Why it is a bad idea to block youtube IP address?

Why it is a bad idea to block youtube IP address?

IP address, L7-filter, layer 7
[caption id="attachment_1136" align="alignleft" width="251"] no youtube in our office[/caption] so, at my client's office, there was a need to block youtube access during working hours (08:00-17:00). the local administrator there tried to create rules on mikrotik router OS firewall, using layer7-filter, block youtube ip address, and the result is more complaints from user :-( (more…)
Read More
September 2017, GLC webinar: Integrating Radius with Mikrotik

September 2017, GLC webinar: Integrating Radius with Mikrotik

webinar
Integrating Radius with Mikrotik. In this webinar, we started the discussion from the introduction of radius, AAA concept, and typical RADIUS implementation. We then move forward on example configuration on NAS (to connect to radius), radius server (to allow NAS query the RADIUS server), creating services on radius server, and last create account on radius server. At the end of presentation, we discuss about the benefits of using GLC radius compared to traditional radius server. (more…)
Read More
combining 2 ISP with one mikrotik routerboard

combining 2 ISP with one mikrotik routerboard

load balancing, PCC
In this project (click here for the detail), our client requests to combining 2 ISP with one mikrotik. This case is different from the previous one that was using BGP protocol and whole end devices are using public IP address. This project is challenging because both ISP gives Public IP address which is just enough for point-to-point connection only. End-devices (laptop, PC, etc) will use private IP address, where router will do NAT (Network Address Translation) on these private IP when they are going out to internet. Topology of the network can be seen at the picture above. So, the technical plan would be: (more…)
Read More
Why it is a bad idea to drop packets using l7-filter on mikrotik

Why it is a bad idea to drop packets using l7-filter on mikrotik

firewall, L7-filter, Regex
[caption id="attachment_1079" align="alignleft" width="300"] picture from wikipedia[/caption] This article will explain the effect on RouterOS if you drop packets using l7-filter on mikrotik. As we know from previous articles here,  mikrotik supports Regex for pattern matching. one of its purpose to match traffic based on information on layer 7 (application layer). Mikrotik has wiki page that explain how the L7 filter works. and on that page, they already warns user that using l7-filter for dropping packet will increase CPU usage and cause router instability. (more…)
Read More
August 2017, GLC Webinar: BGP filter on mikrotik

August 2017, GLC Webinar: BGP filter on mikrotik

webinar
BGP filter on mikrotik. In this webinar, we start the discussion with an introduction to BGP like AS to AS connection, comparison BGP routing and traditional routing, also BGP peering. we then talk about problem that might occur during BGP peering, its effects, and the solution. finally we cover an example of how to configure BGP filter on mikrotik. (more…)
Read More
July 2017, GLC Webinar: VRRP on Mikrotik

July 2017, GLC Webinar: VRRP on Mikrotik

webinar
vrrp on mikrotik. In this webinar, we discuss a mikrotik feature that is called VRRP (Virtual Router Redundancy Protocol ) which could provide dedundancy on the your network. We started the webinar by introducing the VRRP protocol, then discuss an example implementation on Mikrotik Router. some mistakes on VRRP configuration were also covered here. (more…)
Read More