Community discussions

MikroTik App

Search found 105 matches

by BlackRat
Fri Aug 23, 2024 10:07 pm
Forum: Beginner Basics
Topic: New router but no 5GHz - broken?
Replies: 3
Views: 721

Re: New router but no 5GHz - broken?

.... /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik add authentication-types=wpa2-psk group-key-update=1h mode=dynamic-keys name=\ home supplicant-identity="" /interface wireless set [ find default-name=wlan1 ] band=2ghz-onlyn country=russia4 di...
by BlackRat
Fri Aug 23, 2024 6:46 pm
Forum: Beginner Basics
Topic: New router but no 5GHz - broken?
Replies: 3
Views: 721

New router but no 5GHz - broken?

Hi.
We have RBD53iG-5HacD2HnD and I can't find 5GHz network near router... Only 2GHz. Wifi interfaces was setup same (different only for 5GHz setting)... And If I try to scan from this MikroTik - I can't see any 5ПРя from MikroTik...
Broken 5GHz?
by BlackRat
Tue Aug 20, 2024 12:03 pm
Forum: Beginner Basics
Topic: Some ports on switches are slow
Replies: 6
Views: 915

Re: Some ports on switches are slow

The problem eliminated by switch reboot. :shock:
by BlackRat
Mon Aug 19, 2024 4:13 pm
Forum: Beginner Basics
Topic: Some ports on switches are slow
Replies: 6
Views: 915

Re: Some ports on switches are slow

Most of the ports working normaly.
by BlackRat
Mon Aug 19, 2024 12:34 pm
Forum: Beginner Basics
Topic: Some ports on switches are slow
Replies: 6
Views: 915

Re: Some ports on switches are slow

I have 2 vlan's. One for management, (vlan10) and for internet connection (vlan20).
I didn't check all ports. Only 34 and 36. 34 is bad, 36 is good.
by BlackRat
Mon Aug 19, 2024 12:33 pm
Forum: Beginner Basics
Topic: Some ports on switches are slow
Replies: 6
Views: 915

Re: Some ports on switches are slow

Using ROS. The problem in on the port 34. Temporary I moved connection from 34 to 36. Config is minimal. I didn't config any queues... Config is: /interface bridge add name=bridge pvid=10 vlan-filtering=yes /interface vlan add interface=bridge name=vlan10-management vlan-id=10 /interface wireless se...
by BlackRat
Mon Aug 19, 2024 11:47 am
Forum: Beginner Basics
Topic: Some ports on switches are slow
Replies: 6
Views: 915

Some ports on switches are slow

Hi. We have several switches: CRS354-48G-4S+2Q+ ( 7.15.1 ). Several ports have a problem: download speed is approximately 10Mb/s (speed of connection is 1Gb/s). When I change port (for example from 36 to 34) - its ok. Incoming and outgoing traffiс is all right. It is not a problem of patchcord and p...
by BlackRat
Fri Aug 02, 2024 8:11 pm
Forum: Beginner Basics
Topic: snmpwalk = ok, snmpget = No Such Object available on this agent at this OID
Replies: 0
Views: 1178

snmpwalk = ok, snmpget = No Such Object available on this agent at this OID

I try to monitor wireguard tunnel by snmp. Does it possible? I tried to monitor route for wireguard tunnel... For example: root@niyamamon:~ # snmpwalk -v 2c -c MySNMPCommunity routeripaddress .1.3.6.1.2.1.4.24.4.1.16 ... IP-FORWARD-MIB::ipCidrRouteStatus.172.20.0.0.255.255.255.0.0.172.20.254.253 = I...
by BlackRat
Mon Nov 28, 2022 9:04 pm
Forum: Beginner Basics
Topic: DNS not resolving domain names
Replies: 11
Views: 12975

Re: DNS not resolving domain names

Try to add access rule at the top:
add action=accept chain=input comment="ESTABLISHED, RELATED" connection-state=established,related
by BlackRat
Fri Aug 26, 2022 1:24 pm
Forum: Beginner Basics
Topic: R11e-LTE not working after firmware upgrade
Replies: 11
Views: 5955

Re: R11e-LTE not working after firmware upgrade

Downgraded to factory firmware (6.46.4) - problem still exists...
by BlackRat
Fri Aug 26, 2022 12:05 pm
Forum: Beginner Basics
Topic: R11e-LTE not working after firmware upgrade
Replies: 11
Views: 5955

Re: R11e-LTE not working after firmware upgrade

When R11e-LTE6 found it didn't have serial number... Now what I should to do to revert normal operation?
by BlackRat
Fri Aug 26, 2022 12:02 pm
Forum: Beginner Basics
Topic: R11e-LTE not working after firmware upgrade
Replies: 11
Views: 5955

Re: R11e-LTE not working after firmware upgrade

Hmm.. After Netinstall (now 6.49.6) problem exists.
by BlackRat
Thu Aug 25, 2022 9:43 pm
Forum: Beginner Basics
Topic: R11e-LTE not working after firmware upgrade
Replies: 11
Views: 5955

Re: R11e-LTE not working after firmware upgrade

Mikrotik RBD53GR-5HacD2HnD, updated to latest modem firmware first (Router firmware was 6.49.4).
Then upgraded router to 7.4.1.
Now LTE not working.
Thinking of Netinstall to 6.49.6...
Modem is appearing for a seconds, then disappear.
by BlackRat
Fri Feb 18, 2022 3:37 pm
Forum: Beginner Basics
Topic: Slow download over tunnel
Replies: 4
Views: 684

