Community discussions

MikroTik App

Search found 1089 matches

by Caci99
Thu Nov 21, 2024 12:42 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1630
Views: 434398

Re: 📣 WinBox 4 is here 📣

Anyone experiencing flickering screen when winbox window is in background and you move the mouse around? It is very common to open winbox and then work on another window but the winbox window keeps flickering and is quite annoying. Not possible to attach screenshot, and strangely enough even the na...
by Caci99
Wed Nov 20, 2024 10:22 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1630
Views: 434398

Re: 📣 WinBox 4 is here 📣

Anyone experiencing flickering screen when winbox window is in background and you move the mouse around? It is very common to open winbox and then work on another window but the winbox window keeps flickering and is quite annoying. Not possible to attach screenshot, and strangely enough even the nat...
by Caci99
Wed Sep 18, 2024 9:23 pm
Forum: Announcements
Topic: Question to our users about controllers
Replies: 82
Views: 69849

Re: Question to our users about controllers

1) Are you interested in a central controller for MikroTik devices? Sure, mostly for wireless because that is commonly the case where one would find a lot of devices on the same network, but managing a bunch of SwOS would be good as well. If we are talking about managing devices across different si...
by Caci99
Thu Aug 29, 2024 11:30 am
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1630
Views: 434398

Re: 📣 WinBox 4 is here 📣

In general I do not get that exited about new looks, but it is nice to see some effort put into it. Obviously, as mentioned in the opening post, there are functionalities that are not there yet. Two suggestion I have at the first glance 1. when entering the field of user and password at first window...
by Caci99
Mon Jun 10, 2024 11:42 am
Forum: General
Topic: Little hicckup IPSec tunnel ROS 7.15
Replies: 0
Views: 852

Little hicckup IPSec tunnel ROS 7.15

I experienced some weird behavior when moving from 6.49.13 to 7.15 with IPSec site to site tunnel. Generally being cautious when moving from 6.49 to 7.x last week I did such upgrade for the purpose of moving capsman to wifi wave2. It all went smooth, with the exception of IPSec tunnel. This tunnel w...
by Caci99
Fri Feb 02, 2024 1:44 pm
Forum: Announcements
Topic: Newsletter #116 | January 2024
Replies: 106
Views: 37309

Re: Newsletter #116 | January 2024

.. CRS is a switch, why do you need RAM at all in there ? How about buffering? When you connect two switches via SFP and the main traffic is at one port, a server for example, there are too many TX pauses because the switches between them see the connection at 10GB, but the ethernet where the major...
by Caci99
Mon Jan 15, 2024 1:29 pm
Forum: General
Topic: User poll about using Winbox
Replies: 107
Views: 111281

Re: User poll about using Winbox

About point 3
One thing that comes to mind, is to not save sessions which are <own>. That way if one wants to assign a self defined session is easier to pick it up from the drop down menu of sessions instead of scrolling.
Screenshot 2024-01-15 122334.jpg
by Caci99
Mon Jan 15, 2024 10:25 am
Forum: General
Topic: User poll about using Winbox
Replies: 107
Views: 111281

Re: User poll about using Winbox

1. Yes 2. I use sessions a lot in saving windows and column widths on particular routers. For example in core routers I use it to have always queues and firewall in first view, on capsman routers I set it to view capsman window at first opening etc. 3. No opinion right now 4. I guess it does, ones y...
by Caci99
Sat Aug 19, 2023 11:37 pm
Forum: Announcements
Topic: SwOS Lite version 2.17 released!
Replies: 20
Views: 106155

Re: SwOS Lite version 2.17 released!

Long long overdue, when was the last update? Two years ago?
But we need SWOS update as well, not only lite.
by Caci99
Fri Jun 16, 2023 10:29 am
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 366
Views: 139857

Re: v7.10 [stable] is released!

What fix are you referring to? This release has several fixes on wifi wave2. Clients can not connect WiFi only reboot will help. Check forum there is plenty of reports. That is a very general statement you are stating. There are plenty of reports but not all can be attributed to ROS, many can be mi...
by Caci99
Thu Jun 15, 2023 4:16 pm
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 366
Views: 139857

Re: v7.10 [stable] is released!

Fix for WiFi will be in 7.11 so stay at 7.8
What fix are you referring to? This release has several fixes on wifi wave2.
by Caci99
Wed Nov 17, 2021 10:41 pm
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 138
Views: 84668

Re: v6.49.1 [stable] is released!

There is still a risk you can be locked out by some malicious employers who can have physical access. I If you take security seriously, all network equipment and servers etc should be in a locked space. Would you place a server outside in public, no. Just with an usb emulating mouse or keyboard you...
by Caci99
Wed Nov 17, 2021 9:08 pm
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 138
Views: 84668

Re: v6.49.1 [stable] is released!

*) routerboot - enabling "protected-routerboot" feature requires a press of a button; Finally!! I have been talking multiple times to Mikrotik about this since long. Glad they took some measures now. There is still a risk you can be locked out by some malicious employers who can have phys...
by Caci99
Sat Oct 09, 2021 4:30 pm
Forum: Announcements
Topic: v6.48.5 [long-term] is released!
Replies: 167
Views: 113187

Re: v6.48.5 [long-term] is released!

Mikrotik has more options, yes...But only non functionality feature! That is stretching the reality by quite some lengths beyond imagination. I do run small and big networks based on Mikrotik and hardly can recall any bug impacting the network, performance wise there are things I wish they can do b...
by Caci99
Sat Oct 09, 2021 10:15 am
Forum: Announcements
Topic: v6.48.5 [long-term] is released!
Replies: 167
Views: 113187

Re: v6.48.5 [long-term] is released!

I think it has been already discussed a lot about the change log of long term releases. What they will put in the forum as change log is the change to the latest stable version from which the long term has derived. If one wants to see the whole change from the latest long term release you can find i...
by Caci99
Thu Aug 26, 2021 11:37 am
Forum: Announcements
Topic: WinBox v3.29 released!
Replies: 113
Views: 38596

Re: WinBox v3.29 released!

Unfortunately the bug that occurs when holding down mousebutton on a window which is frequently updated, e.g. to change column width or to move a line up or down, is still present! It has been reported so many times already and I think it also was reproduced at MikroTik, please fix it. (back to ver...
by Caci99
Wed Sep 23, 2020 1:14 pm
Forum: Announcements
Topic: v6.47.4 [stable] is released!
Replies: 68
Views: 39555

Re: v6.47.4 [stable] is released!

do you use doh (dns over https) ? it will reduce the amount of your memory No I don't use it. The router has standard DNS servers and barely uses DNS at all. (it is not a resolver for other systems in the network) I have located the problem and will inform MikroTik in de support case I had opened f...
by Caci99
Wed Jun 03, 2020 10:26 am
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 348
Views: 181074

Re: v6.47 [stable] is released!

!) dns - added client side support for DNS over HTTPS (DoH) (RFC8484);
Does this mean we will see the end of filtering via DNS anytime soon?
by Caci99
Thu Apr 02, 2020 12:46 pm
Forum: RouterBOARD hardware
Topic: netPower 15FR, powering it up
Replies: 0
Views: 2731

netPower 15FR, powering it up

I put my hands on netPower 15FR for first time and trying to figure out how it can be deployed. In my lab I am using Hex PoE, CRS112-8P, hAP AC2 and netPoer 15FR. My first test was powering from CRS112 in one of the receiving 15 interfaces and then connect hex poe and hap ac2. The hex poe was connec...
by Caci99
Wed Mar 18, 2020 6:22 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 88171

Re: Winbox v3.22 released!

Shift+Ins in Terminal works at least in Wine for MacOS.
One learns a new thing everyday. Thanks Chupaka for the tip :)
by Caci99
Fri Jan 31, 2020 12:47 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 86
Views: 95545

Re: v6.45.8 [long-term] is released!

If you check from winbox the change log that appears at /system package you will see that it has all changes since 6.45. Is there a better way to alert a user about the change log? No indeed, but do you mind to consider cli-only setups? Mikrotik site is the default place for changelogs as for me an...
by Caci99
Fri Jan 31, 2020 12:41 pm
Forum: General
Topic: hAP ac^2 performance drop
Replies: 9
Views: 3579

Re: hAP ac^2 performance drop

What kind of test are you doing? Have you checked, filters, fast track, bridge, etc..?
That does not look good, looks like a case to write to support.
by Caci99
Thu Jan 30, 2020 11:01 am
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 86
Views: 95545

Re: v6.45.8 [long-term] is released!

17 answers and none about the release. It probably means that the release is stable indeed :D All this discussion should be put in another topic guys if you are unhappy about the release channels and how are those named. If you check from winbox the change log that appears at /system package you wil...
by Caci99
Wed Dec 04, 2019 8:38 pm
Forum: Announcements
Topic: v6.46 [stable] is released!
Replies: 113
Views: 72362

Re: v6.46 [stable] is released!

Big issue!
After the upgrade hap ac2 (RouterBOARD D52G-5HacD2HnD-TC) - stopped working any wi-fi (2 and 5 GHz)!
After downgrade to 6.45.7 - wi-fi work fine.
No issues at all for me, upgraded two hAP AC2 fine, one has a lot of configurations as well (ipsec, qos, etc..).
by Caci99
Sat Nov 02, 2019 10:09 am
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 75247

Re: v6.44.6 [long-term] is released!

there must be a problem with LtAP and 6.44.6 i have a raspberry connected to eth0 (the LtAP is powered over POE) .... everytime when i restart the raspi ... i see a eth up/down/up/down ... and no DHCP IP is assigned. When i disable the eth port for 1-2 minutes .... then enable the eth port ... then...
by Caci99
Fri Nov 01, 2019 4:39 pm
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 75247

Re: v6.44.6 [long-term] is released!

to Caci99
All customers use L2TP/IPsec and OVPN, but there is a Keenetic-4GII which has only PPTP!
PPTP is dependable on GRE. They have changed how GRE handles first packets ( version 6.44.3 maybe ).
If you go to that topic you will see some workarounds how to handle the GRE connections.
by Caci99
Fri Nov 01, 2019 10:32 am
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 75247

Re: v6.44.6 [long-term] is released!

I had a problem after upgrade on LtAP with DHCP Server and the raspberry on the ETH Port. I took 2-3 LtAP reboots so that the Raspberry finally got a IP adresse from DHCP ( always ETH down/ETH up/ETH down/ETH up ....) Richard Those are symptoms of no synchronization between the two ethernet interfa...
by Caci99
Fri Nov 01, 2019 10:30 am
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 75247

Re: v6.44.6 [long-term] is released!

Hello ! After upgrading from 6.44.2 to 6.44.6, the PPTP stopped working. L2TP and OpenVPN work well. RouterBOARD 750G r3.
Glad that PPTP does not work. It is so outdated and unsecured that undoes the purpose of VPN. Stick to L2TP with IPSEC or OpenVPN.
by Caci99
Wed Oct 30, 2019 4:58 pm
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 75247

Re: v6.44.6 [long-term] is released!

