Community discussions

MikroTik App

Search found 140 matches

by fpascual
Mon Aug 04, 2008 4:05 pm
Forum: General
Topic: eMule Traffic Limit per Hours
Replies: 0
Views: 714

eMule Traffic Limit per Hours

Hi, I need to limit eMule traffic but only in a certain period of the day (9am to 18pm), how can I do that with version 2.9.27 ?. Thanks in advance.
by fpascual
Tue Apr 22, 2008 6:12 am
Forum: General
Topic: I can´t establish output ftp or rdp connections
Replies: 4
Views: 1714

Re: I can´t establish output ftp or rdp connections

Please, someone can help me ?. Thanks in advance.
by fpascual
Mon Apr 14, 2008 1:15 am
Forum: General
Topic: I can´t establish output ftp or rdp connections
Replies: 4
Views: 1714

Re: I can´t establish output ftp or rdp connections

I forgot put my nat rules, sorry: 0 ;;; Nat de la Lan chain=srcnat out-interface=externa src-address=192.168.1.0/24 action=masquerade 1 ;;; Permito eMule Pto TCP 7415 chain=dstnat in-interface=externa protocol=tcp dst-port=7415 action=dst-nat to-addresses=192.168.1.2 to-ports=7415 2 ;;; Permito eMul...
by fpascual
Sun Apr 13, 2008 11:50 pm
Forum: General
Topic: I can´t establish output ftp or rdp connections
Replies: 4
Views: 1714

I can´t establish output ftp or rdp connections

I can´t connect from my LAN to FTP or RDP outside services. This is my schema: INTERNET -> CABLEMODEM -> MIKROTIK -> LINKSYS AP MODE -> LAN PC These are my firewall filter forward rules: 0 ;;; Permito Terminal Server solo desde el Trabajo - IMPSAT chain=forward src-address=200.X.X.X dst-address=192....
by fpascual
Tue Jul 10, 2007 7:01 pm
Forum: General
Topic: Limit DNS Querys
Replies: 0
Views: 707

Limit DNS Querys

I receive a distributed DoS/DDoS UDP attack to a DNS Service, how can I detect and filter dinamically ?. I supposed from /ip firewall filter with "limit", but I can´t do it.

Thanks a Lot
by fpascual
Wed May 09, 2007 9:08 pm
Forum: General
Topic: Downstream BGP
Replies: 3
Views: 1488

Downstream BGP

Hi, I have 5 BGP peers and need to control some traffic by manually form.
I controlled upstream traffic via mangle rules and static routes, but, how can I configured some kind of downstream traffic to receive them for a particular bgp peer ?.



Thanks
by fpascual
Wed May 09, 2007 3:44 pm
Forum: General
Topic: Graphs Question
Replies: 4
Views: 1126

Sorry, and what´s about Vlans graphs ?.


Thanks
by fpascual
Wed May 09, 2007 2:59 pm
Forum: General
Topic: Graphs Question
Replies: 4
Views: 1126

Excellent sergejs, thanks a lot !.
by fpascual
Tue May 08, 2007 6:37 pm
Forum: General
Topic: Graphs Question
Replies: 4
Views: 1126

Graphs Question

Hi, I´m using /tool graphing and can´t understand how I must read the graphs.

Interfaces Traffic Graphs and Queue Graphs, In both cases, wich is the traffic that go from mi LAN to Internet and vice versa ?.


Thanks a lot.
by fpascual
Wed Apr 25, 2007 5:41 pm
Forum: General
Topic: Problems with NAT
Replies: 7
Views: 7998

by fpascual
Wed Apr 25, 2007 5:22 pm
Forum: General
Topic: Problems with NAT
Replies: 7
Views: 7998

Fijate esto: /ip firewall filter ;;; Permito FTP chain=forward dst-address=192.168.1.2 protocol=tcp dst-port=21 action=accept /ip firewall nat ;;; Permite FTP chain=dstnat protocol=tcp dst-port=21 action=dst-nat to-addresses=192.168.1.2 to-ports=21 Tenes que habilitarlo en el forward tambien. En las...
by fpascual
Wed Apr 25, 2007 5:00 pm
Forum: General
Topic: Problems with NAT
Replies: 7
Views: 7998

No tenes dst-nat para la Wan 2 tambien ?.
Otra cosa, las reglas de forward estan correctas ?
by fpascual
Wed Apr 25, 2007 3:34 pm
Forum: General
Topic: Problems with NAT
Replies: 7
Views: 7998

Hola Alberto, para hacer port forwarding (lo que vos queres hacer) se utiliza dstnat. Fijate, tengo una PC con un FTP y quiero que desde Internet ingresen al puerto: ;;; Permite FTP chain=dstnat protocol=tcp dst-port=21 action=dst-nat to-addresses=192.168.1.2 to-ports=21 Con respecto al gre, fijate,...
by fpascual
Fri Apr 13, 2007 7:37 pm
Forum: Scripting
Topic: DDNS Resolve
Replies: 0
Views: 1285

DDNS Resolve

I have a friend with ddns, how can I make a firewall rule or vpn connection if I have only the hostname ?

