Community discussions

MikroTik App

Search found 592 matches

  • 1
  • 2
by kirshteins
Mon Mar 28, 2011 9:18 am
Forum: General
Topic: bridge mac-address problem
Replies: 6
Views: 3862

Re: bridge mac-address problem

Do you have any VLAN port in bridge without MAC address?
by kirshteins
Tue Mar 22, 2011 4:16 pm
Forum: General
Topic: RB1100 freezing problem
Replies: 3
Views: 1256

Re: RB1100 freezing problem

Please send this report to support@mikrotik.com along with supout.rif file from this router http://wiki.mikrotik.com/wiki/Manual:Su ... utput_File
by kirshteins
Tue Mar 08, 2011 12:01 pm
Forum: Beginner Basics
Topic: Help Pls - Check
Replies: 4
Views: 1331

Re: Help Pls - Check

by kirshteins
Mon Mar 07, 2011 8:47 am
Forum: General
Topic: rb450 reboot problem
Replies: 50
Views: 13530

Re: rb450 reboot problem

by kirshteins
Fri Mar 04, 2011 1:23 pm
Forum: General
Topic: RB750: Log dropped packets?
Replies: 7
Views: 14165

Re: RB750: Log dropped packets?

Adding action=log increases the options. You can use custom chain if you need to log and drop different kinds of traffic. For example, add chain "log and drop" that logs and drops all traffic that is processed through it. /ip firewall filter add chain="log and drop" action=log ad...
by kirshteins
Fri Mar 04, 2011 12:49 pm
Forum: General
Topic: RB750: Log dropped packets?
Replies: 7
Views: 14165

Re: RB750: Log dropped packets?

Yes, that is correct.
by kirshteins
Fri Mar 04, 2011 12:44 pm
Forum: General
Topic: RB750: Log dropped packets?
Replies: 7
Views: 14165

Re: RB750: Log dropped packets?

Make log rule (action=log) with same conditions as drop rule and place it before the drop rule.
by kirshteins
Fri Mar 04, 2011 12:41 pm
Forum: General
Topic: v5rc10 released
Replies: 77
Views: 14419

Re: v5rc10 released

v5RC10 mipsbe: having an IP on a loopback interface (a bridge interface with no ports) router thinks it has to forward ICMP traffic to its loopback interface so it decrements the TTL once redundantly leading to a traceroute that looks like there is a route loop. Is this problem repeatable in older ...
by kirshteins
Fri Mar 04, 2011 12:27 pm
Forum: General
Topic: 5rc11?
Replies: 33
Views: 8400

Re: 5rc11?

4.17:
fixed RB1100 ether11,12,13 and RB800 ether3 resetting problem;
Is this gonna be fixed in 5rc11 as well?
Yes, it will be fixed in 5.0rc11 as well.
by kirshteins
Fri Mar 04, 2011 11:09 am
Forum: Wireless Networking
Topic: RB800 ethernet port dropping traffic
Replies: 10
Views: 1956

Re: RB800 ethernet port dropping traffic

Please generate and send supout.rif file to support@mikrotik.com together with report of this problem.
http://wiki.mikrotik.com/wiki/Manual:Su ... utput_File
by kirshteins
Fri Mar 04, 2011 10:20 am
Forum: Wireless Networking
Topic: RB800 ethernet port dropping traffic
Replies: 10
Views: 1956

Re: RB800 ethernet port dropping traffic

Please upgrade and test with latest v4.17:
What's new in 4.17 (2011-Mar-02 10:53):
*) fixed RB1100 ether11,12,13 and RB800 ether3 resetting problem;
by kirshteins
Fri Mar 04, 2011 10:06 am
Forum: Wireless Networking
Topic: RB800 ethernet port dropping traffic
Replies: 10
Views: 1956

Re: RB800 ethernet port dropping traffic

Please describe or draw network topology diagram. What RouterOS version is it? Do you have any mangle action=mark-packet rules? Is there a masquerade NAT configured on this router?
by kirshteins
Thu Mar 03, 2011 8:02 am
Forum: SwOS
Topic: SwOS on RB750G?
Replies: 1
Views: 2220

Re: SwOS on RB750G?

Unfortunately it is not possible to install SwOS on RB750G.
by kirshteins
Wed Mar 02, 2011 12:55 pm
Forum: General
Topic: rb450 reboot problem
Replies: 50
Views: 13530

Re: rb450 reboot problem (caught on video)

..It doesn't happen everytime..
How often does it happen? I manage to reproduce it roughly once out of 15 tries.
by kirshteins
Wed Mar 02, 2011 9:34 am
Forum: General
Topic: Block some sites
Replies: 1
Views: 595

Re: Block some sites

Check out this guide: http://wiki.mikrotik.com/wiki/How_to_Bl ... sing_Proxy
You can specify src-address or src-address range for each access rule.
by kirshteins
Wed Mar 02, 2011 8:07 am
Forum: Beginner Basics
Topic: Gre and TCP 1723 PPTP Connections
Replies: 7
Views: 11749

Re: Gre and TCP 1723 PPTP Connections

Test with skipping this part:
ip firewall service-port set pptp ports="1723"
by kirshteins
Tue Mar 01, 2011 4:39 pm
Forum: Beginner Basics
Topic: Gre and TCP 1723 PPTP Connections
Replies: 7
Views: 11749

Re: Gre and TCP 1723 PPTP Connections

Flag "i" shows its invalid. Unset ports and try again
/ip firewall service-port set pptp ports=""
by kirshteins
Tue Mar 01, 2011 4:30 pm
Forum: Beginner Basics
Topic: Gre and TCP 1723 PPTP Connections
Replies: 7
Views: 11749

Re: Gre and TCP 1723 PPTP Connections

Most probably NAT breaks PPTP. Make sure PPTP NAT helper is enabled
/ip firewall service-port enable pptp
by kirshteins
Tue Mar 01, 2011 1:20 pm
Forum: General
Topic: Browsing Performance Priority High
Replies: 3
Views: 2600

Re: Browsing Performance Priority High

This presentation guides you through QoS and traffic priorities using RouterOS: PDF sildes, Video
by kirshteins
Tue Mar 01, 2011 12:57 pm
Forum: General
Topic: rb450 reboot problem
Replies: 50
Views: 13530

Re: rb450 reboot problem

my configuration is very simple, i have bridge interface, pppoe server and thats all
Can you try to disable bridge/-s and PPPoE server/-s on by one and check whether you can reproduce this problem? I tested configuration you described with RB450G v4.16/2.29 and reboot is successful.
by kirshteins
Tue Mar 01, 2011 9:11 am
Forum: General
Topic: 750G switch serious speed problem
Replies: 7
Views: 2159

Re: 750G switch serious speed problem

Just to test it I turned off auto negotiation on one port of a RB750G and fixed it to 100 Mbps full duplex. The other side was a PC 1Gbps card with auto negotiation enabled. I got dramatic drop of actual data transfer speed from 70 Mbps to about 0.5 Mbps.
Please check the link about duplex mismatch.
by kirshteins
Tue Mar 01, 2011 8:23 am
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

Yeah, I found the same thing. But only mangle rules that affect ether 11-13. And it SEEMS only mangle rules that have a queue acting on them.
This problem will be fixed in next release of RouterOS v4.x and v5.x. Thank you for the input.
by kirshteins
Mon Feb 28, 2011 3:44 pm
Forum: General
Topic: rb450 reboot problem
Replies: 50
Views: 13530

Re: rb450 reboot problem

i have one rb1100 with the same problem

if i trigger a system reboot command, the routerboard never came back again. only if i took the power off and on.

no console messages.
Please send supout.rif file to support@mikrotik.com.
by kirshteins
Mon Feb 28, 2011 1:33 pm
Forum: Beginner Basics
Topic: bandwitdh management
Replies: 2
Views: 924

Re: bandwitdh management

You can use script and scheduler for this task. Please check out 2nd example at http://wiki.mikrotik.com/wiki/Manual:System/Scheduler.
by kirshteins
Mon Feb 28, 2011 12:19 pm
Forum: General
Topic: rb450 reboot problem
Replies: 50
Views: 13530

Re: rb450 reboot problem

Can anyone post console output after reboot command as requested by sergejs?
by kirshteins
Mon Feb 28, 2011 10:08 am
Forum: Beginner Basics
Topic: Routerboard 450G Problem with facebook and youtube
Replies: 6
Views: 2187

Re: Routerboard 450G Problem with facebook and youtube

I have routerboard 450g and problem with opening facebook and youtube. Its seems like a firewall blocks it. I checked options in ip- firewall sections, but I dont see any blocked url. I am beginner You can try to reset configuration /system reset-configuration and reapply necessary configuration. A...
by kirshteins
Mon Feb 28, 2011 8:21 am
Forum: General
Topic: 750G switch serious speed problem
Replies: 7
Views: 2159

Re: 750G switch serious speed problem

Is this problem actual with auto-negotiation enabled on both ends? Please make sure that this is not the case of http://en.wikipedia.org/wiki/Duplex_mismatch.
by kirshteins
Thu Feb 24, 2011 10:03 am
Forum: General
Topic: Ethernet Problem
Replies: 5
Views: 2127

Re: Ethernet Problem

by kirshteins
Thu Feb 24, 2011 8:49 am
Forum: General
Topic: rb450 reboot problem
Replies: 50
Views: 13530

Re: rb450 reboot problem

Please describe powering of those Routerboards. Can you reproduce this problem using default configuration?
by kirshteins
Tue Feb 22, 2011 8:34 am
Forum: Beginner Basics
Topic: MT as vlan switch
Replies: 15
Views: 2775

Re: MT as vlan switch

Hello. I am a beginner. Can you please explain me how to configure RouterBOARD 750 for work with vlan like this: vlan4, vlan5 ==> [ether1] [ether2] [ether3] [ether4] == vlan4 ==> computer [ether5] == vlan5 ==> another computer Please give more detailed description of your configuration. What is the...
by kirshteins
Wed Feb 16, 2011 2:16 pm
Forum: General
Topic: WOL
Replies: 7
Views: 1610

Re: WOL

It seems problem is in v3.30. WOL in v4.x, v5.x works fine.
by kirshteins
Wed Feb 16, 2011 8:15 am
Forum: The Dude
Topic: How to block HTTTPS
Replies: 2
Views: 1250

Re: How to block HTTTPS

Try /ip firewall address-list add address=66.220.144.0/20 disabled=no list=facebook_ip_addresses add address=69.63.176.0/20 disabled=no list=facebook_ip_addresses add address=204.15.20.0/22 disabled=no list=facebook_ip_addresses /ip firewall filter add action=drop chain=forward disabled=no dst-addre...
by kirshteins
Wed Feb 16, 2011 8:02 am
Forum: General
Topic: WOL
Replies: 7
Views: 1610

Re: WOL

Does the target device support this feature? Is target device on same the LAN segment?
by kirshteins
Wed Feb 16, 2011 7:59 am
Forum: General
Topic: New switch feature bridge with fancy name?
Replies: 6
Views: 1912

Re: New switch feature bridge with fancy name?

