Community discussions

MikroTik App

Search found 47 matches

by jonm
Sat May 17, 2008 12:29 am
Forum: General
Topic: Forwarding broadcast from pptp vpn
Replies: 3
Views: 1597

Re: Forwarding broadcast from pptp vpn

I am running 3.0. How do I bridge my client pptp vpn connections?
by jonm
Sun Apr 20, 2008 6:52 am
Forum: General
Topic: Forwarding broadcast from pptp vpn
Replies: 3
Views: 1597

Forwarding broadcast from pptp vpn

I'm trying to use a pp2p vpn server to play network games with friends. The connection works but we cannot see each other in the game. After doing some research it turns out the udp broadcasts are required and don't seem to work. Any ideas on how to get broadcast packets from vpn connections to forw...
by jonm
Sun Apr 20, 2008 6:38 am
Forum: General
Topic: PPTP Connected but cannot access other PCs
Replies: 4
Views: 2427

Re: PPTP Connected but cannot access other PCs

Okay. I rebooted the mikrotik router and the problem went away (weird).
by jonm
Sun Apr 20, 2008 3:42 am
Forum: General
Topic: PPTP Connected but cannot access other PCs
Replies: 4
Views: 2427

PPTP Connected but cannot access other PCs

I have setup a PPTP server using version 3.7. (1 NIC only, 192.168.1.50/24) I have mapped TCP 1723 through my firewall (along with GRE). I can connect remotely to my PPTP server. (connect and receive address 192.168.1.60) I can ping the server's IP address from remote client. (ping 192.168.1.50 from...
by jonm
Tue Jan 23, 2007 7:54 pm
Forum: General
Topic: Block non dhcp users?
Replies: 7
Views: 2128

Block non dhcp users?

I'm using static dhcp on one of my networks. I have a entry for each pc/printer with its mac address. Is there any way to block traffic coming (/ip firewall filter) if it is not coming from one of my dhcp people? For instance, if they assign a static address to their pc? Basically, I just don't want...
by jonm
Thu Jan 18, 2007 2:42 pm
Forum: General
Topic: Can't access my dst-nat web service from inside
Replies: 5
Views: 2119

do you think using src-nat without masquerading would work better.
Like this?

add chain=srcnat out-interface=OUT action=src-nat to-addresses=205.162.x.x to-ports=0-65535
by jonm
Thu Jan 18, 2007 2:24 pm
Forum: General
Topic: Can't access my dst-nat web service from inside
Replies: 5
Views: 2119

add chain=dstnat dst-address=205.162.x.x protocol=tcp dst-port=80 action=dst-nat to-addresses=172.16.0.6 to-ports=80


Here is the NAT rule, with the exception that I changed part of the dst-address to conceal the real IP.
by jonm
Thu Jan 18, 2007 1:45 pm
Forum: General
Topic: Can't access my dst-nat web service from inside
Replies: 5
Views: 2119

Can't access my dst-nat web service from inside

Mikrotik box, 2 network cards, INSIDE and OUTSIDE. I'm using masquerading to allow the private inside network access to the internet. I'm also using dstnat to map through port 80 to a webserver on the private INSIDE network. Here's the problem I can access the webservice with its OUTSIDE/PUBLIC addr...
by jonm
Tue Dec 12, 2006 9:27 pm
Forum: General
Topic: linksys WRT54GSV4 will not connect
Replies: 2
Views: 1296

We've been running mirotik PPPoE server for our wISP clients for a couple of years. Occasionally we do have routers that simply will not connect. We either upgrade the router firmware or replace it. It seems like early on we had a lot of trouble with linksys routers working inconsistently. Now if yo...
by jonm
Tue Dec 12, 2006 9:15 pm
Forum: General
Topic: Securing a RouterOS Server
Replies: 2
Views: 1399

Place rules in the [/ip firewall filter] to block traffic. There are 3 main 'chains' you can place rules in: Input - For packets addressed to the router Output - For packets leaving the router Forward - For packets going through the router, this where you want to put most of your internet rules I wo...
by jonm
Tue Dec 12, 2006 9:09 pm
Forum: General
Topic: One Network Many PPPOE connection and pppoe connection ????
Replies: 7
Views: 2731

I strongly agree, there are many times when interface routing would be very handy. We use it all the time on our Cisco routers. Say why do you need to have 4 pppoe-client connections to the same place anyway?
by jonm
Sun Dec 10, 2006 4:26 am
Forum: General
Topic: Setting priority of network traffic
Replies: 0
Views: 1033

