Community discussions

MikroTik App

Search found 1765 matches

by CelticComms
Fri Mar 01, 2013 10:23 pm
Forum: Beginner Basics
Topic: NAT; opened ports are not reachable from the local network
Replies: 16
Views: 5086

Re: NAT; opened ports are not reachable from the local netwo

Add hairpin NAT. See the link in the first post of the thread.
by CelticComms
Fri Mar 01, 2013 8:18 pm
Forum: General
Topic: Mikrotic Router cannot obtain ip from cisco router
Replies: 1
Views: 622

Re: Mikrotic Router cannot obtain ip from cisco router

Are the routerboards connected to the 2950 on access ports? Trunk ports? More detail...?
by CelticComms
Fri Mar 01, 2013 3:39 pm
Forum: Beginner Basics
Topic: DMZ w/public IP
Replies: 8
Views: 3097

Re: DMZ w/public IP

If the /28 is routed to an address on your WAN interface then you just route the addresses into the DMZ and apply the required filters for functionality and security.
by CelticComms
Fri Mar 01, 2013 2:55 pm
Forum: General
Topic: IP scan tool buggy
Replies: 8
Views: 5588

Re: IP scan tool buggy

If you look at the traffic it will show on ether2 not ether4. If the interface and IP address are in conflict it seems to go with the IP address.
by CelticComms
Fri Mar 01, 2013 2:20 pm
Forum: Wireless Networking
Topic: Google Only works with https
Replies: 3
Views: 1200

Re: Google Only works with https

Are you using a web proxy? The Google sites generally redirect http to https now, so it sounds as if something is causing problems for the redirects.
by CelticComms
Fri Mar 01, 2013 3:46 am
Forum: General
Topic: Firewall on same subnet
Replies: 11
Views: 3849

Re: Firewall on same subnet

You should show your network layout but the most likely reason that your rules had no effect is that the traffic between the clients and server are not going through the router. If for instance you have a switch on that subnet the router probably never sees intra-subnet traffic. Figure a way to get ...
by CelticComms
Fri Mar 01, 2013 3:35 am
Forum: Beginner Basics
Topic: Basic routing question: destination ip-address vs. interface
Replies: 3
Views: 1897

Re: Basic routing question: destination ip-address vs. inter

add dst-address=0.0.0.0/0 gateway=int_to_isp This had been the only default route available and the mikrotik didnt use it. It will have tried to use the route but failed because it couldn't ARP for the target IP. Using the interface as the "route" even on a non PtP segment often works in ...
by CelticComms
Thu Feb 28, 2013 3:21 pm
Forum: Beginner Basics
Topic: Stop access between 2 LAN
Replies: 6
Views: 2925

Re: Stop access between 2 LAN

Allow NEW connections from office to guest but only allow ESTABLISHED and RELATED in the opposite direction.
by CelticComms
Wed Feb 27, 2013 10:20 pm
Forum: Beginner Basics
Topic: Basic Firewall Question(s)
Replies: 3
Views: 1291

Re: Basic Firewall Question(s)

No - traffic which doesn't match the rules continues on down and is implicitly accepted which is why you must have a drop all (remaining) at the end of the relevant chain.
by CelticComms
Wed Feb 27, 2013 7:38 pm
Forum: General
Topic: Home use
Replies: 8
Views: 1703

Re: Home use

The 2011 has variants with SFP but the only wireless option is built-in.
by CelticComms
Wed Feb 27, 2013 7:18 pm
Forum: General
Topic: About OSPF
Replies: 12
Views: 4136

Re: About OSPF

Are NSSA areas fixed in v6?
by CelticComms
Wed Feb 27, 2013 5:47 pm
Forum: Beginner Basics
Topic: Stop access between 2 LAN
Replies: 6
Views: 2925

Re: Stop access between 2 LAN

It looks as if you had no forward chain filters prior to adding that one - so in effect you have no "firewall" in the generally accepted meaning. Input chain filters only protect the router itself. Have a look at the wiki entry I referenced earlier. The place you want to be is where your l...
by CelticComms
Wed Feb 27, 2013 4:09 pm
Forum: Beginner Basics
Topic: Basic Firewall Question(s)
Replies: 3
Views: 1291

Re: Basic Firewall Question(s)

How did you create your firewall? Quickfig? Manually? Perhaps you should upload the output from /IP Firewall as it stands. The "firewall" is created by the application of a certain set of basic packet filters, state-aware packet filters and connection tracking to the router. Many Mikrotik ...
by CelticComms
Wed Feb 27, 2013 2:38 pm
Forum: Beginner Basics
Topic: Stop access between 2 LAN
Replies: 6
Views: 2925

Re: Stop access between 2 LAN

Do you have *any* forwarding chain rules at the moment? If you don't then you should read the following and block the inter-LAN traffic as part of generally securing your forwarding paths. http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter The basics are: Allow NEW connections from each LAN to ...
by CelticComms
Wed Feb 27, 2013 2:28 pm
Forum: General
Topic: Help about Firewall rules
Replies: 2
Views: 651

Re: Help about Firewall rules

Check the order of your forward rules and make sure that the traffic from that MAC address is dropped before you hit the accept rule for that general path.

You should be able to use src MAC address in that way.
by CelticComms
Tue Feb 26, 2013 10:39 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 1
Views: 729

Re: port forwarding

Upload your config using output from /export compact. Destination NAT is what you want and the devices need to be using the router's internal address as their default gateway.
by CelticComms
Tue Feb 26, 2013 8:06 pm
Forum: Beginner Basics
Topic: NAT problem
Replies: 14
Views: 6859

Re: NAT problem

I suggest that you tidy it up to have only current entries present. I don't know what the IP address allocations are at this point. Make sure that your public IPs are on the WAN facing interface and make sure that your basic inbound destinations NATs are working. I only saw one internal server menti...
by CelticComms
Tue Feb 26, 2013 7:23 pm
Forum: General
Topic: Home use
Replies: 8
Views: 1703

Re: Home use

The 2011 series is designed with home use in mind and does have a version with 2.4GHz wireless. The other unit is an x86 based platform and does not have WiFi built in. It can take a PCIe mini card for 3G/4G and can also take a disk drive if you want to run a web proxy. It is designed more for comme...
by CelticComms
Tue Feb 26, 2013 6:41 pm
Forum: General
Topic: Devide global and locsl traffic
Replies: 2
Views: 793

Re: Devide global and locsl traffic

It is hard to say from the description. What was the reason for the IPIP tunnel? Is the path between router B and A private or public?
by CelticComms
Tue Feb 26, 2013 6:08 pm
Forum: Beginner Basics
Topic: rb2011 - poor performance with uk bt infinity
Replies: 42
Views: 19146

Re: rb2011 - poor performance with uk bt infinity

Which modem device is it connected to?
by CelticComms
Tue Feb 26, 2013 4:02 pm
Forum: General
Topic: NAT with 2 bridges
Replies: 2
Views: 2564

Re: NAT with 2 bridges

Well one thing is that you have the gateway IP on Ether3:
add address=192.168.2.254/24 interface=ether3 network=192.168.2.0
That needs to be on the bridge.
by CelticComms
Tue Feb 26, 2013 3:52 pm
Forum: General
Topic: Cisco Conversions
Replies: 3
Views: 1053

Re: Cisco Conversions

If you are new to Mikrotik make life easy for yourself and use Winbox or Webfig.

The rule would be of the form:

add action=dst-nat chain=dstnat dst-address=public_IP dst-port=445 protocol=tcp to-addresses=internal_IP to-ports=445
by CelticComms
Tue Feb 26, 2013 1:30 pm
Forum: Beginner Basics
Topic: EXACT Difference between Router and Bridge mode of Mikrotek
Replies: 3
Views: 14425

Re: EXACT Difference between Router and Bridge mode of Mikro

There really is no such thing as bridge mode or router mode in RouterOS or on the RouterBoard products. Different elements of the same device can be bridging/switching while others are routing. Bridging/switching operates at level 2 of the network stack while routing operates at level 3. Other featu...
by CelticComms
Tue Feb 26, 2013 12:54 am
Forum: Beginner Basics
Topic: NAT; opened ports are not reachable from the local network
Replies: 16
Views: 5086

Re: NAT; opened ports are not reachable from the local netwo

It will show the masqueraded address for queries from the local network but should show the public IPs for external queries.

That is a downside to using this trick. The better fix is to split the servers and local clients into different subnet/masks and force traffic through the router that way.
by CelticComms
Tue Feb 26, 2013 12:14 am
Forum: General
Topic: How to assign a public IP to a server, without NAT?
Replies: 6
Views: 10973

Re: How to assign a public IP to a server, without NAT?

The method described using the loopback address is sometimes used but it it is router/host OS dependent and can be difficult to debug if it is not working so I am usually reluctant to even suggest it. It sounds as if the private link net version was suggested in which case the routing entry on the r...
by CelticComms
Mon Feb 25, 2013 10:52 pm
Forum: Beginner Basics
Topic: NAT problem
Replies: 14
Views: 6859

Re: NAT problem

1) You would typically have the public IPs to which you are source NATing outbound traffic on your WAN/outside interface - not the LAN/inside interface. 2) What cbrown indicated above will work if you only have relevant private IPs on the router interface that the server is connected to. If there is...
by CelticComms
Mon Feb 25, 2013 8:04 pm
Forum: Beginner Basics
Topic: rb2011 - poor performance with uk bt infinity
Replies: 42
Views: 19146

Re: rb2011 - poor performance with uk bt infinity

The auto-neg on the 1 Gb ports is handled by the Atheros 8327 which is also used in some other products including some TP-Link units. It would be interesting to know if a given VDSL device works OK with a non-Mikrotik 8327 port but ends up at 10Mb on the 2011.
by CelticComms
Mon Feb 25, 2013 6:45 pm
Forum: Beginner Basics
Topic: NAT; opened ports are not reachable from the local network
Replies: 16
Views: 5086

Re: NAT; opened ports are not reachable from the local netwo

The problem is that your original NAT entry is only NATing when the in-interface is Ether1 - presumably your WAN interface. The traffic from your local LAN subnet will never go through that NAT so the hairpin entry will never be triggered. If you make the original NAT entries dependent on your WAN p...
by CelticComms
Mon Feb 25, 2013 5:45 pm
Forum: Beginner Basics
Topic: NAT; opened ports are not reachable from the local network
Replies: 16
Views: 5086

Re: NAT; opened ports are not reachable from the local netwo

These are only the NAT entries. NAT traffic is also subject to the forwarding chain filters. Try making the entries including the hairpin entries and then upload the config using the output from /export compact.
by CelticComms
Mon Feb 25, 2013 5:35 pm
Forum: Beginner Basics
Topic: NAT; opened ports are not reachable from the local network
Replies: 16
Views: 5086

Re: NAT; opened ports are not reachable from the local netwo

I did not see any forward chain filters listed.

