Community discussions

Search found 5549 matches

by mrz
Mon Jul 23, 2018 2:46 pm
Forum: General
Topic: IPSec PH-1 did not working with sha256
Replies: 2
Views: 22

Re: IPSec PH-1 did not working with sha256

You need to set sha256 for phase1 on both ends, not just on CCR.
by mrz
Mon Jul 23, 2018 2:23 pm
Forum: General
Topic: CRS317 - HW. Offloading only works on a single bridge, is it a bug?
Replies: 2
Views: 50

Re: CRS317 - HW. Offloading only works on a single bridge, is it a bug?

Currently yes, HW only on one bridge.
by mrz
Fri Jul 20, 2018 6:20 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: EoIP with DDNS [SOLVED]
Replies: 5
Views: 212

Re: EoIP with DDNS [SOLVED]

set local-address to 0.0.0.0 then it will be automatically picked
by mrz
Fri Jul 20, 2018 5:01 pm
Forum: General
Topic: PPTP / security / fire-walling brute force / timeout / compression - MPLS [SOLVED]
Replies: 2
Views: 96

Re: PPTP / security / fire-walling brute force / timeout / compression - MPLS [SOLVED]

PPTP is very unsecure, use other more secure tunnels, for example sstp, ipsec.
by mrz
Fri Jul 20, 2018 3:14 pm
Forum: Forwarding Protocols
Topic: MPLS TE Bug?
Replies: 9
Views: 278

Re: MPLS TE Bug?

It will not affect traffic, because this value does not represent actual traffic on interface (unless you are using auto bandwidth limitation feature).
by mrz
Fri Jul 20, 2018 1:54 pm
Forum: General
Topic: Ikev2 + Eap Radius + Windows 10 Not Working - But Working On Apple Devices
Replies: 5
Views: 200

Re: Ikev2 + Eap Radius + Windows 10 Not Working - But Working On Apple Devices

Most likely it is not the whole chain but only part of it. Take into consideration that if CRL is used, then CRL can be signed by completely different CA chain.
by mrz
Fri Jul 20, 2018 1:49 pm
Forum: Forwarding Protocols
Topic: MPLS TE Bug?
Replies: 9
Views: 278

Re: MPLS TE Bug?

Yes, currently it is not possible to set 10G value, since it is administrative value you can choose lower numbers, it does not have to represent actual bandwidth.
by mrz
Thu Jul 19, 2018 6:23 pm
Forum: General
Topic: Bridge Interface Link Local address generation
Replies: 1
Views: 70

Re: Bridge Interface Link Local address generation

Yes, ll addresses are generated from MAC address. From your provided info it is hard to tell why you have identical ll addresses, generate supout files and contact support.
by mrz
Thu Jul 19, 2018 5:25 pm
Forum: General
Topic: PROXY HTTPS
Replies: 6
Views: 190

Re: PROXY HTTPS

ROS Web proxy can work only with http traffic.
by mrz
Thu Jul 19, 2018 5:01 pm
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 38
Views: 4479

Re: Winbox v3.16 released!

Win10 and linux+wine did not experience any of your listed problems.
by mrz
Thu Jul 19, 2018 2:37 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 815
Views: 141995

Re: Feature requests

[admin@rOS] /ip firewall> filter add time=

Time ::= [!]Start-End,Day
Start -- 0s..1d (time interval)
End -- 0s..1d (time interval)
Day ::= sun|mon|tue|wed|thu|fri|sat[,Day*]
by mrz
Thu Jul 19, 2018 2:20 pm
Forum: General
Topic: Ikev2 + Eap Radius + Windows 10 Not Working - But Working On Apple Devices
Replies: 5
Views: 200

Re: Ikev2 + Eap Radius + Windows 10 Not Working - But Working On Apple Devices

If it works with self signed and does not work with cert provider certs, then you simply did not install full cert chain.
by mrz
Wed Jul 18, 2018 2:23 pm
Forum: Forwarding Protocols
Topic: VLANS over VPLS
Replies: 4
Views: 159

Re: VLANS over VPLS

Then bridge only vpls with ethernet, vlan tags will be forwarded over the tunnel and will be managed by switches.
by mrz
Wed Jul 18, 2018 1:57 pm
Forum: Forwarding Protocols
Topic: VLANS over VPLS
Replies: 4
Views: 159

Re: VLANS over VPLS

You don't need to add vlan on vpls interfce. add vlans on ethernet and bridge them with VPLS tunnel.
by mrz
Tue Jul 17, 2018 5:13 pm
Forum: Beginner Basics
Topic: Any MikroTik dsl router with netflow capabiliies
Replies: 3
Views: 174

Re: Any MikroTik dsl router with netflow capabiliies

Mikrotik DSL router does not exist.
by mrz
Mon Jul 16, 2018 4:47 pm
Forum: Scripting
Topic: I defined the variable... but the function doesn't process it.
Replies: 10
Views: 245

Re: I defined the variable... but the function doesn't process it.

