Community discussions

MikroTik App

Search found 1174 matches

by Anumrak
Fri Jun 15, 2018 12:02 pm
Forum: Forwarding Protocols
Topic: VRF Management
Replies: 7
Views: 10825

Re: VRF Management

AFAIK management not works in vrf. Only clients traffic.
by Anumrak
Fri Jun 15, 2018 11:51 am
Forum: Beginner Basics
Topic: I've lost my hairpin NAT [SOLVED]
Replies: 5
Views: 2104

Re: I've lost my hairpin NAT [SOLVED]

Open two more colon "To Address", "To Ports" and find to which local IP:port you translating your 76.212.90.etc
by Anumrak
Sat Jun 09, 2018 11:40 am
Forum: Forwarding Protocols
Topic: OSPF - How large can a flat network grow?
Replies: 8
Views: 2859

Re: OSPF - How large can a flat network grow?

In a WISP covering a very extensive area with 30 PPPoE servers, more than 300 PtMP and more than 2000 CPE we had problem with MPLS: sometimes MPLS forwarding table doesn't follow OSPF. We decided to split the very big OSPF domain into several little ones using iBGP. Routing tables have diminished f...
by Anumrak
Sat Jun 09, 2018 9:42 am
Forum: General
Topic: IPv6 Default Gateway ::/0 unreachable
Replies: 5
Views: 6999

Re: IPv6 Default Gateway ::/0 unreachable

Try add a route 2000::/3 on router. And your clients will be routed with ::/0 from RA. And switch off ND on all interfaces, but exacly you need.
by Anumrak
Sat Jun 09, 2018 9:36 am
Forum: Beginner Basics
Topic: L2TP & IPSEC with Windows 10
Replies: 12
Views: 7313

Re: L2TP & IPSEC with Windows 10

What IP do you receive from ISP?
by Anumrak
Fri Jun 08, 2018 5:15 pm
Forum: Forwarding Protocols
Topic: OSPF - How large can a flat network grow?
Replies: 8
Views: 2859

Re: OSPF - How large can a flat network grow?

Do you use bfd protocol between peers?
by Anumrak
Fri Jun 08, 2018 4:00 pm
Forum: Forwarding Protocols
Topic: OSPF - How large can a flat network grow?
Replies: 8
Views: 2859

Re: OSPF - How large can a flat network grow?

In a single ospf area must be not more than 100 routers I believe. I hope you using lsa type 3 between areas in order to save processors time to recalculate shortest path. With OSPF help you have to announce only tech nets. For large scale better use BGP.
by Anumrak
Fri Jun 08, 2018 1:35 pm
Forum: General
Topic: HELP ME PLEASE!
Replies: 8
Views: 2464

Re: HELP ME PLEASE!

I'm afraid its a reset and re-configure. There's no way to reset a password.

Be safe, netinstall for a Clean router.

Sent from Tapatalk
If i reset and i re-configure, data they will be lost?

Thank You
Yes, of course.
by Anumrak
Fri Jun 08, 2018 1:32 pm
Forum: Forwarding Protocols
Topic: Temporarily disable BGP full route feed
Replies: 7
Views: 3280

Re: Temporarily disable BGP full route feed

Great, this works on my test environment, thanks for your help :-) # Add static default 0.0.0.0/0 route, necessary since i will not get this route from my full feed /ip route add distance=1 gateway=x.x.x.x # Add in-going filter to the BGP Peer /routing bgp peer set BGPPeerName in-filter=isp1-in # A...
by Anumrak
Fri Jun 08, 2018 10:16 am
Forum: Forwarding Protocols
Topic: Layer2 VPN packet filtering [SOLVED]
Replies: 3
Views: 10268

Re: Layer2 VPN packet filtering [SOLVED]

You can block all frames with ethertype 0x86DD on bridge filter. Or, if you have some switches between routers, on them with L2 access list.
by Anumrak
Thu Jun 07, 2018 5:24 pm
Forum: Forwarding Protocols
Topic: Temporarily disable BGP full route feed
Replies: 7
Views: 3280

Re: Temporarily disable BGP full route feed

First filter rule allow 0.0.0.0/0
Second deny everything else.
by Anumrak
Thu Jun 07, 2018 11:18 am
Forum: General
Topic: HELP ME PLEASE!
Replies: 8
Views: 2464

Re: HELP ME PLEASE!

Just reset your router ASAP and upload backup. That's it.
by Anumrak
Thu Jun 07, 2018 11:17 am
Forum: Forwarding Protocols
Topic: HELP - BGP Peer dropping, odd VPN log message
Replies: 3
Views: 1725

Re: HELP - BGP Peer dropping, odd VPN log message

Check your RAM on router. Maybe your peer begin to redistribute to you full view, you memory ends and that's it?
by Anumrak
Thu Jun 07, 2018 11:12 am
Forum: Forwarding Protocols
Topic: Bypass vpls for certain subnet. Design question
Replies: 1
Views: 996

Re: Bypass vpls for certain subnet. Design question

If devices in your network have to work on layer 2 better, then use vpls. If not, better use mp-bgp l3 vpn subnets over mpls. mpls ldp will base on ospf protocol. bgp peers loopbacks will announce over ospf and cctv networks will announce over ibgp. On each router create vrf "cctv" and do ...
by Anumrak
Thu Jun 07, 2018 10:58 am
Forum: Forwarding Protocols
Topic: Ebgp to IBGP
Replies: 2
Views: 1158

Re: Ebgp to IBGP

Just setup your iBGP peers with same AS number.
by Anumrak
Wed Jun 06, 2018 2:04 pm
Forum: General
Topic: Routing more than one lan through IPSEC
Replies: 8
Views: 1544

Re: Routing more than one lan through IPSEC

just add routes

add 10.0.127.2 to your routers via 192.168.2.254

add 192.168.1.0/24,192.168.2.0/23 and 192.168.4.0/24 via 192.168.2.254 (or l2tp ((ipsec))) to 10.0.127.2
Tha doesnt work because DW of each office is unmanaged router, thnks
Use routes + source nat.
by Anumrak
Mon Jun 04, 2018 4:06 pm
Forum: Beginner Basics
Topic: Cannot Access VPN from Outside
Replies: 2
Views: 1047

Re: Cannot Access VPN from Outside

First of all: in which IP address resolves your domain from router or your computer? nslookup or smth Second: Did you open tcp 1723 port to MIkrotik PPTP server? If IP address of your ISP terminates on your router modem, the you should allow forwarding this port to IP address 192.168.2.3 with NAT ad...
by Anumrak
Mon Jun 04, 2018 3:54 pm
Forum: General
Topic: VLAN SWITCH
Replies: 38
Views: 5097

Re: VLAN SWITCH

Why not? In house A set route 0.0.0.0/0 to 192.168.0.1 and in house B set route 0.0.0.0/0 to 192.168.81.1. Router A will always sent packets to Internet through his ISP and B will always sent packets to Internet through vlan tag. Easy :)
by Anumrak
Mon Jun 04, 2018 10:28 am
Forum: Beginner Basics
Topic: 3 subnet 1 mikrotik
Replies: 2
Views: 781

Re: 3 subnet 1 mikrotik

Yes, it can be done with it.
by Anumrak
Fri Jun 01, 2018 4:17 pm
Forum: General
Topic: statistic page for PPPoE users
Replies: 3
Views: 992

Re: statistic page for PPPoE users

Through your web server + some mysql base with their usernames and + some ROS scripting. In ISP world people suing billing platform.
by Anumrak
Fri Jun 01, 2018 4:11 pm
Forum: Beginner Basics
Topic: Foolishly added filter rule is preventig access to RouterOS.
Replies: 7
Views: 1749

Re: Foolishly added filter rule is preventig access to RouterOS.

Hey. Try MAC Telnet access. If there will be no luck, then only hard reset.
by Anumrak
Fri Jun 01, 2018 2:20 pm
Forum: General
Topic: Massive PPPoE Drops
Replies: 8
Views: 3176

Re: Massive PPPoE Drops

Try to connect with wire only. If OK, then see what is a problem with wireless. Solve the problem consistently.
by Anumrak
Mon May 28, 2018 2:02 pm
Forum: Beginner Basics
Topic: RouterOS 5.20 - IP Route List
Replies: 13
Views: 4879

Re: RouterOS 5.20 - IP Route List

Two /32 routes to 192.168.1.1 interface WAN1, and 0.0.0.0/0 to WAN2 gateway IP interface WAN2 without any marking. Traffic won't go to 10.10.10.1 and 10.10.10.2 though WAN2, because we always have specific long prefix routes in RIB.
by Anumrak
Fri May 25, 2018 9:29 am
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

Nice presentation by the way :)
by Anumrak
Thu May 24, 2018 10:31 pm
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

Well what happens is that : If I say I use SLAAC (managed=0) My Windows hosts uses SLAAC just all right, but has no DNS If I say I use SLAAC (managed=0) and want to provide DNS throught DHCPV6 (other=1) My Windows hosts uses SLAAC just all right, but still has no DNS : it performs no DHCPV6 request...
by Anumrak
Thu May 24, 2018 9:04 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Try to add NAT rule which action is accept, chain is srcnat with source ip net 10.10.10.0/24. It's means that you will not nat it, just pass though the tunnel. And lift him above the rest. That's wrong. Just checked with l2tp/ipsec vpn in transport mode, icmp went well in both directions. Looks lik...
by Anumrak
Thu May 24, 2018 3:51 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Try to add NAT rule which action is accept, chain is srcnat with source ip net 10.10.10.0/24. It's means that you will not nat it, just pass though the tunnel. And lift him above the rest.
by Anumrak
Thu May 24, 2018 3:42 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

What is lan interface? It's a bridge or ethernet port? If it's bridge with added ethernet port in your LAN, then assign in bridge interface arp-proxy mode. If LAN is ethernet port, just assign on it arp-proxy.
by Anumrak
Thu May 24, 2018 2:39 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Try to find the packet with source IP 10.10.10.255 in torch. We need to know routing decision executes or not.
by Anumrak
Thu May 24, 2018 2:31 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Then I'm joining question :)
I believe after the router decapsulates the packet, new IP look up for 10.0.0.211 and router have to choose outbound interface. Don't know why he can't just put packet inside LAN interface.