Re: Slow download over tunnel

Tried MTU on IPIP 1420, 1410... Nothing helped.
Additionally used on both routers:
/ip firewall mangle
add action=change-mss chain=forward in-interface=ipip-tunnel-test new-mss=1380 passthrough=yes protocol=tcp tcp-flags=syn

download VS upload = 1 x 15..20 times.
by BlackRat
Fri Feb 18, 2022 10:15 am
Forum: Beginner Basics
Topic: Slow download over tunnel
Replies: 4
Views: 684

Re: Slow download over tunnel

Ping speed in ipip-tunnel = 52Mb/s x 62 Mb/s
by BlackRat
Fri Feb 18, 2022 9:48 am
Forum: Beginner Basics
Topic: Slow download over tunnel
Replies: 4
Views: 684

Re: Slow download over tunnel

On Office Router2 /routing table add fib name=inet add disabled=no fib name=tunnel /ip address add address=192.168.253.254/24 interface=bridge-local network=192.168.253.0 add address=192.168.200.2/30 interface=ipip-tunnel-test network=192.168.200.0 add address=192.168.38.1/24 interface=bridge-tunnel...
by BlackRat
Fri Feb 18, 2022 9:30 am
Forum: Beginner Basics
Topic: Slow download over tunnel
Replies: 4
Views: 684

Slow download over tunnel

Hi. I have next scheme: Router1 = VDS MikroTik CHR (License level P1) with single interface (ether1) Router2 = MikroTik RB4011iGS+ (office) On Router2 there is 2 networks on different bridges: bridge-local = main network 192.168.253.0/24 bridge-tunnel = separated network 192.168.38.0/24 There is IPI...
by BlackRat
Wed Nov 03, 2021 8:47 am
Forum: General
Topic: Duplicate ACK in the IPSec tunnel
Replies: 0
Views: 709

Duplicate ACK in the IPSec tunnel

Hi. I have two routers and IPSec tunnel between them. Windows--NetworkA--RouterA---internet---RouterB--NetworkB--Linux When I try to ssh from Windows to RouterB (inner interface) all worked nice. I can see full export without issues. When I try to ssh from Windows to Linux I have an headache, becaus...
by BlackRat
Mon Sep 20, 2021 2:02 pm
Forum: General
Topic: Duplicated ACK tunnel...
Replies: 0
Views: 733

Duplicated ACK tunnel...

Two sites. First site - two ISP (first ISP-wired connection "ISP1" = bridge-inet, the second ISP-LTE passthrough connection "ISP2" = bridge-yota). Second connection (LTE) we don't use now (but all rules for it exists). My internal network: 192.168.XXX.0/24 Clien's internal networ...
by BlackRat
Tue Sep 14, 2021 11:22 am
Forum: General
Topic: IPSec - invalid length of payload
Replies: 6
Views: 6470

Re: IPSec - invalid length of payload

Same situation! parsing packet failed, possible cause: wrong password I have about 45 different IPSEC-tunnels and only one of the routers generating this error. I tried to change proposals - same situation. Tunnel established, but constantly see this error! /system routerboard print routerboard: yes...
by BlackRat
Sun Aug 22, 2021 9:01 pm
Forum: Scripting
Topic: API: Hot to get routerboard parameters
Replies: 3
Views: 1622

Re: API: Hot to get routerboard parameters

Ok. I found one of the ways how to get it: my ( $ret_get_props, @aoh_props ) = $api->query( '/system/routerboard/print',{} ); print "The router current-firmware is: $aoh_props[0]->{'current-firmware'}\n"; and we will get current-firmware of the routerboard... print "The router model i...
by BlackRat
Sun Aug 22, 2021 7:14 pm
Forum: Scripting
Topic: API: Hot to get routerboard parameters
Replies: 3
Views: 1622

API: Hot to get routerboard parameters

Hi.
I newbie in Perl and MikroTik::API.
I using Perl to get Routerboard parameters.
How can I get values of the /system routerboard print page?
Should I use 8 singe line queries or I can get all parameters in one query?
by BlackRat
Tue Aug 03, 2021 9:07 am
Forum: General
Topic: IPSec - invalid length of payload
Replies: 6
Views: 6470

Re: IPSec - invalid length of payload

I have RB4011iGS+ with 6.48.3 installed that connected to the RouterOS-x86 6.48.3. And I have the same situation: 13:05:09 ipsec,debug ===== received 76 bytes from XX.XXX.XX.XX[1025] to YY.YYY.YYY.YY[4500] 13:05:09 ipsec,debug,packet 53c28f4e 6b6fd2c5 8ce8c01f 63c109a1 05100201 00000000 0000004c 8ab...
by BlackRat
Wed Jul 28, 2021 9:49 pm
Forum: General
Topic: Two providers. Unstable behavior. [SOLVED]
Replies: 9
Views: 1993

Re: Two providers. Unstable behavior. [SOLVED]

Made ping test. And I think, that reason is wrong settings for additional address for external interface. I should use 85.xxx.xxx.20/24 and 85.xxx.xxx.21/24 instead of 85.xxx.xxx.20/32 and 85.xxx.xxx.21/24
Thanks' to CZFan anв mkx.
by BlackRat
Wed Jul 28, 2021 8:30 pm
Forum: General
Topic: Two providers. Unstable behavior. [SOLVED]
Replies: 9
Views: 1993

Re: Two providers. Unstable behavior. [SOLVED]

