Community discussions

MikroTik App

Search found 6009 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 21
by mrz
Fri May 29, 2020 9:28 am
Forum: General
Topic: API for C#
Replies: 3
Views: 453

Re: API for C#

In the same topic look at "Class with SSL support", it has new authentication method.
by mrz
Mon May 18, 2020 10:04 am
Forum: RouterOS v7 BETA
Topic: beta5: Is this an error in the script parser? [SOLVED]
Replies: 2
Views: 574

Re: beta5: Is this an error in the script parser? [SOLVED]

First you are trying to use undeclared variable gArr Then you are declaring global variable with the same name in 'if' scope. I assume that you want to access already existing global variable and if it does not exist or is empty then add first entry, in that case script should look something like th...
by mrz
Wed May 13, 2020 8:04 pm
Forum: RouterOS v7 BETA
Topic: beta5: script parser error [SOLVED]
Replies: 2
Views: 560

Re: beta5: script parser error [SOLVED]

It is not related to beta version and as far as I know never supposed to work. What you are doing in script is run first loop which returns internal id (for example *1 for ether1) In next loop you are trying to find IP address with interface equal to "*1", obviously it will fail because there is no ...
by mrz
Mon Apr 27, 2020 10:14 am
Forum: Forwarding Protocols
Topic: OSPF disabling all ports on 'state change from Full to Down'
Replies: 7
Views: 2406

Re: OSPF disabling all ports on 'state change from Full to Down'

CCR does not work correctly with half duplex links, it is hardware limitation. For interface not to hang completely it is occasionally flapped. Regarding RB3011, if switch group is overloaded it will reset the switch group One workaround is: /interface ethernet switch set switch1,switch2 cpu-flow-co...
by mrz
Tue Apr 21, 2020 1:33 pm
Forum: RouterOS v7 BETA
Topic: FEATURE REQUEST: Add Basic Firewall Rule Wizard
Replies: 41
Views: 7078

Re: FEATURE REQUEST: Add Basic Firewall Rule Wizard

Very similar to default config is described in first time configuration
https://help.mikrotik.com/docs/display/ ... gtheRouter
"ProtectingtheRouter" and "ProtectingtheClient" sections
by mrz
Wed Apr 15, 2020 1:12 pm
Forum: Forwarding Protocols
Topic: Problems with MPLS IPv4 VPN
Replies: 70
Views: 23049

Re: Problems with MPLS IPv4 VPN

Regarding Issue1:
RDs should be unique, so this is not a RouterOS bug, but misconfiguration.

Regarding Issue2:
Yes we are aware of route selection problems in VRFs, unfortunately you will have to wait for ROS v7 updates.
by mrz
Wed Apr 15, 2020 8:44 am
Forum: RouterOS v7 BETA
Topic: Question: Multi-thread BGP
Replies: 9
Views: 2717

Re: Question: Multi-thread BGP

Load distribution between cores can be done without multithreading.
https://www.youtube.com/watch?v=NbfKplzda7I
by mrz
Tue Apr 14, 2020 6:07 pm
Forum: RouterOS v7 BETA
Topic: Question: Multi-thread BGP
Replies: 9
Views: 2717

Re: Question: Multi-thread BGP

All I can say is tht it will not be multithreaded. AFAIK none of currently existing implementations are fully multithreaded.
by mrz
Tue Apr 14, 2020 6:03 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: BGPQ3 Automated Routing Policies
Replies: 2
Views: 1310

Re: Feature Request: BGPQ3 Automated Routing Policies

You should ask BGPQ3 devs not MT.
by mrz
Tue Apr 14, 2020 11:29 am
Forum: RouterOS v7 BETA
Topic: Cannot set routing-mark or table for routing rule
Replies: 11
Views: 6342

Re: Cannot set routing-mark or table for routing rule

Yes, routing marks do not work at the moment.
by mrz
Tue Apr 14, 2020 9:34 am
Forum: RouterOS v7 BETA
Topic: mangle and routing-mark can not work for RouterOS v7
Replies: 9
Views: 2540

Re: mangle and routing-mark can not work for RouterOS v7

THere are several problems with routing marks in beta5. Wait until beta6 is released.
by mrz
Thu Apr 09, 2020 3:03 pm
Forum: General
Topic: RB133 Slow internet speed test
Replies: 3
Views: 1429

Re: RB133 Slow internet speed test

mipsle support is dropped (last fully supported version 6.32.3 and 6.32.4)
by mrz
Thu Apr 09, 2020 12:07 pm
Forum: RouterOS v7 BETA
Topic: V7 Routing Protocols Option [SOLVED]
Replies: 3
Views: 2038

Re: V7 Routing Protocols Option [SOLVED]

no, it is in-house development.
by mrz
Thu Apr 09, 2020 11:28 am
Forum: RouterOS v7 BETA
Topic: Feature Request - BGP RPKI
Replies: 23
Views: 6497

Re: Feature Request - BGP RPKI

Currently work in progress
by mrz
Thu Apr 09, 2020 11:28 am
Forum: RouterOS v7 BETA
Topic: V7 Routing Protocols Option [SOLVED]
Replies: 3
Views: 2038

Re: V7 Routing Protocols Option [SOLVED]

RouterOS is not using quagga and will not use FRR
by mrz
Thu Apr 09, 2020 11:25 am
Forum: Forwarding Protocols
Topic: How to redistribute OSPF Metric to BGP Local Pref.
Replies: 1
Views: 1350

Re: How to redistribute OSPF Metric to BGP Local Pref.

RouterOS v6 does not have such functionality.
by mrz
Wed Apr 01, 2020 12:10 pm
Forum: Forwarding Protocols
Topic: OSPF disabling all ports on 'state change from Full to Down'
Replies: 7
Views: 2406

Re: OSPF disabling all ports on 'state change from Full to Down'

OSPF goes down because physical links are flapping, it can be seen in your logs. Logs are written asynchronously, so when difference between events are in milliseconds interface flap may appear after OSPF message.
by mrz
Wed Apr 01, 2020 9:34 am
Forum: General
Topic: Correction request : Authority flag for Import CA Certificate Autority in RouterOS
Replies: 9
Views: 2117

Re: Correction request : Authority flag for Import CA Certificate Autority in RouterOS

This certificate have "Authority" flag and was show in WebFig under Certificate > Sign menu as CA and you can use to TRY to sign certificate, but you CANNOT sign another certificate because there is NOT the private key. There is specific flag that indicates whether private key is imported no matter...
by mrz
Fri Mar 27, 2020 9:35 am
Forum: Forwarding Protocols
Topic: Loopback as MPLS Interface [SOLVED]
Replies: 2
Views: 1566

Re: Loopback as MPLS Interface [SOLVED]

MPLS interface entries are required to correctly determine MPLS MTU on interfaces participating in MPLS packet forwarding. Without these entries MPLS will not work properly, I would suggest to leave default "all" enabled.
by mrz
Thu Mar 26, 2020 9:08 am
Forum: RouterOS v7 BETA
Topic: FEATURE REQUEST: Add Basic Firewall Rule Wizard
Replies: 41
Views: 7078

Re: FEATURE REQUEST: Add Basic Firewall Rule Wizard

That is why we have quickset where you can disableenable default firewall ruleset or default NAT rules.
by mrz
Wed Mar 25, 2020 7:52 am
Forum: Forwarding Protocols
Topic: OSPF loses default-route with virtual-link
Replies: 2
Views: 1227

Re: OSPF loses default-route with virtual-link

default route over virtual link does not work in v6. This problem is fixed in ROSv7.
by mrz
Fri Mar 20, 2020 10:37 am
Forum: Scripting
Topic: PHP API Login Method Example [Help Please] [SOLVED]
Replies: 11
Views: 2565

Re: PHP API Login Method Example [SOLVED]

I do not know anything about php api, but shouldn't it be like this?
$this->write('/login', false);
$this->write('=name=' . $login, false); 
$this->write('=password=' . $password);
by mrz
Fri Mar 20, 2020 10:17 am
Forum: Scripting
Topic: PHP API Login Method Example [Help Please] [SOLVED]
Replies: 11
Views: 2565

Re: PHP API Login Method Example [SOLVED]

send in initial login message
/login
=name=user
=password=xxx
by mrz
Mon Mar 16, 2020 4:19 pm
Forum: General
Topic: Feature requests
Replies: 1216
Views: 262464

Re: Feature requests

Thanks, If you find anything else strange with history report to support.
by mrz
Wed Mar 11, 2020 12:38 pm
Forum: General
Topic: How to raise "upgradeable to"?
Replies: 26
Views: 5123

Re: How to raise "upgradeable to"?

