Community discussions

MikroTik App

Search found 48 matches

by mt99
Tue Apr 16, 2024 10:41 pm
Forum: General
Topic: 17.4.1 APPLE iOS cannot be static in DHCP
Replies: 24
Views: 1434

Re: 7.14.1 APPLE iOS cannot be static in DHCP

Well, I can share what I do with the iDevices on my network. If I care about assigning an IP, I just give it a DHCP reservation with a client ID. That way I don't have to bother with turning off the private IP address feature. It's been a while since I set it up, but if you go into configure IP on t...
by mt99
Sun Feb 18, 2024 8:56 pm
Forum: General
Topic: What's the point of 7.12.2?
Replies: 1
Views: 292

What's the point of 7.12.2?

Other than it being a "factory only release", and that it was released at the same time as 7.13.3, I can't find any other information about it anywhere. What's it for? Does it backport fixes from the 7.13.x branch?
by mt99
Mon Feb 05, 2024 5:43 pm
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 266058

Re: v7.13.3 [stable] is released!

I don't see much evidence that Mikrotik is taking this storage space issue seriously. But they have to do something for devices that can't run v6 and are still being sold, because they have guaranteed a minimum of 5 years support. Whether they break out monolithic packages, come up with a "lite...
by mt99
Mon Feb 05, 2024 4:46 am
Forum: Scripting
Topic: Syntax difference in versions, how to handle? [SOLVED]
Replies: 12
Views: 2020

Re: Syntax difference in versions, how to handle? [SOLVED]

:if ([/system package get 0 version] ~ "^6") do={:execute "/export terse" as-string} else={:execute "/export terse show-sensitive" as-string} Syntax will not be checked in string for execute, it will only break execute if is wrong syntax in it. This use of :execute for...
by mt99
Wed Jan 10, 2024 1:53 am
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 266058

Re: v7.13.1 [stable] is released!

Please tell me that US-locked WAPs don't default to "Latvia"! Totally agree with others that these kind of functionality updates are what the beta is for, but I guess regulatory changes don't need testing.
by mt99
Sun Sep 17, 2023 8:41 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 82
Views: 12912

Re: Mikrotik SUCKS

I understand the frustration, especially when you're in a work setting where you need to get something functioning under a deadline. Sometimes we all need to vent a little bit. But seriously, it might be worth it to hire a consultant. Not to do everything, but to help fill in some of the specific it...
by mt99
Fri Jul 28, 2023 12:44 am
Forum: Announcements
Topic: WinBox v3.39 released!
Replies: 96
Views: 59985

Re: WinBox v3.39 released!

Mikrotik should publish the hash of their firmwares and winbox software Totally agree that MT should publish the Winbox hash in their checksums list like their NPKs. In the meantime, I'm used to validating the digital signature. But I recently moved to running Winbox in Wine and I wasn't able to fi...
by mt99
Wed Jul 19, 2023 1:31 am
Forum: Containers
Topic: Whitelisting web destinations from container
Replies: 3
Views: 3131

Re: Whitelisting web destinations from container

Hi, thanks for responding. I just prefer to provision resources in accordance with least privilege. I know the Pihole only requires Internet access to the adlist servers to get its updates, so that's what I give it. But I expected my first question would be "Do you need to run Pihole and NextDN...
by mt99
Wed Jul 19, 2023 12:27 am
Forum: Containers
Topic: Whitelisting web destinations from container
Replies: 3
Views: 3131

Whitelisting web destinations from container

Greetings all - I have a couple existing Docker containers that I want to migrate to RouterOS. I have a Pihole container that handles DNS for internal clients, and then an Alpine container I built that runs the NextDNS client (since unfortunately they don't support RouterOS natively) for DoH. The Pi...
by mt99
Tue Jun 20, 2023 7:29 pm
Forum: General
Topic: Netinstall R7 - how to keep R6-based config?
Replies: 10
Views: 792

Re: Netinstall R7 - how to keep R6-based config?