I suggest that you put the hairpin NAT entries in and then upload the output from /export compact so we can see the total config.
by CelticComms
Mon Feb 25, 2013 5:19 pm
Forum: General
Topic: Cisco Conversions
Replies: 3
Views: 1053

Re: Cisco Conversions

It is NATing traffic to TCP port 445 on Fa 0/1 to the same port on internal host 172.17.8.50. Presumably FA 0/1 is their WAN interface. That is the SMB port so I hope they have some restrictions in the firewall.... ;) You would achieve the same with a (hopefully restricted) destination NAT entry in ...
by CelticComms
Mon Feb 25, 2013 5:08 pm
Forum: Beginner Basics
Topic: NAT; opened ports are not reachable from the local network
Replies: 16
Views: 5086

Re: NAT; opened ports are not reachable from the local netwo

Hairpin NAT is what you need so if that hasn't solved the problem check your forwarding rules to make sure that you are allowing the hairpin traffic.
by CelticComms
Mon Feb 25, 2013 2:51 pm
Forum: RouterBOARD hardware
Topic: RB2011UAS-RM - auto negotiation problem
Replies: 112
Views: 73059

Re: RB2011UAS-RM - auto negotiation problem

I wouldn't be surprised if Mikrotik have not been able to reproduce the problem reliably. There have been problems of the other OpenReach modem the HG612 having auto-neg problems on some PC ethernet card drivers although I have not seen such comments regarding the ECI V-2FUb/I Rev.B. The other 3 lin...
by CelticComms
Mon Feb 25, 2013 2:28 pm
Forum: Beginner Basics
Topic: Blocking internal PC from web access
Replies: 1
Views: 740

Re: Blocking internal PC from web access

If you want to block access to the proxy server so that it can't even be accessed by manually setting the proxy on the PC then block access to it using input filters.
by CelticComms
Mon Feb 25, 2013 1:15 am
Forum: General
Topic: ipv6 routing now working
Replies: 22
Views: 6332

Re: ipv6 routing now working

It looks as if the ISP has used part/all of your /56 as the link network. If they believe that the link network is 2A01:5B8:A1::/56 and that their router address on that is 2A01:5B8:A1::1 then it is not surprising that the subsequent routing to /64s on the routerboard is not working. Instead, ask th...
by CelticComms
Sun Feb 24, 2013 6:41 pm
Forum: General
Topic: ipv6 routing now working
Replies: 22
Views: 6332

Re: ipv6 routing now working

How is the ISP presenting the allocation 2A01:5B8:A1::/56 to you? If it is simply being sent to your interface then you should be able to allocate an IPv6 address on a /64 to the WAN interface and an IP address on another /64 to the LAN interface and routing should ensue. I suggest that you go back ...
by CelticComms
Sat Feb 23, 2013 3:23 pm
Forum: Beginner Basics
Topic: RB751G-2HnD Installation help
Replies: 1
Views: 734

Re: RB751G-2HnD Installation help

You need to add 4 VLAN interfaces on the Mikrotik unit. Give these the VLAN numbers you desire and assign them to the Ether interface that you will use to connect to the HP switch. Then add 4 Bridges on the Mikrotik unit - e.g. VLBr10, VLBr20 etc. On the wireless interface you can assign one SSID to...
by CelticComms
Sat Feb 23, 2013 2:05 pm
Forum: Beginner Basics
Topic: Selective subnet destination routing to WAN side - possible?
Replies: 3
Views: 1478

Re: Selective subnet destination routing to WAN side - possi

You can use Mangle to set a routing mark on the relevant traffic (set by src address or inbound interface or whatever allows the distinction) and then make a default route entry for ISP2 with that same routing mark.
by CelticComms
Fri Feb 22, 2013 4:40 pm
Forum: General
Topic: How to properly configure this network?
Replies: 5
Views: 1454

Re: How to properly configure this network?

How come I cant see or access WIFI AP on Ether3 port from VLAN10 or VLAN12, but I can access it from Mikrotik?

Matej
It could be a number of reasons but check the default gateway settings on the AP.
by CelticComms
Fri Feb 22, 2013 4:19 am
Forum: General
Topic: Mesh instead of rstp bridge
Replies: 2
Views: 1271

Re: Mesh instead of rstp bridge

Are the two ISP ports joining the ring at the same location and what are they currently connected to on the Mikrotik side?
by CelticComms
Fri Feb 22, 2013 1:53 am
Forum: General
Topic: How to properly configure this network?
Replies: 5
Views: 1454

Re: How to properly configure this network?

Yes - all networks are routed by default. By applying filters in the forwarding chain you can block the forwarding behaviour.

If you are using the device as a firewall you should configure IP Firewall. The following might be useful:

http://wiki.mikrotik.com/wiki/Securing_ ... rOs_Router
by CelticComms
Fri Feb 22, 2013 1:05 am
Forum: Beginner Basics
Topic: RB750 Bridge+firewall
Replies: 8
Views: 9542

Re: RB750 Bridge+firewall

If I put the rule in the IP>FIREWALL FORWARD path to allow ESTABLISHED & RELATED for instance, how does the RB750 'know' the direction to apply these rules correctly. IP Firewall has no notion of LAN/WAN etc. - it just knows about interfaces, or bridge ports in the case where it is being applie...
by CelticComms
Thu Feb 21, 2013 1:40 pm
Forum: Beginner Basics
Topic: best way to access api from remote location?
Replies: 3
Views: 1317

Re: best way to access api from remote location?

The best way to access a router from a VPS would be VPN? It is better in the sense that it can provide authentication and confidentiality - the price for that is the overhead of the VPN method chosen. Accessing the API over a public network without a VPN is a significant security risk. If you only ...
by CelticComms
Tue Feb 19, 2013 7:30 pm
Forum: Beginner Basics
Topic: RouterOS - No Firewall - Pure Router
Replies: 10
Views: 3103

Re: RouterOS - No Firewall - Pure Router

This smells like a System Center issue.... Try using Torch in Winbox and look at ether1 (i.e. the interface that the router connects to the 5723 on). Click on all the option boxes including port and set the timeout to longer than the default 3 seconds - say 30 seconds. Now try your ping test - you s...
by CelticComms
Tue Feb 19, 2013 6:38 pm
Forum: Beginner Basics
Topic: Firewall rules RB751 v5.23 to separate/isolate 3 subnets
Replies: 2
Views: 1759

Re: Firewall rules RB751 v5.23 to separate/isolate 3 subnets

Use filters (in IP Firewall) in the forwarding chain to determine which paths are permitted and drop the remaining denied paths.
by CelticComms
Mon Feb 18, 2013 2:28 pm
Forum: Beginner Basics
Topic: Can I bridge TWO (2) wireless cards on ONE (1) RouterBoard?
Replies: 10
Views: 3334

Re: Can I bridge TWO (2) wireless cards on ONE (1) RouterBoa

The bonding approach would work and can make use of both links when both are working. If the wireless gear is Mikrotik at both ends you have a lot of different options (some layer 2 approaches do not work well across multiple vendors). To bring clarity to the situation I suggest that you list and pr...
by CelticComms
Mon Feb 18, 2013 5:09 am
Forum: Beginner Basics
Topic: Can I bridge TWO (2) wireless cards on ONE (1) RouterBoard?
Replies: 10
Views: 3334

Re: Can I bridge TWO (2) wireless cards on ONE (1) RouterBoa

You can either do this by having redundant links at layer 3 - (i.e. IP routing with OSPF determining the route actually used) or you *could* have redundant links operating at layer 2 provided that you have STP taking care of layer 2 loop avoidance. If you are not familiar with layer 2, STP, ARP reso...
by CelticComms
Sat Feb 16, 2013 3:31 pm
Forum: Beginner Basics
Topic: could not determine local IP adress
Replies: 2
Views: 2531

Re: could not determine local IP adress

Sounds more like the PPPoE client couldn't determine the local IP address to be used by the PPPoE session - i.e. the address it expected to be supplied by the PPPoE server.
by CelticComms
Sat Feb 16, 2013 3:16 pm
Forum: General
Topic: HP Printer - won't send pckts to other subnet. nat rule?
Replies: 1
Views: 1065

Re: HP Printer - won't send pckts to other subnet. nat rule?

You could put the printer on a static IP and simply masquerade the traffic destined for it on egress from the routerboard. The printer will then see that traffic as originating from the routerboard's IP on its local subnet. Which HP printer model is this? I have seen some HP printers do weird things...
by CelticComms
Sat Feb 16, 2013 6:26 am
Forum: Beginner Basics
Topic: RouterOS - No Firewall - Pure Router
Replies: 10
Views: 3103

Re: RouterOS - No Firewall - Pure Router

Look in the filters section of IP Firewall for entries in the forwarding chain. With no entries RouterOS will route anything to anywhere. I suspect that you have entries which are restricting the routing function. Also remember that the target must also know a route back to the ping originator. If t...
by CelticComms
Fri Feb 15, 2013 3:04 pm
Forum: Beginner Basics
Topic: Routing marks
Replies: 3
Views: 1731

Re: Routing marks

It may also be useful for you to look at VRFs under /IP Routing. By placing specific interfaces into a VRF the system will automatically mark traffic on those interfaces with the VRF routing mark and connected routing table entries for the relevant IPs will be marked with the appropriate routing mar...
by CelticComms
Fri Feb 15, 2013 2:54 pm
Forum: Forwarding Protocols
Topic: Public IP's
Replies: 6
Views: 2287

Re: Public IP's

Can you ping the ISP gateway? Which DNS servers are you using - are lookups working?

Do you have any NAT rules active?

Output from /export compact would be useful.
by CelticComms
Wed Feb 13, 2013 5:11 pm
Forum: Beginner Basics
Topic: "default" filtering IPv6
Replies: 2
Views: 1231

Re: "default" filtering IPv6

If you are looking for basic firewall functionality in the IPV6 firewall then you need to protect the routerboard itself by setting input filters and protect devices beyond the router by setting filters in the forwarding chain. In the forwarding chain you want to allow new connections from the LAN t...
by CelticComms
Tue Feb 12, 2013 12:31 am
Forum: Forwarding Protocols
Topic: OSPF neighborship stays up eventhough int is unreachable
Replies: 9
Views: 4142

Re: OSPF neighborship stays up eventhough int is unreachable

Tell me please, your mikrotik ospf-router answer to ping 224.0.0.5 when link is up ?
No - annoyingly.... ;)

Are you using area type NSSA? I have seen that do very strange things on ROS 5.
by CelticComms
Sun Feb 10, 2013 3:36 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

I suggest that you install ROS 5.23 rather than any of the ROS 6 versions since there is more experience of IGMP on ROS 5 available at this point.

Then you need to be prepared to do some detective work.....
by CelticComms
Sun Feb 10, 2013 2:01 pm
Forum: General
Topic: Can't work out simple VLAN setup
Replies: 3
Views: 1296

Re: Can't work out simple VLAN setup

Is VLAN 1 tagged or untagged on the trunk?

It would be helpful if you uploaded the output from /export compact on the routerboard.
by CelticComms
Sat Feb 09, 2013 6:38 pm
Forum: Beginner Basics
Topic: 3 VLANS and per VLAN his own gateway? HOW?
Replies: 17
Views: 4062

Re: 3 VLANS and per VLAN his own gateway? HOW?

I'm not sure what you mean by "right routes for the VLANs". How are you providing IP numbers to the wireless clients? If you have an upstream device doing that then it would set the gateway as required. If you want the routerboard to do that you would have to attach DHCP servers to the VLA...
by CelticComms
Sat Feb 09, 2013 6:03 pm
Forum: Beginner Basics
Topic: R493G and DHCP client
Replies: 5
Views: 1764

Re: R493G and DHCP client

Some ISPs have delays on providing IPs to multiple MAC addresses via DHCP.

