Community discussions

MikroTik App

Search found 1547 matches

by cmit
Tue Aug 22, 2006 1:32 pm
Forum: General
Topic: reverse proxy?
Replies: 4
Views: 19463

To question 2):

Yes, MikroTik IS based on Linux.

The new web-proxy is developed from ground up by MikroTik, IIRC. But that has more or less nothing to do with the question if it's based on Linux?!

Best regards,
Christian Meis
by cmit
Tue Aug 22, 2006 1:29 pm
Forum: General
Topic: Who Broke It?
Replies: 21
Views: 4320

duh, how come you can post then? nothing has been down, new messages appear all the time.
The "was" in my message should have said enough - it's (of course) working now again ;-)

Best regards,
Christian Meis
by cmit
Tue Aug 22, 2006 1:28 pm
Forum: General
Topic: Disable webbox
Replies: 6
Views: 3738

I THINK he meant to activate HotSpot on the system, and modify the login page (which has not be a login page after all - it could just be a static page saying "Go away"). But I would not activate HotSpot just for that purpose - too many possibly undesired side-effects in my opinion... Best...
by cmit
Tue Aug 22, 2006 10:48 am
Forum: General
Topic: Who Broke It?
Replies: 21
Views: 4320

For me it was down since yesterday afternoon (CET)...

Best regards,
Christian Meis
by cmit
Mon Aug 21, 2006 5:25 pm
Forum: General
Topic: Bandwidth sharing (prioritising DNS)
Replies: 5
Views: 3307

You have to swap rules 3 and 4 in your mangle rules - the one putting packet-marks on all packets from a connection has to be last! This will only prioritize the DNS requests (i.e. outgoing DNS queries), as you are mangling/packet-markting according to DESTINATION port 53. So the counter behaviour y...
by cmit
Mon Aug 21, 2006 3:41 pm
Forum: General
Topic: Disable webbox
Replies: 6
Views: 3738

You could a) restrict access to the web interface (using the address range limitation of "/ip service" or the firewalling features) b) disable the www service (/ip service). Option b) doesn't hurt, you only cannot download the winbox.exe file from the router, if you would need it. With 2.9...
by cmit
Mon Aug 21, 2006 3:38 pm
Forum: Wireless Networking
Topic: 240km link , any suggestions?
Replies: 64
Views: 17481

Well, I have no practical experience with such long distance links (and regulations here in Germany do surely not permit the necessary EIRP ;) ), but in theory there should be no unsolvable problem. Not too long ago two guys made a 279 km WiFi link (see here: http://www.wilac.net/modules.php?op=modl...
by cmit
Mon Aug 21, 2006 2:34 pm
Forum: General
Topic: Bandwidth sharing (prioritising DNS)
Replies: 5
Views: 3307

For completeness, you should also mangle the TCP variant of DNS. Just add another mangle rule to write a connection-mark, and put it BEFORE the rule placing the final packet marks: So just add the following: / ip firewall mangle add chain=prerouting protocol=tcp dst-port=53 action=mark-connection \ ...
by cmit
Mon Aug 21, 2006 1:02 pm
Forum: General
Topic: Does such a device exist?
Replies: 3
Views: 1430

Very surely not native, i.e. in one device. As MikroTik still does not support any ADSL modem, the only way to achieve this would be to combine at least two separate devices into one case, i.e. an ADSL modem and a MikroTik system. But I think that's not what you are looking for... Best regards, Chri...
by cmit
Mon Aug 21, 2006 11:56 am
Forum: General
Topic: RouterOS 2.10 -> RouterOS3
Replies: 6
Views: 5018

As has been written here by MikroTik guys several times: The first public betas are planned for this autumn. You won't get anyone to name a release date right now. I personally wouldn't hold my breath for it... Example from the 2.9 development: The first beta came out in July 2004, the first relase ...
by cmit
Fri Aug 18, 2006 2:53 pm
Forum: General
Topic: slow link between pc and router
Replies: 5
Views: 1697

A colleague just had a similar problem. He was using the MAC-WinBox protocol (i.e. connecting not via ip address, bus via mac address to the RouterOS box). Using ip to connect solved all speed issues. I myself have run into issues from time to time with the MAC level protocols in RouterOS. As those ...
by cmit
Thu Aug 17, 2006 12:58 pm
Forum: General
Topic: Double-click required for all forum links?
Replies: 18
Views: 3853

And not only that - at least for the response time for the forum dropped dramatically. Something seems to have been speed up ;-)

Best regards,
Christian Meis
by cmit
Thu Aug 17, 2006 12:50 pm
Forum: General
Topic: Double-click required for all forum links?
Replies: 18
Views: 3853

Fine here, too!

Thanks, Normunds.

Best regards,
Christian Meis
by cmit
Wed Aug 16, 2006 10:14 pm
Forum: General
Topic: Double-click required for all forum links?
Replies: 18
Views: 3853

And I thought something was wrong with me ;-)

Christian
by cmit
Wed Aug 16, 2006 5:12 pm
Forum: General
Topic: Double-click required for all forum links?
Replies: 18
Views: 3853

Strange - but I have a spare mouse at hand, just in case the current one won't survive today because of this ;)

Best regards,
Christian Meis
by cmit
Wed Aug 16, 2006 4:04 pm
Forum: General
Topic: Block port's
Replies: 6
Views: 1830

Perhaps they were testing the parallel processing for the new dual-cpu support in 3.x? :D
If yes, MikroTik will have to rework the synchronisation part of that :lol:

Best regards,
Christian Meis
by cmit
Wed Aug 16, 2006 3:34 pm
Forum: General
Topic: Double-click required for all forum links?
Replies: 18
Views: 3853

Double-click required for all forum links?

Is it just me, or do you also experience this: I have to click every link/button TWICE in the forum for the page to reload or whatever I want to achieve. I do have this from several systems with different browsers. Is this some micros**t-ish "embedded confirmation dialog": Are you SURE you...
by cmit
Thu Aug 10, 2006 5:29 pm
Forum: Wireless Networking
Topic: NStreme question
Replies: 11
Views: 2556

It will work fine for a point-to-multi-point network (and is what NStreme was designed for, amongst other - to work around hidden station problem etc.). The only thing (rather obvious) to observe is that all your clients have to MikroTik, too (and be configured for NStreme)... Best regards, Christia...
by cmit
Thu Aug 10, 2006 4:23 pm
Forum: General
Topic: mikrotik newbie settings
Replies: 7
Views: 2527

You at least have to configure NAT/masquerading, like this: /ip firewall nat add chain=srcnat out-interface=wan action=masquerade . And you don't assign a DNS server to your clients, so I suppose you will have a hard time doing anything with name resolution - i.e. practically everything. Best regard...
by cmit
Wed Aug 09, 2006 10:11 pm
Forum: General
Topic: Not quite what we suspected...
Replies: 5
Views: 2111

ROTFL - that was a good one :lol:

Best regards,
Christian Meis
by cmit
Tue Aug 08, 2006 10:14 pm
Forum: General
Topic: DNS Problem
Replies: 9
Views: 2805

Are you REALLY sure you are still masquerading your outgoing DNS requests?

Best regards,
Christian Meis
by cmit
Mon Aug 07, 2006 2:44 pm
Forum: General
Topic: Tftp Server? (Help needed)
Replies: 9
Views: 2936

Double-no ...

Best regards,
Christian Meis
by cmit
Thu Aug 03, 2006 3:22 pm
Forum: General
Topic: simple routing ... need help
Replies: 17
Views: 4685

So now your Windows client (replacing the Cisco) must have a route to the subnet of client1 (or its' default route to the MikroTik)...

Best regards,
Christian Meis
by cmit
Thu Aug 03, 2006 2:51 pm
Forum: General
Topic: simple routing ... need help
Replies: 17
Views: 4685

Sorry, no Cisco guy ;) Have thrown out the last Cisco years ago.

But should be something like
ip route  192.168.10.0 255.255.255.252 192.168.10.253
or the like...

Don't you have a reference manual for the Cisco? :cry:

Best regards,
Christian Meis
by cmit
Thu Aug 03, 2006 2:40 pm
Forum: General
Topic: simple routing ... need help
Replies: 17
Views: 4685

You need to configure a route in the Cisco telling it to reach the subnet 192.168.10.0/30 over gateway 192.168.10.253!

Best regards,
Christian Meis
by cmit
Thu Aug 03, 2006 1:23 pm
Forum: General
Topic: simple routing ... need help
Replies: 17
Views: 4685

Then it probably is the missing route on the Cisco...

Best regards,
Christian Meis
by cmit
Thu Aug 03, 2006 1:12 pm
Forum: General
Topic: simple routing ... need help
Replies: 17
Views: 4685

Does the client have a default route to 192.168.10.2?

Does the Cisco also have a /30 netmask?

Best regards,
Christian Meis
by cmit
Thu Aug 03, 2006 10:23 am
Forum: General
Topic: 2 Nic's Cant Communicate Lan1 to Lan2
Replies: 1
Views: 1143

Without using additional "help" (like WINS server, LMHOSTS file), windows machines can only communicate in the same subnet. So you would have to bridge you two LAN interfaces and use one common address space, for example...

Best regards,
Christian Meis
by cmit
Tue Aug 01, 2006 9:16 pm
Forum: Wireless Networking
Topic: RSTP - path cost and root port question
Replies: 34
Views: 21150

Beware of the difference: The access list is used for an AP interface, controlling which clients you want to be able to connect (or to deny access). The connect list is used on a wireless client (!) interface to control to which APs you want to connect. So: An AP interface will not use the connect l...
by cmit
Tue Aug 01, 2006 10:42 am
Forum: General
Topic: Bridge Filter bug on Terminal
Replies: 7
Views: 1973

Aaah, now that sounds more like the old script-Eugene I know... :D

Best regards,
Christian Meis
by cmit
Thu Jul 27, 2006 11:36 am
Forum: General
Topic: PPPoE User Profile Change
Replies: 6
Views: 3236

I suppose he meant that changing (for example) the users' bandwidth assignment via changing the profile. But I agree with Sten that changing this on the fly would possible create to much trouble. And after all, switching profiles might mean that the users' ip address could change, which wouldn't wor...
by cmit
Wed Jul 26, 2006 4:01 pm
Forum: RouterBOARD hardware
Topic: Ethernet NIC ports and names changing?
Replies: 4
Views: 2188

Right now I don't have any RB532s left in the office, but installations at customer locations often do use ether2 for client connections, and those are the ports that are also labeled ether2 on the case...

