Community discussions

Search found 231 matches

by vecernik87
Fri Oct 19, 2018 1:04 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 40
Views: 5574

Re: URGENT security reminder

If it is old RouterOS and you get "bad password" it means you have access to vulnerable winbox service. All you need to do is try the Proof of Concept: https://github.com/BasuCert/WinboxPoC It is really simple to use, all you need is python3 installed and IP/MAC of the device. Someone hacked your de...
by vecernik87
Fri Oct 19, 2018 12:29 pm
Forum: Beginner Basics
Topic: Router shows used space, but no files are on it
Replies: 3
Views: 85

Re: Router shows used space, but no files are on it

Yes, it does count system as well.
If you need space just temporary, you can upload your files into root folder, not into "flash". Root folder is actually ramdisk, so it has much more space. However, it gets empty with each restart.
by vecernik87
Fri Oct 19, 2018 8:44 am
Forum: Beginner Basics
Topic: simple switch and WiFi AP (no dhcp, no nat)
Replies: 5
Views: 228

Re: simple switch and WiFi AP (no dhcp, no nat)

There is no defconf for this purpose. Easiest is to do /system reset-configuration no-defaults=yes WARNING! after this command, your router will restart, disable wifi and lose any IP and password will be blank again. You will need to connect via MAC (either from another mikrotik or with winbox) Then...
by vecernik87
Fri Oct 19, 2018 1:54 am
Forum: Announcements
Topic: v6.43.4 [stable] is released!
Replies: 17
Views: 1998

Re: v6.43.4 [stable] is released!

When updating from 6.43.2 to 6.43.4 one of my hAP ac2 logged this message (similar to message in this post after update to 6.43.4): oct/19 00:10:46 script,warning DefConf gen: Unable to find wireless interface(s) However all the configuration seems to be intact and this message is NOT logged on sub...
by vecernik87
Fri Oct 19, 2018 12:11 am
Forum: Beginner Basics
Topic: hAP ac² decreases Ethernet speed
Replies: 1
Views: 85

Re: hAP ac² decreases Ethernet speed

My first guess would be cable. If it is not cable, then second and third guess would be cable again. (or maybe connector) :D Cable can easily cause issues, especially when it is too long or damaged or near source of interference. Now, seriously: 95Mbps sounds exactly like your L1 stuck in 100Mbps ra...
by vecernik87
Thu Oct 18, 2018 12:17 am
Forum: General
Topic: Mesh tab in Winbox
Replies: 1
Views: 175

Re: Mesh tab in Winbox

I never opened mesh instead of IP. But every single time (sometime even twice in a row) I open IP instead of IPv6. :lol:
by vecernik87
Wed Oct 17, 2018 11:59 pm
Forum: General
Topic: Is it a bug?About eoip in bridge use the same mac address?
Replies: 2
Views: 147

Re: Is it a bug?About eoip in bridge use the same mac address?

using VLAN interface in bridges may be dangerous: https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration. Especially if you include EOIP you can very easily end up with loops. From your description it is not really clear if you really have same MAC and what interfaces have same MAC. You can p...
by vecernik87
Wed Oct 17, 2018 11:34 pm
Forum: General
Topic: [ASK] default configuration
Replies: 7
Views: 250

Re: [ASK] default configuration

@nichky Best would be to check your detailed logs from both server and client. There will be your "unknown" reason written. It is highly possible that you don't have enabled such logging, so you will need to add logging actions for topics "ipsec" and "l2tp" (one action for each topic) and once your ...
by vecernik87
Wed Oct 17, 2018 9:49 am
Forum: General
Topic: ROS 6.43.2 export config BUG
Replies: 3
Views: 147

Re: ROS 6.43.2 export config BUG

Not a bug: https://forum.mikrotik.com/viewtopic.php?f=21&t=139353&p=688546&hilit=speed%3D100Mbps#p688693 tl;dr: setting is not used if auto-negotiation is enabled . Before 6.43, default value was 100Mbps. Since 6.43 default value is 1Gbps. Export shows only difference between config and default valu...
by vecernik87
Wed Oct 17, 2018 9:17 am
Forum: General
Topic: [ASK] default configuration
Replies: 7
Views: 250

Re: [ASK] default configuration

That yellow marked text will limit your SRC-NAT to match (and translate) only non-IPsec outgoing traffic. There is no reason to do SRC-NAT on IPsec processed packets as they will likely have IP of the router itself.
by vecernik87
Wed Oct 17, 2018 9:05 am
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 1279

