Community discussions

MikroTik App

Search found 34 matches

by makp
Mon Apr 29, 2019 7:49 am
Forum: General
Topic: DHCP on VLAN issues
Replies: 0
Views: 676

DHCP on VLAN issues

Hi, I have RB 1100 set up with multiple DHCP servers and VLANs, 2 UniFi NanoHD different floors and a UniFi Mesh outside they are connected too RB1100 via UniFi Though Switch (POE). For the WiFi I hat 2 SSID (2,4G and 5) one for the house (VLAN 125) and one for guest (VLAN 150), when setting up IOT ...
by makp
Sat Jun 11, 2016 12:29 pm
Forum: Beginner Basics
Topic: Winbox says Wrong User Name or Password (RB750GL)
Replies: 8
Views: 7128

Re: Winbox says Wrong User Name or Password (RB750GL)

Mikrotik RouterOS [hr] CVE-2016-85005 A long standing problem in the Mikrotik RouterOS is the default username and password. All versions including the 6.34 release have default user of “admin” with no password. While some folks change this, many devices are compromised within the first few hours o...
by makp
Sun May 29, 2016 12:51 am
Forum: Beginner Basics
Topic: Port forwarding does not work!
Replies: 3
Views: 1380

Re: Port forwarding does not work!

/ip firewall nat add action=dst-nat chain=dstnat disabled=no dst-port=12000 in-interface=pppoe-out1 protocol=tcp to-addresses=192.168.88.10 to-ports=12000 add action=dst-nat chain=dstnat disabled=no dst-port=8888 in-interface=pppoe-out1 protocol=tcp to-addresses=192.168.88.10 to-ports=8888 With traf...
by makp
Sun May 29, 2016 12:19 am
Forum: Beginner Basics
Topic: [yet another] simple port forwarding doesn't work?
Replies: 32
Views: 5621

Re: [yet another] simple port forwarding doesn't work?

I think your firewall rules where the real culprits dropping traffic and when that was fixed the Hairpin was needed. Remember: add chain=input connection-state=established,related ... New rules goes in here. .. add action=drop chain=input And your are not the only one getting gray hair when reading ...
by makp
Sat May 28, 2016 11:17 pm
Forum: Beginner Basics
Topic: [yet another] simple port forwarding doesn't work?
Replies: 32
Views: 5621

Re: [yet another] simple port forwarding doesn't work?

I dont realy know about the bridge thing. But of course if port is a slave its the master you use. add chain=srcnat src-address=192.168.1.0/24 dst-address=192.168.1.103 protocol=tcp dst-port=8082 out-interface=ETHERPORTWITHWEBSERVER action=masquerade the out-interface is the port you have the webser...
by makp
Sat May 28, 2016 11:00 pm
Forum: Beginner Basics
Topic: [yet another] simple port forwarding doesn't work?
Replies: 32
Views: 5621

Re: [yet another] simple port forwarding doesn't work?

I have no mobile to check with. Can you look above a few posts for my response to sob re: hairpin? I tried it and it didn't help but I wasn't 100% clear on what interface to specify.
Give me a moment.
by makp
Sat May 28, 2016 10:49 pm
Forum: Beginner Basics
Topic: [yet another] simple port forwarding doesn't work?
Replies: 32
Views: 5621

Re: [yet another] simple port forwarding doesn't work?

I haven't seen any PM funktion

But if you client is on the same subnet you need the hairpin.

Have you tried with your mobile phone, that was my approach until I got the correct filters.
by makp
Sat May 28, 2016 10:40 pm
Forum: Beginner Basics
Topic: [yet another] simple port forwarding doesn't work?
Replies: 32
Views: 5621

Re: [yet another] simple port forwarding doesn't work?

Your webserver is that on same subnet as the client your using, if so you have to check:

http://wiki.mikrotik.com/wiki/Hairpin_NAT

I have my webserver on a different subnet, and I have enabled the DNS in my RB just for the webserver, to keep traffic LAN traffic inside.
by makp
Sat May 28, 2016 10:30 pm
Forum: Beginner Basics
Topic: [yet another] simple port forwarding doesn't work?
Replies: 32
Views: 5621

Re: [yet another] simple port forwarding doesn't work?

Sorry I edited my posting when you posted. OK maybe its because you are missing the "action=accept" If you dont have any use of the forward rules you made disable them. Only have these 2 rules enable: chain=input action=accept connection-state=established,related log=no log-prefix="&q...
by makp
Sat May 28, 2016 10:10 pm
Forum: Beginner Basics
Topic: [yet another] simple port forwarding doesn't work?
Replies: 32
Views: 5621

Re: [yet another] simple port forwarding doesn't work?