See the date of original post. A lot has changed since then. mipsle devices are deprecated.
by mrz
Wed Mar 11, 2020 11:34 am
Forum: RouterBOARD hardware
Topic: CRS354-48P-4S+2Q+ and orther
Replies: 7
Views: 4694

Re: CRS354-48P-4S+2Q+ and orther

Power supply to power 48 POE ports is huge. Physically there is no space to put second PSU.
by mrz
Tue Mar 10, 2020 10:43 am
Forum: Forwarding Protocols
Topic: Where is igmp-proxy?
Replies: 1
Views: 1388

Re: Where is igmp-proxy?

install multicast package.
by mrz
Thu Mar 05, 2020 2:20 pm
Forum: General
Topic: ip-sec between MikroTik and Cisco ASA not passing traffic
Replies: 23
Views: 3833

Re: ip-sec between MikroTik and Cisco ASA not passing traffic

By looking at installed SA counters my guess is that RouterOS matches packets against policy properly, encapsulates and sends them to remote peer.
Either remote peer is dropping incoming packets or does not send a reply.
by mrz
Thu Mar 05, 2020 12:18 pm
Forum: General
Topic: ip-sec between MikroTik and Cisco ASA not passing traffic
Replies: 23
Views: 3833

Re: ip-sec between MikroTik and Cisco ASA not passing traffic

Do you have any fasttrack rules or other routing tables than main?
by mrz
Tue Mar 03, 2020 6:05 pm
Forum: Beginner Basics
Topic: Default firewall rules and connecting using PPPoE
Replies: 5
Views: 2059

Re: Default firewall rules and connecting using PPPoE

No, default firewall rules won't protect if a new pppoe WAN interface is added afterwards.
This is false information. Default configuration for quite some blocks access on interfaces that are not in either LAN or WAN interface lists.
by mrz
Tue Mar 03, 2020 6:03 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 3579

Re: OSPF Drops when adding a comment?

Changing comments on interface and address does not trigger any reconnects.
You know how it goes, if you have encountered a problem on specific interfaces then contact support with request to fix it.
by mrz
Tue Mar 03, 2020 3:34 pm
Forum: General
Topic: DHCPv6 DUID change - bug?
Replies: 14
Views: 4663

Re: DHCPv6 DUID change - bug?

RFC states: The DUID is designed to be unique across all DHCP clients and servers, and stable for any specific client or server - that is, the DUID used by a client or server SHOULD NOT change over time if at all possible; for example, a device's DUID should not change as a result of a change in the...
by mrz
Tue Mar 03, 2020 3:15 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 3579

Re: OSPF Drops when adding a comment?

No it is specific to protocols. For example BGP in v7 will have parameters that will not reset connection.
OSPF should also have parameters that will not reset adjacencies.
by mrz
Tue Mar 03, 2020 12:00 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 3579

Re: OSPF Drops when adding a comment?

BTW OSPF in v7beta is already implemented, so if you have any complains or suggestions about v7 OSPF feel free to send them to support while it is in beta state.
by mrz
Tue Mar 03, 2020 11:42 am
Forum: General
Topic: TTL expires in transit.
Replies: 2
Views: 1230

Re: TTL expires in transit.

You have a routing loop somewhere. Run traceroute to see where.
by mrz
Mon Mar 02, 2020 2:12 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 16
Views: 4188

Re: ProtonVPN on Mikrotik

SHA512 is not supported and UDP is supported only in ROS v7
by mrz
Mon Mar 02, 2020 1:23 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 16
Views: 4188

Re: ProtonVPN on Mikrotik

Unfortunately, Mikrotik routers do not support OpenVPN client connection, therefore, it is not possible to set up a ProtonVPN connection on it. We're sorry for the inconveniences.
BTW OVPN is also supported, maybe they require some specific OVPN feature?
by mrz
Mon Mar 02, 2020 12:26 pm
Forum: General
Topic: ProtonVPN on Mikrotik
Replies: 16
Views: 4188

Re: ProtonVPN on Mikrotik

By looking at this example:
https://protonvpn.com/support/linux-ikev2-protonvpn/

it is very similar to nordvpn config, so you can use NordVPN RouterOS setup example as a reference:
https://wiki.mikrotik.com/wiki/IKEv2_EA ... d_RouterOS
by mrz
Mon Mar 02, 2020 11:57 am
Forum: Forwarding Protocols
Topic: BGP VPN4 Issues
Replies: 1
Views: 1728

Re: BGP VPN4 Issues

You need either fullmesh (all peers connected to each other) or set for example R2 as route reflector.
by mrz
Fri Feb 28, 2020 11:57 am
Forum: RouterOS v7 BETA
Topic: 7beta5 Bricked my HAPAC2
Replies: 2
Views: 2634

Re: 7beta5 Bricked my HAPAC2

How old was bootloader? Very old bootloader will not work with v7. Try to load backup booter and then reinstall with netinstall.
by mrz
Fri Feb 21, 2020 11:39 am
Forum: RouterOS v7 BETA
Topic: Feature request: RPKI integration/validation
Replies: 1
Views: 1600

Re: Feature request: RPKI integration/validation

Use search, there are already several topics about RPKI.
In short, we are working on it.
by mrz
Thu Feb 20, 2020 2:36 pm
Forum: Forwarding Protocols
Topic: BGP merging two ASN to one i.e. operating two ASN simultanously in one part of the network
Replies: 4
Views: 1727

Re: BGP merging two ASN to one i.e. operating two ASN simultanously in one part of the network

Yes, confederations are used to migrate to new AS while still keeping the old AS during migration process. In terms of setup you just need to specify "confederation-as" and "confederation-peers" in BGP instance configuration.
by mrz
Thu Feb 20, 2020 1:59 pm
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 77
Views: 20610

Re: Feature Request: IPSEC Improvements

That would require to store large CA database on the router.
by mrz
Thu Feb 20, 2020 10:21 am
Forum: General
Topic: Feature Request: IPSEC Improvements
Replies: 77
Views: 20610

Re: Feature Request: IPSEC Improvements

It works if you do not use IP unnumbered (at least on Cisco)
by mrz
Wed Feb 19, 2020 4:40 pm
Forum: General
Topic: IKEv2 IPsec VPN and IPv6
Replies: 7
Views: 2270

Re: IKEv2 IPsec VPN and IPv6

But in my case it would be connections made FROM various IPv4 devices (PCs and phones) TO a router that sits behind a NATTED IPv4 and only has public IPv6 visible to the internet... Don't know how that would work (I remember reading that the new IP CLOUD already has IPv6 support, so maybe it could ...
by mrz
Thu Feb 13, 2020 12:33 pm
Forum: Scripting
Topic: API for Disabled Users
Replies: 1
Views: 1365

Re: API for Disabled Users

receive all disabled hotspot users via API query and count them in your app.
by mrz
Mon Feb 10, 2020 11:22 am
Forum: Scripting
Topic: logs mikrotik CGNAT NETMAP
Replies: 1
Views: 1616

Re: logs mikrotik CGNAT NETMAP

Set log=yes for that NAT rule and set up logging in /system logging menu to send all firewall logs to remote syslog server.
by mrz
Mon Feb 10, 2020 11:06 am
Forum: Forwarding Protocols
Topic: Selective filtering of BGP routes distributed into OSPF not working?
Replies: 2
Views: 1565

Re: Selective filtering of BGP routes distributed into OSPF not working?

OSPF-in chain is used only when routes are received from other OSPF neighbors.
To control what external routes will be sent to other OSPF neighbors you need to use OSPF out.
by mrz
Tue Jan 28, 2020 12:03 pm
Forum: RouterOS v7 BETA
Topic: Feature Request - BGP RPKI
Replies: 23
Views: 6497

Re: Feature Request - BGP RPKI

ROS didn't use Quagga and no there will not be FRR.
by mrz
Mon Jan 27, 2020 2:34 pm
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 121
Views: 31189

Re: v6.46.2 [stable] is released!

Auto upgrader will not try to install if at least one package is missing or not finished downloading.
by mrz
Tue Jan 21, 2020 2:08 pm
Forum: General
Topic: Simple Queues script to change type [SOLVED]
Replies: 9
Views: 1061

Re: Simple Queues script to change type [SOLVED]

If you have more than one item with total-queue="default-small" then you need to iterate through find results.
For example using foreach
:foreach i in=[find where total-queue="default-small"] do={set $i total-queue=wireless-default }
by mrz
Tue Jan 21, 2020 11:30 am
Forum: General
Topic: Simple Queues script to change type [SOLVED]
Replies: 9
Views: 1061

Re: Simple Queues script to change type [SOLVED]

set [find total-queue="default-small" ] total-queue=wireless-default
by mrz
Tue Jan 21, 2020 9:52 am
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 121
Views: 31189

Re: v6.46.2 [stable] is released!

Sometimes I just get the files from the mikrotik.com download section, collecting the main package and some optional packages, then I FTP the whole thing to the router and reboot. This is in fact the only way to add one or more optional packages. Of course after doing the FTP I first list the Files...
by mrz
Mon Jan 20, 2020 4:48 pm
Forum: RouterOS v7 BETA
Topic: IP route table display
Replies: 5
Views: 2129

Re: IP route table display

You can do print on the same menu and you will see parameters related only to static IP routes. Routing route should be used to monitor all routes (including filtered ones) and their protocol specific parameters. eally breaking an old Mikrotik tradition of changing stuff on a menu level (in this cas...
by mrz
Mon Jan 20, 2020 12:13 pm
Forum: Forwarding Protocols
Topic: Further BGP improvements?
Replies: 4
Views: 1801

Re: Further BGP improvements?

Yes, we are working on BGP at the moment. First beta with enabled BGP is coming soon.
by mrz
Thu Jan 16, 2020 7:15 pm
Forum: Scripting
Topic: API enable\disable ip sec peer
Replies: 2
Views: 1579

Re: API enable\disable ip sec peer

Please read documentation on how to use API
https://wiki.mikrotik.com/wiki/Manual:A ... escription
by mrz
Thu Jan 16, 2020 2:22 pm
Forum: RouterOS v7 BETA
Topic: IP route table display
Replies: 5
Views: 2129

Re: IP route table display

v7 have completely reworked routing table with completely different flags. v7 Has 3 Flag columns: * shows if route is dynamically added by any protocol * route status flag (active, inactive, disabled) * protocol flag (bgp, osf,static,connected etc.) I would suggest to use /routing/route menu to moni...
by mrz
Mon Jan 13, 2020 12:28 pm
Forum: Forwarding Protocols
Topic: OSPF Networks
Replies: 2
Views: 1547

Re: OSPF Networks

@marcocamza If you mean add /12 in OSPF network configuration so that OSPF runs on all matching networks, then yes you can do it.
If you mean to advertise /12 instead /24 then no, unless you run those networks in area, then you can do summarization on ABR.
by mrz
Thu Jan 09, 2020 1:01 pm
Forum: Forwarding Protocols
Topic: does Mikrotik support RFC5549
Replies: 2
Views: 1857

Re: does Mikrotik support RFC5549

At the moment, no, it is not supported.
by mrz
Thu Jan 09, 2020 12:58 pm
Forum: Forwarding Protocols
Topic: Default Route from BGP to OSPF
Replies: 21
Views: 9014

Re: Default Route from BGP to OSPF

Yes, that particular problem from 2017 is fixed. If you have the same symptoms contact support.
by mrz
Wed Nov 27, 2019 11:48 am
Forum: RouterOS v7 BETA
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 3664

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

We are open to suggestions while v7 is in beta state.
by mrz
Tue Nov 26, 2019 5:28 pm
Forum: RouterOS v7 BETA
Topic: DS-Lite (dual stack lite) internet connection as defined in RFCs 6333 and 6334
Replies: 5
Views: 3538

Re: DS-Lite (dual stack lite) internet connection as defined in RFCs 6333 and 6334

We will try to add some functionality to read options in the script.
by mrz
Tue Nov 26, 2019 4:28 pm
Forum: Scripting
Topic: Can't specify log buffer as variable
Replies: 2
Views: 1382

Re: Can't specify log buffer as variable

Do not use the system parameter names as variable names and everything will work as expected:
https://wiki.mikrotik.com/wiki/Manual:S ... able_names
by mrz
Tue Nov 26, 2019 4:13 pm
Forum: RouterOS v7 BETA
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 3664

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

/routing table
add name=G-2 vrf=main
add name=G0SQ vrf=main
add name=CIR vrf=main

/ip/route
add gateway="EXTRA PPPOE@main" dst-address=0.0.0.0/0^G-2
add gateway=192.168.100.1@main dst-address=0.0.0.0/0^G-SQ
add gateway=103.225.xx.xx@main dst-address=0.0.0.0/0^CIR
...
by mrz
Mon Nov 25, 2019 12:55 pm
Forum: RouterOS v7 BETA
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 3664

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

Show what IP routes and route rules you had on v6 and I will show you how they should look like in v7.
by mrz
Mon Nov 25, 2019 11:56 am
Forum: RouterOS v7 BETA
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 3664

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

It is just an example to show the syntax. Use addresses you want to route.
by mrz
Fri Nov 22, 2019 12:13 pm
Forum: Forwarding Protocols
Topic: BGP: Remove extra prepends from upstream
Replies: 2
Views: 1573

Re: BGP: Remove extra prepends from upstream

Just prioritize by setting local pref or weights in your end.
by mrz
Wed Nov 13, 2019 12:19 pm
Forum: General
Topic: Microsoft CA - SCEP
Replies: 1
Views: 416

Re: Microsoft CA - SCEP

Enable certificate debug logs to see what exactly fails.
by mrz
Wed Nov 13, 2019 10:45 am
Forum: RouterOS v7 BETA
Topic: [ROS 7.0b3] Kernel module 'igb' [SOLVED]
Replies: 12
Views: 5388

Re: [ROS 7.0b3] Kernel module 'igb' [SOLVED]

If you know that driver is in vanilla kernel, then write to support with attached supout file from the device, we will see if it can be enabled.
by mrz
Mon Nov 11, 2019 9:24 am
Forum: RouterOS v7 BETA
Topic: Can't SSH from CHR Version 7.0 Beta 3
Replies: 3
Views: 2623

Re: Can't SSH from CHR Version 7.0 Beta 3

Problem will be solved in next beta.
by mrz
Fri Nov 08, 2019 5:06 pm
Forum: RouterOS v7 BETA
Topic: OpenVPN Bad decompression
Replies: 5
Views: 2835

Re: OpenVPN Bad decompression

Name at least one good reason to support LZO? Even on standard OpenVPN it is being deprecated
by mrz
Tue Nov 05, 2019 10:13 am
Forum: Scripting
Topic: adding item with place-before on cleared list fails
Replies: 1
Views: 1504

Re: adding item with place-before on cleared list fails

Because console does not know where "0" is located unless you do print before.
by mrz
Mon Nov 04, 2019 4:20 pm
Forum: RouterOS v7 BETA
Topic: VRF IPv6 support with RouterOS v7
Replies: 4
Views: 3380

Re: VRF IPv6 support with RouterOS v7

Yes, it will. At the moment VRFs are still not enabled.
by mrz
Mon Nov 04, 2019 4:18 pm
Forum: RouterOS v7 BETA
Topic: 7.0 Beta2 script bug
Replies: 2
Views: 2523

Re: 7.0 Beta2 script bug

x86 and CHR won't have routerboard menu. Solution:
:do { :put [/system routerboard print] } on-error={:put "not supported"}
by mrz
Mon Nov 04, 2019 4:03 pm
Forum: RouterOS v7 BETA
Topic: Can't SSH from CHR Version 7.0 Beta 3
Replies: 3
Views: 2623

Re: Can't SSH from CHR Version 7.0 Beta 3

What is the remote device? If it is RouterOS does it have strong-crypto enabled too? If it is not ROS devices, does it have enabled all needed algorithms that is used by the ssh client when strong crypto is enabled?
by mrz
Tue Oct 15, 2019 11:09 am
Forum: Scripting
Topic: dynamic=no doesn't work in /ip route
Replies: 4
Views: 1765

Re: dynamic=no doesn't work in /ip route

Works with find too:
[admin@p3_450] /ip route> :put [find  where !dynamic]      
*2;*1
[admin@p3_450] /ip route> :put [find  where !static]        
*401691fd
by mrz
Mon Oct 14, 2019 6:36 pm
Forum: Scripting
Topic: dynamic=no doesn't work in /ip route
Replies: 4
Views: 1765

Re: dynamic=no doesn't work in /ip route

When route is not dynamic then "dynamic" parameter is not set wich is not equal to "no" Correct way is [admin@p3_450] /ip route> print where dynamic Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibi...
by mrz
Mon Oct 14, 2019 6:32 pm
Forum: Forwarding Protocols
Topic: Static MPLS configuration
Replies: 4
Views: 2980

Re: Static MPLS configuration

For static LDP bindings to work, you also need static routes in routing table: [admin@p3_450] /mpls local-bindings> print Flags: X - disabled, A - advertised, D - dynamic, L - local-route, G - gateway-route, e - egress # DST-ADDRESS LABEL PEERS 0 G 10.255.0.0/24 1000 1 G 10.255.1.0/24 1113 [admin@p3...
by mrz
Fri Oct 11, 2019 12:24 pm
Forum: Forwarding Protocols
Topic: BGP bug report
Replies: 1
Views: 1817

Re: BGP bug report

On the right upper corner is a search
viewtopic.php?f=14&t=146206&p=719583
by mrz
Wed Oct 09, 2019 12:22 pm
Forum: Scripting
Topic: Login API pear2/Net_RouterOS 6.45.x
Replies: 4
Views: 2463

Re: Login API pear2/Net_RouterOS 6.45.x

I do not see a problem you just try new login method and fall back if you receive ret, as shown in the python example:
https://wiki.mikrotik.com/wiki/Manual:A ... ple_client

See "login" function
by mrz
Fri Oct 04, 2019 5:17 pm
Forum: General
Topic: Winbox - 64bits
Replies: 1
Views: 716

Re: Winbox - 64bits

by mrz
Fri Oct 04, 2019 1:46 pm
Forum: Forwarding Protocols
Topic: Filters for +500 prefixes
Replies: 9
Views: 3050

Re: Filters for +500 prefixes

Similar feature is currently in development.
by mrz
Fri Oct 04, 2019 11:51 am
Forum: RouterOS v7 BETA
Topic: adding fib to vrf failed with timeout
Replies: 3
Views: 3063

Re: adding fib to vrf failed with timeout

Thank you for the report, at this moment VRFs are not implemented. Adding table to the vrf will simply crash the route.
by mrz
Thu Oct 03, 2019 2:22 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 88906

Re: RB4011

If you see unclassified process, generate supout file and send it to support.
by mrz
Mon Sep 30, 2019 10:31 am
Forum: Forwarding Protocols
Topic: PPP & VRF bug? [SOLVED]
Replies: 3
Views: 2766

Re: VRF bug? [SOLVED]

PPP is not fully VRF aware. Workaround is to change table with route filters or use scripts to add routes manually to correct VRF.
by mrz
Fri Sep 27, 2019 7:30 pm
Forum: RouterOS v7 BETA
Topic: Cannot set routing-mark or table for routing rule
Replies: 11
Views: 6342

Re: Cannot set routing-mark or table for routing rule

Config is changed in v7
/routing table
add fib name=xx vrf=main
/ip route
add dst-address=8.8.8.8^xx gateway=10.155.101.1@main
/ip route rule 
add dst-address=1.1.1.1 action=lookup table=xx
by mrz
Fri Sep 27, 2019 6:17 pm
Forum: RouterOS v7 BETA
Topic: RouterOS v7.0beta2 bug fund
Replies: 9
Views: 4602

Re: RouterOS v7.0beta2 bug fund

- IPv4 route marking/rules appears to be dead Routing mark is configured differently, first you add the table and only then you can add routes to the table or use it in routing rules. /routing table add fib name=xx vrf=main /ip route add dst-address=8.8.8.8^xx gateway=10.155.101.1@main /ip route ru...
by mrz
Fri Sep 27, 2019 4:36 pm
Forum: RouterOS v7 BETA
Topic: RouterOS v7.0beta2 bug fund
Replies: 9
Views: 4602

Re: RouterOS v7.0beta2 bug fund

There is not much new because most of the new features were backported already to v6.
If you see trivial small bugs, list them here anyway
by mrz
Tue Sep 17, 2019 10:21 am
Forum: Scripting
Topic: Is QuickSet available via the API?
Replies: 1
Views: 1718

Re: Is QuickSet available via the API?

No.
by mrz
Mon Sep 16, 2019 11:11 am
Forum: Beginner Basics
Topic: RB4011iGS+5HacQ2HnD-IN remove default config
Replies: 2
Views: 846

Re: RB4011iGS+5HacQ2HnD-IN remove default config

not related to v7beta, moved to basics.
by mrz
Thu Sep 12, 2019 11:09 am
Forum: RouterOS v7 BETA
Topic: Should OSPF work?
Replies: 3
Views: 3525

Re: Should OSPF work?

To run ospfv3 use following settings:

/routing ospf
instance add name=instance_v3 version=3
area add name=backbone_v3 instance=instance_v3
interface add network=%ether1 area=backbone_v3

But OSPFv3 might not work, thee are problems with LS Updates
by mrz
Tue Sep 10, 2019 6:59 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 179553

Re: RouterOS v7.0 beta1 - when?

Recursive nexthops in v7 works without any scripts.
by mrz
Fri Sep 06, 2019 4:22 pm
Forum: General
Topic: RouterOS v7.0beta1 (ARM)
Replies: 203
Views: 53848

Re: RouterOS v7.0beta1 (ARM)

BGP currently disabled, stay tuned.
by mrz
Mon Sep 02, 2019 10:55 am
Forum: Scripting
Topic: Decimals ?
Replies: 5
Views: 3367

Re: Decimals ?

Yes only integers. Anywhere where you see decimal representation is actually a string.
by mrz
Thu Aug 29, 2019 10:52 am
Forum: Scripting
Topic: Running script via API does not set global variable
Replies: 3
Views: 1729

Re: Running script via API does not set global variable

does it work with dont-require-permissions=yes?
by mrz
Wed Aug 28, 2019 12:54 pm
Forum: General
Topic: Error Terminal command symbol - $
Replies: 4
Views: 1064

Re: Error Terminal command symbol - $

$ is a special char and must be escaped:
https://wiki.mikrotik.com/wiki/Manual:S ... _Sequences
by mrz
Thu Aug 22, 2019 11:54 am
Forum: Forwarding Protocols
Topic: BGP and more specific routes.
Replies: 10
Views: 2835

Re: BGP and more specific routes.

I might be mistaken, but by looking at your config, looks like you set /22 on sfp interface, and then divide clients in two subnets, by assigning on client side /23 subnets? This will also cause packet drops.
by mrz
Thu Aug 22, 2019 9:56 am
Forum: Forwarding Protocols
Topic: BGP and more specific routes.
Replies: 10
Views: 2835

Re: BGP and more specific routes.

Using interface name as gateway is invalid setup on broadcast networks. You can use it only on point to point interfaces, otherwise you will get those "mysterious" packet drops.
by mrz
Thu Aug 22, 2019 9:53 am
Forum: Forwarding Protocols
Topic: route ospf error -> Discarding packet: locally originated
Replies: 25
Views: 32450

Re: route ospf error -> Discarding packet: locally originated

Do you have connection tracking enabled?
by mrz
Tue Aug 20, 2019 11:36 am
Forum: Forwarding Protocols
Topic: Multicast Routing
Replies: 1
Views: 1927

Re: Multicast Routing

by mrz
Tue Aug 13, 2019 4:49 pm
Forum: Scripting
Topic: api login issues 6.46beta16
Replies: 2
Views: 2649

Re: api login issues 6.46beta16

by mrz
Fri Aug 09, 2019 5:20 pm
Forum: General
Topic: Mac telnet problem after upgrade... wrong password
Replies: 7
Views: 3007

Re: Mac telnet problem after upgrade... wrong password

see my post above.
You will not be able to connect from old ROS versions to 6.45.3
by mrz
Tue Aug 06, 2019 11:27 am
Forum: Announcements
Topic: v6.45.3 [stable] is released!
Replies: 90
Views: 35042

Re: v6.45.3 [stable] is released!

It will not include peer, if you upgraded from version where policy was set without peer.
If you set peer after upgrade or added policy already in v6.45.3 then it will be exported.
by mrz
Thu Aug 01, 2019 12:46 pm
Forum: Forwarding Protocols
Topic: default route via TE Tunnel and OSPF
Replies: 4
Views: 2106

Re: default route via TE Tunnel and OSPF

Well yes, you could use other routing protocol that does not listen on interface. For example BGP and set lower distance than OSPF routes.

Or try to change nexthop in routing filter for OSPF routes, but this would reliably work only on external routes.
by mrz
Thu Aug 01, 2019 11:06 am
Forum: Forwarding Protocols
Topic: default route via TE Tunnel and OSPF
Replies: 4
Views: 2106

Re: default route via TE Tunnel and OSPF

Probably easiest way is to simply run OSPF on TE interface.
by mrz
Mon Jul 29, 2019 10:38 am
Forum: Scripting
Topic: mass-enable all of my vlan using script
Replies: 7
Views: 2562

Re: mass-enable all of my vlan using script

/interface vlan enable [find]
by mrz
Fri Jul 26, 2019 3:01 pm
Forum: Forwarding Protocols
Topic: Route selection - What am I missing? [SOLVED]
Replies: 3
Views: 2782

Re: Route selection - What am I missing? [SOLVED]

Will not be changed in current implementation, but there are plans to redo this part in new implementation on which we are working right now.
by mrz
Fri Jul 26, 2019 11:24 am
Forum: Scripting
Topic: 6.43 change in login process and API libraries?
Replies: 18
Views: 8616

Re: 6.43 change in login process and API libraries?

The reason is new password storage. To keep md5 we would need to store password in plain text on the router, which is not what we want. Do you use tenet over unsecure networks? I think not, most likely you will chose ssh instead. With api is the same, consider unsecure api as telnet, and api over ss...
by mrz
Thu Jul 25, 2019 6:46 pm
Forum: Forwarding Protocols
Topic: Some OSPF commands not working on V6.45.2
Replies: 4
Views: 2178

Re: Some OSPF commands not working on V6.45.2

v6 is multi instance OSPF. From the manual:
"Since v3.17 it is possible to run multiple OSPF instances. General OSPF configuration now is moved to instances."
and
"For multi instance OSPF you have to use following command: /routing ospf instance print status"
by mrz
Thu Jul 25, 2019 5:58 pm
Forum: Forwarding Protocols
Topic: Route selection - What am I missing? [SOLVED]
Replies: 3
Views: 2782

Re: Route selection - What am I missing? [SOLVED]

How route selection is made in v6 you will not get other BGP route active because BGP does not trigger best path selection algorithm in this situation. Order is as follows: * BGP elects best route from all received BGP routes using best path selection algorithm. * BGP marks the route as candidate ro...
by mrz
Thu Jul 25, 2019 5:00 pm
Forum: Scripting
Topic: Built in function library
Replies: 60
Views: 26486

Re: Built in function library

and how exactly it is related to scripting functions?
by mrz
Thu Jul 25, 2019 2:15 pm
Forum: General
Topic: How add prefix From Bgp peer to address-list
Replies: 4
Views: 743

Re: How add prefix From Bgp peer to address-list

At the moment there is no direct way. You could write a script which adds prefixes to address list, but that may lead to extensive CPU usage if BGP table is very large.
by mrz
Wed Jul 24, 2019 12:35 pm
Forum: General
Topic: Mac telnet problem after upgrade... wrong password
Replies: 7
Views: 3007

Re: Mac telnet problem after upgrade... wrong password

Mac telnet will not work if you try to telnet to device with installed older RouterOS (with old user store)
by mrz
Wed Jul 24, 2019 11:43 am
Forum: Scripting
Topic: 6.43 change in login process and API libraries?
Replies: 18
Views: 8616

Re: 6.43 change in login process and API libraries?

