Community discussions

MUM Europe 2020
 
marklodge
Member Candidate
Member Candidate
Topic Author
Posts: 211
Joined: Sun Jun 21, 2009 6:15 pm

Breaking my head trying to access yahoo and other https site

Thu Nov 10, 2011 1:45 am

i have had a problem now for 3 weeks, cant access yahoo mail nor paypal and some other ssl sites. (some ssl https sites do work tho, like hostgator cpanel and gmail )
i have completely RESET my mikrotik rb433 and upgraded it to the latest v5.8
and all i configured was a super basic pppoe server using radius and adding a route and masquerade rule.
and i still cannot access yahoo. i am stumped. please help

i just exported my whole config if you want to have a look









  MMM      MMM       KKK                          TTTTTTTTTTT      KKK
  MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK
  MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK
  MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK
  MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK
  MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      TTT     III  KKK  KKK

  MikroTik RouterOS 5.8 (c) 1999-2011       http://www.mikrotik.com/





[admin@MikroTik] > export
# jan/02/1970 00:22:49 by RouterOS 5.8
# software id = 6S61-VQPK
#
/interface bridge
add admin-mac=00:00:00:00:00:00 ageing-time=5m arp=enabled auto-mac=yes \
    disabled=no forward-delay=15s l2mtu=1522 max-message-age=20s mtu=1500 \
    name=bridge1 priority=0x8000 protocol-mode=rstp transmit-hold-count=6
/interface ethernet
set 0 arp=enabled auto-negotiation=yes disabled=no full-duplex=yes l2mtu=1526 \
    mac-address=00:0C:42:44:90:87 mtu=1500 name=ether1 speed=100Mbps
set 1 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited \
    disabled=no full-duplex=yes l2mtu=1522 mac-address=00:0C:42:44:90:88 \
    master-port=none mtu=1500 name=ether2 speed=100Mbps
set 2 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited \
    disabled=no full-duplex=yes l2mtu=1522 mac-address=00:0C:42:44:90:89 \
    master-port=none mtu=1500 name=ether3 speed=100Mbps
/interface ethernet switch
set switch1 mirror-source=none mirror-target=none name=switch1
/interface wireless security-profiles
set default authentication-types="" eap-methods=passthrough group-ciphers=\
    aes-ccm group-key-update=5m interim-update=0s management-protection=\
    disabled management-protection-key="" mode=none name=default \
    radius-eap-accounting=no radius-mac-accounting=no \
    radius-mac-authentication=no radius-mac-caching=disabled \
    radius-mac-format=XX:XX:XX:XX:XX:XX radius-mac-mode=as-username \
    static-algo-0=none static-algo-1=none static-algo-2=none static-algo-3=\
    none static-key-0="" static-key-1="" static-key-2="" static-key-3="" \
    static-sta-private-algo=none static-sta-private-key="" \
    static-transmit-key=key-0 supplicant-identity=MikroTik tls-certificate=\
    none tls-mode=no-certificates unicast-ciphers=aes-ccm wpa-pre-shared-key=\
    "" wpa2-pre-shared-key=""
/interface wireless
set 0 adaptive-noise-immunity=none allow-sharedkey=no antenna-gain=0 \
    antenna-mode=ant-a area="" arp=enabled band=5ghz-a basic-rates-a/g=6Mbps \
    basic-rates-b=1Mbps bridge-mode=enabled burst-time=disabled \
    channel-width=20mhz compression=no country=no_country_set \
    default-ap-tx-limit=0 default-authentication=yes default-client-tx-limit=\
    0 default-forwarding=yes dfs-mode=none disable-running-check=no disabled=\
    yes disconnect-timeout=3s distance=dynamic frame-lifetime=0 frequency=\
    5180 frequency-mode=manual-txpower frequency-offset=0 hide-ssid=no \
    hw-fragmentation-threshold=disabled hw-protection-mode=none \
    hw-protection-threshold=0 hw-retries=7 mac-address=00:0C:42:63:E0:1F \
    max-station-count=2007 mode=station mtu=1500 name=wlan1 \
    noise-floor-threshold=default nv2-cell-radius=30 nv2-noise-floor-offset=\
    default nv2-preshared-key="" nv2-qos=default nv2-queue-count=2 \
