{"id":458,"date":"2018-04-15T17:44:48","date_gmt":"2018-04-15T15:44:48","guid":{"rendered":"https:\/\/blog.hepc.ro\/?p=458"},"modified":"2018-04-15T17:44:48","modified_gmt":"2018-04-15T15:44:48","slug":"mikrotik-dnsntpupgrade-si-remote","status":"publish","type":"post","link":"https:\/\/blog.hepc.ro\/?p=458","title":{"rendered":"Mikrotik DNS,NTP,Upgrade si Remote"},"content":{"rendered":"<p>Pe 31 martie 2018, am primit un mail de la Mikrotik, legat de o problema de securitate pentru utilizatorii care ruleaza versiuni mai vechi de RouterOS. Pe scurt toti ce-i care ruleaza routerOS mai vechi de\u00a0v6.38.5 (din martie 2017) sunt indemnati sa faca upgrade urgent. N-am sa detaliez aici despre ce este vorba, mesajul oficial il puteti gasi aici\u00a0<a href=\"https:\/\/forum.mikrotik.com\/viewtopic.php?f=21&amp;t=132499\">https:\/\/forum.mikrotik.com\/viewtopic.php?f=21&amp;t=132499<\/a><\/p>\n<p>In cele ce urmeaza voi incerca sa explic cum putem face Upgrade si cum se configureaza manual DNS,NTP si remote Winbox, pe un hEX lite.<\/p>\n<p><!--more--><\/p>\n<h4>Mikrotik Upgrade<\/h4>\n<p>Pentru upgrade trebuie sa stim urmatoarele informatii: modelul de routerboard, versiunea curenta RouterOS si arhitectura. Toate astea le putem afla din Winbox, in meniul System -&gt; Resources. Odata ce avem aceste informatii, vom accesa\u00a0<a href=\"https:\/\/mikrotik.com\/download\">https:\/\/mikrotik.com\/download<\/a> si verificam la ce arhitectura se incadreaza modelul nostru. In cazul de fata, hEX lite corespunde cu arhitectura MIPSBE, prin urmare vom descarca versiunea 6.41.4 (Current) de la Main package.<\/p>\n<p><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/systemResources-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-467\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/systemResources-1-300x242.png\" alt=\"\" width=\"300\" height=\"242\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/systemResources-1-300x242.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/systemResources-1-768x620.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/systemResources-1.png 818w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>\u00a0 \u00a0 \u00a0<a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDownloads.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-466\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDownloads-300x161.png\" alt=\"\" width=\"300\" height=\"161\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDownloads-300x161.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDownloads-768x413.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDownloads-1024x551.png 1024w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDownloads.png 1248w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Fisierul descarcat va avea denumirea routeros-mipsbe-6.41.4.npk si o dimensiune de aprox 10MB. Toate bune pana aici, mai departe vom incarca fisierul in memoria flash folosind Winbox si accesand optiunea &#8220;File&#8221; din meniul din stanga. <em>Inainte de a continua cu upgrade-ul, este <span style=\"color: #ff0000;\">RECOMANDAT<\/span> sa efectuam un backup al configuratiei existente (in caz ca&#8230;.)<\/em>. Backup-ul se face tot in meniul &#8220;File&#8221;, accesand butonul Backup, stabilirea unui nume pt fisierul de backup si apasand din nou Backup. Fisierul .npk se va incarca in memorie prin butonul &#8220;Upload&#8221; si procesul nu ar trebui sa dureze mai mult de cateva secunde. Daca totul a mers ok pana aici, fisierul .npk ar trebui sa apara in lista mai jos, iar ultimul pas este sa restartam RouterOS din meniul System -&gt; Reboot. Asteptam ca dispozitivul sa reporneasca, dupa care putem verifica in &#8220;Log&#8221; daca upgrade-ul s-a aplicat.<\/p>\n<p><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikBackupConfig.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-474\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikBackupConfig-300x245.png\" alt=\"\" width=\"300\" height=\"245\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikBackupConfig-300x245.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikBackupConfig-768x627.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikBackupConfig.png 810w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a> <a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikUploadFile.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-473\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikUploadFile-300x244.png\" alt=\"\" width=\"300\" height=\"244\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikUploadFile-300x244.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikUploadFile-768x625.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikUploadFile.png 812w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a> <a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikReboot.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-472\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikReboot-300x247.png\" alt=\"\" width=\"300\" height=\"247\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikReboot-300x247.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikReboot-768x633.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikReboot.png 806w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a> <a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikLog.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-476\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikLog-300x246.png\" alt=\"\" width=\"300\" height=\"246\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikLog-300x246.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikLog-768x629.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikLog.png 810w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<h4>Manual DNS<\/h4>\n<p>De regula, prefer sa configurez manual DNS-urile, in special in situatia in care router-ul se afla in spatele unei alte retele LAN. In Winbox, din meniul IP-&gt;DNS, introducem dns-urile in primele campuri. Primele doua DNS-uri vor fi cele de la ISP, iar dupa preferinte putem adauga si DNS-urile de la google si cloudflare\u00a0(8.8.8.8 respectiv 1.1.1.1). Va recomand sa rebifati casuta &#8220;Allow Remote Requests&#8221;, altfel va puteti trezi cu CPU-ul router-ului la 100% cum am patit eu mai demult.<\/p>\n<p><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDNS.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-480\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDNS-300x241.png\" alt=\"\" width=\"300\" height=\"241\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDNS-300x241.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDNS-768x618.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikDNS.png 825w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a> <a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/dns.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-479\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/dns-271x300.png\" alt=\"\" width=\"271\" height=\"300\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/dns-271x300.png 271w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/dns.png 414w\" sizes=\"auto, (max-width: 271px) 100vw, 271px\" \/><\/a><\/p>\n<h4>Manual NTP<\/h4>\n<p>Setarile NPT (Network Time Protocol) le vom efectua in linie de comanda din Terminal. Pentru Romania eu folosesc urmatoarele IP-uri: 91.216.151.59 si 92.86.106.228. Comanda va arata in felul urmator:\u00a0 <em>\/system ntp client set enable=yes primary-ntp=91.216.151.59 secondary-ntp=92.86.106.228.\u00a0<\/em>Putem introduce ip-urile si din meniul System -&gt; SNTP Client.<\/p>\n<p><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNtpCmd.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-484\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNtpCmd-300x154.png\" alt=\"\" width=\"300\" height=\"154\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNtpCmd-300x154.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNtpCmd-768x395.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNtpCmd.png 817w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNTP.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-483\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNTP-295x300.png\" alt=\"\" width=\"295\" height=\"300\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNTP-295x300.png 295w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikNTP.png 581w\" sizes=\"auto, (max-width: 295px) 100vw, 295px\" \/><\/a> <a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikSNTP.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-486\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikSNTP-269x300.png\" alt=\"\" width=\"269\" height=\"300\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikSNTP-269x300.png 269w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/mikrotikSNTP.png 388w\" sizes=\"auto, (max-width: 269px) 100vw, 269px\" \/><\/a><\/p>\n<h4>Remote Winbox<\/h4>\n<p>Pentru a accesa routerul Mikrotik de la distanta folosind ip-ul public si Winbox trebuie sa stabilim niste reguli in meniul IP-&gt;Firewall-&gt;Filter Rules. Vom apasa pe buton &#8220;+&#8221; din colt stanga sus al tabului FilterRules iar in fereastra ce apare la tabul General vom seta Chain: input, Protocol: 6 (tcp), Dst.Port: 8291. Ne mutam in tabul Action iar acolo in campul Action selectam &#8220;accept&#8221; si mai departe ii vom da un numa acestei noi reguli de ex: WinboxRemote, apasand butonul Comment din dreapta dupa care OK pentru a inchide fereastra. Implicit noua regula ce am salvat-o se va regasi in lista de la Filter Rules la baza, pe ultima pozitie. Pentru ca aceasta regula sa functioneze corect si sa avem acces remote prin winbox va trebui sa mutam regula de pe ultima pozitie din lista, deasupra primei reguli ce contine un X rosu si cuvantul drop, folosind Drag&amp;Drop cu mouse-ul.<\/p>\n<p><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/firewall-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-492\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/firewall-1-274x300.png\" alt=\"\" width=\"274\" height=\"300\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/firewall-1-274x300.png 274w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/firewall-1.png 502w\" sizes=\"auto, (max-width: 274px) 100vw, 274px\" \/><\/a>\u00a0<a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterRules.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-491\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterRules-300x259.png\" alt=\"\" width=\"300\" height=\"259\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterRules-300x259.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterRules-768x663.png 768w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterRules.png 789w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterAccept.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-490\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterAccept-300x277.png\" alt=\"\" width=\"300\" height=\"277\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterAccept-300x277.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterAccept.png 579w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><a href=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterList.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-489\" src=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterList-300x300.png\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterList-300x300.png 300w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterList-150x150.png 150w, https:\/\/blog.hepc.ro\/wp-content\/uploads\/filterList.png 584w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>That&#8217;s all Folks! \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pe 31 martie 2018, am primit un mail de la Mikrotik, legat de o problema de securitate pentru utilizatorii care [&#8230;]<\/p>\n","protected":false},"author":1,"featured_media":296,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"categories":[63],"tags":[83,55,82,85,84,51],"class_list":["post-458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tutorial","tag-dns","tag-mikrotik","tag-ntp","tag-remote","tag-upgrade","tag-winbox"],"_links":{"self":[{"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=\/wp\/v2\/posts\/458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=458"}],"version-history":[{"count":21,"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=\/wp\/v2\/posts\/458\/revisions"}],"predecessor-version":[{"id":495,"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=\/wp\/v2\/posts\/458\/revisions\/495"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=\/wp\/v2\/media\/296"}],"wp:attachment":[{"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hepc.ro\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}