Community discussions

MikroTik App

Search found 38 matches

by tholderbaum
Wed May 24, 2023 3:48 pm
Forum: General
Topic: IPV6 DHCP client does not add correct default route after reboot
Replies: 25
Views: 3336

Re: IPV6 DHCP client does not add correct default route after reboot

The Mikrotik default config is essentially not to accept RAs, you have to explicitly enable them with: /ipv6 settings set accept-router-advertisements=yes If you do that make sure to configure the firewall to discard RAs from unwanted interfaces and/or nodes. I am not sure that is entirely true. In...
by tholderbaum
Thu Jan 20, 2022 6:50 pm
Forum: General
Topic: Letsencrypt requires an open Webfig HTTP port 80
Replies: 10
Views: 8650

Re: Letsencrypt requires an open Webfig HTTP port 80

2022-01-20_18-44-27.png So I played with this further on my test rig. Basically the issue was you had to have both the port 80 traffic allowed on the input chain AND the web fig enabled under IP Services. the requirement appears to be both. I tried it 4 different ways: Port 80 open and Webfig enabl...
by tholderbaum
Thu Jan 20, 2022 5:03 pm
Forum: General
Topic: Letsencrypt requires an open Webfig HTTP port 80
Replies: 10
Views: 8650

Letsencrypt requires an open Webfig HTTP port 80

I really appreciate the inclusion of LetsEncrypt certificates. I have been playing with them, but I have run into a significant problem. It appears that to obtain or renew a certificate, the process requires an open port 80. Not just that, but specifically you have to enable Webfig on port 80. Which...
by tholderbaum
Wed Dec 02, 2020 6:36 pm
Forum: General
Topic: Unusual Problem
Replies: 0
Views: 394

Unusual Problem

I have a Mikrotik CCR 1036. I am running non default ports for winbox. I am running 6.46.8 Long term This morning, I attempted to login, and found that no password I have was valid. We then tried the default password of admin with no password, and got in. The issue is that the router is completely o...
by tholderbaum
Wed Mar 11, 2020 6:07 pm
Forum: General
Topic: Routing 4 lans and 4 wans [SOLVED]
Replies: 22
Views: 9900

Re: Routing 4 lans and 4 wans [SOLVED]

It looks like you have the routing marks setup, but you don't define what to do with them Routing marks should lead to a separate route table for each WAN. Essentially, you need a default route on each route table for each WAN interface.
by tholderbaum
Fri Jun 01, 2018 5:57 pm
Forum: General
Topic: I can't set a DNS name that starts with a digit.
Replies: 3
Views: 3224

Re: I can't set a DNS name that starts with a digit.

I can confirm this behavior. RFC 1178 recommends not using DNS Host names that start with numbers. https://tools.ietf.org/html/rfc1178 here is the relevant section: Don't use digits at the beginning of the name. Many programs accept a numerical internet address as well as a name. Unfortunately, some...
by tholderbaum
Mon May 21, 2018 9:14 pm
Forum: General
Topic: why mikroitk Donot Cross File sharing traffic
Replies: 7
Views: 3060

Re: why mikroitk Donot Cross File sharing traffic

It is difficult to understand what you are trying to accomplish. I assume you are trying to open TCP/445 from the outside through the firewall. If so then it is a 2 step process: Step one, you need to define the dstnat rule: /ip firewall nat add action=dst-nat chain=dstnat dst-address=publicIP dst-p...
by tholderbaum
Wed Mar 07, 2018 8:51 pm
Forum: Beginner Basics
Topic: L2TP and IPSEC just not working IPSec Error
Replies: 7
Views: 4611

Re: L2TP and IPSEC just not working IPSec Error

Can you please post your config? Can you verify that you have UDP/1701,500 and 4500 open on the input chain? Also are you accepting IPSEC-AH,ESP and GRE packets?
by tholderbaum
Wed Mar 07, 2018 8:46 pm
Forum: Beginner Basics
Topic: VLAN and Bridge
Replies: 1
Views: 775

Re: VLAN and Bridge

Hi everyone, i have this scennario: RB750Gr3 (inntended to be a load balancer) - eth1 to RB3011 RB3011 (inntended to be a pppoe srvr): - eth1 to RB750 - eth10 to OmniTIK Omnitik - eth1 to RB3011 - eth2 to NanoBeam AP (1) - eth3 to NanoBeam AP (2) RB750 - eth1 to NanoBeam Station (1) - eth5 to ADSL ...
by tholderbaum
Wed Mar 07, 2018 8:41 pm
Forum: Beginner Basics
Topic: Mikrotik L2TP VPN works but can not reach LAN IPs
Replies: 3
Views: 2367

Re: Mikrotik L2TP VPN works but can not reach LAN IPs

Did you allow traffic between the different subnets?

For example:

If my lan is 10.1.1.0/24

and my VPN users are on 10.1.2.0/24

I have to allow traffic between the two subnets.

If that doesn't work, can you post your config?
by tholderbaum
Wed Mar 07, 2018 8:35 pm
Forum: Beginner Basics
Topic: Difference between /interface bridge filter and /ip filter?
Replies: 4
Views: 8176

Re: Difference between /interface bridge filter and /ip filter?

For starters, you need to understand that from a networking perspective. Bridges work just like a switch. When you create a bridge, and add to interfaces together, you are saying that those interfaces are link together as if they were plugged into a same switch. This commonly referred too as a layer...
by tholderbaum
Fri Feb 02, 2018 10:11 pm
Forum: Beginner Basics
Topic: Working L2TP iPsec VPN but no Ping to computer?
Replies: 8
Views: 8067

Re: Working L2TP iPsec VPN but no Ping to computer?

try to locate rule 10 on the 2th place, then try to ping from your vpn. the firewall is work like instruction sets, one by one and the first match is the one that catches. Nope still nothing. you mean /ip route print? I was thinking to add to NAT chain=srcnat action=accept src-address=192.168.100.0...
by tholderbaum
Fri Feb 02, 2018 10:03 pm
Forum: Beginner Basics
Topic: Quick config guide for new member of Mikrotik ?
Replies: 4
Views: 1432

Re: Quick config guide for new member of Mikrotik ?

Hi. Is some general guide available for new Mikrotik users how to setup new instance in common enviroment like small office ? Simple specification: - what to buy to have good background for 100 devices office ? (50 PCs, 40 mobile phones, 5 printers, some guests coming in and out frequently) with re...
by tholderbaum
Wed Jan 31, 2018 11:51 pm
Forum: General
Topic: Security & VLAN
Replies: 3
Views: 2007

Re: Security & VLAN

Hi all, I have multiple devices on my LAN and I am segregating them for security purposes into 3 groups using 3 VLANs (2 tagged, one untagged). All the devices are connected to a managed VLAN aware switch. Now, I want to connect those devices to the Internet via a MTK router (I'm currently playing ...
by tholderbaum
Wed Jan 31, 2018 11:42 pm
Forum: General
Topic: Remote setup
Replies: 3
Views: 1143

Re: Remote setup

Hi Guys, Does anyone have a method to remotely configure a new, out the box unit directly. The device will be connected to a lan, not wan directly. I can think of using TeamViewer etc to get to a PC and do basic config, then remote to device directly. VPN to network and config from there Any other ...
by tholderbaum
Wed Jan 31, 2018 11:37 pm
Forum: General
Topic: Isolate an IP [SOLVED]
Replies: 5
Views: 5277

Re: Isolate an IP [SOLVED]

What is the best way to isolate an IP on wired or wireless network? The goal is for that IP to be able to connect to the outside world/internet but nothing on the LAN Specifically here the most basic way. /ip firewall filter add action=accept chain=forward src-address={YourIP Here} out-interface={Y...
by tholderbaum
Mon Jan 15, 2018 10:08 pm
Forum: General
Topic: Need some advice...
Replies: 5
Views: 1450

Re: Need some advice...

I have tried the RB2011. The most I would do is 2 tunnels. If you are doing the hub and spoke VPN method, then the 2011 would be fine for the spokes. However, The CCR1009-7G blows the absolute doors off the RB2011. There really is no comparison. It can handle your loads without an issue. I run a sli...
by tholderbaum
Mon Jan 15, 2018 9:57 pm
Forum: General
Topic: VLAN Trunking Router / SW / SW [SOLVED]
Replies: 6
Views: 2918

Re: VLAN Trunking Router / SW / SW [SOLVED]

Here is what I do: On the firewall: (Assumes Ether2 is the interface you want to trunk. /interface vlan add interface=ether2 name="vlan1" vlan-id=1 add interface=ether2 name="vlan2" vlan-id=2 add interface=ether2 name="vlan3" vlan-id=3 add interface=ether2 name="vl...
by tholderbaum
Mon Jan 15, 2018 9:38 pm
Forum: General
Topic: IOS VPN into RB3011 behind Verizon NAT
Replies: 9
Views: 1912

Re: IOS VPN into RB3011 behind Verizon NAT

Cmaney is correct. Bridge mode is the way to go here. I just did this for a client. The Guide works by downloading the guide and other information and then sending it over the COAX cable to the boxes. All you have to do is plug the WAN port on the verizon router into an open port on the Mikrotik. Ad...
by tholderbaum
Mon Jan 15, 2018 9:34 pm
Forum: General
Topic: Dual VPN / same provider
Replies: 15
Views: 4188

Re: Dual VPN / same provider

Can you please post the config for the tunnels as well as any IPSec config?
by tholderbaum
Thu Sep 14, 2017 7:27 pm
Forum: General
Topic: Router losing time settings
Replies: 1
Views: 1366

Re: Router losing time settings

I don't know where to post this so I just chose the Genera post. I have a client who is running RB2011UiAS-2HnD. This router is giving problems. It keeps losing clock settings which I setup for time-based firewall filters. Every time I try to log into the router it kicks me out after 2 minutes. I h...
by tholderbaum
Thu Sep 14, 2017 7:11 pm
Forum: General
Topic: Bridge for tagged and untagged traffic
Replies: 4
Views: 2195

Re: Bridge for tagged and untagged traffic

Hello, I did not understan from the manuals if a configuration like this could create logical loops or other problems: /interface bridge add name=bridge1-untagged add name=bridge2-Vlan2 add name=bridge3-Vlan3 /interface vlan add interface=ether1 name=vlan-2a vlan-id=2 add interface=ether2 name=vlan...
by tholderbaum
Thu Sep 14, 2017 7:03 pm
Forum: General
Topic: How to select where the traffic goes out through. Router with several IP's on the same interface
Replies: 6
Views: 2303

Re: How to select where the traffic goes out through. Router with several IP's on the same interface

Hi, We have just migrated our GNU/Linux router to a Mikrotik CCR1009-7G-1C-1S+ . We have mainly a bunch of IP address (public and privat) on the combo1 interface and that's it But now when doing connections from the router to somewhere , they are failing. For example: DNS client on the router has s...
by tholderbaum
Fri Sep 01, 2017 11:46 pm
Forum: General
Topic: Mikrotik Fault Tolerance Solution
Replies: 4
Views: 2366

Re: Mikrotik Fault Tolerance Solution

The issue with MikroTik and HA in general is the lack of any way to sync two routers together. When I saw your thread I was hoping you would post some way of syncing both routers automatically. Especially on a statefull firewall with connection tracking the lack of state sync can cause many issues ...
by tholderbaum
Fri Sep 01, 2017 11:40 pm
Forum: General
Topic: Mikrotik Fault Tolerance Solution
Replies: 4
Views: 2366

Re: Mikrotik Fault Tolerance Solution

I had considered VRRP. The problem being that at the colo datacenter (Peak 10), they clear tier mac address tables every 5 hours, instead of anything more reasonable. The problem being that the having the IP addresses come up with entirely different MAC addresses was not being recognized fast enough...
by tholderbaum
Fri Sep 01, 2017 7:14 pm
Forum: General
Topic: CSS106/RB260GS to be un-managed switch
Replies: 2
Views: 1080

Re: CSS106/RB260GS to be un-managed switch

Can you post a network diagram? Hand drawn is fine. On the face of it, running vlans precludes the use of an unmanaged switch because you have to do at least some form of routing. Your network diagram would help to determine what you need.
by tholderbaum
Fri Sep 01, 2017 7:07 pm
Forum: General
Topic: can I run 2 scripts at the same time?
Replies: 1
Views: 1143

Re: can I run 2 scripts at the same time?

