Community discussions

MikroTik App

Search found 66 matches

by sebus46
Mon Aug 26, 2024 9:34 pm
Forum: RouterOS beta
Topic: Wireguard. How can i seen peer ip in Mikrotik?
Replies: 7
Views: 7407

Re: Wireguard. How can i seen peer ip in Mikrotik?

And how to check if Mikrotik AS CLIENT itself connects to the remote server? (as in 3rd party VPN service) ?
by sebus46
Mon Aug 26, 2024 8:42 pm
Forum: Beginner Basics
Topic: 2WAN as Failover and Setup Wireguard KEY as Client [SOLVED]
Replies: 36
Views: 9022

Re: 2WAN as Failover and Setup Wireguard KEY as Client [SOLVED]

Same setup but using Surfshark VPN (private key needs to be specified on WG interface) I use DoH only on MT, any idea how to deal with DNS for the LAN iOS clients? (when only certain ones are to use the tunnel via routing rules) If they are normal devices with DHCP reservations then I can do a diffe...
by sebus46
Mon Aug 26, 2024 7:28 pm
Forum: Beginner Basics
Topic: Surfshark VPN does not work with WG on MT
Replies: 19
Views: 9124

Re: Surfshark VPN does not work with WG on MT

Surfshark VPN finally works with my Hex S and Wireguard These instructions are incomplete, at least missing private key part and DNS entries (as one gets from Surfshark account configuration download) One must create WG-Surfshark interface with private-key="YOUR PRIVATE KEY as generated on Sur...
by sebus46
Mon Aug 26, 2024 6:18 pm
Forum: Beginner Basics
Topic: Surfshark VPN does not work with WG on MT
Replies: 19
Views: 9124

Re: Surfshark VPN does not work with WG on MT

Exactly the same USI

Make sure you have check-gateway="none"
by sebus46
Sat Aug 10, 2024 2:30 pm
Forum: Beginner Basics
Topic: can not ping 8.8.8.8 from my MT router
Replies: 11
Views: 4573

Re: can not ping 8.8.8.8 from my MT router

Experienced the exact same today. From client can ping 8.8.8.8, but NOT from Mikrotik itself [admin@MikroTik] > ping 8.8.8.8 SEQ HOST SIZE TTL TIME STATUS 0 8.8.8.8 timeout 1 8.8.8.8 timeout 2 8.8.8.8 timeout 3 8.8.8.8 timeout sent=4 received=0 packet-loss=100% Cludflare works [admin@MikroTik] > pin...
by sebus46
Sat Aug 10, 2024 1:42 pm
Forum: Beginner Basics
Topic: Route via a Specific Interface Only
Replies: 16
Views: 6086

Re: Route via a Specific Interface Only

Thank you!
by sebus46
Sat Aug 10, 2024 11:38 am
Forum: Beginner Basics
Topic: Route via a Specific Interface Only
Replies: 16
Views: 6086

Re: Route via a Specific Interface Only

I assume these gateway addresses are just VERY BAD examples
You cannot route via Google/Cloudflare DNS servers! (unless I am missing something or not understanding it)
by sebus46
Fri May 31, 2024 8:56 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 68
Views: 42098

Re: Black list for failed login to IPSec VPN

I will test it (but had zero attempts in last few days after locked my router to only UK addresses - as the "attacks" normally come from elsewhere further East)
Would still like to know why the other script does the odd input of 0.0.0.0
by sebus46
Wed May 29, 2024 5:58 pm
Forum: Scripting
Topic: Howto disable/delete a route by parameters, not by number?
Replies: 9
Views: 21035

Re: Howto disable/delete a route by parameters, not by number?

Can't do it

/ip route remove [find where immediate-gw="ether10-HeyB"]
no such item (4)
by sebus46
Fri May 24, 2024 9:47 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 68
Views: 42098

Re: Black list for failed login to IPSec VPN

Definitely the same, script inputs 0.0.0.0 to the list
by sebus46
Wed May 01, 2024 7:50 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 2256

Re: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

I have no issue applying it (and it works) but Winbox GUI cannot handle the display of it!

