Welcome Guest ( Log In | Register )

176 Pages « < 107 108 109 110 111 > » Bottom

Outline · [ Standard ] · Linear+

Enterprise Networking Mikrotik Routers (RouterBoard & RouterOS), User and owner discussion group

views
     
sjovie05
post May 2 2020, 04:14 AM

Getting Started
**
Junior Member
131 posts

Joined: Dec 2009



QUOTE(raymond82 @ May 2 2020, 02:06 AM)
try to enable debug logs for wireless
*
i have enabled this. let see if i can get anything concrete tomorrow.

QUOTE(heidarren @ May 2 2020, 03:18 AM)
Are you using iPhone? iOS 13 has this bug for long time, Apple still no respond yet. restart your device and you will be fine
*
i am using samsung note 10+. the issue is that it lost connectivity to the wifi for 10-15 seconds, then it gets connected back automatically.

Anyone have any idea about the extensive data loss error from the debugging below?

user posted image

This post has been edited by sjovie05: May 3 2020, 02:11 AM
PC_CHEAH
post May 6 2020, 09:46 PM

Getting Started
**
Junior Member
67 posts

Joined: Jun 2015


Hi, I tried to setup ikev2 vpn for surfshark vpn.
the connection from router to their server is established but things are not working as expected.
I only want my phone (192.168.0.5) to connect to vpn but the tunnel doesn't hide my true IPv6 and it is not using the VPN DNS.
....

When I IPLeak test the connection for my device, ipv4 vpn ip is detected, but ISP ipv6 are also detected. The DNS detected are google dns, not the VPN dns. (ip leaked)
Then, I disabled ipv6 in the router, my device (vpn) could not get any internet anymore.

I also excluded ipsec from fasttrack and added mark connections in mangle
I doubt there are something to do with the DNS settings, or firewall, not sure.
and is there any ways that I can automatically disable ipv6 to the clients when using the VPN without actually disable IPv6 in the router?

I also posted to MikroTik forum: https://forum.mikrotik.com/viewtopic.php?f=...533c653e64a12fa

any mikrotik sifu can look into my config
» Click to show Spoiler - click again to hide... «


This post has been edited by PC_CHEAH: May 6 2020, 09:47 PM
asellus
post May 7 2020, 09:29 AM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(PC_CHEAH @ May 6 2020, 09:46 PM)
Hi, I tried to setup ikev2 vpn for surfshark vpn.
the connection from router to their server is established but things are not working as expected.
I only want my phone (192.168.0.5) to connect to vpn but the tunnel doesn't hide my true IPv6 and it is not using the VPN DNS.
....

When I IPLeak test the connection for my device, ipv4 vpn ip is detected, but ISP ipv6 are also detected. The DNS detected are google dns, not the VPN dns. (ip leaked)
Then, I disabled ipv6 in the router, my device (vpn) could not get any internet anymore.

I also excluded ipsec from fasttrack and added mark connections in mangle
I doubt there are something to do with the DNS settings, or firewall, not sure.
and is there any ways that I can automatically disable ipv6 to the clients when using the VPN without actually disable IPv6 in the router?

I also posted to MikroTik forum: https://forum.mikrotik.com/viewtopic.php?f=...533c653e64a12fa

any mikrotik sifu can look into my config
» Click to show Spoiler - click again to hide... «

*
Have you marked your connection in /ipv6 firewall mangle?
Did surfshark vpn even support IPv6 on the VPN?
PC_CHEAH
post May 7 2020, 02:41 PM

Getting Started
**
Junior Member
67 posts

Joined: Jun 2015


QUOTE(asellus @ May 7 2020, 09:29 AM)
Have you marked your connection in /ipv6 firewall mangle?
Did surfshark vpn even support IPv6 on the VPN?
*
I suppose they do not support ipv6, I intend to block ipv6 for my vpn tunnel device on the router side. Not very sure how to do that on ipv6 firewall.
asellus
post May 7 2020, 04:33 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(PC_CHEAH @ May 7 2020, 02:41 PM)
I suppose they do not support ipv6, I intend to block ipv6 for my vpn tunnel device on the router side. Not very sure how to do that on ipv6 firewall.
*
Considering how ipleak.net works, IPv6 route leak is inevitable. No good way to disable IPv6 for a device when connected to the VPN due to the inflexibility of routerOS' IKEv2 implementation, routerOS' hopeless IPv6 stack and, if you use TM Unifi, their IPv6 limitations too. The latter two is especially infuriating.

Just disable IPv6 to use the VPN correctly.
PC_CHEAH
post May 7 2020, 05:11 PM

Getting Started
**
Junior Member
67 posts

Joined: Jun 2015


QUOTE(asellus @ May 7 2020, 04:33 PM)
Considering how ipleak.net works, IPv6 route leak is inevitable. No good way to disable IPv6 for a device when connected to the VPN due to the inflexibility of routerOS' IKEv2 implementation, routerOS' hopeless IPv6 stack and, if you use TM Unifi, their IPv6 limitations too. The latter two is especially infuriating.

