Community discussions

MikroTik App

Search found 102 matches

by theprojectgroup
Wed Sep 06, 2023 3:12 pm
Forum: RouterBOARD hardware
Topic: chateau 5G boot loop- netinstall not working
Replies: 12
Views: 6577

Re: chateau 5G boot loop- netinstall not working

A few others have exactly the same issues: https://www.reddit.com/r/mikrotik/comme ... boot_loop/
Mate I have exactly the same problem after attempted upgrade 7.11.2
by theprojectgroup
Fri Sep 01, 2023 10:00 am
Forum: RouterBOARD hardware
Topic: chateau 5G boot loop- netinstall not working
Replies: 12
Views: 6577

Re: chateau 5G boot loop- netinstall not working

I tried various machines (even an old windows xp), switches in between, etc.
Can anyone test with a "working" chateau 5g if it boots netinstall at all?
by theprojectgroup
Thu Aug 31, 2023 10:57 pm
Forum: RouterBOARD hardware
Topic: chateau 5G boot loop- netinstall not working
Replies: 12
Views: 6577

Re: chateau 5G boot loop- netinstall not working

I have the same issue and the linked tips won't work for me. Did you ever fix this unit? In my case I can see with wireshark: - bootp request from chateau 5g and reply from my machine (client ip is assigned) - tftp transfer for file vmlinux: CleanShot 2023-08-31 at 21.51.07@2x.png - tftp transfer co...
by theprojectgroup
Thu Jun 22, 2023 3:40 pm
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 134
Views: 26181

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

Switched to UniFi APs - Just works.
by theprojectgroup
Mon Apr 10, 2023 8:37 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

PeterXC
interface/detect-internet/print
    detect-interface-list: none
       lan-interface-list: none
       wan-interface-list: none
  internet-interface-list: none
  
   installed-version: 7.9rc2
  
by theprojectgroup
Mon Apr 03, 2023 11:59 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

You might get much better overall performance figures if running iperf3 with multiple parallel streams ("-P 8" or something). Your absolutely right and I often see higher rates when using parallel streams. But in my environment. With a single stream I can saturate my 300Mbit WAN line but ...
by theprojectgroup
Sun Apr 02, 2023 8:11 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

No, it was: name="ch-5ghz-march" frequency=5180,5260,5500 width=20/40/80mhz skip-dfs-channels=all I just tested with fully auto. Does it mean to leave everything empty? Seems to work but TCP is still very slow! Other none AX devices like 802.11ac don't show this behaviour... name="ch-...
by theprojectgroup
Sat Apr 01, 2023 9:11 pm
Forum: General
Topic: Feature Request: Ed25519 SSH keys
Replies: 57
Views: 20345

Re: Feature Request: Ed25519 SSH keys

+1. Please, still unsupported in 2023?
by theprojectgroup
Mon Mar 27, 2023 8:25 pm
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

*) wifiwave2 - fixed issue which lead to VLAN-tagged wireless clients receiving tagged traffic from other VLANs;
viewtopic.php?t=194781
Could this explain the issues with a Windows VM running on a Wireless client?
by theprojectgroup
Mon Mar 27, 2023 8:21 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

v7.8 [stable] is released: https://forum.mikrotik.com/viewtopic.php?t=193986 - Update: - still the same issue - ~100Mbits/sec TCP download on client / 780 Mbits/sec upload - UDP is fine v7.9beta [testing] is released: https://forum.mikrotik.com/viewtopic.php?t=194781 - Update: - still the same issue...
by theprojectgroup
Sun Mar 05, 2023 9:25 pm
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

Makes sense, thanks a lot.
by theprojectgroup
Sun Mar 05, 2023 7:40 pm
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

The whole thing is (almost) never due to bugs in switches/bridges, so it's not clear why are we still discussing it in this forum? Maybe because people run into that issue, google it up, find this topic, and don't read my post #4 :D Hey Sindy. I hear you and thanks for the hint with drivers strippi...
by theprojectgroup
Sun Mar 05, 2023 2:14 am
Forum: General
Topic: Windows 10 Router Advertisement leaking
Replies: 5
Views: 966

Re: Windows 10 Router Advertisement leaking

Had the same issue and was suspecting my MikroTik as the culprit but I was very wrong. I found a few background infos about this topic: https://forum.mikrotik.com/viewtopic.php?p=988242#p988242 Basically It's default behaviour by Windows drivers which comply WHQL: https://docs.microsoft.com/en-us/wi...
by theprojectgroup
Sun Mar 05, 2023 1:35 am
Forum: General
Topic: IPv6 Advertising two ranges on one interface [SOLVED]
Replies: 5
Views: 2227

Re: IPv6 Advertising two ranges on one interface [SOLVED]

viewtopic.php?p=988242#p988242

Is your client a Windows machine connect untagged to a port which also has tagged VLANs on it?
It looks like Windows just strips off the vlan tags and then gets the RAs which are in VLAN tagged packets.
by theprojectgroup
Sun Mar 05, 2023 1:27 am
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

I'm still seeing this issue in various deployments. Searching the net shows lots of people have similar issues only related to IPv6 RAs and it looks like only WindowscClients are affected... It looks like Windows just strips off the vlan tags and then gets the RAs which are in VLAN tagged packets. -...
by theprojectgroup
Sat Mar 04, 2023 10:41 pm
Forum: Containers
Topic: Container for mDNS repeater
Replies: 9
Views: 7427

Re: Container for mDNS repeater

Thanks a lot for the great work and building the container image!

