Community discussions

MikroTik App

Search found 66 matches

by minfrin
Mon Aug 19, 2024 11:42 am
Forum: RouterOS beta
Topic: Feature Request - NAT64/DNS64 CGN
Replies: 36
Views: 27639

Re: Feature Request - NAT64/DNS64 CGN

Would be great to have the IPv4 holdouts not hold the rest of us to ransom.

+1
by minfrin
Tue Oct 10, 2023 2:03 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM: Which port is sfp-sfpplus2?
Replies: 2
Views: 2328

CRS328-24P-4S+RM: Which port is sfp-sfpplus2?

I have someone at a remote site verifying where cables are plugged in, we have a CRS328-24P-4S+RM. The manual contains no pictures of the device, and we need a clear and unambiguous description of which port is which. Is sfp-sfpplus2 the top left SFP+ socket, or the bottom left SFP+ socket? The labe...
by minfrin
Sat Oct 07, 2023 8:15 pm
Forum: General
Topic: Netinstall stuck at "Waiting for RouterBOARD..."
Replies: 2
Views: 1131

Re: Netinstall stuck at "Waiting for RouterBOARD..."

There are multiple ways for firewalls to break things. In the case of Rocky9 you need to disable the firewall like this:
[root@netinstall ~]# service firewalld stop
by minfrin
Sat Oct 07, 2023 7:26 pm
Forum: General
Topic: Netinstall stuck at "Waiting for RouterBOARD..."
Replies: 2
Views: 1131

Netinstall stuck at "Waiting for RouterBOARD..."

Been stuck trying to un-brick a CAP XL ac, and have not got netinstall to work. Most specifically, netinstall hangs having done this: [root@netinstall ~]# ./netinstall-cli -a 192.168.88.1 routeros-7.11.2-arm.npk Version: 7.12rc1(2023-10-05 06:32:41) Interface Mask: 255.255.255.0 Using Client IP: 192...
by minfrin
Fri Oct 06, 2023 8:03 pm
Forum: RouterBOARD hardware
Topic: RouterOS 7.11.2 bricks CAP ac after routine update
Replies: 3
Views: 3675

RouterOS 7.11.2 bricks CAP ac after routine update

Hi all, Routine upgrade of a CAP ac: MMM MMM KKK TTTTTTTTTTT KKK MMMM MMMM KKK TTTTTTTTTTT KKK MMM MMMM MMM III KKK KKK RRRRRR OOOOOO TTT III KKK KKK MMM MM MMM III KKKKK RRR RRR OOO OOO TTT III KKKKK MMM MMM III KKK KKK RRRRRR OOO OOO TTT III KKK KKK MMM MMM III KKK KKK RRR RRR OOOOOO TTT III KKK K...
by minfrin
Sat Mar 04, 2023 12:16 pm
Forum: RouterBOARD hardware
Topic: RouterOS 7.8 bricked cAP XL ac
Replies: 14
Views: 6177

Re: RouterOS 7.8 bricked cAP XL ac

Tried a Rocky8 machine using a spare ethernet port, and a Latte Panda running Windows 10. My other options are an RPi and a Macbook Pro, neither will help. I am imagining that netinstall is something cobbled together in the past that only works under specialised circumstances. I see reports of peopl...
by minfrin
Sat Mar 04, 2023 11:21 am
Forum: RouterBOARD hardware
Topic: RouterOS 7.8 bricked cAP XL ac
Replies: 14
Views: 6177

Re: RouterOS 7.8 bricked cAP XL ac

Already tried downgrading netinstall to 7.7, no luck.

tcpdump shows that the device is making many bootp requests, but netinstall ignores these completely.

Just tried Windows, also no luck. Different switch, no luck.

