Posts

Resolving PRC Portal Session Drops in MikroTik Dual-WAN Environments Without Sacrificing Aggregated Bandwidth

Image
Category: MikroTik RouterOS / Network Engineering • ROS Version: RouterOS v7 1. Executive Summary & Problem Statement In Dual-WAN RouterOS configurations utilizing Per Connection Classifier (PCC) with the both-addresses-and-ports classifier, network operators can successfully deliver aggregated bandwidth ("Combined Speed") across multi-threaded applications, video streaming, and speed tests. However, sensitive local infrastructure—specifically the Professional Regulation Commission (PRC) CPDAS portal ( cpdas.prc.gov.ph ) —frequently fails to load, returning ERR_CONNECTION_REFUSED or persistent HTTP connection timeouts. Root Cause Analysis Modern web portals enforce strict IP Session Tracking to prevent session hijacking. Under the both-addresses-and-ports PCC scheme, individual client HTTP/HTTPS requests (such as fetching static assets, scripts, or authentication tokens)...

Why Didn't I Know? The Manifesto of the Exhausted "Messenger" From Friend Groups to Work Contracts

Image
There are days you'll wake up and realize: You aren't a partner in planning. You were just made a human secretary, a messenger, and a stress shock-absorber. Whether it's a friend group, a project, or your actual day job (especially if you're stuck in the sub-contracting system), the story is always the same. You're the one catching the lists, you're the one grilled when things change, but when it comes to actual decisions and budgets? Total silence. 1. The Endless Loop of Lists and Commands It's easy to bark orders when you aren't the one doing the heavy lifting. Every single day, you get ambushed by a mountain of requests: "List this down." "Update the changes" (with zero in-game adjustments to their actual plans). "Why do you have no idea what's going on?" Why on earth do I have no idea? Simple: Not because you're too lazy to find out, but because you know you don't h...

AIOps & SecOps Case Study using local ai and n8n - Part 2

Image
Part 2: Mini Self-Healing Infrastructure & Dynamic AIOps Remediation 1. Executive Summary & The Shift to Active Remediation In Part 1 , we established a foundational Zero-Cloud AIOps & Security Digest Engine , focusing on telemetry collection, log aggregation, and local AI-driven analysis to maintain complete data privacy without recurring cloud API costs. However, passive visibility only solves half the problem. Systems administrators still face the operational burden of manually executing routine fixes for recurring infrastructure anomalies. This installment explores Dynamic AIOps Remediation —bridging the gap between automated insight and system-level execution. By embedding an orchestration engine within our local architecture, telemetry alerts no longer just trigger notifications; they trigger intelligent, context-aware recovery workflows. 2. Architectural Enhancements & Component Stack To execute automated remediation ...

Open WebUI Password Reset Hell: A Real-World Troubleshooting Guide

Getting locked out of your self-hosted AI interface is frustrating. Getting locked out when traditional password reset methods completely fail is another level of tech hell. Recently, while managing an Open WebUI instance hosted inside a Proxmox LXC container , I ran into a brutal authentication loop. The standard documentation workflows didn't work. If you are stuck in an "Incorrect Email or Password" loop despite updating your SQLite database, this technical breakdown and step-by-step rescue guide is for you. The Anatomy of the Authentication Loop When you search for "Open WebUI forgot password," the official documentation points you to a simple database update via SQLite or using runtime environment variables ( WEBUI_ADMIN_EMAIL / WEBUI_ADMIN_PASSWORD ). However, in production environments, three hidden blockers often trigger a persistent lockout loop: The Python SQLite Illusion: Open WebUI utilizes Python’s built-in drivers to read and write ...

AIOps & SecOps Case Study using local ai and n8n - Part 1

Image
Building a Zero-Cloud AIOps & Security Digest Engine Executive Summary Objective: Establish a 100% self-hosted, private SOC/NOC reporting system that aggregates network telemetry and threat logs without relying on external cloud infrastructure. Core Stack: Zabbix 7, n8n, Suricata IDS/IPS, MikroTik REST API, Ollama (Qwen), and SMTP. Key Impact: Reduced daily log review time from 30+ minutes down to a 1-minute email digest, eliminating third-party API costs while keeping internal IP architectures fully isolated. The Problem: Alert Fatigue vs. Data Sovereignty Log Telemetry Overload: Manually reviewing thousands of daily Suricata entries ( fast.log / eve.json ) alongside Zabbix metrics induces severe operator fatigue. Data Sovereignty & Privacy Constraints: Transmitting internal IP schemas, network topology, and vulnerability vectors to public cloud LLM APIs poses...

Pro-Level MikroTik Connection Tracking Security & Timeout Hardening

Image
Default network gateway configurations are rarely optimized for security out of the box. In MikroTik RouterOS, the connection tracking engine defaults to keeping established TCP connections alive for up to 24 hours (`1d`). In active environments, this accumulates thousands of "ghost connections," burdening system memory and opening doors to resource exhaustion attacks. This article highlights how to harden your conntrack state table through strict timeout reduction and aggressive SYN flood mitigation. Architecture Overview: Conntrack State Table Hardening graph TD A[Incoming Network Packets] -->|State Inspection| B[MikroTik Conntrack Table] subgraph Hardening ["Timeout & Security Policy"] B -->|TCP Established: Lowered to 4 Hours| C[Purges Stale / Ghost Sessions] B -->|SYN Sent/Received: Lowered to 5 Seconds| D[Mitigates Port Scans & SYN Floods] ...

MikroTik CAKE Queue & Flow Optimization: Anti-Bufferbloat Guide for Small Networks

Image
In small to medium networks (such as 10 to 30 active users doing simultaneous streaming, downloads, and competitive gaming), standard router queues frequently fail to manage latency. When a single user saturates the bandwidth, packets pile up in buffers inside the router, causing ping to spike dramatically—a destructive phenomenon known as bufferbloat . This article details how to implement and optimize the advanced CAKE (Common Applications Kept Enhanced) queue type in MikroTik RouterOS v7 to guarantee absolute latency control. Architecture Overview: CAKE Queue Flow & Memory Allocation graph TD A[Incoming Heavy Traffic] -->|Router Interface| B[CAKE Queue Engine] subgraph Tuning ["CAKE Precision Tuning"] B -->|Flow Mode: dual-dsthost / dual-srchost| C[Fair Bandwidth Distribution] B -->|Memory Limit: 4MB - 8MB| D[Optimized Dropping Without RAM Bloat] ...