Hi, I am sorry, I have maybe dumb question, I am new here, I tried to find out why don't see in upgrades this "long-term" version. I have RB962UiGS-5HacT2HnT hAP running on 6.42.11 and in winbox I see that it is actual or latest version. Is it correct? I have some problems with IPSec/IKEv...
by Caci99
Wed Oct 30, 2019 11:17 am
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 75247

Re: v6.44.6 [long-term] is released!

hAP ac2 on 5g Tx rate picks up very slowly after a device is connected. If the freq. is set to auto, it thinks a lot about detecting radar, i gave up and put it on a non DFS channel. Ping seems fine, ill play with it more tomorrow and add to this reply if I find anything wrong. As far as I know, th...
by Caci99
Mon Oct 07, 2019 8:54 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 36
Views: 16864

Re: MikroTik MQS

Great. How about the wifi configuration? It let configure SSID and PSK with AES only? The Ethernet interface I believe that is fast Ethernet, in any case Gigabit. Right? Thanks for share your first impressions with us. Regards. The OS is quite limited, still version 1.1. But wifi configuration is i...
by Caci99
Mon Oct 07, 2019 12:21 pm
Forum: RouterBOARD hardware
Topic: MikroTik MQS
Replies: 36
Views: 16864

Re: MikroTik MQS

I got one MQS in hand and here are my first impressions: The MQS for some reason will not power up from CRS112-8P-4S which I have in my lab from poe-in using straight or cross over cable, but it will power up from rb260GSP Using a Power bank at my hand, one rated at output 5V x1A, MQS does power up ...
by Caci99
Sat Oct 05, 2019 12:09 pm
Forum: Virtualization
Topic: VPS, experiences on running CHR on VPS [SOLVED]
Replies: 8
Views: 23874

Re: VPS, experiences on running CHR on VPS [SOLVED]

I started with debian machine and then just overwrote system disk with ROS image. They issue coupons worth 10€ so you can try yourself before purchasing. Thank you guys I managed to do it with Aruba, but I would guess it can be done with any other VPS provider. I installed first Debian and then fla...
by Caci99
Fri Oct 04, 2019 11:17 am
Forum: Virtualization
Topic: VPS, experiences on running CHR on VPS [SOLVED]
Replies: 8
Views: 23874

Re: VPS, experiences on running CHR on VPS [SOLVED]

As It's just for private use (holding several VPN tunnels with low traffic + dude) the smallest one for 2.79€/month is more than enough.
Are you using Linux as a template with virtualbox? Can virtualbox run at 64 bit?
by Caci99
Thu Oct 03, 2019 9:20 pm
Forum: Virtualization
Topic: VPS, experiences on running CHR on VPS [SOLVED]
Replies: 8
Views: 23874

Re: VPS, experiences on running CHR on VPS [SOLVED]

Which option have you picked up there? Which is the most economical one for CHR?
by Caci99
Thu Oct 03, 2019 2:44 pm
Forum: Virtualization
Topic: VPS, experiences on running CHR on VPS [SOLVED]
Replies: 8
Views: 23874

VPS, experiences on running CHR on VPS [SOLVED]

I am thinking on running a CHR on VPS, mostly for vpn connections for customers who do not have public IP and want to access their resources. It maybe run as dude server as well. But it is not easy to find a reliable VPS service who can offer full virtualization in order to run CHR as I found out. A...
by Caci99
Fri Aug 30, 2019 8:28 pm
Forum: Announcements
Topic: v6.45.5 [stable] is released!
Replies: 53
Views: 53672

Re: v6.45.5 [stable] is released!


Where is the procedure detailed on how firewall rules are automatically created?

-tp
I didn't say it exists, I said they can implement it.
by Caci99
Fri Aug 30, 2019 2:46 pm
Forum: Announcements
Topic: v6.45.5 [stable] is released!
Replies: 53
Views: 53672

Re: v6.45.5 [stable] is released!

There is no bug. It just got fixes some Versions ago. "The accuracy of your information could be sucessfully questioned". You are right that the bug consisting in having the firewall too open for GRE was fixed, but bundled with this fix came another bug - the very first GRE packet of a ne...
by Caci99
Sat Aug 10, 2019 2:52 pm
Forum: Announcements
Topic: Newsletter #90
Replies: 55
Views: 42301

Re: Newsletter #90

Normis: June news repost Ok, it's amazing that the CCR1072 is still the biggest Hard, I'm a fan of Mikrotik, but in the ISP where I work, we are with a troughput of almost 20Gb, reaching almost saturate some 10Gb interfaces and with a CPU that peeks already 50% (it's a BGP core) and I have nothing ...
by Caci99
Wed Aug 07, 2019 10:14 am
Forum: Announcements
Topic: Newsletter #90
Replies: 55
Views: 42301

Re: Newsletter #90

... Of course. But, I was refering to 2.4GHz QRT2 vs 2.4GHz LHG XL 52 ac. Is it possible that I could potentially see improvement in that area, if 5GHz option fails ? Not necessary. If I recall it correct, LHG shoud be a bigger antenna than QR2, that means a narrower beam distribution. It depends o...
by Caci99
Tue Aug 06, 2019 8:24 pm
Forum: General
Topic: to delete
Replies: 2
Views: 1263

Re: MT PPTP Client host not pinging remote lan

Can remote host 10.2.1.233 ping your MT?
Try masquerade without specifying out-interface.
by Caci99
Tue Aug 06, 2019 8:14 pm
Forum: Announcements
Topic: Newsletter #90
Replies: 55
Views: 42301

Re: Newsletter #90

Would pair of LHG XL 52 ac be decent replacement for pair of QRT2, for PtP ? Using QRT2s because of tree foliage, haven't tried 5GHz yet in those conditions. 5GHz is more prone to obstacles than 2.4GHz, it is already lucky that your link works behind foliage, usually it is a big problem for wireles...
by Caci99
Thu Jun 06, 2019 6:48 pm
Forum: RouterBOARD hardware
Topic: cAP lite - POE (passive or 802.3af/at)
Replies: 9
Views: 5890

Re: cAP lite - POE (passive or 802.3af/at)

My guess is the PD has the resistance installed on another pair from where the PSE sends the signal, thus not detecting PoE on the device and not powering it up. By doing a crossover cable, the signal gets response and powers it up.
by Caci99
Thu Jun 06, 2019 9:36 am
Forum: RouterBOARD hardware
Topic: cAP lite - POE (passive or 802.3af/at)
Replies: 9
Views: 5890

Re: cAP lite - POE (passive or 802.3af/at)

I had the same issue trying to power up a cAP Lite with a Longse LS-RT2412. Decided to use a Cross Over cable and lo and behold, the cAP Lite powers up. There got to be some issues on how these switches detect the device, otherwise I don't see why a cross over cable works and a straight one does not.
by Caci99
Thu May 23, 2019 9:42 pm
Forum: SwOS
Topic: Problems with SFP
Replies: 3
Views: 3919

Re: Problems with SFP

It is the case to write to mikrotik support. Sounds like drivers are missing.
by Caci99
Thu May 23, 2019 12:18 pm
Forum: SwOS
Topic: Problems with SFP
Replies: 3
Views: 3919

Re: Problems with SFP

Have you tried to change the auto negotiation option?
by Caci99
Wed May 15, 2019 1:42 pm
Forum: Wireless Networking
Topic: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message
Replies: 23
Views: 9234

Re: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message

I've noticed this behavior on a capsman I was configuring with wsap and cAP AC. I noticed some of the interfaces were labeled with "i" (inactive) on the winbox list. I disabled the DFS on the configuration and that solved the problem. If your APs are close to each other and DFS enabled the...
by Caci99
Wed May 15, 2019 1:21 pm
Forum: Announcements
Topic: v6.43.15 [long-term] is released!
Replies: 17
Views: 19383

Re: v6.43.15 [long-term] is released!

Support got back really fast. No wonder. Memory leak in "long-term" (previously "bug-fix") branch is ridiculous failure of their QA team. I find it sad if we can't rely even on the most stable branch. Maybe its time to offer money for better support? If the fee is reasonable, I ...
by Caci99
Sat Mar 23, 2019 10:33 am
Forum: General
Topic: IPSEC same peer, two networks
Replies: 3
Views: 1461

Re: IPSEC same peer, two networks

Hello emils,
I did try your suggestion without waiting for Monday to contact the other part and it worked :)
Thank you
Now back to wiki to understand better what level=unique means
by Caci99
Fri Mar 22, 2019 11:54 pm
Forum: General
Topic: IPSEC same peer, two networks
Replies: 3
Views: 1461

Re: IPSEC same peer, two networks

The other end is a watchguard firebox.
I can not try this today unfortunately, only from Monday.
Will come back with results.
by Caci99
Fri Mar 22, 2019 1:13 pm
Forum: General
Topic: IPSEC same peer, two networks
Replies: 3
Views: 1461

IPSEC same peer, two networks

Hello I am trying to build an IPSEC IKE1 between two peers. One of the peers has two networks: /ip ipsec policy src-address=192.168.1.0/24 src-port=any dst-address=192.168.0.0/24 dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes sa-src-address=90.90.90.90 sa-dst-a...
by Caci99
Tue Mar 12, 2019 11:30 am
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 102794

Re: v6.44 [stable] is released!

Is it ok that we have < 3 MB of free space on our 16 MB devices after update?
It depends on your files, for example on mine Hap ac lite there is nearly 4MB. On these boards the update package is saved on RAM instead of HDD.
by Caci99
Wed Feb 13, 2019 7:35 pm
Forum: Announcements
Topic: v6.42.12 [long-term] is released!
Replies: 27
Views: 27618

Re: v6.42.12 [long-term] is released!

This is the end Mikrotik! Regulation got u by the balls. With antenna gain and TX limitation there is no way to use Mikrotik wireless devices anymore unless u stick to a version prior to these awful changes. Even if I would tend to see the root of these changes outside of Mikrotik the devices are c...
by Caci99
Mon Dec 24, 2018 8:05 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 87027

Re: v6.43.8 [stable] is released!

why not just change the country to "no country" instead of switching to regulatory??? Let me guess... Because someone set 'country' value for some reason? :) Of course, because as long as the rules were respected, many ISPs like me respected them, now that the collapse is now total, we ha...
by Caci99
Mon Dec 24, 2018 3:18 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 87027

Re: v6.43.8 [stable] is released!

You are right that there could have been two ways to adjust the inaccurate setting for some users. We chose to adjust towards compliance, not towards incompliance. If user has set a country, he possibly wanted to be compliant already. I've CPE scheduled to autoupgrade via scheduler script "/sy...
by Caci99
Fri Dec 21, 2018 12:02 pm
Forum: Announcements
Topic: MikroTik News December 2018 (Issue #86)
Replies: 25
Views: 24775

Re: MikroTik News December 2018 (Issue #86)

The PWR AP is an interesting product, but I would love to see it in 5GHz instead of 2.4GHz. We are slowly starting to ditch 2.4 APs in every solution. How to you limit the area of coverage of this product? If it is transmitting through power lines, what stops it to go to the neighbor apartment? . P...
by Caci99
Wed Dec 19, 2018 8:51 pm
Forum: Announcements
Topic: MikroTik News December 2018 (Issue #86)
Replies: 25
Views: 24775

Re: MikroTik News December 2018 (Issue #86)

The PWR AP is an interesting product, but I would love to see it in 5GHz instead of 2.4GHz. We are slowly starting to ditch 2.4 APs in every solution.
How to you limit the area of coverage of this product? If it is transmitting through power lines, what stops it to go to the neighbor apartment?
by Caci99
Mon Dec 17, 2018 11:20 pm
Forum: Wireless Networking
Topic: Bridge port received packet with own address as source, probably loop
Replies: 54
Views: 148204

Re: Bridge port received packet with own address as source, probably loop

I decided to update my hAP ac Lite to 6.43.7 today. It is running for more than 12 hours now and I haven't noticed any message in the log about this issue. I don't have a remote syslog to save all logs, but it looks like the issue is solved. Also, looking at versions change log Mikrotik has made som...
by Caci99
Fri Dec 14, 2018 12:41 pm
Forum: Wireless Networking
Topic: Bridge port received packet with own address as source, probably loop
Replies: 54
Views: 148204

Re: Bridge port received packet with own address as source, probably loop

Well, receiving a packet with same mac address is definitely a loop. The issue here is how to analyze the loop apart from the obvious checking mac addresses of the interfaces. In my opinion this is related whenever you have bridge interfaces created, be it STP, RSTP or none. The learning of the mac-...
by Caci99
Tue Dec 11, 2018 9:56 pm
Forum: Wireless Networking
Topic: CAPsMAN errors in log
Replies: 11
Views: 19080

Re: CAPsMAN errors in log

I encountered this weird issue today as well. I was trying to add to the Capsman running on RB2011UiAS-2HnD its own wireless interface. Bridge was created with interfaces from eth2 to eth10 in it. The reason why you see "removing stale connection..." in logs, is because the Cap disconnects...
by Caci99
Tue Dec 04, 2018 12:46 pm
Forum: General
Topic: Simple Queue Parenting Graphical Representation [SOLVED]
Replies: 4
Views: 2449

Re: Simple Queue Parenting Graphical Representation [SOLVED]

Just select parent option on the simple queue, it is on the second tab of simple queue configuration.
by Caci99
Thu Nov 22, 2018 10:34 pm
Forum: General
Topic: dhcp snooping and netinstall
Replies: 0
Views: 983

dhcp snooping and netinstall

Hello
Has anyone had trouble with netinstall after enabling dhcp snooping on the bridge?
In my lab, router can not find netinstall server every time I enable dhcp snooping on the bridge. This has happened on two types of routerboards acting as switches, one was RB1100 and on the CRS112-8P-4S.
by Caci99
Mon Aug 20, 2018 4:55 pm
Forum: Beginner Basics
Topic: Capsman and Virtual AP - how to setup?
Replies: 6
Views: 13478

Re: Capsman and Virtual AP - how to setup?