To check if that is a problem you can temporarily set the MAC address of the WAN port to be the same as the (known working) computer and see if that changes anything.
by CelticComms
Sat Feb 09, 2013 4:50 pm
Forum: General
Topic: Please help debug mikrotik port forwarding problem
Replies: 6
Views: 2337

Re: Please help debug mikrotik port forwarding problem

Are you sure that the upstream ISP doesn't filter certain ports?
by CelticComms
Sat Feb 09, 2013 4:39 pm
Forum: General
Topic: Please help debug mikrotik port forwarding problem
Replies: 6
Views: 2337

Re: Please help debug mikrotik port forwarding problem

I suggest that you test the port 82 forward on the "working" web site and then return it to the "problem" web site. If the web sites are on the same server and the forward works for one then it should work for the other. Perhaps there are absolute address references in the source...
by CelticComms
Sat Feb 09, 2013 4:21 pm
Forum: General
Topic: Please help debug mikrotik port forwarding problem
Replies: 6
Views: 2337

Re: Please help debug mikrotik port forwarding problem

DId you really mean that the web server is establishing a PPPoE connection or is the PPPoE DSL connection being handled by the Mikrotik unit?

Port 8080 is often used for caching. Have you checked that another port (say 82) doesn't cure the problem?
by CelticComms
Sat Feb 09, 2013 12:45 am
Forum: Beginner Basics
Topic: 3 VLANS and per VLAN his own gateway? HOW?
Replies: 17
Views: 4062

Re: 3 VLANS and per VLAN his own gateway? HOW?


@CelticComms
i.e. you create VLAN interfaces and then bridge those interfaces to the Virtual AP interfaces.
Is there another way without bridging the interfaces and using a routing method?
Yes it would be possible but if there is no requirement to route bridging is more efficient.
by CelticComms
Fri Feb 08, 2013 11:16 pm
Forum: Beginner Basics
Topic: PPPoE configuration - help needed
Replies: 3
Views: 3041

Re: PPPoE configuration - help needed

If the computer is set to use the router for DNS service that would explain the ability to make DNS lookups. On a NAT system you will have to masquerade outbound traffic on that PPPoE interface. If you already have a masquerade entry for Ether1 (out-interface) change the interface to the PPPoE inter...
by CelticComms
Fri Feb 08, 2013 9:47 pm
Forum: Beginner Basics
Topic: 3 VLANS and per VLAN his own gateway? HOW?
Replies: 17
Views: 4062

Re: 3 VLANS and per VLAN his own gateway? HOW?

To access the tagged VLANs coming from the Cisco you need to create VLAN interfaces under /interface/vlan and assign them to the Ether port connected to the Cisco with the correct VLAN IDs. Then create the same number of bridges and add both the relevant VLAN interface and the corresponding WLAN (Vi...
by CelticComms
Fri Feb 08, 2013 7:36 pm
Forum: Beginner Basics
Topic: 3 VLANS and per VLAN his own gateway? HOW?
Replies: 17
Views: 4062

Re: 3 VLANS and per VLAN his own gateway? HOW?

What do you want at Ether 2 on the RouterBoard? Untagged or tagged?

If you have the option of using three tagged VLANS coming from the Cisco I would do so - it allows a cleaner config on the RouterBoard.
by CelticComms
Fri Feb 08, 2013 6:19 pm
Forum: Beginner Basics
Topic: 3 VLANS and per VLAN his own gateway? HOW?
Replies: 17
Views: 4062

Re: 3 VLANS and per VLAN his own gateway? HOW?

The question would be clearer if you could mark the diagram with where each VLAN is to be tagged or untagged. e.g. Cisco trunk ports using 802.1q by default have VLAN 1 as the native (untagged) VLAN.
by CelticComms
Fri Feb 08, 2013 5:41 pm
Forum: Beginner Basics
Topic: Is it possible to change direction packets ?
Replies: 7
Views: 1622

Re: Is it possible to change direction packets ?

How I said before, all computers and printers connected through switches. and (! important ! in one local net) i.e. if i ping from computer 192.168.1.100 to printer with IP 192.168.1.101, packets doesn't reach router. And i can't make firewall rules. OK - so you are talking about traffic within the...
by CelticComms
Fri Feb 08, 2013 5:08 pm
Forum: Beginner Basics
Topic: Is it possible to change direction packets ?
Replies: 7
Views: 1622

Re: Is it possible to change direction packets ?

Many commercial networks are heavily switched ... :)

Can you try to be a bit more precise with the question?
by CelticComms
Fri Feb 08, 2013 1:50 am
Forum: General
Topic: Is this the way to block unwanted SIP traffic?
Replies: 2
Views: 1876

Re: Is this the way to block unwanted SIP traffic?

Do you have an existing DST NAT rule for port 5060? If you do you can simply limit its operation to a given SRC. Address or use a Src Address List for multiple addresses.
by CelticComms
Thu Feb 07, 2013 2:41 pm
Forum: Beginner Basics
Topic: 3 vlans and 3 wans how to?
Replies: 2
Views: 1084

Re: 3 vlans and 3 wans how to?

You could use mangle to mark routing on external traffic from those VLANs then have corresponding routing table entries specifying the gateway to be used by each routing mark.
by CelticComms
Thu Feb 07, 2013 12:50 pm
Forum: Beginner Basics
Topic: Only smarthost can connect on port 25
Replies: 2
Views: 950

Re: Only smarthost can connect on port 25

In the destination NAT rule you can use either the Src. Address or Src. Address List to restrict the NAT rule to traffic from either a single address or list of addresses respectively.
by CelticComms
Wed Feb 06, 2013 8:17 pm
Forum: Beginner Basics
Topic: Configure RB2011LS-IN Routers
Replies: 4
Views: 1451

Re: Configure RB2011LS-IN Routers

You have to decide if the fiber link is going to be actually *on* one of those subnets or whether it will be its own link network linking the two networks together. Then of course the clients on in each building need to know to use the route to the other network so how do those clients currently get...
by CelticComms
Wed Feb 06, 2013 4:21 pm
Forum: Beginner Basics
Topic: Two networks and DHCP server
Replies: 9
Views: 25372

Re: Two networks and DHCP server

Don't try to use two DHCP servers. One server can do both the dynamic and static clients even in the different subnets on that one interface. Make sure that you also have the relevant Networks entries for both subnets under /IP DHCP Server.
by CelticComms
Wed Feb 06, 2013 4:01 pm
Forum: Forwarding Protocols
Topic: OSPF causing a lot of traffic on WAN interface
Replies: 9
Views: 2832

Re: OSPF causing a lot of traffic on WAN interface

Do you run BGP to your ISP or do they send traffic to you for your IPs based on a static route? In that case check that when the link goes down and you lose the internal routes to those IPs that you are not then forwarding the traffic back to your upstream ISP who is then forwarding them back to you...
by CelticComms
Wed Feb 06, 2013 3:39 pm
Forum: Beginner Basics
Topic: Two networks and DHCP server
Replies: 9
Views: 25372

Re: Two networks and DHCP server

Are these on the same router? Both DHCP servers show Ether1.
by CelticComms
Wed Feb 06, 2013 2:21 pm
Forum: Beginner Basics
Topic: Two networks and DHCP server
Replies: 9
Views: 25372

Re: Two networks and DHCP server

Make sure that you have an IP Pool assigned to the relevant DHCP server. Post output from /ip dhcp-server for comment.
by CelticComms
Tue Feb 05, 2013 9:52 pm
Forum: Beginner Basics
Topic: Cisco to Mikrotik OSPF
Replies: 9
Views: 10447

Re: Cisco to Mikrotik OSPF

The active dynamic OSPF entries appear in the RouterOS routing table with the ADo flag. You can see the LSAs behind those routes in the OSPF LSA tab.
by CelticComms
Tue Feb 05, 2013 8:37 pm
Forum: Forwarding Protocols
Topic: OSPF causing a lot of traffic on WAN interface
Replies: 9
Views: 2832

Re: OSPF causing a lot of traffic on WAN interface

I suggest looking at your routing and NAT entries to unravel this. If external clients are sending DNS queries to your IP range and your internal route to those IPs is down then you *might* be sending the traffic back out to your ISP who promptly sends it back to you giving the appearance of heavy t...
by CelticComms
Tue Feb 05, 2013 5:47 pm
Forum: Forwarding Protocols
Topic: OSPF causing a lot of traffic on WAN interface
Replies: 9
Views: 2832

Re: OSPF causing a lot of traffic on WAN interface

There are actually multiple IPs showing on both sides - both your IPs and external. Not really enough information to know what is going on, but assuming that you do actually run DNS services which are accessed from external addresses (i.e. DNS services for sites you are hosting etc.) check that when...
by CelticComms
Tue Feb 05, 2013 3:46 pm
Forum: Forwarding Protocols
Topic: OSPF + BGP in Mikrotik v5.21
Replies: 2
Views: 1630

Re: OSPF + BGP in Mikrotik v5.21

Look at your routing at RB1100A and see what paths are being chosen to Office A addresses. In the diagram you show the same /24 subnet for Offices A and B - is that a typo?
by CelticComms
Tue Feb 05, 2013 3:34 pm
Forum: General
Topic: How does Ruterbord -Bridge RSTP- decide which is root port?
Replies: 5
Views: 8281

Re: How does Ruterbord -Bridge RSTP- decide which is root po

Or let me be clear - How does ROuterBoard decide which of the interfaces will have a role as root port?
The root port is that bridge's lowest cost path to the designated root bridge. See below:

http://en.wikipedia.org/wiki/Spanning_Tree_Protocol
by CelticComms
Tue Feb 05, 2013 5:57 am
Forum: Beginner Basics
Topic: Cisco to Mikrotik OSPF
Replies: 9
Views: 10447

Re: Cisco to Mikrotik OSPF

If you have adjacency established then the answer to why there is no internet access is probably to be found in the routing table. Is OSPF inserting a default (internet) route? If not suspect the Cisco OSPF config. If you have a default (internet) route then check - does the outside world have a ret...
by CelticComms
Tue Feb 05, 2013 12:49 am
Forum: Forwarding Protocols
Topic: OSPF causing a lot of traffic on WAN interface
Replies: 9
Views: 2832

Re: OSPF causing a lot of traffic on WAN interface

I'm not sure that I follow your question.