Either use :parse or better option write a function. See examples in the manual
https://wiki.mikrotik.com/wiki/Manual:S ... #Functions
by mrz
Mon Jul 16, 2018 4:38 pm
Forum: Scripting
Topic: I defined the variable... but the function doesn't process it.
Replies: 10
Views: 245

Re: I defined the variable... but the function doesn't process it.

What exactly you want to do?
You need to compare string value from V1 to something to return boolean.
by mrz
Mon Jul 16, 2018 4:17 pm
Forum: Scripting
Topic: I defined the variable... but the function doesn't process it.
Replies: 10
Views: 245

Re: I defined the variable... but the function doesn't process it.

You V1 value is string:
:global V1 "($timetest>09:00:00)and($timetest<17:00:00)"

Of course it cannot be used as boolean.
by mrz
Mon Jul 16, 2018 11:40 am
Forum: Scripting
Topic: How to read file content using API?
Replies: 6
Views: 212

Re: How to read file content using API?

You can't directly with api. Download file via ftp and then read content locally.
by mrz
Fri Jul 13, 2018 6:35 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 443
Views: 55637

Re: v6.43rc [release candidate] is released!

default now is aes-sha256
by mrz
Fri Jul 13, 2018 6:34 pm
Forum: Scripting
Topic: How to read file content using API?
Replies: 6
Views: 212

Re: How to read file content using API?

<<< /file/get
<<< =.id=*D034A
<<< =.proplist=contents
<<<
by mrz
Fri Jul 13, 2018 12:28 pm
Forum: Scripting
Topic: How to read file content using API?
Replies: 6
Views: 212

Re: How to read file content using API?

You will not get file content if file size is larger than 4KB.
by mrz
Thu Jul 12, 2018 7:51 pm
Forum: Scripting
Topic: /system default-configuration
Replies: 4
Views: 204

Re: /system default-configuration

It will not be configurable from RouterOS, in the future we might show configuration applied by netinstall there, but at the moment it will always show factory default configuration.
by mrz
Thu Jul 12, 2018 2:56 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 443
Views: 55637

Re: v6.43rc [release candidate] is released!

If dhcpv6 was not working reliably for you then upgrade.
by mrz
Wed Jul 11, 2018 1:57 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: LLDP
Replies: 122
Views: 35344

Re: LLDP

I completely agree that some features are still missing, but that doesn't fit a statement that MT is not doing anything since since 2010
by mrz
Wed Jul 11, 2018 12:29 pm
Forum: Virtualization
Topic: CHR ova 6.41rc31 downgrade to 6.38.7
Replies: 3
Views: 674

Re: CHR ova 6.41rc31 downgrade to 6.38.7

Just like error says min allowed version is 6.41.3
by mrz
Tue Jul 10, 2018 6:22 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: LLDP
Replies: 122
Views: 35344

Re: LLDP

Please clarify "not doing anything"? LLDP initial support was added in 2016-Sep-30
by mrz
Tue Jul 10, 2018 6:19 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Two LTE miniPCIe-modules not working on RBM33G [BUG]
Replies: 9
Views: 584

Re: Two LTE miniPCIe-modules not working on RBM33G [BUG]

3. What endpoints did the employee mean. support, when offered to reduce them? Here is explanation what is USB endpoint https://www.keil.com/pack/doc/mw/USB/html/_u_s_b__endpoints.html At the moment it looks like you are deliberately cutting some devices, so that people buy your r11e_lte... It is n...
by mrz
Tue Jul 10, 2018 3:39 pm
Forum: Scripting
Topic: Cannot start scripts by names from netwatch [SOLVED]
Replies: 5
Views: 178

Re: Cannot start scripts by names from netwatch [SOLVED]

From chanelog:
*) netwatch - limit to read, write, test and reboot policies for Netwatch script execution;

Make sure that scripts does not exceed these policies.
by mrz
Tue Jul 10, 2018 3:20 pm
Forum: Scripting
Topic: Cannot start scripts by names from netwatch [SOLVED]
Replies: 5
Views: 178

Re: Cannot start scripts by names from netwatch [SOLVED]

Make sure that script you want to execute does not have more permissions that allowed by netwatch.
by mrz
Tue Jul 10, 2018 12:57 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: IPv6 - by default
Replies: 7
Views: 442

Re: IPv6 - by default

There are default ipv6 firewall rules, when you enable ipv6, reset configuration then ipv6 rules will be applied.
by mrz
Fri Jun 22, 2018 3:14 pm
Forum: Announcements
Topic: v6.42.4 [current]
Replies: 93
Views: 9053

Re: v6.42.4 [current]

upower3, pe1chl - API problem will be fixed in next version.
by mrz
Fri Jun 22, 2018 12:21 pm
Forum: General
Topic: PPPOE ERROR or May be "BUG"
Replies: 4
Views: 170

Re: PPPOE ERROR or May be "BUG"

