Maybe, define address list in /ip fir add then make 2 (two) rules for your "Transparent Bridging" as follows: chain=forward connection-state=related action=accept chain=forward connection-state=established action=accept chain=forward connection-state=new src-address-list=... action=accept ...
I suppose you to redirect tcp-80 to Mikrotik Proxy Server and then passthrough to your DansGuardian proxy. The traffic for redirect as follows: chain=dstnat protocol=tcp dst-port=80 src-address-list=filtered action=redirect to-ports=8080 make sure you have enabled ROS module > web-proxy, where runni...
If possible, pls a wishlist for custom tools for device, such as Remote Desktop connection, VNC Viewer, Radmin, etc.
Currently, from tools only: WinBox, Telnet, etc.
Thx.
Pls do not using user-manager hotspot (my me, hotspot is not time restriction.
Pls using standard transparent-proxy/proxy using nat or filter/firewall for time and days of week. Be caution, these features running well on RouterOS beta version 3.
For me, it is better using dynamic simple queue based on hotspot and/or user/group for ul/dl.
I ever did as you meant, hotspot environment is different, if you make /queue tree for priority where maybe work and will burden your M/T ROS. So, forget it. Let's it be as Mikrotik RouterOS doing.
For me, pls do not burden a lot of address-list for porn-site, will make your M/T ROS getting slow. Using another solution like from http://www.iss.net or alike solutions(s).
Several tips to block spam: from LAN > to Internal Mailserver: -use SMTP authentication in your mailserver, where it means that users from Outlook/Mozilla/etc must using their POP3 username and passwd when sending email -only permit trusted ip to send email without validation to your mailserver from...
For me, M/T ROS v3.0 b7 is very stable, we're using M/T RouterBOARD 532 as well as WRAP. Highly recommended for testing. Also, IGP such OSPF do the best.
There are only minor (? bugs) as follows:
-console has crashed if doing: /export file xxx
-dfs not working
Yes, I agree.
How to really know the next coming release of stable and powerful Mikrotik RouterOS if not tested in real/production. We must test it in isolated live environment.
Also happen to me (at M/T ROS v.3beta7), dfs is not working also.
Just set the M/T as: ap-bridge, band: 2.4GHz b-g, 2412MHz, scan-list: 2412,2437,2462, freq-mode: manual-txpower. dfs-mode: radar detect.
Let's try to: -on /ip fir addr, just add the ip-addr or name of your specific website -on /ip firewall filter > on extra: hotspot select: from client -and just reject with tcp-reset for more detailed information regarding hotspot, pls: -ip firewall filter print dynamic -ip firewall nat print dynamic...
you have 1-ISP with 3-Public ip-addr, to use all of your three public ip just pls using: - on /ip route, pls mention pref-src on default - using the other 2-public ip-address for src-nat on your src-adress-group - also, you are able to to chain=dstnat to allow traffic from INTERNET > INTERNAL LAN wi...
Yes, pls always do backup with:
-on WinBOX, click click File and Backup
-on Terminal, /system backup save
will guarantee if something happen on your M/T ROS beta version, pls using Netinstall to downgrade to v2.9x and wil do restore it again.
It is very simple. Ok?
May the the newest version of Mikrotik RouterOS (currently, on version 3.0 beta 7) will outperform on OLSR, pls review some of the materials on http://mum.mikrotik.com.
Yes, of course you could do that with:
-redirect incoming traffic on port tcp-26 (for example, not port 25/stmp), and just pls to specify src-address-list on your M/T ROS, and on your incoming mailserver in lan/private segment to allow the specific ip-address to allow smtp relaying. May help ...
or the alternative resolution to resolve your BIOS upgrade on your Mikrotik RouterBOARD are: -make sure from M/T RouterOS you are able to ping such as http://www.yahoo.com and getting good reply if not: pls just setting: /ip route, and setting the right gateway, /ip dns (setting the right 1st/2nd fo...
from Winbox, pls see the ip-addr, change your computer ip-address with the same subnet but different ip-addr. Pls just using Winbox (for your information, there are two kind of winbox version right now, v.2.2.10 and v.2.2.11. Just using v.2.2.10, pls download from http://www.mikrotik.co.id/getfile.p...
I agree with Normis to not running M/T ROS on USB because of USB device is not suitable for running powerful Mikrotik RouterOS (except for just for testing purposes. Pls just using the device/hardware as recommended from Mikrotik. This is very stable system that must be running on stable device(s), ...
Just pls to mention of what: -wireless radio; -what type of antenna; -how many km to p2p or p2mp my recommendations are: -just follow the documentation from Mikrotik documentation as well as search for nstreme in all forums; -using 48v power supply -(maybe) using combination of ap/ap-bridge with wds...
-on "Connection Tracking", TCP Established Time-out change from 1d to 01:00:00
-pls do not using many rules on mangle, nat, and/or filter
-pls do not activate modules on Mikrotik RouterOS you do not needed it