The traffic in the graphic is DNS lookups which are failing - note the zero rx rate.
by CelticComms
Mon Feb 04, 2013 11:42 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

I see a DHCP Server assigned to interface "IPTV Network" but no sign of an IP address assigned to that interface which is most likely why the DHCP Server is flagged invalid. Solution - add a valid IP address to interface "IPTV Network"!
by CelticComms
Mon Feb 04, 2013 6:00 pm
Forum: General
Topic: dmz with public ips
Replies: 2
Views: 864

Re: dmz with public ips

If the extra /28 is ***routed*** to you via another IP range on your WAN link then you can simply use the extra /28 directly on the WAN interface and make sure that you are allowing necessary routing between the WAN and DMZ port in the forwarding rules.
by CelticComms
Mon Feb 04, 2013 3:25 pm
Forum: Beginner Basics
Topic: Hundreds of VPN
Replies: 10
Views: 2493

Re: Hundreds of VPN

I would flesh out what your topology/transport options are and then see whether the viable options point towards a static or dynamic routing model.

e.g. If most endpoints really only have one path back to the central systems then dynamic routing may be unnecessary.
by CelticComms
Mon Feb 04, 2013 2:52 pm
Forum: Beginner Basics
Topic: Cisco to Mikrotik OSPF
Replies: 9
Views: 10447

Re: Cisco to Mikrotik OSPF

If you are having problems forming adjacency also check: That OSPF traffic (protocol 89) is not blocked - should be able to see traffic from Cisco using Torch on RouterOS. That netmasks match - mismatched netmasks sometimes allow pings to succeed but adjacency will fail. That the Hello and Dead inte...
by CelticComms
Sun Feb 03, 2013 5:56 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

It looks as if you do not have a valid IP on the interface that the second DHCP server is attached to thus the DHCP server will show invalid.
by CelticComms
Sun Feb 03, 2013 2:47 pm
Forum: Beginner Basics
Topic: Hundreds of VPN
Replies: 10
Views: 2493

Re: Hundreds of VPN

Will the endpoints still be using some kind of cellular modem as their connection to the central location or do you have something else in mind?
by CelticComms
Sat Feb 02, 2013 10:31 pm
Forum: Beginner Basics
Topic: Hundreds of VPN
Replies: 10
Views: 2493

Re: Hundreds of VPN

What is the nature of the connections between the endpoints and the central location?
by CelticComms
Fri Feb 01, 2013 8:21 pm
Forum: General
Topic: master/slave eth or join bridge
Replies: 1
Views: 1029

Re: master/slave eth or join bridge

The bridge is implemented at the RouterOS level (uses CPU cycles) whereas the master/slave options refer to ports on switch chips which can be enslaved without giving RouterOS more work to do.
by CelticComms
Fri Feb 01, 2013 1:33 pm
Forum: General
Topic: VLAN: Inter VLAN Routing - Beginner Advice
Replies: 7
Views: 5462

Re: VLAN: Inter VLAN Routing - Beginner Advice

Some IP phones (e.g. Cisco) which have an on-board switch allow the tagging of the VOIP traffic. It is probably a good idea to check if the phones there have that capability.
by CelticComms
Fri Feb 01, 2013 3:04 am
Forum: General
Topic: VLAN: Inter VLAN Routing - Beginner Advice
Replies: 7
Views: 5462

Re: VLAN: Inter VLAN Routing - Beginner Advice

The CCR could certainly act as an internal inter VLAN router. It would be easier to comment of you could list the goals that you have in mind for the introduction of VLANs. As Dobby said, it would also be useful to know how many clients/devices are in each building. Have you considered having any ad...
by CelticComms
Thu Jan 31, 2013 7:50 pm
Forum: General
Topic: RB411U with Sierra Wireless 3G inaccessible when 3G drops
Replies: 4
Views: 1244

Re: RB411U with Sierra Wireless 3G inaccessible when 3G drop

Which version of ROS are you running? Are you sure that the problem occurs when the 3G signal drops, or is it possible that the router itself is having an issue which results in the 3G connection dropping along with everything else.
by CelticComms
Wed Jan 30, 2013 1:56 pm
Forum: General
Topic: How to manage a RB behind a RB from the WAN?
Replies: 29
Views: 4951

Re: How to manage a RB behind a RB from the WAN?

What IP is the VPN client being given?
Is proxy arp running on the internal interface of the main router?
What does the routing table look like on the devices that you can't ping?
by CelticComms
Wed Jan 30, 2013 12:30 am
Forum: General
Topic: How to manage a RB behind a RB from the WAN?
Replies: 29
Views: 4951

Re: How to manage a RB behind a RB from the WAN?

Oh really? Is that the case if they are based on a hotspot setup too? As long as the port is open in the input filter chain and the router has a valid IP route back to you it should be possible to simply enter the IP number directly. Note that in certain situations if you VPN to a front door device...
by CelticComms
Tue Jan 29, 2013 11:19 pm
Forum: General
Topic: How to manage a RB behind a RB from the WAN?
Replies: 29
Views: 4951

Re: How to manage a RB behind a RB from the WAN?

I guess it would be better if I could connect into the 'master' aka site 1 RB450G and then access winbox from there. But once I've connected into that RB how do I allow the discovery tool to find the others (i.e. firewall rules) If you know the IP address of those internal routers then you don't ne...
by CelticComms
Tue Jan 29, 2013 9:26 pm
Forum: Beginner Basics
Topic: Static DHCP Lease question
Replies: 2
Views: 773

Re: Static DHCP Lease question

....................... but can I assign addresses to these static leases that are not in the regular DHCP pool?
Yes
by CelticComms
Tue Jan 29, 2013 8:08 pm
Forum: General
Topic: Internet access
Replies: 27
Views: 4496

Re: Internet access

Those threads primarily give further examples of why it is hard to use the equipment in the way that you are trying to. Perhaps if you can give some idea of the physical layout a rearrangement would be possible. e.g. placing the AP mode device at the router end would make life a lot easier.
by CelticComms
Tue Jan 29, 2013 6:46 pm
Forum: General
Topic: EOIP over PPTP browsing issues
Replies: 12
Views: 11389

Re: EOIP over PPTP browsing issues

I have same problem also. I'm between two rb2011 made ​​eoip tunnel. Tunnel working properly, I can ping other side, but when I try to ping without fragment, packets greater than 1250 can not pass. This doesn't really sound the same as the instances in the thread. What is maximum non-fragmented MTU...
by CelticComms
Tue Jan 29, 2013 3:40 pm
Forum: Beginner Basics
Topic: Basic configuration Mistake
Replies: 2
Views: 937

Re: Basic configuration Mistake

Check your firewall rules - and post if the problem isn't clear. I suspect that you will find that you are doing a SRC NAT or Masquerade on traffic leaving Eth2.
by CelticComms
Tue Jan 29, 2013 2:54 pm
Forum: General
Topic: How to add destination IPs over 10000pps to the address list
Replies: 4
Views: 1228

Re: How to add destination IPs over 10000pps to the address

I remember that dst-limit was having some issues a while back - not sure about limit. I will have a look at some filters and see if I can swap one of mine to use limit temporarily.
by CelticComms
Tue Jan 29, 2013 3:37 am
Forum: Beginner Basics
Topic: Trunking Vlans to VMWare (Block VLAN->VLAN traffic)
Replies: 13
Views: 3070

Re: Trunking Vlans to VMWare (Block VLAN->VLAN traffic)

Yes. Do you have an example based on my info above? Go into /IP Firewall and add a filter in the forwarding chain with nothing selected except Action=Drop. At that point no traffic will be routed between interfaces at level 3. You may then want to add specific rules *above* that "drop all"...
by CelticComms
Tue Jan 29, 2013 1:09 am
Forum: General
Topic: How to manage a RB behind a RB from the WAN?
Replies: 29
Views: 4951

Re: How to manage a RB behind a RB from the WAN?

It would probably be less work and more secure to VPN to the first device and then access the Winbox interface on all of them via the (encrypted) VPN
by CelticComms
Tue Jan 29, 2013 1:06 am
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

Can you confirm whether your VDSL modem is in bridge mode - or are you double NATing?
by CelticComms
Mon Jan 28, 2013 6:43 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

................ For that, I have Set Up an DHCP Server for serving also this network, but it shows up red and won´t work. So what have to be done to get this thing realized? Thanks in advance Make sure that the interface has a valid IP number on it. If it doesn't the DHCP server will be flagged in...
by CelticComms
Mon Jan 28, 2013 5:41 pm
Forum: General
Topic: netbios broadcast on mikrotik
Replies: 2
Views: 1566

Re: netbios broadcast on mikrotik

If you have anything which can act as a WINS server it would be preferable.

RouterOS doesn't have one of those "check the box" options for Netbios broadcast that some consumer devices have. It can be done - but WINS is probably preferable.
by CelticComms
Mon Jan 28, 2013 3:13 pm
Forum: General
Topic: How to add destination IPs over 10000pps to the address list
Replies: 4
Views: 1228

Re: How to add destination IPs over 10000pps to the address

For TCP and UDP traffic it would be possible to use connection rate to add addresses to a list based on total (in & out) connection rate. I'm not sure if there is a way to do it based on actual packet rate.
by CelticComms
Mon Jan 28, 2013 2:38 pm
Forum: Beginner Basics
Topic: VMWare setup help with bonding and vlans
Replies: 2
Views: 1928

Re: VMWare setup help with bonding and vlans

Is the bonded connection working but VLANs not?

Presumably you are bridging something else to the bonded interface?
by CelticComms
Mon Jan 28, 2013 12:26 pm
Forum: Beginner Basics
Topic: Easiest Tunnel between 2 Lan
Replies: 6
Views: 1469

Re: Easiest Tunnel between 2 Lan

anyone? is Ipsec enough for that? IPSEC would also provide encryption. To help narrow the choice decide if you want: a) IP (Level 3) connectivity b) Ethernet (Level 2) connectivity c) Encryption d) Authentication Different features create different overheads. e.g. encryption adds overhead but if th...
by CelticComms
Mon Jan 28, 2013 12:14 pm
Forum: Beginner Basics
Topic: Why do I need to use a bridge?
Replies: 6
Views: 1617

Re: Why do I need to use a bridge?

No entries in IP Firewall.

Now with the bridge configured the router is working like a simple switch, isn't it?
Yes -in simple terms a switch is simply a multi-port bridge.

Can you upload output from /export compact so we can see why you were not observing routing among the attached subnets?
by CelticComms
Mon Jan 28, 2013 12:11 pm
Forum: General
Topic: VPN between two identical subnets
Replies: 8
Views: 3444

Re: VPN between two identical subnets

At the end with the Windows PPTP client is there anything else on the local subnet that the Windows PC needs access to other than the gateway/router? If not and if you don't mind the Windows PC accessing the internet via "Location A" then PPTP and proxy-ARP could work until a better soluti...
by CelticComms
Sun Jan 27, 2013 10:58 pm
Forum: General
Topic: Failover WAN 2 sites
Replies: 1
Views: 644

Re: Failover WAN 2 sites

If you set the gateways for each ISP to be checked (e.g. by PING) then that gives you a mechanism for marking the corresponding routes down if an ISP connection goes down. You can then add default routes pointing to the EFM link but with suitable distance settings such that those secondary routes ar...
by CelticComms
Sun Jan 27, 2013 10:25 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

Look in the IGMP Proxy settings under interfaces. On that upstream interface add 0.0.0.0/0 as an alternative subnet - you will see a place for that entry. I am suggesting this because you don't know what addresses the IPTV provider will be streaming from yet...
by CelticComms
Sun Jan 27, 2013 9:51 pm
Forum: Beginner Basics
Topic: Why do I need to use a bridge?
Replies: 6
Views: 1617

Re: Why do I need to use a bridge?

What entries do you have in /IP Firewall? If there are no entries in the forwarding chain then all traffic will normally be forwarded among the various attached networks according to the routing table.
by CelticComms
Sun Jan 27, 2013 9:44 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

On the IGMP proxy upstream interface temporarily add 0.0.0.0/0 under alternate subnets since there is a good chance that the servers are not on the same subnet. Once you see where the traffic comes from you can provide suitable limits.
by CelticComms
Sun Jan 27, 2013 4:02 pm
Forum: Beginner Basics
Topic: EoIP 450G low speed
Replies: 4
Views: 1962

Re: EoIP 450G low speed

Can you describe the path between the two systems and check the latency between them?
by CelticComms
Sun Jan 27, 2013 12:28 am
Forum: General
Topic: Sprint 3g 598 usb data card with 411U
Replies: 3
Views: 1136

Re: Sprint 3g 598 usb data card with 411U

Which firmware version does the 598U show? e.g. I looked at a 598U which works fine in an RB411U (inc. cold starts) and it showed:

Model: T598 Rev 1.0 (2)
Revision: p2505002

These are visible in Info - the firmware revision is right at the start of the long "Revision" string.
by CelticComms
Sat Jan 26, 2013 10:19 pm
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...

