Community discussions

MikroTik App

Search found 82 matches

by afuchs
Tue Dec 06, 2022 2:58 pm
Forum: Beginner Basics
Topic: DHCP dont have ping!
Replies: 17
Views: 2788

Re: DHCP dont have ping!

Hello netmasterpro, if you use /export hide-sensitive file=x you get a file, that can be open in any text editor, so you can post only a part of it or use placeholder. At least the configuration part of the DHCP server shouldn't be a problem to post. There a a couple of things that can cause such pr...
by afuchs
Fri Sep 16, 2022 2:19 pm
Forum: General
Topic: Portknocking for dst-nat? [SOLVED]
Replies: 7
Views: 1803

Re: Portknocking for dst-nat? [SOLVED]

Do you relay need forwarding? Why don't use a roadwarrior-VPN-solution (You can specify what is reachable over the VPN in the firewall).

If you need to use port forwarding, keep in mind that it consists of the NAT and rules in the forward chain, so you can allow/block access there as well.
by afuchs
Wed Aug 17, 2022 2:58 pm
Forum: Scripting
Topic: Mikrotik script per ssh
Replies: 2
Views: 1335

Re: Mikrotik script per ssh

First, Ir´tried to make remote configuration exports some time ago (versiion 6) and found some sifferencess (e.g,"yes" and "no" was replaced with "true" and "false"), so I couldn't copy some pars of the export right back to the router (e.g. if I had deleted so...
by afuchs
Thu Aug 11, 2022 2:55 pm
Forum: Beginner Basics
Topic: Problem with 6.** version
Replies: 16
Views: 1341

Re: Problem with 6.** version

Mmm...

are you sure your Client answer ping requests?
Windows drop ping requests per default untill you allow it in the (Windows Defenser) Firewall (https://kb.iu.edu/d/aopy).
by afuchs
Thu Jul 28, 2022 11:41 am
Forum: Beginner Basics
Topic: Hotspot: Change subnet after login or isolate unlogged users
Replies: 6
Views: 995

Re: Hotspot: Change subnet after login

An interesting topic.
I don't think, that you can get this kind of security by changing the Subnet only on IP-base,
I think you search for client isolation (there are some article here like "Wireless Client Isolation" viewtopic.php?t=173693).
by afuchs
Wed Jul 27, 2022 2:44 pm
Forum: Beginner Basics
Topic: CANNOT PING MY ROUTER
Replies: 5
Views: 573

Re: CANNOT PING MY ROUTER

Just to be sure, isn't there a general drop or reject rule (no strings attached)?
You don't have to specify icmp directly to block it.
Please also check again what is in the input and output chain.


More information usually leads to better and more accurate answers.
by afuchs
Fri Jun 10, 2022 5:24 pm
Forum: General
Topic: Bridging two phy interfaces and client can't ping. [SOLVED]
Replies: 2
Views: 838

Re: Bridging two phy interfaces and client can't ping. [SOLVED]

Wat is your hAP ac configuration? Get your PC his IP-address from the CHR or from the hAP ac? Are PC and Printer in the same network?
The hAP ac is not only a simple access point, depending on the configuration it can be a complete router with a firewall.
by afuchs
Thu Jun 02, 2022 11:50 am
Forum: Scripting
Topic: How to find certain CAPS with FIND WHERE command [SOLVED]
Replies: 4
Views: 2894

Re: How to find certain CAPS with FIND WHERE command [SOLVED]

For exact match
 /caps-man radio> print where REMOTE-CAP-IDENTITY="BTH"

For regex match
 /caps-man radio> print where REMOTE-CAP-IDENTITY~"BTH"
by afuchs
Fri May 20, 2022 4:15 pm
Forum: Scripting
Topic: Ping then put for SNMP
Replies: 11
Views: 3194

Re: Ping then put for SNMP

Is the SNMP-Check a must?
Quick google search sows that Zabbx can Perform SSH checks ([/url]), and Routeros supports ssh too.
by afuchs
Fri May 13, 2022 12:06 pm
Forum: Beginner Basics
Topic: How to remove a dynamic DNS?
Replies: 17
Views: 10018

Re: How to remove a dynamic DNS?

If you connect with your ISP wiht pppoe or with a DCHP-client uncheck the Box 'use Peer DNS' (Winbox) or set
use-peer-dns=no
(terminal).
by afuchs
Thu May 12, 2022 4:17 pm
Forum: Scripting
Topic: Drop inactive hotspot devices after x minute
Replies: 3
Views: 842

Re: Drop inactive hotspot devices after x minute

I am not an expert in Scripting but with
[/ ip hotspot host print where authorized 

you get a list of all authorized and with
[ /ip hotspot host print where !(authorized )
[
of all not authorized hosts.
by afuchs
Wed Apr 06, 2022 5:15 pm
Forum: Scripting
Topic: A little help please
Replies: 45
Views: 3693

Re: A little help please

Have you tryed //system scheduler add name="create _file" on-event=<your script to generate file> policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-time=startup ? startup - execute the script 3 seconds after the system startup. (from https://wiki.mikrotik.com/wi...
by afuchs
Thu Mar 24, 2022 5:36 pm
Forum: Beginner Basics
Topic: Emulate/simulate forwarding ip address on an interface
Replies: 4
Views: 689

Re: Emulate/simulate forwarding ip address on an interface

If I want to test something with mikrotik I use Virtulbox or Eve-NG (https://www.eve-ng.net/), for simulating. If I want have to test something on teal hardware, I rot the traffic to a PC or a VM, without the service (blocked by PC firewall / monitored wireshark, whats needed). A other option is to ...
by afuchs
Wed Mar 09, 2022 1:02 pm
Forum: General
Topic: Fasstrack and rules
Replies: 13
Views: 1689

Re: Fasstrack and rules

Please help me out. I started to look over your firewall rules and found the most of the them are disabled=yes . Can you please point at the rules that you want to use, /ip firewall filter add action=fasttrack-connection chain=forward connection-state=established,related hw-offload=yes add action=ac...
by afuchs
Wed Mar 09, 2022 10:55 am
Forum: General
Topic: Fasstrack and rules
Replies: 13
Views: 1689

Re: Fasstrack and rules

Post more details, like what mirotik you use, what rules did not work and what do you want to achieve with the rules.
To post a a export of your configuration ( /export file=[filename] hide-sensitive) would help to.
by afuchs
Tue Mar 08, 2022 3:32 pm
Forum: Beginner Basics
Topic: problems logging in with winbox but web portal works [SOLVED]
Replies: 19
Views: 4830

Re: problems logging in with winbox but web portal works [SOLVED]

In the most cases where I got the problem, that WinBox closed immediately on a router connection, I had a to old Winbox version or it was a new one but the ROS was older and I had to use the Tools / Legacy Mode in Winbox to connect.
by afuchs
Fri Mar 04, 2022 4:06 pm
Forum: Wireless Networking
Topic: <50m link from home wifi to parking lot
Replies: 9
Views: 1686

Re: <50m link from home wifi to parking lot

Witch access point do have?
As far as I know all devices under
Wireless for home and office
are omnidirectional even the wAP series for outdoor.
by afuchs
Thu Mar 03, 2022 9:19 am
Forum: Wireless Networking
Topic: Some Problem for My Daughter room
Replies: 1
Views: 537

Re: Some Problem for My Daughter room

Thanks for the map but it would be better if you can describe. witch room is yours and witch one is that of your daughter. I thing the first things you should check is if you got a better signal is you move your access point and if there is something moveable in the path, like a metal shelf or so. Y...
by afuchs
Wed Mar 02, 2022 5:21 pm
Forum: RouterBOARD hardware
Topic: Omnitik 5 PoE ac disconnect issue
Replies: 10
Views: 5199

Re: Omnitik 5 PoE ac disconnect issue

If you conned with the Winbox over ethernet or WLAN? Have you checked your uptime to bee sure that sure Omnitik and wAP ac aren't rebooting? Have you a 5 GHz (DFS/ radar) or a 2.4 GHz connection? Witch distance and are there obstetrical in the way (trees, cars, people, water lines,..)? Is the WLAN i...
by afuchs
Mon Feb 28, 2022 5:10 pm
Forum: Announcements
Topic: Mēris botnet information
Replies: 75
Views: 233648

Re: Mēris botnet information

If you want it more difficult and minimally safer, have a look here
https://wiki.mikrotik.com/wiki/Port_Knocking
There are some interesting thread in the forum too.
by afuchs
Fri Feb 25, 2022 4:49 pm
Forum: Beginner Basics
Topic: [Ask] 2 Mikrotik with 2 Network [SOLVED]
Replies: 2
Views: 5469

Re: [Ask] 2 Mikrotik with 2 Network [SOLVED]

You did not mention, witch network is on the connection between the routers. There a a couple of ways to to this, her is one example (eventually not the best): Crate a intermediate network like 172.16.0.0/30 (the network is freely chosen from a private network range, others can be used) Assign 172.1...
by afuchs
Fri Feb 25, 2022 2:20 pm
Forum: General
Topic: Big problem with Netwatch, Mikrotik loop restart
Replies: 17
Views: 3441

Re: Big problem with Netwatch, Mikrotik loop restart

How are you able to open an encrypted backup file in hex editor, search and change specific values, save and use it?
Is there no real encryption or where you able to decrypt and re encrypt the file?
by afuchs
Fri Feb 25, 2022 2:13 pm
Forum: Beginner Basics
Topic: Firewall rule for allow access only from a specific URL
Replies: 3
Views: 5709

Re: Firewall rule for allow access only from a specific URL

I Used this a Couple of versions but I am on 6.49.3 (because of dependencies with other systems). For an example I have created a address list 'google-Test' and used the URL 'www.google.de' (1). The Router resolved the url to the IP-Address (2). And I can use the address list in the firewall rules (...
by afuchs
Thu Feb 24, 2022 3:03 pm
Forum: General
Topic: Big problem with Netwatch, Mikrotik loop restart
Replies: 17
Views: 3441

Re: Big problem with Netwatch, Mikrotik loop restart

Well if yo have a other device, witch you can set the two IP-addresses on and connect to your Mikrotik so it could reach it (don't now your routing), you can perhaps get it done. I think of something like a second router as your simulated default ISP and fake hosts. If this doesn't work for you, res...
by afuchs
Thu Feb 24, 2022 2:18 pm
Forum: Beginner Basics
Topic: Firewall rule for allow access only from a specific URL
Replies: 3
Views: 5709

Re: Firewall rule for allow access only from a specific URL

You can use ip firewall address list.
You can add the public ip or the fqdn (url) to the address list and use it an the advanced tap of your firewall rule in 'Src. Address List' to accept the traffic.

Assuming that the URL can be resolved by the router, so you have a public dns service.
by afuchs
Thu Feb 24, 2022 12:15 pm
Forum: Beginner Basics
Topic: Can't ping between two specific LANs
Replies: 9
Views: 3878

Re: Can't ping between two specific LANs

Only to make it sure... For a while i came across some devices, that were only reachable on the same network, because they where configured/build that way. A few of these devices hat a option to change this behavior, other not. I had to google for a while to find the information. I think perhaps you...
by afuchs
Wed Feb 23, 2022 3:40 pm
Forum: Beginner Basics
Topic: Can't ping between two specific LANs
Replies: 9
Views: 3878

Re: Can't ping between two specific LANs

And if you hover with your mouse over the entry in the first column of firewall connection you got o popup like this:
popup.PNG
For a successful ping you need a SC, if you only get a C, than the router didn't get replay packets or the packets cant be matched to the request.
by afuchs
Wed Feb 23, 2022 3:18 pm
Forum: Beginner Basics
Topic: Can't ping between two specific LANs
Replies: 9
Views: 3878

Re: Can't ping between two specific LANs

If I understand your config right, it seams that you haven't multiple LANs on on port, you have some LANs on multiple Ports. /interface bridge port add bridge=bridge-VPN interface=eoip-GermanVPS add bridge=bridge-General interface=ether5-General trusted=yes add bridge=bridge-Software interface=ether...
by afuchs
Fri Feb 18, 2022 4:08 pm
Forum: General
Topic: Push same traffic to different devices
Replies: 13
Views: 1454

Re: Push same traffic to different devices

If you get a already a multicast, you only need clients on both devices to register to it.
If not you probably need something like a multicast proxy (if something like this exists and is legal to use).
by afuchs
Fri Feb 18, 2022 2:14 pm
Forum: General
Topic: Push same traffic to different devices
Replies: 13
Views: 1454

Re: Push same traffic to different devices

What do you mean with returning traffic? If you start a request on an Internal device (e.g. PC) to an external source (e.g. www.google.de) it doesn't make sense do direct the answer to a different internal device. If you have internal server that should be requestet from the Internet (e.g. own webse...
by afuchs
Wed Feb 09, 2022 5:31 pm
Forum: Beginner Basics
Topic: PCC example: What does Accept mean in prerouting chain ? [SOLVED]
Replies: 2
Views: 2386

Re: PCC example: What does Accept mean in prerouting chain ? [SOLVED]

