Community discussions

MikroTik App

Search found 1286 matches

by IntrusDave
Sun Jul 23, 2017 7:38 pm
Forum: Scripting
Topic: How do I run a custom binary?
Replies: 19
Views: 8185

Re: How do I run a custom binary?

Hey guys, make sure you don't respond with an answer that he doesn't like. Honest and respectful answers get you rated negative by this noob.
by IntrusDave
Sun Jul 23, 2017 7:34 pm
Forum: General
Topic: reset method
Replies: 6
Views: 1734

Re: reset method

Sorry, forgot the answer.

You will need to disconnect pins 1 and 2 to cut the power to the unit.
by IntrusDave
Sun Jul 23, 2017 7:33 pm
Forum: General
Topic: reset method
Replies: 6
Views: 1734

Re: reset method

https://en.wikipedia.org/wiki/Power_ove ... et#Pinouts

I still think just power cycling the power supplying the power would be much simpler.
by IntrusDave
Sun Jul 23, 2017 1:02 am
Forum: Scripting
Topic: How do I run a custom binary?
Replies: 19
Views: 8185

Re: How do I run a custom binary?

Allowing 3rd party binaries to run on a router/firewall is a massive security hole that could/would be used as an exploit and backdoor. I could not imagine any situation that I would ever trust a router that will run an arbitrary executable. Maybe a little linksys or something, but this isn't going ...
by IntrusDave
Sat Jul 22, 2017 9:32 pm
Forum: General
Topic: AVX2 and AVX-512
Replies: 1
Views: 1249

Re: AVX2 and AVX-512

No, not at this time. (maybe in ros 7)
by IntrusDave
Sat Jul 22, 2017 9:27 pm
Forum: Scripting
Topic: How do I run a custom binary?
Replies: 19
Views: 8185

Re: How do I run a custom binary?

RouterOS is a closed platform. You can not run a 3rd party binary.
by IntrusDave
Sat Jul 22, 2017 9:26 pm
Forum: SwOS
Topic: Error indication by LEDs
Replies: 1
Views: 2190

Re: Error indication by LEDs

Port speed / activity..
by IntrusDave
Sat Jul 22, 2017 9:13 pm
Forum: General
Topic: Backup Issue.
Replies: 4
Views: 1288

Re: Backup Issue.

Look into an external solution.

I use a UNIX server - The server makes an SSH connection, creates a backup, downloads the backup, then places it into an SVN repository. That way I can roll back to any config needed.
by IntrusDave
Sat Jul 22, 2017 9:06 pm
Forum: General
Topic: how to install on mini sata x86?
Replies: 7
Views: 3073

Re: how to install on mini sata x86?

RouterOS will only install on a SATA based device. the m.2 interface on most boards support both mSATA and PCIe. Make sure the drive is SATA based and not NVMe based. The NVMe (PCIe) require a much newer Linux kernel (something in 4.x range) while RouterOS is current still running a 2.x kernel.
by IntrusDave
Sat Jul 22, 2017 3:32 am
Forum: General
Topic: CRS
Replies: 1
Views: 904

Re: CRS

Log into it and use Quick Set.
by IntrusDave
Fri Jul 21, 2017 6:48 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

for those interested, the DNS now holds the list sizes. { :local list1 [ :resolve server=mikrotikfilters.com server-port=6502 domain-name=127.0.0.4 ]; :local list2 [ :resolve server=mikrotikfilters.com server-port=6502 domain-name=127.0.0.5 ]; :local list3 [ :resolve server=mikrotikfilters.com serve...
by IntrusDave
Fri Jul 21, 2017 6:29 pm
Forum: Beginner Basics
Topic: How do I fix this?
Replies: 4
Views: 1251

Re: How do I fix this?

Maybe wrong interface names?
by IntrusDave
Fri Jul 21, 2017 6:09 pm
Forum: General
Topic: Overlapping Subnets on same router
Replies: 4
Views: 1600

Re: Overlapping Subnets on same router

You are going to have far more problems trying to get this working than is you simply use unique subnets for each site. While reverse NAT is possible, you will find that it is not practical and very complicated to manage.
by IntrusDave
Fri Jul 21, 2017 5:57 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I've updated the server side to prevent units with 64M or less from pulling list 3. It's simply too big and causes the units to panic with an out of memory error. I watched one unit download the list and reboot more than 30 times last night, until I forced it to grab list two on the server side.
by IntrusDave
Fri Jul 21, 2017 5:55 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The previous version has been disabled because of abuse. Please remove all the blacklist scripts, and run the installer from the first post.
It provides you with a much more stable and flexible platform. Once installed, read over the .conf file and make changes to suit your needs.
by IntrusDave
Fri Jul 21, 2017 7:11 am
Forum: General
Topic: Access to service after logon
Replies: 12
Views: 2236

Re: Access to service after logon

can you manually add a dynamic entry and see what happens?
/ip firewall address-list add address=1.1.1.1 list=zzTest timeout=00:00:15
by IntrusDave
Fri Jul 21, 2017 6:44 am
Forum: General
Topic: Access to service after logon
Replies: 12
Views: 2236

Re: Access to service after logon

This is great, and I love port knocking... except the current RouterOS broke the timeout for address-list items. Right now, when they expire, they just sit their at 00:00:00 and are never removed. What version does that? I use Port Knocks quite a bit and had not seen that I was able to get in when ...
by IntrusDave
Fri Jul 21, 2017 2:15 am
Forum: General
Topic: Access to service after logon
Replies: 12
Views: 2236

Re: Access to service after logon

I do not. I run Mac :)
But I will look into it. I haven't yet because of the timeout issue.
by IntrusDave
Fri Jul 21, 2017 2:10 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The script is called once an hour, however that only means that you will make a single DNS lookup to see if the filters have changed. If there is no change, then no update is downloaded. If the DNS returns a newer serial number than the current installed list, then the new list is downloaded. The li...
by IntrusDave
Fri Jul 21, 2017 2:04 am
Forum: General
Topic: Access to service after logon
Replies: 12
Views: 2236

Re: Access to service after logon

I think you should consider using port knocking for what you want.

This is great, and I love port knocking... except the current RouterOS broke the timeout for address-list items.
Right now, when they expire, they just sit their at 00:00:00 and are never removed.
by IntrusDave
Fri Jul 21, 2017 12:52 am
Forum: General
Topic: Is hEX (RB750Gr3) can handle 2 x 100M WANs?
Replies: 9
Views: 4288

Re: Is hEX (RB750Gr3) can handle 2 x 100M WANs?

I have no issue with getting 100mbps. That the line speed of my fastest IPSec partner.
by IntrusDave
Thu Jul 20, 2017 11:42 pm
Forum: RouterBOARD hardware
Topic: Lte not working on 922UAGS-5HPacD
Replies: 7
Views: 2140

Re: Lte not working on 922UAGS-5HPacD

Make sure you buy the correct model for your carrier. Most LTE modems come in 2 varieties, WCDMA & GMS.
by IntrusDave
Thu Jul 20, 2017 11:37 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I go away for a week and everything has changed. :shock: @IntrusDave, thank you again for all your work on this blacklist. Unfortunately for me, the automated scripting is now too intrusive and is itself a serious security risk, so I'm out. If in the future you resume publishing a blacklist of addr...
by IntrusDave
Thu Jul 20, 2017 10:13 pm
Forum: Scripting
Topic: tx-bytes rx-bytes have spaces and are unusable. Please help (edited and added more info)
Replies: 7
Views: 4538

Re: tx-bytes rx-bytes have spaces and are unusable. Please help (edited and added more info)

I use this code to fix it. The Global creates a reusable function, then use the "$removeSpace t=" to call the function :global removeSpace do={ :local temp; :for i from=0 to=([:len $t] - 1) do={ :local char [:pick $t $i]; :if ($char = " ") do={ :set $char ""; } :set tem...
by IntrusDave
Thu Jul 20, 2017 10:00 pm
Forum: RouterBOARD hardware
Topic: Lte not working on 922UAGS-5HPacD
Replies: 7
Views: 2140

Re: Lte not working on 922UAGS-5HPacD

The RB922UAGS-5HPacD does not come with an LTE modem installed. The SIM in on the system board, but you must install the modem into the Mini PCIe socket.
by IntrusDave
Thu Jul 20, 2017 7:22 pm
Forum: General
Topic: Access to service after logon
Replies: 12
Views: 2236

Re: Access to service after logon

This isn't something supported by MikroTik. A good solution would be setting up a VPN service and requiring a VPN connection first.
by IntrusDave
Thu Jul 20, 2017 7:04 pm
Forum: RouterBOARD hardware
Topic: Lte not working on 922UAGS-5HPacD
Replies: 7
Views: 2140

Re: Lte not working on 922UAGS-5HPacD

Likely an incompatible modem, or a modem that only supports PPP. What type of make and model did you use?
by IntrusDave
Thu Jul 20, 2017 7:01 pm
Forum: General
Topic: RB260GSP with QRT5ac on a 12V Batterie, QRT reboots every few minutes
Replies: 5
Views: 2101

Re: RB260GSP with QRT5ac on a 12V Batterie, QRT reboots every few minutes

I agree, 12V is likely your issue. Can you wire the batteries in series and switch to 24V?
by IntrusDave
Thu Jul 20, 2017 6:56 pm
Forum: Virtualization
Topic: CHR initial time wrong
Replies: 12
Views: 4761

Re: CHR initial time wrong

No need to be rude. Clearly he doesn't understand, which is easily explained by his post count (that was his 1st post). Anyway - The CHR doesn't have any of the VM tools installed, so it is unable to communicate directly with the host to get the date and time. Unfortunately, you only real choice is ...
by IntrusDave
Thu Jul 20, 2017 6:47 pm
Forum: General
Topic: how to install on mini sata x86?
Replies: 7
Views: 3073

Re: how to install on mini sata x86?

netinstall is for MikroTik devices only. It will not work on x86.

