Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Alarbus
Mar 31, 2010
I have an RB493G at my parents house, and it's on 4.14. The only issue is that it seems to dislike my touchpad running cyanogenmod. I have an RB751 set up at my place, and it's on 5.11 or something. This works fine with the touchpad, interestingly enough. What's the risk of upgrading the 493 to version 5? It would be great to not have to hook up an old unencrypted ap every time I stop by.

When we move, I'm going to have to justify a new 493, I can tell a difference with wired connections, the 493 is just more responsive. The 751 is definitely better than other home routers, though.

Adbot
ADBOT LOVES YOU

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
I've upgraded many many routerboards from 4.x to 5.x. Once, one had to be manually power cycled, then it came up fine. It wouldn't hurt to go to 4.17 first, and ensure the firmware (/system routerboard print; /system routerboard upgrade) is up to date as well.

CuddleChunks
Sep 18, 2004

Upgrade that bad boy to 5.18 or whatever is current. Check System -> License first to make sure you're authorized for 5.x, then full speed ahead!

Alarbus
Mar 31, 2010
Thanks guys! Looks like the 493 can go to 7.x, so I'm good for a while.

Is there a guide for upgrading, or is it just in their wiki? Or is it "push button, wait"?

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
There's probably a few ways to get the software uploaded. I always just ftp upload the new package, reboot, '/system routerboard upgrade', reboot.

Alarbus
Mar 31, 2010
poo poo. The process to 4.17 went fine, the process to 5.19 has not. I don't get the double beep, and WinBox doesn't see the router. Suggestions?

Weird Uncle Dave
Sep 2, 2003

I could do this all day.

Buglord

Alarbus posted:

poo poo. The process to 4.17 went fine, the process to 5.19 has not. I don't get the double beep, and WinBox doesn't see the router. Suggestions?

I had a few rare problems with 3.x to 4.x upgrades, but never one that couldn't be resolved by power-cycling the router.

If you've already done that, you might want to go read up on network boot, and maybe dig out a serial cable.

Alarbus
Mar 31, 2010

Weird Uncle Dave posted:

I had a few rare problems with 3.x to 4.x upgrades, but never one that couldn't be resolved by power-cycling the router.

If you've already done that, you might want to go read up on network boot, and maybe dig out a serial cable.

Yeah, I had to run out, but I'm looking into network boot. Apparently I don't have any serial cables on hand. It's been power cycled a number of times now.


Thanks

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
Odd. Bad download/md5? If FTP upload was binary mode used? Like Dave, I've never had an upgrade issue that couldn't be fixed by a power cycle.

Alarbus
Mar 31, 2010
I dropped the files into WinBox, and was using a wired connection for that. I guess it could be a bad download, I didn't check that first. :(

CuddleChunks
Sep 18, 2004

Alarbus - :( I'm sorry this went buggy on you.

Now is the time for fun. Plug in with a serial cable, check the boot sequence. I had to recover a board once from that level and it was goofy but well-documented. You go in, set the boot order to be Netboot. Setup your pc with the netboot software and a known good firmware. Reboot the machine, let it perk up and borg itself with new firmware. It should then boot normally.

Don't forget to upgrade the routerboard internal firmware as you go.
/system routerboard upgrade

Alarbus
Mar 31, 2010

CuddleChunks posted:

Alarbus - :( I'm sorry this went buggy on you.

Now is the time for fun. Plug in with a serial cable, check the boot sequence. I had to recover a board once from that level and it was goofy but well-documented. You go in, set the boot order to be Netboot. Setup your pc with the netboot software and a known good firmware. Reboot the machine, let it perk up and borg itself with new firmware. It should then boot normally.

Don't forget to upgrade the routerboard internal firmware as you go.
/system routerboard upgrade

Yeah. I did the firmware upgrade after 4.17, and that came up fine. 5.19 didn't go so well. It beeps once, which tells me that it at least isn't hard bricked, but apparently the serial to usb adapters locally were not the proper gender. Now waiting on an Amazon shipment.

I'd probably be less cranky if I hadn't also had to have nine sutures removed today, from a nasty cut on my pinky from a beer glass breaking while washing it. What a pain.

Alarbus
Mar 31, 2010
So, this isn't going well.

I have a USB to serial adapter, and a serial cable. Both PuTTy and HyperTerm can see serial adapter and open a connection on COM5. I've tried 9600 and 115200 baud, with the parity, stop and flow control set correctly. Both applications give me a blank window on boot up. :(

It beeps once, and there's the faint click shortly after, but nothing else. I'm not sure what else to try, since I can't get the serial console to come up with ANYTHING.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
Can you confirm that the serial console and settings work properly on another device? 115k is the default for Mikrotik, 9600 for pretty much any other router (Cisco, Juniper, etc).

You could try this procedure: http://wiki.mikrotik.com/wiki/Manual:Netinstall

Alarbus
Mar 31, 2010
Yeah, after I wrote that, I moved everything to the desktop and tried again, no luck. I initially tried it with 9600 baud, but moved it to 115200 based on the Mikrotik docs.

Maybe I'm missing something, but I have Netinstall open, but the device doesn't show up. Is there a trick to using it that I'm missing?

CuddleChunks
Sep 18, 2004

Unfortunately you have to get into the unit's serial interface in order to talk to the underlying routerboard bootloader and tell it that it should netboot. It doesn't do it by default.

Crapola.

Hell, I'd be happy to take a crack at fixing it if you wanted to send it over my way. Let me take a look at some other things I've got here and see if there might be a serial setting that works best for that before you do anything.

From the manual we have: 115200bit/s, 8 data bits, 1 stop bit, no parity by default. Turn off Flow Control. Fire up hyperterminal, set those settings, whack the spacebar a few times to try and sync up and then reboot. You should get a boot screen flashing by as the unit boots. If it doesn't, I'd call the vendor and report it as a busted unit. It should *not* glitch out on a simple firmware upgrade.

CuddleChunks fucked around with this message at 19:32 on Aug 15, 2012

Alarbus
Mar 31, 2010
I've tried both reset buttons, and just double checked the settings in PuTTY and HyperTerm. I sent an email to r0c-n0c, hopefully I hear from them soon.

I mean, it COULD be something between the usb-serial adapter, but that's brand new, and the f/f serial cable, but that's also brand new. I'd prefer to avoid buying more poo poo from Staples. I checked the order history at r0c-n0c, I bought it October of last year. I still have warranty left, right?


Edit: Called Tom at r0c-n0c. Serial cable is not crossover serial cable (null modem). Throwing more money at Amazon for overnight. Hopefully I can fix this tomorrow! He said that as long as it beeps once, you can fix it, but you have to use the serial cable to get it to trigger netinstall. Woo.

Alarbus fucked around with this message at 19:47 on Aug 15, 2012

Alarbus
Mar 31, 2010
Double post, but IT WORKS.

Buy a null modem cable folks, that was a five minute process with the right part. Despite my screwing around with the wrong part, this was probably the easiest repair process ever. No wonder everyone was confused when nothing I did worked.

Thanks guys! Also, props to Tom at r0c-n0c for answering the phone while on the road and making sure I understood the whole process.

niss
Jul 9, 2008

the amazing gnome
I've looked around online and can't seem to locate anything, but is there any type of rack mount housing for the RB751. I am looking to replace my aging wrt54g and am really interested in this unit, but want to be able to rack mount it in my cabinet.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
http://www.balticnetworks.com/mikrotik-rackmount-adapter-for-routerboard-rb-750-series-triple.html

niss
Jul 9, 2008

the amazing gnome

Thank you.. exactly what I was looking for. I guess I couldn't find it since they are calling it an adapter.

thebigcow
Jan 3, 2001

Bully!
How well does the wireless work after its been shoved into a rack full of metal stuff?