I'm not entirely convinced that netinstall works properly.
by minfrin
Sat Mar 04, 2023 12:07 am
Forum: RouterBOARD hardware
Topic: RouterOS 7.8 bricked cAP XL ac
Replies: 14
Views: 6177

Re: RouterOS 7.8 bricked cAP XL ac

After the device starts, tcpdump immediately shows this: 21:03:17.598981 IP 0.0.0.0.bootpc > 255.255.255.255.bootps: BOOTP/DHCP, Request from 18:fd:74:3e:d7:b0 (oui Unknown), length 300 21:03:17.799113 IP 0.0.0.0.bootpc > 255.255.255.255.bootps: BOOTP/DHCP, Request from 18:fd:74:3e:d7:b0 (oui Unknow...
by minfrin
Fri Mar 03, 2023 6:44 pm
Forum: RouterBOARD hardware
Topic: RouterOS 7.8 bricked cAP XL ac
Replies: 14
Views: 6177

RouterOS 7.8 bricked cAP XL ac

Hi all,

Went through the standard update process for 7.7 to 7.8 on a cAP XL ac, and after a long time the device has not returned. Power and user lights on, E1 light flickering, not responding to mac-telnet.

Anyone encountered this before?

Regards,
Graham
--
by minfrin
Sat Oct 08, 2022 2:22 pm
Forum: RouterBOARD hardware
Topic: Numbering of SFP+ ports on the CRS328-24P-4S+RM - which one is sfp-sfpplus1?
Replies: 1
Views: 614

Numbering of SFP+ ports on the CRS328-24P-4S+RM - which one is sfp-sfpplus1?

Hi all, 10 0000 miles away from me right now is a CRS328-24P-4S+RM, reporting that sfp-sfpplus1 is connected and running to a downstream device. I also have a photo showing me that of the 4 SFP+ ports, the bottom left and bottom right ports are plugged into a cable. Alas the picture of the port numb...
by minfrin
Thu Sep 29, 2022 4:44 pm
Forum: General
Topic: LtAP and GPS: where is the date/time coming from when GPS has no signal?
Replies: 0
Views: 326

LtAP and GPS: where is the date/time coming from when GPS has no signal?

Hi all, I have an LtAP that has been incorrectly installed (a story for another day) with a GPS that reports no signal. This makes sense, as the device is sitting deep in a cupboard with no signal. However, despite reporting zero satellites, zero validity, the date-and-time is updated somehow and co...
by minfrin
Mon Aug 22, 2022 12:40 pm
Forum: General
Topic: LTE: how do I reply to a USSD message?
Replies: 0
Views: 420

LTE: how do I reply to a USSD message?

The manual at https://wiki.mikrotik.com/wiki/Manual:Tools/Sms#USSD_messages shows how to send a USSD message, and this works: /tool/sms/send lte1 phone-number="*136*1#" type=ussd I get a response inviting me to continue the conversation by sending "1". How do I sent the "1&q...
by minfrin
Sat Aug 20, 2022 10:51 am
Forum: General
Topic: LTE: How do you send a USSD message and receive a response?
Replies: 4
Views: 4190

Re: LTE: How do you send a USSD message and receive a response?

your lte1 is not registered (R) on gsm-only. Is supported from your modem and mobile operator? That cut and paste is between times while it was connected, it is back connected again. [minfrin@rescue] /interface/lte> print Flags: R - RUNNING Columns: NAME, MTU, NETWORK-MODE, APN-PROFILES # NAME MTU ...
by minfrin
Fri Aug 19, 2022 6:55 pm
Forum: General
Topic: LTE: How do you send a USSD message and receive a response?
Replies: 4
Views: 4190

Re: LTE: How do you send a USSD message and receive a response?

You must enable GSM or 3G, LTE only is not able to send USSD codes. Am I right in understanding that the following command enables GSM? [minfrin@rescue] /interface/lte> set lte1 network-mode=gsm [minfrin@rescue] /interface/lte> print Flags: R - RUNNING Columns: NAME, MTU, NETWORK-MODE, APN-PROFILES...
by minfrin
Fri Aug 19, 2022 5:24 pm
Forum: General
Topic: LTE: How do you send a USSD message and receive a response?
Replies: 4
Views: 4190

LTE: How do you send a USSD message and receive a response?