Best regards,
Christian Meis
by cmit
Wed Jul 26, 2006 2:09 pm
Forum: RouterBOARD hardware
Topic: Ethernet NIC ports and names changing?
Replies: 4
Views: 2188

I personally have never seen such behaviour on a RouterBoard.
This can happen if you swap the physical network interfaces (like changing PCI nics), but this is hard on a RB532... ;)

Best regards,
Christian Meis
by cmit
Wed Jul 26, 2006 12:23 pm
Forum: Wireless Networking
Topic: tx/rx signal strength is -89 -92 (Please help )
Replies: 32
Views: 15153

Our director not allowed to use 5 or 10 ghz .In our country this frequency licenzed and most compnies using it.
He didn't write to use 5 or 10 Ghz frequencies, but 5 or 10 MHz channel bandwidth!

Best regards,
Christian Meis
by cmit
Wed Jul 26, 2006 12:08 pm
Forum: General
Topic: Identify download using port 80
Replies: 8
Views: 2458

I suppose what you want is to make long http downloads slower and "normal" websurfing (web browser) quick? As - like Normunds said - there's no technical difference between the two, the only thing you could do is use the bursting feature. Using that (you'll find several examples for it her...
by cmit
Tue Jul 25, 2006 9:23 am
Forum: General
Topic: internet disconnection
Replies: 10
Views: 2119

It's really frustrating... When you want someone to help you here (which most guys do in their SPARE TIME, for free and for fun!), you have to describe your problem in a sensible way so that someone not knowing what's inside your mind can understand it. Just telling "I'm using Ethernet" do...
by cmit
Mon Jul 24, 2006 3:11 pm
Forum: General
Topic: RADIUS: Max-Session-Time attribute not defined
Replies: 7
Views: 10837

Max-Session-Time is not what you are after if used alone. This attribute tells RouterOS how long one "login" may last, i.e. if the user is allowed to have at most 1 (continuous) hour being online. This does however not stop him from logging in again immediately. What you are after has to b...
by cmit
Wed Jul 12, 2006 9:10 am
Forum: General
Topic: Routing Problem, im new...
Replies: 10
Views: 2691

Ah - that was not really clear from your post.
What kind of wireless gear is between the boxes? Is this a routed or bridged wireless connection?

Best regards,
Christian Meis
by cmit
Tue Jul 11, 2006 10:34 pm
Forum: General
Topic: Routing Problem, im new...
Replies: 10
Views: 2691

That won't work out of the box. You cannot bridge a wireless station interface in RouterOS.
You have to use WDS for that. There are several examples on how to achieve a transparent bridge in RouterOS in the docs/wiki/forum.

Best regards,
Christian Meis
by cmit
Mon Jul 10, 2006 9:52 pm
Forum: RouterBOARD hardware
Topic: How to install OS on RB 532
Replies: 12
Views: 5363

Make sure that - the PC netinstall is running on and your router are on the same layer 2 network - netinstall has the "boot from net" option enabled (can't remember it's real name right now...) - the RB is configured to boot from LAN (first) I've had some strange problems sometimes with a ...
by cmit
Fri Jul 07, 2006 8:28 pm
Forum: Wireless Networking
Topic: Simple CPE - Station mode
Replies: 17
Views: 5607

Probabily , or probabily not ..... depend from answer .. you answer is not correct ( the first answer )
Just for completeness: Which answer is not correct?

Best regards,
Christian Meis
by cmit
Fri Jul 07, 2006 8:26 pm
Forum: Wireless Networking
Topic: Simple CPE - Station mode
Replies: 17
Views: 5607

Marco, I don't know how other vendors are doing it, but I know of some code to accomplish this under Linux. You have to do MAC-NAT, inspect (and change on the fly) ARP requests/answers etc. to get a "real" transparent bridge. @MikroTik: Perhaps MikroTik would want to take a look at this co...
by cmit
Fri Jul 07, 2006 8:22 pm
Forum: Wireless Networking
Topic: web proxy cache size is limited by memory size
Replies: 4
Views: 1491

Zong,

version 2.9 has a completely reworked hotspot, which is configured totally different than in version 2.8 etc.

Read the manual on this - I think it's explained quite good there.

Best regards,
Christian Meis
by cmit
Fri Jul 07, 2006 4:17 pm
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

Sleep well ;)

Best regards,
Christian Meis
by cmit
Fri Jul 07, 2006 3:38 pm
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

I see. It seems the order of your mangling rules is creating this problem. My examples always do it like this: - create a connection-mark for specific conditions (like protocol=tcp, dst-port=80 to mark a http-connection), with passthrough=yes - the next (!!) rule is the rule to mark all packets in t...
by cmit
Fri Jul 07, 2006 3:18 pm
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

You only should have passthrough=yes for the rules with action=mark-connection. Rules with action=mark-packet should have passthrough=no in your case!

Best regards,
Christian Meis
by cmit
Fri Jul 07, 2006 2:25 pm
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

Dmitry isn't actually marking packets in this example, but only creating connection-marks. Then it's right to have passthrough=no. In your example you will have to have passthrough=yes on the rules to mark connections, and passthrough=no on the rules that mark all packets belonging to a certain conn...
by cmit
Fri Jul 07, 2006 12:03 pm
Forum: Wireless Networking
Topic: Simple CPE - Station mode
Replies: 17
Views: 5607

I think that you don't understand question. And is not a protocol limitation , but a routeros limitation , other os work. (...) Now , the question in simple mode for you can understand better: I don't want to argue with you. Being rude to people here on the forum will probably not get you more answ...
by cmit
Fri Jul 07, 2006 9:43 am
Forum: General
Topic: Redirect Port 25 - > 2525 - easy ?
Replies: 11
Views: 5277

I'm not sure I understand what you want to achieve. If your want to dst-nat every outgoing SMTP connection so that just the dst-port is changed to 2525 (and the destination address is leaved unchanged), you would have to use 1 ;;; EMAIL chain=dstnat src-address=192.168.5.0/24 protocol=tcp dst-port=2...
by cmit
Fri Jul 07, 2006 8:57 am
Forum: General
Topic: Redirect Port 25 - > 2525 - easy ?
Replies: 11
Views: 5277

If you actually want all your clients' outgoing SMTP traffic to the server 64.151.x.x, your first dst-nat rule should read like this: 1 X ;;; EMAIL chain=dstnat src-address=192.168.5.0/24 protocol=tcp dst-port=25 action=dst-nat to-addresses=64.151.x.x to-ports=2525 (and then, of course, not disabled...
by cmit
Thu Jul 06, 2006 5:38 pm
Forum: Wireless Networking
Topic: Simple CPE - Station mode
Replies: 17
Views: 5607

Standard question, standard answer:

You can NOT bridge a wireless station (protocol limitation). Use WDS for that.
And PLEASE learn to use the search function of this forum - this question has been asked way too often already...

Best regards,
Christian Meis
by cmit
Thu Jul 06, 2006 9:16 am
Forum: Scripting
Topic: Wild Card DNS
Replies: 14
Views: 8761

Done ;)

Best regards,
Christian Meis
by cmit
Wed Jul 05, 2006 5:22 pm
Forum: General
Topic: Remote gateway and failover
Replies: 2
Views: 1439

"/tool netwatch" lets you ping ip address and execute scripts on up/down events...

Best regards,
Christian Meis
by cmit
Wed Jul 05, 2006 2:12 pm
Forum: Wireless Networking
Topic: d-link lan card
Replies: 17
Views: 4100

Then I'm out of ideas.

Do you perhaps have a chance to install the same card in another PC and try to run RouterOS there (just to see if it's recognized there)?

Best regards,
Christian Meis
by cmit
Wed Jul 05, 2006 9:36 am
Forum: The User Manager
Topic: USER MANAGER
Replies: 7
Views: 5708

And (if this hasn't changed in the very latest version) know that the user-manager can only be configured from the terminal/console, not via WinBox (until now).

Best regards,
Christian Meis
by cmit
Wed Jul 05, 2006 9:35 am
Forum: General
Topic: Redirect Port 25 - > 2525 - easy ?
Replies: 11
Views: 5277

As long as connection-tracking is enabled (which it is by default), there's usually no need to configure the "reverse route".

Perhaps post your complete ip address config, ip routing and nat config?

Best regards,
Christian Meis
by cmit
Wed Jul 05, 2006 9:33 am
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

Eugene: So I understand that the fact the a queue is a child of another queue will automatically only treat traffic that is falling into it's parents' queue? So marking traffic only as "HTTP" (opposed to marking it as "HTTP for client A") does not lead to problem here? Best regar...
by cmit
Tue Jul 04, 2006 11:32 pm
Forum: Wireless Networking
Topic: d-link lan card
Replies: 17
Views: 4100

And you do have the wireless package installed and enabled? ("/system package print")

Best regards,
Christian Meis
by cmit
Tue Jul 04, 2006 11:10 pm
Forum: Wireless Networking
Topic: d-link lan card
Replies: 17
Views: 4100

Sorry if this sound stupid, but did you check that you have a license including wireless and actually have the wireless package installed and enabled?

Best regards,
Christian Meis
by cmit
Tue Jul 04, 2006 11:06 pm
Forum: General
Topic: low priority or less bandwidth to big downloads¿?
Replies: 2
Views: 1026

You could implement something like this using the burst features of MikroTik queueing. With that could give a higher bandwidth for the first seconds of a HTTP connection (i.e. for browsing) and limit the bandwidth for longer HTTP connections (i.e. downloads). Read more in the docs here: http://www.m...
by cmit
Tue Jul 04, 2006 7:22 pm
Forum: Wireless Networking
Topic: d-link lan card
Replies: 17
Views: 4100

If it even doesn't show up in the PCI resources, you should look for things like

a) BIOS configuration
b) physical installation (is the card firmly in the PCI slot?)
c) defective card (have another one to try?)

Best regards,
Christian Meis
by cmit
Tue Jul 04, 2006 5:33 pm
Forum: Scripting
Topic: Free Hotspot user time limitation
Replies: 25
Views: 56112

You can configure the hotspot to allow the free trial users and assign a special profile for the trial (free) users (limiting to 5 kb, for example). If you configure "normal" hotspot users, those will of course be able to use your service without limitations (or only the limitation you imp...
by cmit
Tue Jul 04, 2006 4:39 pm
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

OK, now I got what you want to achieve... dumb me! I haven't tried this myself, but could imagine the following could work: Mark the packets as in my previous example, so that you have packet-marks on all packet for "client 1, HTTP", "client 1, DNS" etc. Then create a simple queu...
by cmit
Tue Jul 04, 2006 4:01 pm
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

Yes, it will. I wrote that and was under the impression that you want to achieve exactly what you get with this: packet-marks for every combination of source address and "protocol", to queue all those per user AND protocol.