I have called another script from within a script before such as to define variables. But I think in your case, the best practice is to have separate schedules that fire off the separate scripts. it is cleaner and easier to troubleshoot this way.
by tholderbaum
Fri Sep 01, 2017 6:56 pm
Forum: General
Topic: Connecting Multiple Questions
Replies: 2
Views: 1174

Re: Connecting Multiple Questions

Hi Guys, I'm struggling to setup MikroTik to bridge to local network on ether1 port. This is my current setup: There is a network 192.168.222.1 (No DHCP) in the building which is intended for VOIP Phones, if plugged into this switch the phones work normally On the same network the ISP's outside net...
by tholderbaum
Fri Sep 01, 2017 6:47 pm
Forum: General
Topic: Mikrotik Fault Tolerance Solution
Replies: 4
Views: 2366

Mikrotik Fault Tolerance Solution

Everyone, We developed a fault tolerant solution for our main Mikrotik CCR 1036 router. This router is used at the main shared firewall for our entire hosted customer base. Right now, we have 25 subnets and 47 tunnels to our various clients. When this firewall goes down, we needed a method to minimi...
by tholderbaum
Fri May 05, 2017 6:55 pm
Forum: General
Topic: VPN IPSEC
Replies: 6
Views: 1624

Re: VPN IPSEC

I can help you with that. I just need to understand if it is a tunnel between two Mikrotiks or between a mikrotik and something else.
by tholderbaum
Thu May 04, 2017 9:08 pm
Forum: General
Topic: RouterOS Upgrade Question
Replies: 3
Views: 1300

Re: RouterOS Upgrade Question

Thanks.

That is the plan. I have a set of lab routers and non critical routers we will test on. When we approve a version, we will upload it to the update unit, which will update our production units.
by tholderbaum
Thu May 04, 2017 7:23 pm
Forum: General
Topic: Networking Problem
Replies: 4
Views: 1575

Re: Networking Problem

Remember to disable the windows firewall.
by tholderbaum
Thu May 04, 2017 7:21 pm
Forum: General
Topic: VPN IPSEC
Replies: 6
Views: 1624

Re: VPN IPSEC

This code is my standard VPN setup: It is a bit different than yours. Try it out, and see how it works for you. Comment: This proposal works for most devices. /ip ipsec proposal add auth-algorithms=sha256,sha1 enc-algorithms=\ aes-256-cbc,aes-192-cbc,aes-128-cbc,3des name=L2TPVPN_Proposal pfs-group=...
by tholderbaum
Thu May 04, 2017 6:55 pm
Forum: General
Topic: Is it necessary to install CCR on all remote sites?
Replies: 15
Views: 3128

Re: Is it necessary to install CCR on all remote sites?

Assuming you have some sort of tunnel between the two sites, it sounds like the RB2011 is becoming a bottleneck for you. I would switch to a CCR1009, especially the new ones. A CCR1009 will blow the doors off of a 2011 any day of the week. Introducing an RB750 doesn't really help you. If the 2011 is...
by tholderbaum
Thu May 04, 2017 6:46 pm
Forum: General
Topic: RouterOS Upgrade Question
Replies: 3
Views: 1300

RouterOS Upgrade Question

Guys, We manage about 75 Mikrotiks. We have about 15 CCR1009, 55 RB2011s, and the remaining being split among AH1100x2 and rb750 and CRS switches I have to update all of them from time to time, but I also want to thoroughly test the versions before using them. I have a script which can update Router...
by tholderbaum
Fri Sep 26, 2014 11:57 am
Forum: General
Topic: Winbox 3 beta
Replies: 243
Views: 148697

Re: Winbox 3

There is a bug that i cannot stand When using winbox version 3, it will not let me copy and paste anything via either CTRL+V or right-click to paste. I run about 30 mikrotiks all over Florida and each one has at least 2 separate admin accounts, each with 24 character randomly generated password whic...
by tholderbaum
Wed Aug 13, 2014 5:16 pm
Forum: General
Topic: Tunnel Routing Question
Replies: 0
Views: 643

Tunnel Routing Question

Here is my question http://s12.postimg.org/o3eqvd0rh/Mikrotik_Tunnel_Configuration.jpg I have the following network. We run a hosted datacenter. We use a Mikrotik AH1100x2 as our core router. In the datacenter, we have our corp network, (Red), which has a tunnel to our main office, (also in red). Th...
by tholderbaum
Thu Jan 23, 2014 3:37 am
Forum: General
Topic: /tool fetch missing???
Replies: 1
Views: 1087

/tool fetch missing???

I am trying to put script in to upload the router config to a FTP server. I was using the scripts I found elsewhere on this board. However, when I try to do the upload it appears that the fetch tool is missing. I dont have in any of my Mikrotiks. I am running routerOS 6.7. Any idea on how to get it ...