    nv2-security=disabled on-fail-retry-time=100ms periodic-calibration=\
    default periodic-calibration-interval=60 preamble-mode=both \
    proprietary-extensions=post-2.9.25 radio-name=000C4263E01F \
    rate-selection=legacy rate-set=default scan-list=default \
    security-profile=default ssid=MikroTik station-bridge-clone-mac=\
    00:00:00:00:00:00 supported-rates-a/g=\
    6Mbps,9Mbps,12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps supported-rates-b=\
    1Mbps,2Mbps,5.5Mbps,11Mbps tdma-period-size=2 tx-power-mode=default \
    update-stats-interval=disabled wds-cost-range=50-150 wds-default-bridge=\
    none wds-default-cost=100 wds-ignore-ssid=no wds-mode=disabled \
    wireless-protocol=unspecified wmm-support=disabled
set 1 adaptive-noise-immunity=none allow-sharedkey=no antenna-gain=0 \
    antenna-mode=ant-a area="" arp=enabled band=5ghz-a basic-rates-a/g=6Mbps \
    basic-rates-b=1Mbps bridge-mode=enabled burst-time=disabled \
    channel-width=20mhz compression=no country=no_country_set \
    default-ap-tx-limit=0 default-authentication=yes default-client-tx-limit=\
    0 default-forwarding=yes dfs-mode=none disable-running-check=no disabled=\
    yes disconnect-timeout=3s distance=dynamic frame-lifetime=0 frequency=\
    5180 frequency-mode=manual-txpower frequency-offset=0 hide-ssid=no \
    hw-fragmentation-threshold=disabled hw-protection-mode=none \
    hw-protection-threshold=0 hw-retries=7 mac-address=00:0C:42:3A:8B:84 \
    max-station-count=2007 mode=station mtu=1500 name=wlan2 \
    noise-floor-threshold=default nv2-cell-radius=30 nv2-noise-floor-offset=\
    default nv2-preshared-key="" nv2-qos=default nv2-queue-count=2 \
    nv2-security=disabled on-fail-retry-time=100ms periodic-calibration=\
    default periodic-calibration-interval=60 preamble-mode=both \
    proprietary-extensions=post-2.9.25 radio-name=000C423A8B84 \
    rate-selection=legacy rate-set=default scan-list=default \
    security-profile=default ssid=MikroTik station-bridge-clone-mac=\
    00:00:00:00:00:00 supported-rates-a/g=\
    6Mbps,9Mbps,12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps supported-rates-b=\
    1Mbps,2Mbps,5.5Mbps,11Mbps tdma-period-size=2 tx-power-mode=default \
    update-stats-interval=disabled wds-cost-range=50-150 wds-default-bridge=\
    none wds-default-cost=100 wds-ignore-ssid=no wds-mode=disabled \
    wireless-protocol=unspecified wmm-support=disabled
/interface wireless manual-tx-power-table
set wlan1 manual-tx-powers="1Mbps:17,2Mbps:17,5.5Mbps:17,11Mbps:17,6Mbps:17,9M\
    bps:17,12Mbps:17,18Mbps:17,24Mbps:17,36Mbps:17,48Mbps:17,54Mbps:17,HT20-0:\
    17,HT20-1:17,HT20-2:17,HT20-3:17,HT20-4:17,HT20-5:17,HT20-6:17,HT20-7:17,H\
    T40-0:17,HT40-1:17,HT40-2:17,HT40-3:17,HT40-4:17,HT40-5:17,HT40-6:17,HT40-\
    7:17"
set wlan2 manual-tx-powers="1Mbps:17,2Mbps:17,5.5Mbps:17,11Mbps:17,6Mbps:17,9M\
    bps:17,12Mbps:17,18Mbps:17,24Mbps:17,36Mbps:17,48Mbps:17,54Mbps:17,HT20-0:\
    17,HT20-1:17,HT20-2:17,HT20-3:17,HT20-4:17,HT20-5:17,HT20-6:17,HT20-7:17,H\
    T40-0:17,HT40-1:17,HT40-2:17,HT40-3:17,HT40-4:17,HT40-5:17,HT40-6:17,HT40-\
    7:17"
/interface wireless nstreme
set wlan1 disable-csma=no enable-nstreme=no enable-polling=yes framer-limit=\
    3200 framer-policy=none
set wlan2 disable-csma=no enable-nstreme=no enable-polling=yes framer-limit=\
    3200 framer-policy=none
/ip hotspot profile
set default dns-name="" hotspot-address=0.0.0.0 html-directory=hotspot \
    http-cookie-lifetime=3d http-proxy=0.0.0.0:0 login-by=cookie,http-chap \
    name=default rate-limit="" smtp-server=0.0.0.0 split-user-domain=no \
    use-radius=no
/ip hotspot user profile
set default idle-timeout=none keepalive-timeout=2m name=default shared-users=\
    1 status-autorefresh=1m transparent-proxy=no
/ip ipsec proposal
set default auth-algorithms=sha1 disabled=no enc-algorithms=3des lifetime=30m \
    name=default pfs-group=modp1024
/ip pool