RouterOS for x86 will only install on the first BIOS supported drive detected. You will need to disconnect all drives, except the drive you want it installed on. And that drive must be a BIOS bootable device.
by IntrusDave
Thu Jul 20, 2017 6:43 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Thank you for the script, but I have to say that, as least in my limited testing, I stumbled upon too many blocked gmail servers. I couldn't even send an email from my gmail account to my corporate address. The worst part is that gmail somehow didn't even alert me that the message did not go throug...
by IntrusDave
Thu Jul 20, 2017 6:40 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Morning, tnx for explaining the script rights issue, to bad we are struggling with that, for now it works here. @Dave I noticed the script got updated to 2.0.3 in the past 12 hours, it would be nice to see some kind of changelog if possible ? Keep up the good work ! Eddie release notes are in the f...
by IntrusDave
Thu Jul 20, 2017 6:40 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Hi all i'm running in my ccr-1009-8G-1S-1S+ log is show notthing but Script List show this messeage https://goo.gl/yYE2do https://goo.gl/yYE2do messeage is " LOG 【;(eval (eval /putmessage=$t) (eval /log warningmessage=$t))】 urlEncode【;(eval (eval /localname=$temp) (eval /forcounter=$i;do=;(eva...
by IntrusDave
Wed Jul 19, 2017 8:47 pm
Forum: General
Topic: Is hEX (RB750Gr3) can handle 2 x 100M WANs?
Replies: 9
Views: 4288

Re: Is hEX (RB750Gr3) can handle 2 x 100M WANs?

I've been running a Rb3011 with two 300mbps WANs and 24 IPsec tunnels for almost a year with no issues. The CPU is quire powerful. I have recently replaced it with a RB1100AHx4, but only because I wanted the internal storage.
by IntrusDave
Wed Jul 19, 2017 7:31 pm
Forum: General
Topic: Slack not working when using eoip tunnel
Replies: 1
Views: 1128

Re: Slack not working when using eoip tunnel

Check your MTU. EoIP has a smaller MTU, and without adjusting for it, https often fails.
by IntrusDave
Wed Jul 19, 2017 7:27 pm
Forum: General
Topic: Is hEX (RB750Gr3) can handle 2 x 100M WANs?
Replies: 9
Views: 4288

Re: Is hEX (RB750Gr3) can handle 2 x 100M WANs?

The hEX should be able, but if you can, I would go with a RB3011.
by IntrusDave
Wed Jul 19, 2017 7:25 pm
Forum: Scripting
Topic: Scrip permission error
Replies: 3
Views: 4555

Re: Scrip permission error

Give the script full permissions. Also, make sure it's owned by a user with full access.
by IntrusDave
Wed Jul 19, 2017 6:51 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

No worries, I have no intention of including rules beyond the basic examples provided in the initial posts.
by IntrusDave
Wed Jul 19, 2017 4:36 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Hi Dave, First of all thanks for an amazing job and all effort you're putting into this. It's working just fantastic on my hAP-ac router. A small idea to consider: how about extending firewall filter rules with autoblock functionality for intruders trying to get to a router or network? A dynamic li...
by IntrusDave
Wed Jul 19, 2017 4:33 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Unfortunately, taking away the permissions ends with empty scripts. Taking away ANY of them causes issues - I do not know why. You *SHOULD NOT* need "password" or "sensitive", but removing them causes the failure.
by IntrusDave
Wed Jul 19, 2017 2:11 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Just pushed out 2.0.2.2 :)
new auto-script-update script is included. It pulls the current version from the server and updates if needed.
by IntrusDave
Wed Jul 19, 2017 12:58 am
Forum: General
Topic: Anyone else having this VPN issue?
Replies: 17
Views: 3929

Re: Anyone else having this VPN issue?

My issues are all Mikrotik to Mikrotik. My Mikrotik to Cisco IPsec VPNs never seem to fail.
by IntrusDave
Wed Jul 19, 2017 12:54 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Just released 2.0.2 with minor bug fixes. Run the auto-update/install script to update.
by IntrusDave
Tue Jul 18, 2017 7:18 pm
Forum: General
Topic: Anyone else having this VPN issue?
Replies: 17
Views: 3929

Re: Anyone else having this VPN issue?

No idea at all. And I am unable to force it to happen, so I can't even submit a support request.
by IntrusDave
Tue Jul 18, 2017 7:12 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Check for the Scheduler and Script Policies. Make sure that all of the boxes are marked.
by IntrusDave
Tue Jul 18, 2017 2:16 am
Forum: General
Topic: Router Max Connections?
Replies: 7
Views: 4793

Re: Router Max Connections?

The CRS is a switch (Cloud Router Switch) with routing ability. The RB2011 has the same CPU. I would recommend that you invest in a router more suited for what you are doing. The RB3011, RB1100AHx4, and CCR1009 will all do nicely for that. To be honest, all of the MMIPS based units are great boxes f...
by IntrusDave
Tue Jul 18, 2017 2:11 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

So two things... Some users are simply blocked at my firewall, and now two users have been added to the list itself. I don't see this as "poisoning" as they are the ones that were actively trying to find security holes. (They have been trying SQL injections) Given that they are active atta...
by IntrusDave
Mon Jul 17, 2017 6:24 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

You should be getting the same logging both ways. If not, check the schedule policy and the script policy and make sure all of the boxes are checked.
by IntrusDave
Mon Jul 17, 2017 6:18 am
Forum: General
Topic: Anyone else having this VPN issue?
Replies: 17
Views: 3929

Re: Anyone else having this VPN issue?

I have the same issue. It has gotten to the point that I have a script on every router to kill the IPSec connections and flush the SA's, at the same time on both ends.
by IntrusDave
Mon Jul 17, 2017 2:46 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I've shut down the old service (pre 2.0 script). I found that several users were leaching the large list and rebranding it as their own. They were also trying to probe the server side for exploits. Again, I offer my list as a free service to the MikroTik community. If people continue to abuse it, I ...
by IntrusDave
Mon Jul 17, 2017 12:21 am
Forum: General
Topic: rest with out reset button
Replies: 4
Views: 1279

Re: rest with out reset button

?

if the router is powered by PoE, then you can cycle the PoE port's power.
by IntrusDave
Mon Jul 17, 2017 12:20 am
Forum: RouterBOARD hardware
Topic: RB1100AHx4 Dude Edition
Replies: 52
Views: 20092

Re: RB1100AHx4 Dude Edition

fat32 if you need to move data between the router and a PC. What's the logic behind this? The router has to read the file into RAM and send it, and the other way around on writing. And this has nothig to do with the undelying file system. So unless you want to move that SSD physically to a Windows ...
by IntrusDave
Mon Jul 17, 2017 12:14 am
Forum: Beginner Basics
Topic: Please HELP, Firewall Basic Question....
Replies: 3
Views: 863

Re: Please HELP, Firewall Basic Question....

/ip firewall filter add place-before=0 chain=input src-address=10.0.9.10-10.0.9.12
/ip firewall filter add chain=input action=drop
then remove any other input rules.
by IntrusDave
Sat Jul 15, 2017 5:27 pm
Forum: General
Topic: rest with out reset button
Replies: 4
Views: 1279

Re: rest with out reset button

you can power cycle using PoE, but you can not trigger a Net-Install.
by IntrusDave
Sat Jul 15, 2017 5:23 pm
Forum: Beginner Basics
Topic: Please HELP, Firewall Basic Question....
Replies: 3
Views: 863

Re: Please HELP, Firewall Basic Question....

create an accept rule on the input chain, with 10.0..9.10-10.0.9.12 as the source address.
then create a drop-all rule for everything else.

https://wiki.mikrotik.com/wiki/Manual:I ... all/Filter
by IntrusDave
Sat Jul 15, 2017 5:15 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 Dude Edition
Replies: 52
Views: 20092

Re: RB1100AHx4 Dude Edition

So all the dude data would be saved on the 60gb drive? If you want, yes. Configure the disk in the "system -> disks" menu first. Hi Normis, formating with ext3 or fat32 ? which is better for routeros ? Just a guess - ext3, as it's native for Linux and has better corruption protection. fat...
by IntrusDave
Sat Jul 15, 2017 5:14 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

in my testing, the 64M units are struggling with anything other than the small list. I'm seeing about 60% of the 64M units pull the medium list 10+ times in a row. That is telling me that the 64M units are having kernel panics and rebooting. At this time, the server is now forcing the small list on ...
by IntrusDave
Fri Jul 14, 2017 10:03 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

released version 2.0.1 with minor improvements.