Sniff the traffic with torch. What can you see there? In LAN interface.
by Anumrak
Thu May 24, 2018 2:23 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Print here firewall filter rules.
by Anumrak
Thu May 24, 2018 2:21 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Wow, I meant from 10.0.0.1 to 10.10.10.255 :)
by Anumrak
Thu May 24, 2018 2:14 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Can you ping from router with source 10.0.0.1 to 10.10.10.2? And show your "ip route print".
by Anumrak
Thu May 24, 2018 2:05 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Stop all ppp sessions and reconnect.
by Anumrak
Thu May 24, 2018 2:02 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Show traceroute from 10.10.10.2 to 10.0.0.211. Tracing route to 10.0.0.211 over a maximum of 30 hops 1 29 ms 29 ms 30 ms 10.0.0.1 2 * * * Request timed out. 3 * * * Request timed out. If you have correct new IP 10.10.10.2 from pool 10.10.10.2-10.10.10.255 and local address of ppp profile is 10.10.1...
by Anumrak
Thu May 24, 2018 1:57 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Show traceroute from 10.10.10.2 to 10.0.0.211.
by Anumrak
Thu May 24, 2018 1:50 pm
Forum: Beginner Basics
Topic: IPV6 static addressing
Replies: 5
Views: 4818

Re: IPV6 static addressing

Post here config of IPv6 - Address. IPv6 - ND. IPv6 - Neighbors.
by Anumrak
Thu May 24, 2018 1:49 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Your logic is more adapted for L2 VPN. And you have here L3 vpn with ppp base. You already have LAN on Tik with 10.0.0.0/16. Make in ppp profile local address 10.10.10.1 and remote from pool 10.10.10.2-10.10.10.255.
by Anumrak
Thu May 24, 2018 1:45 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Can LAN device ping vpn PC? 10.0.0.2.
by Anumrak
Thu May 24, 2018 1:42 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Try below:

VPNConfig.JPG
He done it
0.0.0.0 0.0.0.0 On-link 10.0.0.2 26
by Anumrak
Thu May 24, 2018 1:41 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Okay, seems you going through the tunnel. Look for firewall settings on 10.0.0.211 or Tik filter for forwarding. Try to ping another device in home LAN. In LAN working and from Tik working too.. https://image.ibb.co/eHjf1T/55.png I mean ping from vpn PC another LAN device. Aka 10.0.0.145 or whateve...
by Anumrak
Thu May 24, 2018 1:33 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Okay, seems you going through the tunnel. Look for firewall settings on 10.0.0.211 or Tik filter for forwarding. Try to ping another device in home LAN.
by Anumrak
Thu May 24, 2018 1:25 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

Do traceroute from PC to 8.8.8.8.
by Anumrak
Thu May 24, 2018 1:08 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

You won't recieve IP from dhcp server. ROS can't do such thing. What route do you have on pptp client to reach 10.0.0.0/16? And what IP addresses your LAN devices have? I receive IP from DHCP server: 10.0.0.2 and about the route, I post all routes I have. /ip route add check-gateway=ping distance=1...
by Anumrak
Thu May 24, 2018 1:05 pm
Forum: General
Topic: Weird NAT issue on v6.42.1
Replies: 8
Views: 1451

Re: Weird NAT issue on v6.42.1

You better assign input and output interfaces in rules.
by Anumrak
Thu May 24, 2018 12:56 pm
Forum: General
Topic: Can't ping to any device in LAN through VPN
Replies: 40
Views: 23146

Re: Can't ping to any device in LAN through VPN

You won't recieve IP from dhcp server. ROS can't do such thing. What route do you have on pptp client to reach 10.0.0.0/16? And what IP addresses your LAN devices have?
by Anumrak
Fri May 18, 2018 5:23 pm
Forum: General
Topic: Client authentication, where? And how?
Replies: 2
Views: 1219

Re: Client authentication, where? And how?

The fact is that large providers have historically been able to provide services via the PPPoE protocol and vendors that sold them hardware should support it. In fact: vendors got money, providers don't need to change something in their network. Over time, it has not become worse, and cold patches c...
by Anumrak
Thu May 17, 2018 10:16 am
Forum: General
Topic: Bridge sending out ARP messages using multiple MAC address from ports
Replies: 9
Views: 3961

Re: Bridge sending out ARP messages using multiple MAC address from ports

Carefully disable arp on users interfaces(I hope you connecting to router not on this interface) and see arp requests ends or not. If yes, manage dhcp arp inspection with arp reply-only property and create dhcp server with "Add arp for leases" option. After it dynamic arp records will appe...
by Anumrak
Thu May 17, 2018 10:11 am
Forum: General
Topic: Bridge wlan and eth2 on HaP - Wi-Fi to Ethernet converter [SOLVED]
Replies: 11
Views: 2521

Re: Bridge wlan and lan [SOLVED]

Just create dhcp server on bridge interface and put in this bridge eth2 and wlan2 interfaces. Should work.
by Anumrak
Wed May 16, 2018 4:28 pm
Forum: Beginner Basics
Topic: hEX - simple example not working
Replies: 2
Views: 604

Re: hEX - simple example not working

What your firewall filter rules on hex? Can you ping PC's from Tik itself? If yes, check your firewall rules.
by Anumrak
Wed May 16, 2018 12:45 pm
Forum: General
Topic: Bridge sending out ARP messages using multiple MAC address from ports
Replies: 9
Views: 3961

Re: Bridge sending out ARP messages using multiple MAC address from ports

Do you have proxy arp enabled on some of interfaces in users direction? If users connected to your network with IP network without PPP, they must put IP address of gateway, not interface.
by Anumrak
Wed May 16, 2018 11:42 am
Forum: Beginner Basics
Topic: Change Lan port to WAN [SOLVED]
Replies: 5
Views: 4677

Re: Change Lan port to WAN [SOLVED]

I'm sorry. Lower than 6.41. You have master port default config. Eth 3, 4, 5 are slaves for Eth2. You can see it in interface config.
by Anumrak
Wed May 16, 2018 11:31 am
Forum: Beginner Basics
Topic: Change Lan port to WAN [SOLVED]
Replies: 5
Views: 4677

Re: Change Lan port to WAN [SOLVED]

What version of RouterOS do you have on hAPac2? If lower that 6.40, then you have master port config in each interface. Check it.
by Anumrak
Wed May 16, 2018 10:49 am
Forum: Beginner Basics
Topic: VPN's IPs and DHCP
Replies: 6
Views: 12336

Re: VPN's IPs and DHCP

You can get IP from dhcp server through pptp tunnel, but not from ROS. Install Ubuntu server behind the MikroTik router, manage strongSwan server dhcpd and pptpd and here you go. What I achieved is I connected with IKEv2 client and one more time connected with pptp client inside IKEv2 tunnel. And go...
by Anumrak
Tue May 15, 2018 5:38 pm
Forum: General
Topic: Bridge sending out ARP messages using multiple MAC address from ports
Replies: 9
Views: 3961

Re: Bridge sending out ARP messages using multiple MAC address from ports

Maybe you sould try set static admin mac on a bridge in order he will not send request from multiple macs. But better way, i think, is to switch off ports till this crap is over. And think what can do host behind that port. I have set static admin MAC on the bridge long before this is happening. Al...
by Anumrak
Tue May 15, 2018 5:09 pm
Forum: General
Topic: Bridge sending out ARP messages using multiple MAC address from ports
Replies: 9
Views: 3961

Re: Bridge sending out ARP messages using multiple MAC address from ports

Maybe you sould try set static admin mac on a bridge in order he will not send request from multiple macs. But better way, i think, is to switch off ports till this crap is over. And think what can do host behind that port.
by Anumrak
Tue May 15, 2018 4:49 pm
Forum: Beginner Basics
Topic: UPNP issue with PS4
Replies: 4
Views: 1971

Re: UPNP issue with PS4

OR you can do double nat through second router :) 3074 -> 1301 -> 3074 3074 -> 1302 -> 3074 3074 -> 1303 -> 3074. But it's true that your console needs global addresses :) That's best option. /28 network. OR you can get ipv6 /48 block from hurricane electric and assign public ipv6 addresses fo free :)
by Anumrak
Tue May 15, 2018 11:40 am
Forum: General
Topic: Problem with PPPoE connections after upgrade to 6.42.1
Replies: 4
Views: 3020

Re: Problem with PPPoE connections after upgrade to 6.42.1

I believe problem in switching. Because of TCP MSS negotiation. After this frames with vlan tag of 1512 bytes, for example, can't get through switch ports with MTU 1500. But with PPPoE MTU 1480 it can.
by Anumrak
Tue May 15, 2018 10:38 am
Forum: Forwarding Protocols
Topic: VPLS with Cisco devices
Replies: 1
Views: 1048

Re: VPLS with Cisco devices

Try in lab with Cisco 7606 with WS-X6724-SFP or WS-X6704-10GE modules. It support simple configuration of layer 2 virtual circuits to downlinks and to uplinks without awful bridge domains.
by Anumrak
Tue May 15, 2018 10:31 am
Forum: General
Topic: Port forwarding not working
Replies: 16
Views: 2897

Re: Port forwarding not working

try action dst-nat instead of netmap and specify in-interface.
No, didn't help.
I have several perfectly working forwards like rdp, vnc and ssh, but problem with samba.
Do you have counters moving in this rule? If yes, then problem in PCs.
by Anumrak
Tue May 15, 2018 9:16 am
Forum: General
Topic: Port forwarding not working
Replies: 16
Views: 2897

Re: Port forwarding not working

I'm not sure action=netmap accepts a single IP address as to-addresses value, you should use action=dst-nat instead. And put back the src-address=your.current.ip.address , as it was not the reason why it did not work. Plus you don't need to use to-ports if you don't need to change the original dst-...
by Anumrak
Tue May 15, 2018 9:15 am
Forum: General
Topic: Port forwarding not working
Replies: 16
Views: 2897

Re: Port forwarding not working

try action dst-nat instead of netmap and specify in-interface.
by Anumrak
Mon May 14, 2018 5:04 pm
Forum: Scripting
Topic: Script for Enable Wireless
Replies: 1
Views: 810

Re: Script for Enable Wireless

Before you run your script try to type it in terminal with tab. You could miss some input keys. If you'll try to run it in terminal, in case of mistake, in windows you'll see: incorrect line or reply from code.
by Anumrak
Mon May 14, 2018 1:42 pm
Forum: Forwarding Protocols
Topic: Filter Spesific OSPF routes
Replies: 11
Views: 3902

Re: Filter Spesific OSPF routes

I played around with some filter rules. One issue i had with redistributing connected was that some of the connected routes was already in the routing table because of ospf. So what is did is create a bgp-out filter. for example. /routing filter add chain=bgp-out prefix=10.10.0.0/24 prefix-length=2...
by Anumrak
Sat May 12, 2018 12:26 pm
Forum: Forwarding Protocols
Topic: VPLS leaking interface
Replies: 8
Views: 2059

Re: VPLS leaking interface

If they are in same l2 domain, you can try to ping host in different VPLS. Dump it and see what you got.
not working. I cant ping from different VPLS interface.
Means horizon rule works :) It's just ldp signaling traffic you see.
by Anumrak
Fri May 11, 2018 5:21 pm
Forum: Forwarding Protocols
Topic: Routing next hop recursion not working over PPP framed routes
Replies: 4
Views: 2536

