Community discussions

MikroTik App

Search found 13 matches

by williamm
Sun Sep 29, 2013 1:14 am
Forum: General
Topic: Conditional forwarder with 443 port,
Replies: 3
Views: 2101

Re: Conditional forwarder with 443 port,

The problem in changing the SSTP port is that users are connecting from Windows machines and in the SSTP client there's not an easy way to change the port. Maybe I'll need to change the VPN protocol to another one like PPTP for instance. My first choice to SSTP was because user connects from differe...
by williamm
Sat Sep 28, 2013 6:01 pm
Forum: General
Topic: Conditional forwarder with 443 port,
Replies: 3
Views: 2101

Conditional forwarder with 443 port,

Hi, Currently we have one public IP and we are using a Mikrotik box as VPN server using SSTP protocol. Now our users needs to reach one internal https server and I cannot redirect the 443 port to that server because SSTP will stop to work. Is there a way to include some entries in the public DNS Ser...
by williamm
Mon Feb 08, 2010 4:17 pm
Forum: Beginner Basics
Topic: Connecting 2 MK's using IPsec, 1 side with dynamic IP
Replies: 4
Views: 9432

Re: Connecting 2 MK's using IPsec, 1 side with dynamic IP

Hi gregsowell, I've just checked your slides. Great job! I've considering the slides showing two Mikrotiks with one private IP even in my case I have both public IP's with one side being dynamic (PPPoE). You suggest to put the private WAN IP in SA Src Address from IPSEC policy but in my setup this s...
by williamm
Mon Jan 18, 2010 8:30 pm
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 59635

Re: IPSEC and NAT-T problem

sergejs, I really don't know why the log informs that about encryption-algorithm mismatch. Both the ipsec proposal and peer and configured with 3des. Maybe the "peer" in line logs refers to the ipsec client. And If you check the next line in logs, it's informed that the encryption peer is ...
by williamm
Sat Jan 16, 2010 10:22 pm
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 59635

Re: IPSEC and NAT-T problem

sergejs, Here is my /log print: 18:12:06 ipsec respond new phase 1 negotiation: 189.19.xxx.xxx[500]<=>201.1.xxx.xxx[500] 18:12:06 ipsec begin Identity Protection mode. 18:12:06 ipsec received broken Microsoft ID: MS NT5 ISAKMPOAKLEY 18:12:06 ipsec received Vendor ID: RFC 3947 18:12:06 ipsec received...
by williamm
Sat Jan 09, 2010 7:45 pm
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 59635

Re: IPSEC and NAT-T problem

sergejs, The RouterOS device is a Soekris x86 SBC model NET4501. It's running the L2TP/IPSec server with the following IPSec config: /ip ipsec proposal set default auth-algorithms=sha1 disabled=no enc-algorithms=3des lifetime=30m \ name=default pfs-group=modp1024 /ip ipsec peer add address=0.0.0.0/...
by williamm
Sun Jan 03, 2010 3:15 am
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 59635

Re: IPSEC and NAT-T problem

Well, I've just tried with v4.4 but with no success. Please "rpress" did you need to configure anything in /ip ipsec policy? I did not put anything there because I've let the /ip ipsec peer with Gererate Policy enabled. When connecting, the RouterOs creates two Installed SAs with the Publi...
by williamm
Mon Nov 16, 2009 6:12 am
Forum: Beginner Basics
Topic: Connecting 2 MK's using IPsec, 1 side with dynamic IP
Replies: 4
Views: 9432

Connecting 2 MK's using IPsec, 1 side with dynamic IP

Hi, I'm trying to connect 2 distant LAN's using one MK in each point. The 2 MK's reach the Internet through ADSL modems but one of them (let's call it Remote Router) has dynamic IP using PPPoe and the other has fixed IP (Local Router). I'm trying to set up the Local Router to generate automatically ...
by williamm
Thu Oct 29, 2009 3:29 am
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 59635

Re: IPSEC and NAT-T problem

Exactly, this Microsoft changing only should affect NAT servers but in my case also the server has a public IP so only the client is behind a NAT. Besides that, I've tried to change the client to a XP SP1 machine and the problem persists. Is there anyone who tried with the new v4.x software? Mine ha...
by williamm
Tue Oct 20, 2009 4:58 am
Forum: General
Topic: IPSEC and NAT-T problem
Replies: 60
Views: 59635

Re: IPSEC and NAT-T problem

Hi, I'm Experiencing exactly the same problem. RouterOS version is 3.20. The L2TP/IPSEC client is a Vista SP2 computer and is behind a NAT device (Dlink DI-624). The L2TP/IPSEC server is the Mikrotik with Public IP and NAT-T enabled. The log shows the same error: ipsec the length in the isakmp heade...
by williamm
Sun Sep 04, 2005 2:38 am
Forum: Scripting
Topic: Find Problem,
Replies: 2
Views: 1821

Find Problem,

Since I have several gateways (one without routing mark and others with routing marked for routing policy), I need to change them in a script. Using the exact example in docs (below), it changes all my default gateways. /ip route set [/ip route find dst-address="0.0.0.0/0"] gateway 10.0.0....
by williamm
Mon Apr 04, 2005 3:02 pm
Forum: General
Topic: [Changed] Policy routing with dynamic IP's
Replies: 2
Views: 1913

Hey Guys,

Am I the only one who has tried to connect a RouterOS into dual PPPoE gateways with dynamic IP´s?
by williamm
Sun Apr 03, 2005 3:19 am
Forum: General
Topic: [Changed] Policy routing with dynamic IP's
Replies: 2
Views: 1913

[Changed] Policy routing with dynamic IP's

Hi, I need to set up policy routing based on source address of my internal IP's. Some IP's from my internal network should reach Internet using gateway 01 and other internal IP's using gateway 02. The problem is that these two Internet interfaces are PPPoE clients with dynamic IP's. I have created ...