I have a Mikrotik LTAP RouterOS 7.4 with a R11e-LTE6_V034 firmware modem inside, with a simcard that I am trying to activate. Having read manuals and browsed forums I understand there are two mechanisms that can be used to send USSD messages, however there seems to be few details on where the respon...
by minfrin
Tue May 03, 2022 12:06 am
Forum: RouterBOARD hardware
Topic: CRS309-1G-8S+: Poor PPPoE performance
Replies: 8
Views: 4226

Re: CRS309-1G-8S+: Poor PPPoE performance

I'm confused - the Cloud ROUTER Switch is not a router - can you explain? An analysis of the router while loaded shows both CPUs on the device maxed out, so while CPU bound PPPoE does not appear to be single threaded. Do you have some kind of evidence to back up the claim that the RB4011, RB5009, et...
by minfrin
Sun May 01, 2022 1:10 pm
Forum: RouterBOARD hardware
Topic: CRS309-1G-8S+: Poor PPPoE performance
Replies: 8
Views: 4226

CRS309-1G-8S+: Poor PPPoE performance

Hi all, I have a CRS309-1G-8S+ that is routing a series of VLANs to the internet via a PPPoE connection provided by BT OpenReach. While the line is provisioned for a max download of 1000Mbps, the CRS309-1G-8S+ is maxing out both CPUs at around 400Mbps. Is there a way to get the CRS309-1G-8S+ to achi...
by minfrin
Sun Apr 10, 2022 11:46 pm
Forum: Beginner Basics
Topic: NTP stuck on Waiting....
Replies: 93
Views: 30139

Re: NTP stuck on Waiting....

Hi all, Posting my experience as it may help someone. Had same problem, NTP stuck in waiting. Eventually I discovered I could ping in one direction but not the other, odd. Turned out two interfaces on different VLANs were enabled for OSPFv3, and there was an asymmetrical route. As soon as OSPF was l...
by minfrin
Mon Mar 21, 2022 4:55 pm
Forum: RouterBOARD hardware
Topic: CRS305-1G-4S+IN with 1Gbps PPPoE - will it be fast enough?
Replies: 1
Views: 1245

CRS305-1G-4S+IN with 1Gbps PPPoE - will it be fast enough?

Hi all, I am considering a CRS305-1G-4S+IN to act as a router between a WAN port running PPPoE at 1Gbps, and the rest of the ports switched together. Will this router be fast enough to handle some modest routing, including IP masquerading and some basic filter rules at 1Gbps through the WAN port? Th...
by minfrin
Tue Mar 01, 2022 1:52 pm
Forum: General
Topic: Bug: /system routerboard usb excluded from export on LtAP
Replies: 0
Views: 194

Bug: /system routerboard usb excluded from export on LtAP

Hi all, Small bug I've found in RouterOS 7.1.3 on an LtAP. When the configuration is set as follows: /system routerboard usb> set type=mini-PCIe overriding the default value of type: USB-type-A This is excluded from the /export command. This breaks config backups, as the system routerboard usb setti...
by minfrin
Mon Feb 21, 2022 2:58 pm
Forum: General
Topic: Is my Serial Console enabled and switched on?
Replies: 2
Views: 520

Is my Serial Console enabled and switched on?

Hi all, I have a CRS328-24P-4S+RM, and have it's serial console plugged in. The serial console does not respond. Other serial consoles work on other devices, so we know the client side works fine. We have tried different cables, introducing null modem cables, nothing works. The question is, given th...
by minfrin
Wed Jan 19, 2022 9:45 pm
Forum: General
Topic: download.mikrotik.com does not work via IPv6
Replies: 3
Views: 1296

Re: download.mikrotik.com does not work via IPv6

Seeing the same problem alas. Little-Net:routeros minfrin$ wget -c https://download.mikrotik.com/routeros/7.1.1/routeros-7.1.1-mipsbe.npk --2022-01-19 21:38:58-- https://download.mikrotik.com/routeros/7.1.1/routeros-7.1.1-mipsbe.npk SSL_INIT Resolving download.mikrotik.com (download.mikrotik.com)......
by minfrin
Fri May 29, 2020 8:26 pm
Forum: General
Topic: Collectd monitoring via SNMPv3 - Timeout (plaintext scopedPDU header type 00: s/b 30)
Replies: 1
Views: 2989

Re: Collectd monitoring via SNMP - Timeout (plaintext scopedPDU header type 00: s/b 30)

Turns out all routerboards default to the same engine-id by default. This confuses net-snmp, and in turn collectd-snmp, which use one engine definition for all unrelated connections. One router works, all other routers reject the packets, and trigger the timeouts. Workaround is to manually set a uni...
by minfrin
Fri May 29, 2020 7:14 pm
Forum: General
Topic: snmp,debug v3 err: 1 not in time window or incorrect engine boots
Replies: 1
Views: 2817