Where traffic can be easily sniffed by 3rd parties you should establish secure connection anyway.
by mrz
Mon Jul 22, 2019 4:06 pm
Forum: Scripting
Topic: Still getting old API '=ret' on 6.45.1 [SOLVED]
Replies: 5
Views: 2660

Re: Still getting old API '=ret' on 6.45.1 [SOLVED]

I don't think that API is returning =ret, it looks more like a bug in that C code.
To verify what exactly RouterOS is sending back run a packet sniffer.
by mrz
Fri Jul 19, 2019 2:05 pm
Forum: Forwarding Protocols
Topic: Can't establish LDP session between two Mikrotik routers
Replies: 7
Views: 2351

Re: Can't establish LDP session between two Mikrotik routers

As I mentioned in my previous post. If you are adding interfaces which are part of the bridge, then LDP interface should be "bridge", not a slave.
by mrz
Thu Jul 18, 2019 2:23 pm
Forum: General
Topic: how to display Password of PPPOE user from a Mikrotik router?
Replies: 5
Views: 2177

Re: how to display Password of PPPOE user from a Mikrotik router?

This menu is not supposed to show any passwords. Go to "secrets" tab if users are authenticated locally.
by mrz
Thu Jul 18, 2019 1:46 pm
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 150
Views: 73003

Re: v6.46beta [testing] is released!

And why it is wrong? Nexthop is the relay so MAC should be fro the relay. By the way adding ARP in relay setups is useless, since clients are not in the same broadcast domain.
by mrz
Thu Jul 18, 2019 1:40 pm
Forum: Forwarding Protocols
Topic: Can't establish LDP session between two Mikrotik routers
Replies: 7
Views: 2351

Re: Can't establish LDP session between two Mikrotik routers

LDP interface configuration is invalid. Are those interfaces slaves? if yes then you need to add master.
by mrz
Wed Jul 17, 2019 2:30 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 179553

Re: RouterOS v7.0 beta1 - when?

Will not run, you need one core per pixel.
by mrz
Mon Jul 15, 2019 3:59 pm
Forum: General
Topic: Loging not working with multiple topics?
Replies: 9
Views: 1933

Re: Loging not working with multiple topics?

As I mentioned log message with topic "error AND warning AND info" does not exist in real world.
Just look at your log messages and see how topics are used, then you will understand.
by mrz
Mon Jul 15, 2019 3:34 pm
Forum: Forwarding Protocols
Topic: OSPF state changes on long Ethernet POE leads
Replies: 2
Views: 1825

Re: OSPF state changes on long Ethernet POE leads

First you need to find out the reason for state changes. Is it a link flap?
by mrz
Mon Jul 15, 2019 3:04 pm
Forum: General
Topic: Loging not working with multiple topics?
Replies: 9
Views: 1933

Re: Loging not working with multiple topics?

Not outdated, I do not see example with topics="error,warning,info"
/system logging add topics=ntp,debug,!packet
This is completely different of what you have configured.

Example in wiki will log all log entries with topics ntp AND debug AND NOT packet, in short NTP debug packets.
by mrz
Fri Jul 12, 2019 11:44 am
Forum: General
Topic: Loging not working with multiple topics?
Replies: 9
Views: 1933

Re: Loging not working with multiple topics?

Not outdated, I do not see example with topics="error,warning,info"
by mrz
Thu Jul 11, 2019 5:42 pm
Forum: Scripting
Topic: bypass script errors/wrong commands
Replies: 15
Views: 2547

Re: bypass script errors/wrong commands

Most likely interface doe snot exist yet when you execute script at startup.
Add delay or loop that waits until interfaces appear.
by mrz
Thu Jul 11, 2019 1:20 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

Anyone who had problems with OSPF (/routing ospf lsa print triggers busy loop) in this version please try 6.46beta9 if possible.
by mrz
Thu Jul 11, 2019 10:18 am
Forum: Scripting
Topic: bypass script errors/wrong commands
Replies: 15
Views: 2547

Re: bypass script errors/wrong commands

Basic example:
:global setPoe [:parse ":put \"set poe settings here\"!"];
:if ($poeExist = 1) do={
  $setPoe;
}
by mrz
Wed Jul 10, 2019 2:50 pm
Forum: Scripting
Topic: bypass script errors/wrong commands
Replies: 15
Views: 2547

Re: bypass script errors/wrong commands

It is a syntax error if parameter does not exist, and you cannot catch these errors at runtime.
One way is to use "parse" command to execute command line based on parameters, which check if poe should exist on this router.
by mrz
Wed Jul 10, 2019 12:31 pm
Forum: General
Topic: VRF route mark question
Replies: 1
Views: 487

Re: VRF route mark question

Routing mark names are local to your router, other devices in the network do not see VRF names.
by mrz
Tue Jul 09, 2019 3:43 pm
Forum: Beginner Basics
Topic: DHCP option by rule [SOLVED]
Replies: 4
Views: 1084

Re: DHCP option by rule [SOLVED]

Or use vendor class id to give specific option sets based on ID client is sending.
by mrz
Tue Jul 09, 2019 12:54 pm
Forum: Beginner Basics
Topic: IPSec features in default configuration
Replies: 4
Views: 1208

Re: IPSec features in default configuration

ipsec-policy=out,none menas that rule will NAT only those connections that are not matched by any ipsec policy.
by mrz
Tue Jul 09, 2019 10:44 am
Forum: General
Topic: Loging not working with multiple topics?
Replies: 9
Views: 1933

Re: Loging not working with multiple topics?

logging expects that log entry will have all three of those topics. I have never seen log entry with topics, for example "info,warning,error,firewall" .
Logic is "info and warning and error"

If you want to log all three occurrences, then you need to add three separate rules.
by mrz
Mon Jul 08, 2019 7:02 pm
Forum: General
Topic: DNS wiki example not work. Why?
Replies: 3
Views: 619

Re: DNS wiki example not work. Why?

instead of "name" use "regexp" if you are adding regexp.
by mrz
Mon Jul 08, 2019 2:07 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 59131

Re: RB4011: wlan1 disabling itself [SOLVED]

Is your IPTV multicast or unicast?
by mrz
Mon Jul 08, 2019 10:57 am
Forum: Beginner Basics
Topic: /ip firewall NAT on bridge with use-ip-firewall not working
Replies: 4
Views: 914

Re: /ip firewall NAT on bridge with use-ip-firewall not working

If there is no IP address on an interface, then NAT cannot translate.
by mrz
Mon Jul 08, 2019 10:53 am
Forum: Beginner Basics
Topic: DHCPv6-client
Replies: 1
Views: 460

Re: DHCPv6-client

Are you sure that there is a DHCP server? Most likely provider is giving out stateless address and you do not need dhcp client to receive this address.
See description here:
https://wiki.mikrotik.com/wiki/Manual:I ... figuration
by mrz
Mon Jul 08, 2019 10:31 am
Forum: Beginner Basics
Topic: IPSec features in default configuration
Replies: 4
Views: 1208

Re: IPSec features in default configuration

1. What ipsec-policy parameter do is described in the firewall manual: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter#Properties 2. Now that you know what ipsec-policy means, read here why packets matching ipsec policy must not be NATed https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#NAT_an...
by mrz
Mon Jul 08, 2019 10:18 am
Forum: Forwarding Protocols
Topic: DHCP relay over OSPF!!
Replies: 1
Views: 1668

Re: DHCP relay over OSPF!!

It doesn't matter OSPF or static routing, as long as relay can reach the server.
by mrz
Fri Jul 05, 2019 6:26 pm
Forum: General
Topic: IPsec peer identity verification when using IKEv2 with RSA authentication
Replies: 1
Views: 752

Re: IPsec peer identity verification when using IKEv2 with RSA authentication

It verifies that client cert is signed by the same chain. There is no need to have client cert on the server.
by mrz
Thu Jul 04, 2019 1:13 pm
Forum: Announcements
Topic: Winbox v3.19 released!
Replies: 33
Views: 17929

Re: Winbox v3.19 released!

- drag and drop for me work only with direction from the desktop environment to the "wine winbox". The opposite direction (from winbox to the kde/xfce) not work for me. Try to copy files while logged using ip address, not mac address.
Right click on the file and choose "Download", problem solved.
by mrz
Thu Jul 04, 2019 1:02 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

@arsalansiddiqui you need to fix your API wrapper so that login parameters are sent as described in the wiki.
Here is another topic
viewtopic.php?f=9&t=136475
by mrz
Wed Jul 03, 2019 12:18 pm
Forum: General
Topic: Block .exe from local network
Replies: 5
Views: 739

Re: Block .exe from local network

Proxy can be used to deny access to specific file types.
by mrz
Tue Jul 02, 2019 4:54 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

In terms of connection tracking there will be always the one that initiates/creates (call it whatever you like) new connection. If remote device trying to initiate connection it should not be accepted by "establish/related" rule because connection does not exist yet. That is what happened before the...
by mrz
Tue Jul 02, 2019 4:12 pm
Forum: General
Topic: Packet sniffer size limit
Replies: 2
Views: 608

Re: Packet sniffer size limit

Limit is 10..4294967295 KiB
by mrz
Tue Jul 02, 2019 4:11 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

As far as I understand you are trying to configure server. Server requires RADIUS server with EAP support. Locally on the router it is not supported.
by mrz
Tue Jul 02, 2019 3:57 pm
Forum: General
Topic: NordVpn and mikrotik?
Replies: 22
Views: 5908

Re: NordVpn and mikrotik?