add name=pool1 ranges=10.0.0.100-10.0.0.255
add name=pool2 ranges=192.168.0.6-192.168.0.100
add name=pool3 ranges=192.168.17.5-192.168.17.50
/port
set 0 baud-rate=auto data-bits=8 flow-control=none name=serial0 parity=none \
    stop-bits=1
/ppp profile
set default change-tcp-mss=yes local-address=10.0.0.1 name=default only-one=\
    default remote-address=pool1 use-compression=default use-encryption=\
    default use-mpls=default use-vj-compression=default
add change-tcp-mss=default local-address=10.5.60.8 name=2 only-one=default \
    remote-address=pool3 use-compression=default use-encryption=default \
    use-mpls=default use-vj-compression=default
set default-encryption change-tcp-mss=yes local-address=10.0.0.9 name=\
    default-encryption only-one=default remote-address=10.0.0.10 \
    use-compression=default use-encryption=yes use-mpls=default \
    use-vj-compression=default
/queue type
set default kind=pfifo name=default pfifo-limit=50
set ethernet-default kind=pfifo name=ethernet-default pfifo-limit=50
set wireless-default kind=sfq name=wireless-default sfq-allot=1514 \
    sfq-perturb=5
set synchronous-default kind=red name=synchronous-default red-avg-packet=1000 \
    red-burst=20 red-limit=60 red-max-threshold=50 red-min-threshold=10
set hotspot-default kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=\
    5
set only-hardware-queue kind=none name=only-hardware-queue
set multi-queue-ethernet-default kind=mq-pfifo mq-pfifo-limit=50 name=\
    multi-queue-ethernet-default
set default-small kind=pfifo name=default-small pfifo-limit=10
/queue simple
add burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s direction=both \
    disabled=yes limit-at=1M/1M max-limit=1M/1M name=queue1 parent=none \
    priority=8 queue=default-small/default-small total-queue=default-small
/routing bgp instance
set default as=65530 client-to-client-reflection=yes disabled=no \
    ignore-as-path-len=no name=default out-filter="" redistribute-connected=\
    no redistribute-ospf=no redistribute-other-bgp=no redistribute-rip=no \
    redistribute-static=no router-id=0.0.0.0 routing-table=""
/routing ospf instance
set default disabled=no distribute-default=never in-filter=ospf-in \
    metric-bgp=auto metric-connected=20 metric-default=1 metric-other-ospf=\
    auto metric-rip=20 metric-static=20 name=default out-filter=ospf-out \
    redistribute-bgp=no redistribute-connected=no redistribute-other-ospf=no \
    redistribute-rip=no redistribute-static=no router-id=0.0.0.0
/routing ospf area
set backbone area-id=0.0.0.0 disabled=no instance=default name=backbone type=\
    default
/snmp
set contact="" enabled=no engine-id="" location="" trap-version=1
/snmp community
set public address=0.0.0.0/0 authentication-password="" \
    authentication-protocol=MD5 encryption-password="" encryption-protocol=\
    DES name=public read-access=yes security=none write-access=no
/system logging action
set memory memory-lines=100 memory-stop-on-full=no name=memory target=memory
set disk disk-file-count=2 disk-file-name=log disk-lines-per-file=100 \
    disk-stop-on-full=no name=disk target=disk
set echo name=echo remember=yes target=echo
set remote bsd-syslog=no name=remote remote=0.0.0.0 remote-port=514 \
    src-address=0.0.0.0 syslog-facility=daemon syslog-severity=auto target=\
    remote
/system routerboard settings
set baud-rate=115200 boot-delay=2s boot-device=nand-if-fail-then-ethernet \
    boot-protocol=bootp cpu-frequency=300MHz enable-jumper-reset=yes \
    enter-setup-on=any-key force-backup-booter=no
set baud-rate=115200 boot-delay=2s boot-device=nand-if-fail-then-ethernet \
    boot-protocol=bootp cpu-frequency=300MHz enable-jumper-reset=yes \
    enter-setup-on=any-key force-backup-booter=no
/tool user-manager profile
add name="" name-for-users="" override-shared-users=off price=0 starts-at=now \
    validity=0s
add name="" name-for-users="" override-shared-users=off price=0 starts-at=now \
