Community discussions

MikroTik App

Search found 68 matches

by dg3feh
Sun Dec 08, 2024 7:32 pm
Forum: RouterBOARD hardware
Topic: Router with 24EthernetPorts and SFP+
Replies: 0
Views: 1159

Router with 24EthernetPorts and SFP+

Hello! Does anyone know if there will be something like the CCR2004-16G-2S+ with 24 ethernet ports and at least one SFP+? I have been using a CRS125-24G-1S for years, but its performance as a router has definitely reached its limits. I would like to stick with one device. But the CRS326-24G-2S+IN is...
by dg3feh
Mon Jul 01, 2024 12:08 am
Forum: Beginner Basics
Topic: Tunneling internet traffic through IPsec tunnel
Replies: 8
Views: 1780

Re: Tunneling internet traffic through IPsec tunnel

I will say what the majority would say. Use Wireguard with VXLAN/EOIP (if using layer 2). The CRS125 is MIPSBE with 1 core cpu, and that was never good with OpenVPN or IPSEC
CRS125 with v7 is also dump, because u loose the HW offloading.

I still have to solve my IPSEC issue, any idea?
by dg3feh
Sun Jun 30, 2024 8:08 pm
Forum: Beginner Basics
Topic: Tunneling internet traffic through IPsec tunnel
Replies: 8
Views: 1780

Re: Tunneling internet traffic through IPsec tunnel

Concur like 200-400 Mbps max for ethernet and a portion of that for any VPN. What is your ISP throughput at home? 400MBit/s up and down in fiber Do you have a public IP at home (static or dynamic)? dynamic, but that is well fixed by the l2tp which works fine. EGADs, Your rules are a mess and need t...
by dg3feh
Sun Jun 30, 2024 8:04 pm
Forum: Beginner Basics
Topic: Tunneling internet traffic through IPsec tunnel
Replies: 8
Views: 1780

Re: Tunneling internet traffic through IPsec tunnel

Although this is beside the point, IPsec won't give you any performance advantages compared to OpenVPN unless both endpoints (i.e., both your routers) support AES hardware acceleration. If there is no hardware acceleration, consider using WireGuard instead. But since your home "router" CR...
by dg3feh
Tue Jun 18, 2024 8:40 pm
Forum: Beginner Basics
Topic: Tunneling internet traffic through IPsec tunnel
Replies: 8
Views: 1780

Tunneling internet traffic through IPsec tunnel

Hello! I operate on Mikrotik at home and one as access point if we are on holiday. Until now I used OpenVPN, but the performance isn't any longer acceptable, therefore I wanna change to IPsec/L2TP. The site to site connection works fine, but the tunneling of the holiday network towards the internet ...
by dg3feh
Wed Nov 01, 2023 12:06 am
Forum: Beginner Basics
Topic: CAPsMAN ROS v6 and v7
Replies: 5
Views: 2498

Re: CAPsMAN ROS v6 and v7

Ok. I will send back the hap ax3. based on that the device is useless for me. I have to think over how to deal with wifi in the future. Mikrotik won't be considered. Shame on u if u fool me once, shame on me if u fool me twice I dislike hard breaks without any backward compatibility for an entire pe...
by dg3feh
Tue Oct 31, 2023 5:30 pm
Forum: Beginner Basics
Topic: CAPsMAN ROS v6 and v7
Replies: 5
Views: 2498

Re: CAPsMAN ROS v6 and v7

Hello! I did some tests with different hardware an ROS v7.11.2 - hexS - hap ac2 - hap ax3 hexS with wifiwave2 package works as a CAPsManger with the hap ax3 (which uses wifiwave2). hap ac2 does not connect as a CAP to the hexS in this configuration hap ac2 does not accept the wifiwave2 package (not ...
by dg3feh
Mon Oct 30, 2023 1:53 pm
Forum: Beginner Basics
Topic: CAPsMAN ROS v6 and v7
Replies: 5
Views: 2498

