Jump to content

Цялата активност

Този поток се обновява автоматично     

  1. Последният час
  2. gbdesign

    UDP flood продължение.

    Добре, сега положението се поизясни. Виждам, че ти се запълва контракс таблицата, което означава, че правиш NAT. По принцип, аз си слагам сървърите винаги зад рутери и до тях DNAT-вам, само това, което трябва да стига до тях. В твоя случай обаче, не ми е ясно, защо въобще ползваш NAT. След като не ти се запълва канала, имаш две възможности: 1. Увеличи размера на NAT таблицата - грешният подход. 2. разкарай NAT правилата. Ако системата е от един сървър, не виждам смислена причина да се прави NAT на машината. Без NATняма да имаш connection tracking и съответно няма да имаш проблем с препълване на таблицата за тях.
  3. Днес
  4. bgoptic

    Продавам антени и захранвания

    Нови MikroTik rbwapg-60adkit 1бр. 240лв./бр. MikroTik Omnitik G-5hacd 1бр. 100лв./бр. SXT SA5 AC 3бр. 110лв./бр. Wi-Tek wi-PMS308GR 1бр. 50лв./бр. Wi-Tek wi-PMS326GFR 1бр. 70лв./бр. Mean Well 24v AD-155B 1бр. 45лв./бр. Mean Well 48v AD-155C 1бр. 45лв./бр. PoE Panel 19 12port Gb  2бр. 30лв./бр. Стари MikroTik rb2011uias-rm 1бр. 85лв./бр. MikroTik rb2011l-rm 1бр. 75лв./бр. SXT 5ac 2бр. 75лв./бр. SXT SA5 ac 1бр. 85лв./бр. TP-Link MC220L 2бр. 30лв./бр. За повече инфо телефон: +420 77 три 016 шест 17(viber) или на Л.С.
  5. talibana

    UDP flood продължение.

    Точно така е, целят ме с udp но с нисък трафик и всичко увисва, намерих един тоол fastnetmon има доста интересни опции,но дали ще ми помогнат в случая, и след това да предавам ип-тата на хостинг компанията и от там да се блокират цели мрежи.
  6. computer

    UDP flood продължение.

    Може би със скриншота от спийдтест, @talibana иска да каже че има 1Г капацитет. Ако е така от другата му графика се виждат пикове по 50 мбит и не се връзва да има влошаване на услугата спрямо предоставената информация. От тук можем да кажем, че или не мери правилно или не блокира правилно или не обяснява правилно.
  7. Велин

    UDP flood продължение.

    Ами тръгваш тогава по каналния ред , започваш да сигнализираш органите и да се жалваш, че услугата ти е саботирана, подаваш жалби където се сетиш, флудовете по принцип са опасен прецедент за сигурността на всяка мрежа. И се молиш да натиснат където трябва та някой да се стресне , все пак на Явор Колев това му е работата.
  8. Купувам Cisco 2960G 8-12 порта на разумна цена , по принцип ми трябва такъв заради размера, че ще е на тясно. Велин о897осем43седем73
  9. 111111

    UDP flood продължение.

    Прочети втория пост Каквото и да режеш на входа на лан картата, то на изхода на срещулежащия интерфейс то вече е минало и запълнило канала.
  10. Вчера
  11. talibana

    UDP flood продължение.

    Човек,не съм тръгнал да се хваля, как да ти го обесня,че търся решение на проблема,нищо повече...
  12. gbdesign

    UDP flood продължение.