Alarbus
Mar 31, 2010

thebigcow posted:

How well does the wireless work after its been shoved into a rack full of metal stuff?

Well, the RB751 has a spot for an external MMCX antenna, he could (should) just be running that out of the metal.

TX297
Nov 7, 2005

IM A HUGE FAGGOT WHO STEALS BYOB AVATARS.
Alright, it seems since DNSChanger Monday Suddenlink has decided to hijack all my DNS requests and route them through their servers despite me having everything set up for OpenDNS. I can opt out of their stupid "search suggestions", but it switches back silently every 2 weeks and I like my connection to be RFC2308-compliant, but whatever.

I know in DD-WRT I could set a bogus nxdomain entry for the search page IPs using DNSMasq, but I have no clue how to approach it with RouterOS.

NOTinuyasha
Oct 17, 2006

 
The Great Twist
You can sign up for Hurricane Electric's IPv6 tunnel service and push all DNS requests over that? That seems like a sane response to me. It's free and they probably have a tunnel server local enough that there's no impact on performance.

Weird Uncle Dave
Sep 2, 2003

I could do this all day.

Buglord

TX297 posted:

Alright, it seems since DNSChanger Monday Suddenlink has decided to hijack all my DNS requests and route them through their servers despite me having everything set up for OpenDNS. I can opt out of their stupid "search suggestions", but it switches back silently every 2 weeks and I like my connection to be RFC2308-compliant, but whatever.

I know in DD-WRT I could set a bogus nxdomain entry for the search page IPs using DNSMasq, but I have no clue how to approach it with RouterOS.

The Mikrotik DNS service is fairly limited (here's the wiki page). I don't think you can do NXDOMAIN or other custom responses; it basically only does A records.

How are they doing what they're doing? Is your router getting DNS servers from your ISP, that they keep changing back/overriding, or are they actually intercepting and rewriting DNS packets? (If the latter, do you also have problems with other outside DNS, like Google's servers?)

TX297
Nov 7, 2005

IM A HUGE FAGGOT WHO STEALS BYOB AVATARS.

Weird Uncle Dave posted:

The Mikrotik DNS service is fairly limited (here's the wiki page). I don't think you can do NXDOMAIN or other custom responses; it basically only does A records.

How are they doing what they're doing? Is your router getting DNS servers from your ISP, that they keep changing back/overriding, or are they actually intercepting and rewriting DNS packets? (If the latter, do you also have problems with other outside DNS, like Google's servers?)

I believe they're actually intercepting and rewriting DNS packets. I have an OpenDNS account that stays updated with my dynamic IP, opendns.com/welcome works as intended, I have 208.67.220.220 and 208.67.222.222 set as the DNS servers in RouterOS, and I've tested the behavior setting the DNS servers in TCP/IP settings on my PC. I was an early DNSCrypt tester so I have the client installed on my MacBook which returns NXDOMAIN on nonexistent domains as intended and they recently released the PC client, so I think I'm going to give that a look. I'd like to have handled it at the source, but oh well. If it really bugs me I'll plug in my original WRT54G and delegate DNS off to that. I'd really like to find out how it's happening, as OpenDNS can only confirm it's my ISP and my ISP will pretty much tell me the only way to resolve it is to get a business account. Ugh, I can't wait to move out of this town next year...

feld
Feb 11, 2008

Out of nowhere its.....

Feldman

NOTinuyasha posted:

You can sign up for Hurricane Electric's IPv6 tunnel service and push all DNS requests over that? That seems like a sane response to me. It's free and they probably have a tunnel server local enough that there's no impact on performance.

