Community discussions

MikroTik App

Search found 123 matches

by atakacs
Mon Mar 20, 2023 10:06 am
Forum: Beginner Basics
Topic: CAPSMAN shows device with MAC adress
Replies: 1
Views: 377

CAPSMAN shows device with MAC adress

Hello I have recently added a new RBMAPL-2ND device into my CAPSMAN setup and for some reason it is recognized but shows up with it's MAC address, not IP. It did get a DHCP IP on the ETH port, I can ping it but can not connect to it using Winbox (or SSH but did not turn it on anyway). What might I h...
by atakacs
Thu Jan 27, 2022 1:08 pm
Forum: Virtualization
Topic: Container on MIPS hardware
Replies: 1
Views: 4741

Container on MIPS hardware

Not sure this is the right place to ask...

Appartently the container 7.x feature is also supported on SMIPS hardware. Assuming I want to build one what processor architecture should I use ? My goal is to try this https://github.com/Fluent-networks/tailscale-mikrotik.

Any feedback most welcome
by atakacs
Mon Jan 24, 2022 6:55 pm
Forum: General
Topic: OVPN site to site routing issue
Replies: 1
Views: 698

OVPN site to site routing issue

I am having a weird (at least to me) issue with a site to site setup using OVPN (Mikrotik to Mikrotik). The tunnel is up and from Site A I can reach the subnet on Site B. However from site B I can not reach the site A subnet. Yet from router B I can reach subnet A, but not from the devices "beh...
by atakacs
Tue Jan 18, 2022 11:28 am
Forum: Beginner Basics
Topic: Internet failover bast practice
Replies: 7
Views: 2376

Re: Internet failover bast practice

Thanks - most instructive for the newbee that I am
by atakacs
Tue Jan 18, 2022 10:50 am
Forum: Beginner Basics
Topic: User/pass not preserved in backup ?
Replies: 8
Views: 4215

Re: User/pass not preserved in backup ?

Oh ok did not realise that backup went up to MAC assignments - it would indeed be problematic.

But if I am going to swap two routers with exact same model I can do a backup -> restore ?
by atakacs
Sun Jan 16, 2022 10:34 pm
Forum: Beginner Basics
Topic: User/pass not preserved in backup ?
Replies: 8
Views: 4215

Re: User/pass not preserved in backup ?

Also, it is not a good practice to return a .backup from one router to another.
Even to same hardware that is mean to replace the original ?
by atakacs
Sun Jan 16, 2022 10:33 pm
Forum: Beginner Basics
Topic: Internet failover bast practice
Replies: 7
Views: 2376

Re: Internet failover bast practice

The second scenario
by atakacs
Sun Jan 16, 2022 6:40 pm
Forum: Beginner Basics
Topic: Internet failover bast practice
Replies: 7
Views: 2376

Internet failover bast practice

I have two ISP delivering internet to my site and and have their respective links connected to ETH1 and ETH2 of my router.

What is the "best" way to have automatic switchover between the two WAN (say based on a ping of a "known good host") ?
by atakacs
Sun Jan 16, 2022 6:37 pm
Forum: Beginner Basics
Topic: User/pass not preserved in backup ?
Replies: 8
Views: 4215

User/pass not preserved in backup ?

Probably a dumb question but are user/pass preserved in backups ? I have a brand new CCR1009-7G on which i have restored a (password protected) backup from another CCR and although it seems to have the config loaded I can't connect to is with the same credentials that are working on the original rou...
by atakacs
Thu Jan 13, 2022 6:22 pm
Forum: General
Topic: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working
Replies: 45
Views: 25478

Re: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working

Was there any resolution to that ? Still pretty much seeing the same problem :/
by atakacs
Thu Jan 13, 2022 6:19 pm
Forum: RouterOS beta
Topic: 7.2rc2 pulled ?
Replies: 5
Views: 2752

Re: 7.2rc2 pulled ?

ok - sorry for the "noise"
by atakacs
Thu Jan 13, 2022 10:25 am
Forum: RouterOS beta
Topic: 7.2rc2 pulled ?
Replies: 5
Views: 2752

7.2rc2 pulled ?

I'm pretty sure I have seen a 7.2rc2 yesterday in the testing "train" and was about to install in on our lab setup... but no seeing it anymore !? Was it pulled ?
by atakacs
Tue Dec 21, 2021 7:32 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 442
Views: 232428

Re: v7.1.1 is released!

Any update / input / remark / comment on the IPSec issues lots of people are having ?
by atakacs
Tue Dec 21, 2021 8:09 am
Forum: General
Topic: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working
Replies: 45
Views: 25478

Re: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working

Some "official" response would indeed be appreciated...
by atakacs
Tue Dec 21, 2021 8:08 am
Forum: General
Topic: Site to Site IPsec failing - worse with 7.1
Replies: 2
Views: 1074

Re: Site to Site IPsec failing - worse with 7.1

Thanks for the pointer - my issue is a bit different insofar as the tunnel is actually working for a while but eventually stops. I even have witnessed article failure, ie. some subnets continue to work when others stop. Not good :/
by atakacs
Mon Dec 20, 2021 1:43 pm
Forum: General
Topic: Site to Site IPsec failing - worse with 7.1
Replies: 2
Views: 1074

Site to Site IPsec failing - worse with 7.1

I am having a worsening issue by which an IPsec tunnel I have between our local CCR-1009-8G and an Ubiquiti USG Pro is randomly - but regularly - silently failing. By silently failing I mean that the traffic simply stops flowing - the peer seems still up, there is nothing apparent (maybe I need more...
by atakacs
Thu Dec 02, 2021 8:22 am
Forum: General
Topic: Confused about DHCP server
Replies: 15
Views: 2558

Re: Confused about DHCP server

I dont think its possible or wise to attach your VPN connections to bridges. Simply make the firewall rules you need to allow connectivity from VPN access to LAN subnets and vice versa etc...... (...) Seems like you have many tunnels. So use firewall rules for VPN tunnel to LAN connectivity So use ...
by atakacs
Thu Dec 02, 2021 8:14 am
Forum: Beginner Basics
Topic: How would you go about this - 2 separate nets 1 router
Replies: 3
Views: 1074