Probably can be updated with a script if assigned IP has changed.
by mrz
Tue Jul 02, 2019 1:10 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

It is wrong if initiator is remote router.
by mrz
Tue Jul 02, 2019 1:03 pm
Forum: General
Topic: Mikrotik API
Replies: 1
Views: 814

Re: Mikrotik API

Make sure you are using correct authentication method:
https://wiki.mikrotik.com/wiki/Manual:API#Initial_login
by mrz
Tue Jul 02, 2019 1:01 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 179553

Re: RouterOS v7.0 beta1 - when?

Right ... 5.1.11 released 17 Jun 2019 ...
by mrz
Tue Jul 02, 2019 12:50 pm
Forum: General
Topic: ROUTEROS V6 RC AND V7 BETA
Replies: 3
Views: 1428

Re: ROUTEROS V6 RC AND V7 BETA

No, FRR will not be integrated. We already working on new routing code that will outperform FRR in certain scenarios.
by mrz
Tue Jul 02, 2019 12:48 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

!) ike2 - added support for EAP authentication methods (eap-tls, eap-ttls, eap-peap, eap-mschapv2) as initiator; Since this is "as initiator," can I assume this isn't supported for running as a roadwarrior config? If so, when is support for that coming, if at all? Road warrior client is always an i...
by mrz
Tue Jul 02, 2019 12:46 pm
Forum: Scripting
Topic: Mikrotik API call not working [SOLVED]
Replies: 34
Views: 13332

Re: Mikrotik API call not working [SOLVED]

I didn't trying to hype on that, but I strongly believe that another important notice about old-style API authentication deprecation starts with this release will be very pleased for many MikroTik users.
Thank you.
We will add note regarding API, too.
by mrz
Tue Jul 02, 2019 12:44 pm
Forum: Forwarding Protocols
Topic: BGP load-balance per-packet
Replies: 3
Views: 2123

Re: BGP load-balance per-packet

True ECMP for BGP is currently unsupported, but if for example two links point to the same remote router, where you want to run BGP, then you can set up single multihop peer over ECMP.
See example here:
https://wiki.mikrotik.com/wiki/Manual:B ... interfaces
by mrz
Mon Jul 01, 2019 2:52 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 179553

Re: RouterOS v7.0 beta1 - when?

If you are talking about SACK panic, then all Linux version starting from 2.6.29 are affected.
by mrz
Mon Jul 01, 2019 2:06 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

What winbox version?
by mrz
Mon Jul 01, 2019 2:02 pm
Forum: Scripting
Topic: Mikrotik API call not working [SOLVED]
Replies: 34
Views: 13332

Re: Mikrotik API call not working [SOLVED]

Not true. See how it is done in our api example client:
https://wiki.mikrotik.com/wiki/Manual:A ... ple_client
by mrz
Mon Jul 01, 2019 1:06 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

That is an option for RouterOS OVPN clients, for which this exact change apply. It has nothing to do with non-RouterOS OVPN client.
by mrz
Mon Jul 01, 2019 1:04 pm
Forum: Scripting
Topic: Mikrotik API call not working [SOLVED]
Replies: 34
Views: 13332

Re: Mikrotik API call not working [SOLVED]

Important note!!!
Due to removal of compatibility with old version passwords in this version...
...
!) user - removed insecure password storage;
...
by mrz
Mon Jul 01, 2019 1:00 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 112083

Re: v6.45.1 [stable] is released!

@roe1974 Simple:
verify-server-certificate=yes
by mrz
Mon Jul 01, 2019 12:54 pm
Forum: Scripting
Topic: Mikrotik API call not working [SOLVED]
Replies: 34
Views: 13332

Re: Mikrotik API call not working [SOLVED]

There is already important note due to removal of compatibility with old version passwords.
Third party software should have been fixed long time ago ,new authentication method was introduced back in May 2018.
by mrz
Mon Jul 01, 2019 12:27 pm
Forum: Scripting
Topic: Mikrotik API call not working [SOLVED]
Replies: 34
Views: 13332

Re: Mikrotik API call not working [SOLVED]

Yes, make sure you are using new authentication method.
by mrz
Mon Jul 01, 2019 9:58 am
Forum: Scripting
Topic: Mikrotik API call not working [SOLVED]
Replies: 34
Views: 13332

Re: Mikrotik API call not working [SOLVED]

Make sure your PHP code is using new authentication method:
https://wiki.mikrotik.com/wiki/Manual:API#Initial_login
by mrz
Thu Jun 27, 2019 12:49 pm
Forum: Forwarding Protocols
Topic: OSPF Linux MikroTik
Replies: 4
Views: 2501

Re: OSPF Linux MikroTik

NBMA should work if multicast is blocked. It is possible that provider is blocking not multicast, but OSPF.
by mrz
Fri Jun 21, 2019 4:40 pm
Forum: Scripting
Topic: Bug in script variables?
Replies: 7
Views: 1424

Re: Bug in script variables?

Problem looks to be specific to your router: [admin@3C22-atombumba] > /ip dhcp-server lease print count-only where server~"DHCP-Pool-vlan1-Home" 18 [admin@3C22-atombumba] > /ip dhcp-server lease print count-only where server~"vlan1-Home" 18 [admin@3C22-atombumba] > /ip dhcp-server lease print count-...
by mrz
Fri Jun 21, 2019 4:34 pm
Forum: General
Topic: AccessPoint Router test video series - English subtitles
Replies: 4
Views: 780

Re: AccessPoint Router test video series - English subtitles

IPSEC results seems a bit off on all routers. What config you are using?
by mrz
Mon Jun 17, 2019 1:27 pm
Forum: General
Topic: DHCPv6 op 79 - Client Link-Layer Address Option
Replies: 6
Views: 1306

Re: DHCPv6 op 79 - Client Link-Layer Address Option

Options looks useful and not very hard to implement.
by mrz
Fri Jun 14, 2019 1:22 pm
Forum: Scripting
Topic: :tobool not working as expected
Replies: 4
Views: 1429

Re: :tobool not working as expected

Currently :tobool does not work at all. If you could list all values that you would like to convert then we can try to implement it.
by mrz
Fri Jun 14, 2019 12:43 pm
Forum: General
Topic: Feature request: Append values to configuration
Replies: 11
Views: 2521

Re: Feature request: Append values to configuration

Works for me, if in your script you try to add new interface to the VRF right after it is created, then make sure that you add some delay or check if interface exist. Interface may not appear right away if CPU has some load.
by mrz
Thu Jun 13, 2019 10:57 am
Forum: General
Topic: Feature request: Append values to configuration
Replies: 11
Views: 2521

Re: Feature request: Append values to configuration

Post /ip route vrf print output
by mrz
Wed Jun 12, 2019 10:10 am
Forum: General
Topic: Feature request: Append values to configuration
Replies: 11
Views: 2521

Re: Feature request: Append values to configuration

One of the interfaces you are trying to add does not exist, so you get an error.
by mrz
Tue Jun 11, 2019 5:05 pm
Forum: Forwarding Protocols
Topic: ❗️❓ UNSTABLE VPLS on Wireless networks
Replies: 13
Views: 3030

Re: ❗️❓ UNSTABLE VPLS on Wireless networks

Agree, check OSPF stability over particular wireless link.
by mrz
Mon Jun 10, 2019 2:44 pm
Forum: Scripting
Topic: how to get .id via python
Replies: 5
Views: 1511

Re: how to get .id via python

thanks for your reply but I not looking for OID but rather .id test = api(cmd='/ip/firewall/address-list/print') id = api(cmd='/=.proplist=.id') brings: librouteros.exceptions.MultiTrapError: no such command or directory (=.proplist=.id), no such command Most likely you are doing message encoding w...
by mrz
Mon Jun 10, 2019 11:52 am
Forum: Scripting
Topic: how to get .id via python
Replies: 5
Views: 1511

Re: how to get .id via python

To get only specific parameter via API use proplist, wiki has all the info you need:
https://wiki.mikrotik.com/wiki/Manual:A ... escription
And here is example:
https://wiki.mikrotik.com/wiki/Manual:API#OID
by mrz
Fri Jun 07, 2019 9:49 am
Forum: Forwarding Protocols
Topic: main diffrence between weight & local pref?
Replies: 5
Views: 2097

Re: main diffrence between weight & local pref?

Maybe only with scripts.
by mrz
Thu Jun 06, 2019 5:22 pm
Forum: Forwarding Protocols
Topic: main diffrence between weight & local pref?
Replies: 5
Views: 2097

Re: main diffrence between weight & local pref?

I do not think that cause of such a different performance is caused just by changing whether you set weight or pref-src. There is no significant difference between both in terms of performance. Total time can be affected which peer starts to load routes first and if these routes will be best routes ...
by mrz
Thu Jun 06, 2019 3:45 pm
Forum: Forwarding Protocols
Topic: main diffrence between weight & local pref?
Replies: 5
Views: 2097

Re: main diffrence between weight & local pref?