    validity=0s
add name="" name-for-users="" override-shared-users=off price=0 starts-at=now \
    validity=0s
add name="" name-for-users="" override-shared-users=off price=0 starts-at=now \
    validity=0s
add name="" name-for-users="" override-shared-users=off price=0 starts-at=now \
    validity=0s
/tool user-manager profile limitation
add address-list="" download-limit=0B group-name="" ip-pool="" name="" \
    rate-limit-burst-rx=11000000B rate-limit-burst-time-rx=9s \
    rate-limit-burst-time-tx=9s rate-limit-burst-treshold-rx=3000000B \
    rate-limit-burst-treshold-tx=3000000B rate-limit-burst-tx=11000000B \
    rate-limit-min-rx=3000000B rate-limit-min-tx=3000000B rate-limit-rx=\
    3000000B rate-limit-tx=3000000B transfer-limit=0B upload-limit=0B \
    uptime-limit=0s
add address-list="" download-limit=0B group-name="" ip-pool="" name="" \
    rate-limit-burst-rx=9000000B rate-limit-burst-time-rx=7s \
    rate-limit-burst-time-tx=7s rate-limit-burst-treshold-rx=1000000B \
    rate-limit-burst-treshold-tx=1000000B rate-limit-burst-tx=9000000B \
    rate-limit-min-rx=512000B rate-limit-min-tx=512000B rate-limit-rx=\
    1000000B rate-limit-tx=1000000B transfer-limit=0B upload-limit=0B \
    uptime-limit=0s
add address-list="" download-limit=0B group-name="" ip-pool="" name="" \
    rate-limit-burst-rx=10000000B rate-limit-burst-time-rx=9s \
    rate-limit-burst-time-tx=9s rate-limit-burst-treshold-rx=3000000B \
    rate-limit-burst-treshold-tx=3000000B rate-limit-burst-tx=10000000B \
    rate-limit-min-rx=3000000B rate-limit-min-tx=3000000B rate-limit-rx=\
    3000000B rate-limit-tx=3000000B transfer-limit=0B upload-limit=0B \
    uptime-limit=0s
add address-list="" download-limit=0B group-name="" ip-pool="" name="" \
    rate-limit-burst-rx=10000000B rate-limit-burst-time-rx=9s \
    rate-limit-burst-time-tx=9s rate-limit-burst-treshold-rx=1000000B \
    rate-limit-burst-treshold-tx=1000000B rate-limit-burst-tx=10000000B \
    rate-limit-min-rx=1000000B rate-limit-min-tx=1000000B rate-limit-rx=\
    1000000B rate-limit-tx=1000000B transfer-limit=0B upload-limit=0B \
    uptime-limit=0s
/user group
set read name=read policy="local,telnet,ssh,reboot,read,test,winbox,password,w\
    eb,sniff,sensitive,api,!ftp,!write,!policy" skin=default
set write name=write policy="local,telnet,ssh,reboot,read,write,test,winbox,pa\
    ssword,web,sniff,sensitive,api,!ftp,!policy" skin=default
set full name=full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,\
    winbox,password,web,sniff,sensitive,api" skin=default
/interface bridge port
add bridge=bridge1 disabled=no edge=auto external-fdb=auto horizon=none \
    interface=ether3 path-cost=10 point-to-point=auto priority=0x80
/interface bridge settings
set use-ip-firewall=no use-ip-firewall-for-pppoe=no use-ip-firewall-for-vlan=\
    no
/interface ethernet switch port
set ether2
set ether3
set switch1_cpu
/interface l2tp-server server
set authentication=pap,chap,mschap1,mschap2 default-profile=\
    default-encryption enabled=no max-mru=1460 max-mtu=1460 mrru=disabled
/interface ovpn-server server
set auth=sha1,md5 certificate=none cipher=blowfish128,aes128 default-profile=\
    default enabled=no keepalive-timeout=60 mac-address=FE:19:78:38:0A:C7 \
    max-mtu=1500 mode=ip netmask=24 port=1194 require-client-certificate=no
/interface pppoe-server server
add authentication=pap,chap,mschap1,mschap2 default-profile=2 disabled=no \
    interface=bridge1 keepalive-timeout=10 max-mru=1480 max-mtu=1480 \
    max-sessions=0 mrru=disabled one-session-per-host=no service-name=pppoe
add authentication=pap,chap,mschap1,mschap2 default-profile=default disabled=\
    no interface=ether2 keepalive-timeout=10 max-mru=1500 max-mtu=1500 \
    max-sessions=0 mrru=disabled one-session-per-host=no service-name=\
    service1
/interface pptp-server server
set authentication=mschap1,mschap2 default-profile=default-encryption \