Hence my suggestion to proceed as I described in my previous post. It gives device admin chance to clean up the config on the way :idea: Thanks for your thoughtful reply. Ugh, I was hoping to avoid rebuilding from scratch but you're probably right :) I wonder what your thoughts are for importing in...
by mt99
Mon Jun 19, 2023 1:16 am
Forum: General
Topic: Netinstall R7 - how to keep R6-based config?
Replies: 10
Views: 792

Re: Netinstall R7 - how to keep R6-based config?

If device, being worked on, is properly working under v6, then I wonder what good would netinstall do (compared to "normal" ROS upgrade via "upgrade" channel) That's a fair question. These devices are kind of old (back from when RouterBOOTs had changelogs :D ) and have been upgr...
by mt99
Sun Jun 18, 2023 4:13 am
Forum: General
Topic: Netinstall R7 - how to keep R6-based config?
Replies: 10
Views: 792

Re: Netinstall R7 - how to keep R6-based config?

Yes, something like that :lol: I guess what I'm wondering is whether people have had bad experiences with importing an R6 config onto R7. Is that the recommended way to go, or is it just asking for trouble? I'm just trying to avoid a situation where the import doesn't complete and now you have a dev...
by mt99
Sun Jun 18, 2023 12:18 am
Forum: General
Topic: Netinstall R7 - how to keep R6-based config?
Replies: 10
Views: 792

Netinstall R7 - how to keep R6-based config?

Greetings all. I previously migrated one router from R6 to R7 with Netinstall instead of upgrading it. I wanted to do it that way to make the migration as clean as possible, and I didn't care about the previous config. I have other routers to migrate and I'd like to keep using Netinstall, but I want...
by mt99
Thu Apr 20, 2023 7:49 pm
Forum: General
Topic: Any way to execute commands on a container from the host?
Replies: 2
Views: 634

Any way to execute commands on a container from the host?

Hi folks, I installed 7.8 on my RB3011 and got pihole up and running on it. I want to kick off a script in the container when it boots up. Is there a way to trigger this from the router? Basically I'm looking for an equivalent to "docker exec pihole bash -c 'mycoolscript.sh'"
by mt99
Sun Sep 18, 2022 7:19 am
Forum: General
Topic: send_pubkey_test: no mutual signature algorithm [SOLVED]
Replies: 17
Views: 13198

Re: send_pubkey_test: no mutual signature algorithm [SOLVED]

In my case, a new Ubuntu 22.04 server I migrated to wouldn't use the identity file even though I was using the proper syntax. The -vv switch argument on the SSH command showed that the signature algorithm wasn't being accepted. Create a new file in /etc/ssh/ssh_config.d, call it anything .conf, and ...
by mt99
Wed Jul 20, 2022 7:49 pm
Forum: General
Topic: Does anyone need 35 RB 3011s?
Replies: 1
Views: 313

Does anyone need 35 RB 3011s?

If you're in or can get to NE Illinois, maybe you might be interested in this - https://www.govdeals.com/index.cfm?fa=Main.Item&itemid=42&acctid=17271 I swear I'm not involved in this in any way, just saw it out there. Personally I think they're asking too high, but I know supplies are tight...
by mt99
Mon Jan 10, 2022 1:09 am
Forum: Announcements
Topic: v6.48.6 [long-term] is released!
Replies: 126
Views: 275496

Re: v6.48.6 [long-term] is released!

When will RouterOS v6 reach end of life?
I would say, unless we see a new testing branch for v6, that v6 feature development is winding down. But hopefully Mikrotik will make some kind of statement about that so their customers can plan accordingly.
by mt99
Tue May 25, 2021 6:22 am
Forum: Beginner Basics
Topic: RB750gr3 vs RB760IGS?
Replies: 4
Views: 7906

Re: RB750gr3 vs RB760IGS?

The estimates in the video seem rather arbitrary to me. The fact that the test results for both devices are the same tells you everything you need to know - they are comparable from a performance perspective. But the fact that the RB760IGS has the SFP port, as well as POE out, is a distinctive diffe...
by mt99
Fri Feb 05, 2021 5:11 am
Forum: General
Topic: When you're so desperate for high-speed Internet...
Replies: 1
Views: 692

When you're so desperate for high-speed Internet...