Re: snmp,debug v3 err: 1 not in time window or incorrect engine boots

What it means is that two or more hosts (in this case routerboards) have the same SNMPv3 engine ID, and net-snmp has mixed up the hosts it has been told to monitor, and is using the engine ID from one router to send requests to another. In this case you will see one router return SNMPv3 data as norm...
by minfrin
Thu May 28, 2020 5:18 pm
Forum: General
Topic: snmp,debug v3 err: 1 not in time window or incorrect engine boots
Replies: 1
Views: 2817

snmp,debug v3 err: 1 not in time window or incorrect engine boots

Hi,

I have a router that responds as follows to an SNMPv3 request:

snmp,debug v3 err: 1 not in time window or incorrect engine boots

What does it mean, and how do I fix it?

Regards,
Graham
--
by minfrin
Sun May 24, 2020 2:07 pm
Forum: General
Topic: Collectd monitoring via SNMPv3 - Timeout (plaintext scopedPDU header type 00: s/b 30)
Replies: 1
Views: 2989

Collectd monitoring via SNMPv3 - Timeout (plaintext scopedPDU header type 00: s/b 30)

Hi all, Trying to monitor various routerboards using collectd. Snmpwalk using SNMPv3 works great, I can connect to the routerboards no problem. In the case of collectd, I can connect to one big switch and get a response, or two small switches and get a response, and more than that and the attempts t...
by minfrin
Thu Apr 30, 2020 12:42 am
Forum: RouterBOARD hardware
Topic: hEX S + SFP+ in the near future?
Replies: 1
Views: 1499

hEX S + SFP+ in the near future?

Hi all,

Is there any chance of one of these with SFP+ on the roadmap?

https://mikrotik.com/product/hex_s

Regards,
Graham
--
by minfrin
Sun Feb 16, 2020 1:36 am
Forum: General
Topic: SCEP and https URLs: failure: Not a HTTP URL!
Replies: 1
Views: 2831

SCEP and https URLs: failure: Not a HTTP URL!

Hi all, When adding a SCEP server that is part of a wider SSL secured server, the following error occurs: [minfrin@router] /certificate> add-scep template=test-name scep-url=https://interop.redwax.eu/test/simple/scep failure: Not a HTTP URL! Are there plans to fix the SCEP client so that it can conn...
by minfrin
Sun Feb 16, 2020 1:11 am
Forum: General
Topic: Certificates and the Y2038 bug: invalid-after=jan/01/2038
Replies: 0
Views: 1860

Certificates and the Y2038 bug: invalid-after=jan/01/2038

Hi all, Testing some interoperability on routeros v6.46.3, and have picked up that a digital certificate cannot be valid past Jan 1 2038. The certificate in question is valid until Feb 6 16:38:56 2040. 1 T name="test-name_CA" issuer=CN=Redwax Interop Testing Root Certificate Authority 2040...
by minfrin
Mon Nov 19, 2018 12:18 pm
Forum: General
Topic: How do you use ssh agent forwarding on the routeros ssh client?
Replies: 9
Views: 5012

Re: How do you use ssh agent forwarding on the routeros ssh client?

Unfortunately port forwarding (whether using the command line or config) only allows you to jump one step past a mikrotik, and is therefore not useful in a secure environment.

Can you confirm when SSH agent forwarding will be supported?
by minfrin
Fri Nov 16, 2018 12:43 pm
Forum: General
Topic: How do you use ssh agent forwarding on the routeros ssh client?
Replies: 9
Views: 5012

Re: How do you use ssh agent forwarding on the routeros ssh client?

How do I get this supported by Mikrotik?

We have a strict no password policy, and the inability to forward keys make it difficult for us to enforce that policy.
by minfrin
Thu Nov 15, 2018 7:35 pm
Forum: General
Topic: How do you use ssh agent forwarding on the routeros ssh client?
Replies: 9
Views: 5012

How do you use ssh agent forwarding on the routeros ssh client?