Thanks a lot.
by fpascual
Thu Apr 12, 2007 9:32 pm
Forum: General
Topic: Mangle Question
Replies: 9
Views: 2480

Oh, ok, yes, in this moment I use mangle to tag the packets and then statics routes to route him. I think that can make this job with BGP too.
by fpascual
Thu Apr 12, 2007 8:49 pm
Forum: General
Topic: Mangle Question
Replies: 9
Views: 2480

No Tom, I´m not talking about mangle with BGP, just need to route some upstream traffic depending on the source addresses. I mean: IF my router receive a packet with XXXX source address range and YYYY destination address, I need to route this packet to Peer N (I decide for wich peer send this packet...
by fpascual
Thu Apr 12, 2007 5:17 pm
Forum: General
Topic: Mangle Question
Replies: 9
Views: 2480

Ok Tom, I read your post about BGP. Look, I need route some networks by src-address: add chain=prerouting in-interface=red_acceso src-address=200.X.6.0/24 dst-address-list=bloques_nacionales action=accept comment="200.X.6.0/24 Upstream Nacional" disabled=no add chain=prerouting in-interfac...
by fpascual
Thu Apr 12, 2007 4:57 pm
Forum: General
Topic: Mangle Question
Replies: 9
Views: 2480

Ohhh, thanks a lot !.
And then I must to configure 1 line per network in address list, is it correct ?.
Can I make this traffic treatment with BGP directly ?.
by fpascual
Thu Apr 12, 2007 4:27 pm
Forum: General
Topic: Mangle Question
Replies: 9
Views: 2480

Another question, I have 5 BGP peers and use mangle to take a control to upstream traffic (balancing 3 international providers), how can I do that with BGP ?
by fpascual
Thu Apr 12, 2007 4:23 pm
Forum: General
Topic: Mangle Question
Replies: 9
Views: 2480

Mangle Question

Hi, can I put more than one dst-address into a single mangle rule ?, I must to configure tagging to more than 20 networks.


Thanks
by fpascual
Wed Apr 11, 2007 4:36 pm
Forum: General
Topic: Interfaces Question
Replies: 1
Views: 891

Interfaces Question

I need a router with follow interfaces:

2 Channelized E1/PRI ports
4 Serial Network Interfaces
2 Fast Ethernet Interfaces

Can I make this with mikrotik ?


Thanks to all.
by fpascual
Sat Apr 07, 2007 6:22 pm
Forum: General
Topic: Port
Replies: 16
Views: 3761

Yes, before I try with TCP and doesn`t work.
Is correct use "telnet mk_ip port" to activate knocking ???, I think this is my problem.

Thanks to all.
by fpascual
Sat Apr 07, 2007 5:19 pm
Forum: General
Topic: Port
Replies: 16
Views: 3761

No skill ... Take a look of my firewall rules: [admin@mk] ip firewall filter> print input Flags: X - disabled, I - invalid, D - dynamic 0 ;;; Permito SSH desde la LAN chain=input in-interface=interna src-address=192.168.1.0/24 protocol=tcp dst-port=22 action=accept 1 ;;; Permito SSH - Port Knocking ...
by fpascual
Sat Apr 07, 2007 2:40 pm
Forum: General
Topic: Port
Replies: 16
Views: 3761

JJCinAZ, doesn`t work ...
by fpascual
Thu Apr 05, 2007 10:50 pm
Forum: General
Topic: Port
Replies: 16
Views: 3761

Take a look please: 19 ;;; Permito SSH - Port Knocking SSH - Interface Externa chain=input in-interface=externa dst-port=2021 action=add-src-to-address-list address-list=ssh_ok address-list-timeout=15m 20 ;;; Acepto SSH Verificado - Port Knocking chain=input in-interface=externa protocol=tcp dst-por...
by fpascual
Wed Apr 04, 2007 9:28 pm
Forum: General
Topic: Port
Replies: 16
Views: 3761

Yes, but I want to do a port knocking only one port.

UDP port 2021 -> add src to list A
Permit List A for 15 minutes


Then, I must use telnet to this port ?? (like "telnet 192.168.1.1 2021")

In this momento I use port knocking but with http port ....


Thanks !.
by fpascual
Fri Mar 30, 2007 8:42 pm
Forum: General
Topic: Routing
Replies: 0
Views: 760

Routing

I must to configure a customer wich 2 internet access. Y need route VPN and VOIP between 1 interface and the rest for the other, wich is the best method ?, ECMP ?. For packet tagging I use ip firewall mangle with this options VPN connection-type=pptp and other one with connection-type=gre Is this co...
by fpascual
Tue Mar 27, 2007 3:40 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

Finally the problem was the 3COM cards, now use Realtek ..., I can´t understand what´s happend.



Thanks
by fpascual
Mon Mar 26, 2007 1:45 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

When monitoring links status I saw "link-ok" and then "no-link" (flaps), I supposed that the problem is the 3COM cards, could it be ??, could be the 2.9.41 version ?.

Please help me.


Thanks a lot.
by fpascual
Sun Mar 25, 2007 9:42 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

I´m using 4 NIC´s 3COM 3c905C-TX/TX-M [Tornado] and connect him directly to peers, the link is OK, what could it be ??.


Thanks
by fpascual
Sat Mar 24, 2007 8:44 am
Forum: General
Topic: Port
Replies: 16
Views: 3761

Yes, I tried to use /ip firewall filter with a different ports but doesn`t work.
Can you paste me an example please ?.


