/tool/torch
=interface=ether1
/tool/torch
=interface=ether1
=src-address=0.0.0.0/0
/ip firewall mangle add chain=prerouting action=change-ttl new-ttl=increment:1
[admin@TestPlace] > ip fi man add new-priority=
NewPriority ::= NewPriority | NewPriority
NewPriority ::= 0..63 (integer number)
NewPriority ::= from-dscp | from-dscp-high-3-bits | from-ingress
I'd rather say, removed, not fixed:*) ethernet - fixed interface speed reporting for x86 in log after reboot or if "disable-running-check=yes";
17:51:27 interface,info ether3 link up
17:51:27 interface,info ether6 link up
17:51:27 interface,info ether7 link up
in other words, it will search only interface/connected (by the way, which of two exactly? tech guys, we need your knowledge!) routes in routing table, not all routes? thankslocal proxy-arp normally means: router will reply to ARP for hosts it can directly reach, not for hosts it can route to.
when it will be in the manual? need at least a short description...*) arp - added local-proxy-arp feature;
and what happens with ARP table when you do that? we're not telepathistsThe problem only occur when i connect DVR on one of the interface on Mikrotik
check IP -> ARP when problem appears
originally it was something like "I'm 99,999% sure you will be fine with 640k"I'm 99,999% sure you will be fine with 500k
what does it mean? try to plug 220V and repeatWhat do you do if this doesn't work?
need more details. how do you mark necessary traffic, what do you expect and what goes wrong?its not work !
I don't have this column so new users won't see it too, I thinkWinBox still show us in many paces the "zombie" tabs like comment
Please remove it because all new users try use the comment even from terminal.
/system/script/run
=.id=script1
!done
=ret=Hello, I'm a script! And this is my output
--- mikrotik.Read();
+++ List<string> test2 = mikrotik.Read();
mikrotik.Send("/ip/hotspot/user/set");
mikrotik.Send("=comment=killed");
mikrotik.Send("/ip/hotspot/user/set", false);
mikrotik.Send("=comment=killed", false);
8.8.8.8 is host1what mean host1 and host2?
how can i make it ping to 8.8.8.8 for example?
just add one more Radius Server entry with the same settings1) having a secondary (or multiple) IP address in the event the first IP becomes unavailable or times out.
RouterOS X86: Show R before interface name of interface list but this interface not connected with any device, why?
/interface ethernet set etherX disable-running-check=no
what do you use them for?Some time ago the possibility to change dynamic simple queues was removed, so my script which adds "packet-parks" parameter stopped working.
as it was said, just add eoipv6 tunnel, not eoip:and what about the IPv6 EoIP?
[admin@TestPlace] /interface eoipv6> add remote-address=2a00:1028:8386:8c5e::1 tunnel-id=0
maybe that's the reason? try to change this to default setting (vlan-mode=fallback), for example/interface ethernet switch port
set 0 vlan-mode=disabled
set 1 vlan-mode=disabled
set 2 vlan-mode=disabled
set 3 vlan-mode=disabled
set 4 vlan-mode=disabled
did what?
do you see both MAC addresses under Bridge Hosts on 450?
try to ping both 192.168.1.1 and 192.168.1.5 from 450
what about first manual checking and then completely disabling port on link down (when some intruder tries to install transparent bridge)?Without crypto there is no way to protect against a transparent bridge sniffing everything.
are you sure that iph_nat_tbl addresses are directly accessible via ether1, without some gateway?../ip route
add comment="iph route" distance=1 gateway=ether1 routing-mark=iph_route
it is available even without scripting: http://wiki.mikrotik.com/wiki/Advanced_ ... _ScriptingI know that currently this can be achieved by using Netwatch and some scripting but it would be much easier if it were available directly on the route's properties.
http://www.mikrotik.com/consultantswhere can i find a freelancer to seutup this for me?
And what if I need infinite timeout?Address lists can still be dynamic. Creating an item with a timeout makes it dynamic. it really should not be a big issue.
also, why not just "/interface set interfacename xxxx"?Isn't it much better and safer to use /interface set [find name="interfacename"] xxxx ?