CAPsMAN ROS v6 and v7

Hello! My CAPsMAN server runs on a v6 device. Is it possible to bind a v7 device as a CAPsMAN client to this v6 server? In v6 the device which were handed over to CAPsMAN have to been explicitly specified (interface in the CAP card). I can't find that within the v7. Any hints are welcome! BR Holger
by dg3feh
Sun Oct 22, 2023 3:30 pm
Forum: General
Topic: SFP functionality on CRS125-24G-1S
Replies: 6
Views: 1088

Re: SFP functionality on CRS125-24G-1S

....and at the end of the day the CRS326 is an old device on an old chip(set) wich is not well supported by ROS v7. We already tested that, btw the same with CRS125.
by dg3feh
Sun Oct 22, 2023 3:08 pm
Forum: General
Topic: SFP functionality on CRS125-24G-1S
Replies: 6
Views: 1088

Re: SFP functionality on CRS125-24G-1S

Hello all! I don't want to discuss new HW for my switch, but nevertheless CRS125 does HW offloading in ROS v6, there is no need for 2 SFP+. The only question was whether anyone had tested such SFP modules in the CRS125!? If it is not working I need a new 24-copper-port Router with one SFP for WAN up...
by dg3feh
Sun Oct 22, 2023 12:52 pm
Forum: General
Topic: SFP functionality on CRS125-24G-1S
Replies: 6
Views: 1088

Re: SFP functionality on CRS125-24G-1S

Hi! Thx for ur answer! The table in the wiki https://wiki.mikrotik.com/wiki/MikroTik_wired_interface_compatibility#10G_SFP+/25G_SFP28 lists quite a lot of modules higher than 1G working with that device. Therefore the question: Has someone tried that already? Buying a new switch is senseless due to ...
by dg3feh
Sat Oct 21, 2023 7:05 pm
Forum: General
Topic: SFP functionality on CRS125-24G-1S
Replies: 6
Views: 1088

SFP functionality on CRS125-24G-1S

Hello! My CRS125-24G-1S gets more and more load and is also a little bit old fashioned as a Router. I wanna degrade that device just being a switch and transfer the routing to a RB5009. Therefore I want to connect the RB5009 with the CRS125 with 2.5G ethernet. Has anyone checked the SFP on the CRS12...
by dg3feh
Sun Feb 13, 2022 8:59 am
Forum: Beginner Basics
Topic: Two PPPoE WAN Interfaces and static routes
Replies: 1
Views: 707

Two PPPoE WAN Interfaces and static routes

Hello! I have two PPPoE WAN Interfaces running. In general all clients have to use PPPoE_1 and if it is down PPPoE_2. That works fine with distances 5 and 10. So far so good. I have one IP (or Interface on MT side), that have to use PPPeE_2 in anycase. How can i setup a static route for that? All cl...
by dg3feh
Wed Jan 26, 2022 7:14 pm
Forum: RouterOS beta
Topic: SFP functionality in RB760iGS with v7
Replies: 2
Views: 2576

Re: SFP functionality in RB760iGS with v7

At MT it's getting worse and worse. WPA3 isn't supported, SFPs stop working, etc. It's time to look for an alternative provider...
by dg3feh
Fri Jan 21, 2022 11:06 am
Forum: RouterOS beta
Topic: SFP functionality in RB760iGS with v7
Replies: 2
Views: 2576

SFP functionality in RB760iGS with v7

Hello!

My test router is a simple hex-s RB760iGS. After updating to v7.1.1the SFP module is no longer recognized. It is a simple fs.com BiDi fiber module, which works fine since ever in several MTs. After downgrading to v6.49.2 everything is fine again. Any hints what is wrong here?

BR Holger
by dg3feh
Wed Dec 16, 2020 1:26 pm
Forum: RouterBOARD hardware
Topic: SFP Optical Transceiver from EDGE Technologies
Replies: 0
Views: 860

SFP Optical Transceiver from EDGE Technologies

Hello! Has anyone had any experience with Edge optical transceivers (e.g. https://edgeoptic.com/Pub_downloads/Datasheets/BIDI-1.25G-SFP-21-ADS.pdf) ? They explicitly offer programming for Mikrotik. I had asked about parameter settings as well as diagnostic and status messages that are availible/visi...
by dg3feh
Mon Feb 03, 2020 5:10 pm
Forum: General
Topic: Fritzbox -> Mikrotik VPN
Replies: 16
Views: 11221

Re: Fritzbox -> Mikrotik VPN

Hello!