Re: Wireless router in every hotel room

@axe50397: I must apologize for my previous statement about heat... I realized that my GrooveA 52 has temperature sensor on PCB so I can relatively easy test these conditions.. After all it seems that my fear of overheating was too big and you should have no issues: 2018-10-17_1641.png 10:40 monitor...
by vecernik87
Wed Oct 17, 2018 3:39 am
Forum: Wireless Networking
Topic: Best Antenna for Groove to be Used as WiFi Booster
Replies: 2
Views: 93

Re: Best Antenna for Groove to be Used as WiFi Booster

Antenna gain directly depends on beamwidth. As the boat rotate (yaw,pitch,roll) your antenna must have enough beamwidth to cover all possible angles, otherwise it will drop your connection. You correctly decided that you need omnidirectional antenna because boat moves around anchor. (i.e. yaw is 0-3...
by vecernik87
Tue Oct 16, 2018 11:54 pm
Forum: Announcements
Topic: Winbox v3.18 released!
Replies: 25
Views: 3483

Re: Winbox v3.18 released!

Me too. No issues at all:
2018-10-17_0748.png
Winbox 3.18 and RouterOS 6.40.2

If you can't connect, it might be infected device... these old versions are vulnerable so unless you have properly blocked access to its winbox/http services, anyone can gain access..
by vecernik87
Tue Oct 16, 2018 11:35 pm
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 1279

Re: Wireless router in every hotel room

Not sure what is the connection with AP's in hotel room :lol: I guess (based on title of your post) you managed to submit your reply to incorrect thread. anyway, you are not first: https://forum.mikrotik.com/viewtopic.php?t=66469 There are more people who achieved more than 100% CCQ, but only this h...
by vecernik87
Tue Oct 16, 2018 2:21 am
Forum: RouterBOARD hardware
Topic: New "RB2011".... reloaded [SOLVED]
Replies: 11
Views: 522

Re: New "RB2011".... reloaded [SOLVED]

Do you really need router with 10 ports and wifi? Wouldn't it be easier to have stuff nicely separated? i.e. have router for routing, switch for switching, AP for wifi? For example - router will be probably hidden somewhere. It will never be positioned properly to utilize wifi coverage as much as po...
by vecernik87
Tue Oct 16, 2018 12:58 am
Forum: Scripting
Topic: Script to block Child Pornography URL through file.txt
Replies: 1
Views: 238

Re: Script to block Child Pornography URL through file.txt

If i understand it correctly, your government willingly distribute list of child porn websites? :lol: thats really twisted... Anyway, there is not much help unless there are specifications how is it supposed to be done. Typical and easiest way is to simply block DNS (or redirect DNS requests to some...
by vecernik87
Sat Oct 13, 2018 9:21 am
Forum: General
Topic: Jailbreak for RouterOS 6.43.2 released [SOLVED]
Replies: 16
Views: 1138

Re: Jailbreak for RouterOS 6.43.2 released [SOLVED]

I think silently allowing jailbreak is the best solution. People who do that will be clearly aware they are doing some non-standard stuff which may or may not work. On the other hand, if we ask mikrotik to support "root", they would have to spend significant amount of resources to make it fool-proof...
by vecernik87
Fri Oct 12, 2018 9:04 am
Forum: General
Topic: Severe Performance Drop RB3011
Replies: 32
Views: 855

Re: Severe Performance Drop RB3011

what kind of speed test is it? If it is TCP based, how many paralel streams/connections? If only one, it might be the issue as such test is strongly affected by latency. Adding mangle rule is going to introduce slight delay as the packet must be processed in another block of code. Just to make sure ...
by vecernik87
Fri Oct 12, 2018 7:41 am
Forum: General
Topic: Jailbreak for RouterOS 6.43.2 released [SOLVED]
Replies: 16
Views: 1138

Re: Jailbreak for RouterOS 6.43.2 released [SOLVED]

plenty of devices now have USB. It requires: - USB - admin access (username+password) so it is not really "vulnerability", just jailbreak (you own the device, you should be able to do whatever you want with it without limitations) You can't misuse it if you don't have admin access. (gonna try it onc...
by vecernik87
Fri Oct 12, 2018 6:00 am
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 1279

Re: Wireless router in every hotel room

I think you got almost everything sorted :) Just one note I forgot to mention earlier: There are many PoE standards (or proprietary solutions) and the difference is not just voltage (very common misconception). If you look for PoE phone and you want to daisy-chain it behind AP, it needs to be compat...
by vecernik87
Fri Oct 12, 2018 5:42 am
Forum: General
Topic: Which chains do SrcNAT and DstNAT go through?
Replies: 7
Views: 277

Re: Which chains do SrcNAT and DstNAT go through?