    Не ти разбирам вметката. Хвалиш ли се или какво?
  13. Закачи ТВ-то и нас-а към някой суич и пробвай. Да видим дали е от микротика...
  14. bgoptic

    Продавам антени и захранвания

    Нови MikroTik rbwapg-60adkit 1бр. 240лв./бр. MikroTik Omnitik G-5hacd 1бр. 100лв./бр. SXT SA5 AC 3бр. 110лв./бр. Wi-Tek wi-PMS308GR 1бр. 50лв./бр. Wi-Tek wi-PMS326GFR 1бр. 70лв./бр. Mean Well 24v AD-155B 1бр. 45лв./бр. Mean Well 48v AD-155C 1бр. 45лв./бр. PoE Panel 19 12port Gb  2бр. 30лв./бр. Стари MikroTik rb2011uias-rm 1бр. 85лв./бр. MikroTik rb2011l-rm 1бр. 75лв./бр. MikroTik rb750gl 1бр. 35лв./бр. MikroTik Groove 5hn 1бр. 45лв./бр. SXT 5ac 2бр. 75лв./бр. SXT SA5 ac 1бр. 85лв./бр. TP-Link MC220L 2бр. 30лв./бр. За повече инфо телефон: +420 77 три 016 шест 17(viber) или на Л.С.
  15. talibana

    UDP flood продължение.

    да мина на 10ГБ ?
  16. gbdesign

    UDP flood продължение.

    От UDP флуд, не можеш да се опазиш сам. Трябва да го направи доставчика ти на свързаност към Интернет. Обикновено такава услуга се заплаща и обикновено цената и е от порядъка на 2-5К евро. Другият вариант е да си вземеш по-голям канал свързаност и да се надяваш, че няма да го запълнят. Ако обаче интереса, на атакуващите е сериозен, ще те избухат без проблем с много трафик и тогава само първият вариант помага.
  17. talibana

    UDP flood продължение.

    Здравейте, на всички! ето ,че пиша отново пак същата история но на нова глава,така да започна на кратко, от известно време съм под атаките на udp флоод отново, този път проблема,че е самата хардуерна защита неможе да улови самия трафик тъй като не е много голям, а в същото време ми препълва всичко и всичко пада Хоствам цс сървъри и съм все още на челните позиции както за България така Света, но конкуренцията не иска да ме остави (gameservers.bg) в които се съмнявам най-много,защото единствено те останаха на пазара и гледат да откажат стари кучета като мен,но не са познали. по-голямата част от логовете са така! Другото което е,първоначално вдигнах лимит-а на conntrack_max net.netfilter.nf_conntrack_max = 524288 графиката ми от трафика ми. Просто си говорих администратор-а и каза,че такъв трафик на графиките на Radware-а дори не се забелязва на фона на 20ГБ. Имали ли начин с iptables да филтрирам атаки от този род или каузата е загубена отново, Iptables-а съм отворил единствено портовете които ми трябват всичко останало дропвам,но без успех от tcpdump логовете са спофнати ип-та различен размер на пакета различни ип-та като ботнет,но с нисък трафик. Не искам да кастря този порт защото ми е нужен, гледах в един руски форум един модул за iptables CS Validation module for iptables. Но,все си мисля,че ще има някаква ползва от него,все още не съм получил отговор-а от създателя, Ще съм благодарен на някой ако ми даде някакво времемно решение.
  18. Нови MikroTik rbwapg-60adkit 1бр. 240лв./бр. MikroTik Omnitik G-5hacd 1бр. 100лв./бр. SXT SA5 AC 3бр. 110лв./бр. Wi-Tek wi-PMS308GR 1бр. 50лв./бр. Wi-Tek wi-PMS326GFR 1бр. 70лв./бр. Mean Well 24v AD-155B 1бр. 45лв./бр. Mean Well 48v AD-155C 1бр. 45лв./бр. PoE Panel 19 12port Gb  2бр. 30лв./бр. Стари MikroTik rb2011uias-rm 1бр. 85лв./бр. MikroTik rb2011l-rm 1бр. 75лв./бр. MikroTik rb750gl 1бр. 35лв./бр. MikroTik Groove 5hn 2бр. 45лв./бр. SXT 5ac 2бр. 75лв./бр. SXT SA5 ac 1бр. 85лв./бр. SXT Lite5 ac 1бр. 55лв./бр. SXT Lite 5 1бр. 50лв./бр. TP-Link MC220L 2бр. 30лв./бр. За повече инфо телефон: +420 77 три 016 шест 17(viber) или на Л.С.
  19. Гост

    RouterOS 6.44rc1 [Testing]

    6.44rc1 changelog:Important note!!! Backup before upgrade! Due to major IPsec configuration changes in RouterOS v6.44beta39+ (see changelog below), it is advised to make a backup before upgrading. Regular downgrade will still be possible as long as no changes in IPsec peer menu are done. MAJOR CHANGES IN v6.44: ---------------------- !) cloud - added command "/system backup cloud" for backup storing on cloud (CLI only); !) ipsec - added new "identity" menu with common peer distinguishers; !) ipsec - removed "main-l2tp" exchange-mode, it is the same as "main" exchange-mode; !) ipsec - removed "users" menu, XAuth user configuration is now handled by "identity" menu; !) radius - initial implementation of RadSec (Radius communication over TLS); !) speedtest - added "/tool speed-test" for ping latency, jitter, loss and TCP and UDP download, upload speed measurements (CLI only); !) telnet - do not allow to set "tracefile" parameter; !) upgrade - release channels renamed - "bugfix" to "long-term", "current" to "stable" and "release candidate" to "testing"; !) upgrade - "testing" release channel now can contain "beta" together with "release-candidate" versions; ---------------------- Changes in this release: !) ipsec - added new "identity" menu with common peer distinguishers; !) radius - initial implementation of RadSec (Radius communication over TLS); *) dhcpv4-server - use ARP for conflict detection; *) discovery - use source MAC address from master interface for MNDP packets (introduced in v6.44beta50); *) fetch - improved file downloading to slow memory; *) hotspot - added per-user NAT rule generation based on "incoming-filter" and "outgoing-filter" parameters; *) ike1 - fixed memory leak; *) ipsec - allow to specify single address instead of IP pool under "mode-config"; *) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters; *) lte - added initial support for Telit LN940; *) lte - added option to lock the LTE operator; *) smb - added commenting option for SMB users (CLI only); *) supout - fixed Profile output on single core devices; *) userman - added first and last name fields for signup form; *) webfig - improved file handling; *) winbox - improved file handling; *) wireless - improved AR5212 response to incoming ACK frames; *) wireless - improved system stability for all ARM devices with wireless; *) wireless - improved system stability for all MIPSBE devices with 802.11ac wireless; Other changes since v6.43.12: *) bgp - properly update keepalive time after peer restart; *) bridge - added option to monitor fast-forward status; *) bridge - count routed FastPath packets between bridge ports under FastPath bridge statistics; *) bridge - disable fast-forward when using SlowPath features; *) bridge - fixed BOOTP packet forwarding when DHCP Snooping is enabled; *) bridge - fixed DHCP Option 82 parsing when using DHCP Snooping; *) bridge - fixed log message when hardware offloading is being enabled; *) bridge - fixed packet forwarding when changing MSTI VLAN mappings; *) bridge - fixed packet forwarding with enabled DHCP Snooping and Option 82; *) bridge - fixed possible memory leak when using MSTP; *) bridge - fixed system's identity change when DHCP Snooping is enabled (introduced in v6.44beta61); *) bridge - improved packet handling when hardware offloading is being disabled; *) bridge - improved packet processing when bridge port changes states; *) btest - added multithreading support for both UDP and TCP tests; *) btest - added warning message when CPU load exceeds 90% (CLI only); *) capsman - always accept connections from loopback address; *) certificate - added support for multiple "Subject Alt. Names"; *) certificate - enabled RC2 cipher to allow P12 certificate decryption; *) certificate - fixed certificate signing by SCEP client if multiple CA certificates are provided; *) certificate - show digest algorithm used in signature; *) chr - assign interface names based on underlying PCI device order on KVM; *) chr - distribute NIC queue IRQ's evenly across all CPUs; *) chr - fixed IRQ balancing when using more than 32 CPUs; *) chr - improved system stability when insufficient resources are allocated to the guest; *) cloud - added "ddns-update-interval" parameter; *) cloud - do not reuse old UDP socket if routing changes are detected; *) cloud - ignore "force-update" command if DDNS is disabled; *) cloud - improved DDNS service disabling; *) cloud - made address updating faster when new public address detected; *) conntrack - added new "loose-tcp-tracking" parameter (equivalent to "nf_conntrack_tcp_loose" in netfilter); *) console - renamed IP protocol 41 to "ipv6-encap"; *) console - updated copyright notice; *) crs317 - fixed packet forwarding when LACP is used with hw=no; *) crs317 - fixed TX not working on sfp-sfpplus9 interface (introduced in v6.40beta12); *) crs328 - fixed SFP+ interface linking on CRS328-24P-4S+RM (introduced in v6.44beta17); *) crs3xx - fixed packet forwarding through SFP+ ports when using 100Mbps link speed; *) crs3xx - fixed SFP+ linking using 1.25G SFP modules (introduced in v6.44beta39); *) crs3xx - fixed slow bootup, upgrade and SFP status read (introduced in v6.44beta20); *) crs3xx - improved fan control stability; *) crs3xx - improved stability when adding ACL rules on CRS326 and CRS328 devices (introduced in 6.44beta39); *) defconf - fixed configuration not generating properly on upgrade; *) defconf - fixed default configuration loading on RB4011iGS+5HacQ2HnD-IN; *) defconf - fixed IPv6 link-local address range in firewall rules; *) dhcp - added "allow-dual-stack-queue" setting for IPv4/IPv6 DHCP servers to control dynamic lease/binding behaviour; *) dhcp - properly load DHCP configuration if options are configured; *) dhcpv4-server - added "parent-queue" parameter (CLI only); *) dhcpv4-server - added "User-Name" attribute to RADIUS accounting messages; *) dhcpv4-server - fixed service becoming unresponsive after interface leaves and enters the same bridge; *) dhcpv6-client - use default route distance also for unreachable route added by DHCPv6 client; *) dhcpv6-server - allow to add DHCPv6 server with pool that does not exist; *) dhcpv6-server - fixed missing gateway for binding's network if RADIUS authentication was used; *) dhcpv6-server - improved DHCPv6 server stability when using "print" command; *) dhcpv6-server - show "client-address" parameter for bindings; *) discovery - detect proper slave interface on bounded interfaces; *) discovery - fixed malformed neighbor information for routers that has incomplete IPv6 configuration; *) discovery - send master port in "interface-name" parameter; *) discovery - show neighbors on actual bridge port instead of bridge itself for LLDP; *) e-mail - added info log message when e-mail is sent successfully; *) ethernet - added "tx-rx-1024-max" counter to Ethernet stats; *) ethernet - fixed IPv4 and IPv6 packet forwarding on IPQ4018 devices; *) ethernet - fixed linking issues on wAP ac, RB750Gr2 and Metal 52 ac (introduced in v6.43rc52); *) ethernet - fixed packet forwarding when SFP interface is disabled on hEX S; *) ethernet - fixed VLAN1 forwarding on RB1100AHx4 and RB4011 devices; *) ethernet - improved per core ethernet traffic classificator on mmips devices; *) export - fixed "silent-boot" compact export; *) fetch - added "http-header-field" parameter; *) fetch - added option to specify multiple headers under "http-header-field", including content type; *) fetch - fixed fetching with "as-value" creating an empty file (introduced in v6.44beta20); *) fetch - fixed "without-paging" option; *) fetch - improved stability when using HTTP mode; *) fetch - removed "http-content-type" parameter; *) gps - increase precision for dd format; *) gps - moved "coordinate-format" from "monitor" command to "set" parameter; *) health - improved fan control stability on CRS328-24P-4S+RM; *) hotspot - added "https-redirect" under server profiles; *) ike1 - fixed "rsa-key" authentication (introduced in v6.44beta); *) ike2 - added option to specify certificate chain; *) ike2 - added peer identity validation for RSA auth (disabled after upgrade); *) ike2 - allow to match responder peer by "my-id=fqdn" field; *) ike2 - fixed local address lookup when initiating new connection; *) ike2 - improved subsequent phase 2 initialization when no childs exist; *) ike2 - properly handle certificates with empty "Subject"; *) ike2 - retry RSA signature validation with deduced digest from certificate; *) ike2 - send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received; *) ike2 - show weak pre-shared-key warning; *) ipsec - added account log message when user is successfully authenticated; *) ipsec - added basic pre-shared-key strength checks; *) ipsec - added new "remote-id" peer matcher; *) ipsec - allow to specify single address instead of IP pool under "mode-config"; *) ipsec - fixed active connection killing when changing peer configuration; *) ipsec - fixed all policies not getting installed after startup (introduced in v6.43.8); *) ipsec - fixed stability issues after changing peer configuration (introduced in v6.43); *) ipsec - hide empty prefixes on "peer" menu; *) ipsec - improved invalid policy handling when a valid policy is uninstalled; *) ipsec - made dynamic "src-nat" rule more specific; *) ipsec - made peers autosort themselves based on reachability status; *) ipsec - moved "profile" menu outside "peer" menu; *) ipsec - properly detect AES-NI extension as hardware AEAD; *) ipsec - removed limitation that allowed only single "auth-method" with the same "exchange-mode" as responder; *) ipsec - require write policy for key generation; *) kidcontrol - added IPv6 support; *) kidcontrol - added "reset-counters" command for "device" menu (CLI only); *) kidcontrol - added statistics web interface for kids (http://router.lan/kid-control); *) kidcontrol - added "tur-fri", "tur-mon", "tur-sat", "tur-sun", "tur-thu", "tur-tue", "tur-wed" parameters (CLI only); *) kidcontrol - dynamically discover devices from DNS activity; *) kidcontrol - fixed validation checks for time intervals; *) kidcontrol - properly detect time zone changes; *) kidcontrol - use "/128" prefix-length for IPv6 addresses; *) l2tp - fixed IPsec secret not being updated when "ipsec-secret" is changed under L2TP client configuration; *) lcd - made "pin" parameter sensitive; *) led - fixed default LED configuration for RBSXTsq-60ad; *) led - fixed default LED configuration for wAP 60G AP devices; *) led - fixed PWR-LINE AP Ethernet LED polarity ("/system routerboard upgrade" required); *) lldp - fixed missing capabilities fields on some devices; *) lte - added additional ID support for Novatel USB730L modem; *) lte - added "cell-monitor" command for R11e-LTE international modem (CLI only); *) lte - added "ecno" field for "info" command; *) lte - added "firmware-upgrade" command for R11e-LTE international modems (CLI only); *) lte - added initial support for multiple APN for R11e-4G (new modem firmware required); *) lte - added multiple APN support for R11e-4G; *) lte - added support for JioFi JMR1040 modem; *) lte - fixed connection issue when LTE modem was de-registered from network for more than 1 minute; *) lte - fixed DHCP IP acquire in 3G mode for r11e-lte (introduced in v6.44beta54); *) lte - fixed DHCP IP acquire (introduced in v6.43.7); *) lte - fixed DHCP relay packet forwarding when in passthrough mode; *) lte - fixed IPv6 activation for R11e-LTE-US modems; *) lte - fixed Jaton/SQN modems preventing router from booting properly; *) lte - fixed LTE interface not working properly after reboot on RBSXTLTE3-7; *) lte - fixed