Community discussions

MikroTik App

Search found 1084 matches

by Caci99
Wed Feb 25, 2015 1:58 pm
Forum: General
Topic: QOS on RB493G
Replies: 3
Views: 1351

Re: QOS on RB493G

Well, to prioritize traffic, first you need to identify it among others. This can be done in mangle. I don't know much about OpenVPN, but you either identify by the port used by OpenVPN or by IP address that goes by one site to the other. Than you assign priority in queue tree with parent and child ...
by Caci99
Wed Feb 18, 2015 7:09 pm
Forum: Announcements
Topic: hAP lite
Replies: 391
Views: 239477

Re: hAP lite

Ok. It is cheap. But having only 32MB of ram?? Now, when wee see that it is very limiting for running v6.x and expecting that v7.x will be again more requesting? Why? Powering by unreliable small tiny micro usb connector? Why? No POE in? Why? Not possible to use wide range of power adapters like fo...
by Caci99
Wed Feb 18, 2015 2:51 pm
Forum: Announcements
Topic: hAP lite
Replies: 391
Views: 239477

Re: hAP lite

It looks promising, but a bit low on wireless power, very good price/feature ratio anyway. Isn't it time to have all ethernet ports on gigabit speed? What could be the cost of it? Nowadays all laptops and desktops, or network HDD cases ship with gigabit ethernet. I would also like to see a 5GHz prod...
by Caci99
Thu Feb 12, 2015 3:14 pm
Forum: General
Topic: Torrent
Replies: 43
Views: 15121

Re: Torrent

I have to admit I am bit lost with the scripting and rest. We were supposed to have an easy life, not make it harder. For me it was easy enough to browse on the download page when new version was out, click on torrent link and download. We even used to get email when new version was out, never mind ...
by Caci99
Thu Feb 12, 2015 1:33 pm
Forum: General
Topic: Torrent
Replies: 43
Views: 15121

Re: RouterOS v6.27 released

Torrents will return after we surgically remove them from the RouterOS release system, and make them entirely separate. The biggest problem with torrents is the initial seeding. There exists no stable command line torrent client that we know of. I don't quite understand what you have said there :),...
by Caci99
Thu Feb 12, 2015 12:35 pm
Forum: General
Topic: Torrent
Replies: 43
Views: 15121

Re: RouterOS v6.27 released

THX :DDD
upgraded a few rb's just to see how it goes.....
no torrent to share the love?
http://www.mikrotik.com/download/router ... 27.torrent

Though, there are no seeders to download from yet :(
Yes, thanks for the link. But why has Mikrotik removed the all file torrent link?
by Caci99
Wed Feb 11, 2015 2:51 pm
Forum: Beginner Basics
Topic: SMB and cyrillic symbols
Replies: 2
Views: 2501

Re: SMB and cyrillic symbols

Do you believe this is a problem related to RouterOS? I don't think so, because I don't think ROS changes the characters of the files. It must be related to the operating system from where you are trying to view the files, they might not support Cyrillic characters. To test it, try to browse the sam...
by Caci99
Wed Feb 11, 2015 2:42 pm
Forum: General
Topic: Winbox 3 RC
Replies: 636
Views: 208495

Re: Winbox 3 RC

I think it would be nice if the columns of winbox could be moved left or right, to rearrange them at one's needs.
I am talking about the columns of the connect window: address; session; group; note
I for example would have arranged them in this order: address; note; session ....

Can it be done?
by Caci99
Tue Feb 10, 2015 2:31 pm
Forum: General
Topic: Unidentified Network When Mikrotik Connect
Replies: 1
Views: 3027

Re: Unidentified Network When Mikrotik Connect

I guess you are talking about the Windows message Unidentified Network. Normally that happens because Windows detects that you are connected to a different router, that is discovered by Windows because of a different mac-address. Just chose public network. Also, next time, try to be more specific ab...
by Caci99
Sat Feb 07, 2015 2:28 pm
Forum: General
Topic: RouterOS v6.26!
Replies: 69
Views: 33083

Re: RouterOS v6.26!

What happened to the torrent link to download all packages? It isn't anymore on the download page, although adding it manually it works
http://www.mikrotik.com/download/router ... 26.torrent
by Caci99
Thu Feb 05, 2015 11:45 pm
Forum: General
Topic: automatic queue for user
Replies: 4
Views: 2127

Re: automatic queue for user

Actually, now that I am thinking of it again, I got it wrong :oops: The connection that I calculated as 1125kB, means a connection at a given time, not over 30 seconds. I have to rethink about it again, sorry.
by Caci99
Wed Feb 04, 2015 3:51 pm
Forum: General
Topic: automatic queue for user
Replies: 4
Views: 2127

Re: automatic queue for user

Let's think of it this way. If a connection has 300kbs for 30s, it means there are at least 9000kbps or 1125kB. Create a rule in firewall mangle: /ip firewall mangle add chain=forward action=add-dst-to-address-list protocol=tcp address-list=test address-list-timeout=1m in-interface=WAN out-interface...
by Caci99
Sun Feb 01, 2015 12:11 am
Forum: General
Topic: Email to SMS text gateway
Replies: 3
Views: 1725

Re: Email to SMS text gateway

but I understand there is a daily limit to the number of SMS notifications which will be sent ? Yes it does have, although I don't know how much. It depends on how sms you think you will get. Since google is in two step verification with sms, the limit must be a considerable number. Worth trying an...
by Caci99
Sat Jan 31, 2015 12:31 pm
Forum: General
Topic: OpenDNS - Catch all DNS traffic
Replies: 11
Views: 16804

Re: OpenDNS - Catch all DNS traffic

Hi all, I am trying to add the rule /ip firewall nat add chain=dstnat in-interface=LAN protocol=udp dst-port=53 action=redirect I do not have an interface called lan. Here is my interface list. Do I add the rules for each LAN interface or is there a way to globally address all of them? [admin@conSh...
by Caci99
Wed Jan 28, 2015 12:35 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2115

Re: Connected Interfaces Won't Communicate

Oh well then :), one more thing learned :).
I guess you can edit the title of the topic as the opener of it.
by Caci99
Tue Jan 27, 2015 8:23 pm
Forum: General
Topic: Email to SMS text gateway
Replies: 3
Views: 1725

Re: Email to SMS text gateway

Try this
http://techawakening.org/free-sms-alert ... docs/1130/
It will send an sms with the subject of email inline
by Caci99
Tue Jan 27, 2015 7:19 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2115

Re: Connected Interfaces Won't Communicate

Here is how I would have done it: /ip firewall mangle add chain=forward src-address=192.168.2.0/24 dst-address=192.168.3.0/24 action=accept add chain=forward src-address=192.168.3.0/24 dst-address=192.168.2.0/24 action=accept add chain=forward src-address=192.168.2.0/24 action=mark-connection new-co...
by Caci99
Mon Jan 26, 2015 2:24 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2115

Re: Connected Interfaces Won't Communicate

Static Route Dst-Add: 0.0.0.0, Gateway: PPPoE Dst-Add: 0.0.0.0, Gateway: 192.168.1.1 Are these routes both active? I don't think so. Because without policy routing in place, the router will just chose one of the two. Anyway, try to add an accept rule before/above the masquerade rule: /ip firewall n...
by Caci99
Mon Jan 26, 2015 12:16 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2115

Re: Connected Interfaces Won't Communicate

Are you using routing marks in /ip firewall mangle and in /ip route?
by Caci99
Wed Jan 21, 2015 9:50 pm
Forum: General
Topic: Interface queue type
Replies: 11
Views: 13945

Re: Interface queue type

As I understand it, hardware-queue is beneficial on switch like scenarios. The packets are processed on the hardware (NIC interface). In router situations, packets are inspected in source and destination, hardware queue will require CPU to do that, which in ethernet-default does not need it since et...
by Caci99
Wed Jan 21, 2015 7:33 pm
Forum: General
Topic: Interface queue type
Replies: 11
Views: 13945

Re: Interface queue type

There is a short explanation at the wiki: http://wiki.mikrotik.com/wiki/Manual:Queue#Queue_Types From this page: only-hardware-queue leaves interface with only hw transmit descriptor ring buffer which acts as a queue in itself. Usually at least 100 packets can be queued for transmit in transmit desc...
by Caci99
Tue Jan 20, 2015 8:09 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5426

Re: 2pppoe wans linked to separate interfaces

Well, the idea is simple. One marks the traffic by means of mangle and then routes that traffic to the desired gateway in ip routes.
Either that gateway is not working, or dns settings on laptop are not correct (not able to resolve http).
by Caci99
Tue Jan 20, 2015 7:58 pm
Forum: General
Topic: Need to export part of long list, how?
Replies: 2
Views: 976

Re: Need to export part of long list, how?

try this
/ip dhcp-server lease
print file=test where address>172.25.33.0 and address<172.25.34.0
by Caci99
Mon Jan 19, 2015 11:05 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5426

Re: 2pppoe wans linked to separate interfaces

I am a bit baffled why this is not working. Let's try a different approach. Keep all the config that is needed for this one to work, i.e the mangle rules stay, leave only the masquerade rule in /ip firewall nat, and then disable all rest in nat and in /ip firewall filter and see if it works or not.
by Caci99
Mon Jan 19, 2015 9:57 pm
Forum: General
Topic: can't make PCC and Port Forward work together
Replies: 7
Views: 2100

Re: can't make PCC and Port Forward work together

Well, masquerade substitutes the source address with the one of the interface the packet is leaving. I am not sure why this helps your case, looks like the router does not keep track from where the connection is coming and does not reply from the same gateway. Masquerade helps it ( I don't know how ...
by Caci99
Mon Jan 19, 2015 12:45 pm
Forum: General
Topic: can't make PCC and Port Forward work together
Replies: 7
Views: 2100

Re: can't make PCC and Port Forward work together

Try with a general masquerade rule:
/ip firewall nat
add chain=srcnat action=masquerade
leave the other masquerade rules, but disable them for the purpose of testing.
by Caci99
Mon Jan 19, 2015 12:28 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5426

Re: 2pppoe wans linked to separate interfaces

It should work, I don't see anything stopping it from working. Try it again, try it with pinging from laptop. Are you using dhcp-server? If yes what is the lease to the laptop, ip address, gateway, dns server? If not, post in here /ip firewall, /ip route, /ip addresses to have the whole picture in o...
by Caci99
Sun Jan 18, 2015 2:38 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5426

Re: 2pppoe wans linked to separate interfaces

What about the masquerade rule? How is it set?
Try with a simple masquerade:
/ip firewall nat
add chain=srcnat action=masquerade
by Caci99
Sat Jan 17, 2015 10:26 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5426

Re: 2pppoe wans linked to separate interfaces

On the mangle rules, change the last one passthrough=no
/ip firewall mangle
chain=prerouting action=mark-routing new-routing-mark=laptop passthrough=no connection-mark=laptop
that means that packets will not be processed any more and the mark will remain.
by Caci99
Sat Jan 17, 2015 7:44 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5426

Re: 2pppoe wans linked to separate interfaces

Ok, at the moment of enabling those rules i can't ping/reach my internal network/hosts 192.168.10.0/24 from my vpn-pptp connection 192.168.30.0/24 network, why is that? That's because with policy routing in place, when network 192.168.10.0/24 tries to reach 192.168.30.0/24 instead of using the defa...
by Caci99
Fri Jan 16, 2015 11:51 am
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5426

Re: 2pppoe wans linked to separate interfaces

Use routing marks in mangle, and after that apply the routing marks in routing table /ip firewall mangle add chain=prerouting src-address=computer1 action=mark-connection new-connection-mark=comp1 add chain=prerouting connection-mark=comp1 action=mark-routing new-routing-mark=comp1 same should be do...
by Caci99
Fri Jan 16, 2015 11:42 am
Forum: General
Topic: Priority Queuing Question
Replies: 1
Views: 978

Re: Priority Queuing Question

Yes, it is possible. In order to apply priority you should really understand how it works. You need at first a parent queue which will control its child queues. The child queues are were priority is applied. I would recommend use queue tree, but it can be done with simple queues as well. Read these ...
by Caci99
Thu Jan 15, 2015 7:23 pm
Forum: General
Topic: NTP client/server not working
Replies: 3
Views: 2670

Re: NTP client/server not working

and what configuration did you use to intercept time sync requests? Basically, the same as with dns requests redirect. That's where I got the idea from. NTP sends requests on udp protocol port 123: /ip firewall nat add chain=dstnat action=redirect to-ports=123 protocol=udp dst-address-type=!local d...
by Caci99
Thu Jan 15, 2015 7:19 pm
Forum: General
Topic: RB850 DHCP Failover Impossible?
Replies: 5
Views: 2360

Re: RB850 DHCP Failover Impossible?

Why you can't have the same Gateway check on DHCP that you have for static is anyone's guess... I guess that is the nature of the dhcp protocol, it doesn't look for the dhcp server until lease time expires (at my knowledge). And you can't modify a dynamic route, that's how mikrotik thought about it...
by Caci99
Thu Jan 15, 2015 11:58 am
Forum: General
Topic: NTP client/server not working
Replies: 3
Views: 2670

Re: NTP client/server not working

I have it working fine actually on a RB951Ui-2HnD, ROS 6.22. I have it setup as client and server, and I even setup a "transparent" server, meaning that all computers on LAN do synchronize with the router even if they point to another server.
by Caci99
Wed Jan 14, 2015 3:12 pm
Forum: General
Topic: Help required with MTU settings
Replies: 5
Views: 3203

Re: Help required with MTU settings

Set the MTU to default (1500), then try pinging something on the internet without fragmentation first, do discover what mtu is accepted without fragmentation. And then set the MTU according to the result. /ping 4.2.2.2 do-not-fragment size=1500 repeat the ping changing the size until you get an answ...
by Caci99
Wed Jan 14, 2015 2:47 pm
Forum: General
Topic: Mikrotik Half Bridge PPPoE
Replies: 6
Views: 4022

Re: Mikrotik Half Bridge PPPoE

Try by bridging the two ethernet ports of first router and look if the second router can discover the pppoe server and create the pppoe-client on the second router. If that is not enough, set the arp=proxy-arp on the bridge interface, that should do it.
by Caci99
Wed Jan 14, 2015 12:26 pm
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4174

Re: Subnet Isolation Problem

Ok, some success :) I didn't bother trying to ping a device on the other subnet earlier, so cool yes it's blocking comms between addresses on the different subnets. I tried that input filter rule but I can still ping the gateway? The rule in input chain works. In your case it is not working because...
by Caci99
Tue Jan 13, 2015 10:25 pm
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4174

Re: Subnet Isolation Problem

As @rmmccann says, you should try it from one device of subnet A to another device on subnet B. For example, you have: /ip address add address=1.1.1.1/24 interface=ether3 add address=2.2.2.1/24 interface=ether4 With the above configuration and filter rules, you should not be able to ping 2.2.2.10 fr...
by Caci99
Tue Jan 13, 2015 2:54 pm
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4174

Re: Subnet Isolation Problem

Yeah I tried that and still no luck, used command line and then the gui in Winbox and still the connection continues to ping away happily between subnets. You should not try it from the router itself, which obviously can reach those subnets, otherwise wouldn't be able to route them. Try it from on ...
by Caci99
Tue Jan 13, 2015 1:36 pm
Forum: General
Topic: RB850 DHCP Failover Impossible?
Replies: 5
Views: 2360

Re: RB850 DHCP Failover Impossible?

When it fails what happens? Do you still have a gateway active on /ip routes form the dhcp client? I would suggest to turn the modem into bridge, so that you have one NAT only. For the failover, take a look at this article http://wiki.mikrotik.com/wiki/Advanced_Routing_Failover_without_Scripting it ...
by Caci99
Mon Jan 12, 2015 11:44 am
Forum: General
Topic: Firewall
Replies: 2
Views: 1699

Re: Firewall

You need to find what IP addresses their servers have, or on what port they negotiate the updates, and then drop the connections on firewall filter in forward chain for those IP-s or ports.
by Caci99
Mon Jan 12, 2015 11:39 am
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4174

Re: Subnet Isolation Problem

It is normal that subnets on the same router communicate with each other, as you have discovered. As soon as you add an IP on one interface, its subnet is part of the connected routes. To stop them from communicating with each other, you need firewall filter routes. For example, let suppose that you...
by Caci99
Mon Jan 12, 2015 11:33 am
Forum: General
Topic: Hacked & Need Help!
Replies: 6
Views: 3008

Re: Hacked & Need Help!

What kind of installation is this?
If he does have a backup, he can reset the router and then restore the backup. Otherwise, he can only reset it and start from scratch, and put a decent username and password to protect the router.
by Caci99
Fri Jan 09, 2015 8:20 pm
Forum: General
Topic: When is it required to reboot a mikrotik to apply changes??
Replies: 5
Views: 8283

Re: When is it required to reboot a mikrotik to apply change

Unused marks will not disappear until reboot. For example.
Of course, but that doesn't affect the configuration in any way, they are just unused. The point being, you do not need to reboot the router when you do some changes.
by Caci99
Fri Jan 09, 2015 2:48 pm
Forum: Beginner Basics
Topic: mikrotik to replace a fortigate 60b unit
Replies: 7
Views: 3766

Re: mikrotik to replace a fortigate 60b unit

That's a long list of requests. It does not fit entirely in my 22" screen :) 1. I remember long time ago to have tested if two pppoe can be established on the same interface, and if recall it worked. But why would you need both of them on the same interface? It is always better to have them sep...
by Caci99
Fri Jan 09, 2015 2:01 pm
Forum: Beginner Basics
Topic: how many marks on a packet
Replies: 5
Views: 2937

Re: how many marks on a packet

Well, a packet can have only one mark, but if you are trying to achieve some QOS you should definitely know the flow diagram. You can a mark packet in prerouting chain and apply that mark in global-in queue, and then remark the packet in forward chain to apply it in global out queue. http://wiki.mik...
by Caci99
Fri Jan 09, 2015 1:32 pm
Forum: General
Topic: When is it required to reboot a mikrotik to apply changes??
Replies: 5
Views: 8283

Re: When is it required to reboot a mikrotik to apply change

There is no need for a reboot of the router to save the settings and changes that you made. They are saved on the fly as you made them.
by Caci99
Fri Jan 09, 2015 11:22 am
Forum: General
Topic: How long it takes mikrotik to answer support emails ?
Replies: 12
Views: 3239

Re: How long it takes mikrotik to answer support emails ?

Badly working ethernets in RB133 running
I was about to ask about the 133c when I saw your post :). Those routers are loooong time ago :), I am positively surprised you still have them at hand.
Maybe it is Mikrotik way by not answering you, telling that it is time to ditch those routers :)
by Caci99
Thu Jan 08, 2015 12:03 pm
Forum: General
Topic: Looking for wireless solution Mikrotik / Ubiquiti
Replies: 11
Views: 3284

Re: Looking for wireless solution Mikrotik / Ubiquiti

I see you have done your research well, the RB951G-2HnD is a very good router for small to medium needs. I would recommend Mikrotik over Ubiquity anytime because of its stability and control. But again, when it comes to wireless situation, you can never be 100% secure, it is very dependable on the i...
by Caci99
Thu Jan 08, 2015 11:44 am
Forum: General
Topic: How long it takes mikrotik to answer support emails ?
Replies: 12
Views: 3239

Re: How long it takes mikrotik to answer support emails ?

January 6 is holiday, isn't it? Also, the previous days were mostly holidays, so they might have some accumulated emails. Usually they answer within 24 hours.
by Caci99
Wed Dec 31, 2014 12:57 pm
Forum: General
Topic: howto block hotspot shield
Replies: 5
Views: 4850

Re: howto block hotspot shield

I think the best way is to block these kind of sites by dns filtering. First you need to setup a transparent dns redirecting: /ip firewall nat add chain=dstnat action=redirect to-ports=53 protocol=udp dst-address-type=!local dst-port=53 add chain=dstnat action=redirect to-ports=53 protocol=tcp dst-a...
by Caci99
Tue Dec 30, 2014 11:54 am
Forum: General
Topic: MikroTik SXT 5HPnD
Replies: 1
Views: 930

Re: MikroTik SXT 5HPnD

Check this post first: http://forum.mikrotik.com/viewtopic.php?f=3&t=70546#p359041 Check also /system routerboard settings set enable-jumper-reset=no If it still does not work, then boot the routerboard, complete the configuration you want and then export it: /export file=sxt5hpnd copy the file ...
by Caci99
Sat Dec 27, 2014 5:03 pm
Forum: General
Topic: Simple queue o Queue Tree + pcq OS v6.x
Replies: 6
Views: 18259

Re: Simple queue o Queue Tree + pcq OS v6.x

To understand limit-at and max-limit you need to understand how priority works. For example: /queue tree add name=download parent=ether2 max-limit=10M queue-type=default add name=priority_download parent=download limit-at=1M max-limit=10M priority=1 packet-mark=priority queue-type=pcqdown add name=o...
by Caci99
Sat Dec 27, 2014 1:26 pm
Forum: General
Topic: Simple queue o Queue Tree + pcq OS v6.x
Replies: 6
Views: 18259

Re: Simple queue o Queue Tree + pcq OS v6.x

The main difference is that in queue tree all packets will get processed at the same time through the queues, while in simple queue a packet must go through all queues until it matches the one about that specific packet. PCQ will ensure that traffic is distributed evenly in a flexible way, but it ca...
by Caci99
Sat Dec 27, 2014 1:09 pm
Forum: General
Topic: redirect a specific web site to ip address
Replies: 2
Views: 2985

Re: redirect a specific web site to ip address

I think it is because the www.alamaltarfeeh.com does not exist and can not be resolved from dns servers into an IP address. Try it with an actual domain name, like www.cnn.com
by Caci99
Sat Dec 27, 2014 12:54 pm
Forum: General
Topic: Email Configuration for Google Server
Replies: 3
Views: 2363

Re: Email Configuration for Google Server

So I was resolving the wrong address; smtp.google.com when it should have been smtp.gmail.com :/

I feel silly now..
There's nothing silly about it ;), everybody makes wrong steps and learns from.
I have to google myself to see the gmail settings whenever I need to :).
by Caci99
Fri Dec 26, 2014 12:27 pm
Forum: General
Topic: Email Configuration for Google Server
Replies: 3
Views: 2363

Re: Email Configuration for Google Server

/tool e-mail
address: smtp.gmail.com
port: 587
start-tls: yes
from: user@gmail.com
user: user@gmail.com
password: your password
If you are using two step authentication in gmail, generate a password for a service, and use the generated password.
by Caci99
Tue Dec 23, 2014 1:46 pm
Forum: General
Topic: Assign public ip to client
Replies: 1
Views: 1081

Re: Assign public ip to client

by Caci99
Tue Dec 23, 2014 1:24 pm
Forum: General
Topic: how to make user permission to read its own configuration ?
Replies: 2
Views: 915

Re: how to make user permission to read its own configuratio

Try webfig and the feature to design skins in webfig:

http://wiki.mikrotik.com/wiki/Manual:Webfig
by Caci99
Mon Dec 22, 2014 3:08 pm
Forum: General
Topic: Mikrotik doesn't work
Replies: 4
Views: 1438

Re: Mikrotik doesn't work

Thanks for the answer, but i guess device can't finish booting. As i said when i powered on even there is no plugged cable, nothnigs happened. But earlier it works when i reset with default configuration. In rare cases, I have seen that a routerboard won't boot when an update is done, but never whe...
by Caci99
Mon Dec 22, 2014 1:48 pm
Forum: General
Topic: RB951G-2HND web proxy
Replies: 4
Views: 4743

Re: RB951G-2HND web proxy

Th Routerboard HDD does not have any capability to store files for webproxy. You have set it to store files on internal HDD, it is causing very high write and read on it, and I am afraid you will wear the internal HDD pretty fast.
by Caci99
Mon Dec 22, 2014 1:00 pm
Forum: General
Topic: Mikrotik doesn't work
Replies: 4
Views: 1438

Re: Mikrotik doesn't work

When you do a reset, the routerboard probably will load the default configuration. With the default configuration you can connect via IP when the ethernet cable is on ether1 of the board, but you can not connect via mac-address. To connect via mac-address, connect the ethernet cable on one of the in...
by Caci99
Wed Dec 17, 2014 12:03 pm
Forum: General
Topic: Advise for hotel
Replies: 15
Views: 4012

Re: Advise for hotel

@flatbat I have worked with RB9512n and is just ... not that powerful to manage certain configurations. It could be could for pretty small offices, but that's it.
I like the idea proposed by @jarda, a central switch on each floor and Access Point like the cAP on the hallway for every 4 to 6 rooms
by Caci99
Tue Dec 16, 2014 2:17 pm
Forum: General
Topic: Advise for hotel
Replies: 15
Views: 4012

Re: Advise for hotel

I don't have such experience at all, but I don't like the RB951-2n, I would go for RB951Ui-2HnD. You might have a look at cAP2n as well.
by Caci99
Tue Dec 16, 2014 2:12 pm
Forum: Announcements
Topic: RouterOS v6.23.1 special release
Replies: 9
Views: 13145

Re: RouterOS v6.23.1 special release

Shuold, but do not work properly MANY times - see manry problems with CCR's.
This is a forum where people post their problems. Very, very, very rarely you would see posts with success stories. It is an irony of life actually, you would notice a device exits when it gives problems :)
by Caci99
Thu Dec 11, 2014 4:14 pm
Forum: Scripting
Topic: random wifi password
Replies: 19
Views: 53361

Re: random wifi password

Very interesting @jspool. I would have given some karma if the option would have still been there :).
Interesting how you have chosen to randomize the password. I will play a little bit when time will be available.
Thank you for sharing it.
by Caci99
Wed Dec 10, 2014 2:25 pm
Forum: Scripting
Topic: random wifi password
Replies: 19
Views: 53361

Re: random wifi password

@jspool That will be great, can you post your solution to have a look at it?
by Caci99
Fri Nov 14, 2014 4:45 pm
Forum: General
Topic: New forum look & feel
Replies: 64
Views: 13107

Re: New forum look & feel

I am using latest firefox, and here is the empty spaces left and right when in full screen
by Caci99
Thu Nov 13, 2014 10:39 pm
Forum: General
Topic: New forum look & feel
Replies: 64
Views: 13107

Re: New forum look & feel

Too much space wasted, among others big margins on the left and on the right.
by Caci99
Wed Nov 12, 2014 1:03 pm
Forum: General
Topic: downloading limit
Replies: 1
Views: 721

Re: downloading limit

Well, the RB750 has 100Mbps ethernet ports, so it will limit itself for 100Mbps :).
You can use simple queues to limit the customer by specifying the target IP address in the simple queue.
by Caci99
Mon Nov 10, 2014 3:45 pm
Forum: General
Topic: how to block attack from known IP
Replies: 2
Views: 1690

Re: how to block attack from known IP

Only when the IP is on the ssh_blacklist it is blocked. The first three stages are there so that you don't let yourself out if you accidentally input wrong credentials.
If you want to go a step further, you could even try port knocking http://wiki.mikrotik.com/wiki/Port_Knocking
by Caci99
Sat Nov 08, 2014 11:31 am
Forum: Scripting
Topic: random wifi password
Replies: 19
Views: 53361

Re: random wifi password

Have a look at this topic:
http://forum.mikrotik.com/viewtopic.php?f=2&t=73402

Still, I would like someone with better knowledge on RouterOS scripting, to do this within a routerboard, instead from a Windows machine.
by Caci99
Sat Nov 08, 2014 11:14 am
Forum: General
Topic: professional help wanted in Munich-Sendling
Replies: 6
Views: 2450

Re: professional help wanted in Munich-Sendling

Wake up guys. It was 3 years ago...
You think the hotel is closed? :)
by Caci99
Fri Nov 07, 2014 3:06 pm
Forum: General
Topic: Now it won't route!
Replies: 16
Views: 4459

Re: Now it won't route!

So, to understand, you are using a RB411 with the only purpose of connecting a machine to the rest of the network. You either configure the 411 in bridge transparent mode, which is the logical choice since the machine needs to be part of the network, or you configure 411 as router and it will route ...
by Caci99
Mon Nov 03, 2014 1:43 pm
Forum: General
Topic: Process logging 100% CPU
Replies: 5
Views: 2599

Re: Process logging 100% CPU

even if you try for terminal? terminal might be a bit lighter than winbox, so it might be easier for the CPU to display the rules.
by Caci99
Mon Nov 03, 2014 1:31 pm
Forum: General
Topic: Process logging 100% CPU
Replies: 5
Views: 2599

Re: Process logging 100% CPU

Go to /system logging and try disabling one by one the log rules until the CPU drops. Than analyze the one causing it.
by Caci99
Thu Oct 23, 2014 1:22 pm
Forum: General
Topic: SCRIPT: Dual WAN Load Balancing with Fail-over
Replies: 27
Views: 113097

Re: SCRIPT: Dual WAN Load Balancing with Fail-over

Rules number 6 and 7 are those who would divide the traffic in two streams. From your picture it looks like they are not doing it, one has 300 000 packets, the other 150 000 packets. It does not seem right, I mean, the configuration is ok, but it is not doing the separation right, one rule grabs mor...
by Caci99
Wed Oct 22, 2014 11:19 am
Forum: General
Topic: SCRIPT: Dual WAN Load Balancing with Fail-over
Replies: 27
Views: 113097

Re: SCRIPT: Dual WAN Load Balancing with Fail-over

The dns you specified on the dhcp server will get eventually distributed to the devices wich will get ip configuration from dhcp servers. It depends on what clients these devices are using. Windows client, to cut it short, will query the first dns server, and if it can not resolve it, will query the...
by Caci99
Mon Oct 20, 2014 1:45 pm
Forum: General
Topic: Queue problem on data-rate of local servers
Replies: 10
Views: 2581

Re: Queue problem on data-rate of local servers

It is still a bit of guess as the picture is not full yet, but if the client is downloading more than its queue, it means that part of traffic from the client is captured by the queue of the webserver which is first in order. Simple queues are executed in their order, once the traffic is captured by...
by Caci99
Sun Oct 19, 2014 11:30 pm
Forum: General
Topic: SCRIPT: Dual WAN Load Balancing with Fail-over
Replies: 27
Views: 113097

Re: SCRIPT: Dual WAN Load Balancing with Fail-over

In routerOS, is not recomended to use dns servers from different providers. Stick to one, google for example. The router will send requests to resolve dns names randomly at both servers specified. If they are from diferent providers, might cause problems.
by Caci99
Sat Oct 18, 2014 11:46 pm
Forum: Scripting
Topic: Need help with failover script
Replies: 6
Views: 2064

Re: Need help with failover script

Have you tried ECMP configuration? The problem with ECMP is that it will flush the connections table every 10 minutes or so, thus reseting all the connections. This behavior is problematic for connections which require authentication, but it might work in your case and is pretty straitght forward.
by Caci99
Sat Oct 18, 2014 7:41 pm
Forum: Scripting
Topic: Need help with failover script
Replies: 6
Views: 2064

Re: Need help with failover script

Let's take the first route for example: add check-gateway=ping comment=wan11 distance=1 gateway=192.168.160.1 routing-mark=to_wan1 If 192.168.160.1 is not reachable for any reason, traffic marked with routing-mark=to_wan1 has nowhere to go, because there is no backup route for it. So you need to add...
by Caci99
Sat Oct 18, 2014 7:36 pm
Forum: General
Topic: SCRIPT: Dual WAN Load Balancing with Fail-over
Replies: 27
Views: 113097

Re: SCRIPT: Dual WAN Load Balancing with Fail-over

Are you sure I must choose 'both addresses' only and not 'both addresses and ports'? I just want to clarify this because most of the dual wan load balancing script I've seen uses 'both addresses and ports'. This confused me. Read the wiki about the classifier, and you will get it better. If you div...
by Caci99
Sat Oct 18, 2014 3:47 pm
Forum: Beginner Basics
Topic: RB951-2n thinks it's Jan/01/1970 unless I use SNTP
Replies: 4
Views: 1375

Re: RB951-2n thinks it's Jan/01/1970 unless I use SNTP

OK. Should this use much bandwidth ? I'm on a 10 GB cap.
Oh no, not at all. It's just very small packets. I don't actually know how much but it is pretty small. You can monitor udp port=123 on the wan interface if you really want to know how much it uses.
by Caci99
Sat Oct 18, 2014 3:03 pm
Forum: Scripting
Topic: Need help with failover script
Replies: 6
Views: 2064

Re: Need help with failover script

If the script does disable the route for that particular traffic, than you should have a backup route with bigger distance for that traffic, so that the router can switch the traffic through the other route. For example: /ip route add dst-address=0.0.0.0/0 gateway=pppoe-out1 distance=1 routing-mark=...
by Caci99
Sat Oct 18, 2014 2:57 pm
Forum: Beginner Basics
Topic: RB951-2n thinks it's Jan/01/1970 unless I use SNTP
Replies: 4
Views: 1375

Re: RB951-2n thinks it's Jan/01/1970 unless I use SNTP

That's the normal behavior, the routerboard does not have a battery inside to keep the memory up. Every time you reboot you need to use SNTP or NTP client to synchronize time and date.
by Caci99
Sat Oct 18, 2014 2:23 pm
Forum: General
Topic: Queue problem on data-rate of local servers
Replies: 10
Views: 2581

Re: Queue problem on data-rate of local servers

You better post your simple queues, to see how are those configured. I don't think any one can understand what is going on without having a look at the configuration involved.
by Caci99
Fri Oct 17, 2014 3:35 pm
Forum: General
Topic: How to block images/results on google search?
Replies: 5
Views: 4027

Re: How to block images/results on google search?

Have you tried opendns? Redirect transparently all dns requests to your router, and set opendns on the router dns. See if it can block requests to "malicious" websites
by Caci99
Fri Oct 17, 2014 1:39 pm
Forum: General
Topic: PCC rules explanation
Replies: 3
Views: 1296

Re: PCC rules explanation

Well, you have the explanation in the wiki itself, every rule is explained there. The accept action, means that that particular traffic is not processed by the other rules, it is excluded from being processed. The dst-type=!local means not local, and with local here is intended networks assigned in ...
by Caci99
Fri Oct 17, 2014 10:48 am
Forum: General
Topic: Web Proxy
Replies: 3
Views: 1734

Re: Web Proxy

What do you mean by statistics for every user? To do that,you probably would need a PC with cacti in it for example, which would collect data from routerboard.
A good place to start is wiki http://wiki.mikrotik.com/wiki/Main_Page
by Caci99
Thu Oct 16, 2014 12:12 pm
Forum: General
Topic: SCRIPT: Dual WAN Load Balancing with Fail-over
Replies: 27
Views: 113097

Re: SCRIPT: Dual WAN Load Balancing with Fail-over

Sorry for late response I would change the classifier from "both addresses and ports" to "both addresses" Also, in the route table, for the normal route you are using a different gateway which I can't figure out where is coming from. I am talking about this: add check-gateway=pin...
by Caci99
Tue Oct 14, 2014 10:43 am
Forum: General
Topic: SCRIPT: Dual WAN Load Balancing with Fail-over
Replies: 27
Views: 113097

Re: SCRIPT: Dual WAN Load Balancing with Fail-over

How are you testing it? From a single computer? Also, post your config in here, so we can have a look at it.
by Caci99
Mon Oct 13, 2014 1:15 pm
Forum: General
Topic: SCRIPT: Dual WAN Load Balancing with Fail-over
Replies: 27
Views: 113097

Re: SCRIPT: Dual WAN Load Balancing with Fail-over

Have you tried the pcc method?
http://wiki.mikrotik.com/wiki/PCC
by Caci99
Mon Oct 06, 2014 11:17 am
Forum: General
Topic: blacklisting a certain gateway
Replies: 2
Views: 1170

Re: blacklisting a certain gateway

by Caci99
Mon Oct 06, 2014 11:12 am
Forum: General
Topic: How to remove slave interfaces?
Replies: 4
Views: 59794

Re: How to remove slave interfaces?

Because they are part of bridge interface, so are considered as slave of that bridge.
by Caci99
Sat Sep 13, 2014 2:28 pm
Forum: Beginner Basics
Topic: Mikrotik RB750 how to [block everything,then allow specific]
Replies: 3
Views: 1654

Re: Mikrotik RB750 how to [block everything,then allow speci

It is about the order you put on the firewall filter. The rules which would allow the traffic should be put before/above the rule that drops it.
by Caci99
Sat Sep 13, 2014 2:22 pm
Forum: General
Topic: PPPOE Clients Disconnecting so badly
Replies: 7
Views: 4600

Re: PPPOE Clients Disconnecting so badly

Thanks for reply but unfortunately disconnections also occur in segment with no ptp links (all cables ) Oh well, I guessed it wrong then :) Anyway, the pppoe tunnel is pretty sensitive to not stable links, you might be experiencing some packet drops or port flapping. Also, activate the pppoe info i...
by Caci99
Sat Sep 13, 2014 11:53 am
Forum: General
Topic: PPPOE Clients Disconnecting so badly
Replies: 7
Views: 4600

Re: PPPOE Clients Disconnecting so badly

i'm using a ptp link for a remote lan (ubnt nanostation) You have the answer right there. The wireless link can go down often for very short amount of time. In normal situations, when these disconnections occur you wouldn't notice them. But the pppoe tunnel is very sensitive, so at every disconnect...
by Caci99
Wed Sep 10, 2014 2:21 pm
Forum: General
Topic: I have a real probleme
Replies: 6
Views: 1773

Re: I have a real probleme

okay sir how I can know the necessary files from the unnecessary files .. and how i can degrade the version to 5.24 I wait your asnwer sir You can post in here the file list of your router to have a look at it. Type in terminal /file print without-paging copy and paste in here. To downgrade you jus...
by Caci99
Tue Sep 09, 2014 2:03 pm
Forum: General
Topic: I have a real probleme
Replies: 6
Views: 1773

Re: I have a real probleme

Your hdd is full, look at the bottom of the window of "file list". 61.4MB of 61.4MB used.
Clear it up and free the necessary space for the files to be uploaded.
by Caci99
Fri Aug 22, 2014 1:12 pm
Forum: General
Topic: Dual wan PCC using one wan only
Replies: 5
Views: 2368

Re: Dual wan PCC using one wan only

Try changing per-connection-classifier to both-addresses only and see what happens.
by Caci99
Fri Aug 22, 2014 11:33 am
Forum: General
Topic: Dual wan PCC using one wan only
Replies: 5
Views: 2368

Re: Dual wan PCC using one wan only

Are the counters on mangle rules running? Do you see there packets captured by those mangle rules?
by Caci99
Thu Aug 21, 2014 2:21 pm
Forum: General
Topic: source of unused address list name
Replies: 15
Views: 4131

Re: source of unused address list name

Probably still in memory, a restart should delete it. But nothing to be concerned of.
by Caci99
Wed Aug 20, 2014 11:54 am
Forum: General
Topic: Do I have a BAD Routerboard?
Replies: 2
Views: 1101

Re: Do I have a BAD Routerboard?

At the moment that it happens, look at the router for any strange behavior, any unusual traffic or high CPU. You should also protect your router from dns attacks: /ip firewall filter add chain=input action=drop protocol=tcp in-interface=ether1-gateway dst-port=53 add chain=input action=drop protocol...
by Caci99
Tue Aug 19, 2014 1:27 pm
Forum: General
Topic: RB951-2hdn - bricked
Replies: 9
Views: 2486

Re: RB951-2hdn - bricked

I have a lot of RB951Ui-2HnD and never had problem with them, but what are you describing is not unfamiliar. The electric shock does not come only from the power supply, mostly it will come from ethernet cables, specially if any of them runs outdoor. Have you tried the reset jumper if it can cancel ...
by Caci99
Mon Aug 18, 2014 12:55 pm
Forum: General
Topic: Web Proxy
Replies: 3
Views: 1734

Re: Web Proxy

In the access list of the web proxy have you tried to specify the source address? That should do it, like:
/ip proxy access
add src-address=192.168.1.x dst-host=whatever action=allow
by Caci99
Thu Aug 14, 2014 10:23 pm
Forum: General
Topic: Redirect all traffic from a spesific ip number to a web page
Replies: 9
Views: 55771

Re: Redirect all traffic from a spesific ip number to a web

The only way to redirect to url, as far as I know, is by using webproxy. To do that first you need to enable it: /ip proxy set enable=yes The default port should be 8080 but you can change it if you need to. Of course you don't need any cache, the purpose of proxy in this case is only for redirectin...
by Caci99
Wed Aug 13, 2014 4:33 pm
Forum: General
Topic: Redirect all traffic from a spesific ip number to a web page
Replies: 9
Views: 55771

Re: Redirect all traffic from a spesific ip number to a web

I just tested it and works fine. I am on ROS 6.18. Is the server within your network? What other rules do you have in /firewall nat and /firewall mangle?
by Caci99
Wed Aug 13, 2014 3:05 pm
Forum: General
Topic: Redirect all traffic from a spesific ip number to a web page
Replies: 9
Views: 55771

Re: Redirect all traffic from a spesific ip number to a web

Do you know the ip of your webserver? Is this server hosting only one webserver?
The simple way to do it is:
/ip firewall nat
add chain=dstnat src-address=10.0.11.187 protocol=tcp action=dst-nat to-addresses=webserver_ip to-ports=80
by Caci99
Tue Aug 12, 2014 12:13 pm
Forum: General
Topic: Lagging on load-balance setup
Replies: 5
Views: 3451

Re: Lagging on load-balance setup

Glad to hear it helped I also added a "chain=input in-interface=!bridge-local action=drop" rule at the very end of the filter section to stop similar connections to the router Be carefull with that rule though, you might be blocking useful connections from your LAN to the router, might eve...
by Caci99
Mon Aug 11, 2014 12:00 pm
Forum: General
Topic: Assign public ip directly to Private Interface
Replies: 11
Views: 5691

Re: Assign public ip directly to Private Interface

I think with the solution that you provided let the customer to use only private ip assigned but linked to a public ip address. I still want the customer to just add his public ip address on his router . But it works the same, when from internet someone requests that public IP, it will connect to t...
by Caci99
Fri Aug 08, 2014 11:55 am
Forum: General
Topic: Lagging on load-balance setup
Replies: 5
Views: 3451

Re: Lagging on load-balance setup

I would make slight changes to your config as follows: /ip firewall mangle add action=mark-connection chain=input connection-mark=no-mark in-interface=pppoe1 new-connection-mark=wan1 add action=mark-connection chain=input connection-mark=no-mark in-interface=pppoe2 new-connection-mark=wan2 add actio...
by Caci99
Mon Aug 04, 2014 11:51 am
Forum: Beginner Basics
Topic: asymetric QoS for 2 nated network
Replies: 4
Views: 1308

Re: asymetric QoS for 2 nated network

2. "To allow traffic between the two networks you should add mangle rules which should stay on top of the others:" It is necesery? This trafic go trhoug router not olny by bridge? To mangle it, i must turn on bridge use-ip-firewall (i can/t do thent due to performace reason) The traffic b...
by Caci99
Sat Aug 02, 2014 3:38 pm
Forum: Beginner Basics
Topic: asymetric QoS for 2 nated network
Replies: 4
Views: 1308

Re: asymetric QoS for 2 nated network

First, you don't need two masquerade rules, remove the one: action=masquerade chain=srcnat src-address=192.168.2.0/24 to-addresses=0.0.0.0 What you are looking for requires careful mangle rules which will mark packets, and then use those packet marks in a queue tree using pcq. To allow traffic betwe...
by Caci99
Sat Aug 02, 2014 12:28 am
Forum: General
Topic: loose access
Replies: 10
Views: 2526

Re: loose access

I need a lift, I would like to avoid that... You want to avoid lifting? :) Well I can't help you with that. so we need this feature for the future in the routerboard firmware You can make an /export compact and than add a script which will load the exported file via scheduler at startup. Never test...
by Caci99
Sat Aug 02, 2014 12:07 am
Forum: General
Topic: loose access
Replies: 10
Views: 2526

Re: loose access

I just want to know if in the routerboard(bootloader) there is a possibility to do an tftp or other method...
Of course there is, you can use Netinstall, look for it in the wiki. But you just can't use it if not physically accessed.
by Caci99
Fri Aug 01, 2014 1:03 pm
Forum: General
Topic: Static IP and PPPoE on same port
Replies: 1
Views: 932

Re: Static IP and PPPoE on same port

You mean the pppoe interface does have a static IP and does not get it from the server?
In that case just put the IP on the profile you are using for the pppoe interface (probably the default profile). You can find it in /ppp profile and there set the local address
by Caci99
Fri Aug 01, 2014 12:34 pm
Forum: General
Topic: loose access
Replies: 10
Views: 2526

Re: loose access

You have lost access both on ethernet side and wireless side?
Unfortunately, the only way to regain access is to physically access the device and reset it.
by Caci99
Thu Jul 31, 2014 2:31 pm
Forum: General
Topic: Mikrotik-Rate-Limit
Replies: 4
Views: 1880

Re: Mikrotik-Rate-Limit

Unfortunately users will not be getting a fixed IP And they will be part of the same address list, always. It might look as more work, but actually it could be less in future. Using address lists will help also having less queues by grouping them in queue tree instead of creating hundreds of dynami...
by Caci99
Thu Jul 31, 2014 2:13 pm
Forum: General
Topic: Mikrotik-Rate-Limit
Replies: 4
Views: 1880

Re: Mikrotik-Rate-Limit

I would go by using address list option on pppoe profile. Just assign an address list on the profile and live the rates blank on both, routeros and radius.
Then use address list to mark packets in mangle, and use those marks in queues.
by Caci99
Thu Jul 17, 2014 1:17 pm
Forum: General
Topic: how to block teamviewer?
Replies: 12
Views: 14701

Re: how to block teamviewer?

Hi to all i would like to know if possible to block teamviewer application? thanks I don't think it is possible to do it through firewall filter since teamviewer uses port 80 and 443. So I would go by adding static entries in dns, and redirecting dns requests to the router: /ip dns static add name=...
by Caci99
Thu Jul 17, 2014 12:58 pm
Forum: General
Topic: POOR wireless performance
Replies: 7
Views: 2583

Re: POOR wireless performance

Fine tuning the wireless performance may prove harder than you think, especially indoors. First of all, I would not recommend to connect to an AP which is in a different floor, because the signal is greatly influenced by the structure of the building itself. Second, how far are the APs from each oth...
by Caci99
Tue Jul 15, 2014 10:54 am
Forum: General
Topic: Mangle connections Problem !!!
Replies: 6
Views: 1653

Re: Mangle connections Problem !!!

populated?
what you mean ???
By populated I mean, are there IP addresses in the address list?
Have you tried to specify an IP address as source instead of an address list?
by Caci99
Sat Jul 12, 2014 3:08 pm
Forum: General
Topic: incoming email marked with router IP
Replies: 2
Views: 1149

Re: incoming email marked with router IP

My guess is, it has to do with the masquerade rule. The masquerade rule normally should look like this: /ip firewall nat chain=srcnat action=masquerade out-interface=ether1 assuming ether1 is the interface which connects to the internet. If no out-ineterface is specified, than router will change the...
by Caci99
Fri Jul 11, 2014 3:03 pm
Forum: General
Topic: Mangle connections Problem !!!
Replies: 6
Views: 1653

Re: Mangle connections Problem !!!

- EC list is enabled in address list
It is enabled, but it is also populated, right?
Try removing from first rule the bit: dst-address-type=""
by Caci99
Fri Jul 11, 2014 2:52 pm
Forum: General
Topic: Routing public ip block to existing another subnet
Replies: 3
Views: 1604

Re: Routing public ip block to existing another subnet

First, you should add the addresses given to you on your WAN interface. That's where you connect to your ISP.
Secondly you can use netmap to do what you want http://wiki.mikrotik.com/wiki/Manual:IP ... :1_mapping
by Caci99
Fri Jul 11, 2014 2:48 pm
Forum: General
Topic: Mangle connections Problem !!!
Replies: 6
Views: 1653

Re: Mangle connections Problem !!!

Is the EC list populated? Which one of the two rules is not working (counters are running)? Is there any other mangle rule which might grab the traffic before the two you posted?
by Caci99
Fri Jul 11, 2014 2:44 pm
Forum: General
Topic: why use Torch & Connections different ?
Replies: 1
Views: 863

Re: why use Torch & Connections different ?

Torch will keep the information gathered alive for three seconds, or whatever time you choose in timeout field.
Maybe it is that setting that populates more the torch.
Anyway, haven't bothered before to look at it like this.
by Caci99
Mon Jul 07, 2014 12:05 pm
Forum: RouterBOARD hardware
Topic: Mac address of device attached to the CRS
Replies: 9
Views: 4056

Re: Mac address of device attached to the CRS

@rwaters
Nice spotting, that was it :)
by Caci99
Sat Jul 05, 2014 8:33 pm
Forum: RouterBOARD hardware
Topic: Mac address of device attached to the CRS
Replies: 9
Views: 4056

Re: Mac address of device attached to the CRS

The information is "in" it, the problem is, can it be read from the switch chip, and if yes, what amount of resources would it require... I don't think that collecting 24 mac addresses is that much resource hungry. If the switch can survive a bridge interface, which is a "software&qu...
by Caci99
Sat Jul 05, 2014 3:44 pm
Forum: RouterBOARD hardware
Topic: Mac address of device attached to the CRS
Replies: 9
Views: 4056

Re: Mac address of device attached to the CRS

Create a bridge and put the port in question on it.
It will allow you to see the MACs under bridge/hosts.
Kind of a workaround, but shouldn't the switch learn the mac addresses of the devices attached to it? This information got to be somewhere on it :). MikroTik could kindly make it available.
by Caci99
Sat Jul 05, 2014 10:52 am
Forum: RouterBOARD hardware
Topic: Mac address of device attached to the CRS
Replies: 9
Views: 4056

Re: Mac address of device attached to the CRS

Well, I have configured it as a switch, all interfaces are slaves to ether1, and I have disabled connection tracking on firewall. So it is not possible to sniff traffic. I was hoping that the switch would learn and know the mac addresses of the devices attached to it, as a matter of fact it must do ...
by Caci99
Sat Jul 05, 2014 10:30 am
Forum: RouterBOARD hardware
Topic: Mac address of device attached to the CRS
Replies: 9
Views: 4056

Mac address of device attached to the CRS

Is there any chance to know the mac address of computers connected to the ethernet interfaces of CRS-s, even better the IP address :)?
by Caci99
Thu Jun 26, 2014 2:28 pm
Forum: General
Topic: Browsing the webpage for longer than - add to address-list
Replies: 8
Views: 1594

Re: Browsing the webpage for longer than - add to address-li

@tigran
take a look at the solution worked out with the help of @rextended (you might add him some carma if it helps)
http://forum.mikrotik.com/viewtopic.php ... 52#p432730
by Caci99
Thu Jun 26, 2014 2:21 pm
Forum: General
Topic: Address list jump on next address list option request
Replies: 6
Views: 2207

Re: Address list jump on next address list option request

So, I tried it yesterday and today, and here is with what I came out: /ip firewall mangle add chain=prerouting action=accept src-address=1.1.1.1 dst-address=2.2.2.2 src-address-list=1h add chain=prerouting action=add-src-to-address-list src-address=1.1.1.1 dst-address=2.2.2.2 src-address-list=5min a...
by Caci99
Sat Jun 21, 2014 7:24 pm
Forum: General
Topic: Address list jump on next address list option request
Replies: 6
Views: 2207

Re: Address list jump on next address list option request

Good thinking, but I will try it tomorrow, maybe. Right now I am following world cup :). And you are very generous on carma points, while those should go to you :).
Tuscany eh, been there a couple of times, beatiful.
by Caci99
Sat Jun 21, 2014 2:29 pm
Forum: General
Topic: Address list jump on next address list option request
Replies: 6
Views: 2207

Address list jump on next address list option request

Hello I would like to see a feature on address lists, which would enable to add the addresses on one address list to another once the time of the first expires. It is very helpful in configurations where one would like to give time specific services. For example, if I would want that someone browses...
by Caci99
Thu Jun 19, 2014 2:13 pm
Forum: General
Topic: Browsing the webpage for longer than - add to address-list
Replies: 8
Views: 1594

Re: Browsing the webpage for longer than - add to address-li

It really depends on what you want to do. Mangle is generally used for marking connections, packets which in turn can be farther used in routes and queues or address lists. In firewall filter you generally put rules for dropping, allowing connections etc. Mangle can process packets in prerouting or ...
by Caci99
Thu Jun 19, 2014 1:52 pm
Forum: RouterBOARD hardware
Topic: RB953GS-5HnT!!!! 3x3 MIMO finally is there!
Replies: 12
Views: 8426

Re: RB953GS-5HnT!!!! 3x3 MIMO finally is there!

What can be the possible scenarios of use of this routerboard?
by Caci99
Thu Jun 19, 2014 1:38 pm
Forum: General
Topic: Browsing the webpage for longer than - add to address-list
Replies: 8
Views: 1594

Re: Browsing the webpage for longer than - add to address-li

You can play a little bit with limit option or dst-limit in /ip firewall mangle
http://wiki.mikrotik.com/wiki/Manual:IP ... Properties
by Caci99
Thu Jun 19, 2014 1:20 pm
Forum: General
Topic: Redundancy for Fiber & Wireless Link with Same Single IP
Replies: 9
Views: 2447

Re: Redundancy for Fiber & Wireless Link with Same Single IP

If I disable the interface or ip address on fiber link, then how come script will know the main fiber link is up and it should switch back ? I haven't tested it, but i guess if you disable the ip address, not the interface itself, you can execute a mac ping: /ping 00:01:02:03:04:05 interface=sfp1 a...
by Caci99
Thu Jun 19, 2014 10:16 am
Forum: General
Topic: Redundancy for Fiber & Wireless Link with Same Single IP
Replies: 9
Views: 2447

Re: Redundancy for Fiber & Wireless Link with Same Single IP

What if you disable the address on fiber interface, instead of disabling the interface itself, and then test the link by arp ping? You should note first the mac address of the gateway. Just guessing.
by Caci99
Tue Jun 17, 2014 1:14 pm
Forum: General
Topic: Redundancy for Fiber & Wireless Link with Same Single IP
Replies: 9
Views: 2447

Re: Redundancy for Fiber & Wireless Link with Same Single IP

I am afraid this would require some scripting. The way I am thinking about it, is assign the IP to the two interfaces, but leave the backup interface disabled like: /ip address add address=1.1.1.1/24 interface=wlan1 add address=1.1.1.1/24 interface=sfp1 /interfaces set wlan1 disabled=yes Then, if th...
by Caci99
Wed Jun 11, 2014 11:44 am
Forum: General
Topic: v6.14 released
Replies: 114
Views: 38012

Re: v6.14 released

The ip cloud is a nice feature, but trickier than I would have expected. It would be nice if in the future the user can specify it's own domain name so that it can be remembered.
by Caci99
Sat Jun 07, 2014 2:32 pm
Forum: General
Topic: Easy Question
Replies: 5
Views: 1690

Re: Easy Question

It is not clear why you need a second router in between, but if I understood it correctly you need netmap
http://wiki.mikrotik.com/wiki/Manual:IP ... :1_mapping
by Caci99
Sat May 31, 2014 1:50 pm
Forum: General
Topic: Most effective defense against DNS flood,advice,experiences
Replies: 14
Views: 5012

Re: Most effective defense against DNS flood,advice,experien

Whenever I configure a dns cache on routerboard (accept dns requests), I do add the following rules on it, and so far it has worked:
/ip firewall filter
add chain=input action=drop protocol=tcp in-interface=WAN dst-port=53
add chain=input action=drop protocol=udp in-interface=WAN dst-port=53
by Caci99
Wed May 28, 2014 10:54 am
Forum: General
Topic: NAT with local devices
Replies: 5
Views: 1210

Re: NAT with local devices

Hmm..So If I am not mistaking I should add the following rule:

/ip firewall nat add chain=srcnat src-address=192.168.20.0/24 dst-address=192.168.20.10 protocol=tcp dst-port=1000 out-interface=LAN action=masquerade

?
Yes
by Caci99
Mon May 26, 2014 12:50 pm
Forum: General
Topic: NAT with local devices
Replies: 5
Views: 1210

Re: NAT with local devices

by Caci99
Thu May 22, 2014 2:32 pm
Forum: General
Topic: Unknown Traffic from router
Replies: 2
Views: 1328

Re: Unknown Traffic from router

Also, run torch (/tool torch) on the interface where the traffic is happening, and see what traffic it is and on which port, from whom to where.
A wild guess, it can be either proxy or dns.
by Caci99
Mon May 19, 2014 2:26 pm
Forum: General
Topic: am i under attack??
Replies: 4
Views: 1362

Re: am i under attack??

what is logging tryouts??
As @jarda eplained, they are just attempts to log in on to your router. I shouldn't be very concerned as long as you change the default user and the password. But if you want, you can add this to your firewall:
http://wiki.mikrotik.com/wiki/Bruteforc ... prevention
by Caci99
Mon May 19, 2014 2:00 pm
Forum: General
Topic: Help Need: Dual route to gateway
Replies: 7
Views: 2316

Re: Help Need: Dual route to gateway

Well, I don't much that "box" you have in there, but can't you put the box in between the modem and the RB450G, and do configurations on the box? Otherwise you are dealing with three NAT steps there, which is not that good. You would need rule for the box traffic on the RB450G: /ip firewal...
by Caci99
Mon May 19, 2014 12:55 pm
Forum: General
Topic: Help Need: Dual route to gateway
Replies: 7
Views: 2316

Re: Help Need: Dual route to gateway

What kind of service are you trying to offer through that proxy? Is it http? Is it a Radius? Either way, you don't need to redirect the traffic that way. For http service just add a rule of dstnat on your RB450G /ip firewall nat add chain=dstnat src-address="your desired IPs" protocol=tcp ...
by Caci99
Sun May 18, 2014 10:12 pm
Forum: General
Topic: Marked packet - bandwidth shaping
Replies: 4
Views: 1436

Re: Marked packet - bandwidth shaping

You have comprehended it right with small exceptions. Well done for trying it out yourself, is the best way to learn it ;) To answer some of your questions: If i understood PCQ correctly, with the suggest 10M parent and 512 per child The 512kbps I putted in limit-at in example, means that the queue ...
by Caci99
Thu May 15, 2014 11:23 pm
Forum: General
Topic: queue on a bridge (odd config)
Replies: 7
Views: 1468

Re: queue on a bridge (odd config)

I have done sometime queue on ethernet interfaces, and it works. I have no experience on bridge interface, the only way to find out is to test it. If you apply the queue on the bridge, it will affect all interfaces on that bridge.
by Caci99
Thu May 15, 2014 10:33 pm
Forum: General
Topic: queue on a bridge (odd config)
Replies: 7
Views: 1468

Re: queue on a bridge (odd config)

Well, considering that modem does not have capability of limiting the bandwidth of an interface, you need to put the RB951 in between, or a small managed switch (like RB260GS) which can do the limiting. You might want to try, to bridge ether4 and ether5 together on the 951 (in and out for cisco) and...
by Caci99
Thu May 15, 2014 10:13 pm
Forum: General
Topic: queue on a bridge (odd config)
Replies: 7
Views: 1468

Re: queue on a bridge (odd config)

Thanks for the suggestion, but as I stated in the op, the client won't accept the 1:1 nat Oops, missed that, sorry. How do they achieve that anyway? I mean, what is the actual config of the nod? Is the modem in bridge-mode and the public IP is on Cisco? Can't they just assign a private IP on it so ...
by Caci99
Thu May 15, 2014 10:06 pm
Forum: General
Topic: Marked packet - bandwidth shaping
Replies: 4
Views: 1436

Re: Marked packet - bandwidth shaping

Since you are applying the same limits on all IPs I would suggest to use pcq first. Then move all of it on queue tree. To do that mark packets for all IPs and mark packets for desired traffic (don't mix them). On the queue tree, create a parent queue with max-limit the bandwidth available to you and...
by Caci99
Thu May 15, 2014 9:45 pm
Forum: General
Topic: queue on a bridge (odd config)
Replies: 7
Views: 1468

Re: queue on a bridge (odd config)

I would have tried this: 1. Configure the modem as bridge, and connect RB951 to it. This way, it will be the RB951 who will manage it all, public IP, NAT, QOS etc. 2. Connect cisco to ether5 for example and PBX to ether4. Do a netmap on RB951 so that you can pass a public IP to the Cisco router. htt...
by Caci99
Thu May 15, 2014 1:18 pm
Forum: General
Topic: How do i block 100% netflix, hulu, youtube, roku, etc.
Replies: 13
Views: 26019

Re: How do i block 100% netflix, hulu, youtube, roku, etc.

If you want to block those pages completely, setup a transparent dns first: /ip firewall nat add chain=dstnat action=redirect to-ports=53 protocol=udp dst-address-type=!local dst-port=53 add chain=dstnat action=redirect to-ports=53 protocol=tcp dst-address-type=!local dst-port=53 This way, no matter...
by Caci99
Sat May 03, 2014 9:27 pm
Forum: General
Topic: Port forwarding across Nat'd network
Replies: 12
Views: 2923

Re: Port forwarding across Nat'd network

So it should be run into the modem?
Correct?
Yes.
by Caci99
Sat May 03, 2014 9:20 pm
Forum: General
Topic: Port forwarding across Nat'd network
Replies: 12
Views: 2923

Re: Port forwarding across Nat'd network

Dynamic dns client, I'm talking about public ip from my isp is dymanic
http://en.wikipedia.org/wiki/Dynamic_DNS
Oh, I see. Well that depends on the modem, what kind of dyndns it supports, since it the modem who gets the dynamic public IP.
by Caci99
Sat May 03, 2014 9:08 pm
Forum: General
Topic: Port forwarding across Nat'd network
Replies: 12
Views: 2923

Re: Port forwarding across Nat'd network

but how about dynamic dns client? Shouldn't I run it? You mean dhcp client? What about them? If you mean that tey do have a dynamic IP because of the dhcp server, then you can force the dhcp server to give them the same IP by setting the client as static in the lease table of dhcp server. Which way...
by Caci99
Sat May 03, 2014 2:03 pm
Forum: General
Topic: Port forwarding across Nat'd network
Replies: 12
Views: 2923

Re: Port forwarding across Nat'd network

There are too many nodes (NAT) involved in that map which is not good. If you can I would recommend to bridge them until you serve the final network. Anyway, there are two ways to reach to your camera. First is by doing a nat rule on every node: /ip firewall nat add chain=dst-nat dst-address=modem a...
by Caci99
Sat May 03, 2014 1:38 pm
Forum: General
Topic: Forward to a local webserver
Replies: 6
Views: 2064

Re: Forward to a local webserver

I think you also need a rule in the mangle placed before the PCC rules:
/ip firewall mangle
chain=prerouting in-interface=LAN dst-address=192.168.1.0/24 action=accept
This might help to not process this traffic and force it through the specified gateways of your PCC
by Caci99
Fri May 02, 2014 7:54 pm
Forum: General
Topic: RB2011UiAS-2HnD-IN - High CPU Usage - Watch Video To See
Replies: 3
Views: 1734

Re: RB2011UiAS-2HnD-IN - High CPU Usage - Watch Video To See

CPU at 66% wouldn't be a big issue. Anyway, it seems a bit strange because it looks as if you are using only small packets. According to Mikrotik, this router should hit 40Mbps tested with 64byte packets. With larger packets it can reach a lot more obviously. Try to find out what kind of traffic is ...
by Caci99
Thu May 01, 2014 2:17 pm
Forum: General
Topic: RB2011UiAS-2HnD-IN - High CPU Usage - Watch Video To See
Replies: 3
Views: 1734

Re: RB2011UiAS-2HnD-IN - High CPU Usage - Watch Video To See

Look in /tool profile what service is consuming the CPU
by Caci99
Sat Apr 26, 2014 4:15 pm
Forum: General
Topic: firewall filter 'drop' rule not working?
Replies: 1
Views: 1679

Re: firewall filter 'drop' rule not working?

Try a netstat on client PC and see what connections are active, also look at connection tracking on router what connections of the client are established.
Anyway, have you considered using radius for your purpose?
by Caci99
Fri Apr 11, 2014 4:36 pm
Forum: General
Topic: Netinstall DHCP boot
Replies: 9
Views: 7166

Re: Netinstall DHCP boot

I see, thought that by pressing the reset button would have forced the router into bootp, apparently that is not happening, right?
by Caci99
Fri Apr 11, 2014 2:32 pm
Forum: General
Topic: Netinstall DHCP boot
Replies: 9
Views: 7166

Re: Netinstall DHCP boot

You should be able to boot the RB into netinstall by keeping the reset button pressed until the power lights goes off. Quote from quick guide: In case you wish to boot the device from network, for example to use MikroTik Netinstall, hold the RESET button of the device when starting it until the LED ...
by Caci99
Fri Mar 28, 2014 2:57 pm
Forum: General
Topic: 6.11 + Hide SSID
Replies: 3
Views: 2520

Re: 6.11 + Hide SSID

I don't think that is possible when using nv2
by Caci99
Thu Mar 27, 2014 10:39 pm
Forum: General
Topic: Routeros 6.9 - Simple queue problem
Replies: 4
Views: 1581

Re: Routeros 6.9 - Simple queue problem

Do you mean 57kbps (not kpps)? That might be the problem. I don't have a CCR, so can't tell very much in regard, but I would suggest to use multi-queue-ethernet on the interfaces queues as first step. This type of queue is for multi-core routers like yours. Then try to increase the size of the type ...
by Caci99
Thu Mar 27, 2014 3:58 pm
Forum: General
Topic: Routeros 6.9 - Simple queue problem
Replies: 4
Views: 1581

Re: Routeros 6.9 - Simple queue problem

Do you see dropped packets in the queue? If yes, how many of them in relation to those passed.
by Caci99
Fri Mar 21, 2014 10:17 pm
Forum: General
Topic: Child Protection for specific host/ip address in LAN
Replies: 2
Views: 1804

Re: Child Protection for specific host/ip address in LAN

You can setup your router DNS with the opendns servers, and then redirect specific IP to your dns cache, like: /ip firewall nat add chain=dstnat action=redirect to-ports=53 src-address=192.168.88.100 protocol=udp dst-address-type=!local dst-port=53 and assign on the other computers another dns serve...
by Caci99
Fri Mar 21, 2014 10:08 pm
Forum: General
Topic: 6.x on CCR [Invalid]
Replies: 20
Views: 8101

Re: 6.x useless on CCR

Maybe it is not up to me to say it, but you're making your own issue as a general one. I know some guys that have CCR-s and are very happy with them. This is a user forum where can be asked for help or discussion and not airing your frustration with the equipment. Nothing is perfect, just gets bette...
by Caci99
Sun Mar 09, 2014 10:14 pm
Forum: General
Topic: proxy for https connecton
Replies: 7
Views: 2727

Re: proxy for https connecton

is there another way to solve this?
I think it is against the idea of https it self. https are secure connections, and wouldn't be apropriate for any to cache sensitive pages (except for NSA :) )
by Caci99
Tue Mar 04, 2014 3:49 pm
Forum: General
Topic: Queue tree - Agregate a set of interfaces as parent
Replies: 2
Views: 994

Re: Queue tree - Agregate a set of interfaces as parent

You can group these interfaces under a bridge interface, or you can using mangling in such way that you can then apply the markings from mangle under the queue tree using global as interface, for example: /ip firewall mangle chain=forward action=mark-packet protocol=tcp new-packet-mark=down_e2 in-in...
by Caci99
Wed Feb 26, 2014 3:18 pm
Forum: General
Topic: Ipsec between RB1200 Cisco ASA 5520
Replies: 3
Views: 1421

Re: Ipsec between RB1200 Cisco ASA 5520

Thank you @mrz, that is what I have basically done. But I am not seeing any connection established. It should appear under remote peers, right?
by Caci99
Wed Feb 26, 2014 1:03 pm
Forum: General
Topic: Ipsec between RB1200 Cisco ASA 5520
Replies: 3
Views: 1421

Ipsec between RB1200 Cisco ASA 5520

Hello. I am completely new to Ipsec and as a result lost at it :). There is a company who is asking for an Ipsec connection and the counterpart is using Cisco ASA 5520. The IT of the other company has not been at help at all at assisting. So basically I configured Ipsec as per criteria given, but I ...
by Caci99
Tue Feb 25, 2014 10:50 am
Forum: General
Topic: Android USB Tethering
Replies: 5
Views: 15817

Re: Android USB Tethering

Samsung S4 works too at modem level. How did you enable the internet sharing from mikrotik ? IP firewall masquerading ? Care to share some steps?
well, it is basically the same as with any other situation, masquerade, gateway, dns.
by Caci99
Thu Feb 13, 2014 12:18 pm
Forum: Beginner Basics
Topic: RouterOS guidance.
Replies: 4
Views: 1357

Re: RouterOS guidance.

If I recall correctly, the RB2011 has two switches, the first includes ether1 to ether5 and the second ether6 to ether10. Now first lets assume that your WAN port is ether1. You should group the interfaces of first switch under ether 2: /interface ethernet set master-port=ether2 ether3 set master-po...
by Caci99
Wed Feb 12, 2014 7:29 pm
Forum: General
Topic: choosing the best DNS for ISP use
Replies: 9
Views: 6607

Re: choosing the best DNS for ISP use

my question is if i can subscribe to a premium DNS server near in europe, Regards Tough question :), for me at least. If your current dns server does not satisfy your needs, try switching to an open dns server and cache the requests on your mikrotik router and then redirect all users with transpare...
by Caci99
Wed Feb 12, 2014 2:43 pm
Forum: General
Topic: choosing the best DNS for ISP use
Replies: 9
Views: 6607

Re: choosing the best DNS for ISP use

You want to build your own or you want to know which provider is better? What is the problem you are facing with DNS servers? Generally speaking, your local DNS provider should be better (if they have build a good one). That is because it is faster to reach and it will redirect you to the right serv...
by Caci99
Mon Feb 10, 2014 2:28 pm
Forum: General
Topic: Static PPTP Interface
Replies: 5
Views: 1845

Re: Static PPTP Interface

It is simple. Just normally create dynamic one and after establishing connection double click onto dynamic interface - name will be something like <pptp-in1> -> then select "copy" and rename new (static) interface to same name "pptp-in1". After disconnect pptp link you will have...
by Caci99
Mon Feb 10, 2014 1:45 pm
Forum: General
Topic: Session limit per IP
Replies: 1
Views: 3426

Re: Session limit per IP

Try something like this: /ip firewall filter add chain=forward action=drop protocol=tcp in-interface=LAN connection-limit=100,32 In the connection-limit field the 100 number is the total connections, the 32 is the netmask, so with this you are applying a 100 connection limit to every IP on your LAN ...
by Caci99
Sat Feb 08, 2014 7:58 pm
Forum: General
Topic: Static PPTP Interface
Replies: 5
Views: 1845

Re: Static PPTP Interface

Well, that would still create a dynamic pptp interface, right?
by Caci99
Sat Feb 08, 2014 3:43 pm
Forum: General
Topic: Static PPTP Interface
Replies: 5
Views: 1845

Static PPTP Interface

I am trying to find in the wiki how to create a static PPTP interface, but can not find it.

Any one knows how to?
by Caci99
Fri Feb 07, 2014 8:20 pm
Forum: General
Topic: Nat rule
Replies: 1
Views: 1000

Re: Nat rule

have you tried specifying the incoming interface in your nat rule, like:
/ip firewall nat
add chain=dst-nat protocol=tcp in-interface=pppoe1 action=dstnat .... etc
by Caci99
Fri Feb 07, 2014 11:35 am
Forum: General
Topic: is there anyway to know password mistake?
Replies: 20
Views: 5022

Re: is there anyway to know password mistake?

The only issue is that it won't reset when a good connection is established right? What do you mean by reset? A valid connection will connect at first attempt and the source IP will be part of the stage1 list which has a time out of 1m. Obviously, you would not attempt a second connection and after...
by Caci99
Thu Feb 06, 2014 2:33 pm
Forum: General
Topic: is there anyway to know password mistake?
Replies: 20
Views: 5022

Re: is there anyway to know password mistake?

Thanks , it's very helpful I need SSH service - and I don't always from witch computer I will try to enter it.(this is why I don't block the IP ) Port knocking as some already mentioned or you can use some filter rules which you can find on the wiki, like these for example: /ip firewall filter add ...
by Caci99
Tue Feb 04, 2014 1:56 pm
Forum: General
Topic: a guess question
Replies: 3
Views: 943

Re: a guess question

Maximum recommended CAT5 length is 100 meters. Maybe that could be causing the problem? Yes, I know that, but it still connects. I have once even done a 160 meters long :) (good quality cable). How can the cable influence it? Maybe you are right, maybe some kind of electrical field or something (I ...
by Caci99
Tue Feb 04, 2014 1:46 pm
Forum: General
Topic: a guess question
Replies: 3
Views: 943

a guess question

Hello, a guess question :) I have a network made of two switches Core Router -->Switch+network -->Switch2+network Network is the same in both cases, the second switch is just an extension to another building. The cable that connects the two switches is some 120 meters long. What happens is that some...
by Caci99
Mon Jan 20, 2014 10:06 pm
Forum: General
Topic: Port Forward/Nat
Replies: 11
Views: 3180

Re: Port Forward/Nat

when i do a traceroute to 1.0.0.2 i never see 1.0.0.1 hop 13 and 14 are both showing 1.0.0.2 but when I do one to 1.0.0.1 I see 1.0.0.1. I'm sorry, my bad. If you execute traceroute from PBX you should reach 1.0.0.2 after two hops with no 1.0.0.1 in between. Anyway, I think you should test the conn...
by Caci99
Mon Jan 20, 2014 8:01 pm
Forum: General
Topic: Port Forward/Nat
Replies: 11
Views: 3180

Re: Port Forward/Nat

The PBX is connecting to our host who is Flowroute and it shows on there the ip address that is connected to it. The IP it is showing is the address of the Mikrotik not the PBX. Since it is a netmap, it is possible that PBX shows IP 1.0.0.1 instead of 1.0.0.2. Form the point of view of PBX, it does...
by Caci99
Mon Jan 20, 2014 2:33 pm
Forum: General
Topic: Port Forward/Nat
Replies: 11
Views: 3180

Re: Port Forward/Nat

Can you do an export of /ip firewall nat and post it in here? Also, how are you testing PBX, is the phone trying to connect from LAN or from outside your LAN?
by Caci99
Sat Jan 18, 2014 8:30 pm
Forum: General
Topic: Port Forward/Nat
Replies: 11
Views: 3180

Re: Port Forward/Nat

Yes, delete those rules or change the action on those rules to netmap. These rules should be the first, always, so that traffic of these rules does not get processed by the others.
by Caci99
Sat Jan 18, 2014 2:19 pm
Forum: General
Topic: Port Forward/Nat
Replies: 11
Views: 3180

Re: Port Forward/Nat

What you are trying to do is actually a one to one NAT. So your PBX will act as it has the WAN IP address. The rules are ok, but I would change them with action netmap: chain=dstnat dst-address=1.0.0.2 action=netmap to-address = 10.0.0.10 chain=srcnat src-address=10.0.0.10 action=netmap to-addresses...
by Caci99
Sat Jan 18, 2014 2:13 pm
Forum: General
Topic: How to Control ethernet bandwidth
Replies: 1
Views: 834

Re: How to Control ethernet bandwidth

Try a simple queue with target the intended interface
by Caci99
Fri Jan 17, 2014 4:54 pm
Forum: General
Topic: Firewall drop rules
Replies: 2
Views: 896

Re: Firewall drop rules

Because in the second rule, the packet going through, must meet both criteria in order to match it and be dropped. Obviously they don't match, meaning packets coming from 192.168.100.0/24 do not go out of bridge 1
by Caci99
Fri Jan 10, 2014 9:49 pm
Forum: General
Topic: MikroTik blocks iTunes device's restore
Replies: 6
Views: 3178

Re: MikroTik blocks iTunes device's restore

There does not seem to be any rule blocking your communication. Any way, you can feel safe disabling the firewall filter rules for the purpose of testing it.
by Caci99
Thu Jan 09, 2014 2:51 pm
Forum: General
Topic: Bandwidth management by IP address?
Replies: 3
Views: 1124

Re: Bandwidth management by IP address?

I think dude http://www.mikrotik.com/thedude can help you with that, or ntop on a linux PC.
by Caci99
Wed Jan 08, 2014 9:01 pm
Forum: General
Topic: RB951G-2HnD can use UBNT 24V POE adapter?
Replies: 5
Views: 2752

Re: RB951G-2HnD can use UBNT 24V POE adapter?

What it means is that RB951 can support power from 8 to 30V, and if I am correct all routerboards do with the exception of RB800. So you are safe to plug a 24V power supply.
by Caci99
Fri Jan 03, 2014 3:32 pm
Forum: General
Topic: What does NF and SNR actually report?
Replies: 2
Views: 1305

Re: What does NF and SNR actually report?

I think it is because the station from which you are monitoring is not yet connected to any AP, so that it can measure the noise floor on the channel it is connected. I have seen in real life links, on a very wireless crowded area, the noise floor dropping at -75 (very bad), actually jumping all the...
by Caci99
Fri Dec 27, 2013 8:45 pm
Forum: General
Topic: Android USB Tethering
Replies: 5
Views: 15817

Re: Android USB Tethering

I just tried it with my Samsung Galaxy S3, android version 4.1.2 and RB951G.
In the router it will add an interface lte1, then just add a dhcp client on this interface and you're done.
by Caci99
Tue Dec 24, 2013 9:17 pm
Forum: General
Topic: Happy X-mas
Replies: 4
Views: 1467

Re: Happy X-mas

Nice one, Happy Christmas and New Year :)
by Caci99
Thu Dec 19, 2013 1:54 pm
Forum: General
Topic: IP hangs, but I still can access via MAC address
Replies: 9
Views: 2635

Re: IP hangs, but I still can access via MAC address

May be an IP conflict in your LAN?
by Caci99
Wed Dec 18, 2013 10:21 pm
Forum: General
Topic: Connection sharing between several companies
Replies: 3
Views: 1172

Re: Connection sharing between several companies

It depends on how are you trying to implement it and if your current configuration interferes with it. A straight forward config should be a simple queue with target address=192.168.10.0/24 (the network of one company for example), or as target the interface at which it does connect. More info about...
by Caci99
Wed Dec 18, 2013 8:42 pm
Forum: General
Topic: NAT: going out and coming back in
Replies: 4
Views: 1639

Re: NAT: going out and coming back in

How often does the IP change? You might want to have a look at these links:
http://wiki.mikrotik.com/wiki/Manual:Sc ... _host-name
http://wiki.mikrotik.com/wiki/Use_host_ ... wall_rules
by Caci99
Wed Dec 18, 2013 3:19 pm
Forum: General
Topic: Internet access filter in a LAN
Replies: 3
Views: 1028

Re: Internet access filter in a LAN

Create an address list with addresses from the group you want to limit, then add a firewall rule for each time interval you want to block them:
/ip firewall filter
add chain=forward action=drop in-interface=LAN src-address-list=group1 time=12h-14h,sun,mon,tue,wed,thu,fri,sat
by Caci99
Tue Dec 17, 2013 8:27 pm
Forum: General
Topic: Getting lost license key
Replies: 2
Views: 991

Re: Getting lost license key

You should write to support, here in the forum there is not much help to provide with your problem :).
by Caci99
Tue Dec 17, 2013 1:47 pm
Forum: General
Topic: Masquerade not working correctly
Replies: 4
Views: 3038

Re: Masquerade not working correctly

But i'm not sure that an UDP stream could have invalid state =( Well, udp connections are stateless, so ... yes. But I think Router OS can manage them and see they are invalid. In the connection table it should appear as an unreplied connection anyway. You might want to set the time-out for udp con...
by Caci99
Tue Dec 17, 2013 1:25 pm
Forum: General
Topic: Masquerade not working correctly
Replies: 4
Views: 3038

Re: Masquerade not working correctly

That should be considered an invalid connection and should be dropped by a firewall rule on the forward chain, same as the one you have on the input chain about invalid connections.
by Caci99
Fri Dec 06, 2013 7:52 pm
Forum: General
Topic: Tunnel Interfaces (PPTP) and QOS
Replies: 0
Views: 942

Tunnel Interfaces (PPTP) and QOS

I have a simple network, not many users in it, and have some queue tree to share the bandwidth. It works fine actually, pretty satisfied. Mean while, I do have also a remote location which connects to the same router via wireless. Some devices on the remote site are connected to the router using PPT...
by Caci99
Mon Dec 02, 2013 3:23 pm
Forum: General
Topic: v6.7 released
Replies: 225
Views: 133498

Re: v6.7 released

*) address-list - allow manually adding timeoutable entries;
*) address-list - show dynamic entry timeout;
This option is available only in terminal right now, not in winbox, right?
by Caci99
Tue Nov 19, 2013 3:30 pm
Forum: General
Topic: Marking packets from another machine on a per-user basis
Replies: 4
Views: 1319

Re: Marking packets from another machine on a per-user basis

If got it right, you have some server to which users connect, and this server then does some kind of nat? and sends requests to the router using it's own IP? But you want to differentiate the connections of users before they live the sever so router can distinguish from which one it is coming althou...
by Caci99
Thu Nov 14, 2013 10:46 am
Forum: General
Topic: Lure users to Hotspot
Replies: 3
Views: 970

