by sebastia
Tue Jun 11, 2019 8:55 pm
Forum: RouterBOARD hardware
Topic: RBSXTR problem with LTE
Replies: 17
Views: 2591

Re: RBSXTR problem with LTE

My LTE is a backup link so it's used exceptionally by design.
by sebastia
Tue Jun 11, 2019 5:06 pm
Forum: RouterBOARD hardware
Topic: RBSXTR problem with LTE
Replies: 17
Views: 2591

Re: RBSXTR problem with LTE

I do Jun 1 00:07:11 ltegw.home script,error checkLTE: loss of lte1, recycling Jun 1 06:51:12 ltegw.home script,error checkLTE: loss of lte1, recycling Jun 1 12:11:12 ltegw.home script,error checkLTE: loss of lte1, recycling Jun 1 14:59:12 ltegw.home script,error checkLTE: loss of lte1, recycling Jun...
by sebastia
Tue Jun 11, 2019 4:47 pm
Forum: RouterBOARD hardware
Topic: RBSXTR problem with LTE
Replies: 17
Views: 2591

Re: RBSXTR problem with LTE

I've upgraded by netwatch to scheduler as well. In my case, the "state:11" are not related to ISP: they don't register anything at their end, must be something local. I'm inclined to think so too, as I didn't had these issues when the device was new. Started appearing after some months of operation ...
by sebastia
Tue Jun 11, 2019 4:39 pm
Forum: Wireless Networking
Topic: SXT LTE lost lte interface
Replies: 37
Views: 8425

Re: SXT LTE lost lte interface

It's same modem but different antenna...
by sebastia
Tue Jun 11, 2019 4:32 pm
Forum: Beginner Basics
Topic: 1 mikrotik, 2 ISPs, 2 LANs, can't make LANS see each other
Replies: 2
Views: 377

Re: 1 mikrotik, 2 ISPs, 2 LANs, can't make LANS see each other

Hi I've looked at first config only: it's using mangling to route traffic. It could be done, but is quite heavy on cpu. Better solution: use routing rules together with routing tables. Todo: * add/adjust routing tables * add routing rules * clean up existing config # route table /ip route add gatewa...
by sebastia
Tue Jun 11, 2019 2:12 pm
Forum: General
Topic: Interface packets discard.
Replies: 9
Views: 1277

Re: Interface packets discard.

right. any queueing in place which limits the traffic?

Or just post your config: /export hide-sensitive compact...
by sebastia
Tue Jun 11, 2019 1:12 pm
Forum: General
Topic: RouterOS Virtual Labs
Replies: 84
Views: 116116

Re: RouterOS Virtual Labs

No issues here on GNS3: pings ok from one end to other
[admin@MikroTik] /interface ethernet> export
# jun/11/2019 10:13:21 by RouterOS 6.44.3
# software id = 
#
#
#

2R-setup.png
by sebastia
Tue Jun 11, 2019 12:39 pm
Forum: General
Topic: Interface packets discard.
Replies: 9
Views: 1277

Re: Interface packets discard.

Looks to me like traffic is going to pppoe-dait (internet?) from ether1 (lan?). Download probably. No drops. -> upload
by sebastia
Tue Jun 11, 2019 12:06 pm
Forum: General
Topic: Tagged input packet with VLAN ID
Replies: 3
Views: 406

Re: Tagged input packet with VLAN ID

Bad news: since the devices can't tag traffic themselves, with an unmanaged switch it's not possible to isolate the networks. You'll need something to do that for them: indeed managed switch would do the trick, but also any routerboard with 5 ports (if the count is correct). So suggest you get a che...
by sebastia
Tue Jun 11, 2019 11:58 am
Forum: General
Topic: Block Vlan traffic to other networks
Replies: 2
Views: 595

Re: Block Vlan traffic to other networks

Thread continues here viewtopic.php?f=13&t=149245
by sebastia
Tue Jun 11, 2019 11:40 am
Forum: Beginner Basics
Topic: How to block access vlan from my local network?
Replies: 9
Views: 914

Re: How to block access vlan from my local network?

Hi glaukos You could isolate vlan network to specific routing table, which would only know of internet: * create route table for vlan, with default route to your gateway (internet) * configure routing rule to route all traffic from vlan through that table # route table /ip route add gateway=<gateway...
by sebastia
Mon Jun 10, 2019 12:17 pm
Forum: Scripting
Topic: Script implementing Active Congestion Control
Replies: 62
Views: 8140

Re: Script implementing Active Congestion Control

Hi @rayohms rate of transmission is adjusted based on timing of the ping to test server. See first post: ** response < 25ms -> increase rate by 1/10 of range (max rate - min rate) ** 25 <= response < xxx -> decrease rate by "floor(response / 50) * 1/10 of range" Also as mentioned by frank: * needs Q...
by sebastia
Wed Jun 05, 2019 1:17 pm
Forum: Scripting
Topic: Script implementing Active Congestion Control
Replies: 62
Views: 8140

Re: Script implementing Active Congestion Control

Do you mean that it's not working for you? What issues do you have?
by sebastia
Wed May 22, 2019 7:32 pm
Forum: General
Topic: Strange RP filter behavior
Replies: 12
Views: 977

Re: Strange RP filter behavior

Routing & firewalling? ;) It's core functions, the rest is add-ons.
by sebastia
Wed May 22, 2019 12:07 pm
Forum: Wireless Networking
Topic: R11e-LTE firmware bug.
Replies: 18
Views: 3765

Re: R11e-LTE firmware bug.

Hi

Do you have IP reverse path filter set to strict on lte modem? Try lowering it, loose should be enough.
by sebastia
Wed May 22, 2019 11:58 am
Forum: General
Topic: Strange RP filter behavior
Replies: 12
Views: 977

Re: Strange RP filter behavior

If thinking outside the box is allowed (literally here), dnsmasq is the solution here: it can do selective forwarding for domains & ranges (reverse dns).
by sebastia
Fri May 17, 2019 5:13 pm
Forum: General
Topic: How to PCQ this?
Replies: 5
Views: 537

Re: How to PCQ this?

when defining queues / limits / ... upload is first: queue=<up>/<down>

another option for multiple ranges: use parent queue with the limits defined there
by sebastia
Tue May 14, 2019 8:55 pm
Forum: Beginner Basics
Topic: Re-phrase o a warning on Wiki PCC page
Replies: 3
Views: 349

Re: Re-phrase o a warning on Wiki PCC page

Suppose you have

Wan1	---		--- Lan1
		Router
Wan2	---		--- Lan2

If you setup for LAN1 to go over Wan1 and Lan2 over Wan2, you might also want for Lan1 to be able to connect to Lan2.
To do that you need to accept traffic without mangling.
by sebastia
Tue May 14, 2019 7:30 pm
Forum: General
Topic: RB750GR3 for a 30 PCs Gaming event?
Replies: 10
Views: 821

Re: RB750GR3 for a 30 PCs Gaming event?

Nope, Gr3 won't do. Since you want ot balance, you'll need to skip FastTrack. Without it gr3 won't be able to cope with bandwidth.

You need more power. 4011 will do for example
by sebastia
Mon May 13, 2019 10:36 pm
Forum: Scripting
Topic: Set timer or some other way to prevent script from running multiple times in short time [SOLVED]
Replies: 5
Views: 837

Re: Set timer or some other way to prevent script from running multiple times in short time [SOLVED]

maybe?
* set a ":global bandwidth_already_informed_flag=1;
* start scheduler to reset in 60min

Another solution: use graphing to monitor usage over longer time interval (not just instantaneous).
by sebastia
Mon May 13, 2019 12:21 am
Forum: The Dude
Topic: Notification on network usage
Replies: 4
Views: 830

Re: Notification on network usage

I've noticed afterwards that your question is in dude section, while my response related to RouterOS, which I'm guessing is not what you're after.
by sebastia
Sun May 12, 2019 4:10 pm
Forum: Beginner Basics
Topic: Simple Queues vs Queue Tree
Replies: 3
Views: 930

Re: Simple Queues vs Queue Tree

have a look:
https://www.youtube.com/watch?v=loaVBWq6cWA
slides are linked
by sebastia
Sun May 12, 2019 3:38 pm
Forum: Beginner Basics
Topic: DMZ local ip to another without dstnat/port-forward the ports [SOLVED]
Replies: 6
Views: 555

Re: DMZ local ip to another without dstnat/port-forward the ports [SOLVED]

So you have two wans and two lans. How do you isolate them? VRF?
instead of natting, routing info needs to be update. List your config (/export hide-sensitive compact)
by sebastia
Sat May 11, 2019 11:06 pm
Forum: The Dude
Topic: Notification on network usage
Replies: 4
Views: 830

Re: Notification on network usage

by sebastia
Sat May 11, 2019 11:05 pm
Forum: General
Topic: Fastrack no working
Replies: 1
Views: 218

Re: Fastrack no working

by sebastia
Sat May 11, 2019 10:55 pm
Forum: Beginner Basics
Topic: DMZ local ip to another without dstnat/port-forward the ports [SOLVED]
Replies: 6
Views: 555

Re: DMZ local ip to another without dstnat/port-forward the ports [SOLVED]

why not just route: just connect to .1.10/11 address?

gateway of 0.100 is 0.1 = Tik right?
and Tik knows how to get to 1.1x...
by sebastia
Fri May 10, 2019 9:30 pm
Forum: General
Topic: Queue tree upload max-limit stops working when parent=ether1
Replies: 7
Views: 812

Re: Queue tree upload max-limit stops working when parent=ether1

Hey HzMeister You are correct in your assumption: this is a working setup. Clipboard01.png /queue tree add max-limit=29M name=ext parent=bridgeExt add name=ext20 packet-mark=20 parent=ext priority=2 add name=ext30 packet-mark=30 parent=ext priority=3 add name=extFT packet-mark=no-mark parent=ext pri...
by sebastia
Fri May 10, 2019 9:01 pm
Forum: General
Topic: Equal Bandwidth Distribution: PCQ vs. "Untouched"
Replies: 8
Views: 1235

Re: Equal Bandwidth Distribution: PCQ vs. "Untouched"

If it was up to me, the pcq-total-limit shouldn't be much larger than 1/10 s of max transmission on upload side: suppose you have a gamer, that would have latency of 100ms.... he wouldn't be happy. On download the queue is only there to account for and spread the bandwidth. It's an artificial bottle...
by sebastia
Wed May 08, 2019 11:45 pm
Forum: General
Topic: VoIP with load balancing PCC
Replies: 29
Views: 1902

Re: VoIP with load balancing PCC

Documentation is not clear on that point: https://wiki.mikrotik.com/wiki/Manual:HTB. One example has such situation, but the effect/goal is not elaborated. Then again is that a valid situation for you? I would think not: voip should have higher prio, and it's volume will be much smaller than rest in...
by sebastia
Wed May 08, 2019 8:45 pm
Forum: Beginner Basics
Topic: Bridge interface not showing traffic [SOLVED]
Replies: 18
Views: 1957

Re: Bridge interface not showing traffic [SOLVED]

I think the problem is the wan bridge itself. For QOS to work, one needs to control the transmission. But in your case traffic is bypassing queue on bridge (because its in hardware / accelerated) which results in unpredictable queueing to ISP.
by sebastia
Wed May 08, 2019 11:04 am
Forum: Beginner Basics
Topic: Firewall chain for virtual interfaces of tunnels [SOLVED]
Replies: 2
Views: 360

Re: Firewall chain for virtual interfaces of tunnels [SOLVED]

Input chain is for any packet coming INTO router, from any available interface.
forward chain is for packets passing through router, so from one interface of router to another.
by sebastia
Wed May 08, 2019 10:38 am
Forum: General
Topic: Equal Bandwidth Distribution: PCQ vs. "Untouched"
Replies: 8
Views: 1235

Re: Equal Bandwidth Distribution: PCQ vs. "Untouched"

* current mangles should work, but specifying interface is easier than working with ip's ** to eth2 -> download ** to eth1 -> upload * at this time there is no advantage in mangling as all to-from-lan is marked with "pcq-connection", still a to-do for future? * usually (except some specific situatio...
by sebastia
Tue May 07, 2019 7:12 pm
Forum: General
Topic: HOWTO: Dual WAN PCC with Dynamic IP
Replies: 34
Views: 6142

Re: HOWTO: Dual WAN PCC with Dynamic IP

LTE probably gets an /32 ip? That's a point-to-point connection, and in such a case the "gateway" can be determined by OS (=ip at the other end), so interface is enough.
by sebastia
Tue May 07, 2019 5:19 pm
Forum: General
Topic: Equal Bandwidth Distribution: PCQ vs. "Untouched"
Replies: 8
Views: 1235

Re: Equal Bandwidth Distribution: PCQ vs. "Untouched"

if accounting bandwidth per users it's usually because it's scarce, and hence queueing will be used. PCQ is a type of queue.

PCC is load balancing / routing method (pcc requires mangling). so indeed spreading the load is the essence.
by sebastia
Tue May 07, 2019 2:09 pm
Forum: General
Topic: VoIP with load balancing PCC
Replies: 29
Views: 1902

Re: VoIP with load balancing PCC

it should work: verify counters on queues that they are actually used.
Only packets with no-mark for wan2, as queue is attached to wan2.

Make sure max-limit is not too high: there should be no buffering on isp modem => no added latency.
by sebastia
Tue May 07, 2019 10:06 am
Forum: General
Topic: dst-limit not matching when rate is higher than 5000
Replies: 3
Views: 435

Re: dst-limit not matching when rate is higher than 5000

That was indeed the post / thread I meant...
by sebastia
Tue May 07, 2019 9:52 am
Forum: General
Topic: VoIP with load balancing PCC
Replies: 29
Views: 1902

Re: VoIP with load balancing PCC

You can use "no-mark" for bulk! So what you can do, is mangle voip selectively and throw rest of unmarked packets in "bulk" queue. What is needed: * in postrouting, mark packets with PBX connection mark -> for that you'll need a separate connection mark * setup htb on wan interface (not global) with...
by sebastia
Mon May 06, 2019 11:56 pm
Forum: General
Topic: VoIP with load balancing PCC
Replies: 29
Views: 1902

Re: VoIP with load balancing PCC

add a queue tree on wan link, and define queues matching packet marks.
https://wiki.mikrotik.com/wiki/Manual:Queue#Queue_Tree
https://wiki.mikrotik.com/wiki/Manual:HTB
by sebastia
Mon May 06, 2019 11:12 pm
Forum: General
Topic: VoIP with load balancing PCC
Replies: 29
Views: 1902

Re: VoIP with load balancing PCC

if you really want to do marking, reuse existing marks: add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local in-interface=bridge src-address=192.168.1.100 new-connection-mark=WAN2 passthrough=yes comment="Voip connection mark WAN2" Rest of original script can b...
by sebastia
Mon May 06, 2019 10:14 pm
Forum: General
Topic: VoIP with load balancing PCC
Replies: 29
Views: 1902

Re: VoIP with load balancing PCC

Assign an "unused" mark so it's not processed by other mangles and uses default routing.
/ip firewall mangle
add action=mark-connection connection-mark=no-mark chain=prerouting src-address=<pbx box> comment="Mark pbx" new-connection-mark=PBX
by sebastia
Mon May 06, 2019 9:27 pm
Forum: Beginner Basics
Topic: Open port between Guest WIFI and my main network [SOLVED]
Replies: 23
Views: 1516

Re: Open port between Guest WIFI and my main network [SOLVED]

Ok i'll take a look at that, but i think i foud a solution, with the Hairpin Nat i can access the camera on the port 88 !
That will do the trick too but only for one destination?
Getting a bit complex ? ;-)
by sebastia
Mon May 06, 2019 9:25 pm
Forum: Beginner Basics
Topic: Open port between Guest WIFI and my main network [SOLVED]
Replies: 23
Views: 1516

Re: Open port between Guest WIFI and my main network [SOLVED]

Great minds ... ;-) (Selfish, yes ;-) )
by sebastia
Mon May 06, 2019 9:07 pm
Forum: Beginner Basics
Topic: Open port between Guest WIFI and my main network [SOLVED]
Replies: 23
Views: 1516

Re: Open port between Guest WIFI and my main network [SOLVED]

Hey * don't use wpa, it's broken To do what you want you need to have the notion of connection tracking: allow connection from lan to guest (and related responses, so conn tracking needed) but don't allow connections (new) from guest to lan. Bridge firewall doesn't have that capability. You could tr...
by sebastia
Mon May 06, 2019 12:11 pm
Forum: General
Topic: Equal Bandwidth Distribution: PCQ vs. "Untouched"
Replies: 8
Views: 1235

Re: Equal Bandwidth Distribution: PCQ vs. "Untouched"

Hi 1. No, connection have both up and down "legs". Hence your mangling changes the connection marks on a connection back and forth to "up" and "down", with unpredictable results on the actual packet mangling... 2. available bandwidth will be split equally and depending on load. If one users is not u...
by sebastia
Sat May 04, 2019 1:58 pm
Forum: Beginner Basics
Topic: Bridge interface not showing traffic [SOLVED]
Replies: 18
Views: 1957

Re: Bridge interface not showing traffic [SOLVED]

Got me wondering: CCR1009-7G-1C-1S+ doesn't have any switch chip, https://i.mt.lv/cdn/rb_files/CCR1009-7G-1C-1Splus-170321154504.png So traffic between ports, part of bridge will need to be passed on by cpu in software. Hence I would expect all traffic should be visible and accounted for? BUT it doe...
by sebastia
Fri May 03, 2019 3:01 pm
Forum: RouterBOARD hardware
Topic: hEX RB750Gr2 grounding
Replies: 3
Views: 735

Re: hEX RB750Gr2 grounding

If cable goes outside, it should be grounded, directly or indirectly. GR2 is not grounded on it's own, and given it's enclosure of plastic, not sure you can.
Perhaps you should ground cable directly?
by sebastia
Thu May 02, 2019 8:25 pm
Forum: General
Topic: How to set ping parameters in IP route?
Replies: 1
Views: 218

Re: How to set ping parameters in IP route?

