Community discussions

MikroTik App

Search found 48 matches

by mdd
Thu Jan 23, 2025 2:58 pm
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 4
Views: 217

Re: IPSEC multiple policy with p2p

Hi Sindy, From my tests that what i was thinking about these policies - they are like "traffic selectors or markers" Also if i use /32 mask on both ends it will be pretty tight p2p between hosts as i guess (no outside access to other IP address). As for the last part of question as far i u...
by mdd
Thu Jan 23, 2025 11:24 am
Forum: General
Topic: IPSEC multiple policy with p2p
Replies: 4
Views: 217

IPSEC multiple policy with p2p

Hi just wondering as i see it works, but need to be clear on this: I have P2P Ipsec connection and added with 3 x policy from one subnet to different subsets (in pic) and PH2 is all establish with the same p2p ipsec tunnel and it works. I did not found any information if i can use like that. Tried t...
by mdd
Mon Jun 12, 2023 10:14 am
Forum: General
Topic: Twice NAT example
Replies: 12
Views: 1877

Re: Twice NAT example

Ok thank you all for the good discussion. TA least now i have good understanding about this problem and solutions about this kind "twice nat".
by mdd
Fri Jun 09, 2023 2:09 pm
Forum: General
Topic: Twice NAT example
Replies: 12
Views: 1877

Re: Twice NAT example

twice_nat.PNG
Not go too as i have server in a same subnet as a client has in the same subnet ;( Any suggestion welcome again.
I cannot do anything on other side router "BiurasB".
192.168.111.x is server network
is on BiuraA with the same subnet 192.168.1.0/24
by mdd
Thu Jun 08, 2023 3:10 pm
Forum: General
Topic: Twice NAT example
Replies: 12
Views: 1877

Re: Twice NAT example

Thank you dadaniel. I will try your setup on lab if this what i was looking for.
For all yes i know about IP subnet planing, but sometimes you have clients with less knowledge about anything like it. More - they do not want do any change on there network for reason.
by mdd
Tue Jun 06, 2023 2:31 pm
Forum: General
Topic: Twice NAT example
Replies: 12
Views: 1877

Twice NAT example

Hi all, I am trying NAT rules on MK to mimic this Solution #2 – Policy Twice NAT on One side on this article https://www.practicalnetworking.net/stand-alone/vpn-overlapping-networks/ but cant get it working ;( So asking for you all maybe someone has this kind of knowledge how to implement this ? So ...
by mdd
Mon Dec 12, 2022 3:25 pm
Forum: General
Topic: IPSEC + overlaping subnet again [SOLVED]
Replies: 4
Views: 2793

Re: IPSEC + overlaping subnet again [SOLVED]

Thanks Sob for correcting. How the rules be written ?
by mdd
Tue Oct 25, 2022 9:08 am
Forum: General
Topic: IPSEC + overlaping subnet again [SOLVED]
Replies: 4
Views: 2793

Re: IPSEC + overlaping subnet again [SOLVED]

Not sure if i done right, but seems it works. Here if someone needs help about this too. I have added these rules before main outgoing masquerade rule. /ip firewall nat add action=accept chain=srcnat comment="Client" dst-address=10.168.10.0/24 src-address=10.14.0.0/16 to-addresses=10.168.1...
by mdd
Wed Oct 12, 2022 11:49 am
Forum: General
Topic: IPSEC + overlaping subnet again [SOLVED]
Replies: 4
Views: 2793

IPSEC + overlaping subnet again [SOLVED]

Hi all have one question need some advise, as i have very unhelpful client (strong security requirements and no support staff) with ipsec overlapping local sub nets. I have read lots of info and tried few setups, some king of them works half way but not fully (netmap). Does client needs to do any ch...
by mdd
Wed Oct 12, 2022 11:22 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Thank you Sindy help me to get some advance knowleague.
by mdd
Tue Aug 30, 2022 9:42 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Tried to adapt to see what i will be removing with this command line: So use /ip firewall connection print detail where srcnat and protocol=ipsec-esp . But as it is working now, chances are high that this command will also show nothing because the NATed connection has expired in the meantime due to...
by mdd
Mon Aug 29, 2022 4:23 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Where exactly to add this as i am bit now confused. If one of the IPSEC tunnel works, and other dont - how this will affect working one? At worst it would cause a loss of several packets of the working one, until the Mikrotik would send a packet towards the client. Thats not problem :) Tried to /ip...
by mdd
Mon Aug 29, 2022 2:21 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Ok. Some how got working both tunnels now. I have added protocol=!ipsec-esp to my main GW .163
/ip firewall nat
add action=masquerade chain=srcnat comment=GW out-interface=ether1 \
src-address=!10.240.240.250 protocol=!ipsec-esp

