Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Enterprise Networking Mikrotik Routers (RouterBoard & RouterOS), User and owner discussion group

views
     
kwss
post Oct 3 2025, 10:09 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(skywardsword @ Oct 3 2025, 10:03 PM)
I am using the Mikrotik "Back to home" app... which does not have the MTU setting from what I could see.  when it is connected it shows connected via IPv4 relay. (I off the wifi to test the mobile connection). at this moment, after updating to V7.20 and setting the mikrotik's setting to max MTU MRU 1500. the back to home app seems to work pretty ok already. so I probably do not need to set the mobile phone's Back to home app's MTU.
edit: sorry I said I used wireguard. I am actually using the Back to home app, by mikrotik , which uses Wireguard.
*
I don't use the BTH app, but I am guessing they should have some kind of Path MTU Discovery mechanism inside. They are networking product maker and cannot be that dumb. Mobile network is notorious for smaller than usual MTU due to all the encapsulation between eNB.

Upload should work because your MRU allows it.
If you test download and it works too, then you can stop here.
Else you might need to set 1320 inside Mikrotik

BTH is still wireguard behind the scene. They just package it into an easy to use app and Mikrotik operates a relay.

This post has been edited by kwss: Oct 3 2025, 10:11 PM
kwss
post Oct 30 2025, 01:06 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
The latest beta support Post Quantum Cryptography for IPSec now
*) ipsec - support Post-Quantum Pre-shared Key (PPK) with QKD integration (CLI only) (additional fixes);

Just in time after this year's DEFCON warning.
Anyone interested of Quantum computing progress in breaking cryptography can watch it here

kwss
post Oct 30 2025, 01:48 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(tng55 @ Oct 30 2025, 01:30 PM)
mikrotik can track website URL HTTP and HTTPS FULL history multiple PC ???
few PCS each ip i can do but each PC track URL HTTP and HTTPS FULL history
its possible ???

if found website we want block too
*
You use packet matcher but it's very leaky.

My suggestion is just use NextDNS as DoH resolver in Mikrotik.
In the forwarding rule, block dst port 53 and 853.

You then proceed to add your blocking rule inside NextDNS.
Then you review the log regularly to identify anyone trying to bypass like using VPN or whatnot.

You still cannot prevent people who bypass by not doing domain lookup when they connect to their VPN.
kwss
post Oct 30 2025, 01:58 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(tng55 @ Oct 30 2025, 01:52 PM)
no worry multiple PC don't have VPN i aware

my office staff always use google chrome Incognito
that why i wanna check history what he use

NextDNS need purchase not free hmmmm
*
Then NextDNS easiest and most robust when combined with Mikrotik forward chain rules.
They got option to prevent usage of Apple Private Relay and other DNS too so it's very easy to configure. Basically don't need to know very in-depth how things work.

Free for 300k query. Not enough then rm8 per month. Bayar jer.
kwss
post Oct 30 2025, 03:01 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(tng55 @ Oct 30 2025, 02:33 PM)
i not sure 300k query enough or not due office multiple PC

packet matcher but it's very leaky
why very leaky any issue leaky
*
Try first, decide later. Maybe your staff didn't actually do anything then you don't pay loh.
You can continue using even if you exceed 300k and don't pay. NextDNS just won't do any filtering.
Unless your staff only do bad shit at the end of month when you already exceeded 300k.

RM8 very expensive for your business meh? Can claim as company expenses.
One burger special at those tepi jalan how much already?
Mixed rice how much?
Per month bro. Not per day.

Packet matching is stateless and only recognize header, options and payload using regex.
If there is fragmentation, it won't work.
If it is QUIC or HTTP/3, it won't work because the SNI is "encrypted".
If any of the keyword appear in any packet due to your filter being too generic, then it will have a lot of false positive.
Packet matcher is a data plane operation, meaning it must punt to control plane for logging, which is very CPU intensive.
It will definitely fill up your router log.
You won't gain any insight with how router log is being displayed.
You need solid knowledge and lots of testing to even make it work properly.

Finally I am not gonna offer any support for packet matcher in your use case. Tell you upfront first.
It is normally used at the edge for ACL use case, not URL filtering use case.
kwss
post Oct 30 2025, 03:35 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
tng55 if you are really kedekut then run a PiHole container inside your Mikrotik router.
Then proceed to add the forward chain rule to block dst port 53 and 853.
You will need to recreate all the ruleset that NextDNS already has.

I am not providing free tech support for this setup as well. You are on your own.
kwss
post Oct 30 2025, 10:20 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(tng55 @ Oct 30 2025, 09:43 PM)
how can exceed 300k for 300K is URL history ? i never try before

many big company they also can trance fully http and https let say big company 100 computer but they easy trance http and https hmmm i not sure what they are use  hmm.gif

i am not kedekut but i saw NextDNS business 1 year RM790 but not lifetime
ever year RM790 wow expensive can't claim
*
300k is the queries, not history. You can set log duration separately.
How many computer do you have? Use the free one first and then personal.

There are many types:
1. DLP, which log at the endpoint
2. SIEM, which log flow at the network, and also can mirror traffic if you install a tap
3. MITM proxy, where you install a root CA on every computer and decrypt all traffic

You can pick one, or a combination of them. But damn how big is your business?
If you are the boss and you have to ask this in a forum, don't need to consider.
Those solution requires full tech team to run.
For SIEM, SOAR, EDR, you need a fully staffed Security Operation Center.

EDIT:
You didn't tell me what you are looking specifically. You suspect he steal your data? Upload to cloud? Or just snaking around?
Very different scenario you know.

This post has been edited by kwss: Oct 30 2025, 10:21 PM
kwss
post Oct 31 2025, 01:32 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(tng55 @ Oct 31 2025, 01:17 AM)
not steal data and not upload to clud
my office computer 5PCS
i saw staff use google chrome Incognito that he use surfing to much so i can't trance website visit HTTP OR HTTPS
that why i want trance his usage browser internet
once i found we will block like faceook and whatsapp and etc and google search and personal use website

that only very imported
that why i asking mikrotik can trance history website i will set block
*
Look, the stuff you want is simple.
So make it simple.

Just get started in nextdns and use it as your DNS server now.
Don't need Mikrotik.
Don't need blocking.
Just see what website gets logged.
See how many requests you used a month from now.

What router you using in your office?
kwss
post Oct 31 2025, 05:42 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(tng55 @ Oct 31 2025, 02:31 AM)
my office is ASUS ROUTER AC68U lol not yet to get mikrotik

you are sure nextdns enough 300k for 5PCS ???
can view usage history then can i set some site block
*
I already said go register an account, put it into your Asus and monitor.
You don't waste my time keep asking the same thing with zero progress.
kwss
post Oct 31 2025, 03:01 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(tng55 @ Oct 31 2025, 01:15 PM)
ohhh i will do register free site https://nextdns.io/ its correct
*
Okay so you go to your Asus and configure DoT.
You should see the logs starts showing.
You can also starts blocking already.

9 Pages « < 7 8 9Top
 

Change to:
| Lo-Fi Version
0.0179sec    0.40    7 queries    GZIP Disabled
Time is now: 27th November 2025 - 02:15 PM