Setting priority of network traffic

Here is my setup. 1 router, (mt 2.9.38), 3 ethernet interfaces, 1 PPPOE client interface Interface 1 - OUT - Connects to the internet Interface 2 - PPPOE-out1 - Internet connection Interface 3 - STAFF - Internal staff network Interface 4 - PUBLIC - Public access network I'm trying to set this up so ...
by jonm
Thu Mar 30, 2006 2:15 am
Forum: General
Topic: Rate-Limit not working on PPPoE
Replies: 2
Views: 1729

Okay, I rework my radius server and now the attribute is succesfully passed to the Mikrotik box! A dynamic queue (Simple) is created when a user connects. However, the max-limit is always set to 0/0 instead of what I set it to '256k/256k'. Any ideas?
by jonm
Thu Mar 30, 2006 12:49 am
Forum: General
Topic: Rate-Limit not working on PPPoE
Replies: 2
Views: 1729

Rate-Limit not working on PPPoE

I have a MT box running 2.9.11. Currently I have pppoe users authenticating via RADIUS. I've added the Mikrotik Rate-Limit attribute to my dictionary. I've also added the rate-limit attribute to my pppoe user profile. In debug mode I can see the Rate-Limit attribute being sent. However, it appears t...
by jonm
Fri Mar 03, 2006 9:04 pm
Forum: General
Topic: Cisco PPPOE-Client trouble
Replies: 0
Views: 776

Cisco PPPOE-Client trouble

Hey everyone, I've got a bizarre issue here. We have a MT pppoe-server that seems to work fine for everyone except a customer with a cisco 1700 router connecting as a pppoe-client. We have set our max mru and mtu in our pppoe server to 1400. However, when the cisco connects the MT box shows its MTU=...
by jonm
Tue Aug 02, 2005 8:19 pm
Forum: General
Topic: Per-Packet T1 Load Balancing?
Replies: 2
Views: 1486

I really don't want to use any sort of nat for these backhaul connections, so that sounds great.
by jonm
Tue Aug 02, 2005 7:07 pm
Forum: General
Topic: Per-Packet T1 Load Balancing?
Replies: 2
Views: 1486

Per-Packet T1 Load Balancing?

Does mt support per-packet load balancing across T1s? I'm currently running a cisco router that load balances 2 T1s for our backhaul. I'm wondering if it is possible to swap it our for a mikrotik, however it must be per-packet and not per-destination load balancing. The best I can find in the MT man...
by jonm
Fri Jul 29, 2005 6:27 am
Forum: General
Topic: Help dissecting TZSP protocol.
Replies: 3
Views: 2499

I'm actually trying to write a server to receive the stream. I'm having trouble decoding the wrapper.
by jonm
Fri Jul 29, 2005 5:01 am
Forum: General
Topic: Help dissecting TZSP protocol.
Replies: 3
Views: 2499

Help dissecting TZSP protocol.

Hi all, I've been using the /tool sniffer with a streaming server to a ethereal client to troubleshoot malicous traffic on my mikrotik network. Anyway, I've reached the limit of what I can do with ethereal. I'm trying to write my own TZSP receiver in .NET. I can capture the packets but I'm having tr...
by jonm
Wed May 25, 2005 5:19 pm
Forum: General
Topic: Masquerade with outside interface as pppoe-client
Replies: 2
Views: 1768

I got it figured out. I was specifying an out-interface. I replaced that with specifying the source-address subnet and not specifying an out-interface. Now everything works great.
by jonm
Tue May 24, 2005 9:48 pm
Forum: General
Topic: Masquerade with outside interface as pppoe-client
Replies: 2
Views: 1768

Masquerade with outside interface as pppoe-client

Hi all, I'm setting up a MT box to be a basic NAT router. Everything works fine when I set the outside address to a static IP. However, when I switch the outside address to pppoe-client nothing is masqueraded. The pppoe-client connects successfully. I have even tried changing the 'outside-interface'...
by jonm
Tue Mar 08, 2005 6:07 pm
Forum: General
Topic: RouterOS from a FlashDisk or CD?
Replies: 1
Views: 1116

RouterOS from a FlashDisk or CD?