Re: Routing next hop recursion not working over PPP framed routes

Thanks for the tip. It would work for this contrived example with static routes, but what about with BGP or other protocols which use next hop addresses? My use case is using BGP over PPPoE. As client terminating service, PPPoE not using much in BGP design. BGP using in full mesh IP network or over...
by Anumrak
Fri May 11, 2018 5:09 pm
Forum: General
Topic: Can route to internet but not between local Subnets
Replies: 10
Views: 2191

Re: Can route to internet but not between local Subnets

Hi Thank you all for the reply. I have decided to reset the Mikrotik to factory default and started my configuration over again ( Was not much config 3 Ports and 1 additional route + DHCP etc..) Now it works.. ( Must have just been some wrong setting somewhere that I could not see) Both Routing Bet...
by Anumrak
Fri May 11, 2018 5:07 pm
Forum: General
Topic: Can route to internet but not between local Subnets
Replies: 10
Views: 2191

Re: Can route to internet but not between local Subnets

You cannot route between subnets by default. That's the point of having different subnets, so the hosts can communicate with those on their subnet but not others. Those dynamic routes that are being made are for Internet access so those subnets can route out to the Internet. If you want 10.0.16.0/2...
by Anumrak
Fri May 11, 2018 4:56 pm
Forum: Forwarding Protocols
Topic: Routing next hop recursion not working over PPP framed routes
Replies: 4
Views: 2536

Re: Routing next hop recursion not working over PPP framed routes

Yeah, now it's common behavior for ppp routes. You just need select interface instead of IP address on other side.
by Anumrak
Fri May 11, 2018 4:49 pm
Forum: Forwarding Protocols
Topic: VPLS leaking interface
Replies: 8
Views: 2059

Re: VPLS leaking interface

If they are in same l2 domain, you can try to ping host in different VPLS. Dump it and see what you got.
by Anumrak
Fri May 11, 2018 4:45 pm
Forum: General
Topic: Can route to internet but not between local Subnets
Replies: 10
Views: 2191

Re: Can route to internet but not between local Subnets

You cannot route between subnets by default. That's the point of having different subnets, so the hosts can communicate with those on their subnet but not others. Those dynamic routes that are being made are for Internet access so those subnets can route out to the Internet. If you want 10.0.16.0/2...
by Anumrak
Fri May 11, 2018 4:39 pm
Forum: Forwarding Protocols
Topic: Filter Spesific OSPF routes
Replies: 11
Views: 3902

Re: Filter Spesific OSPF routes

I might be wrong, but I think redistribute /32 routes from each pppoe address each time it's connected, it's not really good idea.
by Anumrak
Fri May 11, 2018 3:02 pm
Forum: Forwarding Protocols
Topic: VPLS leaking interface
Replies: 8
Views: 2059

Re: VPLS leaking interface

Maybe it's VPLS management signaling packets? You should dump this and watch in a wireshark. Also, check all interfaces have the same horizon value. And make sure you have latest ROS version.
by Anumrak
Fri May 11, 2018 2:42 pm
Forum: General
Topic: Can route to internet but not between local Subnets
Replies: 10
Views: 2191

Re: Can route to internet but not between local Subnets

Why you think Tik can't route? If you see dynamic routes of LANs in routing table, then it routes. Try to traceroute between hosts in different subnets. If you can see first hop as his gateway IP and after trace is snaps, then host in destination just blocks ICMP.
by Anumrak
Fri May 11, 2018 2:15 pm
Forum: General
Topic: How to get MAC of host (not via ARP list)
Replies: 5
Views: 1151

Re: How to get MAC of host (not via ARP list)

You cannot, but it was not easy to understand that you wanted an IP<->MAC address maping from your original post given that the title of the topics doesn't mention IP address at all. In the arp table there are translations for active IP addresses; if the address has been inactive for some time, the...
by Anumrak
Fri May 11, 2018 1:36 pm
Forum: General
Topic: IPv6 ND Inspection(anti-spoofing)
Replies: 2
Views: 857

Re: IPv6 ND Inspection(anti-spoofing)

I heard about Secure ND(SeND). Does ROS support it/will support it?
by Anumrak
Fri May 11, 2018 10:25 am
Forum: General
Topic: Problem communication when connect a RB951
Replies: 2
Views: 539

Re: Problem communication when connect a RB951

Maybe you have a loop in switched network or duplicate IP address. Check these two cases.
by Anumrak
Fri May 11, 2018 9:56 am
Forum: General
Topic: How to get MAC of host (not via ARP list)
Replies: 5
Views: 1151

Re: How to get MAC of host (not via ARP list)

Hey. You can look it in switch tab in active hosts. Try to implement it in your script with "get" function.
by Anumrak
Fri May 11, 2018 9:32 am
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

Cool that you done with it :)
by Anumrak
Fri May 11, 2018 9:29 am
Forum: Beginner Basics
Topic: Weird dns cache entries [SOLVED]
Replies: 1
Views: 1314

Re: Weird dns cache entries [SOLVED]

That dns flood from your LAN, so these requests just flooding your RAM on router, what is not cool. You should block dns queries for this host and figure out how to fix him, then release the host.

P.S.: I bet that's a virus.
by Anumrak
Thu May 10, 2018 5:15 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

I am sure he will be very happy :D Yesterday just called him about 50 times to take a ipconfig/renew on the PCs... :D Shutting down the physical Ethernet port and switching it on again should be enough to make the DHCP client on Windows start from Discovery, no need to call Mr. Kovács for each try....
by Anumrak
Thu May 10, 2018 5:09 pm
Forum: Scripting
Topic: How remove master-port on RoS for both new and old RoS?
Replies: 4
Views: 1901

Re: How remove master-port on RoS for both new and old RoS?

Try to use in script "else" after "if". In "else" you can add new bridge, when "if" will detect absent of master-port. Experiment! :)
by Anumrak
Thu May 10, 2018 4:37 pm
Forum: Scripting
Topic: How remove master-port on RoS for both new and old RoS?
Replies: 4
Views: 1901

Re: How remove master-port on RoS for both new and old RoS?

In 6.41+ there is no master port anymore, that's why your sript can't find it in config. What's new in 6.41 (2017-Dec-22 11:55): Important note!!! Backup before upgrade! RouterOS (v6.40rc36-rc40 and) v6.41rc1+ contains new bridge implementation that supports hardware offloading (hw-offload). This up...
by Anumrak
Thu May 10, 2018 4:30 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

At the moment both local DHCP server has been disabled on the Mikrotiks. I have checked the ARP table on both Mikrotik and I can see some communication from 192.168.10.1. Once I've seen there was an IP offer from the DHCP server but the client refuse it :O BTW yep that a good idea to put directly a...
by Anumrak
Thu May 10, 2018 4:21 pm
Forum: Forwarding Protocols
Topic: Filter Spesific OSPF routes
Replies: 11
Views: 3902

Re: Filter Spesific OSPF routes

And if you want more flexible BGP routing, you should switch off synchronizaion with IGP routing table.

https://wiki.mikrotik.com/wiki/Manual%3 ... GP#Network
by Anumrak
Thu May 10, 2018 4:19 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

You should disable DHCP servers on both Tiks and try to recieve IP from WIN server. If Tiks recieving addresses from him, then the problem in switch or in OS of the client. Try to recieve address from WIn server without switch. Connect directly to a Tik with your PC.
by Anumrak
Thu May 10, 2018 4:08 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

Yes, I have a bridge called "EoIP bridge" and an EoIP interface called "EoIP-to-D" (left side) and "EoIP-to-M" (right side). I've created a local DHCP server to "EoIP bridge". And as I mentioned it works properly, but when I enabled the "EoIP" it cr...
by Anumrak
Thu May 10, 2018 3:45 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

On which interface do you create dhcp server on Tik? Maybe you create the server on EoIP interface which bridged with your lan?
by Anumrak
Thu May 10, 2018 3:36 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

What OS is on "DHCP from server"? Can you test it on another OS?
by Anumrak
Thu May 10, 2018 3:24 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

Can interface bridge(new one maybe) on left Tik get IP from Win DHCP Server?
Can anyone get IP from it?
by Anumrak
Thu May 10, 2018 3:13 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

Do you have the only one dhcp server enabled? When you trying to recieve the address from 192.168.10.1.
by Anumrak
Thu May 10, 2018 2:52 pm
Forum: General
Topic: EoIP tunnel issue
Replies: 27
Views: 4235

Re: EoIP tunnel issue

You should bridge ether interfaces and eoip tunnels on both Tiks for all the way to dhcp client. If this is correct, you should print here your config.
by Anumrak
Thu May 10, 2018 2:37 pm
Forum: General
Topic: Blocking IPv6 through the EoIP tunnel
Replies: 4
Views: 2002

Re: Blocking IPv6 through the EoIP tunnel

which ports use NDP?
It's ICMPv6 protocol. Number 58 on IPv6 layer. Like OSPF protocol is number 89 on IP layer.
by Anumrak
Thu May 10, 2018 2:19 pm
Forum: General
Topic: Blocking IPv6 through the EoIP tunnel
Replies: 4
Views: 2002

Re: Blocking IPv6 through the EoIP tunnel

IPv6 using neighbor discovery protocol, so just disable it on EoIP interface or on hardware interface into lan.
by Anumrak
Thu May 10, 2018 2:15 pm
Forum: Forwarding Protocols
Topic: Filter Spesific OSPF routes
Replies: 11
Views: 3902

Re: Filter Spesific OSPF routes

You can choose of: 1) Full mesh topology between BGP peers with using of loopback IP's of OSPF process; 2) Route Reflector(s) which can recieve routes from "BGP Clients" and redistribute them to others with no need of full mesh; 3) Use MPLS for BGP peers connectivity over OSPF network. Las...
by Anumrak
Thu May 10, 2018 1:33 pm
Forum: Forwarding Protocols
Topic: Filter Spesific OSPF routes
Replies: 11
Views: 3902

Re: Filter Spesific OSPF routes

Routing Filters works more with BGP. You can separate areas of your OSPF domain by several, for ex. 0.0.0.1, 0.0.0.2, 0.0.0.3 and all these will connects to area 0.0.0.0 and then you can create totally stubby area in order to this area can recieve only default route to 0.0.0.0 area. /routing ospf ar...
by Anumrak
Thu May 10, 2018 12:19 pm
Forum: Forwarding Protocols
Topic: Port forwarding not working
Replies: 2
Views: 1135

Re: Port forwarding not working

Try to find some firewall activity on end point machine. Rules are pretty simple.
by Anumrak
Thu May 10, 2018 11:59 am
Forum: Beginner Basics
Topic: Internet-connection doesnt work
Replies: 3
Views: 728

Re: Internet-connection doesnt work

Paste here firewall filter rules and NAT rules.
by Anumrak
Thu May 10, 2018 11:54 am
Forum: Beginner Basics
Topic: Firewall Rules: Block ICMP from WAN (PPPOE connection) [SOLVED]
Replies: 22
Views: 9539