Solution for what exactly? Either you allow user to log in multiple times or not.
by mrz
Fri Jun 22, 2018 11:53 am
Forum: General
Topic: PPPOE ERROR or May be "BUG"
Replies: 4
Views: 170

Re: PPPOE ERROR or May be "BUG"

Of course if you enable "only one" then router will not allow multiple connections of the same user.
by mrz
Thu Jun 21, 2018 12:16 pm
Forum: Forwarding Protocols
Topic: MPLS/VPLS will not form between iBGP neighbors
Replies: 23
Views: 617

Re: MPLS/VPLS will not form between iBGP neighbors

LDP will not assign labels to BGP routes
by mrz
Wed Jun 20, 2018 12:12 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: ROS 7 Beta
Replies: 21
Views: 2607

Re: ROS 7 Beta

It is interesting that you are waiting for something and you do not remember even what it was :D
by mrz
Tue Jun 19, 2018 4:27 pm
Forum: General
Topic: Maximum speed on 10 Gb port for mikrotik CCR1036
Replies: 5
Views: 308

Re: Maximum speed on 10 Gb port for mikrotik CCR1036

9.9Gbps

maybe you have 1.25Gbps SFP module.
by mrz
Tue Jun 19, 2018 2:39 pm
Forum: Virtualization
Topic: CHR P-Unlimited - amount of L2TP - PPTP - EOIP ?
Replies: 6
Views: 289

Re: CHR P-Unlimited - amount of L2TP - PPTP - EOIP ?

Depends on available resources on host.
by mrz
Tue Jun 19, 2018 11:05 am
Forum: General
Topic: S.O.S New vurnelabilty on 6.42.3 ????? [SOLVED]
Replies: 22
Views: 3589

Re: S.O.S New vurnelabilty on 6.42.3 ????? [SOLVED]

Did you change passwords after you upgraded to latest version?
by mrz
Tue Jun 19, 2018 11:02 am
Forum: Virtualization
Topic: CHR neighbour discovery problem
Replies: 5
Views: 372

Re: CHR neighbour discovery problem

Looks to me like host configuration problem. I can see from CHR all other CHRs and other devices in neighbor list, Winbox discovers all CHRs with no problems: [admin@MikroTik] /ip neighbor> print # INTERFACE ADDRESS MAC-ADDRESS IDENTITY VERSION 0 ether1 2.2.2.2 08:00:27:8B:66:7F MikroTik 7.0beta... ...
by mrz
Mon Jun 18, 2018 3:10 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)
Replies: 10
Views: 770

Re: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)

Ike2 and DHCP server are completely unrelated. DHCP server does not give out addresses after ike2 client connects, if that is what you are trying to do. If you are asing about DHCP unrelated to ike2 connection then see the manual how to add options: https://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Serv...
by mrz
Mon Jun 18, 2018 12:14 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 180
Views: 47127

Re: VPNfilter official statement

What are you talking about?
v6.40.8 includes patches to fix known vulnerabilities including latest winbox port vulnerability.
by mrz
Mon Jun 18, 2018 12:05 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)
Replies: 10
Views: 770

Re: Bugreport: Split-include buggy for (at least) IKEv2 (6.40.2 current and 6.41rc18)

Windows ignores splitnets configured on the router.

A for DHCP option 121 you can already do that by configuring options on DHCP server.
by mrz
Fri Jun 15, 2018 6:42 pm
Forum: Announcements
Topic: VPNfilter official statement
Replies: 180
Views: 47127

Re: VPNfilter official statement

Security advisory emails were sent to all users that are in our database.
by mrz
Fri Jun 15, 2018 1:41 pm
Forum: RouterBOARD hardware
Topic: RB850Gx2 vs RB450Gx4
Replies: 49
Views: 3538

Re: RB850Gx2 vs RB450Gx4

To keep you guys busy with speculations :D
by mrz
Fri Jun 15, 2018 11:29 am
Forum: Forwarding Protocols
Topic: BGP IP Issue
Replies: 4
Views: 259

Re: BGP IP Issue

Use firewall with dst-limit and add-to-address-list action.
by mrz
Thu Jun 14, 2018 3:48 pm
Forum: Beginner Basics
Topic: No wireless interface on RB941-2nD-TC
Replies: 7
Views: 327

Re: No wireless interface on RB941-2nD-TC

Contact support
by mrz
Thu Jun 14, 2018 1:41 pm
Forum: Scripting
Topic: How to hide output of "once"
Replies: 3
Views: 155

Re: How to hide output of "once"

You can't. It will always be printed to terminal.
by mrz
Wed Jun 13, 2018 5:28 pm
Forum: General
Topic: L2TP IPSec (no suit proposal found)
Replies: 57
Views: 1499

Re: L2TP IPSec (no suit proposal found)

Do you have location's C IP address added as ipsec peer on the server or not??
by mrz
Wed Jun 13, 2018 5:26 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 443
Views: 55637

Re: v6.43rc [release candidate] is released!

Please read the changelog.