Community discussions

Search found 5473 matches

by mrz
Fri May 18, 2018 11:59 am
Forum: General
Topic: IPv6 BGP unreachable nexthop through loopback
Replies: 5
Views: 175

Re: IPv6 BGP unreachable nexthop through loopback

Currently recursive routing will not work if gateway is link local address.
by mrz
Fri May 18, 2018 11:18 am
Forum: General
Topic: network 255.255.255.255 how to add route?
Replies: 1
Views: 80

Re: network 255.255.255.255 how to add route?

There is no need to add route. Ipsec is policy based, so if you want to forward all traffic over the tunnel, simply add source nat rule to change src address to 10.40.99.195
by mrz
Fri May 18, 2018 11:10 am
Forum: General
Topic: dhcp-client "add-default-route=special-classless" - why option 3 (router) is still requested?
Replies: 8
Views: 218

Re: dhcp-client "add-default-route=special-classless" - why option 3 (router) is still requested?

ROS client works as sindy described, "router" option is ignored if option 121 is received form the server. Exception is if add-default-route=special-classless is set, then "router" option is not ignored.
by mrz
Thu May 17, 2018 3:11 pm
Forum: General
Topic: dhcp-client "add-default-route=special-classless" - why option 3 (router) is still requested?
Replies: 8
Views: 218

Re: dhcp-client "add-default-route=special-classless" - why option 3 (router) is still requested?

You cannot disable options 3 and 121 in requests. What is the main reason for such feature?
by mrz
Wed May 16, 2018 2:41 pm
Forum: General
Topic: Checking whether items are present
Replies: 14
Views: 291

Re: Checking whether items are present

It is just an example you can increase count to any value you need 60 or 90
by mrz
Wed May 16, 2018 2:30 pm
Forum: General
Topic: Is it so hard to use dynamic IP VPNs with mikrotik
Replies: 23
Views: 567

Re: Is it so hard to use dynamic IP VPNs with mikrotik

Why isn't it possible to configure an IPSEC-tunnel dynamically where the HQ does not know the IP of of the BO (dialup) It is certainly possible without 4 tunnels in so called road warrior setups. Set up ipsec+modeconf and problem solved, there are even example sin the manual: https://wiki.mikrotik....
by mrz
Wed May 16, 2018 1:05 pm
Forum: General
Topic: Checking whether items are present
Replies: 14
Views: 291

Re: Checking whether items are present

Delay is one option, but better option would be to wait for interfaces to load, for example if your config script depend on ethernet interfaces then do something like in code below. :local count 0; :while ([/interface ethernet find] = "") do={ :if ($count = 30) do={ :log warning "DefConf: Unable to ...
by mrz
Tue May 15, 2018 6:37 pm
Forum: General
Topic: Winbox Login over Windows Server RADIUS [SOLVED]
Replies: 15
Views: 427

Re: Winbox Login over Windows Server RADIUS [SOLVED]

I do not know anything about Windows radius server, but shouldn't you specify vendor code and value should be "full", not "Mikrotik-Group=full"?
At least that how it looks like from your provided screenshots.
by mrz
Tue May 15, 2018 6:24 pm
Forum: General
Topic: Checking whether items are present
Replies: 14
Views: 291

Re: Checking whether items are present

Yes, if there are dynamic entries then [find dynamic=no] should be used. "foreach" in this case is unnecessary, it should be used if you want to edit specific rules or any other reason when you need to loop through all found entries.
by mrz
Tue May 15, 2018 6:00 pm
Forum: General
Topic: Checking whether items are present
Replies: 14
Views: 291

Re: Checking whether items are present

/ip firewall filter remove [find]
by mrz
Mon May 14, 2018 10:22 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature Req: IKEv2 server and client
Replies: 285
Views: 58993

Re: Feature Req: IKEv2 server and client

Yes, EAP pasthrough to external RADIUS is supported.
by mrz
Fri Apr 27, 2018 5:32 pm
Forum: General
Topic: Script to remove a file issue [SOLVED]
Replies: 7
Views: 327

Re: Script to remove a file issue [SOLVED]

I would assume that either $backupfile variable is not defined or nothing is stored in it when executing script.
by mrz
Thu Apr 26, 2018 6:21 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 23286

Re: v6.42.1 [current]

You should be worried when you see OVPn user logged in message :)
by mrz
Thu Apr 26, 2018 11:35 am
Forum: Forwarding Protocols
Topic: BGP routes from peers not redistributed to other peers
Replies: 1
Views: 96

Re: BGP routes from peers not redistributed to other peers

Do you use the same instance for all BGP peers?
by mrz
Wed Apr 25, 2018 2:42 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 204
Views: 64844