Image

The prefix is not displayed. It is 0 but even zero ideally should show
by sebus46
Wed Apr 24, 2024 8:02 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 2256

Re: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

That is really nice, thanks

But Winbox GUI cannot handle the display of this rule
by sebus46
Mon Apr 22, 2024 8:25 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 2256

Re: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

Had to use Routing / Rules to "lookup only" in WAN2 table for specific addresses to go out to internet using WAN2 But also had to add additional rules for the same addresses, ABOVE, using main table for the local network access for these devices that are set to use WAN2 table Otherwise the...
by sebus46
Tue Apr 16, 2024 11:08 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

...make an existing IP static then take out the MAC address and enter a client ID there and save. Either way, iOS devices get their IP with no issues here on both ROS 6 and 7. Worth a try at least? Will test more (with all devices), but quick test seems to have worked. Thanks edit 1: No dice, next ...
by sebus46
Tue Apr 16, 2024 11:01 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

17.4.1 no, no security apps (and what would any do anyway in case of dynamic vs static IP from same DHCP server?)
by sebus46
Tue Apr 16, 2024 9:59 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

No, sorry, does NOT work (with any iPhone in the house) Each & every one fails the exactly same (as per first post) Dynamic works, Static never allows connection (Offer/Bound/Declined) It does happen with ANY address (ie one that could have NEVER previously be issued/used like 192.168.88. 250 ) ...
by sebus46
Tue Apr 16, 2024 9:51 pm
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

Re: SIP phone cannot register from VLAN [SOLVED]

Just in case anybody ever comes across it Of course the "gods" here can say that I have this or that wrong etc, but the fix was to get one extra rule in IP Firewall/Filters as first in forward chain ;;; voip2 allow chain=forward action=accept protocol=udp src-address=VOIP_SERVER_IP dst-por...
by sebus46
Sat Apr 13, 2024 6:51 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Anybody eny ideas? This is not a RoS Issue ... this is an Apple Setting that you must change if you want the Apple device to get a static IP I will use an iPhone as an example: On the iPhone Go to Settings and Wi-Fi THEN touch the i that is encircled turn off ==>> Private Wi-Fi Address This will en...
by sebus46
Sat Apr 13, 2024 10:43 am
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Ok, with such an attitude I guess you are not seriously trying to resolve the issue then. If you are serious, be nice towards people who are trying to help you and read up on https://debug.guide/. Debugging like that guide specifies is part of real life for technicians too! Thanks for this (not tha...
by sebus46
Sat Apr 13, 2024 10:41 am
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Oh well, not much help here (not that I expected any) I lost faith in this community some time ago. No, I have no extenders. Each & any other device (but iOS) work perfectly fine Same iOS device(s) on another network work perfectly fine. So I am remaining unbias, but if you have only 2 devices i...
by sebus46
Fri Apr 12, 2024 8:45 am
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Can you reproduce the issue on a clean RouterOS install with a minimal configuration? Do you have Private Wifi enabled on iOS? Also latest iOS installed, I think that's 17.4.1? Answers already in first post (if one reads all) Well, it is called real life. One does not have luxury of clean router se...
by sebus46
Thu Apr 11, 2024 8:29 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Am I the only one with this issue?

Probably not
by sebus46
Wed Apr 10, 2024 7:48 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

Re: 7.14.1 iOS cannot be static in DHCP

Apple iOS
by sebus46
Wed Apr 10, 2024 8:38 am
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 2389

17.4.1 APPLE iOS cannot be static in DHCP

iOS 17.4.1, tried with 3 separate devices If I try to either convert existing lease to static OR create brand new entry ( it does not matter if MAC is real or Private WiFi Address ) the behaviour is always the same In DHCP I see: offer, bound, declined dhcp-vlan1 (defcon) client 2E:CE:6B:FC:93:A6 de...
by sebus46
Fri Mar 29, 2024 2:44 pm
Forum: General
Topic: Drop all from WAN not DSTNATed
Replies: 13
Views: 7406

Re: Drop all from WAN not DSTNATed

My two cents. The use of ! is tricky and should be avoided by new users as its a powerful tool (using a chainsaw when a butter knife is needed). Being cool is not a reason to use it. Do not want to upset higher powers. The 3 rules are indeed clear & logical, but that is 3 lines of code. Was the...
by sebus46
Fri Mar 29, 2024 12:40 pm
Forum: General
Topic: Wireguard Client - Handshake for peer did not complete
Replies: 22
Views: 25497

