- Starting Winbox
- Interface Overview
- WinBox не видит микротик
- Can’t see my Mikrotik hAP ac in Winbox
- WinBox не подключается к Mikrotik
- Компьютер не видит mikrotik
- Не видны ПК за микротиками
- Если устройство Микротик полностью недоступно, то его можно восстановить при помощи технологии Netinstall.
- Управление и восстановление подключения после сбоя маршрутизатора MikroTik
- Введение
- «Не могу получить доступ к MikroTik по Ip-адресу»
- «Шеф, все пропало!»
- Вам помогла эта статья?
- Item copy
- Work Area and child windows
- Sorting out displayed items
- Customizing list of displayed columns
- Drag & Drop
- Run Winbox on macOS
- Микротик компьютеры не видят друг друга
- Advanced mode
- Transferring Settings
- Summary
- Troubleshooting
- Run Winbox on Linux
- Traffic monitoring
- Simple mode
- Command Line
- IPv6 connectivity
- Через Mikrotik не видна локалка
Starting Winbox
Winbox loader can be downloaded from the MikroTik download page. When winbox.exe is downloaded, double click on it, and the Winbox loader window will pop up. There are two Winbox loader modes: simple which is enabled by default and advanced.
Для настройки и управления оборудованием Mikrotik, лучше использовать специальную программу WinBox. С её помощью все это делать гораздо удобней. Можно конечно пользоваться и веб интерфейсом Mikrotik. При подключение к Mikrotik через ПО WinBox очень часто возникают различные ошибки, их достаточно много. Но есть самые распространенные которые встречаются в 90% случаях. Сегодня рассмотрим одну самую часто встречающуюся ошибку, которая не позволят подключиться к Mikrotik.
У меня достаточно много статей которые касаются оборудования Mikrotik, рекомендую с ними ознакомиться.
Mikrotik ограничение скорости
Mikrotik работа с провайдером Домру
Как узнать кто загружает канал
Делим трафик поровну Mikrotik
Mikrotik потери пакетов
Interface Overview
- Menu bar on the left — list of all available menus and sub-menus. This list changes depending on what packages are installed. For example if IPv6 package is disabled, then IPv6 menu and all it’s sub-menus will not be displayed.
- Work area — area where all menu windows are opened.
On the Main toolbar’s left side is located undo and redo buttons to quickly undo any changes made to configuration. On the right side is located:
- winbox traffic indicator displayed as a green bar,
- indicator that shows whether winbox session uses encryption
- The menu bar on the left — list of all available menus and sub-menus. This list changes depending on what packages are installed. For example, if the IPv6 package is disabled, then the IPv6 menu and all its sub-menus will not be displayed.
- Work area — an area where all menu windows are opened.