Re: Firewall Rules: Block ICMP from WAN (PPPOE connection) [SOLVED]

Change this "add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=\
new in-interface=ether1" on pppoe-out1 in in-interface, please.
by Anumrak
Thu May 10, 2018 11:33 am
Forum: Beginner Basics
Topic: DHCP over EoIP
Replies: 2
Views: 1359

Re: DHCP over EoIP

Just bridge eth3 and EoIP tunnel interface on Tik A and EoIP Tunnel and eth2 on Tik B.
by Anumrak
Thu May 10, 2018 9:34 am
Forum: General
Topic: IPv6 ND Inspection(anti-spoofing)
Replies: 2
Views: 857

Re: IPv6 ND Inspection(anti-spoofing)

Up.
by Anumrak
Mon May 07, 2018 4:07 pm
Forum: General
Topic: IPv6 ND Inspection(anti-spoofing)
Replies: 2
Views: 857

IPv6 ND Inspection(anti-spoofing)

Didn't find topic with answers, so do a ROS have such feature? How to prevent IPv6 spoofing on layer 2 from specific multicast mac? Attacker will refresh ND cach with IP - MAC, don't really understand what mechanic from ROS can handle it.
by Anumrak
Fri May 04, 2018 5:35 pm
Forum: General
Topic: more public IP addresses
Replies: 5
Views: 1193

Re: more public IP addresses

Bridge other Tik interfaces, assign 2.2.2.0/29 network on vlan interface and choose other Tik ports as untagged in bridge ports, I suppose. https://wiki.mikrotik.com/wiki/Manual%3 ... p_examples
by Anumrak
Fri May 04, 2018 5:29 pm
Forum: Forwarding Protocols
Topic: VPN Client ISSUE
Replies: 2
Views: 2591

Re: VPN Client ISSUE

Try mschapv2 on both side, encryption must be MPPE 128 bits on both sides(better be) and check mtu on both sides, must match.
by Anumrak
Fri May 04, 2018 5:19 pm
Forum: General
Topic: Fetch tool over VPN
Replies: 8
Views: 2907

Re: Fetch tool over VPN

is anybody resolved this ?
Maybe a static route into vpn interface?
by Anumrak
Fri May 04, 2018 1:08 pm
Forum: Beginner Basics
Topic: Trivial blocking IP question [SOLVED]
Replies: 3
Views: 981

Re: Trivial blocking IP question [SOLVED]

1) Input chain is using for router itself. Forward is using for hosts between router;
2) In that case you should add filter rule for LAN interface for output chain in order to manipulate local addresses. And dst-address must be local address.
by Anumrak
Fri May 04, 2018 12:52 pm
Forum: Beginner Basics
Topic: ipv6 tunnel and DHCPv6
Replies: 8
Views: 1958

Re: ipv6 tunnel and DHCPv6

In windows you should set them manually. no, I will kill myself doing this Maybe you can post console commands how to set static ipv6 to my windows server, because I'm not sure that I understand you previous explanation. I understand that I should get /48 prefix in HE. But what should I do next, be...
by Anumrak
Fri May 04, 2018 12:23 pm
Forum: Beginner Basics
Topic: ipv6 tunnel and DHCPv6
Replies: 8
Views: 1958

Re: ipv6 tunnel and DHCPv6

You can assign IPv6 DNS too in IP - DNS. Just write them next to IPv4. In windows you should set them manually.
You can assign static IPv6 address to server. Static address is not recommended only for laptops, xbox/ps and PC's.
by Anumrak
Fri May 04, 2018 10:57 am
Forum: Beginner Basics
Topic: ipv6 tunnel and DHCPv6
Replies: 8
Views: 1958

Re: ipv6 tunnel and DHCPv6

You already have ipv6 address of server and yours. It's /64 network. In order to assign to your clients ipv6 addresses in auto mode, your sould assign to yourself in HE account /48 network, it's about 65536 /64 networks for your devices in LAN. After you get /48 prefix, you can delegate from it /64 ...
by Anumrak
Sat Apr 28, 2018 2:32 pm
Forum: Beginner Basics
Topic: HELP Firewall Rules
Replies: 9
Views: 2189

Re: HELP Firewall Rules

And I'm sorry for incorrect sequence: chain=input action=accept protocol=tcp psd=21,3s,3,1 src-address="IP of your Hex" chain=input action=drop src-address-list=Port_Scanner chain=input action=add-src-to-address-list protocol=tcp psd=21,3s,3,1 address-list=Port_Scanner address-list-timeout...
by Anumrak
Sat Apr 28, 2018 2:21 pm
Forum: Beginner Basics
Topic: HELP Firewall Rules
Replies: 9
Views: 2189

Re: HELP Firewall Rules

Try something like this: chain=input action=drop src-address-list=Port_Scanner chain=input action=accept protocol=tcp psd=21,3s,3,1 src-address="IP of HEx" chain=input action=add-src-to-address-list protocol=tcp psd=21,3s,3,1 address-list=Port_Scanner address-list-timeout=1w or with a whi...
by Anumrak
Sat Apr 28, 2018 1:08 pm
Forum: Beginner Basics
Topic: HELP Firewall Rules
Replies: 9
Views: 2189

Re: HELP Firewall Rules

Extract Hex IP from list or deactivate the rule? I would like it if possible to make a white list with the addresses known to be excluded from the rule. sorry but I'm trying to learn! Try something like this: chain=input action=drop src-address-list=Port_Scanner chain=input action=accept protocol=t...
by Anumrak
Sat Apr 28, 2018 12:46 pm
Forum: Beginner Basics
Topic: newbie
Replies: 3
Views: 870

Re: newbie

Already found it , tnx to YT.... tnx for the many helpfull answers ;) still have a question that i can't seem to find on www.... how to set mac filtering on the router for wireless ( and maybe also for wired connections) kind regards yoeri You should filter mac address in /interface wireless access...
by Anumrak
Sat Apr 28, 2018 12:37 pm
Forum: Beginner Basics
Topic: HELP Firewall Rules
Replies: 9
Views: 2189

Re: HELP Firewall Rules

Extract Hex IP from list or deactivate the rule?
by Anumrak
Sat Apr 28, 2018 10:21 am
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

It's nice that ipv6 has priority over ipv4 :) It is so unusual that ipv4 now more in support role.
by Anumrak
Fri Apr 27, 2018 5:39 pm
Forum: General
Topic: Can't connect after changing IP
Replies: 6
Views: 2933

Re: Can't connect after changing IP

What new IP is and on what interface do you change it? Don't use quick set, use just winbox, in which you can see every settings.
by Anumrak
Fri Apr 27, 2018 5:13 pm
Forum: General
Topic: Can't connect after changing IP
Replies: 6
Views: 2933

Re: Can't connect after changing IP

So, then it's security issue :) Check IP - Services and System - Users. Check IP's from which your Tik can be available.
by Anumrak
Fri Apr 27, 2018 3:54 pm
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

I think I'll prefer to use just slaac, without statless dhcpv6. Will wait for statefull dhcpv6. But thanks for your answers and help! :)
by Anumrak
Fri Apr 27, 2018 1:32 pm
Forum: Beginner Basics
Topic: Hurricane Electric Tunnel Broker implementation help
Replies: 4
Views: 5417

Re: Hurricane Electric Tunnel Broker implementation help

Hello. I'm need to implement a double stack IPv4-IPv6 for my LAN. ether2 - DHCP server for (IPv4 with 100.64.0.0/24 pool and IPv6 with the pools that deppends on Hurricane Electric) ether6 - DHCP client, it's the port connected to modem ADSL2+ which implements an dhcp server with a nat to a dinamic...
by Anumrak
Fri Apr 27, 2018 10:42 am
Forum: Beginner Basics
Topic: Firewall Rules: Block ICMP from WAN (PPPOE connection) [SOLVED]
Replies: 22
Views: 9539

Re: Firewall Rules: Block ICMP from WAN (PPPOE connection) [SOLVED]

Why you choose in-interface as ether1 instead of pppoe-out1?
by Anumrak
Fri Apr 27, 2018 10:36 am
Forum: General
Topic: Can't connect after changing IP
Replies: 6
Views: 2933

Re: Can't connect after changing IP

These addresses must be in same broadcast domain. Is that true? If can't do this on running system, then use "Safe mode" or configure IP from mac-telnet connection, without IP connectivity.
by Anumrak
Fri Apr 27, 2018 9:19 am
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

Sorry for misunderstanding about "now". It was "not". If I set "other options" with dhcpv6 server active on advertising interface, I will not get dnsv6 servers to my PC. DNSv6 are set in IP - DNS. There are v4 and v6 servers. I know about dhcp options, but did not try y...
by Anumrak
Thu Apr 26, 2018 3:55 pm
Forum: General
Topic: Sizing
Replies: 8
Views: 1679

Re: Sizing

Very interested in answer :) For smallest model.
by Anumrak
Thu Apr 26, 2018 3:47 pm
Forum: Forwarding Protocols
Topic: Static routing instead of OSPF
Replies: 2
Views: 1210

Re: Static routing instead of OSPF

I have a ring of 7 routers, running MPLS and VPLS with OSPF routing.
I am picking up high latency issues between two points, so I suspect looping somewhere along the line.
I am thinking about cancelling OSPF routing and just creating static routes, what are your thoughts?
Simple OSPF is better.
by Anumrak
Thu Apr 26, 2018 3:45 pm
Forum: Forwarding Protocols
Topic: L2VPN -- Targeted LDP
Replies: 3
Views: 2183

Re: L2VPN -- Targeted LDP

Try it "pw-type=tagged-ethernet" with raw type. And bridge ether ports with vpls interface to client side.
by Anumrak
Thu Apr 26, 2018 3:42 pm
Forum: Scripting
Topic: Looking For an answer too zero mac addresses...
Replies: 11
Views: 11246

Re: Looking For an answer too zero mac addresses...