Best regards,
Christian Meis
by cmit
Tue Jul 04, 2006 3:36 pm
Forum: Scripting
Topic: Free Hotspot user time limitation
Replies: 25
Views: 56112

The hotspot "trial user" feature of RouterOS does exactly this! See the MikroTik Hotspot docs: http://www.mikrotik.com/docs/ros/2.9/ip/hotspot . If you put "30m/1d" as value for the trial-uptime parameter and active (only) the trial login method, each user (which is identified by...
by cmit
Tue Jul 04, 2006 2:14 pm
Forum: General
Topic: Is it possable?
Replies: 23
Views: 4270

Something like that? (From memory, check syntax...) /ip firewall mangle add src-address=xxx.xxx.xxx.xxx/32 action=mark-packet new-packet-mark=from_xxxx passthrough=yes add packet-mark=from_xxxx protocol=tcp dst-port=80 action=mark-connection new-connection-mark=http-conn-from-xxxx passthrough=yes ad...
by cmit
Tue Jul 04, 2006 9:43 am
Forum: General
Topic: urgent help needed ... QoS questions
Replies: 25
Views: 4678

Sorry, I did not really read all of your rules completely - my bad. You should create a connection-mark based on some "protocol identifiers", like "TCP, dst-port 110". The rule after that should create the packet-mark, but just based on the fact if that packet belongs to a marked...
by cmit
Tue Jul 04, 2006 9:23 am
Forum: Wireless Networking
Topic: d-link lan card
Replies: 17
Views: 4100

I have never used D-Link cards myself.
The D-Link website only has a "DWL-G520" no "DWL-520". That DWL-G520 should be Atheros, but I seem to remember that someone on the forum also had problems using this card - use the search function...

Best regards,
Christian Meis
by cmit
Tue Jul 04, 2006 9:17 am
Forum: General
Topic: urgent help needed ... QoS questions
Replies: 25
Views: 4678

Every rule where you set a packet-mark should have its' passthrough set to no in your example. So packets already marked do not pass the mangle rules further down. You passthrough=yes makes every packet traverse the following mangle rules also, and every packets is (again) matched by the last rule, ...
by cmit
Tue Jul 04, 2006 9:12 am
Forum: General
Topic: urgent help needed ... QoS questions
Replies: 25
Views: 4678

Just create a last (position is important!) mangle rule to mark all packets with a packet-mark of "the_rest" for example. Then every packet that's not already mangled before (take care of your passthrough=yes/no settings!) will get marked with "the_rest". You then can queue those...
by cmit
Tue Jul 04, 2006 8:47 am
Forum: General
Topic: urgent help needed ... QoS questions
Replies: 25
Views: 4678

Hmmm, your decision... :D

Best regards,
Christian Meis
by cmit
Tue Jul 04, 2006 8:35 am
Forum: Wireless Networking
Topic: d-link lan card
Replies: 17
Views: 4100

What kind of D-Link cards?
Are they on the list of supported hardware on the MikroTik website?

What does "/system resource pci print" say?

Best regards,
Christian Meis
by cmit
Tue Jul 04, 2006 8:28 am
Forum: General
Topic: urgent help needed ... QoS questions
Replies: 25
Views: 4678

cylent, your first mangle rule should have passthrough set to "yes", otherwise no packets will get a http packet mark, so nothing can be possibly queued furtheron. So it should read 0 chain=prerouting protocol=tcp dst-port=80 action=mark-connection new-connection-mark=http-con passthrough=...
by cmit
Mon Jul 03, 2006 1:19 pm
Forum: General
Topic: get through to home system from work
Replies: 10
Views: 2076

That might very well be the case...

The layer 2 approach will only work if you're on the same physical network segment with your router (i.e. "at home") - sorry for that confusion...

Best regards,
Christian Meis
by cmit
Mon Jul 03, 2006 11:20 am
Forum: General
Topic: get through to home system from work
Replies: 10
Views: 2076

Have you disabled telnet/ssh in "/ip services", by any chance?
Or does a firewall rule reject those connections?

Tried to do a layer 2 (MAC-telnet/MAC-WinBox) connection?

Best regards,
Christian Meis
by cmit
Mon Jul 03, 2006 11:17 am
Forum: General
Topic: RB230 verses RB532
Replies: 12
Views: 2627

Hi Allesio, sorry, but I REALLY cannot imagine that this is correct. I read the page you quoted (in broken-Google-english ;) ), and it really references this Gateworks product. But this REALLY is based on a XScale CPU, and I am very sure that there is NO XScale version of MikroTik. Perhaps someone f...
by cmit
Mon Jul 03, 2006 10:19 am
Forum: General
Topic: get through to home system from work
Replies: 10
Views: 2076

Really, I think WinBox encryption should be good enough, but anyway: Let's take PuTTY as SSH client in this example. Open PuTTY, enter the destination address (your RouterOS ip address), but do NOT click the "Open" button to connect yet. In the left options tree go to "Connection => S...
by cmit
Sat Jul 01, 2006 5:45 pm
Forum: General
Topic: Need some guidance in Mikrotik configuration
Replies: 4
Views: 1830

Hi Michael, you can create bandwidth limits quite simple for PPTP connections. Every PPTP client is assigned to a PPP profile, where you can configure simple rate limiting options. (PPP profiles docs see here: http://www.mikrotik.com/docs/ros/2.9/guide/aaa_ppp.content#13.4.2.1 , see parameter "...
by cmit
Fri Jun 30, 2006 11:08 pm
Forum: General
Topic: RB + VOIP
Replies: 8
Views: 3065

Be careful - SIP and H.323 are two different protocols.

I don't know of any cards that could be plugged into a RB500 and are supported by RouterOS.

Best regards,
Christian Meis
by cmit
Fri Jun 30, 2006 11:07 pm
Forum: Wireless Networking
Topic: other bands supported?
Replies: 6
Views: 1849

Hi Peter, you might want to invest some time using the search function for this forum. There is plenty of content on this topic. WiMax support is planned for some future release, but nothing really decided yet, if I read MikroTik correcty. The 900 MHz cards from Ubiquiti are supported. The Ubiquiti ...
by cmit
Fri Jun 30, 2006 11:04 pm
Forum: Wireless Networking
Topic: how to configure MT for 2 wireless Networks in same place
Replies: 1
Views: 941

If you want to connect to two different wireless networks at the same time, you will need two wireless interfaces in your client...

Best regards,
Christian Meis
by cmit
Fri Jun 30, 2006 4:59 pm
Forum: General
Topic: RB230 verses RB532
Replies: 12
Views: 2627

Those are based on XScale CPUs, which are not currently supported by MikroTik. And every question if those will be supported, was a clear "no" so far...

Best regards,
Christian Meis
by cmit
Fri Jun 30, 2006 11:47 am
Forum: Scripting
Topic: Wild Card DNS
Replies: 14
Views: 8761

Not yet...

Christian
by cmit
Fri Jun 30, 2006 9:42 am
Forum: Scripting
Topic: Wild Card DNS
Replies: 14
Views: 8761

I would say just returning a VERY low TTL (like only a few seconds max) should make this a non-issue. At least, if the clients implementation isn't broken. Clients not correctly interpreting the TTL value (and forgetting the cache entry after that few seconds in our case) could run into problems. Bu...
by cmit
Fri Jun 30, 2006 9:36 am
Forum: General
Topic: Redirect Port 25 - > 2525 - easy ?
Replies: 11
Views: 5277

Action "redirect" always redirects to the local router itself - you have to use action "dst-nat" for that...

Please read the manual ;) ...

Best regards,
Christian Meis
by cmit
Thu Jun 29, 2006 5:19 pm
Forum: Wireless Networking
Topic: AP isolation
Replies: 5
Views: 12057

Set "default-forwarding=no" on your wireless interface...

Best regards,
Christian Meis
by cmit
Thu Jun 29, 2006 3:40 pm
Forum: Scripting
Topic: Wild Card DNS
Replies: 14
Views: 8761

Hi GJS,

I have thrown together a small but effective (still experimental ;) ) Windows executable that does just this - works as a DNS server and returns the same ip address for all A queries.

If interested, contact me offline (info at cmit dot de)...

Best regards,
Christian Meis
by cmit
Thu Jun 29, 2006 3:24 pm
Forum: General
Topic: EoIP - how do i set it up
Replies: 5
Views: 1921

Your description of your first EoIP tunnel try reads good - create EoIP interfaces with the ip address of the adjacent wireless interface as then "remote-address". Then bridge The EoIP interface on each system with the ethernet interface, and you should be set. Things to watch out for: - G...
by cmit
Thu Jun 29, 2006 2:40 pm
Forum: General
Topic: EoIP - how do i set it up
Replies: 5
Views: 1921

Look here: http://wiki.mikrotik.com/wiki/Transpare ... o_Networks for a how-to (using WDS, not EoIP).

If you really want EoIP - that's not too hard, too, but has a bit more performance overhead than WDS.

Best regards,
Christian Meis
by cmit
Wed Jun 28, 2006 4:18 pm
Forum: General
Topic: Connection tracking and packet fragmentation
Replies: 7
Views: 4677

Hi Sten - yep - I was thinking of our chat about this when I finally made out the reason (disabled conn-track)...

Does work with conn-track on though, so ... :roll:

Best regards,
Christian Meis
by cmit
Tue Jun 27, 2006 4:47 pm
Forum: General
Topic: Connection tracking and packet fragmentation
Replies: 7
Views: 4677

Yep - and that makes any mangle rule with connection-marks behave, well, let's say.... strange ;)

Best regards,
Christian Meis
by cmit
Tue Jun 27, 2006 2:54 pm
Forum: General
Topic: Connection tracking and packet fragmentation
Replies: 7
Views: 4677

Hmmm, just stumbled across this when trying to introduce some basic traffic shaping/priorities on a bridge just filtering out NetBIOS and some other protocols until now. Somewhen I must have disabled connection-tracking on that system, and was wondering why the mangle rules (using connection-marks) ...
by cmit
Mon Jun 26, 2006 11:27 pm
Forum: General
Topic: systen halted dont work
Replies: 2
Views: 983

What "server" do you restart? Your MikroTik? Or something else?

Best regards,
Christian Meis
by cmit
Thu Jun 22, 2006 4:14 pm
Forum: Wireless Networking
Topic: RB500 AP slows down on load ....
Replies: 5
Views: 1822

Could very well be interference then... Can you try to use another frequency?

What other wireless activities does a site survey/scan show you?
What is your CCQ/noise level?