Now I need to know how to give the priority to the vlan in the local network?
Have a look at this part of the WiKi:

http://wiki.mikrotik.com/wiki/Manual:Queue
by CelticComms
Sat Jan 26, 2013 9:49 pm
Forum: General
Topic: IKE IPsec VPN Checkpoint
Replies: 1
Views: 3044

Re: IKE IPsec VPN Checkpoint

Are you talking about the return traffic on an established connection or differences depending on who initiates the connection?

Have the forwarding rules been updated to take account of the expected traffic via the tunnel?
by CelticComms
Sat Jan 26, 2013 9:32 pm
Forum: Beginner Basics
Topic: Witch port is best for WAN on RB1100AH!!??
Replies: 2
Views: 1314

Re: Witch port is best for WAN on RB1100AH!!??

Port 11 is connected to the network processor via the same type interface as the two Atheros switch chips which support ports 1-5 & 6-10, whereas ports 12 & 13 are connected via PCIe interfaces. Ports 11 & 12 can be configured to failover (essentially join together at Level1) and port 13...
by CelticComms
Sat Jan 26, 2013 8:04 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

From your config it looks as if the PPPoE client "VDSL MediaNet Dial" uses VLAN7. The VLAN is just defining the broadcast domain for the PPPoE connection. It is the PPPoE client which will ultimately carry your local LAN subnet traffic to the ISP so it is the PPPoE client interface "V...
by CelticComms
Sat Jan 26, 2013 7:51 pm
Forum: General
Topic: Dual WAN routing, no failover
Replies: 6
Views: 2326

Re: Dual WAN routing, no failover

It looks is if 4 entries would get you there: A mangle rule with in-interface set to mark routing for traffic from ether4 as "ISP1". A mangle rule with SRC address list set to mark routing for traffic from four ISP1 subnets on ether3 as "ISP1". An address list containing the four...
by CelticComms
Sat Jan 26, 2013 3:58 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

does it mean, that I have to chance the 0.0.0.0 to 0.0.0.0/0 or what is the deal? The other Masquerade is for fibre connector, I have no sfp, so I have deaktivated the port. I think that you must have selected source NAT on that rule at some point thus the to-addresses setting appeared. I don't thi...
by CelticComms
Fri Jan 25, 2013 11:27 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

add action=masquerade chain=srcnat comment="default configuration" \ out-interface="VDSL Modem Uplink" to-addresses= 0.0.0.0 Before looking at anything else could you get rid of the 0.0.0.0 . 0.0.0.0/0 and 0.0.0 are not the same thing. Note that your other masquerade has no to-a...
by CelticComms
Fri Jan 25, 2013 3:00 am
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...


I had already set it off, but change nothing.
You changed it since uploading the config?
by CelticComms
Fri Jan 25, 2013 12:37 am
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...

Set the service tag option OFF. That is for 802.1ad use.
by CelticComms
Fri Jan 25, 2013 12:31 am
Forum: Beginner Basics
Topic: 2 isp to 1 lan
Replies: 8
Views: 4722

Re: 2 isp to 1 lan

by CelticComms
Thu Jan 24, 2013 8:43 pm
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...

I'm note sure what is being tagged to "10" or where you pinged and from where.

Can you upload the current output from /export compact and give a clear indication of what the settings are on the phone?
by CelticComms
Thu Jan 24, 2013 7:35 pm
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...

How you prioritize the traffic is another subject. As regards the VLAN itself once it is established you need to get down to basics. e.g. is it pulling an IP lease from the DHCP server on VLAN2? Can you ping the VLAN2 client using /Tools Ping?
by CelticComms
Thu Jan 24, 2013 6:58 pm
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...

What do you mean by set the network settings for that DHCP? Network and Pool is created... Sounds correct. If I don't set a vlan1, how to give a priority to the vlan2? On RouterOS you do not need to create VLAN1 as you would on a Cisco device. If VLAN1 is the untagged traffic on an Ethernet port th...
by CelticComms
Thu Jan 24, 2013 5:58 pm
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...

Create the VLAN interface for VLAN2 and assign it to the bridge. Add an IP the the VLAN2 interface, then add a DHCP server to the VLAN 2 interface with an appropriate IP Pool. Remember to also set the network settings for that DHCP server. If VLAN1 is "untagged" then you don't need to crea...
by CelticComms
Thu Jan 24, 2013 1:36 pm
Forum: Beginner Basics
Topic: RB2011 19" Problems with routing
Replies: 30
Views: 8148

Re: RB2011 19" Problems with routing

It would help if you could upload the config - output from /export compact.

It is not clear from the description if you are using NAT for clients or if the relevant outbound interfaces are masqueraded.
by CelticComms
Wed Jan 23, 2013 11:50 pm
Forum: Beginner Basics
Topic: VoIP problems
Replies: 4
Views: 2106

Re: VoIP problems

SIP just provides the control signalling. You need ports open for the RTP traffic (audio) too.
by CelticComms
Wed Jan 23, 2013 11:03 pm
Forum: Beginner Basics
Topic: How to set a VLN on RB750GL/RB751...
Replies: 17
Views: 3264

Re: How to set a VLN on RB750GL/RB751...

The switch has some VLAN features which may or may do what you want: http://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features If you want to create the VLANs the generic way within RouterOS you: Create one or more VLAN interfaces and assign them to the relevant Ethernet interface. You can then assi...
by CelticComms
Wed Jan 23, 2013 4:39 pm
Forum: General
Topic: Is there such a model
Replies: 10
Views: 2120

Re: Is there such a model

The 433UAH and 433UAHL have 3 ethernet, USB and some PCI mini slots of you want to add WiFi. There are cases available which have enough space to allow the dongle to be internal and run the external antenna connection to the back of the case for connection of an external antenna.
by CelticComms
Wed Jan 23, 2013 4:32 pm
Forum: Beginner Basics
Topic: few NETs on ONE interface
Replies: 4
Views: 1149

Re: few NETs on ONE interface

I think i found it in
/ip addresses "add new"
That is correct if you simply want multiple subnets serviced by the same interface on the router.
by CelticComms
Tue Jan 22, 2013 10:11 pm
Forum: General
Topic: routerOS frequently floods LAN
Replies: 6
Views: 2753

Re: routerOS frequently floods LAN

Here are the firewall rules. Some are disable and some are used for hotspot but disabled currently. I'm also using mangle and NAT to make sure that traffic can pass even though the ISP doesnt allow routers (student ISP) but i hate not being able to use a firewall. At a very fast glance I only saw t...
by CelticComms
Tue Jan 22, 2013 7:09 pm
Forum: General
Topic: some help with NAT+no-ip.org
Replies: 2
Views: 882

Re: some help with NAT+no-ip.org

It would be more useful to see your config (/export compact). The image doesn't really help.

The input filter chain in /IP Firewall control access to the router itself.
by CelticComms
Tue Jan 22, 2013 6:32 pm
Forum: General
Topic: Is there such a model
Replies: 10
Views: 2120

Re: Is there such a model

We operate both Mikrotik boards with USB modems internally to the enclosure and RouterOS running on third party embedded X86 boxes which have internal PCIe mini plus several gigabit ethernet interfaces. VPN from dynamic / private addresses at the remote Mikrotik end to a central Cisco unit can be do...
by CelticComms
Tue Jan 22, 2013 6:20 pm
Forum: Beginner Basics
Topic: Problem installing MikroTik 5.22 on Dell PowerEdge R210 II
Replies: 16
Views: 4305

Re: Problem installing MikroTik 5.22 on Dell PowerEdge R210

Can you describe that part of the BIOS settings? I thought I had configured one of those to ATA mode.
by CelticComms
Tue Jan 22, 2013 5:27 pm
Forum: General
Topic: routerOS frequently floods LAN
Replies: 6
Views: 2753

Re: routerOS frequently floods LAN

There are standard DOS attacks that use multicast etc. . If you upload your firewall rules we can comment on them.
by CelticComms
Tue Jan 22, 2013 5:24 pm
Forum: General
Topic: Internet access
Replies: 27
Views: 4496

Re: Internet access

???????????????????????????????
I suggested a specific test to carry out......
by CelticComms
Tue Jan 22, 2013 5:14 pm
Forum: Beginner Basics
Topic: Set ETH2 as WAN port
Replies: 6
Views: 2360

Re: Set ETH2 as WAN port

Try to be more specific - "not work" is rather vague.

Make sure that the interface is not in a bridge or slaved to another interface. Check the status of the interface - is it up? Speed? Duplex?
by CelticComms
Tue Jan 22, 2013 4:02 pm
Forum: Beginner Basics
Topic: Set ETH2 as WAN port
Replies: 6
Views: 2360

Re: Set ETH2 as WAN port

You add the DHCP client to the relevant interface in:

/IP
DHCP Client
by CelticComms
Mon Jan 21, 2013 5:18 pm
Forum: General
Topic: ARP Proxy with only a subnet
Replies: 3
Views: 2845

Re: ARP Proxy with only a subnet

Glad to hear that it solved the immediate problem. Don't forget to consider migrating to a VLAN solution at some point. :)
by CelticComms
Sun Jan 20, 2013 12:50 am
Forum: General
Topic: routerOS frequently floods LAN
Replies: 6
Views: 2753

Re: routerOS frequently floods LAN

The description sounds like a fairly standard DOS attack. What are your current firewall rules?
by CelticComms
Sun Jan 20, 2013 12:16 am
Forum: Beginner Basics
Topic: Routing and PPPOE
Replies: 10
Views: 2277

Re: Routing and PPPOE

And Leased line customer on LAN will be given IP 202.140.x.37-202.140.47.64. How will I write the route on MT ? These numbers seem a bit odd but to give you an example, try using a network allocation 202.140.x.32/28 You could either: A Place the IP 202.140.x.33 on your gateway router Allocate 202.1...
by CelticComms
Sat Jan 19, 2013 7:02 pm
Forum: General
Topic: ARP Proxy with only a subnet
Replies: 3
Views: 2845

Re: ARP Proxy with only a subnet

If you give the RouterBoard an IP address on 198.51.100.0/24 on the relevant interface then proxy arp will not reply to requests from that subnet.

If those switches support VLANs I would suggest moving to VLANs and dumping proxy arp.
by CelticComms
Sat Jan 19, 2013 6:19 pm
Forum: Beginner Basics
Topic: Basic router setup, with VPN for 2 locations
Replies: 2
Views: 1220

Re: Basic router setup, with VPN for 2 locations

Which device did TWC provide? If their modem can be placed in bridge mode you can take the static IP directly on the routerboard which makes VPN options easier.
by CelticComms
Fri Jan 18, 2013 5:30 pm
Forum: Beginner Basics
Topic: Public IP to router?
Replies: 10
Views: 2013

Re: Public IP to router?

The NAT and forwarding filter entries are probably where I would start.

If it is hard to sanitize for public posting you can contact me by email.
by CelticComms
Fri Jan 18, 2013 2:21 pm
Forum: General
Topic: Mikrotik Support URGENT - Suggestion
Replies: 1
Views: 698

Re: Mikrotik Support URGENT - Suggestion

Could you explain what you mean by the hotspot server "going down".