The rules in your mean, that traffic to the IP-address ranges 10.111.0.0/24 and 10.112.0.0/24 that enters the Router of the LAN-Interface will be accepted, so the following mangle rules did not affect the traffic (first match). If you do not use such rules it the PCC rules could route your traffic. ...
by afuchs
Thu Feb 03, 2022 3:27 pm
Forum: Scripting
Topic: Function to convert B, KiB, MiB or GiB in a script
Replies: 18
Views: 4780

Re: Function to convert B, KiB, MiB or GiB in a script

I don't know, what you want to archive, but perhaps the 'monitor ' command could be something for you, but I have no idea if you can isolate one of the parameters. /interface monitor-traffic duration=1 ether4 name: ether4 rx-packets-per-second: 0 rx-bits-per-second: 0bps fp-rx-packets-per-second: 0 ...
by afuchs
Tue Jan 25, 2022 4:42 pm
Forum: Beginner Basics
Topic: VPN - Disable the use of the Internet via VPN
Replies: 16
Views: 6796

Re: VPN - Disable the use of the Internet via VPN

I use mainly SSTP-VPN with the Windows Internal Client, in some cases L2TP/IPsec (Apple can't run STTP without 3 Party products). In both of them, you can use the split tunnel option on Windows. But if you want to block internet traffic on your router, I don't know a other way to block it in the fir...
by afuchs
Fri Jan 21, 2022 5:49 pm
Forum: General
Topic: seek help
Replies: 24
Views: 2637

Re: seek help

In my office are 4 ethernet ports (wall outlets if it is the correct term), so I can switch to the port of my work college or the printer. By the way, we have offices with more ports and persons. How do you think about blocking the mining traffic with the firewall (if possible) or a separate (transp...
by afuchs
Fri Jan 21, 2022 5:24 pm
Forum: Beginner Basics
Topic: VPN Access via *mynetname.net
Replies: 44
Views: 19610

Re: VPN Access via *mynetname.net

Than you have only the option of port forwarding if the site-router has no public ip.
by afuchs
Fri Jan 21, 2022 4:39 pm
Forum: Beginner Basics
Topic: VPN Access via *mynetname.net
Replies: 44
Views: 19610

Re: VPN Access via *mynetname.net

You could forward the VPN -related ports or end the VPN on the main router. If you use the main Router for the VPN you have to choices: - extent the target network to the main router or - let the VPN end in a transfer network between the two routers, so you get a separate way for the VPN - clients. ...
by afuchs
Fri Jan 21, 2022 4:09 pm
Forum: General
Topic: seek help
Replies: 24
Views: 2637

Re: seek help

Why is it so important, that you assign a IP-Address to specific ethernet ports? Isn't it possible that someone use a other port? Perhaps something like the hotspot https://wiki.mikrotik.com/wiki/Manual:IP/Hotspot or a separate proxy can do the trick. The internal traffic is free, but to use the Int...
by afuchs
Thu Nov 25, 2021 5:41 pm
Forum: General
Topic: How to explain my boss about complexity of RouterOS
Replies: 9
Views: 2109

Re: How to explain my boss about complexity of RouterOS

Step 1: Do a demonstration how to configure something 'easy stuff', like dest. Nat for a couple of ports on multiple WANs and how to set up the filter rules, with your coworker AND your boss. Step 2: Decide if you want to 'help out' as a contractor, if you do it for free you will work the next years...
by afuchs
Mon Nov 08, 2021 4:14 pm
Forum: General
Topic: Detected conflict by ARP response (configuration error?)
Replies: 6
Views: 27475

Re: Detected conflict by ARP response (configuration error?)

Hello, I found this article https://forum.mikrotik.com/viewtopic.php?t=155523 which describes the same error massage. I am not sure if this could be helpful, because it describes, that the error is raised by the Mirkrotik-DHCP-Server, but the point There's a device configured with proxy-arp and acts...
by afuchs
Wed Nov 03, 2021 12:09 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 140
Views: 66117

Re: Mikrotik router Hacked!!!