On the Main toolbar’s left side is located:
- undo
- redo
- Safe Mode
- Currently loaded session
More about Safe mode and undoing performed actions read in this article.
- an indicator that shows whether the Winbox session uses encryption
- Winbox traffic indicator displayed as a green bar,
r136a8Сообщения: 201Зарегистрирован: 04 дек 2017, 00:01
WinBox не видит микротик
ChupakaСообщения: 3663Зарегистрирован: 29 фев 2016, 15:26Откуда: Минск
Контактная информация:
12 янв 2021, 14:23
Проблема может быть в наличии нескольких сетевых подключений (например, какой-нибудь VPN с эмуляцией Ethernet, или виртуальный Ethernet от виртуальных машин типа VMware Workstation) — это не тот случай?
12 янв 2021, 14:32
Chupaka писал(а): ↑12 янв 2021, 14:23
Приветствую.
Да Вы были правы, проблема была в виртуальной машине!
Сообщения: 1Зарегистрирован: 19 апр 2022, 08:31
19 апр 2022, 09:47
R1 порт 1 -WAN -пустой
R1 порт 2 -bridgeLAN — R2 WAN
R1 порт 3 -bridgeLAN — R3 WAN
R1 порт 4 -bridgeLAN — R4 WAN
R1 порт 5 -bridgeLAN — MacBook
Видит только два роутера R1, R2((
проверил сервисы, порты, отключил firewall
Winbox loader can be downloaded from the mikrotik download page. When winbox.exe is downloaded, double click on it and winbox loader window will pop up:
Note: It is recommended to use IP address whenever possible. MAC session uses network broadcasts and is not 100% reliable.
You can also use neighbor discovery, to list available routers use Neighbors tab:
From list of discovered routers you can click on IP or MAC address column to connect to that router. If you click on IP address then IP will be used to connect, but if you click on MAC Address then MAC address will be used to connect to the router.
Note: Neighbor discovery will show also devices which are not compatible with Winbox, like Cisco routers or any other device that uses CDP (Cisco Discovery Protocol). If you will try to connect to SwOS device, then connection will be established through web browser
Description of buttons and fields of loader screen
- Connect — Connect to the router
- Connect To RoMON — Connect to RoMON Agent
- Open In New Window — Leaves loader open in background and opens new windows for each device to which connection is made.
- Connect To: — destination IP or MAC address of the router
- Password — password used for authentication
- Keep Password — if unchecked, password is not saved to the list
- Browse — Browse file directory for some specific session
- Keep Password — if unchecked, password is not saved to the list
- Secure mode — if checked, winbox will use DH-1984 for key exchange and modified and hardened RC4-drop3072 encryption to secure session.
- Autosave session — Saves sessions automatically for devices to which connection are made.
- Session — Saved router session.
- Note — Note that is assigned to save router entry.
- Group — Group to which saved router entry is assigned.
- RoMON Agent — Select RoMON Agent from available device list
Description of menu items in loader screen
- New — Create new managed router list in specified location
- Open — Open managed router list file
- Save As — Save current managed router list to file
- Exit — Exit Winbox loader
- Advanced Mode — Enables/Disables advanced mode view
- Import — Imports saved session file
- Export — Exports saved session file
- Move Session Folder — Change path where session files are stored
- Clear cache — Clear winbox cache
- Check For Updates — Check for updates for Winbox loader
Warning: Managed routers list is not encrypted by default. To encrypt it, set the master password!
For example (with no password):
Winbox supports IPv6 connectivity. To connect to the routers IPv6 address, it must be placed in square braces the same as in web browsers when connecting to IPv6 server.
Example:
Winbox neighbor discovery is now capable of discovering IPv6 enabled routers. As you can see from the image below, there are two entries for each IPv6 enabled router, one entry is with IPv4 address and another one with IPv6 link-local address. You can easily choose to which one you want to connect:
Can’t see my Mikrotik hAP ac in Winbox
Hello, I made some changes in my mikrotik hap ac, and then later on I couldn’t connect again to it.
I can’t see device in winbox window. I tried restart holding restart button before plugging it on, but it didn’t helped, tried other LAN ports. Problem is still here.
Ethernet adapter tells this:
Autoconfiguration IPv4 Address. . : 169.254.22.0
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . :
I don’t have an idea what’s going on.
EDIT: Mtik is running, I can see my wireless network, it means that I didn’t restore it to factory settings with restart holding reset button for 5 seconds and plugging to power until he beeps
The normal way to solve this, is using tab «Neighborgs» in WinBOX and see if the hAP ac2 appears. You must be on the same LAN (level 2), no router in between.
Then click the MAC address instead of the IP address, and connect via the MAC address. Use the MAC connect until the IP problem is fixed.
«Neighbors» are empty, I m connected to hAP ac directly to my notebook.
I tried manully set up MAC address to connect, but it didn’t work.
I tried with all other ports.
LED is green solid when I connect to that port.
How to factory reset this device? I tried everything but I can still see my wireless network that I configure on Mikrotik.
I tried turn off and pressing reset button and then turn it on while reset button is pressed for 5sec, 10sec, 15sec, 1 minute.
I restarted it for few times more, and now I can connect it via Winbox.
Huh, thanks for help, hope it wont occur again
I;ve got the same problem on this device. I can’t reset it, pressing 30s before disconnecting, 30 s after plug in power. No change. It still keeps configuration. Any idea how to reset hAP ac2?
When I plug the access point in its not showing up in winbox, or as a mikrotik SSID or even in the app to program. Any suggestions?
I just got exactly same problem with you.
Made some changes and thought something was wrong and that made winbox or web not able to connect to router.
Last edited by thylawrence on Wed Jan 19, 2022 8:34 pm, edited 1 time in total.
Что делать когда winbox не может подключиться к роутеру Mikrotik?
«Could not connect to 192.168.88.1:80 — no response!»

Вот что тогда делать, данный роутер Mikrotik RB951Ui-2Hnd не оборудован консольным портом, чтобы сбросить все настройки.
На заметку : все дальнейшие действия происходят на моей рабочей системе Ubuntu 12.04.5 Desktop amd64
Во многих статьях интернета все больше сводится к тому, что в процессе ранее когда подключали данный Mikrotik не корректно произвели обновление или просто напросто прервали сам процесс, но у меня исключительная ситуация — я не подключал ни куда данный роутер, а купил таким.
Как я уже знаю, что устройства Mikrotik поддерживают такие протоколы управления, как:
Для того, чтобы поправить текущую ситуацию придется задействовать один из ниже указанных способов.
Первый способ: попробовать сделать reset всем настройкам