Thanks a lot.
by fpascual
Fri Mar 23, 2007 6:31 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

I need to update the PC configuration. i got working right now a PC with 4 NICs. i wanted to upgrade this very old equipment with a new one, with the addition of 1 more NIC. i have tested several motherboards earlier with no success: the biggest problem is to find some MB with 5 PCI slots. when find...
by fpascual
Fri Mar 23, 2007 5:03 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

Janisk, I didn´t change the ttl, I´m going to try this tomorrow, what value must have ?. Remember that my production router have the ttl=1 and is a copy of them.
by fpascual
Fri Mar 23, 2007 2:55 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

Danail, no: 200.XX.17.151 is my production router that work OK 200.XX.17.1 is the router of my provider (PEER1) I´m trying to change a hardware for a new one and copy the configuration of the production router to this new one (and with which have the problem). Do you understand me ?. Yes, I supposed...
by fpascual
Fri Mar 23, 2007 2:01 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

Danail, I can´t reach 200.xx.17.1 with ping. Look the routing table: # DST-ADDRESS PREF-SRC G GATEWAY DISTANCE INTERFACE 828 ADC 200.XX.17.0/24 200.XX.17.151 0 Peer1 829 Db 200.xX.17.0/24 r 200.XX.25.49 30 Peer2 And this is the routing table of my production router (it work fine): # DST-ADDRESS PREF...
by fpascual
Thu Mar 22, 2007 2:21 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

07:22:57 route,bgp,info Failed to open TCP connection: No route to host 07:22:57 route,bgp,info RemoteAddr=200.xx.17.1 07:22:57 route,bgp,info RemotePort=179 07:23:17 route,bgp,debug,timer ConnectRetryTimer expired 07:23:17 route,bgp,debug,timer RemoteAddr=200.xx.17.1 07:23:17 route,bgp,debug Connec...
by fpascual
Wed Mar 21, 2007 6:43 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

Yes Sam, in the other router (which are working now !) have the same configuration (with ttl=1).
by fpascual
Wed Mar 21, 2007 1:19 pm
Forum: General
Topic: BGP Problem
Replies: 16
Views: 4066

BGP Problem

I configured a new hardware with RouterOS 2.9.41 and the same configuration that the other MK that works fine. With the original router all works great, it have RouterOS 2.9.30. When connect the new hardware with the same configuration, 4 of 6 bgp peer doesn´t established the connection: Example: na...
by fpascual
Wed Mar 21, 2007 2:23 am
Forum: General
Topic: Port
Replies: 16
Views: 3761

Port

Where can I define other ports than /ip service ?, I`m trying to configure port knocking in port 48220 but can`t define them.


Thanks.
by fpascual
Tue Mar 20, 2007 4:42 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Ok, thanks a lot !
by fpascual
Tue Mar 20, 2007 3:54 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Ok, if I put 2.9.39 if the same ?, I have this version installed in a backup router.


Thanks
by fpascual
Sat Mar 17, 2007 1:12 am
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Ok, thanks !
by fpascual
Sat Mar 17, 2007 12:30 am
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Ok, do you recommend me to wait or put 2.9.38 ?
by fpascual
Fri Mar 16, 2007 11:45 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Ok Sam, thanks a lot, do you consider that my filter is correctly configured ?.
What about 2.9.40 version ?, have any BGP change with respect 2.9.38 ?
by fpascual
Fri Mar 16, 2007 11:39 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Thanks Sam !, what I must do to upgrade only routing-test package ?
by fpascual
Fri Mar 16, 2007 11:03 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

2.9.30 Sam
by fpascual
Fri Mar 16, 2007 9:30 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Yes
by fpascual
Fri Mar 16, 2007 9:12 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Ok, I have the following problem: Example: I have ISP1, and need to: Discard AS 26XX Discard 200.X.5.0/24 and 200.X.31.0/24 networks Accept 200.X.0.0/19 and 200.X.80.0/20 networks Deny any any And when apply this filter doesn´t work: add chain=filter-ISP1-out bgp-as-path=26XX invert-match=no action=...
by fpascual
Fri Mar 16, 2007 4:19 pm
Forum: General
Topic: Routing Filter
Replies: 18
Views: 2813

Routing Filter

I´m trying to read /routing filter and can´t understand.
I must define my networks to publish in /routing bgp network, and then, what can I do in /routing filter ?.
The question is very basic, I know, but can´t understand.


Thanks a lot
by fpascual
Tue Feb 27, 2007 5:08 pm
Forum: General
Topic: Read Only Permission
Replies: 3
Views: 1126

Ahhh, ok ok, I understand.

Thanks !!
by fpascual
Tue Feb 27, 2007 2:47 pm
Forum: General
Topic: Read Only Permission
Replies: 3
Views: 1126

Read Only Permission

It is possible that a "read only" user have permissions to reboot the mk ??.


Thanks
by fpascual
Wed Feb 21, 2007 1:32 pm
Forum: General
Topic: Routing Question
Replies: 7
Views: 1697

OK, thanks sergejs !.
by fpascual
Tue Feb 20, 2007 8:58 pm
Forum: General
Topic: Routing Question
Replies: 7
Views: 1697

Normis, thanks, I apply packet tagging from /ip firewall mangle and then statics routes with routing-mark in /ip route, thats correct ??.


Thanks
by fpascual
Mon Feb 19, 2007 4:31 pm
Forum: General
Topic: Routing Question
Replies: 7
Views: 1697

I mean, is this the correct method or exist a better way to do the same ?

Thanks
by fpascual
Mon Feb 19, 2007 4:27 pm
Forum: General
Topic: Routing Question
Replies: 7
Views: 1697

Oh, yes Normis, works fine, but I think that exist other method, is´n it ?.