ping target is the gateway address. There is no other ip involved. If you want something else please have a look at https://wiki.mikrotik.com/wiki/Advanced ... _Scripting
by sebastia
Thu May 02, 2019 8:20 pm
Forum: Beginner Basics
Topic: 2 Mikrotik behind firewall
Replies: 13
Views: 806

Re: 2 Mikrotik behind firewall

You're welcome.
by sebastia
Thu May 02, 2019 5:32 pm
Forum: General
Topic: Given the hardware similarities
Replies: 2
Views: 292

Re: Given the hardware similarities

Look at OpenWRT maybe?
by sebastia
Thu May 02, 2019 1:43 am
Forum: General
Topic: Interface Queue Causing Slow Performance
Replies: 2
Views: 324

Re: Interface Queue Causing Slow Performance

If you have excess capacity, why use queues ;-) ? Someone else on the forum had a setup in production, where the backbone was unlimited, and policing / shaping happened closer to clients. 1500 packets x 1500 b/packet = 2,2MB 4Gbps / 8bit/byte = 512MB/s 2,2MB / 512MB/s = 4ms looks to be fine from buf...
by sebastia
Wed May 01, 2019 12:24 pm
Forum: General
Topic: One physical port/ multiple bridges
Replies: 5
Views: 911

Re: One physical port/ multiple bridges

Hoy

These are the same vlans, so all you need to do is add the n'th eoip as new port to bridge, and indicate which vlans (101 & 2) need to pass over it.
by sebastia
Wed May 01, 2019 11:59 am
Forum: Beginner Basics
Topic: 2 Mikrotik behind firewall
Replies: 13
Views: 806

Re: 2 Mikrotik behind firewall

You'll also need to:
indicate in which vlans it partiipates under /interface ethernet switch vlan
change from access to trunk under /interface ethernet switch port
by sebastia
Tue Apr 30, 2019 9:25 pm
Forum: General
Topic: Upgrade from old firmware, is it safe?
Replies: 2
Views: 303

Re: Upgrade from old firmware, is it safe?

it's still a supported device.
Before you upgrade: "/export compact" your full config + export any certificates / keys you have in use, as these are not part of "export"
you're bridge config will change, so be careful with restore if needed.

BootRom can be updated after software update.
by sebastia
Tue Apr 30, 2019 9:20 pm
Forum: Beginner Basics
Topic: 2 Mikrotik behind firewall
Replies: 13
Views: 806

Re: 2 Mikrotik behind firewall

if firewall doing the vlan routing?

and both Tik's are used as smart switches then?

If you use Tik1Port3 for connection to Tik2, then this port has to be cofigured as trunk too, just like Port2: so all vlans (or the relevant ones) present and all tagged.
by sebastia
Tue Apr 30, 2019 8:58 pm
Forum: Beginner Basics
Topic: NAT not working in load balance (2 WAN)
Replies: 5
Views: 544

Re: NAT not working in load balance (2 WAN)

Or more likely... PCC is available from v3 see top right corner. Or see history: https://wiki.mikrotik.com/index.php?title=Manual:PCC&action=history On top of that, it was user generated content, when it was still allowed. FastTrack has been added only recently. And best of all: the wiki on FT(https...
by sebastia
Tue Apr 30, 2019 2:36 pm
Forum: General
Topic: DHCP Queue needed
Replies: 3
Views: 328

Re: DHCP Queue needed

This could work. Just need to change the limits pcq-rate to your liking. Setting total max for upload & download is advisable to provide overall QoS.
by sebastia
Tue Apr 30, 2019 2:15 pm
Forum: Beginner Basics
Topic: 2 Mikrotik behind firewall
Replies: 13
Views: 806

Re: 2 Mikrotik behind firewall

Tik1 Port3 is access port: only untagged traffic for vlan 21 will pass.

If you want vlan 21 & 22 on Tik2, you'll need to use Port2 of Tik1 as this one is trunk port.

Note: "set ether2 vlan-mode=secure vlan-header=add-if-missing" without saying which id doesn't make sense
by sebastia
Tue Apr 30, 2019 11:26 am
Forum: Beginner Basics
Topic: 2 Mikrotik behind firewall
Replies: 13
Views: 806

Re: 2 Mikrotik behind firewall

List your config on Tik1 (/export hide-senstive compact) and indicate who you want to connect: from what interface to which?
by sebastia
Tue Apr 30, 2019 11:24 am
Forum: Scripting
Topic: [newbie] How to get a script to run automatically
Replies: 3
Views: 554

Re: [newbie] How to get a script to run automatically

which script? what is your config? (-> /export hide-sensitive compact)
by sebastia
Mon Apr 29, 2019 11:36 am
Forum: General
Topic: simple queue missing traffic (ie not working) (simple 1 pc setup)
Replies: 4
Views: 510

Re: simple queue missing traffic (ie not working) (simple 1 pc setup)

With queuing one can only really control the transmitting side: so before almost filling the uplink pipe, what to send. On reception side it's a hack: by dropping some packets already transmitted and received, TCP and ONLY tcp, can be forced to back down / slow transmission. The UPD is connection le...
by sebastia
Mon Apr 29, 2019 1:32 am
Forum: Beginner Basics
Topic: FastTrack and dual WAN
Replies: 4
Views: 604

Re: FastTrack and dual WAN

mark connections for fasttrack in chain=forward, only from lan to wan1.
by sebastia
Mon Apr 29, 2019 1:29 am
Forum: Beginner Basics
Topic: LTE passthrough winbox issue
Replies: 5
Views: 1500

Re: LTE passthrough winbox issue

have tried the search feature? https://wiki.mikrotik.com/wiki/Manual:Interface/LTE#Passthrough_Example LTE pass-through is locked to specific MAC (either given or chosen), so communication from another MAC on same subnet is not affected (hijacked), and router can be reached. wrt bridge, on the clien...
by sebastia
Sun Apr 28, 2019 12:46 pm
Forum: Beginner Basics
Topic: Recommended LTE modem for RBwAPR-2nD?
Replies: 3
Views: 393

Re: Recommended LTE modem for RBwAPR-2nD?

if you're are "remote" why don't you have a look at LHG LTE, or high gain external antennae.

I myself use SXT LTE and throughput wise happy with it, but I'm not in "remote" area.
by sebastia
Sun Apr 28, 2019 12:39 pm
Forum: General
Topic: 2 WAN Transmit on 1 Specific interface using separate VLANs
Replies: 3
Views: 388

Re: 2 WAN Transmit on 1 Specific interface using separate VLANs

Hi

Have a look at VRF/routing rules, with it you can setup independent routing for specific incoming interfaces.
by sebastia
Sun Apr 28, 2019 12:33 pm
Forum: Wireless Networking
Topic: How to make Wireless Wire Dish tu autoreboot after a rain?
Replies: 6
Views: 853

Re: How to make Wireless Wire Dish tu autoreboot after a rain?

Just a thought, you may want to introduce some "delay" on detection, so when it's raining your hardware doesn't continuously power-cycle...
by sebastia
Sun Apr 28, 2019 12:30 pm
Forum: Beginner Basics
Topic: FastTrack and dual WAN
Replies: 4
Views: 604

Re: FastTrack and dual WAN

With FastTrack enabled, mangling is bypassed. So all your traffic goes over your default wan link, and you're not using both.
Mangling and FastTrack are incompatible.

What you could do: FastTrack default route. and process "special" route (=wan2) using full processing.
by sebastia
Fri Apr 26, 2019 4:28 pm
Forum: Wireless Networking
Topic: How to make Wireless Wire Dish tu autoreboot after a rain?
Replies: 6
Views: 853

Re: How to make Wireless Wire Dish tu autoreboot after a rain?

Have you tried recycling the radio / wireless interface only? You could script that: based on ping loss recycle radio.
by sebastia
Fri Apr 26, 2019 2:56 pm
Forum: Scripting
Topic: FUP Script with Auto Carry over.
Replies: 3
Views: 678

Re: FUP Script with Auto Carry over.

The idea is simple: currently the daily quota is fixed in script. Make it a dynamic field, and store similar to other params in a file. On roll-over, at midnight, run another script which adds the unused bandwidth to allowed quota parameter / file and resets the counter to 0. Make sure you "first" s...
by sebastia
Fri Apr 26, 2019 11:42 am
Forum: General
Topic: simple queue missing traffic (ie not working) (simple 1 pc setup)
Replies: 4
Views: 510

Re: simple queue missing traffic (ie not working) (simple 1 pc setup)

Your config is not in sync with the screenshots.

This queue should to the trick: target should be "internal" ip range / interface.
add max-limit=100M/100M name=queue3 target=192.168.1.14/32

You might want to reduce the bucket-size (which defaults to 0.1) to have a finer control over the bandwidth.
by sebastia
Fri Apr 26, 2019 10:29 am
Forum: General
Topic: Two SXT LTE, one for each subnet - how?
Replies: 4
Views: 312

Re: Two SXT LTE, one for each subnet - how?

You could indeed.
by sebastia
Thu Apr 25, 2019 12:35 pm
Forum: Beginner Basics
Topic: Recommended LTE modem for RBwAPR-2nD?
Replies: 3
Views: 393

Re: Recommended LTE modem for RBwAPR-2nD?