I have this question as well.... it seems I lose visibility on the ports when I bridge. I have no graphs any more to show how much traffic is going through them. Is there a work around for this? Please clarify whether you use bridging or switching. It is normal that only master-port of a switching ...
by kirshteins
Tue Feb 15, 2011 3:47 pm
Forum: General
Topic: RB 493ah 10Meg Rates
Replies: 1
Views: 765

Re: RB 493ah 10Meg Rates

How long cable are you using? Does 10M device support auto-negotiation and full-duplex transmission?
by kirshteins
Tue Feb 15, 2011 3:41 pm
Forum: RouterBOARD hardware
Topic: RB750G "switch-all-port=no" does not work?
Replies: 1
Views: 849

Re: RB750G "switch-all-port=no" does not work?

Only RB450G supports switch-all-port=yes/no feature.
by kirshteins
Tue Feb 15, 2011 3:27 pm
Forum: Beginner Basics
Topic: lan access
Replies: 9
Views: 1618

Re: lan access

by kirshteins
Tue Feb 15, 2011 10:18 am
Forum: RouterBOARD hardware
Topic: RB1100: Port speed problem with Motorola BSR100 on Ether4
Replies: 2
Views: 993

Re: RB1100: Port speed problem with Motorola BSR100 on Ether

What type and how long cable are you using? Is it 10Mbps full or half duplex?
by kirshteins
Mon Feb 14, 2011 4:08 pm
Forum: General
Topic: Arping problem
Replies: 4
Views: 1922

Re: Arping problem

This bug will be fixed. Thanks.
by kirshteins
Mon Feb 14, 2011 12:05 pm
Forum: General
Topic: disable web interface
Replies: 10
Views: 49376

Re: disable web interface

Chain=output will only affect traffic issued from the router, not a traffic going through the router.
by kirshteins
Mon Feb 14, 2011 7:56 am
Forum: General
Topic: how to block https://www.facebook.com
Replies: 23
Views: 36709

Re: how to block https://www.facebook.com

Try blocking 443/TCP to the
  • 66.220.144.0-66.220.159.255
    69.63.176.0-69.63.191.255
    204.15.20.0-204.15.23.255
IP addresses
Have you tested?
by kirshteins
Fri Feb 11, 2011 9:18 am
Forum: General
Topic: RB1100 crashing/freeze when disconnecting cable from ether13
Replies: 11
Views: 2755

Re: RB1100 crashing/freeze when disconnecting cable from eth

Problem with RB1100 crashing/freeze after link down on ether11-ether13 is fixed in v5.0rc9. Please upgrade.
by kirshteins
Wed Feb 09, 2011 3:55 pm
Forum: Wireless Networking
Topic: WDS problem?
Replies: 11
Views: 2220

Re: WDS problem?

Not exactly "routed". WDS works similar as network of interconnected ethernet switches - host table is used to determine egress ports and RSTP can block ports (according to its topology) to prevent switch loops.
by kirshteins
Wed Feb 09, 2011 3:06 pm
Forum: Wireless Networking
Topic: WDS problem?
Replies: 11
Views: 2220

Re: WDS problem?

The purpose of WDS is to interconnect APs without a need of a additional backbone. "all packets to all interfaces" can cause serious bridge loops when packets are broadcast. Spanning tree protocol is there to prevent them.
by kirshteins
Wed Feb 09, 2011 2:14 pm
Forum: Wireless Networking
Topic: WDS problem?
Replies: 11
Views: 2220

Re: WDS problem?

Try setting protocol-mode=rstp on WDS bridges if it is not already set.
by kirshteins
Wed Feb 09, 2011 12:34 pm
Forum: General
Topic: how to block https://www.facebook.com
Replies: 23
Views: 36709

Re: how to block https://www.facebook.com

Try blocking 443/TCP to the
  • 66.220.144.0-66.220.159.255
    69.63.176.0-69.63.191.255
    204.15.20.0-204.15.23.255
IP addresses
by kirshteins
Tue Feb 08, 2011 3:26 pm
Forum: General
Topic: 5.0RC5 Ethernet ports flapping on two different RB-750s
Replies: 31
Views: 12603

Re: 5.0RC5 Ethernet ports flapping on two different RB-750s

Thank you very much for your reports. This bug will be fixed in next release of RouterOS.
by kirshteins
Mon Feb 07, 2011 2:12 pm
Forum: General
Topic: How to configure RSTP between Mikrotik and CISCO
Replies: 1
Views: 5032

Re: How to configure RSTP between Mikrotik and CISCO

Unfortunately current RouterOS RSTP implementation is not compatible with MSTP.
by kirshteins
Fri Feb 04, 2011 1:17 pm
Forum: General
Topic: Mikrotik RSTP + Cisco RSTP bridges problem, is it possible ?
Replies: 3
Views: 2159

Re: Mikrotik RSTP + Cisco RSTP bridges problem, is it possib

Are VLAN interfaces put on bridge interfaces or are they one of the bridge ports? Have you tested without any VLAN configuration on Routerbords?
by kirshteins
Tue Feb 01, 2011 10:34 am
Forum: RouterBOARD hardware
Topic: RB493G Switches and Bridging
Replies: 3
Views: 1978

Re: RB493G Switches and Bridging

1. I assume that traffic coming in on one of those ports and bound for a host on another of that switch's ports doesn't go all the way up to the bridge, it just goes through the switch and out the correct port, and won't impact the system CPU performance, is this correct? No, bridged traffic will m...
by kirshteins
Fri Jan 28, 2011 8:23 am
Forum: General
Topic: WOL
Replies: 7
Views: 1610

Re: WOL

Routerboards do not have support to be WOL destination devices.
by kirshteins
Thu Jan 27, 2011 10:09 am
Forum: General
Topic: ip address conflict still on after setting ARP static
Replies: 5
Views: 1983

Re: ip address conflict still on after setting ARP static

Do you have arp=disabled on that interface clients connect to?
by kirshteins
Thu Jan 27, 2011 8:33 am
Forum: General
Topic: Double Bridge
Replies: 5
Views: 1294

Re: Double Bridge

That, most probably, is the cause of two bridge buttons appearing.
by kirshteins
Wed Jan 26, 2011 11:12 am
Forum: General
Topic: How create VLAN with mikrotik and linksys srw2024 switch?
Replies: 16
Views: 5197

Re: How create VLAN with mikrotik and linksys srw2024 switch

mikrotik vlans are competibale with linksys or cisco?
Yes, compatible with IEEE 802.1Q
by kirshteins
Wed Jan 26, 2011 11:04 am
Forum: General
Topic: Double Bridge
Replies: 5
Views: 1294

Re: Double Bridge

Do you have stpbridge-legacy-3.30.npk package installed?
by kirshteins
Fri Jan 21, 2011 12:16 pm
Forum: General
Topic: Hairpin NAT not working
Replies: 5
Views: 3994

Re: Hairpin NAT not working

add action=dst-nat chain=dstnat comment="HTTP Server" disabled=no \ dst-address=83.141.117.106 dst-port=80 in-interface="IBB DSL WAN" \ protocol=tcp to-addresses=172.29.1.11 to-ports=80 It seems in-interface="IBB DSL WAN" is causing this problem. Http requests from LAN...
by kirshteins
Fri Jan 21, 2011 11:26 am
Forum: General
Topic: Hairpin NAT not working
Replies: 5
Views: 3994

Re: Hairpin NAT not working

Try setting:
/interface bridge settings set use-ip-firewall=yes
by kirshteins
Wed Jan 19, 2011 3:04 pm
Forum: RouterBOARD hardware
Topic: rb750 rx error
Replies: 5
Views: 3047

Re: rb750 rx error

What type and how much traffic is going through? What devices are connected to each interface? Are you using standard 12V/0.5A power supply? Also, please, send supout.rif file to support@mikrotik.com
by kirshteins
Wed Jan 19, 2011 9:30 am
Forum: General
Topic: RB450G Link Lights
Replies: 1
Views: 1144

Re: RB450G Link Lights

Yes, green light shows that link speed is 1Gbps. Only orange light glowing means link speed is 10/100Mbps. Orange light shows network activity.
by kirshteins
Tue Jan 18, 2011 1:59 pm
Forum: Beginner Basics
Topic: Master Port Problem on RB750
Replies: 6
Views: 2364

Re: Master Port Problem on RB750

Hello, I wonder if all 5 ports are equally configurable on a RB750? I have a feeling that ether5 has some problems (5.0rc7) as PPPoE is configurable but does not work as well as ether5 can not act as local master nor as a DHCP server port. The same configuration on ether3 works perfect. Regards, Z ...
by kirshteins
Mon Jan 17, 2011 12:57 pm
Forum: Beginner Basics
Topic: Master Port Problem on RB750
Replies: 6
Views: 2364

Re: Master Port Problem on RB750

Only ether2-ether5 can be switched on RB750.
by kirshteins
Fri Jan 14, 2011 1:27 pm
Forum: General
Topic: Arping problem
Replies: 4
Views: 1922

Re: Arping problem

Specifying an interface is a must for ARP-ping.
by kirshteins
Thu Jan 13, 2011 11:07 am
Forum: RouterBOARD hardware
Topic: 493g
Replies: 2
Views: 1085

Re: 493g

Yes, all RB493G ethernet interfaces can be used as standalone ports. What exactly is not working with all interfaces except ether2 and ether6? Are speed/act LEDs glowing?
by kirshteins
Mon Jan 10, 2011 10:48 am
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

Re: SwOS version 1.4 released!

