Welcome Guest ( Log In | Register )

4 Pages < 1 2 3 4 >Bottom

Outline · [ Standard ] · Linear+

Enterprise Networking Mikrotik Routers (RouterBoard & RouterOS), User and owner discussion group

views
     
asellus
post Nov 11 2013, 06:45 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(mroctopus @ Nov 11 2013, 01:10 AM)
hi, i m helping friend to set up a office with 30 pc clients and need to have network bandwidth control for each pc. Unifi provided a router but without such feature. Which router should i get for such purpose, and is there a step-by-step guide on this? sorry i didn't go through the 40 pages long thread in forum perhaps it has mentioned be4.
*
Quick and dirty way to do it.

- Get a reasonably powerful routerboard for that amount of users like MikroTik RB2011UAS-2HnD-IN if you need wireless or MikroTik RB2011L-IN if Ethernet-only.
- Make sure each PC clients has its own static DHCP entry in routerOS.
- Make sure set ARP to reply-only to prevent them from bypassing DHCP.
- Make a firewall entry so that they cannot bypass the router when it comes to DNS lookup.
- Then make a hierarchical simple queue so that all 30 PCs will only share 1Mb upload and 1Mb download speed while your own hog the 24Mb upload and download speed.
asellus
post Nov 13 2013, 01:20 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(jianwei87 @ Nov 13 2013, 12:14 PM)
I have change DNS setting to 8.8.8.8 and 8.8.4.4 but once I connected to my wireless network I'm getting this value. Why?
*
What is the IP address of the Mikrotik router?
asellus
post Nov 13 2013, 06:05 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(jianwei87 @ Nov 13 2013, 02:58 PM)
I'm creating a hotspot service for user. So that is my hotspot IP address.
*
If that's the case then what you have seen is normal.
asellus
post Nov 14 2013, 12:47 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(jianwei87 @ Nov 13 2013, 11:57 PM)
Possible to change the DNS to display 8.8.8.8 and 8.8.4.4?
*
No, you cannot do that. Just specify that DNS servers in routerOS and all the clients will use them anyway.
asellus
post Nov 14 2013, 09:51 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(jianwei87 @ Nov 14 2013, 09:36 AM)
I had specify the DNS already in my routerOS but they never display.
*
They will not display, but they will be used.
asellus
post Dec 4 2013, 06:45 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(mroctopus @ Dec 4 2013, 02:52 PM)
ok.. above sound too technical for me.

hahah

Is there anyone can configure the router on site? just let me know how much your service charge.
*
Contact CloudComputer, he may be able to help you.
asellus
post Dec 5 2013, 12:20 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(gahkin @ Dec 4 2013, 11:29 PM)
hi , any can guide me how to block all mac address to limit access internet by group ? i was search online they got guide me to create firewall > address list here create group then only put IP list. but if how can block by mac address then i no need worry user will change ip address to get access internet.

sos : http://thinkxfree.wordpress.com/2012/02/08...block-attacker/
*
Do not block via MAC address; they can be changed. Instead, set the ARP option of the interface where the DHCP server is running to 'reply-only' so that people who set their network interface to static IP address will not have any route to the router at all.

asellus
post Aug 14 2014, 11:04 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(seng87 @ Aug 14 2014, 10:10 AM)
Sorry... I was wanting to use 192.168.1.1-192.168.2.254 hence the correct network should be 192.168.1.0/23.. Correction in this area. As for the DNS  I did untick the use peer dns but it doesn't work.. I'll try again later. Thanks for the reply.. Appreciate your help. But the IP subnetting is giving me some problem.
*
192.168.1.1-192.168.2.254 is not 192.168.1.0/23. If you want to use that range for DHCP then declare a /22 and then use the said range for your purposes.
asellus
post Sep 3 2014, 01:36 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(SupremeSS @ Sep 3 2014, 10:44 AM)
How do i make priority network for my pc? Example: 10mbps from maxis home fibre, reserved 7 mbps for my pc..because when i play dota 2, other smart phone loading youtube i will be getting high ping.
*
Use the 'Queues' feature of this.
asellus
post Oct 2 2014, 06:20 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


Master port and its slave ports turned those group of ports into an unmanaged switch.
asellus
post Jan 29 2016, 12:26 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(soonwai @ Jan 28 2016, 05:45 PM)
I've been messing with my firewall so most rules are off the moment. Today I realised that I have about 1000/sec inbound UDP connections from the internet to port 53 (DNS) of my router. Any ideas what that is? It chews up 8-10mbps of my ingoing/outgoing bandwidth.

DDOS? Though not very effective since router is still ok.

Anyway port 53 filters are back up.

user posted image
This is about 1 min after I enabled the filters.