3 users doesn't sound like a heavy load.
by CelticComms
Fri Jan 18, 2013 3:14 am
Forum: Beginner Basics
Topic: Blocking DNS
Replies: 3
Views: 986

Re: Blocking DNS

You probably want to DST NAT outbound DNS traffic unless it originates from your internal DNS server in which case it is allowed to pass outside as normal.
by CelticComms
Thu Jan 17, 2013 10:27 pm
Forum: Beginner Basics
Topic: Routing and PPPOE
Replies: 10
Views: 2277

Re: Routing and PPPOE

How are the static IP customers attached to the router? Also via PPPoE? Another way?
by CelticComms
Thu Jan 17, 2013 9:19 pm
Forum: Beginner Basics
Topic: Public IP to router?
Replies: 10
Views: 2013

Re: Public IP to router?

Try uploading your /export compact output so we can see the current situation.
by CelticComms
Thu Jan 17, 2013 8:07 pm
Forum: General
Topic: Internet access
Replies: 27
Views: 4496

Re: Internet access

Your problems are probably caused by using station pseudo-bridge mode with the "station" end connected to a router. On the PC try pinging both the routerboard at 0.30 and the gateway at 0.1. Then look at the ARP cache (arp -a). Are you seeing an ARP entry for 0.1 which is distinct from 0.3...
by CelticComms
Thu Jan 17, 2013 6:58 pm
Forum: General
Topic: Firewall - allow connections in one direction
Replies: 3
Views: 3886

Re: Firewall - allow connections in one direction

If the subnet that these clients are on is 192.168.0.0/24 connected to one router interface then traffic between 192.168.0.x and 192.168.0.y isn't going to be routed via the router so firewall filters would have no effect. If one of the addresses is actually the routerboard then use input filters to...
by CelticComms
Thu Jan 17, 2013 6:52 pm
Forum: Beginner Basics
Topic: Public IP to router?
Replies: 10
Views: 2013

Re: Public IP to router?

Try using trace route to see what is happening to the internal traffic.
by CelticComms
Thu Jan 17, 2013 5:19 pm
Forum: Beginner Basics
Topic: Public IP to router?
Replies: 10
Views: 2013

Re: Public IP to router?

Sounds like you may need hairpin NAT:

http://wiki.mikrotik.com/wiki/Hairpin_NAT
by CelticComms
Thu Jan 17, 2013 2:16 pm
Forum: General
Topic: Ethernet speed is changing automatically 1gbps to 100mbps
Replies: 1
Views: 698

Re: Ethernet speed is changing automatically 1gbps to 100mbp

Very hard to comment without more context!

Presumably you expect 1 Gbps? Remember that 1000BASE-T uses all 4 pairs in a CAT5 cable so some cable faults will cause a link to revert to 100BASE-TX.
by CelticComms
Wed Jan 16, 2013 10:52 pm
Forum: General
Topic: Forwarding NAT to second router?
Replies: 3
Views: 1134

Re: Forwarding NAT to second router?

It really depends on what service you want to be available to clients behind that second router. e.g. you could have basic NAT for the R2's traffic on R1 and have NAT/PAT for the R2 clients on R2 if that allowed all required services to run. Many permutations - more info required to filter out possi...
by CelticComms
Wed Jan 16, 2013 2:30 pm
Forum: General
Topic: 2 public ip blocks on same router with 2 different gateways
Replies: 3
Views: 1162

Re: 2 public ip blocks on same router with 2 different gatew

OK - well you mentioned that the ADSL router was set to bridge but handing the ADSL router the layer 3 (IP) traffic on its IP address doesn't sound like normal bridge behaviour.
by CelticComms
Wed Jan 16, 2013 1:48 pm
Forum: General
Topic: 2 public ip blocks on same router with 2 different gateways
Replies: 3
Views: 1162

Re: 2 public ip blocks on same router with 2 different gatew

You mention 1.1.1.1 both in the context of the ADSL router having that address and it being the gateway on the RouterBoard and it isn't clear exactly what your setup is.

Could you post output from /export compact?
by CelticComms
Tue Jan 15, 2013 11:48 pm
Forum: Beginner Basics
Topic: VLANS on trunk interface with DHCP
Replies: 3
Views: 2796

Re: VLANS on trunk interface with DHCP

You need to apply the IP addresses / netmasks to the VLAN interfaces not the TRNK_LAN interface.

The DHCP servers are showing invalid status because you have them bound to interfaces which have no IP/netmasks.
by CelticComms
Tue Jan 15, 2013 6:55 pm
Forum: Beginner Basics
Topic: Low connection speed
Replies: 5
Views: 1616

Re: Low connection speed

You say that you disabled the auto-negotiation on the WAN port. The Cisco gear at the other end will then speed sense the line at 100 Mbps but will set the port to HALF DUPLEX even if your end is set to full duplex - and that kills the throughput due to late collisions etc. . Either you need to get ...
by CelticComms
Tue Jan 15, 2013 5:53 pm
Forum: Beginner Basics
Topic: PPOE disconnecting
Replies: 1
Views: 625

Re: PPOE disconnecting

Can you post the output from /export compact so we can get an overview?
by CelticComms
Tue Jan 15, 2013 5:07 pm
Forum: Beginner Basics
Topic: Routing Help !!!
Replies: 6
Views: 1534

Re: Routing Help !!!

If you really just want to route (no NAT & no firewall) then you could place the WAN/LAN interfaces in 2 different VRFs (In IP / Route). Make 2 VRF entries and assign one WAN & LAN to each. Those interfaces will then only see routing entries for the other interfaces in their VRFs. That is a ...
by CelticComms
Tue Jan 15, 2013 4:48 pm
Forum: General
Topic: Sub VLAN interface?
Replies: 13
Views: 5216

Re: Sub VLAN interface?

The presence of bridges can confuse matters....

Probably best if you upload output from /export compact so we can get an overview.
by CelticComms
Tue Jan 15, 2013 3:09 pm
Forum: General
Topic: Sub VLAN interface?
Replies: 13
Views: 5216

Re: Sub VLAN interface?

In my configuration, I have a VLAN set up: /int vlan add vlan-id=254 name=VLAN254 interface=ether8 ... and an IP on the VLAN: /ip addr add address=192.168.16.2/24 interface=VLAN254 ... This one MikroTik itself can ping its own IP address there, but another MikroTik across a trunked connection canno...
by CelticComms
Tue Jan 15, 2013 2:52 pm
Forum: Beginner Basics
Topic: Port forwarding not working for me on RB411 / 6.0
Replies: 6
Views: 1671

Re: Port forwarding not working for me on RB411 / 6.0

OK - well if Torch doesn't show the connection attempt it sounds as if the problem is further back at the APN level....
by CelticComms
Tue Jan 15, 2013 2:43 pm
Forum: General
Topic: Mikrotik propitiatory solution for FTTx
Replies: 11
Views: 6762

Re: Mikrotik propitiatory solution for FTTx

clock accuracy should not be an issue Mikrotik can define the hardware compatibility or we can use the same SFP at both ends so there should not be clocking issue Ok - well tell that to all the OLT/ONT manufacturers! I'll wait for the prices to drop and use a system that doesn't depend on wishful t...
by CelticComms
Tue Jan 15, 2013 1:43 pm
Forum: Beginner Basics
Topic: PING issues
Replies: 3
Views: 1997

Re: PING issues

Is the RouterBoard the only device in path?

I ask because there are a bunch of devices from companies like Netgear which drop pings greater than 512 bytes.
by CelticComms
Mon Jan 14, 2013 7:00 pm
Forum: General
Topic: PING an IP address assigned to a VLAN interface on an RB1200
Replies: 5
Views: 5039

Re: PING an IP address assigned to a VLAN interface on an RB

What does the routing table look like on the RB1200? Have you only tried pinging from the command line? Any difference if you use the tool in Winbox and explicitly state the interface?
by CelticComms
Mon Jan 14, 2013 4:44 pm
Forum: Beginner Basics
Topic: Trunking Vlans to VMWare (Block VLAN->VLAN traffic)
Replies: 13
Views: 3070

Re: Trunking Vlans to VMWare (Block VLAN->VLAN traffic)

The router will route (forward) all traffic unless you stop it in the forwarding filters.

You can start with a simple rule in the forwarding chain with action=drop. Then add rules above it with action="accept" for any traffic that you actually want to forward.
by CelticComms
Mon Jan 14, 2013 3:02 pm
Forum: General
Topic: Filter connections from a PPTP Server
Replies: 2
Views: 918

Re: Filter connections from a PPTP Server

If you make a PPTP interface specifically for that incoming PPTP user then you can simply limit the traffic in the forwarding filters based on a combination of inbound interface, src IP, destination IP etc.
by CelticComms
Mon Jan 14, 2013 2:54 pm
Forum: General
Topic: DHCP issue - getting ip address from WAN port
Replies: 2
Views: 930

Re: DHCP issue - getting ip address from WAN port

If you want port 1 to be the WAN port then it would not be "bridged" to ports 2-5 in a typical LAN/WAN setup. The bridge is transporting the DHCP requests/responses to your upstream WAN connection's DHCP server and that is why you are getting WAN addresses assigned to LAN devices.
by CelticComms
Mon Jan 14, 2013 2:48 pm
Forum: Beginner Basics
Topic: Port forwarding not working for me on RB411 / 6.0
Replies: 6
Views: 1671

Re: Port forwarding not working for me on RB411 / 6.0

Is the connection working for internet access?

Make sure that the device at 192.168.1.103 is using the routerboard as its default gateway.

Does the APN actually allow inbound traffic? You can use Torch on the interface to see if you are seeing the inbound 3389 traffic.
by CelticComms
Sun Jan 13, 2013 3:47 pm
Forum: Beginner Basics
Topic: DHCP leases being offered but not accepted
Replies: 9
Views: 11087

Re: DHCP leases being offered but not accepted

If you dump some of that ARP traffic to a pcap file and look at it in WireShark you should be able to tell if it is circulating traffic.
by CelticComms
Fri Jan 11, 2013 11:57 pm
Forum: Beginner Basics
Topic: cant configure NAT rule for webserver
Replies: 4
Views: 1749

Re: cant configure NAT rule for webserver

It looked like you perhaps combined the text for a couple of rules - cut & paste issue maybe.

Upload the output from /export compact if you want your config checked.
by CelticComms
Thu Jan 10, 2013 9:38 pm
Forum: General
Topic: Sub VLAN interface?
Replies: 13
Views: 5216

Re: Sub VLAN interface?

The gateway is a routing entry. The IP allocation to an interface is just the IP number and netmask.
by CelticComms
Thu Jan 10, 2013 8:31 pm
Forum: General
Topic: 2 public IP's on wan port 1
Replies: 4
Views: 1599

Re: 2 public IP's on wan port 1

You can certainly put the additional public IP on your WAN interface but you would still need to NAT over to the server. Placing the public IP directly on the server can also be done even if that IP is part of the WAN linknet but that involves various ARP / ARP proxy features and is best only done o...
by CelticComms
Thu Jan 10, 2013 7:45 pm
Forum: Beginner Basics
Topic: about subnet and range
Replies: 6
Views: 3186

Re: about subnet and range

Check if the rules will take a range - 1.2.3.4-1.2.3.5.

A 2 host range has ending /31.
by CelticComms
Thu Jan 10, 2013 6:49 pm
Forum: General
Topic: Sub VLAN interface?
Replies: 13
Views: 5216

Re: Sub VLAN interface?

IP addresses are assigned to VLAN interfaces like any other interface.