Re: Advisory: Vulnerability exploiting the Winbox port

It can be done with one simple firewall rule. Create interface list and add /ip firewall filter add in-interface-list=xx ... And what if you have disabled conntrack? In a powerful router, we need all power for routing purposes, and firewall is downstream it. Any linux service can be bound to a spec...
by mrz
Wed Apr 25, 2018 7:47 am
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 204
Views: 64844

Re: Advisory: Vulnerability exploiting the Winbox port

It can be done with one simple firewall rule.
Create interface list and add
/ip firewall filter add in-interface-list=xx ...
by mrz
Tue Apr 24, 2018 5:56 pm
Forum: Beginner Basics
Topic: Securing your router
Replies: 8
Views: 339

Re: Securing your router

fixed
by mrz
Tue Apr 24, 2018 5:03 pm
Forum: Beginner Basics
Topic: Securing your router
Replies: 8
Views: 339

Re: Securing your router

by mrz
Tue Apr 24, 2018 4:42 pm
Forum: Beginner Basics
Topic: Securing your router
Replies: 8
Views: 339

Re: Securing your router

Discovery configuration syntax is changed, it uses interface lists now
https://wiki.mikrotik.com/wiki/Manual:I ... figuration
by mrz
Tue Apr 24, 2018 3:03 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 204
Views: 64844

Re: Advisory: Vulnerability exploiting the Winbox port

Only difference between firewall access restriction and ip service access restriction is that last one accepts connection, if source address does not match allowed list closes it. Firewall drops starting from the first syn packet.
by mrz
Mon Apr 23, 2018 6:44 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature Req: IKEv2 server and client
Replies: 285
Views: 58993

Re: Feature Req: IKEv2 server and client

Did you configured IOS and ROS as stated in these notes?
https://wiki.mikrotik.com/wiki/Manual:I ... figuration
by mrz
Mon Apr 23, 2018 5:54 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 204
Views: 64844

Re: Advisory: Vulnerability exploiting the Winbox port

!) winbox - fixed vulnerability that allowed to gain access to an unsecured router; Shifting of the blame onto users... what else are we supposed to use for remote management? Where do you see shifting blame on the users? It is information for users to know that routers are safe against this vulner...
by mrz
Mon Apr 23, 2018 4:53 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 23286

Re: v6.42.1 [current]

by mrz
Mon Apr 23, 2018 4:30 pm
Forum: General
Topic: VRF for management
Replies: 3
Views: 789

Re: VRF for management

We have plans to change this in the future, but most likely it will not happen in ROS v6
by mrz
Mon Apr 23, 2018 10:19 am
Forum: RouterOS v6 RC and v7 BETA
Topic: [Feature Request] - Support RFC6164
Replies: 5
Views: 1541

Re: [Feature Request] - Support RFC6164

You can assign /127 address and it works, however there is a problem if this address is used as gateway. Gateways from /127 addresses cannot be resolved.
by mrz
Mon Apr 23, 2018 10:16 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature Req: IKEv2 server and client
Replies: 285
Views: 58993

Re: Feature Req: IKEv2 server and client

@MikroTikFan
What are you waiting? IKE2 was backported to v6 long time ago.
by mrz
Mon Apr 23, 2018 10:13 am
Forum: Forwarding Protocols
Topic: MPLS - massive throughput difference on CHR when using explicit nulls
Replies: 51
Views: 3762

Re: MPLS - massive throughput difference on CHR when using explicit nulls

Hyper-V works because it does not assemble packets into 64k buffers. But this assembly happens only for traffic which source and destination is also virtual guest. If destination is physical router outside VM environment then there should be no problem with MPLS.
by mrz
Fri Apr 20, 2018 5:19 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Can't upgrade Routerboard version
Replies: 8
Views: 597

Re: Can't upgrade Routerboard version

From your screenshot upgrade firmware shows 3.33, do you have custom firmware file uploaded on the router? Check files menu
by mrz
Thu Apr 19, 2018 6:21 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 241
Views: 20516

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

@ mlenhart Read warning that was given to you when your post was deleted. If you start a rant in other completely unrelated topics about the problem which already has its own topic, then of course such post will be removed. Constructive critics and suggestions are welcome in topics where they belong...
by mrz
Thu Apr 19, 2018 5:52 pm
Forum: Announcements
Topic: v6.42 [current]
Replies: 146
Views: 14101

Re: v6.42 [current]

Do you actually reported to support?
If it is on the same router, then for me it looks like problem with interface driver not separate processes.
by mrz
Thu Apr 19, 2018 10:21 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Can not upgrade RB1100Dx4 to 6.42 due to double package installation
Replies: 3
Views: 236