    enabled=no keepalive-timeout=30 max-mru=1460 max-mtu=1460 mrru=disabled
/interface sstp-server server
set authentication=pap,chap,mschap1,mschap2 certificate=none default-profile=\
    default enabled=no keepalive-timeout=60 max-mru=1500 max-mtu=1500 mrru=\
    disabled port=443 verify-client-certificate=no
/interface wireless align
set active-mode=yes audio-max=-20 audio-min=-100 audio-monitor=\
    00:00:00:00:00:00 filter-mac=00:00:00:00:00:00 frame-size=300 \
    frames-per-second=25 receive-all=no ssid-all=no
/interface wireless sniffer
set channel-time=200ms file-limit=10 file-name="" memory-limit=10 \
    multiple-channels=no only-headers=no receive-errors=no streaming-enabled=\
    no streaming-max-rate=0 streaming-server=0.0.0.0
/interface wireless snooper
set channel-time=200ms multiple-channels=yes receive-errors=no
/ip accounting
set account-local-traffic=no enabled=no threshold=256
/ip accounting web-access
set accessible-via-web=no address=0.0.0.0/0
/ip address
add address=10.0.0.45/24 disabled=no interface=ether1 network=10.0.0.0
add address=10.0.11.2/24 disabled=no interface=ether1 network=10.0.11.0
add address=10.0.12.1/24 disabled=no interface=ether2 network=10.0.12.0
add address=10.0.0.7/24 disabled=no interface=ether2 network=10.0.0.0
add address=192.168.0.1/32 disabled=no interface=bridge1 network=192.168.0.1
/ip dhcp-server config
set store-leases-disk=5m
/ip dns
set allow-remote-requests=yes cache-max-ttl=1w cache-size=2048KiB \
    max-udp-packet-size=512 servers=208.67.222.222,196.28.75.220
/ip dns static
add address=10.0.11.2 disabled=no name=ads ttl=1d
/ip firewall connection tracking
set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s \
    tcp-close-wait-timeout=10s tcp-established-timeout=1d \
    tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s \
    tcp-syn-received-timeout=5s tcp-syn-sent-timeout=5s tcp-syncookie=no \
    tcp-time-wait-timeout=10s udp-stream-timeout=3m udp-timeout=10s
/ip firewall nat
add action=masquerade chain=srcnat disabled=no out-interface=ether1
add action=masquerade chain=srcnat disabled=yes out-interface=ether2
/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=no ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061 sip-direct-media=yes
set pptp disabled=no
/ip hotspot service-port
set ftp disabled=no ports=21
/ip neighbor discovery
set ether1 disabled=no
set ether2 disabled=no
set ether3 disabled=no
set bridge1 disabled=no
set wlan1 disabled=yes
set wlan2 disabled=yes
/ip proxy
set always-from-cache=no cache-administrator=webmaster cache-hit-dscp=4 \
    cache-on-disk=no enabled=no max-cache-size=none max-client-connections=\
    600 max-fresh-time=3d max-server-connections=600 parent-proxy=0.0.0.0 \
    parent-proxy-port=0 port=8080 serialize-connections=no src-address=\
    0.0.0.0
/ip route
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.0.11.22 scope=30 \
    target-scope=10
/ip service
set telnet disabled=no port=23
set ftp disabled=no port=21
set www disabled=no port=80
set ssh disabled=no port=22
set www-ssl certificate=none disabled=yes port=443
set api disabled=yes port=8728
set winbox disabled=no port=8291
/ip socks
set connection-idle-timeout=2m enabled=no max-connections=200 port=1080
/ip ssh
set forwarding-enabled=no
/ip traffic-flow
set active-flow-timeout=30m cache-entries=4k enabled=no \
    inactive-flow-timeout=15s interfaces=all
/ip upnp
set allow-disable-external-interface=yes enabled=no show-dummy-rule=yes
/mpls
set dynamic-label-range=16-1048575 propagate-ttl=yes
/mpls interface
add disabled=no interface=all mpls-mtu=1508
/mpls ldp
set distribute-for-default-route=no enabled=no hop-limit=255 loop-detect=no \
    lsr-id=0.0.0.0 path-vector-limit=255 transport-address=0.0.0.0 \
    use-explicit-null=no
/port firmware
set directory=firmware
/ppp aaa
set accounting=yes interim-update=0s use-radius=yes
/queue interface
set ether1 queue=ethernet-default
set ether2 queue=ethernet-default