[admin@BR] > :put [ /sys reso get uptime ]
52w1d18:09:13
[admin@BR] > :put ([ /int get ether3 tx-byte ] / 1024 / 1024 / 1024 / 1024)
9456
please check dynamic entries with domain name. they count down to 0s and stay here foreverdomain lists for firewall
the same thing here. Normis, could you add changes to the top or bottom of the changelist, not in the middle?I must have missed the announcement of domain lists
/ip fi nat add chain=dstnat in-interface=lan protocol=tcp dst-port=80 action=dst-nat to-addresses=10.0.0.2 to-ports=SQUID_PORT
oh my gosh! shut up and take my money!- Routing filter action "Update Address List" which adds/removes matching prefixes from an address list
Winbox 3.4 disconnects from Mikrotik
and what if you connect by IP?When I try to connect to Mikrotik using MAC address
is it with parent=global or parent=<interface>?is there any improvement in queue tree being assigned to a single core in a multi-core router?
1) authorizationHow can I generate his queue so that he does not bypass the limits?
is it v6.34.3 problem? can you reproduce it on v6.35rc?Avoid using magnet to attach your mAP Lite.
Small bug in console:
It was released in 2016Code: Select allMikroTik RouterOS 6.34.3 (c) 1999-2015 http://www.mikrotik.com/
already fixed in RCWhat's new in 6.35rc29 (2016-Mar-14 15:30):
*) console - update copyright notice;
is it because this subforum is about RC and BETA versions?unfinsihed products
and the very first v7 bug report a typo: should be 'connected', I thinkCode: Select allC - connect, S - static, r - rip, b - bgp, o - ospf
support@mikrotik.comGood day! Where to send a request to add functionality in Winbox?
if you have MTCRE, it is automatically assumed you have MTCNA. Even if you passed MTCNA 8 years ago, if your MTCRE is active, you automatically have MTCNA
I think, it should be "are now refreshed" or "were not refreshed"*) winbox - incomplete ARP entries are not refreshed;
did you mean 'use-ip-firewall' in bridge settings? it should not affect Bridge FilterBridge firewall has to be enabled explicitly. It is off by default.
problem in arp entry ip and mac on cero 00:00:00:00:00:00 i put the bug fix and is the same and teh version v6.35rc and is the same
What's new in 6.33.5 (2015-Dec-28 09:13):
*) arp - show incomplete ARP entries;
seems like I won't be there I can't find affordable plane tickets from Minsk to Ljubljana. 500 euro is a bit expensiveChupaka CU at the MUM
what does that mean for performance?*) kernel - general improvement for core process scheduling;
a type cast?..What is Byte() ?
Always. It's not a bug. Router reboots, gives out IPs via DHCP, and only after that he learns DNSs via PPPoE. DHCP Server cannot force clients to renew DHCP leases, AFAIRthis is a temporary solution until they fix the bug ?
or always use dns statically ?
bwahaha, glad to hear that =)It's working!!!)))) I'm sorry, there was no active users))
Thank you very-very much!))
what's the reason? it should be in Log after rebootTried few times to re-download file and re-upload it to winbox. It just doesnt want to install.
Any suggestions?
rc14 is here, but no dude*.npk around =(We will release it with one of the next RC builds
can't find it in Download section... =(
http://forum.mikrotik.com/viewtopic.php?t=26790How do I run this command with api?:Code: Select all/tool user-manager user remove [find username=demo]
well, I drag it - and it moves just like in WinBox...So how do you move firewall / other rules in webfig? There is no re-ordering capability as far as I can tell so I have to keep using winbox.
checked my x86 installation - the link points to mikrotik.com...indeed before posting here, i did that. in IE, Firefox and also google chrome. sure it's not cached.
yahooo!!!We plan to make a new Dude release this year
What's new in 6.33rc33 (2015-Oct-26 11:50):
*) trafflow - report flow addresses in v1 and v5 without NAT awerness
What's new in 6.33rc33 (2015-Oct-26 11:50):
*) trafflow - report flow addresses in v1 and v5 without NAT awerness
What's new in 6.33rc33 (2015-Oct-26 11:50):
*) trafflow - report flow addresses in v1 and v5 without NAT awerness
the reason could be some other srcnat rule before this one, for exampleI have setup a rule such as this
chain=srcnat action=masquerade src-address=10.10.10.21
I am not seeing any traffic hitting this rule at all this src nat is not working.