Maybe you should make static dhcp leases with arp records? With arp reply only function on physical port. Your situation reminds me dhcp starvation attack, if you have a lot of macs with zeros.
by Anumrak
Thu Apr 26, 2018 3:38 pm
Forum: Beginner Basics
Topic: Port forwarding behind CGNAT
Replies: 5
Views: 6424

Re: Port forwarding behind CGNAT

Unfortunately, there is now way to forward traffic to you from ISP router, except you working in this ISP :(
by Anumrak
Thu Apr 26, 2018 3:05 pm
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

Stateless DHCPv6 now working. Works only ND and RA and static DNSv6.
Can anyone confirm this?
by Anumrak
Thu Apr 26, 2018 9:48 am
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

Stateless DHCPv6 not working. Works only ND and RA and static DNSv6.
by Anumrak
Wed Apr 25, 2018 4:30 pm
Forum: General
Topic: Sizing
Replies: 8
Views: 1679

Re: Sizing

admin - /29, office - /27, guests - /22. Don't know why everybody are silent :)
by Anumrak
Wed Apr 25, 2018 2:53 pm
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

You already have advertising, so you just need to enable other config in options, add DHCPv6 server to same interface without specifying pool and it will work in stateless mode and provide info to clients that ask (as instructed by other config flag in RA). That's what I meant. Will try, thanks! :)
by Anumrak
Wed Apr 25, 2018 2:25 pm
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Re: Can't get DNSv6 from SLAAC

Microsoft only added support for DNS from RA not so long ago. And as far as I know, only to Windows 10, no backports. But you can use DHCPv6, RouterOS supports stateless server.
You mean I need to manage dhcpv6 server + IPv6 advertising?
by Anumrak
Wed Apr 25, 2018 12:31 pm
Forum: General
Topic: Can't get DNSv6 from SLAAC
Replies: 27
Views: 9385

Can't get DNSv6 from SLAAC

Hi everyone. I've managed IPv6 to my LAN, in IPv6 network discovery I've enabled DNS advertising and advertising IPv6 address itself from prefix. My laptop got addresses and DNSv6 too. PC's with win 8.1 also got addresses, but didn't get dnsv6 servers addresses. Is it true that windows OS can't inst...
by Anumrak
Tue Apr 17, 2018 1:47 pm
Forum: General
Topic: TLS and authentication without username/password in OpenVPN. PLEASEE!!!
Replies: 2
Views: 1811

Re: TLS and authentication without username/password in OpenVPN. PLEASEE!!!

А прокси через socks5 не пробовал? Вроде работает хорошо и логина, пароля не требует.
by Anumrak
Tue Apr 17, 2018 10:15 am
Forum: Forwarding Protocols
Topic: Network Design suggestions......
Replies: 4
Views: 1738

Re: Network Design suggestions......

OSPF must work just fine if all of your interfaces in area 0, because ldp will work only in one area as a vpls. If you did the same in higher version, then it might be a bug.
by Anumrak
Mon Apr 16, 2018 5:07 pm
Forum: Forwarding Protocols
Topic: What L2-VPN should be used?
Replies: 11
Views: 2578

Re: What L2-VPN should be used?

So you mean at first ipsec side to side and then over that eoip? Correct?
Thanks!
Correct :)
by Anumrak
Mon Apr 16, 2018 11:09 am
Forum: General
Topic: How to connect local subnets of VPN clients
Replies: 9
Views: 3106

Re: How to connect local subnets of VPN clients

Route to 192.168.0.0/22 from each client. Or specific /24 route, doesn't matter.
by Anumrak
Fri Apr 13, 2018 2:45 pm
Forum: General
Topic: multi site connections
Replies: 1
Views: 589

Re: multi site connections

You can imagine several private addresses and use ospf over EoIP over IPsec. If network belongs to his company, he can use nets without encryption.
by Anumrak
Fri Apr 13, 2018 1:30 pm
Forum: General
Topic: Firewal rules conditions
Replies: 5
Views: 1134

Re: Firewal rules conditions

You only need to see these rules in config. I think it's "and".
by Anumrak
Fri Apr 13, 2018 12:59 pm
Forum: Forwarding Protocols
Topic: What L2-VPN should be used?
Replies: 11
Views: 2578

Re: What L2-VPN should be used?

No. Then use custom IPsec profile.
by Anumrak
Fri Apr 13, 2018 9:21 am
Forum: Beginner Basics
Topic: Arp Reply only in Bridge...
Replies: 1
Views: 834

Re: Arp Reply only in Bridge...

Use access list in wireless + static dhcp leases with "add arp for dhcp lease" option.
by Anumrak
Thu Apr 12, 2018 4:25 pm
Forum: Beginner Basics
Topic: Make server live
Replies: 7
Views: 975

Re: Make server live

Yahoo! :)
by Anumrak
Thu Apr 12, 2018 3:04 pm
Forum: General
Topic: EoIP over VPN - Help with packet overhead and MSS calculation
Replies: 5
Views: 1887

Re: EoIP over VPN - Help with packet overhead and MSS calculation

What network exactly you want to connect? Layer 2 or 3? If 2, use EoIP + IPsec. If 3 use L2TP + IPsec. Hi Anumrak, Layer 2 mean bridged network and Layer 3 for routed network.. why you prefer to use pppoe over L2TP ( if mean carrying pppoe_client customer to pppoe_server over l2tp )connection on La...
by Anumrak
Thu Apr 12, 2018 3:02 pm
Forum: Beginner Basics
Topic: Static IP to Client over PPPOE
Replies: 7
Views: 6523

Re: Static IP to Client over PPPOE

Maybe you should assign this address in ppp secret user profile as remote address? Hi Anumrak, Thank you for your reply, it was late last night when I wrote this post so I left out the stuff that I did try to solve this. I added the static IP to the ppp secret as remote address and in gives the sta...
by Anumrak
Thu Apr 12, 2018 1:17 pm
Forum: Beginner Basics
Topic: Make server live
Replies: 7
Views: 975

Re: Make server live

Post here routes on router, nat and firewall rules.
by Anumrak
Thu Apr 12, 2018 11:33 am
Forum: Beginner Basics
Topic: How works bridge and gateways?
Replies: 2
Views: 1020

Re: How works bridge and gateways?

Have one project, but it can't use multiple wan address. I've a trouble with it, because I use PCC and two ISPs. At somethimes this project define second rout and reserve second ISPs' WAN address. Can somebody tell how I can block second ISP route on my client in bride interface? Thanks. Simple. Ju...
by Anumrak
Thu Apr 12, 2018 11:28 am
Forum: Beginner Basics
Topic: Make server live
Replies: 7
Views: 975

Re: Make server live

If you want connect to ssh server in LAN you need to add nat dst rule for 22 port. If you want to connect to router, you need accepting rule for 22 port in input chain. But be careful, I recommend you to use source address list.

I meant that packets counter increase - rule works.
by Anumrak
Thu Apr 12, 2018 10:29 am
Forum: General
Topic: mikrotik - pppoe client delay connection [SOLVED]
Replies: 9
Views: 10310

Re: mikrotik - pppoe client delay connection

I have one Mikrotik Routerboard with 6.41.3 firmware. VLAN for multiple areas are configured in Cisco 3560 Gigabit switches and TRUNK is connected with CCR. PPPoE Server with proper settings is configured for each vlan. RB resources are OK, no heating , CPU usage 3 to 4 % max , PING from users PC (...
by Anumrak
Thu Apr 12, 2018 10:18 am
Forum: General
Topic: PPPoE MTU issue
Replies: 14
Views: 18097

Re: PPPoE MTU issue

I was always wondering why the default value is 1480. Isn't best practise 1492? Yeah! Exactly my point! How would there be fragments when the PPPoE Client packs everything into a 1492 large paket? Exactly. Where the additional 12 bytes (1492 - 1480) come from? Please MK guys, enlight us! :) Headers...
by Anumrak
Thu Apr 12, 2018 10:11 am
Forum: Forwarding Protocols
Topic: What L2-VPN should be used?
Replies: 11
Views: 2578

Re: What L2-VPN should be used?

I meant EoIP + IPsec secret. Default is sha1/aes128cbc.
by Anumrak
Thu Apr 12, 2018 10:01 am
Forum: Beginner Basics
Topic: Make server live
Replies: 7
Views: 975

Re: Make server live

1) Why you using 22 port? Ypu allowed only 80;
2) Does counters of your NAT rule ticking?
by Anumrak
Thu Apr 12, 2018 9:56 am
Forum: Beginner Basics
Topic: Static IP to Client over PPPOE
Replies: 7
Views: 6523

Re: Static IP to Client over PPPOE

Maybe you should assign this address in ppp secret user profile as remote address?
by Anumrak
Wed Apr 11, 2018 4:57 pm
Forum: General
Topic: PPPoE MTU issue
Replies: 14
Views: 18097

Re: PPPoE MTU issue

Well, I believe there is some transit node, maybe switch, that drops all frames with mtu higher than 1506 bytes. In bad case, you have 1518(1492+8(pppoe)+18(ethernet + vlan). With 1492 MTU in PPPoE interface (for web surfing, f.e.) PC generating TCP MSS segments with web site with 1452 bytes. Means ...
by Anumrak
Wed Apr 11, 2018 4:20 pm
Forum: Forwarding Protocols
Topic: What L2-VPN should be used?
Replies: 11
Views: 2578

Re: What L2-VPN should be used?

EoIP over IPsec. If optical links between cities would be yours, then VPLS.
by Anumrak
Wed Apr 11, 2018 4:15 pm
Forum: General
Topic: PPPoE MTU issue
Replies: 14
Views: 18097

Re: PPPoE MTU issue

so I take it 1492 is good for general PPPoE on it's own? why would fragmentation cause issue for some CPE to drop PPPoE session?
So, maybe it's not fragmentation? Maybe it's enabled compression it pppoe profile? It is drop PPPoE connection with tense traffic.
by Anumrak
Wed Apr 11, 2018 4:13 pm
Forum: General
Topic: EoIP over VPN - Help with packet overhead and MSS calculation
Replies: 5
Views: 1887

Re: EoIP over VPN - Help with packet overhead and MSS calculation

What network exactly you want to connect? Layer 2 or 3? If 2, use EoIP + IPsec. If 3 use L2TP + IPsec.
by Anumrak
Wed Apr 11, 2018 4:11 pm
Forum: Forwarding Protocols
Topic: PPTP VPN working, file sharing not
Replies: 4
Views: 2504

Re: PPTP VPN working, file sharing not

Anyway it's firewall job. Search for rules in PC or in router.
by Anumrak
Wed Apr 11, 2018 4:08 pm
Forum: General
Topic: PPPoE MTU issue
Replies: 14
Views: 18097

Re: PPPoE MTU issue

1480 bytes in PPPoE tunnel came from extra overheads in frames, if want to use pppoe over vpls or over eoip or all these over l2tp/ipsec :)
by Anumrak
Mon Apr 09, 2018 5:33 pm
Forum: Forwarding Protocols
Topic: announce private ip over bgp or ospf
Replies: 2
Views: 1272

Re: announce private ip over bgp or ospf

Create new address family and vrf with new router distinguisher and route target for export and import through mp-bgp, attache interfaces to this vrf and redistribute these neworks into iBGP :) At all the route though all bgp neighbores your new RD must be in routing filters as accepted.
by Anumrak
Mon Apr 09, 2018 5:29 pm
Forum: General
Topic: Forward Drop invalid | Broke my IP routing?
Replies: 4
Views: 2371

Re: Forward Drop invalid | Broke my IP routing?