You can use this as start, removing all your actual routes, route rules and mangles /ip dns set servers=1.1.1.1,8.8.8.8 /ip route add comment="A - 1.1.1.1 must be reachable only from ISP1" distance=1 dst-address=1.1.1.1/32 gateway=85.XXX.XXX.1 scope=10 add comment="B - Recursive Rout...
by BlackRat
Wed Jul 28, 2021 7:05 pm
Forum: General
Topic: Two providers. Unstable behavior. [SOLVED]
Replies: 9
Views: 1993

Re: Two providers. Unstable behavior. [SOLVED]

@BlackRat, the setting you highlited is IMO invalid. It's not logical to have address with network address set to same value. If bridge-inet should use both addresses 85.xxx.xxx.20 and 85.xxx.xxx.21 and when router uses either of WAN addresses it can directly connect to the same subnet (which is lo...
by BlackRat
Wed Jul 28, 2021 7:02 pm
Forum: General
Topic: Two providers. Unstable behavior. [SOLVED]
Replies: 9
Views: 1993

Re: Two providers. Unstable behavior. [SOLVED]

I have special rule for additional NAT
add action=src-nat chain=srcnat out-interface=bridge-inet src-address=192.168.188.200 to-addresses=85.XXX.XXX.20
because I want to use another external address for my internal Server.
by BlackRat
Wed Jul 28, 2021 6:22 pm
Forum: General
Topic: Two providers. Unstable behavior. [SOLVED]
Replies: 9
Views: 1993

Two providers. Unstable behavior. [SOLVED]

Hi. My config in general: bridge-inet - main ISP, backup-bridge - backup ISP and ISP for some IP-IP tunnel. I try to create config where my Router can accept connections from main and backup channels. Some times working well, but sometimes I have problem that I cannot understand. I have two ISP. And...
by BlackRat
Fri May 28, 2021 3:08 pm
Forum: Wireless Networking
Topic: CAPS + Windows 10 clients
Replies: 2
Views: 1137

Re: CAPS + Windows 10 clients

It is now other AP's with the same SSID... /caps-man channel add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=disabled name=UMEWirelessNetwork-2 tx-power=20 add band=5ghz-a/n/ac control-channel-width=20mhz extension-channel=Ce name=UMEWirelessNetwork-5 tx-power=10 add band=2ghz-b/g/...
by BlackRat
Fri May 28, 2021 12:54 pm
Forum: Wireless Networking
Topic: CAPS + Windows 10 clients
Replies: 2
Views: 1137

CAPS + Windows 10 clients

Hi all! I have 5 AP's connected to CAPSMAN. Two of them very closed to each other, so I decided to separate one of these AP's from other config and created another config for single AP. Now I have problem: some time a Windows 10 client when it connected to WiFi can't renew IP. The only way: forget W...
by BlackRat
Sun Mar 28, 2021 5:30 pm
Forum: Beginner Basics
Topic: Cannot get value with console command
Replies: 3
Views: 651

Re: Cannot get value with console command

Thank you! Now I understand... ReadTheFuckinManual - very important rule. :(

Sorry...
by BlackRat
Sun Mar 28, 2021 4:00 pm
Forum: Beginner Basics
Topic: Cannot get value with console command
Replies: 3
Views: 651

Re: Cannot get value with console command

[admin@MikroTik] > /system routerboard print
routerboard: yes
board-name: hAP ac^2
model: RBD52G-5HacD2HnD
serial-number: YYYYYYYYYY
firmware-type: ipq4000L
factory-firmware: 6.44
current-firmware: 6.48.1
upgrade-firmware: 6.48.1
by BlackRat
Sun Mar 28, 2021 4:00 pm
Forum: Beginner Basics
Topic: Cannot get value with console command
Replies: 3
Views: 651

Cannot get value with console command

Strange problem. I have dhcp-client: [admin@MikroTik] > /ip dhcp-client print Flags: X - disabled, I - invalid, D - dynamic # INTERFACE USE-PEER-DNS ADD-DEFAULT-ROUTE STATUS ADDRESS 0 bridge-inet yes yes bound XXX.XXX.XXX.XXX/BB But can't get any values by console: [admin@MikroTik] > /ip dhcp-client...
by BlackRat
Tue Mar 23, 2021 12:34 am
Forum: Beginner Basics
Topic: Try to make ppp-oit1 as main routeк interface.
Replies: 2
Views: 590

Try to make ppp-oit1 as main routeк interface.

Hi. ROS: 6.48.1 Sorry, but... I have wired interface on bridge-inet->ether1 (with DHCP-CLIENT) and 3G-modm ppp-out1 interface on usb1. When I try to made default route distance for ppp-out1 as 1 and default route distance for dhcp-client as 2 I'm getting constanty swapping out interfaces... What's w...
by BlackRat
Wed Mar 03, 2021 9:27 am
Forum: General
Topic: HTTP access : Authentication failed: invalid username or password
Replies: 0
Views: 794

HTTP access : Authentication failed: invalid username or password

Hi. Today faced with strange problem:
MikroTik, CRS109-8G-1S-2HnD, 6.48.1.
I can connect by winbox, ssh. But cannot login to web.
user = admin. It is only one user in the system...
by BlackRat
Fri Aug 28, 2020 12:36 am
Forum: General
Topic: SOLVED! cAP AC (RBcAPGi-5acD2nD) netinstall on Windows 10
Replies: 0
Views: 1457

SOLVED! cAP AC (RBcAPGi-5acD2nD) netinstall on Windows 10

I faced to problem with Netinstall and Windows 10 Prof. I couldn't see any devices in netinstall. My failed actions: 1. Disabled firewall 2. Enabled firewall and make "Allow all income traffic" rule (all ports, all programs... all all for all) 3. Disabled all properties TCP/IP settings (le...
by BlackRat
Thu Jun 04, 2020 8:22 am
Forum: General
Topic: CHR (6.47) stuck with "No irq handler for vector (irq -1)" error
Replies: 2
Views: 1612