и через некоторое время (обычно минуту или две) уже можно будет попробовать подключиться к устройству Mikrotik через утилиту winbox — В одном случае у меня данный способ привел к положительному результату, я получил доступ к устройству.
Подключаю сетевой провод в первый порт на устройстве Mikrotik

Запускаю утилиту netinstall через wine, на появившееся окно с надписью «Bind bootp failed: (10013)» не обращаем внимание, т. е. Нажимать OK не следует иначе закроется сама утилита netinstall.
Через Browse указываем каталог местоположения прошивки, в моем случае это /home/aollo, а после нажимаем кнопку Net booting и активируем (Установка галочки Boot Server Enabled и указанием IP адреса текущей системы), что текущая система будет выступать PXE сервером с адресом Вашей системы где запущена утилита netinstall

Раз так, то попробую задействовать резервный ноутбук: HP ProBook 4540s с операционной системой Windows 7 Профессиональная SP1.
Подключаю к ноутбуку (выставляю статику 192.168.88.100) сетевой кабель, а другим разъемом в второй порт на роутере Mikrotik.
Проделываю все операции по переводу роутера Mikrotik в режим загрузки по сети, но так ни на одном из портов ничего не удается сделать. Может я пока чего-то не понимаю.
WinBox не подключается к Mikrotik
И так вы установил WinBox ввели IP адрес Mikrotik, лоин и пароль нажали кнопку «Connect» и увидели вот такую ошибку.
ERROR: router does not support secure connection please enable Legacy Mode if you want to connect anyway
Если перевести то это означает следующие.
Маршрутизатор не поддерживает безопасное соединение пожалуйста, включите устаревший режим, если вы все равно хотите подключиться
Это говорит о том что WinBox пытается подключиться к вашему устройству используя безопасное соединение а ваш Mikrotik его не поддерживает. Т.е у него старая прошивка.

Самый простой способ это включить в WinBox функцию Legacy Mode, она позволяется подключаться к Микротик менее защищенным способ.

Защищенное подключение поддерживается в RouterOS выше версии 6.43. Но лучше обновить прошивку Mikrotik тем более что сделать это очень просто.
Компьютер не видит mikrotik
Бесплатный чек-листпо настройке RouterOSна 28 пунктов
Не видны ПК за микротиками
Правила форума Как правильно оформить вопрос. Прежде чем начать настройку роутера, представьте, как это работает. Попробуйте почитать статьи об устройстве интернет-сетей. Убедитесь, что всё, что Вы задумали выполнимо вообще и на данном оборудовании в частности. Не нужно изначально строить Наполеоновских планов. Попробуйте настроить простейшую конфигурацию, а усложнения добавлять в случае успеха постепенно. Пожалуйста, не игнорируйте правила русского языка. Отсутствие знаков препинания и неграмотность автора топика для многих гуру достаточный повод проигнорировать топик вообще.
1. Назовите технологию подключения (динамический DHCP, L2TP, PPTP или что-то иное) 2. Изучите темку «Действия до настройки роутера». viewtopic.php?f=15&t=2083 3. Настройте согласно выбранного Вами мануала 4. Дочитайте мануал до конца и без пропусков, в 70% случаев люди просто не до конца читают статью и пропускают важные моменты. 5. Если не получается, в Winbox открываем терминал и вбиваем там /export hide-sensitive. Результат в топик под кат, интимные подробности типа личных IP изменить на другие, пароль забить звездочками. 6. Нарисуйте Вашу сеть, рисунок (схему) сюда. На словах может быть одно, в действительности другое.
Прошу помочь начинающему. Настроил VPN через L2tp пока без IPSec. подключение нормально
Две сети 192.168.0.1 и 192.168.1.1 объединены в общую сеть через L2tp. VPN сетка 172.16.30.1-172.16.30.10
Микротик на стороне сети 1 интерфейсе 192.168.1.1 на VPN 172.16.30.1 Микротик на стороне сети 2 : 192.168.0.1 на VPN 172.16.30.2 Пинг ходит с ПК в сети 1 до 192.168.0.1, но не проходит до любого компьютера в сети 2 Тоже самое обратно пинг с сети 2 до 192.168.1.1 ходит нормально но любого компа в сети 1 нет.
Соответственно пинги с сети1 в сеть 2 не проходят
К устройствам компании MikroTik можно подключиться с помощью разных протоколов (в скобках указан используемый по-умолчанию порт):
Управлять способами подключения можно в меню RouterOS: /ip services.

В таком случае, используя утилиту WinBox, мы можем получить доступ к устройству с помощью MAC-адреса (маршрутизатор должен быть подключен к вашей сети патч-кордом):


Если устройство Микротик полностью недоступно, то его можно восстановить при помощи технологии Netinstall.
С помощью патч-корда подключаем компьютер к первому интерфейсу Микротика (на остальных нет загрузки по сети). Прежде чем начать прошивку, рекомендуется отключить все сетевые интерфейсы, кроме того, к которому подключен Микротик, выключить антивирус и брандмауэр (в том числе брэндмауэр WINDOWS).
Дальнейший порядок действий такой:

3. Нажимаем на кнопку Net Booting.

4. Указываем IP адрес 10.1.1.4

5. Переводим Микротик в режим загрузки по сети:
6. Через некоторое время в окне netinstall появится Ваш Микротик, его необходимо выделить.

7. Если Вы хотите сохранить предыдущую конфигурацию — поставьте галочку в чекбоксе “keep old configuration”
8. Выбираем директорию, в которой сохранена прошивка, и жмем Ок.
9. Выбираем прошивку.

10. Обращаем Ваше внимание на то, что не рекомендуется менять значения поля key
11. Нажимаем кнопку install.

12. Ожидаем, пока прошивка загрузится на Микротик, установится и устройство перезагрузится.

Теперь можно сбросить настройки устройства на дефолтные при помощи кнопки RESET и подключиться к устройству по адресу 192.168.88.1
Управление и восстановление подключения после сбоя маршрутизатора MikroTik
г. Санкт-Петербург, ст. м. «Приморская»,ул. Одоевского, д. 24 к. 1, 2 этаж
![]()
В данной статье мы рассмотрим способы подключения к RouterOS после сбоя.
Введение
К устройствам компании MikroTik можно подключиться с помощью разных протоколов:

«Не могу получить доступ к MikroTik по Ip-адресу»
2. Нажимаем кнопку с многоточием, расположенную правее окна ввода адреса;


«Шеф, все пропало!»
С помощью патч-корда подключаем компьютер к первому интерфейсу Микротика (на остальных нет загрузки по сети). Прежде чем начать прошивку, рекомендуется отключить все сетевые интерфейсы, кроме того, к которому подключен Микротик, выключить антивирус и брандмауэр.
Дальнейший порядок действий такой: 1. Назначаем IP адрес 10.1.1.2 сетевому интерфейсу к которому подключен Микротик. 2. Запускаем Netinstall от имени администратора.




7. Если Вы хотите сохранить предыдущую конфигурацию — поставьте галочку в чекбоксе “keep old configuration” 8. Выбираем директорию, в которой сохранена прошивка, и жмем Ок. 9. Выбираем прошивку.

10. Обращаем Ваше внимание на то, что не рекомендуется менять значения поля key 11. Нажимаем кнопку install.


После этого к устройству можно подключаться штатными средствами.
Вам помогла эта статья?
Приглашаем пройти обучение в нашем тренинг-центре и научиться настраивать оборудование MikroTik на профессиональном уровне! Узнайте расписание ближайших курсов и бронируйте место!
Item copy
This shows how easy it is to copy an item in Winbox. In this example, we will use the COPY button to make a Dynamic PPPoE server interface into a Static interface.
This image shows us the initial state, as you see DR indicates «D» which means Dynamic:
Double-Click on the interface and click on COPY:
A new interface window will appear, a new name will be created automatically (in this case pppoe-in1)
After this Down/Up event this interface will be Static:
Work Area and child windows
Winbox has MDI interface meaning that all menu configuration (child) widows are attached to main (parent) Winbox window and are showed in work area.
Child windows can not be dragged out of working area. Notice in screenshot above that Interface window is dragged out of visible working area and horizontal scroll bar appeared at the bottom. If any window is outside visible work area boundaries the vertical or/and horizontal scrollbars will appear.
Each child window has its own toolbar. Most of the windows have the same set of toolbar buttons:
Almost all windows have quick search input field at the right side of the toolbar. Any text entered in this field is searched through all the items and highlighted as illustrated in screenshot below
Notice that at the right side next to quick find input filed there is a dropdown box. For currently opened (IP Route) window this dropdown box allows to quickly sort out items by routing tables. For example if main is selected, then only routes from main routing table will be listed.
Similar dropdown box is also in all firewall windows to quickly sort out rules by chains.
Sorting out displayed items
Almost every window has a Sort button. When clicking on this button several options appear as illustrated in screenshot below
Example shows how to quickly filter out routes that are in 10.0.0.0/8 range
- Press Sort button
- Chose Dst.Address from the first dropdown box.
- Chose in form the second dropdown box. «in» means that filter will check if dst address value is in range of specified network.
- Enter network against which values will be compared (in our example enter «10.0.0.0/8»)
- These buttons are to add or remove another filter to the stack.
- Press Filter button to apply our filter.
As you can see from screenshot winbox sorted out only routes that are within 10.0.0.0/8 range.
Comparison operators (Number 3 in screenshot) may be different for each window. For example «Ip Route» window has only two is and in. Other windows may have operators such as «is not», «contains», «contains not».
Winbox allows to build stack of filters. For example if there is a need to filter by destination address and gateway, then
- set first filter as described in example above,
- set up seconf filter to filter by gateway
- press Filter button to apply filters.
Customizing list of displayed columns
By default winbox shows most commonly used parameters. However sometimes it is needed to see another parameters, for example «BGP AS Path» or other BGP attributes to monitor if routes are selected properly.
Winbox allows to customize displayed columns for each individual window. For example to add BGP AS path column:
- Click on little arrow button (1) on the right side of the column titles or right mouse click on the route list.
- From popped up menu move to Show Columns (2) and from the sub-menu pick desired column, in our case click on BGP AS Path (3)
Changes made to window layout are saved and next time when winbox is opened the same column order and size is applied.
It is also possible to enable Detail mode. In this mode all parameters are displayed in columns, first column is parameter name, second column is parameter’s value.
To enable detail mode right mouse click on the item list and from the popupmenu pick Detail mode
It is possible to list items by categories. In tis mode all items will be grouped alphabetically or by other category. For example items may be categorized alphabetically if sorted by name, items can also be categorized by type like in screenshot below.
To enable Category view, right mouse click on the item list and from the popupmenu pick Show Categories
Drag & Drop
It is possible to upload and download files to/from router using winbox drag & drop functionality. You can also download file by pressing right mouse button on it and selecting «Download».
Note: Drag & Drop does not work if winbox is running on Linux using wine. This is not a winbox problem, wine does not support drag & drop.
Winbox can be used as a tool to monitor traffic of every interface, queue or firewall rule in real-time. Screenshot below shows ethernet traffic monitoring graphs.
Run Winbox on macOS
Wine is a software that allows you to run Windows executable files on macOS. Install latest Wine software from the official Wine HQ homepage, during installation you must check the «64 bit» checkbox, so that it can operate in macOS Catalina and newer. Then, you will have to launch Winbox 64bit version using this command line:
/Applications/Wine Staging.app/Contents/Resources/wine/bin/wine64 /Applications/winbox64.exe
Change the command according to where you installed Wine and where you have put the Winbox64 executable.
This is the easiest and most reliable way to run Winbox on new macOS versions.
For older macOS versions, It is possible to use Winbox in Apple macOS operating system by using Wine emulation software. For easier use it can be combined with WineBottler software to create a more convenient executable.
Also for older macOS versions, If the bottled version does not work, you can use Homebrew to install Wine and then launch the regular Winbox.exe file from our download page
brew cask install xquartz
brew install wine
If you’d like to create a launcher in MacOS, to avoid launching Wine from the Terminal, you can do it with Automator and save the result as a service or as an app. This is an example setup:
![]()
Микротик компьютеры не видят друг друга
Starting with macOS 10.15 Catalina, Apple has removed support for 32bit applications, meaning it is no longer possible to use regular Wine and regular Winbox in this OS. Wine has made available a 64bit version for macOS, and MikroTik has released a special Winbox64.exe version as well.
Winbox has an MDI interface meaning that all menu configuration (child) widows are attached to the main (parent) Winbox window and is showed in the work area.

Child windows can not be dragged out of the working area. Notice in the screenshot above that the Interface window is dragged out of the visible working area and a horizontal scroll bar appeared at the bottom. If any window is outside visible work area boundaries the vertical or/and horizontal scrollbars will appear.
Almost all windows have a quick search input field on the right side of the toolbar. Any text entered in this field is searched through all the items and highlighted as illustrated in the screenshot below

Notice that on the right side next to the quick find input filed there is a drop-down box. For the currently opened (IP Route) window, this drop-down box allows to quickly sort out items by routing tables. For example, if the main is selected, then only routes from the main routing table will be listed. A similar drop-down box is also in all firewall windows to quickly sort out rules by chains.
Advanced mode
- Browse — Browse file directory for some specific session
- Keep Password — if unchecked, the password is not saved to the list
- Secure mode — if checked, Winbox will use DH-1984 for key exchange and modified and hardened RC4-drop3072 encryption to secure the session.
- Autosave session — Saves sessions automatically for devices to which connections are made.
- Session — Saved router session.
- Note — Note that is assigned to save router entry.
- Group — Group to which saved router entry is assigned.
- RoMON Agent — Select RoMON Agent from the available device list
Managed routers list is encrypted, but it can still be loaded in other Winbox without problems IF the master password is not set for it!
By default, Winbox shows the most commonly used parameters. However sometimes it is needed to see other parameters, for example, «BGP AS Path» or other BGP attributes to monitor if routes are selected properly.
- Click on the little arrow button (1) on the right side of the column titles or right mouse click on the route list.
- From popped up menu move to Show Columns (2) and from the sub-menu pick the desired column, in our case click on BGP AS Path (3)