The counters ticking on this rule? If yes, check firewall filters rules with source addresses, static arp records and mangle rules. Put config here. Or maybe you'll find a mistake by yourself :)
by Anumrak
Mon Apr 09, 2018 5:20 pm
Forum: General
Topic: High latency [SOLVED]
Replies: 3
Views: 5341

Re: High latency [SOLVED]

Why your ttl is changing? If network would be at 1 hop, ttl would be 64 and won't be routable. Make traceroute to gateway, check every interface on every hop, check crc errors on interfaces. If you have fiber cables, check Tx/Rx optical attenuation, if it's lower or higher interface threshold, chang...
by Anumrak
Mon Apr 09, 2018 4:54 pm
Forum: Beginner Basics
Topic: Hide HS gateway
Replies: 5
Views: 1580

Re: Hide HS gateway

Or you may use DHCP server in ROS in option "Add arp for dhcp lease" and set terminating interface with ARP reply-only. You'll got static dhcp leases and unknown mac addresses won't connect to you gateway.
by Anumrak
Fri Apr 06, 2018 5:01 pm
Forum: Beginner Basics
Topic: .mynetname.net
Replies: 6
Views: 20148

Re: .mynetname.net

I think you can't, because it working not on config level, but on ROS level. So you can use IP updating from other dns hoster based on script.
by Anumrak
Fri Apr 06, 2018 4:29 pm
Forum: Forwarding Protocols
Topic: Firewall rules for LDP (MPLS) [SOLVED]
Replies: 6
Views: 3740

Re: Firewall rules for LDP (MPLS) [SOLVED]

Hi Anumrak, I don't quite follow... Du you suggest that i narrow down my firewall rules by selecting an interface? I have other routers conneted to all interfaces of this device, and will want LDP to work for all of them. I have the allow TCP 646 output firewall rule on top of my list, and the coun...
by Anumrak
Fri Apr 06, 2018 10:45 am
Forum: General
Topic: Problem critical PPPoE server (ppp/active connections) High CPU!!!
Replies: 3
Views: 2039

Re: Problem critical PPPoE server (ppp/active connections) High CPU!!!

I think cause of this is using NAT Masq rule instead of src-nat. Masq rule need to flush all relative connections when link fails. And you have it 2k.
by Anumrak
Fri Apr 06, 2018 10:07 am
Forum: Forwarding Protocols
Topic: Firewall rules for LDP (MPLS) [SOLVED]
Replies: 6
Views: 3740

Re: Firewall rules for LDP (MPLS) [SOLVED]

Try to select the output and input interfaces in rules.
by Anumrak
Thu Apr 05, 2018 11:00 am
Forum: General
Topic: A little question about VPN work
Replies: 1
Views: 376

Re: A little question about VPN work

Imagine that the useful data is you. And VPN is an underground tunnel. In a normal situation, you can not cross the road, because it will forbid you to traffic rules and an impassable number of different cars. But if you use an underground tunnel, you'll end up on the other side of the street and no...
by Anumrak
Thu Apr 05, 2018 10:43 am
Forum: General
Topic: Sniffer Tool
Replies: 3
Views: 918

Re: Sniffer Tool

Before.
by Anumrak
Thu Apr 05, 2018 10:37 am
Forum: Beginner Basics
Topic: Hide HS gateway
Replies: 5
Views: 1580

Re: Hide HS gateway

Use HSRP/VRRP. It will create virtual mac-address of the virtual gateway over real net.
by Anumrak
Thu Apr 05, 2018 10:34 am
Forum: Beginner Basics
Topic: Problem to access routerboard via browser from remote host
Replies: 11
Views: 3522

Re: Problem to access routerboard via browser from remote host

Uhhh.... Guys. Rule is correct. If you google the range of 100.100.100.101 you'll find network 100.64.0.0/10. Means 100.64.0.0 - 100.127.255.255. It is Carrier Grade NAT. User is behind NAT of his ISP. Means that global IP in Internet is not 100.100.100.101. It's defferent. So, he can't do port forw...
by Anumrak
Tue Apr 03, 2018 11:35 am
Forum: General
Topic: IPSec Routing Issue
Replies: 3
Views: 602

Re: IPSec Routing Issue

You should create static routes to both these networks via ipsec tunnel interfaces or create masq nat rule on one side. Print here your main routing table and firewall nat.
by Anumrak
Tue Apr 03, 2018 10:28 am
Forum: General
Topic: VPLS fragmentation
Replies: 3
Views: 1073

Re: VPLS fragmentation

Ping with "don't fragment" bit.
by Anumrak
Tue Apr 03, 2018 10:08 am
Forum: Forwarding Protocols
Topic: l2tp Server behind NAT router
Replies: 3
Views: 5059

Re: l2tp Server behind NAT router

In theory, there must be NAT rule on border and correct firewall rules on second router-server. With default rules on second router(establish, related connections), there must be no problems, because initiator of first packets is client.
by Anumrak
Tue Apr 03, 2018 9:48 am
Forum: General
Topic: Online game issue [SOLVED]
Replies: 11
Views: 3177

Re: Online game issue [SOLVED]

I have no need for schemes like yours, so there are no scripts themselves. Try searching for the answer here: viewforum.php?f=9
by Anumrak
Tue Apr 03, 2018 9:44 am
Forum: Beginner Basics
Topic: NAT not passing source ip address
Replies: 3
Views: 717

Re: NAT not passing source ip address

Make a masquerade rule with defined out-interface.

If it won'thelp, post here your config from terminal.
by Anumrak
Mon Apr 02, 2018 4:04 pm
Forum: Forwarding Protocols
Topic: Strange problems on port forwarding [syn sent]
Replies: 1
Views: 2204

Re: Strange problems on port forwarding [syn sent]

What MTU do you have on tunnel interfaces?
by Anumrak
Mon Apr 02, 2018 3:52 pm
Forum: General
Topic: Online game issue [SOLVED]
Replies: 11
Views: 3177

Re: Online game issue [SOLVED]

Dear Shavnary Better & Long Lasting solution is to provide Real Ip / Public IP to those users whom are getting issue.. Use "Proxy-Arp" on your WAN Interface.. then release static Real IP to your these users. Smile Kashif Khan ARP table will be filled with entries for subscribers as lo...
by Anumrak
Mon Apr 02, 2018 2:52 pm
Forum: Beginner Basics
Topic: BLock IP camera output connection
Replies: 10
Views: 3967

Re: BLock IP camera output connection

Firewall forward drop rule with source and destination. But you better google about these connections, maybe it needs these cameras.
by Anumrak
Mon Apr 02, 2018 2:49 pm
Forum: General
Topic: Online game issue [SOLVED]
Replies: 11
Views: 3177

Re: Online game issue [SOLVED]

Dear Shavnary Better & Long Lasting solution is to provide Real Ip / Public IP to those users whom are getting issue.. Use "Proxy-Arp" on your WAN Interface.. then release static Real IP to your these users. Smile Kashif Khan ARP table will be filled with entries for subscribers as lo...
by Anumrak
Mon Apr 02, 2018 11:47 am
Forum: Forwarding Protocols
Topic: MPLS/VPLS hang
Replies: 2
Views: 1511

Re: MPLS/VPLS hang

Try to use ldp signaling, not bgp.
by Anumrak
Mon Apr 02, 2018 11:43 am
Forum: Forwarding Protocols
Topic: Static IP to Client
Replies: 3
Views: 1502

Re: Static IP to Client

Just set pppoe server up, assign local address as public IP on your side, remote ip is ip you want to give to user. Other BRAS stuff is more complex, you should google it.
by Anumrak
Mon Apr 02, 2018 11:35 am
Forum: General
Topic: Splitting routes in the same (10.) net.
Replies: 2
Views: 554

Re: Splitting routes in the same (10.) net.

This is the problem I could use some help on. Both routes below are provided by dhcp servers. Route zero (0) is the only route to the ( 10.0.0.0/24 ) network. Route one (1) is the only path to non ten (10) net addresses. How do I setup the routes so all ten (10) net addresses %99.99999 with the exc...
by Anumrak
Mon Apr 02, 2018 11:24 am
Forum: General
Topic: Online game issue [SOLVED]
Replies: 11
Views: 3177

Re: Online game issue [SOLVED]

Better solution is to sell static IP's forwarded to requested users by phone call from them or from your web site script. Biggest providers living just like that.
by Anumrak
Mon Apr 02, 2018 11:21 am
Forum: General
Topic: PPPoE MTU issue
Replies: 14
Views: 18097

Re: PPPoE MTU issue

Your PPPoE MTU is 1500
Then you maximum ICMP payload is 1472(1500-20(IP header)-8(ICMP Header).
By default PPPoE 1480 bytes and maximum ICMP payload is 1452 bytes.
by Anumrak
Mon Apr 02, 2018 10:56 am
Forum: General
Topic: Online game issue [SOLVED]
Replies: 11
Views: 3177

Re: Online game issue [SOLVED]

Issue of your clients in NAT technology. All these applications need opened ports right in themselves. They don't care on your provider's NAT. They think they have global IP in order outside servers can interact with them. You have to do static NAT 1:1 to these users, or give them public routable IP.
by Anumrak
Mon Apr 02, 2018 10:43 am
Forum: Beginner Basics
Topic: NAT not passing source ip address
Replies: 3
Views: 717

Re: NAT not passing source ip address

You need the correct NAT rule. Please post a simple scheme to be more clear.
by Anumrak
Fri Mar 23, 2018 11:48 am
Forum: Forwarding Protocols
Topic: Increase MTU from 1526 to 1600
Replies: 6
Views: 2370

Re: Increase MTU from 1526 to 1600

vpls is established, i can ping with 1500, and there is one vlan interface on this vpls tunnel, i have increased advertise mtu to 1526, and also MTU to 1526 to see if it allows bigger packets, but it would fragment. and i have put IP address on both ends to test. Can you ping with 1500 payload with...
by Anumrak
Thu Mar 22, 2018 1:50 pm
Forum: Beginner Basics
Topic: Recommendation for vlan routing [SOLVED]
Replies: 5
Views: 1210

Re: Recommendation for vlan routing [SOLVED]

Any soho router.
by Anumrak
Thu Mar 22, 2018 1:49 pm
Forum: Beginner Basics
Topic: Port forwarding for multiple web interfaces
Replies: 18
Views: 6511

Re: Port forwarding for multiple web interfaces

You can set up different ports on WAN side being forwarded to different internal IP addresses (regardless of port) in the following manner: /ip firewall nat add action=dst-nat chain=dstnat comment="inbound port 80 goes to LAN host 1 port 80" dst-port=80 \ in-interface="your WAN inter...
by Anumrak
Thu Mar 22, 2018 1:40 pm
Forum: Beginner Basics
Topic: Special route to the internet for specific Ports/IPs/MACs
Replies: 9
Views: 1269

Re: Special route to the internet for specific Ports/IPs/MACs

Just make static routing to exact destinations?
by Anumrak
Wed Mar 21, 2018 4:11 pm
Forum: Forwarding Protocols
Topic: Increase MTU from 1526 to 1600
Replies: 6
Views: 2370

