Grab a support file on 7.8, downgrade to 7.7, if it works again using 7.7, open a support ticket.
Grab a support file on 7.8, downgrade to 7.7, if it works again using 7.7, open a support ticket.
Even that can be gotten around, speaking from experience.. haha Time and effort..As long as you don't blacklist EVERYTHING and only allow certain IPs/sites, there is always a way around the blocks.
我stand corrected..Ah, you do not know the quic protocol...UDP in your suggestion is not necessary.
You turn it off in the clients.Do you say that you can stop me from browsing where I want without having 100% control of the client? PC/Mobil etc.
How do you block DoH/DoQ/DoT?
Huh? Why would you use different masks?You do not need /30
/32 works with /31 on the remote side.
我t may not work if your mentioned firewall is not set up properly and blocks the traffic or incorrectly set up a routing table that does not allow route traffic through the router.
You can also get those as 4+ ports.
Coupled with these DC splitters:
Going to try that tonight.Have downgraded to 6.49.7, will see how that goes...
Nothing of any significance, was watching it the last time a reboot happened.whattool/profileshowing?(keep it running)
on logical reason would be, that one of those parameters getting overloaded
Every 30-60 minutes now, sometimes 5-10.7.4.1 just rebooted on me.
Less than 7.5 and 7.6 but still happening.
Open a support ticket and include the supout files..?Any way of getting Mikrotik to look at the supout files to figure out why?
7.4.1 just rebooted on me.7.4.1 seems to be stable for me, I'll update here if it still crash.
我ndeed..我've got the exact same issue on a CCR1009-8G-1S-1S+ that has just started in the last couple of days.
似乎有点有限公司incidence that that three of us have the same issue starting around the same time with similar models??
Netinstall has already been done.i think is too early for netinstall.
whattool/profileshowing?(keep it running)
on logical reason would be, that one of those parameters getting overloaded
These?sorry for the silly question but what adapter can be used to plug the rb5009 using the 2-pin terminal? are ther any simple dc adpater pluggable to an outlet available?
Wasn't a power supply issue.我got the exact same problem with my CCR1009-8G-1S-1S+
That mirrors my thoughts..You might want to netinstall the device to make sure there isn't an issue with the flash or the os install. I would also check the capacitors to make sure none are failing. If you have a backup power supply, I would also test that as well.
Why?Hello
We have a lot of already installed routers CCR 1009
And now we have bought SD cards for this devices
v7.5 seems to have fixed it.Was able to eventually "see" the LTE device in RouterOS but never got it working..
Mine is a different device ID, but it is now working.*) lte - fixed AT channel for Sierra Wireless modems with device ID 0x9091;
This is wrong.
Bridge -> Ports -> Delete Ether7
我P -> Addresses -> Add ->
Address: 10.10.10.254
Network: 10.10.10.254 (this is auto generated when you leave it blank)
我nterface: ether7-access
Like what exactly?可能有些用户未经授权的这ngs on the server and I am afraid that the data center will raise this issue knowing that the server is online.Why do you want to drop icmp?? Makes no sense.
Use the serial console and the boot menu..我cannot even get the CCR2004-16G to netinstall. holding reset during boot never does anything. Tried on ports Eth1 and Eth16.
Simply does not work.
What is doing the scanning and why does it have access to the Mikrotik admin interfaces?One of my customers is subject to PCI DSS quarterly vulnerability scans. They sent me a report which enumerates several problems with www-ssl service (Webfig over TLS).
Huh? Source?Native x86/64 installation is no longer supported, use CHR to get access to all device drivers.
我t definitely has a bridge-mode..4000XG. I'll look through the instructions for it though
我f you are turning off the M$ firewall or allowing a program, and it is still blocked, yes, M$ issue.You should not default to a position of "MS is wrong, because MS" rather than considering that non-RFC compliant use of UDP and IP is the real problem.
我nteresting.. I didn't know this was possible.. May need to try it, just to know that it works and I can say I did it...Only way to transfer files over serial is to set up PPP connection over it instead of console. Then you can run IP and winbox or SSH/SFTP over it.
But does that fix it?i know this but avoiding it
RB2011这样做太……i have seen an special situation on rb3011, it has a longer jack to properly reach the internal board
Why? How do you figure that will help??hello guys
我have problem with spamhaus, all of my ip blocked in spamhaus
我wanna set rule in firewall to limit 5 Email per hour
how to configuration this rule ?
can you help me ?
Yes, two-factor-authentication is required for app passwords.
EDIT. Ok it now appeared as available after enabling two factor authentication. Seems it may be the solution to this.
Did you reboot the router after connecting the USB-Serial adapter?Please tell me how to fix this!!
The problem exists with ROSv6.49.6 and ROSv7.2.3
Have the 0.0.0.0/0 route use the VPN as the gateway. Set a static route for the VPN's IP to use the 'normal' gateway.Basically, I am looking for option (VPN or none), no VPN -> no internet traffic
Check layer 1 first...There's also duplex and auto negotiation errors in the log sporadically.
The mascaraed rule.. Default was 192.168.88.0/24? Would need to be adjusted to /23 as well.Ok I understand about the pools. On Firewall NAT what rule would exactly should be customize?
Regards.
Most of your blocklist.de entries. Not sure of your other lists though.Adding more lists just for learning purposes, which one is duplicated?
Then then fix/correct your DNS server config.
Thanks for your answer!, i have that configuration on my topology, but, my DNS server on remotes sites prefers the other DNS server and no take information from my principal DNS server,
我P-Addresses and delete the ether1 IP(s).我t’s not supposed to be a static ip it’s supposed to be dhcp
Static IPs?How will I make devices on bridge 2 accessible remotely over L2TP without adding a DHCP server for bridge 2?
Nice. Thank you.Remember asyncronous ":execute"...
我P-DHCP ClientHow do I enable dhcp client
This doesn't help the OP because they have three servers to pick from in a drop-down to pick from.This is what I am using at home:
First, contact your ISP and find out what it is *supposed* to be.How do I do this?
So a replacement for Quick-Set?Probably, my supposition, for autoconfig script, that once executed (on interactive terminal, obviously)
ask for SSID, passwords, RouterOS users names and passwords, IP???, etc.
*if* you could, what would you want it to do?hello ,
can I make an interactive script where I waiting for replay and then save it?
VPN on Mikrotik can be very, very slow depending on the settings used, something for you to fix..我saw that VPN connection speed of my Mikrotik client is very very slow. If I connect to VPN server from my PC VPN connection speed is normal. And all banned sites open. Maybe this is the reason?
DHCP?we would like to know how we can distribute our /24 block example 1.1.1.1/24 to our clients with NO nat
Yeah.. It doesn't make sense...That fits into the crazy department - they don't provide a service that damn near everyone uses, and then block any attempt to use any one of the many available public NTP servers.
Yes. Personally, I wouldn't bother with prioritizing, make connections to both, their network should do that part.Should I simply setup 2x BGP connections, 1 to each address and somehow prioritise their usage?
But you said,The "secret" refers to PSK.
So now I am very confused..YVW. thats an ON and OFF option it works with RSA no password. I guess just a handshake.
So where do you put the IPSec secret?YVW. thats an ON and OFF option it works with RSA no password. I guess just a handshake.
Thank you..
我宁愿黑名单/下降的第一次尝试using a wrong username, but that is the idea..我prefer a script that will put in a blacklist all the usernames login attempts (more than 3 attempts) that are not users of the system.
They are not logged differently. That would make this too easy..我am not sure if the message that are logged are different if its wrong user or wrong password.
Login failure for user x from a.b.c.d via service"
Putting a switch between the printer and router would fix it..我t's only interesting when you don't have to face it.
Yes, I try and assume nothing..Seriously, you gotta ask that?)
Confirmed.Looks like they changed some things..Seems to be back up now.
Half-truths at best and really bizare interpretations of the results of the reseachers' "tests"...我s there any truth to this?
From a network/systems admin point of view, DoH is a huge PITA!Uuu DoH evil!! beware of DoH!! boo!
Stop spying on your users.
No, you can't do what you want.
根据Turris支持,它是戴更新ly.我t is a weekly list so just update it at 06H30 am and polling it will only create mor load on their side.
我did try those first..Using pref-src / "Pref. Source" / "Preferred Source" on route without involving consuming firewall rules???
Thank you!According to the:routing filterdocumentation [1] it looks like you can use the:routing filter set set-pref-src=option in inbound filters.
Something from the Czech language?.I challenge you to explain the origin of the name "hei" rule
Oh.. *shaking my head*By the time am done, the security will be so tight that, you will have to physically access the router/switches to hack me
Send me the best hacker in the world, they wont get anywhere!!!
So much for a newbie asking dumb questions
RouterOS 3??Router OS 3 i think
many thanks
No, 'drop all' is a bad idea..Just make sure your firewall drops all except your own incoming traffic like vpn.
None of them are needed for things to work.What am asking is about essential services that MUST be on for things to work
You need the services on that you plan to use.Please let me know what services i need on and if this is a good idea
Packets are endless, not just once.你可以只剥了个橘子吃一次……
我f its peeled for you why complain?
我could ask someone else to tie my shoes everytime I put them on because they could.. Wouldn't it be better if I tied my own?At that point it doesn't matter if the customers are blocking the bogons or not, because I do it first for everyone ...