I am trying the same. Could u please send me a screenshot of the FritzBox Config? That is the strange part for me.

How have u fixed the dynamic ip adress problem?

BR

Holger
by dg3feh
Thu Jul 04, 2019 1:14 pm
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1869

Re: Best way to connect a remote site by some kind of VPN?

is that only done by a passphrase? no keys possible?
by dg3feh
Thu Jul 04, 2019 12:44 pm
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1869

Re: Best way to connect a remote site by some kind of VPN?

The GRE documentation ist not the best one at mikrotik. Do I have to use the static addresses generated by L2TP as local/remote address and afterwards the routing is done in the routing table? Where is the encryption defined at GRE?
by dg3feh
Thu Jul 04, 2019 12:16 pm
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1869

Re: Best way to connect a remote site by some kind of VPN?

IPsec works with policies not with routing and 0.0.0.0 is not accept there......
by dg3feh
Thu Jul 04, 2019 11:54 am
Forum: Beginner Basics
Topic: Best way to connect a remote site by some kind of VPN?
Replies: 7
Views: 1869

Best way to connect a remote site by some kind of VPN?

Hello all! I want to connect a remote site (small network with a Mikrotik) behind a natted router with my home site which is also a Mikrotik. I want to have access to my computers on my home site and beside that I want to route all traffic from the remote site to the internet through the tunnel and ...
by dg3feh
Wed Mar 13, 2019 2:48 pm
Forum: General
Topic: IPsec connection between several sites over on concentrator
Replies: 0
Views: 597

IPsec connection between several sites over on concentrator

Hello! I have one site with DDNS running als a concentrator for my network. The concentrators network is 192.168.51.0/24. I connect two satelite sites (192.168.54.0/24 and 192.168.55.0/24) to the concentrator by L2TP/IPsec. That works fine. so I get access from the satelite sites to the concentrator...
by dg3feh
Wed Sep 19, 2018 4:06 pm
Forum: Beginner Basics
Topic: IPsec over L2TP with client-side behind a natted-router
Replies: 2
Views: 1139

IPsec over L2TP with client-side behind a natted-router

Hello! I run a L2TP Server on my Mikrotik at home (VDSL connection). The Client side is a Mikrotik connected to some kind of WLAN router running NAT. The configuration export without secrets u find here: Server: server.txt.rsc Client: client.txt.rsc The L2TP connection seems to work (R for running, ...
by dg3feh
Tue Aug 21, 2018 10:39 am
Forum: General
Topic: How to build a simple user interface to choose a WLAN?
Replies: 0
Views: 718

How to build a simple user interface to choose a WLAN?

Hello! I want to set up a mikrotik based on a RB433UL for my parents motor home. The aim is to provide a secure 2GHz WLAN in the RV (R11e-2HPnD). This WLAN connects to the Internet by using a LTE connection (R11e-LTE) or if available a WLAN connection (R52HnD). To set up this within RouterOS is not ...
by dg3feh
Mon Mar 19, 2018 12:15 pm
Forum: Wireless Networking
Topic: Mikrotik as a secure gateway behind public WLAN
Replies: 3
Views: 1419

Re: Mikrotik as a secure gateway behind public WLAN

Yes, B is mandatory, because in this network are several clients with internal traffic which should have no connection to the outside. I found the problem. operating with a wan-bridge for wlan and ether1 as out-interface doesn't work. the routing here was not clear. using the wlan-to-wan and the eth...
by dg3feh
Sun Mar 18, 2018 1:13 am
Forum: Wireless Networking
Topic: Mikrotik as a secure gateway behind public WLAN
Replies: 3
Views: 1419

Mikrotik as a secure gateway behind public WLAN

Hello! I wanna try the following. A) I want to act a MT as a station connected to a (pubilc) wlan. That works fine, I get an IP, DNS, NTP, default route by the WLANs DHCP. B) I want to provide a local WPA2-WLAN for my clients using the network 192.168.54.0/24. That works also fine. C) I want to rout...
by dg3feh
Sat Mar 17, 2018 6:06 pm
Forum: Wireless Networking
Topic: CAPsMAN and AMSDU together with iOS
Replies: 2
Views: 1824

CAPsMAN and AMSDU together with iOS

Hello!

