Additional MIBs in Mikrotik Dude

Mikrotik Dude is the NMS framework solution. It’s capable of monitoring any network device with SNMP support. The SNMP protocol (RFC1157 and other) is the public standard for network management. Therefore, Windows supports the SNMP protocol. You can check these posts about the SNMP feature or Dude monitoring.

In this post, I will show you how to add a few Microsoft MIB files into the Dude’s MIB repository. And this process is very simple. Even better; you can use the same process for any other device or service.

Continue reading


How to setup the PPTP client in Windows 7 and later

In this article, I will guide you through the process of setup of the PPTP client in Windows 7 and later OS. This tutorial also covers the Windows server platform. The client side setup does not depends on the type of VPN server.

Thanks to the Mikrotik RouterOS and similar platforms, setup for this kind of tunnel is very simple today. Moreover, this tutorial is the client-side part of our PPTP series. You can find here the detailed explanation of the server side setup.

Continue reading

How to integrate your Mikrotik router with Windows AD

Whether you need to authenticate your users for PPP or any other Mikrotik service, you can do that either through the internal database or using the external RADIUS server. On the other hand, your corporate users want to use one login for all network services.

Additionally, you can connect any Mikrotik device with your Windows AD.

Let’s make the magic!

Continue reading

Using PPTP VPN on the Mikrotik router

The PPTP protocol was developed by a group of vendors during the late 1990s. It’s still very popular, although it contains many security issues. The part of its popularity lays in the simplicity of the implementation and the built-in support in virtually every operating system.

The specification for PPTP was published in RFC2637. This type of VPN is well known for implementing on the Microsoft Windows platforms. Additionally, many other vendors implemented (at the very least) the client version and the server part is implemented in Mikrotik RouterOS, too.

Continue reading

Two gateways for Internet access

Today, many companies, even the small ones, have two Internet links. Sometimes, those links are used as a primary and backup link. However, we can use them at the same time and make a kind of automatic load balancing.

The routing scenario when we have two (or more) links, which are active in the same time, is named Equal Cost Multi-Path (ECMP) routing. It’s described in RFC2991, and also is the part of IEEE 802.1q-2014 standard.

Let’s see how to make it in Mikrotik RouterOS.

The Scenario of ECMP routing

The scenario looks like this. A company must have Internet access. They will obtain at least two links from the different ISPs. We will connect both links to the same Mikrotik router.

Mikrotik RouterOS supports this scenario and it’s easy to deploy. However, you need to consider a few aspects in this scenario:

  • Both links must be directly accessible from the Internet – you shouldn’t be NATed by the ISP’s device.
  • In the ECMP scenario, both links must be fast. The bandwidths doesn’t need to be the same, but there is no sense in making this between fast fibre optics link of 20 Mbps and slow ADSL of 2 Mbps.
  • Although this should be obvious, both links must be rock-solid stable. If they aren’t, this will be a real mess and you will have a lot of problems.
  • You need to manually specify the default route
  • This will not work perfectly if you’re using the cable Internet access – in case of the link failure, the cable modem becomes a DHCP server and Mikrotik will try to route through the dead link

What will happen when the first user wants to access the Internet? Mikrotik will forward it to the first link in the list. The second user will be sent to the second link. The third user will go over the third link. If there is no third link, then the first link will be used again. And so on. Mikrotik will assign the exit link dynamically cycling through the list.

What will happen if one link goes down? There will be a short interruption in the service for all users on that link, but the next IP packet will be forwarded on the first available link.

When the second link returns to service, Mikrotik will offload this link in use and send some traffic over the second link. And everything works automatically.

Now you can see why you need to have the links of the approximately same speed and why they must be stable. I saw the effects when they are not both stable – the router will be overloaded with the calculations where to send packets as it continuously must fail over traffic to the stable link.

Configuring ECMP routing

The configuration is very simple. First, write down the speed of every link and calculate their speed ratio.

Here is an example. Let’s say they are 20Mbps and 20Mbps. Then their ratio is 1:1. That means that one connection will go over the first link and one over the second for the perfect balancing.

Here is the second example. Let’s have links of 10 Mbps and 30 Mbps. Then their ratio is 1:3. In this scenario, we will establish one connection over the first link and three connections over the second link for the perfect balancing.

You need to add the default route to the place (which means the Internet and it’s opposite to which means home). If you have only one link, you will specify as the destination and either port name or IP address of the ISPs router as the gateway.


In this scenario, we will add the first gateway and then we will click on the down arrow right to the status field (reachable ether1). We will open again the same field for the gateway.

Now, type the IP address of the second gateway. Repeat this process for every gateway you have. When you finish, click on [ OK ] and add the route to the routing table.

In this scenario, you should enable the option Check Gateway and choose ping. Now, Mikrotik will check the link state and fail over on the error.

In case that your ratio is not 1:1, repeat every gateway according to ratio. So, if the ratio is 1:3, then enter the first gateway once and the second gateway three times.

The best part here is that this process is automatic. When you configure it, Mikrotik will do the rest of the job.

You should intensively monitor the behaviour of your router during the first few days to see if this will work. If you see instabilities or increased load on the router, consider another strategy.

Stay tuned.

Redirecting the USB 3G modem into the Mikrotik virtual router

The selected Mikrotik Routerboards have the USB port. This port is intended to be used either as an additional storage or to connect different external devices, like the USB 3G modem. Now, if you have the USB modem and only Mikrotik VM, what can you do?

Of course, we should use the magic. We can redirect the USB device from the host to the VirtualBox guest. I already described this mechanism in this post. However, we have here a few more steps.

Ready? Then let’s begin.
Continue reading

Your MikroTik router may be compromised

I had a few phone calls from my friends during the past few days related to the new hacker attack on the Mikrotik routers. The unknown file named mikrotik.php appears between the files and you have a new script named script3_. Even more, your firewall is disabled.

This attack exploits vulnerabilities in the Web service. Although this blog claims that this vulnerability is fixed in the RouterOS version 6.38.5, I found that many routers that are not updated to the latest version are infected. A few of mine routers with the RouterOS versions 6.38.5, 6.39.x, 6.40.x or even 6.42.3 were attacked. Continue reading