Community discussions

MikroTik App

Search found 123 matches

byatakacs
Mon Mar 20, 2023 10:06 am
Forum:Beginner Basics
Topic:CAPSMAN shows device with MAC adress
Replies:1
Views:161

CAPSMAN shows device with MAC adress

Hello I have recently added a new RBMAPL-2ND device into my CAPSMAN setup and for some reason it is recognized but shows up with it's MAC address, not IP. It did get a DHCP IP on the ETH port, I can ping it but can not connect to it using Winbox (or SSH but did not turn it on anyway). What might I h...
byatakacs
Thu Jan 27, 2022 1:08 pm
Forum:Virtualization
Topic:Container on MIPS hardware
Replies:1
Views:2331

Container on MIPS hardware

Not sure this is the right place to ask...

Appartently the container 7.x feature is also supported on SMIPS hardware. Assuming I want to build one what processor architecture should I use ? My goal is to try thishttps://github.com/Fluent-networks/tailscale-mikrotik.

Any feedback most welcome
byatakacs
Mon Jan 24, 2022 6:55 pm
Forum:General
Topic:OVPN site to site routing issue
Replies:1
Views:613

OVPN site to site routing issue

我有一个奇怪的(至少对我来说)问题site to site setup using OVPN (Mikrotik to Mikrotik). The tunnel is up and from Site A I can reach the subnet on Site B. However from site B I can not reach the site A subnet. Yet from router B I can reach subnet A, but not from the devices "beh...
byatakacs
Tue Jan 18, 2022 11:28 am
Forum:Beginner Basics
Topic:Internet failover bast practice
Replies:7
Views:1868

Re: Internet failover bast practice

Thanks - most instructive for the newbee that I am
byatakacs
Tue Jan 18, 2022 10:50 am
Forum:Beginner Basics
Topic:User/pass not preserved in backup ?
Replies:8
Views:2825

Re: User/pass not preserved in backup ?

Oh ok did not realise that backup went up to MAC assignments - it would indeed be problematic.

But if I am going to swap two routers with exact same model I can do a backup -> restore ?
byatakacs
Sun Jan 16, 2022 10:34 pm
Forum:Beginner Basics
Topic:User/pass not preserved in backup ?
Replies:8
Views:2825

Re: User/pass not preserved in backup ?

Also, it is not a good practice to return a .backup from one router to another.
Even to same hardware that is mean to replace the original ?
byatakacs
Sun Jan 16, 2022 10:33 pm
Forum:Beginner Basics
Topic:Internet failover bast practice
Replies:7
Views:1868

Re: Internet failover bast practice

The second scenario
byatakacs
Sun Jan 16, 2022 6:40 pm
Forum:Beginner Basics
Topic:Internet failover bast practice
Replies:7
Views:1868

Internet failover bast practice

I have two ISP delivering internet to my site and and have their respective links connected to ETH1 and ETH2 of my router.

What is the "best" way to have automatic switchover between the two WAN (say based on a ping of a "known good host") ?
byatakacs
Sun Jan 16, 2022 6:37 pm
Forum:Beginner Basics
Topic:User/pass not preserved in backup ?
Replies:8
Views:2825

User/pass not preserved in backup ?

Probably a dumb question but are user/pass preserved in backups ? I have a brand new CCR1009-7G on which i have restored a (password protected) backup from another CCR and although it seems to have the config loaded I can't connect to is with the same credentials that are working on the original rou...
byatakacs
Thu Jan 13, 2022 6:22 pm
Forum:General
Topic:After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working
Replies:45
Views:20278

Re: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working

Was there any resolution to that ? Still pretty much seeing the same problem :/
byatakacs
Thu Jan 13, 2022 6:19 pm
Forum:RouterOS beta and rc versions
Topic:7.2rc2 pulled ?
Replies:5
Views:2494

Re: 7.2rc2 pulled ?

ok - sorry for the "noise"
byatakacs
Thu Jan 13, 2022 10:25 am
Forum:RouterOS beta and rc versions
Topic:7.2rc2 pulled ?
Replies:5
Views:2494

7.2rc2 pulled ?

I'm pretty sure I have seen a 7.2rc2 yesterday in the testing "train" and was about to install in on our lab setup... but no seeing it anymore !? Was it pulled ?
byatakacs
2021年12月21日星期二7:32点
Forum:Announcements
Topic:v7.1.1 is released!
Replies:445
Views:209013

Re: v7.1.1 is released!

Any update / input / remark / comment on the IPSec issues lots of people are having ?
byatakacs
Tue Dec 21, 2021 8:09 am
Forum:General
Topic:After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working
Replies:45
Views:20278

Re: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working

Some "official" response would indeed be appreciated...
byatakacs
Tue Dec 21, 2021 8:08 am
Forum:General
Topic:Site to Site IPsec failing - worse with 7.1
Replies:2
Views:977

Re: Site to Site IPsec failing - worse with 7.1

Thanks for the pointer - my issue is a bit different insofar as the tunnel is actually working for a while but eventually stops. I even have witnessed article failure, ie. some subnets continue to work when others stop. Not good :/
byatakacs
Mon Dec 20, 2021 1:43 pm
Forum:General
Topic:Site to Site IPsec failing - worse with 7.1
Replies:2
Views:977

Site to Site IPsec failing - worse with 7.1

I am having a worsening issue by which an IPsec tunnel I have between our local CCR-1009-8G and an Ubiquiti USG Pro is randomly - but regularly - silently failing. By silently failing I mean that the traffic simply stops flowing - the peer seems still up, there is nothing apparent (maybe I need more...
byatakacs
Thu Dec 02, 2021 8:22 am
Forum:General
Topic:Confused about DHCP server
Replies:15
Views:1903

Re: Confused about DHCP server

I dont think its possible or wise to attach your VPN connections to bridges. Simply make the firewall rules you need to allow connectivity from VPN access to LAN subnets and vice versa etc...... (...) Seems like you have many tunnels. So use firewall rules for VPN tunnel to LAN connectivity So use ...
byatakacs
Thu Dec 02, 2021 8:14 am
Forum:Beginner Basics
Topic:How would you go about this - 2 separate nets 1 router
Replies:3
Views:972