Thanks
by fpascual
Mon Feb 19, 2007 4:21 pm
Forum: General
Topic: Routing Question
Replies: 7
Views: 1697

Routing Question

I have two peers to send international traffic, one by default (A) and the other (B) with /ip firewall mangle rules to mark packets and then put static routing. The idea is change this schema and passtrough the most traffic by the B provider, besides of /ip firewall mangle, wich other method can I u...
by fpascual
Tue Feb 13, 2007 3:47 pm
Forum: General
Topic: Problem With 2.9.39 and IRQ
Replies: 5
Views: 2761

I think the problem is the mother: Asus P4S8X-X Rev 1.01 Bios Ver 1002 Chipset 648

Someone know if it compatible ?.



Thanks
by fpascual
Tue Feb 13, 2007 2:27 pm
Forum: General
Topic: Problem With 2.9.39 and IRQ
Replies: 5
Views: 2761

Now I tried to switch cards into different pci slots and when execute /interface ethernet disable "n" and then enable show me this output:

"action failed (6)"
by fpascual
Tue Feb 13, 2007 1:51 pm
Forum: General
Topic: Problem With 2.9.39 and IRQ
Replies: 5
Views: 2761

When I execute /system resource pci print command only figures 4 cards (not 5) and with the same IRQ=255 ...
by fpascual
Mon Feb 12, 2007 10:37 pm
Forum: General
Topic: Problem With 2.9.39 and IRQ
Replies: 5
Views: 2761

Problem With 2.9.39 and IRQ

I´m trying to install a RouterOS v 2.9.39 and doesn´t recognizes my 5 (five) eth cards. I have this setup: Mother Asus P4S8X-X Rev 1.01 Bios Ver 1002 Chipset 648 P 4 2.66 Ghz Processor 5 (five) 3com 905C-TX-M Network Cards Nvidia Gforce 4 MX 4000 1 X 256 DDR 8 Chips AGP Slot Gforce 4 MX 4000 PCI Slo...
by fpascual
Mon Feb 05, 2007 3:06 pm
Forum: General
Topic: Voip and Vpn Between 2 Connections
Replies: 8
Views: 1650

Voip packets.
With mangle I mark packets for the both ways ? (input and output)
by fpascual
Mon Feb 05, 2007 2:47 pm
Forum: General
Topic: Voip and Vpn Between 2 Connections
Replies: 8
Views: 1650

Ok ok, and marking the packet matches in connection-type=h323 no ?


Thanks
by fpascual
Mon Feb 05, 2007 2:39 pm
Forum: General
Topic: Voip and Vpn Between 2 Connections
Replies: 8
Views: 1650

Sorry janisk, I don´t understand.
by fpascual
Mon Feb 05, 2007 2:07 pm
Forum: General
Topic: Voip and Vpn Between 2 Connections
Replies: 8
Views: 1650

Voip and Vpn Between 2 Connections

I have a customer with 2 adsl connections. They use normal internet traffic and in addition VPN and VOIP traffic. I want to route VOIP traffic through one of this connections and the rest for the other. I must use /ip firewall mangle feature ?, in this case, i must use "connection-type" op...
by fpascual
Wed Jan 31, 2007 2:48 pm
Forum: General
Topic: Queue by Mac Address
Replies: 1
Views: 1348

Queue by Mac Address

Hi, can I apply a simple queued to an specific mac address ?, I´m trying to do that but can´t find the option.


Thanks a lot
by fpascual
Fri Jan 05, 2007 4:12 pm
Forum: General
Topic: Port Knocking
Replies: 6
Views: 1802

I tested with "telnet my_host 7777" comand from remote windows and doesn't work. Look the rules: 1 ;;; Port Knocking SSH - Interface Externa chain=input in-interface=externa src-address=0.0.0.0/0 protocol=tcp dst-port=7777 action=add-src-to-address-list address-list=ssh_ok address-list-tim...
by fpascual
Fri Jan 05, 2007 2:23 pm
Forum: General
Topic: Port Knocking
Replies: 6
Views: 1802

Yes janisk, 887 is an example only.
If i configure port 5555 doesn't work. I make a telnet to my host port 5555 and don't matches with "add-src-to-address-list" action.
Do you understand ?.


Thanks
by fpascual
Thu Jan 04, 2007 4:56 pm
Forum: General
Topic: BGP Next Hop
Replies: 2
Views: 1145

Thanks Gregor, is eBgp, but just work, I forget it reset the bgp session.


Regards
by fpascual
Thu Jan 04, 2007 4:53 pm
Forum: General
Topic: Port Knocking
Replies: 6
Views: 1802

Port Knocking

I configure port knocking for ssh login but doesn't work at least that use an open port by mikrotik (like 80). Rules: ;;; Port Knocking SSH - Interface Externa chain=input in-interface=externa src-address=0.0.0.0/0 protocol=tcp dst-port=80 action=add-src-to-address-list address-list=ssh_ok address-l...
by fpascual
Tue Jan 02, 2007 10:17 pm
Forum: General
Topic: BGP Next Hop
Replies: 2
Views: 1145

BGP Next Hop

I'm publishing N networks and the last day I aggregate a lot of more. This lasts routes are publishing with different "Next Hop" than the others, what could it be ?, is it configurable ?.

Please help me !.


Sorry for my english.


Thanks a lot.
by fpascual
Tue Jan 02, 2007 8:32 pm
Forum: Wireless Networking
Topic: Clear Logs
Replies: 1
Views: 873

Clear Logs

How to clear logs stored on disk ?
by fpascual
Thu Dec 28, 2006 2:32 am
Forum: General
Topic: Drop Logging Attempt
Replies: 1
Views: 738

Drop Logging Attempt

Exist some way (like address lists) to drop "n" ssh logging attempt via ? (for example, drop an IP address who attempt 3 times with logging failure).