missing running (R) flag for Jaton LTE modems; *) lte - fixed passthrough DHCP address forward when other address is acquired from operator; *) lte - fixed reported "rsrq" precision (introduced in v6.43.8); *) lte - improved compatibility for Alt38xx modems; *) lte - improved SIM7600 initialization after reset; *) lte - improved SimCom 7100e support; *) lte - query "cfun" on initialization; *) lte - require write policy for at-chat; *) lte - update firmware version information after R11e-LTE/R11e-4G firmware upgrade; *) netinstall - do not show kernel failure critical messages in the log after fresh install; *) ntp-client - fixed "dst-active" and "gmt-offset" being updated after synchronization with server; *) port - improved "remote-serial" TCP performance in RAW mode; *) ppp - added "at-chat" command; *) ppp - fixed dynamic route creation towards VPN server when "add-default-route" is used; *) profiler - classify kernel crypto processing as "encrypting"; *) profile - removed obsolete "file-name" parameter; *) proxy - removed port list size limit; *) radius - implemented Proxy-State attribute handling in CoA and disconnect requests; *) rb3011 - implemented multiple engine IPsec hardware acceleration support; *) rb4011 - fixed SFP+ interface full duplex and speed parameter behavior; *) rb4011 - improved SFP+ interface linking to 1Gbps; *) rbm33g - improved stability when used with some USB devices; *) romon - improved reliability when processing RoMON packets on CHR; *) routerboard - removed "RB" prefix from PWR-LINE AP devices; *) routerboard - require at least 10 second interval between "reformat-hold-button" and "max-reformat-hold-button"; *) sfp - fixed possible reboot loop when inserting SFP modules in CRS328-4C-20S-4S+ (introduced in v6.44beta61); *) smb - fixed macOS clients not showing share contents; *) smb - fixed Windows 10 clients not able to establish connection to share; *) sniffer - save packet capture in "802.11" type when sniffing on w60g interface in "sniff" mode; *) snmp - added "dot1qPortVlanTable" and "dot1dBasePortTable" OIDs; *) snmp - changed fan speed value type to Gauge32; *) snmp - fixed "rsrq" reported precision; *) snmp - fixed w60g station table; *) snmp - removed "rx-sector" ("Wl60gRxSector") value; *) snmp - report bridge ifSpeed as "0"; *) snmp - report ifSpeed 0 for sub-layer interfaces; *) ssh - added "allow-none-crypto" parameter to disable "none" encryption usage (CLI only); *) ssh - added error log message when key exchange fails; *) ssh - close active SSH connections before IPsec connections on shutdown; *) ssh - fixed non-interactive shell not returning all output (introduced in v6.44); *) ssh - fixed public key format compatibility with RFC4716; *) ssh - fixed single command execution (introduced in v6.44beta9); *) supout - fixed "poe-out" output not showing all interfaces; *) switch - added comment field to switch ACL rules; *) switch - fixed ACL rules on IPQ4018 devices; *) system - accept only valid path for "log-file" parameter in "port" menu; *) system - removed obsolete "/driver" command; *) tr069-client - added "check-certificate" parameter to allow communication without certificates; *) tr069-client - added "connection-request-port" parameter (CLI only); *) tr069-client - added support for InformParameter object; *) tr069-client - fixed certificate verification for certificates with IP address; *) tr069-client - fixed HTTP cookie getting duplicated with the same key; *) tr069-client - increased reported "rsrq" precision; *) traceroute - improved stability when sending large ping amounts; *) traffic-flow - reduced minimal value of "active-flow-timeout" parameter to 1s; *) tunnel - properly clear dynamic IPsec configuration when removing/disabling EoIP with DNS as "remote-address"; *) upgrade - made security package depend on DHCP package; *) usb - improved power-reset error message when