Community discussions

MikroTik App

Search found 22 matches

by luddite
Thu Dec 29, 2022 10:03 am
Forum: General
Topic: Very Slow output for traffic passing through CHR
Replies: 12
Views: 6372

Re: Very Slow output for traffic passing through CHR

Same same, just found this post, after umpteen MTU adjustments and iperf tests between Windows and Linux hosts over the Vultr VPC I can only get 300-600Mbps - Mbps! (tried lots of mtu values from 1300 up to 1450) Like poster above said if enabling NIC connecting directly to internet get 4Gbps from S...
by luddite
Wed Jun 03, 2020 11:59 am
Forum: Scripting
Topic: RouterSCRIPTS - A collection of scripts for RouterBOARD devices
Replies: 35
Views: 26669

Re: RouterSCRIPTS - A collection of scripts for RouterBOARD devices

Just want to say thanks for this amazing work, there is a lot in it, and a lot in your replies to people, good effort helping the community.

Hope to use and explore these scripts.
by luddite
Thu Mar 21, 2019 10:43 am
Forum: General
Topic: Netwatch to an IP address on the other side of a IPSEC VPN
Replies: 5
Views: 9125

Re: Netwatch to an IP address on the other side of a IPSEC VPN

It works! but how? anybody can explain? I found this puzzling too, it works because your ipsec tunnel has a policy that applies to traffic destined for that address range, but traffic has to be on lan interrface to get picked up by the policy, that route gets traffic for that range onto lan where t...
by luddite
Sat Mar 09, 2019 11:30 am
Forum: General
Topic: L2TP - Multiple Clients from Same IP
Replies: 0
Views: 676

L2TP - Multiple Clients from Same IP

Have L2TP Server working fine for one user, at another site I have three users all behind the same IP address and using L2TP and for those users the sessions keep disconnecting.

Is there a solution for multiple L2TP users behind one IP address? (if that is the issue)
by luddite
Fri Feb 08, 2019 1:59 pm
Forum: General
Topic: SSTP VPN Behind other FW Possible [SOLVED]
Replies: 3
Views: 1799

Re: SSTP VPN Behind other FW Possible [SOLVED]

(thanks for replies, this has surfaced again as an issue) This particular branch office was a public IP but due to poor 4G reception with our usual carrier we had to go with one which gives us a private nat'ed IP - cant get ipsec working with one of those. Hence wanting to punch through the Fortigat...
by luddite
Wed Nov 21, 2018 6:43 am
Forum: General
Topic: SSTP VPN Behind other FW Possible [SOLVED]
Replies: 3
Views: 1799

SSTP VPN Behind other FW Possible [SOLVED]

Head office FW is a Fortigate. Branch offices MT. Have some IPSEC VPN's from MT t o Fortigate - stable - but some sites have non-public IP address' and so want to use SSTP from branch MT to an internal MT behind the Fortigate. Have tried to forward port 12345 to internal MT port 443 so I can use SST...
by luddite
Sun Sep 30, 2018 2:38 pm
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

Damnation. I tried to check I wasn't bungling before I posted. That worked, now I will move on to rest of config. Thanks.
by luddite
Sun Sep 30, 2018 1:17 pm
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

No cigar Sindy, here is full message. /interface bridge add fast-forward=no name=bridge1 /interface bridge port add bridge=bridge1 interface=wlan2-Albatross add bridge=bridge1 interface=wlan1-Riverhawk /interface bridge settings set use-ip-firewall=yes /ip firewall mangle # in/out-interface matcher ...
by luddite
Fri Sep 28, 2018 1:58 am
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

Sindy I get in/out matcher not possible on slave interface when trying to match packets coming in on wlan, I cant see a way to classify wlan traffic without the vlans - not that I know how to get the vlans working mind... Tried to PM you but board doesent allow it - perhaps you could consult for me ...
by luddite
Thu Sep 27, 2018 12:49 pm
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

Ok, hopefully I am getting closer, pretty sure I have made a fundamental error here with vlan, any comments welcome. /interface lte set [ find ] name=lte1 /interface bridge add fast-forward=no name=bridge-Albatross add fast-forward=no name=bridge-LAN add fast-forward=no name=bridge-Riverhawk /interf...
by luddite
Sun Sep 23, 2018 2:37 pm
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

Most decent of you to reply in such detail, and also for your earlier suggestion.
I didn't try yet as it is stretching my networking skills, but I will learn if I try so pushing on with it now.
Very grateful for your help.
by luddite
Sun Sep 23, 2018 1:29 pm
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