For the moment seems working. Not 100% sure why ...
by mdd
Mon Aug 29, 2022 1:50 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

This /ip firewall connection print ... shows that the IPsec stack has bound the connection properly to .163 but the firewall has src-nated it to .162. So do prevent the masquerade rule from acting on ESP by adding a protocol=!ipsec-esp match condition to it as I've suggested in my previous post (it...
by mdd
Mon Aug 29, 2022 9:16 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Hi Sindy,

Still not luck.. one of IPSEC tunnel works at the moment, but other one still not Working one use the right gw ip .163.
Other non working /ip firewall print still show ip with .162 for some reason. Same thing i can see in captured packets.
cap_not_right_ip.PNG
by mdd
Fri Aug 19, 2022 11:23 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

cap_ipsec.PNG One more strange behave ether1 GW has few public IP on it. 162. 163 . 16X. For multiple IPSEC tunnel ends i am trying to use just one .163. For some reason one of IPSEC client .177 using .163 MY GW has established connection and tunnel traffic goes now on both sides // not sure why it...
by mdd
Fri Aug 19, 2022 10:21 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

I am confused. The packet dissection (bottommost picture) shows a packet from the client to your Mikrotik (src-mac-address Cisco, dst-mac-address Mikrotik). That would mean that the ESP traffic is only coming from the client to your Mikrotik as no ESP sent from your address. In such case, it would ...
by mdd
Thu Aug 18, 2022 2:12 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

I have tried to capture, but none packets captured even from IP romete or local IP, or fithout filter :( What this could be. Tried to to flush, to disable and enable IPSEC peers but no packets were captured. Connections still showing establised. ???? What was the exact command line you used for sni...
by mdd
Wed Aug 17, 2022 1:42 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

If the pinging causes the corresponding raw rules to count, it means the traffic does reach your Mikrotik. Ping echo packets are send from my Router, but never gets back. Just to clear. If the the corresponding installed-sa (from your public address to client's one) also counts as you ping, the IPse...
by mdd
Tue Aug 16, 2022 4:17 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

When we do ping on tunnel's end point we are getting only counters increased from our side to remote side on RAW rules. I have added some of configuration here ips/subnets randomly created here for public view. /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroT...
by mdd
Fri Aug 12, 2022 10:51 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Hi Sindy, From that behave and all forums i have read about king of this isues maybe NAT rules affecting the traffic (just presuming). But i have made RAW rules that NAT not be involved in translation. But counters of these rules never grow when no traffic go in/out. Tunnel allways eshablished. /ip ...
by mdd
Wed Aug 10, 2022 9:43 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Have two ipsec tunels setups with clients: (clients side can not check, but they say that all other existing tunnels works fine for them only with mine are problems) Can find what is the issue on my side :( On my side > /ip ipsec statistics print in-errors: 0 in-buffer-errors: 0 in-header-errors: 0 ...
by mdd
Tue Aug 09, 2022 3:34 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Unfortunately the issue still exis :( Traffics goes one way (seems to me by counters on rules incress) RAW.PNG when pingin remote. Again were working for few days after disabled/enable peers tunnel is up but no traffic passing. Pinging from 10.254.0.0/24. Any suggestion how to trace this traffic by ...
by mdd
Wed Jun 22, 2022 3:21 pm
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

ok guys found what the issue was - hw could not coupe with high encryption levels. Now when we change encryption to lover settings it works.
by mdd
Mon May 09, 2022 11:34 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

2Sindy - yes they are both on pub IPs. Input chaings are added to accept ESP. 2memelchenkov - select "none" in profiles PFS. I will wait until other side will change this too to see if this helps. No i am using 6.45.9 version, but other side use newer version - this what worries me more as...
by mdd
Fri May 06, 2022 8:28 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

Re: P2P IPSEC strange behavere [SOLVED]

Any advise at least how to troubleshoot or look for the issues ?
by mdd
Wed May 04, 2022 9:09 am
Forum: General
Topic: P2P IPSEC strange behavere [SOLVED]
Replies: 31
Views: 3778

P2P IPSEC strange behavere [SOLVED]