CHR (6.47) stuck with "No irq handler for vector (irq -1)" error

Hi.
Yesterday I updated my CHR on Selectel.ru provider to the version 6.47.
Today I found that I can't connect to winbox and router stuck with error: do_IRQ: 0.105 No irq handler for vector (irq -1).
by BlackRat
Tue Nov 19, 2019 5:05 pm
Forum: SwOS
Topic: CSS326-24G-2S+ cannot upgrade from 2.8p to 2.10
Replies: 0
Views: 3170

CSS326-24G-2S+ cannot upgrade from 2.8p to 2.10

I have two CSS326-24G-2S+, one of them has version 2.8p. And I can't upgrade it automatically either manually. I can see new version (2.10) features but when I try to upgrade nothing happens.
by BlackRat
Thu Nov 07, 2019 3:47 pm
Forum: General
Topic: CRS328-24P-4S+ forget config after reboot.
Replies: 7
Views: 1849

Re: CRS328-24P-4S+ forget config after reboot.

Check installation = OK
Problem persists since previous versions (even not 6.45.6)... But, it seems to me not from the beginning... Ok will try to use netinstall ASAP...
by BlackRat
Tue Nov 05, 2019 5:38 pm
Forum: General
Topic: CRS328-24P-4S+ forget config after reboot.
Replies: 7
Views: 1849

Re: CRS328-24P-4S+ forget config after reboot.

/interface bridge add name=bridge-inet protocol-mode=none add name=bridge-local /interface ethernet set [ find default-name=ether1 ] name=ether01 speed=100Mbps set [ find default-name=ether2 ] name=ether02 speed=100Mbps set [ find default-name=ether3 ] name=ether03 speed=100Mbps set [ find default-n...
by BlackRat
Tue Nov 05, 2019 11:21 am
Forum: General
Topic: CRS328-24P-4S+ forget config after reboot.
Replies: 7
Views: 1849

Re: CRS328-24P-4S+ forget config after reboot.

Can anybody help me?
Should I change hardware? This is important customer with such stupid problem!
by BlackRat
Thu Oct 31, 2019 9:45 am
Forum: General
Topic: CRS328-24P-4S+ forget config after reboot.
Replies: 7
Views: 1849

Re: CRS328-24P-4S+ forget config after reboot.

Safe mode not active.
Problem persist. After reboot there no ports in the bridge---ports list other than CAPx...
by BlackRat
Thu Oct 31, 2019 9:20 am
Forum: General
Topic: CRS328-24P-4S+ forget config after reboot.
Replies: 7
Views: 1849

CRS328-24P-4S+ forget config after reboot.

Hi all. I have CRS328-24P-4S+ ether1--ether23 are in the bridge-local ether24 in the bridge-inet CAPSMAN is working. both AP's are in the bridge-local too. After reboot device shows me that only CAPX interfaces (from AP's) are in the bridge-local and that's all. No other ports in list! So I need to ...
by BlackRat
Mon Jun 17, 2019 3:21 pm
Forum: General
Topic: PPP + RADIUS + Win.ADDomain = Problem
Replies: 4
Views: 1450

Re: PPP + RADIUS + Win.ADDomain = Problem

SOLVED:
I removed "domain" from RADIUS server config page on MikroTik. Now I can see packets from MikroTik to RADIUS server.
by BlackRat
Mon Jun 17, 2019 1:45 pm
Forum: General
Topic: PPP + RADIUS + Win.ADDomain = Problem
Replies: 4
Views: 1450

Re: PPP + RADIUS + Win.ADDomain = Problem

I used packet sniffer on MikroTik on internal bridge and did'n found any packets from MikroTik to RADIUS server... As you can see in the log there is no 3 sec (now I use 3 seconds timeout) between all debug messages !
by BlackRat
Fri Jun 14, 2019 2:49 pm
Forum: General
Topic: PPP + RADIUS + Win.ADDomain = Problem
Replies: 4
Views: 1450

PPP + RADIUS + Win.ADDomain = Problem

Hi. My config: 2011UiAS (6.44.3) + Windows 2003 Small Business Server (with Active Directory)... When I try to use pptp connection I got: 14:39:43 radius,debug new request 1b:02 code=Access-Request service=ppp called-id= ROUTEREXTERNALIP 14:39:43 radius,debug no radius server found for 1b:02 14:39:4...
by BlackRat
Sun Dec 03, 2017 2:29 pm
Forum: Beginner Basics
Topic: CRS125-24G-1S bondig + VLAN
Replies: 0
Views: 488

CRS125-24G-1S bondig + VLAN

Hi. Have next config: 1. MikroTik switch CRS125-24G-1S 2. VMWare Server (1 management + 4 LAN ports) 3. FreeBSD storage-server (2 LAN ports) Need to create: 1. VLAN 8 for LAN 2. VLAN18 for Storage-LAN 3. VMWare server must use untagged port in 8 VLAN for management and tagged 4 LAN ports (8 and 18) ...
by BlackRat
Thu Nov 30, 2017 10:45 am
Forum: General
Topic: RB952Ui-5ac2nD-TC power problem?
Replies: 1
Views: 752

Re: RB952Ui-5ac2nD-TC power problem?

Solved. It was a power problem. Now using UPS and no issues since UPS installed.
by BlackRat
Wed Nov 08, 2017 3:58 pm
Forum: General
Topic: RB952Ui-5ac2nD-TC power problem?
Replies: 1
Views: 752

RB952Ui-5ac2nD-TC power problem?

Strange problem. Mikrotik RB952Ui-5ac2nD-TC + USB-modem + 2 viop gateways grandstream + one computer over WiFi. Some time we lost config on mikrotik and could restore only from backup! It happened more than 4 times per two days! Password is strong and nobody knows it :( Only winbox and ssh ports is ...
by BlackRat
Thu May 25, 2017 4:12 pm
Forum: The Dude
Topic: CHR (x86_64) v6.39.1 + Dude unstable connection
Replies: 1
Views: 980

Re: CHR (x86_64) v6.39.1 + Dude unstable connection

Sorry. Found another host with same IP-address in the network segment.
by BlackRat
Tue May 23, 2017 6:00 pm
Forum: The Dude
Topic: CHR (x86_64) v6.39.1 + Dude unstable connection
Replies: 1
Views: 980

CHR (x86_64) v6.39.1 + Dude unstable connection

I use VMWare installation of CHR (x86_64) + Dude. Very unstable. Periodicaly lost connection (E1000 or VMXNET3). Interface disable/enable helps. :(
by BlackRat
Tue May 23, 2017 5:34 pm
Forum: The Dude
Topic: CHR (x86_64) Dude wrong time
Replies: 0
Views: 865

CHR (x86_64) Dude wrong time

When added MikroTik device to "devices" and insert wrong password I can see wrong time in RouterOS Connection Status. GMT Offset not implemented there...
by BlackRat
Wed Feb 22, 2017 9:58 am
Forum: General
Topic: CRS125-24G-1S and "magic" port (probably loop)
Replies: 0
Views: 689

CRS125-24G-1S and "magic" port (probably loop)

Good day! I have CRS125-24G-1S and Samsung MFU. When I use ether9 for Samsung MFU I'l get an error: interface,warning eth10: bridge port received packet with own address as source address (e4:8d:8c:6e:61:2a), probably loop Ether10 up's automatically. When I use ether10 for Samsung MFU Ether9 up's au...
by BlackRat
Sun Feb 12, 2017 12:05 pm
Forum: General
Topic: Strange IPSec issue
Replies: 2
Views: 809

Re: Strange IPSec issue

There was an error in peer ip address. :( Sorry. It's my innatension.
by BlackRat
Sun Feb 12, 2017 8:00 am
Forum: General
Topic: Strange IPSec issue
Replies: 2
Views: 809

Strange IPSec issue

I have 3 devices (MikroTik 1. A-router - 1200 (6.38.1) (internal network 192.168.0.0/24; external IP 194.87.66.170) 2. B-router - 2011UAS-2HnD (6.38.1) (internal networks 192.168.253.0/24 and 192.168.8.0/24; external IP 31.173.44.209) 3. C-router - 2011UAS-2HnD (6.38.1) (internal network 192.168.7.0...
by BlackRat
Mon Dec 12, 2016 6:17 am
Forum: General
Topic: SNMP strange problem. 2011UAS-2HnD 6.37
Replies: 4
Views: 1069

Re: SNMP strange problem. 2011UAS-2HnD 6.37

Simple reboot helped me. :(
by BlackRat
Thu Dec 08, 2016 9:36 am
Forum: General
Topic: SNMP strange problem. 2011UAS-2HnD 6.37
Replies: 4
Views: 1069

SNMP strange problem. 2011UAS-2HnD 6.37

Can't add any SNMP community.When I try to open IP--SNMP I'l get SNMP Setting: Enabled = empty Trap Community (is red) = unknown Can't add any community in the communities section. When I try to insert something like this "/snmp community set public name="public" address=192.168.0.5/3...
by BlackRat
Wed Nov 09, 2016 12:11 pm
Forum: General
Topic: http, https problems
Replies: 1
Views: 658

Re: http, https problems

Temprary: I made old ISP as http, https forwarder. Now http, https working without any issues. :(
How to investigate this problem?
by BlackRat
Wed Nov 09, 2016 11:35 am
Forum: General
Topic: http, https problems
Replies: 1
Views: 658

http, https problems

Changed Internet service provider and now we have strange problem. RDP, SNMP, POP3 protocols working fine, but HTTP and HTTPS have strange behavior. google-sites working exelent. Other sites - waiting for connections.
Please help. Can't working now.
by BlackRat
Mon Sep 26, 2016 11:42 am
Forum: Beginner Basics
Topic: ipv6 + tunnelbroker interface
Replies: 1
Views: 944

ipv6 + tunnelbroker interface

Please provide working example of ipv6 filter rules. We have tunnelbroker interface sit1. LAN-interface is bridge-local. We have internal DNS-server with static ipv6 address (all LAN servers have static address too). Now we have rules: /ipv6 firewall filter add action=accept chain=input comment=&quo...
by BlackRat
Thu Mar 24, 2016 1:00 pm
Forum: Beginner Basics
Topic: VPN Server (pptp) and more then 1 vpn sessions
Replies: 2
Views: 1930

Re: VPN Server (pptp) and more then 1 vpn sessions

Have the same troubles. I try to connect more than one pptp session to the MikroTik. The second VPN sessions stale on User login/password checking ant terminate with 806 error.
Try to investigate the reason. May be troubles are connected to the local firewall.
by BlackRat
Fri Oct 16, 2015 11:17 am
Forum: General
Topic: IPSec tunnel become unavailable
Replies: 5
Views: 1196

Re: IPSec tunnel become unavailable

Ok. Another trouble. I have two locations. Both locations has two ISP (active-backup). And both locations use simple recursive routing for failower. I created 4 ipip-tunnels: Offices location has the same config: ipip-main-isp-remotemain-isp ipip-main-isp-remotebackup-isp ipip-backup-isp-remotemain-...
by BlackRat
Fri Oct 16, 2015 10:54 am
Forum: General
Topic: IPSec tunnel become unavailable
Replies: 5
Views: 1196

Re: IPSec tunnel become unavailable

This can be an issue of mismatching lifetimes (peer definition as well as proposal) or lifebytes (peer defintion).
Additionallly, make sure that both Peers sync against the very same NTP server. IPsec is very delicate in timing.