To clarify you need to select FW file and press upgrade to downgrade. Have you tested with another PC?
by kirshteins
Mon Jan 10, 2011 9:42 am
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

Re: SwOS version 1.4 released!

What exactly happens when you try to reboot switch? What is your network topology between switch and management device? Reboot is working perfectly fine for me.
by kirshteins
Fri Jan 07, 2011 3:00 pm
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

Re: SwOS version 1.4 released!

This is v1.2 problem not v1.4 problem. Try upgrading from different PC/OS/browser.
by kirshteins
Thu Jan 06, 2011 2:07 pm
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

Re: SwOS version 1.4 released!

Is it possible for SwOS to be easily modified for the next release so that we would access the web interface regardless of vlan tags and vlan settings? :) We will check what can be done about it. I agree than it can be very confusing when VLAN Header "add if missing" or "always strip...
by kirshteins
Thu Jan 06, 2011 2:04 pm
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

Re: SwOS version 1.4 released!

If you specify Allow From VLAN make sure VLAN Mode is not disabled on ingress port. Then you should be able to connect to port2 or port3 using VLAN 16 tag.
by kirshteins
Thu Jan 06, 2011 1:05 pm
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

Re: SwOS version 1.4 released!

Port4 removes VLAN header on egress. That is why you cannot connect with VLAN tagged frames.
by kirshteins
Thu Jan 06, 2011 11:17 am
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

Re: SwOS version 1.4 released!

need your assistance please.... to be able to remotely access the SWos
Which port are you trying to access through? Make sure IP address you are trying to connect from is in Allow From range.
by kirshteins
Wed Jan 05, 2011 10:06 am
Forum: SwOS
Topic: SwOS version 1.4 released!
Replies: 21
Views: 8144

SwOS version 1.4 released!

What's new in 1.4:

*) added ability to limit access by VLAN;
*) added ability to disable Mikrotik Discovery Protocol;
*) fixed problem - connecting to SwOS over VLAN did not work;
*) fixed problem - switch sometimes stopped responding;
http://www.mikrotik.com/download.html
by kirshteins
Tue Jan 04, 2011 9:59 am
Forum: General
Topic: Bridge Filter problem
Replies: 9
Views: 3191

Re: Bridge Filter problem

After loosing hundred hairs, I made it work, but not like I was doing it, instead of doing normal ip/firewall/filter bridge rules I did the same filtering but matching the traffic with mangle, I use mangle rules with the in-bridge-port/out-bridge-port option. Can somebody explain this? why is not w...
by kirshteins
Mon Jan 03, 2011 8:46 am
Forum: SwOS
Topic: troubleshooting with VLAN and port trunk
Replies: 14
Views: 7873

Re: troubleshooting with VLAN and port trunk

It means when a eth frame comes in port x , when it gets out port y it should have a vlan tag added. X is "access" port and y us a "trunk" port. Set Default VLAN ID for port x and VLAN Header = add if missing for port y. Set VLAN Mode = strict for both ports and add entry in VLA...
by kirshteins
Mon Jan 03, 2011 8:16 am
Forum: RouterBOARD hardware
Topic: RB450G Gigabit problem
Replies: 11
Views: 7732

Re: RB459G Gigabit problem

Are all 450G ethernet interfaces affected? Have you tested with multiple cables?
by kirshteins
Fri Dec 17, 2010 2:58 pm
Forum: RouterBOARD hardware
Topic: Autonegotiation failure after ROS upgrade
Replies: 7
Views: 2310

Re: Autonegotiation failure after ROS upgrade

What power supply are you using?
by kirshteins
Mon Dec 13, 2010 4:07 pm
Forum: SwOS
Topic: Feature request
Replies: 12
Views: 6988

Re: Feature request

SwOS does not make any IP routing decisions as there is no need for it (as SwOS does not run programs like ping-to or ssh-client etc.). 250GS still should be accessible behind VPN.
by kirshteins
Fri Dec 10, 2010 3:41 pm
Forum: SwOS
Topic: SwOS version 1.3 released!
Replies: 16
Views: 6493

Re: SwOS version 1.3 released!

Please post your TFTP and DHCP-server configuration if possible.
by kirshteins
Fri Dec 10, 2010 10:40 am
Forum: SwOS
Topic: SwOS version 1.3 released!
Replies: 16
Views: 6493

Re: SwOS version 1.3 released!

Make sure you allow this file to be downloadable in TFTP configuration.
by kirshteins
Thu Dec 09, 2010 10:46 am
Forum: SwOS
Topic: Block bad ARP request
Replies: 3
Views: 6783

Re: Block bad ARP request

Unfortunately, yes, this rule blocks all ARP traffic from the device. 250GS hardware does not support more advanced ARP matching features.
by kirshteins
Wed Dec 08, 2010 9:32 am
Forum: SwOS
Topic: SwOS version 1.3 released!
Replies: 16
Views: 6493

Re: SwOS version 1.3 released!

What is status of ACL LED? It should start blinking few seconds after power up, if reset button is pressed. Configuration will be reset if you release reset at this point. Otherwise (after 10 seconds of ACT blinking) it will start to blink twice as frequent and switch will try to boot using BOOTP. h...
by kirshteins
Wed Dec 08, 2010 9:08 am
Forum: SwOS
Topic: SwOS version 1.3 released!
Replies: 16
Views: 6493

Re: SwOS version 1.3 released!

Both reset-button and reset-hole are intended to work at the moment when board is being powered up. It works the same way with all Routerboards.
by kirshteins
Wed Dec 08, 2010 8:15 am
Forum: General
Topic: RB750G switch mode, want to see live traffic in Winbox
Replies: 2
Views: 1258

Re: RB750G switch mode, want to see live traffic in Winbox

You can access this data by using the terminal
/interface ethernet print stats interval=1s
by kirshteins
Tue Dec 07, 2010 3:29 pm
Forum: General
Topic: RouterOS v5.0 RC5
Replies: 41
Views: 11444

Re: RouterOS v5.0 RC5

The native bridge filter don't works, just the firewall ones if ticked "Use Ip Firewall". Just tested in x86 here.
What bridge filter rules are not working for you? I cannot reproduce any problems on Routerboards or x86.
by kirshteins
Thu Dec 02, 2010 11:15 am
Forum: SwOS
Topic: what's wrong with upload speed limiting?
Replies: 4
Views: 4653

Re: what's wrong with upload speed limiting?

SwOS will simply drop everything that exceed bandwidth limit on ingress port significantly decreasing TCP speed. It is recommend to limit speed on egress ports.
by kirshteins
Thu Dec 02, 2010 9:36 am
Forum: SwOS
Topic: SwOS version 1.3 released!
Replies: 16
Views: 6493

SwOS version 1.3 released!

What's new in 1.3: *) added ability to specify ethernet ports from which it is allowed to connect to the switch; *) fixed problem - reboot sometimes made switch unresponsive; *) fixed problem - Hosts table were not shown sometimes; *) fixed problem - sometimes it didn't respond to ARP requests or re...
by kirshteins
Wed Dec 01, 2010 4:19 pm
Forum: SwOS
Topic: Some connection trouble with RB250
Replies: 4
Views: 3151

Re: Some connection trouble with RB250

What SwOS version are you using? Are all ports affected?
by kirshteins
Tue Nov 30, 2010 10:55 am
Forum: RouterBOARD hardware
Topic: Problems with RB411U
Replies: 4
Views: 2340

Re: Problems with RB411U

So only one LED works (the one on the left)? is this hardware or software made?
Orange LED works the same way as green one, but for 10Mpbs links.
by kirshteins
Tue Nov 30, 2010 10:22 am
Forum: SwOS
Topic: Firmware 1.2 - Switch MAC dont work in ACL!
Replies: 2
Views: 3250

Re: Firmware 1.2 - Switch MAC dont work in ACL!

The behavior of ACL has been changed in v1.2 - ACL are no longer affecting traffic going-to or coming-from the CPU of the switch. It is best to use Allow From feature in System tab to restrict access to the switch. Sorry for inconvenience it might caused.
by kirshteins
Tue Nov 30, 2010 10:16 am
Forum: SwOS
Topic: Block bad ARP request
Replies: 3
Views: 6783

Re: Block bad ARP request

Try filtering by Ethertype:0x0806 and Src. MAC.
by kirshteins
Fri Nov 26, 2010 10:58 am
Forum: General
Topic: VLAN trunk
Replies: 11
Views: 3879

Re: VLAN trunk

VLAN setting under switch section is to manage VLANs going through switch chip, while standard VLAN interface manages VLANs going through CPU.
by kirshteins
Thu Nov 25, 2010 1:23 pm
Forum: SwOS
Topic: VLAN Trunk over two RB250GS?
Replies: 2
Views: 4799

Re: VLAN Trunk over two RB250GS?

Yes, this scenario should work without any problems. On 1st switch make sure you have entries in VLAN table with ether1,ether5 for each VLAN-ID and port5 set VLAN header = leave as is. There are no need for adjustments on 2nd switch.
by kirshteins
Tue Nov 23, 2010 2:49 pm
Forum: General
Topic: RB450G rebooted
Replies: 2
Views: 576

Re: RB450G rebooted

It is best to send this report to support@mikrotik.com along with supout.rif file.

http://wiki.mikrotik.com/wiki/Manual:Su ... utput_File
by kirshteins
Wed Nov 17, 2010 2:50 pm
Forum: General
Topic: how to switch all port on rb493.
Replies: 13
Views: 4053

Re: how to switch all port on rb493.

Only ether2-ether5 can be switched together on RB750.
by kirshteins
Mon Nov 15, 2010 8:53 am
Forum: SwOS
Topic: SwOS 1.2 not reporting SNMP correctly
Replies: 11
Views: 8448

Re: SwOS 1.2 not reporting SNMP correctly

I cannot reproduce this problem. What is your SNMP configuration on 250GS?
by kirshteins
Wed Nov 10, 2010 12:20 pm
Forum: SwOS
Topic: RB 250GS proper ground
Replies: 3
Views: 2796

Re: RB 250GS proper ground

It is an indoor switch and it is not meant to be grounded. Try grounding via one of the mounting holes, if you want to use it outdoors.
by kirshteins
Thu Nov 04, 2010 3:59 pm
Forum: SwOS
Topic: MTU on RB250GS?
Replies: 8
Views: 7765

Re: MTU on RB250GS?