I think I got it guys. Started a new CAPsMAN from scratch for testing.
I think I had it wrong on defining slaves on provisioning configuration. Will test a bit more and let you know how things go.
by Caci99
Sat Aug 18, 2018 3:28 pm
Forum: Beginner Basics
Topic: Capsman and Virtual AP - how to setup?
Replies: 6
Views: 13478

Re: Capsman and Virtual AP - how to setup?

Config on CapsMan: /interface bridge add name=bridgeCAPS auto-mac=yes add name=bridgeGuest auto-mac=yes /interface bridge port add bridge=bridgeCAPS interface=ether2 add bridge=bridgeCAPS interface=ether3 add bridge=bridgeCAPS interface=ether4 add bridge=bridgeCAPS interface=ether5 /caps-man datapat...
by Caci99
Sat Aug 18, 2018 11:17 am
Forum: Beginner Basics
Topic: Capsman and Virtual AP - how to setup?
Replies: 6
Views: 13478

Re: Capsman and Virtual AP - how to setup?

Did you guys managed to get this done?
When I set Virtual AP to CAP they will cause the real wireless interfaces to be excluded and deactivated. I am trying this on Ceiling AC with Hex as Caps manager.
Basically by adding any virtual AP none of the interfaces will join Caps Manager
by Caci99
Wed Aug 15, 2018 10:27 pm
Forum: General
Topic: Routes with check-ping should only become active if they can ping the gateway
Replies: 9
Views: 3656

Re: Routes with check-ping should only become active if they can ping the gateway

Either way is my request unreasonable? i.e. a route with check-ping should only become active if the gateway IP is ping-able? No, not unreasonable at all :). It should become active only if ping is successful. My suspicion though (since I haven't tested such a thing), is about the ethernet link. As...
by Caci99
Wed Aug 15, 2018 11:03 am
Forum: General
Topic: Routes with check-ping should only become active if they can ping the gateway
Replies: 9
Views: 3656

Re: Routes with check-ping should only become active if they can ping the gateway

It is a seamless process, I have done many with desired result and no issues. That is why I recommend to start with a basic setup with only one host per link to check. Also, why should the interface of the modem go down? The modem might lose connection but the ethernet link should remain up. I suspe...
by Caci99
Tue Aug 14, 2018 1:30 pm
Forum: General
Topic: Routes with check-ping should only become active if they can ping the gateway
Replies: 9
Views: 3656

Re: Routes with check-ping should only become active if they can ping the gateway

This is how I see it: add comment=CABLE distance=1 dst-address=208.67.222.222/32 gateway=67.253.120.1 scope=10 add distance=20 dst-address=208.67.222.222/32 type=blackhole add comment=CABLE distance=1 dst-address=1.1.1.1/32 gateway=67.253.120.1 scope=10 add distance=20 dst-address=1.1.1.1/32 type=bl...
by Caci99
Mon Aug 13, 2018 12:28 pm
Forum: General
Topic: Routes with check-ping should only become active if they can ping the gateway
Replies: 9
Views: 3656

Re: Routes with check-ping should only become active if they can ping the gateway

On your first part of post, where you have the printed route table, there are 4 routes with destination 0.0.0.0/0 which are the routes to the internet. I don't see the rules for these on the second part where you have posted the export of the route table. From what I can see on the first part, you h...
by Caci99
Fri Aug 10, 2018 12:45 pm
Forum: General
Topic: Routes with check-ping should only become active if they can ping the gateway
Replies: 9
Views: 3656

Re: Routes with check-ping should only become active if they can ping the gateway

Post your routing configuration, it is not easy to understand without looking at it.
I suspect you have defined interface as gateway instead of IP address.
by Caci99
Mon Jun 25, 2018 12:03 pm
Forum: SwOS
Topic: CSS326-24G-2S+ unable to upgrade
Replies: 11
Views: 11805

Re: CSS326-24G-2S+ unable to upgrade

For those who can not advance past version 2.4, I got word from support and they have introduced a dhcp client at version 2.5 so very probably the switch gets an ip address from dhcp server and no longer answers to the default ip. No I feel dumb :), I should have checked my dhcp server for new lease...
by Caci99
Fri Jun 22, 2018 12:43 pm
Forum: SwOS
Topic: CSS326-24G-2S+ unable to upgrade
Replies: 11
Views: 11805

Re: CSS326-24G-2S+ unable to upgrade

It is a strange problem indeed. I can upgrade up to 2.4, after that it is impossible to upgrade.
I will write to support a bit later and see what they have to say.
by Caci99
Tue Jun 19, 2018 4:47 pm
Forum: General
Topic: PPPoE or modem?
Replies: 5
Views: 1877

Re: PPPoE or modem?

Try pinging to internet, that's where you'll have a worse jitter. Also, moving pppoe to mikrotik will help with that, modems CPU are not ideal, while the routerboard will definitely handle it better.
by Caci99
Tue Jun 19, 2018 10:38 am
Forum: General
Topic: PPPoE or modem?
Replies: 5
Views: 1877

Re: PPPoE or modem?

If you are not noticing any drop in pppoe connection while it is configured on the mikrotik (after the wireless link) than your wireless link is pretty good. About the voice drops, those are very sensitive to latency and more to jitter. You need to monitor them and configure some QOS to optimize for...
by Caci99
Mon Jun 18, 2018 2:32 pm
Forum: General
Topic: PPPoE or modem?
Replies: 5
Views: 1877

Re: PPPoE or modem?

Every time in such cases I recommend to put modem in bridge mode and let mikrotik handle the pppoe. There are two advantages at place, first you have only one NAT node, and secondly the processing power of routerboard is far better than that of a modem. PPPoE is senstive to the wireless, meaning any...
by Caci99
Mon May 21, 2018 2:43 pm
Forum: Announcements
Topic: v6.42.2 [current]
Replies: 65
Views: 35863

Re: v6.42.2 [current]

RouterOS version 6.42.2 has been released in public "current" channel! Before an upgrade: ... 3) Device has enough free storage space for all RouterOS packages to be downloaded. ... You might remove that warning about storage available, it is confusing for people I believe. There are rout...
by Caci99
Mon Apr 23, 2018 1:41 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 203
Views: 267258

Re: Advisory: Vulnerability exploiting the Winbox port

How it works: The vulnerability allowed a special tool to connect to the Winbox port, and request the system user database file. They gain access on a file within the router, right? What kind of information is stored in there? You don't know what is stored in the system user database file ???? :lol...
by Caci99
Mon Apr 23, 2018 1:30 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 203
Views: 267258

Re: Advisory: Vulnerability exploiting the Winbox port

How it works: The vulnerability allowed a special tool to connect to the Winbox port, and request the system user database file.
They gain access on a file within the router, right? What kind of information is stored in there?
by Caci99
Mon Apr 23, 2018 1:23 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 203
Views: 267258

Re: Advisory: Vulnerability exploiting the Winbox port

I use firewall rules which will kick an IP address if login fails after three attempts. Will this method be sufficient to be protected from this vulnerability?

By the way, thank you for letting us know about it.
by Caci99
Mon Apr 16, 2018 8:05 pm
Forum: Announcements
Topic: Winbox 3.13 released!
Replies: 59
Views: 45199

Re: Winbox 3.13 released!

Moving the focus on the password field while you're browsing the managed list does not make sense to me. The purpose of having the managed list is to save the credentials of your own routers along with their addresses, so moving to the password to insert the password does not make sense, I already h...
by Caci99
Tue Mar 06, 2018 11:24 am
Forum: Announcements
Topic: Newsletter #81 (March 2018)
Replies: 23
Views: 21486

Re: Newsletter #81 (March 2018)

Caci99 - User Manager is a separate package which can be installed on your device running RouterOS. Support for MMIPS and ARM platforms was added in 6.42rc versions. You can now test it if you are willing to try out rc version and, of course, you will be able to use it also when 6.42 and later full...
by Caci99
Mon Mar 05, 2018 12:03 pm
Forum: Announcements
Topic: Newsletter #81 (March 2018)
Replies: 23
Views: 21486

Re: Newsletter #81 (March 2018)

UserManager can be run on ARM now. What ROS is needed to run it, or is it a separate package?
by Caci99
Mon Feb 12, 2018 10:32 am
Forum: Announcements
Topic: Winbox 3.12 released!
Replies: 55
Views: 74442

Re: Winbox 3.12 released!

Confirming. When you select an item in 'Managed' list, WinBox copies credentials to the text boxes in the top of window and moves focus to 'Password' field for some reason. That's not what I'm expecting :) Yep, I see it now after chupaka post what you guys meant. Winbox moves focus to password fiel...
by Caci99
Fri Feb 09, 2018 4:50 pm
Forum: Announcements
Topic: Winbox 3.12 released!
Replies: 55
Views: 74442

Re: Winbox 3.12 released!

i cant show it with video. please open winbox with many saved adresses. i have 48 items in my address book. mark one and try to scroll up-down with the mouse wheel. it does not. with 3.11 was possible.
Using Win7x86, it works for me
by Caci99
Mon Jan 29, 2018 10:59 pm
Forum: Announcements
Topic: Winbox 3.11 released!
Replies: 94
Views: 367845

Re: Winbox 3.11 released!

You clicked on the Note header to cause it to be sorted by Note. Click on the column header you want to use for sorting, you can sort on 2 different colums this way. This is indicated by the arrow in the column header. It is not that. The sorting on the Note column somehow is not behaving as it sho...
by Caci99
Mon Jan 29, 2018 8:59 pm
Forum: Announcements
Topic: Winbox 3.11 released!
Replies: 94
Views: 367845

Re: Winbox 3.11 released!

Having trouble since a couple of days ago sorting saved routers by "Note" column. Using winbox 3.11 on Win7, but being using it like this for a long time and did not have this issue. Now that I'm trying to add a new router and a note for it, will put it always last, unless I add a 0 before...
by Caci99
Mon Dec 11, 2017 2:44 pm
Forum: General
Topic: netinstall doesnt work
Replies: 9
Views: 2959

Re: netinstall doesnt work

Is there any other service running on PC which may block the port of Netinstall (I can't recall on which port Netinstall runs)? I have had this issue with Acronis Snap Deploy before. I have seen scenarios, not with netinstall but other cases, when auto-negotiation does not work as expected, so tryin...
by Caci99
Fri Dec 08, 2017 1:49 pm
Forum: Announcements
Topic: Winbox 3.11 released!
Replies: 94
Views: 367845

Re: Winbox 3.11 released!

Strangely enough, today the winbox 3.11 was reported as virus form Avira, containing traces of TR/AD.Swrort.absza. This has to be a false positive, I have being using winbox 3.11 since when it came out with the same antivirus protection. An update of Avira might have caused the problem.
by Caci99
Fri Nov 17, 2017 2:41 pm
Forum: General
Topic: DHCP client to be added at address list
Replies: 3
Views: 2318

Re: DHCP client to be added at address list

Hey. Better make dhcp pool with IP's which in address-list range.
That won't cut it. Devices connecting to dhcp server are from different people with different rules to be applied. I can't put them all on the same pool, unless I can differentiate them by dhcp option
by Caci99
Fri Nov 17, 2017 1:40 pm
Forum: General
Topic: DHCP client to be added at address list
Replies: 3
Views: 2318

DHCP client to be added at address list

Hello Is there a way to add a particular dhcp client at an address list? There is a script option at dhcp server to be run when client gets ip address, but how to make it run for a particular set of clients instead for all. Maybe using dhcp option? But I am not that familiar with those and how to ru...
by Caci99
Mon Oct 16, 2017 8:26 pm
Forum: Announcements
Topic: RouterOS (v6.39.3, v6.40.4, v6.41rc) NOT affected by WPA2 vulnerabilities
Replies: 58
Views: 154584

Re: RouterOS NOT affected by WPA2 vulnerabilities

It's important to note that this is a client vulnerability - patching your router / AP does not prevent the attack from working on connected devices. You need to update almost every device that has WPA2 support. Which means every device :) ( I guess every one secures wireless connection on WPA2) If...
by Caci99
Mon Oct 16, 2017 12:39 pm
Forum: Beginner Basics
Topic: how to monitor data plan in NS
Replies: 4
Views: 1411

Re: how to monitor data plan in NS

okay the graphing tool does monitor data and kinda everything but only inside the router what goes in and what goes out. but it doesn't tell what and how much data went to let's say to nano station #1 or how much nano station #2 has uploaded . that what i want to monitor . To acquire data from Nano...
by Caci99
Mon Oct 16, 2017 12:36 pm
Forum: Announcements
Topic: RouterOS (v6.39.3, v6.40.4, v6.41rc) NOT affected by WPA2 vulnerabilities
Replies: 58
Views: 154584

Re: RouterOS NOT affected by WPA2 vulnerabilities

So what does this mean exactly in general? Can the password be stolen? How has Mikrotik fixed it, if it is the protocol itself who is vulnerable?
by Caci99
Sat Oct 14, 2017 1:13 pm
Forum: Beginner Basics
Topic: newbe question about two bridges
Replies: 1
Views: 988

Re: newbe question about two bridges

Try to configure it as any router and just do net mapping for IP = 10.2.3.55
https://wiki.mikrotik.com/wiki/Manual:I ... :1_mapping
You will assign two IP on the WAN interface, 10.2.3.253 and 10.2.3.55 and than do net mapping.
by Caci99
Sat Oct 14, 2017 1:01 pm
Forum: Beginner Basics
Topic: how to monitor data plan in NS
Replies: 4
Views: 1411

Re: how to monitor data plan in NS

I don't know much about ubiquity devices but on mikrotik side you can activate the graphing tool built in the Router OS. Though with every reboot you will lose the graphing. If you don't want to lose the graphing data you can use dude to monitor it or NTOP. NTOP would need to activate traffic flow o...
by Caci99
Fri Sep 15, 2017 2:27 pm
Forum: Announcements
Topic: Newsletter 78 with 1GBPS WIRELESS PRODUCT ANNOUNCEMENT!
Replies: 109
Views: 51875

Re: Newsletter 78 with 1GBPS WIRELESS PRODUCT ANNOUNCEMENT!