Are you using Winbox?
by CelticComms
Thu Jan 10, 2013 6:44 pm
Forum: General
Topic: Enable IPv6 behind MikroTik
Replies: 3
Views: 1780

Re: Enable IPv6 behind MikroTik

Install the IPv6 package on the Mikrotik and allocate some /64s from the /48.
by CelticComms
Thu Jan 10, 2013 3:12 pm
Forum: General
Topic: Multiple IP's
Replies: 6
Views: 1243

Re: Multiple IP's

If you plan to NAT the traffic anyway (i.e. not put the public IPs on the server(s)) then placing the IPs on the public interface is should always work. Otherwise you really need to know how the traffic is being passed to be sure what will work and what will not. For example, if traffic for an addit...
by CelticComms
Thu Jan 10, 2013 2:58 pm
Forum: General
Topic: Multiple IP's
Replies: 6
Views: 1243

Re: Multiple IP's

That could work if the traffic for the relevant IP was being routed to another IP on the interface. If the upstream expects the IPs to all be directly ARPable then the something needs to respond to the ARP request.
by CelticComms
Thu Jan 10, 2013 2:25 pm
Forum: General
Topic: Multiple IP's
Replies: 6
Views: 1243

Re: Multiple IP's

Where were the additional public IPs applied in the alternate case? On the internal hosts?
by CelticComms
Wed Jan 09, 2013 9:21 pm
Forum: Beginner Basics
Topic: using routing mark to specify a WAN IP for NAT'd customer
Replies: 2
Views: 1307

Re: using routing mark to specify a WAN IP for NAT'd custome

How is the WAN interface normally NATted? If there is a default masquerade maybe you need a SRC NAT entry earlier to catch the specific conditions for the customer's outbound traffic.
by CelticComms
Wed Jan 09, 2013 8:18 pm
Forum: General
Topic: a way around multiple pppoe logins from one mac
Replies: 7
Views: 3406

Re: a way around multiple pppoe logins from one mac

In RouterOS only the bridge MAC address is seen by devices attached to bridge member ports so virtual interfaces will not help in this case - you would always be presenting PADI packets from the bridge MAC address. Are you trying to use some kind of free service? If the bearer circuit can support 30...
by CelticComms
Wed Jan 09, 2013 7:38 pm
Forum: Beginner Basics
Topic: Can't ping routers' gateway address
Replies: 10
Views: 14352

Re: Can't ping routers' gateway address

If you look at those ARP entries the problem seems to be that the same MAC address is showing for 10.20.1.20 and 10.20.1.2 even although 10.20.1.2 is assigned to router B. I suspect this is being caused by something in the configuration of the radio devices. The ping request to is probably being cir...
by CelticComms
Wed Jan 09, 2013 6:34 pm
Forum: Beginner Basics
Topic: Can't ping routers' gateway address
Replies: 10
Views: 14352

Re: Can't ping routers' gateway address

Suggest you check the ARP table on router A and see what MAC address it thinks the ping target it is on. I
by CelticComms
Wed Jan 09, 2013 6:00 pm
Forum: Beginner Basics
Topic: Can't ping routers' gateway address
Replies: 10
Views: 14352

Re: Can't ping routers' gateway address

Where is the address 10.20.1.20 assigned to?
by CelticComms
Wed Jan 09, 2013 5:04 pm
Forum: Beginner Basics
Topic: cant configure NAT rule for webserver
Replies: 4
Views: 1749

Re: cant configure NAT rule for webserver

The section:
out-interface=WAN
looks unlikely since the server is presumably on a LAN interface.

Try removing that from the rule. Also, your server needs to be pointing to the RouterBoard as its default gateway.
by CelticComms
Wed Jan 09, 2013 4:20 pm
Forum: General
Topic: dhcp error
Replies: 7
Views: 2117

Re: dhcp error

You have run out of addresses in the pool. Either extend the pool, shorten the lease time or add additional pools (plus other implied config changes).
by CelticComms
Wed Jan 09, 2013 3:26 pm
Forum: General
Topic: MikroTik why not turn to new Cisco/Juniper?
Replies: 33
Views: 14545

Re: MikroTik why not turn to new Cisco/Juniper?

Since the question seems based on questionable assumptions I offer a tongue in cheek answer: Because it is more fun being Mikrotik! Mikrotik has done fairly well at identifying areas not served well by the likes of Cisco and hopefully the owners are seeing a reasonable return on the capital invested...
by CelticComms
Wed Jan 09, 2013 3:13 pm
Forum: Beginner Basics
Topic: Can't ping routers' gateway address
Replies: 10
Views: 14352

Re: Can't ping routers' gateway address

Had a very quick look while drinking coffee and didn't see a reason for the problem. Could you try a trace route?
by CelticComms
Tue Jan 08, 2013 3:59 pm
Forum: Beginner Basics
Topic: Configure 450 router to be a switch
Replies: 1
Views: 681

Re: Configure 450 router to be a switch

For the RB450 that you want to behave as a switch just make sure that Ether2-5 have Ether 1 set as master and it should provide layer 2 switching.
by CelticComms
Tue Jan 08, 2013 3:25 pm
Forum: Beginner Basics
Topic: DHCP-Server And Bridge problem.
Replies: 2
Views: 1437

Re: DHCP-Server And Bridge problem.

Not 100% sure of your question but note that:

1) If a bridge is present run the DHCP server on the bridge not the member ports.
2) Make sure a relevant IP address is assigned to the interface otherwise the DHCP server will show as "invalid".
by CelticComms
Tue Jan 08, 2013 3:06 pm
Forum: Beginner Basics
Topic: Can't ping routers' gateway address
Replies: 10
Views: 14352

Re: Can't ping routers' gateway address

Sounds like an addressing/routing issue. Can you upload the routing tables from the 2 routers?
by CelticComms
Mon Jan 07, 2013 2:26 pm
Forum: General
Topic: Mikrotik propitiatory solution for FTTx
Replies: 11
Views: 6762

Re: Mikrotik propitiatory solution for FTTx

A TDMA based solution would require clock accuracy similar to what is required of OLTs (or suffer a larger overhead to accommodate poorer clock accuracy) so I suspect that you may as well use SFP format OLTs and get the savings from those fast becoming mass produced items.
by CelticComms
Sun Jan 06, 2013 3:10 pm
Forum: Beginner Basics
Topic: Help with network configuration
Replies: 4
Views: 1299

Re: Help with network configuration

By default the router will route any networks that you define unless rules in the forward chain in /IP Filters stop it from doing so. It sounds as if you want to do something which likely involves SRC/DST NAT and/or Masquerade but I couldn't tell exactly what you want to achieve. Can you give more d...
by CelticComms
Sat Jan 05, 2013 6:49 pm
Forum: General
Topic: RB2011UAS stopped working during heavy traffic on SFP
Replies: 10
Views: 3385

Re: RB2011UAS stopped working during heavy traffic on SFP

That conversation probably related to differences between the chipsets on the routerboards. It is still possible to create VLAN "trunks" in RouterOS on the RB2011 but currently not possible to do so at the chip level on the AR8327.
by CelticComms
Sat Jan 05, 2013 3:10 pm
Forum: General
Topic: RB2011UAS stopped working during heavy traffic on SFP
Replies: 10
Views: 3385

Re: RB2011UAS stopped working during heavy traffic on SFP

@nissandata ..................... If you have inside of one box setted up VLANs it should work proper, but if you are setting up an uplink and you will now transport the VLANs through this uplinks it is so called out a "trunk" and this is purely not supported by the RB2011. Or better and ...
by CelticComms
Fri Jan 04, 2013 6:10 pm
Forum: Beginner Basics
Topic: [SOLVED] PPTP Server problem
Replies: 16
Views: 32965

Re: PPTP Server problem

Does the WAN port have a public IP on it?
by CelticComms
Fri Jan 04, 2013 4:12 pm
Forum: Beginner Basics
Topic: Traffic flow: why packet does not traverse SRC-NAT
Replies: 8
Views: 5549

Re: Traffic flow: why packet does not traverse SRC-NAT

You have passthrough=yes on the mark-routing rule. Are there any other mark-routing rules below it? If there are they could be overwriting the mark.
by CelticComms
Fri Jan 04, 2013 4:03 pm
Forum: General
Topic: Fix Public IP Issue
Replies: 5
Views: 1694

Re: Fix Public IP Issue

OK - this is one of those messy/grey areas where different routers take different approaches. The cleanest solution which will work with any router is: 1) Give the server a private address. 2) Use SRC NAT to ensure that the server's outbound traffic originates with the correct public address. 3) Use...
by CelticComms
Fri Jan 04, 2013 3:22 pm
Forum: General
Topic: Neighbour discovery tool for Linux?
Replies: 5
Views: 6713

Re: Neighbour discovery tool for Linux?

LLDP is relatively new. Cisco had been doing CDP for a long time before LLDP came along.

Mikrotik implemented both an IP based discovery system (UDP port 5678) and also uses CDP style L2 SNAP announcements.
by CelticComms
Fri Jan 04, 2013 3:15 pm
Forum: Beginner Basics
Topic: [SOLVED] PPTP Server problem
Replies: 16
Views: 32965

Re: PPTP Server problem

The service port entry should not be needed to have PPTP running directly on RouterOS.

Can you try removing the new connection-state qualification on this rule:


add action=accept chain=input connection-state=new disabled=no dst-port=1723 in-interface=OTEnet6x protocol=tcp
by CelticComms
Fri Jan 04, 2013 12:31 am
Forum: General
Topic: Name Resolution between EoIP Tunnels
Replies: 1
Views: 708

Re: Name Resolution between EoIP Tunnels

If you use the RouterOS DNS server you could let it cache entries pulled from the central office DNS server so that all lookups don't use tunnel bandwidth, but of course if you lose the tunnel it might fail external lookups unless you can have it use an external DNS server if the tunnel fails. The m...
by CelticComms
Fri Jan 04, 2013 12:00 am
Forum: General
Topic: Neighbour discovery tool for Linux?
Replies: 5
Views: 6713

Re: Neighbour discovery tool for Linux?

RouterOS sends out CDP type packets too so maybe one of the Linux CDP tools would help:

http://openmaniak.com/cdp.php


I suspect Google has others too.
by CelticComms
Thu Jan 03, 2013 11:26 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

The reason is each pppoe-out (gateway) connection only has enough bandwidth to support 2-3 pcs thus the subnetting. OK - so you want to share the traffic over the PPPoE connections, but from what you have said so far you don't need to create multiple subnets in order to do that! You can simply use ...
by CelticComms
Thu Jan 03, 2013 9:42 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

As far as I see the 3 different subnets are all on the same physical network so quite what purpose they server is a mystery to me. You can specify IP ranges in the Src Address field of a mangle rule - so why not keep it simply and just use one subnet? I suspect that you went down that path because y...
by CelticComms
Thu Jan 03, 2013 8:48 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

Indeed it should, but let's roll back a bit further. Why place the 3 ranges on different subnets? You could have 3 pools within the same subnet which means the same gateway and then just mark routing using mangle rules which have the Src. Address set to a range such as 192.168.10.1-192.168.10.x . If...
by CelticComms
Thu Jan 03, 2013 8:18 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

Thats exactly what i was doing. the only thing you changed in that example is the gateway which would be invalid ... because i need to use the pppoe client connections as gateways. . No. These entries are placing rules in the relevant routing table to provide a path back the the originating IPs. In...
by CelticComms
Thu Jan 03, 2013 8:08 pm
Forum: Beginner Basics
Topic: [SOLVED] PPTP Server problem
Replies: 16
Views: 32965

Re: PPTP Server problem

The ARP setting wouldn't stop the PPTP connection from being made.