...that you run your own fiber and start your own ISP: https://arstechnica.com/information-technology/2021/01/jared-mauch-didnt-have-good-broadband-so-he-built-his-own-fiber-isp/ Guy likes his cheap, Mikrotik CPE though: "At customer homes, Mauch installs a Mikrotik RBFTC11 media converter with...
by mt99
Tue Sep 15, 2020 6:03 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 131
Views: 62517

Re: RB3011 port flopping - bad design

So I wonder if anyone happened to see this in the 6.46.7 (long term) changelog:

*) switch - correctly enable and disable CPU Flow Control on RB3011UiAS;

Apologies if this isn't news, as I typically only pay attention to long term. I also don't want to get anyone's hopes up :)
by mt99
Wed Jan 22, 2020 9:07 pm
Forum: General
Topic: My public IP is getting raped by port scanners - is that normal?
Replies: 24
Views: 6187

Re: My public IP is getting raped by port scanners - is that normal?

I didn't read this thread closely and there's already been some good suggestions - but is your external IP on Shodan? You don't need a logon or API key to check for one IP on their site. https://www.shodan.io/search?query= and type in your external IP at the end of the link. Once I saw activity from...
by mt99
Mon Jan 06, 2020 7:02 am
Forum: RouterBOARD hardware
Topic: How Does the CRS328-24P-4S+RM Perform as a Router?
Replies: 8
Views: 6101

Re: How Does the CRS328-24P-4S+RM Perform as a Router?

I'm not familiar with these devices, but I took a look at the CRS125. It's got a lot going for it, but whether it's the best choice depends on the capabilities you need now or anticipate needing soon. Take a look at https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches to see how it stack...
by mt99
Sun Jan 05, 2020 4:14 am
Forum: RouterBOARD hardware
Topic: How Does the CRS328-24P-4S+RM Perform as a Router?
Replies: 8
Views: 6101

Re: How Does the CRS328-24P-4S+RM Perform as a Router?

First of all, good job in asking these questions before making the purchase. There's so many posts where someone bought a CRS, thinking or hoping that it could be their all in one solution, only to be schooled the hard way. I would never call myself a expert in Mikrotik gear, but I don't think any C...
by mt99
Tue Sep 24, 2019 7:50 pm
Forum: RouterOS beta
Topic: Torrent client
Replies: 59
Views: 36566

Re: Torrent client

So there has to be years worth of "please enable feature X in v7" threads, why not investigate and prioritize those? If you don't know the use cases already, you have a solution in search of a problem. As for what to do with the torrent client, perhaps it's too simplistic but from a securi...
by mt99
Mon May 27, 2019 7:11 pm
Forum: General
Topic: save my router backups on a usb stick
Replies: 3
Views: 3824

Re: save my router backups on a usb stick

Assuming you connected the USB, it's formatted, and shows up as disk1 in System -> Disks:
/system backup save name=disk1/yourbackup.backup
by mt99
Sat Apr 27, 2019 3:05 am
Forum: General
Topic: DNS Failover
Replies: 24
Views: 18341

Re: DNS Failover

Everything starting with my_* should be customized for your environment. I use the router as the DNS server so I can still have control and a central place to redirect via NAT rule. For this to work best, I also recommend setting the router as a second DNS server address on all clients. This works f...
by mt99
Mon Apr 22, 2019 2:54 am
Forum: General
Topic: DNS Failover
Replies: 24
Views: 18341

Re: DNS Failover

This is exactly correct, all DNS servers are equal to the client so setting a “secondary” DNS server doesn’t work the way you might think. I use a Pihole which runs on a 2010 Mac Mini, and even though I dropped in a new hard drive I had concerns about redundancy. So I use scripts with netwatch to se...
by mt99
Sat Feb 23, 2019 3:55 am
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 52758

Re: Security issue when Winbox exposed

I think it's great that Zerodium started a bug bounty program for Mikrotik. It's not like the bad guys don't know, they're just providing incentives for full disclosure. So patch early and patch often my friends! Unfortunately that isn't how it works. Zerodium will pay for Mikrotik exploits and the...
by mt99
Fri Feb 22, 2019 5:38 am
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 52758