Thanks and happy new year!
by fpascual
Wed Dec 27, 2006 2:17 pm
Forum: General
Topic: Unknown State
Replies: 3
Views: 1396

I'm login in via ssh
by fpascual
Tue Dec 26, 2006 2:14 pm
Forum: General
Topic: Unknown State
Replies: 3
Views: 1396

Unknown State

I have 1 interface that show me the follow:

status: unknown


But, when I make pings outside from mk works fine, the problem is that I can't ping from the lan host to Internet (yes to mk).

What could it be ?


Thanks !
by fpascual
Wed Dec 13, 2006 6:51 pm
Forum: General
Topic: Antispam
Replies: 3
Views: 2337

Antispam

I use routeros 2.9.30, is there a way to detect and prevent spam with firewall filters ?

Thanks
by fpascual
Thu Dec 07, 2006 10:04 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

You should first put those lines into a script, then schedule the script in another command... the scheduler doesn't seem to like full blown scripts.

Glad you are following along : )

Sam
Yes yes, it's a great idea.


Thanks a lot !.
by fpascual
Thu Dec 07, 2006 8:44 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Sam, works great !!, thanks a lot !.


Regards.
by fpascual
Thu Dec 07, 2006 7:44 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Ok, I understand, the question is, how can I scheduled each ":if" statement and configure in permanent mode ?
by fpascual
Thu Dec 07, 2006 7:28 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Sam, the ":if" statements must be configured in /system scheduler path ?.
I put the six ":if" with right configuration but doesn't works, how can I view the sentences ?. Do you understand me ?


Thanks
by fpascual
Thu Dec 07, 2006 3:56 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Sam, thanks a lot, but, how can I identify between my 6 bgp peers ?, I must to create 6 bridge interfaces and 6 scripts ?. When I put the script receive an error message ] system scheduler<SAFE> :if ([/routing bgp peer get [/routing bgp peer find name=cymru] state ] = established) do={/int bridge se...
by fpascual
Wed Dec 06, 2006 8:32 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Sam, no, don't have options to make ssh.
In a whatsup cisco routers a bgp peer query OID.IP_PEER(oid[dot]ip_peer), can I do that in MK ?
How can I do to make an script for query via snmp ?
by fpascual
Wed Dec 06, 2006 8:03 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

The OID is .1.3.6.1.2.1.4.24.3.0, but, how can I identify the corresponding peer ?

$snmpwalk -Os -c [community] -v 1 IP_ADDRESS .1.3.6.1.2.1.4.24.3.0

$ip.24.3.0 = Gauge32: 7021

Sound like I receive 7021 routes, but from all the peers.

Thanks
by fpascual
Tue Dec 05, 2006 4:47 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Ok, understand, someone knows how to do that on a Whatsup ?
by fpascual
Mon Dec 04, 2006 7:28 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Thanks, I need to monitor only if BGP sessions are active, are this oid correct ?.
by fpascual
Mon Dec 04, 2006 2:51 pm
Forum: General
Topic: Monitor BGP under WhatsUp
Replies: 17
Views: 7430

Monitor BGP under WhatsUp

Hi, I need to monitor the BGP state of my mk under a WhatsUp system, what's the oid that need to put into them ?


Thanks a lot.
by fpascual
Wed Nov 29, 2006 8:18 pm
Forum: General
Topic: About Commands
Replies: 1
Views: 730

About Commands

Hi, I wan't to know if exist a command like those in Cisco:

1) sh ip route x.x.x.x
2) sh ...... | include {string}


Thanks a lot.
by fpascual
Thu Nov 09, 2006 2:57 pm
Forum: General
Topic: SSH Access
Replies: 5
Views: 1556

Understood Christian, thanks !
by fpascual
Thu Nov 09, 2006 1:33 pm
Forum: General
Topic: SSH Access
Replies: 5
Views: 1556

You mean, put 0.0.0.0/0 in Permit Networks and then filtering in /ip firewall filter ?, what kind of chain is ?.

Thanks a lot Sergejs
by fpascual
Thu Nov 09, 2006 4:02 am
Forum: General
Topic: SSH Access
Replies: 5
Views: 1556

SSH Access

How must I do if I want to access the Mikrotik from 2 different networks ?, for example, 192.168.1.50 and other Public network ? (configuring in /service ssh and /user.

Thanks a lot.
by fpascual
Wed Nov 08, 2006 9:09 pm
Forum: General
Topic: SNMP Server
Replies: 2
Views: 1211

SNMP Server

Sorry, have MK an MRTG server service inside ?


Thanks
by fpascual
Fri Oct 27, 2006 10:25 pm
Forum: General
Topic: Messenger Filtering
Replies: 1
Views: 1658

I use this rule: [admin@] ip firewall mangle<SAFE> print Flags: X - disabled, I - invalid, D - dynamic 0 protocol=tcp tcp-options=syn-only action=passthrough tcp-mss=1452 1 ;;; Permito Messeger src-address=10.0.0.79/32 dst-address=:1863 action=accept mark-connection=CHAT-OK 2 ;;; Marco Paquetes dest...
by fpascual
Thu Oct 26, 2006 3:50 pm
Forum: Wireless Networking
Topic: Proper Shutdown - 2.9.30
Replies: 4
Views: 1590

Ok Normis, I'm going to do that.