Re: How would you go about this - 2 separate nets 1 router

Very feasible, the only question I have is why are the two VLANS 'open' to each other.
Ok... what woud be your approach to this ?
Why not just have one LAN then?
Fair question question - we want to be able to filter between the two or even to split (obviously loosing the redudency)
by atakacs
Wed Dec 01, 2021 6:00 pm
Forum: Beginner Basics
Topic: How would you go about this - 2 separate nets 1 router
Replies: 3
Views: 1074

How would you go about this - 2 separate nets 1 router

Hello I have a CCR 1009-8G on which I want to achieve the following config. 2 WAN connections - WAN1 to ETH1, WAN2 to ETH8 2 LAN connections - say LAN1 to ETH2 and LAN2 to ETH7 Each LAN independent (with NAT and unroutable address space - say 192.168.100.0/24 and 192.168.200.0/24) - LAN1 access inte...
by atakacs
Wed Dec 01, 2021 8:24 am
Forum: General
Topic: Confused about DHCP server
Replies: 15
Views: 2558

Re: Confused about DHCP server

Hello Many thanks for taking the time to review my config ! I am still obviously learning Mikrotik and any and all input is much appreciated ! (1) Your are missing one thing....... Maybe? /interface list member add interface=ether1 list=WAN add interface=bridgeNet1 list=LAN add interface=bridgeNet2 ...
by atakacs
Tue Nov 30, 2021 12:23 pm
Forum: General
Topic: Confused about DHCP server
Replies: 15
Views: 2558

Re: Confused about DHCP server

VLANs would be another option, with everything on the same bridge but VLAN'ed off from each other.
Yep - good idea.

Still not completely sure this isn't some bug (or at minimum an "edge case")
by atakacs
Tue Nov 30, 2021 11:48 am
Forum: General
Topic: Confused about DHCP server
Replies: 15
Views: 2558

Re: Confused about DHCP server

Found my issue
add name=dhcp-Net2 ranges=192.168.0.101-192.198.0.199
Typo here :((

That being said not sure the DHCP server should serve from another unrelated pool ...
by atakacs
Tue Nov 30, 2021 10:32 am
Forum: General
Topic: Confused about DHCP server
Replies: 15
Views: 2558

Re: Confused about DHCP server

Here we go - pretty basic IMHO # nov/30/2021 09:21:18 by RouterOS 7.1rc7 # software id = 018C-7TFP # # model = CCR1009-8G-1S-1S+ # serial number = **** /interface bridge add name=bridgeNet2 add name=bridgeNet1 /interface ethernet set [ find default-name=ether1 ] comment=WAN1 set [ find default-name=...
by atakacs
Tue Nov 30, 2021 9:58 am
Forum: General
Topic: Confused about DHCP server
Replies: 15
Views: 2558

Confused about DHCP server

Hello I'm seeing something unexpected with my DHCP server. I have two servers defined, bound to two different networks and adapters: [mktadmin@mkt-sx-00] /ip/dhcp-server> print Columns: NAME, INTERFACE, ADDRESS-POOL, LEASE-TIME # NAME INTERFACE ADDRESS-POOL LEASE-TIME 0 dhcp-Net1 bridgeNet1 dhcp-Net...
by atakacs
Sat Nov 27, 2021 11:20 am
Forum: RouterOS beta
Topic: v7.1rc7 [development] is released!
Replies: 174
Views: 57202

Re: v7.1rc7 [development] is released!

Do you see anything that should not me here ? [xxx@mkt-sx-00] /system package> print Flags: X - disabled # NAME VERSION SCHEDULED 0 routeros-tile 6.49.1 1 system 6.49.1 2 ipv6 6.49.1 3 wireless 6.49.1 4 hotspot 6.49.1 5 mpls 6.49.1 6 routing 6.49.1 7 ppp 6.49.1 8 dhcp 6.49.1 9 security 6.49.1 10 adv...
by atakacs
Sat Nov 27, 2021 12:51 am
Forum: RouterOS beta
Topic: v7.1rc7 [development] is released!
Replies: 174
Views: 57202

Re: v7.1rc7 [development] is released!

Was rc7 pulled ?

I could download earlier today but not now (2300 GMT) ?
by atakacs
Fri Nov 26, 2021 3:23 pm
Forum: Beginner Basics
Topic: Best site to site sertup
Replies: 5
Views: 2600

Re: Best site to site sertup

Thanks - didn't realise Wireguard was now proposed by RouterOS.
by atakacs
Thu Nov 25, 2021 10:16 pm
Forum: Beginner Basics
Topic: Best site to site sertup
Replies: 5
Views: 2600

Best site to site sertup

I’d be interested to hear about your opinion about the best protocol to use to site to site VPN. This is Mikrotik to Mikrotik. Each side has multiple subnets. By “best” I mean Easy to setup Performance Reliability I have a few IPSec setups that work but I find them rather hard to setup - and some ju...
by atakacs
Thu Nov 25, 2021 10:09 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 IPsec site-to-site performance
Replies: 4
Views: 5340

Re: RB1100AHx4 IPsec site-to-site performance

i recommend you use CHR. I already use several CHR routers on 1Gbps WAN links with GRE+IPsec tunnels (aes-128 gcm). Even with 1vCPU routers can 950Mbps.
That's rather impressive.
by atakacs
Mon Jul 26, 2021 8:37 pm
Forum: General
Topic: Site to Site IPsec - muti subnet routing & capturing
Replies: 4
Views: 1383

Re: Site to Site IPsec - muti subnet routing & capturing

Thanks I'm afraid this is getting somewhat above my "paygrade" (or more to the point my level of competency). I dont think there is any issue with the WAN link between the two sites - both are on a Gb symmetric fiber with high level SLA. Ping is stable between both sites and absolutely &qu...
by atakacs
Mon Jul 26, 2021 1:05 pm
Forum: General
Topic: Site to Site IPsec - muti subnet routing & capturing
Replies: 4
Views: 1383

Site to Site IPsec - muti subnet routing & capturing

Hello I need to setup a site to site VPN where the Mikrotik router holds multiple subnets. The remote site is managed via a Ubiquiti USG. https://i.imgur.com/stu35Ls.png Overall I have this setup on the mikrotik https://i.imgur.com/Pp4nkr5.png The tunnel is established but I have a hard time reachin...
by atakacs
Fri Jun 11, 2021 12:09 pm
Forum: Beginner Basics
Topic: Winbox 64 bits ?
Replies: 3
Views: 1284

Re: Winbox 64 bits ?

Understood - thanks
by atakacs
Fri Jun 11, 2021 11:56 am
Forum: Beginner Basics
Topic: Confused about chains
Replies: 19
Views: 2764

Re: Confused about chains

Thans for all those excellent advises that I am implenting as we speak !
A bit of a thread drift but how do you do port knocking in mikrotk ?
by atakacs
Fri Jun 11, 2021 12:33 am
Forum: General
Topic: OVPN site-to-site return route ?
Replies: 6
Views: 1031

Re: OVPN site-to-site return route ?

Might be a little thick but can i push return routes on the OVPN server from the client ?! I so how ?
by atakacs
Fri Jun 11, 2021 12:13 am
Forum: Beginner Basics
Topic: Confused about chains
Replies: 19
Views: 2764

Confused about chains

Hi My very fist firewall filter rule is [xxx@mkt-sx-00] /ip firewall filter> print Flags: X - disabled, I - invalid, D - dynamic 0 ;;; drop blacklisted chain=forward action=drop src-address-list=DenyLIst log=yes log-prefix="deny-" I have IP 190.6.38.79 in my DenyLIst yet it seem to find a ...
by atakacs
Fri Jun 11, 2021 12:05 am
Forum: Beginner Basics
Topic: Winbox 64 bits ?
Replies: 3
Views: 1284

Winbox 64 bits ?

Hi

Probably a stupid quesiton... but what's the point of a 64bits Winbox ? what use case / config would require it ?

Just curious :)
by atakacs
Fri Jun 11, 2021 12:04 am
Forum: General
Topic: OVPN site-to-site return route ?
Replies: 6
Views: 1031

Re: OVPN site-to-site return route ?

You can include them in the .ovpn configuration, e.g. route 192.168.99.0 255.255.255.0 vpn_gateway
This is mikrotik to mikrotik - are there ovpn config files involved (I only ibnteract with the Winbox GUI or CLI) ?
by atakacs
Wed Jun 09, 2021 12:36 pm
Forum: General
Topic: OVPN site-to-site return route ?
Replies: 6
Views: 1031

Re: OVPN site-to-site return route ?

hmm so what choices do I have ?
write a script that add those routes ?
by atakacs
Wed Jun 09, 2021 1:45 am
Forum: General
Topic: OVPN site-to-site return route ?
Replies: 6
Views: 1031

OVPN site-to-site return route ?

Hello I have a setup with a site to site OpenVPN tunnels which require static routing (ie to subnets “behind” the Ovpn). On the client side I am using the parameter routes on the /ppp secret row, where I can specify a destination gateway. This works fine to route from the client subnet(s) to the ser...
by atakacs
Sun May 16, 2021 5:34 pm
Forum: General
Topic: IPsec Policies with multiple subnets
Replies: 2
Views: 4631

IPsec Policies with multiple subnets

I have a working IPSec site to site VPN and I now need to make a second subnet available behind one of the routers. As far as I understand the IPSec Policy only maps 1:1 (ie one source to one destination subnet) I have tried to duplicate the policy but although the new one would work this kills the ...
by atakacs
Sun May 16, 2021 5:29 pm
Forum: General
Topic: Cloutik feedback ?
Replies: 20
Views: 6233

Re: Cloutik feedback ?

I agree that the website doesn't inspire much confidence... that's why I was asking for feedback... of which I got none. I guess in and itself it is already saying something :)
by atakacs
Wed Apr 14, 2021 2:48 pm
Forum: General
Topic: Cloutik feedback ?
Replies: 20
Views: 6233

Re: Cloutik feedback ?

Thanks for the feedback so far. I understand & appreciate the limits / issues that such a concept is raising. What I wanted to hear was actualy first hand experience with it (or equivelent product). Out of curiousity, how are the "real pro" handling this when you have hundreds of devic...
by atakacs
Tue Apr 13, 2021 7:46 pm
Forum: General
Topic: Cloutik feedback ?
Replies: 20
Views: 6233

Cloutik feedback ?

Hi

Not seeing much discussion about this service here.

Anyone using it ? Feedback ? Issues ?

Thanks in advance !
by atakacs
Mon Mar 22, 2021 7:54 pm
Forum: General
Topic: Static routes via non persistent connections
Replies: 2
Views: 590

Re: Static routes via non persistent connections

Maybe - let me give it a try (it might be all I need it this works every time a client connects)
by atakacs
Mon Mar 22, 2021 2:32 pm
Forum: General
Topic: Static routes via non persistent connections
Replies: 2
Views: 590

Static routes via non persistent connections

Hello I have a setup with some site to site OpenVPN tunnels which require static routing (ie to subnets “behind” the Ovpn. Everything works perfectly except that sometime the Ovpn tunnel will go down and will become “unreachable” in the static routes. When it reconnects the route remains down and I ...
by atakacs
Sun Mar 21, 2021 3:00 pm
Forum: General
Topic: [Resolved] OVPN s-t-s having cert issue ?
Replies: 1
Views: 3715

Re: [Resolved] OVPN s-t-s having cert issue ?

If anyone happens to have the same issue: I was somehow missing the matching private key on the client router (thought I had it transferred but turned out not to be the case).
Still wish we could have a more explicit log entry...
by atakacs
Thu Mar 18, 2021 8:36 pm
Forum: General
Topic: [Resolved] OVPN s-t-s having cert issue ?
Replies: 1
Views: 3715

[Resolved] OVPN s-t-s having cert issue ?