I have the problem, that all apple devices loose their WiFi connection, if they are not used. I read in several other threads, that reducing the AMSDU values to 4096 solved the problem. How do I change that value if I use CAPsMAN?

BR Holger
by dg3feh
Thu Mar 15, 2018 8:23 pm
Forum: Forwarding Protocols
Topic: Webserver NAT/Hairpin behind PPPoE
Replies: 4
Views: 2582

Re: Webserver NAT/Hairpin behind PPPoE

Strange, but it doesn't work with an explicit destination IP. I have now an additional problem. I want to route http://<external-ip>:8100 to another webserver 192.168.51.231. add action=accept chain=forward comment=Heatermeter disabled=yes dst-port=8100 log=yes log-prefix=HM-forward: protocol=tcp ad...
by dg3feh
Thu Mar 15, 2018 5:03 pm
Forum: Forwarding Protocols
Topic: Webserver NAT/Hairpin behind PPPoE
Replies: 4
Views: 2582

Re: Webserver NAT/Hairpin behind PPPoE

Hello! Thanks for ur help! I changed the dst-nat to add action=dst-nat chain=dstnat comment="Port-forwarding HTTPS zum Server" dst-address=!192.168.51.254 dst-address-type=local dst-port=443 log-prefix="APACHE443: " \ protocol=tcp to-addresses=192.168.51.230 to-ports=443 add acti...
by dg3feh
Thu Mar 15, 2018 12:40 pm
Forum: Forwarding Protocols
Topic: Webserver NAT/Hairpin behind PPPoE
Replies: 4
Views: 2582

Webserver NAT/Hairpin behind PPPoE

Hello! I am geting a bit nut with my firewall rules. My WAN connection is a PPPoE connection with a dynamic IP, the DynDNS works fine. The local networks I use: 192.168.50.0/24 - only modem in 192.168.51.0/24 - main LAN - Mikrotik Router 192.168.51.254 - Web-Server 192.168.51.230 192.168.53.0/24 - g...
by dg3feh
Thu Dec 07, 2017 12:04 am
Forum: Beginner Basics
Topic: FireTV Stick and wAP G-5HacT2HnD
Replies: 0
Views: 548

FireTV Stick and wAP G-5HacT2HnD

Hello!

I run an AP wAP G-5HacT2HnD and it works fine for all Device (Win7/Win10, Linux, iOS, Android, etc.) Since one week I own a FireTV Stick (the new one with Alexa) and it does not connect to the Mikrotik. I run WPA2 PSK with aes ccm. Does anyone have a hint?

BR Holger
by dg3feh
Wed Jul 26, 2017 9:27 am
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

In /ip firewall service-port there is the possibility to reduce the TTL for SIP connections: SIP helper. Additional options: sip-direct-media allows redirect the RTP media stream to go directly from the caller to the callee. Default value is yes. sip-timeout allows adjust TTL of SIP UDP connections....
by dg3feh
Tue Jul 25, 2017 1:54 pm
Forum: Beginner Basics
Topic: Writing output to usb-stick
Replies: 0
Views: 861

Writing output to usb-stick

Hello! I tried to write the sniffer log to a Memorystick, without success. [admin@Router-HH] /disk> print # NAME LABEL TYPE DISK FREE SIZE 0 disk1 1GB-MEMSTIC fat32 PDU01_1G 71G2.0 968.6MiB 984.0MiB ...that seems ok for me. I found the disk1 in the files: [admin@Router-HH] /file> print # NAME TYPE S...
by dg3feh
Thu Jul 20, 2017 9:14 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

"use peer DNS" results in a "push". These DNS are dynamical set by the ISP.