I just wrote a little HowTo set this up: viewtopic.php?t=194185&hilit=mdns+repeater+container

Now I'm able to share Airprint and Airplay with my guest vlan / wlan.
by theprojectgroup
Sat Mar 04, 2023 10:32 pm
Forum: Useful user articles
Topic: HowTo: mDNS-repeater on MikroTik using container / Docker
Replies: 17
Views: 12429

HowTo: mDNS-repeater on MikroTik using container / Docker

I didn't find a howto on the forum so I wanted to share something back. Apple Airplay or Airprint clients use multicast DNS to discover speakers & printers on the network. mDNS uses the IP address 224.0.0.251, which is "administratively scoped" and does not leave the subnet. "mdns...
by theprojectgroup
Sun Feb 26, 2023 5:57 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

Nice manners, please.
by theprojectgroup
Sun Feb 26, 2023 5:10 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

you could set both interfaces (one for 2,4 and one for 5ghz) to the same ssid name.
by theprojectgroup
Fri Feb 24, 2023 8:43 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

Does this looks like a bridging + TCP + ether1 2.5GbE issue?
UDP works fine.
What is your range during tests?
60-100 cm
by theprojectgroup
Fri Feb 17, 2023 1:15 pm
Forum: Beginner Basics
Topic: Extremely poor WiFi of MacBook Pro M1 PRO [SOLVED]
Replies: 17
Views: 2905

Re: Extremely poor WiFi of MacBook Pro M1 PRO [SOLVED]

@normis

Is there any overview available of possible frequencies?
https://help.mikrotik.com/docs/display/ ... properties

Can you please share your wireless and bridge settings?
by theprojectgroup
Thu Feb 16, 2023 4:24 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

yep, already did both!
by theprojectgroup
Thu Feb 16, 2023 3:53 pm
Forum: Beginner Basics
Topic: Extremely poor WiFi of MacBook Pro M1 PRO [SOLVED]
Replies: 17
Views: 2905

Re: Extremely poor WiFi of MacBook Pro M1 PRO [SOLVED]

I have similar issues described here and I don't think it's a platform issue. See my iperf3 results. It looks like it's an issue of bridging the 2.5GbE port (ether1) with wifi1 and TCP. https://forum.mikrotik.com/viewtopic.php?p=984769#p984769 - iperf3 TCP download via bridge & 2.5GbE is really ...
by theprojectgroup
Thu Feb 16, 2023 3:32 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

Does this looks like a bridging + TCP + ether1 2.5GbE issue? UDP works fine. Still had a chance to access an AX Windows machine but it looks like it's not a platform issue. Macbook Air M2 < wifi1 < bridge 1 < ether1 (2.5GbE) < Intel NUC8 with Thunderbolt 10 GbE TCP - iperf3 Up - Good iperf3 -c 192.1...
by theprojectgroup
Wed Feb 15, 2023 6:13 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

The issue doesn't exist when doing NAT, only when WLAN < Bridge > ethernert > server.
by theprojectgroup
Wed Feb 15, 2023 11:29 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

Will Try other Windows AX devices but I don't see why this is mac related.

If the traffic is bridged = bad
If the traffic is NATed = good
So this seems a bridging issue, right?

The AX Macbook Air M2 and MacBook Pro M1Max work great with UniFi AX APs btw.
by theprojectgroup
Wed Feb 15, 2023 10:42 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

Still the same issue on latest RC.
by theprojectgroup
Sun Jan 29, 2023 2:54 am
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76955

Re: v7.8beta [testing] is released!

No, it's not.
I am very sorry, but it is.
hAP ax2 & 3 have major stability and performance issues since their release for at least a few people.