Because ethernet header (14 bytes) + two VLAN tags (2*4=8 bytes) + 1500 payload exceeds 1518 bytes and gets dropped.
by kirshteins
Thu Nov 04, 2010 9:54 am
Forum: SwOS
Topic: MTU on RB250GS?
Replies: 8
Views: 7765

Re: MTU on RB250GS?

250GS can forward jumbo frames, but its CPU cannot receive ethernet frames bigger than 1518 bytes. Ethernet frame size is 1522 bytes, if you use double-tagging and 1500 bytes of IP load. Is that a normal standard or just a MT implementation behavior? IEEE 802 packets may have a minimum size restrict...
by kirshteins
Wed Nov 03, 2010 11:14 am
Forum: Beginner Basics
Topic: Simple Bridge
Replies: 2
Views: 998

Re: Simple Bridge

Which ports are you PCs connected to? Also, please, post your bridge configuration.
/interface bridge export
by kirshteins
Mon Nov 01, 2010 1:59 pm
Forum: SwOS
Topic: MTU on RB250GS?
Replies: 8
Views: 7765

Re: MTU on RB250GS?

SwOS v1.2 supports up to 9000 byte frames, so there should not be any problems.
by kirshteins
Tue Oct 19, 2010 9:14 am
Forum: SwOS
Topic: troubleshooting with VLAN and port trunk
Replies: 14
Views: 7873

Re: troubleshooting with VLAN and port trunk

Try the following configuration:
swos.png
by kirshteins
Wed Oct 13, 2010 8:46 am
Forum: General
Topic: Switch group problem on v3.30
Replies: 5
Views: 3238

Re: Switch group problem on v3.30

Switches 0 and 1 are physically separated, so you cannot make single port switching group. However you can bridge master ports of both switch groups.
by kirshteins
Fri Oct 08, 2010 12:37 pm
Forum: RouterBOARD hardware
Topic: AR8316 Switch Chip and CPU Speed for RB450G
Replies: 1
Views: 2274

Re: AR8316 Switch Chip and CPU Speed for RB450G

It is 1Gbps speed between CPU and and four ports of AR8316, while fifth port is optional to share this 1Gbps with other ports or to give up its ability to be switched with other ports for standalone 1Gbps speed to CPU.
http://wiki.mikrotik.com/wiki/Switch_Ch ... _Switching
by kirshteins
Fri Oct 08, 2010 8:40 am
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

Can anyone test whether link drops occur by entering RouterBOOT setup and testing from that point?
by kirshteins
Fri Oct 01, 2010 2:56 pm
Forum: SwOS
Topic: Dumb question?
Replies: 4
Views: 3424

Re: Dumb question?

For example, 32k f/s means that this port will not forward more than 32'000 broadcast frames per second. Unicast option means whether unicast frames without MAC address entry in host table will be treated as broadcast frames.
by kirshteins
Thu Sep 30, 2010 3:22 pm
Forum: General
Topic: Why do we come here ?
Replies: 10
Views: 2456

Re: Why do we come here ?

Does anyone have a clue what is going on ?
Perhaps it is because of loneliness... as wives don't want to talk about routers :)
by kirshteins
Thu Sep 30, 2010 3:11 pm
Forum: General
Topic: RB750G switch and monitoring
Replies: 3
Views: 1384

Re: RB750G switch and monitoring

You can get stats from switch chip itself: /interface ethernet print interval=1s stats where name="ether1" name: "ether1" rx-broadcast: 675948 rx-pause: 0 rx-multicast: 70697 rx-fcs-error: 0 rx-align-error: 0 rx-runt: 0 rx-fragment: 0 rx-64: 519755 rx-65-127: 220824 rx-128-255: 9...
by kirshteins
Thu Sep 30, 2010 9:45 am
Forum: General
Topic: Backup restore
Replies: 10
Views: 10808

Re: Backup restore

It is strongly recommended to load backup only to the same model router it was taken from. You can follow Martín' s advice and edit export file. Or you can simply export only configuration that you need, for example, /ip firewall export ; /ip dns export ; /ip address export etc. Then merge it into o...
by kirshteins
Tue Sep 28, 2010 8:25 am
Forum: SwOS
Topic: Dumb question?
Replies: 4
Views: 3424

Re: Dumb question?

http://wiki.mikrotik.com/wiki/SwOS#Forw ... uote]Storm Rate - Limit the number of broadcast packets transmitted by an interface
Include Unicast - Include unicast packets without an entry in host table in Storm Rate limitation[/quote]
by kirshteins
Mon Sep 27, 2010 2:50 pm
Forum: SwOS
Topic: Pings TO the switch dropped, high ping...
Replies: 4
Views: 5199

Re: Pings TO the switch dropped, high ping...

Seems like SwOS have some problems with ARP replies. You can add static ARP entries for your switches on the Dude server to confirm.
by kirshteins
Mon Sep 27, 2010 11:02 am
Forum: General
Topic: RouterOS v5 RC1
Replies: 82
Views: 25778

Re: RouterOS v5 RC1

wildbill442, what device is connected to ether13 when these problems occur?
by kirshteins
Thu Sep 23, 2010 4:09 pm
Forum: SwOS
Topic: Netwatch failures
Replies: 4
Views: 3176

Re: Netwatch failures

Try adding static ARP entries on RB450G for both RB250G.
by kirshteins
Wed Sep 22, 2010 4:19 pm
Forum: General
Topic: squid
Replies: 9
Views: 2103

Re: squid

Try to add following rule before the other destination NAT rule. Check whether it helps.
/ip firewall nat
add action=accept chain=dstnat dst-port=80 protocol=tcp src-address=172.18.1.2 
by kirshteins
Mon Sep 20, 2010 8:16 am
Forum: General
Topic: Password recovery
Replies: 1
Views: 2151

Re: Password recovery

It is impossible to recover it, but you can reset it by:
http://wiki.mikrotik.com/wiki/Manual:Password_reset
or
http://wiki.mikrotik.com/wiki/Netinstall
by kirshteins
Mon Sep 20, 2010 8:08 am
Forum: Beginner Basics
Topic: RB750 Cant connect winbox or telnet to Eth1 Port
Replies: 6
Views: 8137

Re: RB750 Cant connect winbox or telnet to Eth1 Port

Yes, the other rule
filter add chain=input action=accept protocol=icmp comment="default config
uration"
accepts ICMP packets. This is why you could ping the interface.
by kirshteins
Fri Sep 17, 2010 9:41 am
Forum: General
Topic: how to switch all port on rb493.
Replies: 13
Views: 4053

Re: how to switch all port on rb493.

Only ether2-ether9 can be switched together on RB493. To use ether2 as master-port for all ports use the following command:
/interface ethernet set ether3,ether4,ether5,ether6,ether7,ether8,ether9 master-port=ether2
by kirshteins
Thu Sep 16, 2010 12:47 pm
Forum: SwOS
Topic: Netwatch failures
Replies: 4
Views: 3176

Re: Netwatch failures

Is there any NAT configured in this setup?
by kirshteins
Thu Sep 16, 2010 10:12 am
Forum: Beginner Basics
Topic: RB750 Cant connect winbox or telnet to Eth1 Port
Replies: 6
Views: 8137

Re: RB750 Cant connect winbox or telnet to Eth1 Port

Most input on ether1 is blocked by default on RB750. There are default firewall filter rules, that will accept pings, but will drop other services. you can try to disable them. /ip firewall filter add chain=input action=accept protocol=icmp comment="default config uration" filter add chain...
by kirshteins
Thu Sep 16, 2010 9:34 am
Forum: Beginner Basics
Topic: I have no idea what to do.
Replies: 4
Views: 1204

Re: I have no idea what to do.

No, it will work on all RouterOS versions.
by kirshteins
Wed Sep 15, 2010 1:24 pm
Forum: SwOS
Topic: SwOS Web interface error
Replies: 20
Views: 12374

Re: SwOS Web interface error

Does this problem occur when using any other web browser than Firefox 3.6.9?
by kirshteins
Wed Sep 15, 2010 8:13 am
Forum: Beginner Basics
Topic: Allowing traffic between ports on a RB750
Replies: 3
Views: 1020

Re: Allowing traffic between ports on a RB750

Please clarify your problem and what are you trying to achieve.
by kirshteins
Tue Sep 14, 2010 12:18 pm
Forum: SwOS
Topic: Byte counts for each port under "Statistics" will be reset ?
Replies: 2
Views: 2034

Re: Byte counts for each port under "Statistics" will be res

Each counter will reset at 2^32=4294967296.
by kirshteins
Mon Sep 13, 2010 8:45 am
Forum: SwOS
Topic: SwOS Web interface error
Replies: 20
Views: 12374

Re: SwOS Web interface error

Is host table contents displayed properly? When this error occurs, please, save it as "Web Page, complete" and send those files to support@mikrotik.com
by kirshteins
Fri Sep 10, 2010 3:50 pm
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

All 3 (11-13) trouble making ports are connected with a couple of Cisco L3 2948G switches. The only way that worked without giving me trouble was with auto negotiation off at 100/FDX. I will be submitting the supout file soon. We tested multiple RB1100 with Cisco L3 2948G and did not experience any...
by kirshteins
Fri Sep 10, 2010 3:41 pm
Forum: SwOS
Topic: Locked out of Switch
Replies: 3
Views: 2713

Re: Locked out of Switch

"upgrading do not interrupt"
Simply power cycle switch if you are running SwOS 1.0 and see this message.
The download file is only 37 kbytes - is this correct
Yes, it is very lightweight OS.
by kirshteins
Fri Sep 10, 2010 3:08 pm
Forum: SwOS
Topic: Locked out of Switch
Replies: 3
Views: 2713

Re: Locked out of Switch

What version are you running? You can try alternative method to reset switch - take it out of the case and close reset hole with metal object while powering up the board. In a similar way like http://wiki.mikrotik.com/wiki/File:Passw.jpg
by kirshteins
Tue Sep 07, 2010 2:26 pm
Forum: SwOS
Topic: Vlan Trunk / Access port configuration
Replies: 3
Views: 10661

Re: Vlan Trunk / Access port configuration

Set VLAN Header = add if missing for port5. Everything else looks fine.
by kirshteins
Mon Sep 06, 2010 9:00 am
Forum: Beginner Basics
Topic: I need help
Replies: 1
Views: 639

Re: I need help

You do not have any IP address or DHCP server configured on LAN2 interface. You can bridge LAN and LAN2 together to use same IP address and DHCP server for both interfaces: http://wiki.mikrotik.com/wiki/Bridge
by kirshteins
Mon Sep 06, 2010 8:42 am
Forum: SwOS
Topic: I tried the RB250GS...
Replies: 2
Views: 3349

Re: I tried the RB250GS...