Re: How would you go about this - 2 separate nets 1 router

Very feasible, the only question I have is why are the two VLANS 'open' to each other.
Ok... what woud be your approach to this ?
Why not just have one LAN then?
公平问题问题——我们希望能够费尔ter between the two or even to split (obviously loosing the redudency)
byatakacs
Wed Dec 01, 2021 6:00 pm
Forum:Beginner Basics
Topic:How would you go about this - 2 separate nets 1 router
Replies:3
Views:972

How would you go about this - 2 separate nets 1 router

Hello I have a CCR 1009-8G on which I want to achieve the following config. 2 WAN connections - WAN1 to ETH1, WAN2 to ETH8 2 LAN connections - say LAN1 to ETH2 and LAN2 to ETH7 Each LAN independent (with NAT and unroutable address space - say 192.168.100.0/24 and 192.168.200.0/24) - LAN1 access inte...
byatakacs
Wed Dec 01, 2021 8:24 am
Forum:General
Topic:Confused about DHCP server
Replies:15
Views:1903

Re: Confused about DHCP server

Hello Many thanks for taking the time to review my config ! I am still obviously learning Mikrotik and any and all input is much appreciated ! (1) Your are missing one thing....... Maybe? /interface list member add interface=ether1 list=WAN add interface=bridgeNet1 list=LAN add interface=bridgeNet2 ...
byatakacs
Tue Nov 30, 2021 12:23 pm
Forum:General
Topic:Confused about DHCP server
Replies:15
Views:1903

Re: Confused about DHCP server

VLANs would be another option, with everything on the same bridge but VLAN'ed off from each other.
Yep - good idea.

Still not completely sure this isn't some bug (or at minimum an "edge case")
byatakacs
Tue Nov 30, 2021 11:48 am
Forum:General
Topic:Confused about DHCP server
Replies:15
Views:1903

Re: Confused about DHCP server

Found my issue
Code:Select all
add name=dhcp-Net2 ranges=192.168.0.101-192.198.0.199
Typo here:((

That being said not sure the DHCP server should serve from another unrelated pool ...
byatakacs
Tue Nov 30, 2021 10:32 am
Forum:General
Topic:Confused about DHCP server
Replies:15
Views:1903

Re: Confused about DHCP server

Here we go - pretty basic IMHO # nov/30/2021 09:21:18 by RouterOS 7.1rc7 # software id = 018C-7TFP # # model = CCR1009-8G-1S-1S+ # serial number = **** /interface bridge add name=bridgeNet2 add name=bridgeNet1 /interface ethernet set [ find default-name=ether1 ] comment=WAN1 set [ find default-name=...
byatakacs
Tue Nov 30, 2021 9:58 am
Forum:General
Topic:Confused about DHCP server
Replies:15
Views:1903

Confused about DHCP server

Hello I'm seeing something unexpected with my DHCP server. I have two servers defined, bound to two different networks and adapters: [mktadmin@mkt-sx-00] /ip/dhcp-server> print Columns: NAME, INTERFACE, ADDRESS-POOL, LEASE-TIME # NAME INTERFACE ADDRESS-POOL LEASE-TIME 0 dhcp-Net1 bridgeNet1 dhcp-Net...
byatakacs
Sat Nov 27, 2021 11:20 am
Forum:RouterOS beta and rc versions
Topic:v7.1rc7 [development] is released!
Replies:174
Views:50367

Re: v7.1rc7 [development] is released!

Do you see anything that should not me here ? [xxx@mkt-sx-00] /system package> print Flags: X - disabled # NAME VERSION SCHEDULED 0 routeros-tile 6.49.1 1 system 6.49.1 2 ipv6 6.49.1 3 wireless 6.49.1 4 hotspot 6.49.1 5 mpls 6.49.1 6 routing 6.49.1 7 ppp 6.49.1 8 dhcp 6.49.1 9 security 6.49.1 10 adv...
byatakacs
Sat Nov 27, 2021 12:51 am
Forum:RouterOS beta and rc versions
Topic:v7.1rc7 [development] is released!
Replies:174
Views:50367

Re: v7.1rc7 [development] is released!

Was rc7 pulled ?

I could download earlier today but not now (2300 GMT) ?
byatakacs
Fri Nov 26, 2021 3:23 pm
Forum:Beginner Basics
Topic:Best site to site sertup
Replies:5
Views:1713

Re: Best site to site sertup

Thanks - didn't realise Wireguard was now proposed by RouterOS.
byatakacs
Thu Nov 25, 2021 10:16 pm
Forum:Beginner Basics
Topic:Best site to site sertup
Replies:5
Views:1713

Best site to site sertup

I’d be interested to hear about your opinion about the best protocol to use to site to site VPN. This is Mikrotik to Mikrotik. Each side has multiple subnets. By “best” I mean Easy to setup Performance Reliability I have a few IPSec setups that work but I find them rather hard to setup - and some ju...
byatakacs
Thu Nov 25, 2021 10:09 pm
Forum:RouterBOARD hardware
Topic:RB1100AHx4 IPsec site-to-site performance
Replies:4
Views:4644

Re: RB1100AHx4 IPsec site-to-site performance

i recommend you use CHR. I already use several CHR routers on 1Gbps WAN links with GRE+IPsec tunnels (aes-128 gcm). Even with 1vCPU routers can 950Mbps.
That's rather impressive.
byatakacs
Mon Jul 26, 2021 8:37 pm
Forum:General
Topic:Site to Site IPsec - muti subnet routing & capturing
Replies:4
Views:921

Re: Site to Site IPsec - muti subnet routing & capturing

谢谢我恐怕这是略高于my "paygrade" (or more to the point my level of competency). I dont think there is any issue with the WAN link between the two sites - both are on a Gb symmetric fiber with high level SLA. Ping is stable between both sites and absolutely &qu...
byatakacs
Mon Jul 26, 2021 1:05 pm
Forum:General
Topic:Site to Site IPsec - muti subnet routing & capturing
Replies:4
Views:921

Site to Site IPsec - muti subnet routing & capturing

Hello I need to setup a site to site VPN where the Mikrotik router holds multiple subnets. The remote site is managed via a Ubiquiti USG. https://i.imgur.com/stu35Ls.png Overall I have this setup on the mikrotik https://i.imgur.com/Pp4nkr5.png The tunnel is established but I have a hard time reachin...
byatakacs
Fri Jun 11, 2021 12:09 pm
Forum:Beginner Basics
Topic:Winbox 64 bits ?
Replies:3
Views:813

Re: Winbox 64 bits ?