Will the Woobm work as client device on desktops or laptops to connect them to an AP?
by Caci99
Wed Aug 16, 2017 12:21 pm
Forum: General
Topic: Router Compromised - Security flaw ?
Replies: 26
Views: 5263

Re: Router Compromised - Security flaw ?

I do usually add these rules on firewall filter, got them from wiki: add action=drop chain=forward comment="Drop invalid packets" \ connection-state=invalid disabled=no add action=drop chain=input comment="" connection-state=invalid disabled=no add action=drop chain=output commen...
by Caci99
Wed Aug 16, 2017 11:13 am
Forum: General
Topic: Router Compromised - Security flaw ?
Replies: 26
Views: 5263

Re: Router Compromised - Security flaw ?

So, router was accessed using it's private IP, right? That means he knows port forwarding of core router. I bet he knows password too, how he does it's another story. In ten years I have worked with mikrotik, since ROS 2.9.x , I have never encountered a case where routerboard was compromised with ju...
by Caci99
Tue Aug 15, 2017 1:17 pm
Forum: General
Topic: Router Compromised - Security flaw ?
Replies: 26
Views: 5263

Re: Router Compromised - Security flaw ?

Are you reading logs from router memory? it can not save more than 100 lines, so maybe there are previous attacks which you can not see.
Also, look at this:
viewtopic.php?f=21&t=119308
by Caci99
Mon Jul 17, 2017 10:10 pm
Forum: General
Topic: Will PCQ still work even if computers are using a different DHCP server?
Replies: 1
Views: 852

Re: Will PCQ still work even if computers are using a different DHCP server?

As long as all of the traffic is passing through the router, PCQ will work.
It depends on how you have configured it.
by Caci99
Fri Jun 09, 2017 10:41 pm
Forum: General
Topic: Feature Req: IKEv2 server and client
Replies: 291
Views: 182559

Re: Feature Req: IKEv2 server and client

When you set exchange-mode=ike2 :)
:lol: got it
by Caci99
Thu Jun 08, 2017 7:35 pm
Forum: General
Topic: Feature Req: IKEv2 server and client
Replies: 291
Views: 182559

Re: Feature Req: IKEv2 server and client

Guys, a dumb question, but ... how can I understand if I'm using IKEv2 or not? :)
by Caci99
Wed May 17, 2017 2:17 pm
Forum: General
Topic: presentation :)
Replies: 3
Views: 1177

Re: presentation :)

by Caci99
Sat Mar 18, 2017 2:02 pm
Forum: General
Topic: alarm port with Mikrotik
Replies: 12
Views: 4116

Re: alarm port with Mikrotik

Your mikrotik router is behind another router, so you are basically double nat-ing. The first router must have a nat config which sends the request to mikrotik IP 192.168.1.2 on port 33000. Is it so? Also, from your posted rules looks like the ones for this port are disabled. Have you enabled them w...
by Caci99
Sat Mar 18, 2017 1:44 pm
Forum: General
Topic: Assign daily bandwidth quota
Replies: 1
Views: 4441

Re: Assign daily bandwidth quota

Take a look at this topic
viewtopic.php?f=13&t=87565&hilit=month+data+limit
It might be a good start what you are looking for.
by Caci99
Wed Feb 22, 2017 11:52 pm
Forum: General
Topic: https problem on hotspot
Replies: 97
Views: 126532

Re: https problem on hotspot

This is less and less of an issue these days, as most devices connecting to a hotspot are smart enough to automatically issue a regular http request and if it's redirected, present the user with the login page. Not at the moment though, there are still a lot of devices which don't do that, which gi...
by Caci99
Wed Feb 22, 2017 11:11 pm
Forum: General
Topic: https problem on hotspot
Replies: 97
Views: 126532

Re: https problem on hotspot

Hi Guys, Finally after long forum reading and googling, I am able to work with SSL and HTTPS sites. I will post all the details after few other test and post a video also if its a 100% success. Finger crossed. https://youtu.be/gth9SG_O8j0 That video didn't show that much how were you doing it. Can ...
by Caci99
Mon Feb 20, 2017 8:27 pm
Forum: General
Topic: https problem on hotspot
Replies: 97
Views: 126532

Re: https problem on hotspot

To start the SSL connection, doesn't the browser need first to connect to the server? By sending a request for connection, isn't it visible to the router on port 443 and as result redirected to hotspot login page? What am I missing here? When the client wants to connect to https://google.com, the c...
by Caci99
Mon Feb 20, 2017 4:31 pm
Forum: General
Topic: https problem on hotspot
Replies: 97
Views: 126532

Re: https problem on hotspot

I am a bit in the dark here.

To start the SSL connection, doesn't the browser need first to connect to the server? By sending a request for connection, isn't it visible to the router on port 443 and as result redirected to hotspot login page? What am I missing here?
by Caci99
Fri Feb 03, 2017 11:20 pm
Forum: General
Topic: Do any queue types respect Priority markings?
Replies: 26
Views: 7777

Re: Do any queue types respect Priority markings?

That is a lot of simple queues you would need to create for each customer. Mikrotik says that they have improved a lot the performance of simple queues, but I haven't tried it in real world since I am a lot more comfortable with queue tree. The good thing about queue tree is that all queues are tre...
by Caci99
Fri Feb 03, 2017 2:27 pm
Forum: General
Topic: Do any queue types respect Priority markings?
Replies: 26
Views: 7777

Re: Do any queue types respect Priority markings?

The good thing about queue tree is that all queues are treated at the same time, while with a simple queue the packet must check them all in their order until it matches the one which deals with it. To my knowledge, this is totally wrong. The current implementation if Simple Queues uses hash-table ...
by Caci99
Thu Feb 02, 2017 11:33 pm
Forum: General
Topic: Do any queue types respect Priority markings?
Replies: 26
Views: 7777

Re: Do any queue types respect Priority markings?

That is a lot of simple queues you would need to create for each customer. Mikrotik says that they have improved a lot the performance of simple queues, but I haven't tried it in real world since I am a lot more comfortable with queue tree. The good thing about queue tree is that all queues are trea...
by Caci99
Thu Feb 02, 2017 9:39 pm
Forum: General
Topic: Do any queue types respect Priority markings?
Replies: 26
Views: 7777

Re: Do any queue types respect Priority markings?

They each get a simple queue created dynamically when their PPPoE Connection is authenticated through RADIUS. Because they are dynamic, I can't do more than pick what Queue Type will be used. You mentioned that customers are dynamic and thus you can't apply the queue to your needs, so I offered an ...
by Caci99
Thu Feb 02, 2017 10:52 am
Forum: General
Topic: Do any queue types respect Priority markings?
Replies: 26
Views: 7777

Re: Do any queue types respect Priority markings?

Well, you know that to have priority work it needs a reference, meaning queue1 has higher priority to queue2. That's why the queues need to be related as in queue tree. When they re not related, it is not possible to apply priority. In case of pppoe users, do not set limits on the profile of users, ...
by Caci99
Thu Jan 19, 2017 8:10 pm
Forum: General
Topic: check-gateway=ping isnot works, but netwatch - works
Replies: 7
Views: 6492

Re: check-gateway=ping isnot works, but netwatch - works

Keep it as I posted it. By using 8.8.8.8 or any other live host (all the time accessible computer on the internet) as your gateway you are actually checking by ping this host and not the gateway of your ISP. This will solve the problem when connection to your ISP is working but connection to interne...
by Caci99
Wed Jan 18, 2017 8:02 pm
Forum: General
Topic: check-gateway=ping isnot works, but netwatch - works
Replies: 7
Views: 6492

Re: check-gateway=ping isnot works, but netwatch - works

If the configuration is as you have posted, then it is wrong. The right one should be as follows /ip route add dst-address=8.8.8.8 gateway=1.1.1.1 scope=10 target-scope=10 add dst-address=0.0.0.0/0 gateway=8.8.8.8 distance=1 check-gateway=ping add dst-address=0.0.0.0/0 gateway=2.2.2.1 distance=5 Thi...
by Caci99
Wed Dec 21, 2016 11:25 am
Forum: General
Topic: Dual Balancing Router
Replies: 1
Views: 845

Re: Dual Balancing Router

It depends on how much bandwidth you want to pass through the router, and what level of QOS will it have if any. Also how do you connect to it from the remote locations, are you using any IPSEC? You see, almost any router of MikroTik can do that with PCC configuration, but the power of the router sh...
by Caci99
Thu Nov 10, 2016 2:04 pm
Forum: General
Topic: PPTP And L2tP strange case
Replies: 14
Views: 6256

Re: PPTP And L2tP strange case

as i know windows support l2tp
Windows does support l2tp, but only with ipsec. You have to change something in windows register to be able to connect to a l2tp server without ipsec. Maybe the same goes for android.
by Caci99
Thu Nov 10, 2016 1:29 pm
Forum: General
Topic: PPTP And L2tP strange case
Replies: 14
Views: 6256

Re: PPTP And L2tP strange case

Are you trying to connect via l2tp a windows device? If I recall it correctly, windows does not support l2tp without ipsec.
by Caci99
Thu Nov 10, 2016 1:23 pm
Forum: General
Topic: How to create Redundancy
Replies: 6
Views: 2265

Re: How to create Redundancy

Thing is, both pppoe and dhcp clients will find the server by broadcast packets. The way you have created the network, if the two routerboards have arp=proxy-arp in their bridge interface, means that every device is in the same broadcast domain. So every device will find either server 1 or server 2 ...
by Caci99
Wed Oct 26, 2016 12:33 pm
Forum: General
Topic: Filter rule
Replies: 1
Views: 862

Re: Filter rule

Well, put the IPs you want to bypass the rule in an address list and then create rule with action=accept and source the address list and put this rule above the one you created for block. But in future, you better post the rule you have created to see how you are approaching it, so the answer can be...
by Caci99
Thu Oct 20, 2016 2:16 pm
Forum: General
Topic: Horrible experience with wireless. In need of a fix.
Replies: 10
Views: 2887

Re: Horrible experience with wireless. In need of a fix.

AP in every test is TP-Link? If moving your AP 20m away gives you a hooping -40 in signal and better performance, it means there is either an alignment issue (i doubt it given your capabilities) or interference. Someone must have put something which greatly disturbs your signal path. I would recomme...
by Caci99
Wed Oct 19, 2016 1:50 pm
Forum: General
Topic: Horrible experience with wireless. In need of a fix.
Replies: 10
Views: 2887

Re: Horrible experience with wireless. In need of a fix.