But I am very glad you seem to be not affected .
by theprojectgroup
Sun Jan 29, 2023 12:14 am
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76955

Re: v7.8beta [testing] is released!

hAP ax3 wifi is very slow and unstable (but it's also on stable ROS):
viewtopic.php?p=980696&hilit=hap+ax3#p980696
Looks like it's bridge related. When routing and natting, throughput is stable in both directions.
by theprojectgroup
Sat Jan 28, 2023 11:58 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48864

Re: MikroTik hAP ax3 poor WiFi performance

Same here with hAP ax3. Client MacBook Air M2 (AX) iperf3 sending > WiFi1 (5G) + ether1 in one bridge > ether1 > nuc8 350-750 Mbit/s (quiet unstable...) Client MacBook Air M2 (AX) iperf3 receiving < WiFi1 (5G) + ether1 in one bridge < ether1 < nuc8 70-120 Mbit/s (quiet unstable...) Client MacBook Ai...
by theprojectgroup
Wed Dec 21, 2022 9:01 pm
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 134
Views: 26181

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

@jacobp posted here: https://forum.mikrotik.com/viewtopic.php?t=191635#p973040 The 7.7rc2 release has fixed my issue with the hAP ax2 radios. With the countries field now populated, the wifi radios start up and devices associate just fine. Thanks to the Mikrotik team for getting that taken care of! ...
by theprojectgroup
Thu Dec 15, 2022 2:19 pm
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 134
Views: 26181

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

... connect to AC3 with LAN cable via Winbox without sucess.
I don't think it's related. The hAP ax2 is accessible via LAN. It just stops broadcasting BSSID beacons and you can't connect anymore...
by theprojectgroup
Sun Dec 11, 2022 12:42 am
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 134
Views: 26181

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

Same here. WiFi drops every night, only reboot helps. /interface/wifiwave2/export # dec/10/2022 23:40:36 by RouterOS 7.6 # software id = JAMW-UMX1 # # model = C52iG-5HaxD2HaxD /interface wifiwave2 set [ find default-name=wifi2 ] configuration.mode=ap .ssid=MyWiFi2G /interface wifiwave2 channel add f...
by theprojectgroup
Thu Nov 17, 2022 11:48 pm
Forum: Wireless Networking
Topic: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!
Replies: 53
Views: 10286

Re: hAP ax² WiFi6 (802.11ax) Initial Tests, good news!

Can you please post your wifi config of hap ax2?
Thanks.
by theprojectgroup
Wed Nov 16, 2022 8:51 am
Forum: Wireless Networking
Topic: wifiwave2 snmp metrics missing hAP ax2
Replies: 12
Views: 4121

wifiwave2 snmp metrics missing hAP ax2

Hi, I noticed my snmp monitoring (LibreNMS) is missing wireless metrics like client count, etc. since I replaced a hAP ac2 with a hAP ax2 running routerOS 7.7beta4 and wifiwave2 package. hAP ac2 7.7beta4 CleanShot 2022-11-16 at 07.42.01@2x.png hAP ax 2 7.7beta4 CleanShot 2022-11-16 at 07.43.21@2x.pn...
by theprojectgroup
Sat Oct 08, 2022 9:02 pm
Forum: General
Topic: Random wired link down
Replies: 6
Views: 4168

Re: Random wired link down

Stupid question but how to proper earth these soho devices like hap ac, hap ac2?
Experiencing same issues here at home. The issue started when no one was at home during holidays and I got saw multiple random link downs in my monitoring.
by theprojectgroup
Mon Aug 08, 2022 9:23 am
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

There is a manual https://help.mikrotik.com/docs/display/ROS/Switch+Chip+Features#SwitchChipFeatures-PortSwitching maybe it could put some light on the problem: Switch chips with a VLAN table support (QCA8337, Atheros8327 , Atheros8316, Atheros8227 and Atheros7240) can override the port isolation c...
by theprojectgroup
Mon Aug 08, 2022 9:19 am
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

Config Export /interface bridge add admin-mac=AA:BB:CC:DD:EE:C8 auto-mac=no comment=defconf name=bridge \ protocol-mode=stp /interface ethernet set [ find default-name=ether1 ] comment="connected to M-net FritzBox" name=\ ether1-wan speed=100Mbps set [ find default-name=ether2 ] comment=\ ...
by theprojectgroup
Sun Aug 07, 2022 2:41 pm
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

No,
I am on current ROS 7 and I answered here because the topic perfectly matches my issue.
by theprojectgroup
Sun Aug 07, 2022 11:10 am
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

Hm. How is it possible that this is going over WiFi?
IIRC WLAN tags aren't sent over WiFi, right? But my Win-VM running on the mac (connected via WiFI) inside Parallels Hypervisor receives RAs so there must be some leak...
by theprojectgroup
Sat Aug 06, 2022 11:30 pm
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

The still persists, even when I disable the particular VLANs on the switch:
CleanShot 2022-08-06 at 22.29.06@2x.png
CleanShot 2022-08-06 at 22.51.28@2x.png
CleanShot 2022-08-06 at 22.33.47@2x.png
by theprojectgroup
Sat Aug 06, 2022 11:25 pm
Forum: General
Topic: Router Advertisement leakage across VLANs
Replies: 25
Views: 4071

Re: Router Advertisement leakage across VLANs

I have exactly the same issue. I have a MT at my home office with: hAP AC2: - bridge (is default vlan1) without vlan filtering enabled - vlans configured on switch chip On my macbook connected via WLAN i have a windows VM running which gets IPv6 addresses from a few, sometimes all vlan interfaces wi...
by theprojectgroup
Fri May 06, 2022 9:43 am
Forum: Wireless Networking
Topic: LTE Cellular and IPv6 ...
Replies: 4
Views: 6327

Re: LTE Cellular and IPv6 ...