Cheers
-Chris
Yea! I found lifetime mismatch! Thank you!
by BlackRat
Fri Oct 16, 2015 10:14 am
Forum: General
Topic: IPSec tunnel become unavailable
Replies: 5
Views: 1196

IPSec tunnel become unavailable

Hi. Have customer with two locations connected by IPSec tunnel. One location: RB1200 v.6.28 Second location: RB2011LS v.6.32.2 Some time IPSec tunnel is stopworking and I can't find a reason and method to restore tunnel. While IPSec is not working I see that internet on both sides is working perfect...
by BlackRat
Sun Oct 26, 2014 5:46 am
Forum: General
Topic: 6.20 release. Time zone Europe/Moscow = +4 (need +3)
Replies: 2
Views: 1555

6.20 release. Time zone Europe/Moscow = +4 (need +3)

Please update time zone Europe/Moscow. Now GMT Offset is +3
http://www.timeanddate.com/time/change/russia/moscow
by BlackRat
Wed Aug 06, 2014 12:34 pm
Forum: The User Manager
Topic: User-manager + WPA2 Enterprise + LinkSys AP
Replies: 4
Views: 6176

Re: User-manager + WPA2 Enterprise + LinkSys AP

No answers means no solutions for wireless clients?
by BlackRat
Thu Jul 31, 2014 8:41 am
Forum: The User Manager
Topic: User-manager + WPA2 Enterprise + LinkSys AP
Replies: 4
Views: 6176

Re: User-manager + WPA2 Enterprise + LinkSys AP

Use mikrotik, but still can't authenticate users from usermanager. Use this config: 1. base router with usermanager (6.17): 2011UAS-2HnD 2. ap (6.17): 751G-2HnD on the ap: /interface bridge add admin-mac=D4:CA:6D:20:E3:99 auto-mac=no l2mtu=1598 name=bridge-local /interface ethernet set [ find defaul...
by BlackRat
Wed Jul 30, 2014 12:59 pm
Forum: The User Manager
Topic: User-manager + WPA2 Enterprise + LinkSys AP
Replies: 4
Views: 6176

User-manager + WPA2 Enterprise + LinkSys AP

Hi. Use this config: 1. Access Point: LinkSys WRT54GL 2. Access Point: Apple AirPort time capsule 3. Switch: MikroTik CRS125-24G-1S I use User Manager on MikroTik and try to configure WPA2 Enterprise on AP's. But I've got an error in User Manager: Username: user01 User IP: 0.0.0.0 Host IP: 10.10.10....
by BlackRat
Thu Mar 06, 2014 3:42 pm
Forum: Beginner Basics
Topic: NAT and internal link
Replies: 6
Views: 2266

Re: NAT and internal link

I tried to add
add action=dst-nat chain=dstnat dst-address=xxx.xxx.xxx.110 dst-port=443 protocol=tcp src-address=192.168.30.0/24 to-addresses=192.168.30.1 to-ports=443
at the top of NAT rules, not working... :(
by BlackRat
Thu Mar 06, 2014 3:37 pm
Forum: Beginner Basics
Topic: NAT and internal link
Replies: 6
Views: 2266

Re: NAT and internal link

ok. Try to minimise words quantity... Internal DNS. DNS Zone: mydomain.local SERVER1 = 192.168.30.1 SERVER2 = 192.168.30.2 DNS Zone: mydomain.ru MAIL = 192.168.30.1 others records copied from external DNS-server (that hosts mydomain.ru) For external users (all right!) For SERVER1: add action=dst-nat...
by BlackRat
Thu Mar 06, 2014 1:44 pm
Forum: Beginner Basics
Topic: NAT and internal link
Replies: 6
Views: 2266

NAT and internal link

Hi. My company has LAN with domain mydomain.LOCAL. We have 2 servers (SERVER1 and SERVER2) My users wants to use single name mail.mydomain.ru (external internet address) for external access to the mail server SERVER1 (https) and RDP to terminal server SERVER2 because I configured 2 NAT rules: 1. fro...
by BlackRat
Mon Aug 12, 2013 3:32 pm
Forum: General
Topic: RADUIS and Russian logins
Replies: 0
Views: 593

RADUIS and Russian logins

Hi. We are using 2011UAS as VPN server. Mikrotik configured as RADIUS client for Windows NAP server. When we use login in English - all ok. If we try to use login in Russian language - we get errors from Windows Server... So... Is it possible to fix this problem or we need to use ONLY english in the...
by BlackRat
Mon Jul 29, 2013 9:14 pm
Forum: Beginner Basics
Topic: Some packages not available
Replies: 1
Views: 872

Some packages not available

One time we have faced with "broken" mikrotik. And restore it with help of netinstall. Then we manualy install packages on it. So... Now we need to upgrade (remotely) it to last version. But "The Dude" shows "some packages not available"... What packages I should instal...
by BlackRat
Mon Jul 29, 2013 9:59 am
Forum: General
Topic: 6.2 and 951G-2HnD and SNMP
Replies: 3
Views: 2072