1km distance with a 24dbi antenna and -69 signal? That is low, would have expected something below -60. The behavior is typical of interference scenario. How is the line of sight, any kind of obstruction? Even leafs of trees can cause problems. Have you tried changing the frequency, change to superc...
by Caci99
Wed Oct 19, 2016 1:39 pm
Forum: General
Topic: router access to internet
Replies: 2
Views: 1222

Re: router access to internet

chain=output is for traffic outgoing from the router itself. Try to mark in mangle and see if it helps.
by Caci99
Tue Oct 18, 2016 10:54 am
Forum: General
Topic: I can't remotely manage with NTH balance
Replies: 2
Views: 1127

Re: I can't remotely manage with NTH balance

Connection to router shouldn't, and doesn't look, be influenced by your policy routing in mangle. What is probably happening, is that you are sending request to WAN2 but router chooses WAN1 as gateway. In the routing table, put the gateway of the connection you need as default, with smaller distance...
by Caci99
Tue Oct 11, 2016 7:51 pm
Forum: General
Topic: Cannot login after v6.37.1 update
Replies: 2
Views: 2962

Re: Cannot login after v6.37.1 update

If you can't log in there is no way to access the router. The only way would be, as you mention, reset or netinstall.
But anyway, how come you left it with default credentials, changing username and password should be the first thing to do on a routerboard.
by Caci99
Tue Oct 11, 2016 2:34 pm
Forum: General
Topic: Address list issue
Replies: 1
Views: 1100

Re: Address list issue

Post how you are creating those address lists, they look dynamic so it maybe the changes are normal because it depends on how the lists are created.
Also, post your configuration of policy routing to see how traffic chooses one gateway over another.
by Caci99
Wed Jul 06, 2016 12:06 pm
Forum: General
Topic: Automatic Failover using check-ping url without set public IP on mikrotik
Replies: 4
Views: 6239

Re: Automatic Failover using check-ping url without set public IP on mikrotik

You have misunderstood that article completely. What is achieved through that method is using an external, not on your network, as gateway through recursive routing. By doing this, you can rely on check gateway by ping to see if gateway is up or not. Basically, if your gateway is 192.168.1.1, using ...
by Caci99
Sat Jun 25, 2016 1:30 pm
Forum: Wireless Networking
Topic: View how wifi clients are connected in ros
Replies: 2
Views: 6767

Re: View how wifi clients are connected in ros

Look at the the registration table and the data rate of connected clients, you can deduct by that.
But I believe B is very old and very very slim chance there is still any device around.

Edit: andriys beat to me it ;)
by Caci99
Thu May 26, 2016 8:13 pm
Forum: RouterBOARD hardware
Topic: wAP AC (General questions and experience)
Replies: 118
Views: 61443

Re: wAP AC (General questions and experience)

The product is very nice, but I don't know why Mikrotik is putting that kind of default configuration where you can't connect from ethernet, same as with mAP-lite. It is frustrating trying to connect with it. A 5 sec job turns into 5 min. Not every one has in their labs laptops. So the only way for ...
by Caci99
Wed Mar 09, 2016 12:11 pm
Forum: General
Topic: Torrent
Replies: 43
Views: 15688

Re: Torrent

Guys, this topic has got away from its main subject. The whole point of this topic is to have the ability to download all files of all architectures (mipsbe, tile, ppc, etc.). This is what is asked about a year ago. Whether it is a torrent or a file from http makes little difference. Some of us have...
by Caci99
Thu Feb 18, 2016 9:05 pm
Forum: General
Topic: Troubleshotting the load balancer
Replies: 4
Views: 1595

Re: Troubleshotting the load balancer

13 ;;; WAN1 3/0 chain=prerouting action=mark-connection new-connection-mark=WAN1_conn passthrough=yes dst-address-type=!local src-address-list=!vpnusers dst-address-list=!vpnusers in-interface=bridge-local connection-mark=no-mark per-connection-classifier=both-addresses-and-ports:3/0 log=no log-pre...
by Caci99
Tue Feb 16, 2016 2:59 pm
Forum: General
Topic: Troubleshotting the load balancer
Replies: 4
Views: 1595

Re: Troubleshotting the load balancer

It's all about how you configure the PCC. You can't possibly load balance providers which have different factor. If one is giving you 160/20 the other 80/40 it just can't be load balanced at full use. One has a ratio of 8/1 the other 2/1.
Post your PCC rules and see how packets are divided.
by Caci99
Wed Feb 10, 2016 12:22 pm
Forum: RouterBOARD hardware
Topic: mAP lite
Replies: 58
Views: 28320

Re: mAP lite

Does it have full routerOS functions? Yes it does, but keep in mind it is a small device so no fancy configurations (vpn, vlan, bgp :) ) I'm wondering if after initial setup I can place it in station mode. Is it possible to use map-lite's ether port to connect the device to wifi ap? Of course you c...
by Caci99
Fri Feb 05, 2016 7:28 pm
Forum: General
Topic: my PCC dual wan initial setup won't work
Replies: 15
Views: 5095

Re: my PCC dual wan initial setup won't work

Hi, Caci99 just one question, anyway to test PCC works or not? I mean i need to know traffic are both going through WAN1 and WAN2 equally, or most are. Thanks In a day average it would almost equalize, but the most important is the packets average because different connections would have different ...
by Caci99
Thu Feb 04, 2016 7:58 pm
Forum: General
Topic: my PCC dual wan initial setup won't work
Replies: 15
Views: 5095

Re: my PCC dual wan initial setup won't work

Hi, @Caci99 The router runs well today, i may do more configuration test tomorrow. 1. add both port forwarding and uPnP to this router, then VPNs (OpenVPN, PPTP, IKEV2...) on both WANs. 2. Stick clients (or certain inside lan IP, ports, mac) to use dedicated output WAN route. 3. Automatic block IP ...
by Caci99
Wed Feb 03, 2016 2:06 pm
Forum: General
Topic: my PCC dual wan initial setup won't work
Replies: 15
Views: 5095

Re: my PCC dual wan initial setup won't work

It works! I re-worked the mangle rules as you typed. Then, rechecked the masquerade rule, modified it from /ip firewall mangle add chain=prerouting out-interface=ether7-wan1 action=masquerade add chain=prerouting out-interface=ether8-wan2 action=masquerade to /ip firewall mangle add chain=srcnat ou...
by Caci99
Wed Feb 03, 2016 12:48 pm
Forum: General
Topic: my PCC dual wan initial setup won't work
Replies: 15
Views: 5095

Re: my PCC dual wan initial setup won't work

ok, i removed the pcc part fo first 2 mangle rules as you mentioned. But I still can't ping 8.8.4.4 from my laptop, while passed from router, there must be something wrong on ether the route rule, or the mangle rules. Thanks. Ok, let's try with rules order and disabling the first two rules: /ip fir...
by Caci99
Wed Feb 03, 2016 11:51 am
Forum: General
Topic: my PCC dual wan initial setup won't work
Replies: 15
Views: 5095

Re: my PCC dual wan initial setup won't work

The first two mangle rules, remove the part about per connection classifier: /ip firewall mangle add chain=prerouting dst-address=112.65.129.176/30 in-interface=bridge1 per-connection-classifier=both-addresses:2/0 add chain=prerouting dst-address=140.206.103.132/30 in-interface=bridge1 per-connectio...
by Caci99
Tue Feb 02, 2016 3:18 pm
Forum: General
Topic: my PCC dual wan initial setup won't work
Replies: 15
Views: 5095

Re: my PCC dual wan initial setup won't work

My 2 WANs come from same ISP with exact same bandwidth and latency. That's very good for PCC For the masquerade, i do intend to use src-nat method cuz i have static wan ip, hope it should be better than masquerade. Choose which one you prefer, it is basically the same. if i set dhcp server running ...
by Caci99
Tue Feb 02, 2016 2:42 pm
Forum: General
Topic: my PCC dual wan initial setup won't work
Replies: 15
Views: 5095

Re: my PCC dual wan initial setup won't work

First, how are the two connections provided to you in term of bandwidth and latency? If they are not symmetrical you will have problems. With symmetrical I mean they should have more or less same latency and equal down/up or one has to be the factor of the other down/up. Second, dns servers should b...
by Caci99
Thu Jan 28, 2016 1:37 pm
Forum: RouterBOARD hardware
Topic: mAP lite
Replies: 58
Views: 28320

Re: mAP lite

By default, you are only able to access the router through wireless interface as it is stated in the quick guide. The logic behind that is the ethernet goes to wall (ISP) and users are connected to wireless. Fair enough, but you have to consider that a lot of people still use ethernet for configura...
by Caci99
Wed Jan 27, 2016 9:23 pm
Forum: RouterBOARD hardware
Topic: mAP lite
Replies: 58
Views: 28320

Re: mAP lite

I just put my hands on this device and it is very nice. Still figuring out the range of use of it, it is to be considered as "mobile" wireless device rather than a fixed one, although it will serve as a fix AP very well. Anyway, my problem is with its default configuration. In a device whi...
by Caci99
Sun Jan 10, 2016 11:40 pm
Forum: General
Topic: Wireless Bandwidth Share Equal
Replies: 9
Views: 3299

Re: Wireless Bandwidth Share Equal

If you see counters running in mangle than that config is working.
As for the queues, don't forget to specify limit-at and max-limit of the queues. If you leave them 0 they will not work.
by Caci99
Sat Jan 09, 2016 3:13 pm
Forum: General
Topic: Wireless Bandwidth Share Equal
Replies: 9
Views: 3299

Re: Wireless Bandwidth Share Equal

Good, that's the way to start getting help :), try it first and post your config. Now to the point, first it is important that wireless interface named qbtcm is not part of any bridge interface. I will assume it is not. Second, your mangle seem correct to some extent, but I would mark connections fi...
by Caci99
Fri Jan 08, 2016 4:55 pm
Forum: General
Topic: Wireless Bandwidth Share Equal
Replies: 9
Views: 3299

Re: Wireless Bandwidth Share Equal

It is not about copy paste, is about understanding the example and then implement it on your network. First, you should start with marking packets coming and going from your wireless interface in the mangle. Then those packet marks are used in the queue tree using the pcq type you have defined. If y...
by Caci99
Fri Jan 08, 2016 1:34 pm
Forum: General
Topic: Wireless Bandwidth Share Equal
Replies: 9
Views: 3299

Re: Wireless Bandwidth Share Equal

PCQ is the way to go. You can check on the wiki page some examples on how to implement it to your needs, like:
http://wiki.mikrotik.com/index.php?titl ... edirect=no

Try it out, and then post your config in here if anything does not goes to plan.
by Caci99
Mon Jan 04, 2016 1:59 pm
Forum: General
Topic: NAT Problems
Replies: 4
Views: 1577

Re: NAT Problems

What is your masquerade rule?
Try to set the masquerade rule with out-interface=WAN only, if it isn't already like that.
by Caci99
Mon Dec 28, 2015 12:35 pm
Forum: General
Topic: Protected RouterBOOT
Replies: 127
Views: 94813

Re: Protected RouterBOOT

I have wrote it before, but I will repeat it. The situation is as @kgninfos describes it. You give CPE for free to new customer (or whatever deal you are offering), than competition arrives and offers him a better deal using the CPE. Customer is unaware of what is behind, he is just looking for the ...
by Caci99
Mon Dec 28, 2015 12:23 pm
Forum: General
Topic: question about protected-routerboot
Replies: 5
Views: 2654

Re: question about protected-routerboot

Try netinstall as @pukkita already suggested. Otherwise contact mikrotik support (although might take a while to get an answer since it is holiday season)
by Caci99
Sat Dec 26, 2015 1:46 pm
Forum: General
Topic: Simple PCQ Queue not working as expected
Replies: 1
Views: 1660

Re: Simple PCQ Queue not working as expected

Well, your max limit is 1M/10M. 10M should be the download, but it depends on which interface the queue is attached. I suspect that the queue is attached to the WAN so by definition the download is the Tx of the interface, and Tx on the WAN interface is actually the upload from your point of view. S...
by Caci99
Sat Dec 26, 2015 1:30 pm
Forum: General
Topic: question about protected-routerboot
Replies: 5
Views: 2654

Re: question about protected-routerboot

What is the firmware version of the routerboard? Have you tried to update it?
by Caci99
Sun Dec 06, 2015 7:56 pm
Forum: General
Topic: Mikrotik RouterOS Upgrading Issue....Please Assist.
Replies: 5
Views: 1854

Re: Mikrotik RouterOS Upgrading Issue....Please Assist.

There is always a slim chance that something can go wrong (unfortunately) but not much to be worried. I would recommend these steps: 1. Backup your config using export command from terminal. 2. reset the router with no defaults. 3. update to legacy ROS, 5.x I believe. 4. update license and then firm...
by Caci99
Sat Dec 05, 2015 2:31 pm
Forum: General
Topic: Mikrotik RouterOS Upgrading Issue....Please Assist.
Replies: 5
Views: 1854

Re: Mikrotik RouterOS Upgrading Issue....Please Assist.