Does anyone know if it is possible to run the routerOS from a bootable CD or USB flashdrive? I just thought this would be cool to dork around with new/beta versions.
by jonm
Fri Dec 17, 2004 4:08 pm
Forum: General
Topic: PPTP Server help
Replies: 9
Views: 3029

they are. RADIUS works flawlessly to the same pppoe server. It just doesn't work with the pptp-server, I never receive any radius requests and mikrotik logs a 'radius timeout' message.
by jonm
Thu Dec 16, 2004 10:45 pm
Forum: General
Topic: PPTP Server help
Replies: 9
Views: 3029

I have been running my radius in debug mode. I do not receive any radius packets. However the Mikrotik log complains of a radius timeout?? That's what made me think I had a configuration issue.
by jonm
Thu Dec 16, 2004 5:55 pm
Forum: General
Topic: PPTP Server help
Replies: 9
Views: 3029

[admin@coreRTR1] > /ppp [admin@coreRTR1] ppp> /inter pptp-serv [admin@coreRTR1] interface pptp-server> print [admin@coreRTR1] interface pptp-server> server [admin@coreRTR1] interface pptp-server server> print enabled: yes mtu: 1460 mru: 1460 authentication: mschap2 keepalive-timeout: disabled defau...
by jonm
Thu Dec 16, 2004 5:30 pm
Forum: General
Topic: PPTP Server help
Replies: 9
Views: 3029

I've tried that with no luck. How do I set the mikrotik to use the second ppp service for pptp and not to use the first ppp that is for pppoe?
by jonm
Thu Dec 16, 2004 1:51 am
Forum: General
Topic: Controlling Radius IPs
Replies: 2
Views: 1396

Controlling Radius IPs

Is there anyway to specify which IP Radius request come from? For some reason they are not coming from the address I want them to (I have multiple outside addresses bound to my card). Radius will reject the request if it is not coming from the correct IP (it gives a bad digest type error). Any help ...
by jonm
Thu Dec 16, 2004 1:45 am
Forum: General
Topic: PPTP Server help
Replies: 9
Views: 3029

PPTP Server help

Hey All, I'm trying to setup a PPTP server. I want to be able to authenticate to RADIUS. How do I set that up? I'm already using pppoe on this box and authenticating to radius just fine. I'm a little stumped on how to set this up for PPTP. PPTP ignores my current radius setup and there is no option ...
by jonm
Mon Nov 29, 2004 5:41 pm
Forum: General
Topic: PPPoE Rate-Limit
Replies: 3
Views: 1936

All of the values I've tried so far have been from this dictionary. I've tried the Ascend and the Mikrotik Rate-Limit. No luck so far.
by jonm
Mon Nov 29, 2004 3:26 pm
Forum: General
Topic: MT can't Masquerade the same subnet on seperate interfaces?
Replies: 5
Views: 2168

I'm stumped as to why you would even want to run 2 interfaces on the same subnet..
by jonm
Mon Nov 29, 2004 3:24 pm
Forum: General
Topic: Can't get basic 2 line script to work.
Replies: 6
Views: 2522

ah hah! That works! Thanks.
by jonm
Sat Nov 27, 2004 3:43 am
Forum: General
Topic: PPPoE Rate-Limit
Replies: 3
Views: 1936

PPPoE Rate-Limit

Hey all, I've just got my new pppoe-server setup! It authenticates to my Emerald Radius 3 server! (that took a some work). The real problem now is getting it to limit traffic. I've setup a the Rate-Limit Attribute (vendor=14988, value=8) however it does not seem to work. I've put several values in t...
by jonm
Sat Nov 27, 2004 12:14 am
Forum: General
Topic: Can't get basic 2 line script to work.
Replies: 6
Views: 2522

Eugene!

That works for the DHCP but not for the pppoe-server ;( pppoe server entires have service-names and not just plain names. Any ideas would be greatly appreciated!
by jonm
Mon Nov 15, 2004 2:33 am
Forum: General
Topic: Can't get basic 2 line script to work.
Replies: 6
Views: 2522

Print command? I can't find one in the manual and I get error message about it not being valid when I try to use it (I'm using ver 2.8.18). Do you mean the PUT command? I've tried that too, no error messages are logged, but the action is not performed when I run the script any ideas here? I think sc...
by jonm
Fri Nov 12, 2004 7:44 pm
Forum: General
Topic: Can't get basic 2 line script to work.
Replies: 6
Views: 2522

Can't get basic 2 line script to work.

Hey all, I'm trying to write a script to disable dhcp and pppoe. However, everytime I run the script I either get an error like 'input does not match any value of item name' or I do not receive an error but the actions are not carried out? Any ideas here? /system script set 0 source={/interface pppo...
by jonm
Fri Nov 12, 2004 3:22 am
Forum: General
Topic: /ppp profile local-address?
Replies: 1
Views: 2083

/ppp profile local-address?