Thanks a lot
by fpascual
Thu Oct 26, 2006 3:01 pm
Forum: Wireless Networking
Topic: Proper Shutdown - 2.9.30
Replies: 4
Views: 1590

Normis, thanks but the watchdog in the other mikrotik is active (with 2.9.17 and more power hardware).
Could it be other thing or only wathdog ?

Thanks a lot.

Regards
by fpascual
Wed Oct 25, 2006 6:07 pm
Forum: Wireless Networking
Topic: Proper Shutdown - 2.9.30
Replies: 4
Views: 1590

Proper Shutdown - 2.9.30

Hi, I'm trying the 2.9.30 version and in a moment the router reload: 11:39:29 system,error,critical router was rebooted without proper shutdown The same configuration runs in another with 2.9.17 version and works fine. This is the watchdog config in boths: [admin@FW1] system> watchdog print reboot-o...
by fpascual
Thu Oct 19, 2006 6:55 pm
Forum: General
Topic: Messenger Filtering
Replies: 1
Views: 1658

Messenger Filtering

Hi, I'm trying to block msn messenger for PC 192.168.1.25 and doesn't work. This is the rule: /ip firewall rule forward add src-address=192.168.1.25/32 dst-address=0.0.0.0/0 content=gateway.messenger.hotmail.com,login.gateway.hotmail.com,login.live.com,messenger.msn.com,webmessenger.msn,passport.net...
by fpascual
Tue Oct 17, 2006 2:56 pm
Forum: General
Topic: Clone Configuration
Replies: 9
Views: 4766

Hi, I make the backup but when I replace for the original doesn't work, 2 of my 6 BGP sessions they are in ACTIVE state.
I make a copy line by line and don't forget nothing, what it can be happening ??

Thanks a lot.
by fpascual
Mon Oct 09, 2006 5:14 pm
Forum: General
Topic: BGP Problem
Replies: 0
Views: 2029

BGP Problem

I have a BGP session between MK and Cisco Router. It's strange because in Cisco the session is OK, but not in MK. Look that: CISCO (200.x.x.9) AS1#sh ip bgp sum Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 200.x.x.11 4 xxxx 5203 7098 6565 0 0 02:58:49 33 MIKROTIK (200.x.x.11) [...
by fpascual
Mon Oct 09, 2006 4:35 pm
Forum: General
Topic: Old Versions
Replies: 6
Views: 5971

Ok Normis, I understand. I'm making a copy of core router (2.9.17 Version) under production using 2.9.30, but when apply the backup doesn't work fine, then, I want to make a test with the original version to discard this, if work ok with this test it mean that i'm make a mistake copying the original...
by fpascual
Fri Oct 06, 2006 9:53 pm
Forum: General
Topic: Old Versions
Replies: 6
Views: 5971

Old Versions

Sorry, where can I download the old 2.9.17 version ?.
Another question, can I find a specific net into the /ip route ?, I mean, an equivalent to "sh ip route x.x.x.x" in Cisco.


Thanks a lot.
by fpascual
Thu Oct 05, 2006 5:53 pm
Forum: General
Topic: Clone Configuration
Replies: 9
Views: 4766

Understood, thanks !
by fpascual
Thu Oct 05, 2006 4:10 pm
Forum: General
Topic: Clone Configuration
Replies: 9
Views: 4766

What do you recommend me ?
by fpascual
Thu Oct 05, 2006 3:14 pm
Forum: General
Topic: Routing Problem
Replies: 3
Views: 2921

Eugene, thank you very much !, i'm going to try.
by fpascual
Thu Oct 05, 2006 3:00 pm
Forum: General
Topic: Clone Configuration
Replies: 9
Views: 4766

Ok, I understand, I need make an export and then change the ethernet mac address ?, only that ?, another change ?. The "backup" have the same number of ethernet cards.

Thanks !
by fpascual
Wed Oct 04, 2006 9:30 pm
Forum: General
Topic: Routing Problem
Replies: 3
Views: 2921

Regarding to the last issue, why mikrotik chooses eBGP than iBGP ?, how do I set mikrotik to choose iBGP than eBGP ?, is it possible ?.

Thanks
by fpascual
Wed Oct 04, 2006 6:00 pm
Forum: General
Topic: Routing Problem
Replies: 3
Views: 2921

Routing Problem

Please, help me. I have MK router with 6 peers. One of them connect me to netwok 200.x.x.0/23 directly (trought a cisco router into my AS). The problem is that the MK router show me that: # DST-ADDRESS PREFSRC G GATEWAY DISTANCE INTERFACE 1319 Db 200.x.x.0/23 r CISCO_MY_AS 200 red_acceso 1320 ADb 20...
by fpascual
Wed Oct 04, 2006 3:34 pm
Forum: General
Topic: Clone Configuration
Replies: 9
Views: 4766

Clone Configuration

How can I do to copy identical configuration from one router to another with different hardware ?.

Thanks
by fpascual
Tue Oct 03, 2006 10:18 pm
Forum: General
Topic: BGP Capabilities
Replies: 2
Views: 2424

Oh, ok, thanks a lot Eugene.
by fpascual
Tue Oct 03, 2006 9:36 pm
Forum: General
Topic: BGP Capabilities
Replies: 2
Views: 2424

BGP Capabilities

Sorry, in routeros, where can I found prepending, route maps and other issues like cisco routers ?

Thanks a lot.
by fpascual
Fri Sep 29, 2006 8:45 pm
Forum: General
Topic: Upgrade Problem
Replies: 1
Views: 2190

Upgrade Problem

I upgraded my system from 2.9.27 to 2.9.30 and when reboot the machine it halts or freezes in "Loading System E" messages, what could it be ??