Old version will not longer function soon. Please use the install script in the first post to update.
Auto-Script-Update is being testing in house. I hope to have the routers updating themselves next week.
by IntrusDave
Fri Jul 14, 2017 6:18 am
Forum: General
Topic: Interfaces Up/Down every 3 seconds
Replies: 4
Views: 3683

Re: Interfaces Up/Down every 3 seconds

If you can not easily replace the cable, try manually setting the speed on each end. I've seen them many times in my 35 years of networking. It is most often the cable, but I have also seen interfaces fail after a power cycle. Most recently, I had this happen on a CCR1009. The interface was constant...
by IntrusDave
Wed Jul 12, 2017 10:04 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

For the time being, I'm very happy with the list system and BGP will not be implemented anytime soon. Currently, about 60% of the systems pulling the blacklist are dynamic IP. That number could be MUCH higher, as some ISP's don't force an IP change unless the modem is offline for a few hours. I will...
by IntrusDave
Wed Jul 12, 2017 2:04 am
Forum: General
Topic: What is Google DNS doing here?
Replies: 9
Views: 2256

Re: What is Google DNS doing here?

All Android based devices use Google DNS for things other than DNS. (Like how I use DNS to alert clients about blacklist updates) These devices include Phones, Tablets, Refrigerators, Air Conditioners, notebooks, TVs, DVD/Bluray payers... the list goes on and on. I've found that if you are redirecti...
by IntrusDave
Tue Jul 11, 2017 10:24 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The RAW rule is not blocking outgoing traffic. But it IS blocking the response from the the remote address.
by IntrusDave
Tue Jul 11, 2017 6:53 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Hi msatter, thank you very much for your quick answer. I solve the problem as here but I wonder that when i add my ip block in here like 123.123.32.0/22, is this not make problem to me ? because when i add rule to accept for my ip blocks, blacklisted ip's can attack to my ip range if I true. furthe...
by IntrusDave
Sun Jul 09, 2017 9:07 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

diff would work, if I can guarantee that every router will get every update. If someone misses an update, the whole process is screwed. It would require a complete do-over on the backend, and I would have to build the scripts in realtime to deal with differences in versions. Still far too many only ...
by IntrusDave
Sun Jul 09, 2017 8:56 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The issue with that is that with 200,000+ entries the [find where address=xxx.xxx.xxx.xxx] is really REALLY slow. Each list causes RouterOS to check EVERY entry each time. so you are looking at 200,000*200,000 loops. That's 40+ Billion loops.
by IntrusDave
Sun Jul 09, 2017 7:54 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Oh, also... The changes resulted in new list sizes. the "small list" (#1) is only 46kb now (down from 118kb). Medium (#2) is 860kb (down from 2.2M), large is 4M (down from 12M).
by IntrusDave
Sun Jul 09, 2017 7:51 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Now that the import/export is moved to the server side script generation, I can make changes on the fly without the need to update the script. So, I've returned to the old "remove, then add" method. The "add, or update" was never completing on low end routers. Even CCR's were tak...
by IntrusDave
Sun Jul 09, 2017 7:13 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released! (New bridge implementation delayed till 6.41rc)
Replies: 207
Views: 65799

Re: v6.40rc [release candidate] is released! (New bridge implementation)

before this RC, ether5 was 64:D1:54:CF:04:3C. I can't get it to change back
Does /interface ethernet reset-mac-address ether5 command fail?

I does not fail, but it does not do anything at all.
by IntrusDave
Sun Jul 09, 2017 12:18 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released! (New bridge implementation delayed till 6.41rc)
Replies: 207
Views: 65799

Re: v6.40rc [release candidate] is released! (New bridge implementation)

I have a MAC conflict /interface ethernet set [ find default-name=ether5 ] mac-address=64:D1:54:CF:04:3B set [ find default-name=ether11 ] speed=1Gbps set [ find default-name=ether12 ] name=ether12-IoT set [ find default-name=ether13 ] name=ether13-WAN [djoyce@Intrus_AltaLoma] /interface ethernet> p...
by IntrusDave
Sun Jul 09, 2017 11:36 am
Forum: Wireless Networking
Topic: The Famous WISP
Replies: 2
Views: 746

Re: The Famous WISP

You need to configure you wireless as the WAN, setup it the wifi in client mode. Then configure the ethernet ports as the LAN. It's not a difficult setup, but you will need to head to the Wiki to learn more first.

http://wiki.mikrotik.com/
by IntrusDave
Sun Jul 09, 2017 11:32 am
Forum: Beginner Basics
Topic: port forwarding problem to mailserver zimbra
Replies: 2
Views: 3032

Re: port forwarding problem to mailserver zimbra

The NAT looks okay - though I would remove the DNS redirect. Do you have the correct Forward Accept rules? Oh, also - all of those rules could have been simplified into one. chain=dstnat action=dst-nat to-addresses=11.11.11.212 protocol=tcp dst-port=22,25,110,143,465,587,993,995,3443,7071,7143,7993,...
by IntrusDave
Sun Jul 09, 2017 2:56 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

It looks like we’ve uncovered a bug. The timers on dynamic entries aren’t removing the entries when they reach 0.

I’ll change the script to do the remove and add when I get home tonight.

Going to sit in a pool for the evening. It’s 110°F right now. I can’t think anymore.
by IntrusDave
Sat Jul 08, 2017 10:57 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released! (New bridge implementation delayed till 6.41rc)
Replies: 207
Views: 65799

Re: v6.40rc [release candidate] is released! (New bridge implementation)

dynamic firewall address-list items are not being removed when they expire.
by IntrusDave
Sat Jul 08, 2017 10:37 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I will say that the BGP method would be simpler to manage over a large distribution, and the implementation on the client side is brain-dead simple: enable BGP (if not already using BGP) with any private ASN other than 64567. (or just use their real ASN if they're already running BGP). in-filter=ac...
by IntrusDave
Sat Jul 08, 2017 10:17 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Well, right off the bat, BGP fails me.
Peers do not support dynamic IPs.
This is a show stopper for me, as most of the routers I deal with are dynamic.
by IntrusDave
Sat Jul 08, 2017 9:41 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

were there thoughts about BGP feed?..
Okay, I give. Can you point me to a basic setup for BGP. I don't even know where to start.
by IntrusDave
Sat Jul 08, 2017 7:25 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Thank you. It's definitely still a beta. I'm really not happy with the update process. I like using the "functions" to make the list smaller, and it works well on my x86 and CHR boxes, but even my CCR1016 in my datacenter struggles with the process. using BartoszP's concept of "add, u...
by IntrusDave
Sat Jul 08, 2017 7:11 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

not very happy with the speed... Still trying to figure a good way to do this.
by IntrusDave
Sat Jul 08, 2017 3:28 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

So - this process is VERY slow. The initial import is quick, but the updates take a very long time. The upside is that the entries are left in place so that their is no gap in protection.
by IntrusDave
Sat Jul 08, 2017 3:22 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

New script is live. grab the installer in the first post.
Make sure you remove any old schedules and scripts.

Remember this is an RC. it may have bugs.
by IntrusDave
Sat Jul 08, 2017 2:11 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

too much work for the slow units. I think I have a solution.
It's slow... but there is no "unprotected time".
by IntrusDave
Fri Jul 07, 2017 10:00 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I think I've found a viable balanced solution. I'll be posting the first beta of the new system later today.
by IntrusDave
Fri Jul 07, 2017 7:41 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I have an idea :idea: for you:
:local l "dynamicBlacklist"
/ip f a
a l=$l a=127.0.0.1
I like this. going to see how much it slows things down.
by IntrusDave
Fri Jul 07, 2017 11:56 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I thought of that. Diff won't work. Everyone would have to always be current. Some will update as soon as an update is available. Others will only update daily. Some even update weekly, even though the list expires after 24 hours.
by IntrusDave
Fri Jul 07, 2017 11:45 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

My concern isn't so much size, but time.
With the majority of routers pulling the list being single core, my tests have shown that an import / update like that causes dropped packets.
by IntrusDave
Fri Jul 07, 2017 11:35 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I'm sure that would work, but with 200,000 entries in the "large" list, that would make the file size almost 40M.

I suppose I can generate two sets of lists, one the other way and one this way..?
by IntrusDave
Fri Jul 07, 2017 4:49 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Bad news. Removing in the background and importing in foreground doesn't work. The background removal is executed on the same CPU core, so overall speed is only a few seconds difference. The issue I am seeing on all of the multicore routers is that the delay needed before starting the import is 10~2...
by IntrusDave
Thu Jul 06, 2017 6:24 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Great new that you are going to take the next step, to have better control of and more flexible way of initiating updates by means of DNS. I have managed this morning to not have any need any more for smaller files now I can remove and import the dynamicBlacklist at same moment. This reduces the ex...
by IntrusDave
Thu Jul 06, 2017 6:02 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I've started work on "2.0.0". I will no longer be updating this branch. The new branch (going with more normal version numbers) will be more modular and, if installed with the included installer script, it will keep itself updated with the current version and will only update the blacklist...
by IntrusDave
Thu Jul 06, 2017 5:53 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

In your posted code, you have the delay set to 0. It's fine in the hosted code at https://mikrotikfilters.com/updateBlacklist.rsc
Thank you. Corrected.
by IntrusDave
Thu Jul 06, 2017 9:07 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

ROFL oops. I fixed it. Should have been NOW not NOT

s/not/now/
by IntrusDave
Thu Jul 06, 2017 7:19 am
Forum: Announcements
Topic: v6.40rc [release candidate] is released!
Replies: 231
Views: 77901

Re: v6.40rc [release candidate] is released!

script 2 must be:
:global test;
:put $test
OoooOoooohhhhh! Okay :)
by IntrusDave
Thu Jul 06, 2017 6:46 am
Forum: Announcements
Topic: v6.40rc [release candidate] is released!
Replies: 231
Views: 77901

Re: v6.40rc [release candidate] is released!