I wouldn't trust that every application can handle doing IPv4 lookups to an IPv6 DNS server. There's still a huge amount of broken DNS stuff out there and remember not every program uses the OS DNS recursor code. First example off the top of my head is FireFox.

edit: Chrome also has their own DNS recursor code.

feld fucked around with this message at 17:46 on Aug 20, 2012

NOTinuyasha
Oct 17, 2006

 
The Great Twist
It shouldn't matter if he's using the the RouterOS DNS server for his LAN, which is the default configuration. Though according to this thread, the built-in DNS server is totally busted and worth avoiding so there's no way to win.

chizad
Jul 9, 2001

'Cus we find ourselves in the same old mess
Singin' drunken lullabies
Has anyone ordered MikroTik kit from Xagyl Communications before? Seems like they have the best pricing for the RB750GL/RB250GS combo I'm looking at, but I'm seeing some really funky behavior with their online store that's making me wonder if I should trust them with my billing info. What's happening is when I search for either of the above (or any other item, it looks like), it shows "In Stock" in the search results list and on the actual product page. But when I add it to my cart, the status changes to "Out of Stock". (If you stay on the product page for a bit, you can watch the status change on it's own, or if you go to your cart and then back to the product you'll see it's changed.) I can't tell if this is just a quirk of whatever shopping cart software they're using or if their site is horribly broken and I should order from somewhere else.

chizad fucked around with this message at 19:36 on Aug 27, 2012

other people
Jun 27, 2004
Associate Christ

chizad posted:

Xagyl Communications

I ordered a device from them a few months ago, it came up as order #34 or something cute like that. It took a while to show up, but it was the right thing and nothing funny happened with the CC that I noticed.

I am not eager to order from them again, but it worked, so whatever.

chizad
Jul 9, 2001

'Cus we find ourselves in the same old mess
Singin' drunken lullabies

Kaluza-Klein posted:

I ordered a device from them a few months ago, it came up as order #34 or something cute like that. It took a while to show up, but it was the right thing and nothing funny happened with the CC that I noticed.

I am not eager to order from them again, but it worked, so whatever.

That gives me a bit more confidence in them, but I ended up just spending the extra :10bux: and ordered from r0c-n0c. My order already shipped and should be here tomorrow, but it may not be until next week that I get a chance to get everything set up.

Nystral
Feb 6, 2002

Every man likes a pretty girl with him at a skeleton dance.

chizad posted:

That gives me a bit more confidence in them, but I ended up just spending the extra :10bux: and ordered from r0c-n0c. My order already shipped and should be here tomorrow, but it may not be until next week that I get a chance to get everything set up.

Tom is a great guy and incredably responsive.

I got a RB493 + r52Hn and trying to set it up and running into some issues due to my complete lack of knowledge of what I just go myself into.

I want to create a total of 4 VLANs
Eth1 and WLAN in VLAN 1
Eth2, 4, and 6 in VLAN 2
Eth3, 5, and 7 in VLAN 3
Eth 8 and 9 in VLAN 4

VLAN1 cannot communicate to any other VLAN
VLAN 2 and 3 can communicate with 4 but no each other.

* Using winbox I got a DHCP server running and serving out IPs on 192.168.88.0/24 off eth1. Will I have to create DHCP "servers" for all interfaces?

* How do I create a vlan for the above interfaces? Initally it looks like I'm stuck with creating different "vlan segments" for each interfac and then assigning them to the same VLAn vs creating one vlan and assigning several inerfaces to it.

* can I create a virtual AP with a second SSID and assign that to VLAN 2? How?

other people
Jun 27, 2004
Associate Christ

chizad posted:

That gives me a bit more confidence in them, but I ended up just spending the extra :10bux: and ordered from r0c-n0c. My order already shipped and should be here tomorrow, but it may not be until next week that I get a chance to get everything set up.

I bought a mikrotik from them that came with a bent ethernet port and my email to them was not responded to :/. It's all a crap shoot.

CuddleChunks
Sep 18, 2004

What in the gently caress are you doing Nystral?

Blocking communication from one VLAN to another sounds like firewall duties and some creative IP range trickery but holy hell what weirdass setup are you trying to make?

Nystral
Feb 6, 2002

Every man likes a pretty girl with him at a skeleton dance.

CuddleChunks posted:

What in the gently caress are you doing Nystral?

Blocking communication from one VLAN to another sounds like firewall duties and some creative IP range trickery but holy hell what weirdass setup are you trying to make?

It's going to sit in front of 3 Mac Minis running ESXi with thunderbolt to gig Ethernet adapters. So the onboard NICs will be in one vlan and the thunderbolts on another. There is also a ReadyNAS in there (VLAN4) for VM storage. The major thing was that it all fits in a backpack, which is why I am trying to make this work vs separating this out to a managed switch and consumer router/firewall combo.

However I had been so focused on using VLANS I forgot about firewalls entirely. :(

falz
Jan 29, 2005

01100110 01100001 01101100 01111010

Nystral posted:

Tom is a great guy and incredably responsive.

I got a RB493 + r52Hn and trying to set it up and running into some issues due to my complete lack of knowledge of what I just go myself into.

I want to create a total of 4 VLANs
Eth1 and WLAN in VLAN 1
Eth2, 4, and 6 in VLAN 2
Eth3, 5, and 7 in VLAN 3
Eth 8 and 9 in VLAN 4

VLAN1 cannot communicate to any other VLAN
VLAN 2 and 3 can communicate with 4 but no each other.

* Using winbox I got a DHCP server running and serving out IPs on 192.168.88.0/24 off eth1. Will I have to create DHCP "servers" for all interfaces?

* How do I create a vlan for the above interfaces? Initally it looks like I'm stuck with creating different "vlan segments" for each interfac and then assigning them to the same VLAn vs creating one vlan and assigning several inerfaces to it.

* can I create a virtual AP with a second SSID and assign that to VLAN 2? How?
Do you actually need them to be VLANs, or just unique within the Mikrotik? If you don't need tagged frames to leave the Mikrotik, just setup bridge groups with the ports as members, put the IP addresses you want on each bridge interface, then a firewall rules with default deny to block.

Virtual AP is pretty much the same, bridge your virtual interface to whatever bridge interface.

Not posting any sample code for this, it's pretty pointy-clicky if you're using winbox.

If you do need VLANs it's kind of annoying to configure trunk ports - to have multiple VLANs interfaces created- one for each vlan+physical interface combo. I seem to have this example documented already:
code:
/interface bridge
 add name=bridge-vlan101
 add name=bridge-vlan102

/ip address
 add address=10.0.1.1/24   interface=bridge-vlan101
 add address=10.0.255.1/24 interface=bridge-vlan102

/interface vlan
 add interface=ether4 name=ether4-vlan101 use-service-tag=no vlan-id=101
 add interface=ether4 name=ether4-vlan102 use-service-tag=no vlan-id=102

 add interface=ether5 name=ether5-vlan101 use-service-tag=no vlan-id=101                                                                                
 add interface=ether5 name=ether5-vlan102 use-service-tag=no vlan-id=102

/interface bridge port
 ; one untagged vlan per physical interface
 add bridge=bridge-vlan101 interface=ether4
 add bridge=bridge-vlan101 interface=ether5

 ; one or more tagged vlan per physical interface
 add bridge=bridge-vlan101 interface=ether4-vlan101
 add bridge=bridge-vlan102 interface=ether4-vlan102

 add bridge=bridge-vlan101 interface=ether5-vlan101
 add bridge=bridge-vlan102 interface=ether5-vlan102

falz fucked around with this message at 22:13 on Aug 28, 2012

CuddleChunks
Sep 18, 2004

Nystral posted:

~~Crazytalk~~

Thank you for describing this setup. It sounds hella complicated but I hope that falz's sweet VLAN info will help you get going.

Mug
Apr 26, 2005
Can anyone who uses a mikrotik in their home network actually see this website?
https://kmau.dealer-portal-ap.net/irj/portal

Because I sure has hell can't, and neither can anyone else I know who uses mikrotik in any configuration. Every other router works fine.

Adbot
ADBOT LOVES YOU

CuddleChunks
Sep 18, 2004

Works fine in IE9, not in Chrome. See your HoTS thread for more info.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply