Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
PUBLIC TOILET
Jun 13, 2009

falz posted:

You have to have two radios in a router if you want to have it be an AP and also bridge back to another.

Or the power line adapters instead. Thanks.

Adbot
ADBOT LOVES YOU

thebigcow
Jan 3, 2001

Bully!

PUBLIC TOILET posted:

Or the power line adapters instead. Thanks.

If this doesn't work out and you have coax in the walls don't forget MoCA adapters. The TiVo store is the cheapest place I've seen a pair.

Gorson
Aug 29, 2014

I know I've done this before but I can't figure out what I'm doing wrong. I've got a Mikrotik Groove-a here I bought for my brother to use as an additional outdoor access point to put in his network. He's using an off-the-shelf router to connect to the internet. I want clients to be able to connect to the Groove and get a DHCP address from the router and connect to the internet, but I can't get the Groove to function being set up as a simple access point, ie no routing no NAT on the Groove. Let's assume his internal network is 192.168.0.0/24.

thebigcow
Jan 3, 2001

Bully!

Gorson posted:

I know I've done this before but I can't figure out what I'm doing wrong. I've got a Mikrotik Groove-a here I bought for my brother to use as an additional outdoor access point to put in his network. He's using an off-the-shelf router to connect to the internet. I want clients to be able to connect to the Groove and get a DHCP address from the router and connect to the internet, but I can't get the Groove to function being set up as a simple access point, ie no routing no NAT on the Groove. Let's assume his internal network is 192.168.0.0/24.

latvia.com is down so I can't grab examples right now, but have you looked into the quickset options? It's the top button in winbox and I'm not sure where in the web interface. Home AP sounds about right for what you are describing.

jeeves
May 27, 2001

Deranged Psychopathic
Butler Extraordinaire
Looks like they're finally putting it a tiny bit of better patch management besides "Download bestest version"

6.29.1 will have just bug fixes of 6.29, versus before all new content (including new bugs) plus previous bug fixes would have gone right to 6.30.

Mikrotik: joining the 1990s.

thebigcow
Jan 3, 2001

Bully!

jeeves posted:

Looks like they're finally putting it a tiny bit of better patch management besides "Download bestest version"

6.29.1 will have just bug fixes of 6.29, versus before all new content (including new bugs) plus previous bug fixes would have gone right to 6.30.

Mikrotik: joining the 1990s.

6.29.1 is already out and I am running it LIVE A LITTLE MAN

Gorson
Aug 29, 2014

thebigcow posted:

latvia.com is down so I can't grab examples right now, but have you looked into the quickset options? It's the top button in winbox and I'm not sure where in the web interface. Home AP sounds about right for what you are describing.

I got it working, but only through this process:

1. reset Groove
2. log in via Winbox
3. Set up security profile
4. Change WLAN to "AP Bridge"
5. Set up SSID, change security profile, channel, etc
6. Create a new bridge, add wlan and ether-1 on ports tab
7. Create DHCP client

I did not change any IP addresses, and plugged it into the network here at work and am able to access the internet from a laptop. Is this a viable configuration? I'm not sure what I am doing wrong on the Quick Set for "Home AP".

*edit* disabled DHCP client and set a static IP on ether-1, so now I can connect to the internet through it and configure it via a static local IP. Now it is working as I would like.

Gorson fucked around with this message at 22:53 on Jul 1, 2015

Kenlon
Jun 27, 2003

Digitus Impudicus
I recently moved, and my old mikrotik gave up the ghost in the process - it will no longer power on.

I'm considering getting a RB850Gx2, but I need wireless too. Any recommended APs to pair with it that won't break the bank?

Atreus
Sep 20, 2005
Home AC stuff is supposedly scheduled for sometime this half of the year, I might suggest borrowing something or waiting to see how they pan out, alternatively the haplite is pretty decent as a hold over.

jeeves
May 27, 2001

Deranged Psychopathic
Butler Extraordinaire
Apparently a bunch of CCRs crashed due to the leap second. Heh.

Kenlon
Jun 27, 2003

Digitus Impudicus

Atreus posted:

Home AC stuff is supposedly scheduled for sometime this half of the year, I might suggest borrowing something or waiting to see how they pan out, alternatively the haplite is pretty decent as a hold over.

Waiting isn't really doable - I need to VPN into home from outside, among other things, and the comcast cable modem/router combo is awful. Getting a hAP-lite to provide wireless alongside the RB850Gx2 may very well be what I do. (Curse you, Latvia and your ability to make me spend money.)

Rexxed
May 1, 2010

Dis is amazing!
I gotta try dis!

Kenlon posted:

I recently moved, and my old mikrotik gave up the ghost in the process - it will no longer power on.

I'm considering getting a RB850Gx2, but I need wireless too. Any recommended APs to pair with it that won't break the bank?