I have a scripting issue. if one script sets a global, another script is not able to see it. However, I can see them on the console. Script 1 :global test "test" Script 2 :put $test running the scripts from the console, I would expect Script 2 to output "test", but it's output is...
by IntrusDave
Thu Jul 06, 2017 6:06 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

New script updated. I'm now including a change log on in the first post.
by IntrusDave
Thu Jul 06, 2017 5:00 am
Forum: General
Topic: Fetch to SD problem
Replies: 1
Views: 487

Re: Fetch to SD problem

I have checked the SD cards and they are fine. Each was able to write 10GB at a rate of 2GB per minute without errors.
by IntrusDave
Thu Jul 06, 2017 4:47 am
Forum: General
Topic: Fetch to SD problem
Replies: 1
Views: 487

Fetch to SD problem

Hey guys, are any of you experiencing problems with downloading using "fetch" and saving directly to an SD? All of my CCR1009's with a 16GB high-endurance microSD are having problems. Anything over a few hundred kilobytes fails with an incomplete download. fetching to the NAND works perfec...
by IntrusDave
Thu Jul 06, 2017 2:05 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I have a request. I was testing with a more informative disabling and enabling from the log entries and when I did not disable and enable again as normal is done on an import I did not get only the normal logging but not the huge numbers of the removals and adds to the list in the log. I was very n...
by IntrusDave
Thu Jul 06, 2017 1:32 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I doubt they are false positives. Speedtest.net servers are NOT controlled by them. They are 3rd parties that are often shared hosts. If they get blocked, it's because they have allowed a host, shared host, or infected host to remain online. Even Amazon's AWS gets blocked because spammers will "...
by IntrusDave
Tue Jul 04, 2017 11:55 pm
Forum: Scripting
Topic: Telnet output to variable
Replies: 1
Views: 672

Re: Telnet output to variable

you know... maybe I'll just use DNS. I'll have to see how that works.
by IntrusDave
Tue Jul 04, 2017 11:49 pm
Forum: Scripting
Topic: Telnet output to variable
Replies: 1
Views: 672

Telnet output to variable

So, I was hoping to simple run this, and have the output placed into a variable that I could then parse. Unfortunately, it appears that the telnet output is sent directly to the console and cannot be captured. Any ideas of a simple way to get text from an outside source into a variable WITHOUT writi...
by IntrusDave
Tue Jul 04, 2017 11:35 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Older client scripts requested "dynamic" (the "get=dynamic" in the URL) requests for the old "dynamic" are currently being redirected to "medium", and will soon be switched to an automatic selection based on the CPU and memory. I'll be honest, I have no intere...
by IntrusDave
Tue Jul 04, 2017 7:46 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Unfortunately it's not possible to tell the source of the block. The lists are generated from 12 different high profile blocklists, as well as a network of over 200 routers. Once the server has all of the sources, the IP addresses are extracted and then aggregated into a new list that has the subnet...
by IntrusDave
Tue Jul 04, 2017 3:04 am
Forum: Scripting
Topic: NPK or gzip support?
Replies: 0
Views: 503

NPK or gzip support?

Hoping that one of the MikroTik guys can comment on this... My blacklist is getting very large. I'm hoping to be able to send the script (about 200,000 "add" lines) in a compressed format. Is it possible to compress it on the server side and send it as an NPK, then import from that? Thanks
by IntrusDave
Tue Jul 04, 2017 2:11 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I had a quick peek at 2017.7.3f and I have to admit that I am a bit lost on it. Update: Before the v [ScriptVer] would undergo a cleaning of spaces which are replaced by %20 for use in the URL which is not not more done. I have still the word (testing) in my version string with a space in front. It...
by IntrusDave
Mon Jul 03, 2017 10:04 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Updated the script with minor bug fixes, speed ups, and more detail when run from the console.
by IntrusDave
Mon Jul 03, 2017 7:05 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Next thought is to only supply the addresses itself and that would shrink the size of the medium file from 4.1MB to 729KB but then we have to split it up in more than 177 files due to 4096 bytes String limit present in RouterOS. With more than 80% of the routers pulling the list only having a MIPS ...
by IntrusDave
Mon Jul 03, 2017 6:58 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I went through different options how to reduce traffic and the quick and easy one is removing the comment in the medium and large file and that gives a reduction in traffic of over 20% assuming that the users of the medium and large file know what that addresslist is named dynamicBlacklist stands f...
by IntrusDave
Mon Jul 03, 2017 6:51 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

please keep in mind that with all the chaos in the world now, the list is regenerated every 4 hours. I don't recommend holding on to an older list for more than 8 hours. Also, I have no bandwidth caps so I have no issue with people downloading several times a day - But I don't want it abused and pul...
by IntrusDave
Sat Jul 01, 2017 3:25 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The new backend and script are live. Make sure you read the comments and select the correct script for your router. *** DO NOT SELECT THE LARGE LIST FOR ROUTERS WITH LESS THAN 20M FREE DISK OR LESS THAN 256M Memory! *** Recommendation: Routers with 32M~128M memory - "small" list Routers wi...
by IntrusDave
Fri Jun 30, 2017 7:04 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

were there thoughts about BGP feed?..
Too much work :)
by IntrusDave
Fri Jun 30, 2017 5:53 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Today’s update is going to be huge. Not sure when I will push it it out though. I am rewriting the backend that builds the list. I will be pushing out 3 lists soon. Small - about 750kb - intended for home users Standard - about 2M - intended for businesses Full - about 14M - intended for internet se...
by IntrusDave
Thu Jun 29, 2017 9:09 am
Forum: General
Topic: Random Port Attack
Replies: 15
Views: 3460

Re: Random Port Attack

Also, consider adding a RAW drop rule to drop the subnet that the attack is coming from.
by IntrusDave
Thu Jun 29, 2017 9:08 am
Forum: General
Topic: Random Port Attack
Replies: 15
Views: 3460

Re: Random Port Attack

Are you running my BlackList? It will help protect you from many attacks.

If this is a DDoS attack, and you have a dynamic IP, the simple solution is to change your MAC address on the WAN port and reboot the modem to get a new IP address.

viewtopic.php?f=9&t=98804
by IntrusDave
Thu Jun 29, 2017 7:30 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I think you need to check that you have a reliable date in the first place. It can be a while between boot up and acquiring the current date and time. I would not count on a simple delay being enough, I would sanity check the date. I second that. If I've learned anything about RouterOS, it's that y...
by IntrusDave
Wed Jun 28, 2017 9:58 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

That's why I have always had two scheduled tasks. One for Startup and one every 24 hours.
by IntrusDave
Wed Jun 28, 2017 8:44 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I updated both the server and script to correct for the notification not displaying. I also changed the script so that the previous entries are not removed if the throttling kicks in. I would love to NOT have to throttle, but several people have set up their units to update every 5 minutes. at 2M ea...
by IntrusDave
Wed Jun 28, 2017 7:49 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

That could be just the update timing. Currently, my list collects the data a 5am PST and rebuilds then. several of the sources also rate limit, but I may be able to push it and rebuild it ever 6 hours. that may keep them more in sync.

Okay, I changed the cron job to run every 6 hours.
by IntrusDave
Wed Jun 28, 2017 7:40 pm
Forum: General
Topic: RB3011 instability ROS 6.39.2
Replies: 5
Views: 1486

Re: RB3011 instability ROS 6.39.2

Very odd indeed. This is one of those times that we may just not have an answer. If I was in front of the box and was able to go through the config line-by-line, I might be able to figure it out. But I've often just found that a fresh start is a better way to deal with it.
by IntrusDave
Wed Jun 28, 2017 7:45 am
Forum: General
Topic: RB3011 instability ROS 6.39.2
Replies: 5
Views: 1486

Re: RB3011 instability ROS 6.39.2

I would make a backup of the config, then reset to factory and do a very simple config, then test each port. You may have inadvertently changed something in the config that killed the port. If you want a simple setup - clear the config, then set ports 2,3,4,5 to master port 1. Ports 7,8,9,10 to mast...
by IntrusDave
Wed Jun 28, 2017 2:12 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

So far so good. Doesn't help the low end units much.
a quick test...

RB2011 - 123 seconds
CCR1016 - 25 seconds
RB1100AHx4 - 20 seconds
RB3011 - 33 seconds

....WOW! The new RB1100AHx4 is faster than a 16 core CCR.
by IntrusDave
Wed Jun 28, 2017 1:06 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

That looks like a nice clean solution. I'll test it out on the gear I have and then update the code. Thanks!
by IntrusDave
Tue Jun 27, 2017 8:56 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Updated the script with the recommended remove code. It appears to speed the update process by 38~75 seconds on most routers.
by IntrusDave
Mon Jun 26, 2017 9:03 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I rewrote the backend this morning. It now takes all of the sources and purges the /32's into the their corresponding subnet, if it is listed. it cut the size by 50%. it was in the 42,000 range, now back down to 21,000.
by IntrusDave
Mon Jun 26, 2017 7:05 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

David, please consider including blocklist.de's block list. I've been using both your blocklist and the one from squidblacklist.org for a little bit and so far the only major difference is from blocklist.de. If you add that then I can drop squidblacklist.org.
Done.
by IntrusDave
Mon Jun 26, 2017 6:39 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

By the way, why is the default path "disk1/dynamic.rsc"? because that is the default path of a USB or SATA drive. If the driver does not exist, it simply creates that path. This way the USB is used if it's there. Anyway, fun fun. I hadn't tried this before: jun/23/2017 10:50:44 system,err...
by IntrusDave
Mon Jun 26, 2017 6:32 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

it didn't work for me (CCR1016-12G)
error :
/tool fetch url="https://mikrotikfilters.com/updateBlacklist.rsc" mode=https;
status: failed

failure: connection timeout
Connection Timout on that would imply that your IP may be blocked to start with.
by IntrusDave
Thu Jun 22, 2017 4:42 pm
Forum: Beginner Basics
Topic: Configuration backup using sftp
Replies: 4
Views: 2807

Re: Configuration backup using sftp

Not with SFTP, no. You could use an HTTPS PUT and upload it to a web server.
by IntrusDave
Thu Jun 22, 2017 4:40 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

then consider using both =) first quickly remove for recent versions, then slow cleanup for older ones if necessary
I'll do that for the next release.
by IntrusDave
Thu Jun 22, 2017 8:29 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I think that C-z in "0KiBC-z" stands for Compression gzip so it is there and now it is how to get that working for the .RSC
the C-z means "Control-Z to Pause", not compressed-zip
by IntrusDave
Thu Jun 22, 2017 6:38 am
Forum: General
Topic: RB1100AHx2 slow wan speed
Replies: 1
Views: 656

Re: RB1100AHx2 slow wan speed

We can't remotely begin to help without seeing the config.
you need to post the compact export for interfaces, bridges, and firewall. Maybe even the queues.
by IntrusDave
Wed Jun 21, 2017 9:53 pm
Forum: Beginner Basics
Topic: Configuration backup using sftp
Replies: 4
Views: 2807

Re: Configuration backup using sftp

Use ssh on the server side. It's simpler and doesn't require anything special on the router side.
ssh username@ip_address "/export compact" > routerBackup_export.rsc
by IntrusDave
Wed Jun 21, 2017 7:04 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The server does compress the content.... As seen by this compression test.
by IntrusDave
Wed Jun 21, 2017 5:57 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The loop is to deal with older versions of RouterOS that would only remove the first item it found when using Find.
by IntrusDave
Wed Jun 21, 2017 8:00 am
Forum: RouterBOARD hardware
Topic: USB Battery to power routerboard
Replies: 21
Views: 6935

Re: USB Battery to power routerboard

No

1amp at 5 volts is 5 watts
1amp at 12 volts is 12 watts

It’s best to understand how many watts the device needs and what voltage it requires.
by IntrusDave
Tue Jun 20, 2017 6:23 pm
Forum: General
Topic: hap ac - reset configuration HOW?!
Replies: 2
Views: 3919

Re: hap ac - reset configuration HOW?!

From the quick guide:
by IntrusDave
Tue Jun 20, 2017 9:48 am
Forum: Scripting
Topic: Simplified DSCP/QoS Setup Script
Replies: 14
Views: 11616

Re: Simplified DSCP/QoS Setup Script

The mangle rules created by the script only mark the packets for DSCP. You will need to create new rules to set the DSCP for the video packets. Keep in mind that QoS only works for your outbound traffic. Unless you are using an MPLS for your WAN, you can not control your inbound QoS.
by IntrusDave
Tue Jun 20, 2017 9:25 am
Forum: Beginner Basics
Topic: DNS to DHCP
Replies: 3
Views: 756

Re: DNS to DHCP

Don't pass the DNS to the clients. Have the clients use the router as the DNS, and have the router use the ISP. Allow the router to use it's cache to reduce the LTE load.
by IntrusDave
Tue Jun 20, 2017 9:22 am
Forum: Beginner Basics
Topic: Very weird issue about RouterOS and MS domain, please help
Replies: 14
Views: 2794

Re: Very weird issue about RouterOS and MS domain, please help

Just enable RouterOS DHCP server, no any MS DHCP server.
This is your problem. You should use the MS DHCP. It will register your workstations in the DNS. Use the services that the AD provides. (DHCP, DNS, WINS)
by IntrusDave
Tue Jun 20, 2017 9:18 am
Forum: Scripting
Topic: Simplified DSCP/QoS Setup Script
Replies: 14
Views: 11616

Re: Simplified DSCP/QoS Setup Script

Yes, you would need to mangle rules to mark the packets with the priority that you want them to have.
by IntrusDave
Tue Jun 20, 2017 6:58 am
Forum: General
Topic: SWITCH crs112
Replies: 10
Views: 2397

Re: SWITCH crs112

The bandwidth test in the switch will not show the true speed. You will need to use something like a Linux based test on two boxes connected to the switch.
by IntrusDave
Mon Jun 19, 2017 8:57 pm
Forum: General
Topic: Block Botnet attack
Replies: 1
Views: 1935

Re: Block Botnet attack

Why don't you built an address list of the PSN IP addresses, add a filter that blocks and logs the connections. Then you can see the local IP addresses that are attacking. Then clean them.
by IntrusDave
Mon Jun 19, 2017 8:41 pm
Forum: RouterBOARD hardware
Topic: USB Battery to power routerboard
Replies: 21
Views: 6935

Re: USB Battery to power routerboard

two 12v deep cycle batteries, a 50w solar panel and a charge controller will do what you need.
by IntrusDave
Mon Jun 19, 2017 5:55 pm
Forum: Scripting
Topic: Simplified DSCP/QoS Setup Script
Replies: 14
Views: 11616

Re: Simplified DSCP/QoS Setup Script

Your router will honor the QOS tagging in the packets
by IntrusDave
Mon Jun 19, 2017 5:49 am
Forum: General
Topic: SWITCH crs112
Replies: 10
Views: 2397

Re: SWITCH crs112

It sounds like you are bridging or routing, and not switching.
The device can do wire-speed forwarding on all ports.
Did you remove the default config? Set all the ports in a bridge?
If you are using it as a switch, then all ports should have port 1 as it's master.
by IntrusDave
Mon Jun 19, 2017 5:43 am
Forum: General
Topic: DSCP need help
Replies: 2
Views: 1084

Re: DSCP need help

The device / application sets the DSCP. You VoIP signaling is 26, while your VoIP audio is 46. It's best not to change from the defaults. You will want to configure the router to read and use the DSCP bits. I use the script in this post to setup the routers. https://forum.mikrotik.com/viewtopic.php?...
by IntrusDave
Mon Jun 19, 2017 5:37 am
Forum: Beginner Basics
Topic: Very weird issue about RouterOS and MS domain, please help
Replies: 14
Views: 2794

Re: Very weird issue about RouterOS and MS domain, please help

DNS needs to be pointed at the AD server.
That's may only guess without any info on the design of the network.
by IntrusDave
Fri Jun 16, 2017 8:47 am
Forum: RouterBOARD hardware
Topic: RB3011UIAS-RM
Replies: 4
Views: 1493

Re: RB3011UIAS-RM

While I don’t know the solution to your problem, this topic has piqued my curiosity. If it were me, I would first try connecting a PC to Ether1 and see if I got the same result. Next I would try a Crossover cable between the port and the modem. Next I would try manually setting the port speed and du...
by IntrusDave
Thu Jun 15, 2017 11:57 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Doing the copy and paste from post #1 worked. Still not sure why it stopped working. Thank you!
Sweet, glad it fixed it for you.
by IntrusDave
Wed Jun 14, 2017 10:15 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

try a copy/paste from the first post. Not sure what the issue is, the server isn't reporting any issues.
by IntrusDave
Tue Jun 13, 2017 6:13 am
Forum: Beginner Basics
Topic: Mikrotik+parts of sites
Replies: 3
Views: 996

Re: Mikrotik+parts of sites

Are you using EoIP for anything?
by IntrusDave
Tue Jun 13, 2017 6:11 am
Forum: Virtualization
Topic: CHR on ESXi - VM got stopped
Replies: 4
Views: 4573

Re: CHR on ESXi - VM got stopped

Consider at least upgrading to ESXi 5.5, preferably 6.5. I had MANY issues with VM and even full host crashes with 5.1, most have been resolved after moving to 6.5
by IntrusDave
Tue Jun 13, 2017 6:08 am
Forum: Beginner Basics
Topic: AirPrint with Mikrotik hap AC and Bridge
Replies: 3
Views: 2374

