The official Mikrotik router thread

Me again. Not sure if this is a Mikrotik question or Wireguard question :)

Scenario: My wife is a contractor, meaning multiple clients, and use our company email, gmail, etc. One of the companies she is contracted to, only allows her to use their notebook, which is so locked down it is stupid (no gmail, no personal Onedrive, crap like that). Now 2FA on their main package is registered to her gmail account, but she can't access it from her PC, and retyping codes from a phone is no fun.

I was thinking using a WireGuard VPN (already set up on home environment) to get to Gmail. but obviously installing WireGuard client is not an option. I am sure you can create a manual VPN connect to WireGuard without the client, but I have no idea how to do that.

Like I said, not sure if this is Mikrotik or WireGuard.
TIA
 
Me again. Not sure if this is a Mikrotik question or Wireguard question :)

Scenario: My wife is a contractor, meaning multiple clients, and use our company email, gmail, etc. One of the companies she is contracted to, only allows her to use their notebook, which is so locked down it is stupid (no gmail, no personal Onedrive, crap like that). Now 2FA on their main package is registered to her gmail account, but she can't access it from her PC, and retyping codes from a phone is no fun.

I was thinking using a WireGuard VPN (already set up on home environment) to get to Gmail. but obviously installing WireGuard client is not an option. I am sure you can create a manual VPN connect to WireGuard without the client, but I have no idea how to do that.

Like I said, not sure if this is Mikrotik or WireGuard.
TIA
1. Chrome Incognito -> Rustdesk Webclient -> homepc -> gmail
2. Chrome Incognito -> Apache Guacamole (on RPI5) -> homepc -> gmail
I use a variation of (2)

EDIT:
Also works with Edge or Firefox
 
Last edited:
Me again. Not sure if this is a Mikrotik question or Wireguard question :)

Scenario: My wife is a contractor, meaning multiple clients, and use our company email, gmail, etc. One of the companies she is contracted to, only allows her to use their notebook, which is so locked down it is stupid (no gmail, no personal Onedrive, crap like that). Now 2FA on their main package is registered to her gmail account, but she can't access it from her PC, and retyping codes from a phone is no fun.

I was thinking using a WireGuard VPN (already set up on home environment) to get to Gmail. but obviously installing WireGuard client is not an option. I am sure you can create a manual VPN connect to WireGuard without the client, but I have no idea how to do that.

Like I said, not sure if this is Mikrotik or WireGuard.
TIA
If she is allowed more than one browser then set the other one up with a proxy?
 
Like I said, not sure if this is Mikrotik or WireGuard.
Think this is a Windows problem. Can you even access a hotspot from the phone.

Seems odd they block gmail but allow it as 2fa :) Just get them to issue a new email for the 2fa
 
Think this is a Windows problem. Can you even access a hotspot from the phone.

Seems odd they block gmail but allow it as 2fa :) Just get them to issue a new email for the 2fa
I haven't tried the full config on the PC, first testing on my side. So not even sure if it will work via VPN to bypass their network and proxy, but they might block it elsewhere.

The gmail account was registered on one of the systems they use (as she is actually a contractor). To change that login is more of a ball ache than anything else
 
I haven't tried the full config on the PC, first testing on my side. So not even sure if it will work via VPN to bypass their network and proxy, but they might block it elsewhere.

The gmail account was registered on one of the systems they use (as she is actually a contractor). To change that login is more of a ball ache than anything else
Ok so set up a rule on GMAIL to forward the email to another email address. Let me know where I send the invoice :laugh:
 
What's new in 7.20.6 (2025-Dec-04 14:00):


*) bgp - fixed missing VRF parameter in template configuration after upgrade;
*) console - improved service stability and memory allocation when using "regexp" operator;
*) console - improved service stability when executing commands that can timeout;
*) dhcp - execute "lease-script" with DHCP server creator user permissions;
*) pppoe-server - fixed client disconnects when multiple servers with different service names are active (introduced in v7.20);
*) routerboard - do not show "upgrade-firmware" if available installation is older than minimal supported one;
*) socksify - listen on all addresses for incoming connections;
*) system - updated PCI id names;

Upgrade 2 devices. No issues so far.
 
I'm curious, has anyone here been ARP poisoned/spoofed? I noticed something very odd last night, a ghost ARP entry in my ARP table, on ether1 (my WAN), for a device that hasn't been on for a couple of weeks. If I removed the entry, it would just pop up again a second later. I made a quick change to ether1 ARP from enabled to reply-only, which removed this ghost entry. My FNO doesn't do client isolation, so I suspect there's been some packet leakage, and my filter rules wouldn't have applied due to ARP being layer2...

The weird part is, a quick whois on the IP shows that it's from the US Department of Defence???

Screenshot 2026-01-14 ARP.png
Screenshot 2026-01-14 094147.png
 
I'm curious, has anyone here been ARP poisoned/spoofed? I noticed something very odd last night, a ghost ARP entry in my ARP table, on ether1 (my WAN), for a device that hasn't been on for a couple of weeks. If I removed the entry, it would just pop up again a second later. I made a quick change to ether1 ARP from enabled to reply-only, which removed this ghost entry. My FNO doesn't do client isolation, so I suspect there's been some packet leakage, and my filter rules wouldn't have applied due to ARP being layer2...

The weird part is, a quick whois on the IP shows that it's from the US Department of Defence???

View attachment 1878268
View attachment 1878270
Oh jinne nou is jy in die k@k! :)
 
Oh jinne nou is jy in die k@k! :)
Lol, I don't think I have anything to worry about, my traffic is pretty sterile except for seeding torrents 24/7 on a private tracker. Just odd that that particular IP would be in my ARP, so I'm definitely thinking this is due to the absence of client isolation on the FNO side.
 
What's new in 7.21 (2026-Jan-12 14:56):

Link here because the list is too long to be able to be posted on here:

 
Top
Sign up to the MyBroadband newsletter
X