Have you checked the power transformer? It seems to be the first thing recommended to check when a mikrotik router won't work.

thebigcow
Jan 3, 2001

Bully!
What kind of throughput do you need? Is 2.4 GHz wireless fine or do you need 5? Do you need bigger than normal Ethernet frames? The RB2011-whatever might do everything you want for $100. Fancier than that and the costs start getting out of hand.

PUBLIC TOILET
Jun 13, 2009

So I have an exported configuration (.rsc) from a MikroTik running version 5.26. I'm attempting to import it into a MikroTik running version 6.30. I've been using verbose mode while importing because the process is failing on multiple sections of the script. For instance, version 6.30 doesn't seem to understand the "l2mtu" variable or the "channel-width" variable. I'm guessing that I shouldn't waste my time trying to do this and should only stick to doing this between routers running the same version software (6.x to 6.x)? Would I be better off just upgrading all routers to 6.30 and doing an export from a working one then import on the one needing configuration? Or is there a way to import a 5.x configuration to a 6.x router?

Kenlon
Jun 27, 2003

Digitus Impudicus
Welp. I got the routers, set up the RB850Gx2 just fine, and then performed some classic sawing-the-limb-I'm-sitting on with the hAP lite. And the reset procedure (hold reset for five seconds when booting the device) doesn't seem to be restoring it to factory settings.

jeeves
May 27, 2001

Deranged Psychopathic
Butler Extraordinaire

Kenlon posted:

Welp. I got the routers, set up the RB850Gx2 just fine, and then performed some classic sawing-the-limb-I'm-sitting on with the hAP lite. And the reset procedure (hold reset for five seconds when booting the device) doesn't seem to be restoring it to factory settings.

/system reset no-defaults=yes

thebigcow
Jan 3, 2001

Bully!

PUBLIC TOILET posted:

So I have an exported configuration (.rsc) from a MikroTik running version 5.26. I'm attempting to import it into a MikroTik running version 6.30. I've been using verbose mode while importing because the process is failing on multiple sections of the script. For instance, version 6.30 doesn't seem to understand the "l2mtu" variable or the "channel-width" variable. I'm guessing that I shouldn't waste my time trying to do this and should only stick to doing this between routers running the same version software (6.x to 6.x)? Would I be better off just upgrading all routers to 6.30 and doing an export from a working one then import on the one needing configuration? Or is there a way to import a 5.x configuration to a 6.x router?

Its changed enough that I wouldn't try importing a 5.x config to 6.x. You could dump the old one to text for comparison.

thebigcow
Jan 3, 2001

Bully!

jeeves posted:

/system reset no-defaults=yes

Doesn't work if you can't connect to it.

Does winbox still see it if you connect on the same l2 network? Or is your problem also that you don't have a working login?

jeeves
May 27, 2001

Deranged Psychopathic
Butler Extraordinaire

thebigcow posted:

Doesn't work if you can't connect to it.

Does winbox still see it if you connect on the same l2 network? Or is your problem also that you don't have a working login?

Yeah, try doing a Winbox MAC address connect. It's the second best to a console port (if it works).

thebigcow
Jan 3, 2001

Bully!
Look at this gigantic list of things and tremble

quote:

What's new in 6.30 (2015-Jul-08 09:07):

*) wireless - added WMM power save suport for mobile devices;
*) firewall - sip helper improved, large packets no longer dropped;
*) fixed encryption 'out of order' problem on SMP systems;
*) email - fix sending multiple consecutive emails;
*) fixed router lockup on leap seconds with installed ntp package;
*) ccr - made hardware watchdog work again (was broken since v6.26);
*) console - allow users with 'policy' policy to change script owner;
*) icmp - use receive interface address when responding with icmp errors;
*) ipsec - fail ph2 negitioation when initiator proposed key length
does not match proposal configuration;
*) timezone - updated timezone information to 2015e release;
*) ssh - added option '/ip ssh stong-crypto'
*) wireless - improve ac radio coexistence with other wireless clients, optimized
transmit times to not interfere with other devices;
*) console - values of $".id", $".nextid" and $".dead" are avaliable for
use in 'print where' expressions;
*) console - ':execute' command now accepts script source in "{}" braces,
like '/system scripts add source=' does;
*) console - ':execute' command now returns internal number of running job,
that can be used to check and stop execution. For example:
:local j [:execute {/interface print follow where [:log info "$name"]}]
:delay 10s
:do { /system script job remove $j } on-error={}
*) console - firewall 'print' commands now show all entries including
dynamic, 'all' argument now has no effect;
*) ipsec - increase replay window to 128;
*) fixed file transfer on devices with large RAM memory;
*) pptp - fixed "encryption got out of sync" problem;
*) ppp - disable vj tcp header compression;
*) api - reduce api tcp connection keepalive delay to 30 seconds,
will timeout idle connections in about 5 minutes;
*) pptp & l2tp & sstp client: support the case were server issues its tunnel
ip address the same as its public one;
*) removed wireless package from routeros bundle package,
new wireless-fp is left in place and wireless-cm2 added as option;
*) pptp & l2tp client: when adding default route, add special exception route for
a tunnel itself (no need to add it manually anymore);
*) improved connection list: added connection packet/byte counters,
added separate counters for fasttrack, added current rate display,
added flag wheather connection is fasttracked/srcnated/dstnated,
removed 2048 connection entry limit;
*) tunnels - eoip, eoipv6, gre,gre6, ipip, ipipv6, 6to4 tunnels
have new property - ipsec-secret - for easy setup of ipsec
encryption and authentication;
*) firewall - added ipsec-policy matcher to check wheather packet
was/will be ipsec processed or not;
*) possibility to disable route cache - improves DDOS attack
handling performance up to 2x (note that ipv4 fastpath depends on route cache);
*) fasttrack - added dummy firewall rule in filter and mangle tables
to show packets/bytes that get processed in fasttrack and bypass firewall;
*) fastpath - vlan interfaces support fastpath;
*) fastpath - partial support for bonding interfaces (rx only);
*) fastpath - vrrp interfaces support fastpath;
*) fixed memory leak on CCR devices (introduced in 6.28);
*) lte - improved modem identification to better support multiple identical modems;
*) snmp - fix system scripts table;