Just disable IPv6 to use the VPN correctly.
*
after disabling ipv6, all websites I browse just connection timed out, but I'm able to ping IP addresses.

I doubt the dns are also a problem.
the dynamic servers below are vpn dns es.
» Click to show Spoiler - click again to hide... «

I think it query the router first (custom DNS) and not the vpn dnses below, could this be the cause of the timeout?
From mikrotik forums, they said it is the encrypted packets not getting delivered to the vpn tunnel. Not sure what can I do about this.


This post has been edited by PC_CHEAH: May 7 2020, 05:28 PM
asellus
post May 7 2020, 10:33 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(PC_CHEAH @ May 7 2020, 05:11 PM)
after disabling ipv6, all websites I browse just connection timed out, but I'm able to ping IP addresses.

I doubt the dns are also a problem.
the dynamic servers below are vpn dns es.
» Click to show Spoiler - click again to hide... «

I think it query the router first (custom DNS) and not the vpn dnses below, could this be the cause of the timeout?
From mikrotik forums, they said it is the encrypted packets not getting delivered to the vpn tunnel. Not sure what can I do about this.
*
If you set up the DNS server directly on the computer ethernet adapter (try using Google DNS), will you still see the same problem?
PC_CHEAH
post May 8 2020, 05:26 PM

Getting Started
**
Junior Member
67 posts

Joined: Jun 2015


QUOTE(asellus @ May 7 2020, 10:33 PM)
If you set up the DNS server directly on the computer ethernet adapter (try using Google DNS), will you still see the same problem?
*
Yes.
asellus
post May 8 2020, 05:42 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(PC_CHEAH @ May 8 2020, 05:26 PM)
Yes.
*
Go to /ip dhcp-server network and explicitly tell the DHCP server to only serve the router's IP address OR the Quad9 IP addresses but NOT BOTH.
PC_CHEAH
post May 9 2020, 05:34 PM

Getting Started
**
Junior Member
67 posts

Joined: Jun 2015


QUOTE(asellus @ May 8 2020, 05:42 PM)
Go to /ip dhcp-server network and explicitly tell the DHCP server to only serve the router's IP address OR the Quad9 IP addresses but NOT BOTH.
*
It didn't work though, my VPN devices also get the dns I set.
asellus
post May 9 2020, 05:47 PM

#gompusas
Group Icon
Elite
4,541 posts

Joined: Jan 2003
From: BSRPPG51 Access Concentrator


QUOTE(PC_CHEAH @ May 9 2020, 05:34 PM)
It didn't work though, my VPN devices also get the dns I set.
*
Go to /ip ipsec mode-config and then delete Surfshark's mode-config connection mark and address list. Then disable IPv6. Restart the router, then try going to ipleak.net
cybercrew
post May 13 2020, 01:36 AM

Getting Started
**
Junior Member
183 posts

Joined: Sep 2009
From: Petaling Jaya, Malaysia



Anyone using USB LAN Adapter on Mikrotik RB750gr3 here?

If yes please share the model of your USB Lan Adapter.

It seems only ASIX AX88772 chipset will work but many are areporting even that doesnt work in mikrotik forum.


quadcube
post May 13 2020, 12:22 PM

Regular
******
Senior Member
1,924 posts

Joined: May 2009
From: Yokohama, JP


QUOTE(cybercrew @ May 13 2020, 01:36 AM)
Anyone using USB LAN Adapter on Mikrotik RB750gr3 here?

If yes please share the model of your USB Lan Adapter.

It seems only ASIX AX88772 chipset will work but many are areporting even that doesnt work in mikrotik forum.
*
just tested mine USB LAN adapter on my HAP AC.

HAP AC detects the USB LAN adapter and list it as an ethernet interface (Auto nego: incomplete, rate: unknown)
on the other end, device could not get any IP
added the new interface to bridge, DHCP now serves an IP to the device

The USB LAN adapter that I tested
https://www.planex.co.jp/products/usb-lan1000r/spec.shtml
cybercrew
post May 13 2020, 08:30 PM

Getting Started
**
Junior Member
183 posts

Joined: Sep 2009
From: Petaling Jaya, Malaysia



QUOTE(quadcube @ May 13 2020, 12:22 PM)
just tested mine USB LAN adapter on my HAP AC.

HAP AC detects the USB LAN adapter and list it as an ethernet interface (Auto nego: incomplete, rate: unknown)
on the other end, device could not get any IP
added the new interface to bridge, DHCP now serves an IP to the device

The USB LAN adapter that I tested
https://www.planex.co.jp/products/usb-lan1000r/spec.shtml
*
Thanks..but where did you got this from..I couldn't find this model in lazada or shopee..

Any other model.apart.from.this?
quadcube
post May 13 2020, 08:46 PM

Regular
******
Senior Member
1,924 posts

Joined: May 2009
From: Yokohama, JP


QUOTE(cybercrew @ May 13 2020, 08:30 PM)
Thanks..but where did you got this from..I couldn't find this model in lazada or shopee..

Any other model.apart.from.this?
*
bought a bunch of them from JP, it's one of the popular driverless USB LAN adapter in JP. not sure if there's any in MY

don't have any other USB LAN adapter to test
cybercrew
post May 13 2020, 09:04 PM

Getting Started
**
Junior Member
183 posts

Joined: Sep 2009
From: Petaling Jaya, Malaysia



no wonder.. when i google .. it is mostly redirecting to JP stores.. anyway thanks for the info.
quadcube
post May 13 2020, 10:49 PM

Regular
******
Senior Member
1,924 posts

Joined: May 2009
From: Yokohama, JP


QUOTE(cybercrew @ May 13 2020, 09:04 PM)
no wonder.. when i google .. it is mostly redirecting to JP stores.. anyway thanks for the info.
*
try to find the adapter that supports CDC-ECM or CDC-NCM (linux driver) out of the box. not sure what is the exact problem that u faced but my assumption would be something related to drivers?
engonaplane
post May 13 2020, 11:41 PM

New Member
*
Junior Member
43 posts

Joined: Mar 2020
QUOTE(th3game @ Dec 18 2019, 04:42 PM)
hi guys..im still exploring my new hap ac2 and got question..
» Click to show Spoiler - click again to hide... «


Aleady tried to use mikrotik wifi to connect to those local IP but cannot sad.gif

Any solutions/suggestions will be highly appreciated..sorry if my question is bit noob
*
if i recall correctly you can do a manual ARP route to force it across. But however I am curious / don't understand why you decided to run 3 VLANs in your home just to split by AP.

I have the same setup (but only 1 mikrotik). All run on the same network range (no VLAN) allowing me to easily maintain all APs regardless where I am connected. I don't think you use up 200+ IP addresses right?

QUOTE(th3game @ Mar 14 2020, 10:38 PM)
anyone managed to setup IPSec ikev2 on mikrotik router for remote clients?

*
this should help
https://forum.mikrotik.com/viewtopic.php?t=145138

hao0302
post May 16 2020, 02:24 AM

New Member
*
Junior Member
49 posts

Joined: May 2011


QUOTE(th3game @ Dec 18 2019, 04:42 PM)
hi guys..im still exploring my new hap ac2 and got question..

I have the following setup:

Internet ---->HAP AC2 (local ip 192.168.1.1) --->Dlink dgs 1100 switch (static local IP 192.168.1.2)---> asus router as APs static local ip 192.168.1.3 & 192.168.1.4 (not Vlan aware devices)

hap ac2 trunking port 2 (vlan30,vlan40) to the switch port 1 n configured as tagged vlans
asus AP 1 connect to port 3 on switch as untagged vlan30
asue AP 2 connect to port 4 on switch as untagged vlan40

vlan30 - tagged port 1, untagged port 3
vlan40 - tagged port 1, untagged port 4
management vlan - vlan1

router hap ac2
DHCP address space : 192.168.1.0/24
gateway for DHCP network : 192.168.1.1
addresses to give out : 192.168.1.10 - 192.168.1.254

interface : vlan30
DHCP address space : 10.10.30.0/24
gateway for DHCP network : 10.10.30.1
addresses to give out : 10.10.30.2 - 10.10.30.254

interface : vlan40
DHCP address space : 10.10.40.0/24
gateway for DHCP network : 10.10.40.1
addresses to give out : 10.10.40.2 - 10.10.40.254

default config enable for hap ac2

i can access the internet wifi from asus AP 1 and got ip 10.10.30.254
i can access the internet wifi from asus AP 2 and got ip 10.10.40.254

questions..

I am able to connect to the hap ac2 local IP (192.168.1.1) via Winbox when connected to mikrotik wifi

I also want to be able to connect to the switch (192.168.1.2) & Asus APs (192.168.1.3 & 192.168.1.4) via local IP wirelessly.

Aleady tried to use mikrotik wifi to connect to those local IP but cannot sad.gif

Any solutions/suggestions will be highly appreciated..sorry if my question is bit noob
*
You need to enable forward between vlan30,40 with the local ip under ip>firewall.
Btw if you are not planning to isolate these three network you may use only one ip range instead of difference vlans.

quadcube
post Jun 8 2020, 09:44 PM

Regular
******
Senior Member
1,924 posts

Joined: May 2009
From: Yokohama, JP


anyone managed to maintain IKEv2 connection for more than 8 minutes?

setup an IKEv2 VPN server on the HAP AC^2, certificate authenticated. client used is a Mac.

176 Pages « < 107 108 109 110 111 > » Top
 

Change to:
| Lo-Fi Version
0.0232sec    0.51    6 queries    GZIP Disabled
Time is now: 21st December 2025 - 10:16 PM