If the routerboard is in remote, I would not recommend the update because it is a huge jump in OS version and it can go wrong. If it is on your desk, you probably would need first to update to ROS 4.x or 5.x (check the legacy on download page) because the 3.10 has still the old license system with 7...
by Caci99
Mon Nov 16, 2015 2:38 pm
Forum: General
Topic: How to use maximum available bandwidth
Replies: 2
Views: 1629

Re: How to use maximum available bandwidth

This will involve queue tree, address list and mangle. In the pppoe profile do not create limits, instead add the users to address lists which would represent the packets you are offering to the customers. Address list for 256kbps users, for 512kbps and so on. Then, use mangle to mark traffic from t...
by Caci99
Thu Nov 12, 2015 7:44 pm
Forum: General
Topic: TR-069
Replies: 12
Views: 8796

Re: TR-069

What could be the use of this TR-069 in MikroTik? Never heard of it before.
by Caci99
Wed Nov 04, 2015 1:08 pm
Forum: Beginner Basics
Topic: Firewall filter ignoring src-address-list=?
Replies: 8
Views: 2308

Re: Firewall filter ignoring src-address-list=?

What are you exactly experiencing? From those rules I can see that network 10.0.0.0/8 will always connect, you are accepting connections from that network. That means IPs form 10.0.0.1 to 10.254.254.254 can connect. The timeout of the blacklist is only 3 minutes, so after three minutes every IP on t...
by Caci99
Wed Nov 04, 2015 11:14 am
Forum: General
Topic: Kindly Guide me
Replies: 1
Views: 899

Re: Kindly Guide me

With policy routing. Mark packets in mangle: /ip firewall mangle add chain=prerouting in-interface=LAN src-address=192.168.1.0/24 action=mark-connection new-connection-mark=network1 add chain=prerouting in-interface=LAN src-address=172.16.16.0/24 action=mark-connection new-connection-mark=network2 a...
by Caci99
Sat Oct 31, 2015 2:15 pm
Forum: General
Topic: Winbox losing MAC connection to RB850Gx2
Replies: 46
Views: 20659

Re: Winbox losing MAC connection to RB850Gx2

I have written to support a couple of weeks ago about this issue, and they answered that they will look at it and fix it later. When, they didn't specify :) I wrote to support again a couple of weeks ago, and yet no fix has been introduced to this problem. I believe the fix is not coming soon. It m...
by Caci99
Fri Oct 30, 2015 12:36 pm
Forum: Beginner Basics
Topic: Problem WAN Failover Mikrotik
Replies: 1
Views: 900

Re: Problem WAN Failover Mikrotik

If you change the distance manually it is obvious that you have to do it manually again.
But you better post here your IP configuration and your route configuration. Also, what kind of connection are you using to connect to the internet (pppoe, dhcp, IP)?
by Caci99
Mon Oct 26, 2015 1:25 pm
Forum: General
Topic: Blocking A website
Replies: 3
Views: 2399

Re: Blocking A website

Try this rule: /ip firewall filter add chain=forward action=reject reject-with=tcp-reset protocol=tcp content="Host: www.vimeo.com" /ip firewall filter add chain=forward action=reject reject-with=tcp-reset protocol=tcp content="Host: www.netflix.com" And move this rules to the t...
by Caci99
Tue Oct 13, 2015 11:13 am
Forum: Wireless Networking
Topic: Balance connected customers between AP - s
Replies: 12
Views: 5237

Re: Balance connected customers between AP - s

3. Turn off some or all of the lower data rates. They'll hog airtime if clients end up using any of them. Turn off the lower data rates? That's the first time I hear it. Or do you mean the "802.11b" data rates? be careful with kicking clients when they fall behind some signal level, some ...
by Caci99
Thu Oct 08, 2015 7:25 pm
Forum: Wireless Networking
Topic: Balance connected customers between AP - s
Replies: 12
Views: 5237

Re: Balance connected customers between AP - s

You can limit max number of stations which can connect to an AP, together with limiting the minimum signal should be enough to provide reasonable WiFi service. Keep in mind that you want to limit signal from client to AP, as per your post I would understand that you want to limit the signal strengt...
by Caci99
Thu Oct 08, 2015 1:13 pm
Forum: Wireless Networking
Topic: Balance connected customers between AP - s
Replies: 12
Views: 5237

Balance connected customers between AP - s

In my area there is an increasing demand of using multiple Access Points in one place with same SSID capable of serving 100 or more customers. The area to be covered are usually conference rooms, halls, big entertainment buildings, etc, meaning customers come and go, so no need to use any radius or ...
by Caci99
Thu Oct 08, 2015 12:42 pm
Forum: Wireless Networking
Topic: Very unusual wifi behavior on a 1,000 seater theater deployment using 9 GrooveA 52HPn, 2 SXT 2, and 1 wAP 2nD
Replies: 15
Views: 3832

Re: Very unusual wifi behavior on a 1,000 seater theater deployment using 9 GrooveA 52HPn, 2 SXT 2, and 1 wAP 2nD

So you instaled all this in the same room/hall or more than two in the same room? Allow me to :lol: With all due respect, I don't think there is anything to laugh at it. Everyone learns a lot of things the hard way. As a bad experience as it is, it is nice it was shared so other will know what not ...
by Caci99
Wed Oct 07, 2015 12:35 pm
Forum: General
Topic: RB with two uplinks
Replies: 2
Views: 1261

Re: RB with two uplinks

Try this: /ip firewall mangle add chain=input in-interface=WAN1 action=mark-connection new-connection-mark=wan1 add chain=input in-interface=WAN2 action=mark-connection new-connection-mark=wan2 add chain=postrouting connection-mark=wan1 action=mark-routing new-routing-mark=wan1 passthrough=no add ch...
by Caci99
Tue Oct 06, 2015 2:18 pm
Forum: General
Topic: MAC not refresh automatically
Replies: 4
Views: 1452

Re: MAC not refresh automatically

V6.2 on CCR1036-12G-4S .
customers are connecting statically. all the ARP table are dynamic.
It depends on the timeout of a dynamic arp entry then. I don't know the timeout of arp in mikrotik (but I guess it shouldn't be long). Do you see them after a long time they have been disconnected?
by Caci99
Mon Oct 05, 2015 12:16 pm
Forum: General
Topic: MAC not refresh automatically
Replies: 4
Views: 1452

Re: MAC not refresh automatically

What routerboard are you using? Are the customers connected to the router in any particular way (dhcp, pppoe, etc..)?
The entries in the arp table are dynamic?
by Caci99
Mon Oct 05, 2015 12:13 pm
Forum: General
Topic: Winbox 3 RC
Replies: 636
Views: 216148

Re: Winbox 3 RC

I don't know if it is already reported.
When you lose connection to a routerboard the window of the winbox3.xrc moves to the top left corner of the screen, instead of preserving the same position. Using Windows 7.
by Caci99
Tue Sep 01, 2015 10:24 am
Forum: Announcements
Topic: v6.30.4 bugfix release
Replies: 103
Views: 42820

Re: v6.30.4 bugfix release

There is still a problem with connection bytes and connection rate when used together. I am using this feature from long time to divide the "heavy traffic" from "normal traffic". But since version 6.30, I think, it is not working anymore. The rule is something like: chain=forward...
by Caci99
Thu Aug 20, 2015 2:17 pm
Forum: General
Topic: RB750 - High latency on LAN
Replies: 3
Views: 2913

Re: RB750 - High latency on LAN

What is the CPU value at the moment when this happens?
When you say latency is high, you do ping from LAN to the router or from the router to LAN?
I suspect there might be another device with the same IP of the router on the network which is responding to the ping, causing conflict.
by Caci99
Tue Aug 18, 2015 9:35 pm
Forum: General
Topic: Mximum PPPoE users seem to be only 112
Replies: 9
Views: 2293

Re: Mximum PPPoE users seem to be only 112

Nice you found a way out of it :) The 2011 has less RAM and CPU then 1100AHx2, so it could be hardware related. This can be easily verified by looking at system resources on the 2011 (although I hardly believe you have reached the ceiling of the resources of it). Otherwise it could be software relat...
by Caci99
Tue Aug 18, 2015 11:37 am
Forum: General
Topic: Mximum PPPoE users seem to be only 112
Replies: 9
Views: 2293

Re: Mximum PPPoE users seem to be only 112

I think there got to be something on the log, it can not be all ok. Weather it is a problem when creating the tunnel or when trying to get the IP. If the IP are handled by radius, try once to assign the IP from the router itself.
by Caci99
Mon Aug 17, 2015 9:55 pm
Forum: General
Topic: Mximum PPPoE users seem to be only 112
Replies: 9
Views: 2293

Re: Mximum PPPoE users seem to be only 112

Activate the log for pppoe in /system log and check what the log says about it.
by Caci99
Mon Aug 17, 2015 8:12 pm
Forum: General
Topic: Mximum PPPoE users seem to be only 112
Replies: 9
Views: 2293

Re: Mximum PPPoE users seem to be only 112

What IP pool are you using? Are there any more IPs available in the pool?
by Caci99
Mon Aug 17, 2015 1:14 pm
Forum: Announcements
Topic: 6.31 released
Replies: 227
Views: 82359

Re: 6.31 released

please fix connection-rate problem in next bug release!

http://forum.mikrotik.com/viewtopic.php ... 12#p495212
Second this, it is not working any more. I noticed this since version 6.30 (but might have happened before).
by Caci99
Fri Aug 14, 2015 1:09 pm
Forum: General
Topic: PPTP and L2TP/IPSec are NOT secure. Use OpenVPN.
Replies: 8
Views: 5771

Re: PPTP and L2TP/IPSec are NOT secure. Use OpenVPN.

Everything is crack-able. As @43north said, stay off the net if you want security. Just a couple of days ago I was reading how in Israel managed to compromise an "air gapped computer" by using cell phones for experimental purposes. So, if somebody is on to you, they will eventually get the...
by Caci99
Mon Jun 29, 2015 3:11 pm
Forum: General
Topic: Lost packets
Replies: 4
Views: 1850

Re: Lost packets

You can create a new queue by duplicating the "ethernet-default" and naming it as you wish. Increase the size from 50 to 100 for example and assign the created queue to the interface and see if this will help or not.
by Caci99
Mon Jun 29, 2015 2:52 pm
Forum: General
Topic: Lost packets
Replies: 4
Views: 1850

Re: Lost packets

Probably those packets are dropped by any queue you might have in. If you don't have any queue then they are dropped by the default queue of the interface. Increasing the size of the queue might help, though it will increase the latency.
by Caci99
Mon Jun 22, 2015 2:08 pm
Forum: Beginner Basics
Topic: Hairpin NAT issue
Replies: 7
Views: 2767

Re: Hairpin NAT issue

On the hairpinnat rule, try removing the destination port:
chain=srcnat action=masquerade protocol=tcp src-address=192.168.0.0/24
      dst-address=192.168.0.248 out-interface=bridge1 log=no
      log-prefix="" 
by Caci99
Thu Jun 04, 2015 9:52 pm
Forum: General
Topic: Firewall Connection, TCP established to non-existent IPs
Replies: 24
Views: 6537

Re: Firewall Connection, TCP established to non-existent IPs

I don't know what is it, but... why doesn't these connections get marked properly? 90% connections get marked properly and behave as expected, w/o these "stalled" connections. Then, amongst the "stalled" ones, only a 5% of these Unreplied, TCP state established "orphan"...
by Caci99
Thu Jun 04, 2015 1:13 pm
Forum: General
Topic: Firewall Connection, TCP established to non-existent IPs
Replies: 24
Views: 6537

Re: Firewall Connection, TCP established to non-existent IPs

This is a topic about understanding very well ip tables, which I don't :). Anyway, an established connection is not the same with an established tcp. What could be happening is, if the client closes the http connection without sending an ack packet (or something like that), so the router considers t...
by Caci99
Wed Jun 03, 2015 12:25 pm
Forum: General
Topic: Hardening Mikrotik
Replies: 5
Views: 1839

Re: Hardening Mikrotik

In /ip service you can see the www-ssl service. But you would need a certificate to establish a connection I guess, otherwise there could not be encrypted connection without it.
by Caci99
Wed Jun 03, 2015 12:22 pm
Forum: General
Topic: A configuration for two local networks and two gateways of the same Internet Provider
Replies: 1
Views: 813

Re: A configuration for two local networks and two gateways of the same Internet Provider

/ip firewall mangle add chain=prerouting src-address=192.168.10.0/24 action=mark-connection new-connection-mark=conn1 add chain=prerouting connection-mark=conn1 action=mark-routing new-routing-mark=conn1 passthrough=no Same for network 192.168.20.0/24 /ip route add dst-address=0.0.0.0/0 routing-mar...
by Caci99
Wed Jun 03, 2015 12:06 pm
Forum: General
Topic: Firewall Connection, TCP established to non-existent IPs
Replies: 24
Views: 6537

Re: Firewall Connection, TCP established to non-existent IPs

I tried (as mentioned before) such script: :foreach i in=[/ip firewall connection find tcp-state=established assured=no] do={ /ip firewall connection remove $i}; But it does nothing. How can I automatically remove such records? Try putting instead of assured=no seen-reply=no My guess is this are in...
by Caci99
Wed May 27, 2015 4:55 pm
Forum: General
Topic: Setting Up A Basic Firewall Rule In Winbox?
Replies: 3
Views: 2791

Re: Setting Up A Basic Firewall Rule In Winbox?