Re: Can not upgrade RB1100Dx4 to 6.42 due to double package installation

It should not be possible to install double packages. Did you installed second package in one of the RC versions?
by mrz
Wed Apr 18, 2018 5:59 pm
Forum: Forwarding Protocols
Topic: BGP max-prefix-restart-time
Replies: 2
Views: 122

Re: BGP max-prefix-restart-time

This parameter works only when peer was disconnected due to max prefix limit reached.
by mrz
Wed Apr 18, 2018 12:55 pm
Forum: General
Topic: IPV6 Help
Replies: 2
Views: 164

Re: IPV6 Help

Here is an example how to use received pool
https://wiki.mikrotik.com/wiki/Manual:I ... r_local_RA
by mrz
Tue Apr 17, 2018 11:48 am
Forum: Forwarding Protocols
Topic: RFC7911
Replies: 2
Views: 169

Re: RFC7911

Currently no.
by mrz
Mon Apr 16, 2018 1:57 pm
Forum: General
Topic: netinstall defaul configuration
Replies: 7
Views: 340

Re: netinstall defaul configuration

Because when you log and run import manually, all drivers are already loaded.
by mrz
Thu Apr 12, 2018 12:02 pm
Forum: Virtualization
Topic: What machine for 40Gbps Edge Router?
Replies: 10
Views: 755

Re: What machine for 40Gbps Edge Router?

There was a good presentation at EU MUM about CHR performance on different hypervisors
https://youtu.be/xcgdGA1W_0o
by mrz
Wed Apr 11, 2018 3:14 pm
Forum: Virtualization
Topic: What machine for 40Gbps Edge Router?
Replies: 10
Views: 755

Re: What machine for 40Gbps Edge Router?

Only your host must support 40G interfaces. CHR uses virtual interfaces.
by mrz
Wed Apr 11, 2018 1:12 pm
Forum: General
Topic: netinstall defaul configuration
Replies: 7
Views: 340

Re: netinstall defaul configuration

Use delay at the top of the script or loop to wait for ethernet interfaces. It is necessary because script may be executed before drivers are loaded.
by mrz
Wed Apr 11, 2018 1:10 pm
Forum: General
Topic: AP and separate DHCP on same RB
Replies: 23
Views: 588

Re: AP and separate DHCP on same RB

Your NAT rule is will not work because your specified out-interface is a slave.
by mrz
Wed Apr 11, 2018 1:03 pm
Forum: General
Topic: VPLS fragmentation
Replies: 3
Views: 181

Re: VPLS fragmentation

Yes, VPLS packets are fragmented silently. You can see if packet is fragmented by running packet sniffer on out interface.
by mrz
Mon Apr 09, 2018 3:52 pm
Forum: RouterBOARD hardware
Topic: CCR1072-1G-8S+ max number of routes
Replies: 3
Views: 279

Re: CCR1072-1G-8S+ max number of routes

Max theoretical number of routes depends on installed amount of RAM:
https://wiki.mikrotik.com/wiki/Manual:B ... e_table.3F
by mrz
Mon Apr 09, 2018 3:50 pm
Forum: RouterBOARD hardware
Topic: MUM Europe 2018 - New hardware incoming
Replies: 20
Views: 3068

Re: MUM Europe 2018 - New hardware incoming

Great, however not sure why the included QSFP in these models. Compared with other vendors usually 4 x SFP+ is enough. The only usually include QSFP if the ports are all 10Ge or SFP+. Not complaining as such, but a little strange.
QSFP+ could be used for future features, like stacking.
by mrz
Thu Mar 29, 2018 1:22 pm
Forum: Wireless Networking
Topic: CapsMan not providing DHCP addresses when virtual WLAN Interface changes.
Replies: 4
Views: 158

Re: CapsMan not providing DHCP addresses when virtual WLAN Interface changes.

Of course you need wlan interface in the bridge, if DHCP server is reachable on the bridge.
There is an option to add automatically created interfaces in the bridge.
by mrz
Wed Mar 28, 2018 6:07 pm
Forum: RouterBOARD hardware
Topic: LHG 60G
Replies: 55
Views: 7080

Re: LHG 60G

Yes, it is the same.
by mrz
Wed Mar 28, 2018 5:58 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 43644

Re: Urgent security advisory

Yes, upgrade and for security reasons change password, too.
by mrz
Wed Mar 28, 2018 5:35 pm
Forum: General
Topic: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection
Replies: 8
Views: 251

Re: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection

And as I mentioned master port will have link as long as one of its slaves has link.

If ether6 is not master in your configuration then contact support with attached supout.rif file.
by mrz
Wed Mar 28, 2018 5:14 pm
Forum: General
Topic: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection
Replies: 8
Views: 251

Re: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection

Depends on your configuration, most likely in your config ether6 is master port. Master port will always be on as long as there are link for any of its slaves.