The official Mikrotik router thread

Please may I ask for your guidance I have a RB951Ui-2HnD. I have implemented a firewall rule that has locked me out of the Webconfig page, I can't seem to access via WinBox either, there is no serial connection on these devices that I know of, does anyone perhaps know if there is a way of connecting to it and deleting that rule, without a full reset?

:oops: forgot to take a backup before doing so.

https://mikrotik.com/product/RB951Ui-2HnD

I have been googling and trying different ideas for a full day now to try avoid the reset.

Some other ways to try connecting are:
  1. Telnet
  2. SSH
  3. MAC telnet with another ROS device or through Neighbor Viewer (https://mikrotik.com/download/neighbour.zip)
If the RB is not being detected in neighbor viewer, try "mac telnet to" using the mac address associated with the port number you are physically connected to. Test all 5 ports. The first and last mac addresses are listed on the label under the router, using this the other 3 ports mac addresses can be determined.
 
Just noticed I posted in the incorrect thread. Have moved.
 
Last edited:
Please may I ask for your guidance I have a RB951Ui-2HnD. I have implemented a firewall rule that has locked me out of the Webconfig page, I can't seem to access via WinBox either, there is no serial connection on these devices that I know of, does anyone perhaps know if there is a way of connecting to it and deleting that rule, without a full reset?

:oops: forgot to take a backup before doing so.

https://mikrotik.com/product/RB951Ui-2HnD

I have been googling and trying different ideas for a full day now to try avoid the reset.
Oof, I made sure when trying these I limited them to certain ports that aren't in use allowing if something happens there is a backup. Have you tried ssh/telnet?
 
Oof, I made sure when trying these I limited them to certain ports that aren't in use allowing if something happens there is a backup. Have you tried ssh/telnet?
Thanks for the suggestion, I think in my attempt to be secure I previously disabled SSH and telnet,, seems I did a really good job of locking myself out , but I had to reset and start from an older backup in the end. However it was a valuable lesson in running my home network, appreciate the response thanks
 
Does Mikrotik have a Device that can do adsl ( because at airport we only have that ) but also a fibre connection for when we do upgrade ?
 
Does Mikrotik have a Device that can do adsl ( because at airport we only have that ) but also a fibre connection for when we do upgrade ?
Negative,you can add a cheap modem via WAN port for ADSL,its a bit obscure tech worldwide to dedicate resources to develop for afaik (USB might work but I can't confirm it)
 
Does anybody here have an opinion on the Mikrotik MQS and Woobm's usefulness?
 
What would the firewall command be to allow any traffic to and from a certain IP?

I would like to open/allow incoming and outgoing traffic to a certain IP (vm in the cloud).

Thank you.
 
Yes, I have.

/ip firewall filter
add action=accept chain=input connection-state=established,related
add action=drop chain=input connection-state=invalid
add action=accept chain=input icmp-options=8:0-255 protocol=icmp
add action=accept chain=input dst-port=53,123 in-interface=bridge-lan protocol=udp
add action=drop chain=input
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1-fibre
 
In IP Tables, I use this:


root@server:~# iptables -I INPUT -p tcp -s 1.2.3.4 -j ACCEPT
root@server:~# iptables -I OUTPUT -p tcp -s 1.2.3.4 -j ACCEPT
 
Well,its easy enough to whitelist traffic,but it might not be what you're after unless you do a blanket deny with specific allow rules

In IP Tables, I use this:


root@server:~# iptables -I INPUT -p tcp -s 1.2.3.4 -j ACCEPT
root@server:~# iptables -I OUTPUT -p tcp -s 1.2.3.4 -j ACCEPT

Firewall -> Filter
CHAIN: Forward
ACTION: Accept

SOURCE ADDRESS: IP
or
DESTINATION ADDRESS: IP
 
In IP Tables, I use this:


root@server:~# iptables -I INPUT -p tcp -s 1.2.3.4 -j ACCEPT
root@server:~# iptables -I OUTPUT -p tcp -s 1.2.3.4 -j ACCEPT
Mikrotik is identical:
/ip firewall filter
add action=accept chain=input protocol=tcp src-address=1.2.3.4
 
Any of you tried the Lora routers from Mikrotik?

I am thinking of running a Lora gateway and it seems Mikrotik now offers gateways.

Anyone doing anything in the Lora space?
 
Any of you tried the Lora routers from Mikrotik?

I am thinking of running a Lora gateway and it seems Mikrotik now offers gateways.

Anyone doing anything in the Lora space?
There's someone doing iot temperature monitoring of an egg hatchery using LoRa
 
So, with all the Govt BS and snooping, I want to setup Express VPN on my Routerboard 750 ... anyone done this, and can give some guidance? The "how-to" online doesn't make any sense to me

Thanks
 
So, with all the Govt BS and snooping, I want to setup Express VPN on my Routerboard 750 ... anyone done this, and can give some guidance? The "how-to" online doesn't make any sense to me

Thanks
I'm also interested in this, but I have NordVPN and would like to use wireguard...
 
Top
Sign up to the MyBroadband newsletter
X