Re: Increase MTU from 1526 to 1600

Thank you for the response, but how can i test 1508 on VPLS, i tried pinging from a Mikrotik connected to one end of VPLS circuit to an ip on other end, but it cannot ping. Does vpls tunnel is tagged with some vlan? Or it's just bridged with interface bridge with IP address? Does vpls tunnel is est...
by Anumrak
Wed Mar 21, 2018 9:38 am
Forum: Beginner Basics
Topic: Block web site with Firewall
Replies: 10
Views: 25288

Re: Block web site with Firewall

Post here your firewall config. You should block them just on layer 3.
by Anumrak
Mon Mar 19, 2018 2:20 pm
Forum: General
Topic: L2 MTU sizes - STILL confused
Replies: 12
Views: 25062

Re: L2 MTU sizes - STILL confused

Additionally i'm a bit confused about the MPLS MTU size needing to be changed at all? We currently have 1500 byte VPLS interfaces working just fine with the MPLS MTU size set to the default of 1508 (L2MTU at 1600) MPLS MTU have to include vpls header(one more mpls header), that's why mpls mtu bigge...
by Anumrak
Mon Mar 19, 2018 12:25 pm
Forum: Beginner Basics
Topic: VPN over VPN - beginner's question [SOLVED]
Replies: 4
Views: 1546

Re: VPN over VPN - beginner's question [SOLVED]

As you can see, 0.0.0.0/0 go through L2TP, because of a distance. 0 is better than 1. You need put in pptp client "add default gateway" or make static routing to resourses in net which you want to be reachable via pptp client. That's it.
by Anumrak
Wed Mar 14, 2018 11:30 am
Forum: Beginner Basics
Topic: ipsec router behind microtik on same ip address
Replies: 1
Views: 665

Re: ipsec router behind microtik on same ip address

Of course. Through destination nat.
by Anumrak
Wed Mar 14, 2018 11:02 am
Forum: General
Topic: L2 MTU sizes - STILL confused
Replies: 12
Views: 25062

Re: L2 MTU sizes - STILL confused

I'm of the understanding that MPLS needs 2 labels if not directly connected? so 8 byte overhead for MPLS not 4 is that correct? And in that case, does VPLS replace one of the labels (8 byte overhead), or add to it (12 bytes)? The reason I need to know exact MTU is we have multiple vendors for radio...
by Anumrak
Wed Mar 14, 2018 10:59 am
Forum: General
Topic: L2 MTU sizes - STILL confused
Replies: 12
Views: 25062

Re: L2 MTU sizes - STILL confused

Additionally i'm a bit confused about the MPLS MTU size needing to be changed at all? We currently have 1500 byte VPLS interfaces working just fine with the MPLS MTU size set to the default of 1508 (L2MTU at 1600) MPLS MTU have to include vpls header(one more mpls header), that's why mpls mtu bigge...
by Anumrak
Wed Mar 14, 2018 10:32 am
Forum: General
Topic: L2 MTU sizes - STILL confused
Replies: 12
Views: 25062

Re: L2 MTU sizes - STILL confused

Normal mpls header is 4 bytes. Two mpls headers here recognized as vpls(transport and client labels). L2MTU is physical interface mtu. Vlan header here on picture is 802.1Q header which is 4 bytes, that's correct. What is not correct, that untagged mpls explained here with vlan header, what is illog...
by Anumrak
Wed Mar 14, 2018 9:30 am
Forum: Forwarding Protocols
Topic: MTU VLAN
Replies: 1
Views: 1161

Re: MTU VLAN

Your vlan are encapsulated in mpls, and mpls will be encapsed in ethernet. So physical interface MTU must count mpls header, 802.1Q header and so on. Every next logical interface MTU after physical must be lower than previous, because previous carry on headers of following.
by Anumrak
Wed Mar 14, 2018 8:38 am
Forum: Forwarding Protocols
Topic: Increase MTU from 1526 to 1600
Replies: 6
Views: 2370

Re: Increase MTU from 1526 to 1600

Whatever your set vpls mtu, mpls mtu must be higher by 4 bytes.
by Anumrak
Wed Mar 14, 2018 8:30 am
Forum: Forwarding Protocols
Topic: PPPoE over MPLS - VPLS, Question about Actual MTU/ L2MTU
Replies: 6
Views: 3102

Re: PPPoE over MPLS - VPLS, Question about Actual MTU/ L2MTU

I meant that if PPPoE interface set on 1480 MTU that means this interface terminates PPPoE headers, but interface itself do not count it header size. i see. IP headers =/= L2 frame headers, and in case of PPPoE it's a frame header. therefore it is perfectly logical for ROS to not to take them into ...
by Anumrak
Tue Mar 13, 2018 4:32 pm
Forum: Forwarding Protocols
Topic: PPPoE over MPLS - VPLS, Question about Actual MTU/ L2MTU
Replies: 6
Views: 3102

Re: PPPoE over MPLS - VPLS, Question about Actual MTU/ L2MTU

MTU is IP MTU without IP header Correct me if I wrong :) you are. MTU (or IP MTU) is the packet size, e.g. if it is for IP, it consists of the IP/IPv6 header and the IP payload. MPLS MTU is the frame size, where the frame consists of one or more MPLS labels (4 bytes each) and the MPLS payload, whic...
by Anumrak
Tue Mar 13, 2018 4:15 pm
Forum: General
Topic: CPU usage 100%
Replies: 3
Views: 4497

Re: CPU usage 100%

Also check layer 7 firewall action. It better be off.
by Anumrak
Tue Mar 13, 2018 4:12 pm
Forum: General
Topic: VLAN transparency in Mikrotik
Replies: 2
Views: 1596

Re: VLAN transparency in Mikrotik

Maybe EoIP tunnels between routers? And bridge ports and vlans in routers. If you have MPLS Core, then better would be VPLS tunnels.
by Anumrak
Tue Mar 13, 2018 4:00 pm
Forum: Beginner Basics
Topic: No internet router Mikrotik
Replies: 13
Views: 9476

Re: No internet router Mikrotik

easy way: download the package, upload to your router (open file, drag the file to it) and reboot all master port settings will be replaced with bridge. so if you have any, change it to bridge before the upgrade. Thanks, how could I check if I have master port? Open ethernet interface and you'll fi...
by Anumrak
Tue Mar 13, 2018 3:57 pm
Forum: Beginner Basics
Topic: Two different network ?
Replies: 5
Views: 1282

Re: Two different network ?

Better post a scheme :)
by Anumrak
Tue Mar 13, 2018 3:48 pm
Forum: Beginner Basics
Topic: VPN over VPN - beginner's question [SOLVED]
Replies: 4
Views: 1546

Re: VPN over VPN - beginner's question [SOLVED]

After both connections, print here your routing table.
by Anumrak
Wed Mar 07, 2018 1:13 pm
Forum: Forwarding Protocols
Topic: PPPoE over MPLS - VPLS, Question about Actual MTU/ L2MTU
Replies: 6
Views: 3102

Re: PPPoE over MPLS - VPLS, Question about Actual MTU/ L2MTU

L2MTU is ethernet MTU without ethernet header, MTU is IP MTU without IP header, Actual MTU is MTU that is set right now on interface. Full frame MTU is ethernet frame MTU with all headers above itself without ethernet header(14 bytes). https://wiki.mikrotik.com/wiki/Manual%3AMaximum_Transmission_Uni...
by Anumrak
Wed Mar 07, 2018 9:11 am
Forum: Beginner Basics
Topic: Two different network ?
Replies: 5
Views: 1282

Re: Two different network ?

Thanks, But let say we have two different network like 10.1.101.1 and 192.168.20.1, how can I bridge these 2 networks to be accessible. From 10.1.101 to 192.168.20 and revers. Thanks Without router, you can't merge them, it's illogically. Bridge can merge layer 2 segment in same network, not layer ...
by Anumrak
Tue Mar 06, 2018 4:00 pm
Forum: Beginner Basics
Topic: how to use two interfaces in trunk
Replies: 3
Views: 865

Re: how to use two interfaces in trunk

I have a RouterOS as 3 interfaces, how do I use them in trunk?
Create interfaces vlan and assign ethernet interface inside them. After you bridge this vlan in one bridge, these ports will forward all trafic with these vlans.
by Anumrak
Tue Mar 06, 2018 12:11 pm
Forum: Beginner Basics
Topic: Two different network ?
Replies: 5
Views: 1282

Re: Two different network ?

I want to use my router to bridge 2 networks that I have, 192.168.20.1 and 192.168.25.1 I need to joint these into the same network, I have many camera on .20 to be accessible from .25, cam you help me to know how to program the router to link these to network together Join these /24 nets in one 19...
by Anumrak
Mon Mar 05, 2018 2:25 pm
Forum: Beginner Basics
Topic: 2 Separate Vlan / Subnets on one Lan.
Replies: 4
Views: 2485

Re: 2 Separate Vlan / Subnets on one Lan.

Hi Guys i have 2 networks 192.168.23.x and one 192.168.11.x that run on separate lan's but come together at one switch that links them. What are the options to have these incorporated into one lan while still being able to control traffic between the 2 different networks. Should Vlan work or Differ...
by Anumrak
Mon Mar 05, 2018 2:01 pm
Forum: General
Topic: Bridge - Use local Gateway
Replies: 2
Views: 812

Re: Bridge - Use local Gateway

Make a static routing in office 2. Specific routes for duty needs add to office 1 and 0.0.0.0/0 add to your ISP in office 2.
by Anumrak
Mon Mar 05, 2018 12:44 pm
Forum: General
Topic: VLAN and MTU Problems
Replies: 6
Views: 7925

Re: VLAN and MTU Problems

Hello, i have mikrotik in x86 pc and recently i have created 6 vlan in my mikrotik. my main LAN have 1500 Max MTU and my every vlan also have MTU 1500 and all vlan have PPPoE Server in PPPoE Server MTU is 1480, But some of modem can not connect to pppoe server, i am confuse about this MTU is these ...
by Anumrak
Mon Mar 05, 2018 9:01 am
Forum: Beginner Basics
Topic: Untagged vlan [SOLVED]
Replies: 23
Views: 27779

Re: Untagged vlan [SOLVED]

Not all equipment have to support 802.1Q traffic. Or these users do not have to think how it works or manage it.
by Anumrak
Fri Mar 02, 2018 10:38 am
Forum: Forwarding Protocols
Topic: BGP protocol
Replies: 2
Views: 1348

Re: BGP protocol

It's signaling other BGP neighbors about networks with some rules for them. Also BGP is path vector protocol, and it's not necessary to learn all topology like OSPF/ISIS. In Internet we don't need it. BGP can pass through many "families" of routes like l2vpn, l3vpn, ipv4 and ipv6. Also you...
by Anumrak
Thu Mar 01, 2018 2:26 pm
Forum: Beginner Basics
Topic: Untagged vlan [SOLVED]
Replies: 23
Views: 27779