Re: AirPrint with Mikrotik hap AC and Bridge

Once you put VLANs in play, you no longer have a "flat" network. You can run a pig and trace route from a notebook to the printer. If you have more than 1 hop, then you are routing and AirPrint will not work. It is a broadcast protocol. You issue is likely the VLAN tagging on the WLAN inte...
by IntrusDave
Mon Jun 12, 2017 9:30 pm
Forum: RouterBOARD hardware
Topic: CCR1072 RAM
Replies: 10
Views: 2953

Re: CCR1072 RAM

DDR1333 and DDR1600 have different latencies. MikroTik is providing throughput details for the CPU clocked at either 1GHz or 1.2GHz, using DDR3 1333 or DDR3 1600.
by IntrusDave
Sat Jun 10, 2017 9:43 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

SHouldn't be an issue for most. The server will flag routers that get excessive and throttle them to 4 download in a 24 hour period.
by IntrusDave
Sat Jun 10, 2017 5:16 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Thanks to someone setting up 50 routers to download every 2 minutes, the server is now blocking any router that downloads more than 4 times in a 24 hour period.
by IntrusDave
Fri Jun 09, 2017 6:01 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The script was updated last week to work with the new backend servers. You can find the update in the first post of this thread
by IntrusDave
Fri Jun 09, 2017 12:42 am
Forum: RouterBOARD hardware
Topic: R52Hn antenna & Frequency CONFIGURATION questions.
Replies: 2
Views: 1061

Re: R52Hn antenna questions.

One of the bonuses of 2.4 and 5GHz is that the 5Ghz is half the wavelength of the 2.4Ghz. That means that you can use a single antenna tunes for 2.4Ghz as a ½ wave 5Ghz antenna. That said, just find a nice 2/5Ghz dual band omni and you are set. The wireless config in RouterOS will let you select whi...
by IntrusDave
Fri Jun 09, 2017 12:36 am
Forum: General
Topic: Mikrotik Initial Setup
Replies: 9
Views: 2296

Re: Mikrotik Initial Setup

In that case, simply add (or change) the current IP on ether1 to the IP that you would like it to have. Optionally, you can use the DHCP client to have the CRS pull it's own address and configure it's gateway and DNS automatically.
by IntrusDave
Thu Jun 08, 2017 11:12 pm
Forum: Beginner Basics
Topic: Default filter firewall
Replies: 4
Views: 18141

Re: Default filter firewall

Also, it's easier to understand the rules if you post them using this:
/ip firewall filter export compact
by IntrusDave
Thu Jun 08, 2017 11:08 pm
Forum: Beginner Basics
Topic: Default filter firewall
Replies: 4
Views: 18141

Re: Default filter firewall

The detail and understanding is something that you will gain by reading. https://wiki.mikrotik.com/wiki/Manual:TOC Read the filter section of the Wiki first. Once you cover that, it will become clear as to what they are doing. Just having someone explain it here will not help you in the future. Once...
by IntrusDave
Thu Jun 08, 2017 11:03 pm
Forum: General
Topic: Adding mikrotikOS to an existing network
Replies: 1
Views: 590

Re: Adding mikrotikOS to an existing network

Everything you need is all in one place: https://wiki.mikrotik.com/wiki/Manual:TOC Start there, get your basics covered, then post back here for help on refining the setup. You will need to read and learn about the RouterOS before anyone here will be able to help. Without the basic understanding, yo...
by IntrusDave
Thu Jun 08, 2017 11:00 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Whitelisting is accomplished by creating a new address-list and a new filter rule. 1) Create an address list - say.. "Whitelist" and add the IP addresses that you need never be blocked. 2) create a new filter "Accept" rule, using the src-address-list you created. 3) place the new...
by IntrusDave
Thu Jun 08, 2017 3:21 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I noticed today when I started Firefox that I were getting hits on the blacklist. I followed the IP and found that it lead to hackademix.net and secure.informaction.com and looking on the site it was probably an plug-in was generating the hits and that was No-script. I use this plug-in for years an...
by IntrusDave
Thu Jun 08, 2017 3:17 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I've updated the statistics page today. It now normalizes the memory and shows the percentage of each category
by IntrusDave
Wed Jun 07, 2017 6:58 am
Forum: Scripting
Topic: "startup" script runs too early
Replies: 13
Views: 4627

Re: "startup" script runs too early

PMs are blocked here. You have Facebook or twitter?
by IntrusDave
Wed Jun 07, 2017 6:52 am
Forum: Scripting
Topic: "startup" script runs too early
Replies: 13
Views: 4627

Re: "startup" script runs too early

Jim - Do you work for DWP or SCE?
by IntrusDave
Wed Jun 07, 2017 1:14 am
Forum: Scripting
Topic: "startup" script runs too early
Replies: 13
Views: 4627

Re: "startup" script runs too early

Here is the first two lines of my startup script: :log info "Starting System Startup script" :delay 00:00:20 Note that all this script does is send me an E-Mail that lets me know that the router has booted. Leave it to the HAM's to understand. :) That's almost exactly what I use. It works...
by IntrusDave
Mon Jun 05, 2017 4:17 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

No problem at all. I enjoy it.
by IntrusDave
Mon Jun 05, 2017 4:12 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Fixed. Sorry about that. typo in the code.
by IntrusDave
Mon Jun 05, 2017 3:58 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Not sure why its not working all of a sudden. I updated the script a few days ago and was working as of yesterday... Now when the script runs, it says its downloading the blacklist but nothing else happens.
What are the last two octets of the public IP?
by IntrusDave
Fri Jun 02, 2017 8:58 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I've cleared all my starts and started fresh. Here is a quick and dirty stats page on the hardware accessing the list.

https://mikrotikfilters.com/blstats.php
by IntrusDave
Fri Jun 02, 2017 8:14 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Awesome! Thanks for still doing this. Now that you got more stats, you should create some public pages cause i love me some random statistics!
I was just starting on a page that shows each type and number of routers that pulls the list.
by IntrusDave
Fri Jun 02, 2017 8:02 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Glad it's working for everyone now. Stats are MUCH more accurate now. The server was starting to block devices behind NAT routers because it thought some were downloading hundreds of times per hour. Now it sees each as a separate device.
by IntrusDave
Thu Jun 01, 2017 7:42 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script


syntax error (line 62 column 11)[/code]
I found the line 62 error and corrected it. delete the items you have, and reinstall. it should be good to go.
by IntrusDave
Thu Jun 01, 2017 7:40 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I've updated the script to deal with the CHR using system-id instead of software-id. Annoying that they are different... I've tested on the following units with no failures. CCR1009-7G-1C-1S+ CCR1009-8G-1S-1S+ CCR1016-12G CCR1036-12G-4S CHR CRS109-8G-1S-2HnD CRS125-24G-1S CRS125-24G-1S-2HnD hAP+ac h...
by IntrusDave
Thu Jun 01, 2017 6:59 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I am on a RB951Ui-2HnD
can you post the /system license print ?
by IntrusDave
Thu Jun 01, 2017 6:48 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I'm guessing that everyone with issues are running CHR. I've found the problem and I'm working on a fix right now. I'll post the update in about an hour.
by IntrusDave
Wed May 31, 2017 8:27 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Sorry man. More than 500 routers already updated and working with the new script. You are having copy/paste issues. I can't fix that for you.
by IntrusDave
Wed May 31, 2017 5:39 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

That would mean that you need the current script. It's available in the first post.
by IntrusDave
Wed May 31, 2017 5:12 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Your URL is wrong.
Note the ? between "download.php" and "get"
url="https://mikrotikfilters.com/download.php?get=dynamic&model=$model&version=$ver&memory=$memory&id=$name&ver=$scriptVer&softid=$softid"
by IntrusDave
Wed May 31, 2017 8:48 am
Forum: General
Topic: Serial connection: garbled output: spaces?
Replies: 4
Views: 1830

Re: Serial connection: garbled output: spaces?