Post your firewall filter to have a look what is causing the block. Normally the firewall filter is blank, which means nothing is blocked through it, unless you have preserved the default configuration, or you have added some of your own. From where to where is the person trying to print? Are the tw...
by Caci99
Tue May 26, 2015 1:44 pm
Forum: General
Topic: PPPOE client throuth another router
Replies: 1
Views: 958

Re: PPPOE client throuth another router

As you said, you need to configure the wireless router as bridge transparent.
Create a bridge interface with arp=proxy arp. Add to this bridge the wireless and ethernet interfaces. Remove NAT from it, and check on the second router if you can connect to the pppoe-server.
by Caci99
Tue May 26, 2015 1:19 pm
Forum: General
Topic: Setting Up A Basic Firewall Rule In Winbox?
Replies: 3
Views: 2791

Re: Setting Up A Basic Firewall Rule In Winbox?

It really depends on what level of security you want to achieve. When blocking all incoming connections, one should be really careful to specify the incoming interface, otherwise you would be left out of the router. Yoy may have a look at: http://wiki.mikrotik.com/wiki/Securing_your_router http://wi...
by Caci99
Thu May 14, 2015 12:05 pm
Forum: General
Topic: How to buy license Level 3
Replies: 4
Views: 2179

Re: How to buy license Level 3

Thanks..

but i still need a clear answer.

Regards
Well, the clear answer is contact support.
by Caci99
Wed May 13, 2015 3:52 pm
Forum: General
Topic: How to buy license Level 3
Replies: 4
Views: 2179

Re: How to buy license Level 3

I believe you would need to contact support for that. Mikrotik does not give Level 3 license if you do not order less than a 100 I think.
But why would you need a Level3 anyway, any routerboard would come with at least Level3 installed.
by Caci99
Mon May 11, 2015 3:11 pm
Forum: General
Topic: Big problem with routes
Replies: 3
Views: 1455

Re: Big problem with routes

I suspect that all pppoe connections are part of the same network from the point of view of your provider. Looking at the last route you have posted: 4 ADC dst-address=10.0.0.1/32 pref-src=86.122.51.229 gateway=rds_acc50_229,rds_acc50_228,rds_fb100 gateway-status=rds_acc50_229 reachable,rds_acc50_22...
by Caci99
Wed Apr 29, 2015 11:19 am
Forum: General
Topic: Help Required with RB750 firewall setup
Replies: 1
Views: 985

Re: Help Required with RB750 firewall setup

First of all, I would suggest to turn the modem into bridge and let the RB750 do the pppoe-client and routing since it is far better this way, although this is not related to your issue. For your problem, I would use connection rate. The problem with torrents is that it is almost impossible to ident...
by Caci99
Wed Apr 22, 2015 11:42 am
Forum: General
Topic: Password changed on some of my clients cpe's
Replies: 3
Views: 1391

Re: Password changed on some of my clients cpe's

I guess you have tried the default credentials to login (admin and no password) in case the RBs have reset themselves. If that is not the case, I don't think it is possible to change the password without having access to the RB. Unfortunately there is no way to reset the RB without using netinstall ...
by Caci99
Wed Apr 15, 2015 12:47 pm
Forum: General
Topic: Tunelling over NAT
Replies: 4
Views: 1355

Re: Tunelling over NAT

You would need access to one router with Public IP. Then, from the router of your friend, create a VPN tunnel giving IP address on the first router with the Public IP. From there you can use dst-nat to access whatever device you want. For example, you have a router "A" with public IP 1.1.1...
by Caci99
Wed Apr 15, 2015 12:38 pm
Forum: General
Topic: who can create *dynamic* DST-NAT rules?
Replies: 3
Views: 1696

Re: who can create *dynamic* DST-NAT rules?

Most probably those are rules created by upnp. Disable it and you will not have any more dynamic nat rules. There are softs and devices who are designed to discover if there is upnp supported by the router and create rules at their need.
Menu for upnp is /ip upnp
by Caci99
Wed Apr 01, 2015 12:37 pm
Forum: General
Topic: Copy using winbox
Replies: 1
Views: 1114

Re: Copy using winbox

Use /export file=whatever and then copy the file to desktop.
For example
/ip arp export file=arp
/queue simple export file=queue_simple
by Caci99
Wed Mar 25, 2015 10:52 am
Forum: General
Topic: Winbox losing MAC connection to RB850Gx2
Replies: 46
Views: 20659

Re: Winbox losing MAC connection to RB850Gx2

I have written to support a couple of weeks ago about this issue, and they answered that they will look at it and fix it later. When, they didn't specify :)
by Caci99
Mon Mar 16, 2015 8:16 pm
Forum: Announcements
Topic: hAP lite
Replies: 391
Views: 246216

Re: hAP lite

I compared contents of the software and was disappointed.
What is there to be disappointed. It is a small device with little RAM. Do you miss NTP server on a home router? Than you can always chose RB951Ui-2HnD
by Caci99
Mon Mar 16, 2015 6:49 pm
Forum: General
Topic: Weird behaviour for NAT
Replies: 4
Views: 2238

Have you tried to change the service ports on mikrotik router?
by Caci99
Mon Mar 16, 2015 11:41 am
Forum: General
Topic: Weird behaviour for NAT
Replies: 4
Views: 2238

Re: Weird behaviour for NAT

Why are you trying to dstnat to the router itself? In your dstnat rules you have specified as to-addresses the IP of the router, you are doing some kind of redirect here. The dstnat rules on the modem should be sufficient to reach the router services you are trying to reach. Although I would suggest...
by Caci99
Thu Feb 26, 2015 7:36 pm
Forum: General
Topic: Protected RouterBOOT
Replies: 127
Views: 94813

Re: Protected RouterBOOT

Like I said, I cant think of a single device that can be completely locked down. And I can't think of single bank which can't be stolen, coincidentally one was stolen two weeks ago in my town :). This doesn't mean that measures has to be taken. How does password differ from Protected RouterBOOT set...
by Caci99
Thu Feb 26, 2015 12:13 am
Forum: General
Topic: Protected RouterBOOT
Replies: 127
Views: 94813

Re: Protected RouterBOOT

This is a 'contract' issue, not a software / hardware problem. I can't think of many/any devices that can't be forced to factory reset in some way. Oh well, so nothing to do about it, right? What about routerboards on towers and masts out in the open? Are you going to pay guards who's salary exceed...
by Caci99
Wed Feb 25, 2015 11:24 pm
Forum: General
Topic: Protected RouterBOOT
Replies: 127
Views: 94813

Re: Protected RouterBOOT

This is a good feature but not as I would have expected it to act yet. It is a good first step to protect the routerboards which are installed into the open. My main concern is about SXT Lite. What actually happens, is that a customer asks for internet connection, and generally a SXT is installed at...
by Caci99
Wed Feb 25, 2015 1:58 pm
Forum: General
Topic: QOS on RB493G
Replies: 3
Views: 1411

Re: QOS on RB493G

Well, to prioritize traffic, first you need to identify it among others. This can be done in mangle. I don't know much about OpenVPN, but you either identify by the port used by OpenVPN or by IP address that goes by one site to the other. Than you assign priority in queue tree with parent and child ...
by Caci99
Wed Feb 18, 2015 7:09 pm
Forum: Announcements
Topic: hAP lite
Replies: 391
Views: 246216

Re: hAP lite

Ok. It is cheap. But having only 32MB of ram?? Now, when wee see that it is very limiting for running v6.x and expecting that v7.x will be again more requesting? Why? Powering by unreliable small tiny micro usb connector? Why? No POE in? Why? Not possible to use wide range of power adapters like fo...
by Caci99
Wed Feb 18, 2015 2:51 pm
Forum: Announcements
Topic: hAP lite
Replies: 391
Views: 246216

Re: hAP lite

It looks promising, but a bit low on wireless power, very good price/feature ratio anyway. Isn't it time to have all ethernet ports on gigabit speed? What could be the cost of it? Nowadays all laptops and desktops, or network HDD cases ship with gigabit ethernet. I would also like to see a 5GHz prod...
by Caci99
Thu Feb 12, 2015 3:14 pm
Forum: General
Topic: Torrent
Replies: 43
Views: 15688

Re: Torrent

I have to admit I am bit lost with the scripting and rest. We were supposed to have an easy life, not make it harder. For me it was easy enough to browse on the download page when new version was out, click on torrent link and download. We even used to get email when new version was out, never mind ...
by Caci99
Thu Feb 12, 2015 1:33 pm
Forum: General
Topic: Torrent
Replies: 43
Views: 15688

Re: RouterOS v6.27 released

Torrents will return after we surgically remove them from the RouterOS release system, and make them entirely separate. The biggest problem with torrents is the initial seeding. There exists no stable command line torrent client that we know of. I don't quite understand what you have said there :),...
by Caci99
Thu Feb 12, 2015 12:35 pm
Forum: General
Topic: Torrent
Replies: 43
Views: 15688

Re: RouterOS v6.27 released

THX :DDD
upgraded a few rb's just to see how it goes.....
no torrent to share the love?
http://www.mikrotik.com/download/router ... 27.torrent

Though, there are no seeders to download from yet :(
Yes, thanks for the link. But why has Mikrotik removed the all file torrent link?
by Caci99
Wed Feb 11, 2015 2:51 pm
Forum: Beginner Basics
Topic: SMB and cyrillic symbols
Replies: 2
Views: 2675

Re: SMB and cyrillic symbols

Do you believe this is a problem related to RouterOS? I don't think so, because I don't think ROS changes the characters of the files. It must be related to the operating system from where you are trying to view the files, they might not support Cyrillic characters. To test it, try to browse the sam...
by Caci99
Wed Feb 11, 2015 2:42 pm
Forum: General
Topic: Winbox 3 RC
Replies: 636
Views: 216148

Re: Winbox 3 RC

I think it would be nice if the columns of winbox could be moved left or right, to rearrange them at one's needs.
I am talking about the columns of the connect window: address; session; group; note
I for example would have arranged them in this order: address; note; session ....

Can it be done?
by Caci99
Tue Feb 10, 2015 2:31 pm
Forum: General
Topic: Unidentified Network When Mikrotik Connect
Replies: 1
Views: 3118

Re: Unidentified Network When Mikrotik Connect

I guess you are talking about the Windows message Unidentified Network. Normally that happens because Windows detects that you are connected to a different router, that is discovered by Windows because of a different mac-address. Just chose public network. Also, next time, try to be more specific ab...
by Caci99
Sat Feb 07, 2015 2:28 pm
Forum: General
Topic: RouterOS v6.26!
Replies: 69
Views: 33826

Re: RouterOS v6.26!