The issue is not so much the modem but the antenna's.
Although since the modem is limited to 150 / 50 mb down / up max theoretical bandwidth, higher CAT radio's can get better throughput with same similar quality of signal.
by sebastia
Thu Apr 25, 2019 12:27 pm
Forum: General
Topic: Two SXT LTE, one for each subnet - how?
Replies: 4
Views: 312

Re: Two SXT LTE, one for each subnet - how?

Hi What could work: dedicated routing tables for both lte links, and a set of routing rules to direct traffic in these directions. /ip route add comment=LTE1 gateway=<gw1> routing-mark=lte1 add comment=LTE2 gateway=<gw2> routing-mark=lte2 /ip route rule add action=lookup src-address=<local> dst-addr...
by sebastia
Thu Apr 25, 2019 11:53 am
Forum: Scripting
Topic: FUP Script with Auto Carry over.
Replies: 3
Views: 678

Re: FUP Script with Auto Carry over.

Hey

If you're planning on posting the script anyway, why don't you post already what you have, so people will chip in?
by sebastia
Wed Apr 17, 2019 4:18 pm
Forum: Beginner Basics
Topic: simple failover
Replies: 3
Views: 371

Re: simple failover

Have a look at this viewtopic.php?t=124946
by sebastia
Wed Apr 17, 2019 11:43 am
Forum: Beginner Basics
Topic: simple failover
Replies: 3
Views: 371

Re: simple failover

hi

If you can isolate isp2 usage to some ip/range, then you could configure routing rule(s) to route traffic from these ips over ips2.
=> dedicated usage

otherwise it's not possible without mangling
by sebastia
Wed Apr 17, 2019 10:31 am
Forum: Scripting
Topic: Bridge Vlans
Replies: 1
Views: 315

Re: Bridge Vlans

Since you intent to use 750up as smart switch, it's supported / possible. The uni would then handle the routing.
Not sure though what switch capabilities the 750up has
by sebastia
Sat Apr 13, 2019 11:27 am
Forum: General
Topic: Mikrotik IP Cloud vs P2P
Replies: 8
Views: 750

Re: Mikrotik IP Cloud vs P2P

"Especially in our country" would that be China with "The Great Firewall" (or North Korea) ? That's indeed unusual and regime induced
by sebastia
Sat Apr 13, 2019 11:18 am
Forum: General
Topic: 3 ISP channels needed to work simultaneously
Replies: 8
Views: 707

Re: 3 ISP channels needed to work simultaneously

You'll need another routing-mark, next to existing pppoe-rt, and some mechanism to direct traffic to that routing table. This can be:
* mangling: each packet to go over lte, needs that routing-mark set in prerouting chain
* routing rule

BTW: new routing table + routing rule(s) = VRF ;-)
by sebastia
Sat Apr 13, 2019 11:06 am
Forum: General
Topic: Pass WAN over VLAN [SOLVED]
Replies: 15
Views: 1062

Re: Pass WAN over VLAN [SOLVED]

what he said ;-)
by sebastia
Sat Apr 13, 2019 12:53 am
Forum: General
Topic: Pass WAN over VLAN [SOLVED]
Replies: 15
Views: 1062

Re: Pass WAN over VLAN [SOLVED]

What I meant indeed. I guess the advantage would be that bridge would already have done the security (vlan filter) checks.
by sebastia
Sat Apr 13, 2019 12:07 am
Forum: RouterBOARD hardware
Topic: Difference between CRS 125 and the CRS326-24G-2S + RM
Replies: 3
Views: 822

Re: Difference between CRS 125 and the CRS326-24G-2S + RM

main differences will be in switch chip capabilities: same config will result in hw or sw processing. Ex vlan-filtering -> CRS3:hw <> CRS1xx:sw
by sebastia
Sat Apr 13, 2019 12:03 am
Forum: General
Topic: Pass WAN over VLAN [SOLVED]
Replies: 15
Views: 1062

Re: Pass WAN over VLAN [SOLVED]

B2 copy-paste error -> name=ether1-vlan-20-access since vlan 100 is passed to bridge1, I would setup the vlan interface on bridge not the ether5 directly (haven't verified if there would be a difference) /interface vlan add comment="WAN Passthrough VLAN" interface=ether5-trunk-to-b1 name=WAN \ vlan-...
by sebastia
Fri Apr 12, 2019 7:49 pm
Forum: General
Topic: Pass WAN over VLAN [SOLVED]
Replies: 15
Views: 1062

Re: Pass WAN over VLAN [SOLVED]

BTW, in real world, not on CHR in GNS3, you'll probably will want, depending on bandwidth, to use vlan filtering of /interface switch chip, as this will be in hardware. the vlan-filtering in bridge is only on CRS3xx in hardware.
by sebastia
Fri Apr 12, 2019 7:23 pm
Forum: General
Topic: Pass WAN over VLAN [SOLVED]
Replies: 15
Views: 1062

Re: Pass WAN over VLAN [SOLVED]

Try this On B1 /interface bridge vlan add bridge=bridge1 tagged=ether5 ,bridge1 untagged=ether1 vlan-ids=100 On B2: /interface bridge vlan add bridge=bridge1 tagged=ether5,bridge1 untagged=ether1 vlan-ids=100 /interface vlan add interface=bridge1 name=v100 vlan-id=100 /ip address add address=1.1.1.2...
by sebastia
Fri Apr 12, 2019 5:23 pm
Forum: General
Topic: Pass WAN over VLAN [SOLVED]
Replies: 15
Views: 1062

Re: Pass WAN over VLAN [SOLVED]

vlan = virtual lan, so what you try to do is not out of the ordinary. Instead of using another physical cable you use vlan instead. To achieve what you want: mark the wan interface on hap as (to-be) as access port for wan vlan: so untagging on egress, and tagging on ingress for WAN interface configu...
by sebastia
Fri Apr 12, 2019 12:52 pm
Forum: General
Topic: RADSEC not work for me
Replies: 3
Views: 354

Re: RADSEC not work for me

recently additional field was added:
--subject-alt-name="DNS:<fqdn>,IP:<ip>" (snippet from easyrsa script)
by sebastia
Fri Apr 12, 2019 12:21 pm
Forum: Scripting
Topic: Script to verify incoming IP address and block it in firewall (add to address list)
Replies: 4
Views: 767

Re: Script to verify incoming IP address and block it in firewall (add to address list)

A more fundamental question is: should that service be accessible from internet? And if so, from the whole internet or just specific location? The default firewall should be: allow only specific / needed traffic (ip / range / service) block everything else This eliminates the need to check on source...
by sebastia
Fri Apr 12, 2019 12:16 pm
Forum: Beginner Basics
Topic: /interface list usage question
Replies: 2
Views: 325

Re: /interface list usage question

Ports under bridge are "slaves", and can't be addressed independently. One can only address the bridge. So you can't match on only some ports of the bridge.
by sebastia
Fri Apr 12, 2019 12:07 pm
Forum: General
Topic: RADSEC not work for me
Replies: 3
Views: 354

Re: RADSEC not work for me

I would expect that you need to import the signing chain into /certificate. This will allow to verify the signatures on the used certificates.
by sebastia
Thu Apr 11, 2019 11:29 am
Forum: General
Topic: How do I block Proxy website online
Replies: 5
Views: 1311

Re: How do I block Proxy website online

...you would need...
You can input address - ip/dns by following command:
/ip firewall address-list add address=<ip/dns> list=<list-name>

and then use these in firewall rules, ex:
/ip firewall filter add dst-address-list=<list-name> ...
by sebastia
Thu Apr 11, 2019 11:06 am
Forum: General
Topic: Domain resolution + local services
Replies: 5
Views: 412

Re: Domain resolution + local services

The server A is in same subnet as the client right?
Are the dst-port and to-ports same? Then just add a static dns entry on Tik for the sub-domain pointing to the internal ip.

If ports are different, you'll need to add src-nat nat rule for traffic from lan to lan. See "hairpin" for more details
by sebastia
Thu Apr 11, 2019 10:48 am
Forum: General
Topic: How do I block Proxy website online
Replies: 5
Views: 1311

Re: How do I block Proxy website online

Hi OpenDNS could easily be bypassed by using ip's instead of dns names. To achieve what you want, you would need to compile/import an "address list" of known proxy servers and deny connections to those ip's in Tik firewall. Such lists do exists (ex: OpenDNS) but not sure if you can export them (and ...
by sebastia
Wed Apr 10, 2019 9:31 pm
Forum: General
Topic: Mikrotik IP Cloud vs P2P
Replies: 8
Views: 750

Re: Mikrotik IP Cloud vs P2P

** applicable to IPv6 only
by sebastia
Wed Apr 10, 2019 12:16 pm
Forum: General
Topic: How to manual set IPv6 link-local address on interface?
Replies: 4
Views: 553

Re: How to manual set IPv6 link-local address on interface?