Maybe have a look at your Firewall filter. As a newbie I am I would start to log firewall rules, and then see if it is the firewall filter. We have a similar setup I have my webserver on 80, my firewall is - thanks to ZeroByte: 0 chain=input action=accept connection-state=established,related log=no ...
by makp
Fri May 27, 2016 2:44 pm
Forum: General
Topic: Someone to login my Mikrotik
Replies: 13
Views: 4206

Re: Someone to login my Mikrotik

The solution shown above is the correct one: allow established/related, allow certain internal IP's, drop everything else. Unfortunately the default MikroTik setting is to drop only what comes in on the ether1-gateway interface which is presumed to be the internet interface. However when you add an...
by makp
Fri May 27, 2016 2:32 pm
Forum: General
Topic: Someone to login my Mikrotik
Replies: 13
Views: 4206

Re: Someone to login my Mikrotik

This part is scared to me, cause my company that I work with, They will buy Mikrotik device and I'll have to look after it. lol Thanks for info and solution makp. Just remember to set password og change/add user BEFORE connecting to internet, its not RouterOS that is the culprit, the culprit is err...
by makp
Fri May 27, 2016 1:07 pm
Forum: General
Topic: Someone to login my Mikrotik
Replies: 13
Views: 4206

Re: Someone to login my Mikrotik

I got the same in my log after setup, I could see from the IPs they where "local" and originated from my ISP, but I stopped services I didn't need and made "stupid" firewall filters that solved the login attempts, I did as you describe find solution for a specific issue hence mak...
by makp
Fri May 27, 2016 12:58 pm
Forum: Beginner Basics
Topic: setting mikrotik
Replies: 2
Views: 866

Re: setting mikrotik

I started with configuring my broadband as bridge, leaving all the nice config to RB.

Then I went here

http://wiki.mikrotik.com/wiki/MikroTik_RouterOS
http://wiki.mikrotik.com/wiki/Manual:TOC

And google for specific questions like https://www.youtube.com/watch?v=wBVqzYYnAJ8

And know I am here :)
by makp
Tue May 24, 2016 9:01 pm
Forum: Wireless Networking
Topic: Mikrotik AC vs Ubiquiti - RB 1100AHx2
Replies: 6
Views: 2711

Re: Mikrotik AC vs Ubiquiti - RB 1100AHx2

Not a fan of Ubnt at all. But at this point... capsmanager is pretty far behind UniFi in the tools department.

Says alot as UniFi doesn't give you so much - AP wise.
by makp
Sat May 21, 2016 1:40 pm
Forum: Beginner Basics
Topic: How to isolate two networks from same ether
Replies: 10
Views: 2744

Re: How to isolate two networks from same ether

As pe1chl writes VLAN. I have 2 Ubiquiti APs on same ether with two SSID (home and guest) they are configured with VLAN, in the AP I have assigned the VLAN and they get appropriate IPs from DHCP servers I have configured - I have also set max and up and download speed on the APs so guest is limited ...
by makp
Sat May 21, 2016 3:09 am
Forum: Beginner Basics
Topic: High traffic
Replies: 15
Views: 4642

Re: High traffic

With INPUT everything works [najs]: 0 chain=input action=accept connection-state=established,related log=no log-prefix="" 1 ;;; Adgang til Router fra Interne IP chain=input action=accept src-address-list=Interne_IP log=no log-prefix="" 2 ;;; Disable ICMP chain=input action=drop p...
by makp
Sat May 21, 2016 1:45 am
Forum: Beginner Basics
Topic: High traffic
Replies: 15
Views: 4642

Re: High traffic

You should add a new rule and move it to the very beginning of the input chain: connection-state=established,related action=accept Then add a new rule to the end of the input chain: action=drop (no rules - just drop) Disabled my own copy paste rules. Added the two rules top and bottom, no name reso...
by makp
Fri May 20, 2016 11:20 pm
Forum: Wireless Networking
Topic: Mikrotik AC vs Ubiquiti - RB 1100AHx2
Replies: 6
Views: 2711

Re: Mikrotik AC vs Ubiquiti - RB 1100AHx2

Level 4 is necessary to whatever wireless device you want it to act as Ap with more than one client. It has no special relationship with the capsman other than you can control only those wlans that are on the devices with at least level 4 license to be able to work as access points. OK and thank yo...
by makp
Fri May 20, 2016 11:13 pm
Forum: Beginner Basics
Topic: High traffic
Replies: 15
Views: 4642

Re: High traffic

If you're using the default dhcp client, then there's a default-drop-all rule for interface ether1-gateway, which works and protects the DNS proxy from being hijacked, but unfortunately, there are many users who need to use pppoe, and the common thing is for them to go into the pppoe configuration ...
by makp
Fri May 20, 2016 10:10 pm
Forum: Beginner Basics
Topic: High traffic
Replies: 15
Views: 4642

Re: High traffic

These rules definitely work. Probably your WAN interface doesn't have a default drop rule for it, because you shouldn't need to exclusively drop DNS traffic. I.e. - what _else_ is reaching your router from the WAN side? ssh? webfig? If your WAN interface is pppoe1-out (for example) then make sure t...
by makp
Wed May 18, 2016 11:16 pm
Forum: Beginner Basics
Topic: High traffic
Replies: 15
Views: 4642

Re: High traffic

And you don't need to specify 'new' because you usually have a very early rule in the chain which allows established,related. This means that only invalid and new connection states are left by the time the router is checking any rules in the chain after that rule. You don't want either of these typ...
by makp
Wed May 18, 2016 7:12 pm
Forum: Wireless Networking
Topic: Mikrotik AC vs Ubiquiti - RB 1100AHx2
Replies: 6
Views: 2711

Re:

The only benefit I can imagine is the capsman. Otherwise I would not invest into such huge change unless I would plan some huge development or expect some other advantage that is measurable in money. If you have money for it and just want to play there is nothing against... Does capsman work with a...
by makp
Wed May 18, 2016 4:56 pm
Forum: Wireless Networking
Topic: Mikrotik AC vs Ubiquiti - RB 1100AHx2
Replies: 6
Views: 2711

Mikrotik AC vs Ubiquiti - RB 1100AHx2

Would there be any benefits in adding MikroTik ACs to my network ? At the moment I have 2 x RB1100AHx2 -> 2 x Ubiquiti ThoughSwitch -> 2 x Ubiquiti AC PRO (I also has some older HP and Cisco POE switch and MSM AC but that is collecting dust) Unifi controller cant control ThoughSwitch which I am usin...
by makp
Wed May 18, 2016 4:22 pm
Forum: General
Topic: help with a little project
Replies: 2
Views: 1051

Re: help with a little project

Give some print from your configuration.

And what are you pinging internal address' external submarines :)
by makp
Tue May 17, 2016 11:20 pm
Forum: General
Topic: SOLVED! Subnets different ports cannot connect/ping
Replies: 12
Views: 5783

Re: SOLVED! Subnets different ports cannot connect/ping

I'm having a similar problem with this. I can ping things...sometimes. It'll go through 5 times then request timeout the next 5. I can get on the internet but it's obviously pretty slow. Any ideas? I dont think we have similar issue, I could not ping another subnet at anytime. But I guess you shoul...
by makp
Tue May 17, 2016 8:38 pm
Forum: General
Topic: SOLVED! Subnets different ports cannot connect/ping
Replies: 12
Views: 5783

Re: Subnets different ports cannot connect/ping

Heh - facepalm moment. ;) I never set the mask explicitly because it seems to me that it learns properly from the network prefix itself (unless I'm going mad and remembering things all wrong). Good job catching it - stupid netmask being wrong on the clients. . . I think the mistake was I started up...
by makp
Mon May 16, 2016 10:02 pm
Forum: General
Topic: SOLVED! Subnets different ports cannot connect/ping
Replies: 12
Views: 5783

Re: Subnets different ports cannot connect/ping

post a diagram of your network. (if possible, do it at the VLAN layer because I suspect that you've got layer-2 issues) Really frustrated I read all the post I already had read in here, I saw a post where a guy ha same issue with no ping, but his error was in the ip adresses where he did funny stuf...
by makp
Sat May 14, 2016 3:19 pm
Forum: General
Topic: SOLVED! Subnets different ports cannot connect/ping
Replies: 12
Views: 5783

Re: Subnets different ports cannot connect/ping

If you don't have policy routing, then the most likely culprit is your forward chain in IP firewall. I have tried disabling all rules no changes. I have now moved from hyper-V to a Atom based, but still cant ping 192.168.0.0 net. I have putted in an extra NIC a dual port GIG, the onboard NIC 192.16...
by makp
Fri May 06, 2016 10:45 pm
Forum: General
Topic: SOLVED! Subnets different ports cannot connect/ping
Replies: 12
Views: 5783

Re: Subnets different ports cannot connect/ping

Are you doing any policy routing, such as load balancing multiple ISPs? If so, then add all of your local ranges to IP route rules with action set to lookup-in-specified-table table=main It could be other things, but this is common among load-balance users... Also, you only need the hairpin srcnat/...
by makp
Fri May 06, 2016 2:05 pm
Forum: General
Topic: SOLVED! Subnets different ports cannot connect/ping
Replies: 12
Views: 5783

SOLVED! Subnets different ports cannot connect/ping

Just for fun and testing I setup a CentOS webserver (192.168.0.2) behind RB1100AHx2 on a HyperV, but I cant connect to it from LAN but WAN no problem. First I tried with Hairpin NAT but that didn't solve it, so I got the idea to ping the server but I get a Destination host unreachable. Router can pi...
by makp
Thu Apr 28, 2016 7:19 pm
Forum: General
Topic: Loses all connections RB1100AHx2
Replies: 1
Views: 1027

Re: Loses all connections RB1100AHx2

I think I got it. The issue with lost connection, I guess it was my old Netgear GS110TP i used for POE to my Unifi AP-AC Pro - before changing to RB1100 i used the POE injectors from Ubiqiti. Ubiquti writes AP-AC Pro uses max 9W but i guess its more than that, GS110TP delivers max 16,7W per port i d...
by makp
Thu Apr 28, 2016 1:29 pm
Forum: General
Topic: Loses all connections RB1100AHx2
Replies: 1
Views: 1027

Loses all connections RB1100AHx2

Hi all, Have a strange issue with my Routerboard (6.35), it randomly drops connection LAN/WAN and as you can see from log I am logged in and it takes some time to logon again, internet connection also down - just from last hour and "logged out" is when the connection drops: 11:07:19 system...