Are the two relevant filters set up as input filters allowing:

TCP to port 1723 from the WAN interface?
GRE (protocol 47) from the WAN interface?
by CelticComms
Thu Jan 03, 2013 4:47 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

e.g. add disabled=no distance=1 dst-address=192.168.10.0/29 gateway=LAN-Bridge routing-mark=\ 10users scope=30 target-scope=10 add disabled=no distance=1 dst-address=192.168.20.0/29 gateway=LAN-Bridge routing-mark=\ 20users scope=30 target-scope=10 add disabled=no distance=1 dst-address=192.168.30.0...
by CelticComms
Thu Jan 03, 2013 2:38 pm
Forum: General
Topic: RB2011 Gepon support
Replies: 4
Views: 1394

Re: RB2011 Gepon support

There are some units around which *may* have the required functionality but I have not had a chance to test them yet.

e.g.

http://integranetworks.net/wp-content/u ... Factor.pdf
by CelticComms
Thu Jan 03, 2013 2:25 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

I suggest that you add routing entries to the relevant 192.168.x.y subnets with the appropriate routing marks - I have seen weird things happen without such routes when using mangle to mark routing. Incidentally, are all those PPPoE clients being serviced by the same host? The typical problem with m...
by CelticComms
Thu Jan 03, 2013 2:19 pm
Forum: Beginner Basics
Topic: IP Camera Port forwarding
Replies: 25
Views: 27429

Re: IP Camera Port forwarding

Dst. Address provides the possibility to limit the rule to packets *originally destined* for Dst. Address.

To Addresses is the new address that these relevant traffic should be sent to via NAT.
by CelticComms
Wed Jan 02, 2013 9:24 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

PCC is designed to spread the connection load over multiple streams (PPPoE connections in your case). You should probably at least be aware of the PCC approach before you decide what to use. PCC shares at the connection level which has the advantage that one user can be using multiple PPPoE connecti...
by CelticComms
Wed Jan 02, 2013 8:51 pm
Forum: General
Topic: lan users --> multiple pppoe gateways
Replies: 18
Views: 4525

Re: lan users --> multiple pppoe gateways

You could do something along those lines certainly. You also wopuld have to ensure that the routing table had the appropriate route entries for those routing marks - e.g. a default route entry for the corresponding PPPoE client. Since what you are proposing seems to assign clients randomly to a PPPo...
by CelticComms
Wed Jan 02, 2013 8:44 pm
Forum: Beginner Basics
Topic: Issues acquiring IP from ISP
Replies: 4
Views: 1172

Re: Issues acquiring IP from ISP

Does the ISP possibly limit the IPs provided per line? If you want to test that possibility then temporarily set the routerboard WAN MAC address to the MAC address of the WAN port on the original router and see if it can then get an IP via DHCP.
by CelticComms
Wed Jan 02, 2013 6:02 pm
Forum: General
Topic: Admins challenge for you can EoIP do this i guess no
Replies: 9
Views: 1366

Re: Admins challenge for you can EoIP do this i guess no

OK - that does sound as if MNDP is being transferred ofer the EoIP link. EoIP uses GRE (protocol 47) as does PPTP. Did you try a PPTP connection first and it didn't work? If so maybe port 1723 is blocked.

If the connection is up and functional maybe you have a routing issue...
by CelticComms
Wed Jan 02, 2013 5:41 pm
Forum: General
Topic: Admins challenge for you can EoIP do this i guess no
Replies: 9
Views: 1366

Re: Admins challenge for you can EoIP do this i guess no

It would be useful to know a little more about what is between site 1 and site 2. The fact that you can ping from site 1 simply means that ICMP is being passed. The fact that site 1 and site 2 show up in IP Neighbors could mean a number of things, but if there is a layer 2 path between site 1 and si...
by CelticComms
Wed Jan 02, 2013 2:24 pm
Forum: General
Topic: Fix Public IP Issue
Replies: 5
Views: 1694

Re: Fix Public IP Issue

OK - I think I misread your original post and was confused by the "gateway IP description".

What does the status tab for your PPPoE show when connected?
by CelticComms
Wed Jan 02, 2013 12:36 am
Forum: Beginner Basics
Topic: Reaching only one PC in other subnet
Replies: 15
Views: 4340

Re: Reaching only one PC in other subnet

What is the intent of this rule - and does the ping to 10.10.10.5 work if you disable the rule?
add action=masquerade chain=srcnat comment="masquerade hotspot network" src-address=10.10.10.0/24
by CelticComms
Tue Jan 01, 2013 10:45 pm
Forum: Beginner Basics
Topic: Reaching only one PC in other subnet
Replies: 15
Views: 4340

Re: Reaching only one PC in other subnet

It looks as if you have no effective forwarding filters which would mean that all forwarding is allowed. Hopefully there is a firewall between Ether1 and the internet otherwise you may want to establish forwarding rules! If barred routing is not the problem then perhaps the various masquerade / NAT ...
by CelticComms
Tue Jan 01, 2013 8:22 pm
Forum: General
Topic: Fix Public IP Issue
Replies: 5
Views: 1694

Re: Fix Public IP Issue

If the IP traffic is leaving you with the source set to 120.120.3.2 then your ISP must be presenting it upstream as 120.120.3.1 - i.e. the address from their end of the link net. I suspect that only your ISP can change that.
by CelticComms
Tue Jan 01, 2013 8:05 pm
Forum: Beginner Basics
Topic: Converting my Cisco config
Replies: 3
Views: 2197

Re: Converting my Cisco config

I didn't actually see any "routing" in this config in the layer 3 sense.

Do be aware that RouterOS does not support rapid-PVST. That is only an issue if there are redundant paths and other Cisco gear involved.
by CelticComms
Tue Jan 01, 2013 7:56 pm
Forum: General
Topic: External ip per VLAN and Queues
Replies: 1
Views: 672

Re: External ip per VLAN and Queues

DHCP servers work fine on VLAN interfaces. Did you assign an IP to the interface first? If you don't the DHCP server will not work on the interface.
by CelticComms
Tue Jan 01, 2013 7:52 pm
Forum: General
Topic: IGMP-Proxy multiple interfaces
Replies: 3
Views: 3406

Re: IGMP-Proxy multiple interfaces

IGMP Proxy works with bridge interfaces, ethernet interfaces and VLAN interfaces. Make sure that you are allowing IGMP from relevant interfaces (input filters).
by CelticComms
Tue Jan 01, 2013 7:29 pm
Forum: Beginner Basics
Topic: Reaching only one PC in other subnet
Replies: 15
Views: 4340

Re: Reaching only one PC in other subnet

If clients on those 2 LANs have their default gateway set to the Mikrotik device then by default the Mikrotik would be able to route traffic between the two LANs. The NAT tables are interesting but not sufficient information so please upload the output from /export compact so that we can see all the...
by CelticComms
Sat Dec 29, 2012 1:39 pm
Forum: Beginner Basics
Topic: IP Camera Port forwarding
Replies: 25
Views: 27429

Re: IP Camera Port forwarding

Can you post the output from /export compact?
by CelticComms
Fri Dec 28, 2012 12:58 pm
Forum: Beginner Basics
Topic: Can't surf web on simple config though ping and tracert work
Replies: 5
Views: 1959

Re: Can't surf web on simple config though ping and tracert

Remove this line first:
add address=192.168.88.1/24 comment="default configuration" interface=ether1
and then give us an update.

The partial web page loading is probably due to confused ARP entries caused by this IP mistakenly being on both Ether 1 & 9.
by CelticComms
Fri Dec 28, 2012 12:44 pm
Forum: Beginner Basics
Topic: IP Camera Port forwarding
Replies: 25
Views: 27429

Re: IP Camera Port forwarding

Well that wan IP is class C so I don't know how you would reach that from the outside world.
Class C addresses can be public or private. The OP's WAN address happens to be an RFC 1918 private address but that is not implied by it being "Class C".
by CelticComms
Thu Dec 27, 2012 2:11 pm
Forum: Beginner Basics
Topic: WAN on ether1 with static IP doesn't work
Replies: 8
Views: 2790

Re: WAN on ether1 with static IP doesn't work

DHCP is probably setting:

IP number, subnet, gateway

Route to link network

Default route

DNS servers

so the answer is most likely on one of those.

Post /export compact output for comment if you can't find the problem.
by CelticComms
Wed Dec 26, 2012 3:35 am
Forum: Beginner Basics
Topic: Help compiling DoS / Port scanning drop rules
Replies: 2
Views: 1669

Re: Help compiling DoS / Port scanning drop rules

The rules all appear to be input chain rules so they are only affecting traffic to the routerboard itself - not the forwarding chain which controls traffic to devices "behind" the router.
by CelticComms
Wed Dec 26, 2012 3:24 am
Forum: Beginner Basics
Topic: WAN on ether1 with static IP doesn't work
Replies: 8
Views: 2790

Re: WAN on ether1 with static IP doesn't work

I suggest that you port output from /export compact.

If you have the IP and subnet set correctly on that interface then the static route to that network should appear in the routing table with an S designation. If that isn't happening then something is wrong with the static IP assignment.
by CelticComms
Thu Dec 20, 2012 11:49 am
Forum: Beginner Basics
Topic: Remote PPTP client can't access LAN behind router
Replies: 2
Views: 2765

Re: Remote PPTP client can't access LAN behind router

Yes - you should enable proxy-arp on the LAN interface and your forwarding rules in /IP Firewall need to allow the traffic. Try posting your config using /export compact if you can't get it to work.
by CelticComms
Sat Dec 15, 2012 12:35 am
Forum: General
Topic: Router dies as soon as I connect the network.
Replies: 7
Views: 1808

Re: Router dies as soon as I connect the network.

I'm planning to go back there and just start adding devices one by one, maybe one of them has problem on the ether port. Sounds like a plan ... I would be surprised if a 20 EUR router had STP on its switch - can probably be checked on their web site. Note my comment earlier about the chip switch in...
by CelticComms
Fri Dec 14, 2012 8:43 pm
Forum: Beginner Basics
Topic: Master port config
Replies: 15
Views: 11975

Re: Master port config

If the interface does not have an IP address assigned to it and you try to add a DHCP server it will show it as "invalid". Make sure you have assigned an IP address to the interface that the DHCP server is on.
by CelticComms
Fri Dec 14, 2012 8:28 pm
Forum: Beginner Basics
Topic: Master port config
Replies: 15
Views: 11975

Re: Master port config

Where/when exactly are you seeing "invalid" Command line? Winbox?

You probably don't have a valid IP number on the interface.
by CelticComms
Fri Dec 14, 2012 8:01 pm
Forum: Beginner Basics
Topic: Master port config
Replies: 15
Views: 11975

Re: Master port config

Did you make sure that Ether2 has no master set?
by CelticComms
Fri Dec 14, 2012 7:05 pm
Forum: General
Topic: TCP performance
Replies: 77
Views: 37950

Re: TCP performance [SOLVED!]

If the connections on the switch were not negotiating correctly you have have had one side of the connection running half duplex and the other side running full duplex. That will kill throughput. That condition usually shows up as a spike in late collisions and poor throughput under load. I did not...
by CelticComms
Fri Dec 14, 2012 7:00 pm
Forum: General
Topic: Router dies as soon as I connect the network.
Replies: 7
Views: 1808

Re: Router dies as soon as I connect the network.

No it was not clear that the unit was working elsewhere. The setup may not be working but so far there isn't any evidence that the Mikrotik unit has "failed". If there is a traffic storm it would be evident if you monitor the interfaces. The shortest path to an answer is to examine the ins...