The main difference is that local-pref can be advertised to remote peers, weight cannot. If you want to control selection only locally on single router then use weight.
Regarding performance I doubt that you will notice few second difference on total amount of time needed to process 4M routes.
by mrz
Wed Jun 05, 2019 11:24 am
Forum: General
Topic: Feature request: full crypto speedup for MT7621 chipset (e.g. hEX S)
Replies: 9
Views: 1906

Re: Feature request: full crypto speedup for MT7621 chipset (e.g. hEX S)

Currently there is specific reason for this. maybe in the future you will see HW encryption not only for IpSec.
by mrz
Wed Jun 05, 2019 11:20 am
Forum: Forwarding Protocols
Topic: route ospf error -> Discarding packet: locally originated
Replies: 25
Views: 32450

Re: route ospf error -> Discarding packet: locally originated

MT is saying it is not a problem of OSPF. Packet is sent back to the router by some device. Loop, switch is between is leaking vlan packets from other vlans, etc, etc... OSPF is just processing packets that it receives.
by mrz
Tue Jun 04, 2019 4:59 pm
Forum: Forwarding Protocols
Topic: How to Copy dynamic Route to another route table
Replies: 6
Views: 3180

Re: How to Copy dynamic Route to another route table

You can use VRFs to install to specific table and advertised from it.
by mrz
Tue Jun 04, 2019 4:57 pm
Forum: Forwarding Protocols
Topic: Mikrotik BGP Advertising Issue
Replies: 4
Views: 2236

Re: Mikrotik BGP Advertising Issue

Advertisements menu shows only prefixes that are advertised to remote peers, not the ones received.
by mrz
Tue Jun 04, 2019 3:14 pm
Forum: General
Topic: prerouting download
Replies: 2
Views: 526

Re: prerouting download

Because typically you do not want to shape traffic, which destination is router itself, together with traffic to the local network. If you mark in forward or post routing it will ensure that you will not catch any input traffic.
by mrz
Fri May 17, 2019 5:12 pm
Forum: General
Topic: SSTP + Win7 + Self signed cert.
Replies: 6
Views: 869

Re: SSTP + Win7 + Self signed cert.

Windows client does not use client certificate. Only server side verification is happening.
by mrz
Tue May 14, 2019 11:56 am
Forum: Scripting
Topic: Built in function library
Replies: 60
Views: 26486

Re: Built in function library

You can replace any symbol in your application.
by mrz
Mon May 13, 2019 4:15 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

It does not depend on specific number. You can consider large as 10k+
by mrz
Thu May 09, 2019 10:52 am
Forum: Forwarding Protocols
Topic: RIP with multiple VRFs, multiple default gateways with different routing marks
Replies: 2
Views: 1820

Re: RIP with multiple VRFs, multiple default gateways with different routing marks

You can't currently RIP works only with main table.
You should consider other routing protocol that is capable of running in other routing tables (OSPF, BGP)
by mrz
Thu May 02, 2019 4:53 pm
Forum: Scripting
Topic: Mikrotik API Integration via RAW TCP CLIENT Need help
Replies: 3
Views: 753

Re: Mikrotik API Integration via RAW TCP CLIENT Need help

No, example as per API documentation uses post 6.43 login method by default * on first attempt sends /login =name=xxx =password=yyy * if it returns !trap exit * if it returns "=ret", then fall back to pre 6.43 login method you can see this in "login" function. def login(self, username, pwd): for rep...
by mrz
Thu May 02, 2019 4:39 pm
Forum: General
Topic: Dynamic address lists security hole
Replies: 5
Views: 870

Re: Dynamic address lists security hole

Generate a supout file at the time when you have added dynamic 0.0.0.0/0 entry and send it to support.
by mrz
Thu May 02, 2019 3:15 pm
Forum: Scripting
Topic: Mikrotik API Integration via RAW TCP CLIENT Need help
Replies: 3
Views: 753

Re: Mikrotik API Integration via RAW TCP CLIENT Need help

There is a python example client that works with both pre and post 6.43 versions.

Look at the code, it will show exactly what you need to do
https://wiki.mikrotik.com/wiki/Manual:A ... ple_client
by mrz
Thu May 02, 2019 3:12 pm
Forum: Forwarding Protocols
Topic: [srcnat] strange entry = "!1000,32"
Replies: 2
Views: 2029

Re: [srcnat] strange entry = "!1000,32"

This will match first 1000 connections per destination.
by mrz
Thu May 02, 2019 10:41 am
Forum: Forwarding Protocols
Topic: Mikrotik ECMP - how nexthop is calculated? Hashing?
Replies: 2
Views: 1896

Re: Mikrotik ECMP - how nexthop is calculated? Hashing?

It uses hashing: Source Address, Destination Address, Protocol, Source Port, Destination Port

That is if you are talking about IPv4
by mrz
Thu May 02, 2019 10:28 am
Forum: General
Topic: Feature Request: OpenVPN [ovpn] udp tunnels
Replies: 250
Views: 102135

Re: Feature Request: OpenVPN [ovpn] udp tunnels

You must be from alternate future.
by mrz
Thu Apr 18, 2019 2:21 pm
Forum: Forwarding Protocols
Topic: OSPF type 0x09 error
Replies: 6
Views: 3623

Re: OSPF type 0x09 error

*) ospf - added support for link scope opaque LSAs (Type 9) for OSPFv2;

viewtopic.php?f=21&t=146087&p=727144#p727144
by mrz
Fri Apr 12, 2019 2:48 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 47358

Re: UKNOF 43 CVE

Anyone who still had problems with small RAMs -> viewtopic.php?f=21&t=146087&p=726299#p726296
by mrz
Thu Apr 11, 2019 9:50 am
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 29683

Re: v6 RC and v7 BETA

Please clarify what is "proper IKEv2/IPSEC"?
by mrz
Mon Apr 08, 2019 1:17 pm
Forum: General
Topic: mikrotik scp/sftp client to transfer file between MT
Replies: 13
Views: 13630

Re: mikrotik scp/sftp client to transfer file between MT

mode option is deprecated, left for compatibility with older scripts.
Use url=sftp://
by mrz
Mon Apr 08, 2019 1:15 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

@eworm with url=sftp://xxx.xx/
by mrz
Fri Apr 05, 2019 11:31 am
Forum: General
Topic: IPV6 passthrough rules
Replies: 14
Views: 3307

Re: IPV6 passthrough rules

It is not going to work properly on RouterOS if you add addresses on different interfaces from the same subnet. The same applies to ipv4, too.
So in summary setup shown in Asus System Logs i snot possible on RouterOS.
by mrz
Thu Apr 04, 2019 5:21 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 47358

Re: UKNOF 43 CVE

It is an upgrade problem because of no free space on the router, not related to this thread at all.
by mrz
Thu Apr 04, 2019 5:14 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 47358

Re: UKNOF 43 CVE

Completely unrelated to the topic.
by mrz
Thu Apr 04, 2019 5:07 pm
Forum: General
Topic: IPV6 passthrough rules
Replies: 14
Views: 3307

Re: IPV6 passthrough rules

Ok then it is important to know what kind of configuration you had on Asus, by looking at asus config they allow you to choose between: native tunnel and static if it is native then you also have options to use dhcp-pd or static. All of this can be translated to routeros configuration if you know ex...
by mrz
Thu Apr 04, 2019 2:24 pm
Forum: General
Topic: IPV6 passthrough rules
Replies: 14
Views: 3307

Re: IPV6 passthrough rules

Passthrough most likely means that you need to bridge WAN and LAN port, so that client can directly get the address from provider.
What was the original config on the Asus router?
by mrz
Mon Apr 01, 2019 10:25 am
Forum: General
Topic: VPLS features
Replies: 2
Views: 863

Re: VPLS features

And please add MTU > 1500 for BGP VPLS
Already possible with pw-mtu
by mrz
Fri Mar 29, 2019 4:56 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 47358

Re: UKNOF 43 CVE

It should be enough to limit on edge router, since it already limits to 2 new connections every second, unless routers further along the path have less than 100MB free ram, then probably you will need to limit even more on that specific router.
by mrz
Thu Mar 28, 2019 3:22 pm
Forum: General
Topic: Mikrotik: Change the default Powerbox config!
Replies: 16
Views: 2434

Re: Mikrotik: Change the default Powerbox config!

Power box is the same RB750P, so they share the same configuration. Since there were not a lot of complains, this configuration is being kept.
by mrz
Thu Mar 28, 2019 2:36 pm
Forum: General
Topic: Mikrotik: Change the default Powerbox config!
Replies: 16
Views: 2434

Re: Mikrotik: Change the default Powerbox config!

There is always possibility to set your own default config before putting it in the tower.
by mrz
Thu Mar 21, 2019 2:39 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

You can specify DHCP option set per DHCP network.
by mrz
Tue Mar 19, 2019 6:26 pm
Forum: Forwarding Protocols
Topic: Bgp filter for vpnv4 routes?
Replies: 3
Views: 1949

Re: Bgp filter for vpnv4 routes?