Re: Security issue when Winbox exposed

Agree. Changelog should reflect the fact that this is a security fix rather claiming it's some sort of "improvement" pe1chl called this in post #2 of the 6.43.12 thread so nice catch by him. It's a shame but people who want to get a heads up on recently disclosed RouterOS vulnerabilities ...
by mt99
Mon Sep 17, 2018 11:01 pm
Forum: General
Topic: Stopping connections to TCP port 1720
Replies: 6
Views: 3411

Re: Stopping connections to TCP port 1720

R1CH, I think you're exactly right. I own my own cable modem, and I just unplugged it from the router and was still able to access TCP port 1720 externally. I feel stupid/relieved. Thanks.
by mt99
Mon Sep 17, 2018 2:56 pm
Forum: General
Topic: Stopping connections to TCP port 1720
Replies: 6
Views: 3411

Re: Stopping connections to TCP port 1720

No, luckily socks is still disabled and no UPnP either. I don't have any reason to believe that the router is compromised, everything looks the way I set it. But I'm concerned that there's no way to stop a compromise if someone can figure out a way to exploit that open port. I can't close it, or dro...
by mt99
Mon Sep 17, 2018 12:59 am
Forum: General
Topic: Stopping connections to TCP port 1720
Replies: 6
Views: 3411

Stopping connections to TCP port 1720

I decided to nmap my external IP today to see how my firewall is doing. I was surprised to see that TCP 1720 is wide open to the Internet, and I was confirmed being able to telnet to the port and stay connected as long as I want. I have firewall rules that specifically drop new inbound connections f...
by mt99
Thu Jun 21, 2018 7:14 am
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 39635

Re: v6.42.4 [current]

I upgraded an RB750GL, a 3011, a CRS226, and a RB951G-2HnD from 6.41.4 to 6.42.4 with no issues. However, after the upgrade I noticed that the two routers with DNS servers (one for internal, one for my guest network) were no longer resolving. This wasn't an issue before the upgrade. I did see them ...
by mt99
Wed Jun 20, 2018 2:17 am
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 39635

Re: v6.42.4 [current]

I upgraded an RB750GL, a 3011, a CRS226, and a RB951G-2HnD from 6.41.4 to 6.42.4 with no issues. However, after the upgrade I noticed that the two routers with DNS servers (one for internal, one for my guest network) were no longer resolving. This wasn't an issue before the upgrade. I did see them r...
by mt99
Tue May 15, 2018 2:07 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 99364

Re: v6.42.1 [current]

Ive been testing 43RC11.. It addressed a huge number of issues posted in this thread. Good job Mikrotik. It does not address the short sighted feature neutering of Netwatch tho. I still cannot send a alert or change a LED state based on a ping of a target. Because I use Netwatch for many things, I ...
by mt99
Wed Apr 25, 2018 3:24 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 99364

Re: v6.42.1 [current]

Just updated one of our Metal G-52SHPacn to new v6.42.1 RouterOS. tools/netwatch does not work anymore. When the tested server is "up", we run [:global srvstat "up"] to set the variable srvstat. Did work with 6.41.2 Looks like up event is not working. Version 6.42 has this chang...
by mt99
Mon Mar 26, 2018 5:28 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 537
Views: 190884

Re: v6.42rc [release candidate] is released!

nice of the info, could I use the nas synology or qnap to save or view the logs?
Synology NAS can do it if you install the Log Center package and configure it as the syslog destination for your Mikrotik. QNAP probably does something similar.
by mt99
Wed Mar 14, 2018 9:56 pm
Forum: Announcements
Topic: Winbox 3.12 released!
Replies: 55
Views: 72050

Re: Winbox 3.12 released!