Hi All, Have strange issue with IPSEC P2P setup. All works for a while and after random time tunnel traffic just not forwarding any more. The ipsec says connection established but no traffic getting in/out. And if i try disable peers and policy and after re-enable them - traffic starts forwarding, b...
by mdd
Thu Jan 28, 2021 3:14 pm
Forum: General
Topic: IKEv2 setup + WIN10 built-in client cannot connect anymore [SOLVED]
Replies: 4
Views: 3324

Re: IKEv2 setup + WIN10 built-in client cannot connect anymore [SOLVED]

Yep thats WIN10 issues with Metro GUI. Sorted out now. Thanks all.
by mdd
Thu Jan 28, 2021 2:44 pm
Forum: General
Topic: IKEv2 setup + WIN10 built-in client cannot connect anymore [SOLVED]
Replies: 4
Views: 3324

Re: IKEv2 setup + WIN10 built-in client cannot connect anymore [SOLVED]

Ok good people. One thing i have found out already is that WIN10 issues. For some reason service was disabled "IKE and AuthIP IPsec Keying Modules" and when i enabled and started VPN trys connecting now and hits the Router... As always but... event if i change on adapter configuration and ...
by mdd
Thu Jan 28, 2021 1:51 pm
Forum: General
Topic: IKEv2 setup + WIN10 built-in client cannot connect anymore [SOLVED]
Replies: 4
Views: 3324

IKEv2 setup + WIN10 built-in client cannot connect anymore [SOLVED]

Hello all good people. Just this day realized that i cannot connect to my office using setup, which was working fine before. I have Mikrotik Router setup with IKEv2 vpn. All my clients use win10 build-in client with cert login without password. And now when i trying connect - get this message "...
by mdd
Fri Jun 14, 2019 12:52 pm
Forum: Wireless Networking
Topic: AP and 2 repeaters in one line [SOLVED]
Replies: 2
Views: 1802

Re: AP and 2 repeaters in one line [SOLVED]

Its seems this did helped. Thank you! All the best!
by mdd
Fri Jun 14, 2019 11:29 am
Forum: Wireless Networking
Topic: Netmetal ac triple + 3 omnidireccional antena. Is posible?
Replies: 4
Views: 1726

Re: Netmetal ac triple + 3 omnidireccional antena. Is posible?

Hi i was thinkign about similar setuo but with different configuration anntenas:

1 x Ubiquiti Air Max 13dBi 5GHz DualOmni Antenna (AMO-5G13) connect to two RSPMA
1 x Normal Antenna Omnit connect to last ont RSPMA but pointig down.

Interesting what whould be ?
by mdd
Tue Jun 04, 2019 11:06 am
Forum: Wireless Networking
Topic: AP and 2 repeaters in one line [SOLVED]
Replies: 2
Views: 1802

AP and 2 repeaters in one line [SOLVED]

Hello all, Not sure what this is but i need some help. I have 1 mANTBox 2 12s setup in AP mode and 2 basebox 2 as repeaters setup in 300 m. AP1-------RP2--------RP1 What i am trying to do is to connect those 2 repeaters to AP. Few time i have successfully connected but most of the time 1 reapeter co...
by mdd
Tue Mar 12, 2019 11:29 am
Forum: Wireless Networking
Topic: Water getting into basebox 2s and 5s
Replies: 2
Views: 988

Re: Water getting into basebox 2s and 5s

Hi guys we have similar issues. But in our case we think it is condensation. So weather this year was mixing between cold and warm and this gave us few device dead because of this. Not sure if this a case of condensation, or leaky leds. We needs to be checked.
by mdd
Fri Mar 08, 2019 10:48 am
Forum: Wireless Networking
Topic: CAPsMAN and mobile phones wifi
Replies: 0
Views: 834

CAPsMAN and mobile phones wifi

Hi all, We have CAMsMAN install for our wifi network. Few weeks ago we notice some strange behavior of our guest SSID. The previously used mobile phones connects to guest wifi without any issue, but the phones never used on the network cannot get to internet. I have checked IP on the phone it looks ...
by mdd
Tue Jan 15, 2019 3:54 pm
Forum: Wireless Networking
Topic: CAPsMAN remote access mac and ip
Replies: 1
Views: 1211

CAPsMAN remote access mac and ip

Hello i have general question about why i see in CAPSMAN-> RemoteCAP |Address| bar two types of it: MAC address and IP address.
Remote CAPs working fine, but i still want to know if there arent an issue and not suppose to be like that? Could someone explain for me ?
by mdd
Wed Oct 17, 2018 3:47 pm
Forum: General
Topic: Useless Syslog messages
Replies: 8
Views: 3579