Hey

Link-local is set automatically, and all adresses are in fe80:0:0:0/64 range and so can communicate. If it's somehow gone, just disable and enable interface. It will be auto added.
by sebastia
Sun Apr 07, 2019 12:26 pm
Forum: RouterBOARD hardware
Topic: Mikrotik and LTE cat6
Replies: 9
Views: 3337

Re: Mikrotik and LTE cat6

CAT6 by spec is 300 down and 50 up, as quoted by numerous sources (ex: https://www.cablefree.net/wirelesstechn ... finitions/)
by sebastia
Sat Apr 06, 2019 2:07 am
Forum: General
Topic: Trafic flow takes many time to send information
Replies: 1
Views: 256

Re: Trafic flow takes many time to send information

Hey

it's in config

# if connection remains active, send every 30m
active-flow-timeout: 30m
# if connection terminates, send after 15s
inactive-flow-timeout: 15s

Answser: set active to lower value you wish to have, ex every minute
by sebastia
Fri Apr 05, 2019 7:24 pm
Forum: Beginner Basics
Topic: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]
Replies: 12
Views: 1333

Re: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]

Not sure what you mean by this "I have tried this configuration and have added static route to the USG on 192.168.1.1. ", but you don't need it. on the router: fatcat168@ubnt:~$ show interfaces Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down Interface IP Address S/L Description --------...
by sebastia
Fri Apr 05, 2019 5:52 pm
Forum: Beginner Basics
Topic: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]
Replies: 12
Views: 1333

Re: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]

what do you mean by "modem"? LHG LTE?
by sebastia
Fri Apr 05, 2019 5:17 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

In such form, it does introduce another potential issue: connections lasting longer than "timeout" can be impacted as their packets will get dropped for IPv6 implementing privacy features, which change ipv6 after a while.
Something to keep in mind.
by sebastia
Fri Apr 05, 2019 12:48 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

Thx for info, I guess you do it (the address addition to the list) on connection level, not for each packet?
by sebastia
Thu Apr 04, 2019 9:23 pm
Forum: General
Topic: PLEASE HELP: tunneling 2 mikrotiks with net trafic
Replies: 4
Views: 324

Re: PLEASE HELP: tunneling 2 mikrotiks with net trafic

Something like /ip route # default route add comment=VPN distance=10 gateway=<ip gateway on vpn network> # route to vpn server, for the tunnel itself add comment=VPN-connection dst-address=<public ip of vpn server> distance=5 gateway=<gateway of your ISP> ... <other local networks> and you'll probab...
by sebastia
Thu Apr 04, 2019 9:15 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

@pe1chl, question: in your setup externally initiated ipv6 traffic is disallowed right?
by sebastia
Thu Apr 04, 2019 9:05 pm
Forum: General
Topic: PLEASE HELP: tunneling 2 mikrotiks with net trafic
Replies: 4
Views: 324

Re: PLEASE HELP: tunneling 2 mikrotiks with net trafic

Hi

You need to route all traffic except the vpn itself (so no loops) over the vpn.
BTW, given where you live, I would suggest to upgrade your vpn to higher security, ex IPSec.

Cheers
by sebastia
Thu Apr 04, 2019 12:29 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

Just wondering what will happen / be the effect when "under attack" and hitting memory limit?
* on neighbour mem limit
* on routing cache limit

Router will survive, but what with the legit connections?
by sebastia
Thu Apr 04, 2019 11:19 am
Forum: Beginner Basics
Topic: Bridge 2 vlans
Replies: 7
Views: 595

Re: Bridge 2 vlans

Two elements needed:
* ensure that router on each end knows where/how to forward traffic for the "other end"
* ensure that forward is allowed in /ip firewall filter chain=forward ...
by sebastia
Thu Apr 04, 2019 11:16 am
Forum: Announcements
Topic: v6.44.2 [stable] is released!
Replies: 67
Views: 14544

Re: v6.44.2 [stable] is released!

by sebastia
Thu Apr 04, 2019 10:35 am
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 1089

Re: How much Support RB3011

in that case, have you this set?

/ip settings set rp-filter=strict
by sebastia
Thu Apr 04, 2019 12:29 am
Forum: Beginner Basics
Topic: Bridge 2 vlans
Replies: 7
Views: 595

Re: Bridge 2 vlans

Bridging means the two subnets would become one: one ip range. Is that what you want?
Or do you meant to route traffic between these two vlans?
by sebastia
Wed Apr 03, 2019 12:36 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 1089

Re: How much Support RB3011

This is what I meant: https://mum.mikrotik.com/presentations/ ... 948376.pdf
point 1: slide 23
point 2: slide 16
by sebastia
Tue Apr 02, 2019 11:57 pm
Forum: RouterBOARD hardware
Topic: Mikrotik and LTE cat6
Replies: 9
Views: 3337

Re: Mikrotik and LTE cat6

Mikrotik has announced LTE CAT6 too:
viewtopic.php?f=3&t=146191&hilit=lte+mum
by sebastia
Tue Apr 02, 2019 11:44 pm
Forum: General
Topic: Filter Rule Rate Limit
Replies: 3
Views: 397

Re: Filter Rule Rate Limit

The opposite: dst-limit=20,20,src-address/1s matches anything below that limit, so all src ips below the limit will be added to the list. The offenders will not. Doc: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter#Properties Matches packets until a given rate is exceeded. Rate is defined a...
by sebastia
Tue Apr 02, 2019 11:41 pm
Forum: General
Topic: Trunk Port on MT4011 (RTL8367)
Replies: 7
Views: 739

Re: Trunk Port on MT4011 (RTL8367)

The RTL8367 switch chip doens't even have vlan table... see https://wiki.mikrotik.com/wiki/Manual:S ... troduction
So no hw offloading for vlans
by sebastia
Tue Apr 02, 2019 11:32 pm
Forum: General
Topic: Filter Rule Rate Limit
Replies: 3
Views: 397

Re: Filter Rule Rate Limit

Hey

Normally you would want to accept anything under the limit, and only add if over. So two rules:
1. under limit -> accept
2 over -> add to list

tcp based access is usually a long running connection, ex nslookup program. Less likely to occur.
by sebastia
Tue Apr 02, 2019 7:42 pm
Forum: Scripting
Topic: Reset-config script: enable IPv6 and set parameters
Replies: 2
Views: 400

Re: Reset-config script: enable IPv6 and set parameters

Normally after netinstall all packages are enabled.
by sebastia
Tue Apr 02, 2019 7:39 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 1089

Re: How much Support RB3011

* you're wan ip's are fixed right? then you should be using src-nat instead of masquerade
* do you propagate the dynamic client's ip through dynamic routing? On /ip basis or by ranges? first one (/ip) could cause regular routing updates / sync on clients leaving / disconnecting
by sebastia
Tue Apr 02, 2019 7:25 pm
Forum: General
Topic: Trunk Port on MT4011 (RTL8367)
Replies: 7
Views: 739

Re: Trunk Port on MT4011 (RTL8367)

Just for info, 4011 is not a good match for doing vlan switching/bridging/filtering as it all has to happen in software by cpu.
by sebastia
Tue Apr 02, 2019 12:02 pm
Forum: Beginner Basics
Topic: Bandwidth management using PCQ
Replies: 6
Views: 666

Re: Bandwidth management using PCQ

I do indeed
by sebastia
Tue Apr 02, 2019 11:05 am
Forum: Beginner Basics
Topic: Bandwidth management using PCQ
Replies: 6
Views: 666

Re: Bandwidth management using PCQ

You don't need a parent, but it has it's advantages.

without parent, available bandwidth need to be manual spread over all the queues, upfront.

With a parent, the available bandwidth can be dynamically allocated to queues needing it.
by sebastia
Tue Apr 02, 2019 11:01 am
Forum: Beginner Basics
Topic: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]
Replies: 12
Views: 1333

Re: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]

with pass-through on vlan and mgmt on naked / plain interface, there is no need for mac change.
by sebastia
Tue Apr 02, 2019 12:49 am
Forum: Beginner Basics
Topic: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]
Replies: 12
Views: 1333

Re: LHG LTE Management Passthrough to Unifi USG Router [SOLVED]

that question was answered on the other thread too: mgmt can go over naked eth1.
by sebastia
Mon Apr 01, 2019 8:17 pm
Forum: Beginner Basics
Topic: Bandwidth management using PCQ
Replies: 6
Views: 666

Re: Bandwidth management using PCQ

Hey

with pcq one can limit individual's ip traffic, but for all of the users of that class together the limits are defined by max limit.