set ether3 queue=ethernet-default
set wlan1 queue=wireless-default
set wlan2 queue=wireless-default
/radius
add accounting-backup=no accounting-port=1813 address=192.168.0.1 \
    authentication-port=1812 called-id="" disabled=no domain="" realm="" \
    secret=786786 service=ppp timeout=300ms
/radius incoming
set accept=yes port=1700
/routing bfd interface
set all disabled=no interface=all interval=0.2sec min-rx=0.2sec multiplier=5
/routing mme
set bidirectional-timeout=2 gateway-class=none gateway-keepalive=1m \
    gateway-selection=no-gateway origination-interval=5s preferred-gateway=\
    0.0.0.0 timeout=1m ttl=50
/routing rip
set distribute-default=never garbage-timer=2m metric-bgp=1 metric-connected=1 \
    metric-default=1 metric-ospf=1 metric-static=1 redistribute-bgp=no \
    redistribute-connected=no redistribute-ospf=no redistribute-static=no \
    routing-table=main timeout-timer=3m update-timer=30s
/store
add disabled=no disk=system name=user-manager1 type=user-manager
add disabled=no disk=system name=web-proxy1 type=web-proxy
/system clock
set time-zone-name=manual
/system clock manual
set dst-delta=+00:00 dst-end="jan/01/1970 00:00:00" dst-start=\
    "jan/01/1970 00:00:00" time-zone=+00:00
/system console
add disabled=no port=serial0 term=vt102
/system health
set fan-mode=auto use-fan=main
/system identity
set name=MikroTik
/system logging
add action=memory disabled=no prefix="" topics=info
add action=memory disabled=no prefix="" topics=error
add action=memory disabled=no prefix="" topics=warning
add action=echo disabled=no prefix="" topics=critical
/system note
set note="" show-at-login=yes
/system ntp client
set enabled=no mode=broadcast primary-ntp=0.0.0.0 secondary-ntp=0.0.0.0
/system resource irq
set 0 cpu=auto
set 1 cpu=auto
set 2 cpu=auto
set 3 cpu=auto
set 4 cpu=auto
set 5 cpu=auto
set 6 cpu=auto
/system upgrade mirror
set check-interval=1d enabled=no primary-server=0.0.0.0 secondary-server=\
    0.0.0.0 user=""
/system watchdog
set auto-send-supout=no automatic-supout=yes no-ping-delay=5m watch-address=\
    none watchdog-timer=yes
/tool bandwidth-server
set allocate-udp-ports-from=2000 authenticate=yes enabled=yes max-sessions=\
    100
/tool e-mail
set address=0.0.0.0 from=<> password="" port=25 user=""
/tool graphing
set page-refresh=300 store-every=5min
/tool mac-server
set (unknown) disabled=no interface=all
/tool mac-server ping
set enabled=yes
/tool sms
set allowed-number="" channel=0 keep-max-sms=0 receive-enabled=no secret=""
/tool sniffer
set file-limit=1000KiB file-name="" filter-stream=yes interface=all \
    memory-limit=100KiB memory-scroll=yes only-headers=no streaming-enabled=\
    no streaming-server=0.0.0.0
/tool traffic-generator
set latency-distribution-scale=10 test-id=0
/tool user-manager customer
add backup-allowed=yes disabled=no login=admin parent=admin password="" \
    paypal-accept-pending=no paypal-allowed=no paypal-secure-response=no \
    permissions=owner signup-allowed=no time-zone=+00:00
/tool user-manager profile profile-limitation
add from-time=0s limitation="" profile="" till-time=23h59m59s weekdays=\
    sunday,monday,tuesday,friday,saturday
add from-time=0s limitation="" profile="" till-time=23h59m59s weekdays=\
    sunday,monday,tuesday,friday,saturday
add from-time=0s limitation="" profile="" till-time=23h59m59s weekdays=\
    sunday,monday,tuesday,friday,saturday
add from-time=0s limitation="" profile="" till-time=23h59m59s weekdays=\
    sunday,monday,tuesday,friday,saturday
/tool user-manager router
add customer=admin disabled=no ip-address=192.168.0.1 log=auth-fail name=\
    phlox shared-secret=786786
/tool user-manager user
add customer=admin disabled=no name=demo1 password=demo1 shared-users=\
    unlimited wireless-enc-algo=none wireless-enc-key="" wireless-psk=""
[admin@MikroTik] > 
and attached please find supout
You do not have the required permissions to view the files attached to this post.
 