In the Checksums link on the Downloads page, I notice that there's no MD5 or SHA256 hash listed for winbox.exe. Can this please be added for Winbox 3.12, and future releases moving forward? If it's kept somewhere else, could somebody point out where? Many thanks....
by mt99
Tue Mar 13, 2018 3:41 am
Forum: General
Topic: Slingshot APT [SOLVED]
Replies: 44
Views: 42219

Re: Slingshot APT, RouterOS spying software NOT [SOLVED]

I manage all sorts of systems and I get notified about all of the vulnerabilities for Windows, Windows Software, Linux, Apple, Android, and many others. I subscribe to many different security sites and I am used to detailed explanations of reasons to patch systems so I can determine whether or not ...
by mt99
Sat Feb 17, 2018 5:46 am
Forum: Beginner Basics
Topic: What hardware to use at home
Replies: 6
Views: 2007

Re: What hardware to use at home

Emulation is the best idea when you want to learn, but I'm assuming you want to buy the hardware. I don't look at network gear as an investment, or put all my eggs in one basket. I scale out, not up, and buy smaller boxes that are meant for the tasks I have at hand. Let switches be switches and let ...
by mt99
Sat Jan 13, 2018 8:59 pm
Forum: Announcements
Topic: Securing your device is important
Replies: 50
Views: 42854

Re: Securing your device is important

mt99, do you really expect that every owner of every MikroTik device would follow such a lengthy advise? No, that's why you script it. I would never hand edit all that stuff, plus scripting eliminates the possibility of mistakes. I have a deployment script that I run on every router that has baseli...
by mt99
Sat Jan 13, 2018 7:38 am
Forum: Announcements
Topic: Securing your device is important
Replies: 50
Views: 42854

Re: Securing your device is important

I agree that Mikrotik should move toward unique default passwords, which many other manufacturers have done (usually some component of the MAC address). But at least so far, it seems like these defacements have been happening in instances where the router's administrative services were available fro...
by mt99
Mon Jan 08, 2018 1:24 am
Forum: Beginner Basics
Topic: 6.41: When Netinstall just doesn't cut it
Replies: 8
Views: 2245

Re: 6.41: When Netinstall just doesn't cut it

Yes, exact same device. I only have one RB750GL, and that's the only device I was working on at the time. I know you can't mix backups between devices, even if they are the same model. But I'm glad I got the box back up. It's a decent little performer and the 64 MB of NAND lets me have 3 partitions.
by mt99
Fri Jan 05, 2018 9:50 pm
Forum: Beginner Basics
Topic: 6.41: When Netinstall just doesn't cut it
Replies: 8
Views: 2245

Re: 6.41: When Netinstall just doesn't cut it

I'm just reporting what I personally experienced. I specifically posted this in the beginner forum with an acknowledgement that I might have done something wrong. If Netinstall can be reliably used to do all those things, I'm glad for such a useful tool and I look forward to seeing better documentat...
by mt99
Fri Jan 05, 2018 4:47 am
Forum: Beginner Basics
Topic: 6.41: When Netinstall just doesn't cut it
Replies: 8
Views: 2245

Re: 6.41: When Netinstall just doesn't cut it

That's a good point, I know that ether1 works because you have to use it for Netinstall. But I hadn't thought about explicitly testing the rest of the ports since I was seeing link lights. So I went ahead and tried MAC Winbox on all of them and verified they are working. I got the box back in shape ...
by mt99
Wed Jan 03, 2018 10:42 pm
Forum: Beginner Basics
Topic: 6.41: When Netinstall just doesn't cut it
Replies: 8
Views: 2245

Re: 6.41: When Netinstall just doesn't cut it

Thanks for asking - I did do System > Reset Configuration as well, and even used the reset button to do the same thing. I always thought that Netinstall could reinstall the OS and apply the default config, but in this case it doesn't seem to do that. I'm hoping I just did something wrong, but not su...
by mt99
Wed Jan 03, 2018 6:41 pm
Forum: Beginner Basics
Topic: 6.41: When Netinstall just doesn't cut it
Replies: 8
Views: 2245

6.41: When Netinstall just doesn't cut it

Hi folks, I've read the forum for a while but here is my first question. I was settig up interVLAN routing on my switch and RB750GL router, when I noticed that I couldn't ping the default gateways on the router anymore. So I restored a known good backup on the router, but that didn't fix the problem...