I can't figure out how to limit management access to a port or vlan. http://forum.mikrotik.com/viewtopic.php?p=225658#p225658 Why can't the config file saved be more like a RouterOS config? Please clarify what problems do you have with current configuration backup system? A Mac based telnet login f...
by kirshteins
Mon Sep 06, 2010 8:31 am
Forum: SwOS
Topic: VLANs...
Replies: 6
Views: 5999

Re: VLANs...

Yes, it is possible to drop, for example, VLAN ID=100 packets that are not entering switch through port1 etc. using ACL rules.
by kirshteins
Thu Sep 02, 2010 4:11 pm
Forum: SwOS
Topic: VLANs...
Replies: 6
Views: 5999

Re: VLANs...

Set VLAN Mode = strict for all ports and VLAN Header = add if missing for Port1. I expect users on port 2 and 3 wont be able to access management. Set password to deny management access for users. Also, it seems that ip address can have only /24 mask (why?). RB250GS will not do any routing. SwOS use...
by kirshteins
Tue Aug 31, 2010 9:42 am
Forum: General
Topic: Port Forwarding Issue
Replies: 5
Views: 1117

Re: Port Forwarding Issue

If you do not assign any port then default value: all ports (0-65535) is used. What kind of traffic do you need to forward (UDP, TCP, all traffic)? Please post forwarding NAT rules that stop working and how you determine that they stopped working.
by kirshteins
Tue Aug 31, 2010 9:04 am
Forum: Beginner Basics
Topic: PORT SWITCH IP ASSINGMENT
Replies: 5
Views: 1301

Re: PORT SWITCH IP ASSINGMENT

There should not be any difference between assigning IP address to master or slave port. IP addresses assigned to slave port should work for all switch group ports just as it was assigned to master port. Did you lost connection permanently or just for a few seconds?
by kirshteins
Fri Aug 27, 2010 1:17 pm
Forum: RouterBOARD hardware
Topic: Strange RB800 Problem
Replies: 2
Views: 1078

Re: Strange RB800 Problem

This problem has been fixed in latest version 4.11.
by kirshteins
Fri Aug 27, 2010 8:47 am
Forum: SwOS
Topic: QnQ
Replies: 6
Views: 8874

Re: QnQ

Currently it is not supported. But this feature might be implemented in the future.
by kirshteins
Thu Aug 26, 2010 3:46 pm
Forum: SwOS
Topic: SwOS version 1.2 released!
Replies: 41
Views: 21889

Re: SwOS version 1.2 released!

Please describe your network topology, configuration, how much and what type of traffic is being forwarded through switch when you experience latency issues. We were not able to reproduce any problems with SNMP (tested with Dude v3.6 and v4.0beta2).
by kirshteins
Thu Aug 26, 2010 8:31 am
Forum: SwOS
Topic: SwOS version 1.2 released!
Replies: 41
Views: 21889

Re: SwOS version 1.2 released!

I confirm the issue with the Reboot button. I'm connected over vlan1 from my PC. When I press Reboot the webserver in the switch just dies off silently. The switch itself keeps on forwarding the traffic and not a single packet is lost. If I try to telnet 192.168.88.1 port 80 there is no ARP reply. ...
by kirshteins
Tue Aug 24, 2010 3:22 pm
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

Have anyone tried to reinstall problematic RB1100 using Netinstall and reproduce this problem with default configuration?
by kirshteins
Wed Aug 18, 2010 3:57 pm
Forum: SwOS
Topic: I’m too stupid for SwOS
Replies: 8
Views: 6858

Re: I’m too stupid for SwOS

The tagged traffic against the internal IP number of the switch (vlan1 on PC to vlan1 on the switch) doesn't work well.
What type and size are those packets? 250GS can forward jumbo frames, but cannot receive one itself. Also 250GS can forward packet fragments, but will not fragment itself.
by kirshteins
Mon Aug 16, 2010 8:36 am
Forum: RouterBOARD hardware
Topic: RB411AH Ethernet Orange Light Out
Replies: 1
Views: 1545

Re: RB411AH Ethernet Orange Light Out

This behavior is normal for newest revisions of RB411. Green light will indicate 100Mbps link, while orange 10Mbps link.
by kirshteins
Fri Aug 13, 2010 10:06 am
Forum: SwOS
Topic: SwOS version 1.2 released!
Replies: 41
Views: 21889

Re: SwOS version 1.2 released!

Do you have problems with increased latency and ping timeouts when you ping to or through switch? Are there any transmission errors reported in statistics tab?
by kirshteins
Wed Aug 11, 2010 8:58 am
Forum: SwOS
Topic: SwOS version 1.2 released!
Replies: 41
Views: 21889

Re: SwOS version 1.2 released!

Eben, if you are running v1.1 there should not be any problems upgrading remotely.
by kirshteins
Wed Aug 11, 2010 8:24 am
Forum: SwOS
Topic: Upgrading
Replies: 2
Views: 2366

Re: Upgrading

If you are running v1.0 you will need to upload v1.2 firmware, press upgrade button and manually power cycle your board. If you are running v1.1 reboot part will be done automatically after upgrade.
by kirshteins
Tue Aug 10, 2010 3:54 pm
Forum: SwOS
Topic: SwOS version 1.2 released!
Replies: 41
Views: 21889

SwOS version 1.2 released!

What's new in 1.2: *) fixed problem - reset configuration & reboot did not work; *) fixed problem - VLAN header present/not present matcher did not work in ACL; *) fixed problem - could not match all packets in ACL; *) fixed problem - deleting one ACL entry did not have immediate effect; *) fixe...
by kirshteins
Tue Aug 10, 2010 1:49 pm
Forum: SwOS
Topic: SwOS 1.1 Vlans and too long packets problem
Replies: 1
Views: 2482

Re: SwOS 1.1 Vlans and too long packets problem

Please upgrade to SwOS v1.2.
by kirshteins
Mon Aug 09, 2010 3:44 pm
Forum: Scripting
Topic: backup script for newbie
Replies: 9
Views: 4607

Re: backup script for newbie

Check policies of your script. Perhaps backup file is not fully generated before the attempt to send it. Try to add short delay in between generating backup and sending the file. /system backup save name=([/system identity get name]); /delay delay-time=5s ; /tool e-mail send to= "me@me.com"...
by kirshteins
Mon Aug 09, 2010 8:52 am
Forum: Beginner Basics
Topic: problems by redirecting ports on mikrotik
Replies: 1
Views: 766

Re: problems by redirecting ports on mikrotik

You have to enable WEB proxy, assign parent-proxy (IP address of your Squid server) and parent-proxy-port (if necessary) to make it transparent. More information:

http://wiki.mikrotik.com/wiki/Manual:IP/Proxy
by kirshteins
Thu Aug 05, 2010 1:23 pm
Forum: SwOS
Topic: 250GS Hosts issue
Replies: 3
Views: 2884

Re: 250GS Hosts issue

Both RB450G and RB250GS have Atheros8316 switch chip which supports 2k host table entries. Do this problem occurs when click any other tab apart from hosts? Perhaps you can describe what type of monitoring system you have.
by kirshteins
Wed Aug 04, 2010 4:24 pm
Forum: General
Topic: RouterOS 5 beta 5
Replies: 22
Views: 8989

Re: RouterOS 5 beta 5

Incorrect status of the interfaces: all interfaces are "running" even if nothing connected.
That is normal for x86 as disable-running-check=yes is set by default.
by kirshteins
Wed Aug 04, 2010 2:59 pm
Forum: RouterBOARD hardware
Topic: RB411 Ethernet Freezes (No receive)
Replies: 75
Views: 31664

Re: RB411 Ethernet Freezes (No receive)

If you experience problem where RouterOS reports link as running, but traffic cannot be received, try to unplug Ethernet cable. If Link/Act and 10/100 LEDs are still on then there are problems with Ethernet PHY.
by kirshteins
Wed Aug 04, 2010 10:38 am
Forum: General
Topic: Critical Logins
Replies: 4
Views: 1684

Re: Critical Logins

Changing SSH port worked best for me.
/ip service set ssh port=2222
by kirshteins
Fri Jul 30, 2010 2:36 pm
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

Please list exact device names you are experiencing problems with when connected to RB1100 ether11-ether13. Also state their transmission parameters (speed, duplex mode) if auto negotiation is disabled.
by kirshteins
Fri Jul 30, 2010 9:09 am
Forum: General
Topic: bandwidth-test on RB450G
Replies: 3
Views: 2173

Re: bandwidth-test on RB450G

Bandwidth-test tries to use all bandwidth available. Running UPD BTest both direction without limitation could cause packet drops and that means there will not be complete synchronization between BTest client and server. Do you experience any problems running TCP BTest or single direction UPD BTest?
by kirshteins
Fri Jul 30, 2010 8:40 am
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

Please send supout.rif file to support@mikrotik.com. Generate it while you have auto-negotiation enabled on ether11-ether13. What exact devices are connected to those ports?
by kirshteins
Thu Jul 29, 2010 9:24 am
Forum: Beginner Basics
Topic: IP address and bridging
Replies: 3
Views: 1027

Re: IP address and bridging

Assigning IP addresses to the physical interfaces that are part of the bridge will break things.
It should not break anything. Bridge will simply inherit IP addresses from interfaces assigned as bridge ports.
by kirshteins
Thu Jul 29, 2010 9:07 am
Forum: RouterBOARD hardware
Topic: New RB 750G does not work
Replies: 3
Views: 1499