fewi
Forum Guru
Forum Guru
Posts: 7734
Joined: Tue Aug 11, 2009 3:19 am

Re: Breaking my head trying to access yahoo and other https

Thu Nov 10, 2011 3:17 am

Set your MTU and MSS appropriately for a PPPoE connection. See the FAQ on the wiki for how to.
Specific answers require specific questions. When in doubt, post the output of "/ip address print detail", "/ip route print detail", "/interface print detail", "/ip firewall export", and an accurate network diagram.
 
marklodge
Member Candidate
Member Candidate
Topic Author
Posts: 211
Joined: Sun Jun 21, 2009 6:15 pm

Re: Breaking my head trying to access yahoo and other https

Thu Nov 10, 2011 8:29 am

Set your MTU and MSS appropriately for a PPPoE connection. See the FAQ on the wiki for how to.
Wow, that worked!
but i dont understand how it worked tho. because i just set the MTU and MRU on the pppoe service to: 1500 instead of 1480
isnt it supposed to be less, not more?
i am using ubiquiti airmax sectors with rocketm5 and client side nanostation m5. could that also affect the mtu setting?
 
User avatar
savagedavid
Trainer
Trainer
Posts: 310
Joined: Thu Aug 25, 2005 12:58 pm
Location: Cape Town, South Africa
Contact:

Re: Breaking my head trying to access yahoo and other https

Thu Nov 10, 2011 9:19 am

You are probably accessing the internet through a tunneled connection (e.g. PPtP tunneled over PPPoE to deliver public IP's) and that creates problems with MTU/MSS when using another PPPoE connection inside your network
savagedavid
MTCE+T (MikroTik Certified Everything + Trainer)
MikroTik support and training in South Africa
http://www.mikrotiksa.com
david [at] mikrotiksa dot com
 
marklodge
Member Candidate
Member Candidate
Topic Author
Posts: 211
Joined: Sun Jun 21, 2009 6:15 pm

Re: Breaking my head trying to access yahoo and other https

Thu Nov 10, 2011 6:33 pm

You are probably accessing the internet through a tunneled connection (e.g. PPtP tunneled over PPPoE to deliver public IP's) and that creates problems with MTU/MSS when using another PPPoE connection inside your network
i am using ADSL routers in router mode as my gateways. the adsl routers create the pppoe connection to my isp.
is this what you mean?
 