Understood - thanks
byatakacs
Fri Jun 11, 2021 11:56 am
Forum:Beginner Basics
Topic:Confused about chains
Replies:19
Views:2085

Re: Confused about chains

Thans for all those excellent advises that I am implenting as we speak !
A bit of a thread drift but how do you do port knocking in mikrotk ?
byatakacs
Fri Jun 11, 2021 12:33 am
Forum:General
Topic:OVPN site-to-site return route ?
Replies:6
Views:810

Re: OVPN site-to-site return route ?

Might be a little thick but can i push return routes on the OVPN server from the client ?! I so how ?
byatakacs
Fri Jun 11, 2021 12:13 am
Forum:Beginner Basics
Topic:Confused about chains
Replies:19
Views:2085

Confused about chains

Hi My very fist firewall filter rule is [xxx@mkt-sx-00] /ip firewall filter> print Flags: X - disabled, I - invalid, D - dynamic 0 ;;; drop blacklisted chain=forward action=drop src-address-list=DenyLIst log=yes log-prefix="deny-" I have IP 190.6.38.79 in my DenyLIst yet it seem to find a ...
byatakacs
Fri Jun 11, 2021 12:05 am
Forum:Beginner Basics
Topic:Winbox 64 bits ?
Replies:3
Views:813

Winbox 64 bits ?

Hi

Probably a stupid quesiton... but what's the point of a 64bits Winbox ? what use case / config would require it ?

Just curious :)
byatakacs
Fri Jun 11, 2021 12:04 am
Forum:General
Topic:OVPN site-to-site return route ?
Replies:6
Views:810

Re: OVPN site-to-site return route ?

You can include them in the .ovpn configuration, e.g. route 192.168.99.0 255.255.255.0 vpn_gateway
This is mikrotik to mikrotik - are there ovpn config files involved (I only ibnteract with the Winbox GUI or CLI) ?
byatakacs
Wed Jun 09, 2021 12:36 pm
Forum:General
Topic:OVPN site-to-site return route ?
Replies:6
Views:810

Re: OVPN site-to-site return route ?

hmm so what choices do I have ?
write a script that add those routes ?
byatakacs
Wed Jun 09, 2021 1:45 am
Forum:General
Topic:OVPN site-to-site return route ?
Replies:6
Views:810

OVPN site-to-site return route ?

Hello I have a setup with a site to site OpenVPN tunnels which require static routing (ie to subnets “behind” the Ovpn). On the client side I am using the parameter routes on the /ppp secret row, where I can specify a destination gateway. This works fine to route from the client subnet(s) to the ser...
byatakacs
Sun May 16, 2021 5:34 pm
Forum:General
Topic:“诱导多能性”ec Policies with multiple subnets
Replies:1
Views:1904

“诱导多能性”ec Policies with multiple subnets

I have a working IPSec site to site VPN and I now need to make a second subnet available behind one of the routers. As far as I understand the IPSec Policy only maps 1:1 (ie one source to one destination subnet) I have tried to duplicate the policy but although the new one would work this kills the ...
byatakacs
Sun May 16, 2021 5:29 pm
Forum:General
Topic:Cloutik feedback ?
Replies:20
Views:5226

Re: Cloutik feedback ?

I agree that the website doesn't inspire much confidence... that's why I was asking forfeedback... of which I got none. I guess in and itself it is already saying something :)
byatakacs
Wed Apr 14, 2021 2:48 pm
Forum:General
Topic:Cloutik feedback ?
Replies:20
Views:5226

Re: Cloutik feedback ?

Thanks for the feedback so far. I understand & appreciate the limits / issues that such a concept is raising. What I wanted to hear was actualy first hand experience with it (or equivelent product). Out of curiousity, how are the "real pro" handling this when you have hundreds of devic...
byatakacs
Tue Apr 13, 2021 7:46 pm
Forum:General
Topic:Cloutik feedback ?
Replies:20
Views:5226

Cloutik feedback ?

Hi

Not seeing much discussion about this service here.

Anyone using it ? Feedback ? Issues ?

Thanks in advance !
byatakacs
Mon Mar 22, 2021 7:54 pm
Forum:General
Topic:Static routes via non persistent connections
Replies:2
Views:524

Re: Static routes via non persistent connections

Maybe - let me give it a try (it might be all I need it this worksevery time a client connects)
byatakacs
Mon Mar 22, 2021 2:32 pm
Forum:General
Topic:Static routes via non persistent connections
Replies:2
Views:524

Static routes via non persistent connections

Hello I have a setup with some site to site OpenVPN tunnels which require static routing (ie to subnets “behind” the Ovpn. Everything works perfectly except that sometime the Ovpn tunnel will go down and will become “unreachable” in the static routes. When it reconnects the route remains down and I ...
byatakacs
Sun Mar 21, 2021 3:00 pm
Forum:General
Topic:[Resolved] OVPN s-t-s having cert issue ?
Replies:1
Views:2721

Re: [Resolved] OVPN s-t-s having cert issue ?

If anyone happens to have the same issue: I was somehow missing the matching private key on the client router (thought I had it transferred but turned out not to be the case).
Still wish we could have a more explicit log entry...
byatakacs
Thu Mar 18, 2021 8:36 pm
Forum:General
Topic:[Resolved] OVPN s-t-s having cert issue ?
Replies:1
Views:2721

[Resolved] OVPN s-t-s having cert issue ?

Hello Trying to setup a site to site OVPN but for some reason I can't seem to have both router connecting. On server I see: 18:55:52 ovpn,info TCP connection established from *.*.*.* 18:55:52 ovpn,debug,packet sent P_CONTROL_HARD_RESET_SERVER_V2 kid=0 sid=cb632957515156 pid=0 DATA len=0 18:55:52 ovp...
byatakacs
Thu Mar 18, 2021 8:17 pm
Forum:General
Topic:Multi site-to-site setup advice
Replies:8
Views:1314

Re: Multi site-to-site setup advice

Typing in the IP of any shared resource connects to and from... But you have to know what you are looking for.
Yep - I guess we will have to settle to that solution. IP could be assigned based on the MAC of each device (there are not that many of them)... but we would have loved to step it up :)
byatakacs
Wed Mar 17, 2021 5:30 pm
Forum:General
Topic:Multi site-to-site setup advice
Replies:8
Views:1314

Re: Multi site-to-site setup advice

Any further thoughts on this ? :)
byatakacs
Wed Mar 17, 2021 5:29 pm
Forum:General
Topic:Mutiple SSTP servers
Replies:4
Views:862

Re: Mutiple SSTP servers

In a few words the router (CCR) is servicing multiple, segregated, subnets. I wanted to give SSTP VPN access to the various users of said unrelated subnets - different user / pass / cert - based on the the public IP.
byatakacs
Wed Mar 17, 2021 10:20 am
Forum:General
Topic:Mutiple SSTP servers
Replies:4
Views:862

Re: Mutiple SSTP servers

Thanks for confirming.
byatakacs
Wed Mar 17, 2021 1:28 am
Forum:General
Topic:Mutiple SSTP servers
Replies:4
Views:862

Mutiple SSTP servers

Hello

Is is possible to have mutiple SSTP servers ?

I have a range of public IPs and currently run SSTP server bound to one of the public IP. Can I have more than one server, bound to a different IP. I guess not but just checking...
byatakacs
Mon Mar 15, 2021 12:43 am
Forum:General
Topic:Multi site-to-site setup advice
Replies:8
Views:1314

Re: Multi site-to-site setup advice

Hi Thanks for your interest :) Well, let’s indeed assume 5 warehouses. Each have their unique network with unique subnet - very basic needs (some local LAN devices, internet access). Then we have some unique “line of business” hardware that needs to be able to roam across those 5 warehouses at any t...
byatakacs
Sun Mar 14, 2021 3:00 pm
Forum:General
Topic:Multi site-to-site setup advice
Replies:8
Views:1314

Re: Multi site-to-site setup advice

与multip很接近le warehouses - we will need a specific (dedicated) network (in pratice a specific ETH attached to the router) to allow connecting and "seeing" across all the other locations at any given point. In essece whereever you are, assuming you plug into the "right&quo...
byatakacs
Sat Mar 13, 2021 8:03 pm
Forum:General
Topic:Multi site-to-site setup advice
Replies:8
Views:1314

Multi site-to-site setup advice

Hello I would like to setup a site-to-site setup to deploy around all of the remote sites where all “local” subnets would “see” each other, as well as the “hub” site (idealy with Bonjour/mDNS working across the subnets): https://i.imgur.com/uNA6je2.jpg What would be the best approach for such a setu...
byatakacs
Sat Mar 13, 2021 7:37 pm
Forum:Forwarding Protocols
Topic:OSPF Linux MikroTik
Replies:6
Views:4951

Re: OSPF Linux MikroTik

Did you manage to sort out this issue ?

I gather you are usinghttps://pritunl.com/(which I am looking into) ?
byatakacs
Mon Mar 08, 2021 5:59 pm
Forum:Announcements
Topic:Future of LTE products, user feedback requested
Replies:206
Views:92958

Re: Future of LTE products, user feedback requested

Wow... lots of options :)

Any input as of which would be the most relevant for use in Switzerland (Swisscom or Surise) ?
byatakacs
Tue Jan 26, 2021 3:55 pm
Forum:Beginner Basics
Topic:IP sec negociation error
Replies:6
Views:1451

Re: IP sec negociation error

Thanks - yes it seems I will need both ends of the conversation.

That being said I see
Code:Select all
04:47:41 ipsec,debug -an acceptable proposal found- 04:47:41 ipsec,debug dh(modp1024) 04:47:41 ipsec,debug -agreed on pre-shared key auth-
so there is _some_ handshake going on.
byatakacs
Tue Jan 26, 2021 2:56 pm
Forum:Beginner Basics
Topic:IP sec negociation error
Replies:6
Views:1451

Re: IP sec negociation error

Thanks - good catch on both points. Corrected - still not conencting, athough the hadshake seem to work ok. I can't pinpoint at what step if actually fails... 13:32:58 ipsec,debug === 13:32:58 ipsec,info initiate new phase 1 (Identity Protection): *.*.*.*[500]<=>*.*.*.*[500] 13:32:58 ipsec,debug new...
byatakacs
Mon Jan 25, 2021 6:24 am
Forum:Beginner Basics
Topic:IP sec negociation error
Replies:6
Views:1451

Re: IP sec negociation error

I am probably blind. Where does it say that it fails? See last line " error phase1 negotiation failed due to time up " Also during the whole "handshake" phase it stays on https://i.imgur.com/ETuUGgd.png From my own experience - you should check logs on both sides. They might not...
byatakacs
Fri Jan 22, 2021 4:05 pm
Forum:Beginner Basics
Topic:IP sec negociation error
Replies:6
Views:1451

IP sec negociation error

Hi Trying to setup a site to site VPN and despite what I believe to be similar settings on both ends (Mikrotik to Zywall 110) the negociation fails. 04:47:41 ipsec,info initiate new phase 1 (Identity Protection): *.*.*.*[500]<=>*.*.*.*[500] 04:47:41 ipsec,debug new cookie: 04:47:41 ipsec,debug 77412...
byatakacs
Mon Nov 30, 2020 11:37 pm
Forum:Beginner Basics
Topic:Locked out of ssh/winbox... but how ?
Replies:6
Views:1105

Re: Locked out of ssh/winbox... but how ?

Thanks - that's a neat trick I will make a note of.
I eventually restored a known working backup - I'm still not exactly sure of what I broke there (is there some sort of "diff" tool ?) but it worked out of the box and I simply re-applied the few changes I had since.
byatakacs
Fri Nov 27, 2020 8:04 pm
Forum:Beginner Basics
Topic:Locked out of ssh/winbox... but how ?
Replies:6
Views:1105

Re: Locked out of ssh/winbox... but how ?

Any suggestion ? What can I "trace" to see why my connections are not going through ? Bit strange...
byatakacs
Wed Nov 25, 2020 10:09 pm
Forum:Beginner Basics
Topic:Locked out of ssh/winbox... but how ?
Replies:6
Views:1105

Locked out of ssh/winbox... but how ?

Probably a dumb question but can't figure it out... for some reason I seem to be locked out of ssh / winbox on my router from LAN. Thankfully I have console access but still can't see what is blocking me... I can ping the box from LAN and traffic is flowing ssh & winbox services are active I hav...
byatakacs
Mon Nov 16, 2020 10:30 am
Forum:General
Topic:are this rules on the top mandatory?
Replies:62
Views:5568

Re: are this rules on the top mandatory?

Just wanted to say that I find this thread both fascinating and instructive :)
byatakacs
Sat Nov 14, 2020 6:38 pm
Forum:General
Topic:Mikrotik Captive Portal best practice
Replies:0
Views:443

Mikrotik Captive Portal best practice

I have inherited a few hotel sites running Mikrotik infra with captive portal for WiFi access for their guests. Although things seem to be mostly working ok I suspect some users are managing to bypass the portal to get “unauthorised” internet access. I am trying to understand and locate those possib...
byatakacs
Thu Nov 05, 2020 9:05 am
Forum:Beginner Basics
Topic:About VPN automatic (?) routes
Replies:8
Views:1111

Re: About VPN automatic (?) routes

Thanks - sounds like a clever approach. I have added the rule and there is some progress as packets to subnet 172.16.107.0/24 are not anymore egressing to WAN but are just lost. Can I use /tool sniffer to check if they are actually getting into the tunnel (which would point with an issue with the re...
byatakacs
Thu Nov 05, 2020 1:47 am
Forum:Beginner Basics
Topic:About VPN automatic (?) routes
Replies:8
Views:1111

Re: About VPN automatic (?) routes

I am getting back to his subject as I am clearly still not fully understanding how this is supposed to work. I have an IPsec site-to-site setup where the tunnel comes up ok but I don't have any traffic into the tunnel. If I do a traceroute I see that my packet are (obviously) getting to the gateway ...
byatakacs
Tue Nov 03, 2020 3:03 pm
Forum:General
Topic:Routing issue with PPTP site to site
Replies:4
Views:733

Re: Routing issue with PPTP site to site

To find out whether the issue is at Mikrotik side or the USG side, run /tool sniffer quick interface= ip-protocol=icmp while pinging something else than 172.16.107.254 in 172.16.107.0/24 from 172.16.100.0/24. If you can see ICMP packets towards the pinged IP, the issue is at USG side;...
byatakacs
Mon Nov 02, 2020 6:17 pm
Forum:General
Topic:Routing issue with PPTP site to site
Replies:4
Views:733

Re: Routing issue with PPTP site to site

hmm can't seem to figure it out. I wouldreallyappreciate any suggestion
byatakacs
Fri Oct 30, 2020 12:44 pm
Forum:General
Topic:Routing issue with PPTP site to site
Replies:4
Views:733

Routing issue with PPTP site to site

Hello I'm having a routing issue with a PPTP site to site VPN (between a USG pro and a Mikrotik, and I feel the issue is on the Mikrotik side). On the USG side I have subnet 172.16.107.0/24 with GW 254 On the Mikrotik side I have subnet 172.16.100.0/24 with GW 254 The tunnel comes up without problem...
byatakacs
于2020年10月17日坐一14点
Forum:Beginner Basics
Topic:About VPN automatic (?) routes
Replies:8
Views:1111

Re: About VPN automatic (?) routes

Many thanks for your explanations ! Most educative !
byatakacs
Fri Oct 16, 2020 4:46 pm
Forum:Beginner Basics
Topic:About VPN automatic (?) routes
Replies:8
Views:1111

Re: About VPN automatic (?) routes

Thanks - good starting point for my understanding.

When you say "everything adds routes" do you mean "automatically" or "needed to be explicitly added" ?

Is the policy matcher triggering before the IP routes ?
byatakacs
Fri Oct 16, 2020 9:50 am
Forum:Beginner Basics
Topic:About VPN automatic (?) routes
Replies:8
Views:1111

About VPN automatic (?) routes

Hello I am a bit confused about how (if at all) VPN connections are creating automatic routes in the router and to what extent I have to manage them. My question pertains to PPTP, IPsec and SSTP (I do not use OpenVPN but as we are at it I would be interested to read about it too...). My (admittedly ...
byatakacs
Wed Sep 30, 2020 5:34 pm
Forum:Beginner Basics
Topic:L2tp/IPsec up but can't reach subnet (windows 10 client)
Replies:3
Views:791

Re: L2tp/IPsec up but can't reach subnet (windows 10 client)

It depends. In case the client gets IP address from LAN subnet, you need proxy ARP on LAN interface. Firewall can also be the cause.
Aha - yes they do get IP from the same pool that serves the LAN subnet. Is that not best practice ?
byatakacs
Wed Sep 30, 2020 12:41 am
Forum:Beginner Basics
Topic:L2tp/IPsec up but can't reach subnet (windows 10 client)
Replies:3
Views:791

L2tp/IPsec up but can't reach subnet (windows 10 client)

Hi I have setup a L2TP VPN server on my Mikrotik for use with a Win 10 client to connect. I can initiate the tunnel & connect successfully. I get an IP in the expected subnet from the expected IP pool. My traffic is actually redirected through the VPN gateway (it is by default gateway) - all see...
byatakacs
Wed Sep 30, 2020 12:36 am
Forum:Beginner Basics
Topic:A routing conundrum
Replies:10
Views:1358

Re: A routing conundrum

Some things you should try to do yourself atleast, below is where you can change the default route distance on a DHCP client
More than happy to do so and to learn but quite frankly had no idea how to change the default route distance on a DHCP client... Thanks for your help there !
byatakacs
Tue Sep 29, 2020 11:36 am
Forum:Beginner Basics
Topic:A routing conundrum
Replies:10
Views:1358

Re: A routing conundrum

Next question is how do I achieve it ? Those automatic routes don't seem to be "editable", at least not from Winbox...
Anyone ... ?
byatakacs
Sun Sep 27, 2020 11:55 am
Forum:Beginner Basics
Topic:A routing conundrum
Replies:10
Views:1358

Re: A routing conundrum

I'll probably go with a) as it seems to be the easiest way to get things working (in any case this is only a short term project).

