Community discussions

MikroTik App
 
twnznz
just joined
Topic Author
Posts: 6
Joined: Sun Aug 24, 2014 12:14 pm

Feature request - Connection tracking sync w/other Mikrotik

Mon Dec 08, 2014 3:43 am

Hi,

I'd like to request a feature.

On Linux, one can run 'conntrackd' to synchronize the internal state of the connection tracking table with another Linux box.
This means when a connection is opened and tracked, the state of that connection is copied to the other Linux box and entered into its conntrack table.
This allows you to do things like clustered firewalls, where you can asymmetrically route across these two firewalls, because the connection tracking state is in sync.

If Mikrotik offered such a feature, I would likely consider implementing it as my corporate firewall.

Ideally, also provide a feature to keep firewall rules (filter/nat/mangle) in sync, but not necessarily as I can do that with a script pushing configs.

Thanks,
Tim
 
marrold
Member
Member
Posts: 427
Joined: Wed Sep 04, 2013 10:45 am

Re: Feature request - Connection tracking sync w/other Mikrotik

Mon Jul 06, 2015 8:20 pm

Has there been any progress on this?
 
twnznz
just joined
Topic Author
Posts: 6
Joined: Sun Aug 24, 2014 12:14 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Thu Oct 08, 2015 6:11 am

None yet.
 
kirost
just joined
Posts: 15
Joined: Fri May 13, 2016 4:05 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Fri Jun 24, 2016 2:46 am

This feature will good thing then the Master VRRP router fault.
All connections (nat translations, open tcp sessions) will be modev to backup vrrp router....
 
niumar
just joined
Posts: 4
Joined: Thu Aug 10, 2017 10:47 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Thu Aug 10, 2017 10:56 pm

This feature would be very usefull when you are working with replicated structures, like site and site-backup.
Another application would be on autonomous system that have two out/inbound routers and serves multiple lans.

Any news on that?
 
mtholl
just joined
Posts: 1
Joined: Tue Nov 21, 2017 11:43 am

Re: Feature request - Connection tracking sync w/other Mikrotik

Tue Nov 21, 2017 11:46 am

Hi,

Are there any news on this?
Features like this would make my life so much easier and RouterOS much more useful for mission-critical infrastructure.

Is there any comment from mikrotik themselfs on this?

Regards
 
roysbike
just joined
Posts: 6
Joined: Wed Mar 25, 2015 10:38 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Tue Aug 20, 2019 8:34 am

Has there been any progress on this?
 
jeanpara
just joined
Posts: 9
Joined: Wed Oct 11, 2017 5:47 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Tue Feb 25, 2020 1:44 am

When can we wait for this function? weird if it's specialized sound equipment wan, the wan is not considered critical?
 
markwien
Frequent Visitor
Frequent Visitor
Posts: 69
Joined: Sun Jul 22, 2018 10:49 am

Re: Feature request - Connection tracking sync w/other Mikrotik

Sat Mar 21, 2020 2:57 pm

is there some update on conntrack-sync?

like on vyos:

https://docs.vyos.io/en/latest/appendix ... es/ha.html
 
Widmo
just joined
Posts: 7
Joined: Thu Sep 14, 2017 2:02 am

Re: Feature request - Connection tracking sync w/other Mikrotik

Thu Aug 19, 2021 8:30 pm

Bump in 2021 😁
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Fri Aug 20, 2021 2:46 pm

It works somehow in RouterOS 7.1beta6, linked to the VRRP functionality.
 
metrotyranno
just joined
Posts: 14
Joined: Fri Mar 24, 2017 12:21 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Fri Dec 10, 2021 6:12 pm

Vrrp connection syncing won't really do it for us. We need to sync netmaps of /24's to create HA scenarios'

Could Mikrotik create a native connection tracking sync without needing to use vrrp?
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Sat Dec 11, 2021 10:04 am

I'm not sure whether the synchronization process takes into account any relationship of the connections being synchronized to the VRRP addresses. I can see the connection synchronisation process to run on a pair of CHR running 7.1, and I can see that connections to/from individual addresses of the CHRs are not synchronized. I don't have enough time at this time of the year to create a setup where traffic would be forwarded by one of the CHRs bypassing the VRRP interface, but you should definitely try that first before requesting development which may have actually been already made.
 
metrotyranno
just joined
Posts: 14
Joined: Fri Mar 24, 2017 12:21 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Sat Dec 11, 2021 9:33 pm

It appears the current implementation is an active-backup scenario. We want to use active-active. I've tried setting up bi-directional conntrack syncing but it just errors that the bind has failed. This active-backup is evident from the logs:

vrrp1 starting CONNTRACK SLAVE
and on the other router
vrrp1 starting CONNTRACK MASTER

I will do a full test at the office on monday but seeing the logs I'm reasonably certain it's only 1 way syncing.
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Sat Dec 11, 2021 10:26 pm

seeing the logs I'm reasonably certain it's only 1 way syncing.
Correct, it is one way, and it even seems to either not work or to be more selective than I can understand, I've made a simple test in the meantime and it failed.

I somehow didn't think about the active-active scenario.
 
metrotyranno
just joined
Posts: 14
Joined: Fri Mar 24, 2017 12:21 pm

Re: Feature request - Connection tracking sync w/other Mikrotik

Mon Dec 20, 2021 5:10 pm

The connection tracking does not seem to work properly yet. The log reports that it's setting up the master & slave connections, however when I cause a failover packets are dropped until I clear the firewall connections tracking.

Who is online

Users browsing this forum: Bing [Bot], mkx, Sddaw and 181 guests