Unfortunately no, you can match only RT.
by mrz
Tue Mar 19, 2019 12:30 pm
Forum: Forwarding Protocols
Topic: Bgp filter for vpnv4 routes?
Replies: 3
Views: 1949

Re: Bgp filter for vpnv4 routes?

Add in/out filter chain in BGP VRF instance configuration and then on those chains you will be able to match by prefix.
by mrz
Mon Mar 18, 2019 2:28 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

In what scenario? If it's road warrior (typical when src is unknown or when src has dynamic IP) then policies should be already auto generated.
by mrz
Thu Mar 14, 2019 4:59 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

IKE2 rfc states the use of RSA.
What would be the client devices that support EC? Why exactly you need this?
by mrz
Thu Mar 14, 2019 2:54 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

EC certificates can be used only for www services. Ipsec does not support them.
by mrz
Thu Mar 14, 2019 10:01 am
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 54942

Re: Statement on Vault 7 document release

upgrade ≠ reset configuration

On upgrade system files are replaced with new ones.
by mrz
Wed Mar 13, 2019 5:36 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 54942

Re: Statement on Vault 7 document release

I think there is a lot of confusion what "reset configuration" do, this command wipes all '''configuration''' and thats it. It does not rely on script that you are talking about. "Reset configuration" also has nothing to do with clearing linux file system, it is called "reset configuration" for a re...
by mrz
Wed Mar 13, 2019 3:54 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

check/ip dhcp-server vendor-class-id menu
by mrz
Tue Mar 12, 2019 5:36 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 93385

Re: v6.45beta [testing] is released!

@buset1974 not in v6
by mrz
Tue Mar 12, 2019 5:33 pm
Forum: Forwarding Protocols
Topic: nexthop unreachable via iBGP
Replies: 1
Views: 1746

Re: nexthop unreachable via iBGP

Yes, that is correct, you need to run IGP inside your AS.
For simpler setups you could also use nexthop-choice=force-self in bgp peer settings.
by mrz
Mon Mar 11, 2019 9:17 am
Forum: Forwarding Protocols
Topic: PPTP problem - empty winbox [SOLVED]
Replies: 7
Views: 3080

Re: PPTP problem - empty winbox [SOLVED]

MTU issue, set up mangle rules to reduce TCP MSS.
by mrz
Thu Mar 07, 2019 5:30 pm
Forum: Forwarding Protocols
Topic: BUG - 4-byte ASN and BGP Communities on Route Filters
Replies: 3
Views: 2080

Re: BUG - 4-byte ASN and BGP Communities on Route Filters

RFC states community attribute length
https://tools.ietf.org/html/rfc1997

Upstream peer cannot use Community attribute for what you described. Either they are using large community attribute or different method.
by mrz
Thu Mar 07, 2019 4:31 pm
Forum: Forwarding Protocols
Topic: BUG - 4-byte ASN and BGP Communities on Route Filters
Replies: 3
Views: 2080

Re: BUG - 4-byte ASN and BGP Communities on Route Filters

BGP community attribute is limited to 4bytes in total by the standard. Different parameter is needed, for example large BGP community,which you currently cannot set. It is planned to add in the future, but I cannot tell when exactly. BTW community is administrative value, it does not mean that commu...
by mrz
Thu Mar 07, 2019 2:02 pm
Forum: General
Topic: BUG – v.6.44 on ARM boxes RB3011 is losing IPSEC configuration
Replies: 7
Views: 1443

Re: BUG – v.6.44 on ARM boxes RB3011 is losing IPSEC configuration

It is not the system files but configuration.
by mrz
Tue Mar 05, 2019 5:06 pm
Forum: Scripting
Topic: POST Request with fetch
Replies: 75
Views: 39678

Re: POST Request with fetch

http-header-field="Content-Type: application/json"
by mrz
Tue Mar 05, 2019 3:27 pm
Forum: Forwarding Protocols
Topic: EoIPv6 Tunnel flapping when used to route full BGP feed
Replies: 4
Views: 1901

Re: EoIPv6 Tunnel flapping when used to route full BGP feed

dst=n:n:n:67::1 you should know the gateway to your ISP. It is impossible to guess from your provided config.
by mrz
Tue Mar 05, 2019 12:10 pm
Forum: General
Topic: About NULL in Layer7
Replies: 5
Views: 1584

Re: About NULL in Layer7

Unfortunately current regexp engine does not allow to match \\x00.
by mrz
Tue Mar 05, 2019 11:57 am
Forum: General
Topic: ECDSA cert support?
Replies: 5
Views: 1927

Re: ECDSA cert support?

Added support in v6.45beta6
by mrz
Tue Mar 05, 2019 11:03 am
Forum: Forwarding Protocols
Topic: EoIPv6 Tunnel flapping when used to route full BGP feed
Replies: 4
Views: 1901

Re: EoIPv6 Tunnel flapping when used to route full BGP feed

You are establishing BGP over the tunnel, BGP installs routes and tries to route traffic over the tunnel including tunnel traffic itself, which causes internal loop. Add static route to tunnel remote end to fix the problem.
by mrz
Mon Mar 04, 2019 12:04 pm
Forum: General
Topic: Recursive Routes - Need Help
Replies: 7
Views: 1440

Re: Recursive Routes - Need Help

1. No you need to configure route properly.
/ip route add dst-address87.190.23.57/32 gateway=93.240.147.6x

2. It doesn't work for the same reason I mentioned in previous post.
by mrz
Mon Mar 04, 2019 10:27 am
Forum: Scripting
Topic: What's wrong with "where" ? [SOLVED]
Replies: 3
Views: 920

Re: What's wrong with "where" ? [SOLVED]

When you are trying to match a string, always use quotes. Console tries to guess the type of the variable, but sometimes it is not possible and you get unexpected result.
by mrz
Mon Mar 04, 2019 10:23 am
Forum: General
Topic: Recursive Routes - Need Help
Replies: 7
Views: 1440

Re: Recursive Routes - Need Help

Recursive route cannot be resolved if gateway is interface (not IP address). It is suggested to avoid using gateway interfaces on broadcast networks, since it can lead to unexpected behavior.
by mrz
Thu Feb 28, 2019 6:07 pm
Forum: Forwarding Protocols
Topic: Vlans + VRRP + Multiple Public IP addresses
Replies: 10
Views: 3255

Re: Vlans + VRRP + Multiple Public IP addresses

VRRP cannot work without IP on physical interface unless it is VRRP v3 IPv6
by mrz
Thu Feb 28, 2019 1:22 pm
Forum: General
Topic: /certificate - certs issued on 6.44 can't be imported to long-term 6.42.12
Replies: 2
Views: 494

Re: /certificate - certs issued on 6.44 can't be imported to long-term 6.42.12

Thanks, problem confirmed, will fix it as soon as possible.
by mrz
Thu Feb 28, 2019 1:18 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 48544

Re: v6.44 [stable] is released!

Works as expected: [admin@4p_DUT_DISC Lite5] /interface wireless> set band=5ghz-n/ac Script Error: action cancelled [admin@4p_DUT_DISC Lite5] /interface wireless> set 0 band=5ghz-n/ac failure: bad band or frequency, see 'wireless info' for supported channels [admin@4p_DUT_DISC Lite5] /interface wire...
by mrz
Thu Feb 28, 2019 12:40 pm
Forum: Beginner Basics
Topic: ipsec IKEv1 to Zyxel USG [SOLVED]
Replies: 2
Views: 1195

Re: ipsec IKEv1 to Zyxel USG [SOLVED]

I would recommend to learn how to set up IPSec properly. You can start by looking at configuration examples from the manual:
https://wiki.mikrotik.com/wiki/Manual:I ... ion_Guides
by mrz
Thu Feb 28, 2019 12:06 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 48544

Re: v6.44 [stable] is released!

Incorrect time is cosmetic Winbox bug noticed when there are multiple Winbox instances open. If you check in terminal, time is reported correctly.
by mrz
Thu Feb 28, 2019 10:32 am
Forum: Forwarding Protocols
Topic: Vlans + VRRP + Multiple Public IP addresses
Replies: 10
Views: 3255

Re: Vlans + VRRP + Multiple Public IP addresses

You should set up one VRRP per physical interface.

Regarding loosing 3 IPs per subnet, not correct, you will loose only 2 IPs on a subnet that is running VRRP on IPv4. Or set up VRRP v3 on IPv6 an don't loose any IPs.
by mrz
Thu Feb 28, 2019 10:18 am
Forum: Forwarding Protocols
Topic: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"
Replies: 5
Views: 2191

Re: Same Subnets on adjacent routers getting: Ospf error "Discarding packet: Locally originated"

Run OSPF only on one subet connecting both routers. Check whether RouterIDs are unique.
by mrz
Thu Feb 28, 2019 10:15 am
Forum: Forwarding Protocols
Topic: IPv6 DHCP Relay with PD not installing route
Replies: 7
Views: 3448

Re: IPv6 DHCP Relay with PD not installing route

if you encounterd a bug contact Mikrotik support.
by mrz
Thu Feb 28, 2019 10:13 am
Forum: Forwarding Protocols
Topic: MPLS/VPLS ECMP
Replies: 9
Views: 2789

Re: MPLS/VPLS ECMP

Two options,
* script that checks if dynamic interface was changed;
* use bridge per dynamic interface and in static configuration work with bridge interface.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 21