Almost correct. Only exception is IP-encapsulated data, which might be forwarded but due to the fact that encapsulation/decapsulation is done by router, encapsulated packet is actually generated/received by router and therefore encapsulated packet must go through input/output chain as well. This is ...
by vecernik87
Fri Oct 12, 2018 3:28 am
Forum: Forwarding Protocols
Topic: RB4011 vs. CCR1009 BGP
Replies: 42
Views: 1931

Re: RB4011 vs. CCR1009 BGP

Is it even possible to do table updates in paralel mode without causing some other issues? Why would EVERY manufacturer end up with single-threaded BGP? I saw couple of research papers with experimental implementations of multithreaded BGP, but I am unaware of real implementation by any manufacturer...
by vecernik87
Thu Oct 11, 2018 11:59 pm
Forum: General
Topic: Which chains do SrcNAT and DstNAT go through?
Replies: 7
Views: 277

Re: Which chains do SrcNAT and DstNAT go through?

I am aware of the fact that postrouting happens after both forward and output chains. But in this case, OP was asking specifically, which chain does his example go through, so I tried to stress out that his examples are not going through input/output chain. Apparently, I should express myself better...
by vecernik87
Thu Oct 11, 2018 12:20 pm
Forum: General
Topic: [Feature Request] Winbox username is sent in plain text
Replies: 10
Views: 512

Re: [Feature Request] Winbox username is sent in plain text

Thanks Emils for quick response in both ticket reply and here. I really appreciate it. I will not pretend that I understand how that protocol works. I can only believe it really is secure against MITM. However, it feels like being against recommended way to secure the router: https://wiki.mikrotik.c...
by vecernik87
Thu Oct 11, 2018 9:54 am
Forum: General
Topic: [Feature Request] Winbox username is sent in plain text
Replies: 10
Views: 512

Re: [Feature Request] Winbox username is sent in plain text

@normis: thanks for quick reaction. I sent the email with pcap file and description. (And of course I accidentally made a typo in one sentence, where I wrote "plaintext password" instead of "plaintext username". I replied with another email explaining the mistake, please don't laugh too hard :( its ...
by vecernik87
Thu Oct 11, 2018 8:59 am
Forum: General
Topic: Which chains do SrcNAT and DstNAT go through?
Replies: 7
Views: 277

Re: Which chains do SrcNAT and DstNAT go through?

Thanks for info! I didnt know as there is "Changes in RouterOS v6" section, I somehow thought is up to date. (and I obviously totally missed note that there is new diagram.. all those years :D )
Fortunately, answer is correct even according to new diagram :)
by vecernik87
Thu Oct 11, 2018 8:30 am
Forum: General
Topic: Which chains do SrcNAT and DstNAT go through?
Replies: 7
Views: 277

Re: Which chains do SrcNAT and DstNAT go through?

https://wiki.mikrotik.com/wiki/Manual:Packet_Flow DST-NAT happens in PREROUTING chain which is matched by anything what comes into router. after DST-NAT happens and whole PREROUTING chain ends, it goes to "routing decision" which decide if it is INPUT or FORWARD. As the DST-IP does not match any of ...
by vecernik87
Thu Oct 11, 2018 5:16 am
Forum: General
Topic: [Feature Request] Winbox username is sent in plain text
Replies: 10
Views: 512

Re: [Feature Request] Winbox username is sent in plain text

Confirming with Winbox 3.18 and RoS 6.43.2 and 6.42.7 (I assume all versions are same)

Not sure if there is some interest in fixing it. Recent change of API caused both username AND PASSWORD to be plaintext which is obvious step backwards (or strong signal to use API-SSL instead of normal API)
by vecernik87
Thu Oct 11, 2018 4:18 am
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 1279

Re: Wireless router in every hotel room

Not exactly true. TX power expressed as 0dBm means TX power of 1mW. Yup, you are absolutely right, sorry for that misinformation. Not sure what I was thinking when I wrote it. Maybe I tried to simplify it too much. I was more thinking about the same SSID .... Unfortunately, we have this kind of use...
by vecernik87
Wed Oct 10, 2018 1:45 pm
Forum: Beginner Basics
Topic: No internet connection on my switch
Replies: 9
Views: 281