no bus specified on CCR1072-8G-1S+; *) usb - improved USB device powering on startup for hAP ac^2 devices; *) usb - increased default power-reset timeout to 5 seconds; *) userman - added first and last name fields for signup form; *) userman - show redirect location in error messages; *) user - require "write" permissions for LTE firmware update; *) vrrp - made "password" parameter sensitive; *) w60g - added "10s-average-rssi" parameter to align mode (CLI only); *) w60g - added align mode "/interface w60g align" (CLI only); *) w60g - fixed scan in bridge mode; *) w60g - improved PtMP performance; *) w60g - improved reconnection detection; *) w60g - improved "tx-packet-error-rate" reading; *) w60g - renamed disconnection message when license level did not allow more connected clients; *) w60g - renamed "frequency-list" to "scan-list"; *) watchdog - allow specifying DNS name for "send-smtp-server" parameter; *) winbox - added 4th chain selection for "HT TX chains" and "HT RX chains" under "CAPsMAN/CAP Interface/Wireless" tab; *) winbox - added "allow-dual-stack-queue" parameter in "IP/DHCP Server" and "IPv6/DHCP Server" menus; *) winbox - added "challenge-password" field when signing certificate with SCEP; *) winbox - added "conflict-detection" parameter in "IP/DHCP Server" menu; *) winbox - added "conflict-detection" parameter in "IP/DHCP server" menu; *) winbox - added "coordinate-format" parameter in LTE interface settings; *) winbox - added "radio-name" setting to "CAPsMAN/CAP Interface/General" tab; *) winbox - added "secondary-channel" setting to "CAPsMAN/CAP Interface/Channel" tab; *) winbox - added src/dst address and in/out interface list columns to default firewall menu view; *) winbox - added support for dynamic devices in "IP/Kid Control/Devices" tab; *) winbox - allow setting "network-mode" to "auto" under LTE interface settings; *) winbox - allow specifying interface lists in "CAPsMAN/Access List" menu; *) winbox - fixed "IPv6/Firewall" "Connection limit" parameter not allowing complete IPv6 prefix lengths; *) winbox - fixed L2MTU parameter setting on "W60G" type interfaces; *) winbox - fixed "LCD" menu not shown on RB2011UiAS-2HnD; *) winbox - fixed missing w60g interface status values; *) winbox - moved "Too Long" statistics counter to Ethernet "Rx Stats" tab; *) winbox - renamed "Default AP Tx Rate" to "Default AP Tx Limit"; *) winbox - renamed "Default Client Tx Rate" to "Default Client Tx Limit"; *) winbox - show "R" flag under "IPv6/DHCP Server/Bindings" tab; *) winbox - show "System/RouterBOARD/Mode Button" on devices that have such feature; *) winbox - show "W60G" wireless tab on wAP 60G AP; *) wireless - added new "installation" parameter to specify router's location; *) wireless - improved connection stability for new model Apple devices; *) wireless - improved signal strength at low TX power on LHG 5 ac, LHG 5 ac XL and LDF 5 ac ("/system routerboard upgrade" required); *) wireless - improved system stability for all ARM devices with wireless; *) wireless - improved system stability when scanning for other networks; *) wireless - removed G/N support for 2484MHz in "japan" regulatory domain; *) wireless - report last seen IP address in RADIUS accounting messages; *) wireless - show "installation" parameter when printing configuration; Download the new 'RouterOS 6.44rc1' version here: https://mikrotik.com/download