Re: Wireguard Client - Handshake for peer did not complete

Looking at that last diagram was that from your PHONE?? The GUI picture???? Reason is there is an address that doesnt fit on it what is........ 192.168.77.2/24 Which device is that? To be clear ITS NOT EVEN THE WIREGUARD ADDRESS schema ?????????? That address somehow is auto generated by RouterOS i...
by sebus46
Fri Mar 29, 2024 12:12 am
Forum: General
Topic: Wireguard Config File
Replies: 10
Views: 11623

Re: Wireguard Config File

Github specific repo is gone, but the plugin from NPP++ installs fine

Other repo exists here https://github.com/vladk1973/npp-plugins-x64
by sebus46
Tue Mar 26, 2024 9:45 pm
Forum: Beginner Basics
Topic: Basic Wireguard Setup
Replies: 13
Views: 19022

Re: Basic Wireguard Setup

deleted
by sebus46
Tue Mar 26, 2024 9:11 pm
Forum: General
Topic: Generating WireGuard peer configuration on MikroTik without shell access
Replies: 3
Views: 3047

Re: Generating WireGuard peer configuration on MikroTik without shell access

Is that (QR code) available? Cannot find it on 7.14.1
by sebus46
Tue Mar 26, 2024 2:17 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 2256

Re: Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

Thank you. Appreciate (even if you consider hosed, a basic clean config which fully works - just because something could be done different, that is very authoritarian view)
by sebus46
Tue Mar 26, 2024 1:37 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 2256

Re: Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

If you have a home subnet .88, then call it vlan88 and make it a vlan and then the config will make sense. and where is VLAN50 ???? /ip address add address=192.168.88.1/24 interface= bridge network=192.168.88.0 { wrong } add address=192.168.99.1/24 interface=vlan99 network=192.168.99.0 add address=...
by sebus46
Tue Mar 26, 2024 1:34 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 2256

Re: Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

Grateful for the comments, but I was not asking about my current config. I was asking how to make use of dual-wan (when it is here): - external traffic to the router itself?? aka VPN to stay on ISP1 (unchanged) - and that works just fine - traffic entering/leaving the router by VPN to stay on ISP1 (...
by sebus46
Sat Mar 23, 2024 12:23 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 2256

[solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

7.14.1 on RB4011iGS+ r2 (not complicated setup) # 2024-03-23 10:05:45 by RouterOS 7.14.1 # software id = 5WSQ-IVBW # # model = RB4011iGS+ # serial number = /interface bridge add arp=proxy-arp ingress-filtering=no name=bridge port-cost-mode=short \ vlan-filtering=yes /interface ethernet set [ find de...
by sebus46
Wed Dec 27, 2023 5:28 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ no power on PoE port 10
Replies: 3
Views: 1762

RB4011iGS+ no power on PoE port 10

Trying to power Yealink W70B IP phone base from port 10 (PoE out) But no dice, "force on", but getting no power on the unit Via proper PoE switch or injector, it works with no issue Anybody any ideas? I hope this - https://forum.mikrotik.com/viewtopic.php?t=161635&sid=de5d72217af234f3c...
by sebus46
Fri Jul 14, 2023 9:40 am
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

Re: SIP phone cannot register from VLAN [SOLVED]

As per full config, there is nothing UNTAGGED on Mikrotik (that is done on the switch to where the unit(s) actually connect (because they are PoE) Bridge is tagged for all required VLANs, I do not need VLAN filtering [admin@MikroTik] /interface/vlan> print Flags: R - RUNNING Columns: NAME, MTU, ARP,...
by sebus46
Fri Jul 14, 2023 12:45 am
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

Re: SIP phone cannot register from VLAN [SOLVED]

Yes, and it is above

Flags: X, D - DYNAMIC
Columns: BRIDGE, VLAN-IDS
# BRIDGE VLAN-IDS
0 bridge 1

I do NOT use it in my setup, VLANs are on bridge, I use ONLY 1 interface (ether2)
Everything is in full config on original post
by sebus46
Thu Jul 13, 2023 10:39 am
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

Re: SIP phone cannot register from VLAN [SOLVED]

Incoming SIP rules do not matter, we are talking about OUT connection for now (Register) I have posted full config (which is always what is asked for), but here are the bits: Flags: R - RUNNING; S - SLAVE Columns: NAME, TYPE, ACTUAL-MTU, L2MTU, MAX-L2MTU, MAC-ADDRESS # NAME TYPE ACTUAL-MTU L2MTU MAX...
by sebus46
Tue Jul 11, 2023 11:41 pm
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

Re: SIP phone cannot register from VLAN [SOLVED]