Re: No internet connection on my switch

As I can see you masked your IP now, I will not share it but that also means other people will be unable to come up with some idea if they can't test it. Fact is that previously specified IP is reachable. Even now. If you are sure your device is disconnected (or at least it was disconnected when I o...
by vecernik87
Wed Oct 10, 2018 11:44 am
Forum: Beginner Basics
Topic: No internet connection on my switch
Replies: 9
Views: 281

Re: No internet connection on my switch

I dont see any mistake - it should work.. In addition, your IP is real-world-routable and when I try to ping it, it responds. I can even see open winbox port which is not good at all! You have no firewall rules and such device should not be connected to any untrusted network, especially when your ad...
by vecernik87
Wed Oct 10, 2018 6:38 am
Forum: Announcements
Topic: Security announcement blog
Replies: 110
Views: 14776

Re: Security announcement blog

Thats why I asked Maznu to give bit clearer description. I may not be a blind fanboy but I still believe you guys are doing your best and I find it hard to believe you would leave real reported vulnerability without reaction. If it is just flood attack which overwhelms router and cause restart due t...
by vecernik87
Wed Oct 10, 2018 6:27 am
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 1279

Re: Wireless router in every hotel room

Bit of experience: I have seen similar setup in The Sebel (Melbourne Docklands) - each room having own AP with SSID named according to room number. I can definitely recommend such decision as it delivered absolutely best wireless performance I have ever seen in hospitality business: https://www.spee...
by vecernik87
Wed Oct 10, 2018 12:21 am
Forum: Beginner Basics
Topic: no "home AP" mode in SXT Lite 2
Replies: 16
Views: 467

Re: no "home AP" mode in SXT Lite 2

Can you please share info about shop, where you got your device? Seems to me you were lured into purchase with incorrect info/specification promoted by your seller. If mikrotik say only "License level 3", it might be confusing for new customers. I fully agree with that. However, official product pag...
by vecernik87
Tue Oct 09, 2018 3:01 am
Forum: General
Topic: queue problem
Replies: 16
Views: 678

Re: queue problem

Excelent point! That was it!
I didnt really think this way - I expected that when packet-mark is unset, it will simply cover all packets (both marked and unmarked)
Really big thanks. With this knowledge, OP should have no issues to set up queues correctly.
by vecernik87
Tue Oct 09, 2018 2:28 am
Forum: General
Topic: queue problem
Replies: 16
Views: 678

Re: queue problem

@mducharme: are you sure it will work on interface which is bridged? I tried to set it up and it does not seem to be working (queues are enabled but counters do not increase and limiting does not occur): /interface bridge add fast-forward=no name=bridge-jac /interface bridge port add bridge=bridge-j...
by vecernik87
Mon Oct 08, 2018 11:08 am
Forum: Announcements
Topic: Security announcement blog
Replies: 110
Views: 14776

Re: Security announcement blog

...Meanwhile, I'm still waiting for MikroTik to confirm when Ticket#2018041622003823 (unauthenticated remote crash, does not require any management interface to be open to the attacker) will be fixed. I have no idea what vulnerability is it about and to be honest, I don't want to know. However, if ...
by vecernik87
Mon Oct 08, 2018 1:55 am
Forum: General
Topic: queue problem
Replies: 16
Views: 678

Re: queue problem

That sounds like fasttrack enabled :) Fasttracked connections are "fast" because they skip firewall, queues, etc... There are still some packets going through the slow way, but it is just small percentage. Due to that, you can't see whole "forward" traffic in your queue. Try to disable firewall rul...
by vecernik87
Fri Oct 05, 2018 2:49 pm
Forum: General
Topic: NAT 2 LANs over 2 WANs w/o breaking internal routing
Replies: 8
Views: 287

Re: NAT 2 LANs over 2 WANs w/o breaking internal routing

I bet it would work if you exclude LAN range from dst-address in these mangle rules so internal communication does not get marked lan1/lan2
by vecernik87
Fri Oct 05, 2018 2:44 pm
Forum: General
Topic: queue problem
Replies: 16
Views: 678

Re: queue problem

I am unsure but... what if you enable "use-ip-firewall" for those bridges? Thing is, that Simple queue is applied in input/postrouting, which is L3 (see packet flow diagram ). However, when you bridge two interfaces, it will be pure L2 connection. I haven't try that but maybe, maybe... it will work?...
by vecernik87
Fri Oct 05, 2018 5:20 am
Forum: RouterBOARD hardware
Topic: We plan to make 802.3af compatible devices in the future (2015)
Replies: 1
Views: 267

Re: We plan to make 802.3af compatible devices in the future (2015)

It is not really vendor lock as the same passive POE is used by UBNT and few others. In addition, it is well described and you can practically make DIY injectors with couple of connectors and wires. This simplicity has some advantages. Despite saying that, I would also prefer universal support of 80...
by vecernik87
Fri Oct 05, 2018 3:39 am
Forum: Beginner Basics
Topic: hAP ac2 no files, but almost no free space available
Replies: 5
Views: 381

Re: hAP ac2 no files, but almost no free space available

Unfortunately, all these models with 16MB storage end up like this. Just system package alone takes 7.5MB of space, then you have all additional packages like wireless (2MB!), advanced tools, dhcp, routing, security etc etc... In order to get more storage, I usually replace default bundled package w...
by vecernik87
Thu Oct 04, 2018 6:15 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 940
Views: 153476

Re: Feature requests

@Wyz4k No. I should apologize. I didn't realize it will sound so aggressive. This is certainly about "feature requests". Sometime, requests are great. Sometime not - people submit them due to misunderstanding or lack of information. I just tried to correct some of your statements and I didn't mean t...
by vecernik87
Thu Oct 04, 2018 5:51 am
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 84
Views: 9246

Re: v6.42.9 [long-term] is released!

@mblfone: You should create separate topic about your routing/switching as it is unrelated to this RouterOS release. Anyway shortly said - CCR1016-12G is router, not switch. It does not have switch chip so you cant see "switch" button and it can't be listed among other switches on "switch chip featu...
by vecernik87
Thu Oct 04, 2018 3:57 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 940
Views: 153476

Re: Feature requests

1) unsecured graphing which can't be queried using a script anyway If IP whitelist is not enough, you can limit it to VPN via firewall. 2) have to run a 3rd party snmp server because there is no snmp server from Mikrotik Mikrotik has "The Dude" which works well enough as SNMP server. It is not mast...
by vecernik87
Wed Oct 03, 2018 1:23 am
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 522

Re: hardware acceleration on only one bridge?

@czfan: Based on provided description I expected that HEX is supposed to work only as L2 switch which will do the trunk-edge conversion. If he ended up with 4 vlans on Eth1, 4 Eth ports and 4 bridges (each bridge with one vlan and one port), then to me, it clearly signalizes that he wants to separat...
by vecernik87
Wed Oct 03, 2018 12:18 am
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 522

Re: hardware acceleration on only one bridge?

I might be completely wrong, but it seems to me that you are trying to achieve typical trunk-edge scenario with VLANs. (port 1 as trunk with all VLANs tagged and ports 2,3,4 and 5 as edge, each having single specific untagged VLAN) . If that is true, then you can be achieve your setting directly in ...
by vecernik87
Mon Oct 01, 2018 9:51 pm
Forum: Scripting
Topic: Upcoming Highend CCR Router model
Replies: 3
Views: 419

Re: Upcoming Highend CCR Router model

You should specify if you need Layer 2 or Layer 3 switch. (mikrotik makes only L2 switches) Usually, term "switch" is understood as L2 switch. On the other hand, unless you really need L2 features, it is more common to have L3 backbone network. Otherwise broadcasts might turn it into hell for you. S...
by vecernik87
Sun Sep 16, 2018 10:28 am
Forum: RouterBOARD hardware
Topic: Router brains turn to mush after upgrading to 6.43
Replies: 2
Views: 420

Re: Router brains turn to mush after upgrading to 6.43

Did you try to boot itt up using backup bootloader?

https://wiki.mikrotik.com/wiki/Manual:R ... up_loaders
it is also possible to use the backup booter by turning on the device, with the RESET button pushed
by vecernik87
Thu Sep 13, 2018 3:54 am
Forum: RouterOS v6 RC and v7 BETA
Topic: [Feature Request] sFlow
Replies: 11
Views: 1318

Re: [Feature Request] sFlow

sFlow requires HW support (switchchip / dedicated ASIC). They clearly state it in their overview. It can't be simply added with software update.