Best regards,
Christian Meis
by cmit
Thu Jun 22, 2006 1:55 pm
Forum: Wireless Networking
Topic: 60mbit Over 9km
Replies: 33
Views: 8487

As the CCQ is a measurement of your network connection/signal quality, you would have to improve your signal quality. How to do that depends on the situation: - change frequencies to avoid interference - better/shorter cables - better antennas - using only lower data-rates on the radios, like only u...
by cmit
Thu Jun 22, 2006 1:53 pm
Forum: General
Topic: Winbox doesn't see Mikrotiks when I have two NIC's...
Replies: 4
Views: 1305

Surely not ;-)

But I cannot answer details to this question - this would be left to MikroTik. For the moment it seems to be a fact that you may only have one interface active when using MAC level connections to your RouterOS devices.

Best regards,
Christian Meis
by cmit
Thu Jun 22, 2006 1:16 pm
Forum: General
Topic: Winbox doesn't see Mikrotiks when I have two NIC's...
Replies: 4
Views: 1305

My experience is this: Any MAC-level protocol (MAC-WinBox, MAC-Telnet) does only work if you have only ONE (active) network interface on the machine WinBox is running on. Connections to a router using an IP address (of course) always work. I suppose this has to do with the fact that the MAC-level pr...
by cmit
Thu Jun 22, 2006 10:52 am
Forum: General
Topic: Installing MikroTik into Embedded Disk Card
Replies: 2
Views: 862

Yeah - sure. No problem, just install the same way as to a regular hard disk. We have lots of systems running on IDE-DOMs (the same thing), and you can even purchase those directly from MikroTik with the software already installed...

Best regards,
Christian Meis
by cmit
Wed Jun 21, 2006 8:46 pm
Forum: The User Manager
Topic: Mikrotik User Manager
Replies: 41
Views: 25450

Is the http service active under "/ip services"?

Best regards,
Christian Meis
by cmit
Wed Jun 21, 2006 5:57 pm
Forum: Scripting
Topic: Error sending e-mail invalide from address
Replies: 8
Views: 3500

Bump...

Just stumbled across that in a customer situation again, too.

Any chance to get this added soon? Can't be too hard...

Best regards,
Christian Meis
by cmit
Tue Jun 20, 2006 1:04 pm
Forum: General
Topic: Bridge problem in all versions since 2.9.10
Replies: 14
Views: 4765

Uldis,
can you describe what the problem actually is, please?

Best regards,
Christian Meis
by cmit
Tue Jun 20, 2006 12:04 pm
Forum: General
Topic: Bridge problem in all versions since 2.9.10
Replies: 14
Views: 4765

What does lead you to the suspicion that this is caused by the BRIDGE code?

Best regards,
Christian Meis
by cmit
Tue Jun 20, 2006 9:32 am
Forum: General
Topic: Bridge problem in all versions since 2.9.10
Replies: 14
Views: 4765

Could you be more specific and explain what problem you are seeing, your config, ...?

Best regards,
Christian Meis
by cmit
Tue Jun 20, 2006 8:40 am
Forum: General
Topic: Offtopic: Problem with mikrotik accounting server?
Replies: 5
Views: 1475

Paid your bills? :D
Sorry, couldn't resist...

Best regards,
Christian Meis
by cmit
Tue Jun 20, 2006 8:26 am
Forum: General
Topic: Offtopic: Problem with mikrotik accounting server?
Replies: 5
Views: 1475

It works for me...

Best regards,
Christian Meis
by cmit
Mon Jun 19, 2006 11:05 pm
Forum: General
Topic: Mikrotik PC router with 4 wireless cards ...
Replies: 2
Views: 1105

Why are you putting the wlan interfaces into bridges? Or is there some other interface in each bridge (like an Ethernet interface) which you just didn't mention? Apart from that you have to give us more detailed information on how you have configured things. For example: Wireless AP config (why shou...
by cmit
Mon Jun 19, 2006 8:23 pm
Forum: General
Topic: get through to home system from work
Replies: 10
Views: 2076

Port 80 isn't needed anymore for a WinBox connection. You just would have to enable it to download the Winbox.exe itself. And if you feel WinBox communication with the RouterOS machine isn't secure enough and you like SSH, you can always tunnel your WinBox connection over a SSH connection :D ... Bes...
by cmit
Sun Jun 18, 2006 11:48 am
Forum: General
Topic: portwell lcd
Replies: 19
Views: 6074

Hei Lee - that did the trick, thanks a lot! ;-)

RouterOS is booting now. Never did try disabling USB, because I was working on the local console via a (necessarily) USB keyboard and installing from an USB CD-ROM drive...

So piwi- go ahead and buy them ;-)

Christian
by cmit
Tue Jun 13, 2006 4:57 pm
Forum: General
Topic: portwell lcd
Replies: 19
Views: 6074

Hei piwi3910, we are using several different Portwell systems successfully too. But one model - the NAR5060 - simply refuses to boot MikroTik. I can run about every other OS I can think of, but MikroTik simply does NOT boot. No matter if I use a IDE-DOM or the onboard CF slot. Do you happen to have ...
by cmit
Tue Jun 13, 2006 10:49 am
Forum: General
Topic: Uplink down won't allow redirection to hotspot login.html
Replies: 6
Views: 1688

Unfortunately I don't think you can get RouterOS to do this. Having to place a separate box at each location would be the cost of it, but clearly the only way, as it has to be available when you're offline. On the other hand something like a RB230/RB500/LinkSys WRT54G whatever would probably suffice...
by cmit
Tue Jun 13, 2006 10:03 am
Forum: General
Topic: Uplink down won't allow redirection to hotspot login.html
Replies: 6
Views: 1688

I once was tempted to try the following (but never actually did): You COULD run a local DNS server that answers EVERY request with a dedicated ip address, may be the one of your hotspot. I'm quite sure it shouldn't be to hard to get this part running. Then the script detecting your uplink is down an...
by cmit
Mon Jun 12, 2006 11:00 am
Forum: General
Topic: Routing-Test
Replies: 148
Views: 38785

No offense intended. I myself did something similar using the chat room several times ;)

Christian Meis
by cmit
Mon Jun 12, 2006 10:47 am
Forum: Wireless Networking
Topic: Best setup for long distance P2P links
Replies: 13
Views: 7480

That shouldn't matter in any way. As long as your routing config is good, it can be whereever you want it to...

Best regards,
Christian Meis
by cmit
Mon Jun 12, 2006 10:43 am
Forum: Scripting
Topic: Serial watchdog
Replies: 2
Views: 1524

Unfortunately not, I think.

I would, too, really love to ability to send text to a serial port (from a script)....

Best regards,
Christian Meis
by cmit
Mon Jun 12, 2006 10:41 am
Forum: General
Topic: Shaping with more connections
Replies: 10
Views: 2653

The queue types names are all "http" here (copy and paste ;) ) - beware to adjust them to rdp/smtp/http respectively...

Best regards,
Christian Meis
by cmit
Mon Jun 12, 2006 10:37 am
Forum: General
Topic: Routing-Test
Replies: 148
Views: 38785

Interesting way to do e-mail communicaton :D
SCNR

Christian Meis
by cmit
Mon Jun 12, 2006 10:17 am
Forum: General
Topic: HELP!: pppoe 738: the server did not assign an ip address
Replies: 4
Views: 3156

If you don't have anything in "remote address", the router (PPPoE server) doesn't know what ip address(es) to hand out to connecting clients. So the error message is perfectly legitimate and that definitely was the cause of your problem. What led to this change (that remote address was emp...
by cmit
Fri Jun 09, 2006 1:51 pm
Forum: RouterBOARD hardware
Topic: experience
Replies: 11
Views: 4386

200W? Do you grill your sheep with that? :D

Christian
by cmit
Fri Jun 09, 2006 1:51 pm
Forum: RouterBOARD hardware
Topic: experience
Replies: 11
Views: 4386

4w's for 2.4
Humph!
200w for 5.725 to 5.825 PtP
Aaargh!

:)

Best regards,
Christian Meis
by cmit
Fri Jun 09, 2006 1:47 pm
Forum: General
Topic: load balancing for my dual adsl
Replies: 124
Views: 34872

It's not very difficult to bind outgoing HTTPS traffic to a specific WAN port: mangle it, policy-route it...

Best regards,
Christian Meis
by cmit
Fri Jun 09, 2006 11:53 am
Forum: General
Topic: load balancing for my dual adsl
Replies: 124
Views: 34872

OK, let me try to get this done from some short notes - don't have access to the system my tests are on :( ... My script worked by assigning every user to a dedicated uplink (that was required by the customer). This way you will absolutely be sure that the user will go out with the same source ip ad...
by cmit
Fri Jun 09, 2006 10:05 am
Forum: General
Topic: Ping works, telnet, winbox, webbox don´t
Replies: 3
Views: 2160

I had similar things on two boxes running 2.7.x back then sometimes ;) This symptom only appeared after roughly about 200 day of uptime and was also solved by a reboot. Haven't seen it since then on any of my boxes. I SUSPECT a memory leak was the culprit back then, but can't confirm of course... Be...
by cmit
Fri Jun 09, 2006 9:54 am
Forum: General
Topic: load balancing for my dual adsl
Replies: 124
Views: 34872

If one of the link goes down does it mean that some traffic won`t be routed at all. I surely hope to find the time to dig out and polish up my example. But in the mean time: It was working practically the same way (by adding new src-addresses to address-lists, but with a lower address-list-timeout)...
by cmit
Thu Jun 08, 2006 6:40 pm
Forum: General
Topic: load balancing for my dual adsl
Replies: 124
Views: 34872

The problem with the setup discussed here is (could be) the following, if I'm not completely wrong: For "normal" internet usage this will work. But it WILL eventually send out connections from the SAME user over DIFFERENT uplinks. If you are now using a web application (like online banking...
by cmit
Thu Jun 08, 2006 5:21 pm
Forum: Wireless Networking
Topic: problem linking 2 rb 112 whit atheros Atheros 5213
Replies: 24
Views: 4193

Have you thought of the "usual suspects"? I.e. if you are connected to the router via an interface (an its' ip address) and put that interface into a bridge, it's NORMAL to loose ip connectivity (shortly), because a) the MAC address for that ip might change and b) the bridge will put inter...
by cmit
Thu Jun 08, 2006 1:45 pm
Forum: General
Topic: Version 2.9.25 out
Replies: 28
Views: 5891

As you are advised to configure it via console (just not via WinBox) I'd say it's obvious that the announced problem is not with BPG itself, but with the WinBox interface...

Best regards,
Christian Meis
by cmit
Fri Jun 02, 2006 1:26 pm
Forum: General
Topic: Ubiquiti SR9 support
Replies: 49
Views: 25460

No, that was a "2.10", so the next major release...

