Community discussions

MikroTik App

Search found 18 matches

by lvader
Wed May 24, 2023 6:18 pm
Forum: General
Topic: IPv6, tunnels and TCP MSS
Replies: 2
Views: 996

Re: IPv6, tunnels and TCP MSS

in that particular case, the chain forward or postrouting doesn't matter that much. The post was more about non-functional parameter clamp-tcp-mss=yes on 6to4 interface. if it is not something that is not supposed to inject automatic mangle rules, then probably it should be documented somehow?
by lvader
Tue May 23, 2023 6:37 pm
Forum: General
Topic: IPv6, tunnels and TCP MSS
Replies: 2
Views: 996

IPv6, tunnels and TCP MSS

Some time ago I started to notice some strange "tls timeouts" to some sites hosted at AWS or e.g. GitHub when connection is done over IPv6. I didn't pay attention to that for a while, as those were rare occasions, but recently got curious and tried to debug. To my surprise, I've noticed th...
by lvader
Wed May 17, 2023 10:24 pm
Forum: Forwarding Protocols
Topic: minimal example of BGP with both ipv4 and ipv6?
Replies: 2
Views: 2622

Re: minimal example of BGP with both ipv4 and ipv6?

I have interface, let's say ve1. This interface has both ipv4 and ipv6 addresses (10.81.81.0/24 and fd66:107::/64). bgp session is done on ipv4 addresses The best what I've come up with is something like below. It works, but I don't like this manual setup of nexthop. If I don't do it, it announces f...
by lvader
Tue May 02, 2023 7:10 pm
Forum: Forwarding Protocols
Topic: minimal example of BGP with both ipv4 and ipv6?
Replies: 2
Views: 2622

minimal example of BGP with both ipv4 and ipv6?

Good day.

Anyone have minimal example of ROSv7 BGP connection between two routers over ethernet/vxlan with both ipv4 and ipv6?
From my trials I'm not able to control properly ipv6 address of nexthop if bgp connection is established over ipv4 and afi=ip,ipv6.
by lvader
Sat Jan 14, 2023 11:05 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 113987

Re: v7.7 [stable] is released!

You are right, it is behaving like a masquerade. It's a bug for sure. But also I recommend you avoid NAT66 crap and use NPTv6 instead via mangle, it will preserve the end-to-end princple which NAT of any kind cannot. NPTv6 unfortunately is also buggy. In my experiments it is matching the firewall r...
by lvader
Sat Jan 14, 2023 1:19 am
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 113987

Re: v7.7 [stable] is released!

ipv6 netmap seems to be still broken in this release It's probably your configuration. Works fine for me, including NPTv6 via mangle which is better than netmap as it is stateless. Please double check what you really getting on network side. right now netmap behaves like masquerade. /ipv6 firewall ...
by lvader
Fri Jan 13, 2023 11:23 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 113987

Re: v7.7 [stable] is released!

ipv6 netmap seems to be still broken in this release
by lvader
Tue Dec 20, 2022 6:08 pm
Forum: General
Topic: IPv6 policy routing example.
Replies: 3
Views: 1297

Re: IPv6 policy routing example.

You can update rules for dynamic prefix from lease script.
Thanks for idea, will try. I was trying to avoid hardcoding addresses in the rules.
One idea that I had was to mark-connection on forward chain in mangle, but that seems not working, at least in 7.7rc2.
by lvader
Tue Dec 20, 2022 4:39 pm
Forum: General
Topic: IPv6 policy routing example.
Replies: 3
Views: 1297

IPv6 policy routing example.

Hi. Setup that I have: - two ipv6 tunnels, one from HE.net, another from local ISP via 6rd. - /48 block from HE.net (statically allocated), /56 block from local ISP 6rd (dynamic) - bunch of hosts in "DMZ" and "LAN" that have native IPv6 connectivity on ethernet or wifi. what I'm ...
by lvader
Mon Dec 12, 2022 11:07 am
Forum: Scripting
Topic: newb in scripting: getting byte value from lease-options string.
Replies: 3
Views: 758

Re: newb in scripting: getting byte value from lease-options string.

Well, unfortunately that is not that easy. DHCP option comes as raw byte array inside string type, not as hex string representation. Format of option 212 is like this (values are a bit changed, but should be good enough to get the idea): :local v212 "\0E\26\20\01\22\02\F0\00\00\00\00\00\00\00\0...
by lvader
Sun Dec 11, 2022 2:23 pm
Forum: Scripting
Topic: newb in scripting: getting byte value from lease-options string.
Replies: 3
Views: 758

newb in scripting: getting byte value from lease-options string.

Good day. I'm relatively new to mikrotik scripting, so haven't found myself good answer and asking for pointers to right direction. I'm trying to parse as part of dhcp-client lease script variable in lease-options array. Specifically the option 212 (6rd dhcp info). It is present there as type string...
by lvader
Mon May 02, 2022 10:09 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 81796

Re: v7.2.2 [stable] is released!

For l2tp issue in 7.2.x, I've noticed it also became broken, and after some investigation noticed that default ipsec policy got modified somehow. So, if you have in your config after upgrade something like /ip ipsec policy set 0 dst-address=2001:xxxx/128 src-address=2001:yyyy/128 reset it back to de...
by lvader
Wed Mar 30, 2022 1:24 pm
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40074

Re: v7.1.4 and v7.1.5 is released!

Small fix/suggestion for default configs: if l2tp vpn enabled, those rules are generated. However, this will not work if IPSec enabled for l2tp, the other mikrotik l2tp-clients can't establish connections with it. /ip firewall filter add action=accept chain=input comment="allow IPsec NAT" ...
by lvader
Mon Dec 27, 2021 1:37 pm
Forum: Announcements
Topic: v6.49.2 [stable] is released!
Replies: 64
Views: 124387

Re: v6.49.2 [stable] is released!

Tried to upgrade to 6.49.x on my CRS112-8P-4S. Two SFP-RJ45 adapters stopped to work ("no link") that were previously worked great for almost 4 years. Reverting back to 6.48.6 solved the issue. :( SFP info: marked as "juniper networks": Vendor Name Methode Elec. Vendor Part Numbe...
by lvader
Sat May 08, 2021 4:18 pm
Forum: Announcements
Topic: v6.48.2 [stable] is released!
Replies: 141
Views: 62333

Re: v6.48.2 [stable] is released!

webfig - show "Interfaces" menu by default after logging in;
for me this became broken recently on one of devices (hap ac), and not solved with 6.48.2: when logged in to webfig, it shows "quickset". Is there way to disable quickset alltogether?
by lvader
Wed Mar 06, 2019 7:35 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 304
Views: 157774

Re: v6.45beta [testing] is released!

*) ipsec - fixed dynamic L2TP peer and identity configuration missing after reboot (introduced in v6.44);
would be great to get this fix also to stable 6.44. Very annoying.
by lvader
Tue Feb 26, 2019 1:35 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 96993

Re: v6.44 [stable] is released!

*) defconf - fixed IPv6 link-local address range in firewall rules;
a bit more details on this change? Those default rules are not upgraded automatically, so it would be good to see what exactly changed.
And in overall, it would be good to keep on wiki defconfs for each big releases.