Community discussions

MikroTik App

Search found 24 matches

bylgkahn
Sun Apr 02, 2023 9:38 pm
Forum:General
Topic:what am i missing. cannot get firewall working on ccr1036
Replies:9
Views:389

Re: what am i missing. cannot get firewall working on ccr1036

thanks i am interested.. i will look at that list..

my big countries are china russia kzakstan and brazil believe it or not..
bylgkahn
Sun Apr 02, 2023 8:10 pm
Forum:General
Topic:what am i missing. cannot get firewall working on ccr1036
Replies:9
Views:389

Re: what am i missing. cannot get firewall working on ccr1036

thanks all.. i found the setting now in the ui.. As i said i got it working and have been using it on my older ccr1016 but am preparing the ccr1035 with sft+ to have my isp go over 1g.. And i already have an internal 10g networking to my nas's etc. my firewall would not work with bridge filters it i...
bylgkahn
Sun Apr 02, 2023 6:59 pm
Forum:General
Topic:what am i missing. cannot get firewall working on ccr1036
Replies:9
Views:389

Re: what am i missing. cannot get firewall working on ccr1036

thanks .. very helfull, i have public ips and a mail server.. you cannot use a switch dipshit.. if you dont have anything to contribute DONT and there really are NO home brew routers that do bridging firewalls other than DDWRT and that cannot keep up wioth the trqaffic I need Any anyway those are no...
bylgkahn
Sun Apr 02, 2023 6:50 pm
Forum:General
Topic:what am i missing. cannot get firewall working on ccr1036
Replies:9
Views:389

Re: what am i missing. cannot get firewall working on ccr1036

firured it ouit.. it was this setting. that does not show up in the interface.. the only way seems to be set it in the command line, and it is a strange one to set.. took me forever to figure out the set and get options dont work.. you need to use the edit which brings it up in vi the use-ip-firewal...
bylgkahn
Sun Apr 02, 2023 5:56 pm
Forum:General
Topic:what am i missing. cannot get firewall working on ccr1036
Replies:9
Views:389

what am i missing. cannot get firewall working on ccr1036

Need expert help.. I am setting up a ccr1036 and for the life of me cannot get the firewall to work.. it configured everything exactly like my ccr1016 where the firewall is working. Eventually I want to use the sftp+ ports to get faster than 1g connections, but I even tested on the standard ethernet...
bylgkahn
Tue Jul 19, 2022 8:32 pm
Forum:General
Topic:openvpn路由issue
Replies:2
Views:259

Re: openvpn routing issue

thanks i already did that and as i said i can conenct fine and get the address i am supposed to.. 173.x.x.114 server is 173.x.x.113

i can ping myself at 113 but cannot ping anyhting else including my mail server on 173.x,x.125
bylgkahn
Tue Jul 19, 2022 12:55 am
Forum:General
Topic:openvpn路由issue
Replies:2
Views:259

openvpn路由issue

i have a router with public ips so shouldnt need nat or anything.. i can connect with openvpn and get one of my public ipss. burt pc can only ping itself not even the router or any other addresses on the public subnet (13 address block) any idea what could be going on.. i think maybe the subnet is w...
bylgkahn
Mon Jul 18, 2022 10:30 pm
Forum:Beginner Basics
Topic:Unable to create new certificate
Replies:4
Views:2364

Re: Unable to create new certificate

reboot of box fixed it
bylgkahn
Mon Jul 18, 2022 10:29 pm
Forum:Beginner Basics
Topic:Unable to create new certificate
Replies:4
Views:2364

Re: Unable to create new certificate

same problem. i created two certif. took a break and now no fields other than name are enterable.. it is not a issue with winbox as same from anotyher machine.. something with the micrsotik hw itself.. trying a reboot now.. dont feel like doing the command line version.. please fix this.. otherwise ...
bylgkahn
Thu Mar 05, 2020 8:41 am
Forum:Scripting
Topic:how to detect or allow duplicate ips in firewall address lists
Replies:3
Views:3844

Re: how to detect or allow duplicate ips in firewall address lists

No the OK country lists is much larger ie UK for USA etc etc.
bylgkahn
Thu Mar 05, 2020 1:05 am
Forum:Scripting
Topic:how to detect or allow duplicate ips in firewall address lists
Replies:3
Views:3844

how to detect or allow duplicate ips in firewall address lists

I download ranges of ips from Kazakhstan, Russia, China and Brazil (most attacts to get into my router come from ips in these countires) I then combine these individual address lists to one called foreign and block them. Recently there are incorrect duplicates between these lists which causes the fi...
bylgkahn
Thu Feb 23, 2017 12:27 am
Forum:General
Topic:ipv6 firewall for comcast bridging with static public ips
Replies:0
Views:962

ipv6 firewall for comcast bridging with static public ips

Since I could not fimd a good example of this configuration with an advance firewall for ipv6 for comast (in bridging mode since the default gateway is on the same subnet as your range of ips) anyway here is my firewall that I have is confirmed and tested as working.. Note the ips have been changed....
bylgkahn
Wed Feb 22, 2017 8:16 pm
Forum:General
Topic:Firewall ICMP Rule
Replies:23
Views:42626

Re: Firewall ICMP Rule

这里是我的防火墙规则。复杂得多.. 2 sections one to limit attacks/pings on the router itself and one for my forward rules (net changed in a couple of places for security ... /put "cleaning out icmp_packets_bridge chain" /ipv6 firewall filter remove [/ipv6 firewall filte...
bylgkahn
Tue May 03, 2016 10:28 pm
Forum:Beginner Basics
Topic:pptp vpn issue cannot reach private ip subnet via public pptp address
Replies:1
Views:968

pptp vpn issue cannot reach private ip subnet via public pptp address

I have a public subnet 14 ips. and pptp in the vpn on one of the public ips and can reach my machines on the public ips when i vpn in, However, I can ping the private subnet fine from my routeros box as it also has a second address on my private 192.168.11.x subnet. Hoever, When i vpn in onto one of...
bylgkahn
Fri Apr 15, 2016 6:49 pm
Forum:General
Topic:v6.35 [current] is released!
Replies:103
Views:37342

Re: v6.35 [current] is released!

iisues. .upgraded made me upgrade winbox.. now when I try to log in with winbox it wont let me says rmon is not enabled.
bylgkahn
2016年我的2月1日7:07点
Forum:Announcements
Topic:v6.34 [current] is released!
Replies:91
Views:36351

Re: v6.34 [current] is released!

just for everyone's info.. this version broke our firewall I got an error that said expecting : in this line add chain=ICMP protocol=icmp icmp-options=0:0-255 limit=5,5 action=accept comment="0:0 and limit for 5pac/s" disabled=no I figured out what the change was by export the firewall whi...
bylgkahn
Sat Jan 16, 2016 1:16 am
Forum:Announcements
Topic:v6.33.5 [current] is released!
Replies:120
Views:47627

Re: v6.33.5 [current] is released!

this new release made y 1016g unuseable.. after reboot couldn't even get in the router locally.. anyone have info how to flash back to the 6.33.3 packages assuming I can reset the box and get back in. thanks The configuration had two ip addresses a static public ip ie 173. and a private 192 ip.. bo...
bylgkahn
Fri Jan 15, 2016 11:46 pm
Forum:Announcements
Topic:v6.33.5 [current] is released!
Replies:120
Views:47627

Re: v6.33.5 [current] is released!

this new release made y 1016g unuseable.. afer reboot couldn't even get in the router locally.. anyone have info how to flash back to the 6.33.3 packages assuming I can reset the box and get back in.

thanks
bylgkahn
Sat Dec 12, 2015 11:46 pm
Forum:General
Topic:problem with dos attach via dns
Replies:1
Views:1424

Re: problem with dos attach via dns

i rebooted router and no more crap.. only think i can figure out is that these servers must have been running some denial of service attack over dns that continaully kept the port open (ie via tcp instead of udp) not really sure.. or there is a bug in the router os software and rebooted cleared it.....
bylgkahn
Sat Dec 12, 2015 11:32 pm
Forum:General
Topic:problem with dos attach via dns
Replies:1
Views:1424

problem with dos attach via dns

I saw all kinds of crap dns in my logs once I enabled syslog. Anyway I dont understand why they are getting through the input filters in the firewall .. To debug I explicitely bocked dns on both udp tcp on port 53 in the firewall rules.. even though those two ports were not allowed and should have b...
bylgkahn
Sat Dec 05, 2015 7:22 pm
Forum:RouterBOARD hardware
Topic:RB1100 Fan issue
Replies:47
Views:31140

Re: RB1100 Fan issue

getting a couple of these.. a little lower airflow but much quitter.. will keep you informed when I install

http://www.coolerguys.com/840556098225.html
bylgkahn
Fri Dec 04, 2015 10:53 pm
Forum:RouterBOARD hardware
Topic:performance
Replies:2
Views:1262

Re: performance

thanks i have some more statistics I have reduced my firewall rules to 129 by using address lists which the older h/w did not support. anyway for 129 rules using rb2011 with speedtest maxing out at 170 megabit/sec cpu utilization is about 65-70% I also picked up a cr1016 older model cpu utilization ...
bylgkahn
Thu Dec 03, 2015 12:37 am
Forum:RouterBOARD hardware
Topic:performance
Replies:2
Views:1262

performance

I am going to be setting up a transparent bridging firewall configuration with static ips. The reason I need to bridge is that Comcast gives out an ip block with the default gateway on the same subnet as your ip block. I do not want to do NAT and want to actually use the public ips. I assume the sta...
bylgkahn
Fri Mar 06, 2015 12:28 am
Forum:Beginner Basics
Topic:transparant bridge public ips with same subnet.
Replies:0
Views:882

transparant bridge public ips with same subnet.

on dd=wrt I did the following.. I need the ip to be on the bridge itself and the bridge to run in promiscuous mode and bridge traffic between 1 port which goes to the cable modem and another which goes to a switch with all my local machines I have public ips... I then want to put a firewall on the b...