Update: Looks like a DNS amplification attack. Just had my port 53 opened for a few hours and they found it.
*
You should also go ahead and drop all UDP packet that lands on port 123 too to prevent NTP amplification attacks.
asellus
post Nov 13 2018, 10:21 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(Guardian @ Nov 13 2018, 06:50 PM)
Has anyone used Hex Poe before? I plan to use the PoE feature for Ubiquiti UAC-AP-Lite/Cap AC instead of using multiple power adapters, but hard to find review for this particular product. My plan is for the receiving side of the signal (Ubiquiti LiteBeam), connect to Hex PoE, which will connect to one AP downstairs and one AP upstairs, need some recommendations on switch/router for this matter, thanks.
*
hEX PoE is too expensive for what you want to do. Just grab a dumb Gigabit PoE switch and be done with it.
asellus
post Jan 11 2019, 09:57 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(azmanshah89 @ Jan 10 2019, 04:52 PM)
Hello guys,

Need some advice here, currently my office using router Asus AC-RT3200. We have connectivity since last year. Already make report to TM more than 50 times but the problem keep repeated. The speed is 100Mbps and now upgraded to 800Mbps but the problem still occur. Sometimes the wifi connected but dont have internet connection. Total users are around 100 devices.

1. What mikrotik router is the best for my situation?

2. I have bought RB2011UiAS-2HnD-IN. Is is sufficient to cater all user with stable connectivity?

3. Does this Asus AC-RT3200 is suitable for office usage?

Your help is really appreciated
biggrin.gif
*
Use RB2011 for routing, and the ASUS as wireless access point. Whether the ASUS is good enough for your office depends on the layout.
asellus
post Apr 12 2019, 05:36 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(celciuz @ Apr 12 2019, 02:27 PM)
I am considering a MikroTik router (read about it having being good bang for the bucks) for my home. I plan to keep the router and CCTV NVR in a data cabinet inside the store room (fiber wall socket will be reallocated there). About 10 Cat6a points (reserved 2 for AP one for ground floor and upstairs) since if I place the wireless router inside metal data cabinet the wifi probably won't work well?

Wireless devices I guess probably about 10 or so... phones, tablets, wireless smart switches etc.

What models could I start looking at? And also recommended wireless AP?
*
Assuming that you already have done wiring, use this for router in the closet. For AP, use 2 of these then add Raspberry Pi3 so that you can install the god-damn controller software alongside Pi-Hole for DNS-based adblocking.
asellus
post Dec 16 2019, 09:57 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(th3game @ Dec 16 2019, 09:08 PM)
hi sifus,

finally I got my hands with MikroTik HAP AC2. I tried to setup with Unifi and followed the steps on the web. vlan500 n vlan600 etc. etc...
and the Hypptv works. And the internet was not working when I connect to the wireless AC 5ghz or 2.4Ghz
But when I tried to ping the google.com in the Mikrotik terminal, I got the pinging. weird..
dunno what was wrong during config

from my mac connect wirelessly to the MikroTik, I can ping the gateway (192.168.1.1) and can ping google.com also but when to access the internet using the Safari, there was no internet. try to disconnect and reconnect back, still no luck. pls help

ether 1 - connect to Unifi BTU
ether 5 - connect to Hypptv stb

below is my export config file

» Click to show Spoiler - click again to hide... «

*
CODE
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
   ipsec-policy=out,none out-interface-list=WAN


Try changing your NAT masquerade entry to explicitly use ether1?
asellus
post Dec 16 2019, 10:07 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(th3game @ Dec 16 2019, 10:05 PM)
don't have option for ether1
user posted image
*
Disable 'Out Interface List' and use 'Out Interface' pulldown menu instead.
asellus
post Dec 16 2019, 10:15 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(th3game @ Dec 16 2019, 10:05 PM)


u mean this right?...sorry noob here

user posted image
*
Damn, I forgot, use the pppoe interface name instead.
asellus
post Dec 16 2019, 10:34 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(th3game @ Dec 16 2019, 10:27 PM)
done changeNAT out. interface to to ppoe-out1

but how about DHCP Client..should be ether1?

user posted image
*
I don't think you need to run a DHCP client on ether1 or the pppoe connection. On the other hand, you should run a DHCPv6 client on the pppoe connection instead.
asellus
post May 1 2020, 08:05 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


Major difference looks like to be the LTE6 modem and the brand new casing. It has 5 1Gbe ports, not 5Gbe ports.

I don't think Mikrotik has 5GBe ports outside SFP cages.
asellus
post May 7 2020, 09:29 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(PC_CHEAH @ May 6 2020, 09:46 PM)
Hi, I tried to setup ikev2 vpn for surfshark vpn.
the connection from router to their server is established but things are not working as expected.
I only want my phone (192.168.0.5) to connect to vpn but the tunnel doesn't hide my true IPv6 and it is not using the VPN DNS.
....

When I IPLeak test the connection for my device, ipv4 vpn ip is detected, but ISP ipv6 are also detected. The DNS detected are google dns, not the VPN dns. (ip leaked)
Then, I disabled ipv6 in the router, my device (vpn) could not get any internet anymore.

I also excluded ipsec from fasttrack and added mark connections in mangle
I doubt there are something to do with the DNS settings, or firewall, not sure.
and is there any ways that I can automatically disable ipv6 to the clients when using the VPN without actually disable IPv6 in the router?

I also posted to MikroTik forum: https://forum.mikrotik.com/viewtopic.php?f=...533c653e64a12fa

any mikrotik sifu can look into my config
» Click to show Spoiler - click again to hide... «

*
Have you marked your connection in /ipv6 firewall mangle?
Did surfshark vpn even support IPv6 on the VPN?

4 Pages < 1 2 3 4 >Top
 

Change to:
| Lo-Fi Version
0.0330sec    0.54    7 queries    GZIP Disabled
Time is now: 28th November 2025 - 03:19 AM