Those are ANSI escape sequences. You need to use a terminal that supports ANSI.
Looks like you may be using Linux, you can use also use the screen command from a terminal window.
by IntrusDave
Wed May 31, 2017 8:05 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Okay, I've updated the script again. It didn't like having the path and filename separate. # Import Intrus Managed Filter Lists # © 2016-2017 David Joyce, Intrus Technologies ##### Update your path, is you are using a USB Flash or other storage :global datapath "disk1/dynamic.rsc" ###### D...
by IntrusDave
Wed May 31, 2017 7:41 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Yup, clearly a problem with the remove. I can't seem to get it to accept a variable
by IntrusDave
Wed May 31, 2017 6:37 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Try this
:global datapath "/disk-8G/"
by IntrusDave
Wed May 31, 2017 12:36 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I've updated the script with support for USB Flash as well as the new RB1100AHx4 with internal storage. I has also reworked the backend and script for more accurate accounting. Please update your scripts. # Import Intrus Managed Filter Lists # © 2016-2017 David Joyce, Intrus Technologies ##### Updat...
by IntrusDave
Sun May 28, 2017 6:35 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 Dude Edition
Replies: 52
Views: 20092

Re: RB1100AHx4 Dude Edition

I've pre-ordered one from Baltic Networks. It looks like a nice box and my be just what I'm looking for. The downside is that it should arrive the day before I leave for a 4 week vacation at the beach. Looks like I may be testing how it holds up to sun, sand, and humidity.
by IntrusDave
Fri May 19, 2017 6:38 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The list is stored in memory while active.
If you need to use a flash drive for the update, just add the path of the usb drive to the path of the fetch and import lines.
by IntrusDave
Mon May 15, 2017 6:24 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

My list will not be moving to DNS. It over complicates the process and provides little if any advantages.
by IntrusDave
Thu May 11, 2017 12:08 am
Forum: RouterBOARD hardware
Topic: RB1100AHx4 Dude Edition
Replies: 52
Views: 20092

Re: RB1100AHx4 Dude Edition

Anyone have a release date for this? I'm ready to upgrade all of my sites and this unit would cover just about every use I can think of.
by IntrusDave
Wed May 03, 2017 12:13 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Give this a try... # Import Intrus Managed Filter Lists # ©2016-2017 David Joyce, Intrus Technologies :log warning "Blacklist update in 30 seconds"; # :delay 10 :local model [/system resource get board-name] :local version [/system resource get version] :local memory [/system resource get ...
by IntrusDave
Thu Apr 27, 2017 9:36 pm
Forum: General
Topic: problem : High cpu usage by networking at profile
Replies: 6
Views: 13333

Re: problem : High cpu usage by networking at profile

Disable mangles, filters, & queues.

You have given us nothing to work with. What router? How much bandwidth? What are you filter & mangle rules? What kind of traffic?
by IntrusDave
Thu Apr 27, 2017 6:25 pm
Forum: General
Topic: how to block DHCP request?
Replies: 2
Views: 2197

Re: how to block DHCP request?

1. because you are bridging, and bridging passes all traffic.
2. enable firewall on the bridge and filter UDP 67 & 68 from passing on the ethernet
by IntrusDave
Thu Apr 27, 2017 6:18 pm
Forum: General
Topic: You kill me...
Replies: 7
Views: 1904

Re: You kill me...

I am always amazed when someone refuses to read the release notes, then posts here trying to shame and insult MikroTik for the end user ignorance. The only thing you have accomplished is showing us that you have no place in the I.T. field, and that you will not take responsibility for your own actio...
by IntrusDave
Thu Apr 27, 2017 3:00 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Try downloading directly from here: https://mikrotikfilters.com/updateBlacklist.rsc Unfortunately, I don't have a router that gets this error, so I really can't troubleshoot it. If one of you want to give me access to a router that is having a problem with the script, I can try and figure out what t...
by IntrusDave
Tue Apr 25, 2017 6:53 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Yes, You can create an address list with addresses that you never want blocked, then add an accept rule above the drop rules.
by IntrusDave
Mon Apr 24, 2017 10:28 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

That is the same unit I use for writing my scripts. I have just over 500 of them pulling the list every morning. The error you posted is almost always a simple format or encoding error.
by IntrusDave
Mon Apr 24, 2017 4:35 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I don't know. I stopped using OpenBL a while back.
by IntrusDave
Sat Apr 22, 2017 1:37 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Oh, and I ran some tests today. Filtering based on IP *ONLY* and not subnet.. the download was 112M and had over 2M entries.
by IntrusDave
Sat Apr 22, 2017 1:35 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

On that note - what is really pissing me off is that big hosts like AWS and Google aren't doing anything about shutting down the attacks coming from their networks. Much of the spam is coming from AWS servers that change IP's every hour. So the only way to stop them is to block the whole subnet.
by IntrusDave
Sat Apr 22, 2017 1:32 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The filters are intended to be used as incoming filters, not outgoing. If you change your rules to only block new connections coming in on the WAN interface, all should be good. I don't recommend using the list with the RAW filters. By blocking incoming on the WAN and new connections, you prevent th...
by IntrusDave
Sat Apr 22, 2017 1:23 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I don't blame them. Over the last 3 months my block list has gone from 5k entries to 30k. With most of the attacks coming from Russia and China. I'm starting to consider blocking all of Russia's IP ranges. I know that isn't good for most of the world, but my networks here in the USA are under consta...
by IntrusDave
Thu Apr 20, 2017 1:14 am
Forum: SwOS
Topic: Switch OS 2.1 -- Warning: do not attempt RB260GSP CSS106-1G-4P-1S upgrade over POE Port
Replies: 11
Views: 5483

Re: Switch OS 2.1 will brick your switch!

I'm not sure where the archive for SwitchOS is. But I would try to reset defaults and see if that helps. It sounds like the config corrupted in the upgrade.
by IntrusDave
Wed Apr 19, 2017 11:08 pm
Forum: SwOS
Topic: Switch OS 2.1 -- Warning: do not attempt RB260GSP CSS106-1G-4P-1S upgrade over POE Port
Replies: 11
Views: 5483

Re: Switch OS 2.1 will brick your switch!

Congrats on being the first. Why not just put the switch into TFTP mode and upload the firmware? Not sure why you would have to drive two hours to do that. Or did you really update the firmware remotely without testing on a local device?
by IntrusDave
Wed Apr 19, 2017 5:39 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Every time that I have seen a 400 Error, it is because the Copy/Paste didn't work. Something is the script is wrong... Maybe it has extra formatting, or maybe invalid characters. Make sure the OS that you are using supports UTF-8. Try copying and pasting the script to Notepad, and then copying and p...
by IntrusDave
Wed Apr 12, 2017 4:35 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

OpenBL is currently offline. So right now the filters are limited to my internal sources.
by IntrusDave
Mon Apr 10, 2017 10:49 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The rules are just examples, and should always be adjusted to suit the needs of the network.

I don't know what's going on with OpenBL. I can only assume they have either shut down, or are under DDoS.
by IntrusDave
Sat Apr 08, 2017 6:10 am
Forum: General
Topic: Port 21 and 554 shows as open when doing a port scan from outside
Replies: 8
Views: 2714

Re: Port 21 and 554 shows as open when doing a port scan from outside

It's possible that they are redirecting traffic on those ports. Maybe to try and protect you, or to prevent you from running servers on them.
by IntrusDave
Thu Apr 06, 2017 8:39 pm
Forum: General
Topic: Port 21 and 554 shows as open when doing a port scan from outside
Replies: 8
Views: 2714

Re: Port 21 and 554 shows as open when doing a port scan from outside

simplest explanation is normally the correct one.

You have ports open.

If you need a more detailed answer, you will need to post your firewall filter and nat exports.
by IntrusDave
Thu Apr 06, 2017 6:54 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Glad it's working out for you.
List usage jumped from 4800 to 5100 in the last two days.
by IntrusDave
Fri Mar 31, 2017 6:59 pm
Forum: Announcements
Topic: MUM Europe 2017 Live!
Replies: 64
Views: 25473

Re: MUM Europe 2017 Live!

I have not seen the device yet, but I would guess, yes.
by IntrusDave
Fri Mar 31, 2017 6:49 pm
Forum: Announcements
Topic: MUM Europe 2017 Live!
Replies: 64
Views: 25473

Re: MUM Europe 2017 Live!

what is the propose of this "Woobm" device?
... (W)ireless (O)out (O)of (B)and (M)anagement.

that would be... Management of a device, wirelessly, while not requiring the network to connect.
by IntrusDave
Thu Mar 30, 2017 10:01 pm
Forum: Announcements
Topic: MUM Europe 2017 Live!
Replies: 64
Views: 25473

Re: MUM Europe 2017 Live!

They have been pretty clear that there will be no status updates until a beta is released.
by IntrusDave
Thu Mar 30, 2017 8:54 pm
Forum: Announcements
Topic: MUM Europe 2017 Live!
Replies: 64
Views: 25473

Re: MUM Europe 2017 Live!

No ROS 7 updates?

That's highly disappointing...
ROFL! Did you really expect that??
by IntrusDave
Thu Mar 30, 2017 8:50 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Some interesting stats... +-----+--------------------+ | QTY | model | +-----+--------------------+ | 721 | RB951G-2HnD | | 548 | RB2011UiAS-2HnD | | 374 | RB2011UiAS | | 309 | hAP+ac | | 298 | RB951Ui-2HnD | | 182 | RB751G-2HnD | | 178 | CCR1016-12G | | 174 | SXT+Lite5 | | 166 | CCR1009-8G-1S-1S+ |...
by IntrusDave
Tue Mar 28, 2017 8:53 pm
Forum: General
Topic: RDP password scan
Replies: 6
Views: 2801

Re: RDP password scan

Then you will not be able to block brute force attacks.
by IntrusDave
Tue Mar 28, 2017 1:54 am
Forum: General
Topic: RDP password scan
Replies: 6
Views: 2801

Re: RDP password scan

You can use this free tool, it works well.

http://www.terminalserviceplus.com/rdp-defender.php
by IntrusDave
Mon Mar 27, 2017 10:26 pm
Forum: General
Topic: USB cash drawers
Replies: 10
Views: 2011

Re: USB cash drawers

Okay, I spoke with my sister, and she was also to get my the engineering documents. Unfortunately, the drawer's interface used the Microsoft HID (Human interface device) interface. That means that the drawer receives commands, and sends back status to the system, instead of a simple Serial interface...
by IntrusDave
Sun Mar 26, 2017 8:02 pm
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 390
Views: 139461

Re: v6.39rc [release candidate] is released

A RB3011 with a regular configruation when upgraded from v6.38.5 to v6.39.55 or v6.39.58 device becomes unusable: reboots again and again until it is recovered with reset and netinstall.
I has this same issue. I think it may be from the addition of the partition support.
by IntrusDave
Sat Mar 25, 2017 5:57 am
Forum: General
Topic: USB cash drawers
Replies: 10
Views: 2011

Re: USB cash drawers

Sister confirmed that it's one of her's sold in Ireland. She will get me the engineering specs on Monday.
by IntrusDave
Fri Mar 24, 2017 5:14 pm
Forum: General
Topic: USB cash drawers
Replies: 10
Views: 2011

Re: USB cash drawers

I'll look into this.
My sister is VP of customer service for M-S Cash Drawer.
I'll see if she can get me the details and maybe a sample.