User avatar
savagedavid
Trainer
Trainer
Posts: 310
Joined: Thu Aug 25, 2005 12:58 pm
Location: Cape Town, South Africa
Contact:

Re: Breaking my head trying to access yahoo and other https

Mon Nov 14, 2011 8:23 am

i am using ADSL routers in router mode as my gateways. the adsl routers create the pppoe connection to my isp.
is this what you mean?
Not really, this normally happens with multiple tunnels within. It's always possible that your ISP may be doing something further up the line.

In any event the problem is caused by packet fragmentation and the MSS transform is the accepted method of fixing the issue.
savagedavid
MTCE+T (MikroTik Certified Everything + Trainer)
MikroTik support and training in South Africa
http://www.mikrotiksa.com
david [at] mikrotiksa dot com
 
marklodge
Member Candidate
Member Candidate
Topic Author
Posts: 211
Joined: Sun Jun 21, 2009 6:15 pm

Re: Breaking my head trying to access yahoo and other https

Mon Nov 14, 2011 6:59 pm

i am using ADSL routers in router mode as my gateways. the adsl routers create the pppoe connection to my isp.
is this what you mean?
Not really, this normally happens with multiple tunnels within. It's always possible that your ISP may be doing something further up the line.

In any event the problem is caused by packet fragmentation and the MSS transform is the accepted method of fixing the issue.
thanks very much for the info.
what is the best method of checking for packet fragmentation.
i have been reading about this and i found this: http://www6.nohold.net/Cisco2/ukp.aspx? ... icleid=386

does the MTU setting in the client nanostation affect anything? (screenshot attached)
The max MTU setting on the pppoe-server on the mikrotik is set to 1500 currently.
and its dynamically adding the TCP MSS rule to the mangle at 1452
On this link my ping results show:

C:\Documents and Settings\User>ping -f -l 1500 yahoo.com

Pinging yahoo.com [98.137.149.56] with 1500 bytes of data:

Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.

Ping statistics for 98.137.149.56:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

C:\Documents and Settings\User>ping -f -l 1472 yahoo.com

Pinging yahoo.com [98.137.149.56] with 1472 bytes of data:

Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.

Ping statistics for 98.137.149.56:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

C:\Documents and Settings\User>ping -f -l 1462 yahoo.com

Pinging yahoo.com [98.137.149.56] with 1462 bytes of data:

Reply from 98.137.149.56: bytes=1462 time=457ms TTL=41
Reply from 98.137.149.56: bytes=1462 time=411ms TTL=41
Reply from 98.137.149.56: bytes=1462 time=418ms TTL=41
Reply from 98.137.149.56: bytes=1462 time=440ms TTL=41

Ping statistics for 98.137.149.56:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 411ms, Maximum = 457ms, Average = 431ms

C:\Documents and Settings\User>ping -f -l 1452 yahoo.com

Pinging yahoo.com [98.137.149.56] with 1452 bytes of data:

Reply from 98.137.149.56: bytes=1452 time=432ms TTL=41
Reply from 98.137.149.56: bytes=1452 time=422ms TTL=41
Reply from 98.137.149.56: bytes=1452 time=432ms TTL=41
Reply from 98.137.149.56: bytes=1452 time=430ms TTL=41

Ping statistics for 98.137.149.56:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 422ms, Maximum = 432ms, Average = 429ms

C:\Documents and Settings\User>ping -f -l 1464 yahoo.com

Pinging yahoo.com [98.137.149.56] with 1464 bytes of data:

Reply from 98.137.149.56: bytes=1464 time=428ms TTL=41
Reply from 98.137.149.56: bytes=1464 time=416ms TTL=41
Reply from 98.137.149.56: bytes=1464 time=412ms TTL=41
Reply from 98.137.149.56: bytes=1464 time=414ms TTL=41

Ping statistics for 98.137.149.56:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 412ms, Maximum = 428ms, Average = 417ms

C:\Documents and Settings\User>ping -f -l 1466 yahoo.com

Pinging yahoo.com [98.137.149.56] with 1466 bytes of data:

Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.
Packet needs to be fragmented but DF set.

Ping statistics for 98.137.149.56:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

You do not have the required permissions to view the files attached to this post.

Who is online

Users browsing this forum: maximan and 41 guests