6.2 and 951G-2HnD and SNMP

Use 951G-2HnD. Use snmp-monitoring to control incoming/outgoing bandwith. SNMP enable but no response from MikroTik. But, as you can see on the screenshot the snmp-packets reach router.
So, what the problem with 951G-2HnD?
Others (RB2011L-IN, ...) are working perfect.
by BlackRat
Mon Jul 29, 2013 9:46 am
Forum: General
Topic: IPSec Tunnel - Cant ping remote network from one side
Replies: 3
Views: 4146

Re: IPSec Tunnel - Cant ping remote network from one side

Nobody can help and nobody know how to solve this...
by BlackRat
Mon Jul 29, 2013 9:44 am
Forum: Beginner Basics
Topic: Ping within LAN
Replies: 2
Views: 1368

Re: Ping within LAN

I'm talking about IPSec-tunnel. Not VLAN.
by BlackRat
Wed Jul 24, 2013 5:37 pm
Forum: General
Topic: IPSec tunnels and access troubles
Replies: 6
Views: 1694

Re: IPSec tunnels and access troubles

I used reccomended 6.2 (new). Now all is working perfect.
by BlackRat
Wed Jul 24, 2013 1:32 pm
Forum: Beginner Basics
Topic: RouterOS releases
Replies: 10
Views: 2379

Re: RouterOS releases

Now it's working. We are monitoring the situation... Thank's a lot.
by BlackRat
Wed Jul 24, 2013 12:39 pm
Forum: General
Topic: IPSec tunnels and access troubles
Replies: 6
Views: 1694

Re: IPSec tunnels and access troubles

6.2 has the same issues...
We have 2 IPSec tummels. Suddenly both tunnels ceased to work. We disabled on of them. After that the other works perfect.

:(
So... Do I need downgrade to 6.0?
by BlackRat
Tue Jul 23, 2013 5:59 pm
Forum: Beginner Basics
Topic: Ping within LAN
Replies: 2
Views: 1368

Ping within LAN

Hi. I have Mikrotik 6.2. RouterBoard 2011UAS-2HnD I'm pinging it through LAN (Gigabit port) and have: Ping minimum = 0msec, maximum = 228 msec, average= 57msec. Why? If I ping my LAN-switch I get ping minimum = 0msec, maximum = 0msec, average= 0msec MyComp - 100Mbit/s - LAN switch - 100Mbit/s - Mikr...
by BlackRat
Tue Jul 23, 2013 5:10 pm
Forum: Beginner Basics
Topic: Ping and IPSec tunnel
Replies: 0
Views: 820

Ping and IPSec tunnel

Hi. I created IPSec tunnel between two offices. One side (SITE1): 192.168.0.0/24 and local gateway is 192.168.0.254 (MikroTik) Other side (SITE2): 192.168.1.0/24 and local gateway is 192.168.1.254 (MikroTik) Servers in the SITE1. DNS server in the SITE1. DNS1 = 192.168.0.250 Clients in the SITE2. Wh...
by BlackRat
Tue Jul 23, 2013 10:54 am
Forum: Beginner Basics
Topic: RouterOS releases
Replies: 10
Views: 2379

Re: RouterOS releases

Thank's. Now I can upgrade up to 6.2.
by BlackRat
Tue Jul 23, 2013 10:37 am
Forum: Beginner Basics
Topic: RouterOS releases
Replies: 10
Views: 2379

Re: RouterOS releases

The same error. I saw "upgrade package" in the other package groups... Didn't find in the your archive.
by BlackRat
Tue Jul 23, 2013 8:17 am
Forum: Beginner Basics
Topic: RouterOS releases
Replies: 10
Views: 2379

Re: RouterOS releases

I added files but can't upgrade with The Dude: "no packages available".
by BlackRat
Mon Jul 22, 2013 4:03 pm
Forum: Beginner Basics
Topic: RouterOS releases
Replies: 10
Views: 2379

Re: RouterOS releases

We have IPSec issues...
by BlackRat
Mon Jul 22, 2013 3:42 pm
Forum: Beginner Basics
Topic: RouterOS releases
Replies: 10
Views: 2379

RouterOS releases

Please, give me a link to site with all releases... Need 6.0. Can't find.
by BlackRat
Mon Jul 22, 2013 2:42 pm
Forum: General
Topic: IPSec tunnels and access troubles
Replies: 6
Views: 1694

Re: IPSec tunnels and access troubles

Sorry. Cant's find oficial MikroTik's release 6.0. :(
by BlackRat
Mon Jul 22, 2013 1:58 pm
Forum: General
Topic: IPSec tunnels and access troubles
Replies: 6
Views: 1694

IPSec tunnels and access troubles

Hi. We are support company. We have the monitoring site and the office (tech support). And we are connecting with help of IPSec tunnels to clients offices to monitor equipment. Suddenly we were faced the following trouble: 1. Client claims that IPSec tunnel beetwin client's offcices don't work. 2. W...
by BlackRat
Thu Jul 18, 2013 10:56 am
Forum: Beginner Basics
Topic: MikroTik and VLAN
Replies: 3
Views: 1391

Re: MikroTik and VLAN

What about bridges? Do I need attach IP-address to the bridge or VLAN?
by BlackRat
Thu Jul 18, 2013 9:45 am
Forum: Beginner Basics
Topic: MikroTik and VLAN
Replies: 3
Views: 1391

MikroTik and VLAN

Hi. What is the right way and steps to create VLANs on MikroTik. Do I need to create bridges? My example in file. I try to understand Mikrotik's Wiki, but I found very complex config there and no ideological description. I have bridge-local as corporate LAN, bridge-guests as guests LAN. Do I need to...
by BlackRat
Wed Feb 20, 2013 3:32 pm
Forum: Wireless Networking
Topic: What technology I should use?
Replies: 3
Views: 1434

Re: What technology I should use?