Ex: YT-3mb can limit bandwidth for single ip / users to 1mb, but if there 10 users in that class this class could consume up to 10mb.
by sebastia
Sun Mar 31, 2019 1:52 pm
Forum: RouterBOARD hardware
Topic: Problem with MikroTik RB4011iGS
Replies: 1
Views: 546

Re: Problem with MikroTik RB4011iGS

Maybe it's software corruption, try to netinstall to last stable version.
by sebastia
Sun Mar 31, 2019 1:16 pm
Forum: Wireless Networking
Topic: Mikrotik WAP LTE passtrough/bridge mode and lost of the management
Replies: 4
Views: 619

Re: Mikrotik WAP LTE passtrough/bridge mode and lost of the management

RoMon is a neat solution to having access to wap. One drawback of this approach is that the wap itself is cutoff from network connectivity.
by sebastia
Sat Mar 30, 2019 11:15 am
Forum: Wireless Networking
Topic: Mikrotik WAP LTE passtrough/bridge mode and lost of the management
Replies: 4
Views: 619

Re: Mikrotik WAP LTE passtrough/bridge mode and lost of the management

Hey What you are experiencing is the consequence of pass-through working: lte modem will pick up packets off eth1 for specific mac address. It has been documented by Mikrotik on wiki. Solution: create a vlan interface on ether1 and set pass-through to that interface. Ether1 will then become manageme...
by sebastia
Sat Mar 30, 2019 10:53 am
Forum: Beginner Basics
Topic: Low upload speeds on Xbox One, Download speeds are normal
Replies: 7
Views: 627

Re: Low upload speeds on Xbox One, Download speeds are normal

Try profiling cpu "/tools profile" while doing transfer. Also verify routing from xbox, trace route. Verify the status of connections in "/ip firewall connection". And finally, which protocol is used for that upload? maybe it's some kind of p2p, and being behind firewall, incoming connections will n...
by sebastia
Sat Mar 30, 2019 12:35 am
Forum: Beginner Basics
Topic: Low upload speeds on Xbox One, Download speeds are normal
Replies: 7
Views: 627

Re: Low upload speeds on Xbox One, Download speeds are normal

all mtu's are same, so that's not it.
Have you tried disabling the source routing and arp addition?
by sebastia
Fri Mar 29, 2019 10:06 pm
Forum: Beginner Basics
Topic: Low upload speeds on Xbox One, Download speeds are normal
Replies: 7
Views: 627

Re: Low upload speeds on Xbox One, Download speeds are normal

The ones that's curious:
/ip dhcp-server add-arp=yes ...

/ip settings
set accept-source-route=yes

Other than that and some filter / nat stuff, default config.
Maybe mtu issue, what is the output of "/interface print"?
by sebastia
Fri Mar 29, 2019 7:22 pm
Forum: Beginner Basics
Topic: Low upload speeds on Xbox One, Download speeds are normal
Replies: 7
Views: 627

Re: Low upload speeds on Xbox One, Download speeds are normal

that's only firewall part, but can't see anything wrong
ether1 is wan I guess?

Note:
this one is not needed "add action=accept chain=forward out-interface=ether1 src-address=192.168.1.0/24"

How do you connect to internet? direct ethernet? or some encapsulation?
by sebastia
Fri Mar 29, 2019 7:14 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

Not what I mean. Looking at the remaining workaround, usual end-user blocking any incoming traffic not already established / related , isn't impacted, right? Usual end-user scenario, so not a major network operation, is to block any incoming traffic, unless it is related to already established traff...
by sebastia
Fri Mar 29, 2019 6:59 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

/ipv6 firewall filter add action=drop chain=forward connection-mark=drop connection-state=new /ipv6 firewall mangle add action=accept chain=prerouting connection-state=new dst-address=\ 2001:db8:3::/64 limit=2,5:packet add action=mark-connection chain=prerouting connection-state=new dst-address=\ 2...
by sebastia
Fri Mar 29, 2019 2:21 pm
Forum: RouterBOARD hardware
Topic: RB4011 Metal temperature is really hot
Replies: 46
Views: 8503

Re: RB4011 Metal temperature is really hot

possibly shorter lifespan?
by sebastia
Fri Mar 29, 2019 2:16 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

Hey maznu

Would you mind posting a link to your presentation / video on this forum once it's presented?
by sebastia
Fri Mar 29, 2019 12:42 pm
Forum: General
Topic: How to filter internal traffic.
Replies: 3
Views: 393

Re: How to filter internal traffic.

Some options:
* firewall on host B
* bridge firewall, but that will get tedious fast, also not all switch chips support it, which would require full cpu processing -> slow
* split network in different domains and block traffic between these networks
by sebastia
Thu Mar 28, 2019 11:47 pm
Forum: General
Topic: prioritize upload traffic from one server to one client
Replies: 7
Views: 509

Re: prioritize upload traffic from one server to one client

Packets should be marked only if needed, and you need it when they are sent over tunnel.
Hence, if you connection-mark in forward and packet mark in postrouting and only when output interface is pptp, there won't be double marking.
by sebastia
Thu Mar 28, 2019 7:59 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 43095

Re: UKNOF 43 CVE

So far, Mikrotik communicated on the blog after the release of a fix.
by sebastia
Thu Mar 28, 2019 5:01 pm
Forum: General
Topic: Running IPv6 on Mikrotik? You're out of business in 12 days time
Replies: 32
Views: 16500

Re: Running IPv6 on Mikrotik? You're out of business in 12 days time

Something similar (if not the same) had been already discussed in this forum. In this thread there two issues listed: nd cache & routing / stateful connection exhaustion. Which is is referred here? First can be mitigated by state-full firewall which most end users will use. For non-end-user, addres...
by sebastia
Thu Mar 28, 2019 12:39 pm
Forum: General
Topic: AccessPoint Router test video series - English subtitles
Replies: 4
Views: 603

Re: AccessPoint Router test video series - Introduction - English subtitles

Cool stuff!

Will also other technology be tested, next to fiber?
by sebastia
Thu Mar 28, 2019 12:31 pm
Forum: Beginner Basics
Topic: TTL Expired
Replies: 5
Views: 477

Re: TTL Expired

Check with traceroute, maybe there is a loop in routing.
by sebastia
Thu Mar 28, 2019 9:58 am
Forum: Scripting
Topic: Get a list of all address-list
Replies: 4
Views: 776

Re: Get a list of all address-list

As long as you don't have a lot of different lists, should still be doable, by de-duplicating the array of list names. Best in a separate script. But since there is no way to check if an element is part of an array, except comparing it with each entry, if there are a lot of lists, it's going to be s...
by sebastia
Wed Mar 27, 2019 11:43 pm
Forum: Scripting
Topic: Assigning static IP address that don't expire to clients [SOLVED]
Replies: 6
Views: 743

Re: Assigning static IP address that don't expire to clients [SOLVED]

I have tried that but the expires after still counts down That's how dhcp operates, the assignments are always limited in time, altough with "static" assignment its always same ip. It seems that your client isn't renewing it's ip, which normally happens when 1/2 of time allowed is reached. Check wh...
by sebastia
Wed Mar 27, 2019 11:28 pm
Forum: General
Topic: Firewall rules: dst-limit invert
Replies: 10
Views: 663

Re: Firewall rules: dst-limit invert

#connection analogy is fitting "limit" in doc: Matches packets up to a limited rate (...). Rule using this matcher will match until this limit is reached. ... together with reject rule after such limit rule, one can limit the rate at which events occur. ex: * number of pings: type=icmp & limit=10/s ...
by sebastia
Wed Mar 27, 2019 9:00 pm
Forum: Scripting
Topic: Get a list of all address-list
Replies: 4
Views: 776

Re: Get a list of all address-list

I think it can be done, but going to be hard.

Iterate over all entries and get the list value (get value-name=list) and add to an array, similar to your foreach at the end
remove duplicates from array which would need to be another script
by sebastia
Wed Mar 27, 2019 8:40 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1503

Re: LTE passthrough over EoIP

test with direct connection or dumb switch...
by sebastia
Wed Mar 27, 2019 7:35 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1503

Re: LTE passthrough over EoIP

Your last post is what I had before refactoring to previously posted config: pass-through on ether directly and management on vlan, wrapped by additonal bridge with overridden mac, but * that bridge / vlan won't be in hardware (wasn't a problem for me as it's low volume anyway) * extra config to mai...
by sebastia
Wed Mar 27, 2019 7:13 pm
Forum: General
Topic: Firewall rules: dst-limit invert
Replies: 10
Views: 663

Re: Firewall rules: dst-limit invert

how about that? create specific chain for this in there 2 rules: within limit action=return over limit action=mark @gotspring: queues are for bandwidth only, number of connections, rate of new connections can't be controlled there @anav: most normal users (even power users having a Tik) won't need i...
by sebastia
Wed Mar 27, 2019 6:52 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1503

Re: LTE passthrough over EoIP

Thx
by sebastia
Wed Mar 27, 2019 6:47 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1503

Re: LTE passthrough over EoIP

Hey gotsprings Question: my lte suffers from frequent lte disconnects, which most of the time the modem resolves itself, but sometimes it can't and I need to recycle (stop-start) lte interface to resume connectivity. That the reason why I have netwatch to monitor remote ip. Do you experience similar...
by sebastia
Wed Mar 27, 2019 6:35 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1503

Re: LTE passthrough over EoIP

* Make sure nothing else is using vlan10, especially not the dhcp, as lte will allow only the first client in. * dell switch is a "dumb" switch, with no vlan filtering right? * make sure you configure "/ip settings rp-filter=loose" (or off) on LTE, there is a bug in 6.43+ which will ignore traffic o...
by sebastia
Wed Mar 27, 2019 2:04 pm
Forum: General
Topic: Firewall rules: dst-limit invert
Replies: 10
Views: 663

Re: Firewall rules: dst-limit invert

Resource limiting / protection: rate, capacity, ...
by sebastia
Wed Mar 27, 2019 12:50 pm
Forum: General
Topic: Firewall rules: dst-limit invert
Replies: 10
Views: 663

Re: Firewall rules: dst-limit invert

Follow up by "same" rule minus the limit and desired action.