Re: New RB 750G does not work

Which port are you connecting to? Is Ethernet activity LED shining? How you determine that there is no connection?
by kirshteins
Wed Jul 28, 2010 4:29 pm
Forum: General
Topic: Clock is back to Jan/02/1970 after restart
Replies: 4
Views: 1987

Re: Clock is back to Jan/02/1970 after restart

Routerboards do not have batteries to save clock. You can use NTP client to synchronize time with NTP servers (time.nist.gov, for example). More information:
http://wiki.mikrotik.com/wiki/Manual:Sy ... NTP_client
by kirshteins
Wed Jul 28, 2010 8:50 am
Forum: Beginner Basics
Topic: Dst-Nat done but can't connect internally
Replies: 2
Views: 708

Re: Dst-Nat done but can't connect internally

Try masquerading traffic coming from your LAN network (Src. address) and going to 192.168.1.52 (Dst. address).
by kirshteins
Wed Jul 28, 2010 8:24 am
Forum: General
Topic: switch group
Replies: 1
Views: 840

Re: switch group

There can only be single switch group per physical switch chip. You can use bridging instead.
by kirshteins
Fri Jul 23, 2010 3:46 pm
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

Try to test with recently released v5.0beta5 if possible.
by kirshteins
Wed Jul 14, 2010 12:23 pm
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

I experience the same issue. Connected an RB1100 Ether11 to a cisco ME3400 switch. Interface resets every 10 seconds or so. Ether12 and 13, same issue. All other interfaces works fine. Tried another RB1100 with the same issue. This is a really nasty error. Is there are auto-negotiation enabled on b...
by kirshteins
Wed Jul 14, 2010 11:29 am
Forum: Beginner Basics
Topic: ublock sites from block list
Replies: 6
Views: 1427

Re: ublock sites from block list

Make sure you put this allow rule before general deny youtube.com rule.
by kirshteins
Wed Jul 14, 2010 10:24 am
Forum: Beginner Basics
Topic: ublock sites from block list
Replies: 6
Views: 1427

Re: ublock sites from block list

What blocking method is being used?
by kirshteins
Thu Jul 08, 2010 4:28 pm
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

kewlkeed, poor speed could be result of duplex mismatch. We will investigate why this link does not work at forced 100FD.

verdonker, please send supout.rif file to support@mikrotik.com
by kirshteins
Thu Jul 08, 2010 11:08 am
Forum: RouterBOARD hardware
Topic: RB-1100 Port problems, and performance problems
Replies: 61
Views: 24471

Re: RB-1100 Port problems, and performance problems

Ports 1-10 when set to full duplex 100, they do not connect (No Link) to switch I am using (Nortel 1800) (Cross or straight cable) What is exact configuration for both end (auto-negotiation=yes/no, full-duplex=yes/no, speed)? DO connect when I set them to auto, but they don't have duplex If one end...
by kirshteins
Wed Jul 07, 2010 12:46 pm
Forum: General
Topic: Transfere settings from rb433 to rb133
Replies: 13
Views: 2444

Re: Transfere settings from rb433 to rb133

But how do i Import it then to the new board? Which command do i use?
http://wiki.mikrotik.com/wiki/Manual:Co ... figuration
by kirshteins
Tue Jun 29, 2010 4:35 pm
Forum: General
Topic: Loop Back?
Replies: 15
Views: 4852

Re: Loop Back?

For troubleshooting you can add general masquerade (masquerade everything) rule on top of your SRC-NAT rule list.
by kirshteins
Tue Jun 29, 2010 3:01 pm
Forum: General
Topic: Loop Back?
Replies: 15
Views: 4852

Re: Loop Back?

Try to masquerade traffic coming from your LAN and going to 192.168.2.15. Currently 192.168.2.15 is responding directly to user, while user waits response from router.
by kirshteins
Tue Jun 29, 2010 2:10 pm
Forum: SwOS
Topic: RB250GS IP Addresses Question
Replies: 19
Views: 11030

Re: RB250GS IP Addresses Question

How long should the Upgrading...(Please do not interrupt) message remain on screen?
Just reboot it. In v1.1 reboot after upgrade will happen automatically.
by kirshteins
Mon Jun 21, 2010 10:05 am
Forum: General
Topic: RB1100U and port hang-ups
Replies: 7
Views: 2137

Re: RB1100U and port hang-ups

Please generate supout.rif file when problem occurs and send to support@mikrotik.com together with the description of the problem.
by kirshteins
Thu Jun 17, 2010 12:13 pm
Forum: General
Topic: RouterOS v4.10 released
Replies: 62
Views: 18902

Re: RouterOS v4.10 released

I mean, to be able to use 65535B packet size. See http://forum.mikrotik.com/viewtopic.php?f=3&t=40743 The answer from support was that disabling the IP175D features would not bring any benefits other than be able to use 65535B packet size and I suggested to put it configurable somewhere via con...
by kirshteins
Wed Jun 09, 2010 9:22 am
Forum: Beginner Basics
Topic: arp-gratuitous=auto ???
Replies: 1
Views: 755

Re: arp-gratuitous=auto ???

Auto wasn't supposed to be there. It has been fixed in latest versions.
by kirshteins
Tue Jun 08, 2010 8:59 am
Forum: Beginner Basics
Topic: NTP on RB750 (G) when configured as switch
Replies: 1
Views: 859

Re: NTP on RB750 (G) when configured as switch

Each switch group you configure also has CPU-port, so there shouldn't be any problems to run NTP features on your Routerboards.
More information: http://wiki.mikrotik.com/wiki/Manual:Sw ... p_Features
by kirshteins
Wed May 19, 2010 9:55 am
Forum: RouterBOARD hardware
Topic: RB433 Ethernet hang issue...
Replies: 3
Views: 1207

Re: RB433 Ethernet hang issue...

You can generate supout.rif file after problems occurred and send it to support@mikrotik.com
by kirshteins
Tue May 18, 2010 3:22 pm
Forum: RouterBOARD hardware
Topic: Routerboard 433AH 3v1??? chipset problem IP175D!!!
Replies: 21
Views: 10097

Re: Routerboard 433AH 3v1??? chipset problem IP175D!!!

This problem is caused by additional feature of IP175D switch chip that supports up to 200Mbps speed between CPU and switch, while IP175C only up to 100Mbps. Currently we do not see any benefit form ability to forward 65535-Byte IP packets as all packets exceeding MTU of the interface will get fragm...
by kirshteins
Tue May 18, 2010 12:06 pm
Forum: RouterBOARD hardware
Topic: RB433 Ethernet hang issue...
Replies: 3
Views: 1207

Re: RB433 Ethernet hang issue...

What exactly do you mean by downgrade? What device is connected to ether1? What link status is reported by RouterOS and Ethernet LEDs? Perhaps ether1 is bridged and jammed by bridge loop?
by kirshteins
Tue May 18, 2010 8:18 am
Forum: General
Topic: RB450G vlan in bridge
Replies: 6
Views: 3336

Re: RB450G vlan in bridge

Please send a supout.rif file to support@mikrotik.com from affected router.

http://wiki.mikrotik.com/wiki/Manual:Su ... utput_File
by kirshteins
Mon May 17, 2010 7:48 am
Forum: Beginner Basics
Topic: Router Board 750G
Replies: 4
Views: 1954

Re: Router Board 750G

By default mac-winbox server and neighbor discovery is disabled on 750G ether1. 192.168.88.1 IP address is already assigned to ether2.
by kirshteins
Mon May 10, 2010 2:29 pm
Forum: RouterBOARD hardware
Topic: RB750G tag and untag ports
Replies: 1
Views: 1165

Re: RB750G tag and untag ports

Make sure you have the following configuration
/interface ethernet switch port
set 4 vlan-header=always-strip 
set 2 vlan-header=add-if-missing
by kirshteins
Thu May 06, 2010 2:17 pm
Forum: RouterBOARD hardware
Topic: Ether disabled
Replies: 1
Views: 874

Re: Ether disabled

What RB model is it? You can try to access router using serial console:
http://wiki.mikrotik.com/wiki/Serial_Console
Also you can reset configuration back to factory defaults using this method:
http://wiki.mikrotik.com/wiki/Manual:Password_reset
by kirshteins
Tue Apr 27, 2010 11:16 am
Forum: Beginner Basics
Topic: "TTL expired in transit" with router, works fine without it.
Replies: 3
Views: 2033

Re: "TTL expired in transit" with router, works fine without

Try to trace-route this website with and without router.
by kirshteins
Mon Apr 26, 2010 8:52 am
Forum: RouterBOARD hardware
Topic: RB/750G switch chip features
Replies: 2
Views: 4994

Re: RB/750G switch chip features

1) Only 450G supports this feature.
2) Do you mean adding VLAN tags for specific ports?
by kirshteins
Fri Apr 23, 2010 4:30 pm
Forum: General
Topic: Some questions about RSTP
Replies: 4
Views: 1309

Re: Some questions about RSTP

RSTP can provide you with loop-free topology and also make your redundant links to provide automatic backup, in case active link fails. You can use traffic-monitor tool to disable MT2 - MT6 and MT2 - MT5 links, if there is too much traffic going through MT2 and RSTP will change topology automaticall...
by kirshteins
Tue Apr 06, 2010 2:09 pm
Forum: RouterBOARD hardware
Topic: How switch all 5 Port on RB750?
Replies: 10
Views: 23609

Re: How switch all 5 Port on RB750?