Thanks
by fpascual
Fri Sep 29, 2006 5:39 pm
Forum: General
Topic: BGP - Default Route
Replies: 8
Views: 6378

Eugene, if I upgrade not need to do some changes to work ?, I mean, just upgrade only ?

Thanks !
by fpascual
Fri Sep 29, 2006 4:40 pm
Forum: General
Topic: BGP - Default Route
Replies: 8
Views: 6378

I read about bgp bugs in my MK version (2.9.17), what's happend if I upgrade to new 2.9.30 ?, are this version stable ?, the configuration of 2.9.17 is the same in 2.9.30 or I'm going to make changes in my configuration file ?.

Thanks
by fpascual
Fri Sep 29, 2006 4:03 pm
Forum: General
Topic: BGP - Default Route
Replies: 8
Views: 6378

Thanks, I'm going to apply a filter like this: add chain=test-nap as-path=**** action=discard add chain=test-nap as-path=**** action=discard add chain=test-nap as-path=**** action=discard add chain=test-nap prefix=200.X.X.0/26 prefix-length=26 action=discard add chain=test-nap prefix=200.X.X.128/27 ...
by fpascual
Fri Sep 29, 2006 2:14 pm
Forum: General
Topic: BGP - Default Route
Replies: 8
Views: 6378

janisk, I read this article, but can't understand what I must to do ...
I have some prefixes in /routing filter, but I don't know how filter the default route (0.0.0.0).
Can someone give me an example to filter some prefixes and the default too ?

Thanks a lot
by fpascual
Fri Sep 29, 2006 1:14 am
Forum: General
Topic: BGP - Default Route
Replies: 8
Views: 6378

BGP - Default Route

Hi, I need help. I have mikrotik with version 2.9.17 packages. I don't know why but I'm announcing all my networks (including the default route, the main problem !) to all my providers (6). If I disable redistributed-static in /routing bgp instance I lost my connection with local NAP in my country. ...
by fpascual
Tue Sep 12, 2006 4:13 pm
Forum: General
Topic: Simple Queued
Replies: 4
Views: 1578

Then, I must set up a "limit-at=2000000/2000000" to correcto function ?

Thanks Sergejs.
by fpascual
Tue Sep 12, 2006 3:59 pm
Forum: General
Topic: Simple Queued
Replies: 4
Views: 1578

Sergejs, I need limit a total of networks to 2 Mb bidirectional, not per user, it's a housing customer with 4 networks and a couple of servers.
My configuration is correct or I must to set up another parameter ? (like "total-limit-at").

Thanks !
by fpascual
Tue Sep 12, 2006 3:33 pm
Forum: General
Topic: Simple Queued
Replies: 4
Views: 1578

Simple Queued

Hi, I must apply a limit to simetric 2 Mb to an specific customer. Supposed that the subnets are 192.168.1.0/27 and 192.168.10.0/24, is that correct ??? name="limit-2mb" target-addresses=192.168.1.0/27,192.168.10.0/24 dst-address=0.0.0.0/0 interface=all parent=none direction=both priority=...
by fpascual
Mon Sep 11, 2006 9:59 pm
Forum: General
Topic: BGP Log
Replies: 2
Views: 1363

Changeip, the bgp peer is active ... Into Remote Peer: #sh ip bgp sum Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd Mk_IP 4 #### 187515 235740 888338 0 0 4w5d 24 This is a Cisco Router and debugging don't have any log about BGP errors or not connections.
by fpascual
Mon Sep 11, 2006 4:25 pm
Forum: General
Topic: BGP Log
Replies: 2
Views: 1363

BGP Log

What's mean this log ?:

10:11:09 route,bgp,info Failed to open TCP connection: Operation now in progress
10:11:09 route,bgp,info RemoteAddr=PEER_ADDRESS
10:11:09 route,bgp,info RemotePort=179


Thanks .-
by fpascual
Mon Sep 04, 2006 5:08 pm
Forum: General
Topic: IpSec Debug
Replies: 0
Views: 1057

IpSec Debug

How can I debug IpSec packet with an output like "debug crypto ipsec" on Cisco IOS ?

Thanks a lot
by fpascual
Fri Aug 18, 2006 9:37 pm
Forum: Scripting
Topic: Dynamic IP Change
Replies: 2
Views: 1360

Changeip, thanks for your reply, I can't understand how must apply the mailing option ..., sorry.
by fpascual
Thu Aug 17, 2006 6:23 pm
Forum: Scripting
Topic: Dynamic IP Change
Replies: 2
Views: 1360

Dynamic IP Change

Hi, I need to do an script to e-mail me if a dynamic ip address change by provider, how can I do that ?, I have a lot of costumers with dynamic ip addresses.


Thanks
by fpascual
Wed Aug 09, 2006 7:04 pm
Forum: General
Topic: Traffic Shapping 2.9.17
Replies: 5
Views: 1973

Thanks sergejs, and how can I verify if it is limiting ?
by fpascual
Tue Aug 08, 2006 9:51 pm
Forum: General
Topic: Traffic Shapping 2.9.17
Replies: 5
Views: 1973

Yes, I put in /queue simple name="limit-client-2mb" target-addresses=x.x.x.x/24,x.x.x.x/24,x.x.x.x/30 dst-address=0.0.0.0/0 interface=red_acceso parent=none direction=both priority=8 queue=default-small/default-small limit-at=0/0 max-limit=2097152/2097152 total-queue=default-small That is ...
by fpascual
Tue Aug 08, 2006 6:13 pm
Forum: General
Topic: Traffic Shapping 2.9.17
Replies: 5
Views: 1973

Traffic Shapping 2.9.17

I read the "Bandwidth Control" documentation but can't understand what I must use and how.
I have a housing client with 2 /24 networks and want to limit in 2mb/2mb (upstream and dowstream), how can I do ??