Re: Lure users to Hotspot

Thank you, never noticed that option :).
by Caci99
Wed Nov 13, 2013 2:29 pm
Forum: General
Topic: Static Routes
Replies: 1
Views: 1194

Re: Static Routes

The network 192.168.5.0/24 should reach and print to 192.168.5.50 with no problem. The catch is on the network 192.168.4.0/24. This network does not know where 192.168.5.50 is, so it will ask the router (its own gateway) about it. But since you have implemented policy routing by using PCC, the defau...
by Caci99
Tue Nov 12, 2013 6:38 pm
Forum: General
Topic: Static DNS only works intermittently
Replies: 7
Views: 2599

Re: Static DNS only works intermittently

I guess, mostly I am sure, that the PC is looking at some other DNS server and not the one on the router. What is causing it I don't know, could be a virus alternating the dns servers or redirecting those requests. As a solution I would propose to set up a transparent dns redirect on your router: /i...
by Caci99
Sun Nov 10, 2013 2:00 am
Forum: General
Topic: queue for limiting bandwith per IP address
Replies: 16
Views: 5729

Re: queue for limiting bandwith per IP address

uh, i feel releaved, glad it is working. Have fun :)
by Caci99
Sat Nov 09, 2013 3:30 pm
Forum: General
Topic: Static DNS only works intermittently
Replies: 7
Views: 2599

Re: Static DNS only works intermittently

Are the dhcp clients looking at the router dns? When this happens take a look at the cache of the router dns. In the cache you should find your static entry. If the entry is there then your machines are not requesting your router dns, but some other dns server, I guess.
by Caci99
Sat Nov 09, 2013 3:20 pm
Forum: General
Topic: ssd for mikrotik routeros
Replies: 6
Views: 3863

Re: ssd for mikrotik routeros

The cheapest SSD you can find is good enough. It is only used for storing the operating system, which is only 20 MB in size. You don't get any benefits from using a bigger or faster SSD. Are you sure about that? I ask because I have seen a lot of failures with cheap USB. Now SSD maybe another story...
by Caci99
Sat Nov 09, 2013 12:23 pm
Forum: General
Topic: queue for limiting bandwith per IP address
Replies: 16
Views: 5729

Re: queue for limiting bandwith per IP address

One last thing, set the bridge to use ip firewall, you can find this option in the settings of bridge.
by Caci99
Fri Nov 08, 2013 12:55 pm
Forum: General
Topic: queue for limiting bandwith per IP address
Replies: 16
Views: 5729

Re: queue for limiting bandwith per IP address

/ip address add address=192.168.223.145/24 comment="default configuration" interface=\ ether1-local network=192.168.223.0 Assign the ip address on the bridge interface instead of the ether interface /ip address add address=192.168.223.145/24 comment="default configuration" inter...
by Caci99
Thu Nov 07, 2013 3:42 pm
Forum: General
Topic: WAN interface usage is higher than LAN interface usage
Replies: 10
Views: 6406

Re: WAN interface usage is higher than LAN interface usage

You can also run torch on the WAN interface to see what is causing the traffic.
by Caci99
Thu Nov 07, 2013 1:28 pm
Forum: General
Topic: Lure users to Hotspot
Replies: 3
Views: 970

Lure users to Hotspot

Hello I had this idea about how to lure users to use the hotspot. Give free internet access for one hour in 24 hours or 3 days. After one hour they would need to login. The way I did it, was to allow access to everything in IP walled garden, and using a mangle rule added the IP to an address list. T...
by Caci99
Thu Nov 07, 2013 11:22 am
Forum: General
Topic: queue for limiting bandwith per IP address
Replies: 16
Views: 5729

Re: queue for limiting bandwith per IP address

Please post configs of your antenna. Enter in terminal from winbox and from there copy paste the configs of interfaces, addresses, routes, or just do
/export compact
and paste it in here.
by Caci99
Wed Nov 06, 2013 11:17 pm
Forum: General
Topic: Grant minimum bandwidth
Replies: 2
Views: 1604

Re: Grant minimum bandwidth

To guarantee the minimum bandwidth you need to specify the value of limit-at in the queue. In the hotspot user profile I don't see any option to add that value. So, I think you can play with address lists. Add the users in address lists and leave the limits on the profile empty so it will not create...
by Caci99
Wed Nov 06, 2013 10:20 pm
Forum: General
Topic: Port Forwarding
Replies: 4
Views: 1546

Re: Port Forwarding

I don't know if this could be of any help, but recently I struggled as well with a DVR which I don't remember the brand because it was not mine :). Any way, what I did was: 1. Connect using Internet Explorer, it might require some Active X control available only in Iexplorer. 2. Activate upnp in rou...
by Caci99
Wed Nov 06, 2013 9:24 pm
Forum: General
Topic: Feature request: Timeout and Uptime columns in Address-Lists
Replies: 5
Views: 2645

Re: Feature request: Timeout and Uptime columns in Address-L

Absolutely! I'd like to see this feature as well.
by Caci99
Wed Nov 06, 2013 2:14 pm
Forum: General
Topic: queue for limiting bandwith per IP address
Replies: 16
Views: 5729

Re: queue for limiting bandwith per IP address

So, to get this straight. You have a routerboard which is configured as bridge. And this routerboard you are putting a simple queue which should control the bandwidth of a device which is not in its network, right? Then, try in /ip firewall mangle to mark the packets coming from this device: /ip fir...
by Caci99
Tue Nov 05, 2013 10:20 pm
Forum: General
Topic: I can not access my RouterOS Winbox
Replies: 1
Views: 662

Re: I can not access my RouterOS Winbox

Try deleting the files in mikrotik folder under %appdata%
If you are using Windows 7 try to run winbox as administrator
by Caci99
Tue Nov 05, 2013 10:04 pm
Forum: General
Topic: queue for limiting bandwith per IP address
Replies: 16
Views: 5729

Re: queue for limiting bandwith per IP address

In the target field put the IP address you want to limit, and leave the destination field empty.
The destination field is used when you want to limit a particular connection from target IP to that destination IP
http://wiki.mikrotik.com/wiki/Manual:Qu ... properties
by Caci99
Tue Nov 05, 2013 12:26 pm
Forum: General
Topic: Switching with RouterOS / CRS Questions
Replies: 81
Views: 53560

Re: Switching with RouterOS / CRS Questions

In my opinion, it's a switch, the CPU is much too weak for so many ports.
I am not familiar at all with switching configuration, so sorry for the question but is a 600MHz CPU too small for a switch?
by Caci99
Sun Nov 03, 2013 11:30 pm
Forum: General
Topic: Use Metarouter to Implement Tor Anonymity Software
Replies: 8
Views: 4456

Re: Use Metarouter to Implement Tor Anonymity Software

Look at the config you posted, under /interface ethernet there is no interface named ether2, and that is why it gives you that error, it can not find it. You either name the interfaces ether1, ether2..., ether5, or in the line you are trying to add substitute the value of the ethernet interface with...
by Caci99
Wed Oct 30, 2013 10:29 pm
Forum: General
Topic: Queues Not Working on my Network..plzz suggest
Replies: 13
Views: 2958

Re: Queues Not Working on my Network..plzz suggest

Well, by interface config I meant the list of your interfaces, and also how is it configured as bridge? You have created a bridge interface with physical interfaces in it, right? Unfortunately, as I said I am not that good in Vlans. If no one answer to this topic, try opening another one with some t...
by Caci99
Wed Oct 30, 2013 8:14 pm
Forum: General
Topic: Queues Not Working on my Network..plzz suggest
Replies: 13
Views: 2958

Re: Queues Not Working on my Network..plzz suggest

You better post your interface configuration, bridge configuration and IP addresses if any on the router. Normally it would capture the traffic passing through, unless the traffic is encrypted which I doubt. In the mangle rule I posted above, try chain=prerouting instead of chain=forward and see if ...
by Caci99
Wed Oct 30, 2013 12:55 pm
Forum: General
Topic: Queues Not Working on my Network..plzz suggest
Replies: 13
Views: 2958

Re: Queues Not Working on my Network..plzz suggest

I am not good at Vlans, so I hope someone with better knowledge pops in, but can you tell me if the counters on the mangle rules are counting? Are those rules capturing the traffic?
by Caci99
Wed Oct 30, 2013 11:24 am
Forum: General
Topic: Queues Not Working on my Network..plzz suggest
Replies: 13
Views: 2958

Re: Queues Not Working on my Network..plzz suggest

So the MikroTik Router is bridge and not configured as router, right? In that case go to /firewall mangle and start mangling the traffic from the networks desired /ip firewall mangle add chain=forward src-address=172.168.16.0/24 action=mark-connection new-connection-mark=whatever passthrough=yes add...
by Caci99
Tue Oct 29, 2013 9:40 pm
Forum: General
Topic: Queues Not Working on my Network..plzz suggest
Replies: 13
Views: 2958

Re: Queues Not Working on my Network..plzz suggest

You better post your simple queues config to see how they are configured and what is not working
/queue simple print
From the picture is not clear what is not working.
by Caci99
Tue Oct 29, 2013 9:33 pm
Forum: General
Topic: Mikrotik and dynamic address list
Replies: 6
Views: 4029

Re: Mikrotik and dynamic address list

Well, the list will get populated again automatically, so I don't see the need to save it.
by Caci99
Tue Oct 29, 2013 9:24 pm
Forum: General
Topic: PPPOE server without ip-pool
Replies: 1
Views: 838

Re: PPPOE server without ip-pool

Yes, it is possible. Define the remote IP in the secret you create for the user.
by Caci99
Fri Oct 25, 2013 2:24 pm
Forum: RouterBOARD hardware
Topic: CRS vs Router
Replies: 10
Views: 8692

Re: CRS vs Router

Thank you Normis. Can you briefly explain what is the difference between a Layer 3 Switch and a router?
by Caci99
Fri Oct 25, 2013 2:18 pm
Forum: General
Topic: Use Metarouter to Implement Tor Anonymity Software
Replies: 8
Views: 4456

Re: Use Metarouter to Implement Tor Anonymity Software

You need to have a bridge interface which is named "natBridge" and also an interface named "ether2". The response from router that no such value of interface exists indicates that one of the two interfaces does not exist.
by Caci99
Fri Oct 25, 2013 2:03 pm
Forum: RouterBOARD hardware
Topic: CRS vs Router
Replies: 10
Views: 8692

CRS vs Router

So, with the new series of switches CRS which are Layer 3 switches, what is the main difference between them and a normal router? To what other Mikrotik Router can it be compared?
by Caci99
Tue Oct 22, 2013 4:59 pm
Forum: General
Topic: Firewall Rules to block access from certain IP
Replies: 5
Views: 2314

Re: Firewall Rules to block access from certain IP

They are each connected to a different interface on the router, NAS in port 2, User in Port 3, they are both in the same network 192.168.10.0/24, as the traffic is going through the router (in one interface and out the other) is it possible to restrict traffic to a certain port / IP? If not if I wa...
by Caci99
Mon Oct 21, 2013 3:44 pm
Forum: General
Topic: Firewall Rules to block access from certain IP
Replies: 5
Views: 2314

Re: Firewall Rules to block access from certain IP

What do you mean is going through the router? If you have physically connected the two devices on two different interfaces of the router then the two interfaces must have different IP addresses (but it doesn't look so). Can you post your router config? Basically, the router would block access with f...
by Caci99
Mon Oct 21, 2013 2:41 pm
Forum: General
Topic: Firewall Rules to block access from certain IP
Replies: 5
Views: 2314

Re: Firewall Rules to block access from certain IP

From what you have posted, it seems that both devices are on the same broadcast domain. Thus, no matter what rules you put on the router, they will not work, because the traffic between the devices does not pass through the router, instead they communicate directly with each other.