Hi all, I have routerboard B, that I need to ssh to via routerboard A. All user accounts are protected by SSH keys. I am struggling to get ssh agent forwarding to work. When I log into routerboard A I can log into successfully, but when I log into routerboard B I am asked for a password, when I shou...
by minfrin
Wed Nov 14, 2018 11:36 pm
Forum: Beginner Basics
Topic: Need help - cannot enter admin page on CAP AC
Replies: 6
Views: 8063

Re: Need help - cannot enter admin page on CAP AC

I have exactly the same problem - brand new CAP ac, and it does not have an IP address on boot. No access to a PC, and therefore no ability to run winbox. DId you ever solve this? Edit: Moments later I stumbled on a post that recommended using /tool mac-telnet <MAC> from another mikrotik - this work...
by minfrin
Sat Oct 13, 2018 12:38 am
Forum: General
Topic: IKEv2 VPN and IPv6-tunneled-in-IPv6 - is this supported?
Replies: 2
Views: 1176

Re: IKEv2 VPN and IPv6-tunneled-in-IPv6 - is this supported?

Maybe you're looking for Cisco's ipv6 encapsulation with GRE header? You can add ipv6 in ipv6 by this method I think.
Will this work with a MacOS / iOS / Windows 10 VPN client?

Currently IPv4-in-IPv6 works with MacOS VPN IKEv2, looking for IPv6-in-IPv6.
by minfrin
Thu Oct 11, 2018 3:45 pm
Forum: General
Topic: IKEv2 VPN + Radius + EAP-TLS - why does the radius certificate have to be installed on the router?
Replies: 6
Views: 4780

Re: IKEv2 VPN + Radius + EAP-TLS - why does the radius certificate have to be installed on the router?

Wait. Depending on how the certificate of the RADIUS is generated (self-signed or signed by CA), the RADIUS server must provide the complete chain and the Mikrotik must either have that certificate itself (if it is self-signed) or the CA certificate (if it is signed by a CA) in its trusted certific...
by minfrin
Thu Oct 11, 2018 3:33 pm
Forum: General
Topic: IKEv2 VPN and IPv6-tunneled-in-IPv6 - is this supported?
Replies: 2
Views: 1176

IKEv2 VPN and IPv6-tunneled-in-IPv6 - is this supported?

I have successfully got an IPv4 tunnel running through an IPv6 connection, and this works successfully (for the record, the config is below). Does RouterOS support an IPv6 tunnel running through an IPv6 connection? If so, what must the policy look like to make this work? /ip ipsec mode-config add ad...
by minfrin
Fri Mar 02, 2018 3:41 pm
Forum: General
Topic: IKEv2 VPN + Radius + EAP-TLS - why does the radius certificate have to be installed on the router?
Replies: 6
Views: 4780

IKEv2 VPN + Radius + EAP-TLS - why does the radius certificate have to be installed on the router?

Hi all, I have successfully configured routeros to allow VPN clients to connect via IKEv2, backed with radius, and authenticating using EAP-TLS (no passwords). The config is below. What I discovered is that this configuration would only work if I took the private key and certificate of our radius se...
by minfrin
Fri Aug 07, 2015 3:52 am
Forum: General
Topic: IPv6 multicast - preventing the swamping of switch ports
Replies: 0
Views: 597

IPv6 multicast - preventing the swamping of switch ports

Hi all, I have an IPv6 multicast source that is providing a number of multicasted channels into a Mikrotik 750G on various multicast addresses. Other ports on the 750G are currently being swamped by the traffic, and I'm trying to find a way to cut this traffic down. I understand that Multicast Liste...
by minfrin
Thu Mar 05, 2015 7:38 pm
Forum: Wireless Networking
Topic: EAP-TLS, radius and Session-Timeout: timeout doesn't seem to have any effect
Replies: 0
Views: 1099

EAP-TLS, radius and Session-Timeout: timeout doesn't seem to have any effect

Hi all, I have an AP running a wifi network backed with radius and EAP-TLS, and this is working fine. What I'm struggling with is trying to convince the AP to re-authenticate the client with the radius server, just in case in the mean time, access has been revoked. I have configured the radius serve...
by minfrin
Tue Jun 11, 2013 7:46 pm
Forum: General
Topic: OpenVPN and IPv6
Replies: 11
Views: 6690

Re: OpenVPN and IPv6

I have managed to find references that say that IPv6 works with openvpn in ethernet mode (http://forum.mikrotik.com/viewtopic.php?f=13&t=38026#p187333), it would be good to get a definitive answer. What I have found is that the tunnel seems to be established without a problem, and IPv4 works. Th...
by minfrin
Tue Jun 11, 2013 3:31 pm
Forum: General
Topic: OpenVPN and IPv6
Replies: 11
Views: 6690