Thanks a lot.
by fpascual
Wed Aug 02, 2006 4:49 pm
Forum: General
Topic: Traffic Shapping 2.9.17
Replies: 1
Views: 1082

Traffic Shapping 2.9.17

We have a Routeros 2.9.17 version like border router in our network.
How can I limit the traffic (2mb DW / 2mb US) for two datacenter subnets ???.

Thanks a lot.
by fpascual
Mon Jul 31, 2006 4:41 pm
Forum: Scripting
Topic: Eliminate "Mail" From Script
Replies: 0
Views: 974

Eliminate "Mail" From Script

Hi, I have a Script that send e-mail notification if a host chage the state, how can I modify this script for avoiding sending mail ??


Thanks
by fpascual
Thu Jul 13, 2006 2:19 pm
Forum: General
Topic: Mac Address Filter
Replies: 9
Views: 2356

Bill, thanks, have you got an example of this ?
by fpascual
Wed Jul 12, 2006 3:06 pm
Forum: General
Topic: Mac Address Filter
Replies: 9
Views: 2356

Another question, if I want to set more than one mac address in firewall filter, may I do that ?, eg:

add in-interface=inside src-mac-address=00-08-AA-50-BD-33,00-08-AA-50-BD-35, dst-address=0.0.0.0 dst-port=80 protocol=tcp action=drop comment="" disabled=no



Thanks
by fpascual
Tue Jul 11, 2006 10:14 pm
Forum: General
Topic: Mac Address Filter
Replies: 9
Views: 2356

In this case I have a wireless lan with encore access point and need to put mk between adsl modem and this encore. In the mac address filter into the mk, I must put the wireless mac address no ?

Thanks
by fpascual
Tue Jul 11, 2006 3:05 pm
Forum: General
Topic: Mac Address Filter
Replies: 9
Views: 2356

Ok, understand, do you recommend me to apply firewall filters and not firewall mangle ?.
by fpascual
Tue Jul 11, 2006 2:47 pm
Forum: General
Topic: Mac Address Filter
Replies: 9
Views: 2356

Mac Address Filter

Hi, I need to block internet access to some computers on a customer network, can I do that with /ip firewall mangle feature ?, how ?, they must check e-mails but not access the www and chat, etc.


Thanks a lot
by fpascual
Thu Jul 06, 2006 8:49 pm
Forum: General
Topic: VRRP Question
Replies: 3
Views: 1156

ok, I 've got a two mikrotiks, one is in production, the other is empty(system reset), how should I set up the replication ? After setting up replication, I bring up VRRP, Should I connect them between the fast eth ?

Thanks a lot.
by fpascual
Thu Jul 06, 2006 2:21 pm
Forum: General
Topic: /routing filter in 2.9.26
Replies: 2
Views: 968

Yes, that's right, I don't have this package installed.

Thanks a lot !
by fpascual
Wed Jul 05, 2006 9:05 pm
Forum: General
Topic: VRRP Question
Replies: 3
Views: 1156

VRRP Question

Hi, I have one mk in production and need to spare another one to have a backup, can I use VRRP to do that ?.


Thanks
by fpascual
Wed Jul 05, 2006 5:33 pm
Forum: General
Topic: /routing filter in 2.9.26
Replies: 2
Views: 968

/routing filter in 2.9.26

Hi, where is the equivalent path /routing filter 2.9.1x version in the new 2.9.26 ?.


Thanks
by fpascual
Tue Jul 04, 2006 4:37 pm
Forum: General
Topic: MK Spare
Replies: 0
Views: 648

MK Spare

Hi, I need to do a spare between 2 Mikrotik and when restore the master config with equal interface ethernet names the firewall filters and other configuration parts show me the interfaces like "unknown".
Sorry for my english.

Regards,

Fernando
by fpascual
Tue Jun 13, 2006 8:21 pm
Forum: General
Topic: Problems With Hotmail Access
Replies: 1
Views: 1039

Problems With Hotmail Access

I have a customer with a mikrotik behind an ADSL connection, this is the problem: The hotmail page open ok, but when put a user/pass data redirect to https:/login.live.com and the page doesn´t open (white screen, like time out). I probe connected a laptop directly to the adsl and work OK. The mikrot...
by fpascual
Mon May 29, 2006 4:33 pm
Forum: General
Topic: VPN not Connect
Replies: 2
Views: 1276

Thanks for your reply, the remote is a "Cisco 1811" router with "Cisco IOS Software, C181X Software (C181X-ADVIPSERVICESK9-M), Version 12.4(2)T". The Mikrotik Policy: src-address="IP":any dst-address="IP"/24:any protocol=all action=encrypt level=require ipsec-...
by fpascual
Mon May 29, 2006 3:30 pm
Forum: General
Topic: VPN not Connect
Replies: 2
Views: 1276

VPN not Connect

Hi, I have a tunnel betwen Mikrotik and Cisco Router, when try to connect the Mikrotik log show me this message:

"dequeuing SA request to IP_ADDRESS , phase 1 wait timed out"


Someone can help me please ?



Thanks a lot.

Fernando