Sindy can I please get your opinion on the following idea? This works except when same device joins wlan2, device takes ages to get lease or it doesent get one - Mikrotik grants a lease (can see in log with dhcp debug on) but device doesent seem to accept it. I did a test and made a pool in a differ...
by luddite
Tue Sep 18, 2018 1:06 am
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

Sindy thanks, I got this when I tried
/ip firewall mangle
add action=mark-routing chain=forward new-routing-mark=via-WAN2 in-bridge-port=one-of-the-wlan-ones passthrough=yes

failure: routing-mark allowed only in output and prerouting chains

Appreciate your help.
by luddite
Sun Sep 16, 2018 10:54 am
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

Re: 1 RB, 1 LAN, 2 WLAN, 2 GW

you can place these resources to a dedicated subnet and let the devices in other subnets talk to them via routing; Sindy with say printers being visible on another subnet, how will discovery work with say Mac's finding printers, I think they might use mDNS / Bonjour - I am thinking that is L2, will...
by luddite
Sat Sep 15, 2018 10:34 am
Forum: General
Topic: 1 RB, 1 LAN, 2 WLAN, 2 GW
Replies: 17
Views: 2696

1 RB, 1 LAN, 2 WLAN, 2 GW

Hi, wanting to know if possible for 2 wireless networks to share same LAN but be forced out seperate gateways? Want them to access same printers, network shares etc but to use a different internet connection. I got stuck on a mangle rule and in out matcher not being possible. Would be grateful for e...
by luddite
Fri Sep 07, 2018 10:44 am
Forum: General
Topic: DNS Servers / secondary before primary ?
Replies: 11
Views: 7117

Re: DNS Servers / secondary before primary ?

You da man :)
by luddite
Fri Sep 07, 2018 10:28 am
Forum: General
Topic: DNS Servers / secondary before primary ?
Replies: 11
Views: 7117

Re: DNS Servers / secondary before primary ?

# model = 951Ui-2HnD /interface bridge add arp=proxy-arp auto-mac=no fast-forward=no mtu=1500 name=bridge-local /interface bridge port add bridge=bridge-local interface=ether2-master-local add bridge=bridge-local interface=wlan1 add bridge=bridge-local interface=wlan2 add bridge=bridge-local interf...
by luddite
Fri Sep 07, 2018 3:25 am
Forum: General
Topic: DNS Servers / secondary before primary ?
Replies: 11
Views: 7117

Re: DNS Servers / secondary before primary ?

Excellent idea. Didnt work for some reason, I am just cleaning up export to post. Many thanks. According to default route, your router will pick the WAN address as source address for pings. This will not be picked up by ipsec policy matcher. By adding a simple route for remote subnet to LAN, router ...
by luddite
Thu Sep 06, 2018 9:45 am
Forum: General
Topic: DNS Servers / secondary before primary ?
Replies: 11
Views: 7117

Re: DNS Servers / secondary before primary ?

This would be perfect for my branch office with an IPSEC vpn, except I cant get the router itself to route packets over the VPN so the script always things host is down, anyone have some clues how to do that, tried a mangle rule but no luck. (that layer7 solution mentioned suffers same limitation) T...
by luddite
Sun Aug 19, 2018 3:47 am
Forum: General
Topic: IPsec Routing
Replies: 1
Views: 712

IPsec Routing

Have a good stable ipsec tunnel between two sites. Head office is a windows domain and a branch office with domain client computers. Want branch office domain clients to resolve domain dns queries over tunnel, found this real nice bit of code below but it doesn't work as the branch office router its...
by luddite
Thu Oct 19, 2017 5:18 am
Forum: The User Manager
Topic: Handlink Ticket Printer EOL and only supports old FW- ALTERNATIVES?
Replies: 2
Views: 3696

Re: Handlink Ticket Printer EOL and only supports old FW- ALTERNATIVES?

Hi Turnip, did you find anything that works?

Would love to have a printer you can press a button on that works with Mikrotik or Usermanager...
by luddite
Mon Apr 23, 2012 12:00 am
Forum: Wireless Networking
Topic: Hotspot not working
Replies: 9
Views: 6463

Re: Hotspot not working

(networking noob here...) Hi, I had this issue as well. Looked to me to be dns resoltion, (do mac's use mdns somehow or multicast dns?) anyway they can find hotspot dns name no problem just not pc's. Anyway under hotspot gateway dns name I changed that to an ip address instead of a dns name and boom...