Community discussions

MikroTik App

Search found 45 matches

by Peque
Mon Oct 04, 2021 7:02 pm
Forum: General
Topic: Block between hosts/VLAN
Replies: 2
Views: 657

Block between hosts/VLAN

Hi Mikrotik FOrum I have an issue that I would like your best bid on the little problem I Have an DMZ zone that are only on 1 port - and the port is connected to A single NIC - that i have on my VMware server - the subnet is a /27 In this Setup here - is there any how possible to create a rule that ...
by Peque
Wed May 12, 2021 6:35 pm
Forum: Forwarding Protocols
Topic: 3 public IP's how to create the rules
Replies: 2
Views: 2734

3 public IP's how to create the rules

Hi Forum I have an question regarding having 3 different public's IP - with different portforward pr ip I should have port 80/443 open on each public IP towards 3 differnet subnets. + the ISP have added 2 Extra IP's But the normal portforward from before adding the extra IP's are still working - But...
by Peque
Sat Aug 04, 2018 11:14 am
Forum: Beginner Basics
Topic: Mikrotik IDS IPS Solution
Replies: 0
Views: 2913

Mikrotik IDS IPS Solution

Hi Forum. I want to expand my Mikrotik Setup with more security - and thinking about IDS / IPS Which one should I use or perhaps Both ? BUT as far as I can see is the IPS solution required to be implemented between Internet Providers Modem and my Mikrotik. ( Is this required 2 netcards? ) My Setup i...
by Peque
Wed Nov 15, 2017 12:59 pm
Forum: Beginner Basics
Topic: VPN users
Replies: 2
Views: 757

VPN users

Hi Forum. I've created on my Mikrotik an OpenVPN tunnel How can I the easiest way block all access from VPN session - unless its to this IP 192.168.10.10 Is this easiest through Filter Rules or firewall rules ? and which is the right waty to do this. All access - al ports is OK towards 192.168.10.10...
by Peque
Wed Sep 06, 2017 11:14 am
Forum: Beginner Basics
Topic: VPN Troubles Regarding Which type VPN
Replies: 1
Views: 770

VPN Troubles Regarding Which type VPN

Hi Forum. I have my mikrotik - which I'll like to get working as VPN server for several clients. Round the world we have several networks behind a Westermo Layer3 Switch Lynx model - Those Westermo should be the initializing part in the VPN They don't have internet the whole time - therefor they sho...
by Peque
Tue May 16, 2017 12:54 pm
Forum: General
Topic: VPN question
Replies: 0
Views: 781

VPN question

Hey Forum. I have some questions regarding VPN setup I have a Mikrotik CC1009 which act as VPN server for OpenVPN. This setup is made after this guide: https://rbgeek.wordpress.com/2014/09/10/openvpn-server-setup-on-mikrotik-routeros/ Which works perfect with Road warrior clients. BUT I havew some P...
by Peque
Sat May 06, 2017 12:25 pm
Forum: General
Topic: Question Regarding OpenVPN
Replies: 0
Views: 494

Question Regarding OpenVPN

Hi Forum. I have a CCR-1009 which I want to use as VPN server for OpenVPN. I've used this guide for setup https://rbgeek.wordpress.com/2014/09/10/openvpn-server-setup-on-mikrotik-routeros/ - which is actually working. BUT I have 6 persons who needs this VPN. but having some troubles regarding intern...
by Peque
Tue Nov 22, 2016 7:41 pm
Forum: General
Topic: Mikrotik CCr1009 Crashed totally
Replies: 2
Views: 1205

Mikrotik CCr1009 Crashed totally

Hi Guys. After pressing the download and install the latest software on my CCR1009 it crashed totally. As I can see I cannot get in touch with it at all anymore. I can connect through Serial Port ( Cannot reset it with reset button (Not Working :-( ) I'm getting this message RouterBOOT booter 3.33 C...
by Peque
Tue Sep 27, 2016 7:23 am
Forum: General
Topic: Static DNS problem
Replies: 1
Views: 853

Static DNS problem

Hey Forum. After beeing hosted by a Citrix for a while - we going back to in house hosting., I have a Mikrotik Router but having a problem with a static DNS I must resolve this name : SIL-INS-SERV01 The full name is SIL-INS-SERV01.INSATECH.local - How do I add this as a static entry - since my new n...
by Peque
Mon Sep 19, 2016 9:05 am
Forum: General
Topic: Configuration with a /28 WAN IP
Replies: 1
Views: 749

Configuration with a /28 WAN IP

Hi Forum. I've got A mikrotik CCR1009 - which is setup as Router in the Company. I'm a little in doubt here why this little problem come from and whats the Carse My Public IP is 78.111.168.194/28 ISP Gateway 78.111.168.193 --> Network 78.111.168.192 --------------------------------------------------...
by Peque
Wed Sep 14, 2016 6:28 pm
Forum: General
Topic: DNS troubles in Mikrotik
Replies: 7
Views: 18750

Re: DNS troubles in Mikrotik

Welll - using traceroute from tool gives a empty answer - ,But am online on the router from outsite - the only thing is the network is really slow on this line. And my guess is regarding this DNS problem. But haven't seen that message before regarding this issue: > ping google.com invalid value for ...
by Peque
Wed Sep 14, 2016 5:09 pm
Forum: General
Topic: DNS troubles in Mikrotik
Replies: 7
Views: 18750

Re: DNS troubles in Mikrotik

Hi Guys. Thanks for a quick Reply In my routes I have these: # DST-ADDRESS PREF-SRC GATEWAY DISTANCE 0 ADS 0.0.0.0/0 188.178.222.21 0 1 ADC 188.178.222.20/30 188.178.222.22 WAN 0 2 A S 192.168.201.0/24 192.168.202.1 WAN 1 3 ADC 192.168.202.0/24 192.168.202.1 LAN-bridge 0 Which Should be the right se...
by Peque
Wed Sep 14, 2016 3:28 pm
Forum: General
Topic: DNS troubles in Mikrotik
Replies: 7
Views: 18750

DNS troubles in Mikrotik

Hi Guys. I have a Mikrotik Hex - which I'm using at a little shop. Unfortunably there's a error somewhere I cannot find where it is. When trying to ping directly for Mikrotik Winbox Terminal - I'm getting this: > ping google.com invalid value for argument address: invalid value of mac-address, mac a...
by Peque
Fri Sep 02, 2016 12:03 pm
Forum: General
Topic: SOLVED Arp-request rejected on Mikrotik
Replies: 0
Views: 937

SOLVED Arp-request rejected on Mikrotik

i Forum I've just got a new Line from ISP with a /29 IP Range I can only get traffic through on my main IP 5.103.38.98 - -> not on X.99 X.100 etc The ISP says that the arp-request beeing rejected - How do I fix this so I can use alle IP addresses and forward the designated traffic to this different ...
by Peque
Fri Jul 29, 2016 7:57 am
Forum: General
Topic: FILTER/NAT RULES FOR IPSEC VPN
Replies: 16
Views: 7598

Re: FILTER/NAT RULES FOR IPSEC VPN

My Mistake regarding 192.168.203.0/24

And yes all src NAt are created 
by Peque
Thu Jul 28, 2016 10:00 pm
Forum: General
Topic: FILTER/NAT RULES FOR IPSEC VPN
Replies: 16
Views: 7598

Re: FILTER/NAT RULES FOR IPSEC VPN

Heres My Settings:  Headquarter Router  Filter: > ip firewall filter print  Flags: X - disabled, I - invalid, D - dynamic   0    ;;; Allow FRB access to LAN       chain=forward action=accept src-address=192.168.202.0/24 dst-address=192.168.201.0/24 log=no log-prefix="" NAT: > ip firewall n...
by Peque
Wed Jul 27, 2016 7:11 pm
Forum: General
Topic: FILTER/NAT RULES FOR IPSEC VPN
Replies: 16
Views: 7598

Re: FILTER/NAT RULES FOR IPSEC VPN

My Peers are created like this:  ip ipsec peer print Flags: X - disabled, D - dynamic   0    address=93.161.X.X/32 local-address=:: passive=no port=500        auth-method=pre-shared-key secret="*******" generate-policy=no        policy-template-group=default exchange-mode=main send-initial...
by Peque
Wed Jul 27, 2016 10:43 am
Forum: General
Topic: FILTER/NAT RULES FOR IPSEC VPN
Replies: 2
Views: 777

Re: FILTER/NAT RULES FOR IPSEC VPN

I know my subnets are overlapping.  I've allso tried with the same  none overlapping networks.  The single subnet arent overlapping :  HQ : 192.168.201.0/24 BO1 192.168.202.0/24 BO2 192.168.203.0/24 I've tried both using 192.168.200.0/21 as the main subnet - but allso only with the /24 network  HQ: ...
by Peque
Wed Jul 27, 2016 10:05 am
Forum: General
Topic: FILTER/NAT RULES FOR IPSEC VPN
Replies: 2
Views: 777

FILTER/NAT RULES FOR IPSEC VPN

Hi Forum  I've setting up a system - and can not get the rules for accessing the different network  Headquarter: 192.168.201.0/24 BO1: 192.168.202.0/24 BO2: 192.168.203.0/24 Actually I'm getting the VPN up and running with the IPSEC - following this guide  Ipsec Guide And the VPN are created and tal...
by Peque
Wed Jul 27, 2016 10:00 am
Forum: General
Topic: FILTER/NAT RULES FOR IPSEC VPN
Replies: 16
Views: 7598

FILTER/NAT RULES FOR IPSEC VPN

Hi Forum  I've setting up a system - and can not get the rules for accessing the different network  Headquarter: 192.168.201.0/24 BO1: 192.168.202.0/24 BO2: 192.168.203.0/24 Actually I'm getting the VPN up and running with the IPSEC - following this guide  Ipsec Guide And the VPN are created and tal...
by Peque
Tue Jul 26, 2016 11:42 am
Forum: General
Topic: Creating a VPN - Whats Missing ??? Misssing Lan2Lan connection
Replies: 3
Views: 1057

Re: Creating a VPN - Whats Missing ???

So far so Good.  I've now got the installed SA up and running allso - but still no way to ping from One Lan to Another LAN Was using this guide: http://gregsowell.com/?p=787&cpage=1 Rules on Router 1: 192.168.201.0/24 Filter Rules:  0  D ;;; special dummy rule to show fasttrack counters       ch...
by Peque
Tue Jul 26, 2016 8:53 am
Forum: General
Topic: Creating a VPN - Whats Missing ??? Misssing Lan2Lan connection
Replies: 3
Views: 1057

Re: Creating a VPN - Whats Missing ???

Sorry for a late answer - had a emergency travel to England !  Under IP-sec - Installed SA - No SA installed here. So that Could be the problem - How to fix this ? How do I install these SA since they are not shown  Deleted the Dst rules - and only created the FIlter Rule - On HQ  1    chain=forward...
by Peque
Mon Jul 18, 2016 8:23 am
Forum: General
Topic: Creating a VPN - Whats Missing ??? Misssing Lan2Lan connection
Replies: 3
Views: 1057

Creating a VPN - Whats Missing ??? Misssing Lan2Lan connection

Hey Forum Building my first system with Mikrotik Routers - and trying to get the foillowing up and running.  HQ - 192.168.201.0/24 - Public IP 78.111.168.100 BO - 192.168.202.0/24 - Public IP 78.111.168.210 network.png ---------------------------------------------------------------------------------...
by Peque
Fri Jul 15, 2016 11:25 am
Forum: General
Topic: Best VPN solution
Replies: 0
Views: 659

Best VPN solution

Hey Forum I have to make a litle question in here on howto make the best solution using Mikrotik ROuters. In the HQ I've got a Mikrotik CCR0109-8G-1S-1S+PC on 3 location Branch office I have Mikrotik HeX  Tegning5.pdf The HQ Router should be the Preffered Master Hos - where all Offices are connected...
by Peque
Tue Jul 12, 2016 11:05 am
Forum: General
Topic: Mikrotik/roadWarrior VPN
Replies: 3
Views: 2318

Re: Mikrotik/roadWarrior VPN

tried allso with a Normal OpenVPN gui but only getting this : Tue Jul 12 10:02:28 2016 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info. Tue Jul 12 10:02:28 2016 Socket Buffers: R=[65536->65536] S=[64512->64512] Tue Jul 12 10:...
by Peque
Mon Jul 11, 2016 10:03 am
Forum: General
Topic: Mikrotik/roadWarrior VPN
Replies: 3
Views: 2318

Re: Mikrotik/roadWarrior VPN

OK - Then I give that a try.  I've now followed this guide from the wiki:  OpenVPN Created the certificate with easy-rsa  imported ca,crt,router.crt og router.pem into the Miklrotik and created the OVPN server as described here:  Created the VPN pool:  /ip pool add name=ovpn-pool ranges=192.168.60.1...
by Peque
Mon Jul 11, 2016 8:57 am
Forum: General
Topic: Mikrotik/roadWarrior VPN
Replies: 3
Views: 2318

Mikrotik/roadWarrior VPN

Hey Forum.  I would like to get at VPN client able to connect to the Mikroitik Router.  I'm using securepoint SSL as VPN klient on the laptop.  What I would like is:  Getting a VPN that accesses the LAN network behind the Mikrotik.  I've followed this guide:   Create Certificate  for creating Mikrot...
by Peque
Mon Jun 06, 2016 11:41 am
Forum: Beginner Basics
Topic: Portforwarding based on DNS name
Replies: 9
Views: 8087

Re: Portforwarding based on DNS name

OK Thanks for the Reply

So there's no way to make this work properly unless you'll have 2 public IP's .
I was hoping the Firewall was able to filter incomming traffic depending oin the DNS name instead of the IP!
by Peque
Sun Jun 05, 2016 2:28 pm
Forum: Beginner Basics
Topic: Portforwarding based on DNS name
Replies: 9
Views: 8087

Portforwarding based on DNS name

Hello Forum. I've just getting my Internet connection upgraded, but unfortunably there is only 1 public IP available. Therefor I would like to hear if its possible to filtering the incomming traffic using a Domain name insted of a destination IP. I've got some servers at home and would like to filte...
by Peque
Sun Jun 05, 2016 2:22 pm
Forum: Beginner Basics
Topic: TFTP Issues on CCR1009
Replies: 4
Views: 1954

Re: TFTP Issues on CCR1009

Well - Given up now - Cannot make it boot from this tftp Server.
by Peque
Fri Jun 03, 2016 8:28 am
Forum: Beginner Basics
Topic: TFTP Issues on CCR1009
Replies: 4
Views: 1954

Re: TFTP Issues on CCR1009

Should it be set for all files ?
Since there are many files - so is there any way to defina all at one
by Peque
Thu Jun 02, 2016 1:55 pm
Forum: Beginner Basics
Topic: TFTP Issues on CCR1009
Replies: 4
Views: 1954

TFTP Issues on CCR1009

Hi Forum. I have a little problem that I cannot google my self out of. I've created a dir on my Mikrotik called /tftp Inside I've download a Debian Install pxe But when trying to boot - I'm getting this Then Its writing something about a missing file I cannot read! Its a failed to load a file - But ...
by Peque
Thu Apr 21, 2016 11:40 am
Forum: General
Topic: Internal DNS troubles
Replies: 2
Views: 829

Internal DNS troubles

Hi Forum. I've have a little problem which I cannot solve by my self. I've created my own firewall based on a mikrotik CCr1009. I have created the following networks LAN -> 172.16.100.0/23 DMZ -> 192.168.100.0/24 What I'm trying to is Accessing the servers in DMZ using FQDN. --> test.example.com If ...
by Peque
Sun Mar 27, 2016 11:40 am
Forum: Beginner Basics
Topic: Question Regarding DHCP server
Replies: 3
Views: 905

Re: Question Regarding DHCP server

I've found out - that the network ID not MAC adresse - should be correct - you cannot give a new name to that identifier.

# mar/27/2016 10:38:38 by RouterOS 6.34.3
# software id = MU8X-YJR2
#
by Peque
Sat Mar 26, 2016 12:24 pm
Forum: Beginner Basics
Topic: Question Regarding DHCP server
Replies: 3
Views: 905

Question Regarding DHCP server

Hi Forum I've got a CCR1009-8G-1S-1S+PS running, but having a strange experience. I've created 2 DCHP Pools - (LAN/DMZ) but experience the problem - at my "hosts" are not taking the reserved IP address in the LAN pool. I've created 20 host where only 8 are getting the rigth IP - as created...
by Peque
Tue Mar 08, 2016 1:04 pm
Forum: General
Topic: IPsec TUnnel Connecting - but no no traffic through VPN
Replies: 2
Views: 4748

Re: IPsec TUnnel Connecting - but no no traffic through VPN

Thanks for the link Allthough I'm still having some troubles. I can now ping from 192.168.88.0/24 through 192.168.2.0/24 to Lynx internal network Can access a webpage etc - but cannot access remote desktop (RDP) Internal connection error (works fine from lynx LAN) But cannot ping from Lynx network 1...
by Peque
Tue Mar 08, 2016 9:41 am
Forum: General
Topic: IPsec TUnnel Connecting - but no no traffic through VPN
Replies: 2
Views: 4748

IPsec TUnnel Connecting - but no no traffic through VPN

Hi forum I Playing around and trying to make a VPN tunnel From A Mikrotik HeX to a Westermo Lynx. I'm actually able to get the VPN connection successfully - but cannot send or ping through the VPN - so my guess is a missing Route or some firewall rules - and that where I'm needing your help. My setu...
by Peque
Mon Mar 07, 2016 1:54 pm
Forum: Beginner Basics
Topic: Mikrotik VPN server - mobile Router clients
Replies: 3
Views: 1368

Re: Mikrotik VPN server - mobile Router clients

I just made a quick network view. As Correct assumed - the Mobile Router Is natted behind a Celluar network - thats allso why the mobile router should be the initiating part The Network drawing is attached! The Meaning is getting the Mikrotik as the VPN server - And getting LAN-to-LAN access. As far...
by Peque
Mon Mar 07, 2016 12:32 pm
Forum: Beginner Basics
Topic: Mikrotik VPN server - mobile Router clients
Replies: 3
Views: 1368

Mikrotik VPN server - mobile Router clients

Tegning1.pdf Hello. I'm trying to setup an Mikrotik CCr1009 as VPN server. The main problem here is the clients which should connect to Mikrotik - is som mobile Routers ( NATted IP) Which and how would be the best way to make this Happens The Mikrotik Is on a static IP - and should be a VPN-server ...
by Peque
Wed Jan 20, 2016 11:12 am
Forum: Beginner Basics
Topic: Mikrotik HEX and OpenVPN
Replies: 2
Views: 2927

Mikrotik HEX and OpenVPN

Hi Forum Just playing around with the new Mikrotik HEX Router. Trying to establish a OpenVPN connection to this following the guide from here http://wiki.mikrotik.com/wiki/OpenVPN Selfcreated Certificates from easy-rsa Uploaded the Certificate to Router and to Client - And when trying to establish a...
by Peque
Sat Jan 16, 2016 11:33 am
Forum: Beginner Basics
Topic: Firewall Questions regarding DMZ zone / LAN
Replies: 2
Views: 1413

Re: Firewall Questions regarding DMZ zone / LAN

Thanks Zerobyte. That explained it for me, allthough I managed to block With dropping all new connections from Sourceaddress 172.16.10.0/24 to Out interface LAN. Allthough I should have any rules accessing thay should be placed before this rules. But your example did the explaination fine - Thanks
by Peque
Fri Jan 15, 2016 8:25 pm
Forum: Beginner Basics
Topic: Firewall Questions regarding DMZ zone / LAN
Replies: 2
Views: 1413

Firewall Questions regarding DMZ zone / LAN

Hello. I've have my little network like this setup on a CCR1009-8G-1S-1S+ LAN 172.16.0.0/24 - bridged on ether1,2,3,4 + SPF+ DMZ 172.16.10.0/24 - created on Ether7 WAN static IP - created on Ether8. I would like to allow traffic from LAN to DMZ but noit from DMZ to LAN. As it is now without any rule...
by Peque
Tue Oct 27, 2015 10:35 am
Forum: Beginner Basics
Topic: How to get 5 VLAN working
Replies: 5
Views: 1465

Re: How to get 5 VLAN working

I've done that now - and just to be sure for now. Ive created 5 bridge-vlanXX and attached the interfaces sfp+ & ether2-7 on each bridge. Afterwards I've created DHCP server for each VLAN and attached the DHCP on the bridged VLANS But when connecting a RJ45 Cable to one of these ports with a nor...
by Peque
Tue Oct 27, 2015 8:43 am
Forum: Beginner Basics
Topic: How to get 5 VLAN working
Replies: 5
Views: 1465

Re: How to get 5 VLAN working

Well thanks for the answer. When I'm trying to attach the DHCP server to the interface - it can not be connected to it self - so not sure how to do that Correctly. I can make it work on DMZ interface ( But this is only 1 port/Interface ) But would really have using the sfp+ for 10GB connection betwe...
by Peque
Mon Oct 26, 2015 9:53 am
Forum: Beginner Basics
Topic: How to get 5 VLAN working
Replies: 5
Views: 1465

How to get 5 VLAN working

Hi forum. I'm trying to make this mikriotiuk Router to our new network. But needing 5 VLAN for making it all work - and have tried to follow some guide . Men now I'm stuck and hoping you can help me further. I've bought the CCR1009-8G-1s-1s+ ether1 is the WAN access and ether8 is my DMZ zone The res...