Hello Trying to setup a site to site OVPN but for some reason I can't seem to have both router connecting. On server I see: 18:55:52 ovpn,info TCP connection established from *.*.*.* 18:55:52 ovpn,debug,packet sent P_CONTROL_HARD_RESET_SERVER_V2 kid=0 sid=cb632957515156 pid=0 DATA len=0 18:55:52 ovp...
by atakacs
Thu Mar 18, 2021 8:17 pm
Forum: General
Topic: Multi site-to-site setup advice
Replies: 8
Views: 1786

Re: Multi site-to-site setup advice

Typing in the IP of any shared resource connects to and from... But you have to know what you are looking for.
Yep - I guess we will have to settle to that solution. IP could be assigned based on the MAC of each device (there are not that many of them)... but we would have loved to step it up :)
by atakacs
Wed Mar 17, 2021 5:30 pm
Forum: General
Topic: Multi site-to-site setup advice
Replies: 8
Views: 1786

Re: Multi site-to-site setup advice

Any further thoughts on this ? :)
by atakacs
Wed Mar 17, 2021 5:29 pm
Forum: General
Topic: Mutiple SSTP servers
Replies: 4
Views: 1474

Re: Mutiple SSTP servers

In a few words the router (CCR) is servicing multiple, segregated, subnets. I wanted to give SSTP VPN access to the various users of said unrelated subnets - different user / pass / cert - based on the the public IP.
by atakacs
Wed Mar 17, 2021 10:20 am
Forum: General
Topic: Mutiple SSTP servers
Replies: 4
Views: 1474

Re: Mutiple SSTP servers

Thanks for confirming.
by atakacs
Wed Mar 17, 2021 1:28 am
Forum: General
Topic: Mutiple SSTP servers
Replies: 4
Views: 1474

Mutiple SSTP servers

Hello

Is is possible to have mutiple SSTP servers ?

I have a range of public IPs and currently run SSTP server bound to one of the public IP. Can I have more than one server, bound to a different IP. I guess not but just checking...
by atakacs
Mon Mar 15, 2021 12:43 am
Forum: General
Topic: Multi site-to-site setup advice
Replies: 8
Views: 1786

Re: Multi site-to-site setup advice

Hi Thanks for your interest :) Well, let’s indeed assume 5 warehouses. Each have their unique network with unique subnet - very basic needs (some local LAN devices, internet access). Then we have some unique “line of business” hardware that needs to be able to roam across those 5 warehouses at any t...
by atakacs
Sun Mar 14, 2021 3:00 pm
Forum: General
Topic: Multi site-to-site setup advice
Replies: 8
Views: 1786

Re: Multi site-to-site setup advice

Pretty close with multiple warehouses - we will need a specific (dedicated) network (in pratice a specific ETH attached to the router) to allow connecting and "seeing" across all the other locations at any given point. In essece whereever you are, assuming you plug into the "right&quo...
by atakacs
Sat Mar 13, 2021 8:03 pm
Forum: General
Topic: Multi site-to-site setup advice
Replies: 8
Views: 1786

Multi site-to-site setup advice

Hello I would like to setup a site-to-site setup to deploy around all of the remote sites where all “local” subnets would “see” each other, as well as the “hub” site (idealy with Bonjour/mDNS working across the subnets): https://i.imgur.com/uNA6je2.jpg What would be the best approach for such a setu...
by atakacs
Sat Mar 13, 2021 7:37 pm
Forum: Forwarding Protocols
Topic: OSPF Linux MikroTik
Replies: 6
Views: 5431

Re: OSPF Linux MikroTik

Did you manage to sort out this issue ?

I gather you are using https://pritunl.com/ (which I am looking into) ?
by atakacs
Mon Mar 08, 2021 5:59 pm
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 208
Views: 107261

Re: Future of LTE products, user feedback requested

Wow... lots of options :)

Any input as of which would be the most relevant for use in Switzerland (Swisscom or Surise) ?
by atakacs
Tue Jan 26, 2021 3:55 pm
Forum: Beginner Basics
Topic: IP sec negociation error
Replies: 6
Views: 2399

Re: IP sec negociation error

Thanks - yes it seems I will need both ends of the conversation.

That being said I see
04:47:41 ipsec,debug -an acceptable proposal found- 
04:47:41 ipsec,debug dh(modp1024) 
04:47:41 ipsec,debug -agreed on pre-shared key auth- 
so there is _some_ handshake going on.
by atakacs
Tue Jan 26, 2021 2:56 pm
Forum: Beginner Basics
Topic: IP sec negociation error
Replies: 6
Views: 2399

Re: IP sec negociation error

Thanks - good catch on both points. Corrected - still not conencting, athough the hadshake seem to work ok. I can't pinpoint at what step if actually fails... 13:32:58 ipsec,debug === 13:32:58 ipsec,info initiate new phase 1 (Identity Protection): *.*.*.*[500]<=>*.*.*.*[500] 13:32:58 ipsec,debug new...
by atakacs
Mon Jan 25, 2021 6:24 am
Forum: Beginner Basics
Topic: IP sec negociation error
Replies: 6
Views: 2399

Re: IP sec negociation error

I am probably blind. Where does it say that it fails? See last line " error phase1 negotiation failed due to time up " Also during the whole "handshake" phase it stays on https://i.imgur.com/ETuUGgd.png From my own experience - you should check logs on both sides. They might not...
by atakacs
Fri Jan 22, 2021 4:05 pm
Forum: Beginner Basics
Topic: IP sec negociation error
Replies: 6
Views: 2399

IP sec negociation error

Hi Trying to setup a site to site VPN and despite what I believe to be similar settings on both ends (Mikrotik to Zywall 110) the negociation fails. 04:47:41 ipsec,info initiate new phase 1 (Identity Protection): *.*.*.*[500]<=>*.*.*.*[500] 04:47:41 ipsec,debug new cookie: 04:47:41 ipsec,debug 77412...
by atakacs
Mon Nov 30, 2020 11:37 pm
Forum: Beginner Basics
Topic: Locked out of ssh/winbox... but how ?
Replies: 6
Views: 1275

Re: Locked out of ssh/winbox... but how ?

Thanks - that's a neat trick I will make a note of.
I eventually restored a known working backup - I'm still not exactly sure of what I broke there (is there some sort of "diff" tool ?) but it worked out of the box and I simply re-applied the few changes I had since.
by atakacs
Fri Nov 27, 2020 8:04 pm
Forum: Beginner Basics
Topic: Locked out of ssh/winbox... but how ?
Replies: 6
Views: 1275

Re: Locked out of ssh/winbox... but how ?

Any suggestion ? What can I "trace" to see why my connections are not going through ? Bit strange...
by atakacs
Thu Nov 26, 2020 12:03 am
Forum: Beginner Basics
Topic: Locked out of ssh/winbox... but how ?
Replies: 6
Views: 1275

Re: Locked out of ssh/winbox... but how ?

nope

Image
by atakacs
Wed Nov 25, 2020 10:09 pm
Forum: Beginner Basics
Topic: Locked out of ssh/winbox... but how ?
Replies: 6
Views: 1275

Locked out of ssh/winbox... but how ?

Probably a dumb question but can't figure it out... for some reason I seem to be locked out of ssh / winbox on my router from LAN. Thankfully I have console access but still can't see what is blocking me... I can ping the box from LAN and traffic is flowing ssh & winbox services are active I hav...
by atakacs
Mon Nov 16, 2020 10:30 am
Forum: General
Topic: are this rules on the top mandatory?
Replies: 62
Views: 7170

Re: are this rules on the top mandatory?

Just wanted to say that I find this thread both fascinating and instructive :)
by atakacs
Sat Nov 14, 2020 6:38 pm
Forum: General
Topic: Mikrotik Captive Portal best practice
Replies: 0
Views: 534

Mikrotik Captive Portal best practice

I have inherited a few hotel sites running Mikrotik infra with captive portal for WiFi access for their guests. Although things seem to be mostly working ok I suspect some users are managing to bypass the portal to get “unauthorised” internet access. I am trying to understand and locate those possib...
by atakacs
Thu Nov 05, 2020 9:05 am
Forum: Beginner Basics
Topic: About VPN automatic (?) routes
Replies: 8
Views: 1752

Re: About VPN automatic (?) routes

Thanks - sounds like a clever approach. I have added the rule and there is some progress as packets to subnet 172.16.107.0/24 are not anymore egressing to WAN but are just lost. Can I use /tool sniffer to check if they are actually getting into the tunnel (which would point with an issue with the re...
by atakacs
Thu Nov 05, 2020 1:47 am
Forum: Beginner Basics
Topic: About VPN automatic (?) routes
Replies: 8
Views: 1752

Re: About VPN automatic (?) routes

I am getting back to his subject as I am clearly still not fully understanding how this is supposed to work. I have an IPsec site-to-site setup where the tunnel comes up ok but I don't have any traffic into the tunnel. If I do a traceroute I see that my packet are (obviously) getting to the gateway ...
by atakacs
Tue Nov 03, 2020 3:03 pm
Forum: General
Topic: Routing issue with PPTP site to site
Replies: 4
Views: 862

Re: Routing issue with PPTP site to site

To find out whether the issue is at Mikrotik side or the USG side, run /tool sniffer quick interface=<pptp-ccc-usg> ip-protocol=icmp while pinging something else than 172.16.107.254 in 172.16.107.0/24 from 172.16.100.0/24. If you can see ICMP packets towards the pinged IP, the issue is at USG side;...
by atakacs
Mon Nov 02, 2020 6:17 pm
Forum: General
Topic: Routing issue with PPTP site to site
Replies: 4
Views: 862

Re: Routing issue with PPTP site to site

hmm can't seem to figure it out. I would really appreciate any suggestion
by atakacs
Fri Oct 30, 2020 12:44 pm
Forum: General
Topic: Routing issue with PPTP site to site
Replies: 4
Views: 862

Routing issue with PPTP site to site

Hello I'm having a routing issue with a PPTP site to site VPN (between a USG pro and a Mikrotik, and I feel the issue is on the Mikrotik side). On the USG side I have subnet 172.16.107.0/24 with GW 254 On the Mikrotik side I have subnet 172.16.100.0/24 with GW 254 The tunnel comes up without problem...
by atakacs
Sat Oct 17, 2020 1:14 pm
Forum: Beginner Basics
Topic: About VPN automatic (?) routes
Replies: 8
Views: 1752

Re: About VPN automatic (?) routes

Many thanks for your explanations ! Most educative !
by atakacs
Fri Oct 16, 2020 4:46 pm
Forum: Beginner Basics
Topic: About VPN automatic (?) routes
Replies: 8
Views: 1752

Re: About VPN automatic (?) routes

Thanks - good starting point for my understanding.

When you say "everything adds routes" do you mean "automatically" or "needed to be explicitly added" ?

Is the policy matcher triggering before the IP routes ?
by atakacs
Fri Oct 16, 2020 9:50 am
Forum: Beginner Basics
Topic: About VPN automatic (?) routes
Replies: 8
Views: 1752

About VPN automatic (?) routes

Hello I am a bit confused about how (if at all) VPN connections are creating automatic routes in the router and to what extent I have to manage them. My question pertains to PPTP, IPsec and SSTP (I do not use OpenVPN but as we are at it I would be interested to read about it too...). My (admittedly ...
by atakacs
Wed Sep 30, 2020 5:34 pm
Forum: Beginner Basics
Topic: L2tp/IPsec up but can't reach subnet (windows 10 client)
Replies: 3
Views: 995

Re: L2tp/IPsec up but can't reach subnet (windows 10 client)

It depends. In case the client gets IP address from LAN subnet, you need proxy ARP on LAN interface. Firewall can also be the cause.
Aha - yes they do get IP from the same pool that serves the LAN subnet. Is that not best practice ?
by atakacs
Wed Sep 30, 2020 12:41 am
Forum: Beginner Basics
Topic: L2tp/IPsec up but can't reach subnet (windows 10 client)
Replies: 3
Views: 995

L2tp/IPsec up but can't reach subnet (windows 10 client)

Hi I have setup a L2TP VPN server on my Mikrotik for use with a Win 10 client to connect. I can initiate the tunnel & connect successfully. I get an IP in the expected subnet from the expected IP pool. My traffic is actually redirected through the VPN gateway (it is by default gateway) - all see...
by atakacs
Wed Sep 30, 2020 12:36 am
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 1600

Re: A routing conundrum

Some things you should try to do yourself atleast, below is where you can change the default route distance on a DHCP client
More than happy to do so and to learn but quite frankly had no idea how to change the default route distance on a DHCP client... Thanks for your help there !
by atakacs
Tue Sep 29, 2020 11:36 am
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 1600

Re: A routing conundrum

Next question is how do I achieve it ? Those automatic routes don't seem to be "editable", at least not from Winbox...
Anyone ... ?
by atakacs
Sun Sep 27, 2020 11:55 am
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 1600

Re: A routing conundrum

I'll probably go with a) as it seems to be the easiest way to get things working (in any case this is only a short term project).

Next question is how do I achieve it ? Those automatic routes don't seem to be "editable", at least not from Winbox...
by atakacs
Sat Sep 26, 2020 8:54 pm
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 1600

Re: A routing conundrum

Thanks for your detailed answer - let me try to understand (as there is an obvious educational opportunity here :) ) - clients' 10.2.0.x are only point to point /32 addresses, so other 10.2.0.y are not automatically reachable as part of same subnet, they are routed via B Ok - understood - client A h...
by atakacs
Sat Sep 26, 2020 2:54 pm
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 1600

Re: A routing conundrum

Disabled firewall - not working
by atakacs
Sat Sep 26, 2020 2:26 pm
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 1600

A routing conundrum

I am having the following setup https://i.imgur.com/6KXJbEy.jpg A is a windows workstation connected to a linux box (B) via a L2TP VPN tunnel C is a Mikrotik router connect to the same linux box (B) via a L2TP VPN tunnel D is a server connected the the LAN side of C The IP are assigned as indicated ...
by atakacs
Tue Jul 28, 2020 10:57 am
Forum: RouterOS beta
Topic: v7.1beta1 [development] is released!
Replies: 103
Views: 59370

Re: v7.1beta1 [development] is released!

Cosmetic error on a RB1100AHx4 in Winbox under System>Health. It's showing 49.5 amps. Terminal is showing 495 ma.
Oh- was about to ask for an upgrade from our electric provider :)
by atakacs
Tue Jul 28, 2020 10:52 am
Forum: Beginner Basics
Topic: ,ovpn config to mikrotik vpn client
Replies: 2
Views: 6207

Re: ,ovpn config to mikrotik vpn client

Many thanks - I have managed to have it working !
by atakacs
Mon Jul 27, 2020 11:51 pm
Forum: Beginner Basics
Topic: ,ovpn config to mikrotik vpn client
Replies: 2
Views: 6207

,ovpn config to mikrotik vpn client

Hi I have the following (working) ovpn client config file that I'd like to use from the Mikrotik OpenVPN client (which does - obviously ? - not understand ovpn files) dev tun persist-tun persist-key cipher AES-128-CBC ncp-ciphers AES-256-GCM:AES-128-GCM auth SHA1 tls-client client resolv-retry infin...
by atakacs
Thu Jul 23, 2020 3:20 pm
Forum: Beginner Basics
Topic: PPTP tunel up but no traffic
Replies: 0
Views: 576

PPTP tunel up but no traffic

Hi I'm trying to setup a site to site connection via PPTP but although I managed to have it connecting very quickly I don't have traffic flowing. On relevant item is that I don't see addresses assigned to either peers (although I defined a valid pool for both). https://i.imgur.com/KRxb4rM.jpg https:...
by atakacs
Thu Jul 23, 2020 12:39 pm
Forum: Beginner Basics
Topic: Dynamic ip site to site ipsec help
Replies: 8
Views: 9694

Re: Dynamic ip site to site ipsec help

I'm a bit confused about this. How is the new IP "passed" to the other peer ? I understand that you check the local IP and if it change you modify the IPsec profiles - locally it is pretty trivial but how do you "signal" the remote peer to adapt ?`
by atakacs
Wed Jun 24, 2020 2:18 am
Forum: General
Topic: About IPsec and routing
Replies: 4
Views: 1527

Re: About IPsec and routing

Thanks for this detailed explanation ! Sorry for my somewhat unclear initial description - I wanted to keep it generic. In the case at hand subnet A is 172.16.10.0/24 and subnet B is 172.16.100.0/24. A to B works, B to A does not. Will review my settings per your suggestion and revert.
by atakacs
Wed Jun 24, 2020 2:16 am
Forum: Beginner Basics
Topic: Winbox NAT subtility
Replies: 5
Views: 1964

Re: Winbox NAT subtility

Well it might not make much sense but it is happening right in front of my eyes... 100% reproducible. I can switch between both states at will.

One thing of interrest is that I use SSTP server on said router (which is also on 443 I understand). I think it is somehow realated.
by atakacs
Tue Jun 23, 2020 11:20 pm
Forum: General
Topic: About IPsec and routing
Replies: 4
Views: 1527

Re: About IPsec and routing

well I have this
Image
the Azure policy works (site to site to Azure)
the IM office does not (site to site Mk)
by atakacs
Tue Jun 23, 2020 11:01 pm
Forum: Beginner Basics
Topic: Winbox NAT subtility
Replies: 5
Views: 1964

Re: Winbox NAT subtility

Thanks - my "solution" (a separate rule for 443) works well enough as is.

