Community discussions

Search found 5453 matches

by mrz
Mon Apr 23, 2018 6:44 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature Req: IKEv2 server and client
Replies: 279
Views: 57626

Re: Feature Req: IKEv2 server and client

Did you configured IOS and ROS as stated in these notes?
https://wiki.mikrotik.com/wiki/Manual:I ... figuration
by mrz
Mon Apr 23, 2018 5:54 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port
Replies: 128
Views: 28128

Re: Advisory: Vulnerability exploiting the Winbox port

!) winbox - fixed vulnerability that allowed to gain access to an unsecured router; Shifting of the blame onto users... what else are we supposed to use for remote management? Where do you see shifting blame on the users? It is information for users to know that routers are safe against this vulner...
by mrz
Mon Apr 23, 2018 4:53 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 34
Views: 2519

Re: v6.42.1 [current]

by mrz
Mon Apr 23, 2018 4:30 pm
Forum: General
Topic: VRF for management
Replies: 3
Views: 742

Re: VRF for management

We have plans to change this in the future, but most likely it will not happen in ROS v6
by mrz
Mon Apr 23, 2018 10:19 am
Forum: RouterOS v6 RC and v7 BETA
Topic: [Feature Request] - Support RFC6164
Replies: 5
Views: 1498

Re: [Feature Request] - Support RFC6164

You can assign /127 address and it works, however there is a problem if this address is used as gateway. Gateways from /127 addresses cannot be resolved.
by mrz
Mon Apr 23, 2018 10:16 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature Req: IKEv2 server and client
Replies: 279
Views: 57626

Re: Feature Req: IKEv2 server and client

@MikroTikFan
What are you waiting? IKE2 was backported to v6 long time ago.
by mrz
Mon Apr 23, 2018 10:13 am
Forum: Forwarding Protocols
Topic: MPLS - massive throughput difference on CHR when using explicit nulls
Replies: 50
Views: 3417

Re: MPLS - massive throughput difference on CHR when using explicit nulls

Hyper-V works because it does not assemble packets into 64k buffers. But this assembly happens only for traffic which source and destination is also virtual guest. If destination is physical router outside VM environment then there should be no problem with MPLS.
by mrz
Fri Apr 20, 2018 5:19 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Can't upgrade Routerboard version
Replies: 8
Views: 537

Re: Can't upgrade Routerboard version

From your screenshot upgrade firmware shows 3.33, do you have custom firmware file uploaded on the router? Check files menu
by mrz
Thu Apr 19, 2018 6:21 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 128
Views: 9999

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

@ mlenhart Read warning that was given to you when your post was deleted. If you start a rant in other completely unrelated topics about the problem which already has its own topic, then of course such post will be removed. Constructive critics and suggestions are welcome in topics where they belong...
by mrz
Thu Apr 19, 2018 5:52 pm
Forum: Announcements
Topic: v6.42 [current]
Replies: 146
Views: 12592

Re: v6.42 [current]

Do you actually reported to support?
If it is on the same router, then for me it looks like problem with interface driver not separate processes.
by mrz
Thu Apr 19, 2018 10:21 am
Forum: RouterOS v6 RC and v7 BETA
Topic: Can not upgrade RB1100Dx4 to 6.42 due to double package installation
Replies: 3
Views: 187

Re: Can not upgrade RB1100Dx4 to 6.42 due to double package installation

It should not be possible to install double packages. Did you installed second package in one of the RC versions?
by mrz
Wed Apr 18, 2018 5:59 pm
Forum: Forwarding Protocols
Topic: BGP max-prefix-restart-time
Replies: 2
Views: 100

Re: BGP max-prefix-restart-time

This parameter works only when peer was disconnected due to max prefix limit reached.
by mrz
Wed Apr 18, 2018 12:55 pm
Forum: General
Topic: IPV6 Help
Replies: 2
Views: 146

Re: IPV6 Help

Here is an example how to use received pool
https://wiki.mikrotik.com/wiki/Manual:I ... r_local_RA
by mrz
Tue Apr 17, 2018 11:48 am
Forum: Forwarding Protocols
Topic: RFC7911
Replies: 1
Views: 108

Re: RFC7911

Currently no.
by mrz
Mon Apr 16, 2018 1:57 pm
Forum: General
Topic: netinstall defaul configuration
Replies: 7
Views: 316

Re: netinstall defaul configuration

Because when you log and run import manually, all drivers are already loaded.
by mrz
Thu Apr 12, 2018 12:02 pm
Forum: Virtualization
Topic: What machine for 40Gbps Edge Router?
Replies: 10
Views: 631

Re: What machine for 40Gbps Edge Router?