To clarify: RB750 ports 2-5 can be switched together; RB750G ports 1-5 can be switched together; RB450G by default ports 1-5 can be switched. Supports "switch-all-ports=yes/no" that lets you remove switching ability from ether1, but increases ether1 troughtput to other ports in bridged, an...
by kirshteins
Fri Mar 19, 2010 8:24 am
Forum: Beginner Basics
Topic: how to block pictures (jpg, jpeg,pnp, etc)
Replies: 5
Views: 3827

Re: how to block pictures (jpg, jpeg,pnp, etc)

Follow this guide to set up web proxy: http://wiki.mikrotik.com/wiki/How_to_Block_Websites_&_Stop_Downloading_Using_Proxy Add rules to block different kind of picture files: /ip proxy access add path=*.jpg action=deny add path=*.jpeg action=deny add path=*.png action=deny add path=*.gif action=d...
by kirshteins
Wed Mar 03, 2010 8:38 am
Forum: Beginner Basics
Topic: RB 750G - Firewall Problems
Replies: 3
Views: 2622

Re: RB 750G - Firewall Problems

As you can see in packet flow diagram bridge forward traffic are not being processed through IP firewall by default. Set /interface bridge settings set use-ip-firewall=yes to change this behavior. You can try this guide http://wiki.mikrotik.com/wiki/Use_SSH_to_execute_commands_(DSA_key_login) to set...
by kirshteins
Tue Mar 02, 2010 8:29 am
Forum: General
Topic: window7 and winbox
Replies: 8
Views: 2843

Re: window7 and winbox

Try to set it to "Run as Administrator". Also if you have multiple NICs make sure only the one your are connecting to the router is enabled, and it has IP address assigned.
by kirshteins
Fri Feb 26, 2010 8:13 am
Forum: General
Topic: ethernet problem between to RB 433
Replies: 1
Views: 681

Re: ethernet problem between to RB 433

There is a bug with ether2 and ether3 not working correctly on some RB433 in v4.3. This bug is fixed in latest v4.5.
by kirshteins
Fri Feb 05, 2010 10:32 am
Forum: RouterBOARD hardware
Topic: RB 433 All interfaces disabled
Replies: 2
Views: 1021

Re: RB 433 All interfaces disabled

Please follow this guide to reset any configuration: http://wiki.mikrotik.com/wiki/Password_reset
by kirshteins
Fri Feb 05, 2010 9:20 am
Forum: General
Topic: isolating rb750 ports
Replies: 5
Views: 3615

Re: isolating rb750 ports

RB750 switch does not have advance packet filtering, so it is impossible to isolate networks (it is still possible to isolate VLANs). You can try to use bridge instead of a switching. With "/interface bridge settings set use-ip-firewall=yes" you can use IP firewall.
by kirshteins
Fri Jan 29, 2010 2:06 pm
Forum: General
Topic: isolating rb750 ports
Replies: 5
Views: 3615

Re: isolating rb750 ports

In case ether3 and ether4 are not switched together, you can try to use IP firewall filter to isolate LANs. For example,
/ip firewall filter
add action=drop chain=forward in-interface=ether3 out-interface=ether4
add action=drop chain=forward in-interface=ether4 out-interface=ether3
by kirshteins
Tue Jan 26, 2010 8:35 am
Forum: General
Topic: New switch feature bridge with fancy name?
Replies: 6
Views: 1912

Re: New switch feature bridge with fancy name?

Please take a look at Port switching paragraph.
Why are there now port statistics other than on the master port?
What statistics do you mean?
by kirshteins
Wed Jan 20, 2010 10:22 am
Forum: Beginner Basics
Topic: Reconfiguring the default Ethernet switch config on a 750G
Replies: 3
Views: 1167

Re: Reconfiguring the default Ethernet switch config on a 750G

does it reset without the ports as part of a switch?
No, unless you specify
no-defaults=yes
Also after each configuration reset RouterOS will prompt you after first login whether you want to save default configuration or not.
by kirshteins
Wed Jan 20, 2010 8:22 am
Forum: Beginner Basics
Topic: Reconfiguring the default Ethernet switch config on a 750G
Replies: 3
Views: 1167

Re: Reconfiguring the default Ethernet switch config on a 750G

You can do
/system reset-configuration no-defaults=yes
And default configuration will not be applied after reset. Also you can simply reset configuration and choose to remove configuration when you get prompted.
by kirshteins
Tue Jan 19, 2010 8:40 am
Forum: General
Topic: RB750G changing over from 1Gbps to 100Mbps unexpectedly
Replies: 7
Views: 2876

Re: RB750G changing over from 1Gbps to 100Mbps unexpectedly

In order to link at 1Gbps auto-negotiation must be enabled, as there are more parameters to negotiate other that speed and duplex mode.

How long and what kind of cable are you using? What ROS version? What device are you linking to? Does this affects all ethernet ports?
by kirshteins
Fri Jan 08, 2010 4:24 pm
Forum: General
Topic: help on block sites from Mikrotik
Replies: 15
Views: 2491

Re: help on block sites from Mikrotik

Leave "src-address=0.0.0.0/0" as it is and "<Your WAN Port>" means interface through which you are connecting to Internet.
by kirshteins
Thu Jan 07, 2010 2:17 pm
Forum: Beginner Basics
Topic: Unable to logon to RB493 - timed out!
Replies: 14
Views: 4874

Re: Unable to logon to RB493 - timed out!

Yes, you can use something like screwdriver, ensure both sides of reset hole are connected. Also it is possible that Windows firewall is blocking your MAC address connection. Try to disable it.
by kirshteins
Thu Jan 07, 2010 1:21 pm
Forum: Beginner Basics
Topic: Unable to logon to RB493 - timed out!
Replies: 14
Views: 4874

Re: Unable to logon to RB493 - timed out!

You can also try to reset configuration http://wiki.mikrotik.com/images/1/14/Resethole.jpg
by kirshteins
Wed Dec 30, 2009 1:42 pm
Forum: Beginner Basics
Topic: Port forwarding is not working
Replies: 7
Views: 2163

Re: Port forwarding is not working

Ensure that connection tracking is enabled. Also you can try not to use in-interface parameter for this rule.
I'm testing from both. From internal network the web page is reachable.
Is it reachable using 78.xxx.xxx.xxx?
by kirshteins
Wed Dec 30, 2009 9:01 am
Forum: General
Topic: A stupid mistake
Replies: 6
Views: 1784

Re: A stupid mistake

and how can one block mac telnet? :)
You can turn off this service
/tool mac-server set 0 interface=all disabled=yes
Also the mac-winbox
/tool mac-server mac-winbox set 0 interface=all disabled=yes
by kirshteins
Wed Dec 30, 2009 8:50 am
Forum: Beginner Basics
Topic: Port forwarding is not working
Replies: 7
Views: 2163

Re: Port forwarding is not working

Are you testing from local or public network, or both? Is this forwarding rule "counting" packets? In case you are using bridge you have to enable
/interface bridge settings set use-ip-firewall=yes
by kirshteins
Tue Dec 15, 2009 4:24 pm
Forum: Scripting
Topic: very simple script to enable/disable rules
Replies: 11
Views: 26233

Re: very simple script to enable/disable rules

What version are you using? Does second script log "eth1-208 DOWN: $activa208" part or only disable rule is the one that does not work? What is the result if you paste it directly into terminal? Also i suggest to check script policies.
by kirshteins
Mon Dec 07, 2009 2:52 pm
Forum: Scripting
Topic: ping not responding
Replies: 10
Views: 4495

Re: ping not responding

Yes, ping is ICMP, but you do not have any NAT rule to forward it.
by kirshteins
Mon Nov 23, 2009 8:35 am
Forum: RouterBOARD hardware
Topic: Can I unlock a Crossroads locked to a regulatory domain?
Replies: 10
Views: 3277

Re: Can I unlock a Crossroads locked to a regulatory domain?

It is now possible to start Netinstall without serial connection with the newest firmware. Just hold down the reset button on power up till routerboard starts to etherboot.
by kirshteins
Fri Nov 20, 2009 8:25 am
Forum: RouterBOARD hardware
Topic: Switch
Replies: 15
Views: 6648

Re: Switch

This feature is not supported for the switch chip RB750 have. More information: http://wiki.mikrotik.com/wiki/Switch_Chip_Features
by kirshteins
Thu Nov 19, 2009 8:18 am
Forum: General
Topic: NetworkPro on firewalling
Replies: 6
Views: 1509

Re: NetworkPro on firewalling

Action=jump can be handy if you want to classify specific traffic and apply more than one rule to it. You should read manual about this: http://wiki.mikrotik.com/wiki/Firewall_filter . Pay most attention to action=jump and action=return.
by kirshteins
Tue Nov 17, 2009 1:11 pm
Forum: General
Topic: NetworkPro on firewalling
Replies: 6
Views: 1509

Re: NetworkPro on firewalling

'Action=jump jump-target=drop' means that these packets should now be processed through rules with 'chain=drop'. Do you have any rules with 'chain=drop' ?
by kirshteins
Tue Nov 17, 2009 1:05 pm
Forum: Beginner Basics
Topic: Remove Mikrotik word from ERROR: Gateway Timeout
Replies: 28
Views: 10892

Re: Remove Mikrotik word from ERROR: Gateway Timeout

Currently 'url', 'status', 'error', 'admin' and 'signature' are the only variables. I think that 'signature' could be more divided into smaller parts like 'time' and 'program'. Do you think there should be any other variables? To give different messages to proxy deny rules you can try to play around...
by kirshteins
Mon Nov 16, 2009 2:13 pm
Forum: General
Topic: Does the RB493 support the switch feature on ROS 4.2?
Replies: 6
Views: 1975

Re: Does the RB493 support the switch feature on ROS 4.2?