jeeves
May 27, 2001

Deranged Psychopathic
Butler Extraordinaire
Yeah, I'll be waiting until a 6.30.1 before even touching that.

Also, is RoMON still enabled by default? I haven't upgraded any of my devices past 6.27 due to that thing and people saying you have to go out of your way to disable it once upgrading.

PUBLIC TOILET
Jun 13, 2009

thebigcow posted:

Its changed enough that I wouldn't try importing a 5.x config to 6.x. You could dump the old one to text for comparison.

Yeah I thought so. I didn't yet compare the configurations side-by-side but I believe you regardless. I suppose I might as well do it by hand and export a generic 6.x configuration for future use.

thebigcow
Jan 3, 2001

Bully!

jeeves posted:

Yeah, I'll be waiting until a 6.30.1 before even touching that.

Also, is RoMON still enabled by default? I haven't upgraded any of my devices past 6.27 due to that thing and people saying you have to go out of your way to disable it once upgrading.

I don't remember if it was on by default, but its just a check box unless I'm missing something.

Atreus
Sep 20, 2005
Looks like they released the CCR1072. Multiple cores, but doesn't seem like some of the services are properly multithreaded. ex. BGP

thebigcow
Jan 3, 2001

Bully!

Atreus posted:

Looks like they released the CCR1072. Multiple cores, but doesn't seem like some of the services are properly multithreaded. ex. BGP

MOAR CORES *uses two*

The bigger deal is that its all SFP+ except for a single gig Ethernet port for setup and it has redundant power supplies with fancy clip things to hold the cords. I don't know where it compares to it's competition at 3k but it seems at that price point dealing with Latvian QA isn't worth the savings.

Kenlon
Jun 27, 2003

Digitus Impudicus

jeeves posted:

Yeah, try doing a Winbox MAC address connect. It's the second best to a console port (if it works).

Which it doesn't.


It's goddamn annoying - I know it's there, it's arping for 192.168.88.10 (the address it had before I sawed off the limb) but I cannot connect to it by any means, and trying to factory reset or NetInstall it has been useless.

Atreus
Sep 20, 2005

thebigcow posted:

MOAR CORES *uses two*

The bigger deal is that its all SFP+ except for a single gig Ethernet port for setup and it has redundant power supplies with fancy clip things to hold the cords. I don't know where it compares to it's competition at 3k but it seems at that price point dealing with Latvian QA isn't worth the savings.

Price/performance is awesome compared to some of the access devices that we use here, but that's apples to oranges. Can't compare Cisco/Ciena support to Latvia.

redeyes
Sep 14, 2002

by Fluffdaddy
So I am just getting into Mikrotik stuff and it is quite powerful and awesome. The cheapo 20-25 bux hAP lite models are great for mom and pop situations and stable and fully featured. But I have need to create a wifi bridge between 2 houses seperated by around 500 ft. Both houses will have lots of computer equipment so the speed of the bridge is important. Can someone recommend a AC compatible set of antennas/aps suitable for a point to point bridge?

frayed time
Oct 20, 2008
Are you wanting mikrotik? For a simple point to point it's hard to beat a pair of Ubiquiti Loco M5 units at about $40 a pop.

redeyes posted:

So I am just getting into Mikrotik stuff and it is quite powerful and awesome. The cheapo 20-25 bux hAP lite models are great for mom and pop situations and stable and fully featured. But I have need to create a wifi bridge between 2 houses seperated by around 500 ft. Both houses will have lots of computer equipment so the speed of the bridge is important. Can someone recommend a AC compatible set of antennas/aps suitable for a point to point bridge?

Thanks Ants
May 21, 2004

#essereFerrari


Loco M5 radios are all kinds of awesome. I've literally never had a problem with the pairs I've put up. They are as close to set-and-forget as you can be.

redeyes
Sep 14, 2002

by Fluffdaddy

Thanks Ants posted:

Loco M5 radios are all kinds of awesome. I've literally never had a problem with the pairs I've put up. They are as close to set-and-forget as you can be.

I need more bandwidth.. as high as possible without breaking the bank.

Something like this looks good.. but I am not that familiar with their stuff:
http://www.amazon.com/Mikrotik-RBSX...rds=mikrotik+ac

redeyes fucked around with this message at 03:09 on Jul 15, 2015

PUBLIC TOILET
Jun 13, 2009

Oh look, v6.30.1 was released six days later and two of the fixes in the changelog are exactly the issues I've been running in to while setting up a new router. :negative:

Tapedump
Aug 31, 2007
College Slice
Sooo, I finally got one and set it up this morning.

Things are running well, with PPPoE set up and a couple of ports forwarded, but then I looked at the log.



What the hell is that? (Ignore the time stamps, I had the clock set wrong.) Should I expect more of this, and if so, how should I stop it?

Weird Uncle Dave
Sep 2, 2003

I could do this all day.

Buglord
Probably just bots trying to drive-by hack you. If you don't need telnet (you probably don't), disable it. Also consider adding firewall rules to drop incoming packets from the outside world on SSH and Web ports, unless you really need to log into the Mikrotik itself remotely. As long as the VPN is working, you can just connect to it, then to the unit itself from "inside".

Tapedump
Aug 31, 2007
College Slice
Okay, I'll turn off telnet.

Can you point me at and/or write an example of how to block external packets from hitting SSH or webUI ports? I'm a fast learning, but I often need a good example to crib off of.

I haven't set up the VPN yet, but I'll get to that. I hear you on how that functions vis a vis remote access and security.

theperminator
Sep 16, 2009

by Smythe
Fun Shoe
Unless you wish to log into your router remotely, it would be worthwhile adding a firewall rule dropping all traffic on the input chain with an in-interface of whatever port you're using for wan. This won't affect your NAT rules.

If you need to allow specific things you can add an allow rule before the drop.

Tapedump
Aug 31, 2007
College Slice
ROS newbie here. I have no need of remote administration, and my WAN interface is pppoe-out1.

Could you help with some syntax or do-this-in-Winbox example?

thebigcow
Jan 3, 2001

Bully!

Tapedump posted:

ROS newbie here. I have no need of remote administration, and my WAN interface is pppoe-out1.

Could you help with some syntax or do-this-in-Winbox example?

http://wiki.mikrotik.com/wiki/Manual:Default_Configurations#Firewall.2C_NAT_and_MAC_server

Try that with pppoe-out1

CuddleChunks
Sep 18, 2004

Tapedump posted:

ROS newbie here. I have no need of remote administration, and my WAN interface is pppoe-out1.

Could you help with some syntax or do-this-in-Winbox example?

Telnet into your router or use Winbox to get in. Open a terminal window and drop this in:

/ip firewall filter add action=drop chain=input dst-port=23 in-interface=pppoe-out1 protocol=tcp

That will drop inbound TCP packets on the port used by telnet. You can also turn off telnet access entirely by going to IP -> Services and disabling the telnet service in there.

Adbot
ADBOT LOVES YOU

Tapedump
Aug 31, 2007
College Slice
Thank you all for your replies. I have followed and learned from the guidance.

Now, the last thing is get a L2TP/IPsec VPN set up. I can get the VPN server running, and connect from it remotely, but I cannot ping/see/access anything other than the router.

As is, I connect seemingly fine (getting assigned the IP address 192.168.115.88 I chose), I can bring up the router's Web GUI and ping its LAN address (192.168.115.1) but that's it. I can't ping the file server (192.168.115.99) or use its services (RDP, SAB, SickBeard, etc.).

For lack of knowledge, I used these guides for reference:

http://www.nasa-security.net/mikrotik/mikrotik-l2tp-with-ipsec/
http://ourhat.com/how-to-configure-vpn-with-l2tp-and-ipsec-using-mikrotik-router/

I recall that it was said that in my WAN interface I need to change ARP to proxy-arp or I would have this exact problem. But, when I did so to pppoe-out1, Internet wouldn't work. I see referenced arp-proxy on ether1, but I'm using PPPoE, so...?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply