Community discussions

Search found 5810 matches

by mrz
Thu Apr 18, 2019 2:21 pm
Forum: Forwarding Protocols
Topic: OSPF type 0x09 error
Replies: 6
Views: 1862

Re: OSPF type 0x09 error

*) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;

viewtopic.php?f=21&t=146087&p=727144#p727144
by mrz
Fri Apr 12, 2019 2:48 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 222
Views: 34386

Re: UKNOF 43 CVE

Anyone who still had problems with small RAMs -> viewtopic.php?f=21&t=146087&p=726299#p726296
by mrz
Thu Apr 11, 2019 9:50 am
Forum: RouterOS v6 RC and v7 BETA
Topic: v6 RC and v7 BETA
Replies: 122
Views: 18436

Re: v6 RC and v7 BETA

Please clarify what is "proper IKEv2/IPSEC"?
by mrz
Mon Apr 08, 2019 1:17 pm
Forum: General
Topic: mikrotik scp/sftp client to transfer file between MT
Replies: 11
Views: 6704

Re: mikrotik scp/sftp client to transfer file between MT

mode option is deprecated, left for compatibility with older scripts.
Use url=sftp://
by mrz
Mon Apr 08, 2019 1:15 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 152
Views: 28832

Re: v6.45beta [testing] is released!

@eworm with url=sftp://xxx.xx/
by mrz
Fri Apr 05, 2019 11:31 am
Forum: General
Topic: IPV6 passthrough rules
Replies: 14
Views: 668

Re: IPV6 passthrough rules

It is not going to work properly on RouterOS if you add addresses on different interfaces from the same subnet. The same applies to ipv4, too.
So in summary setup shown in Asus System Logs i snot possible on RouterOS.
by mrz
Thu Apr 04, 2019 5:21 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 222
Views: 34386

Re: UKNOF 43 CVE

It is an upgrade problem because of no free space on the router, not related to this thread at all.
by mrz
Thu Apr 04, 2019 5:14 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 222
Views: 34386

Re: UKNOF 43 CVE

Completely unrelated to the topic.
by mrz
Thu Apr 04, 2019 5:07 pm
Forum: General
Topic: IPV6 passthrough rules
Replies: 14
Views: 668

Re: IPV6 passthrough rules

Ok then it is important to know what kind of configuration you had on Asus, by looking at asus config they allow you to choose between: native tunnel and static if it is native then you also have options to use dhcp-pd or static. All of this can be translated to routeros configuration if you know ex...
by mrz
Thu Apr 04, 2019 2:24 pm
Forum: General
Topic: IPV6 passthrough rules
Replies: 14
Views: 668

Re: IPV6 passthrough rules

Passthrough most likely means that you need to bridge WAN and LAN port, so that client can directly get the address from provider.
What was the original config on the Asus router?
by mrz
Mon Apr 01, 2019 10:25 am
Forum: RouterOS v6 RC and v7 BETA
Topic: VPLS features
Replies: 2
Views: 316

Re: VPLS features

And please add MTU > 1500 for BGP VPLS
Already possible with pw-mtu
by mrz
Fri Mar 29, 2019 4:56 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 222
Views: 34386

Re: UKNOF 43 CVE

It should be enough to limit on edge router, since it already limits to 2 new connections every second, unless routers further along the path have less than 100MB free ram, then probably you will need to limit even more on that specific router.
by mrz
Thu Mar 28, 2019 3:22 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Mikrotik: Change the default Powerbox config!
Replies: 15
Views: 858

Re: Mikrotik: Change the default Powerbox config!

Power box is the same RB750P, so they share the same configuration. Since there were not a lot of complains, this configuration is being kept.
by mrz
Thu Mar 28, 2019 2:36 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Mikrotik: Change the default Powerbox config!
Replies: 15
Views: 858

Re: Mikrotik: Change the default Powerbox config!

There is always possibility to set your own default config before putting it in the tower.
by mrz
Thu Mar 21, 2019 2:39 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 152
Views: 28832

Re: v6.45beta [testing] is released!

You can specify DHCP option set per DHCP network.
by mrz
Tue Mar 19, 2019 6:26 pm
Forum: Forwarding Protocols
Topic: Bgp filter for vpnv4 routes?
Replies: 3
Views: 165

Re: Bgp filter for vpnv4 routes?

Unfortunately no, you can match only RT.
by mrz
Tue Mar 19, 2019 12:30 pm
Forum: Forwarding Protocols
Topic: Bgp filter for vpnv4 routes?
Replies: 3
Views: 165

Re: Bgp filter for vpnv4 routes?