OpenVPN and IPv6

Hi all, I am trying to set up an openvpn server and a RouterOS ovpn client, and have successfully got this working for IPv4. I am now trying to set up openvpn to hand out an IPv6 address, and I am struggling, the openvpn side logs that an IPv6 address is offered to the RouterOS side, but the RouterO...
by minfrin
Mon Oct 08, 2012 1:57 pm
Forum: General
Topic: Feature request: SSL/TLS support for "/tool fetch" (https)
Replies: 4
Views: 2359

Feature request: SSL/TLS support for "/tool fetch" (https)

Hi all, Are there any plans to support https with /tool fetch? It turns out that /tool fetch is used to implement many of the dynamic DNS services, and because the password is revealed to the net in clear text, an attacker can take over the dynamic DNS account. I'd like a way to prevent this. Regard...
by minfrin
Sun Jun 17, 2012 6:26 pm
Forum: General
Topic: ipsec with remote-certificate: Invalid ID length in phase 1
Replies: 1
Views: 3657

Re: ipsec with remote-certificate: Invalid ID length in phas

Adding some more information, the message "Invalid ID length in phase 1" appears inside the racoon code, and means one of two things: - The DN of the certificate presented by server doesn't match the DN expected by the routerboard. - The user FQDN provided inside the subjectAltName doesn't...
by minfrin
Sat Jun 16, 2012 3:28 am
Forum: General
Topic: ipsec with remote-certificate: Invalid ID length in phase 1
Replies: 1
Views: 3657

ipsec with remote-certificate: Invalid ID length in phase 1

Hi all, I have configured a routerboard to establish an ipsec transport policy to an openswan peer, where both sides are authenticated with digital certificates, each one signed by a separate CA, one CA for (what will become) the concentrator, and a second CA for (what will become) the Mikrotik clie...
by minfrin
Tue Jan 10, 2012 6:25 pm
Forum: General
Topic: Wpa2-eap + radius Filter-Id - does this work?
Replies: 1
Views: 881

Wpa2-eap + radius Filter-Id - does this work?

Hi all, I have a wireless access point, configured to use wpa2-eap against a radius server to authenticate. So far, this works fine. I've configured the radius server to return the Filter-Id attribute in an effort to create a custom firewall rule for each person connected to the access point, but so...
by minfrin
Mon Jan 09, 2012 12:54 am
Forum: General
Topic: EAP and WISPr-Redirection-URL: redirecting users after login
Replies: 0
Views: 1258

EAP and WISPr-Redirection-URL: redirecting users after login

Hi all, I have an EAP-TLS secured network that allows people to authenticate using radius, and so far this is working fine. What I'd like to do, is for certain users, based on the radius response, I would like to redirect them to a given webpage on connection, like you would with a hotspot. I've tri...
by minfrin
Tue Dec 27, 2011 7:44 pm
Forum: Wireless Networking
Topic: iPhone4 to Mikrotik wpa2-eap - connection never completes
Replies: 3
Views: 2365

Re: iPhone4 to Mikrotik wpa2-eap - connection never complete

The message "dhcp2 offering lease ... without success" was the key in this case, I needed to add an entry beneath "/ip dhcp-server network" for that specific DHCP pool, which for some reason was missing.
by minfrin
Tue Dec 27, 2011 5:50 pm
Forum: Wireless Networking
Topic: iPhone4 to Mikrotik wpa2-eap - connection never completes
Replies: 3
Views: 2365

Re: iPhone4 to Mikrotik wpa2-eap - connection never complete

I had originally tried wpa2-eap, and the iOS v5.0.1 phone had failed with the same effect. I have now managed some more experimentation, a second iPhone4 running iOS v4.3.5 successfully connects, but for no clear reason the DHCP doesn't complete. If you attempt to renew the lease on the iOS v4.3.5 d...
by minfrin
Tue Dec 27, 2011 4:24 am
Forum: Wireless Networking
Topic: iPhone4 to Mikrotik wpa2-eap - connection never completes
Replies: 3
Views: 2365

iPhone4 to Mikrotik wpa2-eap - connection never completes

Hi all, I have configured a Mikrotik routerboard to have a wireless network that attempts to authenticate using EAP-TLS with a client certificate only, passed through to a radius server which verifies everything. So far, the radius server seems to be working correctly, and the user is accepted, but ...
by minfrin
Sat Jun 19, 2010 4:32 pm
Forum: General
Topic: After reboot, /ip dns changes revert to old settings
Replies: 1
Views: 902