Just got IPv6 on Chateau 5G with german Vodafone over 5G working…
Clients on bridge get IPv6: viewtopic.php?t=183382
by theprojectgroup
Thu May 05, 2022 11:43 pm
Forum: General
Topic: Mikrotik Chateau 5G ipv6 on lte interface is useable but not for lan clients
Replies: 2
Views: 1534

Re: Mikrotik Chateau 5G ipv6 on lte interface is useable but not for lan clients

Ahm... yes - what?
Just right after my post I checked the IP on my MacBook and I have IPv6.
IPv6/ND is set to bridge interface (ether1..5 and wlan interfaces).
Currently using Vodafone over 5G, will check with Telekom soon.
CleanShot 2022-05-05 at 22.36.22@2x.png
by theprojectgroup
Thu May 05, 2022 11:32 pm
Forum: General
Topic: Mikrotik Chateau 5G ipv6 on lte interface is useable but not for lan clients
Replies: 2
Views: 1534

Re: Mikrotik Chateau 5G ipv6 on lte interface is useable but not for lan clients

@Emil, can you confirm this is not supported?
Not sure if I remember correctly, but I had IPv6 LTE working with wAPr...
by theprojectgroup
Wed Feb 09, 2022 10:51 am
Forum: General
Topic: /user export show-sensitive not showing any sensitive informations
Replies: 3
Views: 6639

/user export show-sensitive not showing any sensitive informations

Hi, not sure if this even possible because I guess the user passwords are stored only as hashes, right? I'm wondering what the " show-sensitve " switch does in /user export in RouterOS 7.x I see no difference in the output of /user export with and without the parameter. Thank you in advanc...
by theprojectgroup
Wed Feb 02, 2022 5:33 pm
Forum: RouterOS beta
Topic: Solved: Problem with two default IPv6 routes using dhcpv6-client (7.1rc2)
Replies: 11
Views: 5082

Re: Solved: Problem with two default IPv6 routes using dhcpv6-client (7.1rc2)

Removing "Add Default Route" also worked for me with pppoe and german ISP M-net. Would it be more convenient if we could have these settings in the pppoe-client? Example: Add Default Route: IPv4: yes IPv6: yes < if this is set to yes, then untick for any DHCPv6-Client running on this inter...
by theprojectgroup
Wed Dec 29, 2021 10:04 pm
Forum: The Dude
Topic: Push logs from Mikrotik to Graylog Server
Replies: 8
Views: 14770

Re: Push logs from Mikrotik to Graylog Server

How solved? I can`t see any hint;o). I have the similar problem too. Please describe your issue. It works fine for me: CleanShot 2021-12-29 at 21.00.37@2x.png CleanShot 2021-12-29 at 21.01.38@2x.png CleanShot 2021-12-29 at 21.02.26@2x.png Messages: CleanShot 2021-12-29 at 21.03.00@2x.png
by theprojectgroup
Sat Dec 18, 2021 12:12 am
Forum: General
Topic: L2TP Client kills my Wireguard Client - Multiple clients behind NAT
Replies: 1
Views: 993

Re: L2TP Client kills my Wireguard Client - Multiple clients behind NAT

I just found this and will walk through, could be helpful.


Multiple Road Warrior L2TP/IPsec clients behind NAT - solved:
viewtopic.php?t=132823

What I don't under stand yet: I only have one L2TP client which kills my wireguard clients...
by theprojectgroup
Fri Dec 17, 2021 11:56 pm
Forum: General
Topic: L2TP Client kills my Wireguard Client - Multiple clients behind NAT
Replies: 1
Views: 993

L2TP Client kills my Wireguard Client - Multiple clients behind NAT

Hey Forum I worked on this issue for hours and finally find the solution and want to share it. I have three client machines here in my home lan behind a NAT / Router. Then we have CCR1016-12G Router (routerOS v7.1) in the office which terminates these road warrior clients with l2tp/ipsec and Wiregua...
by theprojectgroup
Mon Dec 13, 2021 10:14 pm
Forum: General
Topic: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working
Replies: 45
Views: 23800

Re: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working

Turns out it is working, same for l2tp ppp dial-in - but only right after a fresh boot.
After a few minutes all tunnel die.
by theprojectgroup
Mon Dec 13, 2021 10:07 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 227176

Re: v7.1 [testing] is released!