Ex:
in-intf=wan & state=new & limit 5/s -> action: accept
in-intf=wan & state=new -> action: drop

Result:
limit number of "new" connection on wan interface to 5/s max. Any additional will be dropped.
by sebastia
Wed Mar 27, 2019 12:42 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1503

Re: LTE passthrough over EoIP

Here is the config for SXT LTE kit # mar/20/2019 23:08:27 by RouterOS 6.44.1 # model = RBSXTR /interface ethernet set [ find default-name=ether1 ] advertise=\ 10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full set [ find default-name=ether2 ] advertise=\ 10M-half,10M-full,100M-half,100M-ful...
by sebastia
Tue Mar 26, 2019 10:16 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1503

Re: LTE passthrough over EoIP

Hey I've lte kit in pass-through working. As of ROS v6.43, it's working with point-to-point ip's 10.177.0.1/32 on lte side and whatever your isp servers on the client side. As of v6.45 Mikrotik will reintroduce (if all goes well) the option to have routed ip's from /30 or wider range, as it was in p...
by sebastia
Tue Mar 26, 2019 3:50 pm
Forum: General
Topic: Mangle rule to match https initial packet [SOLVED]
Replies: 9
Views: 697

Re: Mangle rule to match https initial packet [SOLVED]

Hey

First packets of https connection are the TCP handshake, then followed by ssl handshake.
The first handshake is ip / port based.

What are your criteria?
by sebastia
Tue Mar 26, 2019 2:21 pm
Forum: General
Topic: prioritize upload traffic from one server to one client
Replies: 7
Views: 509

Re: prioritize upload traffic from one server to one client

You can't have a queue tree without a parent, interface doesn't allow it. Further if parent is not linked to the proper / target interface, limiting / shaping will not work on that interface. I don't use ppp myself, but I've understood that you can make it static. To verify that connection are corre...
by sebastia
Tue Mar 26, 2019 2:02 pm
Forum: Beginner Basics
Topic: Configuration from routerboard 750 to hex
Replies: 5
Views: 400

Re: Configuration from routerboard 750 to hex

Start a new thread and provide some info: what problem you see, any logs and the current configuration
by sebastia
Tue Mar 26, 2019 11:45 am
Forum: Beginner Basics
Topic: Config problem, cannot find the problem
Replies: 3
Views: 297

Re: Config problem, cannot find the problem

Hey Welcome on the forum! Regarding your second question: you have dns "redirect" (static entry: /ip dns static add address=13.13.13.6 name=server.domain.com) pointing to local ip, then you don't need to do nat on all interfaces # change add action=dst-nat chain=dstnat comment=Domoticz dst-port=8080...
by sebastia
Tue Mar 26, 2019 11:18 am
Forum: General
Topic: Winbox: Romon Agent not found
Replies: 3
Views: 4343

Re: Winbox: Romon Agent not found

The romon agent, the router which will provide the access to romon network, and to which Winbox needs to connect first before accessing any romon clients, needs to be stored in the managed list.
Is that the case?
by sebastia
Tue Mar 26, 2019 10:56 am
Forum: General
Topic: prioritize upload traffic from one server to one client
Replies: 7
Views: 509

Re: prioritize upload traffic from one server to one client

Hey Some remarks: * you should only mark connection if it's not already marked (in most cases): to avoid repeating same action, so additional condition: " connection-mark=no-mark" * easiest: do connection marking in forward, and packet-marks in postrouting, for specific out-interface only, then ther...
by sebastia
Tue Mar 26, 2019 9:42 am
Forum: General
Topic: Local devices on DHCP are in DNS cache as 0.0.0.0
Replies: 2
Views: 335

Re: Local devices on DHCP are in DNS cache as 0.0.0.0

Or an "on-line" one through dhcp script functionality: viewtopic.php?f=9&t=145177
(self promotion ;-) )
by sebastia
Tue Mar 26, 2019 9:31 am
Forum: General
Topic: Speed when connect to ISP router...
Replies: 2
Views: 228

Re: Speed when connect to ISP router...

Hey You didn't mention SFP, so I'm guessing you're not using it right? Then what you get is max: siee https://i.mt.lv/cdn/rb_files/RB962UiGS-160210082257.png Traffic from Fritz and from lan both need to pass over 1gb/s link, hence theoretical limit of a bit less than 500mb/s Quick fix: use SFP for t...
by sebastia
Tue Mar 26, 2019 9:22 am
Forum: Beginner Basics
Topic: Configuration from routerboard 750 to hex
Replies: 5
Views: 400

Re: Configuration from routerboard 750 to hex

certificate doesn't get exported with /export. You'll need to do it manually: export (or grab backup) and import on new router.
by sebastia
Mon Mar 25, 2019 2:24 pm
Forum: General
Topic: RB2011-iL-RM after botnet attack
Replies: 2
Views: 238

Re: RB2011-iL-RM after botnet attack

Netinstall is the solution. There are some topic on netinstall and how to make it work on this forum, have a look.
by sebastia
Mon Mar 25, 2019 2:21 pm
Forum: Beginner Basics
Topic: Configuration from routerboard 750 to hex
Replies: 5
Views: 400

Re: Configuration from routerboard 750 to hex

Hey

Backup can only be used on same hardware. When migrating to different one, you should export configuration (/export compact file=<name>) and import that on target.
When importing, you'll need to adjust to new hardware configuration.
by sebastia
Mon Mar 25, 2019 1:00 am
Forum: General
Topic: DNS redirect using NAT adding VLAN issue
Replies: 24
Views: 1586

Re: DNS redirect using NAT adding VLAN issue

dnat is a sure way to force your way
by sebastia
Mon Mar 25, 2019 12:49 am
Forum: General
Topic: EoIP not use for ethernet5
Replies: 4
Views: 408

Re: EoIP not use for ethernet5

If you want a different behaviour for eth5 than the rest of the bridge, then you need to isolate it. Two options: another vlan within same bridge or independent of the bridge. Then once isolated, you can setup custom routing for that port, excluding access to tunnel. You do that by creating a dedica...
by sebastia
Mon Mar 25, 2019 12:41 am
Forum: General
Topic: DNS redirect using NAT adding VLAN issue
Replies: 24
Views: 1586

Re: DNS redirect using NAT adding VLAN issue

Natting will work for redirecting naturally, but maybe cleaner / simpler: define different dns server depending on network segment? So, ex: /ip dhcp-server network add address=192.168.88.0/26 dns-server=192.168.88.1 domain=local gateway=192.168.88.1 ntp-server=192.168.88.1 add address=192.168.88.64/...
by sebastia
Sun Mar 24, 2019 6:56 pm
Forum: General
Topic: OpenWRT on Mikrotik
Replies: 2
Views: 550

Re: OpenWRT on Mikrotik

This is not an OpenWRT forum...but you can export / import licence through system menu.
Regarding install check their forums, but probably some variation on netinstall process.
by sebastia
Sun Mar 24, 2019 6:17 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 1089

Re: How much Support RB3011

So: * no bridges/switches, all is routed through cpu (switch is only used for tagging) * there is use of queue simple * there is use of interface queues * there is mangling in place * be careful with "/ip proxy cache-on-disk=yes" it can bog down cpu with IO wait-states and kill the nand * using bgp ...
by sebastia
Sat Mar 23, 2019 10:35 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 1089

Re: How much Support RB3011

List your config (/export hide-sensitive compact) for more in depth feedback.
Some idea's:
* use fast path: https://wiki.mikrotik.com/wiki/Manual:Fast_Path
* disable connection tracking
by sebastia
Sat Mar 23, 2019 10:16 pm
Forum: Scripting
Topic: Basic scripts not working on 6.44.1 (work in 6.43.13)
Replies: 6
Views: 981

Re: Basic scripts not working on 6.44.1 (work in 6.43.13)

Original post did mention "If I copy/paste into terminal window the commands work just fine on 6.44.1" ... So it still works just not in the script.
Permissions maybe?
by sebastia
Sat Mar 23, 2019 10:05 pm
Forum: General
Topic: bridge filter
Replies: 4
Views: 370

Re: bridge filter

You don't do that using bridge firewall, but using routing functionality, when passing traffic from internal to external zone.