After reboot, /ip dns changes revert to old settings

Hi all, I have a strange problem with /ip dns. I need to update the name of the DNS server server in routerboard, and so use /ip dns to change the settings. I can view the new settings, and the routerboard's DNS now works, so far so good. I then reboot the routerboard, and the old dns settings have ...
by minfrin
Sat Jun 19, 2010 4:28 pm
Forum: General
Topic: Routeros v4 upgrade via ssh (ie without winbox)
Replies: 2
Views: 1762

Routeros v4 upgrade via ssh (ie without winbox)

Hi all, I have some routerboards that are embedded within a site, and getting an internet connected windows laptop running winbox up onto the sloped roof of a set of buildings so we can click on "upgrade key" is going to be a health and safety issue for us. Does a method exist to get our l...
by minfrin
Sun Apr 11, 2010 10:47 pm
Forum: General
Topic: Cannot communicate securely with peer: no common encryption
Replies: 2
Views: 3237

Re: Cannot communicate securely with peer: no common encrypt

The clock was wrong (ntp problems, which I'm battling with separately), but the clock wasn't related in this particular case. I managed to restore the hotspot by deleting the certificate from the routerboard, reimporting it, then setting the "ssl-certificate" parameter within the hotspot-p...
by minfrin
Sun Apr 11, 2010 10:07 pm
Forum: General
Topic: Cannot communicate securely with peer: no common encryption
Replies: 2
Views: 3237

Cannot communicate securely with peer: no common encryption

Hi all, I have a 433 routerboard / routeros v3.30 that a while ago had been successfully been configured as a wireless hotspot, complete with an SSL certificate. This worked fine. Having just tried to connect to the hotspot after some time not using the hotspot, I suddenly receive the following erro...
by minfrin
Sun May 17, 2009 3:05 pm
Forum: Wireless Networking
Topic: Detail howto requested: separating traffic from a virtual AP
Replies: 2
Views: 1143

Re: Detail howto requested: separating traffic from a virtual AP

Linux is set up to handle VLAN tags, yes (the interface eth3.2 means "VLAN 2" on "interface 3"). Tcpdump is showing the tagged packets correctly, but ping didn't work.
by minfrin
Sun May 17, 2009 4:15 am
Forum: Beginner Basics
Topic: Setting the initial IP address - how?
Replies: 4
Views: 1403

Re: Setting the initial IP address - how?

This directly contradicts the advice given on the Miktrotik wiki here: http://wiki.mikrotik.com/wiki/Initial_MAC_Winbox_Connection Would it be possible to take this wiki page down, as it no longer seems accurate? I had no luck with a serial cable either, what eventually worked was to hard reset the ...
by minfrin
Sun May 17, 2009 2:50 am
Forum: General
Topic: IPsec secured L2TP tunnels - how?
Replies: 0
Views: 783

IPsec secured L2TP tunnels - how?

Hi all, According to the manual, underneath /ip ipsec peer, it is possible to have L2TP tunnels secured using ipsec: generate-policy (yes | no; default: no) - allow this peer to establish SA for non-existing policies. Such policies are created dynamically for the lifetime of SA. This way it is possi...
by minfrin
Wed May 13, 2009 1:21 am
Forum: Beginner Basics
Topic: Setting the initial IP address - how?
Replies: 4
Views: 1403

Re: Setting the initial IP address - how?

Some brief success with Darwine, the most recent development version (1.1.20) won't work, you need to use the latest stable version (1.0.1) for winbox to start. The success is short lived - winbox cannot find the routerboard, with one exception - if an attempt is made to leave the search window open...
by minfrin
Wed May 13, 2009 12:35 am
Forum: Beginner Basics
Topic: Setting the initial IP address - how?
Replies: 4
Views: 1403

Setting the initial IP address - how?

Hi all, I have a brand new routerboard, and I need to set its initial address. I tried to Google for details of what the default IP address might be, and came back with hits to say there isn't one (???). I found the page below, describing how I might run winbox.exe through the Darwine emulator for M...
by minfrin
Sun May 10, 2009 2:15 pm
Forum: General
Topic: ip dhcp-server: no such IP network on selected interface
Replies: 4
Views: 6879

Re: ip dhcp-server: no such IP network on selected interface

One thing I see: vlan-public and wlan-g-public have the same localnets. I would recommend changing one of them. That is probably the reason the wlan-g-public network assignment is messed up. It should look like this: 2 172.16.250.3/23 172.16.250.0 172.16.251.255 wlan-g-public but vlan-public has th...
by minfrin
Sun May 10, 2009 2:21 am
Forum: General
Topic: When an "invalid" flag appears, how do I find the reason?
Replies: 5
Views: 2193

Re: When an "invalid" flag appears, how do I find the reason?

What I am really trying to do is try set up a hotspot, it is not clear from the documentation whether you need to configure a dhcp server to be used by a hotspot, or whether the hotspot does this on its own. The attempt to create a hotspot using the hotspot setup wizard also results in a hotspot tha...
by minfrin
Sun May 10, 2009 1:05 am
Forum: General
Topic: ip dhcp-server: no such IP network on selected interface
Replies: 4
Views: 6879

Re: ip dhcp-server: no such IP network on selected interface

I continue on regardless, and I try to enter nothing as a DHCP relay, as I don't want to use a DHCP relay: dhcp relay: invalid value for argument relay Ok, so it wants a dhcp relay. So I try the default value: dhcp relay: 172.16.252.3 Select pool of ip addresses given out by DHCP server addresses to...
by minfrin
Sun May 10, 2009 1:00 am
Forum: General
Topic: ip dhcp-server: no such IP network on selected interface
Replies: 4
Views: 6879

ip dhcp-server: no such IP network on selected interface

Hi all, While using the setup tool in an attempt to configure dhcp, I am getting an error message that I do not understand. First off, my ip addresses look like this: # ADDRESS NETWORK BROADCAST INTERFACE 0 172.16.252.3/24 172.16.252.0 172.16.252.255 wlan-a-backbone 1 172.16.250.2/23 172.16.250.0 17...
by minfrin
Sun May 10, 2009 12:48 am
Forum: General
Topic: When an "invalid" flag appears, how do I find the reason?
Replies: 5
Views: 2193

Re: When an "invalid" flag appears, how do I find the reason?

Yes:

3 172.16.250.3/23 172.16.250.3 172.16.250.3 wlan-g-public

It doesn't answer why no reason is given for the error. Is there is way to get some kind of human readable error message out of this?
by minfrin
Sun May 10, 2009 12:13 am
Forum: General
Topic: When an "invalid" flag appears, how do I find the reason?
Replies: 5
Views: 2193

When an "invalid" flag appears, how do I find the reason?

Hi all, After making an attempt to add a dhcp-server on a wifi interface, as below, the dhcp-server is flagged as "invalid": Flags: X - disabled, I - invalid # NAME INTERFACE RELAY ADDRESS-POOL LEASE-TIME ADD-ARP 0 I server1 ether3 dhcp-eth3 3d yes 1 I dhcp-public wlan-g-public public-pool...
by minfrin
Sat May 09, 2009 6:57 pm
Forum: Wireless Networking
Topic: Detail howto requested: separating traffic from a virtual AP
Replies: 2
Views: 1143

Detail howto requested: separating traffic from a virtual AP

Hi all, Does anyone have a detailed howto to solve the following problem: I have an access point, with a virtual AP configured inside it for public use. The main AP is protected WPA2, and works fine. The virtual AP is configured as an open system, and also works fine. What I am struggling to achieve...
by minfrin
Sat May 09, 2009 2:56 am
Forum: Wireless Networking
Topic: Public wifi, VLAN tagged, then connected to a Linux machine
Replies: 0
Views: 1191

Public wifi, VLAN tagged, then connected to a Linux machine

Hi all, I have a simple mikrotik wifi access point, which is plugged directly into a Linux router. I want to have two wireless LANs, one a private WLAN, which works fine, bridged to ether1, and a second public WLAN, bridged to VLAN-2, in turn attached to ether1. The first private WLAN works fine, th...