What happened to the torrent link to download all packages? It isn't anymore on the download page, although adding it manually it works
http://www.mikrotik.com/download/router ... 26.torrent
by Caci99
Thu Feb 05, 2015 11:45 pm
Forum: General
Topic: automatic queue for user
Replies: 4
Views: 2276

Re: automatic queue for user

Actually, now that I am thinking of it again, I got it wrong :oops: The connection that I calculated as 1125kB, means a connection at a given time, not over 30 seconds. I have to rethink about it again, sorry.
by Caci99
Wed Feb 04, 2015 3:51 pm
Forum: General
Topic: automatic queue for user
Replies: 4
Views: 2276

Re: automatic queue for user

Let's think of it this way. If a connection has 300kbs for 30s, it means there are at least 9000kbps or 1125kB. Create a rule in firewall mangle: /ip firewall mangle add chain=forward action=add-dst-to-address-list protocol=tcp address-list=test address-list-timeout=1m in-interface=WAN out-interface...
by Caci99
Sun Feb 01, 2015 12:11 am
Forum: General
Topic: Email to SMS text gateway
Replies: 3
Views: 1831

Re: Email to SMS text gateway

but I understand there is a daily limit to the number of SMS notifications which will be sent ? Yes it does have, although I don't know how much. It depends on how sms you think you will get. Since google is in two step verification with sms, the limit must be a considerable number. Worth trying an...
by Caci99
Sat Jan 31, 2015 12:31 pm
Forum: General
Topic: OpenDNS - Catch all DNS traffic
Replies: 11
Views: 17152

Re: OpenDNS - Catch all DNS traffic

Hi all, I am trying to add the rule /ip firewall nat add chain=dstnat in-interface=LAN protocol=udp dst-port=53 action=redirect I do not have an interface called lan. Here is my interface list. Do I add the rules for each LAN interface or is there a way to globally address all of them? [admin@conSh...
by Caci99
Wed Jan 28, 2015 12:35 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2210

Re: Connected Interfaces Won't Communicate

Oh well then :), one more thing learned :).
I guess you can edit the title of the topic as the opener of it.
by Caci99
Tue Jan 27, 2015 8:23 pm
Forum: General
Topic: Email to SMS text gateway
Replies: 3
Views: 1831

Re: Email to SMS text gateway

Try this
http://techawakening.org/free-sms-alert ... docs/1130/
It will send an sms with the subject of email inline
by Caci99
Tue Jan 27, 2015 7:19 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2210

Re: Connected Interfaces Won't Communicate

Here is how I would have done it: /ip firewall mangle add chain=forward src-address=192.168.2.0/24 dst-address=192.168.3.0/24 action=accept add chain=forward src-address=192.168.3.0/24 dst-address=192.168.2.0/24 action=accept add chain=forward src-address=192.168.2.0/24 action=mark-connection new-co...
by Caci99
Mon Jan 26, 2015 2:24 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2210

Re: Connected Interfaces Won't Communicate

Static Route Dst-Add: 0.0.0.0, Gateway: PPPoE Dst-Add: 0.0.0.0, Gateway: 192.168.1.1 Are these routes both active? I don't think so. Because without policy routing in place, the router will just chose one of the two. Anyway, try to add an accept rule before/above the masquerade rule: /ip firewall n...
by Caci99
Mon Jan 26, 2015 12:16 pm
Forum: General
Topic: Connected Interfaces Won't Communicate
Replies: 7
Views: 2210

Re: Connected Interfaces Won't Communicate

Are you using routing marks in /ip firewall mangle and in /ip route?
by Caci99
Wed Jan 21, 2015 9:50 pm
Forum: General
Topic: Interface queue type
Replies: 11
Views: 16201

Re: Interface queue type

As I understand it, hardware-queue is beneficial on switch like scenarios. The packets are processed on the hardware (NIC interface). In router situations, packets are inspected in source and destination, hardware queue will require CPU to do that, which in ethernet-default does not need it since et...
by Caci99
Wed Jan 21, 2015 7:33 pm
Forum: General
Topic: Interface queue type
Replies: 11
Views: 16201

Re: Interface queue type

There is a short explanation at the wiki: http://wiki.mikrotik.com/wiki/Manual:Queue#Queue_Types From this page: only-hardware-queue leaves interface with only hw transmit descriptor ring buffer which acts as a queue in itself. Usually at least 100 packets can be queued for transmit in transmit desc...
by Caci99
Tue Jan 20, 2015 8:09 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5655

Re: 2pppoe wans linked to separate interfaces

Well, the idea is simple. One marks the traffic by means of mangle and then routes that traffic to the desired gateway in ip routes.
Either that gateway is not working, or dns settings on laptop are not correct (not able to resolve http).
by Caci99
Tue Jan 20, 2015 7:58 pm
Forum: General
Topic: Need to export part of long list, how?
Replies: 2
Views: 1030

Re: Need to export part of long list, how?

try this
/ip dhcp-server lease
print file=test where address>172.25.33.0 and address<172.25.34.0
by Caci99
Mon Jan 19, 2015 11:05 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5655

Re: 2pppoe wans linked to separate interfaces

I am a bit baffled why this is not working. Let's try a different approach. Keep all the config that is needed for this one to work, i.e the mangle rules stay, leave only the masquerade rule in /ip firewall nat, and then disable all rest in nat and in /ip firewall filter and see if it works or not.
by Caci99
Mon Jan 19, 2015 9:57 pm
Forum: General
Topic: can't make PCC and Port Forward work together
Replies: 7
Views: 2260

Re: can't make PCC and Port Forward work together

Well, masquerade substitutes the source address with the one of the interface the packet is leaving. I am not sure why this helps your case, looks like the router does not keep track from where the connection is coming and does not reply from the same gateway. Masquerade helps it ( I don't know how ...
by Caci99
Mon Jan 19, 2015 12:45 pm
Forum: General
Topic: can't make PCC and Port Forward work together
Replies: 7
Views: 2260

Re: can't make PCC and Port Forward work together

Try with a general masquerade rule:
/ip firewall nat
add chain=srcnat action=masquerade
leave the other masquerade rules, but disable them for the purpose of testing.
by Caci99
Mon Jan 19, 2015 12:28 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5655

Re: 2pppoe wans linked to separate interfaces

It should work, I don't see anything stopping it from working. Try it again, try it with pinging from laptop. Are you using dhcp-server? If yes what is the lease to the laptop, ip address, gateway, dns server? If not, post in here /ip firewall, /ip route, /ip addresses to have the whole picture in o...
by Caci99
Sun Jan 18, 2015 2:38 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5655

Re: 2pppoe wans linked to separate interfaces

What about the masquerade rule? How is it set?
Try with a simple masquerade:
/ip firewall nat
add chain=srcnat action=masquerade
by Caci99
Sat Jan 17, 2015 10:26 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5655

Re: 2pppoe wans linked to separate interfaces

On the mangle rules, change the last one passthrough=no
/ip firewall mangle
chain=prerouting action=mark-routing new-routing-mark=laptop passthrough=no connection-mark=laptop
that means that packets will not be processed any more and the mark will remain.
by Caci99
Sat Jan 17, 2015 7:44 pm
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5655

Re: 2pppoe wans linked to separate interfaces

Ok, at the moment of enabling those rules i can't ping/reach my internal network/hosts 192.168.10.0/24 from my vpn-pptp connection 192.168.30.0/24 network, why is that? That's because with policy routing in place, when network 192.168.10.0/24 tries to reach 192.168.30.0/24 instead of using the defa...
by Caci99
Fri Jan 16, 2015 11:51 am
Forum: General
Topic: 2pppoe wans linked to separate interfaces
Replies: 15
Views: 5655

Re: 2pppoe wans linked to separate interfaces

Use routing marks in mangle, and after that apply the routing marks in routing table /ip firewall mangle add chain=prerouting src-address=computer1 action=mark-connection new-connection-mark=comp1 add chain=prerouting connection-mark=comp1 action=mark-routing new-routing-mark=comp1 same should be do...
by Caci99
Fri Jan 16, 2015 11:42 am
Forum: General
Topic: Priority Queuing Question
Replies: 1
Views: 1013

Re: Priority Queuing Question

Yes, it is possible. In order to apply priority you should really understand how it works. You need at first a parent queue which will control its child queues. The child queues are were priority is applied. I would recommend use queue tree, but it can be done with simple queues as well. Read these ...
by Caci99
Thu Jan 15, 2015 7:23 pm
Forum: General
Topic: NTP client/server not working
Replies: 3
Views: 2791

Re: NTP client/server not working

and what configuration did you use to intercept time sync requests? Basically, the same as with dns requests redirect. That's where I got the idea from. NTP sends requests on udp protocol port 123: /ip firewall nat add chain=dstnat action=redirect to-ports=123 protocol=udp dst-address-type=!local d...
by Caci99
Thu Jan 15, 2015 7:19 pm
Forum: General
Topic: RB850 DHCP Failover Impossible?
Replies: 5
Views: 2435

Re: RB850 DHCP Failover Impossible?

Why you can't have the same Gateway check on DHCP that you have for static is anyone's guess... I guess that is the nature of the dhcp protocol, it doesn't look for the dhcp server until lease time expires (at my knowledge). And you can't modify a dynamic route, that's how mikrotik thought about it...
by Caci99
Thu Jan 15, 2015 11:58 am
Forum: General
Topic: NTP client/server not working
Replies: 3
Views: 2791

Re: NTP client/server not working

I have it working fine actually on a RB951Ui-2HnD, ROS 6.22. I have it setup as client and server, and I even setup a "transparent" server, meaning that all computers on LAN do synchronize with the router even if they point to another server.
by Caci99
Wed Jan 14, 2015 3:12 pm
Forum: General
Topic: Help required with MTU settings
Replies: 5
Views: 3576

Re: Help required with MTU settings

Set the MTU to default (1500), then try pinging something on the internet without fragmentation first, do discover what mtu is accepted without fragmentation. And then set the MTU according to the result. /ping 4.2.2.2 do-not-fragment size=1500 repeat the ping changing the size until you get an answ...
by Caci99
Wed Jan 14, 2015 2:47 pm
Forum: General
Topic: Mikrotik Half Bridge PPPoE
Replies: 6
Views: 4293

Re: Mikrotik Half Bridge PPPoE

Try by bridging the two ethernet ports of first router and look if the second router can discover the pppoe server and create the pppoe-client on the second router. If that is not enough, set the arp=proxy-arp on the bridge interface, that should do it.
by Caci99
Wed Jan 14, 2015 12:26 pm
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4375

Re: Subnet Isolation Problem

Ok, some success :) I didn't bother trying to ping a device on the other subnet earlier, so cool yes it's blocking comms between addresses on the different subnets. I tried that input filter rule but I can still ping the gateway? The rule in input chain works. In your case it is not working because...
by Caci99
Tue Jan 13, 2015 10:25 pm
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4375

Re: Subnet Isolation Problem

As @rmmccann says, you should try it from one device of subnet A to another device on subnet B. For example, you have: /ip address add address=1.1.1.1/24 interface=ether3 add address=2.2.2.1/24 interface=ether4 With the above configuration and filter rules, you should not be able to ping 2.2.2.10 fr...
by Caci99
Tue Jan 13, 2015 2:54 pm
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4375

Re: Subnet Isolation Problem

Yeah I tried that and still no luck, used command line and then the gui in Winbox and still the connection continues to ping away happily between subnets. You should not try it from the router itself, which obviously can reach those subnets, otherwise wouldn't be able to route them. Try it from on ...
by Caci99
Tue Jan 13, 2015 1:36 pm
Forum: General
Topic: RB850 DHCP Failover Impossible?
Replies: 5
Views: 2435

Re: RB850 DHCP Failover Impossible?

When it fails what happens? Do you still have a gateway active on /ip routes form the dhcp client? I would suggest to turn the modem into bridge, so that you have one NAT only. For the failover, take a look at this article http://wiki.mikrotik.com/wiki/Advanced_Routing_Failover_without_Scripting it ...
by Caci99
Mon Jan 12, 2015 11:44 am
Forum: General
Topic: Firewall
Replies: 2
Views: 1823

Re: Firewall

You need to find what IP addresses their servers have, or on what port they negotiate the updates, and then drop the connections on firewall filter in forward chain for those IP-s or ports.
by Caci99
Mon Jan 12, 2015 11:39 am
Forum: General
Topic: Subnet Isolation Problem
Replies: 9
Views: 4375

Re: Subnet Isolation Problem

It is normal that subnets on the same router communicate with each other, as you have discovered. As soon as you add an IP on one interface, its subnet is part of the connected routes. To stop them from communicating with each other, you need firewall filter routes. For example, let suppose that you...
by Caci99
Mon Jan 12, 2015 11:33 am
Forum: General
Topic: Hacked & Need Help!
Replies: 6
Views: 3244

Re: Hacked & Need Help!

What kind of installation is this?
If he does have a backup, he can reset the router and then restore the backup. Otherwise, he can only reset it and start from scratch, and put a decent username and password to protect the router.
by Caci99
Fri Jan 09, 2015 8:20 pm
Forum: General
Topic: When is it required to reboot a mikrotik to apply changes??
Replies: 5
Views: 9207

Re: When is it required to reboot a mikrotik to apply change

Unused marks will not disappear until reboot. For example.
Of course, but that doesn't affect the configuration in any way, they are just unused. The point being, you do not need to reboot the router when you do some changes.