Bridge filtering only applies to traffic within ONE subnet.
by sebastia
Sat Mar 23, 2019 2:34 am
Forum: General
Topic: v6.45beta19
Replies: 2
Views: 602

Re: v6.45.19

just for clarity, what is meant is 6.45beta19...
by sebastia
Sat Mar 23, 2019 2:33 am
Forum: Beginner Basics
Topic: Can't connect to a device on VLAN via VPN
Replies: 5
Views: 489

Re: Can't connect to a device on VLAN via VPN

Try pinging IOT step by step from further: starting from router iot ip, then router vpn ip, ... To verify traffic going through, add a log rule in firewall in output and/or postrouting chains. Or just sniff traffic on iot vlan interface. Regarding the vlans & bridges: not related to your issue here,...
by sebastia
Fri Mar 22, 2019 9:55 pm
Forum: Scripting
Topic: rule script
Replies: 1
Views: 363

Re: rule script

try this

/ip firewall nat remove [find comment="rule1"];
/ip firewall nat add place-before=4 ...
by sebastia
Fri Mar 22, 2019 9:10 pm
Forum: Beginner Basics
Topic: Can't connect to a device on VLAN via VPN
Replies: 5
Views: 489

Re: Can't connect to a device on VLAN via VPN

Normally it's a question of routing / firewall, but * in forward: traffic is implicitly allowed already, not dropped -> so allowed * routing is not in config, so default stuff there then: default route over wan + route to all local networks Hence it should be working already. Try diagnosing the issu...
by sebastia
Fri Mar 22, 2019 4:52 pm
Forum: General
Topic: LHG LTE Kit - Passthrough getting address but no internet with more WAN's
Replies: 8
Views: 928

Re: LHG LTE Kit - Passthrough getting address but no internet with more WAN's

With regards to your original issue, post config of the router / 1036: /export hide-sensitive compact. For info: I was able to resolve my issue. It was / is (as from 6.43) a bug in pass-through implementation using routing info for pass-though traffic decision. Because of that rp-filter was erroneou...
by sebastia
Fri Mar 22, 2019 4:28 pm
Forum: General
Topic: Issues with routes with package/routing marks
Replies: 19
Views: 1091

Re: Issues with routes with package/routing marks

Try to understand how client and nvr communicate first. otherwise it's just guessing.
by sebastia
Fri Mar 22, 2019 2:38 pm
Forum: General
Topic: Issues with routes with package/routing marks
Replies: 19
Views: 1091

Re: Issues with routes with package/routing marks

If you disable that rule, responses will not be able to go out over matching isp1 => this basically disables ISP1 routing So then if you have a client in ISP1 range it will connect over ISP2 ip (=that's the only functioning ip connectivity) and since that is your default route for connection from in...
by sebastia
Fri Mar 22, 2019 2:24 pm
Forum: General
Topic: What tunnel method for dynamic ip wan ?
Replies: 1
Views: 325

Re: What tunnel method for dynamic ip wan ?

any tunnel capable of nat traversal will do: sstp, ovpn, ipsec, ...
by sebastia
Fri Mar 22, 2019 2:21 pm
Forum: Beginner Basics
Topic: Can't connect to a device on VLAN via VPN
Replies: 5
Views: 489

Re: Can't connect to a device on VLAN via VPN

Hoi

Config is big help, but not enough. Explain what are you trying to achieve?
* trying to connect from outside? so from ether1-wan?
* connect to vpn server? where is the vpn server?
* access home network over vpn tunnel ending at vpn server?
by sebastia
Fri Mar 22, 2019 2:02 pm
Forum: General
Topic: Forward OpenVPN
Replies: 1
Views: 217

Re: Forward OpenVPN

Hey I'll need two elements: * dst-nat from router ip (+port) to sever ip (+port) * allow traffic in forward chain from ouside to linux server for that specific port The second step might be already there in form of default config: "accept dst-nat-ed traffic in forward" To verify that rules applies l...
by sebastia
Fri Mar 22, 2019 1:58 pm
Forum: General
Topic: Issues with routes with package/routing marks
Replies: 19
Views: 1091

Re: Issues with routes with package/routing marks

"Why does it work only by disabling the only route with the ISP1 mark?"
Please indicate which rule you're disabling.
by sebastia
Thu Mar 21, 2019 10:27 pm
Forum: General
Topic: Issues with routes with package/routing marks
Replies: 19
Views: 1091

Re: Issues with routes with package/routing marks

Just to check: you don't have VRF or routing rules do you? Assuming negative to above, the connections initiated from outside to inside will stick to original WAN interface. So the only question that remains is: how is the app talking to nvr and are in process of this conversation any new connection...
by sebastia
Thu Mar 21, 2019 5:33 pm
Forum: General
Topic: Issues with routes with package/routing marks
Replies: 19
Views: 1091

Re: Issues with routes with package/routing marks

What is the content of "Internal" list?
by sebastia
Thu Mar 21, 2019 1:03 pm
Forum: Scripting
Topic: how to mikrotik connect to linux
Replies: 1
Views: 352

Re: how to mikrotik connect to linux

Hello

Not sure what you want exactly: log forwarding? what is the link with http(s)?
by sebastia
Thu Mar 21, 2019 12:50 pm
Forum: Beginner Basics
Topic: Can't connect to web interface internal
Replies: 10
Views: 924

Re: Can't connect to web interface internal

Hey

You should start by connecting to it and exporting current config ("/export hide-sensitive compact") and post it here, between <code> tags.
by sebastia
Thu Mar 21, 2019 12:13 pm
Forum: General
Topic: Snort / Packet sniffing / NIDSing
Replies: 8
Views: 874

Re: Snort / Packet sniffing / NIDSing

Maybe a "race" condition on start-up. Try to adjust the scheduler with initial delay before sniffer start

:delay 5
/tool sniffer start
by sebastia
Thu Mar 21, 2019 12:24 am
Forum: General
Topic: QoS and Queue tree
Replies: 3
Views: 1288

Re: QoS and Queue tree

Configure tunnel with "dscp: inherit", use that to mangle / mark traffic and finally prioritise / shape
by sebastia
Wed Mar 20, 2019 11:19 am
Forum: Beginner Basics
Topic: mikrotik nat redirect to local from local
Replies: 2
Views: 363

Re: mikrotik nat redirect to local from local

Hey

Since you're changing port number on the external and internal ip's you'll need to do "hairpin" construction. see https://wiki.mikrotik.com/wiki/Hairpin_NAT or search on forlum.
by sebastia
Wed Mar 20, 2019 11:11 am
Forum: General
Topic: Snort / Packet sniffing / NIDSing
Replies: 8
Views: 874

Re: Snort / Packet sniffing / NIDSing

Hey When packet sniffer is used, Fast Path is suspended, so that should be the reason for lack of packets: "sniffer, torch and traffic generator is not running;" -> https://wiki.mikrotik.com/wiki/Manual:Fast_Path#IPv4_handler Fast path / track being enabled is just a flag / toggle: allow it or not. ...
by sebastia
Tue Mar 19, 2019 10:01 pm
Forum: General
Topic: LHG LTE Kit - Passthrough getting address but no internet with more WAN's
Replies: 8
Views: 928

Re: LHG LTE Kit - Passthrough getting address but no internet with more WAN's

I am using passthrough but with 6.42.12: there the dhcp is still handing out a /30 (or wider) and the problem doesn't occur. My config is almost default, with minimal mods: # mar/19/2019 20:27:48 by RouterOS 6.42.12 # model = RBSXTR /interface lte set [ find ] mac-address=AC:FF:FF:00:00:00 mtu=1500 ...
by sebastia
Tue Mar 19, 2019 9:22 pm
Forum: General
Topic: Issues with routes with package/routing marks
Replies: 19
Views: 1091

Re: Issues with routes with package/routing marks

Won't happen: you have only 3 connection marking rules. First two are for incoming from wan, last is this: add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-list="!Internal" in-interface-list=!VPNs new-connection-mark=ISP1_conn passthrough=yes src-address=192.168.10.0/2...
by sebastia
Tue Mar 19, 2019 9:58 am
Forum: General
Topic: LHG LTE Kit - Passthrough getting address but no internet with more WAN's
Replies: 8
Views: 928

Re: LHG LTE Kit - Passthrough getting address but no internet with more WAN's

Hey Thanks for the info. I'm in similar boat as: * lte client is on 6.42.12 * when I upgrade to 6.43+ on SXT LTE kit, after a while I'm no longer able to communicate over passthrough interface. Note: in 6.43 Mikrotik upgraded the pass-through interface to a point-to-point config, with /32 addresses,...
by sebastia
Mon Mar 18, 2019 11:42 pm
Forum: General
Topic: Issues with routes with package/routing marks
Replies: 19
Views: 1091

Re: Issues with routes with package/routing marks

Hey This were actually my suggestions on how to do mangling! Regarding the comments: # why the in-interface-list=!VPN? ---> Large story, it is not needed but it does not disturb if in-interface is matching that's all you need to know, there is no need for "!VPN", as I'm guessing wan1 / 2 are not par...
by sebastia
Sun Mar 17, 2019 10:50 pm
Forum: General
Topic: LHG LTE Kit - Passthrough getting address but no internet with more WAN's
Replies: 8
Views: 928

Re: LHG LTE Kit - Passthrough getting address but no internet with more WAN's

I might be in similar boat as you are. Your LTE is on ROS 6.43+ right? in case 1 (not working) when you ping the gateway (10.177.0.1) what do you see in your ARP table for that ip? In case 2 (working), I see 2 routes over ether3, what are their full details (/ip route print detail)? 0/0 -> 10.177.0....
by sebastia
Sat Mar 16, 2019 7:19 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 3720

Re: load-balancing don't work

scrolling is tiresome activity, agreed
by sebastia
Sat Mar 16, 2019 4:01 pm
Forum: Scripting
Topic: RB750Gr 3 Load Balancing Scripting
Replies: 10
Views: 955

Re: RB750Gr 3 Load Balancing Scripting

Of course I used it in the second context, but it's nice to learn of the first ! (the first was covered by first line already...)