About 20 users with Android devices. I think that 2-5 Mbit/s is enough for one user.
by BlackRat
Wed Feb 20, 2013 2:26 pm
Forum: Wireless Networking
Topic: What technology I should use?
Replies: 3
Views: 1434

What technology I should use?

Hi!
I need to create wireless network for warehouse 40 (w) x 100 (l) x 8-10 (h) (in meters). Can I use Netgear (for example) PoE (802.3af) switch to connect to AP's? What technology I should use (mesh, one SSID + different freq. or somethin else)? How many AP's I need?
by BlackRat
Mon Dec 10, 2012 1:28 pm
Forum: General
Topic: IPSec Tunnel - Cant ping remote network from one side
Replies: 3
Views: 4146

Re: IPSec Tunnel - Cant ping remote network from one side

The same problem. My config is: 192.168.8.0/24--192.168.8.254(mikrotikA)xxx.xxx.xxx.150--xxx.xxx.xxx.129==yyy.yyy.yyy.1--yyy.yyy.yyy.146(mikrotikB)192.168.4.254--192.168.4.0/24 Try to ping from 192.168.4.10 to 192.168.8.10: success Try to ping from 192.168.8.10 to 192.168.4.10: unsuccessfull... xxx....
by BlackRat
Tue Dec 04, 2012 4:00 pm
Forum: Beginner Basics
Topic: VLANs how to?
Replies: 4
Views: 1764

Re: VLANs how to?

Thank's. It's working. I tested with Nortel BayStack 450-24T. All working with this config: 1. create (interface) vlan4 = ether1 2. create (interface) vlan5 = ether1 3. create bridge-vlan4 - I think, not needed 4. create bridge-vlan5 = vlan4 + ether2 (untagged access) 5. Add IP addresses to vlan4 an...
by BlackRat
Tue Dec 04, 2012 12:14 pm
Forum: Beginner Basics
Topic: VLANs how to?
Replies: 4
Views: 1764

Re: VLANs how to?

Try to use this link: http://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Vlan_Table Try to make new config: Port ether1 = tagged (VLAN4 - lan, VLAN5 - management) trunk Port ether2 = untagged (VLAN5 -management) access Config from mikrotik: /interface ethernet switch port> print # NAME SWITCH...
by BlackRat
Tue Dec 04, 2012 9:25 am
Forum: Beginner Basics
Topic: VLANs how to?
Replies: 4
Views: 1764

Re: VLANs how to?

Sorry. Forgot. MikroTik will be as firewall and router between management, storage and LAN networks...
by BlackRat
Tue Dec 04, 2012 9:23 am
Forum: Beginner Basics
Topic: VLANs how to?
Replies: 4
Views: 1764

VLANs how to?

Hi. I have RB1200 and I want to use 1Gb/s switch to maximize throughoutput. I have HP Proliant Server with NIC1 and NIC2. I have Netgear NAS with NIC1 and NIC2. I plan to create VLANS: VLAN 2 - storage - HP Proliant server NIC2 + Netgear NAS NIC2 (ethernet4 + ethernet5) VLAN 3 - internet ethernet10 ...
by BlackRat
Thu Nov 22, 2012 4:04 pm
Forum: Beginner Basics
Topic: nailed up IPSec tunnel
Replies: 3
Views: 2348

nailed up IPSec tunnel

I have ZyXEL ZyWALL 2 Plus from one side and MikroTik 751G-2HnD from another side. In the ZyXEL there is an option "nailed up connection". How I can create nailed up connection from MikroTik's side?
by BlackRat
Thu Nov 22, 2012 3:51 am
Forum: General
Topic: Upgrade from 5.20 to 5.21. RB751G-2HnD
Replies: 8
Views: 2461

Re: Upgrade from 5.20 to 5.21. RB751G-2HnD

Thank's. I tried to run The Dude from inside network and it'k ok.
by BlackRat
Tue Nov 20, 2012 4:42 pm
Forum: General
Topic: Upgrade from 5.20 to 5.21. RB751G-2HnD
Replies: 8
Views: 2461

Re: Upgrade from 5.20 to 5.21. RB751G-2HnD

rule 9 allow snmp to router from outside. :(
by BlackRat
Tue Nov 20, 2012 4:38 pm
Forum: General
Topic: Upgrade from 5.20 to 5.21. RB751G-2HnD
Replies: 8
Views: 2461

Re: Upgrade from 5.20 to 5.21. RB751G-2HnD

Should I open SNMP UDP-161 from external (in the firewall)? I try to monitor from outside.
by BlackRat
Tue Nov 20, 2012 4:29 pm
Forum: General
Topic: Upgrade from 5.20 to 5.21. RB751G-2HnD
Replies: 8
Views: 2461

Re: Upgrade from 5.20 to 5.21. RB751G-2HnD

I turned on SNMP, but no results...
by BlackRat
Tue Nov 20, 2012 4:14 pm
Forum: General
Topic: Upgrade from 5.20 to 5.21. RB751G-2HnD
Replies: 8
Views: 2461

Upgrade from 5.20 to 5.21. RB751G-2HnD

After upgrade I see in "The Dude" that services "partyally down". It CPU. So what the problem? It seems to me router is working fine. But I worry about other routers. Should I upgrade them to 5.21? How I can get rid off the CPU problem?