Add in/out filter chain in BGP VRF instance configuration and then on those chains you will be able to match by prefix.
by mrz
Mon Mar 18, 2019 2:28 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 152
Views: 28832

Re: v6.45beta [testing] is released!

In what scenario? If it's road warrior (typical when src is unknown or when src has dynamic IP) then policies should be already auto generated.
by mrz
Thu Mar 14, 2019 4:59 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 152
Views: 28832

Re: v6.45beta [testing] is released!

IKE2 rfc states the use of RSA.
What would be the client devices that support EC? Why exactly you need this?
by mrz
Thu Mar 14, 2019 2:54 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 152
Views: 28832

Re: v6.45beta [testing] is released!

EC certificates can be used only for www services. Ipsec does not support them.
by mrz
Thu Mar 14, 2019 10:01 am
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 41872

Re: Statement on Vault 7 document release

upgrade ≠ reset configuration

On upgrade system files are replaced with new ones.
by mrz
Wed Mar 13, 2019 5:36 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 41872

Re: Statement on Vault 7 document release

I think there is a lot of confusion what "reset configuration" do, this command wipes all '''configuration''' and thats it. It does not rely on script that you are talking about. "Reset configuration" also has nothing to do with clearing linux file system, it is called "reset configuration" for a re...
by mrz
Wed Mar 13, 2019 3:54 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 152
Views: 28832

Re: v6.45beta [testing] is released!

check/ip dhcp-server vendor-class-id menu
by mrz
Tue Mar 12, 2019 5:36 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 152
Views: 28832

Re: v6.45beta [testing] is released!

@buset1974 not in v6
by mrz
Tue Mar 12, 2019 5:33 pm
Forum: Forwarding Protocols
Topic: nexthop unreachable via iBGP
Replies: 1
Views: 123

Re: nexthop unreachable via iBGP

Yes, that is correct, you need to run IGP inside your AS.
For simpler setups you could also use nexthop-choice=force-self in bgp peer settings.
by mrz
Mon Mar 11, 2019 9:17 am
Forum: Forwarding Protocols
Topic: PPTP problem - empty winbox [SOLVED]
Replies: 7
Views: 517

Re: PPTP problem - empty winbox [SOLVED]

MTU issue, set up mangle rules to reduce TCP MSS.
by mrz
Thu Mar 07, 2019 5:30 pm
Forum: Forwarding Protocols
Topic: BUG - 4-byte ASN and BGP Communities on Route Filters
Replies: 3
Views: 230

Re: BUG - 4-byte ASN and BGP Communities on Route Filters

RFC states community attribute length
https://tools.ietf.org/html/rfc1997

Upstream peer cannot use Community attribute for what you described. Either they are using large community attribute or different method.
by mrz
Thu Mar 07, 2019 4:31 pm
Forum: Forwarding Protocols
Topic: BUG - 4-byte ASN and BGP Communities on Route Filters
Replies: 3
Views: 230

Re: BUG - 4-byte ASN and BGP Communities on Route Filters

BGP community attribute is limited to 4bytes in total by the standard. Different parameter is needed, for example large BGP community,which you currently cannot set. It is planned to add in the future, but I cannot tell when exactly. BTW community is administrative value, it does not mean that commu...
by mrz
Thu Mar 07, 2019 2:02 pm
Forum: General
Topic: BUG – v.6.44 on ARM boxes RB3011 is losing IPSEC configuration
Replies: 7
Views: 534

Re: BUG – v.6.44 on ARM boxes RB3011 is losing IPSEC configuration

It is not the system files but configuration.
by mrz
Tue Mar 05, 2019 5:06 pm
Forum: Scripting
Topic: POST Request with fetch
Replies: 65
Views: 20630

Re: POST Request with fetch

http-header-field="Content-Type: application/json"
by mrz
Tue Mar 05, 2019 3:27 pm
Forum: Forwarding Protocols
Topic: EoIPv6 Tunnel flapping when used to route full BGP feed
Replies: 4
Views: 209

Re: EoIPv6 Tunnel flapping when used to route full BGP feed

dst=n:n:n:67::1 you should know the gateway to your ISP. It is impossible to guess from your provided config.
by mrz
Tue Mar 05, 2019 12:10 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: About NULL in Layer7
Replies: 5
Views: 843

Re: About NULL in Layer7

Unfortunately current regexp engine does not allow to match \\x00.
by mrz
Tue Mar 05, 2019 11:57 am
Forum: General
Topic: ECDSA cert support?
Replies: 5
Views: 1207

Re: ECDSA cert support?

