- 62
- 654 030
Wilmer Almazan / The Network Trip
Canada
Приєднався 18 гру 2020
Video tutorials about networking, cloud computing, and network security. One new video every week. Covering configuration on Cisco, Fortinet, Mikrotik, Ubiquiti and much more.
Block DHCP Attacks - Deep Dive
#DHCP #NetworkSecurity #MikroTik #Networking
In this video, I’ll show you how to block DHCP starvation and spoofing attacks before they bring your network down.
You’ll learn how attackers exploit DHCP to exhaust IP pools or introduce rogue servers-and more importantly, I’ll guide you through practical defenses. With a hands-on lab, I’ll explain how to use DHCP Snooping, Option 82, Port Security, and other strategies to keep your network safe and running smoothly.
📌 What You’ll Learn:
• How DHCP Starvation and Spoofing Attacks Work
• Using DHCP Snooping, Option 82, and Port Security for Defense
• Step-by-Step Lab for Network Protection
Connect with Wilmer Almazan
LinkedIN: www.linkedin.com/in/wilmeralmazan/
Facebook: nsswilmeralmazan/
Twitter: wilmer_almazan
Instagram: wilmer_almazan
mikrotik
routeros 7
ospf
mtcna
mtcre
cybersecurity
routing
cloud computing
virtualization
switching
network automation
In this video, I’ll show you how to block DHCP starvation and spoofing attacks before they bring your network down.
You’ll learn how attackers exploit DHCP to exhaust IP pools or introduce rogue servers-and more importantly, I’ll guide you through practical defenses. With a hands-on lab, I’ll explain how to use DHCP Snooping, Option 82, Port Security, and other strategies to keep your network safe and running smoothly.
📌 What You’ll Learn:
• How DHCP Starvation and Spoofing Attacks Work
• Using DHCP Snooping, Option 82, and Port Security for Defense
• Step-by-Step Lab for Network Protection
Connect with Wilmer Almazan
LinkedIN: www.linkedin.com/in/wilmeralmazan/
Facebook: nsswilmeralmazan/
Twitter: wilmer_almazan
Instagram: wilmer_almazan
mikrotik
routeros 7
ospf
mtcna
mtcre
cybersecurity
routing
cloud computing
virtualization
switching
network automation
Переглядів: 1 750
Відео
Master MikroTik Policy Routing - Rules or Marks?
Переглядів 3 тис.2 місяці тому
#PolicyBasedRouting #mikrotik #mikrotikrouter In this video, we dive deep into Policy-Based Routing (PBR) and how you can use it to control traffic flow on your network. We cover three key topics: - What is Policy-Based Routing? - A clear explanation of PBR and how it can improve traffic management. - Routing Rules - Learn how to define and apply specific routing rules for different types of tr...
Block DNS Flood Attacks on Mikrotik - Live Demo Included!
Переглядів 6 тис.2 місяці тому
#NetworkSecurity #MikroTik #DDoSProtection #CyberSecurity In this video, we dive into the world of DNS flood attacks and how they can overwhelm your network with a flood of small DNS requests, disrupting services and slowing everything down. I’ll give you an overview of what a DNS flood attack is, followed by a live demonstration of its impact on a network. Most importantly, I’ll walk you throu...
Adlist Mikrotik - Step by Step Lab
Переглядів 3,2 тис.2 місяці тому
#MikroTik #Adlist #NetworkSecurity In this video, we dive into MikroTik's Adlist feature, a powerful tool for blocking unwanted ads and boosting your network's security by filtering harmful domains at the DNS level. Whether you're trying to stop ads from cluttering your browsing experience or protect your network from malicious domains. Here’s what we’ll cover in the video: - What is the Adlist...
mDNS Mikrotik - Discover Your Devices Without a DNS Server
Переглядів 4,3 тис.2 місяці тому
#MikroTik #mDNS #MikroTikLabIn mDNS (Multicast DNS) is a protocol that allows devices on the same local network to resolve hostnames without relying on a central DNS server. It operates using multicast to broadcast queries and responses to all devices within the local subnet. mDNS is commonly used for device discovery in home or small office networks, enabling services like printers and smart d...
MACSec Mikrotik - Hop by Hop Encryption
Переглядів 1,6 тис.2 місяці тому
#macsec #mikrotik #networksecurity In this video, I break down the MACsec protocol and how it secures Layer 2 communication across multiple hops. I’ll show you the risks of unencrypted traffic in a multi-hop network and then guide you through the full configuration process of enabling MACsec on MikroTik devices. You'll see step-by-step how to set it up, followed by a demonstration of the networ...