Next question is how do I achieve it ? Those automatic routes don't seem to be "editable", at least not from Winbox...
byatakacs
Sat Sep 26, 2020 8:54 pm
Forum:Beginner Basics
Topic:A routing conundrum
Replies:10
Views:1358

Re: A routing conundrum

Thanks for your detailed answer - let me try to understand (as there is an obvious educational opportunity here :) ) - clients' 10.2.0.x are only point to point /32 addresses, so other 10.2.0.y are not automatically reachable as part of same subnet, they are routed via B Ok - understood - client A h...
byatakacs
Sat Sep 26, 2020 2:54 pm
Forum:Beginner Basics
Topic:A routing conundrum
Replies:10
Views:1358

Re: A routing conundrum

Disabled firewall - not working
byatakacs
Sat Sep 26, 2020 2:26 pm
Forum:Beginner Basics
Topic:A routing conundrum
Replies:10
Views:1358

A routing conundrum

I am having the following setup https://i.imgur.com/6KXJbEy.jpg A is a windows workstation connected to a linux box (B) via a L2TP VPN tunnel C is a Mikrotik router connect to the same linux box (B) via a L2TP VPN tunnel D is a server connected the the LAN side of C The IP are assigned as indicated ...
byatakacs
Tue Jul 28, 2020 10:57 am
Forum:RouterOS beta and rc versions
Topic:v7.1beta1 [development] is released!
Replies:103
Views:54370

Re: v7.1beta1 [development] is released!

Cosmetic error on a RB1100AHx4 in Winbox under System>Health. It's showing 49.5 amps. Terminal is showing 495 ma.
Oh- was about to ask for an upgrade from our electric provider:)
byatakacs
Tue Jul 28, 2020 10:52 am
Forum:Beginner Basics
Topic:,ovpn config to mikrotik vpn client
Replies:2
Views:4589

Re: ,ovpn config to mikrotik vpn client

Many thanks - I have managed to have it working !
byatakacs
Mon Jul 27, 2020 11:51 pm
Forum:Beginner Basics
Topic:,ovpn config to mikrotik vpn client
Replies:2
Views:4589

,ovpn config to mikrotik vpn client

Hi I have the following (working) ovpn client config file that I'd like to use from the Mikrotik OpenVPN client (which does - obviously ? - not understand ovpn files) dev tun persist-tun persist-key cipher AES-128-CBC ncp-ciphers AES-256-GCM:AES-128-GCM auth SHA1 tls-client client resolv-retry infin...
byatakacs
2020年7月23日星期四3:20 pm
Forum:Beginner Basics
Topic:PPTP tunel up but no traffic
Replies:0
Views:523

PPTP tunel up but no traffic

Hi I'm trying to setup a site to site connection via PPTP but although I managed to have it connecting very quickly I don't have traffic flowing. On relevant item is that I don't see addresses assigned to either peers (although I defined a valid pool for both). https://i.imgur.com/KRxb4rM.jpg https:...
byatakacs
Thu Jul 23, 2020 12:39 pm
Forum:Beginner Basics
Topic:Dynamic ip site to site ipsec help
Replies:8
Views:9371

Re: Dynamic ip site to site ipsec help

I'm a bit confused about this. How is the new IP "passed" to the other peer ? I understand that you check the local IP and if it change you modify the IPsec profiles - locally it is pretty trivial but how do you "signal" the remote peer to adapt ?`
byatakacs
Wed Jun 24, 2020 2:18 am
Forum:General
Topic:About IPsec and routing
Replies:4
Views:1394

Re: About IPsec and routing

Thanks for this detailed explanation ! Sorry for my somewhat unclear initial description - I wanted to keep it generic. In the case at hand subnet A is 172.16.10.0/24 and subnet B is 172.16.100.0/24. A to B works, B to A does not. Will review my settings per your suggestion and revert.
byatakacs
Wed Jun 24, 2020 2:16 am
Forum:Beginner Basics
Topic:Winbox NAT subtility
Replies:5
Views:1780

Re: Winbox NAT subtility

Well it might not make much sense but it is happening right in front of my eyes... 100% reproducible. I can switch between both states at will.

One thing of interrest is that I use SSTP server on said router (which is also on 443 I understand). I think it is somehow realated.
byatakacs
Tue Jun 23, 2020 11:20 pm
Forum:General
Topic:About IPsec and routing
Replies:4
Views:1394

Re: About IPsec and routing

well I have this
Image
the Azure policy works (site to site to Azure)
the IM office does not (site to site Mk)
byatakacs
Tue Jun 23, 2020 11:01 pm
Forum:Beginner Basics
Topic:Winbox NAT subtility
Replies:5
Views:1780

Re: Winbox NAT subtility

Thanks - my "solution" (a separate rule for 443) works well enough as is.