無題.png I am also seeing the same problem. In my environment, restarting CCR1009 did not improve the CPU usage. Same here, I disabled ipsec and some routing filters that were migrated over, and everything is OK for now. Before that a reboot would help for a little, but then the IPSec connection woul...
by theprojectgroup
Mon Dec 13, 2021 3:27 pm
Forum: General
Topic: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working
Replies: 45
Views: 23800

Re: After Upgrade from 6.49.1 to 7.1 ipsec Site-Site not working

Same here + L2TP IPSEC Clients can't connect. CCR1016-12G L2TP Clients connects and fails with error "server did not respond" 14:12:59 ipsec,info respond new phase 1 (Identity Protection): 212.114.xx.xx[500]<=>80.187.82.203[500] 14:12:59 ipsec received Vendor ID: RFC 3947 14:12:59 ipsec re...
by theprojectgroup
Mon Sep 27, 2021 9:51 am
Forum: RouterOS beta
Topic: Loosing configuration after reboot (7.1rc3)
Replies: 16
Views: 4386

Re: Loosing configuration after reboot (7.1rc3)

Happened to me six times now - all on "hEX S" units with routerOS 7.1beta6 It works fine for a few weeks, sometimes months and then due to a reboot the routers lost the whole config (no config at all = 0.0.0.0). Restored latest .backup > reboot > coming back without config! Restored from ....
by theprojectgroup
Sat Jul 10, 2021 10:22 am
Forum: RouterOS beta
Topic: hAP AC & 7.1beta6: 100% CPU, Throughput 35% compared to 6.48.3
Replies: 1
Views: 1213

Re: hAP AC & 7.1beta6: 100% CPU, Throughput 35% compared to 6.48.3

Downgraded to 6.48.3, lost configuration (it did a full reset), restored config backup, ~930Mbit/s
by theprojectgroup
Sat Jul 10, 2021 10:12 am
Forum: RouterOS beta
Topic: hAP AC & 7.1beta6: 100% CPU, Throughput 35% compared to 6.48.3
Replies: 1
Views: 1213

hAP AC & 7.1beta6: 100% CPU, Throughput 35% compared to 6.48.3

Hi, I just upgraded my hAP AC from 6.48.3 to 7.1beta6 (including firmware). 6.48.3 - iperf3 single stream tcp - ~70% CPU - 930 MBit/s 7.beta6 - iperf3 single stream tcp - 100%CPU - ~330 Mbit/s CleanShot 2021-07-10 at 09.05.27.png CleanShot 2021-07-10 at 09.11.34.png CleanShot 2021-07-10 at 09.12.09....
by theprojectgroup
Fri Mar 19, 2021 4:43 am
Forum: General
Topic: Where to get Stock Firmware and RouterOS 7.0. (no Beta) for Chateau LTE 12
Replies: 5
Views: 1389

Re: Where to get Stock Firmware and RouterOS 7.0. (no Beta) for Chateau LTE 12

Thx for clarification :-/
So I guess we need to return the batch or Chateaus
Best Regards.
by theprojectgroup
Thu Mar 18, 2021 10:28 am
Forum: General
Topic: Where to get Stock Firmware and RouterOS 7.0. (no Beta) for Chateau LTE 12
Replies: 5
Views: 1389

Where to get Stock Firmware and RouterOS 7.0. (no Beta) for Chateau LTE 12

Hey Forum

we wanto to get get the stock firmware / RouterOS 7.0. (no Beta) our new Chateau LTE 12 shipped with.
We updated to v7.1 Beta5 and want to go back to "stable" 😂.

I can't find any download links.

Thx a lot and best regards.

Flo.
by theprojectgroup
Mon Jan 11, 2021 11:36 pm
Forum: General
Topic: L2TPG IPSEC not working via IPv6. Dial in via IPv4 works fine
Replies: 1
Views: 554

L2TPG IPSEC not working via IPv6. Dial in via IPv4 works fine

Hey Forum, I have an issue with out cloud core router and IPv6. We have a few road warriors dialling in via L2TPG/IPSEC VPN. This just works fine if they use our WAN IPv4 address as the target VPN server! If the VPN client (Windows 10) connects to the routers WAN IPv6 address, it doesn't work and ti...
by theprojectgroup
Wed Nov 11, 2020 11:07 pm
Forum: General
Topic: IPv6 - Advertise router as DNS [SOLVED]
Replies: 19
Views: 26876

Re: IPv6 - Advertise router as DNS [SOLVED]

why complicate your life? /ipv6 dhcp-server option> add code=23 name=dnstest value="'fe80::ceff:e0ff:fabc:abcd'" /ipv6 dhcp-server option> print # NAME CODE VALUE RAW-VALUE [...] 4 dnstest 23 'fe80::ceff:e0ff:fabc:abcd' fe80000000000000ceffe0fffabcabcd Since which routerOS version is this...
by theprojectgroup
Tue Nov 10, 2020 10:12 pm
Forum: General
Topic: IPv6 - Advertise router as DNS [SOLVED]
Replies: 19
Views: 26876

Re: IPv6 - Advertise router as DNS [SOLVED]

Python3 Script to convert the IPv6 address of your DNS to HEX format in /ipv6 dhcp-server option Install ip address module https://docs.python.org/3/library/ipaddress.html #!/usr/bin/python3 # https://docs.python.org/3/library/ipaddress.html # ^^ pip3 install ipaddress import ipaddress ip = input('...
by theprojectgroup
Tue May 12, 2020 5:58 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

Yours also shows all 7. 5+2
Extended Key Usage: Client and server authentication. Same on mine.

