Community discussions

MikroTik App

Search found 22 matches

by swa69er
Thu Feb 09, 2023 6:06 am
Forum: Beginner Basics
Topic: Efficient way to Isolate client / IP address
Replies: 8
Views: 1603

Re: Efficient way to Isolate client / IP address

From your config, better using VLAN. All port except WAN into bridge-port. I use https://forum.mikrotik.com/viewtopic.php?t=143620 for my RB4011 and hAP-AC3. In my case I dont need VLAN tag for my dumb-AP after the mikrotik. Thank you for your suggestion. Will consider learning VLAN Not sure what y...
by swa69er
Wed Feb 08, 2023 9:49 am
Forum: Beginner Basics
Topic: Efficient way to Isolate client / IP address
Replies: 8
Views: 1603

Re: Efficient way to Isolate client / IP address

V6 firmware /export hide-sensitive file=anynameyouwish (minus router serial number, public WANIP information, keys etc ) V7 firmware /export file=anynameyouwish (minus router serial number, public WANIP information, keys etc ) I'm on V7.7 and tried everything, even hide sensitive still I can found ...
by swa69er
Tue Feb 07, 2023 7:16 am
Forum: Beginner Basics
Topic: Efficient way to Isolate client / IP address
Replies: 8
Views: 1603

Re: Efficient way to Isolate client / IP address

To export and paste your configuration (and I'm assuming you are using WebFig or Winbox), open a terminal window, and type (without the quotes) "/export hide-sensitive file=any-filename-you-wish". Is hide sensitive only for password? Is there any way to hide Wireguard public key, comments...
by swa69er
Mon Feb 06, 2023 7:12 pm
Forum: Beginner Basics
Topic: Efficient way to Isolate client / IP address
Replies: 8
Views: 1603

Efficient way to Isolate client / IP address

Greetings, There was a breach long time ago because I'm still learning Mikrotik and managing hundreds of client in multiple sites. I want to check my sanity level on firewall. My raw firewall is 150 lines because I'm a little anxious. At the moment, I'm isolating client just like in the attachment. ...
by swa69er
Fri Sep 02, 2022 2:56 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 75482

Re: v7.5 [stable] is released!

RB5009UGS v7.4.1 to v7.5 so far so good. no issue at the moment
by swa69er
Sat Jun 11, 2022 8:24 pm
Forum: General
Topic: Kernel panic after upgrade from 7.1 to 7.2 VPS x86 CHR [SOLVED]
Replies: 6
Views: 2303

Re: Kernel panic after upgrade from 7.1 to 7.2 VPS x86 CHR [SOLVED]

on AWS EC2 CHR tried to upgrade 7.2 to 7.3 not working
create new instance from 6 to 7.3 its working

I don't like to start again config from beginning, export import cert, etc

is there any solution?
by swa69er
Fri May 27, 2022 7:53 am
Forum: The User Manager
Topic: hotspot login page disconnect after while
Replies: 18
Views: 11641

Re: hotspot login page disconnect after while

basic hotspot + queue is working properly now starting v7.3beta37
trying on beta40 still disconnect after a while
my solution is trying to reboot several times :D
by swa69er
Fri May 27, 2022 7:50 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 112933

Re: v7.3beta [testing] is released!

Screenshot (109).png

Brand new RB5009UGS on v7.3beta40 suddenly, ohhhh!
running hotspot, queue, ovpn, seems normal

WAN eth is barely any packet around 1Mbps
by swa69er
Tue May 17, 2022 5:16 am
Forum: The User Manager
Topic: hotspot login page disconnect after while
Replies: 18
Views: 11641

Re: hotspot login page disconnect after while

I'm planning to buy RB5009 for hotspot. Is this still a problem in v7?
by swa69er
Sun May 08, 2022 9:35 am
Forum: Beginner Basics
Topic: defcon firewall + custom firewall where to put?
Replies: 4
Views: 1328

Re: defcon firewall + custom firewall where to put?

Preferably after default configuration as curernt default config is pretty safe. The last rule in default config drops anything not coming in from LAN. So when adapting default config beware that most guides found on net (mikrotik's own included) predate the current config, hence it's not wise to s...
by swa69er
Sat May 07, 2022 10:43 am
Forum: Beginner Basics
Topic: defcon firewall + custom firewall where to put?
Replies: 4
Views: 1328

defcon firewall + custom firewall where to put?

Last week my MT bricked. I check there are some attack in the network. First netcut, dhcp failed, and some open port 4444 used by malware I'm not networking professional, I found some firewall article that can protect my MT First advanced defcon firewall from MT https://help.mikrotik.com/docs/displa...
by swa69er
Sun Apr 24, 2022 10:40 pm
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 240
Views: 51429

Re: v7.2.1 [stable] is released!