Changes made to window layout are saved and next time when Winbox is opened the same column order and size are applied.
It is also possible to enable Detail mode. In this mode all parameters are displayed in columns, the first column is the parameter name, the second column is the parameter’s value.
To enable detail mode right mouse click on the item list and from the popup menu pick Detail mode

It is possible to list items by categories. In this mode, all items will be grouped alphabetically or by another category. For example, items may be categorized alphabetically if sorted by name, items can also be categorized by type like in the screenshot below.
To enable Category view, right mouse click on the item list and from the popup menu pick Show Categories

Transferring Settings
Микротики есть разные: черные, белые, красные. Но все равно хочется над чем нибудь заморочится.
Или может где-то на роутере есть сеть, с большей маской, и туда эти пакеты по маршрутизации уходят (а им туда и не надо).
Для двух клиентов у вас IP пространство такое (помимо IP сетей, настроенных для локальной сети и интернета)
Чтобы было удобно ими оперировать, на микротике (l2tp сервер) нужно в настройках PPP-секретов прописать фиксированные IP (не брать их из динамического пула) и сделать 2 биндинга (L2TP сервер биндинг) для двух клиентов. В профиле для этих клиентов обязательно поставить «only one», тогда повторное соединение всегда будет делаться под этим фиксированным биндингом. В противном случае создается рядом новый интерфейс с другим именем, и настройки, сделанные для фиксированного биндинга перестают действовать.
Далее, чтобы клиенты видели друг друга, нужно на микротике ((l2tp сервер) прописать маршруты до х x.x.x.1/32 и x.x.x.2/32 через интерфейсы-биндинги с указанием pref.source y.y.y.1/32 и y.y.y.2/32 соответственно.
А чтобы из подсетей, находящихся за микротиками-клиентами заходить на микротики-клиенты, на каждом микротике-клиенте сделать маршруты до сетей y.y.y.у/32 и х x.x.x.x/32 и локальных сетей друга дружки (по 3 маршрута).
Спасибо всем откликнувшимся. Направили. Победил. Опишу подробнее может кому понадобится и так схема

понадобилось прописать маршруты на клиентах до концов туннелей На клиенте №1 /ip route add distance=1 dst-address=Х.Х.Х.5/32 gateway= Х.Х.Х.1 pref-src= Х.Х.Х.2 add distance=1 dst-address=У.У.0.0/24 gateway= Х.Х.Х.1 pref-src= Х.Х.Х.2 add distance=1 dst-address=У.У.1.0/24 gateway= Х.Х.Х.1 pref-src= Х.Х.Х.2
Соответственно обратный на клиенте №2 до Х.Х.Х.2
/ip route add distance=1 dst-address=Х.Х.Х.2/32 gateway=Х.Х.Х.6 pref-src=Х.Х.Х.5 add distance=1 dst-address=У.У.1.0/24 gateway=Х.Х.Х.6 pref-src=Х.Х.Х.5 add distance=1 dst-address=У.У.2.0/24 gateway=Х.Х.Х.6 pref-src=Х.Х.Х.5
Summary
- Winbox.exe is signed with an Extended Validation certificate, issued by SIA Mikrotīkls (MikroTik).
- WinBox uses ECSRP for key exchange and authentication (requires a new Winbox version).
- Both sides verify that the other side knows the password (no man in the middle attack is possible).
- Winbox in RoMON mode requires that the agent is the latest version to be able to connect to the latest version routers.
- Winbox uses AES128-CBC-SHA as an encryption algorithm (requires Winbox version 3.14 or above).
Всем привет.При помощи данного форума был настроен Микротик для небольшой организации.1 и 2 порт это два провайдера (с переключением между ними в случае проблем),3 порт подсеть 192.168.1.05 порт подсеть 192.168.2.0
И во встала задача дать доступ НЕКОТОРЫМ компам из подсети 1.0 в сеть 2.0 и наоборот.
На данный момент эти две сети друг друга не видят.
Собсно вопрос как реализовать такой вариант?
Troubleshooting
Winbox cannot connect to the router’s IP address
I get an error ‘(port 20561) timed out’ when connecting to routers mac address
I can’t find my device in WinBox IPv4 Neighbors list or MAC connection fails with «ERROR could not connect to XX-XX-XX-XX-XX-XX»
Most of the network drivers will not enable IP stack unless your host device has an IP configuration. Set IPv4 configuration on your host device.!Sometimes the device can be discovered due to caching, but MAC connection will still fail with «ERROR: could not connect to XX:XX:XX:XX:XX:XX
- Winbox.exe is signed with an Extended Validation certificate, issued by SIA Mikrotīkls (MikroTik).
- WinBox uses ECSRP for key exchange and authentication (requires new winbox version).
- Both sides verify that other side knows password (no man in the middle attack is possible).
- Winbox in RoMON mode requires that agent is the latest version to be able to connect to latest version routers.
- Winbox uses AES128-CBC-SHA as encryption algorithm (requires winbox version 3.14 or above).
Run Winbox on Linux
It is possible to run Winbox on Linux by using Wine emulation software. Make sure that the Microsoft font pack is installed, otherwise, you may see distortions.
It is possible to upload and download files to/from the router using Winbox drag & drop functionality. You can also download the file by pressing the right mouse button on it and selecting «Download».
Drag & Drop works if Winbox is running on Linux using wine4. Drag and drop between two Winbox windows may fail.
Traffic monitoring
Winbox can be used as a tool to monitor the traffic of every interface, queue, or firewall rule in real-time. The screenshot below shows Ethernet traffic monitoring graphs.

Simple mode
When you open Winbox loader for the first time simple mode layout will be used:
It is recommended to use an IP address whenever possible. MAC session uses network broadcasts and is not 100% reliable.
You can also use neighbor discovery, to list available routers use the Neighbors
From the list of discovered routers, you can click on the IP or MAC address column to connect to that router. If you click on IP address then IP will be used to connect, but if you click on MAC Address then the MAC address will be used to connect to the router.
Neighbor discovery will show also devices that are not compatible with Winbox, like Cisco routers or any other device that uses CDP (Cisco Discovery Protocol). If you will try to connect to a SwOS device, then the connection will be established through a web browser
- Connect — Connect to the router
- Connect To RoMON — Connect to RoMON Agent
- Open In New Window — Leaves loader open in the background and opens new windows for each device to which connection is made.
- Connect To: — destination IP or MAC address of the router
- Password — password used for authentication
- Keep Password — if unchecked, the password is not saved to the list
- FileNew — Create a new managed router list in a specified locationOpen — Open managed router list fileSave As — Save current managed router list to fileExit — Exit Winbox loader
- New — Create a new managed router list in a specified location
- Open — Open managed router list file
- Save As — Save current managed router list to file
- Exit — Exit Winbox loader
ERROR: router does not support secure connection please enable Legacy Mode if you want to connect anyway
Защищенное подключение поддерживается в RouterOS выше версии 6.43. Но лучше обновить прошивку Mikrotik тем более что сделать это очень просто.
Almost every window has a Sort button. When clicking on this button several options appear as illustrated in the screenshot below

The example shows how to quickly filter out routes that are in the 10.0.0.0/8 range
- Press Sort button
- Chose Dst.Address from the first drop-down box.
- Chose in form the second drop-down box. «in» means that filter will check if DST address value is in range of the specified network.
- Enter the network against which values will be compared (in our example enter «10.0.0.0/8»)
- These buttons are to add or remove another filter to the stack.
- Press the Filter button to apply our filter.
As you can see from the screenshot Winbox sorted out only routes that are within the 10.0.0.0/8 range.
Comparison operators (Number 3 in the screenshot) may be different for each window. For example «Ip Route» window has only two is and in. Other windows may have operators such as «is not», «contains», «contains not».
Winbox allows building a stack of filters. For example, if there is a need to filter by destination address and gateway, then
- set the first filter as described in the example above,
- set up a second filter to filter by the gateway
- press the Filter button to apply filters.
Command Line
Здравствуйте, микротик 951Ui-2HnD, RouterOS 6.43.4
Настроен стандартным конфигом через QuickSet. Задача его получать на первый порт Инет от 4G-модема, раздавать Инет на оставшиеся 4 порта и WiFi, ну и локальная сеть с общим принтером.
К микротику подключены маршрутизаторы в режимах Точка Доступа (3шт) и коммутаторы (4шт).
Чё тыкнуть микротику, чтобы компьютеры в сети «видели» друг друга? )) обмен файлами, печать и прочее. Конфиг прилагаю. Спасибо!
Помощь в написании контрольных, курсовых и дипломных работ здесь.
Почему хосты не видят друг-друга?Доброго времени суток! Помогите пожалуйста разобраться со следующим вопросами: Чисто.

2 роутера последовательно, домашняя сеть, устройства подключенные к разным роутерам не видят друг другаДобрый день настраиваю домашнюю сеть. 4g модем от йоты, вставлен в роутер Zyxel Keenetic Omni II.
При отключении «Подключение по локальной сети» компьютер перезагружаетсяПривет народ! Появилась такая проблема. При отключении «Подключение по локальной сети» компьютер.
VLAN с «диким интернетом» в локальной сетиНа сколько безопасно пускать VLAN с «диким» интернетом через локалку транзитом? Нет ли каких.
надеюсь простые свитчи?
схема сети сейчас выглядит так:
Провода прокинуты, все маршрутеры в режимах Точки доступа, т.е. сами ничего не выдают, работают как свич. Принтер отлично стал обнаруживаться фирменной утилитой, всё отлично. Но! Микротик тут настроен тоже как Свич!
Была идея внедрить между LTE-модемом и сетью Шлюз, дабы управлять пользователями, контролировать трафик, устанавливать правила и использовать контент-фильтр, причем индивидуально для каждого пользователя, а не всем подряд, как было когда-то ранее. Но совладать с этой «чудАй-техники» у меня пока никак не получается, постоянно какие-то проблемы.
Возможно Микротик реально настроить так, чтобы и сеть эта работала, и фильтрация средствами SkyDNS была..
В том и дело, что Быстрая настройка не помогла мне сделать этого (в сети никто никого не видел), зато помогла сделать его свичем. Потому он пока так работает.
Это я понял))) только конструктор для крутых профи, а не для простых сельских админов))
Нет, SkyDNS был раньше в Микротике настроен. Только этих настроек у организации нет, в микротик попасть не возможно было, паролей никто не знал, сбит до заводских был. Мастера от провайдера к нам не торопятся, уже неделю ждем. А почему ждем, потому что по контракту эта услуга от оператора связи, а не от SkyDNS напрмямую, потому сами Скай нам помочь тоже не смогли. А asus там, потому что он 4G-МОДЕМ!!)))) на схеме написано же) Без него никак просто. В нем прям стоит сим-карта от МТС и получает корпаративный тариф. Вот и всё. В планах было круто настроить Микротик, но он сложен. Потому вычитал про шлюз (от «ИКС» на FreeBSD), нашел старый комп, установил, интересно конечно, но Инет работает с большими тормозами, причину не нашел пока. Потому снова возвращаемся к старому плану)) понять Микротик)
Т.е. задача по портам хотя бы иметь какое-то управление, статистику потребления трафика и т.д. Но самое главное отделить отдельные группы компов от Инета контент-фильтром.
Не стесняемся, приобретаем большую банку кофе, блок сигарет и вперед за новыми знаниями.
Для меня тоже было открытием)) называется Asus 4G-N12.
Добавлено через 16 минут По поводу фильтра. Имеется ввиду что-то типа родительского контроля. Т.е. по ссылкам выше если делать, то таких сайтов надо ввести ручками (как в примере youtube) тысячи! Это только списки гос.органов всяких. А просто по темам и ключевым словам вообще цифры не реальные..
Сегодня пробовал взять дэмку SkyDNS, попробовать хоть программно на ученических компах фильтровать. Так оно такое тугое! Нормальный инет превращается в унылое гавно. Разрешенные сайты еле-еле открываются. Блокировка работает не информативно, т.е. ты в лучшем случае сразу видишь ответ браузера, что связи нет. В худшем, всё висит и нифига не понятно, ждать чуда или будет блокировка всё таки. Стало понятно, почему до наших действий по модернизации сети, когда фильтр стоял на всю сеть, что висела на микротике, Инет тупил постоянно, и работники думали, что тариф такой им выделяют очень медленный.
Make sure that the Windows firewall is set to allow Winbox connections or disable the windows firewall.
Windows (7/8) does not allow mac connection if file and print sharing is disabled.
Sometimes the device will be discovered due to caching, but MAC connection will still fail with «ERROR: could not connect to XX:XX:XX:XX:XX:XX
Winbox MAC-ADDRESS connection requires MTU value set to 1500, unfragmented. Other values can perform poorly — loss of connectivity can occur.
IPv6 connectivity
Winbox supports IPv6 connectivity. To connect to the router’s IPv6 address, it must be placed in square braces the same as in web browsers when connecting to the IPv6 server. Example:
when connecting to the link-local address interface index must be entered after the %:
Port number is set after the square brace when it is necessary to connect Winbox to other port than the default:
Winbox neighbor discovery is capable of discovering IPv6 enabled routers. There are two entries for each IPv6 enabled router, one entry is with IPv4 address and another one with IPv6 link-local address. You can easily choose which one you want to connect to.
Через Mikrotik не видна локалка
Хотя странно, что вообще что-то нужно: должно бы и так и так работать. Но это не отменяет того, что правильнее сделать так, как я в посте выше написал.
Приложите конфиг с микротика, чтобы не гадать.
В остальном с этим конфигом у вас должен быть доступ из подсети микротика в остальную локалку, но не наоборот.
Если имеется ввиду, что вы диапазон раздаваемых DHCP-сервером микротика адресов, поменяли на ту же подсеть, что и у ростелекомовского роутера, то это плохая идея.