  20. Аз тотално премахнах firewall filter и nat секциите в стената. Не помага. Чудя се и се мая. Противно на всякаква логика. В един бридж са и 2-та интерфейса и вифи и етернет-а. Но по етернет не ми показва сервиио. Иначе самбата си бачка и през 2-та интерфейса. Ето как изглежда и wi fi интерфейса: name="wlan1" mtu=1500 l2mtu=1600 mac-address=4C:5E:0C:6A:F8:D9 arp=enabled disable-running-check=no interface-type=Atheros AR9300 radio-name="RRD AP" mode=ap-bridge ssid="RRD Home" area="" frequency-mode=manual-txpower country=no_country_set antenna-gain=3 frequency=2422 band=2ghz-g/n channel-width=20/40mhz-XX secondary-channel="" scan-list=default wireless-protocol=802.11 rate-set=default supported-rates-b="" supported-rates-a/g=48Mbps,54Mbps basic-rates-b="" basic-rates-a/g=48Mbps,54Mbps max-station-count=25 distance=indoors tx-power=23 tx-power-mode=all-rates-fixed noise-floor-threshold=default nv2-noise-floor-offset=default vlan-mode=no-tag vlan-id=1 wds-mode=disabled wds-default-bridge=none wds-default-cost=100 wds-cost-range=50-150 wds-ignore-ssid=no update-stats-interval=disabled bridge-mode=enabled default-authentication=yes default-forwarding=yes default-ap-tx-limit=0 default-client-tx-limit=0 wmm-support=disabled hide-ssid=no security-profile=rrd key wps-mode=disabled station-roaming=enabled disconnect-timeout=3s on-fail-retry-time=100ms preamble-mode=both compression=no allow-sharedkey=no station-bridge-clone-mac=00:00:00:00:00:00 ampdu-priorities=0 guard-interval=any ht-supported-mcs=mcs-0,mcs-1,mcs-2,mcs-3,mcs-4,mcs-5,mcs-6,mcs-7,mcs-8,mcs-9,mcs-10,mcs- 11,mcs-12,mcs-13,mcs-14,mcs-15,mcs-16,mcs-17,mcs-18,mcs-19,mcs-20,mcs-21,mcs- 22,mcs-23 ht-basic-mcs=mcs-8,mcs-9,mcs-10,mcs-11,mcs-12,mcs-13,mcs-14,mcs-15,mcs-16,mcs-17,mcs-18, mcs-19,mcs-20,mcs-21,mcs-22,mcs-23 tx-chains=0,1 rx-chains=0,1 amsdu-limit=8192 amsdu-threshold=8192 tdma-period-size=2 nv2-queue-count=2 nv2-qos=default nv2-cell-radius=30 nv2-security=disabled nv2-preshared-key="" nv2-mode=dynamic-downlink nv2-downlink-ratio=50 nv2-sync-secret="" hw-retries=7 frame-lifetime=0 adaptive-noise-immunity=ap-and-client-mode hw-fragmentation-threshold=disabled hw-protection-mode=none hw-protection-threshold=0 frequency-offset=0 rate-selection=advanced multicast-helper=default multicast-buffering=enabled keepalive-frames=enabled Ако забележите нещо което да способства работенето на сервиио кажете... P.S. Форматирай си постовете
  21. Аз лично. при подобна ситуация, нулирам броячите, тествам и гледам кой брояч натрупва или съответно не натрупва данни. Надявам се да съм бил полезен
  22. Последната седмица
  23. Спирах целия firewall за проба. Не се появява сервииото. Иначе самбата на synology си излиза и се достъпва. Не е от правилата в стената. Телевизора е с андроид.Във настройките на тв-то научава сървъра. Но на плеярите: VIMU,VLC го няма сервииото. На един андроид бокс в съседна стая на друг суич няма този проблем.
  24. Спри всички дроп правила и тествай При мен си вървят 2 нас-а и един плекс без никакви ядове жично и безжично в лан-а
  25. Това е: /interface bridge add admin-mac=00:0C:42:70:66:F4 auto-mac=no name=bridge-LAN /interface bridge port add bridge=bridge-LAN interface=ether3-sw.hol add bridge=bridge-LAN interface=ether5-sw.spalnia add bridge=bridge-LAN interface=ether2-sw.detska add bridge=bridge-LAN interface=wlan1 interface bridge settings - use-ip-firewall: no use-ip-firewall-for-vlan: no use-ip-firewall-for-pppoe: no allow-fast-path: yes bridge-fast-path-active: yes bridge-fast-path-packets: 23151 bridge-fast-path-bytes: 5632826 bridge-fast-forward-packets: 0 bridge-fast-forward-bytes: 0 Той си е само за локалната мрежа в която живеят ип адресите 192.168.5.0/24
  26. Идеята е че лан-а е за 2 домакинства. Vlan 10 и мрежа 192.168.10.0/24 е за друго домакинство,върви по ви-ви пренос на 5гхз на около 2км. 3-тата мрежа е за гости ограничена по скорост. Това за разликата между UPnP и DLNA не го разбрах? Пробвах да си пусна UPnP на 2-та интерфейса които са ми към 2-те проблемни устойства. Пак не ми върви Serviio-то. Не вярвам проблема да е в преноса на мултикаст трафик както се споменава по форумите. То ако е така нямаше да върви и по ви-фи.
  27. Сега трябва да си разясниш разликата между UPnP и DLNA. Каква е идеята на толкова адресни групи в домашен лан ?
  1. Зареди още активност
×

Important Information

By using this site, you agree to our Terms of Use.