When you sign the certificate on MT, you must select the existing CA. Otherwise you just get a self signed.
by theprojectgroup
Tue May 12, 2020 5:03 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

ahm, if you don't have a value in issuer field the cert is not signed by the CA? ca expiration date doesn't has to match client cert date... try to re-create that all from scratch. New ca on router, new certs on router, sing them with router's ca... match cn and dns (SAN) name of the cert could be a...
by theprojectgroup
Tue May 12, 2020 3:12 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

My certificates: Screenshot 2020-05-12 at 14.08.04.png I guess key usage must be at least tls-client for client and tls-server for server Screenshot 2020-05-12 at 14.09.50.png|200px Screenshot 2020-05-12 at 14.09.59.png|20% Screenshot 2020-05-12 at 14.10.07.png|20% Screenshot 2020-05-12 at 14.10.19....
by theprojectgroup
Wed Apr 29, 2020 9:41 pm
Forum: RouterBOARD hardware
Topic: No beeper on HAP AC2
Replies: 6
Views: 8030

Re: No beeper on HAP AC2

Too bad. In my house I have a ZFS storage and a health-checker script which plays an alert song on all MikroTik devices if a disk or pool failes - https://forum.mikrotik.com/viewtopic.php?t=23976#p288920 # Play "Ozzy Osbourne - Crazy Train" using the /beep command on MikroTik in living roo...
by theprojectgroup
Mon Mar 09, 2020 12:53 pm
Forum: Announcements
Topic: v6.46.4 [stable] is released!
Replies: 106
Views: 78116

Re: v6.46.4 [stable] is released!

We are looking into the communication issues with The Dude connecting through Agent. Other issues related with The Dude "std failure" message must be caused by old version on either The Dude server or RouterOS client. theprojectgroup , please enable SSH debug logs (/system logging add top...
by theprojectgroup
Mon Mar 09, 2020 12:50 pm
Forum: General
Topic: OpenSSH future RSA host key deprecation
Replies: 26
Views: 14338

Re: OpenSSH future RSA host key deprecation

Version 6.46.4 also fixes the issue with public key authentication. All fine now, thanks a lot! This is not fixed. We still have issues (#[SUP-10614]) with public key authentication. The router first advertises rsa-sha2-256 and then declines it: 14:59:56 ssh,debug host key algo: rsa-sha2-256,ssh-rs...
by theprojectgroup
Mon Mar 02, 2020 11:48 am
Forum: Announcements
Topic: v6.46.4 [stable] is released!
Replies: 106
Views: 78116

Re: v6.46.4 [stable] is released!

Big issues with SSH keys since this update (coming from 6.46.1). I use Royal TSX with its "Secure Gateway" feature which is basically a great way to use SSH tunnels in this awesome remote connection manager. I get this error: "An error occurred while opening a Tunnel: A public key cor...
by theprojectgroup
Sun Mar 01, 2020 10:02 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 180642

Re: v6.47beta [testing] is released!

Same here, can't use Royal TSX Secure Gateway with ssh keys anymore:
This is fixed with 6.46.4 stable, so I guess it will be ok with next beta.
I am on 6.46.4 stable. I came from 6.46.1. now i have the issue. I am on confused.
by theprojectgroup
Sun Mar 01, 2020 7:03 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 180642

Re: v6.47beta [testing] is released!

*) ssh - added support for RSA keys with SHA256 hash (RFC8332); Ha, that was fast. Thanks! Will give it a try now. Looks like this breaks public key authentication. If I remove ssh-rsa from host key algorithms I am prompted for a password. Password login succeeds (if always-allow-password-login is ...
by theprojectgroup
Wed Feb 26, 2020 5:55 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

Hey,
yes I generate the certs on MT and export (p12) to my mac, then I use apple configurator:
- add both certificates here:
Screenshot 2020-02-26 at 16.54.23.png
vpn_home.mobileconfig 2020-02-26 16-56-33.png
Screenshot 2020-02-26 at 16.55.15.png
Screenshot 2020-02-26 at 16.55.42.png
by theprojectgroup
Mon Feb 10, 2020 5:47 am
Forum: RouterBOARD hardware
Topic: ltap mini usb power LTE interface off
Replies: 7
Views: 5418

Re: ltap mini usb power LTE interface off

Thx for the tip.
The sources should be fine.
Already tried 10cm cables. Didn’t work.
by theprojectgroup
Sun Feb 09, 2020 5:40 pm
Forum: RouterBOARD hardware
Topic: ltap mini usb power LTE interface off
Replies: 7
Views: 5418

Re: ltap mini usb power LTE interface off

Same here. The products description is horrible due to it's lack of disclaimers regarding function and compatibility. - USB Power not Working (at least LTE is missing, also WiFi is unstable) - GPS only with external antenna (I'm aware that the brochure now includes this but it hasn't a long time) An...
by theprojectgroup
Tue Feb 04, 2020 10:45 pm
Forum: General
Topic: IPv6 Ping does not work with domain names
Replies: 59
Views: 47127

Re: IPv6 Ping does not work with domain names

So now way to display except torch?
Is their any ETA?
Can’t recommend rOS for IPv6 deployments right now.
Many things like vpn, modeconfig, etc. is missing completely
by theprojectgroup
Tue Feb 04, 2020 8:35 am
Forum: General
Topic: IPv6 Ping does not work with domain names
Replies: 59
Views: 47127

Re: IPv6 Ping does not work with domain names

Uff.
Do you guys know a way to display / show the current SLAAC IPv6 address?
by theprojectgroup
Mon Feb 03, 2020 10:07 pm
Forum: General
Topic: IPv6 Ping does not work with domain names
Replies: 59
Views: 47127

Re: IPv6 Ping does not work with domain names

Is this really still an issue?
Is MikroTik still not IPv6 ready?
by theprojectgroup
Thu Nov 14, 2019 10:59 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

I'm on the most current 6.45.7 this is my config: /ip ipsec profile add dh-group=modp2048 dpd-interval=1h enc-algorithm=aes-256 hash-algorithm=sha256 lifetime=1h name=ikev2 /ip ipsec peer add exchange-mode=ike2 name=ikev2 passive=yes profile=ikev2 send-initial-contact=no /ip ipsec proposal add auth-...
by theprojectgroup
Thu Nov 14, 2019 10:24 am
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

no - except of changing to the new certificate ;) Did you change it?
Can you show screenshots of your certs?
Screenshot 2019-11-14 at 09.23.49.png
by theprojectgroup
Wed Oct 30, 2019 10:39 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

SOLVED: Thx to Emils Z. from support. He pointed out, that in iOS13 & macOS Catalina "Apple has added SAN certificate field verification and it fails in the new version because your certificates does not have any Subject Alt". I re-created both certificates for client & server wit...
by theprojectgroup
Wed Oct 23, 2019 6:53 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

Not yet - Emil from support suggested to check the certificate to include the subject alternative names of local and remote id which didn't help (i just tried it with the client certificate)
Screenshot 2019-10-23 at 17.52.16.png
by theprojectgroup
Tue Oct 22, 2019 10:14 am
Forum: General
Topic: MacOS Catalina, iOS, Catalyst, SwiftUI & Wine
Replies: 186
Views: 97372

Re: MacOS Catalina, iOS, Catalyst, SwiftUI & Wine

Thx for the howto run winbox64 !

Make sure to backup "/Users/your-user-name/.wine/drive_c/users/flo/Application Data/Mikrotik" to later restore it to keep your connections...
by theprojectgroup
Tue Oct 22, 2019 9:45 am
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

Just found the RFC wich mentions the truncate issue: https://tools.ietf.org/html/rfc8221 AUTH_HMAC_SHA2_256_128 was not mentioned in [RFC7321], as no SHA2-based authentication was mentioned. AUTH_HMAC_SHA2_256_128 MUST be implemented in order to replace AUTH_HMAC_SHA1_96. Note that due to a long sta...
by theprojectgroup
Mon Oct 21, 2019 11:11 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

I found and iPhone 12.4.2, released after 13. Last update. I am having the same issue. Can anyone confirm? UPDATE: My fault it works. I had to add the "Local ID" I am confused and can’t understand what you are saying. Please let us know what works and what not and how you probably fixed it.
by theprojectgroup
Mon Oct 21, 2019 9:53 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

confirmed, changing to different hash algorithm doesn't help.
by theprojectgroup
Mon Oct 21, 2019 5:38 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Re: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

Don't want to blame anyone... The tunnel seems to establish fine but iOS thinks it's an "User Authentication" error. Regarding to apple we need to "configure the server to truncate the output of the SHA-256 hash to 128 bits" on the MikroTik, but how? Emil is already on it (opened...
by theprojectgroup
Sun Oct 20, 2019 11:37 pm
Forum: General
Topic: Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]
Replies: 40
Views: 41398

Solved: iOS 13 & macOS Catalina IKEv2 VPN not working anymore [SOLVED]

Hey People, since iO13 or macOS Catalina IKEv2 VPN isn't working anymore (client certificates). While trying to connect you get this error: "User authentication failed" From the MikroTik logs everything looks fine (client gets an IP assigned). MacOS Mojave and iOS12 are still working fine....
by theprojectgroup
Fri Aug 30, 2019 6:18 pm
Forum: General
Topic: Can't get IPv6 Address via DHCP Client on MikroTik
Replies: 5
Views: 5308

Re: Can't get IPv6 Address via DHCP Client on MikroTik

In my case my cable ISP doesn't allow bridge mode, so i must use the crappy modem/router of them. I use the mikrotik as vpn gateway, ssh server, etc. This is why I want it to have an ipv6 address.
Currently it's only reachable via ipv4 behind nat / dst-nat for ssh, ipsec, etc.
by theprojectgroup
Fri Aug 30, 2019 12:23 pm
Forum: General
Topic: IPv6 Ping does not work with domain names
Replies: 59
Views: 47127

Re: IPv6 Ping does not work with domain names

This is real ? Still an issue!

Why not just implement a second ping command called ping6?
by theprojectgroup
Thu Aug 29, 2019 11:19 pm
Forum: General
Topic: Can't get IPv6 Address via DHCP Client on MikroTik
Replies: 5
Views: 5308

Re: Can't get IPv6 Address via DHCP Client on MikroTik

If all you want is a IPv6 host address without PD to populate the pool, then you need to get rid of the pool configuration. That assumes that the cable modem/router is serving as the v6 dhcp server (which it appears to be based on the client screen shot). Hey, thx for the hint. I'm wondering how to...
by theprojectgroup
Thu Aug 29, 2019 4:50 pm
Forum: General
Topic: Can't get IPv6 Address via DHCP Client on MikroTik
Replies: 5
Views: 5308

Can't get IPv6 Address via DHCP Client on MikroTik

Hey All, I can't get an IPv6 address on my MikroTik via DHCPv6 Client. My Setup at my home office is like this: Vodafone Germany Docsis 3.1 Cable ISP < > Arris Cable Modem/Router < SWITCH > Clients on LAN, WLAN, etc. and also the MikroTik is connected (Dual Stack, IPv4 and IPv6) Acts as normal Route...
by theprojectgroup
Fri Aug 16, 2019 12:24 am
Forum: General
Topic: Backup and Restore Certificates
Replies: 21
Views: 18186

Re: Backup and Restore Certificates

Is there a recommended way to backup and restore config including certs & keys?
by theprojectgroup
Fri Aug 16, 2019 12:22 am
Forum: General
Topic: IKE2 RSA signature - identity not found for peer: DER DN: [SOLVED]
Replies: 5
Views: 14285

Re: IKE2 RSA signature - identity not found for peer: DER DN: [SOLVED]

Same here, disabling doesn't help.

The strange thing is, it works on iOS fine, but the windows client doesn't. Current RouterOS from today on CCR
by theprojectgroup
Fri Sep 14, 2018 12:29 pm
Forum: General
Topic: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)
Replies: 15
Views: 6833

Re: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)

Any progress here @mrz? You mentioned some improvements in the future.
I have the same issue here with CCR and current routerOS on Windows and macOS/iOS clients.
They only use the first subnet defined in mode-config > split-include. The other subnets for the split tunnel are ignored.
by theprojectgroup
Sat Sep 08, 2018 4:25 pm
Forum: General
Topic: OpenVPN client takes long to connect (up to 20 seconds)
Replies: 1
Views: 1107

Re: OpenVPN client takes long to connect (up to 20 seconds)

What I can see from apple configurator default lifetime is 1440 minutes (24h, 1day). Setting peer & proposal doesn't help. What I found the connection stays longer connected when setting lifetime to 60 minutes in apple configurator vpn profile and also on the Mikrotik CCR-10161-12G. I will test ...
by theprojectgroup
Sat Sep 08, 2018 1:33 pm
Forum: Beginner Basics
Topic: IPsec-SA expired before finishing rekey [SOLVED]
Replies: 4
Views: 10868

Re: IPsec-SA expired before finishing rekey [SOLVED]

I have the same issue with IOS and MacOS (current build): 10:04:00 ipsec processing payload: KE (not found) 10:04:00 ipsec IPsec-SA established: IP_OF_CLIENT[4500]->IP_OF_VPN_Router[4500] spi=0xa37f177 10:04:00 ipsec IPsec-SA established: IP_OF_VPN_Router[4500]->IP_OF_CLIENT[4500] spi=0xb93a775 10:0...
by theprojectgroup
Fri Aug 31, 2018 10:28 am
Forum: General
Topic: OpenVPN client takes long to connect (up to 20 seconds)
Replies: 1
Views: 1107

OpenVPN client takes long to connect (up to 20 seconds)

Hey All, I have an issue with OpenVPN as long I use it on MT routers. It takes up to 20 seconds (until the client says it's connected) to establish a connection from a Mac (tunnelblick or viscosity) or Windows client. It doesn't make a difference which MT model I use, no matter if it's a hexLite or ...
by theprojectgroup
Mon Mar 13, 2017 10:00 pm
Forum: General
Topic: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)
Replies: 134
Views: 49563

Re: Is re-ordering fixed yet with IPSec and hardware acceleration? (Updating thread)

Looking good here on CCR1016-12G, tested before and after the update :)

Site2Site IPIP Tunnel Spain (fibre 300mbits ISP: consumer) <-----------> Germany (fibre 100mbits ISP: m-net corp) with latency:60ms

SMB2 traffic:
speed.png