Nobody has any idea?
by sebus46
Sat Jul 08, 2023 3:27 pm
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

Re: SIP phone cannot register from VLAN [SOLVED]

It is EXTERNAL VoIP provider on the internet (nothing local)
by sebus46
Wed Jul 05, 2023 8:03 pm
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

Re: SIP phone cannot register from VLAN [SOLVED]

Anybody?
by sebus46
Sat Jul 01, 2023 2:53 pm
Forum: Beginner Basics
Topic: SIP phone cannot register from VLAN [SOLVED]
Replies: 11
Views: 4842

SIP phone cannot register from VLAN [SOLVED]

SIP phone --> D-link DGS-1210 switch --> Mikrotik RB4100 --> DSL modem If SIP (Yealink W70B) is on default LAN, it gets 192.168.88.20 & Registers fine at VoIP provider on Internet via DSL line out If I make the port on D-link untagged VLAN 21, W70B gets 192.168.21.2 and Registration FAILS (yet f...
by sebus46
Fri Jun 30, 2023 9:41 am
Forum: General
Topic: SIP Issues
Replies: 40
Views: 9397

Re: SIP Issues

Had very similar issue recently on Yealink W70B Outgoing calls fine, Incoming impossible , only error: this person's phone is currently unavailable Turned out that my provider used one server for Registration and another for Incoming calls So in Yealink had to disable : Accept SIP Trust Server Only ...
by sebus46
Sat Jun 24, 2023 11:54 pm
Forum: General
Topic: DoH server connection error
Replies: 7
Views: 7703

Re: DoH server connection error

Well, this is their final anwser :(
Screenshot 2021-11-08 140020.jpg
That is pathetic!
by sebus46
Thu Jun 22, 2023 8:27 pm
Forum: General
Topic: Bandwidth usage per IP
Replies: 29
Views: 24331

Re: Bandwidth usage per IP

Pity RB4011 does not have USB...
by sebus46
Wed Jun 21, 2023 11:52 am
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

Still, how can I get correct counters for this (or any other) PC? Unless you disable fasttrack you can't, because packets when are marked for fasttrack they are no longer processed by firewall, see https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack In fact if one inputs a dummy entry IP/Kid-control...
by sebus46
Tue Jun 20, 2023 10:30 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

Correct again. That was helpful: https://forum.mikrotik.com/viewtopic.php?t=180035 I still cannot get my head around the counters, dummy rule shows xxx, forward fasttrack shows xx, forward accept est/related/untracked shows x No matter how I want to add them, they do not equal, so lots goes through ...
by sebus46
Tue Jun 20, 2023 9:58 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

Yes indeed, expand in WB makes is as selected, thanks!

In fact scheduler to turn single rule on or off is much cleaner/simpler way to do it! Thanks again

Still, how can I get correct counters for this (or any other) PC?

sebus
by sebus46
Tue Jun 20, 2023 9:21 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

Well, it is not 24/7, it is daily 22:31 till NEXT day 6am
time=0s-23h59m,sun,mon,tue,wed,thu,fri,sat is INDEED the default (not user specified!)

But as I said, I have NO ISSUE with the rule executing correctly, it is only counters that are not logically correct
by sebus46
Tue Jun 20, 2023 8:00 pm
Forum: General
Topic: Feature request: rules groups or rules colors in WinBox
Replies: 9
Views: 3642

Re: Feature request: rules groups or rules colors in WinBox

Nice one, in absence of anything better, that is very good!
by sebus46
Tue Jun 20, 2023 7:01 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

If the machine starts connection only at ie 15:00 then it is in Allowed timeframe and to my logic: that should be the rule that carries on being used for this access (and the counters should be correct) Up to 15:00 there are NO connections Related to this machine), so no counters moving But once the...
by sebus46
Tue Jun 20, 2023 6:55 pm
Forum: Beginner Basics
Topic: Block all outbound ports except DNS, Http and Https
Replies: 6
Views: 14286

Re: Block all outbound ports except DNS, Http and Https

Either allow access from your torrent machine by IP or MAC OR figure out all the ports that torrent requires & allow them instead
Just a tiny bit of logic
by sebus46
Tue Jun 20, 2023 4:59 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

The fast track rule works on connections, not on machines.
But if machine is off, then the connection does not yet exists (to become fastracked)
by sebus46
Tue Jun 20, 2023 3:59 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

Probably was added in some past version, I was using filter rules since before it existed..
Anyway, not very exciting - viewtopic.php?t=129118
I just would like the normal rule to display the counters correctly...
by sebus46
Tue Jun 20, 2023 2:56 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

Thanks, did not think that something with no value still has impact add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ connection-state=established,related hw-offload=yes add action=jump chain=forward comment="--timerestr2--" \ jump-target=restrict-by-ti...
by sebus46
Tue Jun 20, 2023 2:47 pm
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Re: Time restrictions forward rule and counters [SOLVED]

Well, the connection does not exist, the machine is OFF It starts up from cold, so I do not see how it could become fastracked And if dummy rule #0 takes presedence, then what is the point of any rules at all? @rextended, the difference is connection-state="" (which is empty), so I must be...
by sebus46
Tue Jun 20, 2023 10:42 am
Forum: General
Topic: [SOLVED] RB4011 + FINISAR CORP SFP = no-link
Replies: 2
Views: 1033

Re: RB4011 + FINISAR CORP SFP = no-link

Had to change Speed from AUTO to manual 1Gb FD on both ends

While auto worked on RB2011 (ROS 6.48.x), it did not on RB4011 (RB 7.xx)

sebus
by sebus46
Tue Jun 20, 2023 10:33 am
Forum: Beginner Basics
Topic: Time restrictions forward rule and counters [SOLVED]
Replies: 21
Views: 2157

Time restrictions forward rule and counters [SOLVED]

In my forward chain I have: 16 ;;; defconf: fasttrack chain=forward action=fasttrack-connection hw-offload=yes connection-state=established,related 17 ;;; time restrictions upto 10;31 pm chain=restrict-by-time-2 action=reject reject-with=icmp-network-unreachable time=22h31m-23h59m,sun,mon,tue,wed,th...
by sebus46
Tue Jun 20, 2023 10:04 am
Forum: General
Topic: [Solved] DSL modem access
Replies: 3
Views: 444

Re: DSL modem access

User fault. I had wrong nat rule. This was used as guide: https://blog.dical.org/how-to-reach-ppp ... -mikrotik/
by sebus46
Sun Jun 18, 2023 2:43 pm
Forum: Scripting
Topic: Yet another DHCP to DNS script
Replies: 42
Views: 45458

Re: Yet another DHCP to DNS script

I spent some time cleaning up the original script by @dse to incorporate the following:
On ROS 7.10 I get in log few (for various static reservations):
DHCP2DNS (defconf): Failure during dns registration of npi508736.domain_name.home with 192.168.88.39
by sebus46
Sun Jun 18, 2023 9:57 am
Forum: General
Topic: VPN attacks? Blocking?
Replies: 10
Views: 13981

Re: VPN attacks? Blocking?

by sebus46
Sat Jun 17, 2023 8:11 pm
Forum: General
Topic: Accessing modem only
Replies: 4
Views: 2530

Re: Accessing modem only

by sebus46
Sat Jun 17, 2023 7:14 pm
Forum: General
Topic: [Solved] DSL modem access
Replies: 3
Views: 444

[Solved] DSL modem access

That used to work perfectly on 6.48.7 Now on RB4011 with 7.10 it simply does not. All config was re-created from scratch, using an existing export as help Both unis config for this part are identical I have main LAN on ether2 (192.168.88.0/24) ether1 is direct connection to DSL modem (bridge mode, h...
by sebus46
Sat Jun 17, 2023 5:43 pm
Forum: General
Topic: [SOLVED] RB4011 + FINISAR CORP SFP = no-link
Replies: 2
Views: 1033

[SOLVED] RB4011 + FINISAR CORP SFP = no-link

FTLF8524P2BNV-BR I previously used RB2011 with same transceiver to connect to D-Link DGS-1210-16 (using identical module) Had no issue. I expected RB4011 to carry on this setup But while the light shows in the transceiver, and the transceiver is recognized, I simply get no-link name: sfp1 status: no...
by sebus46
Sat Jun 17, 2023 5:37 pm
Forum: General
Topic: Certificate Key Import not possible on v7.7
Replies: 20
Views: 9600

Re: Certificate Key Import not possible on v7.7

I had an issue importing certificates, I checked my certificate and It had some blanck rows at the end. After deleting those rows I could import the certificate Lets Encrypt client 0.38 le64.exe The created crt does indeed have 2 blank lines at the very end That was not a problem ever up to 6.48.7 ...