No hints regarding the file problem? :(
by dg3feh
Thu Jul 20, 2017 2:47 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

Hello all, thanks for u comments. I have a small unix server in my LAN doing mostly nothing ;) (beside family file serving) which is able do act as DNS. Problem is the dynamic push of the ISPs nameserver to the mikrotik. How do I transfer this information to the server? Beside that: Some hints for t...
by dg3feh
Sat Jul 15, 2017 5:02 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

...beside that I tried to write the sniffer log to a Memorystick, without success. [admin@Router-HH] /disk> print # NAME LABEL TYPE DISK FREE SIZE 0 disk1 1GB-MEMSTIC fat32 PDU01_1G 71G2.0 968.6MiB 984.0MiB ...that seems ok for me. I found the disk1 in the files: [admin@Router-HH] /file> print # NAM...
by dg3feh
Sat Jul 15, 2017 4:41 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

In the last 24h I forced a TTL of 1sec to all DNS entries and there where no registration losts on my VoIP. So I am pretty sure that the ISPs DNS SRV Records are corrupt regarding TTL, weight, priority. I am already in discussion with my ISP, but as usual: To get someone on the phone, who is able to...
by dg3feh
Thu Jul 13, 2017 5:14 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

Nope! I know that my VoIP Service is some how currupted by wrong DNS entries, The work around is to ask not the mikrotik DNS cache, but the ISP DNS directly. Thus I want a directive to do that only for the VoIP domains. The rest works fine with the "normal" DNS relay. Only if this is not p...
by dg3feh
Thu Jul 13, 2017 4:51 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

I am talking about the SRV record. If there are two or more entries for a canocial name the descission which is taken is made by pritority and weight. -> https://en.wikipedia.org/wiki/SRV_record
by dg3feh
Thu Jul 13, 2017 2:49 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

Is it possible to see the priority and the weighting of the records?
by dg3feh
Thu Jul 13, 2017 2:42 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Re: Exclude domains from DNS cache!?

Hello!

I know all this. The IPs TTLs and weightings seems to be wrong. I want to send all DNS queries direct to the ISP DNS and all the rest first to the caching name server. The normal TTL is 1h.
Is there no possibility to force this?

BR Holger
by dg3feh
Thu Jul 13, 2017 1:08 pm
Forum: General
Topic: Exclude domains from DNS cache!?
Replies: 28
Views: 6571

Exclude domains from DNS cache!?

Hello! I have quite often regsitration losts on my VoIP. I figured out that the provider is changing all the time the IP Address of the VoIP Server. Thus I need to exclude the Provider Domain from the DNS cache. How can I do this? I need to use the mikrotik as DNS server due to the fact, that the DN...
by dg3feh
Wed Apr 05, 2017 12:12 pm
Forum: Beginner Basics
Topic: OpenVPN client-to-client mode
Replies: 1
Views: 2129

OpenVPN client-to-client mode

Hello!

I have learned that the OpenVPN within Mikrotik has some lacks (e.g. push route, etc). Is it possible to activate client-to-client mode and if so, how?

BR Holger
by dg3feh
Mon Feb 13, 2017 3:51 pm
Forum: Beginner Basics
Topic: Guest-WLAN with dedicated AP - how to reach WAN?
Replies: 1
Views: 1072

Guest-WLAN with dedicated AP - how to reach WAN?

Hello! I run two mikrotik devices: - Cloudswitch CRS125-24-1S - Access point wAP ac The private (W)LAN is 192.168.51.0/24 and the guest WLAN is 192.168.52.0/24. The private LAN incl. WLAN works fine. I setup the WLANs for guest WLAN as virtual APs, put them in a new bridge interface and defined a ne...
by dg3feh
Wed Feb 08, 2017 12:44 pm
Forum: Beginner Basics
Topic: Passing VLAN tagging to Modem
Replies: 1
Views: 747

Passing VLAN tagging to Modem

Hello! I use a Draytek Vigor 130 as a modem and fire up the WAN connection by PPPoE with the router. Rightnow I am connected to a ADSL2+ line and everything works fine. I will switch over to VDSL2+ in a few weeks and for that I need to pass a VLAN Tag from the mikrotik to the modem, but I haven't fo...
by dg3feh
Sat Feb 04, 2017 11:11 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 3090

Re: Hairpin won't work, but why?

But it works now, thanks for ur help.
by dg3feh
Sat Feb 04, 2017 10:23 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 3090

Re: Hairpin won't work, but why?

Correct me, but I masqueraded the request with the external address, why shouldn't match that with !192.168.1.0/24?
by dg3feh
Sat Feb 04, 2017 9:52 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 3090

Re: Hairpin won't work, but why?

Ok, that's the point. I changed it now to /ip firewall nat add action=dst-nat chain=dstnat comment="Portforwarding HTTP zum Server" dst-port=80 log=yes log-prefix=FW80 protocol=tcp \ src-address=!192.168.1.0/24 to-addresses=192.168.1.252 to-ports=80 So that rule only works, if the source i...
by dg3feh
Sat Feb 04, 2017 9:41 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 3090

Re: Hairpin won't work, but why?

So how this thread differs from your previous one ? Because the first one is more general and now only the hairpin is the problem. Is there any specific reason why you refuse to acknowledge that it can't work with dstnat rules that have in-interface=PPPoE-ALICE? :) I have under stand that, but /ip ...
by dg3feh
Sat Feb 04, 2017 8:23 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 3090

Re: Hairpin won't work, but why?

use code on conclusion page of this presentation https://goo.gl/35GBvK , it's work both single wan and multi-wan

credit : https://www.facebook.com/mikrotiktutori ... 126599365/
I can't see the difference to what I am doing....
by dg3feh
Sat Feb 04, 2017 7:51 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 3090

Re: Hairpin won't work, but why?

Ok, I tried that one: /ip firewall nat add action=masquerade chain=srcnat comment="Maskierung LAN" out-interface=PPPoE-ALICE src-address=192.168.1.0/24 add action=src-nat chain=srcnat comment=NTP protocol=udp src-port=123 to-addresses=192.168.1.254 add action=dst-nat chain=dstnat comment=&...
by dg3feh
Sat Feb 04, 2017 3:00 pm
Forum: Beginner Basics
Topic: Hairpin won't work, but why?
Replies: 13
Views: 3090

Hairpin won't work, but why?

Hello! I have the following configuration: FullSizeRender.jpg I want to reach with the normal clients the internet and the server from extranal and subnet 192.168.1.0/24 under the external server address. Beside that I want to reach the modem on its internal address for configuration, etc. The addre...
by dg3feh
Fri Feb 03, 2017 9:07 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

That's just a half of it. You still need proper dstnat rules. And your current ones only work for connections coming from internet (via PPPoE-ALICE interface). Hm. As far as I understood: We are coming from the inside (e.g. 192,168.1.100) and want to connect to the WAN addresss. Therefore we catch ...
by dg3feh
Fri Feb 03, 2017 2:29 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

Yep, two hints: 1) tag is very useful thing. what do u mean by that? 2) Read my previous post again and this time pay a little more attention (extra subhint: you did not touch your dstnat rules).[/quote] As fare as I understod, the Hairpin works by masquerading. The internal call from LAN to the ex...
by dg3feh
Fri Feb 03, 2017 1:46 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

Hello! the Hairpin and the forwarding for the Router still does not work. Here the actual export: [admin@Router-HH] > /export # feb/03/2017 00:42:43 by RouterOS 6.38.1 # software id = D5X7-MT4X # /interface ethernet set [ find default-name=ether2 ] master-port=ether1 set [ find default-name=ether3 ]...
by dg3feh
Thu Feb 02, 2017 1:09 pm
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

I implemented ur hints, and the Harpin still doesn't work :(

also the redirect of the Router HTTPS Interface doesn't work
by dg3feh
Thu Feb 02, 2017 11:41 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

And what about the Hairpin? I need to get that working to get access to the addressbooks an calendars from smartphones while they are connected to the LAN via WLAN
by dg3feh
Thu Feb 02, 2017 9:55 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

Hello! Thank u for ur answer. The routing from the outside works fine for HTTP, HTTPS and SSH. For the Harpin rule u mean: /ip firewall nat add action=masquerade chain=srcnat comment=Hairpin dst-address=192.168.1.252 dst-port=22,80,443 out-interface-list=ether1 protocol=tcp src-address=192.168.1.0/2...
by dg3feh
Wed Feb 01, 2017 11:47 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

Please show a complete /export of your config so it can be debugged. [admin@Router-HH] > /export # feb/01/2017 10:45:22 by RouterOS 6.38.1 # software id = D5X7-MT4X # /interface ethernet set [ find default-name=ether2 ] master-port=ether1 set [ find default-name=ether3 ] master-port=ether1 set [ fi...
by dg3feh
Wed Feb 01, 2017 8:53 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

LAN means LAN, the internal network where both server and client are connected.
How do I define that? These are all ports accept 23 (where the Modem is connected to)
by dg3feh
Wed Feb 01, 2017 1:54 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

Mistake found. I have to use the PPPoE Interface and not the port! Next problem is the Hairpin NAT http://wiki.mikrotik.com/wiki/Hairpin_NAT /ip firewall nat add chain=srcnat src-address=192.168.1.0/24 \ dst-address=192.168.1.2 protocol=tcp dst-port=80 \ out-interface=LAN action=masquerade what does...
by dg3feh
Wed Feb 01, 2017 1:12 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

So the public IP address is assigned to a PPPoE connection on the Mikrotik? Do you have firewall forward rules to accept the incoming connection? dst-nat only tells the system what you want the packets re-written to, it doesn't give it permission to actually forward the traffic. You likely need to ...
by dg3feh
Wed Feb 01, 2017 12:43 am
Forum: Beginner Basics
Topic: DDNS for different providers
Replies: 0
Views: 692

DDNS for different providers

Hello! I did some changes on the DDNS-script given by the Wiki in order to use different providers and protocols: :global ddnsuser "USERNAME" :global ddnspass "PASSWORD" :global theinterface "INTERFACEtoWAN" :global ddnshost DOMAINNAME :global ddnsserver SERVERNAME :glo...
by dg3feh
Wed Feb 01, 2017 12:26 am
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Re: Port-forwarding does not work, but why?

The public IP is held by the PPP Interface on ether23-MODEM.

What kind of forward rule? U can see all my rules in the post.
by dg3feh
Tue Jan 31, 2017 11:09 pm
Forum: Beginner Basics
Topic: Port-forwarding does not work, but why?
Replies: 24
Views: 6884

Port-forwarding does not work, but why?

Hello! I run my LAN on 192.168.1.0/24 and a xDSL connection via a modem (192.168.0.2) which is connected to ether23-MODEM. The internet connections worksfine. The firewall is like this Flags: X - disabled, I - invalid, D - dynamic 0 ;;; Kaputte Pakete DROP chain=input action=drop connection-state=in...
by dg3feh
Mon Jan 30, 2017 3:40 pm
Forum: Beginner Basics
Topic: Routing two Networks on one CRS125-24G-1S
Replies: 2
Views: 1187

Re: Routing two Networks on one CRS125-24G-1S

Thanks!
The defined gateway is not used, if the Vigor130 acts as a modem and not as a router! The route on the modem sloved the problem!

Holger
by dg3feh
Mon Jan 30, 2017 11:11 am
Forum: Beginner Basics
Topic: Routing two Networks on one CRS125-24G-1S
Replies: 2
Views: 1187

Routing two Networks on one CRS125-24G-1S

Hello! I am completely new to mikrotik. The first aim is to connect a local network (192.168.1.0/24) via a modem (DratyTek Vigor 130) to the internet. The modem has a maintenance ip inteface. This on should run in a seperate network (192.168.0.0/24). Mikrotiks IP is set to 192.168.1.254 on ether1 an...