What model drawer is it?
by IntrusDave
Fri Mar 24, 2017 3:46 pm
Forum: General
Topic: Mikrotik in enterprise company
Replies: 7
Views: 5030

Re: Mikrotik in enterprise company

I don't believe that they will change the warranty. However, with the very low price, I recommend ordering a few spare units to keep on hand.
I have only had 1 MikroTik fail - a LHC5 - but I believe that was because it was not grounded.
by IntrusDave
Fri Mar 24, 2017 2:20 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Schedules are allowed to have the same name. -- The server side was updated today. I was forced to make the server require the identity. The public IP and Identity are used for accounting so I can track the bandwidth and number of requires. I understand that some will object to this, and I will prov...
by IntrusDave
Fri Mar 24, 2017 1:19 am
Forum: General
Topic: Mikrotik in enterprise company
Replies: 7
Views: 5030

Re: Mikrotik in enterprise company

I'm not supposed leave the router in the network core.
what does this mean?

I'm not really sure what you are asking - but I use Mikrotik for everything except for my voice PRI's. I use them in each office and my datacenter. I have a total of 31 CCR1016's and 6 CCR1032.
by IntrusDave
Thu Mar 23, 2017 5:03 pm
Forum: General
Topic: cannot access https websites
Replies: 16
Views: 11405

Re: cannot access https websites

Glad to have helped. It took me several days of looking at every little thing to figure that out.
by IntrusDave
Wed Mar 22, 2017 3:26 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

I don't even know where to start with that. Maybe MTU? running pppoe? ssl proxy? wrong MTU? anything different about this router over others?
by IntrusDave
Wed Mar 22, 2017 6:44 am
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Unfortunately, I don't know how to help you with this. I don't see any errors in my server logs. I can only assume that you are getting ssl errors. You should be able to manually install the scripts from the first post.
by IntrusDave
Tue Mar 21, 2017 4:57 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

You issue is that the router simply didn't complete the download. Today's download is 603k. If it's getting out off, you may want to see if your ISP is trying to proxy ssl connections.
by IntrusDave
Tue Mar 21, 2017 12:41 am
Forum: General
Topic: cannot access https websites
Replies: 16
Views: 11405

Re: cannot access https websites

Any chance that you have a ppp or epio interface in a bridge? Everytime that I have seen this issue, it has been an MTU problem. When you add an interface into a bridge, the bridge will automatically lower the MTU of the bridge to the lowest MTU of all of the interfaces. This almost always breaks HT...
by IntrusDave
Mon Mar 20, 2017 9:59 pm
Forum: General
Topic: install mikrotik routerOS dell SAS 6/iR
Replies: 2
Views: 1464

Re: install mikrotik routerOS dell SAS 6/iR

This has been discussed many times before. If you must use the RAID controller, you will need to use CHR on ESXi 6.x.
by IntrusDave
Mon Mar 20, 2017 5:33 pm
Forum: General
Topic: Block IP after X login failures
Replies: 6
Views: 26617

Re: Block IP after X login failures

That's find, but make sure that the rule is placed above any accept rule for established connections.
by IntrusDave
Sun Mar 19, 2017 6:54 pm
Forum: General
Topic: Ryzen build for Routeros
Replies: 7
Views: 2814

Re: Ryzen build for Routeros

I agree with pukkita, a PC is going to cost double what a CCR1009 will cost. Even a CCR1016 is only is the US$500 range.
I use the CCR1016-1S-1S+ for my 500/500 fiber links. They support 50~150 PC's without even getting warm.
by IntrusDave
Sat Mar 18, 2017 7:56 pm
Forum: General
Topic: Block IP after X login failures
Replies: 6
Views: 26617

Re: Block IP after X login failures

You need to put in a filter rule (preferably in the RAW table) to block the blacklisted IP's
by IntrusDave
Fri Mar 17, 2017 12:29 am
Forum: General
Topic: Where do I set up QoS in my 3011?
Replies: 8
Views: 2322

Re: Where do I set up QoS in my 3011?

You can use WinBox. Open System->Scripts, then create a new one. Paste the above script into the editor.
by IntrusDave
Thu Mar 16, 2017 9:51 pm
Forum: General
Topic: Where do I set up QoS in my 3011?
Replies: 8
Views: 2322

Re: Where do I set up QoS in my 3011?

Using that script will get you the framework that you need. Once you have that, you can add a few simple Mangle rules to mark the Plex video as a higher priority than the NAS file transfer. You will also want to keep the ACKs at a higher priority than the rest of the traffic.
by IntrusDave
Thu Mar 16, 2017 9:38 pm
Forum: Wireless Networking
Topic: Severe BUG in firmware 6.37.x - 6.38.5 ! PROBLEM !
Replies: 30
Views: 6861

Re: Severe BUG in firmware 6.37.x - 6.38.5 ! PROBLEM !

This is not a bug. czech republic allows 5725-5875MHz for A/N/AC at up to 14dBm for fixed point-to-point links. It is your responsibility to set the scan list to the range that is legal for your use. If MikroTik blocked that range, then someone would be upset that it was blocked, because they need i...
by IntrusDave
Thu Mar 16, 2017 8:45 pm
Forum: General
Topic: Where do I set up QoS in my 3011?
Replies: 8
Views: 2322

Re: Where do I set up QoS in my 3011?

MikroTik more or less gives you 100% control over everything. So you have to implement QoS using a Queue Tree and Mangle Rules. Simple queues can work, but a Queue Tree/Mangle Rules will do the big work for you. With the RB3011, you have more then enough power to implement full DSCP. with the lower ...
by IntrusDave
Thu Mar 16, 2017 8:12 pm
Forum: General
Topic: Where do I set up QoS in my 3011?
Replies: 8
Views: 2322

Re: Where do I set up QoS in my 3011?

You can try this script. It will setup QoS based on DSCP, honoring applications preferred DSCP packet marking. #Set interface here :local outboundInterface "wan0" #Set bandwidth of the interface (remember, this is for OUTGOING) :local interfaceBandwidth 4M #Set where in the chain the packe...
by IntrusDave
Thu Mar 16, 2017 1:13 am
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 390
Views: 139461

Re: v6.39rc [release candidate] is released

*) ipsec - show hardware accelerated authenticated SAs; Is there any possibility that WinBox could highlight the algorithms that are hardware accelerated on each platform? You mean putting this information into winbox? https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Hardware_encryption. Couldn't hur...
by IntrusDave
Thu Mar 16, 2017 12:46 am
Forum: Announcements
Topic: v6.39rc [release candidate] is released
Replies: 390
Views: 139461

Re: v6.39rc [release candidate] is released

*) ipsec - show hardware accelerated authenticated SAs;
Is there any possibility that WinBox could highlight the algorithms that are hardware accelerated on each platform?
by IntrusDave
Wed Mar 15, 2017 9:34 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

You are correct. I will fix this.
by IntrusDave
Mon Mar 13, 2017 5:16 am
Forum: RouterBOARD hardware
Topic: CCR1072 Booting Failure , Firmware crush
Replies: 4
Views: 1443

Re: CCR1072 Booting Failure , Firmware crush

Use a serial console cable and repartition and reformat the NAND. Make sure you reinstall the latest stable release.
by IntrusDave
Thu Mar 09, 2017 7:53 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

The startup is not a permissions issue. It has to do with the interval. When the interval is 24 hours, the first run doesn't occur until 24 hours after the boot.
by IntrusDave
Thu Mar 09, 2017 4:56 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

Updated the first post and the timeout to 25 hours. The identity is never seen by anyone but me. I do have DOD clearance, so nothing to worry about.. Well, I guess that doesn't mean much now days. You are welcome to set a static name for each router in the script. The database is stored on a separat...
by IntrusDave
Thu Mar 09, 2017 4:34 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

At one point the list was updated every 48 hours, but as malware has spread faster and responses are faster, the list now expires after 24 hours. Maybe upping that to 26 hours will help some. My routers update themselves every 23 hours. The script does run from the terminal as a whole... /system scr...
by IntrusDave
Tue Mar 07, 2017 6:45 pm
Forum: Scripting
Topic: Blacklist Filter update script
Replies: 632
Views: 213678

Re: Blacklist Filter update script

DNS and BGP both complicate things dramatically. The current distribution method is very simple, stable and requires very little to setup.