Unfortunately RB493 supports only port switching feature. Currently there are no plans for other feature support for IP178C or IP175C switch chips.
by kirshteins
Thu Nov 12, 2009 3:49 pm
Forum: General
Topic: RB450g switch and layer 2 traffic separation using VLANs
Replies: 3
Views: 2838

Re: RB450g switch and layer 2 traffic separation using VLANs

The only problem is the assigment of incoming untagged traffic to proper VLAN. This can be achieved with /interface ethernet switch rule add switch=0 ports=ether1 new-vlan-id=1 But, unfortunately, the are no matcher to determine through which port packets will leave and there is no action to remove...
by kirshteins
Wed Nov 11, 2009 4:22 pm
Forum: General
Topic: 3.30 vs 3.20 Queues
Replies: 8
Views: 2090

Re: 3.30 vs 3.20 Queues

Simple queues do not work with Xen package. Do you have it installed?
by kirshteins
Wed Nov 11, 2009 11:28 am
Forum: RouterBOARD hardware
Topic: RB493ah ethernet ports stop routing then restarts
Replies: 33
Views: 12673

Re: RB493ah ethernet ports stop routing then restarts

Everyone with this problem should reinstall this boards using netinstall and upgrade to the latest firmware. If you are still having these issues you should report support@mikrotik.com with steps of reproduction and supout.rif files.
by kirshteins
Wed Nov 11, 2009 11:13 am
Forum: Beginner Basics
Topic: Remove Mikrotik word from ERROR: Gateway Timeout
Replies: 28
Views: 10892

Re: Remove Mikrotik word from ERROR: Gateway Timeout

IS this work with MK V3.22
No, this feature was added in v3.28
by kirshteins
Wed Nov 11, 2009 9:26 am
Forum: Beginner Basics
Topic: Remove Mikrotik word from ERROR: Gateway Timeout
Replies: 28
Views: 10892

Re: Remove Mikrotik work from ERROR: Gateway Timeout

I do not want to reset anything I just want to remove the word "Mikrotik"
In case you do not have webproxy/error.html file under /file
/ip proxy reset-html
will make one. Then you can dowload this error.html file with FTP, edit, and upload back where it was.
by kirshteins
Wed Nov 11, 2009 9:12 am
Forum: Beginner Basics
Topic: Remove Mikrotik word from ERROR: Gateway Timeout
Replies: 28
Views: 10892

Re: Remove Mikrotik work from ERROR: Gateway Timeout

Try to run
/ip proxy reset-html
by kirshteins
Wed Nov 11, 2009 9:02 am
Forum: Beginner Basics
Topic: Remove Mikrotik word from ERROR: Gateway Timeout
Replies: 28
Views: 10892

Re: Remove Mikrotik work from ERROR: Gateway Timeout

Generated Fri, 02 Jan 1970 00:29:31 GMT by 192.168.3.1 (Mikrotik HttpProxy)
You can remove this whole line by editing and removing "$(signature)" from webproxy/error.html under files section.
by kirshteins
Tue Nov 10, 2009 12:39 pm
Forum: General
Topic: Queues not working
Replies: 7
Views: 1430

Re: Queues not working

Xen package is highly experimental and simple queues are not working with it. You can remove it with
/system package uninstall xen;
/system reboot;
Most probably you installed it accidentally by selecting all packages.
by kirshteins
Tue Nov 10, 2009 12:10 pm
Forum: General
Topic: Queues not working
Replies: 7
Views: 1430

Re: Queues not working

Do you have Xen package installed?
by kirshteins
Fri Nov 06, 2009 3:44 pm
Forum: General
Topic: How to email when IP added to address list?
Replies: 7
Views: 4918

Re: How to email when IP added to address list?

Set up action and rule for logger /system logging action action add name=mail email-to=email@server.com target=email /system logging add action=mail disabled=no prefix=_mail topics=firewall Set up e-mail settings under /tool e-mail Then copy your given rule and place a copy before original rule. Cha...
by kirshteins
Fri Nov 06, 2009 3:03 pm
Forum: RouterBOARD hardware
Topic: Problem with new rb 450G
Replies: 6
Views: 1728

Re: Problem with new rb 450G

Try to connect this routerboard with serial console and check whether all ethernet ports are enabled. Or simply netinstall to the newest version as suggested before.
by kirshteins
Thu Nov 05, 2009 12:51 pm
Forum: Scripting
Topic: need script for p2p
Replies: 7
Views: 1945

Re: need script for p2p

I tested this with 3.20 and it worked for me. Once again, make sure "p2p" is in lower-case and "all-p2p" is in quotes. And, of course, if you run both of those commands at the same time then second command line will overwrite changes done by the first line.
by kirshteins
Thu Nov 05, 2009 12:12 pm
Forum: Scripting
Topic: need script for p2p
Replies: 7
Views: 1945

Re: need script for p2p

What version are you running? And what exactly is not working as expected?
by kirshteins
Thu Nov 05, 2009 9:21 am
Forum: Scripting
Topic: need script for p2p
Replies: 7
Views: 1945

Re: need script for p2p

Try
/ip firewall filter set [find p2p="all-p2p"] action=accept
/ip firewall filter set [find p2p="all-p2p"] action=drop
by kirshteins
Wed Oct 28, 2009 4:15 pm
Forum: Beginner Basics
Topic: First time install
Replies: 5
Views: 1481

Re: First time install

Does it have to be a precise adress, ie 192.168.10.10.
Or is it possible to give the whole lan access, ie 192.168.10.0/24 ?
Both. And also IP address range, for example, x.x.x.1-x.x.x.10
by kirshteins
Tue Oct 27, 2009 2:30 pm
Forum: Beginner Basics
Topic: Block Ping To Mikrotik OS
Replies: 5
Views: 2617

Re: Block Ping To Mikrotik OS

IP->Firewall->Filter Rules->"+"
General:
Chain=input
Src. Address=x.x.x.x/x (your LAN)
Protocol=icmp
Advanced:
ICMP type=echo request (under ICMP Options)
Action:
Action=drop

You can also use src-address-list instead of src-address if necessary
by kirshteins
Tue Oct 27, 2009 10:33 am
Forum: Beginner Basics
Topic: Block Ping To Mikrotik OS
Replies: 5
Views: 2617

Re: Block Ping To Mikrotik OS

You can drop only icmp echo requests
icmp-options=8:0-255 protocol=icmp
and/or icmp echo replies
icmp-options=0:0-255 protocol=icmp
coming from/going to your LAN. In this case rest of icmp will work.
by kirshteins
Tue Oct 27, 2009 8:47 am
Forum: RouterBOARD hardware
Topic: Mirror port on RB750?
Replies: 3
Views: 6182

Re: Mirror port on RB750?

I get "all-port-switch not supported on this board" and similar error messages. This is because of the bug in Winbox. It will be fixed in next v4.2 version of RouterOS. For now you can configure it using command line interface: /interface ethernet switch set numbers=0 mirror-source=ether2...
by kirshteins
Thu Oct 22, 2009 8:37 am
Forum: General
Topic: pptp filter rule problem
Replies: 1
Views: 825

Re: pptp filter rule problem

Apart from GRE protocol PPTP also uses TCP port 1723, that is dropped by the last rule.
by kirshteins
Wed Oct 21, 2009 4:09 pm
Forum: Beginner Basics
Topic: Edit Error Page Of Web Master cache
Replies: 18
Views: 3655

Re: Edit Error Page Of Web Mastr cache

No, this feature was added in v3.28
by kirshteins
Wed Oct 21, 2009 4:05 pm
Forum: Beginner Basics
Topic: Edit Error Page Of Web Master cache
Replies: 18
Views: 3655

Re: Edit Error Page Of Web Mastr cache

Make sure you are using v3.28 or newer. If still cannot find it you can do
/ip proxy reset-html
it will restore this file if its missing.
by kirshteins
Wed Oct 21, 2009 11:19 am
Forum: Beginner Basics
Topic: RB450G switched ports
Replies: 4
Views: 2863

Re: RB450G switched ports

First, I've seen that, qith default configuration, ports eth2->5 are switched (switch1). I've tried to remove ports on that switch but I get the following message : "Couldn't remove Switch port etherX, feature is not implemented (3) ". I can't also remove the switch itself. "/interfa...
by kirshteins
Wed Oct 21, 2009 8:53 am
Forum: General
Topic: winbox dosent work with pppoe in win vista and win7
Replies: 14
Views: 2745

Re: winbox dosent work with pppoe in win vista and win7

Are you running pppoe on winXP as well when everything is working? You could also disable firewall, see if it helps.
by kirshteins
Tue Oct 20, 2009 1:54 pm
Forum: General
Topic: RB450 hangs when configured as a switch
Replies: 1
Views: 662

Re: RB450 hangs when configured as a switch

What type of switch chip is it? Do you have any other configuration on this board apart from
/interface ethernet set ether_x master-port=ether_y
by kirshteins
Fri Oct 16, 2009 3:45 pm
Forum: General
Topic: filter HTTP Download
Replies: 4
Views: 1493

Re: filter HTTP Download

Beware with limiting HTTP downloads using connection-bytes as you might end up having problems with huge picture, .swf and .flv etc. files while browsing web pages. Also, as NAB suggested, you can block downloads by filename extensions. This guide shows how it is done in RouterOS: http://wiki.mikrot...
by kirshteins
Thu Oct 15, 2009 3:44 pm
Forum: General
Topic: filter HTTP Download
Replies: 4
Views: 1493

Re: filter HTTP Download

It not that simple separate those two things, but you can create firewall filter rules with option connection-bytes. For example,
/ip firewall filter add chain=forward protocol=tcp dst-port=80 connection-bytes=2000000-0 action=drop
will drop HTTP connections that exceeds 2MB
by kirshteins
Thu Oct 15, 2009 9:06 am
Forum: Beginner Basics
Topic: NAT Can't be that hard?
Replies: 11
Views: 2708

Re: NAT Can't be that hard?

This is not disabled by default :). In winbox under "connections" tab there is a button "tracking" that shows you connection tracking options.
by kirshteins
Thu Oct 15, 2009 8:16 am
Forum: Beginner Basics
Topic: NAT Can't be that hard?
Replies: 11
Views: 2708

Re: NAT Can't be that hard?

Try to enable
/ip firewall connection tracking set enabled=yes
That might be the problem your NAT rule is not working correctly.
by kirshteins
Wed Oct 14, 2009 8:57 am
Forum: Beginner Basics
Topic: PPTP link not working for Mikrtik routers over Inernet
Replies: 27
Views: 12681

Re: PPTP link not working for Mikrtik routers over Inernet

Do your routers show that PPTP tunnel is up and running? Or is it a problem where you cannot pass traffic over established one?
by kirshteins
Wed Oct 14, 2009 8:47 am
Forum: Beginner Basics
Topic: NAT Can't be that hard?
Replies: 11
Views: 2708

Re: NAT Can't be that hard?

More configuration details are necessary I guess. Have you bridged public and local interfaces? Is that your only NAT rule?
by kirshteins
Tue Oct 13, 2009 3:18 pm
Forum: Wireless Networking
Topic: RB433 with 1x R52 WLAN and 2 LAN Client
Replies: 1
Views: 1015

Re: RB433 with 1x R52 WLAN and 2 LAN Client

Of course such setup is possible. You need NAT rule for each LAN network: /ip firewall nat add action=src-nat chain=srcnat src-address=192.168.2.xxx/x to-addresses=85.199.xxx.200 add action=src-nat chain=srcnat src-address=192.168.3.xxx/x to-addresses=85.199.xxx.201 To isolate your LAN networks from...
  • 1
  • 2