Added support in v6.45beta6
by mrz
Tue Mar 05, 2019 11:03 am
Forum: Forwarding Protocols
Topic: EoIPv6 Tunnel flapping when used to route full BGP feed
Replies: 4
Views: 209

Re: EoIPv6 Tunnel flapping when used to route full BGP feed

You are establishing BGP over the tunnel, BGP installs routes and tries to route traffic over the tunnel including tunnel traffic itself, which causes internal loop. Add static route to tunnel remote end to fix the problem.
by mrz
Mon Mar 04, 2019 12:04 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Recursive Routes - Need Help
Replies: 7
Views: 452

Re: Recursive Routes - Need Help

1. No you need to configure route properly.
/ip route add dst-address87.190.23.57/32 gateway=93.240.147.6x

2. It doesn't work for the same reason I mentioned in previous post.
by mrz
Mon Mar 04, 2019 10:27 am
Forum: Scripting
Topic: What's wrong with "where" ? [SOLVED]
Replies: 3
Views: 327

Re: What's wrong with "where" ? [SOLVED]

When you are trying to match a string, always use quotes. Console tries to guess the type of the variable, but sometimes it is not possible and you get unexpected result.
by mrz
Mon Mar 04, 2019 10:23 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Recursive Routes - Need Help
Replies: 7
Views: 452

Re: Recursive Routes - Need Help

Recursive route cannot be resolved if gateway is interface (not IP address). It is suggested to avoid using gateway interfaces on broadcast networks, since it can lead to unexpected behavior.
by mrz
Thu Feb 28, 2019 6:07 pm
Forum: Forwarding Protocols
Topic: Vlans + VRRP + Multiple Public IP addresses
Replies: 9
Views: 566

Re: Vlans + VRRP + Multiple Public IP addresses

VRRP cannot work without IP on physical interface unless it is VRRP v3 IPv6
by mrz
Thu Feb 28, 2019 1:22 pm
Forum: General
Topic: /certificate - certs issued on 6.44 can't be imported to long-term 6.42.12
Replies: 2
Views: 170

Re: /certificate - certs issued on 6.44 can't be imported to long-term 6.42.12

Thanks, problem confirmed, will fix it as soon as possible.
by mrz
Thu Feb 28, 2019 1:18 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 27949

Re: v6.44 [stable] is released!

Works as expected: [admin@4p_DUT_DISC Lite5] /interface wireless> set band=5ghz-n/ac Script Error: action cancelled [admin@4p_DUT_DISC Lite5] /interface wireless> set 0 band=5ghz-n/ac failure: bad band or frequency, see 'wireless info' for supported channels [admin@4p_DUT_DISC Lite5] /interface wire...
by mrz
Thu Feb 28, 2019 12:40 pm
Forum: Beginner Basics
Topic: ipsec IKEv1 to Zyxel USG [SOLVED]
Replies: 2
Views: 197

Re: ipsec IKEv1 to Zyxel USG [SOLVED]

I would recommend to learn how to set up IPSec properly. You can start by looking at configuration examples from the manual:
https://wiki.mikrotik.com/wiki/Manual:I ... ion_Guides
by mrz
Thu Feb 28, 2019 12:06 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 27949

Re: v6.44 [stable] is released!

Incorrect time is cosmetic Winbox bug noticed when there are multiple Winbox instances open. If you check in terminal, time is reported correctly.
by mrz
Thu Feb 28, 2019 10:32 am
Forum: Forwarding Protocols
Topic: Vlans + VRRP + Multiple Public IP addresses
Replies: 9
Views: 566

Re: Vlans + VRRP + Multiple Public IP addresses

You should set up one VRRP per physical interface.

Regarding loosing 3 IPs per subnet, not correct, you will loose only 2 IPs on a subnet that is running VRRP on IPv4. Or set up VRRP v3 on IPv6 an don't loose any IPs.
by mrz
Thu Feb 28, 2019 10:18 am
Forum: Forwarding Protocols
Topic: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"
Replies: 5
Views: 306

Re: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"

Run OSPF only on one subet connecting both routers. Check whether RouterIDs are unique.
by mrz
Thu Feb 28, 2019 10:15 am
Forum: Forwarding Protocols
Topic: IPv6 DHCP Relay with PD not installing route
Replies: 6
Views: 1216

Re: IPv6 DHCP Relay with PD not installing route

if you encounterd a bug contact Mikrotik support.