Only because it's not on your list: - create a new user and delete the admin (don't use somtiing like 'noc' or other standards. - set up a massaging for logins, so you have the chance to notice if someone is working on it who shouldn't (e.g. email for system,account) Backups and configuration export...
by afuchs
Wed Nov 03, 2021 11:21 am
Forum: General
Topic: How many connection marks and packet marks can be set at the same time [SOLVED]
Replies: 3
Views: 2066

Re: How many connection marks and packet marks can be set at the same time [SOLVED]

After reading the forum article I am a bit confused. Caci99 wrote that the traffic should first marked for QoS an than for routing, but i can only find the Interfaces an a global queue. global-in and global-out are not shown in 6.49 and both WANs have different bandwidth so I must somehow adjust the...
by afuchs
Thu Oct 28, 2021 12:54 pm
Forum: General
Topic: How many connection marks and packet marks can be set at the same time [SOLVED]
Replies: 3
Views: 2066

How many connection marks and packet marks can be set at the same time [SOLVED]

Hello. I am confronted with the problem that 1 have a Mirktotik router with multiple WANs and the connection are marked with magle roules and the packetes get there routing mark. Now QoS for VoIP should be implemented but it seams that I need to set Connection marks for this (https://mum.mikrotik.co...
by afuchs
Wed Oct 27, 2021 4:52 pm
Forum: General
Topic: Detected conflict by ARP response (configuration error?)
Replies: 6
Views: 27475

Re: Detected conflict by ARP response (configuration error?)

Hello riwer, are there no duplicates of the MAC or have you also checked the ip address. I would recommend to start some pings to the mentioned IP address right before the check. It is possible that you have IP address is double assigned. If you have a pubic ip range from your ISP, check that you al...
by afuchs
Mon Oct 25, 2021 11:51 am
Forum: General
Topic: I need help converting pot forward to floating WAN [SOLVED]
Replies: 10
Views: 2342

Re: I need help converting pot forward to floating WAN [SOLVED]

Hello, the steps are correct, if you have multiple public IP addresses and you want the forward only at a specific one. This can be use to forward the same port to different internal targets like port 443 to 2 different web servers. If you have just one public IP address of you want the forward on a...
by afuchs
Thu Oct 21, 2021 4:19 pm
Forum: Forwarding Protocols
Topic: OSPF - Is it Possible to have a Backbone Area over a regular Area?
Replies: 3
Views: 3252

Re: OSPF - Is it Possible to have a Backbone Area over a regular Area?

The area ID of the production network is 0.0.0.2 and both router find another and exchange routes. The configuration of the virtual link is not complicated, set the Neigbor ID of the other router and and chose the production area for transit (first renounced encryption). But I get an error on the te...
by afuchs
Thu Oct 21, 2021 10:44 am
Forum: Forwarding Protocols
Topic: OSPF - Is it Possible to have a Backbone Area over a regular Area?
Replies: 3
Views: 3252

OSPF - Is it Possible to have a Backbone Area over a regular Area?

I have a setsing like below: OSPF.png On the main side is a special testing area behind an own router (RB1100AHx2) that is connected with the main router (CCR1009-8G-1S-1S) on the side over a production network. There are 3 other sides connected via VPN and the routes are distributed over the VPN wi...
by afuchs
Tue Oct 19, 2021 4:04 pm
Forum: General
Topic: IPSec error payload missing: ID_R
Replies: 8
Views: 15335

Re: IPSec error payload missing: ID_R

Hello, had someone found a solution for this problem? I have to setup a VPN to Microsoft azure and followed this instructions https://chadschultz.azurewebsites.net/2020/05/21/azure-vpn-gateway-and-mikrotik-ipsec-ike-configuration/. Unfortunately, I get the same error message and the instructions bel...
by afuchs
Fri Oct 15, 2021 4:59 pm
Forum: Beginner Basics
Topic: Seamless failover [SOLVED]
Replies: 20
Views: 11813

Re: Seamless failover [SOLVED]

In most cases I know the dynamic IP address only change, if you restart your router or you or your ISP reset the connection (most at night e.g. 1 am or so) and this result in a temporary loss of connections. There is one point in the video that I can't get. He uses a rule that block all traffic in t...
by afuchs
Fri Oct 15, 2021 11:44 am
Forum: Beginner Basics
Topic: Seamless failover [SOLVED]
Replies: 20
Views: 11813

Re: Seamless failover [SOLVED]

I am not sure how the it expert would do this. The First point is, to detected, that WAN1 is down, than you need to Switch to WAN2. So your Public IP-address must be migrated from WAN1 to WAN2 by your Provider or Skype must detect the change of your public IP and update your running session. I don't...
by afuchs
Fri Oct 01, 2021 10:45 am
Forum: General
Topic: Vendor-class and DHCP Options
Replies: 1
Views: 4047

Vendor-class and DHCP Options

Hello, I am supposed to use option 43 for 2 different kind devices in the same a network. How can I use the Vendor class to do this. The definition of the classes are no problem and I tested these with different ip pools. But it seems, that I can only assign one of the option 43 and I cant find any ...
by afuchs
Thu Sep 16, 2021 4:58 pm
Forum: General
Topic: Why firewall rules are so important...
Replies: 12
Views: 2717

Re: Why firewall rules are so important...

Maybe because you should avoid direct access via the Internet and rather connect via a VPN for administration?
The direct access via the Winbox is already bad enough, but with the web interface without restriction of the source IP it is more of a disaster.
by afuchs
Fri Aug 06, 2021 10:10 am
Forum: Wireless Networking
Topic: Scan wireless frequencies [SOLVED]
Replies: 1
Views: 1822

Re: Scan wireless frequencies [SOLVED]

If you use Winbox:
WLAN.PNG
by afuchs
Wed Aug 04, 2021 3:34 pm
Forum: Beginner Basics
Topic: Why interfaces don't work for firewall rules?
Replies: 12
Views: 1677

Re: Why interfaces don't work for firewall rules?

Lets recap. You have configured: 20 vlans on ether1 that is renamed to z0001/trunk every vlan has a 10.x.y.y network, with x as the number of den VLAn interface (not Vlan ID) you have ipv4-dhcp server for some VLANs, eg interface 0009 you have ipv6-dhcp server for some VLANs and /ipv6 nd prefix set,...
by afuchs
Wed Jul 14, 2021 4:20 pm
Forum: General
Topic: No Neighbors entries
Replies: 10
Views: 3055

Re: No Neighbors entries

Is neighbor discovery active on all devices?
Pleas look in Winbox under IP Neighbors or use /ip neighbor discovery-settings.
There should be a discover-interface-list. Are the interfaces to the other devices in the list?
by afuchs
Thu Jul 08, 2021 12:17 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 331
Views: 116510

Re: mDNS repeater feature

Hello, it would be useful because of apple. One of our customers had the problem, that some of his hotspot users log in and close the status site. After some time, they want to log out and they find it to complicated to use a url with an IP in it, so I set up a static dns entry like 'router.customer...
by afuchs
Tue Jul 06, 2021 4:58 pm
Forum: General
Topic: Public IP not access from local ip
Replies: 6
Views: 986

Re: Public IP not access from local ip

Hallo, if I understand it right, you can access the web service from all over the Worlld with your public ip address, right? And if you try to reach the web service from your local network with public ip address than it doesn't work? If this is the case, you need perhaps a Haripin NAT https://forum....
by afuchs
Tue Jul 06, 2021 4:44 pm
Forum: General
Topic: IPSEC Site-to-Site Routing
Replies: 13
Views: 3010

Re: IPSEC Site-to-Site Routing

Hello, 2 Questions; is there a policy to allow the PCs to connect to the DNS-server? (IP or network of your DNS-server to netzwork local PCs) (network loclalPCs to IP or netzwork of your DNS-Server) is it possible to set the local router as DNS-server for the local PCs and let the Router use your DN...
by afuchs
Fri Jul 02, 2021 3:34 pm
Forum: Wireless Networking
Topic: Dual radio, same ssid , preferred 5GHz band
Replies: 17
Views: 11484

Re: Dual radio, same ssid , preferred 5GHz band

normis didn't mentioned the feature requests for 802.11r/k, Band Steering (e.g. viewtopic.php?f=2&t=151536 of viewtopic.php?f=7&t=132817)
by afuchs
Thu Jul 01, 2021 1:57 pm
Forum: General
Topic: Then would you use arp, proxy-arp and local-proxy-arp
Replies: 4
Views: 2015

Re: Then would you use arp, proxy-arp and local-proxy-arp

Hello. First point, I use bridges to represent the networks (management , hotspot, etc.) on the devices. ARP enable is my default setting. If I set up a VPN (e.g. SSTP) I change the setting of the bridge of the target network to proxy-arp. Why? Because the VPN-client get a IP-address of the same Net...
by afuchs
Wed Jun 23, 2021 9:21 am
Forum: Beginner Basics
Topic: Network Diagram [SOLVED]
Replies: 4
Views: 39984

Re: Network Diagram [SOLVED]

I use yED https://www.yworks.com/products/yed (freeware).
If the basic icon set isn't enough you can add more, e.g. https://github.com/danger89/yEd_cisco_network_icons or create your own.
by afuchs
Thu Feb 25, 2021 9:25 am
Forum: General
Topic: Winbox Question
Replies: 8
Views: 1792

Re: Winbox Question

The .CBC file has all your saved connections not sessions in it (register Manged) or its empty, if you haven't one.
The easiest way would be to File -> Save As... to save it in a Folder of your choice and delete the other from your desktop.
by afuchs
Wed Feb 10, 2021 3:29 pm
Forum: General
Topic: WinBox shrink size on a device [SOLVED]
Replies: 4
Views: 1330

Re: WinBox shrink size on a device [SOLVED]

Hello, that sounds like an Issue with a saves Session (Winbox saves diffrend sessions even if you connect from the same PC to same router over different IP- adresses). Have you ever used the Zomm from Winbox on this session (Settings -> Zoom out)? Perhaps you have accidentally used the shortcut 'Ctr...
by afuchs
Mon Feb 01, 2021 6:00 pm
Forum: Scripting
Topic: Finding and disabling previous static DNS script [SOLVED]
Replies: 5
Views: 2328

Re: Finding and disabling previous static DNS script [SOLVED]

Or you can look in System Scheduler, because you can add script directly there. But it is not the only place where it could be! In this case it could also be a DHCP lease script. /export tells you what it is. Yes I know, but I want try a simple approach first, because some people have problems to r...
by afuchs
Mon Feb 01, 2021 4:49 pm
Forum: General
Topic: VPN IPSEC port change 500
Replies: 4
Views: 7037

Re: VPN IPSEC port change 500

I never used any other than the default ports, but perhaps, this is the setting:
IPSec-port.PNG
by afuchs
Mon Feb 01, 2021 4:44 pm
Forum: Scripting
Topic: Finding and disabling previous static DNS script [SOLVED]
Replies: 5
Views: 2328

Re: Finding and disabling previous static DNS script [SOLVED]

Or you can look in System Scheduler, because you can add script directly there.
by afuchs
Fri Jan 22, 2021 5:37 pm
Forum: General
Topic: 2 Mikrotiks on same layer 2
Replies: 15
Views: 2831

Re: 2 Mikrotiks on same layer 2

Hallo,

do you want to implement router redundancy in the event of a hardware failure?
In this case you should have a look to https://wiki.mikrotik.com/wiki/Manual:Interface/VRRP.
by afuchs
Wed Jan 13, 2021 1:31 pm
Forum: Beginner Basics
Topic: VLAN routing bottleneck on CRS354
Replies: 4
Views: 1056

Re: VLAN routing bottleneck on CRS354

This behavior is normal, because the trafic between to VLANs must be routed, witch is slower than the switching within a vlan. If you want to avoid the trunk to the RB, you must transfer the routing and firewall for the vlans to your switch (CRS - Cloud Router Switch)and use the TK only as a gateway...
by afuchs
Wed Jan 13, 2021 10:24 am
Forum: Beginner Basics
Topic: Port forwarding and firewall improvements [SOLVED]
Replies: 13
Views: 2929

Re: Port forwarding and firewall improvements [SOLVED]

I didn't see a /ip firewall filter add action=accept chain=forward dst-port=2302 protocol=udp add action=accept chain=forward dst-port=2302 protocol=tcp add action=accept chain=forward dst-port=2305 protocol=udp add action=accept chain=forward dst-port=2305 protocol=tcp or likewise in the export, so...
by afuchs
Fri Dec 04, 2020 10:57 am
Forum: Beginner Basics
Topic: Firewall Rules Check
Replies: 16
Views: 2297

Re: Firewall RuHello,les Check

Hello,

I search the IP '104.47.56.161' in Google and it's owned by "Microsoft Azure".
Could it be, that the device 192.168.1.239 try to send mails over a Microsoft 365 account?
by afuchs
Wed Sep 23, 2020 4:14 pm
Forum: Scripting
Topic: Export over api differs from export over terminal [SOLVED]
Replies: 5
Views: 3350

Re: Export over api differs from export over terminal [SOLVED]

Thanks mrz,

As I have seen, I cannot bypass the behavior by calling a backup script on the mikrotik router.
by afuchs
Mon Sep 21, 2020 4:15 pm
Forum: Scripting
Topic: Export over api differs from export over terminal [SOLVED]
Replies: 5
Views: 3350

Export over api differs from export over terminal [SOLVED]

Hello, I am testing the api usage and had written a little python-script based of RouterOS_API from LaiArturs ( https://github.com/LaiArturs/RouterOS_API ). I used the command "/system/package/update/install" to upgrade my test router from 6.47.3 to 6.47.4 and used "/export", &qu...
by afuchs
Mon Sep 21, 2020 2:59 pm
Forum: General
Topic: How to obtain inventory/usage of SFP modules?
Replies: 3
Views: 5364

Re: How to obtain inventory/usage of SFP modules?

Hello, I know my answer will be a little late, but I only had a similar problem just now. I used the following script to read out all ethernet interfaces, it can certainly be improved, but it's a start point. :foreach i in=([/interface ethernet find ]) do={ :local iterfacename [/interface ethernet g...
by afuchs
Fri Aug 07, 2020 3:17 pm
Forum: General
Topic: Help on Restoring RouterOS on RB951G-2HnD
Replies: 31
Views: 11877

Re: Help on Restoring RouterOS on RB951G-2HnD

Hello, regarding Netinstall I once had a problem that it didn't work even with deactivated Windows Firewall. After several attempts I found out that I have to deactivate the adapter for the WLAN interface on my laptop so that Netinstall can find the microtics via the Ethernet interface. I do not kno...
by afuchs
Mon Jul 13, 2020 3:18 pm
Forum: General
Topic: export data to database?
Replies: 4
Views: 2998

Re: export data to database?

On the Mikrtotik, the Configuration is easy. In a simple setting you only need to go to RADIUS add a New one, (IP-Adress and pre shared key) and bind it to the service (ppp). in PPP you must open the Tab secrets and set teh checkbox "Use Radius" under "PPP Authentication&Accountin...
by afuchs
Wed Jul 08, 2020 1:58 pm
Forum: General
Topic: ping problem
Replies: 8
Views: 4639

Re: ping problem

You could check the Firewall on the Mikrotik Router as well, or look after packet drobs in your log. Ther could be a rule in the outbound or Inbound chain, that cuts the traffic off. As a second check you can preform the ping with the interface or the IP address of the router set as source address. ...
by afuchs
Mon Jul 06, 2020 3:28 pm
Forum: Beginner Basics
Topic: Cannot import RSC file into Mikrotik - wrong config order
Replies: 5
Views: 2449

Re: Cannot import RSC file into Mikrotik - wrong config order

Hello, the error message says, that the interface list discover could not be found, so please check where the interface list is created. There muss some section like: /interface list add name=discover and a section where teh interfaces are added /interface list member add interface=ether1 list disco...
by afuchs
Mon Jun 01, 2020 11:33 am
Forum: General
Topic: Problem to setup an IPSec IKEv2 tunnel [SOLVED]
Replies: 2
Views: 4976

Re: Problem to setup an IPSec IKEv2 tunnel [SOLVED]

Thank you sindy.
I had overlooked the post in my search in the forum. As soon as I had taken over the configuration for myself, the tunnel was built.
by afuchs
Sun May 31, 2020 8:46 pm
Forum: General
Topic: Problem to setup an IPSec IKEv2 tunnel [SOLVED]
Replies: 2
Views: 4976

Problem to setup an IPSec IKEv2 tunnel [SOLVED]

Hello all. I am to set up an IPsec tunnel for a cloud telephone system. The system operator has provided instructions for this for a Lancom router ( https://service.swyx.net/hc/de/articles/360000466159-SwyxON-Anschluss-eines-Lancom-Gateway-an-SwyxON-mit-IKEv2 ). However, my configuration on an RB110...
by afuchs
Wed Mar 18, 2020 1:18 pm
Forum: General
Topic: export data to database?
Replies: 4
Views: 2998

Re: export data to database?

With 1000 ppp clients, I would consider using an external RADIUS server. In some settings we use the freeware TekRADIUS (Microsoft SQL Server (Expresse) or SQLLite) for hotspot authentication, but it can also be used for ppp dial-in.
by afuchs
Fri Jan 10, 2020 4:41 pm
Forum: Beginner Basics
Topic: Change network name [SOLVED]
Replies: 9
Views: 14077

Re: Change network name [SOLVED]

Perhaps you can use DHCP ( IP DHCP Server Networks) and set the Domain option (for AD-Domains) or set a WINS-Server.
DHCP-Networks.PNG
by afuchs
Thu Dec 19, 2019 2:52 pm
Forum: General
Topic: Blocking websites not working [SOLVED]
Replies: 11
Views: 7604

Re: Blocking websites not working [SOLVED]

If no other rule matches before (e.g. raw, prerouting) than the rule simple dosen't match.
First, do you try from 192.18.10.96? Your rule matches only traffic form this source.
What happen, wenn you set up a passthroug rule with log and only your Layer-7 regex?