Community discussions

MikroTik App
 
iwantlemonjuice
Member Candidate
Member Candidate
Topic Author
Posts: 101
Joined: Tue Nov 04, 2008 4:53 am
Location: Boracay Island, Philippines

Portal hijack

Tue Apr 24, 2012 7:42 am

Hi all

I would like to tell you a very strange issue here, my RB450G connected to a local ISP which is this local ISP client of BAYANTEL Communication Carrier, now my RB450G has a static IP in assign on ether1 and this port act as src/masquerade as well and i have a hotspot Vlan and belong to ether5. the main problem the other subscriber of this local IP they have also public static IP the worse thing is those other client browse to internet it will redirect to my hotspot :lol: all of them some of resort calling us why my net redirect to your portal and the local ISP blaming us that we are doing something wrong. you guys has experience this kind of problem?

Thanks
 
coffeecoco
Member Candidate
Member Candidate
Posts: 174
Joined: Wed Oct 12, 2005 1:17 pm

Re: Portal hijack

Tue Apr 24, 2012 12:26 pm

lol, imo probably a wrong static route on the PE?
if they blame you, laugh loudly and as you hang up the phone lol.
 
iwantlemonjuice
Member Candidate
Member Candidate
Topic Author
Posts: 101
Joined: Tue Nov 04, 2008 4:53 am
Location: Boracay Island, Philippines

Re: Portal hijack

Tue Apr 24, 2012 2:24 pm

lol, imo probably a wrong static route on the PE?
if they blame you, laugh loudly and as you hang up the phone lol.
hi coffee

this is my simple config only

/ip address
add address=121.xx.xxx.xxx/24 broadcast=121.xx.xxx.xxxx comment=WAN disabled=no \
interface=ether1-local network=121.96.14.0
add address=192.168.1.1/24 broadcast=192.168.1.255 comment="opera vlan id 2" \
disabled=no interface="opera vlan" network=192.168.1.0
add address=192.168.2.1/24 broadcast=192.168.2.255 comment="office vlan id 3" \
disabled=no interface="office vlan" network=192.168.2.0
add address=192.168.3.1/24 broadcast=192.168.3.255 comment=\
"hotspot vlan id 4" disabled=no interface="hotspot vlan" network=\
192.168.3.0

/ip route
add check-gateway=ping comment="" disabled=no distance=1 dst-address=0.0.0.0/0 gateway=121.xx.xx.x \
scope=30 target-scope=10
add comment="" disabled=no distance=1 dst-address=192.168.99.0/24 gateway=100.100.100.11 scope=30 \
target-scope=10
add comment="" disabled=no distance=1 dst-address=192.168.100.0/24 gateway=100.100.100.11 scope=30 \
target-scope=10
add comment="" disabled=yes distance=1 dst-address=192.168.101.0/24 gateway=192.168.100.2 scope=30 \
target-scope=10

and lasty the src nat out-interface to ether1

Thanks
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: Portal hijack

Tue Apr 24, 2012 5:21 pm

If they are being caught and redirected to your hotspot login page, then that means that they are somehow connected to your layer2 quest network and being caught by the hotspot functionality. Do you see extra hosts in your hosts table that you can't account for, like with wrong IP settings? The other possibility is that somehow your hotspot interface is bridged with your WAN interface and is causing problems there.
 
coffeecoco
Member Candidate
Member Candidate
Posts: 174
Joined: Wed Oct 12, 2005 1:17 pm

Re: Portal hijack

Wed Apr 25, 2012 5:40 am

If they are being caught and redirected to your hotspot login page, then that means that they are somehow connected to your layer2 quest network and being caught by the hotspot functionality. Do you see extra hosts in your hosts table that you can't account for, like with wrong IP settings? The other possibility is that somehow your hotspot interface is bridged with your WAN interface and is causing problems there.
that would make sense if the hotspot interface be a member of the bridge or the hotspot interface is set to the bridge?

also your public ip is a /24 can you confirm that's correct? i cant think how that would make a difference tho, it just means hes broadcasting to /24 public i don't know if that effects anything tho ?
 
iwantlemonjuice
Member Candidate
Member Candidate
Topic Author
Posts: 101
Joined: Tue Nov 04, 2008 4:53 am
Location: Boracay Island, Philippines

Re: Portal hijack

Wed Apr 25, 2012 4:46 pm

If they are being caught and redirected to your hotspot login page, then that means that they are somehow connected to your layer2 quest network and being caught by the hotspot functionality. Do you see extra hosts in your hosts table that you can't account for, like with wrong IP settings? The other possibility is that somehow your hotspot interface is bridged with your WAN interface and is causing problems there.
that would make sense if the hotspot interface be a member of the bridge or the hotspot interface is set to the bridge?

also your public ip is a /24 can you confirm that's correct? i cant think how that would make a difference tho, it just means hes broadcasting to /24 public i don't know if that effects anything tho ?
Hi feklar and coffee

I set no bridge in WAN and hotspot interface, yeah im wondering also why the isp set me a /24 i told them to divide /30 and im not sure how they setup there network since they are ISP. lmao :lol: some of their customer freaking out they suspected hijacking the networl lol..... feklar i try to torch in wan to monitor whats port in and out but i never seen any ports belong in hotspot.

Cheers
 
coffeecoco
Member Candidate
Member Candidate
Posts: 174
Joined: Wed Oct 12, 2005 1:17 pm

Re: Portal hijack

Sat Apr 28, 2012 3:52 pm

If they are being caught and redirected to your hotspot login page, then that means that they are somehow connected to your layer2 quest network and being caught by the hotspot functionality. Do you see extra hosts in your hosts table that you can't account for, like with wrong IP settings? The other possibility is that somehow your hotspot interface is bridged with your WAN interface and is causing problems there.
that would make sense if the hotspot interface be a member of the bridge or the hotspot interface is set to the bridge?

also your public ip is a /24 can you confirm that's correct? i cant think how that would make a difference tho, it just means hes broadcasting to /24 public i don't know if that effects anything tho ?
Hi feklar and coffee

I set no bridge in WAN and hotspot interface, yeah im wondering also why the isp set me a /24 i told them to divide /30 and im not sure how they setup there network since they are ISP. lmao :lol: some of their customer freaking out they suspected hijacking the networl lol..... feklar i try to torch in wan to monitor whats port in and out but i never seen any ports belong in hotspot.

Cheers

Well the mikrotik dont belong to the ISP does it?
so there for thats probly your settings that im questioning

Who is online

Users browsing this forum: k6ccc and 47 guests