Say I'm setting up pppoe on my box. What is the local-address setting under /ppp profile? It looks like it should be the internal mikrotik interface address. However, that does not make sense since it is recommended not to have an IP on the internet pppoe interface (for security). Any ideas here? Sh...
by jonm
Tue Nov 09, 2004 6:12 pm
Forum: General
Topic: PPPOE Radius - "No Password"
Replies: 2
Views: 1830

Yep, that fixed that problem! Say, any idea on how users are supposed to get to the internet? I have them on a private IP address. The subnet itself is masqueraded out, but doesn't seem to work. The default gateway is just their own address (which maches sense for PPP). Anything specila I need to do?
by jonm
Mon Nov 08, 2004 8:04 pm
Forum: General
Topic: PPPOE Radius - "No Password"
Replies: 2
Views: 1830

PPPOE Radius - "No Password"

Hi All. I'm trying to setup my MT router as a PPPOE Access Concentrator. I think everything is setup, however my Radius debug messages tell me 'Authenticate: from PPPOE - No Password' . I can only guess that the password is not being sent (testing from WinXP). Any ideas or suggestions here? I have t...
by jonm
Tue Sep 28, 2004 9:34 pm
Forum: General
Topic: TraceRoute breaks VRRP??
Replies: 10
Views: 4361

nevermind, I got it. I looks like I needed to specify the action="nat" instead of 'masquerade'. Thanks for the help. I'm still trying to solve the gratitous arp problem.
by jonm
Tue Sep 28, 2004 8:16 pm
Forum: General
Topic: TraceRoute breaks VRRP??
Replies: 10
Views: 4361

lastguru, I've got another VRRP issue, I'm using src-nat masquerading to let my wireless customers out to the internet. I want the outside vrrp address to be the one that they get src-nat'ted through. does that make any sense? I've tried setting the to-src-address=205.162.25.125, but it does'nt seem...
by jonm
Mon Sep 27, 2004 8:09 pm
Forum: General
Topic: TraceRoute breaks VRRP??
Replies: 10
Views: 4361

okay, now I have a new problem. it appears that cisco routers (2600) also ignore gratitous arp packets. If most other network devices ignore these packets, then what use is vrrp?
by jonm
Mon Sep 27, 2004 5:01 pm
Forum: General
Topic: TraceRoute breaks VRRP??
Replies: 10
Views: 4361

Basically, behind the vrrp interfaces is a Waverider Access-Point, on the otherside of that is my computer. Both the AP and SU are bridges, not routers. Perhaps they are not passing those arp packets.. There may be an issue.. hmm..
by jonm
Mon Sep 27, 2004 3:54 pm
Forum: General
Topic: TraceRoute breaks VRRP??
Replies: 10
Views: 4361

It does'nt seem to matter, WinXPsp2, Win2003. The more I look at this, the more it looks like an arp problem. I need to get some packet captures so I can see what really happens.
by jonm
Mon Sep 27, 2004 8:43 am
Forum: General
Topic: TraceRoute breaks VRRP??
Replies: 10
Views: 4361

UPDATE: It seems to happen no matter what I do, even if I don't do a traceroute. 1. Kill the master, let it reboot. 2. Fails to backup. 3. Master comes back up, takes over master role. 4. Reboot backup. 5. My computer can't get outside, it is still looking for the secondary IP even through it's gat...
by jonm
Mon Sep 27, 2004 8:16 am
Forum: General
Topic: Script to kick PPPOE Connection
Replies: 3
Views: 2968

most access routers implement this feature with SNMP and most radius programs can check to see if a user is really online using snmp. I wonder, can we see the logged on hotspot users with snmp? If not, adding that feature would definetly fix the problem and make it compatible with the majority of ra...
by jonm
Mon Sep 27, 2004 8:11 am
Forum: General
Topic: TraceRoute breaks VRRP??
Replies: 10
Views: 4361

TraceRoute breaks VRRP??

Hey guys, I just setup VRRP on my wireless network. The setup was easy and most everything seems to work fine. However, I'm trying to figure out a very odd problem. When I do a tracert, I don't see the virtual IP, I always see the master router's IP. This seems to be screwing me up. 1. I do a tracer...
by jonm
Mon Sep 27, 2004 8:00 am
Forum: General
Topic: VRRP Issue
Replies: 1
Views: 1551

I've seen some weird issues with VRRP, not a w2k3 issue yet. I actually have a win2k3 box at home behind a vrrp router and it works fine. Make sure to dump your arp table (or restart the computer) after you change the gateway.

arp -d *