Community discussions

MikroTik App
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Reboot all on the chain

Tue Oct 10, 2006 4:05 pm

Hello fellows...
I've experienced a very whicked problem...
It happens once a week or twice...All my mikrotiks(about 5 on the chain) reboot one after another..and there is no visible reason?
Can someone tell me if he/she experienced the same problem and what is the solution?

Regards Promind
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Tue Oct 10, 2006 4:10 pm

enable all logs and set them to `disk` and then see what caused a reboot. either a power problem, or something else.
 
cmit
Forum Guru
Forum Guru
Posts: 1547
Joined: Fri May 28, 2004 12:49 pm
Location: Germany

Tue Oct 10, 2006 5:04 pm

Do you by any chance have the system watchdog enabled and watching its' "neighbours" ip address?

I saw that domino effect once, where one router rebooted because of a power outage, and then all other routers in the chain did the same ;)

Best regards,
Christian Meis
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Tue Oct 10, 2006 10:15 pm

yes I did...but didn't set any neighbour address
...but the fact is that when I disable watchdog machines begin blocking one after another.
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Wed Oct 11, 2006 4:54 pm

enable all logs and set them to `disk` and then see what caused a reboot. either a power problem, or something else.
all logs stored in disk...and nothing again...
log just says router was rebooted without proper shutdown
no other messages...
also it's not power failure I'm 100% sure
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Thu Oct 12, 2006 9:08 am

but it looks like it is. it is nearly impossible for a software/hardware error to occur at the same time on all routers.
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Thu Oct 12, 2006 9:47 am

but it looks like it is. it is nearly impossible for a software/hardware error to occur at the same time on all routers.
I'm pretty sure it's not power failure...
1st router 0km
2nd router 13km
3rd router 47km from 2nd
4th router 36km from 3rd
5th router 32km from 4th
6th router 7km from 5th

All reboot one after another...and there is no visible reason for this...I think this is hack attack...log says someone is trying to connect via ssh and after 10 minutes router reboots...and after that all routers one by one begin rebooting...I've stopped telnet/ftp/ssh/www for now..just left winbox and we'll see if that was the problem

P.S. is there any way to limit winbox connections to particular mac addresses?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Thu Oct 12, 2006 9:48 am

change winbox port in `ip services`, set up firewall in `input chain` to drop all connections except for your IP, change ssh port, read the manual about how to protect your router
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Thu Oct 12, 2006 9:59 am

change winbox port in `ip services`, set up firewall in `input chain` to drop all connections except for your IP, change ssh port, read the manual about how to protect your router
I've done that...no effect for ssh..just disabled it...
I connect through mac address via winbox...

and also I don't see winbox port in services

there are ftp/telnet/ssh/www/www-ssl
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Thu Oct 12, 2006 10:01 am

www
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Thu Oct 12, 2006 10:09 am

www
done that..no effect connects via winbox without any problems


disabled user admin
added random generated user with 12 symbols
added 64 symbol default password for the new user
disabled services all except winbox...and when I do nmap I see that ports 1720 2000 3986 are open?
why are they open? I don't see other services that I should close.
Last edited by promind on Thu Oct 12, 2006 10:18 am, edited 1 time in total.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Thu Oct 12, 2006 10:14 am

you said you use MAC winbox. that's something completely different. see this page about ports RouterOS uses:
http://www.mikrotik.com/docs/ros/2.9/ip/service

if you done all that i recommended - it is not a hack attack. check for power problems. bring down one of the routers, attach it somewhere else and see if it still reboots
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Thu Oct 12, 2006 10:21 am

you said you use MAC winbox. that's something completely different. see this page about ports RouterOS uses:
http://www.mikrotik.com/docs/ros/2.9/ip/service

if you done all that i recommended - it is not a hack attack. check for power problems. bring down one of the routers, attach it somewhere else and see if it still reboots
you see...all routers have backup power device ... it is NOT power failure I'm sure of that... I have other mikrotik with 2.4Ghz card configured as wds on the same electric chain...and this mikrotik does not reboot...I have not configured any ips for this one and probably that saved it!
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

testrun

Thu Oct 12, 2006 7:34 pm

it happened again!
16:30 first mikrotik reboots 30 seconds after the second one and so on and so on....
 
cmit
Forum Guru
Forum Guru
Posts: 1547
Joined: Fri May 28, 2004 12:49 pm
Location: Germany

Thu Oct 12, 2006 8:54 pm

I think you'll have to post your configs to see if it's something misconfigured...

Very strange, otherwise...

Best regards,
Christian Meis
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Fri Oct 13, 2006 3:57 pm

I think you'll have to post your configs to see if it's something misconfigured...

Very strange, otherwise...

Best regards,
Christian Meis
I've figured out the problem...but I don't understand why mikrotik depends on system time?
the battery of the bios has gone away and it always shows time of machine export / p3 866Mhz DELL/ nov/02/2000 . and mikrotik just expires when I fix time manually system licence reports 2 years outage , else 8 hours.
how can that be fixed?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Fri Oct 13, 2006 3:59 pm

send this file to support, we will see what's wrong:
http://wiki.mikrotik.com/wiki/Supout
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Tue Oct 17, 2006 1:23 pm

send this file to support, we will see what's wrong:
http://wiki.mikrotik.com/wiki/Supout
exported config...watched it all over twice and nothing wrong...
and now the real reason is not license key...it's ok...too much traffic goes through the machines...about 20Mbit on P3 866Mhz, can someone tell me what machines should I use for best performance?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Tue Oct 17, 2006 1:56 pm

your machines are enough for the task
 
User avatar
promind
Member Candidate
Member Candidate
Topic Author
Posts: 153
Joined: Thu Feb 23, 2006 11:26 am
Location: Rousse, Bulgaria
Contact:

Mon Oct 23, 2006 12:25 pm

your machines are enough for the task
not enough...I use mikrotik just for bridge...I had enabled connection tracking...that was the problem...connection tracking reduces my cpu usage with about 30% and when the first machine reboots next was "attacked" by the big traffic going to it...and so on and so on...just disabled connection tracking and all went fine...for now :)

P.S: Thank you for your time...and please accept my appologies if I'd disturbed you with my odd questions :)

Who is online

Users browsing this forum: Google [Bot] and 31 guests