Re: Untagged vlan [SOLVED]

Hello, ok I tried that did something and now they say that is not done that way, I need to use bridges and VLANs, I understand VLANs good in cisco but here no luck, can someone explain me the term "untagged VLAN " how can I make VLAN 100 become an "untagged VLAN" ? Just can't wr...
by Anumrak
Tue Jan 23, 2018 11:21 am
Forum: Beginner Basics
Topic: Firewall e Nat Rule - FTP Upload
Replies: 6
Views: 1427

Re: Firewall e Nat Rule - FTP Upload

I did a search on this forum, does this topic answer your question?
viewtopic.php?t=61450
No...i need that an internal IP can upload file, wich rule on firewall i have to make or configure?
Just create port forwarding rule in NAT, that's all.
by Anumrak
Tue Jan 23, 2018 10:37 am
Forum: General
Topic: how to nat public ip subnet with mikrotik
Replies: 6
Views: 2998

Re: how to nat public ip subnet with mikrotik

thank you guys for your comments. at first i would like to explain why i need to nat these ip instead of assign them directly to the servers i have a local hosted website consists of three servers on my lan and because hi speed internet connection is very expensive in my country i thought about sub...
by Anumrak
Tue Jan 23, 2018 9:48 am
Forum: General
Topic: Firewall filter after update blocks my l2tp [SOLVED]
Replies: 8
Views: 6211

Re: Firewall filter after update blocks my l2tp [SOLVED]

Don't know about this rule, probably it's a bug, depends of ROS version. About ssh attack: assign defined IP addresses in IP - Services and System - Users. Or use nonstandart port.
by Anumrak
Mon Jan 22, 2018 4:19 pm
Forum: Forwarding Protocols
Topic: BGP VRF Route Imports
Replies: 3
Views: 1689

Re: BGP VRF Route Imports

by Anumrak
Mon Jan 22, 2018 4:11 pm
Forum: Forwarding Protocols
Topic: Unable to add instance and area to OSPF interface
Replies: 4
Views: 1361

Re: Unable to add instance and area to OSPF interface

When you have multiarea ospf, you have to have abr by adding networks in different areas.
by Anumrak
Mon Jan 22, 2018 4:07 pm
Forum: General
Topic: How to communicate two networks one device?
Replies: 8
Views: 2552

Re: How to communicate two networks one device?

One question. I saw your firewall configuration. If I don't configure an input or an output interface then this firewall rule works bi-directional?


regards
Yes.
by Anumrak
Mon Jan 22, 2018 4:04 pm
Forum: General
Topic: dhcp. info dhcp assigned
Replies: 2
Views: 633

Re: dhcp. info dhcp assigned

I can see here normal dhcp process. What exactly error do you mean?
by Anumrak
Mon Jan 22, 2018 3:48 pm
Forum: General
Topic: how to nat public ip subnet with mikrotik
Replies: 6
Views: 2998

Re: how to nat public ip subnet with mikrotik

Forget about matrix. Your gateway is IP on your ISP side. Mask is a subnet mask for your public network 1.1.1.0/29. Your first public ip you can use for yourself is 1.1.1.2, the last one is 1.1.1.6. You have IPs: 1.1.1.2, 1.1.1.3, 1.1.1.4, 1.1.1.5, 1.1.1.6. The WAN IP you can use for connection to t...
by Anumrak
Mon Jan 22, 2018 3:42 pm
Forum: Beginner Basics
Topic: I have no internet connection help!!!
Replies: 10
Views: 1221

Re: I have no internet connection help!!!

Use just static servers: 8.8.8.8 and 8.8.4.4. It may be as simple as that, but if these are added as part of dhcp config, it won't do anything, as this means that uplink is down You don't have to add them as a part of dhcp config. Just assign them statically in DNS config and they will be in dhcp c...
by Anumrak
Mon Jan 22, 2018 12:34 pm
Forum: Beginner Basics
Topic: I have no internet connection help!!!
Replies: 10
Views: 1221

Re: I have no internet connection help!!!

Use just static servers: 8.8.8.8 and 8.8.4.4. It may be as simple as that, but if these are added as part of dhcp config, it won't do anything, as this means that uplink is down You don't have to add them as a part of dhcp config. Just assign them statically in DNS config and they will be in dhcp c...
by Anumrak
Mon Jan 22, 2018 11:23 am
Forum: Beginner Basics
Topic: I have no internet connection help!!!
Replies: 10
Views: 1221

Re: I have no internet connection help!!!

Use just static servers: 8.8.8.8 and 8.8.4.4.
by Anumrak
Fri Jan 19, 2018 12:06 pm
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

So, answer is obvious. Some software blocks icmp requests or replies. Turn off your firewalls and so on o pc 1 and 2. Could you please help me with the commands to forward packet between the router interfaces ..?? Thanks in advance, The packets are forwarded. Point D drop it for some reason I do no...
by Anumrak
Fri Jan 19, 2018 11:25 am
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

So, answer is obvious. Some software blocks icmp requests or replies. Turn off your firewalls and so on o pc 1 and 2. Could you please help me with the commands to forward packet between the router interfaces ..?? Thanks in advance, The packets are forwarded. Point D drop it for some reason I do no...
by Anumrak
Thu Jan 18, 2018 3:58 pm
Forum: Forwarding Protocols
Topic: ❗❓ MPLS MTU Problem , more than 1500 byte get packet fragmentation error
Replies: 10
Views: 4851

Re: ❗❓ MPLS MTU Problem , more than 1500 byte get packet fragmentation error

Of course only on which you using.
Now its same as 1580 L2MTU on all interfaces on both routers .
change back MPLS interface MTU to 1550 and VPLS L2MTU into 1508 .
... But still have the first problem
What exactly error do you have? Can you paste config export and screenshot?
by Anumrak
Thu Jan 18, 2018 3:39 pm
Forum: Forwarding Protocols
Topic: ❗❓ MPLS MTU Problem , more than 1500 byte get packet fragmentation error
Replies: 10
Views: 4851

Re: ❗❓ MPLS MTU Problem , more than 1500 byte get packet fragmentation error

Make a symmetric MTU on both routers on all interface, f.e. L2MTU. Are they all symmetric?
Do I need this on all interfaces ? even not used by this Point to Point MPLS/VPLS ?
Of course only on which you using.
by Anumrak
Thu Jan 18, 2018 2:00 pm
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

So, answer is obvious. Some software blocks icmp requests or replies. Turn off your firewalls and so on o pc 1 and 2.
by Anumrak
Thu Jan 18, 2018 1:48 pm
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

Please correct me if am wrong with the commands: ip firewall filter add chain=forward action=accept in-interface=ether1 ip firewall filter add chain=forward action=accept in-interface=ether2 (ether1 and ether2 are the two interfaces of the Router) I have added this . still not working. Thanks for t...
by Anumrak
Thu Jan 18, 2018 1:23 pm
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

when i ping from host 1 to host 2 , in arp table of router i could see the ips of both the hosts.. when i traceroute from host1 , (traceroute 192.168.110.3 ) it is reaching only 192.168.12.6 . Seems like packet forward is not happening inside router. Meanwhile i will chek whether firewall is enable...
by Anumrak
Thu Jan 18, 2018 1:12 pm
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

Delete firewall masq rule and disable firewalls on host 1 and 2. Is there an arp records in MikroTik router from these hosts? What traceroute says you? when i ping from host 1 to host 2 , in arp table of router i could see the ips of both the hosts.. when i traceroute from host1 , (traceroute 192.1...
by Anumrak
Thu Jan 18, 2018 12:35 pm
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

Delete firewall masq rule and disable firewalls on host 1 and 2. Is there an arp records in MikroTik router from these hosts? What traceroute says you? when i ping from host 1 to host 2 , in arp table of router i could see the ips of both the hosts.. when i traceroute from host1 , (traceroute 192.1...
by Anumrak
Thu Jan 18, 2018 12:06 pm
Forum: Forwarding Protocols
Topic: ❗❓ MPLS MTU Problem , more than 1500 byte get packet fragmentation error
Replies: 10
Views: 4851

Re: ❗❓ MPLS MTU Problem , more than 1500 byte get packet fragmentation error

Make a symmetric MTU on both routers on all interface, f.e. L2MTU. Are they all symmetric?
by Anumrak
Thu Jan 18, 2018 11:55 am
Forum: General
Topic: Routing between two Mikrotik routers is not working [SOLVED]
Replies: 22
Views: 4559

Re: Routing between two Mikrotik routers is not working [SOLVED]

Delete firewall masq rule and disable firewalls on host 1 and 2. Is there an arp records in MikroTik router from these hosts? What traceroute says you?
by Anumrak
Thu Jan 18, 2018 11:48 am
Forum: Beginner Basics
Topic: How to route WAN to DMZ
Replies: 3
Views: 1076

Re: How to route WAN to DMZ

Do you want to get access to router itself or the LAN behind the router?
by Anumrak
Tue Jan 16, 2018 11:22 am
Forum: General
Topic: HAIRPIN HAT not working [SOLVED]
Replies: 33
Views: 7172

Re: HAIRPIN HAT not working [SOLVED]

You have TCP Reset segments. They transmitted because of wrong or not existing connection. Try to make hairpining to something else in your LAN.
by Anumrak
Mon Jan 15, 2018 2:12 pm
Forum: General
Topic: HAIRPIN HAT not working [SOLVED]
Replies: 33
Views: 7172

Re: HAIRPIN HAT not working [SOLVED]

What is the device 192.168.0.52? This is the server which I want to reach in local network. i want to reach to local server (192.168.0.52) in local network (my local ip: 192.168.0.195) with external ip (1.1.1.10). (My external IP is static) When i try reach from out network (e.g. 2.2.2.2) to (1.1.1...
by Anumrak
Mon Jan 15, 2018 1:21 pm
Forum: General
Topic: HAIRPIN HAT not working [SOLVED]
Replies: 33
Views: 7172

Re: HAIRPIN HAT not working [SOLVED]

What is the device 192.168.0.52?
by Anumrak
Mon Jan 15, 2018 10:14 am
Forum: General
Topic: HAIRPIN HAT not working [SOLVED]
Replies: 33
Views: 7172

Re: HAIRPIN HAT not working [SOLVED]

add action=src-nat chain=srcnat out-interface=Local protocol=tcp src-address=192.168.0.52 src-port=629 to-addresses=1.1.1.10 to-ports=629 Wrong idea. You need only 4 NAT rules: 1) Classic masquerade for your local network in order to go to Internet; 2) Destination NAT IN rule for your provider inter...
by Anumrak
Fri Jan 12, 2018 10:37 am
Forum: Beginner Basics
Topic: Help with pptp
Replies: 1
Views: 538

Re: Help with pptp

Check your firewall rules and IP settings, from which IPs you allowed to connect to you router. Please don't post config here.