Router Redundancy - VRRP Mikrotik (Step by Step)
Переглядів 3,4 тис.3 місяці тому
#VRRP #MikroTik #NetworkRedundancy VRRP in MikroTik: Achieving Network Redundancy for LAN Networks In this video, I dive into why VRRP (Virtual Router Redundancy Protocol) is crucial for ensuring high availability and redundancy in your network. If you're managing critical networks, ensuring uptime is essential. That's where VRRP comes in. I explain: - What VRRP is and why it's important for ne...
DNS over HTTPS (DoH) on MikroTik: Complete Lab
Переглядів 3,3 тис.3 місяці тому
#DoH #MikroTik #DNSoverHTTPS In this video, we dive deep into DNS over HTTPS (DoH), explaining how it works and why it's an important privacy enhancement over traditional DNS. You'll learn how DoH can protect your browsing by encrypting DNS queries, preventing them from being easily intercepted or logged by third parties. We'll cover: - A comparison of traditional DNS vs. DoH - How DoH can impr...
MVRP - Dynamic VLANs Mikrotik (Full Lab - Step by Step)
Переглядів 4,5 тис.3 місяці тому
#MVRP #MikroTik #VLANManagement Master MVRP in MikroTik with This Step-by-Step Lab! In this video, we’re diving into MVRP (Multiple VLAN Registration Protocol) in MikroTik. I’ll guide you through the concept, configuration, and implementation of MVRP with a hands-on, step-by-step lab. Whether you're new to MVRP or looking to expand your MikroTik skills, this lab will help you understand how to ...
Deterring Network Intrusions: How to use DHCP + ARP for MikroTik LAN Security
Переглядів 1,9 тис.3 місяці тому
#mikrotik #dhcp #arp In this video, we'll show you how to improve your LAN security using DHCP and ARP on MikroTik devices. By combining DHCP with static ARP, you can prevent unauthorized devices from joining your network and ensure that only trusted devices get access. Here's what we'll cover: - How DHCP and ARP work together to secure your network. - Setting up static ARP to lock down IP-to-M...
Static ARP on MikroTik Devices
Переглядів 7273 місяці тому
#arp #mikrotiktutorial #mikrotikrouter In this video, we explore how Static ARP can significantly enhance the security of your LAN on MikroTik devices. By locking ARP entries, you can prevent unauthorized devices from hijacking IP addresses and ensure better control over your network. We'll cover: - What ARP is and the difference between dynamic and static ARP entries. - How Static ARP works to...
Mikrotik Certifications & Hardware
Переглядів 3493 місяці тому
#MikroTik #MikroTikCertifications #MikroTikDevices MikroTik Certifications and Devices Explained! In this video, I’ll walk you through everything you need to know about MikroTik Certifications and their wide range of networking devices. Whether you’re looking to become a certified MikroTik professional or want to explore their top-tier devices, this video will guide you through the essentials. ...
What is Mikrotik? - Profile, Operating System & MUMs
Переглядів 6193 місяці тому
MikroTik #RouterOS #MikroTikTraining 🌐 What is MikroTik? 🌐 In this video, I’ll introduce you to MikroTik, the company behind some of the most powerful and flexible networking products in the industry. Whether you're new to networking or already familiar with MikroTik, this video will give you a deeper understanding of the company and its products. ✅ What you’ll learn: - The history and profile ...
Analyzing the ARP Table in Mikrotik Devices
Переглядів 5863 місяці тому
#arp #mikrotik #bridging In this video, we dive into Analyzing the ARP Table on MikroTik Devices! The ARP table is a crucial part of your network's operation, helping resolve IP addresses to MAC addresses. Understanding how to interpret and manage this table can help you troubleshoot network issues and improve efficiency. We’ll cover: - What the ARP table is and how it works in a network. - How...
My First Bridge in Mikrotik Devices
Переглядів 1,2 тис.3 місяці тому
#mikrotiktraining #mikrotik #bridging Welcome to my tutorial on setting up your first bridge in MikroTik devices! This video is perfect for beginners and those new to MikroTik or network bridging. We'll go through the basics of what a network bridge is, its role in connectivity, and a straightforward, step-by-step guide to creating your first bridge using RouterOS. What you'll learn: - Step-by-...
Understanding Bridge Hardware Offloading in Mikrotik Devices
Переглядів 2 тис.3 місяці тому
Understanding Bridge Hardware Offloading in Mikrotik Devices
How to Upgrade or Downgrade Your Mikrotik Router
Переглядів 5423 місяці тому
How to Upgrade or Downgrade Your Mikrotik Router
How to Add a License to your Mikrotik CHR?
Переглядів 5663 місяці тому
How to Add a License to your Mikrotik CHR?
IS-IS Mikrotik Full Lab (Step by Step) - Ep 2
Переглядів 2,5 тис.Рік тому
IS-IS Mikrotik Full Lab (Step by Step) - Ep 2
Port Knocking & Scanner Detection - Mikrotik Firewall Ep 3
Переглядів 7 тис.Рік тому
Port Knocking & Scanner Detection - Mikrotik Firewall Ep 3
Mikrotik Firewall - Protecting the Router (Ep 2)
Переглядів 9 тис.Рік тому
Mikrotik Firewall - Protecting the Router (Ep 2)
Mikrotik Firewall From Scratch - The Basics - Episode 1
Переглядів 13 тис.Рік тому
Mikrotik Firewall From Scratch - The Basics - Episode 1
Controller Bridge / Switch - Mikrotik (Full Lab)
Переглядів 12 тис.Рік тому
Controller Bridge / Switch - Mikrotik (Full Lab)
MLAG With Mikrotik - High Availability (Full Lab)
Переглядів 14 тис.Рік тому
MLAG With Mikrotik - High Availability (Full Lab)
Layer 3 Hardware Offloading Mikrotik - Deep Dive
Переглядів 21 тис.Рік тому
Layer 3 Hardware Offloading Mikrotik - Deep Dive
MACVLAN Mikrotik - Multiple MACs, One Interface
Переглядів 6 тис.Рік тому
MACVLAN Mikrotik - Multiple MACs, One Interface
Secure Login on Mikrotik - Good Bye Passwords!
Переглядів 2 тис.Рік тому
Secure Login on Mikrotik - Good Bye Passwords!
If activate the load balance using pcc and add fasttrack, the loadbalance work normally?
Hello, When using FastTrack, you must configure routing rules, as PCC (Per Connection Classifier) will not function in this setup.
Thank you for this guide. It’s amazing. I am curious how it would be possible to have a global address list, stuff coming through ospf, bgp, etc. Maybe store that on GitHub and have a script update the local entries or something every 5 minutes on a pull. If you have 100 routers out there, some might have prefixes that are owned and not in the rfc private range. It’s manually tedious going to all of them and adding just that one subnet for all 100, just for it to use the main routing table. There must be a better way.
I Have Questions how i can routing web url only in my router
I bought a new mikrotik router hap ax2 and i very dissepoitend with new capsman can you make a video of that? i found a video but didn´t work out for me. My objecti is to control on capsman wifi5 devices and wifi 6
Hi. I have two questions. What would happen if we put mask on vrrp address (for example /24)? And if we create vrrp interface for wan port, which interface will be used for out. interface on nat?
perfectly explained lab! great work!
I’ve just discovered this feature on my mikrotik rb5009 and I found it very intriguing, but I already use 2 × pihole servers on my network with wireguard VPN on my mobile devices so all the ad crap is blocked even when I’m out and about. One of the best videos about mikrotik 👍🏼
I have a question: If you do this then you can not resolve any address if the router is the DNS Server. What can I do about this ?
Hi! You can allow queries from trusted IPs only. There is not a single solution for all scenarios, that would be impossible to show in a single video. The idea is to understand the logic and build the rules according to our needs.
Hi i get this error (Hardware acceleration can only be used with the following qemu executables:qemu-system-x86_64, qemu-system-i386, qemu-kvm) when i try to add any router or use mikrotic router form the image i added
Hi! Go to the template and make sure to select the binary named qemu-system-x86_64. It seems that another one is currently selected.
Hi, buddy, excellent explanation, thanks for your content. I have a question. If I want to have several source interfaces, how could I manage to pass the traffic through l3-hw having multiple broadcast domains as source? For example, if I have several switches connected to different ports, how could I achieve the same, taking into account what you say that we can only have a single bridge. As an additional fact, I am using a CCR2216 and I have several broadcast domains on it, and I do not want to mix them. uplink<------CCR2216 |______sfp1_v20 |______sfp2_v30
Hello! Vlan filtering helps to keep the broadcast domain separate. If thew VLAN 20 is mapped to ports 1,2,3 and VLAN 21 is mapped to ports 4,5,6, then, you have 2 separate broadcast domain and still have one bridge.
Hi Wilmer. Nice video. Can you create a VPN on both routers and create a site to site VPN with two paths?
Hello i love your videos can you make a video about capsman? old one and new one please
I come from Oficial mikrotik channekl and Im from portugal i love you videos my friend
what if i want to whitelist all google related ads? When im shopping for something this adlist will prevent all sponsored google links from openning
You are better. ❤
Hi , I checked with version 7.16.1 on switch option the hardware offloading option not available
Hello! What is your device model?
@TheNetworkTrip great tutorial, thank you so much sir! ❤ Exactly what I looking for. Glad to find your channel.🔥 Did subscribe.
This was very helpful, thank you
Excelente tu canal! todo el canal
Very clean, thanks
hi can i intergrate PBR to ospf?
I have watched your Firewall Series and have enjoyed it immensly. After viewing this several times I believe I have the knowledge to configure my CCR in a secure manner. Thank you very much.
Ok maybe I missed something but L3HW can only work if done through bridge with vlan? Just router port to router port it can't work?
Hello! If we want to have pure routing and hardware offloading (without NAT), we need bridge and VLAN interfaces as explained in this video. If you have WAN and LAN interfaces, you can keep the WAN interface outside the bridge, create NAT rules, and add a rule in the forward chain to FastTrack and enable L3 hardware offloading for that traffic. The initial connection will be managed by the CPU, and then the NAT entries will be copied to the switch chip.
@@TheNetworkTrip oh wow ok I didn't expect that and also possibly explains alot about my performance issues. I don't have any Firewall/Nat rules and connection tracking is disabled just pure L3 Routing from Interface A to Interface B but I'm not using any bridge, I have enabled HW offloading and attempted to offload some of the routes to hardware and they do show the H in routes and the /interface/ethernet/swich/l3hw-settings/monitor shows that HW offloading is enabled with about 5000 out of 1m routes is offloaded (i don't have CPU issues) but I feel performance is shaped somehow where once traffic reaches around 4-5Gbps It seems to struggle.
@@TheNetworkTrip Thanks for the key info, will play around and see if it helps me with my issues.
Hello! Can this work between VLAN and WIREGUARD networks? I have enabled the new Media server (UPNP) on the router and I would like to see it when I'm connecting through Wireguard.
hello, great material but I have a question: what does backbone mean? are these routers that only have L2? do I understand this correctly? my English is poor that's why I'm asking thanks in advance for your answer regards Daniel
That's correct. The backbone is the contiguous Level 2 (L2) network responsible for routing between different areas, ensuring global connectivity and hierarchy within the protocol's domain.
@@wilmeralmazan8824 ok, thanks for the answer; but if I had 6 routers in the same backbone, can only L1 do it? what defines the router DR and BDR as in ospf? L2 connects different arenas - right? and if I have 3 arenas? what does the virtual link with ospf look like? please make a material about it divided into one arena, 2 arenas and 3 arenas with virtual link if you have time thank you and best regards Daniel
@@wilmeralmazan8824 proszę o odpowiedz na poniższe pytanie
Hello Daniel, Great questions! In IS-IS, L1 routers handle intra-area routing, while L2 routers connect different areas via a contiguous backbone. If multiple areas aren’t needed, L1-only works fine. Unlike OSPF, IS-IS uses a DIS (no BDR) on broadcast networks to manage LSP flooding, with the highest priority or MAC determining the DIS. For multi-area setups, L1/L2 routers manage inter-area traffic, and a contiguous L2 backbone is critical. If the backbone isn’t continuous, a virtual link or Mesh Groups can restore connectivity. I’ll prepare content covering these scenarios. Stay tuned!
@@TheNetworkTrip dziękuję za odpowiedz, czekam na materiał; pozdrawiam Daniel
how about dynamic public ip bridged directly as ISP2. how to do the routing table and routes? thanks.
Hi, Nice example. Can this be enabled on a CCR2216 as a border router against the ISP? Taking into account that this router has active BPG that is published to the internet
Hi! That works as long as you are receiving the default route only (because of the BGP's routing table size)
your teaching is absolutely amazing. please don't stop creating great content like this one.
Thanks so much for the great feedback! I’m really happy you find the content helpful. I’ll keep making more-your support means a lot!
@@TheNetworkTrip I have question can we also include the WAN interface for the hardware offloading, or this is pure LAN intervlans?
I have star topology with 3 CCR (I.e. R1,R2 and R3). Each CCR has CRS in front of it. And each CRS has single bridge setup. Because it is a star configuration, RSTP set the port to alternate port and trying to prevent loop. Because of that, I can never ping the GW or the port the CRS port role as alternate port. That creates a problem since I will want to get to some of the host on that subnet. If I turn off RSTP, it creates a loop. Any suggestion?
Wilmer - great video - learning RouterOS and your videos are a great help. The docs don’t mention the CRS-310-8G+2S is not mentioned in the docs as supported for either a Controller Bridge or Port Extender. Do you know why it wouldn’t work? I’d like to use it as the CB. Great videos.
thank you so much for your tutorial
I loved it! Thank you so much!
hi my friend i see a lot of your video but i'm looking for something very very precise and not found any answer online. i will resume we are wisp distributer we have data and iptv. we have hap ac2 most of our client have. the problem is client make mistake they plug anywhere in the router anything and cause us problem so what we want is if the person plug a IPTV into any port with the mac adress began with 00:00:00:00:XX:XX it will go to vlan exp : 10. if he plug anything else will go to default vlan 1 how do i configure this into the router OS ?
Thanks for this great video, very helpful and saved my time.
Strange thing, i cant use github link, the file isnt complete only around 17000 entries, fortunatelly there is also non github link on this host file and its works!
Thank youuu Soo good explianed please can you doing ein Lab ebgp, ibgp full mesh/R.R and ospf
Thank you.
Excellent!! And as would be the case with pppoe-client, in ip routes(v7) it does not allow me to set pppoe as the gateway, it does not recognize it. thanks!!
Thank you so much for the elaborate explanation. You along with The Network Berg are the best!!! Can you also explain how to do recursive routing with policy based routing? I have successfully been able to do this following your tutorial, also the policy based routing watching your video. However I want to combine the 2. Please help! Thanks a lot and stay blessed!
Hello, I have the following question, I don't know if you can answer it... if we have one or more switches in front of the switch that interconnects with the router, we have to place the "trunk" (fiber) ports as "trusted" that interconnect the switches between them? Where several VLANS pass as explained in your video "Mikrotik VLANs - CRS3XX Step by Step - Mikrotik Tutorial". Thanks.
Hello! That’s correct, the trunk interfaces will be trusted.
@@TheNetworkTrip Thanks. I will do it.
The best explanation about routing !!
Glad to hear that!
Thanks for this videos it worked like a charm
Great to hear!
What is the impact (at performance level) of use routing mark as a single mangle rule than marking connections and after that mark-routing of only connections marked before? Other scenario can be mark-connection --> mark-packets ---> mark-routing. What is the best procedure, upon your expertise?
Hello! For this specific scenario, the performance is pretty similar.
"Mas claro, echale agua" as we say the latinamericans!!!! Thanks again Wilmer!!!!!
You bet!
Tks very much Mr. Almanzan for this video. One question: I have on my lan a NAS whit a DNS server to resolve local names, so it is possible to add also this local DNS server to the Mikrotik router so other devices on my lan can use both DNS server to resolve local and external ips? As a solution I did include on the Mikrotik default DHCP server network both the Mikrotik and the NAS server local ips (you on 13.31 included only the Mikrotik IP) but I'm not shure if this is the right way to do it. Pls let me know any hint about.
Hello! If you have a dedicated DNS server, you can configure DoH directly on it; there’s no need to set it up on your router. However, configuring it on your router can provide redundancy in case your dedicated server goes down. In that scenario, your approach of providing the server IPs is effective.
i my case, when I connect my Mikrotic router to my home ISP router. After I have followed your lab Routing instruction, with regard to the routing rules. My computer, sitting on one port inside the mikrotik Router Bridge, can not communicate with other IP inside my ISP router local LAN, but only the IP that is set on the Ether port 1. Am i missing some setting(config) on the Mikrotik hAP ac router ?
Hello! The entries keeping in the main table your local networks should be missing something. Please make sure all your local networks are in the main table.
Can there be a manual route added for computers to access the Internet instead of using nat (masquerade)?
Answered myself - there is no local IP-address in the Internet, they should be masked (netted). So routing is not suitable in this situation.
Hello! If the computers have private IPs, you need NAT.
That’s correct
Thanks. New information for me. Did as you showed, everything works fine.
Great!
Is it possible to use failover, recursive routing, and source route LAN to WAN all together for load balance ?
Hello! That’s possible. Next week I’ll have a video about it.
@@TheNetworkTrip Thank you for your video. Today, I configured failover along with recursive routing and PBR, and both are working together successfully.