A
A
aphazel2017-09-28 18:55:06
Mikrotik
aphazel, 2017-09-28 18:55:06

How to restore connection to mikrotik via winbox?

Hi guys! How is the spirit? Great, great.
The crux of the matter is this. There is a main Mikrotik router that works properly. The firewall was set to closed, i.e. certain things were allowed in the first place, at the very end was the drop of everything else. It so happened that in the process of testing, a colleague created a rule in the firewall on the chain output, indicated in dst. address list A list containing one of the subnet addresses - 192.168.1.190/24, in the action I wrote drop. After that, the rule went to the very bottom of the queue and the winbox connection was interrupted, as well as the ping to the router stopped. Because all access services have been turned off, then winbox is the only chance to connect to the router. At the moment, the Internet is working, employees can connect, but getting into the configuration does not work. What actually screwed up a colleague? Is there a chance to regain control access without a full reset? Is there any console port on RB951Ui-2nD? Will the backups made in the device's memory be saved when it is completely reset via the button? Is there any way to get these backups out?

Answer the question

In order to leave comments, you need to log in

5 answer(s)
L
Ltonid, 2017-09-29
@aphazel

In general, 99% that you have to reconfigure everything, but there is one very difficult trick that will help you make a backup if you haven’t done it before.
If you manage to restart Mikrotik yourself, it will create an autobackup.
There are two ways I know: 1) load the percentage very heavily, for this you need to drive traffic. 2) manage to connect the cables so that his roof is blown away. Depending on the firmware, you can read something else on the Internet.
if you made backups yourself, then yes they are saved with a full reset.

A
Alexander Karabanov, 2017-09-28
@karabanov

In general, use Safe mod to prevent this from happening.
And you can try to connect by MAC

A
Anton Ulanov, 2017-09-28
@antonsr98

you can delete the rule through the console

D
Dmitry Alexandrov, 2017-09-29
@jamakasi666

As a rule, everyone has a console port, but it may not be soldered. Open the router and find nickels on the rx \ tx board, with a probability of 99% they will be 3.3 volts, which means you need a uart that you can buy or make some kind of Nokia \ Samsung \ Siemens from an old cord. Cling to them on these pins and forward. For convenience, for the future, you can solder the pins and drill holes in the case above them so that if this happens again, you can connect without disassembling the router.

K
Kirill Vasiliev, 2017-09-29
@vasilevkirill

if you did not explicitly disable mac-server, then you must connect, since this is a kind of backdoor that cannot be controlled using a regular firewall.
If there is a tench or another microtic, try using mac-telnet
59ce3ab483ca2244753432.png

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question