Best regards,
Christian Meis
by cmit
Tue May 16, 2006 11:52 pm
Forum: General
Topic: DHCP Clients only allowed to open permitted pages
Replies: 6
Views: 2191

And if your names resolve to changing ip addresses (like dyndns names), or belong to big websites (server clusters/load balancers/content delivery networks/... with multiple ip addresses) then you do have a problem... You HAVE to use ip addresses to configure firewall rules. So depending on what you...
by cmit
Tue May 16, 2006 10:15 pm
Forum: General
Topic: hotspot blocks msn, skype and others??
Replies: 16
Views: 2966

:D ... Perhaps someday... ;)

Best regards,
Christian Meis
by cmit
Tue May 16, 2006 10:06 pm
Forum: General
Topic: hotspot blocks msn, skype and others??
Replies: 16
Views: 2966

Do you want a beer and dinner with that as well? A whole section in the manuals, dedicated *just* to this... If I would pretend not to know about masquerading - would I qualify for another beer (and the dinner), too? :D Oh my, I fear the travel costs to Cape Town could ruin that good deal... :P Bes...
by cmit
Tue May 16, 2006 8:44 pm
Forum: Wireless Networking
Topic: ap-bridge mode
Replies: 6
Views: 1946

It's more because MikroTik doesn't really care about developing Prism/Hermes support very much these days. The focus clearly is on Atheros based cards. And if you look around here in the forum you'll find that MOST people do you Atheros based cards nowadays. Not meaning to comment on the quality of ...
by cmit
Tue May 16, 2006 8:39 pm
Forum: General
Topic: hotspot blocks msn, skype and others??
Replies: 16
Views: 2966

The "ip services" menu does only affect which services run ON your RouterOS device (i.e. if you can telnet TO your router, or if you can access the web interface (HTTP)). It has nothing to do with traffic going through the router. As you haven't given any config information, it's hard to h...
by cmit
Tue May 16, 2006 3:09 pm
Forum: The User Manager
Topic: User Manager
Replies: 19
Views: 9790

I'd say that's sensible. From the RADIUS servers' point of view, the routers' request are coming from localhost (127.0.0.1), and from the routers' point of view he can reach the RADIUS server on localhost. So that's perfectly sensible (and does indeed work, as you already noted). Best regards, Chris...
by cmit
Tue May 16, 2006 11:10 am
Forum: Wireless Networking
Topic: 802.11i / WPA2
Replies: 8
Views: 2207

Ehm, WPA2 (PSK) with TKIP and/or AES-CCM is available for quite some time now... What exactly do you miss?

Best regards,
Christian Meis
by cmit
Mon May 15, 2006 10:31 pm
Forum: Wireless Networking
Topic: poll: u.fl vs. mmcx for sr2, sr5 and soldering
Replies: 28
Views: 9935

This is RadioMobile (freeware):
http://www.cplus.org/rmw/english1.html

Best regards,
Christian Meis
by cmit
Mon May 15, 2006 1:22 pm
Forum: The User Manager
Topic: Report for just one user?
Replies: 2
Views: 2367

I think the things needed by many people would be a report where you select the user and then get a report on all "financial" transactions (like credit added etc.) and another one as usage report (include all sessions for that user).

Best regards,
Christian Meis
by cmit
Sun May 14, 2006 10:29 pm
Forum: General
Topic: /system reset improvements
Replies: 20
Views: 7451

Nice one, Sam.

Wouldn't have been to hard for MikroTik to point out this feature - I (and several others) have asked for that for a long time, and always only got answers like "maybe later"... :(

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 5:57 pm
Forum: General
Topic: MT installation parallel with other Linux installation
Replies: 5
Views: 1691

No, not easily. MikroTik will take over the whole harddisk at installation time. You could probably get something going on a system where you can hide/unhide complete harddrives, but ... Or you could run MikroTik in a virtual machine. VMware does work - read the forums, there are some reports on thi...
by cmit
Fri May 12, 2006 5:07 pm
Forum: General
Topic: Guide to Mikrotik + Freeradius for PPP*
Replies: 5
Views: 1847

Nice! Looks quite complete for a basic config if you ask me.

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 3:59 pm
Forum: Wireless Networking
Topic: Authenticate with user/pass by wireless conexion in a radius
Replies: 11
Views: 4906

What exactly do you want to authenticate? The Windows logon? I don't get it, I suppose. I thought you wanted the laptops to connect to the AP, and the be able to log on "for internet usage" using their Active Directory username/password? If yes, they should enter those credentials into the...
by cmit
Fri May 12, 2006 3:53 pm
Forum: General
Topic: 2 EOIP tunnels using single gateway
Replies: 3
Views: 1174

We ended up terminating each connection with a dedicated router and the work with routing to those (using a transfer ip net) in a similar situation.

Not very elegant...

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 3:51 pm
Forum: The User Manager
Topic: Logging of user-manager activity?
Replies: 1
Views: 2235

OK, forget that one.

The debug messages for the user-manager just started to show up in the log correctly. Somehow my SSH session that was open in parallel with a "/log print follow" didn't show them - I only saw them in WinBox on another screen...

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 3:49 pm
Forum: The User Manager
Topic: Report for just one user?
Replies: 2
Views: 2367

Report for just one user?

Can you change the reporting feature so that you can select a user and have to report just include this user?

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 3:47 pm
Forum: The User Manager
Topic: Accounting data management
Replies: 1
Views: 2776

Accounting data management

How does the user-manager treat accounting data? Is it purged after a certain time, can we configure that time, can we manually delete acct data older than X, ...?

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 3:46 pm
Forum: The User Manager
Topic: Logging of user-manager activity?
Replies: 1
Views: 2235

Logging of user-manager activity?

Is the system logging topic "manager" the right one to create log rules for usage of the user-manager?
I created a rule with topic "manager,debug", but only get some sparse log entries for "system,info" when adding a new user, for example.

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 3:39 pm
Forum: The User Manager
Topic: Inaccurate time accounting?
Replies: 2
Views: 2815

Inaccurate time accounting?

I configured a user with a prepaid time of 2 hours. Used that to authenticate a SSH login to the RouterOS machine. After finishing a short session (duration 48s, displayed correctly) I'm displayed a remaining time of "1h:58m:57s" ???

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 3:23 pm
Forum: General
Topic: 2 EOIP tunnels using single gateway
Replies: 3
Views: 1174

I fear that's not possible. As RouterOS always want the route (and that includes the default route) to be configured by entering the next hops' ip address, this won't work (as the gateway is the same on both uplinks). This WOULD work, if you could configure an interface based default route like Linu...
by cmit
Fri May 12, 2006 3:16 pm
Forum: The User Manager
Topic: Small GUI bug
Replies: 1
Views: 2444

Small GUI bug

When extending the time for a user in the users list (not the detail view), the prepaid time is not refreshed and still shows the old value. You have to reload the page yourself to see the new values (by reloading, sorting by another column or the like).

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 2:43 pm
Forum: Wireless Networking
Topic: Authenticate with user/pass by wireless conexion in a radius
Replies: 11
Views: 4906

If I don't misunderstand you intentions, you could run a HotSpot on the MikroTik AP configured to authenticate via FreeRadius. Then set FreeRadius to authenticate the users against the Active Directory (which should be possible, but I haven't tried or even made sure that it can do that. But some RAD...
by cmit
Fri May 12, 2006 2:37 pm
Forum: General
Topic: /system reset improvements
Replies: 20
Views: 7451

Well, of course.

But I think that should be our responsibility. If you REALLY f**k up that way, you (or I ;) ) will have to reinstall via netinstall.

But having the feature would definitely be a good thing!

Best regards,
Christian Meis
by cmit
Fri May 12, 2006 2:30 pm
Forum: General
Topic: /system reset improvements
Replies: 20
Views: 7451

Actually this does NOT solve the issue, which is a feature request I mention for (probably) years now ;-). It would be VERY (VERY VERY) handy to be able to put a script file on the router that will be executed exactly once after a "system reset". That way we could put either a "factor...
by cmit
Thu May 11, 2006 11:14 pm
Forum: The User Manager
Topic: userman not working?
Replies: 7
Views: 6122

Search the forums. There's a description of the command to add user accounts to access the user manager (sorry, don't have it off hand). The user accounts used to authenticate are NOT the normal RouterOS accounts. And there are no default accounts, you have to CREATE at least one first! Best regards...
by cmit
Wed May 10, 2006 5:40 pm
Forum: Wireless Networking
Topic: RADIUS *ugh*
Replies: 23
Views: 3794

Well, I can assure you that RADIUS integration is working quite well (and several other forum users will probably state the same). This most probably is some problem with routing, firewalling or the like prohibiting communication between your MikroTik and the RADIUS server. Best regards, Christian M...
by cmit
Wed May 10, 2006 1:10 pm
Forum: General
Topic: Feature Request (improvement)
Replies: 11
Views: 4970

You already have a log entry in the clients' log stating "unclean reboot because of power failure" or something along that lines if it was a un-clean shutdown. You could just look into the log of the client (which you probably can arrange access to)...

Best regards,
Christian Meis
by cmit
Tue May 09, 2006 3:35 pm
Forum: General
Topic: read log
Replies: 5
Views: 1428

time is in seconds, octets = bytes

Best regards,
Christian Meis
by cmit
Tue May 09, 2006 1:57 pm
Forum: General
Topic: read log
Replies: 5
Views: 1428

I'd say the last two are more the number of packets?

Best regards,
Christian Meis
by cmit
Tue May 09, 2006 9:23 am
Forum: General
Topic: Radio Ticks
Replies: 4
Views: 1505

That's probably the countdown-timer for your warranty time :D ... Just kidding, but I haven't ever heard a radio card make any kind of noise (although I haven't put my ear near a 400 mW card...). Are you sure it's from the card itself? Does it do this only when there's traffic, or also when it's idl...
by cmit
Thu May 04, 2006 8:55 pm
Forum: General
Topic: HTTP DST NAT
Replies: 3
Views: 1292

Why not just use the "real" hotspot feature of MikroTik for this? There's no need to actually have user accounts etc. - you could also just display the "login" page as a welcome page and have a button "go on" there (which would log the user in without further interactio...
by cmit
Wed May 03, 2006 11:31 pm
Forum: Wireless Networking
Topic: RouterOS work width Ubiquiti SR9 (900 mhz)
Replies: 2
Views: 1205

MikroTik states that it works:
http://forum.mikrotik.com//viewtopic.php?t=7007...

That enough? ;)

Best regards,
Christian Meis
by cmit
Wed May 03, 2006 11:24 pm
Forum: Wireless Networking
Topic: Packet forwarding (like AP 2000)
Replies: 5
Views: 1450

I tend to agree with Wildbill...

