Community discussions

MikroTik App

Search found 39 matches

by Babujnik
Fri Jun 02, 2023 11:04 am
Forum: General
Topic: network drive
Replies: 5
Views: 3186

Re: network drive

I believe it requires nfs4.1 in order to mount properly share on ROS.
currently I find rose-storage a bit buggy, i.e doest not mount iscsii from qnap/Synology NAS at all, causing hangout.
by Babujnik
Fri May 26, 2023 5:27 pm
Forum: Announcements
Topic: v7.10rc is released!
Replies: 183
Views: 53906

Re: v7.10rc is released!

any news on fixing issues with iscsi from QNAP/Synology target ?
SUP-109114 opened since April on this issue...
by Babujnik
Fri Mar 24, 2023 12:37 pm
Forum: Announcements
Topic: v7.9beta [testing] is released!
Replies: 118
Views: 26514

Re: v7.9beta [testing] is released!

rose-manager still does not work with QNAP/Synology iscsi targets
by Babujnik
Thu Mar 23, 2023 11:44 am
Forum: General
Topic: HAP AX^2 ether3 LED
Replies: 2
Views: 436

Re: HAP AX^2 ether3 LED

not much option to choose from ;-)
Screenshot 2023-03-23 at 10.43.58.png
by Babujnik
Wed Mar 22, 2023 3:41 pm
Forum: General
Topic: HAP AX^2 ether3 LED
Replies: 2
Views: 436

HAP AX^2 ether3 LED

Hi,

is it just me or there is a general issue with LED for ether3 interface ?
it' simply just not blinking, although interface is up, running, and connection is working without issue. no other interfaces is having this issue. just not sure if to return device for warranty or not :)
by Babujnik
Thu Mar 16, 2023 10:22 am
Forum: General
Topic: FQ_Codel and Mikrotik CCR CPU Utilization
Replies: 39
Views: 6729

Re: FQ_Codel and Mikrotik CCR CPU Utilization

that's why I'm asking :) as soon as I add rules before fasttrack: 3 ;;; cust: guests download chain=forward action=accept connection-state=established,related dst-address=192.168.100.0/24 log=no log-prefix="" 4 ;;; cust: guests upload chain=forward action=accept connection-state=establishe...
by Babujnik
Wed Mar 15, 2023 6:20 pm
Forum: General
Topic: FQ_Codel and Mikrotik CCR CPU Utilization
Replies: 39
Views: 6729

Re: FQ_Codel and Mikrotik CCR CPU Utilization

Here's an example of how I build these. This is a CCR2004 so I can get away with a bit more than on a 4011 but principals are the same. This is a very effective model. I don't use vlans per so this is IP matched match ip and mark UL and DL packets separately via mangle Add a queue tree with NO mark...
by Babujnik
Mon Feb 27, 2023 12:56 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140290

Re: v7.8 [stable] is released!

ROSE-MANAGER still cannot mount iscsi devices from QNAP/Synology NAS to CHR: [237610.752320] iSCSI_F:iscsi_target_login.c:803:iscsi_post_login_handler Login - I[MikroTik][MTK_IP:42944], T[iqn.2000-01.com.synology:valhalla.default-target.cf7d36ec4c8][SYNOLOGY_IP:3260], P[iSCSI/TCP] [237610.788037] iS...
by Babujnik
Fri Feb 10, 2023 11:07 am
Forum: RouterOS beta
Topic: 7.8beta2 adds new package ROSE-storage
Replies: 67
Views: 27370

Re: 7.8beta2 adds new package ROSE-storage

Interesing, as there seems to be issue while trying to run containers from iscsi/nfs disks: [user@lab] /container> add remote-image=pihole/pihole:latest interface=test envlist=pihole_envs root-dir=iscsi/pihole [user@lab] /container> pr 0 name="961c061d-628b-4b29-9cc5-1b25152952f8" tag=&quo...
by Babujnik
Thu Feb 09, 2023 4:56 pm
Forum: RouterOS beta
Topic: 7.8beta2 adds new package ROSE-storage
Replies: 67
Views: 27370

Re: 7.8beta2 adds new package ROSE-storage

@rameex43 make raid1 with tcp-nvme drives @Babujnik Thanks we will try to fix this. @sirbryan Simple partitioning will be available in upcoming versions. We will check what we can do about LVM or ZFS. @issme RDMA is different beast, currently its not planned. must have been issue from QNAP side, as...
by Babujnik
Wed Feb 01, 2023 8:12 am
Forum: Announcements
Topic: WinBox v3.37 released!
Replies: 110
Views: 141089

Re: WinBox v3.37 released!

Any news of native for Linux/MacOS version of winbox ?
by Babujnik
Tue Jan 31, 2023 12:17 pm
Forum: RouterOS beta
Topic: 7.8beta2 adds new package ROSE-storage
Replies: 67
Views: 27370

Re: 7.8beta2 adds new package ROSE-storage

not sure if this is purely to CHR related, but I can't properly list iSCSI on x86 machine: [admin@lab] /disk> add iscsi-address=192.168.0.100 iscsi-iqn=iqn.2004-04.com.qnap:ts-251:iscsi.lab.f84517 slot=nas type=iscsi [admin@lab] /disk> pr action timed out - try again, if error continues contact Mikr...
by Babujnik
Thu Jan 12, 2023 6:09 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114126

Re: v7.7 [stable] is released!

ok.. so how do You import ED25519 SSH keys ?
You can not. This is about ed25519 key exchange. Let's hope host keys and public key authentication will follow...
my bad ! thanks for clarification
by Babujnik
Thu Jan 12, 2023 5:48 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114126

Re: v7.7 [stable] is released!

ok.. so how do You import ED25519 SSH keys ?

public keys generated with "ssh-keygen -t ed25519" seems not to import on RoS:
[user@tik] /user/ssh-keys> import public-key-file=id_ed25519.pub user=user
unable to load key file (wrong format or bad passphrase)!
by Babujnik
Wed Oct 26, 2022 1:36 pm
Forum: General
Topic: IKEv2/IPSec PSK server
Replies: 19
Views: 17732

Re: IKEv2/IPSec PSK server

you configure it like any other IPSEC/IKEv2, just in "identities" you set up "pre shared key" as authorisation method. that's your PSK for android client.
by Babujnik
Fri Oct 07, 2022 3:03 pm
Forum: General
Topic: IPSEC site-to-site connection only one direction [SOLVED]
Replies: 8
Views: 1412

Re: IPSEC site-to-site connection only one direction [SOLVED]

interesting... when I'm connecting with RoadWarrior to SiteB, I can without any issue reach subnets on SiteA. when other way around - connection RoadWarrior to SiteA - I cannot reach subnet on SiteB. below configs of IPSEC and FIREWALL SiteA /ip firewall address-list add address=192.168.0.4 list=lte...
by Babujnik
Wed Oct 05, 2022 7:26 pm
Forum: General
Topic: l2tp with ipsec mschap2 auth issue
Replies: 1
Views: 643

Re: l2tp with ipsec mschap2 auth issue

having same issue between RB760iGS and CHG, both on latest 7.5.
no idea about your case, but in my situation, devices in the end manage to establish connection. sometimes takes 10min, sometimes 40
by Babujnik
Wed Oct 05, 2022 2:31 pm
Forum: General
Topic: IPSEC site-to-site connection only one direction [SOLVED]
Replies: 8
Views: 1412

Re: IPSEC site-to-site connection only one direction [SOLVED]

Or maybe I've misunderstood what you had in mind, and you actually mean that road warriors connected to Site A cannot access subnets on Site B?
apologies if wasn't clear, RoadWarrior connects to SiteA with IPSEC, but cannot access subnets on SiteB.
by Babujnik
Wed Oct 05, 2022 2:24 pm
Forum: General
Topic: IPSEC site-to-site connection only one direction [SOLVED]
Replies: 8
Views: 1412

Re: IPSEC site-to-site connection only one direction [SOLVED]

it's already in main post but: # serial number = A36A0D0B008A /ip ipsec mode-config add address-pool=vpn_pool name=roadwarrior /ip ipsec policy group add name=roadwarrior /ip ipsec profile add dh-group=modp1024 enc-algorithm=aes-128 name=roadwarrior add dh-group=modp2048 enc-algorithm=aes-128 name=i...
by Babujnik
Wed Oct 05, 2022 2:09 pm
Forum: General
Topic: IPSEC site-to-site connection only one direction [SOLVED]
Replies: 8
Views: 1412

Re: IPSEC site-to-site connection only one direction [SOLVED]

one question though - how to make sure that ROADWARRIOR can access SiteB ? because currently I see that it's reaching only SiteA
by Babujnik
Wed Oct 05, 2022 1:39 pm
Forum: General
Topic: IPSEC site-to-site connection only one direction [SOLVED]
Replies: 8
Views: 1412

Re: IPSEC site-to-site connection only one direction [SOLVED]

that was fast :D that's for answer - that did the work.

I think I need a break from configuration as I'm starting to make some basic mistakes and not able to find them -_-
by Babujnik
Wed Oct 05, 2022 1:16 pm
Forum: General
Topic: IPSEC site-to-site connection only one direction [SOLVED]
Replies: 8
Views: 1412

IPSEC site-to-site connection only one direction [SOLVED]

Hi, I've recently set site-to-site connection with IPSEC. peers are established, policies seems to be up. but for some reason I can get connection only in one direction. from SiteB to SiteA is working fine, the opposite direction - no chance. any idea what to take a look on ? I've tried similar sett...
by Babujnik
Thu Sep 29, 2022 5:33 pm
Forum: General
Topic: EoIP + L2TP + IPSEC MTU issue
Replies: 6
Views: 1426

Re: EoIP + L2TP + IPSEC MTU issue

Hi Sindy, I haven't stripped any internal network addresses O_o. anyway, just to have all information in one spot: Site_A (valhalla): # sep/29/2022 16:16:49 by RouterOS 7.5 # software id = CKQB-FCBE # # model = RB760iGS # serial number = A36A0D0B008A add client-to-client-forwarding=yes local-forward...
by Babujnik
Mon Sep 26, 2022 5:38 pm
Forum: General
Topic: EoIP + L2TP + IPSEC MTU issue
Replies: 6
Views: 1426

Re: EoIP + L2TP + IPSEC MTU issue

I've temporary switched to L2TP+BCP, but still no luck: /tool/sniffer/quick interface=mgmt ip-protocol=tcp port=ssh ip-address=192.168.101.9 Columns: INTERFACE, TIME, NUM, DIR, SRC-MAC, DST-MAC, SRC-ADDRESS, DST-ADDRESS, PROTOCOL, SIZE, CPU INTERFACE TIME NUM DIR SRC-MAC DST-MAC SRC-ADDRESS DST-ADDR...
by Babujnik
Sun Sep 25, 2022 11:03 am
Forum: General
Topic: EoIP + L2TP + IPSEC MTU issue
Replies: 6
Views: 1426

Re: EoIP + L2TP + IPSEC MTU issue

Hi Sindy, you're perfectly right, should have thought about exporting more info. guess I've spend too much time on thinking why there is issue with connection.. my apologies :) below export from siteA: /ip ipsec policy group add name=road_warriors /ip ipsec profile add name=road_warriors /ip ipsec p...
by Babujnik
Sat Sep 24, 2022 6:04 pm
Forum: General
Topic: EoIP + L2TP + IPSEC MTU issue
Replies: 6
Views: 1426

EoIP + L2TP + IPSEC MTU issue

Hi everyone, I'm having some issue with (probably) MTU settings in site-2-site connection and L2TP connection to one site. here's config SiteA: /interface bridge add admin-mac=9E:B9:9C:3F:B0:E7 auto-mac=no name=br_100_mgmt add admin-mac=08:55:31:0D:C8:F5 auto-mac=no name=br_200_home add admin-mac=D4...
by Babujnik
Wed Jul 06, 2022 1:31 pm
Forum: RouterOS beta
Topic: VxLAN example configuration
Replies: 19
Views: 35522

Re: VxLAN example configuration

What about VxLAN over IPsec?
i was wondering about that too. or via wireguard maybe
vxlan via L2tp+ipsec

your remote IP's will be those from L2TP connection
by Babujnik
Wed Dec 15, 2021 4:16 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226804

Re: v7.1 is released!

does OSPF works over WireGuard ? I just get hello packets and nothing more...
by Babujnik
Thu Sep 09, 2021 4:22 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 162782

Re: v7.1rc3 adds Docker (TM) compatible container support

from what I've seen - anytime you change variable, you need to remove and create new container.
by Babujnik
Sat Oct 31, 2020 12:36 am
Forum: General
Topic: Mikrotik not revoking certificate from CRL
Replies: 0
Views: 929

Mikrotik not revoking certificate from CRL

Hi, I've noticed some issue with revoking certificates on Mikrotik with external CRL. I'm using easy-rsa on linux box (192.168.0.151) to generate/sign/revoke certificates. some sort of small PKI I've generated certificate, exported it as p12 and imported on mikrotik as shown below: [noyes@midgard] /...
by Babujnik
Thu Mar 07, 2019 4:10 pm
Forum: RouterBOARD hardware
Topic: Powerline with 1gbit
Replies: 10
Views: 3976

Re: Powerline with 1gbit

depends on your electric infrastructure. i can easily get 300mbps between two Fritz devices. and utilizing 100mbps when my ISP gives me 250mbps is a huge loss
by Babujnik
Mon Feb 11, 2019 6:10 pm
Forum: RouterBOARD hardware
Topic: Powerline with 1gbit
Replies: 10
Views: 3976

Re: Powerline with 1gbit

I'm having Fritz! PLC, and works fine.
But there is no chance of monitoring devices unless you're plugged in directly. having it on RouterOS would definitely help and allow for other functionality :)
by Babujnik
Mon Feb 11, 2019 4:19 pm
Forum: RouterBOARD hardware
Topic: Powerline with 1gbit
Replies: 10
Views: 3976

Powerline with 1gbit

Hey,

are you planning to release powerline adapter (like https://mikrotik.com/product/pwr_line_ap) but with gigabit interface ?
I would be really interested in such solution :)
by Babujnik
Wed Jul 18, 2018 12:49 pm
Forum: Wireless Networking
Topic: poor range of 5Ghz, comparing to 2,4Ghz
Replies: 6
Views: 2647

Re: poor range of 5Ghz, comparing to 2,4Ghz

damn.. good to know about that -_- now just question if only to buy a custom repeater, or another MT device and set it up as repeater :D 2,4 GHz is having good range, but with that amount of noise I have near (at least 15 other networks), it's really hard to get good speed. thanks for reposones guys.
by Babujnik
Mon Jul 16, 2018 4:57 pm
Forum: Wireless Networking
Topic: poor range of 5Ghz, comparing to 2,4Ghz
Replies: 6
Views: 2647

poor range of 5Ghz, comparing to 2,4Ghz

Hi, I have a device RouterBOARD 962UiGS-5HacT2HnT, and I've configured it to use both, 5GHz as main network and 2,4GHz wireless interfaces (for some older devices). for some reason, 5Ghz network is having far more worse range. can you please take a look on my config and advise what can I tweak ? 0 R...
by Babujnik
Tue Jul 03, 2018 12:34 am
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 54359

Re: v6.42.5 [current]

is it only me, or wireless performance on 6.42.5 is really bad ? (RouterBOARD 962UiGS-5HacT2HnT) Is ANI enabled? /interface wireless set adaptive-noise-immunity=ap-and-client-mode wlan2 /interface wireless set adaptive-noise-immunity=ap-and-client-mode wlan1 No, i haven't set this function. I can r...
by Babujnik
Mon Jul 02, 2018 2:33 pm
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 54359

Re: v6.42.5 [current]

is it only me, or wireless performance on 6.42.5 is really bad ? (RouterBOARD 962UiGS-5HacT2HnT) Maybe it is device specific? No disconnection or slow network with RBD52G-5HacD2HnD running 6.42.5 maybe it is as you mentioned. haven't changed anything else in environment, except update to 6.42.5. go...
by Babujnik
Mon Jul 02, 2018 11:34 am
Forum: Announcements
Topic: v6.42.5 [current]
Replies: 124
Views: 54359

Re: v6.42.5 [current]

is it only me, or wireless performance on 6.42.5 is really bad ? today I couldn't even work from home, was disconnected every few minutes. speed between workstation and NAS (laptop--WIFI->RB--LAN->NAS) was runing around 800kbs (5Ghz Network !). when downgraded to 6.42.4 - works like a charm (RouterB...
by Babujnik
Wed May 10, 2017 4:11 pm
Forum: Wireless Networking
Topic: wireless speed
Replies: 0
Views: 717

wireless speed

Hi, This is my first post as I encountered issue which started to bother me a lot - wireless speed short topology: modem --> RB951Ui-2HnD--> client problem: - speed between modem and mikrotik: ~90Mbps/20Mbps - speed (via Wifi) between client and Mikrotik: ~ 40/20Mbps - speed (via eth) between client...