What I'd like to understand is what is actually happening "behind the scene" so to speak. What I do differently in setting up a single port vs multi-port NAT rule ?
byatakacs
Tue Jun 23, 2020 10:35 pm
Forum:General
Topic:About IPsec and routing
Replies:4
Views:1394

About IPsec and routing

Hi Currently setting up a site to site VPN and I'm having an issue which seems to be related to routing. The tunnel comes up and I can ping from site A to site B. However I can not reach site A from site B. If I do a traceroute from site B the packets to site A are egressing on the WAN - ie the rout...
byatakacs
Tue Jun 23, 2020 10:20 pm
Forum:Beginner Basics
Topic:Winbox NAT subtility
Replies:5
Views:1780

Winbox NAT subtility

I am in need of some clarification about the syntax to use in a Firewall / NAT rule. I have this (typical for an Exchange server) rule: https://i.imgur.com/dYWcbRC.jpg https://i.imgur.com/hkx1Dlo.jpg That does not work as intended. Ports 25,465,587 and 2525 are forwarded to 172.16.100.20 but 443 end...
byatakacs
Wed May 27, 2020 5:54 pm
Forum:Beginner Basics
Topic:Syntax problem add IPsec Peer
Replies:1
Views:783

[SOLVED] Re: Syntax problem add IPsec Peer

ok self solved...

it was the use of < and > in the IP addresses .... a no no !
byatakacs
Wed May 27, 2020 5:50 pm
Forum:Beginner Basics
Topic:这NAT命令怎么了?
Replies:5
Views:1593

[SOLVED] Re: What's wrong with this NAT command ?

Thanks - that was it !
byatakacs
Wed May 27, 2020 1:54 pm
Forum:Beginner Basics
Topic:这NAT命令怎么了?
Replies:5
Views:1593

Re: What's wrong with this NAT command ?

Because characters < and > shouldn't be there. It's just dst-address=172.16.175.0/24. Right you are - interestingly they would not matter if you enter a single IP, such as in /ip ipsec peer add address=<1.2.3.4> exchange-mode=ike2 local-address=<5.6.7.8> \ name="Somethng" profile="So...
byatakacs
2020年5月27日结婚28点啊
Forum:Beginner Basics
Topic:Syntax problem add IPsec Peer
Replies:1
Views:783

Syntax problem add IPsec Peer

Hi /ip ipsec policy add dst-address=<172.16.175.0/24> peer="myPeer" proposal="myProposal" sa-dst-address=<1.2.3.4> sa-src-address=<5.6.7.8> src-address=<172.16.100.0/24> tunnel=yes expected end of command (line 1 column 35) Having a syntax issue - apparently the "peer" ...
byatakacs
Wed May 27, 2020 12:17 am
Forum:Beginner Basics
Topic:这NAT命令怎么了?
Replies:5
Views:1593

这NAT命令怎么了?

Probably a dumb question but why does this fail
Code:Select all
[me@mikrotik.contoso.com] /ip firewall nat> add action=accept chain=srcnat comment="Something" dst-address=<172.16.175.0/24> src-address=<172.16.100.0/24> value of range must have ip address before '/'

Thanks
byatakacs
Tue May 26, 2020 10:58 pm
Forum:General
Topic:Loosing route setting at random
Replies:0
Views:802

Loosing route setting at random

I'm having a setup in which i establish an SSTP tunnel to a remote site and have a route set to reach the remote subnet (192.168.168.0/24 here) through that tunnel - works fine https://i.imgur.com/C1YRwvt.jpg However, at random intervals, I lose my setting - the route reverts to an "unknown&quo...
byatakacs
Tue May 26, 2020 4:13 pm
Forum:General
Topic:Azure VPN [SOLVED]
Replies:12
Views:23555

Re: Azure VPN[SOLVED]

may I ask how this was solved (I don't see a resolution, but I might be missing something:)) ?
byatakacs
Tue May 26, 2020 3:34 pm
Forum:General
Topic:Azure to OnPrem only working one way
Replies:1
Views:2060

Re: Azure to OnPrem only working one way

Hi did you manage to sort it out ? I seem to have the exact same issue. That being said my problem is (at least partially) on the Mikrotik side. If I do a traceroute to the private IP of the remote (Azure) subnet my packets are egressing through the WAN IP, not the trough the tunnel (which is up in ...
byatakacs
Tue Apr 21, 2020 1:26 am
Forum:Beginner Basics
Topic:Best practice for segregated VPN assigned to specific ETH
Replies:0
Views:1422

Best practice for segregated VPN assigned to specific ETH

Hi Bit of a newbie here... please bear with me. I have the following scenario: Internet WAN of ETH1. 2 LAN on ETH2 and ETH3 SSTP tunnel built from Mk to a server on WAN. I'd like to have one "classic" subnet on ETH2 with a DHCP range etc for LAN access to the Internet and another segregate...
byatakacs
Tue Apr 07, 2020 1:40 am
Forum:RouterBOARD hardware
Topic:Anyone using Huawei ME909s-120 mPCIe ?
Replies:5
Views:3294

Re: Anyone using Huawei ME909s-120 mPCIe ?

ok

do you know how I can "lock it" to a given network (MCC MNC 214 01 in my case) ? Some AT command I guess but not sure how to get there..
byatakacs
Fri Apr 03, 2020 3:23 pm
Forum:RouterBOARD hardware
Topic:Anyone using Huawei ME909s-120 mPCIe ?
Replies:5
Views:3294

Re: Anyone using Huawei ME909s-120 mPCIe ?

thanks - yes it seems to work.

did you manage to do a scan of available networks ?
byatakacs
Thu Apr 02, 2020 1:42 pm
Forum:RouterBOARD hardware
Topic:Anyone using Huawei ME909s-120 mPCIe ?
Replies:5
Views:3294

Re: Anyone using Huawei ME909s-120 mPCIe ?

Well I have managed to have it working but I think it has fairly limited support from ROS (many of the features don't work or are reported as not supported).