I was too excited about Wireguard on V7 so I upgraded all my site to V7 and done well with site to site VPN. And then suddenly I realized my hotspot page is not working and many people found the same problem here in the forum. So I have to downgrade all 5 sites back into V6.49 with OpenVPN and yes i...
by swa69er
Sat Sep 18, 2021 6:09 pm
Forum: General
Topic: DNS over HTTPS
Replies: 265
Views: 134802

Re: DNS over HTTPS

what is the difference between
1 certificate
https://cacerts.digicert.com/DigiCertGl ... CA.crt.pem

100000 certificate :D
https://curl.haxx.se/ca/cacert.pem

I have 3 router using only 1
but 1 other is not working so I have to use 100+ cert
by swa69er
Fri Aug 27, 2021 11:34 am
Forum: General
Topic: DoH Google certificate which one? [SOLVED]
Replies: 3
Views: 6788

Re: DoH Google certificate which one? [SOLVED]

The cacert.pem is the same list that most browsers and operating systems trust. So if you don't trust them, you have a bigger problem :). If you only want to import a specific certificate, inspect the certificate chain of eg https://dns.google/ in your browser and import the relevant root certifica...
by swa69er
Thu Aug 26, 2021 3:33 pm
Forum: General
Topic: DoH Google certificate which one? [SOLVED]
Replies: 3
Views: 6788

DoH Google certificate which one? [SOLVED]

I'm tried DoH Cloudflare and Google and verify DoH certificate work flawlessly when configure DoH for Google, some tutorial told me to download certificate from this site https://cacerts.digicert.com/DigiCertGlobalRootCA.crt.pem I think this one is for Cloudflare, right? and this https://curl.haxx.s...
by swa69er
Tue Apr 06, 2021 3:43 am
Forum: Virtualization
Topic: VPN using CHR (VPN clients can't see an MKT connected as VPN client)
Replies: 1
Views: 6207

Re: VPN using CHR (VPN clients can't see an MKT connected as VPN client)

You have similar problem with me in viewtopic.php?f=15&t=173880&p=850505#p850505
I'm using L2TP/IPSec and CHR on AWS

I encountered your problem before can't see can't ping some of devices
I believe this is routing problem either in cloud CHR or hAP
by swa69er
Sat Mar 27, 2021 7:10 am
Forum: Virtualization
Topic: AWS CHR as L2TP IPSec VPN site-to-site not working
Replies: 0
Views: 6558

AWS CHR as L2TP IPSec VPN site-to-site not working

Hello, my goal is to adopt TP-Link AP from site B to its controller on site A we have Mikrotik CAP shortage in our country then I use TP-Link here is the topology https://i.ibb.co/rbCPjQ5/AWS-Mikrotik-CHR2.png I can ping everything I can see AP from OC200 controller but my problem is I can't adopt A...
by swa69er
Thu Mar 11, 2021 4:46 am
Forum: Useful user articles
Topic: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 (with certs) tunnel + EoIP
Replies: 11
Views: 27970

Re: Mikrotik (behind NAT) to Mikrotik IPSEC/IKE2 tunnel + EoIP on top of that

this is great tutorial I tried 1 router with Public IP and 1 non Public IP, behind NAT tried on AWS EC2 + CHR just follow the step it work perfectly Then I add another router without Public IP, behind NAT all 2 router PH2 state established but just for a minute when I flush installed SAs either 1 is...
by swa69er
Sun Feb 28, 2021 8:25 am
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 67
Views: 49687

Re: OpenVPN SHA256 + UDP

2021
am I the only one here still waiting for sha256, TLS auth, and auth without username/password?

for now I'm trying aws free tier + openvpn AS
I would like to try openvpn Cloud
by swa69er
Tue Feb 23, 2021 10:23 am
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 10305

Re: Double NAT & no public IP for VPN [SOLVED]

Depending on how the NATs in question behave, in particular whether the source port of a UDP packet sent from your router's WAN IP is kept as the packet goes through the NATs all the way to the public IP, it may be possible to establish an IPsec tunnel between the two devices. The source port must ...
by swa69er
Mon Feb 22, 2021 6:09 pm
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 10305

Re: Double NAT & no public IP for VPN [SOLVED]

Hello my friend. If both "routers" are "inside" network (not public IP) and you can't redirect ports, is IMPOSSIBLE" for reaching each other. Both are inside and is not possible to communicate directly both. The only "way" is finding somebody with a public IP allo...
by swa69er
Sat Jan 02, 2021 1:37 pm
Forum: General
Topic: Double NAT & no public IP for VPN [SOLVED]
Replies: 10
Views: 10305

Double NAT & no public IP for VPN [SOLVED]

Hello, this is my first post and I want to say Mikrotik is awesome, disruptive price in my country, best price per performance! but I have problem with VPN. My ISP give me only private ip address, and it's double NAT (first 2 hop is private ip) Tried almost everything and it doesn't work PPTP SSTP O...