There was a good presentation at EU MUM about CHR performance on different hypervisors
https://youtu.be/xcgdGA1W_0o
by mrz
Wed Apr 11, 2018 3:14 pm
Forum: Virtualization
Topic: What machine for 40Gbps Edge Router?
Replies: 10
Views: 631

Re: What machine for 40Gbps Edge Router?

Only your host must support 40G interfaces. CHR uses virtual interfaces.
by mrz
Wed Apr 11, 2018 1:12 pm
Forum: General
Topic: netinstall defaul configuration
Replies: 7
Views: 316

Re: netinstall defaul configuration

Use delay at the top of the script or loop to wait for ethernet interfaces. It is necessary because script may be executed before drivers are loaded.
by mrz
Wed Apr 11, 2018 1:10 pm
Forum: General
Topic: AP and separate DHCP on same RB
Replies: 23
Views: 554

Re: AP and separate DHCP on same RB

Your NAT rule is will not work because your specified out-interface is a slave.
by mrz
Wed Apr 11, 2018 1:03 pm
Forum: General
Topic: VPLS fragmentation
Replies: 3
Views: 168

Re: VPLS fragmentation

Yes, VPLS packets are fragmented silently. You can see if packet is fragmented by running packet sniffer on out interface.
by mrz
Mon Apr 09, 2018 3:52 pm
Forum: RouterBOARD hardware
Topic: CCR1072-1G-8S+ max number of routes
Replies: 3
Views: 244

Re: CCR1072-1G-8S+ max number of routes

Max theoretical number of routes depends on installed amount of RAM:
https://wiki.mikrotik.com/wiki/Manual:B ... e_table.3F
by mrz
Mon Apr 09, 2018 3:50 pm
Forum: RouterBOARD hardware
Topic: MUM Europe 2018 - New hardware incoming
Replies: 18
Views: 2223

Re: MUM Europe 2018 - New hardware incoming

Great, however not sure why the included QSFP in these models. Compared with other vendors usually 4 x SFP+ is enough. The only usually include QSFP if the ports are all 10Ge or SFP+. Not complaining as such, but a little strange.
QSFP+ could be used for future features, like stacking.
by mrz
Thu Mar 29, 2018 1:22 pm
Forum: Wireless Networking
Topic: CapsMan not providing DHCP addresses when virtual WLAN Interface changes.
Replies: 4
Views: 129

Re: CapsMan not providing DHCP addresses when virtual WLAN Interface changes.

Of course you need wlan interface in the bridge, if DHCP server is reachable on the bridge.
There is an option to add automatically created interfaces in the bridge.
by mrz
Wed Mar 28, 2018 6:07 pm
Forum: RouterBOARD hardware
Topic: LHG 60G
Replies: 36
Views: 5914

Re: LHG 60G

Yes, it is the same.
by mrz
Wed Mar 28, 2018 5:58 pm
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 40140

Re: Urgent security advisory

Yes, upgrade and for security reasons change password, too.
by mrz
Wed Mar 28, 2018 5:35 pm
Forum: General
Topic: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection
Replies: 8
Views: 237

Re: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection

And as I mentioned master port will have link as long as one of its slaves has link.

If ether6 is not master in your configuration then contact support with attached supout.rif file.
by mrz
Wed Mar 28, 2018 5:14 pm
Forum: General
Topic: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection
Replies: 8
Views: 237

Re: RB3011UiAS-RM router issue with eht06 blinking with no cable and disconnection

Depends on your configuration, most likely in your config ether6 is master port. Master port will always be on as long as there are link for any of its slaves.
by mrz
Tue Mar 27, 2018 3:29 pm
Forum: Scripting
Topic: Mikrotik script run once/twice and stop
Replies: 1
Views: 95

Re: Mikrotik script run once/twice and stop

Do not use console numbers in scripts.
by mrz
Mon Mar 26, 2018 4:19 pm
Forum: General
Topic: DCHP Option 119 (domain search)
Replies: 4
Views: 1105

Re: DCHP Option 119 (domain search)

Why can't you just use string value?

[admin@MikroTik] /ip dhcp-server option> add name=119 code=119 value="s'clients.example.com,office.example.com'"
by mrz
Fri Mar 23, 2018 5:47 pm
Forum: General
Topic: Lost connection to multiple LHG units
Replies: 24
Views: 994

Re: Lost connection to multiple LHG units

There were no any fw rules at customer side :(
Bad Idea, even worse if router has direct access from internet.
by mrz
Fri Mar 23, 2018 4:27 pm
Forum: General
Topic: Mikrotik FTP users permissions to specific directory ? [SOLVED]
Replies: 2
Views: 140

Re: Mikrotik FTP users permissions to specific directory ? [SOLVED]

Not possible, MT router is not fully functional FTP server.
by mrz
Fri Mar 23, 2018 1:53 pm
Forum: Beginner Basics
Topic: No internet router Mikrotik
Replies: 13
Views: 766

Re: No internet router Mikrotik

Only CCR hat had switch chip was first CCR1009, the one without combo port.
by mrz
Fri Mar 23, 2018 1:39 pm
Forum: General
Topic: firewall advice to pppoe_client customers [SOLVED]
Replies: 26
Views: 729

Re: firewall advice to pppoe_client customers [SOLVED]

Order should be
established,related first
then drop invalid.