Again if anyone has any experience chime in !
byatakacs
Thu Apr 02, 2020 11:54 am
Forum:RouterBOARD hardware
Topic:Problem connecting to RB953GS
Replies:5
Views:2888

Re: Problem connecting to RB953GS

Thanks - it was indeed an issue with the Winbox version. 3.18 allowed me in - updated - all ok !
byatakacs
Wed Apr 01, 2020 12:22 am
Forum:RouterBOARD hardware
Topic:Problem connecting to RB953GS
Replies:5
Views:2888

Re: Problem connecting to RB953GS

Thanks

I might be a bit thick but I don't seem to find the note you are mentioning...
byatakacs
Tue Mar 31, 2020 11:51 pm
Forum:RouterBOARD hardware
Topic:Problem connecting to RB953GS
Replies:5
Views:2888

Problem connecting to RB953GS

Hi I am trying to "resurrect" a relatively (I'd say a 3-4 years) old RouterBoard RB953GS. For some reason I can't seem to be able to connect - after boot it comes up like this in Winbox https://i.imgur.com/e5sS8Mm.jpg but can't seem to actually connect. After a few minutes it altogether di...
byatakacs
Tue Mar 31, 2020 11:33 pm
Forum:RouterOS beta and rc versions
Topic:Feature Request - Wireguard Protocol
Replies:167
Views:78188

Re: Feature Request - Wireguard Protocol

Is there official position from Mikrotik about that ?

I think the overwhelming opinion of the community is very positive about Wireguard. Is it something you are exploring ? commiting to ? definitely not on the roadmap ?
byatakacs
Mon Mar 30, 2020 9:46 pm
Forum:RouterBOARD hardware
Topic:Anyone using Huawei ME909s-120 mPCIe ?
Replies:5
Views:3294

Anyone using Huawei ME909s-120 mPCIe ?

Hi

Anyone using one of those LTE modems with Mikrotik RouterBOARD ? Anything I should be aware of ?

Any feedback welcome !
byatakacs
Sun Mar 29, 2020 11:43 pm
Forum:General
Topic:Multi device routing question
Replies:9
Views:2702

Re: Multi device routing question

Sorry I muss be a little thick... What do you propose I do ?
There is no direct link A to C - everything comes either from B or through B. So I make a srcnat from 172.16.100.0/24 (B subnet) to 192.168.28.1 (D gateway) ?
byatakacs
Sun Mar 29, 2020 10:51 pm
Forum:General
Topic:Multi device routing question
Replies:9
Views:2702

Re: Multi device routing question

Is is possible that same router has both 192.168.199.247 and 192.168.199.3? Further hops depend on following routers, either they must have route to source address (I guess they don't), or you must use srcnat on the last one that does have it. You are correct: router C has both 192.168.199.247 and ...
byatakacs
Sun Mar 29, 2020 5:43 pm
Forum:General
Topic:Multi device routing question
Replies:9
Views:2702

Re: Multi device routing question

Ok back to the bench... So this is router B https://i.imgur.com/sDTlYOP.jpg https://i.imgur.com/lgpquCV.jpg I have defined a route to router C GW (which is 192.168.199.247) - yet my traffic goes to 192.168.199.3 (If I understand this correctly) and does not go further ? Back on the VPN question: if ...
byatakacs
Sun Mar 29, 2020 12:31 am
Forum:General
Topic:Multi device routing question
Replies:9
Views:2702

Re: Multi device routing question

Thanks
当你说" A和B都必须知道在哪里可以找到D's subnet (behind C is the answer)" you mean that I have to define a route to subnet D via GW C ?
Just for my understanding: does the VPN tunnel "auto-create" a route for each subnet on the other side?
byatakacs
Sat Mar 28, 2020 11:02 pm
Forum:General
Topic:Multi device routing question
Replies:9
Views:2702

Multi device routing question

Hi I have a (possibly obvious) routing question. I have a setup with four routers as below. Routes A, B and C are Mikrotik and under my control. Router D is unknown and not under my control (this is a setup I have recently "inherited"). Sorry for the crude schema... https://i.imgur.com/ISN...
byatakacs
Sat Mar 28, 2020 9:47 pm
Forum:RouterBOARD hardware
Topic:953GS 5HPnt ?
Replies:3
Views:2788

Re: 953GS 5HPnt ?

yep, that's the one - was wondering if it was a latter iteration of the design. Thanks.
byatakacs
Sat Mar 28, 2020 7:19 pm
Forum:RouterBOARD hardware
Topic:953GS 5HPnt ?
Replies:3
Views:2788

953GS 5HPnt ?

Hi

Having some time to sort through my equipment messes I have recently unhoardered a routerboard labelled 953GS 5HPnt

Image

Except that I can't find this reference on the Mikrotik site, nor in current or past hardware. Any hint ?

Thanks & regards
byatakacs
Thu Nov 07, 2019 10:30 am
Forum:General
Topic:Setting up site to site IPSEC to USG
Replies:2
Views:1720

Re: Setting up site to site IPSEC to USG

Thanks for your follow up - eventually managed to have it working but honestly can't remember what was the specific issue...
byatakacs
Sun Oct 27, 2019 1:49 pm
Forum:General
Topic:Setting up site to site IPSEC to USG
Replies:2
Views:1720

Setting up site to site IPSEC to USG

Hello
I am trying to define a site to site IPSEC to an Ubiquiti Security Gateway (USG Pro 4). I don't get too far...

Image

Anyone done that ? Seems something missing in the initial dialogue.
byatakacs
Tue Jun 12, 2018 12:51 pm
Forum:RouterBOARD hardware
Topic:SFP compativbility
Replies:0
Views:822

SFP compativbility

We are currently replacing our existing RB2011UAS-2HnD-IN by a CCR1009-7G-1C-+S+PC. Our fiber connection is delivered directly via this SFP module that was working absolutely flawlessly https://i.imgur.com/WmZDUt6.jpg but it does not seem to be recognised by the new router. Is this normal / expected...
byatakacs
Sun Aug 06, 2017 8:15 pm
Forum:Virtualization
Topic:CHR vs Virtualised VM ?
Replies:4
Views:4092

Re: CHR vs Virtualised VM ?

Thanks

We unfortunately don't run 10Gb yet so, as long as it works (which is the case so far), there would not be any significant advantage to move to CHR ?
byatakacs
Sun Aug 06, 2017 12:11 am
Forum:Virtualization
Topic:CHR vs Virtualised VM ?
Replies:4
Views:4092

CHR vs Virtualised VM ?

Hello

At some site we are currently running virtualized RouterOS instances on ESX since 2-3 years, ie. before CHR was released.

Overall this works fine but i was wondering if there was a case in migrating towards CHR ?

Any insight / advice you might have would be most welcome.

Baidu
map