Any idea?
knock-knock on the wood, no complains for the last years. but we don't use CCRs for queueing. only x86, only hardcore@Chupaka Did you find any solution or workaround ? Sometimes the routers cpu remains 100%
requesting more details on this =)*) firewall - fixed limit and dst-limit options.
thanks, reinstalled to solve I hoped there was easy way...Chupaka. Once more. Ignore this bug.
how can I do that now, without network access to the router? I have only CLIAt this time you could still change the flavor of kernel used.
so, it's WinBox-only switch? I cannot change it via CLI?So, enjoy that switch while it is there as in the future it will be removed.
so, what is 'Allow x86-64' tick in x86 RouterOS?unclear, but most likely CHR will get priority with all 64Bit and multicore support for now64 version for bare metal x86 - not planned?
what 'it'?Sadly it does not work for me.
I tried it
How can i disable 60+ firewall rules from terminal?
With "fasttrack dummy rule" I can't perform disable [find] because i can't disable dynamic rule.
disable [find dynamic=no]
fix what? "I have some error, I won't tell you anything about it, but please fix it - aren't you a telepathists?"so please fix this.
it's still allowed, at least on CCR:*) winbox - restrict reversed ranges in dst-port under firewall
so what is the issue?This is not the issue.
:put [/ip address find interface="ether1"]
yep, that should workI have access to several public IP addresses at each location. Can I use one IP for the IPsec EoIP tunnel and a different one for the L2TP server?
because it's not a releaseSorry, I know this is not the 6.30rc topic, but there is no one official.
please write to support@mikrotik.comThere is a problem with the scheduler on v6.30rc22.
and also similar counter in TrafficFlow: how much traffic you have not billednow only thing missing is similar solution for simple queues - dynamic dummy simple queue for fasttracked traffic.
Hi folks.
I need to print on a table id and the name of the hostpot users.
and remove the User by his id.
Can anyone help me.
/ip/hotspot/user/print
=.proplist=.id,name
/ip/hotspot/user/remove
=.id=ID_HERE
http://wiki.mikrotik.com/wiki/API_in_C_SharpI use C Sharp
Anyway,sorry I was wrong upload files, i should upload this file..
your pppoe client receives 5 Mbps of traffic - use Torch on it, not on ether1
your pppoe client receives 5 Mbps of traffic - use Torch on it, not on ether1i have the same problem, can somebody help me ?
any comments on how to balance a few IPv6 uplinks? or just failover for the home Internet?I'm personally against anything to do with nat and IPv6. We don't need another bandaid like nat originally was. Use IPv6 the way it was intended to be used.
on 17th day one of my CCRs became loosing packets on _some_ neighbour routers until reboot... I hope it was just a Moon in wrong phaseNow are 15 days after I have installed the 6.28 on my border BGP routers, my gateways, firewalls and user-managers.
No one single problem
1228800 bps is 1228,8 kbps, and WinBox does not round limits in output. for example, 1228000 should be shown as 1228kHello,
Upload rate in queues is shown in bits instead of kb alson on this version.
The queues are set in radius.
huh... what is full view load time on cisco routers?..full table towards the CCR and 3-5 minute load times
this topic is about optimization, new features will be in version 7Please add support for
I wonder whether those packets will be accounted by Traffic Flow...Note, that all packets that goes fasttrack, will not be visible in firewall and you will not be able to limit them in queue global.
I have 10.200.x.x/18 for clients,
also, it's better to NAT all traffic on uplink interface, so remove 'src-address-list=' from your nat rule/ip firewall address-list
add address=10.220.0.0/18 list=p-108
as you can see in page history, that was me who created and edited that articlewhat you think about this http://wiki.mikrotik.com/wiki/DDoS_Dete ... d_Blocking, they redirect to this post but are different
/ppp/active/remove
=.id=*80000010
And the reason is in Log, isn't it?I had cases where i copy .npk files and then after reboot, device simply wont upgrade
Could this be added as a feature request?
Did you email support to ask for this feature? <...> Forum is not always monitored by staff.
don't expect new 3.x versions at all, even if there's serious bugDon't expect any more 3.x versions unless there is a serious bug fix.???