What I'd like to understand is what is actually happening "behind the scene" so to speak. What I do differently in setting up a single port vs multi-port NAT rule ?
by atakacs
Tue Jun 23, 2020 10:35 pm
Forum: General
Topic: About IPsec and routing
Replies: 4
Views: 1527

About IPsec and routing

Hi Currently setting up a site to site VPN and I'm having an issue which seems to be related to routing. The tunnel comes up and I can ping from site A to site B. However I can not reach site A from site B. If I do a traceroute from site B the packets to site A are egressing on the WAN - ie the rout...
by atakacs
Tue Jun 23, 2020 10:20 pm
Forum: Beginner Basics
Topic: Winbox NAT subtility
Replies: 5
Views: 1964

Winbox NAT subtility

I am in need of some clarification about the syntax to use in a Firewall / NAT rule. I have this (typical for an Exchange server) rule: https://i.imgur.com/dYWcbRC.jpg https://i.imgur.com/hkx1Dlo.jpg That does not work as intended. Ports 25,465,587 and 2525 are forwarded to 172.16.100.20 but 443 end...
by atakacs
Wed May 27, 2020 5:54 pm
Forum: Beginner Basics
Topic: Syntax problem add IPsec Peer
Replies: 1
Views: 862

[SOLVED] Re: Syntax problem add IPsec Peer

ok self solved...

it was the use of < and > in the IP addresses .... a no no !
by atakacs
Wed May 27, 2020 5:50 pm
Forum: Beginner Basics
Topic: What's wrong with this NAT command ?
Replies: 5
Views: 1761

[SOLVED] Re: What's wrong with this NAT command ?

Thanks - that was it !
by atakacs
Wed May 27, 2020 1:54 pm
Forum: Beginner Basics
Topic: What's wrong with this NAT command ?
Replies: 5
Views: 1761

Re: What's wrong with this NAT command ?

Because characters < and > shouldn't be there. It's just dst-address=172.16.175.0/24. Right you are - interestingly they would not matter if you enter a single IP, such as in /ip ipsec peer add address=<1.2.3.4> exchange-mode=ike2 local-address=<5.6.7.8> \ name="Somethng" profile="So...
by atakacs
Wed May 27, 2020 12:28 am
Forum: Beginner Basics
Topic: Syntax problem add IPsec Peer
Replies: 1
Views: 862

Syntax problem add IPsec Peer

Hi /ip ipsec policy add dst-address=<172.16.175.0/24> peer="myPeer" proposal="myProposal" sa-dst-address=<1.2.3.4> sa-src-address=<5.6.7.8> src-address=<172.16.100.0/24> tunnel=yes expected end of command (line 1 column 35) Having a syntax issue - apparently the "peer" ...
by atakacs
Wed May 27, 2020 12:17 am
Forum: Beginner Basics
Topic: What's wrong with this NAT command ?
Replies: 5
Views: 1761

What's wrong with this NAT command ?

Probably a dumb question but why does this fail
[me@mikrotik.contoso.com] /ip firewall nat> add action=accept chain=srcnat comment="Something" dst-address=<172.16.175.0/24> src-address=<172.16.100.0/24>
value of range must have ip address before '/'

Thanks
by atakacs
Tue May 26, 2020 10:58 pm
Forum: General
Topic: Loosing route setting at random
Replies: 0
Views: 863

Loosing route setting at random

I'm having a setup in which i establish an SSTP tunnel to a remote site and have a route set to reach the remote subnet (192.168.168.0/24 here) through that tunnel - works fine https://i.imgur.com/C1YRwvt.jpg However, at random intervals, I lose my setting - the route reverts to an "unknown&quo...
by atakacs
Tue May 26, 2020 4:13 pm
Forum: General
Topic: Azure VPN [SOLVED]
Replies: 12
Views: 64607

Re: Azure VPN [SOLVED]

may I ask how this was solved (I don't see a resolution, but I might be missing something :) ) ?
by atakacs
Tue May 26, 2020 3:34 pm
Forum: General
Topic: Azure to OnPrem only working one way
Replies: 1
Views: 2122

Re: Azure to OnPrem only working one way

Hi did you manage to sort it out ? I seem to have the exact same issue. That being said my problem is (at least partially) on the Mikrotik side. If I do a traceroute to the private IP of the remote (Azure) subnet my packets are egressing through the WAN IP, not the trough the tunnel (which is up in ...
by atakacs
Tue Apr 21, 2020 1:26 am
Forum: Beginner Basics
Topic: Best practice for segregated VPN assigned to specific ETH
Replies: 0
Views: 1475

Best practice for segregated VPN assigned to specific ETH

Hi Bit of a newbie here... please bear with me. I have the following scenario: Internet WAN of ETH1. 2 LAN on ETH2 and ETH3 SSTP tunnel built from Mk to a server on WAN. I'd like to have one "classic" subnet on ETH2 with a DHCP range etc for LAN access to the Internet and another segregate...
by atakacs
Tue Apr 07, 2020 1:40 am
Forum: RouterBOARD hardware
Topic: Anyone using Huawei ME909s-120 mPCIe ?
Replies: 5
Views: 3540

Re: Anyone using Huawei ME909s-120 mPCIe ?

ok

do you know how I can "lock it" to a given network (MCC MNC 214 01 in my case) ? Some AT command I guess but not sure how to get there..
by atakacs
Fri Apr 03, 2020 3:23 pm
Forum: RouterBOARD hardware
Topic: Anyone using Huawei ME909s-120 mPCIe ?
Replies: 5
Views: 3540

Re: Anyone using Huawei ME909s-120 mPCIe ?

thanks - yes it seems to work.

did you manage to do a scan of available networks ?
by atakacs
Thu Apr 02, 2020 1:42 pm
Forum: RouterBOARD hardware
Topic: Anyone using Huawei ME909s-120 mPCIe ?
Replies: 5
Views: 3540

Re: Anyone using Huawei ME909s-120 mPCIe ?

Well I have managed to have it working but I think it has fairly limited support from ROS (many of the features don't work or are reported as not supported).

Again if anyone has any experience chime in !
by atakacs
Thu Apr 02, 2020 11:54 am
Forum: RouterBOARD hardware
Topic: Problem connecting to RB953GS
Replies: 5
Views: 3056

Re: Problem connecting to RB953GS

Thanks - it was indeed an issue with the Winbox version. 3.18 allowed me in - updated - all ok !
by atakacs
Wed Apr 01, 2020 12:22 am
Forum: RouterBOARD hardware
Topic: Problem connecting to RB953GS
Replies: 5
Views: 3056

Re: Problem connecting to RB953GS

Thanks

I might be a bit thick but I don't seem to find the note you are mentioning...
by atakacs
Tue Mar 31, 2020 11:51 pm
Forum: RouterBOARD hardware
Topic: Problem connecting to RB953GS
Replies: 5
Views: 3056

Problem connecting to RB953GS

Hi I am trying to "resurrect" a relatively (I'd say a 3-4 years) old RouterBoard RB953GS. For some reason I can't seem to be able to connect - after boot it comes up like this in Winbox https://i.imgur.com/e5sS8Mm.jpg but can't seem to actually connect. After a few minutes it altogether di...
by atakacs
Tue Mar 31, 2020 11:33 pm
Forum: RouterOS beta
Topic: Feature Request - Wireguard Protocol
Replies: 167
Views: 87057

Re: Feature Request - Wireguard Protocol

Is there official position from Mikrotik about that ?

I think the overwhelming opinion of the community is very positive about Wireguard. Is it something you are exploring ? commiting to ? definitely not on the roadmap ?
by atakacs
Mon Mar 30, 2020 9:46 pm
Forum: RouterBOARD hardware
Topic: Anyone using Huawei ME909s-120 mPCIe ?
Replies: 5
Views: 3540

Anyone using Huawei ME909s-120 mPCIe ?

Hi

Anyone using one of those LTE modems with Mikrotik RouterBOARD ? Anything I should be aware of ?

Any feedback welcome !
by atakacs
Sun Mar 29, 2020 11:43 pm
Forum: General
Topic: Multi device routing question
Replies: 9
Views: 2910

Re: Multi device routing question

Sorry I muss be a little thick... What do you propose I do ?
There is no direct link A to C - everything comes either from B or through B. So I make a srcnat from 172.16.100.0/24 (B subnet) to 192.168.28.1 (D gateway) ?
by atakacs
Sun Mar 29, 2020 10:51 pm
Forum: General
Topic: Multi device routing question
Replies: 9
Views: 2910

Re: Multi device routing question

Is is possible that same router has both 192.168.199.247 and 192.168.199.3? Further hops depend on following routers, either they must have route to source address (I guess they don't), or you must use srcnat on the last one that does have it. You are correct: router C has both 192.168.199.247 and ...
by atakacs
Sun Mar 29, 2020 5:43 pm
Forum: General
Topic: Multi device routing question
Replies: 9
Views: 2910

Re: Multi device routing question

Ok back to the bench... So this is router B https://i.imgur.com/sDTlYOP.jpg https://i.imgur.com/lgpquCV.jpg I have defined a route to router C GW (which is 192.168.199.247) - yet my traffic goes to 192.168.199.3 (If I understand this correctly) and does not go further ? Back on the VPN question: if ...
by atakacs
Sun Mar 29, 2020 12:31 am
Forum: General
Topic: Multi device routing question
Replies: 9
Views: 2910

Re: Multi device routing question

Thanks
When you say "Both A and B must know where to find D's subnet (behind C is the answer)" you mean that I have to define a route to subnet D via GW C ?
Just for my understanding: does the VPN tunnel "auto-create" a route for each subnet on the other side?
by atakacs
Sat Mar 28, 2020 11:02 pm
Forum: General
Topic: Multi device routing question
Replies: 9
Views: 2910

Multi device routing question

Hi I have a (possibly obvious) routing question. I have a setup with four routers as below. Routes A, B and C are Mikrotik and under my control. Router D is unknown and not under my control (this is a setup I have recently "inherited"). Sorry for the crude schema... https://i.imgur.com/ISN...
by atakacs
Sat Mar 28, 2020 9:47 pm
Forum: RouterBOARD hardware
Topic: 953GS 5HPnt ?
Replies: 3
Views: 3055

Re: 953GS 5HPnt ?

yep, that's the one - was wondering if it was a latter iteration of the design. Thanks.
by atakacs
Sat Mar 28, 2020 7:19 pm
Forum: RouterBOARD hardware
Topic: 953GS 5HPnt ?
Replies: 3
Views: 3055

953GS 5HPnt ?

Hi

Having some time to sort through my equipment messes I have recently unhoardered a routerboard labelled 953GS 5HPnt

Image

Except that I can't find this reference on the Mikrotik site, nor in current or past hardware. Any hint ?

Thanks & regards
by atakacs
Thu Nov 07, 2019 10:30 am
Forum: General
Topic: Setting up site to site IPSEC to USG
Replies: 2
Views: 1892

Re: Setting up site to site IPSEC to USG

Thanks for your follow up - eventually managed to have it working but honestly can't remember what was the specific issue...
by atakacs
Sun Oct 27, 2019 1:49 pm
Forum: General
Topic: Setting up site to site IPSEC to USG
Replies: 2
Views: 1892

Setting up site to site IPSEC to USG

Hello
I am trying to define a site to site IPSEC to an Ubiquiti Security Gateway (USG Pro 4). I don't get too far...

Image

Anyone done that ? Seems something missing in the initial dialogue.
by atakacs
Tue Jun 12, 2018 12:51 pm
Forum: RouterBOARD hardware
Topic: SFP compativbility
Replies: 0
Views: 892

SFP compativbility

We are currently replacing our existing RB2011UAS-2HnD-IN by a CCR1009-7G-1C-+S+PC. Our fiber connection is delivered directly via this SFP module that was working absolutely flawlessly https://i.imgur.com/WmZDUt6.jpg but it does not seem to be recognised by the new router. Is this normal / expected...
by atakacs
Sun Aug 06, 2017 8:15 pm
Forum: Virtualization
Topic: CHR vs Virtualised VM ?
Replies: 4
Views: 4572

Re: CHR vs Virtualised VM ?

Thanks

We unfortunately don't run 10Gb yet so, as long as it works (which is the case so far), there would not be any significant advantage to move to CHR ?
by atakacs
Sun Aug 06, 2017 12:11 am
Forum: Virtualization
Topic: CHR vs Virtualised VM ?
Replies: 4
Views: 4572

CHR vs Virtualised VM ?

Hello

At some site we are currently running virtualized RouterOS instances on ESX since 2-3 years, ie. before CHR was released.

Overall this works fine but i was wondering if there was a case in migrating towards CHR ?

Any insight / advice you might have would be most welcome.