Best regards,
Christian Meis
by cmit
Wed May 03, 2006 6:37 pm
Forum: Wireless Networking
Topic: Packet forwarding (like AP 2000)
Replies: 5
Views: 1450

Perhaps if you could tell me how the AP 2000 does it, or what is so special that you want to achieve? I don't know the AP2000.

Or someone else can help?

Best regards,
Christian Meis
by cmit
Wed May 03, 2006 2:27 pm
Forum: General
Topic: NAT не про
Replies: 5
Views: 2073

Well, I can think that your post will probably have something to do with destination NAT. But if you would post in English, you probably would get more help ;)

Best regards,
Christian Meis
by cmit
Wed May 03, 2006 9:40 am
Forum: Scripting
Topic: how to make a profile for users that did not pay´d the bill?
Replies: 18
Views: 6184

Correct me if I'm wrong, but you give out ip addresses from the 10.10.3.0/24 pool to disconnected users, and your dst-nat rule is looking for ip addresses from 10.10.2.0/24.... ;)

Best regards,
Christian Meis
by cmit
Wed May 03, 2006 9:19 am
Forum: General
Topic: MUM: USA
Replies: 68
Views: 14739

"Me too"... :(


Best regards,
Christian Meis
by cmit
Tue May 02, 2006 6:38 pm
Forum: Wireless Networking
Topic: CPE-Antenna alignment via customer / Application available?
Replies: 149
Views: 42997

So, anyone who has not contacted me via e-mail (Arco, Mike, Nuru, Dibatech?) just drop me a line at info at cmit dot de.

All others should have their eval version in their mailboxes...

Best regards,
Christian Meis
by cmit
Fri Apr 28, 2006 10:40 am
Forum: Scripting
Topic: how to make a profile for users that did not pay´d the bill?
Replies: 18
Views: 6184

You webserver at 10.10.10.3 will get the HTTP requests as the clients sent them. I.e. it will be queried for webpages like http://www.yahoo.com, http://www.microsoft.com, http://www.you-name-it.net. Is your webserver config prepared to handle that? (I.e. IP-based HTTP hosting, not using any hostname...
by cmit
Fri Apr 28, 2006 10:33 am
Forum: General
Topic: license email
Replies: 3
Views: 2484

You could also monitor the license expiry date via SNMP. Then your management system could warn you in time before a license is expiring.

Not sure if you can create an alarm using The Dude for that...

Best regards,
Christian Meis
by cmit
Thu Apr 27, 2006 12:00 am
Forum: Wireless Networking
Topic: Register but dont make ping
Replies: 3
Views: 1423

:roll:
Some more config information could help a lot:

- How are your wireless interfaces set up?
- How are ip addresses configured? Routes?
- Firewall rules?

Best regards,
Christian Meis
by cmit
Wed Apr 26, 2006 11:57 pm
Forum: General
Topic: Debug possibilities for system not booting?
Replies: 6
Views: 1844

Yep, I changed virtually everything in the system. So the only constant would be something like RouterOS not liking the chipset on the mainboard or the like.
I don't have the system at hand, and will only be in office again on Friday I suppose...

Best regards,
Christian Meis
by cmit
Wed Apr 26, 2006 7:12 pm
Forum: General
Topic: Debug possibilities for system not booting?
Replies: 6
Views: 1844

No, VGA/keyboard ;)

Best regards,
Christian Meis
by cmit
Wed Apr 26, 2006 4:14 pm
Forum: General
Topic: PPPoE versus HotSpot
Replies: 19
Views: 6719

That would be the info at cmit dot de...

Best regards,
Christian Meis
by cmit
Wed Apr 26, 2006 3:48 pm
Forum: General
Topic: PPPoE versus HotSpot
Replies: 19
Views: 6719

We are using PPPoE over wireless in many situations without noteworthy problems. This is both with RouterOS and other devices as wireless clients. I don't see the immediate problems, as long as your wireless backbone is of good quality (i.e. no really big packet loss etc.). Best regards, Christian M...
by cmit
Wed Apr 26, 2006 2:47 pm
Forum: General
Topic: PPPoE versus HotSpot
Replies: 19
Views: 6719

So the RouterOS PPPoE server (and client) DOES support stateless encryption? Never saw it mentioned in the docs.

I know that MS refuses the negotiate stateless PPP encryption (for PPPoE).

Best regards,
Christian Meis
by cmit
Wed Apr 26, 2006 2:39 pm
Forum: General
Topic: Debug possibilities for system not booting?
Replies: 6
Views: 1844

Debug possibilities for system not booting?

Hi guys, what are my possibilities to do further debugging in the following situation: I have a system where I can use netinstall to install any current RouterOS version without problems (network boot or from CD-ROM) onto all available media (here: CompactFlash, IDE DOM, standard hard disk). After t...
by cmit
Wed Apr 26, 2006 2:20 pm
Forum: General
Topic: PPPoE versus HotSpot
Replies: 19
Views: 6719

I'm sorry, but I'm not aware of a way to achieve this on MikroTik. Stateless MPPE encryption would surely be desireable, as this is a real gain for PPPoE connections over network links with high(er) packet loss (like any wireless network could be, at least from time to time). MikroTik: How about add...
by cmit
Fri Apr 21, 2006 1:52 pm
Forum: RouterBOARD hardware
Topic: Power Break during Upgrade
Replies: 8
Views: 2855

Try changing your baudrate. Sounds like the console could be configured to use another baud rate...

Best regards,
Christian Meis
by cmit
Fri Apr 21, 2006 9:33 am
Forum: General
Topic: 2.9.20 released ...
Replies: 18
Views: 4282

But that would be the way to go in my opinion.

At least I like to have WRITTEN confirmation that (and when) a problem was fixed. And I don't like guessing/trying if it was fixed by the fix for some other bug...

Best regards,
Christian Meis
by cmit
Wed Apr 19, 2006 9:59 pm
Forum: Wireless Networking
Topic: CPE-Antenna alignment via customer / Application available?
Replies: 149
Views: 42997

OK, guys... No need to kiss anyone, actually (or do kiss your wife, if you have one ;) ). I'm totally burried in the finishing stages of a project and not really in the office for the rest of this week. I'll get back to everyone here and the ones who e-mailed me next week. Let me at least get it tra...
by cmit
Wed Apr 19, 2006 9:50 pm
Forum: General
Topic: RADIUS, PPPoE, profiles, and address pools: How to do this?
Replies: 5
Views: 2535

You're welcome ;)

Best regards,
Christian Meis
by cmit
Wed Apr 19, 2006 12:44 am
Forum: RouterBOARD hardware
Topic: Ubiquiti SR5 connectors...
Replies: 15
Views: 6239

Have not got my hands on a SR5 yet, but as far as I can judge, it can use both connectors for our "Mickey Mouse setup" :D

Best regards,
Christian Meis
by cmit
Tue Apr 18, 2006 9:33 pm
Forum: General
Topic: How to autodiscover mikrotik
Replies: 14
Views: 3281

Banging ... my ... head ... on ... the ... wall ...

Thanks! Of course - that was to expect, as I can see our Ciscos with it :D

Best regards,
Christian Meis
by cmit
Tue Apr 18, 2006 9:31 pm
Forum: RouterBOARD hardware
Topic: Ubiquiti SR5 connectors...
Replies: 15
Views: 6239

But you were thinking in the right direction ;).

Using separate antennas for RX and TX allows you to use BIG "ears" without "shouting" so loud that your regulatory body will get angry :D ...

Best regards,
Christian Meis
by cmit
Tue Apr 18, 2006 9:28 pm
Forum: General
Topic: RADIUS, PPPoE, profiles, and address pools: How to do this?
Replies: 5
Views: 2535

The parameter you are looking for is "Framed-Pool". This one allows you to send the name of the ip pool to use to your RouterOS machine in an Access-Accept message.

Best regards,
Christian Meis
by cmit
Tue Apr 18, 2006 6:18 pm
Forum: Wireless Networking
Topic: Removal of Lic from RB 532 and Boot from CF card
Replies: 10
Views: 2411

Ah, now I get what you intend to do (after re-reading your post). Well, that would be a sensible application, and should work without problems with changed MAC addresses. But it still is a fact that each RouterOS license is bound to the installation media it sits on, and so you cannot "move&quo...
by cmit
Tue Apr 18, 2006 4:33 pm
Forum: Wireless Networking
Topic: Removal of Lic from RB 532 and Boot from CF card
Replies: 10
Views: 2411

The problem will be, that the configuration of the wireless card is tied to the MAC address of the wireless interface. So if you use your current setup to create the "backup CF", and then pop in a new wireless interface, the config and the interface possibly won't "get together" ...
by cmit
Tue Apr 18, 2006 4:17 pm
Forum: General
Topic: Some web pages doesn't show up with Mikrotik
Replies: 5
Views: 2322

Or might be a MTU problem?

Best regards,
Christian Meis
by cmit
Tue Apr 18, 2006 4:09 pm
Forum: General
Topic: How to autodiscover mikrotik
Replies: 14
Views: 3281

OK, let me pick that up. :D

I can see roughly what's happening when you press the "..." button in the WinBox connection dialog (broadcasts, ...) using a packet sniffer.

Would MikroTik open up the details of the possible responses of RouterOS devices?

Best regards,
Christian Meis
by cmit
Tue Apr 18, 2006 1:52 pm
Forum: General
Topic: PPPoE timing to disconnect
Replies: 6
Views: 1781

OK. Those advanced "time permissions" can only be handled using a RADIUS server for authentication. There you can configure your users' account limits to your hearts delight ;-). Might be that you need some custom scripting on the RADIUS server of your choice, but you can create (almost) e...
by cmit
Tue Apr 18, 2006 1:27 pm
Forum: General
Topic: PPPoE timing to disconnect
Replies: 6
Views: 1781

To configure a client to automatically (forced) disconnect after a certain online time, use the session timeout. This gives the maximum session uptime a user can have.

I don't understand your second question with online/offline timing. Can you explain more?

Best regards,
Christian Meis
by cmit
Tue Apr 18, 2006 12:50 pm
Forum: Wireless Networking
Topic: CPE-Antenna alignment via customer / Application available?
Replies: 149
Views: 42997

Ok, found it ;) Short list of features: Small client app to help clients/customers to align their (RouterOS based) CPE. (The CPE is queried by SNMP.) The customer just enters the ip address of the CPE and presses "Start". The app is showing you: - system name - MAC (wlan) of you CPE - conf...
by cmit
Sat Apr 15, 2006 10:34 pm
Forum: RouterBOARD hardware
Topic: New user needs help!!
Replies: 4
Views: 13660

To see the whole routers' config, use /export But beware that the commands may not (probably WILL not) be in the right order to recreate this config. I.e. it might be that the command to add an interface to a bridge group is there before the bridge group is actually created. But apart from that this...
by cmit
Sat Apr 15, 2006 10:22 pm
Forum: General
Topic: ping issue
Replies: 6
Views: 1858

I just read all of your different posts... I would say that you REALLY should take the time to read the manual and get some basic ip network knowledge, if you don't have it. And two more suggestions: - Writing that MikroTik is making you crazy and is bad in some way or the other makes at least me as...
by cmit
Fri Apr 14, 2006 9:54 pm
Forum: General
Topic: Ethernet - Wireless - Bridge
Replies: 13
Views: 3339

Good to hear the "click" ;-)...

Best regards,
Christian Meis
by cmit
Fri Apr 14, 2006 9:52 pm
Forum: Wireless Networking
Topic: Distributed Hotspot: A use for EoIP tunnels?
Replies: 2
Views: 1325

That setup does actually work quite well.

I have setup several networks like that, and they work like a charm. Central hotspot on a bridge bridging all EoIP tunnel to the APs (connected back to the hotspot via 5 GHz wireless).

Best regards,
Christian Meis
by cmit
Fri Apr 14, 2006 9:50 pm
Forum: Wireless Networking
Topic: CPE-Antenna alignment via customer / Application available?
Replies: 149
Views: 42997

Let me dig in the office on Tuesday. I think I have something like this flying around my hard disk...

If I just forget to come back here, a short reminder to info at cmit dot de might help ;-)

Best regards,
Christian Meis
by cmit
Wed Apr 12, 2006 5:48 pm
Forum: General
Topic: Ethernet - Wireless - Bridge
Replies: 13
Views: 3339

Yep. You are missing the fact that you simply cannot bridge wireless-station interfaces in RouterOS...

You have to use WDS or EoIP for you needs. There are several threads here in the forum on this topic.

Best regards,
Christian Meis
by cmit
Sun Apr 09, 2006 10:00 pm
Forum: Scripting
Topic: /tool e-mail send file problem
Replies: 5
Views: 2624

Without testing - when your file is named "out.txt", I suppose you should also use "file=out.txt" and not just "file=out" in the command line?

Best regards,
Christian Meis
by cmit
Sun Apr 09, 2006 9:50 pm
Forum: General
Topic: PPPoE & dynamic shaper
Replies: 5
Views: 1865

Just create two different PPP profiles with different rate limit parameters and configure each user to use the appropriate profile for his account type. Or if you are authenticating against a RADIUS server you can just send the ratelimit parameters you want for each account back to the MikroTik... B...
by cmit
Fri Apr 07, 2006 11:02 pm
Forum: General
Topic: Ubiquiti SR9 support
Replies: 49
Views: 25460

Now if only we could use this in Germany ;) ...

Best regards,
Christian Meis
by cmit
Fri Apr 07, 2006 6:17 pm
Forum: General
Topic: text file of config
Replies: 1
Views: 762

/export file=<your_filename_here> Take care of the leading slash - otherwise you would only export the part of the config tree you currently are in. So if you are in "/interface wireless", an export command without the leading "/" would only export the wireless interface setting...
by cmit
Thu Apr 06, 2006 3:02 pm
Forum: General
Topic: 2.9 Hotspot - dynamic firewall rules break static ones
Replies: 26
Views: 5738

So now with 2.9.19 there should be a way to keep the static rules before the dynamic rules. Or at least that's my interpretation of the changelog entry *) added hooks before hotspot dynamic firewall rules for custom modifications; I don't see any docs, but I suppose that the built-in chain "pre...
by cmit
Thu Apr 06, 2006 12:20 pm
Forum: General
Topic: CPU usage details?
Replies: 9
Views: 2297

Fine - but there certainly are more important things to put your work into!

Best regards,
Christian Meis
by cmit
Thu Apr 06, 2006 12:14 pm
Forum: General
Topic: CPU usage details?
Replies: 9
Views: 2297

I know all of that. And I never said it was easy :D. But I SUPPOSE it could be accomplished for at least some parts. So I suppose it would be possible to display resource usage for each running script. Yesterday night I tried to debug a fairly complex script, and the CPU on the system went to 90% qu...
by cmit
Thu Apr 06, 2006 12:11 pm
Forum: Scripting
Topic: Nested command problem
Replies: 2
Views: 1329

You cannot use the "0" to identify the entry you want. This only works on the console, if you have done a "print" of these values before. In scripts you have to use the find command. What you "find" for depends on your application. I suppose you would like to get the ip...
by cmit
Thu Apr 06, 2006 11:57 am
Forum: General
Topic: CPU usage details?
Replies: 9
Views: 2297

Yeah, I know that of course. That's why I wrote "something like top for MikroTik" (perhaps this wasn't clear enough). Of course this would only make sense if it could output something like: script "check_dhcpleases" 0.6% CPU, 823 kB mem PPPoE server "pppoe-server1" 48.3...
by cmit
Wed Apr 05, 2006 3:24 pm
Forum: Scripting
Topic: Scheduler (delay) what does it do?
Replies: 3
Views: 3047

Wasn't that something to make scripts running on system-startup run correctly on RB500 (which don't have a hardware clock and always start Jan 1st 1970)?
Not sure though ;)

Best regards,
Christian Meis
by cmit
Wed Apr 05, 2006 3:21 pm
Forum: General
Topic: CPU usage details?
Replies: 9
Views: 2297

Not possible right now.
This effectively is the question to provide something like "top" for MikroTik - which has been asked for several times here in the forum.

Would come in VERY handy for debugging purposes...

Best regards,
Christian Meis
by cmit
Wed Apr 05, 2006 3:20 pm
Forum: General
Topic: Hotspot and DNS - forced to use the DNS cache?
Replies: 4
Views: 1550

That should be the ip binding feature of hotspot - there you can configure it to allow some addresses to bypass the hotspot...

Best regards,
Christian Meis
by cmit
Wed Apr 05, 2006 1:10 am
Forum: General
Topic: Radius client and Bandwidth limiting
Replies: 13
Views: 4956

RADIUS only sends its' reply parameters (which include the bandwidth limiting settings) after a successful authentication, i.e. at the beginning of a session. So to have new RADIUS settings get into effect, you have to wait for you customer to end his connection and login again. Or, you could termin...
by cmit
Wed Apr 05, 2006 1:07 am
Forum: General
Topic: Winbox and another port than 8291
Replies: 2
Views: 2383

Well: No. ;) In 2.9 RouterOS WinBox is always using this fixed port number (unless 2.8, where you could specify a port number to connect to). You have ruled out a management VPN (why), so the only idea left would be to SSH and create the appropriate SSH tunnel to the MikroTik you want to manage via ...
by cmit
Tue Apr 04, 2006 10:34 am
Forum: Scripting
Topic: External program to view wlan scan results
Replies: 4
Views: 2454

No API until now, but MikroTik announced (search the forum here) that they will produce an API...

Best regards,
Christian Meis
by cmit
Mon Apr 03, 2006 10:18 pm
Forum: General
Topic: Web Proxy Redirect Suspended
Replies: 2
Views: 1172

I don't think you can rewrite requests with RouterOS proxy. But you could set up two webservers on dedicated ip addresses serving the "pay your bill" or "scan for virus" pages as their default web pages. Then create dst-nat rules to redirect the relevant customers' http request t...
by cmit
Mon Apr 03, 2006 5:33 pm
Forum: General
Topic: P2P traphic on port 80...
Replies: 3
Views: 3053

The MikroTik P2P traffic filters do not work just based on ports, but do recognize P2P traffic based on the content. So it will detect P2P traffic going through port 80 (if RouterOS does detect that P2P protocol at all). There are plenty of examples here in the forum and in the manual how to configu...
by cmit
Mon Apr 03, 2006 3:41 pm
Forum: Wireless Networking
Topic: Don't use WPA(2) with Atheros compression in 2.9.18!
Replies: 9
Views: 2961

Don't use WPA(2) with Atheros compression in 2.9.18!

We have had several occurrences of this phenomenon: 2.9.18, only basic wireless configuration with WPA or WPA2 between the routers. Compression (Atheros wireless interfaces) was turned ON. Those links were not able to come up or stay up for more than a few minutes. Typical error log messages would b...
by cmit
Mon Apr 03, 2006 3:18 pm
Forum: General
Topic: Redirecting To Local Hotspot Webpages
Replies: 4
Views: 1393

Without hotspot this won't work on MikroTik.

Best regards,
Christian Meis
by cmit
Sun Apr 02, 2006 9:55 pm
Forum: Wireless Networking
Topic: What’s the problem with the sr2
Replies: 8
Views: 2333

And a CPE is a "Customer Premise Equipment", i.e. the client device that your customers use. Which might be a RB112 for example, or any other wireless client (or wired client, in wired scenarios).

Best regards,
Christian Meis
by cmit
Sun Apr 02, 2006 9:45 pm
Forum: General
Topic: How do I open a port??
Replies: 11
Views: 3088

Using the 2.9 hotspot "ip-binding" feature you can bypass the required hotspot logon for that machine. Depending on your network config you have to add a firewall rule or a dst-nat to this...

Best regards,
Christian Meis
by cmit
Fri Mar 31, 2006 10:18 pm
Forum: General
Topic: Security of logging, how to upgrade securely?
Replies: 1
Views: 804

You could just drag-and-drop the new packages files from your Windows Explorer into the "Files" window in WinBox - this will upload (securely) through WinBox.

Best regards,
Christian Meis
by cmit
Fri Mar 31, 2006 12:04 pm
Forum: Wireless Networking
Topic: Blocking 2.4 GHz Channel
Replies: 3
Views: 1604

Well, this sounds like plain interference. Given that this is a license-free band, everyone can use it. And if you take into account that this frequency is used by other things than wireless networking equipment (like wireless surveillance video cameras, wireless headsets, ...) there are plenty of c...
by cmit
Fri Mar 31, 2006 11:04 am
Forum: Wireless Networking
Topic: Superchannel, CM9s, and radios not seeing each other (scan)
Replies: 7
Views: 2486

Many NEWER Atheros cards do have the a-connector near the center. The CM9 has it on the corner.

Source of confusion, yes ;)

Best regards,
Christian Meis
by cmit
Thu Mar 30, 2006 10:02 am
Forum: General
Topic: BETA Testing and Feature Suggestions for next routeros
Replies: 328
Views: 96530

You can "simulate" this using RouterOSs' safe-mode. This will make all changes done while in safe-mode only temporarly. If you loose connection to your RouterOS machine, it will revert those changes. Only on leaving safe-mode the changes are stored permanently. The hardest thing is to thin...
by cmit
Wed Mar 29, 2006 5:53 pm
Forum: Wireless Networking
Topic: Good signal, low noise, no link
Replies: 19
Views: 5796

John Tully wrote the following explanation on noise-floor during the last few days here:

Noise-floor does take into account everything "not 802.11". I.e. everything "RF" in the frequency range which does not look like an 802.11 frame.

Best regards,
Christian Meis
by cmit
Wed Mar 29, 2006 5:47 pm
Forum: General
Topic: WARNING: 2.9.18 does not pass PPTP traffic properly
Replies: 16
Views: 3739

No problems here, too. Just created a test-setup (all 2.9.18, of course): One RB532 as PPTP-server. Routed connection to another RB532. From behind the second RB532 I right now have two concurrent PPTP sessions through router2 to the PPTP server on router1. Both are up, running and passing traffic.....
by cmit
Wed Mar 29, 2006 5:02 pm
Forum: General
Topic: Installation into a slave disc (/dev/hdb)
Replies: 13
Views: 2936

I have seen comparable strange things with some other embedded boards. E.g. on some Portwell boards, Pretec IDE-DOMs are always recognized as Slave, even if jumpered as Master. PQI DOMs work. When the Pretec DOM is in those systems (as Slave) a netinstall will fail, too. (I suppose due to strangenes...
by cmit
Wed Mar 29, 2006 1:59 pm
Forum: General
Topic: Installation into a slave disc (/dev/hdb)
Replies: 13
Views: 2936

Damn, you're right. Just verified by plugging a IDE-DOM into secondary port, and it's just booting. I REALLY have missed that one completely... That opens up some nice possibilities to use hardware that was unusable until now... VERY nice! But when/where was this announced? Never saw it in the forum...
by cmit
Wed Mar 29, 2006 1:43 pm
Forum: General
Topic: Installation into a slave disc (/dev/hdb)
Replies: 13
Views: 2936

WHAT? ARE YOU SURE?

That would be GREAT, too good to believe...

Best regards,
Christian Meis
by cmit
Wed Mar 29, 2006 1:20 pm
Forum: General
Topic: DDNS
Replies: 8
Views: 4229

I think (guess) he's talking about support for dyndns.org et al...

AFAIK, only changeip.com DDNS is supported native on 2.9.

Best regards,
Christian Meis
by cmit
Wed Mar 29, 2006 1:19 pm
Forum: General
Topic: Installation into a slave disc (/dev/hdb)
Replies: 13
Views: 2936

Nice to hear that - and yes, why not just solder that damned jumper on there in the beginning?! :roll:

Well, at least you have a working solution ;)

Best regards,
Christian Meis
by cmit
Wed Mar 29, 2006 9:50 am
Forum: General
Topic: How do I open a port??
Replies: 11
Views: 3088

Well, you just have to complete the command like this:
/ip firewall nat add chain=dstnat in-interface=Internet protocol=tcp dst-port=3389 action=dst-nat to-addresses=x.x.x.x to-ports=3389
Best regards,
Christian Meis
by cmit
Wed Mar 29, 2006 9:48 am
Forum: General
Topic: Redirecting To Local Hotspot Webpages
Replies: 4
Views: 1393

Well, you HAVE to run hotspot. Then you CAN use the hotspots' HTML pages to your desire. You don't even have to include a login form, if you just want to display something like "You can purchase PPPoE based internet access here: abc Inc. bla blah".

Best regards,
Christian Meis
by cmit
Wed Mar 29, 2006 9:45 am
Forum: General
Topic: Installation into a slave disc (/dev/hdb)
Replies: 13
Views: 2936

Then you're blown :twisted: ... RouterOS will ONLY run from /dev/hda, i.e. IDE primary master. Sorry... Well, not that blown, after all. You have to use a IDE flash-module, that you can drop directly into the mainboards' (primary) IDE connector. Makes I successfully use include Pretec, and PQI. Best...
by cmit
Tue Mar 28, 2006 9:56 am
Forum: The Dude
Topic: PPPoE
Replies: 8
Views: 3487

The problem is that PPPoE connection interfaces are dynamic in RouterOS, i.e. they really disappear/don't exist when the PPPoE connection is down. There was a thread some time ago (about continually graphing PPPoE users, which suffers from the same problem) that suggested creating those PPPoE interf...
by cmit
Tue Mar 28, 2006 9:47 am
Forum: Wireless Networking
Topic: 5ghz AP & slow speeds
Replies: 3
Views: 1607

Zorker, have you actually thought about the vertical beam width of your omni? The datasheet gives some 7 segree (!) vertical beam width, and you wrote you mounted it up 155 ft. ... So at first glance it's no big surprise that you don't get much of a signal standing 155 ft. right BELOW this antenna. ...
by cmit
Mon Mar 27, 2006 2:30 pm
Forum: General
Topic: BETA Testing and Feature Suggestions for next routeros
Replies: 328
Views: 96530

This can already be achieved by using safe-mode. The hardest thing with safe-mode is to remember to enable it BEFORE doing something on remote routers ;)

It pops to my mind every so often in that second when I did something stupid - but then it's too late...

Best regards,
Christian Meis
by cmit
Mon Mar 27, 2006 11:45 am
Forum: RouterBOARD hardware
Topic: When i try to connect with Winbox to Mikrotik AP
Replies: 5
Views: 3522

If you do have more than one network interface in the Windows machine you are trying to run WinBox on, try disabling all other interfaces apart from the one where your RouterOS machine is connected.

Best regards,
Christian Meis
by cmit
Mon Mar 27, 2006 11:30 am
Forum: General
Topic: 2GB limit
Replies: 7
Views: 2137

Filesystem or kernel limits come to mind as the culprits, yes.

But you will have to ask MikroTik directly to get any confirmation on this: support@mikrotik.com.

Best regards,
Christian Meis
by cmit
Fri Mar 24, 2006 7:02 pm
Forum: General
Topic: Torch not detecting ICMP traffic
Replies: 16
Views: 4379

Just tried on a customers' machine with 2.9.18 on it:

Can perfectly see ICMP traffic in torch by doing
/tool torch ether1_public protocol=icmp
Best regards,
Christian Meis
by cmit
Fri Mar 24, 2006 4:33 pm
Forum: General
Topic: Torch not detecting ICMP traffic
Replies: 16
Views: 4379

Completely unrelated to torch, but we stumbeled upon another problem with systems upgraded from 2.8 to 2.9 yesterday (wireless encryption not working). Re-Installing the same system from scratch directly to 2.9 solved the problem. A simple "system reset" did NOT help. So perhaps it really ...
by cmit
Fri Mar 24, 2006 1:16 pm
Forum: General
Topic: 2GB limit
Replies: 7
Views: 2137

Why the heck would you want to upload such a large file TO a router (!) ??? :shock:

Best regards,
Christian Meis
by cmit
Fri Mar 24, 2006 1:14 pm
Forum: General
Topic: Problem with http-downloads via loadbalanced lines
Replies: 51
Views: 16496

Hi Matthias,

I actually do have an idea for some simple solution that is distributing users/traffic (only) according to source address...
If I find the time to put this up as a test installation I would post some more information.

Best regards,
Christian Meis
by cmit
Fri Mar 24, 2006 9:53 am
Forum: General
Topic: demo.mt.lv
Replies: 2
Views: 1110

I'm not really sure why this has to be posted here ;)

There IS demo2.mt.lv after all...

Best regards,
Christian Meis
by cmit
Fri Mar 24, 2006 9:43 am
Forum: Wireless Networking
Topic: Porting internal IPs through a single public IP
Replies: 5
Views: 2224

OK, then this should be a simple setup: /ip firewall nat add chain=dstnat in-interface=ether1 dst-port=82 protocol=tcp action=dst-nat to-addresses=192.168.0.17 to-ports=80 This should forward requests to port 82 coming in on interface ether1 (which should be your public interface name) to the local ...
by cmit
Thu Mar 23, 2006 6:31 pm
Forum: General
Topic: Slowing http Downloads to 64k but allowing browsing to 128k?
Replies: 6
Views: 2418

This can be achieved by using the burst feature of RouterOS queueing. This lets you give your users lets say 256 kbit/s for the first 20 seconds of a http session, and then limits them down to 64 kbit/s after that. That way web surfing (where a request should be done in 20 seconds, or whatever time ...
by cmit
Thu Mar 23, 2006 6:24 pm
Forum: Wireless Networking
Topic: Porting internal IPs through a single public IP
Replies: 5
Views: 2224

Port forwarding should work (there are plenty of examples of this here in the forum). Or you could create some kind of tunnel from your outside client to the MikroTik (PPTP, IPsec, ...) in order to be able to access the whole network on the "inside". Let us know if you need more detailed h...
by cmit
Thu Mar 23, 2006 5:47 pm
Forum: RouterBOARD hardware
Topic: Changelog for RB500-BIOS V1.9?
Replies: 4
Views: 2408

Thank you, Sergejs.

This new option does make sense ;)

Best regards,
Christian Meis
by cmit
Thu Mar 23, 2006 2:17 pm
Forum: Scripting
Topic: how to make a profile for users that did not pay´d the bill?
Replies: 18
Views: 6184

I think this will probably be exactly the problem I described above.

Best regards,
Christian Meis
by cmit
Thu Mar 23, 2006 2:15 pm
Forum: Scripting
Topic: how to make a profile for users that did not pay´d the bill?
Replies: 18
Views: 6184

And take care that TheWebserverOfYourChoice does accept IP-based HTTP requests (i.e. no hostname-based HTTP/1.1 hosting), as the redirected requests from your clients will carry the original host-header-name. So you will get requests for http://www.google.com, http://www.cnn.com etc. to that webserv...
by cmit
Thu Mar 23, 2006 1:18 pm
Forum: RouterBOARD hardware
Topic: Changelog for RB500-BIOS V1.9?
Replies: 4
Views: 2408

Changelog for RB500-BIOS V1.9?

Does anyone have a changelog for the RouterBoard 500-BIOS V1.9? The routerboard.com website still only has the 1.7 on it, but RouterOS 2.9.18 lets me upgrade to 1.9...

Best regards,
Christian Meis
by cmit
Thu Mar 23, 2006 11:35 am
Forum: Scripting
Topic: To retain variable's values after reboot
Replies: 20
Views: 8701

Nice one, too ;)

Best regards,
Christian Meis
by cmit
Wed Mar 22, 2006 9:46 pm
Forum: Wireless Networking
Topic: wireless bridging 2.9.11 and 2.9.12
Replies: 9
Views: 3017

You cannot put a wireless client (station) interface into a bridge. You would have to use WDS to "get through" to the 192.168.100.200 in your example. Depends on if the AP with 192.168.100.200 can do WDS (and will work together with MikroTik WDS).

Best regards,
Christian Meis