Re: Useless Syslog messages

Hi i just have one small suggestion about logs in mikrotik window. It would be nice to have filter feature on log in real time on winbox (similar watchguard fw windows tools). It would save a lot of time to digging ports access or specific ips acces on logs when you need most. At the moment you can ...
by mdd
Thu Sep 13, 2018 11:31 am
Forum: Beginner Basics
Topic: VoIP issues [SOLVED]
Replies: 5
Views: 2519

Re: VoIP issues [SOLVED]

Thank you all. After disabled SIP Helper all works now fine.
by mdd
Fri Sep 07, 2018 8:30 am
Forum: Beginner Basics
Topic: Open VPN Clarification
Replies: 2
Views: 916

Re: Open VPN Clarification

Hi,

It will hold those 10 users. Just make sure it has good bandwidth. later you just keep an i eye on resource.
by mdd
Wed Sep 05, 2018 4:01 pm
Forum: Beginner Basics
Topic: VoIP issues [SOLVED]
Replies: 5
Views: 2519

Re: VoIP issues [SOLVED]

It happens just for some calls not for all (70 cisco phones). Just randomly from different network places where the phones are. I have added on switches qos for voice vlan prority 7. But the issue still exists. Trying to sniff out as phone service provider suggested to turn of ALG too. Bandwidth i h...
by mdd
Tue Sep 04, 2018 3:54 pm
Forum: Beginner Basics
Topic: VoIP issues [SOLVED]
Replies: 5
Views: 2519

Re: VoIP issues [SOLVED]

Hi flyno,

After i disabled it lost all device registration. What next step could be ?
by mdd
Mon Sep 03, 2018 11:09 am
Forum: Beginner Basics
Topic: VoIP issues [SOLVED]
Replies: 5
Views: 2519

VoIP issues [SOLVED]

Hello, Network: Voip provided by external provider and all hard phones are provisioned from service providers server. Mikrotik egde routers CCRXX. VLAN for voip are created. On all swithes (HP 23xx). The voip issue we have are: when calls comes in to hard phone and the person picks up the phone - yo...
by mdd
Thu Aug 16, 2018 9:52 am
Forum: Wireless Networking
Topic: Best LTE Router (based on your experience)
Replies: 10
Views: 3602

Re: Best LTE Router (based on your experience)

Ok this would not fit my purpose (2in1). But as i got some information it will be good for rural area to get connected to 4g/lte. Thanks again gotprings for nice conversation. Now i have all answers.
by mdd
Wed Aug 15, 2018 6:39 pm
Forum: Wireless Networking
Topic: Best LTE Router (based on your experience)
Replies: 10
Views: 3602

Re: Best LTE Router (based on your experience)

What about this SXT LTE kit ? Could this be used too for the same purpose ?
by mdd
Wed Aug 15, 2018 10:39 am
Forum: Wireless Networking
Topic: Best LTE Router (based on your experience)
Replies: 10
Views: 3602

Re: Best LTE Router (based on your experience)

Thanks for update gotsprings!!!
I was looking something modem/router 4g/lte based on mikrotik (2in1) for remote client to get connected to internet without dedicated 4g/lte modem + extra tik router.
So i am guessing i will need to try same setup like you have and see how it goes. Hope it will work.
by mdd
Tue Aug 14, 2018 1:55 pm
Forum: Wireless Networking
Topic: Best LTE Router (based on your experience)
Replies: 10
Views: 3602

Re: Best LTE Router (based on your experience)

Can we use RBwAPR-2nD&R11e-LTE as modem/router for 4G/LTE connection ?
by mdd
Fri Jun 08, 2018 8:20 am
Forum: Wireless Networking
Topic: Wireless AP in container ship yard
Replies: 2
Views: 1378

Re: Wireless AP in container ship yard

Hi Petri, RB are attched next to annthena (dual eggs) on pole (30cm cables). From RB lan cable goes to coms cabinet the lenght is just 20m. All coms cabinets are connected to distribution switch with fibre cables. So cables not giving any issues. I was trying to play with TX power and channels selec...
by mdd
Wed Jun 06, 2018 10:45 am
Forum: Wireless Networking
Topic: Wireless AP in container ship yard
Replies: 2
Views: 1378

Wireless AP in container ship yard

Hi all this is my first post to this forums. So i am sorry if i will be incorrect on some things or words. The situation i am having is that i have poor wireless performance (sometimes loosing to much packets) in in ship yard between container storage areas: AP (912UAG-2HPnD) with antennas are locat...