Due to reasons anav already mentioned.
by mrz
Wed Mar 21, 2018 6:35 pm
Forum: General
Topic: REVOKED CERTIFICATE STILL WORK
Replies: 5
Views: 176

Re: REVOKED CERTIFICATE STILL WORK

Whatever address will be reachable by the client.
by mrz
Wed Mar 21, 2018 6:19 pm
Forum: General
Topic: REVOKED CERTIFICATE STILL WORK
Replies: 5
Views: 176

Re: REVOKED CERTIFICATE STILL WORK

crl host is where crl list will be stored. It cab be routers address, where CA is generated.
by mrz
Wed Mar 21, 2018 5:07 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 728
Views: 132857

Re: Feature requests

This is already possible.
Connect to one router. Set columns you want to see, open windows etc.
Select session/save as

Next time before connecting to new router pick saved session.
by mrz
Wed Mar 21, 2018 2:27 pm
Forum: General
Topic: firewall advice to pppoe_client customers [SOLVED]
Replies: 26
Views: 729

Re: firewall advice to pppoe_client customers [SOLVED]

WAN and LAN are interface lists. You just need to edit WAN interface list.
by mrz
Wed Mar 21, 2018 1:46 pm
Forum: General
Topic: firewall advice to pppoe_client customers [SOLVED]
Replies: 26
Views: 729

Re: firewall advice to pppoe_client customers [SOLVED]

Default firewall rules in latest versions already have protection in such setups.
by mrz
Tue Mar 20, 2018 4:26 pm
Forum: General
Topic: CCR1009-7G-1C No buffer space available
Replies: 23
Views: 912

Re: CCR1009-7G-1C No buffer space available

That is not the case. PPPoE does not use ARP, route cache can be leaked from something else. Generate supout file and send to support.
by mrz
Mon Mar 19, 2018 2:16 pm
Forum: Forwarding Protocols
Topic: BGP multihoming - strange routing issue
Replies: 7
Views: 434

Re: BGP multihoming - strange routing issue

Here you can find how best BGP route is selected in ROS:
https://wiki.mikrotik.com/wiki/Manual:B ... _Algorithm
by mrz
Fri Mar 09, 2018 5:59 pm
Forum: General
Topic: After upgrade firmware 6.40.5, Can't change admin's group to full
Replies: 43
Views: 1775

Re: After upgrade firmware 6.40.5, Can't change admin's group to full

Well if you got lucky and there was no rx-bits-per-second on any of interfaces when script was executed, then reformat-hold-button=299-5 and reformat-hold-button-max=300-5.
by mrz
Fri Mar 09, 2018 5:07 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM
Replies: 6
Views: 517

Re: CRS328-24P-4S+RM

I don't know where are you looking, but it is in products web page.
by mrz
Fri Mar 09, 2018 1:58 pm
Forum: General
Topic: L2TP VPN Client Limit on Level6 [SOLVED]
Replies: 5
Views: 334

Re: L2TP VPN Client Limit on Level6 [SOLVED]

Error has nothing to do with your router. Remote server sends this error, so you should ask provider why this limit is reached.
by mrz
Thu Mar 08, 2018 6:06 pm
Forum: Beginner Basics
Topic: L2TP/IPsec VPN
Replies: 9
Views: 493

Re: L2TP/IPsec VPN

Depends what you have set in your client settings, if you set to route everything over VPN then it will do so. How to set routes in your PC refer to OS vendor documentation.
by mrz
Thu Mar 08, 2018 6:03 pm
Forum: Forwarding Protocols
Topic: routing filter set-bgp-communities ASN 32bit bug/error
Replies: 3
Views: 215

Re: routing filter set-bgp-communities ASN 32bit bug/error

How do you expect it to be fixed? BGP communities are only 4bytes, so it is like trying to carry 2 litres of water in one litre bottle.

Only Extended communities can be used instead.
by mrz
Thu Mar 08, 2018 5:46 pm
Forum: Beginner Basics
Topic: L2TP/IPsec VPN
Replies: 9
Views: 493

Re: L2TP/IPsec VPN

By adding routes manually on your PC, not to route specific networks over the tunnel.
by mrz
Thu Mar 08, 2018 5:42 pm
Forum: Forwarding Protocols
Topic: TE- Failover Testing
Replies: 3
Views: 229

Re: TE- Failover Testing

By enabling BFD or reducing OSPF dead interval

and

setting lower TE reoptimize interval and primary-retry-interval